ISSMP ISSMP®: Information Systems Security Management Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A burgeoning fintech startup, \"Quantalytics,\" has seen a significant increase in demand for agile cross-departmental collaboration. Employees have begun adopting an unapproved, third-party SaaS platform for real-time document sharing and project management, citing its superior user experience and perceived efficiency gains over existing internal tools. The Chief Information Security Officer (CISO), Ms. Anya Sharma, is aware of this shadow IT proliferation. While the platform promises enhanced productivity, it operates outside the organization\'s established security governance framework, raising concerns about data leakage, compliance with financial regulations (e.g., GDPR, CCPA), and potential integration conflicts with the core banking system. Ms. Sharma needs to address this situation strategically, ensuring both operational agility and robust security. Which of the following actions represents the most effective and ISSMP-aligned approach to manage this emerging risk?

Initiate a controlled pilot program for the new SaaS platform, involving a cross-functional team to assess its security controls, compliance implications, and overall business value before proposing policy adjustments or approved integration.
Mandate the immediate cessation of all use of the unapproved SaaS platform and conduct a disciplinary review for employees found to be in violation of the existing security policy.
Develop a comprehensive security awareness training program emphasizing the risks of shadow IT and the importance of adhering to approved software, without directly addressing the specific tool in question.
Engage with the vendor of the unapproved SaaS platform to negotiate a bespoke enterprise license agreement that includes specific security clauses, without first conducting an internal risk assessment or pilot.

About the ISSMP ISSMP®: Information Systems Security Management Professional Certification

These free practice questions are designed to help you assess your readiness for the ISSMP ISSMP®: Information Systems Security Management Professional exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.