Practice ISC Security Planning And Engineering questions with full explanations on every answer.
Start practicing
Security Planning And Engineering — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During the design of a PKI hierarchy for a highly classified system, the ISSEP needs to ensure that the Root CA is kept offline. What is the most appropriate way to sign the Subordinate CA request?
2An ISSEP is evaluating the security of an API gateway. To implement OAuth 2.0 effectively, which flow should be recommended for a native mobile application?
3A system is being designed to process PII. The requirement is to maintain data sovereignty while utilizing a hybrid cloud model. What architectural strategy best achieves this?
4An ISSEP is designing a secure architecture for a cloud environment using NIST SP 800-160. Which architectural pattern should the engineer prioritize to ensure the principle of Least Privilege is enforced at the service-to-service communication layer within a Kubernetes cluster?
5When applying NIST SP 800-53 controls to a new information system, which step occurs immediately after the 'Categorize' process in the RMF?
6When configuring AWS Security Groups for a multi-tier application architecture, an engineer must ensure that the web tier only communicates with the application tier on port 8080. Which configuration best adheres to the principle of Defense in Depth?
7An ISSEP is configuring a WAF to mitigate OWASP Top 10 risks. Which configuration best addresses the 'Injection' category?
8An ISSEP is conducting a gap analysis between a legacy system and ISO/IEC 27001 requirements. The system lacks automated audit logging. Which control implementation is most effective for meeting the 'Logging and Monitoring' requirements?
9An ISSEP must secure a server-to-server connection that currently uses plaintext LDAP. What is the recommended secure alternative?
10In a Zero Trust architecture, what is the most critical function of a Policy Decision Point (PDP)?
11When designing an information system architecture, what is the primary role of a System Security Plan (SSP)?
12An ISSEP is designing a secure CI/CD pipeline. Which technique is most effective for preventing secrets (e.g., API keys) from being committed to the source code repository?
13When implementing FIPS 140-2/-3 validated cryptography in a system, what is the most important factor to verify?
14An organization is adopting ISO 27001. Which document is required to justify the inclusion or exclusion of specific controls?
15You are designing a secure data enclave for highly sensitive research data. What is the most robust method to enforce physical and logical separation?
16What is the primary objective of the 'Assessment' phase in the NIST RMF?
17A system uses SAML 2.0 for SSO. To prevent SAML assertion tampering, what is the mandatory cryptographic requirement?
18An ISSEP needs to secure inter-process communication (IPC) on a Linux host. Which feature should be configured to prevent unauthorized processes from accessing sensitive memory space?
19Which document is used to track and manage vulnerabilities identified during the assessment phase of the RMF?
20An ISSEP is designing a secure storage solution for a database. To ensure data integrity, which mechanism is most reliable?
21When designing for high availability and security, what is the best use of a Load Balancer (LB) from a security perspective?
22In a cloud environment, you must ensure that VM snapshots are encrypted. What is the most effective approach?
23When selecting controls for a system in a high-compliance environment, what is the best practice for tailoring?
24An ISSEP is architecting a secure API environment. Which strategy is most effective for throttling and preventing resource exhaustion?
25What is the correct order of operations when handling a vulnerability in a production system according to the RMF?
26When designing a secure multi-tenant cloud application, what is the best way to ensure tenant data isolation?
27What is the primary goal of the 'Authorization' phase in the NIST RMF?
28An ISSEP is tasked with securing an internal web application. Which headers should be implemented to prevent clickjacking?
29During a system migration, you need to ensure integrity of transferred data. What is the best cryptographic method?
30Which TWO of the following are considered critical components of a Secure Software Development Life Cycle (SDLC)?
31An ISSEP is configuring an AWS S3 bucket. What policy setting best prevents public access while allowing access from a specific VPC?
32Which TWO controls are recommended under NIST SP 800-53 for protecting data at rest in a high-impact system?
33Which TWO methods are effective for managing cryptographic keys in a cloud architecture?
34Which THREE of the following are recognized categories of security controls in NIST SP 800-53?
35Which TWO security standards are most relevant for an ISSEP designing a secure payment processing system?
36Which TWO items should be included in a system's security architecture documentation?
37Which THREE factors are essential when performing a threat model using the STRIDE methodology?
38Which THREE items are required to verify the integrity of a downloaded software package?
39Which THREE actions should be taken when decommissioning an information system to ensure data security?
40Which THREE elements are required in a high-security access control policy?
41Which THREE of the following are necessary to successfully implement Zero Trust in an existing enterprise environment?
42Which THREE methods can be used to ensure high availability for a database in a secure architecture?
43Which THREE items should be included in an Incident Response (IR) plan for an information system?
44An ISSEP architect is designing a system under NIST SP 800-53 controls and needs to implement an automated mechanism to enforce the principle of least privilege for non-privileged accounts. Which configuration in an AWS environment best aligns with the 'AC-6' control requirement?
45When mapping security requirements from ISO/IEC 27001 to a cloud-native architecture, you are configuring Azure Policy to ensure all newly created storage accounts have 'Secure transfer required' enabled. What is the most efficient way to achieve this enforcement?
46You are assessing a system for compliance with FIPS 140-3. You need to ensure that the cryptographic module being used for TLS termination on a load balancer meets specific physical security requirements. Where should you look for the validation status of the cryptographic module?
47An organization is migrating to a Zero Trust architecture as defined in NIST SP 800-207. Which component is responsible for evaluating the context of a request, such as device health and location, before granting access?
48You are designing a secure microservices architecture. To meet the 'Data at Rest' security requirements, you decide to use envelope encryption. Which sequence correctly describes the flow of managing the Data Encryption Key (DEK)?
49In the context of the NIST Risk Management Framework (RMF), which step involves the initial identification of security controls based on the system's impact level?
50You are conducting a threat modeling exercise using the STRIDE methodology. A specific service-to-service communication path lacks mutual TLS. Which STRIDE category does this vulnerability primarily fall under?
51When architecting a system to meet ISO 27001 requirements for secure system engineering, which TWO of the following design principles should be prioritized for protecting sensitive data at rest?
52An ISSEP professional is reviewing an architecture for compliance with NIST SP 800-160, Systems Security Engineering. Which THREE of the following activities are core to the 'Trustworthiness' objective for an engineered system?
53You are designing an incident response architecture for a cloud environment. Which TWO of the following configurations are critical for ensuring effective forensic readiness according to NIST SP 800-61?
The Security Planning And Engineering domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 53 questions in the Security Planning And Engineering domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Planning And Engineering domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included