ISC2 CISSP-ISSEP Certification Sample Questions

CISSP-ISSEP Dumps, CISSP-ISSEP Dumps, CISSP-ISSEP PDF, CISSP-ISSEP VCE, ISC2 CISSP-ISSEP VCE, ISC2 ISSEP PDFThe purpose of this Sample Question Set is to provide you with information about the ISC2 Information Systems Security Engineering Professional exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CISSP-ISSEP certification test. To get familiar with real exam environment, we suggest you try our Sample ISC2 CISSP-ISSEP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISC2 Information Systems Security Engineering Professional (CISSP-ISSEP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISC2 CISSP-ISSEP exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium ISC2 CISSP-ISSEP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISC2 CISSP-ISSEP Sample Questions:

01. An organization is aligning its systems security engineering activities with the Risk Management Framework. Which sequence lists the steps of that framework?
a) Prepare, categorize, select, implement, assess, authorize, monitor
b) Conduct, categorize, select, implement, assess, communicate, monitor
c) Prepare, conduct, select, implement, assess, authorize, monitor
d) Prepare, categorize, select, implement, assess, authorize, dispose
 
02. During implementation of a system security solution, the information systems security engineer contributes to the assessment and authorization activities, including the assessment of system-level controls. Findings from a system-level control assessment may require an update to which two artifacts?
(Choose two.)
a) The accepted test exit criteria
b) The organization-level risk assessment
c) The organization's security control catalog
d) The system-level risk assessment
 
03. A stakeholder asks the systems security engineer to confirm that the delivered system is absolutely trustworthy. Which response reflects how trustworthiness is established in systems security engineering?
a) The system is trustworthy once it provides protection sufficient to prevent any loss of assets under any operating condition the organization is able to foresee
b) The system is trustworthy once every emergent property, such as reliability, resilience, safety, scalability and survivability, has been demonstrated in test
c) Trustworthiness is always relative to a stated set of concerns and to the evidence produced for them, so no system can be declared trustworthy in absolute terms
d) The system is trustworthy once the responsible authority has authorized it to operate
 
04. During implementation, a security engineer contributes to the security assessment and authorization activities by providing input to the package on which the authorizing official will act. What does that authorization package consist of?
a) The security plan, the plan of action and milestones, and the security assessment report
b) The security plan, the plan of action and milestones, and the security control assessment plan
c) The security assessment plan, the plan of action and milestones, and the security assessment report
d) The security plan, the configuration management plan, and the security assessment report
 
05. An organization is deciding how thoroughly storage media must be sanitized before the equipment leaves its control. Which assessment drives that risk-based decision?
a) The system categorization taken at the high-water mark of all three security objectives
b) The availability impact level of the system that the media supported
c) The integrity impact level of the information recorded on the media
d) The confidentiality impact level of the information recorded on the media
 
06. Evidence is gathered during an incident primarily in order to resolve the incident itself. Which additional use of that evidence is the reason strict handling and chain-of-custody requirements are placed on it?
a) Capacity planning for the affected infrastructure
b) Legal proceedings arising from the incident
c) Audit and compliance reporting to the system owner
d) Retraining of the operations staff
 
07. A program is choosing between a predictive and an agile lifecycle for a system that carries security requirements. Which combination of characteristics describes an agile project lifecycle?
a) Requirements baselined up front, each phase performed once, and frequent small deliveries against it
b) Requirements baselined up front, each phase performed once, and a single delivery at the end of the effort
c) Dynamic requirements, work repeated until it is right, and frequent small deliveries that return value
d) Dynamic requirements, work repeated until it is right, and a single delivery when the product is complete
 
08. An organization is preparing to select the initial security control baseline for a new system. Which two determinations must be completed before that baseline can be selected?
(Choose two.)
a) The security categorization of each information type the system will process, store and transmit
b) The residual risk that will remain once every planned control has been implemented
c) The results of the security test and evaluation performed on the integrated system
d) The system impact level, taken as the highest impact assigned across confidentiality, integrity and availability
 
09. A systems security engineer must recommend a response for each analyzed risk. The organization's policy lists acceptance, avoidance, sharing and transfer among the available responses. Which further response completes that set?
a) Escalation, referring the risk to the authorizing official for a formal decision
b) Mitigation, reducing the likelihood or the impact of the risk by applying further controls
c) Deferral, postponing the decision until the next continuous monitoring cycle
d) Aggregation, combining related risks into a single entry on the risk register
 
10. When least privilege is applied to a system element, the privileges it retains are limited to those necessary for a single purpose. What is that purpose?
a) Supporting further functions the element may be given later
b) Satisfying the organization's compliance obligations
c) Performing the element's intended function
d) Matching the clearance held by the element's users

Answers:

Question: 01
Answer: a
Question: 02
Answer: b, d
Question: 03
Answer: c
Question: 04
Answer: a
Question: 05
Answer: d
Question: 06
Answer: b
Question: 07
Answer: c
Question: 08
Answer: a, d
Question: 09
Answer: b
Question: 10
Answer: c

Note: For any error in ISC2 Information Systems Security Engineering Professional (CISSP-ISSEP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (115 votes)