Courseiva

ISC · domain

Law Ethics And Security Compliance Management

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Law Ethics And Security Compliance Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

28 questions5 easy13 medium10 hard

Focused practice

Practice Law Ethics And Security Compliance Management questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Law Ethics And Security Compliance Management

Law Ethics And Security Compliance Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Law Ethics And Security Compliance Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Law Ethics And Security Compliance Management questions (28)

Click any question to see the full explanation, or start a practice session above.

1

A Chief Information Security Officer (CISO) is establishing an ethics program. Which framework provides the most comprehensive international standard for establishing an Information Security Management System (ISMS) encompassing compliance and ethical conduct?

Easy
2

Which principle of 'Ethics in Security Leadership' dictates that a manager should prioritize the safety and privacy of the user over organizational convenience?

Easy
3

In an environment governed by SOX (Sarbanes-Oxley), which feature of AWS IAM must be utilized to maintain strict 'Segregation of Duties' for account administrative tasks?

Hard
4

A security manager is conducting a third-party risk assessment using the NIST Cybersecurity Framework. Which tool in the AWS Artifact portal is most appropriate for obtaining the necessary SOC 2 Type II reports to fulfill compliance auditing requirements?

Medium
5

A company is subject to HIPAA. When configuring Microsoft 365, which feature is critical to ensure that PHI (Protected Health Information) is not accidentally shared via email while meeting 'Minimum Necessary' disclosure standards?

Hard
6

Which TWO actions should a security manager take to ensure an organization remains compliant with the Sarbanes-Oxley (SOX) Act regarding IT controls?

Medium
7

An organization wants to monitor its compliance with CIS Benchmarks automatically. Which tool is best suited to provide an automated 'Compliance Score' against these benchmarks in a multi-cloud environment?

Medium
8

Which THREE configurations are necessary to satisfy the 'Technical Safeguards' requirement under HIPAA for data at rest?

Hard
9

Which THREE items must be included in a 'Data Processing Agreement' (DPA) between a cloud provider and a controller under GDPR?

Hard
10

A company uses Microsoft Entra ID. To comply with the 'Zero Trust' requirement for 'Explicit Verification', which conditional access grant control must be enabled for all administrative access?

Hard
11

Which TWO aspects of the NIST Cybersecurity Framework (CSF) are most relevant when establishing a 'Compliance Program Management' function?

Medium
12

In a Kubernetes cluster, which policy must be configured to ensure that containers are compliant with the CIS Kubernetes Benchmark regarding 'Privileged Containers'?

Hard
13

A firm must adhere to the EU's Digital Operational Resilience Act (DORA). Which activity is the primary compliance requirement for 'Third-Party Risk Management' under this regulation?

Medium
14

Which THREE components are essential for a robust 'Privacy Program' when implementing data protection by design in an cloud environment?

Hard
15

Which feature in Okta is essential for meeting compliance requirements regarding 'Identity Assurance' and 'Strong Authentication' mandated by financial regulations?

Medium
16

When conducting a compliance audit, what is the purpose of a 'Gap Analysis'?

Easy
17

A US-based company is processing data of German citizens. To comply with the Schrems II ruling, which contractual mechanism must they document in their vendor risk management registry?

Hard
18

Which TWO factors must a security officer consider when performing a 'Privacy Impact Assessment' (PIA) for a new cloud application?

Medium
19

Which TWO controls should a manager verify to ensure 'Ethics in Security Leadership' is being practiced regarding internal whistleblower protections?

Medium
20

A multinational organization is deploying an automated compliance monitoring solution across its cloud environments. Which GDPR-related mechanism must the security manager prioritize when configuring data residency policies in Microsoft Purview to ensure automated cross-border transfer controls?

Medium
21

A data controller is managing personal data under GDPR. Which tool within the AWS ecosystem allows the controller to locate and inventory all instances of 'Personal Data' across S3 buckets to support Data Subject Access Requests (DSARs)?

Medium
22

To ensure adherence to the PCI DSS 4.0 requirement for log integrity, which configuration in a centralized SIEM like Splunk is mandatory to prevent unauthorized modification of audit logs?

Medium
23

For an organization to maintain compliance with the GLBA (Gramm-Leach-Bliley Act), which mechanism within Azure Key Vault is required to demonstrate evidence of 'Key Rotation' and 'Access History'?

Medium
24

An organization must comply with CCPA/CPRA requirements regarding 'Right to Delete'. In a hybrid environment utilizing Google Cloud Platform, which mechanism is best suited for implementing automated lifecycle policies to satisfy deletion requests across Cloud Storage buckets?

Hard
25

Which THREE factors must be considered during the 'Compliance Program Management' phase when evaluating whether to adopt a new cloud-based tool?

Hard
26

When drafting an organizational 'Acceptable Use Policy' (AUP), which element is most critical to ensure legal enforceability in a professional environment?

Easy
27

When managing a compliance program, what is the first step in the 'Continuous Compliance' lifecycle?

Easy
28

To comply with the 'Right to Explanation' under certain AI regulations, which feature in Google Vertex AI is used to provide transparency into model decision-making?

Medium

Frequently asked questions

What does the Law Ethics And Security Compliance Management domain cover on the ISC exam?
Law Ethics And Security Compliance Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 28 Law Ethics And Security Compliance Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Law Ethics And Security Compliance Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issmp ISC2-ISSMP law ethics and security compliance management Practice Questions