Courseiva

ISC · domain

Systems Security Engineering Foundations

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) Systems Security Engineering Foundations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

49 questions11 easy23 medium15 hard

Focused practice

Practice Systems Security Engineering Foundations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Systems Security Engineering Foundations

Systems Security Engineering Foundations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Systems Security Engineering Foundations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Systems Security Engineering Foundations questions (49)

Click any question to see the full explanation, or start a practice session above.

1

When designing for 'System Survivability', what is the most critical engineering principle to incorporate?

Hard
2

Which THREE activities are included in the 'Risk Management Framework' (RMF) step 'Assess'?

Medium
3

When applying NIST SP 800-160 Systems Security Engineering principles, which THREE activities are critical during the 'System Design' phase to ensure confidentiality and integrity?

Medium
4

In the context of the NIST Cybersecurity Framework, which function is specifically supported by the 'Systems Security Engineering' process during the 'Identify' stage?

Medium
5

Which principle suggests that the security of a system should not depend on the secrecy of its design or implementation?

Easy
6

Which TWO items should be included in a 'Security Requirements Traceability Matrix' (SRTM) to ensure comprehensive engineering coverage?

Medium
7

When designing high-availability systems, what is the primary security engineering concern regarding 'Fail-over' mechanisms?

Medium
8

Which THREE of the following are considered 'Common Criteria' (ISO/IEC 15408) elements for evaluating the security functionality of a product?

Medium
9

You are performing an audit of a new system's 'Trusted Computing Base' (TCB). Which observation would indicate a violation of the 'Separation of Duties' principle?

Medium
10

Which THREE security-relevant criteria should be assessed when evaluating a cloud service provider (CSP)?

Hard
11

Which THREE items should be included in a thorough 'System Security Plan' (SSP)?

Medium
12

An organization is adopting a DevSecOps model. To ensure security engineering principles are met, which tool should be integrated into the CI/CD pipeline to automate the detection of vulnerabilities in proprietary code during the 'Build' stage?

Hard
13

What is the primary advantage of 'Defense in Depth'?

Easy
14

When using the STRIDE threat modeling methodology, which security principle does 'Tampering' specifically attempt to violate?

Medium
15

Which THREE are key components of a 'Secure Development Lifecycle' (SDL) process?

Medium
16

Which engineering document should be created during the early stages of the system lifecycle to define the security-relevant mission goals and constraints?

Hard
17

When evaluating a system's resilience to 'Supply Chain Attacks', what is the most important engineering practice to implement?

Hard
18

When considering 'System Availability', what is the primary advantage of a 'Load Balancer' in a security engineering context?

Easy
19

When designing a system for 'High Integrity' (using the Biba model), which THREE rules must be enforced?

Hard
20

Which THREE factors must be evaluated when determining if a system component is 'security-critical'?

Easy
21

Which THREE activities are essential when conducting a 'Security Impact Analysis' for a proposed system change?

Hard
22

Which TWO architectural patterns are considered best practices for securing cloud-native applications?

Hard
23

Which THREE components are necessary to define a complete 'Security Policy' for an enterprise system?

Hard
24

When engineering a cryptographically secure system, what is the primary risk associated with custom cryptographic implementations?

Hard
25

In the context of 'Systems Engineering', what does the term 'Security-Enforcing' mean regarding a system component?

Hard
26

When designing a secure system architecture, which TWO of the following are primary considerations for achieving the principle of 'Defense in Depth'?

Hard
27

When conducting a security assessment of a system's 'Trusted Computing Base' (TCB), what is the most important attribute to verify?

Hard
28

Which TWO of the following are valid methods for maintaining the integrity of system design documentation throughout the system lifecycle?

Medium
29

In the systems engineering V-model, how does 'Verification' differ from 'Validation'?

Hard
30

Which THREE factors are critical for an effective 'Continuous Monitoring' (ConMon) program?

Medium
31

When engineering a 'Secure Boot' sequence, what is the primary security objective?

Hard
32

In the context of the System Development Life Cycle (SDLC), what is the primary purpose of a security control baseline?

Easy
33

Which security model is specifically designed to prevent the unauthorized flow of information from high-security levels to low-security levels (no read up, no write down)?

Easy
34

What is the primary function of an 'API Gateway' in a microservices security architecture?

Medium
35

What is the primary benefit of modularity in secure systems design?

Easy
36

What is the primary objective of a 'Security Design Review' early in the lifecycle?

Easy
37

What is the primary risk of a 'Privileged User' who lacks proper oversight?

Easy
38

You are integrating security requirements into the Systems Engineering V-Model. At which stage should the Information Systems Security Engineer (ISSE) define the security functional requirements to ensure traceability to the system architecture?

Medium
39

Which of the following is an example of an 'Administrative' security control?

Easy
40

When designing a system for 'Non-repudiation', which technical control is essential?

Medium
41

What is the primary purpose of a 'Sanitization' process in the context of system decommissioning?

Easy
42

An ISSE is defining the 'Security Architecture' for an enterprise network. Which concept should be prioritized to ensure that an attacker who gains access to one segment cannot easily pivot to others?

Medium
43

When integrating security into the requirements phase, what is the value of 'Misuse Cases'?

Medium
44

During a 'Design Review', an ISSE notices that the system architecture relies on 'Security through Obscurity'. Why is this considered an engineering flaw?

Medium
45

Which THREE of the following are valid 'Authentication' factors?

Medium
46

During the 'Engineering Process Integration' phase, an ISSE identifies that the legacy system lacks support for modern TLS 1.3 encryption. What is the most appropriate engineering response?

Medium
47

In the context of the 'Common Criteria', what is the role of the 'Security Target'?

Medium
48

When configuring a 'Logging and Auditing' system, what is the most important consideration for 'Log Integrity'?

Medium
49

When applying the principle of Least Privilege, which technical implementation is most effective in a microservices architecture?

Medium

Frequently asked questions

What does the Systems Security Engineering Foundations domain cover on the ISC exam?
Systems Security Engineering Foundations questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 49 Systems Security Engineering Foundations questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Systems Security Engineering Foundations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issep ISC2-ISSEP systems security engineering foundations Practice Questions