New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSEP Exam - Topic 1 Question 22 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 22
Topic #: 1
[All ISSEP Questions]

Which of the following individuals is an upper-level manager who has the power and capability to

evaluate the mission, business case, and budgetary needs of the system while also considering the

security risks?

Show Suggested Answer Hide Answer
Suggested Answer: D

DAA is an upper-level manager who has the power and capability to evaluate the mission, business

case, and budgetary needs of the system

while also considering the security risks.

The Designated Approving Authority (DAA), in the United States Department of Defense, is the

official with the authority to formally assume

responsibility for operating a system at an acceptable level of risk. The DAA is responsible for

implementing system security. The DAA can grant

the accreditation and can determine that the system's risks are not at an acceptable level and the

system is not ready to be operational.

Answer option C is incorrect. Certifier is the technical expert of the C&A process, and can be an

individual or an entire team. The certifiers

establish whether a system is prepared to undergo certification, and then use their expertise to

conduct the system certification.

Answer option A is incorrect. User Representative ensures that the operational interests of the

system are maintained. The user groups work

as a supporter for attributes, such as system availability, access, performance, integrity, and

functionality.

Answer option B is incorrect. Program Manager has the responsibility for schedules, costs and

performance, and informing the other team

members of status.


Contribute your Thoughts:

0/2000 characters
Aleisha
4 months ago
Hmm, I thought User Representatives had more power in these decisions?
upvoted 0 times
...
Marya
4 months ago
Totally with you, Noemi! DAA is the right choice.
upvoted 0 times
...
Annabelle
4 months ago
Wait, are we sure it's not C? Certifiers have a role in security.
upvoted 0 times
...
Katheryn
4 months ago
I think it's B, the Program Manager handles budgets too.
upvoted 0 times
...
Noemi
5 months ago
Definitely DAA, they have the final say on security risks.
upvoted 0 times
...
Belen
5 months ago
I practiced a question similar to this, and I think it was about the DAA being responsible for evaluating risks and budgets. That makes sense to me.
upvoted 0 times
...
Leanna
5 months ago
I’m a bit confused. I thought the User Representative had some say in these matters, but I guess they might not have the upper-level authority needed.
upvoted 0 times
...
Jessenia
5 months ago
I think the answer might be DAA, but I'm not entirely sure. I remember something about them having oversight on security risks.
upvoted 0 times
...
Erick
5 months ago
I feel like it could be Program Manager too. They often handle budgets and project scopes, right?
upvoted 0 times
...
Merrilee
5 months ago
Okay, let's see. I'm leaning towards option C - performing a risk assessment. That seems like the best way to get a handle on the project constraints and requirements.
upvoted 0 times
...
Virgina
5 months ago
I'm a bit unsure. Are there scenarios where private SLBs might still interface with public networks? I need to recall those specific use cases.
upvoted 0 times
...
Lina
5 months ago
I vaguely recall something about discovery protocols, but I thought the APIC mainly communicated with the fabric switches directly.
upvoted 0 times
...

Save Cancel