ISC · domain
Law Ethics And Security Compliance Management
Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Law Ethics And Security Compliance Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Law Ethics And Security Compliance Management questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Law Ethics And Security Compliance Management
Law Ethics And Security Compliance Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Law Ethics And Security Compliance Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Law Ethics And Security Compliance Management questions (28)
Click any question to see the full explanation, or start a practice session above.
A Chief Information Security Officer (CISO) is establishing an ethics program. Which framework provides the most comprehensive international standard for establishing an Information Security Management System (ISMS) encompassing compliance and ethical conduct?
Easy2Which principle of 'Ethics in Security Leadership' dictates that a manager should prioritize the safety and privacy of the user over organizational convenience?
Easy3In an environment governed by SOX (Sarbanes-Oxley), which feature of AWS IAM must be utilized to maintain strict 'Segregation of Duties' for account administrative tasks?
Hard4A security manager is conducting a third-party risk assessment using the NIST Cybersecurity Framework. Which tool in the AWS Artifact portal is most appropriate for obtaining the necessary SOC 2 Type II reports to fulfill compliance auditing requirements?
Medium5A company is subject to HIPAA. When configuring Microsoft 365, which feature is critical to ensure that PHI (Protected Health Information) is not accidentally shared via email while meeting 'Minimum Necessary' disclosure standards?
Hard6Which TWO actions should a security manager take to ensure an organization remains compliant with the Sarbanes-Oxley (SOX) Act regarding IT controls?
Medium7An organization wants to monitor its compliance with CIS Benchmarks automatically. Which tool is best suited to provide an automated 'Compliance Score' against these benchmarks in a multi-cloud environment?
Medium8Which THREE configurations are necessary to satisfy the 'Technical Safeguards' requirement under HIPAA for data at rest?
Hard9Which THREE items must be included in a 'Data Processing Agreement' (DPA) between a cloud provider and a controller under GDPR?
Hard10A company uses Microsoft Entra ID. To comply with the 'Zero Trust' requirement for 'Explicit Verification', which conditional access grant control must be enabled for all administrative access?
Hard11Which TWO aspects of the NIST Cybersecurity Framework (CSF) are most relevant when establishing a 'Compliance Program Management' function?
Medium12In a Kubernetes cluster, which policy must be configured to ensure that containers are compliant with the CIS Kubernetes Benchmark regarding 'Privileged Containers'?
Hard13A firm must adhere to the EU's Digital Operational Resilience Act (DORA). Which activity is the primary compliance requirement for 'Third-Party Risk Management' under this regulation?
Medium14Which THREE components are essential for a robust 'Privacy Program' when implementing data protection by design in an cloud environment?
Hard15Which feature in Okta is essential for meeting compliance requirements regarding 'Identity Assurance' and 'Strong Authentication' mandated by financial regulations?
Medium16When conducting a compliance audit, what is the purpose of a 'Gap Analysis'?
Easy17A US-based company is processing data of German citizens. To comply with the Schrems II ruling, which contractual mechanism must they document in their vendor risk management registry?
Hard18Which TWO factors must a security officer consider when performing a 'Privacy Impact Assessment' (PIA) for a new cloud application?
Medium19Which TWO controls should a manager verify to ensure 'Ethics in Security Leadership' is being practiced regarding internal whistleblower protections?
Medium20A multinational organization is deploying an automated compliance monitoring solution across its cloud environments. Which GDPR-related mechanism must the security manager prioritize when configuring data residency policies in Microsoft Purview to ensure automated cross-border transfer controls?
Medium21A data controller is managing personal data under GDPR. Which tool within the AWS ecosystem allows the controller to locate and inventory all instances of 'Personal Data' across S3 buckets to support Data Subject Access Requests (DSARs)?
Medium22To ensure adherence to the PCI DSS 4.0 requirement for log integrity, which configuration in a centralized SIEM like Splunk is mandatory to prevent unauthorized modification of audit logs?
Medium23For an organization to maintain compliance with the GLBA (Gramm-Leach-Bliley Act), which mechanism within Azure Key Vault is required to demonstrate evidence of 'Key Rotation' and 'Access History'?
Medium24An organization must comply with CCPA/CPRA requirements regarding 'Right to Delete'. In a hybrid environment utilizing Google Cloud Platform, which mechanism is best suited for implementing automated lifecycle policies to satisfy deletion requests across Cloud Storage buckets?
Hard25Which THREE factors must be considered during the 'Compliance Program Management' phase when evaluating whether to adopt a new cloud-based tool?
Hard26When drafting an organizational 'Acceptable Use Policy' (AUP), which element is most critical to ensure legal enforceability in a professional environment?
Easy27When managing a compliance program, what is the first step in the 'Continuous Compliance' lifecycle?
Easy28To comply with the 'Right to Explanation' under certain AI regulations, which feature in Google Vertex AI is used to provide transparency into model decision-making?
MediumOther domains
All ISC exam domains
Frequently asked questions
- What does the Law Ethics And Security Compliance Management domain cover on the ISC exam?
- Law Ethics And Security Compliance Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 28 Law Ethics And Security Compliance Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Law Ethics And Security Compliance Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.