Courseiva

CCNA Security Policies and Procedures Questions

36 of 111 questions · Page 2/2 · Security Policies and Procedures · Answers revealed

76
MCQmedium

A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?

A.Use a write-blocker, compute hash of original disk, create image, compute hash of image, and compare hashes.
B.Create a forensic image without write-blocking, then hash the image.
C.Copy all files to an external drive without hashing.
D.Disconnect the hard drive and boot from a live CD to collect data.
AnswerA

A write-blocker prevents modification of the source disk during acquisition, and hashing before and after imaging proves the copy is bit-for-bit identical. Comparing the two hashes verifies integrity, satisfying the requirement to preserve admissible evidence from the compromised workstation.

Why this answer

Proper evidence preservation requires hashing the original disk before imaging and then hashing the image to verify integrity.

77
MCQmedium

A hospital's IT department issues a document that tells administrators the exact sequence of steps to disable a terminated clinician's account, including which systems to check and in what order. The document is mandatory and is referenced during audits. Which type of security documentation does this describe?

A.Security standard
B.Security policy
C.Security guideline
D.Security procedure
AnswerD

A procedure is a detailed, mandatory, step-by-step document describing how to perform a specific task, exactly matching the account deprovisioning instructions. Procedures are operational, reference specific systems, and are commonly used during audits to demonstrate consistent execution. Because the document dictates the exact sequence of actions and is mandatory, it is correctly classified as a security procedure.

Why this answer

A security procedure is the mandatory, detailed, step-by-step documentation that describes how to carry out a specific operational task, such as disabling a terminated user's account across multiple systems in a defined order. Policies state intent, standards define mandatory requirements, and guidelines offer optional advice. The scenario's emphasis on an exact sequence of steps makes the procedure the correct classification.

Exam trap

The trap here is equating any mandatory document with a policy or standard, when the defining characteristic of a procedure is its detailed, sequential instructions for performing a specific task.

78
MCQmedium

A financial services firm must retain security event logs for seven years to satisfy regulatory requirements. The SOC manager asks which property of log data must be preserved so that logs cannot be altered or deleted after collection, even by administrators. Which property should the manager emphasize?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerD

Integrity ensures that log data remains complete and unaltered from the moment it is collected. Controls such as write-once storage, cryptographic hashing, or centralized log servers with restricted permissions preserve integrity so administrators cannot quietly modify or delete entries. This directly satisfies the requirement that logs remain trustworthy evidence throughout a seven-year retention period.

Why this answer

Log integrity means the data has not been altered or destroyed after collection, which is exactly what regulators expect when logs are retained as evidence. Techniques such as write-once media, hashing, and forwarding to hardened centralized collectors enforce integrity. Confidentiality limits who can read logs, availability keeps them reachable, and non-repudiation proves authorship, so none of those properties directly prevents tampering with stored records.

Exam trap

The trap here is equating controlled access with tamper protection, when restricting who can read a log does not stop an authorized administrator from modifying or deleting it.

79
MCQmedium

An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?

A.The date, time, and signature of each person who handled the evidence
B.The IP address of the server
C.The name of the antivirus software installed
D.The operating system version
AnswerA

Documenting the date, time and signature of every handler creates an unbroken chain of custody record, proving who possessed the drive and when, which satisfies the requirement to demonstrate the evidence was not tampered with from seizure to presentation.

Why this answer

Chain of custody requires detailed documentation of who handled evidence and when.

80
Multi-Selecthard

A security manager is drafting a data classification policy and wants to ensure handling requirements are applied consistently. Which TWO elements should the policy define for each classification level? (Choose two.)

Select 2 answers
A.The maximum acceptable recovery time for each business application
B.A list of every employee authorized to access each data repository
C.The specific vendor products approved for encrypting each data type
D.Labeling conventions and handling rules for storage, transmission, and disposal
E.Roles and responsibilities for data owners, custodians, and users
AnswersD, E

A workable classification policy must state how each level is marked and how it must be stored, transmitted, and destroyed. Without labeling conventions, users cannot tell which rules apply, and without handling rules the classification has no operational effect. These elements translate an abstract label into concrete daily behavior, which is what makes the policy enforceable and auditable across departments.

Why this answer

An effective classification policy defines both how data at each level is labeled and handled, and who is accountable for it. Labeling and handling rules make the classification operational, while owner, custodian, and user responsibilities make it enforceable. Product selections, recovery objectives, and user rosters belong in supporting documents rather than the classification policy itself.

Exam trap

The trap here is treating an operational detail like an approved product list as a core policy element, when classification policy must define handling rules and accountability instead.

81
MCQmedium

An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?

A.Risk treatment
B.Qualitative risk assessment
C.Risk identification
D.Quantitative risk assessment
AnswerD

Quantitative risk assessment expresses risk in monetary terms, calculating potential loss values from asset value, exposure factor and annualised rate of occurrence. Assigning a monetary value to potential losses is precisely this method's defining characteristic.

Why this answer

Assigning a monetary value to potential losses is a hallmark of quantitative risk assessment. This method uses numerical data (e.g., dollar amounts, percentages) to calculate metrics such as Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE), enabling objective comparison of risks. In contrast, qualitative methods rely on subjective ratings like high/medium/low.

Exam trap

Cisco often tests the distinction between quantitative and qualitative risk assessment by describing a scenario with monetary values (quantitative) versus subjective ratings (qualitative), leading candidates to confuse risk treatment or identification with the assessment method itself.

How to eliminate wrong answers

Option A is wrong because risk treatment is the process of selecting and implementing controls to mitigate risk, not a method for assigning monetary values to losses. Option B is wrong because qualitative risk assessment uses descriptive scales (e.g., high, medium, low) rather than monetary values to evaluate risk. Option C is wrong because risk identification is the step of recognizing potential threats and vulnerabilities, not the phase where monetary values are assigned.

82
MCQmedium

A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?

A.Initiate the legal hold process to preserve evidence
B.Contain the threat by blocking the IP address on the firewall
C.Escalate the alert to Tier 2 for deeper investigation
D.Perform initial triage to determine the severity and validity
AnswerD

Triage validates whether the alert is a genuine attack or a false positive and assigns severity before escalation or containment. Acting on unverified SIEM data risks wasted effort or disrupting legitimate activity, so initial triage must precede deeper investigation, containment, or notification.

Why this answer

Initial triage is part of Detection and Analysis to determine if the alert is a true positive and assess its priority.

83
MCQeasy

In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Post-Incident Activity
D.Preparation
AnswerC

Post-Incident Activity covers the lessons-learned meeting and revision of the incident response plan, closing the loop after eradication and recovery. It is the final NIST SP 800-61 Rev 2 phase, distinct from preparation, detection and analysis, and containment, eradication and recovery.

Why this answer

The Post-Incident Activity phase of NIST SP 800-61 Rev 2 is specifically designed for conducting a lessons learned meeting, documenting findings, and updating the incident response plan based on those insights. This phase ensures continuous improvement of the incident response process by capturing what worked, what didn't, and what changes are needed for future incidents.

Exam trap

Cisco often tests the misconception that lessons learned and plan updates occur during the Detection and Analysis phase, because candidates confuse the analysis of the incident itself with the analysis of the incident response process performance.

How to eliminate wrong answers

Option A is wrong because Containment, Eradication, and Recovery focuses on stopping the incident, removing the threat, and restoring normal operations, not on documenting lessons learned or updating the plan. Option B is wrong because Detection and Analysis involves identifying and verifying an incident and assessing its impact, not on post-incident review or plan updates. Option D is wrong because Preparation involves establishing and training the incident response team and acquiring tools before an incident occurs, not on documenting lessons learned after an incident.

84
MCQhard

A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?

A.OpenIOC and MISP
B.STIX and TAXII
C.MISP and STIX
D.TAXII and OpenIOC
AnswerB

STIX provides a standardised schema for describing indicators, malware and campaigns, while TAXII defines the transport for exchanging that content between systems. Together they satisfy the requirement to correlate network logs with threat intelligence, since the escalated C2 alert's indicators can be ingested in a machine-readable, vendor-neutral form.

Why this answer

STIX is the format, TAXII is the transport protocol for sharing threat intelligence.

85
MCQhard

A security manager is updating the organization's data classification policy. The policy must align with the CyberOps Associate curriculum and ensure that data handling procedures are consistent. The manager proposes that data classified as 'Public' should still be encrypted when stored on internal servers. Which principle should guide the manager's decision?

A.All data must be encrypted at rest regardless of classification to ensure defense in depth.
B.Encryption is only required for data in transit, not for data at rest, for any classification.
C.Data should be protected according to its classification level, and 'Public' data does not require encryption at rest.
D.The classification of data should be based on the cost of encryption, not on its sensitivity.
AnswerC

Data classification defines the level of protection required. Public data is intended for unrestricted access and does not contain sensitive information, so encryption at rest is not mandated. Applying unnecessary controls increases cost and complexity without adding security value. The principle is to match controls to the classification, ensuring that resources are allocated appropriately and that handling procedures remain consistent with the data's sensitivity.

Why this answer

The guiding principle is that data protection controls should be commensurate with the data's classification. Public data, by definition, is not sensitive and does not require encryption at rest. Encrypting it would add unnecessary overhead without meaningful security benefit.

The policy should ensure that higher classifications, such as Confidential, receive stronger protections like encryption, while Public data can be handled with basic integrity controls. This risk-based approach is consistent with the CyberOps Associate curriculum.

Exam trap

The trap here is equating defense in depth with encrypting everything, which ignores the purpose of data classification and can lead to inefficient use of security resources.

86
MCQhard

An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?

A.Calculates annual loss expectancy (ALE)
B.Assigns numeric probabilities and impact
C.Uses monetary values to estimate loss
D.Ranks risks using scales such as high, medium, low
AnswerD

Qualitative assessments express likelihood and impact using descriptive ordinal scales, such as high, medium, and low, rather than monetary values. This ranking approach suits vendor evaluation where precise financial figures are unavailable, satisfying the stem's requirement for a typical qualitative characteristic.

Why this answer

Qualitative assessments use subjective ratings like high, medium, low.

87
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Preparation
D.Post-Incident Activity
AnswerC

Preparation is the first NIST SP 800-61 Rev 2 phase, covering creation of the incident response plan, team structure, tools and training before any incident occurs. It directly satisfies the stem's requirement for the phase where planning and team assembly happen.

Why this answer

The Preparation phase includes developing the IR plan, team, tools, and conducting exercises.

88
MCQmedium

A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?

A.A set of mandatory requirements and control objectives for organizations that store, process, or transmit cardholder data
B.A voluntary advisory publication that suggests best practices but carries no compliance obligations for the merchant
C.A prescriptive technical configuration baseline that dictates exact settings for every operating system and application in the environment
D.A legal statute enacted by a national government that replaces all contractual security obligations with statutory penalties
AnswerA

PCI DSS is a mandatory framework of requirements and control objectives that applies to any entity storing, processing, or transmitting cardholder data. It defines what must be achieved, such as encrypting transmission of cardholder data over open networks, while leaving implementation choices to the organization. This matches the scenario's need to confirm compliance before an assessment.

Why this answer

PCI DSS is an industry-mandated framework of requirements and control objectives that applies to any organization handling cardholder data. It specifies outcomes, such as protecting stored data and encrypting transmission over open networks, but leaves specific technical implementation to the organization. It is enforced contractually through acquiring banks, not as advisory guidance or as government legislation.

Exam trap

The trap here is confusing a framework of control objectives with a prescriptive technical baseline, when PCI DSS deliberately states requirements while allowing each organization to choose how to implement them.

89
MCQmedium

During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?

A.Data classification policy
B.Acceptable Use Policy
C.Incident response plan
D.Chain of custody form
AnswerD

The chain of custody form records each transfer, handler, timestamp and storage location of evidence. Completing it during collection creates the auditable trail proving the evidence was never tampered with, which is required for it to be admissible.

Why this answer

Chain of custody documentation tracks who handled evidence from collection to court presentation.

90
MCQeasy

A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?

A.Communicate with the media
B.Develop detection signatures
C.Conduct advanced malware analysis
D.Perform initial triage and basic investigation
AnswerD

Tier 1 handles alert monitoring and initial triage, validating whether an alert is a true positive and gathering basic evidence before escalation. Deep malware reverse engineering and enterprise-wide containment decisions belong to Tier 2 or Tier 3, so basic investigation is the correct scope.

Why this answer

Tier 1 analysts monitor alerts and perform initial triage to determine if further investigation is needed.

91
Multi-Selectmedium

A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?

Select 2 answers
A.Forensic analysis of compromised systems
B.Correlating multiple alerts
C.Monitoring SIEM dashboards
D.Initial triage of alerts
E.Threat hunting
AnswersA, E

Forensic analysis of compromised systems involves deep-diving into artefacts, memory, and disk images to determine attacker techniques and scope. This is a Tier 3 activity because it requires advanced expertise beyond Tier 1 triage or Tier 2 escalation, satisfying the advanced threat analysis requirement.

Why this answer

Forensic analysis of compromised systems (A) is a Tier 3 activity because it requires deep expertise in memory, disk, and artifact examination to reconstruct attacker actions and determine root cause. Threat hunting (E) is also typical for Tier 3, as it involves proactively searching for hidden adversaries using hypotheses, advanced analytics, and tools beyond routine alert handling. In contrast, correlating multiple alerts (B) and initial triage of alerts (D) are generally Tier 1 or Tier 2 responsibilities, and monitoring SIEM dashboards (C) is a routine Tier 1 monitoring task rather than advanced analysis.

92
MCQhard

An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?

A.Quantitative risk assessment
B.Operational risk assessment
C.Qualitative risk assessment
D.Hybrid risk assessment
AnswerA

Quantitative risk assessment assigns numerical values to both likelihood and impact, satisfying the stem's requirement for numeric scoring. Unlike qualitative methods, which use descriptive scales such as high, medium or low, it enables arithmetic calculation of expected loss and direct cost-benefit comparison of controls.

Why this answer

Quantitative risk assessment uses numerical values (e.g., monetary, percentages) to calculate risk.

93
MCQeasy

A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?

A.Increase the minimum password length to 12 characters and require complexity.
B.Remove the periodic password expiration and instead enforce a longer minimum length with a blocklist of common passwords.
C.Require passwords to be changed every 30 days to reduce the window of compromise.
D.Implement a requirement for passwords to include at least one special character and one number.
AnswerB

NIST SP 800-63B advises against arbitrary password expiration because it leads to weaker passwords and user frustration. Instead, it recommends a minimum length of 8 characters (preferably more) and checking new passwords against a list of compromised or common passwords. This approach improves security by preventing easily guessed passwords and reducing the need for frequent changes, which often result in incremental variations that attackers can predict.

Why this answer

The analyst should recommend removing periodic password expiration and instead enforcing a longer minimum length with a blocklist of common passwords. NIST SP 800-63B emphasizes that password expiration can degrade security by encouraging weak, predictable passwords. A blocklist prevents users from choosing easily guessed or compromised passwords, and a longer minimum length increases resistance to brute-force attacks.

This approach aligns with modern best practices and reduces the burden on users and help desk.

Exam trap

The trap here is assuming that frequent password changes and complexity requirements are always more secure, when NIST guidelines actually discourage them in favor of length and breach checks.

94
Multi-Selecthard

A security manager is preparing an incident response plan for a retail company. The plan must define how the organization will handle incidents consistently and must satisfy auditors. Which TWO elements are essential components of an incident response policy? (Choose two.)

Select 2 answers
A.A requirement to classify incidents by severity with corresponding escalation and notification criteria
B.A complete list of every vulnerability scanner signature and detection rule deployed in the environment
C.The exact command syntax used to isolate a compromised endpoint from the network
D.A copy of the organization's entire business continuity plan as an appendix
E.Clearly defined roles and responsibilities for the incident response team, including authority to act during an incident
AnswersA, E

Severity classification with escalation and notification criteria ensures incidents of similar impact are handled consistently and that the right stakeholders, including legal and executive management, are informed on time. This directly supports the scenario's need for consistent handling and provides auditors with a measurable decision framework. Without it, response effort and notifications become arbitrary.

Why this answer

An incident response policy governs how incidents are handled consistently by defining team roles, decision authority, and severity-based escalation and notification criteria. Those elements give responders clear direction and give auditors measurable expectations. Detection signatures, exact command syntax, and the full business continuity plan belong to tooling, procedures, or a separate discipline, so they are not essential policy components.

Exam trap

The trap here is treating highly technical operational details, such as scanner signatures or command syntax, as policy content, when a policy defines governance, roles, and decision criteria rather than technical execution.

95
MCQeasy

A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?

A.Tokenization of the primary account number (PAN)
B.Full-disk encryption on all employee laptops
C.Network segmentation between the DMZ and internal network
D.Multifactor authentication for all administrative access
AnswerA

PCI DSS Requirement 3 mandates protection of stored cardholder data. Tokenization replaces the PAN with a surrogate value, so the actual PAN is not stored in the cardholder data environment, directly satisfying the requirement. It reduces scope and is a recognized method for protecting stored cardholder data under PCI DSS.

Why this answer

PCI DSS requires that stored cardholder data be rendered unreadable, and tokenization replaces the PAN with a non-sensitive surrogate, directly fulfilling that requirement. Other controls such as endpoint encryption, segmentation, and MFA are valuable but do not address the specific protection of stored cardholder data. Tokenization also reduces the scope of the cardholder data environment, which is a key compliance benefit.

Exam trap

The trap here is confusing general security controls that reduce scope or harden access with the specific PCI DSS requirement to render stored cardholder data unreadable.

96
MCQmedium

After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?

A.Preparation
B.Containment, Eradication, and Recovery
C.Post-Incident Activity
D.Detection and Analysis
AnswerB

Eradication removes the malware and recovery restores systems from clean backups, both grouped with containment in this single NIST SP 800-61 Rev 2 phase. The stem's containment-then-eradicate-then-restore sequence therefore maps directly onto it, not onto post-incident activity.

Why this answer

Eradication removes the threat, and recovery restores normal operations.

97
MCQeasy

In the context of risk management, which term describes the risk that remains after implementing security controls?

A.Acceptable risk
B.Inherent risk
C.Transfer risk
D.Residual risk
AnswerD

Residual risk is the exposure that persists once security controls have been applied, directly matching the stem's requirement for risk remaining after implementation. Inherent risk exists before controls; residual risk is what survives them, and it must be accepted, transferred, mitigated further, or avoided through risk management decisions.

Why this answer

Residual risk is the risk left after controls are applied. It must be accepted or further treated.

98
MCQeasy

A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?

A.Containment, Eradication, and Recovery
B.Post-Incident Activity
C.Preparation
D.Detection and Analysis
AnswerD

Detection and Analysis covers monitoring, alert triage and initial validation, so the analyst's first assessment of the suspicious download sits here. It precedes containment, meaning triage data gathered now determines whether the incident escalates to the containment, eradication and recovery phase.

Why this answer

Initial triage is part of the Detection and Analysis phase, where alerts are evaluated to determine if they are actual incidents.

99
Multi-Selectmedium

A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)

Select 2 answers
A.List of all software vulnerabilities and patches
B.Detailed network diagram of the organization's infrastructure
C.Consequences for policy violations
D.Definition of acceptable and unacceptable use of organizational assets
E.Step-by-step incident response procedures
AnswersC, D

An effective AUP must outline the consequences of violating the policy, which may include disciplinary action, termination, or legal action. This element deters misuse and ensures consistent enforcement. It also protects the organization legally by establishing that violations are taken seriously. Thus, consequences are an essential component of an AUP.

Why this answer

An Acceptable Use Policy must clearly define acceptable and unacceptable use of organizational assets and specify consequences for violations. These elements set expectations and enable enforcement. Technical details like network diagrams, incident response procedures, and vulnerability lists belong in other documents and are not core components of an AUP.

Exam trap

The trap here is thinking that technical details such as network diagrams or vulnerability lists belong in an AUP, when they are actually part of separate technical or operational documents.

100
MCQhard

During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?

A.A log of who accessed the evidence and when
B.The CVSS score of the vulnerability
C.A copy of the incident response plan
D.The organization's acceptable use policy
AnswerA

A chain-of-custody log records every individual who handled, transferred or accessed the evidence, with timestamps and signatures. This continuous audit trail satisfies the admissibility constraint by proving the evidence was never tampered with between seizure and courtroom presentation.

Why this answer

Chain of custody documentation must include a log of who accessed the evidence, when, and for what purpose, to ensure integrity and admissibility in court. This log creates an auditable trail that proves the evidence has not been tampered with. Without it, the evidence may be deemed inadmissible.

Exam trap

200-201 often tests the misconception that technical details like CVSS scores or policies are part of chain of custody, when the essential element is the access log.

How to eliminate wrong answers

Option B is wrong because the CVSS score is a severity rating for vulnerabilities and is not part of chain of custody documentation. Option C is wrong because the incident response plan is a procedural document, not evidence-specific documentation. Option D is wrong because the acceptable use policy is an organizational policy and does not track evidence handling.

101
MCQmedium

An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?

A.Password complexity requirements
B.Incident reporting procedures
C.Data classification levels
D.Prohibition of using company resources for illegal activities
AnswerD

An Acceptable Use Policy defines permitted and forbidden employee behaviour on organisational systems. Prohibiting use of company resources for illegal activities is a core AUP clause, establishing legal boundaries and enabling disciplinary action, directly satisfying the typical AUP content requirement.

Why this answer

An AUP defines acceptable use of IT resources, including prohibiting unauthorized access, personal use guidelines, and security responsibilities.

102
MCQmedium

During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?

A.Legal counsel
B.Incident handler
C.HR
D.CISO
AnswerA

Legal counsel determines whether legal notification requirements apply, as they interpret breach-notification statutes and regulations governing PII. This satisfies the scenario's constraint: assessing statutory obligations after a PII breach. Security analysts and incident handlers identify and contain the incident, but only legal counsel can judge mandatory disclosure duties to customers, regulators, or authorities.

Why this answer

Legal counsel is primarily responsible for interpreting breach notification laws (e.g., GDPR, CCPA, HIPAA) and determining whether the incident triggers mandatory legal notifications. They assess factors such as the type of data involved, the number of affected individuals, and the jurisdiction to decide if notification is required. The incident handler focuses on technical containment and recovery, not legal analysis.

Exam trap

The trap here is confusing the technical incident response role with the legal compliance role; candidates might assume the incident handler or CISO determines notification requirements, but legal counsel is the correct authority.

How to eliminate wrong answers

Option B is wrong because the incident handler's role is to manage the technical response, not to interpret legal statutes or determine notification obligations. Option C is wrong because HR handles employee-related matters, not customer data breach notifications. Option D is wrong because the CISO oversees the overall security program and may be informed, but legal counsel is the authority on legal notification requirements.

103
MCQmedium

A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?

A.Notify legal counsel immediately
B.Escalate directly to Tier 3 for advanced analysis
C.Perform malware analysis and correlate with other alerts
D.Delete the affected files to contain the spread
AnswerC

Malware analysis identifies the ransomware variant's behaviour, indicators, and capabilities, while correlating with other alerts reveals infection scope and lateral movement. This combination is the appropriate Tier 2 next step before escalation, satisfying the need to characterise a suspected new ransomware variant.

Why this answer

A Tier 2 analyst's role is to perform deeper investigation than Tier 1, including malware analysis and correlating the alert with other telemetry to determine scope and impact. Performing malware analysis and correlating with other alerts is the appropriate next step to confirm whether the ransomware is a new variant and to understand its behavior. This informs containment and escalation decisions.

Exam trap

The trap is jumping to containment or escalation before completing Tier 2 analysis — the exam expects the analyst to investigate and correlate first, not delete files or skip to Tier 3.

How to eliminate wrong answers

Option A is wrong because notifying legal counsel is premature before the incident is confirmed and scoped; legal involvement typically follows confirmed data breach or regulatory triggers. Option B is wrong because escalating directly to Tier 3 without doing Tier 2 analysis skips the analyst's responsibility and may waste Tier 3 resources; Tier 2 should first triage and enrich. Option D is wrong because deleting affected files is a containment action that can destroy evidence and may not stop the ransomware; containment should be coordinated after analysis, and evidence preservation is critical.

104
Multi-Selectmedium

After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?

Select 3 answers
A.Developing metrics to measure IR effectiveness
B.Identifying improvements to the IR process
C.Updating the incident response plan
D.Conducting initial triage of new alerts
E.Restoring systems from backup
AnswersA, B, C

Defining metrics that measure IR effectiveness belongs to Post-Incident Activity, quantifying detection, response and recovery performance after the event. This satisfies the phase's purpose of evaluating what occurred rather than preparing for or containing an incident.

Why this answer

Option A is correct because the Post-Incident Activity phase includes developing metrics (e.g., MTTD, MTTR, containment time) to measure the effectiveness of the incident response process and inform future improvements. Option B is correct because a core output of the lessons learned meeting is identifying improvements to the IR process, such as better detection rules, communication paths, or tooling gaps. Option C is correct because findings from the lessons learned review are used to update the incident response plan, ensuring procedures, playbooks, and roles reflect what was learned.

Option D is not part of this phase; initial triage of new alerts belongs to the Detection and Analysis phase. Option E is also not part of this phase; restoring systems from backup occurs during the Containment, Eradication, and Recovery phase.

Exam trap

The trap is mixing phases — candidates often select 'restore systems from backup' or 'triage alerts' because they sound incident-related, but those belong to Recovery and Detection/Analysis respectively, not Post-Incident Activity.

105
Multi-Selectmedium

A security analyst is reviewing the organization's business continuity plan (BCP) after a recent power outage disrupted operations. The analyst notes that the plan includes an alternate processing site and a backup generator but lacks other key components. Which TWO additional elements should the analyst recommend including to improve the BCP? (Choose two.)

Select 2 answers
A.Documented roles and responsibilities for the continuity team
B.A list of employee personal social media accounts
C.A marketing plan for attracting new customers after the outage
D.A schedule for regular penetration testing of the alternate site
E.A defined recovery time objective (RTO) for critical systems
AnswersA, E

This is correct because a BCP must clearly assign roles and responsibilities so that team members know what to do during a disruption. Without defined roles, recovery efforts can stall due to confusion or duplication. The scenario identifies missing components, and role clarity is a fundamental part of any effective continuity plan.

Why this answer

A business continuity plan should define recovery time objectives to set acceptable downtime limits and assign clear roles and responsibilities to the continuity team. These elements ensure that recovery efforts are prioritized and coordinated. The alternate site and generator address infrastructure, but without RTOs and defined roles, the organization cannot measure or manage its recovery effectively.

Exam trap

The trap here is selecting security testing or marketing activities as BCP components when the plan actually requires recovery objectives and clear team responsibilities.

106
MCQhard

A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?

A.The use of a shared service account with a static password
B.The database administrator's lack of MFA on administrative login
C.The absence of a password vault for the administrator
D.The failure to log administrative database sessions
AnswerA

A shared static credential used for automation cannot be attributed to a specific person, is rarely rotated, and often spreads across scripts and configuration files where it can be harvested. If compromised, it grants persistent privileged access with no MFA and no clear accountability, making containment difficult. This combination of anonymity, persistence, and wide exposure represents the greater risk.

Why this answer

Shared static credentials used for automation create privileged access that cannot be attributed to a person, is seldom rotated, and is often embedded in scripts where it can be harvested. If exposed, the attacker gains persistent administrative access without MFA and without accountability, complicating containment and forensics. A named administrator missing MFA is serious but remains traceable and revocable, so the shared service account poses the greater organizational risk.

Exam trap

The trap here is focusing on the visible MFA policy breach while overlooking that a shared static credential removes attribution and persists far longer, making it the more dangerous exposure.

107
MCQeasy

Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?

A.Containment Eradication and Recovery, Detection and Analysis, Preparation, Post-Incident Activity
B.Post-Incident Activity, Preparation, Detection and Analysis, Containment Eradication and Recovery
C.Preparation, Detection and Analysis, Containment Eradication and Recovery, Post-Incident Activity
D.Detection and Analysis, Preparation, Containment Eradication and Recovery, Post-Incident Activity
AnswerC

NIST SP 800-61 Rev 2 orders the incident response lifecycle as Preparation; Detection and Analysis; Containment, Eradication and Recovery; then Post-Incident Activity. This sequence reflects the standard's four-phase structure, with lessons learned occurring only after recovery completes.

Why this answer

The correct order is Preparation, Detection and Analysis, Containment Eradication and Recovery, and Post-Incident Activity.

108
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?

A.Detection and Analysis
B.Preparation
C.Containment, Eradication, and Recovery
D.Post-Incident Activity
AnswerA

Detection and Analysis covers initial triage, validating alerts and deciding whether an event meets the incident criteria before escalating to containment. This satisfies the stem's requirement, since qualification happens during that phase rather than Preparation, Containment Eradication and Recovery, or Post-Incident Activity.

Why this answer

Initial triage and identification of incidents occur in the Detection and Analysis phase.

109
MCQmedium

A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?

A.Forward logs to a centralized, access-controlled repository with integrity protection
B.Increase the local log file size limit so events are overwritten less frequently
C.Compress logs and email them weekly to the security team's distribution list
D.Store logs only on the originating server with local administrator access
AnswerA

Centralizing logs on a hardened server with restricted access, combined with integrity measures such as hashing or write-once storage, preserves both trustworthiness and availability. If the source host is compromised or destroyed, the copies remain intact for examination. This design also supports retention policies and search during audits, directly meeting the regulator's expectation that records can be produced reliably.

Why this answer

Centralizing logs in an access-controlled repository with integrity protections ensures they survive host compromise or failure and can be trusted during a regulatory examination. Retention enforcement and restricted access are as important as collection, because examiners expect complete, unaltered records that can be produced on demand.

Exam trap

The trap here is equating longer local retention with trustworthy retention, when integrity and centralized control are what actually satisfy an examiner.

110
MCQmedium

A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?

A.NIST SP 800-53
B.NIST SP 800-61
C.NIST SP 800-37
D.NIST SP 800-30
AnswerA

NIST SP 800-53, 'Security and Privacy Controls for Information Systems and Organizations,' provides a comprehensive catalog of security and privacy controls. It is the primary source for federal agencies and many private organizations to select and implement controls. In this scenario, the retail company needs a control catalog, making SP 800-53 the correct reference.

Why this answer

NIST SP 800-53 is the definitive catalog of security and privacy controls for federal information systems and organizations. It is widely adopted by private sector organizations to build robust security programs. The other NIST publications focus on incident handling, risk assessment, and the risk management framework, respectively, and do not provide the comprehensive control catalog needed.

Exam trap

The trap here is confusing NIST SP 800-37, which describes the Risk Management Framework process, with NIST SP 800-53, which actually contains the control catalog.

111
MCQhard

An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)

A.Snort rules
B.TAXII
C.OpenIOC
D.STIX
E.MISP
AnswerB, D

TAXII provides the transport mechanism for exchanging cyber threat intelligence over HTTPS, supporting both structured indicators and full reports through its collections and channels model. It satisfies the ISAC sharing requirement by enabling automated, bidirectional exchange between members, complementing STIX's data representation with the delivery protocol needed for programmatic sharing.

Why this answer

STIX (Structured Threat Information Expression) is the standard for representing structured threat indicators and full reports, enabling both machine-readable indicators and human-readable context. TAXII (Trusted Automated Exchange of Indicator Information) is the transport protocol that defines how STIX content is exchanged over HTTPS. Together, they allow ISAC members to share threat intelligence in a standardized, automated manner.

Snort rules are signatures for intrusion detection, not a sharing standard. OpenIOC is a format for indicators but lacks the report capability and transport protocol. MISP is a platform that can use STIX/TAXII but is not itself a standard or protocol.

Exam trap

Cisco often tests the distinction between a data model (STIX) and a transport protocol (TAXII), and candidates mistakenly choose MISP as a standard instead of recognizing it as a platform that implements these standards.

How to eliminate wrong answers

Option A is wrong because Snort rules are a signature format for intrusion detection systems, not a standard for exchanging threat intelligence between organizations. Option C is wrong because OpenIOC is a format for representing indicators of compromise, but it does not include a transport protocol for sharing full reports or support the structured report exchange required by an ISAC. Option E is wrong because MISP is a platform for threat intelligence sharing, not a standard or protocol; it can use STIX and TAXII for exchange, but MISP itself is not a standard/protocol combination.

← PreviousPage 2 of 2 · 111 questions total

Ready to test yourself?

Try a timed practice session using only Security Policies and Procedures questions.