New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSMP Exam - Topic 5 Question 6 Discussion

Actual exam question for ISC2's ISSMP exam
Question #: 6
Topic #: 5
[All ISSMP Questions]

Which of the following are known as the three laws of OPSEC?

Each correct answer represents a part of the solution. Choose three.

Show Suggested Answer Hide Answer
Suggested Answer: A, B, C

OPSEC is also known as operations security. It has three laws.

The First Law of OPSEC. If you don't know the threat, how do you know what to protect? Although specific threats may vary from site to site or program to program. Employees must be aware of the actual and postulated threats. In any given situation, there is likely to be more than one adversary, although each may be interested in different information.

The Second Law of OPSEC. If you don't know what to protect, how do you know you are protecting it? The 'what' is the critical and sensitive, or target, information that adversaries require to meet their objectives.

The Third Law of OPSEC. If you are not protecting it (the critical and sensitive information), the adversary wins! OPSEC vulnerability assessments, (referred to as 'OPSEC assessments' - OA's - or sometimes as Surveys') are conducted to determine whether or not critical information is vulnerable to exploitation. An OA is a critical analysis of 'what we do' and 'how we do it' from the perspective of

an adversary. Internal procedures and information sources are also reviewed to determine whether there is an inadvertent release of sensitive information.

Answer option D is incorrect. The statement given in the option is not a valid law of OPSEC.


Contribute your Thoughts:

0/2000 characters
Shaniqua
4 months ago
Totally agree with A, it's all about knowing the threat!
upvoted 0 times
...
Latosha
4 months ago
D makes sense too, but I thought there were different laws.
upvoted 0 times
...
Sharita
4 months ago
Wait, are these really the three laws? Seems off.
upvoted 0 times
...
Letha
4 months ago
I think B is also crucial, can't protect what you don't know.
upvoted 0 times
...
Lasandra
5 months ago
A and C are definitely part of OPSEC!
upvoted 0 times
...
Denny
5 months ago
I thought there were specific phrases we had to remember for OPSEC, but I’m confused about which ones apply here.
upvoted 0 times
...
Valentine
5 months ago
C sounds familiar too, but I can't recall if it was one of the main three.
upvoted 0 times
...
Hershel
5 months ago
I think one of the laws is definitely about knowing the threat, but I'm not sure if it's A or D.
upvoted 0 times
...
Delisa
5 months ago
I remember practicing a question like this, and I feel like B is definitely one of the laws.
upvoted 0 times
...
Kerry
5 months ago
I'm a bit unsure about this one. I'll need to review the Splunk documentation to make sure I don't miss any lesser-known comparison operators.
upvoted 0 times
...
Ena
5 months ago
I'm not entirely sure about this, but maybe I should look at Permissions? It could affect who can do what with these issue types.
upvoted 0 times
...
Mattie
5 months ago
I'm a bit unsure about this one. I know these are all database-related terms, but I can't quite remember how they're classified. I'll try to eliminate the options that don't seem right, and then make an educated guess.
upvoted 0 times
...

Save Cancel