ISC2 ISSEP Exam
Information Systems Security Engineering Professional (Page 10 )

Updated On: 9-Feb-2026

What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process Each correct answer represents a complete solution. Choose all that apply.

  1. Develop DIACAP strategy.
  2. Initiate IA implementation plan.
  3. Conduct validation activity.
  4. Assemble DIACAP team.
  5. Register system with DoD Component IA Program.
  6. Assign IA controls.

Answer(s): A,B,D,E,F



You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems

  1. NIST Special Publication 800-59
  2. NIST Special Publication 800-37
  3. NIST Special Publication 800-60
  4. NIST Special Publication 800-53

Answer(s): B



Which of the following documents is described in the statement below It is developed along with all processes of the risk management. It contains the results of the qualitative risk analysis, quantitative risk analysis, and risk response planning.

  1. Risk management plan
  2. Project charter
  3. Quality management plan
  4. Risk register

Answer(s): D



Diane is the project manager of the HGF Project. A risk that has been identified and analyzed in the project planning processes is now coming into fruition. What individual should respond to the risk with the preplanned risk response

  1. Project sponsor
  2. Risk owner
  3. Diane
  4. Subject matter expert

Answer(s): B



Which of the following refers to a process that is used for implementing information security?

  1. Classic information security model
  2. Certification and Accreditation (C&A)
  3. Information Assurance (IA)
  4. Five Pillars model

Answer(s): B






Post your Comments and Discuss ISC2 ISSEP exam prep with other Community members:

Join the ISSEP Discussion