ISC CISSP-ISSEP Exam
Information Systems Security Engineering Professional (Page 9 )

Updated On: 9-Feb-2026

The DoD 8500 policy series represents the Department's information assurance strategy. Which of the following objectives are defined by the DoD 8500 series?
Each correct answer represents a complete solution. Choose all that apply.

  1. Providing IA Certification and Accreditation
  2. Providing command and control and situational awareness
  3. Defending systems
  4. Protecting information

Answer(s): B,C,D



Which of the following security controls is a set of layered security services that address communications and data security problems in the emerging Internet and intranet application space?

  1. Internet Protocol Security (IPSec)
  2. Common data security architecture (CDSA)
  3. File encryptors
  4. Application program interface (API)

Answer(s): B



Fill in the blank with the appropriate phrase. The ____________ is the risk that remains after the implementation of new or enhanced controls.

  1. residual risk

Answer(s): A



Fill in the blank with an appropriate section name. _________________ is a section of the SEMP template, which specifies the methods and reasoning planned to build the requisite trade-offs between functionality, performance, cost, and risk.

  1. System Analysis

Answer(s): A



You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems?

  1. NIST Special Publication 800-59
  2. NIST Special Publication 800-37
  3. NIST Special Publication 800-60
  4. NIST Special Publication 800-53

Answer(s): B






Post your Comments and Discuss ISC CISSP-ISSEP exam prep with other Community members:

Join the CISSP-ISSEP Discussion