Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 1–75

989 questions total · 14pages · All types, answers revealed

Page 1 of 14

Page 2
1
Multi-Selecteasy

Which TWO of the following are principles of the CIA triad? (Select TWO.)

Select 2 answers
A.Confidentiality
B.Integrity
C.Non-repudiation
D.Accountability
E.Authorization
AnswersA, B

Confidentiality ensures information is disclosed only to authorised parties, preventing unauthorised reading or exposure. It forms one of the three core CIA triad principles, alongside integrity and availability, and is therefore a correct selection here.

Why this answer

Confidentiality (A) is a core principle of the CIA triad because it ensures that information is accessible only to authorized parties, typically enforced through encryption, access controls, and classification. Integrity (B) is also a core principle, guaranteeing that data remains accurate, complete, and unaltered except by authorized actions, supported by hashing, checksums, and version controls. Together with Availability, these three form the CIA triad, the foundational model for information security.

Non-repudiation (C) is a related security property ensuring a party cannot deny an action, but it is not one of the three CIA principles. Accountability (D) and Authorization (E) are important access-control and governance concepts, yet neither is a member of the CIA triad.

Exam trap

ISC2 often tests candidates by listing security concepts like non-repudiation or authorization as distractors, expecting you to know that the CIA triad strictly includes only confidentiality, integrity, and availability.

2
MCQeasy

A company's security policy states that employees should only have access to the data necessary to perform their job functions. This is an example of which principle?

A.Defense in depth
B.Separation of duties
C.Fail-safe
D.Least privilege
AnswerD

Least privilege grants users only the access required for their job functions, nothing more. This precisely matches the policy described in the stem, restricting employees to data necessary for their duties and thereby limiting potential blast radius from misuse or compromise.

Why this answer

The principle of least privilege dictates that users and systems should be granted only the minimum permissions necessary to perform their tasks. By restricting data access to job-required information, the company directly implements this security control, reducing the attack surface and limiting potential damage from compromised accounts.

Exam trap

ISC2 often tests least privilege by contrasting it with separation of duties, where candidates mistakenly choose separation of duties because both involve restricting access, but separation of duties specifically splits conflicting tasks among different people to prevent collusion, not to limit data access per role.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered security strategy using multiple controls (e.g., firewalls, IDS, encryption) to protect assets, not a single access restriction policy. Option B is wrong because separation of duties divides critical tasks among multiple people to prevent fraud (e.g., one person requests a purchase, another approves it), not limiting data access per role. Option C is wrong because fail-safe ensures that a system defaults to a secure state upon failure (e.g., a firewall blocking all traffic when it crashes), not restricting user permissions to job-necessary data.

3
MCQhard

A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?

A.Honeypot
B.Intrusion Prevention System (IPS)
C.Web Application Firewall (WAF)
D.Stateful firewall
AnswerC

A WAF operates at the application layer, terminating and inspecting HTTP and HTTPS requests, applying rule sets such as the OWASP Core Rule Set, and blocking malicious traffic before it reaches the web server. This matches the described inline inspection and blocking requirement.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP and HTTPS traffic at Layer 7, apply rule sets such as the OWASP ModSecurity Core Rule Set, and block malicious requests like SQL injection, XSS, and CSRF before they reach the web server. It understands web protocols and can enforce positive/negative security models based on HTTP headers, cookies, and payloads. This matches the described requirement exactly.

Exam trap

The trap here is confusing an IPS with a WAF — both can block malicious traffic, but only a WAF is purpose-built for HTTP/HTTPS application-layer inspection and OWASP rule enforcement.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not to inspect and block production HTTP/HTTPS traffic. Option B is wrong because an IPS inspects network traffic for known attack signatures and anomalies at Layers 3-7 but is not specialized for HTTP/HTTPS application-layer semantics like OWASP rules; it lacks the deep HTTP parsing and session awareness of a WAF. Option D is wrong because a stateful firewall tracks connection state at Layers 3-4 and cannot inspect HTTP payloads or apply OWASP rules — it only permits or denies based on IP, port, and connection state.

4
Multi-Selectmedium

An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)

Select 2 answers
A.Review permissions regularly
B.Use role-based access control
C.Grant users default full access and restrict later
D.Enable accounts after use
E.Provide write access to all users
AnswersA, B

Regular permission reviews detect and remove accumulated entitlements that no longer match a user's current duties. Least privilege decays as roles change, so periodic review is the control that keeps granted access aligned with actual need rather than historical assignment.

Why this answer

Option A, reviewing permissions regularly, is essential because least privilege requires ongoing verification that users retain only the access needed for their current duties; permissions accumulate over time through role changes and project work, so periodic access reviews (recertification) detect and remove excessive rights. Option B, using role-based access control (RBAC), is essential because assigning permissions to roles rather than individuals lets the organization grant the minimum set of rights required for each job function, and users inherit only those rights through their assigned roles. Option C is wrong because granting default full access and restricting later is the opposite of least privilege, which starts from no access and adds only what is needed.

Option D is wrong because enabling accounts after use is nonsensical and would not limit access during active use. Option E is wrong because providing write access to all users violates least privilege by granting broad modification rights regardless of need.

Exam trap

ISC2 often tests that candidates confuse the principle of least privilege with account management practices like enabling/disabling accounts, or mistakenly think starting with full access and restricting later is acceptable, when in fact least privilege requires a default-deny posture.

5
MCQmedium

Which of the following is the primary purpose of a visitor log and escort policy?

A.To enforce least privilege for employees
B.To provide a record of visitor access and ensure they are supervised
C.To authenticate visitors using biometrics
D.To prevent visitors from accessing the internet
AnswerB

A visitor log creates an auditable record of who entered, when and whom they visited, while escort requirements ensure visitors remain supervised and cannot wander into restricted areas. Together these satisfy the physical-security need for accountability and containment of unvetted individuals on site.

Why this answer

Option B is correct because the primary purpose of a visitor log and escort policy is to maintain a record of who enters a facility and when, and to ensure that visitors are supervised by authorized personnel while on-site. This supports physical security by preventing unauthorized access, enabling accountability, and ensuring that visitors do not wander into restricted areas without an escort.

Exam trap

The trap here is confusing logical access controls (least privilege, biometrics) with physical security controls — candidates may pick 'least privilege' because it sounds security-related, but the question specifically asks about visitor logs and escort policies, which are physical controls.

How to eliminate wrong answers

Option A is wrong because least privilege for employees is enforced through access control policies (e.g., role-based access, least privilege principles) for systems and data, not through visitor logs. Option C is wrong because biometric authentication is a specific access control mechanism, not the primary purpose of a visitor log and escort policy; visitor logs can be paper-based and do not require biometrics. Option D is wrong because preventing visitors from accessing the internet is not a standard goal of visitor management; the focus is on physical access control and supervision.

6
MCQhard

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

A.Isolate the system on a separate network segment with strict access controls
B.Increase logging and monitoring without any network changes
C.Apply a virtual patch using a web application firewall
D.Remove the system from the network entirely
AnswerA

Network isolation on a separate segment with strict access controls limits lateral movement and reachability, compensating for the unpatched vulnerabilities that cannot be remediated. This contains exposure without relying on vendor fixes that are no longer available for the end-of-life system.

Why this answer

Isolating the legacy system on a separate network segment with strict access controls (firewalls, ACLs, micro-segmentation) is a compensating control that reduces the attack surface and limits lateral movement even though the system itself cannot be patched. It directly addresses the risk of exploitation by containing the system.

Exam trap

CC often tests compensating controls, and candidates pick monitoring or WAF options because they sound security-focused; the trap is confusing detection (logging) or narrow protection (WAF) with actual risk reduction through containment.

How to eliminate wrong answers

Option B is wrong because increasing logging and monitoring only improves detection and forensics; it does not reduce the likelihood or impact of exploitation. Option C is wrong because a virtual patch via WAF only protects web application traffic and does not address vulnerabilities in other protocols or services the legacy system may expose. Option D is wrong because removing the system from the network entirely would break the critical operations it supports, which is not acceptable given the scenario.

7
MCQeasy

A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Defense in depth
AnswerA

Least privilege grants each user only the permissions their role requires, nothing more. It satisfies the scenario's constraint by minimising the new employee's access rights, thereby limiting the damage any compromised or misused account could cause across systems.

Why this answer

The principle of least privilege states that a user should be granted only the minimum permissions necessary to perform their job duties. This limits the potential damage from accidents, errors, or malicious activity by ensuring users cannot access resources beyond their scope of work. It is a foundational security principle applied across systems, including access rights for new employees.

Exam trap

The trap here is confusing least privilege with need-to-know or separation of duties, which are related but distinct concepts; the question specifically asks about minimum permissions for job duties.

How to eliminate wrong answers

Option B is wrong because separation of duties divides critical tasks among multiple people to prevent fraud, rather than limiting a single user's permissions to the minimum. Option C is wrong because need-to-know is about restricting access to information based on whether the user requires it for a specific task, which is a subset of least privilege but not the overarching principle described. Option D is wrong because defense in depth is a layered security strategy using multiple controls, not the principle of granting minimal permissions.

8
MCQeasy

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Risk mitigation applies controls that lower either the likelihood or the impact of a threat exploiting a vulnerability. It differs from avoidance, transference and acceptance, which respectively eliminate the activity, shift the loss, or retain the exposure.

Why this answer

Risk mitigation involves implementing security controls to reduce either the likelihood or the impact of a risk. This is the most common risk management strategy because it addresses the risk directly rather than shifting or avoiding it. Examples include patching vulnerabilities, deploying firewalls, or enforcing MFA to lower the probability of exploitation.

Exam trap

The trap here is confusing mitigation with avoidance or acceptance; candidates often pick 'avoidance' when the question mentions reducing likelihood, but avoidance means eliminating the activity altogether.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action, often when the cost of mitigation exceeds the potential loss. Option C is wrong because risk avoidance means eliminating the activity or asset that introduces the risk entirely, such as discontinuing a service. Option D is wrong because risk transfer shifts the financial impact to a third party, typically through insurance or outsourcing, without reducing the likelihood or impact itself.

9
MCQeasy

The exhibit shows recent authentication logs. What type of attack is most likely indicated?

A.Man-in-the-middle attack
B.Brute-force attack
C.Phishing attack
D.Privilege escalation
AnswerB

Repeated failed sign-in attempts from one source against multiple accounts within a short window match brute-force credential guessing. The log pattern of rapid, successive authentication failures is the signature, distinguishing it from password spray, which spreads attempts thinly across many accounts to evade lockout thresholds.

Why this answer

The exhibit shows repeated authentication attempts with different passwords for the same username, which is the hallmark of a brute-force attack. In authentication logs, a high frequency of failed login attempts (e.g., multiple 'Failed password' entries in quick succession) indicates an attacker systematically guessing credentials. This aligns with the CC domain of Access Controls, where brute-force attacks target weak password policies.

Exam trap

ISC2 often tests the distinction between brute-force and dictionary attacks; the trap here is that candidates may confuse repeated login attempts with a phishing attack, but phishing requires user interaction (e.g., clicking a link), whereas brute-force is automated against the authentication service.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack would show evidence of intercepted or modified traffic (e.g., ARP spoofing, SSL stripping), not repeated login failures. Option C is wrong because a phishing attack relies on tricking users into revealing credentials via deceptive emails or websites, not on direct login attempts against the authentication server. Option D is wrong because privilege escalation involves gaining higher-level access after initial compromise (e.g., exploiting SUID binaries or misconfigured sudo), not repeated password guessing.

10
MCQhard

A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?

A.Investigate the root cause of the configuration change
B.Isolate the server from the network
C.Automatically revert the settings to the baseline
D.Update the baseline to match the current configuration
AnswerA

Investigating the root cause first establishes what changed, who or what changed it, and whether it was malicious or accidental, before remediation. Restoring the baseline blindly could destroy forensic evidence or mask an ongoing compromise, so investigation precedes corrective action.

Why this answer

The first action should be to investigate the root cause of the configuration change. This is because a configuration drift could be caused by a legitimate change (e.g., an approved patch) or a malicious act. Understanding the cause informs the appropriate response, whether to revert, isolate, or update the baseline.

Isolating or reverting without investigation could disrupt business operations or destroy evidence.

Exam trap

The trap is assuming immediate containment or remediation is always best; in reality, investigation must precede action to avoid disrupting business or destroying evidence.

How to eliminate wrong answers

Option B is wrong because isolating the server is a containment step that may be premature; without knowing the cause, you might isolate a server that had a legitimate change, causing unnecessary downtime. Option C is wrong because automatically reverting could undo a necessary change (e.g., a security patch) and may not address the root cause, leading to recurrence. Option D is wrong because updating the baseline to match the current configuration would accept a potentially unauthorized or risky change, undermining the purpose of configuration management.

11
Multi-Selecthard

A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)

Select 2 answers
A.Deploying a signature-based intrusion detection sensor on the core switch
B.Applying the principle of least privilege to internal firewall rule sets and access control lists
C.Increasing the bandwidth of the internal network backbone between departments
D.Implementing virtual LANs with inter-VLAN filtering by a firewall
E.Enabling dynamic host configuration protocol snooping on all access switches
AnswersB, D

Restricting internal rules and ACLs so each zone can reach only the services it genuinely needs shrinks the paths available for lateral movement. Combined with segmentation, least privilege ensures that even permitted connections are narrowly scoped, so a single compromised workstation cannot pivot broadly across departments.

Why this answer

Containment requires both breaking the flat network into isolated zones and restricting what traffic may cross between them. VLANs with firewall-enforced inter-VLAN rules provide the zones, while least-privilege ACLs and rule sets ensure that any permitted crossing is minimal, together limiting how far a single compromised workstation can spread.

Exam trap

The trap here is selecting monitoring or performance improvements, which detect or speed up traffic, instead of the two controls that actually partition the network and restrict permitted paths.

12
Multi-Selectmedium

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Select 2 answers
A.Data may be posted on the public website
B.Access to data must be restricted to authorized personnel only
C.Data can be shared with any vendor without a contract
D.Data must be encrypted when stored on servers
E.Data must be deleted after 30 days regardless of business need
AnswersB, D

Confidential data demands need-to-know handling, so restricting access to authorised personnel only enforces least privilege and prevents unauthorised disclosure. This complements the encryption mandate by controlling who may reach the data at all, satisfying the policy's confidentiality requirement beyond cryptographic protection alone.

Why this answer

Option B is correct because Confidential data must be restricted to authorized personnel only, which is a fundamental access control requirement for this classification level. Option D is correct because the scenario explicitly states that Confidential data must be encrypted at rest, and encryption when stored on servers directly satisfies that at-rest requirement. Options A, C, and E do not belong: posting Confidential data on a public website would expose it to unauthorized disclosure, sharing it with any vendor without a contract violates third-party handling and confidentiality obligations, and deleting it after 30 days regardless of business need is an arbitrary retention rule not implied by the encryption or access-control requirements.

Exam trap

CC often tests data classification handling, and candidates might confuse retention requirements with confidentiality requirements, or incorrectly think that confidential data can be shared freely with vendors.

13
MCQmedium

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

A.Availability
B.Integrity
C.Accountability
D.Confidentiality
AnswerA

Redundant servers let a service continue functioning when one fails, directly satisfying the requirement that services remain operational despite failure. Availability is the principle concerned with uptime and continuous access, so eliminating single points of failure protects it rather than integrity, confidentiality or non-repudiation.

Why this answer

Redundant server infrastructure ensures that services remain operational even if one server fails, which directly supports the principle of availability. Availability ensures that systems and data are accessible to authorized users when needed.

Exam trap

The trap here is confusing availability with integrity or confidentiality, as candidates might think redundancy also protects data integrity, but it primarily ensures uptime.

How to eliminate wrong answers

Option B is wrong because integrity ensures data is not modified or altered without authorization, which is not the focus of redundancy. Option C is wrong because accountability ensures actions can be traced to a specific entity, which is unrelated to redundancy. Option D is wrong because confidentiality ensures data is not disclosed to unauthorized parties, which is not addressed by redundancy.

14
MCQmedium

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

A.Availability
B.Confidentiality
C.Non-repudiation
D.Integrity
AnswerD

Digital signatures use asymmetric cryptography to verify that software updates remain unaltered, detecting any modification between publisher and recipient. This directly addresses integrity, the CIA component concerned with data remaining accurate and trustworthy, rather than confidentiality or availability.

Why this answer

Digital signatures use cryptographic hashing and asymmetric encryption to verify that data has not been altered in transit or at rest, which directly addresses the Integrity pillar of the CIA triad. If even a single bit of the software update changes, the signature verification fails, proving tampering. While signatures also provide authentication and non-repudiation, the question specifically asks which CIA triad aspect is primarily addressed, and integrity is the correct mapping.

Exam trap

CC often tests the overlap between integrity and non-repudiation for digital signatures, tempting candidates to choose non-repudiation even though the question asks specifically about the CIA triad.

How to eliminate wrong answers

Option A is wrong because availability concerns ensuring systems and data are accessible when needed (e.g., redundancy, DDoS protection), which digital signatures do not provide. Option B is wrong because confidentiality involves preventing unauthorized disclosure, typically via encryption; digital signatures do not hide data, they verify it. Option C is wrong because non-repudiation is a security property (proving the signer cannot deny signing) but it is not one of the three CIA triad pillars, so it cannot be the 'aspect of the CIA triad' being addressed.

15
MCQhard

A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?

A.Just-in-time (JIT) privileged access
B.Rule-based access control
C.Separation of duties
D.Time-of-day restriction
AnswerA

JIT privileged access grants elevated rights only for a limited period after an approved request, then automatically removes them. The scenario shows exactly this: manager approval, a ticket number, a defined change window, and automatic revocation when the window closes. This minimizes standing privileged access, reducing the attack surface compared with permanently assigned administrator rights.

Why this answer

The company grants elevated production access only after approval and only for a defined window, then revokes it automatically. That is just-in-time privileged access, which eliminates standing administrator rights and limits exposure to the change window. Time restrictions and approvals are components of the model, but the defining characteristic is temporary, request-driven elevation with automatic expiry.

Exam trap

The trap here is stopping at the time window and choosing a scheduling restriction, missing that approval workflow and automatic revocation make this a just-in-time elevation model.

16
MCQeasy

A security analyst is reviewing an alert from the IDS that shows a large number of TCP SYN packets sent to a single port on multiple internal hosts from a single external IP address. The analyst suspects a reconnaissance attack. Which type of attack is this most likely?

A.SYN flood
B.Ping sweep
C.Smurf attack
D.SYN scan
AnswerD

A SYN scan sends TCP SYN packets to many hosts or ports without completing the handshake, seeking open services. The single external source hitting one port across multiple internal hosts matches horizontal reconnaissance, distinguishing it from a full connect scan.

Why this answer

This is most likely a SYN scan (option D), a reconnaissance technique where an attacker sends TCP SYN packets to a specific port on multiple hosts to determine if the port is open. A SYN scan is stealthier than a full TCP connect scan because it never completes the three-way handshake, leaving fewer logs. The IDS alert describes the hallmark behavior of a SYN scan: a single external IP targeting the same port across many internal hosts.

Exam trap

ISC2 often tests the distinction between a SYN flood (DoS) and a SYN scan (reconnaissance), and the trap here is that candidates confuse the use of SYN packets in a volumetric attack versus a probing technique.

How to eliminate wrong answers

Option A is wrong because a SYN flood is a denial-of-service (DoS) attack that aims to overwhelm a single target with SYN packets, exhausting its connection table, not a reconnaissance scan across multiple hosts. Option B is wrong because a ping sweep uses ICMP Echo Request packets (ping) to discover live hosts, not TCP SYN packets to a specific port. Option C is wrong because a Smurf attack is a distributed DoS attack that sends ICMP Echo Requests with a spoofed source IP to a broadcast address, causing amplification, and does not involve TCP SYN packets or port scanning.

17
MCQhard

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

A.Compliant with both RTO and RPO
B.Compliant with RTO but not RPO
C.Compliant with neither
D.Compliant with RPO but not RTO
AnswerB

RTO likely achievable, but RPO is violated due to infrequent backups.

Why this answer

The exhibit shows the required RTO is 4 hours and the actual RTO is 4 hours, meaning the system recovers within the allowed downtime, so it is compliant with RTO. However, the backup interval is 4 hours, so the actual RPO is 4 hours, which exceeds the required RPO of 1 hour. This means up to 4 hours of data could be lost, failing RPO compliance.

Therefore, the correct answer is B.

Exam trap

ISC2 often tests the distinction between RTO and RPO by presenting a scenario where one objective is met and the other is not, and the trap is that candidates confuse which metric measures downtime versus data loss, leading them to incorrectly select A or D.

How to eliminate wrong answers

Option A is wrong because it claims compliance with both RTO and RPO, but the actual RPO of 2 hours exceeds the required 1 hour, so RPO is not met. Option C is wrong because it states compliance with neither, but the actual RTO of 4 hours meets the required 4 hours, so RTO is compliant. Option D is wrong because it claims compliance with RPO but not RTO, which is the reverse of the actual situation: RTO is met and RPO is not.

18
MCQhard

A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured web server that exposed a database directly. Which principle was most lacking in this scenario?

A.Least privilege
B.Fail securely
C.Complete mediation
D.Defense in depth
AnswerD

Defense in depth layers multiple independent controls so one failure cannot expose data. A directly reachable database behind a misconfigured web server shows the missing network segmentation and access controls that would have contained the breach.

Why this answer

Defense in depth is the principle of layering multiple security controls so that a single failure does not expose sensitive data. The scenario describes encryption at rest and in transit (two layers) but a misconfigured web server directly exposed the database — a missing network segmentation or access-control layer. The breach succeeded because no additional layer prevented direct database access, which is the essence of a defense-in-depth failure.

Exam trap

The trap here is confusing defense in depth with least privilege or complete mediation — candidates see 'misconfigured web server' and jump to least privilege, missing that the scenario's core issue is the absence of layered controls beyond encryption.

How to eliminate wrong answers

Option A is wrong because least privilege concerns granting only the minimum permissions needed; while relevant, the core failure here is the absence of layered controls, not excessive permissions. Option B is wrong because fail securely means systems should default to a secure state on failure; the scenario does not describe a failure-mode issue but rather a missing architectural layer. Option C is wrong because complete mediation means every access request is checked against authorization; while the database exposure could involve mediation gaps, the broader and more accurate principle violated is defense in depth, given the reliance on encryption alone.

19
MCQmedium

What is the primary purpose of a digital signature?

A.Ensure data confidentiality
B.Control access to resources
C.Encrypt data at rest
D.Provide data integrity and non-repudiation
AnswerD

A digital signature uses the sender's private key to create a cryptographic hash of the message, letting the recipient verify the data was not altered and binding the sender to it. This satisfies the stem's requirement for both integrity and non-repudiation, since only the private key holder could have produced that signature.

Why this answer

Digital signatures provide integrity (detect tampering) and non-repudiation (proof of origin).

20
MCQeasy

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

A.Risk assessment
B.Business Impact Analysis (BIA)
C.Vulnerability assessment
D.Gap analysis
AnswerB

A Business Impact Analysis identifies critical business functions, quantifies the impact of their disruption, and maps dependencies on systems, people and suppliers, producing the foundation from which recovery priorities and continuity strategies are later derived.

Why this answer

The Business Impact Analysis (BIA) is performed first in BCP development because it identifies critical business functions, their dependencies, and the impact of disruption over time. This data drives recovery time objectives (RTO) and recovery point objectives (RPO), which then inform the rest of the BCP. Risk assessment and other analyses come after the BIA because you must know what to protect before assessing threats to it.

Exam trap

The trap is assuming risk assessment comes first because it sounds foundational — but BCP best practice (and ISO 22301) places the BIA first to define what matters before assessing threats.

How to eliminate wrong answers

Option A is wrong because risk assessment identifies threats and vulnerabilities to assets, but it is performed after the BIA has determined which business functions and assets are critical. Option C is wrong because vulnerability assessment focuses on technical weaknesses in systems, not on identifying critical business functions and their dependencies. Option D is wrong because gap analysis compares current capabilities against desired state and is typically done after the BIA and risk assessment to plan improvements.

21
MCQmedium

An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?

A.Network-based Intrusion Detection System (NIDS)
B.Unified Threat Management (UTM) appliance
C.Firewall with deep packet inspection
D.Network-based Intrusion Prevention System (NIPS)
AnswerA

A NIDS passively monitors network traffic and raises alerts on suspicious patterns without sitting inline, so it cannot drop or block legitimate packets. This satisfies the requirement to detect and alert on intrusions while avoiding any risk of blocking valid traffic.

Why this answer

A Network-based Intrusion Detection System (NIDS) passively monitors network traffic and generates alerts when suspicious patterns are detected, but it does not take any inline action to block traffic. This makes it the correct choice for an organization that wants to detect and alert on potential intrusions without any risk of blocking legitimate traffic, as the NIDS operates out-of-band and cannot drop packets.

Exam trap

ISC2 often tests the distinction between detection (IDS) and prevention (IPS) by emphasizing that an IDS is passive and out-of-band, while an IPS is inline and can block traffic, so the trap here is confusing the alert-only capability of NIDS with the active blocking of NIPS or UTM appliances.

How to eliminate wrong answers

Option B is wrong because a Unified Threat Management (UTM) appliance typically includes intrusion prevention, antivirus, and content filtering that can actively block traffic, which introduces the risk of blocking legitimate traffic. Option C is wrong because a firewall with deep packet inspection (DPI) is an inline device that can drop or reject packets based on application-layer analysis, which could inadvertently block legitimate traffic. Option D is wrong because a Network-based Intrusion Prevention System (NIPS) is an inline device that actively drops or resets malicious traffic, directly contradicting the requirement to avoid blocking legitimate traffic.

22
MCQmedium

A company's security policy requires that all sensitive data be encrypted both at rest and in transit. This is an example of applying which security principle?

A.Separation of duties
B.Need to know
C.Least privilege
D.Defense in depth
AnswerD

Defense in depth layers multiple independent controls so that a failure in one does not expose data. Encrypting sensitive data both at rest and in transit applies two complementary safeguards across different states, matching that layered principle.

Why this answer

Encrypting sensitive data both at rest and in transit applies multiple overlapping controls at different layers of the environment, which is the definition of defense in depth. Rather than relying on a single control, the organization layers cryptographic protections so that compromise of one layer (e.g., a stolen disk) does not automatically expose the data. This is a classic example of layered, redundant security controls.

Exam trap

The trap here is confusing access-control principles (least privilege, need to know, separation of duties) with data-protection layering; candidates who see 'encryption' and reach for an access-control answer miss that the question is about layered controls, not authorization.

How to eliminate wrong answers

Option A is wrong because separation of duties is an administrative control that divides critical tasks among different people to prevent fraud or error — it has nothing to do with encrypting data at multiple states. Option B is wrong because need to know is an access-control principle limiting data access to those with a legitimate requirement, not a data-protection layering strategy. Option C is wrong because least privilege restricts user and process permissions to the minimum necessary; it is an authorization principle, not a data-at-rest/in-transit encryption strategy.

23
MCQmedium

A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerA

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encrypting patient records at rest and in transit, combined with role-based access controls, directly prevents unauthorized viewing or exposure of sensitive health data. This aligns with the architect's goal of protecting patient information from improper disclosure, making confidentiality the principle being addressed.

Why this answer

The architect's measures—encrypting patient records at rest and in transit and restricting access by job roles—are classic controls for protecting confidentiality. Confidentiality focuses on preventing unauthorized disclosure of information. While integrity and availability are also part of the CIA triad, the scenario's emphasis on encryption and access restrictions points specifically to confidentiality.

Exam trap

The trap here is confusing the CIA triad components by assuming that any security control automatically addresses all three, rather than identifying the specific principle targeted by encryption and access controls.

24
MCQmedium

A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?

A.Enable Network Level Authentication for RDP connections
B.Configure the firewall to allow RDP only from specific IP addresses
C.Change the RDP listening port to a non-standard number
D.Disable the Remote Desktop Protocol service if it is not required for administration
AnswerD

Port 3389 is used by Remote Desktop Protocol (RDP). If RDP is not needed, disabling the service closes the port and eliminates a common attack vector. This is the most direct and effective step to reduce the attack surface, as it removes the service entirely rather than just restricting access.

Why this answer

The first step in reducing attack surface is to remove unnecessary services. Since port 3389 is open due to RDP, and if RDP is not required, disabling it eliminates the exposure entirely. Other measures like firewall restrictions or authentication enhancements are useful but secondary to removing the service.

Exam trap

The trap here is opting for a mitigation like firewall rules or port changes instead of eliminating the unnecessary service, which is the most effective way to reduce attack surface.

25
MCQeasy

A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?

A.Grant permissions only to the IT department.
B.Grant permissions based on the user's department membership.
C.Grant each user only the permissions necessary to perform their job duties.
D.Grant all users full control to simplify management.
AnswerC

Granting each user only the permissions their job duties require directly implements least privilege, which demands minimal necessary access. This satisfies the stem's constraint by restricting rights to job scope rather than broad defaults, reducing the attack surface and limiting potential damage from compromised accounts or accidental misuse.

Why this answer

The principle of least privilege means granting each user only the minimum permissions required to perform their job functions — nothing more. Option C directly embodies this by tying permissions to actual job duties rather than broad group membership or department-wide access.

Exam trap

The trap here is confusing 'department membership' with 'job duties' — department-based access sounds reasonable but is broader than least privilege requires, and candidates often pick it as a middle-ground answer.

How to eliminate wrong answers

Option A is wrong because granting permissions to an entire IT department violates least privilege — it grants access to many users who may not need it. Option B is wrong because department-based membership grants permissions based on affiliation rather than actual job need, which is broader than necessary. Option D is wrong because granting all users full control is the opposite of least privilege and maximizes risk.

26
MCQeasy

A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?

A.Identification
B.Authentication
C.Accounting
D.Authorization
AnswerA

Identification is the act of claiming an identity to a system, and the smart card presents a unique credential that tells the workstation who the nurse claims to be. Because the card by itself does not grant access and a password must still follow, it functions as the identification step that precedes authentication in the access control process.

Why this answer

The smart card presents a unique token that asserts who the nurse claims to be, which is the definition of identification. Because the card alone does not grant access and a password must still be supplied, verification of that claim is handled separately by authentication. Authorization and accounting occur only after identity is established and verified.

Exam trap

The trap here is assuming that possessing a physical token automatically verifies identity, when presenting it only claims an identity that still requires separate verification.

27
MCQmedium

A healthcare organization wants to ensure that only authorized clinicians can view patient records, while also maintaining a detailed log of every access for compliance audits. Which security principle is primarily being addressed by restricting access and recording all access attempts?

A.Confidentiality
B.Integrity
C.Accountability
D.Availability
AnswerA

Confidentiality ensures that information is not disclosed to unauthorized individuals. By restricting access to only authorized clinicians and logging all access, the organization is protecting patient records from unauthorized disclosure. The logging supports auditability but the core principle is confidentiality, as it directly prevents unauthorized viewing of sensitive data.

Why this answer

Confidentiality is the principle that ensures information is not disclosed to unauthorized individuals. Restricting access to authorized clinicians directly supports confidentiality by preventing unauthorized viewing of patient records. Logging access attempts supports accountability and auditability, but the core security objective here is to protect the confidentiality of sensitive health information.

Exam trap

The trap here is confusing confidentiality with accountability because logging is mentioned, but the primary goal is to prevent unauthorized disclosure, which is confidentiality.

28
MCQmedium

During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?

A.Notify law enforcement
B.Capture a memory dump
C.Power off the system
D.Run antivirus scan
AnswerB

Volatile memory holds running processes, network connections and encryption keys that vanish on power-off, so capturing a memory dump first preserves this evidence before any shutdown or remediation destroys it. Disk imaging and other collection steps follow afterwards, satisfying the stem's requirement to preserve evidence in the correct order.

Why this answer

Capturing a memory dump (volatile data) is the first priority because it contains critical evidence such as running processes, network connections, and encryption keys that will be lost when the system is powered off. The order of volatility dictates that volatile data must be collected before any non-volatile data, and before any actions that could alter system state.

Exam trap

ISC2 often tests the principle of order of volatility, and the trap here is that candidates mistakenly think powering off the system preserves evidence, when in fact it destroys the most volatile and valuable forensic data.

How to eliminate wrong answers

Option A is wrong because notifying law enforcement is a procedural step that should occur after evidence has been secured, not before, and it does not directly preserve volatile evidence. Option C is wrong because powering off the system destroys volatile memory (RAM) and may cause loss of critical forensic data, such as active network connections and malware in memory. Option D is wrong because running an antivirus scan modifies the system state (e.g., quarantining files, altering timestamps) and can destroy or contaminate evidence, violating forensic integrity.

29
MCQhard

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

A.Escalate the alert to Tier 3 for advanced analysis.
B.Conduct a deeper investigation to identify affected systems and data.
C.Block the external IP address at the firewall immediately.
D.Reboot the server to terminate any malicious processes.
AnswerB

With the alert confirmed genuine, the analyst must scope the compromise: identify which systems communicated with the command-and-control infrastructure and what data was accessed. Containment decisions depend on that evidence, so deeper investigation precedes remediation.

Why this answer

After confirming a SIEM alert is not a false positive, the most appropriate next step is to conduct a deeper investigation to identify affected systems and data. This aligns with the incident response process, where containment and eradication should be based on a thorough understanding of the scope and impact. Immediate blocking or rebooting without investigation could destroy evidence or disrupt business operations.

Exam trap

CC often tests the order of incident response steps, and candidates may jump to containment (blocking) before investigation, which can be counterproductive.

How to eliminate wrong answers

Option A is wrong because escalating to Tier 3 without initial investigation may be premature; Tier 1 or 2 should first gather more context. Option C is wrong because blocking the IP immediately, while a containment step, should be done after understanding the scope to avoid disrupting legitimate traffic or tipping off attackers. Option D is wrong because rebooting the server could destroy volatile evidence and may not remove the root cause, allowing reinfection.

30
MCQmedium

A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?

A.The account lockout threshold is set too high, allowing unlimited authentication attempts
B.The password policy permits weak passwords that are easily guessed
C.The account is not subject to least privilege, so it holds excessive administrative rights
D.The account lacks multifactor authentication, so stolen credentials can be reused from anywhere
AnswerD

Impossible-travel logins from two distant locations within minutes strongly suggest the credentials were captured and reused by an attacker. A long complex password offers no protection once it is stolen, but requiring a second factor such as a hardware token or authenticator app would have blocked the external session. The absence of MFA is the weakness that allows credential replay.

Why this answer

Two successful logins from geographically impossible locations within minutes indicate the credentials were stolen and reused. A long complex password cannot help once it is captured, but adding multifactor authentication means the attacker also needs the second factor, which blocks simple credential replay and is the control missing from this account.

Exam trap

The trap here is blaming password strength for a compromise when the credentials were valid and reused, which only multifactor authentication would have stopped.

31
Multi-Selecthard

According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)

Select 3 answers
A.Allow users to paste passwords to facilitate password manager use
B.Check passwords against known breached password lists
C.Require complex combinations of uppercase, lowercase, numbers, and symbols
D.Require frequent password changes every 30 days
E.Require a minimum length of 8 characters for most accounts
AnswersA, B, E

Allowing paste supports password managers, which NIST SP 800-63B explicitly endorses to reduce reuse and enable longer, higher-entropy secrets. Blocking paste forces weaker, memorable passwords and encourages poor workarounds. This satisfies the stem's recommendation for verifier practices that accommodate credential managers rather than impede them.

Why this answer

Option A is correct because NIST SP 800-63B explicitly recommends permitting "paste" functionality in password fields so that users can employ password managers, which generate and store strong, unique credentials. Option B is correct because the guideline requires verifiers to compare prospective passwords against lists of commonly used, expected, or compromised passwords (e.g., breach corpora) and reject matches. Option E is correct because NIST sets a minimum password length of 8 characters for user-chosen secrets, while encouraging longer passphrases (up to at least 64 characters).

Option C is not recommended because NIST advises against composition rules mandating mixed uppercase, lowercase, digits, and symbols, since they push users toward predictable patterns. Option D is not recommended because NIST discourages forced periodic rotation (e.g., every 30 days) absent evidence of compromise, as it weakens password quality.

Exam trap

The CC exam often tests the outdated belief that complex passwords and frequent changes are recommended, while NIST now advises against them in favor of length and breach checks.

32
MCQhard

A security team discovers that an internal database server is sending large amounts of data to an unknown external IP address. The server is not supposed to communicate externally. Which security control should be implemented to prevent such data exfiltration?

A.Implement a VPN for all external communications
B.Install an intrusion detection system (IDS) on the network segment
C.Configure a firewall to deny all outbound traffic from the database server except to specific authorized destinations
D.Deploy a data loss prevention (DLP) system on the server
AnswerC

An outbound deny-by-default rule with explicit allow-listing stops the server reaching unknown external IPs while permitting legitimate destinations. This blocks the exfiltration channel itself, unlike monitoring or inbound filtering, which would not prevent data leaving the internal database server.

Why this answer

A firewall with restrictive egress rules blocks unauthorized outbound traffic, preventing data exfiltration. Option A (VPN) would not stop the traffic; it could even encrypt and tunnel it. Option B (IDS) can detect but not block.

Option D (DLP) monitors content but may not effectively block at the network level.

33
Multi-Selectmedium

A financial services company is designing a demilitarized zone (DMZ) for its public web and email relay servers. The security architect wants to reduce the attack surface and limit what an attacker can reach if a DMZ host is compromised. Which two design practices should be implemented? (Choose two.)

Select 2 answers
A.Allow the DMZ hosts to initiate connections to any internal server for management convenience.
B.Place the DMZ servers on the same VLAN as internal user workstations to simplify routing.
C.Permit only the specific inbound ports required for the public services into the DMZ.
D.Configure the internal firewall to allow only required DMZ-to-internal traffic and deny the rest.
E.Use the same firewall rule set for both the external and internal firewalls to reduce administrative effort.
AnswersC, D

Restricting inbound access to only the ports needed for web and email reduces the exposed attack surface and prevents attackers from reaching unnecessary services. This is a core DMZ design principle: the external firewall allows only what the public service requires, such as HTTPS for the web server and the mail relay port. It directly limits what an external attacker can probe or exploit.

Why this answer

A DMZ should expose only the ports required for public services and should enforce strict, default-deny rules on the internal firewall so that a compromised DMZ host cannot freely reach internal systems. These two practices reduce attack surface and contain lateral movement. Opening management paths or sharing VLANs and rule sets with internal networks removes the separation that makes the DMZ valuable.

Exam trap

The trap here is treating the DMZ as a trusted extension of the internal network, which leads to permissive rules that allow a compromised host to pivot inward.

34
MCQmedium

An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?

A.Shoulder surfing
B.USB drop attack
C.Tailgating
D.Phishing
AnswerD

The misspelled sender address signals a spoofed identity, the defining trait of phishing: fraudulent email crafted to impersonate a trusted executive and trigger urgent action. Business email compromise is the specific subtype, but phishing correctly names the broader attack category the stem describes.

Why this answer

Phishing is a social engineering attack where an attacker impersonates a trusted entity (here, the CEO) via email to trick the recipient into performing a harmful action, such as transferring funds. The slightly misspelled email address is a classic phishing indicator — attackers register look-alike domains to deceive recipients. This specific CEO-impersonation variant is often called Business Email Compromise (BEC), a form of phishing.

Exam trap

The trap here is that candidates may overthink the scenario and pick a more 'technical' attack like shoulder surfing or tailgating, when the defining characteristic — deceptive email impersonation — clearly maps to phishing.

How to eliminate wrong answers

Option A is wrong because shoulder surfing involves physically observing someone's screen or keyboard to steal credentials or PINs — it has nothing to do with email impersonation. Option B is wrong because a USB drop attack relies on leaving infected USB drives for victims to plug in, exploiting curiosity or carelessness — no USB is involved here. Option C is wrong because tailgating is a physical security breach where an unauthorized person follows an authorized person through a secured door — it is unrelated to email-based deception.

35
MCQmedium

During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerB

WRT is the time needed after systems are restored to validate data and resume normal business operations. Meeting RTO restored the systems, but the outstanding configuration and validation work means WRT was not met, so users could not resume work.

Why this answer

Work Recovery Time (WRT) is the time required to restore business operations after systems are technically recovered. In this scenario, systems were restored within RTO, but users could not resume work due to additional configuration and data validation, meaning WRT was not met. Therefore, WRT is the metric not met.

Exam trap

CC often tests the distinction between RTO and WRT, and candidates may incorrectly assume that meeting RTO means full recovery, ignoring the additional time needed for business operations to resume.

How to eliminate wrong answers

Option A is wrong because RPO relates to data loss, and there is no indication that data loss exceeded the RPO. Option C is wrong because MTD is the total time a system can be down, and the scenario does not specify that MTD was exceeded. Option D is wrong because RTO was met, as systems were restored within the objective.

36
MCQhard

Which of the following is the best practice for managing cryptographic keys in a large organization?

A.Embed keys in application code to ensure availability.
B.Distribute keys to administrators via email for convenience.
C.Use a single key for all encryption to simplify management.
D.Store keys in a centralized hardware security module (HSM) with strict access controls.
AnswerD

Centralised HSM storage satisfies the large-org constraint by keeping private keys inside tamper-resistant hardware that never exposes them to host memory, while strict access controls enforce separation of duties across many administrators. This prevents key extraction and unauthorised signing at scale, unlike keys held in software or scattered per-host stores.

Why this answer

A centralized Hardware Security Module (HSM) provides tamper-resistant, dedicated hardware for secure key generation, storage, and cryptographic operations. Strict access controls (e.g., role-based access, multi-factor authentication) ensure that only authorized personnel can manage keys, while the HSM prevents key extraction even if the host system is compromised. This aligns with NIST SP 800-57 guidelines for key management in large organizations.

Exam trap

ISC2 often tests the misconception that convenience (e.g., embedding keys in code or using a single key) is acceptable for key management, when in fact security and compartmentalization are paramount in enterprise environments.

How to eliminate wrong answers

Option A is wrong because embedding keys in application code exposes them to static analysis, reverse engineering, and version control leaks, violating the principle of key separation and making key rotation nearly impossible. Option B is wrong because distributing keys via email transmits them in cleartext over potentially insecure channels, exposing them to interception and violating confidentiality requirements (e.g., PCI DSS, GDPR). Option C is wrong because using a single key for all encryption violates key separation and compartmentalization; if that key is compromised, all encrypted data is exposed, and it prevents granular access control and rotation without massive re-encryption.

37
MCQhard

A security auditor discovers that a user has been granted read and write access to a sensitive file, but the user's job only requires read access. Which access control principle has been violated?

A.Job rotation
B.Need-to-know
C.Separation of duties
D.Least privilege
AnswerD

Least privilege grants users only the access their role requires. Read and write access to a sensitive file exceeds the read-only requirement, so excessive permissions were assigned. This over-provisioning is precisely the violation the auditor identified.

Why this answer

The principle of least privilege dictates that users should be granted only the minimum permissions necessary to perform their job functions. Granting write access when only read access is required violates this principle by providing unnecessary and potentially harmful capabilities. This is a core access control concept in the CC exam.

Exam trap

ISC2 often tests least privilege by contrasting it with need-to-know, where candidates mistakenly choose need-to-know because both involve limiting access, but least privilege focuses on the permission level (read vs. write) while need-to-know focuses on the data scope.

How to eliminate wrong answers

Option A is wrong because job rotation is a security practice where users periodically switch roles to reduce fraud risk, not a principle about limiting permissions. Option B is wrong because need-to-know restricts access to specific data based on necessity, but the violation here is about the level of privilege (read vs. write), not the data itself. Option C is wrong because separation of duties ensures no single user has conflicting responsibilities (e.g., creating and approving transactions), which is not the issue in this scenario.

38
Multi-Selectmedium

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Select 2 answers
A.Affected customers
B.Legal and public relations
C.All employees
D.Competitors
E.Internal management
AnswersB, E

Legal counsel and public relations must be engaged immediately because ransomware triggers regulatory breach-notification duties and reputational exposure. Legal assesses disclosure obligations, while PR controls messaging to customers, regulators and media. This satisfies the best-practise requirement to notify stakeholders whose functions cannot wait until containment completes.

Why this answer

Option B (Legal and public relations) is correct because during a ransomware incident, legal counsel must be engaged immediately to assess regulatory notification obligations (e.g., GDPR, HIPAA, SEC disclosure rules) and preserve attorney-client privilege, while public relations manages external messaging to protect the organization's reputation and prevent misinformation. Option E (Internal management) is correct because executive leadership and management must be notified right away to authorize incident response actions, allocate resources, make critical business decisions, and fulfill their governance and oversight responsibilities. Option A (Affected customers) is not an immediate notification group; customer notification typically occurs after the scope of the breach is determined and legal/regulatory guidance is obtained, often with a defined timeline.

Option C (All employees) is too broad for immediate notification, as mass communication can cause panic or leaks; only those with a need to know are informed initially. Option D (Competitors) has no legitimate role in incident response notification and would only expose the organization to further risk.

Exam trap

The trap is selecting 'affected customers' or 'all employees' as immediate notifications because they seem most impacted — but best practice prioritizes legal/PR and internal management for controlled, authorized response.

39
MCQmedium

A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?

A.A deny rule for all traffic except HTTP and HTTPS
B.An implicit deny rule at the end of the rule set
C.Explicit allow rules for HTTP and HTTPS, followed by an implicit deny
D.A stateful inspection rule that allows all outbound traffic
AnswerC

To allow only HTTP and HTTPS while blocking all other outbound traffic, the administrator must create explicit allow rules for TCP ports 80 and 443 from the internal network to the internet. These rules should be placed before a final implicit deny rule. This ensures that only the desired traffic is permitted and all other traffic is blocked.

Why this answer

Firewall rule sets are processed in order. To allow only HTTP and HTTPS outbound, explicit allow rules for TCP 80 and 443 must be created first. Then, a final rule (often implicit) denies all other traffic.

This ensures that only the desired traffic is permitted and everything else is blocked, meeting the requirement.

Exam trap

The trap here is assuming that an implicit deny alone is sufficient, when in fact explicit allow rules for the desired traffic must be placed before the deny to permit HTTP and HTTPS.

40
MCQmedium

A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?

A.Mean Time to Repair (MTTR)
B.Recovery Time Objective (RTO)
C.Service Level Agreement (SLA)
D.Recovery Point Objective (RPO)
AnswerB

Recovery Time Objective defines the maximum acceptable time to restore a system after disruption. A two-hour restoration requirement is therefore an RTO, distinguishing it from Recovery Point Objective, which instead specifies tolerable data loss measured in time.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time that a system or application can be unavailable after a disruption. In this scenario, the requirement to restore critical systems within 2 hours directly specifies the RTO. It is a key metric in business continuity planning that drives the design of failover and recovery strategies.

Exam trap

ISC2 often tests the distinction between RTO and RPO, where candidates confuse the time to restore service (RTO) with the acceptable data loss window (RPO).

How to eliminate wrong answers

Option A is wrong because Mean Time to Repair (MTTR) measures the average time taken to repair a failed component, not the maximum allowable downtime for a business process. Option C is wrong because a Service Level Agreement (SLA) is a contractual commitment between a provider and customer, often including uptime percentages, but it does not define the specific recovery time target for a BCP. Option D is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (e.g., how far back in time data may be lost), not the time to restore service.

41
MCQmedium

According to NIST SP 800-63, which password policy is most recommended?

A.Allow short passwords but require numbers and symbols
B.Use complex passwords with special characters and minimal length
C.Enforce a minimum length of 8 characters and check against breached password lists
D.Require frequent password changes every 30 days
AnswerC

NIST SP 800-63B advises against composition and rotation rules, favouring length and blocklist screening. An eight-character minimum combined with checking against breached password lists directly satisfies that guidance, blocking compromised credentials without imposing complexity or expiry requirements.

Why this answer

NIST SP 800-63B recommends a minimum password length of 8 characters (with 15+ encouraged for memorized secrets) and screening new passwords against lists of commonly used and breached passwords. This approach prioritizes length and blocklist checks over forced complexity and rotation.

Exam trap

The trap is that candidates default to legacy advice—complexity and 30-day rotation—when NIST has explicitly moved away from both in favor of length and breach-list screening.

How to eliminate wrong answers

Option A is wrong because allowing short passwords—even with complexity requirements—weakens resistance to brute-force and credential-stuffing attacks. Option B is wrong because NIST explicitly de-emphasizes composition rules (mixed case, symbols) in favor of length and blocklist screening. Option D is wrong because NIST advises against arbitrary periodic rotation, which drives users to predictable patterns like Password1! and Summer2024! rather than improving security.

42
MCQmedium

A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?

A.Separation of duties
B.Least privilege
C.Job rotation
D.Defense in depth
AnswerA

Separation of duties divides a critical task among multiple people so that no single individual can complete it without detection or collusion. Here, creating a vendor payment and approving it are deliberately assigned to two different employees, preventing one person from initiating and authorizing a fraudulent payment. This directly matches the policy's intent and is a classic detective and preventive administrative control in financial and security operations.

Why this answer

The policy prevents any single employee from completing a sensitive transaction end to end by requiring two different people to create and approve a vendor payment. That is separation of duties, an administrative control that limits the opportunity for fraud and error. Least privilege limits what each user can access, defense in depth layers controls, and job rotation changes assignments over time; none of those captures the requirement that two distinct people must be involved in one process.

Exam trap

The trap here is confusing separation of duties with least privilege, since both restrict what a user can do, but only separation of duties requires two different people in one workflow.

43
MCQhard

In a typical Windows environment, which access control model is used for managing file permissions?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Attribute-Based Access Control (ABAC)
AnswerA

Discretionary Access Control (DAC) is the model Windows uses for file permissions: each object's owner sets access via access control lists (ACLs), granting or denying rights to specific users and groups. This satisfies the stem's requirement for the standard access control model managing file permissions in a typical Windows environment.

Why this answer

In a typical Windows environment, file permissions are managed using Discretionary Access Control (DAC), where the owner of a resource (e.g., a file or folder) can grant or deny access to other users or groups. This is implemented via NTFS permissions, which allow the owner to set ACLs (Access Control Lists) on objects, giving them discretion over who can read, write, or execute. Windows does not enforce a system-wide policy beyond the owner's decisions, which is the hallmark of DAC.

Exam trap

ISC2 often tests the misconception that Windows uses RBAC because of Active Directory groups, but AD groups are merely a convenience for assigning DAC permissions, not a role-based system; the key distinction is that DAC gives discretion to the resource owner, while RBAC assigns permissions based on organizational roles defined by an administrator.

How to eliminate wrong answers

Option B (RBAC) is wrong because Windows does not natively use Role-Based Access Control for file permissions; RBAC is typically implemented in enterprise applications or databases (e.g., SQL Server) and assigns permissions based on job functions, not owner discretion. Option C (MAC) is wrong because Mandatory Access Control is not used in standard Windows; it is a feature of high-security systems like SELinux or Trusted Solaris, where a central authority (e.g., a security label) overrides owner decisions. Option D (ABAC) is wrong because Attribute-Based Access Control is not the default model for Windows file permissions; ABAC evaluates policies based on attributes (e.g., time, location) and is more common in modern cloud or network access control systems (e.g., AWS IAM), not in the NTFS permission system.

44
Multi-Selecteasy

Which two of the following are examples of physical access controls? (Select TWO)

Select 2 answers
A.Security guards
B.Encryption
C.Password policies
D.Firewall rules
E.Biometric door locks
AnswersA, E

Security guards satisfy the physical access control requirement because they regulate entry to premises through direct human presence and intervention. Unlike logical controls such as passwords or Microsoft Entra ID authentication, guards physically verify identity and can deny or permit access at the perimeter, which is precisely the tangible, on-site enforcement the question demands.

Why this answer

Security guards (A) are a physical access control because they are personnel who monitor and restrict entry to a facility, directly controlling who physically enters a protected area. Biometric door locks (E) are a physical access control because they use physiological traits such as fingerprints or retina patterns to authenticate a person and physically unlock a door. Encryption (B) is a logical/technical control that protects data confidentiality, not physical entry.

Password policies (C) are administrative controls governing authentication credentials, not physical access. Firewall rules (D) are technical network controls that filter traffic, not physical access controls.

Exam trap

ISC2 often tests the distinction between physical, administrative, and logical/technical controls, and the trap here is that candidates confuse encryption or firewall rules as 'physical' because they are tangible in implementation, but they are actually logical controls that protect data, not physical assets or premises.

45
MCQhard

A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?

A.Role-based access control (RBAC)
B.Mandatory access control (MAC)
C.Discretionary access control (DAC)
D.Attribute-based access control (ABAC)
AnswerB

MAC enforces access based on sensitivity labels assigned to objects and clearances held by subjects, with the system, not users, controlling label changes. The scenario's classification labels, clearances, and inability to bypass checks are defining traits of MAC, making this the correct model.

Why this answer

Mandatory access control bases decisions on labels attached to objects and clearances assigned to subjects, with enforcement handled by the system rather than by user discretion. The scenario's classification labels, clearance levels, and prohibition on bypassing checks all align with MAC. This model is typical in government and military settings where data sensitivity demands strict, non-discretionary control.

Exam trap

The trap here is assuming that any label-based or fine-grained scheme is attribute-based access control, when rigid label and clearance enforcement is specifically mandatory access control.

46
Multi-Selectmedium

A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)

Select 2 answers
A.Low CPU usage on servers
B.Unusually high traffic volume from multiple IP addresses
C.Single source sending many packets
D.Slow network performance and increased latency
E.Decrease in DNS queries
AnswersB, D

Unusually high traffic volume from multiple IP addresses directly satisfies the distributed-source constraint distinguishing DDoS from single-origin DoS. Attackers coordinate botnets so requests flood from many geographically dispersed hosts, exhausting bandwidth or connection tables. This pattern is a primary detection indicator in Microsoft Entra ID and network monitoring tools.

Why this answer

Option B is correct because a DDoS (Distributed Denial-of-Service) attack by definition originates from many compromised hosts (a botnet), so the analyst would observe an unusually high volume of traffic arriving from numerous, often geographically dispersed IP addresses. Option D is correct because the flood of requests exhausts server, bandwidth, or connection-table resources, which manifests as slow network performance, increased latency, timeouts, and unresponsive services for legitimate users. Option A is wrong because a DDoS typically drives CPU, memory, and bandwidth utilization up, not down.

Option C is wrong because traffic from a single source describes a DoS attack, not a distributed one. Option E is wrong because DNS query volume usually spikes during many DDoS attacks (e.g., DNS amplification/reflection) rather than decreasing.

Exam trap

The trap here is confusing DoS (single source) with DDoS (many sources) and assuming resource usage always drops during an attack, when in fact CPU and bandwidth typically spike.

47
MCQeasy

An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Accountability
AnswerB

Separation of duties splits a sensitive transaction across different people so no single individual controls it end to end. Preventing an employee from approving their own expenses enforces that split, removing the ability to self-authorise fraudulent claims.

Why this answer

Correct: B - Separation of duties. Separation of duties prevents a single individual from having conflicting roles. Option A is wrong because least privilege limits access to only necessary resources.

Option C is wrong because defense in depth uses multiple layers. Option D is wrong because accountability tracks actions to individuals.

48
MCQmedium

In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?

A.Detective access control
B.Physical access control
C.Administrative access control
D.Logical access control
AnswerD

Logical access controls govern how subjects interact with systems and data, including session timeouts and authentication settings. A GPO enforcing a 15-minute inactivity lock restricts access through software configuration rather than physical barriers, directly satisfying the stem's requirement for automated session termination within Active Directory.

Why this answer

A GPO-enforced session lock is a logical access control because it is implemented in software/OS policy and governs how users interact with system resources after authentication. Logical controls include passwords, permissions, encryption, and session policies, all enforced by the operating system or applications rather than physical barriers or administrative procedures.

Exam trap

The trap here is confusing the policy document (administrative) with its technical enforcement (logical) — CC often tests whether candidates can distinguish administrative, logical/technical, and physical control categories.

How to eliminate wrong answers

Option A is wrong because detective controls identify and log events after they occur (e.g., IDS, audit logs), whereas a session lock actively enforces a restriction. Option B is wrong because physical controls protect tangible assets (locks, fences, guards), not OS-level session behavior. Option C is wrong because administrative controls are policies, procedures, and training — the GPO is the technical enforcement mechanism, not the policy document itself.

49
MCQeasy

A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?

A.Open authentication with Captive Portal
B.Wi-Fi Protected Access 2 (WPA2) with Pre-Shared Key (PSK)
C.Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)
D.Wired Equivalent Privacy (WEP)
AnswerC

WPA3 introduces SAE, a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline guessing attack; they must interact with the network for each guess, which is detectable and rate-limited. This directly satisfies the requirement for strong encryption and resistance to offline attacks.

Why this answer

WPA3 with SAE is designed to replace WPA2-PSK's vulnerable four-way handshake with a mutually authenticated exchange that resists offline dictionary attacks. It also provides stronger encryption through the use of SAE and, in WPA3-Personal, forward secrecy. The other options either lack strong encryption or remain susceptible to offline attacks.

Exam trap

The trap here is assuming WPA2-PSK is sufficient because it is widely used, when its four-way handshake still permits offline dictionary attacks on weak passphrases.

50
MCQmedium

A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?

A.Account lockout
B.Session timeout
C.Password complexity
D.Least privilege
AnswerA

Account lockout mitigates brute force by disabling an account after a set number of failed attempts, directly blocking continued password guessing from the single IP address. It satisfies the scenario's constraint of repeated authentication failures within a short period, though attackers could still target other accounts.

Why this answer

Account lockout is the most direct mitigation because it disables the account after a defined number of failed attempts, breaking the brute-force loop before the attacker can guess the password. It is a preventive control that directly targets the repeated-failure pattern described in the scenario.

Exam trap

CC often tests the distinction between preventive controls that stop the attack (lockout) and supporting controls that only make the attack harder (complexity) — candidates frequently pick password complexity because it 'sounds' like the right security answer.

How to eliminate wrong answers

Option B is wrong because session timeout only terminates idle sessions after successful authentication — it does nothing to stop repeated failed login attempts. Option C is wrong because password complexity increases the search space but does not stop an attacker from making unlimited guesses; it is a supporting control, not a mitigation for the observed attack. Option D is wrong because least privilege limits what an authenticated user can do, not how many times an attacker can attempt to authenticate.

51
MCQmedium

A university wants to provide guests with internet access through the same physical wireless infrastructure used by staff, but guests must not reach internal research servers. Staff must authenticate with institutional credentials. Which combination of controls best achieves this separation?

A.A single pre-shared key for all users plus a captive portal.
B.MAC address filtering that allows only registered devices on the wireless network.
C.Separate SSIDs mapped to different VLANs, with 802.1X for staff and a guest portal for visitors.
D.WPA3-Personal on a single SSID with a rotating password posted at reception.
AnswerC

Separate SSIDs mapped to distinct VLANs create logical isolation between guest and staff traffic on shared hardware, and 802.1X authenticates staff against institutional credentials while a guest portal handles visitors. Together these controls enforce the requirement that guests reach only the internet and cannot access internal research servers, while staff retain authenticated access.

Why this answer

Separate SSIDs tied to separate VLANs provide the isolation, and using 802.1X for staff plus a guest portal for visitors supplies the differentiated authentication the university needs. Shared keys, MAC filtering, and a single personal-network SSID all fail to distinguish populations or to prevent guests from reaching internal research servers, so they cannot meet the stated requirements.

Exam trap

The trap here is treating wireless encryption, such as WPA3-Personal, as equivalent to user authentication and network segmentation, when it only protects the radio link.

52
MCQhard

A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?

A.Intrusion Prevention System (IPS)
B.Network-based Intrusion Detection System (NIDS)
C.Web Application Firewall (WAF)
D.Stateful firewall
AnswerC

A Web Application Firewall inspects HTTP request contents at the application layer, matching signatures and rules against payloads, URLs and headers. This lets it block malicious HTTP requests, which a packet-filtering firewall or traditional IPS cannot do at that layer.

Why this answer

A Web Application Firewall (WAF) operates at the application layer (Layer 7) and is specifically designed to inspect HTTP/HTTPS traffic, blocking malicious requests such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attacks. It understands HTTP semantics like headers, cookies, methods, and payloads, making it the right tool for application-layer request filtering.

Exam trap

The trap here is confusing an IPS with a WAF: both can block malicious traffic, but only a WAF is purpose-built for HTTP application-layer request inspection, and the question explicitly specifies HTTP requests.

How to eliminate wrong answers

Option A is wrong because an IPS, while capable of deep packet inspection, is a broader network security control focused on detecting and blocking intrusions across many protocols; it is not specialized for HTTP application-layer request filtering. Option B is wrong because a NIDS only detects and alerts on suspicious traffic—it does not block requests. Option D is wrong because a stateful firewall tracks connection state at Layers 3–4 and cannot inspect HTTP payloads or block application-layer attacks.

53
MCQhard

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

A.ICMP flood
B.UDP flood
C.Amplification attack
D.SYN flood
AnswerD

A SYN flood exploits the TCP three-way handshake: spoofed source addresses generate numerous half-open connections, exhausting the server's backlog queue so legitimate clients cannot connect. The never-completed handshake described in the stem is the defining characteristic of this volumetric attack.

Why this answer

A SYN flood sends many SYN packets to exhaust server resources by leaving half-open connections.

54
MCQmedium

A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?

A.Physical
B.Data Link
C.Network
D.Transport
AnswerB

Collisions occur when devices on a shared medium transmit simultaneously; Ethernet's CSMA/CD and frame delivery operate at the Data Link layer, so excessive collisions and dropped frames are diagnosed there. Layer 1 handles raw signalling, not collision handling.

Why this answer

Excessive collisions are a Layer 2 (Data Link) phenomenon because CSMA/CD and collision detection operate at the MAC sublayer of the Data Link layer. When two stations transmit simultaneously on a shared Ethernet segment, their frames collide, and the Data Link layer handles retransmission and backoff. The Physical layer deals with the electrical/optical signalling itself, not collision semantics.

Exam trap

The trap here is that candidates may associate 'dropped frames' with the Physical layer because collisions sound like a cabling/signal problem, but the exam expects recognition that collision handling is defined at the Data Link (MAC) sublayer.

How to eliminate wrong answers

Option A is wrong because the Physical layer concerns voltage levels, cabling, connectors, and bit transmission — it does not define collision handling, which is a MAC-layer function. Option C is wrong because the Network layer handles logical addressing and routing (IP), and collisions are not a routing concern. Option D is wrong because the Transport layer handles end-to-end reliability and flow control (TCP/UDP), which is above the collision domain and unrelated to frame collisions.

55
Multi-Selectmedium

Which TWO of the following are fundamental security principles? (Select TWO.)

Select 2 answers
A.Fail-open
B.Need to share
C.Defense in depth
D.Least privilege
E.Complexity
AnswersC, D

Defense in depth is a fundamental security principle: it layers independent controls so failure of one does not expose the whole system. This satisfies the stem's requirement to select genuine fundamental principles, distinguishing it from specific technologies or implementation tactics.

Why this answer

Defense in depth (C) is a fundamental security principle because it layers multiple independent controls (network, host, application, data) so that if one control fails, others still protect the asset. Least privilege (D) is also fundamental: users, processes, and services should be granted only the minimum access rights needed to perform their function, limiting the blast radius of compromise or misuse. The other options are not fundamental security principles: fail-open (A) is an availability-oriented failure mode that weakens security by allowing access when a control fails, need to share (B) is the opposite of the need-to-know principle, and complexity (E) is a known enemy of security that increases attack surface and misconfiguration risk.

Exam trap

ISC2 often tests the distinction between security principles (like defense in depth and least privilege) and design concepts (like fail-open or complexity), so candidates mistakenly select 'fail-open' because it sounds security-related, but it actually reduces security in a failure scenario.

56
Multi-Selecthard

An organization wants to implement defense in depth for its server room. Which THREE controls should be included?

Select 3 answers
A.Cable locks on all servers
B.Group Policy to enforce password complexity
C.Visitor sign-in log at the front desk
D.CCTV monitoring inside the server room
E.Biometric access control on the server room door
AnswersA, D, E

Physical tamper protection for the servers themselves, satisfying the defense-in-depth requirement for layered physical safeguards. Cable locks deter and delay removal or theft of server hardware, complementing perimeter, door and surveillance controls rather than duplicating them.

Why this answer

A is correct because cable locks are a physical (environmental) control that deters and prevents theft or removal of server hardware, directly supporting defense in depth at the server-room layer. D is correct because CCTV monitoring provides detective and deterrent physical security, recording activity inside the server room so incidents can be identified and investigated. E is correct because biometric access control on the server room door enforces strong, identity-based physical access control (something you are), restricting entry to authorized personnel.

B does not belong because Group Policy password complexity is a logical/technical control for user authentication, not a server-room physical control. C does not belong because a visitor sign-in log at the front desk is an administrative control for the building entrance, not a control protecting the server room itself.

Exam trap

CC often tests the distinction between physical, administrative, and technical controls — candidates pick GPO or visitor logs because they sound security-relevant, but the question scopes to the server room, so only physical controls qualify.

57
MCQeasy

Which access control principle restricts access to data based on the user's job role and tasks?

A.Separation of duties
B.Need to know
C.Defense in depth
D.Least privilege
AnswerB

Need to know restricts data access to what a user's role and tasks actually require, rather than granting broad access by seniority or department. This matches the stem's requirement to limit access based on job role and duties.

Why this answer

Need to know restricts access based on the specific data a user requires to perform their job tasks, which is exactly what the question describes. It is narrower than least privilege: least privilege limits the level of access (e.g., read vs. write), while need to know limits which specific data the user can see.

Exam trap

The trap is conflating least privilege with need to know — CC frequently presents scenarios where the user has the minimum permission level but still sees data they shouldn't, which is a need-to-know violation, not least privilege.

How to eliminate wrong answers

Option A is wrong because separation of duties splits critical tasks among multiple people to prevent fraud, not to restrict data based on job role. Option C is wrong because defense in depth is a layered-security strategy, not a data-access principle. Option D is wrong because least privilege grants the minimum permissions necessary for a role, but it does not by itself restrict which specific records or data categories a user can view — that is the need-to-know principle.

58
MCQeasy

A security analyst notices that a user's account has been used to access sensitive files outside of normal working hours from an unknown IP address. Which security principle is most directly violated?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerD

Unauthorised access to sensitive files exposes data to someone without clearance, directly breaching confidentiality, which governs who may read information. The odd hours and unknown IP indicate compromise, so the violated principle is the protection of data from disclosure.

Why this answer

The scenario describes unauthorized access to sensitive files from an unknown IP address outside normal hours, which directly violates the principle of confidentiality. Confidentiality ensures that data is accessible only to authorized users and systems, and this breach indicates that sensitive information may have been exposed to an unauthorized party.

Exam trap

ISC2 often tests the distinction between confidentiality and integrity by presenting a scenario where data is accessed (not modified), leading candidates to mistakenly choose integrity because they conflate 'unauthorized access' with 'data tampering'.

How to eliminate wrong answers

Option A is wrong because availability concerns ensuring systems and data are accessible when needed, not preventing unauthorized access; the account was still functional, so availability was not violated. Option B is wrong because non-repudiation relates to proving that a specific user performed an action (e.g., via digital signatures or audit logs), not preventing unauthorized access; the issue here is unauthorized use, not repudiation of actions. Option C is wrong because integrity focuses on protecting data from unauthorized modification or corruption; the scenario does not indicate any alteration of files, only access.

59
MCQeasy

An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?

A.Enabling multi-factor authentication on all domain accounts.
B.Using a password manager to generate and store unique passwords for each account.
C.Reusing the same password across multiple systems and services.
D.Changing passwords only when prompted by the system at 90-day intervals.
AnswerC

Reusing the same password across multiple systems means that if one system is breached, the attacker can access other systems using the same credentials. This directly violates the requirement for unique passwords and significantly increases risk. It is a common and dangerous practice that undermines the security policy, making it the correct choice.

Why this answer

The policy requires unique, complex passwords. Reusing the same password across multiple systems violates the uniqueness requirement and creates a cascading risk: compromise of one account can lead to compromise of others. This practice is a well-known security weakness.

The other options either support the policy or are neutral, so password reuse is the clear answer.

Exam trap

The trap here is confusing practices that support password security, such as using a password manager or enabling MFA, with those that undermine it, like reusing passwords.

60
MCQmedium

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

A.Threat
B.Risk
C.Control
D.Vulnerability
AnswerB

Risk is the combination of a vulnerability (the known server flaw), a threat (the actor who could exploit it) and the resulting potential for loss. Neither element alone constitutes risk; their pairing with impact is what the stem describes, making risk the accurate term rather than vulnerability or threat in isolation.

Why this answer

Risk is the combination of a threat exploiting a vulnerability, potentially leading to harm. Here, a threat actor could exploit a known vulnerability to gain unauthorized access, which represents a risk.

Exam trap

CC often tests the distinction between threat, vulnerability, and risk, so candidates might choose 'vulnerability' or 'threat' instead of recognizing that the combination is risk.

How to eliminate wrong answers

Option A is wrong because a threat is a potential cause of an incident, but it does not include the vulnerability. Option C is wrong because a control is a safeguard that mitigates risk, not the combination of threat and vulnerability. Option D is wrong because a vulnerability is a weakness, but it alone does not constitute risk; risk requires a threat to exploit it.

61
Multi-Selecthard

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Select 3 answers
A.They allow logical grouping of users regardless of physical location
B.They eliminate the need for IP addressing
C.They increase the collision domain size
D.They reduce broadcast traffic by dividing broadcast domains
E.They can isolate sensitive systems from the rest of the network
AnswersA, D, E

VLANs decouple broadcast domains from physical switch ports, so membership follows configuration rather than cabling. This satisfies the stem's benefit of grouping users logically irrespective of physical location, letting a department span floors or buildings while remaining one isolated Layer 2 segment.

Why this answer

Option A is correct because VLANs are Layer 2 logical constructs that let you group users by function, department, or role rather than by their physical switch port or building location, so a user in one office can belong to the same VLAN as a colleague elsewhere. Option D is correct because each VLAN forms its own broadcast domain, so broadcasts are confined to the VLAN's member ports instead of flooding the entire switched network, thereby reducing broadcast traffic. Option E is correct because placing sensitive systems (for example, servers holding regulated data) in a dedicated VLAN lets you control inter-VLAN traffic with Layer 3 filtering, ACLs, or a firewall, isolating them from general user traffic.

Option B is not correct because VLANs operate at Layer 2 and still require Layer 3 addressing (IP subnets) for inter-VLAN routing and end-to-end communication. Option C is not correct because VLANs actually shrink collision domains (each switch port is its own collision domain) and divide broadcast domains; they do not increase the collision domain size.

Exam trap

CC often tests the misconception that VLANs eliminate IP addressing or increase collision domains, so candidates who confuse collision and broadcast domains pick the wrong options.

62
MCQeasy

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

A.Tier 1 analyst
B.IT support team
C.Tier 2 analyst
D.Tier 3 analyst
AnswerA

Tier 1 analysts handle initial alert triage, validating whether the failed logins followed by an anomalous successful login represent a genuine incident before escalation. This monitoring and classification duty sits squarely within Tier 1 responsibilities, with Tier 2 and Tier 3 engaged only after triage confirms escalation is warranted.

Why this answer

Tier 1 analysts are responsible for initial alert triage — monitoring the SIEM queue, validating alerts, gathering basic context, and escalating confirmed incidents to Tier 2. The scenario describes a standard alert requiring first-level review, which falls squarely within Tier 1 duties. Escalation to higher tiers occurs only after Tier 1 confirms the incident or determines it requires deeper investigation.

Exam trap

The trap is assuming that because the alert looks serious (unusual geography, successful login), it should go straight to Tier 2 or Tier 3 — but all alerts enter through Tier 1 triage first.

How to eliminate wrong answers

Option B is wrong because IT support handles user account issues and endpoint troubleshooting, not security alert triage in a SOC. Option C is wrong because Tier 2 performs deeper investigation and incident response after Tier 1 escalation — they do not handle initial triage. Option D is wrong because Tier 3 is reserved for advanced threat hunting, malware analysis, and complex incident response, not first-line alert review.

63
MCQeasy

A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?

A.Authentication by the smart card, authorization by the password, and identification by the permitted records.
B.Identification by the smart card, authorization by the password, and authentication by the permitted records.
C.Identification by the smart card, authentication by the password, and authorization by the permitted records.
D.Authorization by the smart card, identification by the password, and authentication by the permitted records.
AnswerC

The smart card supplies a claimed identity, which is the identification step. Typing a password verifies that claim, which is authentication. The patient records the nurse is allowed to view reflect authorization, the process of determining permitted resources after the identity has been proven. This scenario cleanly separates all three concepts and matches the standard CC access control model.

Why this answer

Identification is the act of claiming an identity, which the smart card performs by presenting a unique token. Authentication validates that claim, which the password accomplishes when it matches the stored credential. Authorization then determines which patient records the authenticated nurse may access.

Keeping these three steps distinct is fundamental to the access control concepts domain.

Exam trap

The trap here is treating the smart card as authentication when it is the token that presents the claimed identity before the password verifies it.

64
MCQmedium

Based on the exhibit, which statement about the access control list is true?

A.All IP traffic is permitted except ICMP
B.HTTP traffic is denied
C.Only HTTP traffic is permitted
D.ICMP echo requests are permitted
AnswerA

The ACL's implicit deny is overridden by a permit statement covering all IP protocols, so every packet type is forwarded; only ICMP is explicitly denied by a preceding rule. This matches the exhibit's rule order, where the ICMP deny sits above the blanket permit.

Why this answer

The exhibit shows an access control list (ACL) that explicitly denies ICMP traffic with the entry 'deny icmp any any' and then permits all other IP traffic with 'permit ip any any'. Since ACLs are processed sequentially and the 'permit ip any any' matches all IP protocols (including HTTP, HTTPS, etc.) except those already denied, the result is that all IP traffic is permitted except ICMP. This makes option A correct.

Exam trap

ISC2 often tests the sequential nature of ACLs and the fact that 'permit ip any any' permits all IP protocols except those explicitly denied earlier, leading candidates to mistakenly think ICMP is permitted or that only HTTP is allowed.

How to eliminate wrong answers

Option B is wrong because HTTP traffic (TCP port 80) is a subset of IP traffic and is explicitly permitted by the 'permit ip any any' entry; there is no deny statement for HTTP. Option C is wrong because the ACL permits all IP traffic (except ICMP), not just HTTP; HTTP is only one of many permitted protocols. Option D is wrong because ICMP echo requests are a type of ICMP traffic, and the ACL contains a 'deny icmp any any' statement that blocks all ICMP, including echo requests.

65
MCQmedium

An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:

A.Denial-of-service attacks
B.Brute-force attacks
C.Man-in-the-middle attacks
D.Phishing attacks
AnswerB

Locking an account after five failed attempts within fifteen minutes throttles repeated authentication guesses, directly disrupting automated brute-force attacks. The threshold and time window constrain the rate at which an attacker can try passwords, satisfying the stem's stated control design.

Why this answer

Account lockout after a small number of failed attempts within a short window is a classic brute-force mitigation: it throttles automated password-guessing by making repeated attempts impractical. Brute-force attacks rely on trying many passwords rapidly, so lockout thresholds and time windows directly disrupt that pattern. The control does not address DoS, MITM, or phishing, which operate through different mechanisms.

Exam trap

The trap here is confusing brute-force mitigation (lockout) with DoS prevention, when lockout can actually facilitate DoS rather than prevent it.

How to eliminate wrong answers

Option A is wrong because lockout policies can actually enable denial-of-service by letting attackers lock out legitimate users; they are not designed to prevent DoS. Option C is wrong because man-in-the-middle attacks intercept traffic between parties and are mitigated by encryption and certificate validation, not by login attempt limits. Option D is wrong because phishing tricks users into revealing credentials voluntarily; lockout does not prevent a user from handing over a valid password.

66
MCQmedium

Which of the following best describes a vulnerability in the context of risk management?

A.The likelihood that a threat will exploit a weakness
B.A measure that reduces risk
C.A weakness that can be exploited by a threat
D.A potential cause of an unwanted incident
AnswerC

A vulnerability is an inherent weakness or flaw in a system, configuration or process that a threat actor could exploit to cause harm. It is distinct from a threat (the potential actor or event) and from risk, which combines likelihood and impact.

Why this answer

In risk management frameworks such as ISO 27005 and NIST SP 800-30, a vulnerability is formally defined as a weakness in an asset, system, or control that a threat can exploit to cause harm. Option C captures this exactly: it is the weakness itself, not the probability of exploitation, not a control, and not the threat source. This distinction matters because risk is typically calculated as a function of threat, vulnerability, and impact — the vulnerability is the intrinsic flaw, while likelihood arises from the interaction between threat and vulnerability.

Exam trap

The trap here is confusing the definition of a vulnerability with that of a threat or likelihood, as many candidates conflate 'weakness' with 'probability' or 'cause' under exam pressure.

How to eliminate wrong answers

Option A is wrong because it describes likelihood (or probability) of exploitation, which is a component of risk estimation, not the vulnerability itself. Option B is wrong because a measure that reduces risk is the definition of a security control or countermeasure, not a vulnerability. Option D is wrong because a potential cause of an unwanted incident describes a threat (or threat source), which is distinct from the vulnerability it may exploit.

67
MCQmedium

A company's network uses 802.1X authentication for wired and wireless access. Which component authenticates the user credentials against an identity store?

A.Supplicant
B.Authenticator
C.Authentication server (RADIUS)
D.Access point
AnswerC

The RADIUS authentication server receives the credentials forwarded by the authenticator and validates them against the identity store, returning accept or reject. The supplicant supplies credentials and the switch or access point merely relays them, so the server performs authentication.

Why this answer

In 802.1X, the authentication server (typically a RADIUS server) is the component that validates user credentials against an identity store such as LDAP, Active Directory, or a local database. The supplicant (client) provides credentials, the authenticator (switch or access point) relays EAP frames, but only the RADIUS server performs the actual authentication decision.

Exam trap

ISC2 often tests the misconception that the authenticator (switch or AP) performs authentication, but in 802.1X the authenticator only controls port access based on the RADIUS server's decision, not the credential validation itself.

How to eliminate wrong answers

Option A is wrong because the supplicant is the client software (e.g., on a laptop) that initiates authentication by sending credentials, but it does not validate them against any identity store. Option B is wrong because the authenticator (e.g., a switch or wireless controller) acts as a middleman, forwarding EAP messages between supplicant and RADIUS server, but it does not perform credential validation. Option D is wrong because an access point can act as an authenticator in wireless 802.1X, but it still does not authenticate credentials; it only relays EAP traffic to the RADIUS server.

68
MCQeasy

Which security principle ensures that data cannot be accessed by unauthorized individuals?

A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
AnswerB

Confidentiality directly prevents unauthorised disclosure, ensuring data is readable only by approved parties. It is the principle that satisfies the stem's requirement that data cannot be accessed by unauthorised individuals, distinct from integrity, which protects accuracy, and availability, which protects timely access.

Why this answer

Confidentiality ensures that data is not disclosed to unauthorized individuals, systems, or processes.

69
MCQmedium

During a routine security audit, an analyst finds that several critical servers have misconfigured firewall rules allowing inbound SSH access from the entire internet. Which immediate action should the analyst take?

A.Disable SSH on all servers
B.Notify the server owners and wait for their response
C.Document the finding and include it in the audit report
D.Modify the firewall rules to allow SSH only from specific management IPs
AnswerD

Restricting inbound SSH to known management IPs closes the internet-wide exposure immediately, satisfying the audit's demand for prompt remediation. Unlike disabling SSH entirely or merely logging, it preserves administrative access while removing the attack surface the misconfiguration created.

Why this answer

The immediate priority is to eliminate the critical vulnerability by restricting inbound SSH access to only authorized management IPs. This aligns with the principle of least privilege and the immediate remediation steps in security incident response, as leaving the misconfiguration active even briefly exposes the servers to potential compromise.

Exam trap

ISC2 often tests the distinction between 'documenting' a finding and taking immediate remediation for a critical vulnerability, where candidates mistakenly choose documentation over action because they confuse audit procedures with incident response priorities.

How to eliminate wrong answers

Option A is wrong because disabling SSH entirely would disrupt legitimate administrative access and is an overly drastic measure that could cause operational outages; the correct approach is to restrict access rather than remove the service. Option B is wrong because waiting for server owners introduces an unacceptable delay in mitigating an active, critical vulnerability that exposes the servers to internet-wide brute-force attacks. Option C is wrong because merely documenting the finding without taking immediate corrective action violates the security analyst's duty to remediate critical risks promptly, as per standard incident response procedures.

70
MCQeasy

Which authentication type is a smart card an example of?

A.Type 1 (knowledge)
B.Type 2 (possession)
C.Type 3 (inherence)
D.Multi-factor
AnswerB

A smart card is a physical token you must possess and present, making it something you have. That possession factor satisfies the stem's Type 2 constraint, distinguishing it from knowledge (Type 1) and biometric (Type 3) authentication.

Why this answer

A smart card is a physical token that the user must possess, which maps directly to Type 2 authentication (something you have). The three classic authentication factors are Type 1 (something you know, like a password), Type 2 (something you have, like a smart card or token), and Type 3 (something you are, like a fingerprint). Because the smart card is a physical object held by the user, it is the canonical example of possession-based authentication.

Exam trap

The trap here is confusing a single authentication factor (possession) with multi-factor authentication, causing candidates to select 'Multi-factor' simply because smart cards are often used in MFA deployments.

How to eliminate wrong answers

Option A is wrong because Type 1 (knowledge) refers to something memorized such as a password or PIN, not a physical device. Option C is wrong because Type 3 (inherence) refers to a biometric trait such as a fingerprint or retina scan, which the smart card itself is not. Option D is wrong because multi-factor requires combining two or more different factor types (e.g., smart card plus PIN); a smart card alone is only a single factor, so it is not itself an example of multi-factor authentication.

71
MCQeasy

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

A.Confidential
B.Public
C.Internal
D.Restricted
AnswerD

Restricted classification applies to information whose disclosure would cause catastrophic harm, demanding the strictest controls. It sits above Confidential, Internal and Public in sensitivity, so it satisfies the stem's requirement for the highest protection level reserved for catastrophic-impact data.

Why this answer

'Restricted' is the highest data classification level in most frameworks, reserved for information whose unauthorized disclosure could cause catastrophic harm to an organization, such as trade secrets, national security data, or highly sensitive personal information. It typically mandates the strictest controls, including encryption, need-to-know access, and often regulatory compliance requirements.

Exam trap

The trap here is confusing 'Confidential' with 'Restricted'; many candidates assume Confidential is the highest level, but exam frameworks often place Restricted above it for catastrophic harm.

How to eliminate wrong answers

Option A is wrong because 'Confidential' is a high level but typically below 'Restricted'; confidential data may cause serious harm but not catastrophic harm. Option B is wrong because 'Public' data is intended for public consumption and requires minimal protection. Option C is wrong because 'Internal' data is for internal use only and requires moderate protection, far below the catastrophic-harm threshold.

72
Multi-Selecteasy

Which TWO of the following are examples of integrity controls? (Select TWO)

Select 2 answers
A.Redundancy
B.Digital signatures
C.Firewalls
D.Encryption
E.Hashing
AnswersB, E

Digital signatures verify that data has not been altered in transit and authenticate the signer, directly detecting unauthorised modification. This satisfies the stem's integrity-control criterion because any change to the signed content invalidates the signature, unlike confidentiality controls such as encryption.

Why this answer

Digital signatures (B) are an integrity control because they use asymmetric cryptography to create a verifiable value over a message, allowing the recipient to detect any modification to the data and confirm the signer's identity. Hashing (E) is also an integrity control because a cryptographic hash function such as SHA-256 produces a fixed-length digest that changes if even one bit of the input changes, enabling detection of unauthorized alteration. Redundancy (A) primarily supports availability by duplicating components or data, not by detecting modification.

Firewalls (C) are network access controls that enforce confidentiality and availability boundaries rather than data integrity. Encryption (D) is chiefly a confidentiality control, since it protects data from disclosure, although it may incidentally hinder tampering.

73
MCQmedium

An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?

A.6 months retention with 1 month immediately available
B.24 months retention with 12 months immediately available
C.18 months retention with 6 months immediately available
D.12 months retention with 3 months immediately available
AnswerD

PCI DSS mandates retaining audit trail history for at least twelve months, with the most recent three months immediately available for analysis. This satisfies both constraints in the stem: the minimum retention period and the immediate-availability requirement for authentication logs.

Why this answer

PCI DSS Requirement 10.7 mandates retaining audit logs for at least 12 months, with a minimum of the most recent 3 months immediately available for analysis. This ensures organizations can investigate recent incidents quickly while still preserving a full year of history for forensic and compliance review.

Exam trap

The trap is that candidates may recall a different retention figure (e.g., HIPAA's 6 years or SOX's 7 years) or confuse the retention period with the immediately-available window, leading them to pick an option that swaps or inflates the numbers.

How to eliminate wrong answers

Option A is wrong because 6 months retention with 1 month available falls short of the 12-month/3-month PCI DSS requirement. Option B is wrong because 24 months with 12 months available exceeds the PCI DSS minimum — while longer retention is permitted, it is not the specified requirement, making it an incorrect answer to 'what is the minimum.' Option C is wrong because 18 months with 6 months available also exceeds the PCI DSS baseline and misstates the required figures.

74
MCQmedium

A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?

A.Analyze DNS query patterns
B.Detect port scans from external IPs
C.Examine HTTP request parameters for SQL commands
D.Monitor bandwidth usage for spikes
AnswerC

SQL injection payloads travel inside HTTP request parameters, so inspecting those parameters for SQL keywords and syntax detects the attack at the application layer. Signature matching on packet headers or ports alone would miss the injected commands, making parameter inspection the effective method.

Why this answer

To detect SQL injection attacks, an IDS should examine HTTP request parameters for SQL commands. SQL injection typically involves injecting malicious SQL code into input fields, which then appears in HTTP requests. By analyzing these parameters for patterns like ' OR '1'='1' or UNION SELECT, the IDS can identify and alert on potential attacks.

Exam trap

The trap is confusing SQL injection detection with other network security monitoring like port scan detection or DNS analysis, which are not directly related to SQL injection.

How to eliminate wrong answers

Option A is wrong because DNS query patterns are unrelated to SQL injection; DNS is used for domain resolution, not for carrying SQL payloads. Option B is wrong because port scans indicate network reconnaissance, not SQL injection. Option D is wrong because bandwidth spikes may indicate DoS attacks or large transfers, but not specifically SQL injection.

75
MCQmedium

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

A.Biometric authentication
B.Two-step verification using same factor
C.Multi-factor authentication
D.Single-factor authentication
AnswerC

Multi-factor authentication requires two or more distinct credential categories: something you know (the password) plus something you possess (the one-time passcode generated by the mobile authenticator app). Because the factors span separate categories rather than repeating one, the login satisfies the stem's definition of MFA.

Why this answer

Using a password (something you know) and a one-time passcode from a mobile authenticator app (something you have) combines two different authentication factors: knowledge and possession. This is the definition of multi-factor authentication (MFA).

Exam trap

CC often tests the difference between multi-factor authentication and two-step verification, where two-step verification might use the same factor twice, so candidates might incorrectly choose 'two-step verification using same factor'.

How to eliminate wrong answers

Option A is wrong because biometric authentication involves something you are (e.g., fingerprint), which is not used here. Option B is wrong because two-step verification using the same factor would mean both steps use the same factor type (e.g., two passwords), but here the factors are different. Option D is wrong because single-factor authentication uses only one factor, but here two factors are used.

Page 1 of 14

Page 2