Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 676–750

989 questions total · 14pages · All types, answers revealed

Page 9

Page 10 of 14

Page 11
676
MCQhard

A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?

A.Implement multi-factor authentication on the existing VPN and enforce stricter password policies.
B.Adopt a Zero Trust Architecture (ZTA) that uses an identity-aware proxy and micro-segmentation.
C.Create separate VLANs for each department and restrict inter-VLAN routing with ACLs.
D.Apply the principle of least privilege by reducing user permissions on the network and servers.
AnswerB

An identity-aware proxy evaluates each request against Microsoft Entra ID identity and device posture before granting access, so a stolen VPN credential alone no longer opens the network. Micro-segmentation then enforces per-application reachability, satisfying the requirement that remote workers reach only role-specific apps and that segmentation holds regardless of location.

Why this answer

A Zero Trust Architecture (ZTA) with an identity-aware proxy and micro-segmentation directly addresses all three requirements: it grants access based on identity and device posture, limits remote workers to specific applications, and enforces segmentation regardless of location. ZTA assumes no implicit trust based on network location, which prevents a compromised VPN account from accessing the entire internal network. This is the most comprehensive and aligned solution.

Exam trap

CC often tests the misconception that MFA or network segmentation alone achieves Zero Trust, but the exam expects recognition that ZTA requires identity-based, context-aware access control with micro-segmentation.

How to eliminate wrong answers

Option A is wrong because MFA and stricter password policies improve authentication but do not limit lateral movement or enforce per-application access; a compromised account would still have full network access. Option C is wrong because VLANs and ACLs provide network segmentation but are location-dependent and do not consider identity or device posture, and they are complex to manage for 50 remote workers. Option D is wrong because least privilege reduces permissions but does not enforce device posture or application-specific access, and it is a principle rather than a technical control that fully meets the requirements.

677
MCQmedium

A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?

A.Need-to-know
B.Least privilege
C.Defense in depth
D.Separation of duties
AnswerA

Accessing another department's files breaches need-to-know, which restricts data to individuals whose specific duties require it. Least privilege governs permission scope, not data relevance, so it does not fit this scenario. Need-to-know satisfies the stem's constraint: a user reaching files outside their own department.

Why this answer

The need-to-know principle restricts access to information only to individuals who require it to perform their specific job duties. A user accessing files in a department they do not work in violates this principle because they have no legitimate need for that information.

Exam trap

The trap here is confusing need-to-know with least privilege; candidates often pick least privilege because both involve limiting access, but need-to-know is about information relevance to job duties, not system permissions.

How to eliminate wrong answers

Option B is wrong because least privilege focuses on granting the minimum system permissions necessary for a role, not on restricting access based on job function or information relevance. Option C is wrong because defense in depth is a layered security strategy, not a specific access control principle about individual access rights. Option D is wrong because separation of duties prevents one person from controlling all aspects of a critical process, which is unrelated to accessing another department's files.

678
MCQeasy

Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?

A.TCP
B.HTTP
C.IP
D.UDP
AnswerD

UDP operates at the Transport layer and is connectionless, sending datagrams without handshaking, acknowledgement, or retransmission, so delivery is unreliable. TCP, the alternative Transport protocol, establishes connections and guarantees ordered, reliable delivery, which contradicts both stated constraints.

Why this answer

UDP (User Datagram Protocol) is a Transport layer (Layer 4) protocol that is connectionless and unreliable. It does not establish a connection before sending data, and it does not guarantee delivery, ordering, or error recovery. This makes it suitable for applications that prioritize speed over reliability, such as streaming or DNS.

Exam trap

The trap here is confusing the OSI layers: candidates might think IP is Transport layer because it's connectionless, or assume TCP is unreliable because it's often compared to UDP. Remember: UDP is the connectionless, unreliable Transport layer protocol.

How to eliminate wrong answers

Option A is wrong because TCP is connection-oriented and reliable, using handshakes and acknowledgments to ensure data delivery. Option B is wrong because HTTP is an Application layer protocol, not a Transport layer protocol, and it typically relies on TCP for reliable transport. Option C is wrong because IP operates at the Network layer (Layer 3) and is connectionless but not a Transport layer protocol; it handles addressing and routing, not end-to-end transport.

679
MCQmedium

A SOC analyst detects a series of failed login attempts from a single external IP address targeting multiple user accounts within a short time. Which action should the analyst take FIRST?

A.Block the IP address at the firewall immediately.
B.Verify if any accounts were successfully compromised.
C.Disable all user accounts that were targeted.
D.Notify law enforcement about the attempted breach.
AnswerB

Verifying whether any accounts were successfully compromised establishes impact before containment, distinguishing a failed brute-force attempt from an actual breach. This determines escalation and remediation scope, so it precedes blocking the source IP or resetting credentials.

Why this answer

The correct first step is to verify if any accounts were successfully compromised (Option B). In security operations, the priority is to assess the impact of an incident before taking containment actions. If an account was breached, immediate password resets and session invalidation are needed; blocking the IP prematurely could destroy forensic evidence and alert the attacker, while disabling all accounts causes unnecessary business disruption.

The analyst must confirm compromise via log review (e.g., checking for successful authentication events after the failed attempts) to guide the appropriate response.

Exam trap

ISC2 often tests the principle that containment (e.g., blocking an IP) should not be performed before verifying impact, because the first priority in incident response is to confirm whether a breach actually occurred, not to assume the worst and disrupt operations.

How to eliminate wrong answers

Option A is wrong because immediately blocking the IP at the firewall may destroy forensic evidence (e.g., attacker's subsequent actions) and could be a false positive if the IP is legitimate (e.g., a misconfigured VPN). Option C is wrong because disabling all targeted user accounts without evidence of compromise causes unnecessary operational disruption and may lock out legitimate users; the analyst should first verify if any account was actually breached. Option D is wrong because notifying law enforcement is premature and not the first action; internal incident response procedures (verification, containment, eradication) must be followed first, and law enforcement is typically contacted only after confirming a breach and consulting legal counsel.

680
MCQeasy

A small business owner wants to ensure that their company's data remains accurate and unaltered during transmission over the internet. They regularly send financial reports to their accountant via email. The owner is concerned that a hacker might intercept and modify the reports before they reach the accountant. Which security principle is most directly threatened in this scenario, and what is the best technical control to implement?

A.Confidentiality; encrypt the email attachments
B.Non-repudiation; require read receipts
C.Integrity; apply a digital signature or hash to the files
D.Availability; use a redundant email server
AnswerC

A digital signature or hash verifies the file has not been altered in transit, directly protecting integrity against interception and modification. Confidentiality would address eavesdropping, but the stem's concern is tampering with the financial reports.

Why this answer

Integrity ensures data has not been altered or tampered with during transmission or storage. A digital signature (which uses the sender's private key to sign a hash of the file) or a cryptographic hash allows the recipient to verify that the file arrived exactly as sent. If a hacker modifies the report in transit, the hash/signature verification will fail, exposing the tampering.

Exam trap

The trap here is conflating confidentiality with integrity — candidates see 'hacker intercepts' and jump to encryption, but the question explicitly says the concern is modification, not disclosure.

How to eliminate wrong answers

Option A is wrong because encryption protects confidentiality (keeping data secret from eavesdroppers), not integrity — an attacker could still modify ciphertext or, if they have the key, alter plaintext without detection. Option B is wrong because non-repudiation proves the sender cannot deny sending a message; read receipts only confirm delivery, not authenticity or integrity. Option D is wrong because availability concerns uptime and access to systems, which is unrelated to preventing modification of data in transit.

681
MCQeasy

Refer to the exhibit. ``` C:\> netstat -an | find "LISTENING" TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?

A.HTTP (port 80)
B.Remote Desktop (port 3389)
C.All of the above
D.HTTPS (port 443)
AnswerB

Port 3389 is bound to Remote Desktop Protocol, which permits interactive remote logon and is a frequent target for brute-force and ransomware entry. Disabling it where remote administration is not required removes that exposure, whereas ports 80 and 443 serve expected web traffic.

Why this answer

Remote Desktop Protocol (RDP) on port 3389 is a high-risk service that should typically be disabled on servers unless absolutely necessary, as it provides a direct graphical interface for remote administration and is a common target for brute-force attacks. The output shows RDP listening on a specific internal IP (192.168.1.10), indicating it is bound to a routable interface, which increases exposure. In contrast, HTTP (port 80) and HTTPS (port 443) are standard web services that are often required for a server's function, so they are not typically disabled for attack surface reduction.

Exam trap

ISC2 often tests the misconception that all listening ports are equally risky, but the trap here is that HTTP and HTTPS are expected services on a server, while RDP is a high-risk administrative service that should be disabled unless explicitly required.

How to eliminate wrong answers

Option A is wrong because HTTP (port 80) is a standard web service that is often necessary for serving web content; disabling it would break normal server functionality, and it is not typically disabled solely to reduce attack surface unless the server has no web role. Option C is wrong because not all services listed should be disabled; only Remote Desktop (port 3389) is the one that should typically be disabled, while HTTP and HTTPS are commonly required. Option D is wrong because HTTPS (port 443) is the secure version of HTTP and is essential for encrypted web traffic; it is not a service that should be routinely disabled, as it protects data in transit.

682
MCQmedium

A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?

A.Smurf attack
B.SYN flood
C.ARP spoofing
D.DNS amplification
AnswerB

Half-open connections arise when a host receives SYN packets but never completes the three-way handshake, exhausting the backlog queue. A SYN flood deliberately sends spoofed SYNs at volume, matching the observed pattern and denying legitimate clients access to the web server.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending numerous SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that never complete. The server's connection table fills up, exhausting resources and preventing legitimate connections. This matches the symptom of many half-open TCP connections observed by the analyst.

Exam trap

The trap here is confusing volumetric network attacks (Smurf, DNS amplification) with TCP state exhaustion attacks; candidates may pick Smurf because it also causes many connections, but Smurf uses ICMP, not TCP.

How to eliminate wrong answers

Option A is wrong because a Smurf attack is an ICMP-based amplification attack using broadcast addresses to flood a victim with echo replies, not TCP half-open connections. Option C is wrong because ARP spoofing is a layer 2 attack that poisons ARP caches to intercept traffic, not a flood of TCP connections. Option D is wrong because DNS amplification uses open DNS resolvers and spoofed queries to amplify traffic via large DNS responses, unrelated to TCP handshake states.

683
MCQhard

A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?

A.Rule-based access control, by evaluating time-of-day and managed-device conditions
B.Discretionary access control, by letting the repository owner approve each contractor
C.Role-based access control, by creating a Contractor role with read access
D.Mandatory access control, by labeling the repository as confidential and requiring clearance
AnswerA

Rule-based access control decides access by evaluating conditions at request time. A rule can require that the current time fall within contracted hours and that the connecting device be enrolled and compliant in the management system. Both constraints in the scenario are conditions, making rule-based access control the appropriate model to enforce them dynamically.

Why this answer

The requirements are conditions evaluated when access is requested: the clock must be inside contracted hours, and the device must be company-managed. Rule-based access control inspects exactly such attributes at decision time, enforcing both constraints together. Role, discretionary, and mandatory models govern who may access what, but none of them natively evaluate time-of-day or device posture.

Exam trap

The trap here is choosing a role-based model because contractors form a group, missing that the scenario's constraints are contextual conditions rather than job-function permissions.

684
MCQmedium

A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Rule-based access control
AnswerB

RBAC grants permissions to roles rather than individuals, and users receive access through role assignment. When the employee moves from accounting to marketing, the role changes and permissions follow automatically. This matches the scenario precisely, where HR role data drives access updates without per-user permission edits.

Why this answer

Role-based access control centralizes permissions in roles and assigns users to those roles. When an employee's job function changes, updating the role assignment automatically adjusts access, which reduces administrative overhead and errors. The scenario's automatic permission change driven by HR role data is the defining characteristic of RBAC in enterprise environments.

Exam trap

The trap here is confusing role-based access control with rule-based access control because both use the word rules or roles in casual descriptions.

685
MCQeasy

A small accounting firm wants to let guests connect to the internet in its lobby without exposing the internal file server or the payroll system. The network administrator is told to add a separate wireless network that uses different IP addressing and cannot route to internal resources. Which security principle is the administrator primarily applying?

A.Data remanence
B.Network segmentation
C.Non-repudiation
D.Least privilege
AnswerB

Segmenting the guest wireless onto separate IP addressing and blocking routes to internal systems isolates untrusted traffic from sensitive resources. This is a core network security control that limits the blast radius if a guest device is compromised. It directly implements the requirement that guests reach only the internet, not the file server or payroll system.

Why this answer

Separating guest wireless onto distinct IP addressing and preventing routes to internal systems is a segmentation control. Segmentation confines untrusted devices to a limited network zone, so a compromised guest endpoint cannot directly reach the payroll system or file server. The other concepts address data remnants, proof of actions, or user permissions, none of which create the required network boundary.

Exam trap

The trap here is confusing an access-control principle like least privilege with the network design control that actually isolates guest traffic from internal subnets.

686
MCQhard

A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?

A.No action needed; the rule is satisfied
B.Store the tape copy in a secure offsite location
C.Use cloud storage as an additional copy
D.Add a third copy to the external hard drive
AnswerB

Storing the tape copy offsite satisfies the 3-2-1 rule's requirement for one copy at a separate geographic location, protecting against site-wide disasters such as fire or flood. The external hard drive and on-site tape already provide three copies across two media types, so only geographic separation remains outstanding.

Why this answer

The 3-2-1 rule requires three copies of data (including the original), stored on at least two different media types, with at least one copy stored offsite. Currently, the company has the original data plus two backups (external HDD and tape) — three copies total — but both backups are on-site. To fully comply, one of the backup copies must be moved to an offsite location.

Option B, storing the tape copy offsite, satisfies the '1 offsite' requirement.

687
MCQeasy

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

A.Availability
B.Authentication
C.Integrity
D.Confidentiality
AnswerC

Hashing produces a fixed-length digest from the transmitted data; any modification changes the digest, so the recipient can verify the data arrived unaltered. This directly satisfies the requirement to detect alteration during transmission, which is the integrity principle.

Why this answer

Hashing produces a fixed-length digest that acts as a fingerprint of the data. If even a single bit changes during transmission, the resulting hash will differ, allowing the receiver to detect any alteration. This directly enforces the security principle of integrity, which ensures data is not modified in an unauthorized or accidental manner.

Exam trap

The trap here is confusing integrity with authentication or confidentiality; candidates often think hashing provides authentication because it verifies data, but it only ensures the data hasn't changed, not who sent it.

How to eliminate wrong answers

Option A is wrong because availability ensures timely and reliable access to resources, typically addressed by redundancy, backups, and DDoS protection—not by hashing. Option B is wrong because authentication verifies the identity of a user or system, often using passwords, certificates, or biometrics, whereas hashing alone does not prove who sent the data. Option D is wrong because confidentiality protects data from unauthorized disclosure, usually through encryption (e.g., AES, TLS), not hashing, which does not hide the original data.

688
MCQhard

A security manager is reviewing the organization's approach to risk. The manager decides to purchase cyber insurance to transfer some of the financial risk associated with a data breach. Which risk management strategy is being used?

A.Risk acceptance
B.Risk avoidance
C.Risk transference
D.Risk mitigation
AnswerC

Risk transference shifts the financial impact of a risk to a third party, such as an insurance company. By purchasing cyber insurance, the organization transfers some of the financial risk of a data breach to the insurer. This is a classic example of risk transference.

Why this answer

Risk transference involves shifting the financial impact of a risk to another party, often through insurance or contracts. Cyber insurance is a common method of transferring the financial consequences of a data breach. The organization still owns the risk of the breach occurring, but the financial loss is partially borne by the insurer.

This strategy is distinct from avoidance, mitigation, and acceptance.

Exam trap

The trap here is confusing risk transference with mitigation because insurance is a control, but it does not reduce the likelihood or impact of the breach itself, only the financial aftermath.

689
Multi-Selectmedium

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

Select 2 answers
A.ARP poisoning
B.SYN flood
C.DNS amplification
D.Setting up a rogue Wi-Fi access point
E.ICMP flood
AnswersA, D

ARP poisoning sends forged ARP replies that bind the attacker's MAC address to a legitimate IP, so traffic between victim and gateway flows through the attacker. This enables interception and modification on the local subnet, a classic MITM technique.

Why this answer

ARP poisoning (A) is a classic MITM technique: the attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway (or another host), causing victim traffic to flow through the attacker, who can then intercept or modify it. Setting up a rogue Wi-Fi access point (D) is also a common MITM method, often called an evil twin attack, where victims connect to the attacker-controlled AP and all their traffic is relayed or captured by the attacker. The other options are denial-of-service or amplification attacks rather than interception techniques: a SYN flood (B) exhausts TCP connection state to deny service, DNS amplification (C) abuses open DNS resolvers to flood a target with large responses, and an ICMP flood (E) overwhelms a target with ping traffic — none of these position the attacker to intercept and relay traffic between two parties.

Exam trap

The trap here is confusing DoS attacks (SYN flood, DNS amplification, ICMP flood) with MITM attacks; candidates may select any flooding technique thinking it involves interception, but only ARP poisoning and rogue APs directly enable man-in-the-middle positioning.

690
MCQhard

An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?

A.DNS poisoning
B.MAC flooding
C.ARP spoofing
D.IP spoofing
AnswerC

ARP spoofing works by sending forged ARP replies that bind the attacker's MAC address to a legitimate server's IP, poisoning victims' ARP caches so traffic is redirected through the attacker for interception. This directly satisfies the stem's constraint of impersonating the server's IP-to-MAC mapping.

Why this answer

ARP spoofing (or ARP poisoning) involves sending fake ARP replies to associate the attacker's MAC with a victim's IP, enabling man-in-the-middle attacks.

691
Multi-Selectmedium

A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)

Select 2 answers
A.Subnetting
B.Firewalls
C.VLANs
D.IDS
E.Honeypots
AnswersA, C

Subnetting divides a larger IP network into smaller logical subnets using the subnet mask, separating traffic at Layer 3. Each subnet forms its own broadcast domain, giving the administrator a valid method to segment the network.

Why this answer

Subnetting (A) is a valid segmentation method because it divides a single IP address space into smaller logical networks using subnet masks, creating separate broadcast domains and controlling traffic flow between subnets via routing. VLANs (C) are also valid segmentation methods because they logically partition a physical switch into multiple isolated Layer 2 broadcast domains, typically defined by 802.1Q tagging, allowing separation of devices regardless of physical location. Firewalls (B) enforce security policy between zones but are access-control devices rather than a segmentation technique themselves.

IDS (D) monitors and alerts on malicious traffic but does not segment the network, and honeypots (E) are decoy systems used for detection and research, not segmentation.

Exam trap

The trap here is confusing security tools (firewalls, IDS, honeypots) with actual segmentation mechanisms; candidates often pick firewalls because they are associated with network separation, but firewalls enforce policy between segments rather than create them.

692
MCQeasy

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

A.Authentication
B.Confidentiality
C.Integrity
D.Availability
AnswerB

Confidentiality directly prevents unauthorised disclosure by restricting data access to approved parties only. It is the CIA principle concerned with secrecy, unlike integrity (unauthorised modification) or availability (timely access). This satisfies the stem's requirement that data is not disclosed to unauthorised individuals.

Why this answer

Confidentiality is the CIA triad principle that ensures information is not disclosed to unauthorized individuals, systems, or processes. It is enforced through encryption, access controls, and data classification. Authentication verifies identity but does not itself guarantee confidentiality, and integrity and availability address different properties.

Exam trap

The trap is confusing authentication with confidentiality — candidates often pick authentication because it 'sounds like security,' but authentication is an identity-verification function, not the data-secrecy principle.

How to eliminate wrong answers

Option A is wrong because authentication is the process of verifying a claimed identity (e.g., via passwords, MFA) — it is a prerequisite for access control but not the confidentiality principle itself. Option C is wrong because integrity ensures data is accurate and unaltered, not that it is kept secret. Option D is wrong because availability ensures data and systems are accessible when needed, which is unrelated to preventing disclosure.

693
MCQmedium

An organization implements a defense-in-depth strategy by deploying firewalls, intrusion detection systems, and endpoint protection. Which security principle does this approach primarily demonstrate?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Zero trust
AnswerC

Defense in depth is a layered security approach where multiple controls are used to protect assets. By deploying firewalls, intrusion detection systems, and endpoint protection, the organization creates overlapping defenses that reduce the likelihood of a single point of failure. This directly exemplifies the defense-in-depth principle, which is a core security strategy.

Why this answer

The correct answer is defense in depth. This principle involves implementing multiple layers of security controls so that if one fails, others still provide protection. Firewalls, intrusion detection systems, and endpoint protection are classic examples of layered defenses.

Least privilege, separation of duties, and zero trust are related but distinct concepts that do not directly describe the scenario.

Exam trap

The trap here is confusing defense in depth with zero trust, assuming any multiple-control deployment is zero trust, when zero trust specifically requires continuous verification and no implicit trust.

694
MCQhard

A hospital's compliance officer is mapping controls for a new patient portal. The legal team wants documented assurance that a clinician cannot later deny having approved a medication order submitted through the portal. Which security principle is the legal team most directly requesting?

A.Integrity
B.Availability
C.Non-repudiation
D.Confidentiality
AnswerC

Non-repudiation provides irrefutable evidence that a specific identity performed a specific action, so the clinician cannot credibly deny approving the order. Digital signatures and tamper-evident audit logs bound to the clinician's authenticated identity deliver this proof. The legal team wants documented assurance of authorship and approval, which is precisely what non-repudiation supplies in a dispute.

Why this answer

The legal team needs proof of who performed an action so it cannot be denied later. That is non-repudiation, usually achieved with digital signatures, strong authentication, and tamper-evident audit logging tied to individual identities. Integrity protects against unauthorized changes, confidentiality protects against disclosure, and availability protects against loss of access; none of these establishes undeniable authorship of the medication order.

Exam trap

The trap here is choosing integrity because the order record must remain unchanged, when the actual requirement is proving which clinician performed the action.

695
MCQhard

A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?

A.Reciprocal agreement
B.Warm site
C.Cold site
D.Hot site
AnswerD

A hot site provides a fully mirrored, continuously replicated environment, enabling activation well within the two-hour RTO while keeping data loss inside the fifteen-minute RPO. Warm and cold sites cannot meet such aggressive recovery targets.

Why this answer

A hot site is a fully operational duplicate of the primary data center with real-time or near-real-time data replication, allowing recovery within minutes. It is the only strategy that can meet an RTO of 2 hours and an RPO of 15 minutes for a trading platform. Hot sites are expensive but necessary for near-instantaneous recovery.

Exam trap

The trap is assuming a warm site is 'good enough' because it has some equipment; candidates must map the stated RTO/RPO to the site type that can actually meet those numbers.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement relies on another organization's facilities and is not guaranteed available, typically yielding recovery in days, far exceeding a 2-hour RTO. Option B is wrong because a warm site has hardware and some data but requires configuration and restoration, usually taking hours to days, which cannot meet a 15-minute RPO. Option C is wrong because a cold site is an empty facility with power and cooling but no equipment, requiring days or weeks to restore, the slowest option.

696
Multi-Selectmedium

A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)

Select 2 answers
A.Require a complex password on the local administrator account of each POS system.
B.Deploy a host-based firewall on each POS system with rules that allow only the payment application and management agent.
C.Enable full-disk encryption on the POS system drives to protect data at rest.
D.Install an antivirus agent on each POS system and schedule a full scan every night.
E.Place POS systems on a dedicated VLAN with an ACL that allows only traffic to the payment processor and a management server.
AnswersB, E

A host-based firewall on the POS system enforces least privilege at the endpoint by permitting only required outbound and inbound flows for the payment application and management agent. Even if the terminal is compromised, other network paths are blocked. This directly limits what the system can reach, complementing network segmentation.

Why this answer

A dedicated POS VLAN with a restrictive ACL and a host-based firewall on each terminal both enforce least privilege on network reachability. The VLAN and ACL stop lateral movement at the network layer, while the host firewall restricts the endpoint's own traffic to only necessary services. Antivirus, password complexity, and full-disk encryption improve other areas but do not limit what a compromised POS system can reach.

Exam trap

The trap here is equating endpoint hardening or data-at-rest protection with network reach limitation, when only segmentation and host-based filtering actually restrict where a compromised system can connect.

697
MCQmedium

A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?

A.Deploy file integrity monitoring on the repositories
B.Enforce a password complexity policy for all accounts
C.Require multi-factor authentication for repository access
D.Revoke the contractor's access rights during offboarding
AnswerD

Revoking access rights is the administrative control that directly removes the contractor's ability to authenticate and reach internal repositories once the engagement ends. Timely offboarding, including disabling accounts and removing group memberships, closes the window in which former credentials remain usable. This matches the scenario because the goal is to prevent a dismissed contractor from using issued credentials, which only revocation accomplishes.

Why this answer

The scenario's core problem is that a former contractor retains valid credentials after the contract ends. Administrative controls govern people and processes, and timely revocation of access rights during offboarding removes the account's authority entirely. Monitoring detects but does not prevent, password complexity does not invalidate a known password, and MFA still lets the former contractor log in, so revocation is the correct control.

Exam trap

The trap here is treating a technical authentication hardening measure as a substitute for terminating a former worker's authorization.

698
MCQeasy

Based on the incident log, at which step did the incident response team contain the threat?

A.14:30 - Scanned system, detected Trojan.Downloader
B.14:45 - Removed malware via AV
C.14:25 - Isolated WKS-045 from network
D.14:35 - Escalated to incident handler
AnswerC

Isolating WKS-045 at 14:25 satisfies the containment requirement by severing the compromised endpoint's network connectivity, preventing lateral movement and further command-and-control communication. Containment means limiting spread, not eradication or recovery, so this action directly matches the incident response phase the question asks about.

Why this answer

Containment is the immediate step to prevent the threat from spreading, and isolating WKS-045 from the network at 14:25 achieves this by cutting off its network connectivity. This aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized before eradication or recovery. The log shows isolation occurred before scanning or removal, making it the correct containment action.

Exam trap

ISC2 often tests the distinction between containment and eradication, where candidates mistakenly choose removal (Option B) as containment, but containment must stop the spread before any cleanup occurs.

How to eliminate wrong answers

Option A is wrong because scanning the system and detecting Trojan.Downloader at 14:30 is a detection and analysis step, not containment; containment must happen before or concurrently with analysis to stop lateral movement. Option B is wrong because removing malware via AV at 14:45 is an eradication step, which occurs after containment to eliminate the threat from the isolated system. Option D is wrong because escalating to the incident handler at 14:35 is a communication and coordination step, not a technical containment action; it does not directly stop the threat from spreading.

699
MCQmedium

A company's security policy requires that all employees use strong passwords and change them every 90 days. An employee writes their password on a sticky note and attaches it to their monitor. Another employee sees it and uses it to log into the first employee's account to send a fake email. The security team is conducting a post-incident review. Which security principle failed, and what is the most effective long-term solution to prevent this type of incident?

A.Integrity; conduct annual security awareness training
B.Accountability; implement multi-factor authentication
C.Availability; prohibit sticky notes in the office
D.Confidentiality; enforce 15-character passwords
AnswerB

MFA ensures that a password alone is not sufficient for access.

Why this answer

The failure is a breach of accountability because the employee who shared the password and the one who used it without authorization violated the principle that actions should be traceable to individuals. The most effective long-term solution is to implement multi-factor authentication (B), which reduces the risk of password sharing and theft. Option A is wrong because annual security awareness training, while helpful, is often insufficient to change behavior long-term; Option C is wrong because prohibiting sticky notes is difficult to enforce and does not address the root cause; Option D is wrong because longer passwords do not prevent users from writing them down or sharing them.

700
Multi-Selectmedium

Which TWO of the following are examples of administrative security controls? (Choose two.)

Select 2 answers
A.Intrusion detection system
B.Security awareness training
C.Firewall
D.Encryption
E.Background checks for employees
AnswersB, E

Training is an administrative control that educates users on security policies.

701
MCQhard

An organization is implementing a new system that processes financial transactions. To reduce the risk of fraud, they ensure that no single individual can both initiate and approve a transaction. Which security principle is this?

A.Need to know
B.Separation of duties
C.Accountability
D.Least privilege
AnswerB

Separation of duties splits a critical transaction across distinct roles, so initiation and approval require different identities. This directly satisfies the stem's constraint that no single individual performs both actions, preventing unilateral fraud. Unlike least privilege, which limits access scope, separation of duties enforces workflow-level checks within Microsoft Entra ID governance.

Why this answer

Separation of duties (SoD) is the security principle that prevents a single individual from having conflicting responsibilities, such as both initiating and approving a financial transaction. By splitting these tasks across different roles, the organization reduces the risk of fraud or error because collusion would be required to bypass controls. This is a core internal control mechanism in financial systems and aligns with the principle of dual control.

Exam trap

ISC2 often tests the distinction between 'separation of duties' and 'least privilege' by presenting a scenario where a user has too many permissions, tempting candidates to choose least privilege, but the core issue is the conflict of having both initiation and approval authority, not the amount of access.

How to eliminate wrong answers

Option A is wrong because 'need to know' restricts access to information based on job requirements, not the division of conflicting tasks. Option C is wrong because 'accountability' ensures actions can be traced to an individual, but does not inherently prevent a single person from performing both initiation and approval. Option D is wrong because 'least privilege' limits permissions to the minimum necessary for a role, but does not address the conflict of having both initiation and approval capabilities within the same role.

702
MCQeasy

A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?

A.Integrity
B.Authentication
C.Confidentiality
D.Availability
AnswerC

Encryption renders data unreadable to anyone lacking the decryption key, whether stored on disk or moving across the network. This directly satisfies the confidentiality aspect of the CIA triad, which concerns preventing unauthorised disclosure. Integrity concerns alteration, and availability concerns access, so neither fits the scenario's protection of data at rest and in transit.

Why this answer

Encryption protects data confidentiality by ensuring that only authorized parties can read the data. Whether at rest (stored on disk) or in transit (moving across networks), encryption renders data unreadable to unauthorized users, directly addressing the confidentiality aspect of the CIA triad. Integrity, authentication, and availability are separate concerns not primarily addressed by encryption alone.

Exam trap

CC often tests the confusion between confidentiality and integrity — candidates may think encryption also ensures data integrity, but encryption primarily provides confidentiality; integrity requires additional mechanisms like hashing.

How to eliminate wrong answers

Option A is wrong because integrity ensures data has not been altered, which encryption alone does not guarantee — hashing or digital signatures are needed for integrity. Option B is wrong because authentication verifies identity, which encryption does not provide; authentication mechanisms like passwords or certificates are separate. Option D is wrong because availability ensures data is accessible when needed, and encryption does not directly impact availability (though losing keys can affect it, that is not the primary purpose).

703
Multi-Selectmedium

Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?

Select 2 answers
A.Requiring multi-factor authentication for all remote access
B.Implementing a SIEM with centralized logging from critical systems
C.Conducting annual security awareness training for all employees
D.Deploying endpoint detection and response (EDR) agents on all workstations
E.Standardizing firewall rules across all network segments
AnswersB, D

SIEM correlates events and alerts analysts, reducing detection time.

Why this answer

A SIEM with centralized logging aggregates and correlates logs from critical systems, enabling real-time analysis and automated alerting. This drastically reduces MTTD by surfacing indicators of compromise (IoCs) within minutes rather than hours or days, as manual log review would require.

Exam trap

The trap here is that candidates confuse preventive controls (MFA, training, firewall rules) with detective controls, failing to recognize that only logging and monitoring tools directly reduce the time to detect an incident.

704
MCQhard

A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?

A.Both RTO and RPO are exceeded
B.RPO is exceeded but RTO is met
C.Both RTO and RPO are met
D.RTO is exceeded but RPO is likely met
AnswerD

Total recovery of five hours exceeds the four-hour RTO, so that target is breached. Hourly incremental backups with transaction-log rollforward cap data loss near one hour, so the one-hour RPO is likely satisfied despite the overrun.

Why this answer

The RTO is 4 hours, but the total time to make the database fully operational is 5 hours, so RTO is exceeded. The RPO is 1 hour, and backups are taken every hour; the data loss is at most 1 hour of transactions, so RPO is likely met. Therefore, RTO is exceeded but RPO is likely met.

Exam trap

CC often tests the distinction between RTO and RPO, and candidates may incorrectly assume that restoration time alone defines RTO, ignoring additional steps like transaction log roll-forward.

How to eliminate wrong answers

Option A is wrong because RPO is not exceeded; the hourly backups meet the 1-hour RPO. Option B is wrong because RTO is exceeded, not met. Option C is wrong because RTO is exceeded, so both cannot be met.

705
MCQmedium

A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties splits a critical transaction across multiple people so no single employee controls it end to end. Requiring one person to raise a payment and another to approve it directly satisfies the stem's constraint: preventing one employee from both approving and disbursing funds.

Why this answer

Separation of duties is the principle that no single individual should have control over all aspects of a critical process. By preventing one employee from both approving and disbursing payments, the company ensures that multiple people are involved, reducing the risk of fraud or error.

Exam trap

The trap is confusing separation of duties with least privilege; candidates may pick least privilege because both involve limiting access, but separation of duties specifically addresses dividing tasks among multiple people to prevent fraud.

How to eliminate wrong answers

Option A is wrong because need-to-know is about restricting access to information based on job requirements, not dividing tasks. Option B is wrong because defense in depth is a layered security strategy, not a specific task-division principle. Option C is wrong because least privilege limits permissions to the minimum necessary, but does not address the separation of approval and disbursement tasks.

706
Multi-Selecthard

Which TWO of the following are examples of detective security controls? (Choose two.)

Select 2 answers
A.Data backup and restoration procedures.
B.Security logging and monitoring.
C.Intrusion detection system (IDS) alerts.
D.Encryption of sensitive data.
E.Firewall rules that block certain traffic.
AnswersB, C

Security logging and monitoring records and analyses activity to identify incidents after or during their occurrence, satisfying the stem's requirement for detective controls. Unlike preventive controls, which block actions, logging detects and alerts on suspicious events, enabling timely response. This makes it a recognised example of a detective security control.

Why this answer

Detective controls are designed to identify and record security events after or while they occur, and both B and C fit that definition. B (Security logging and monitoring) is correct because collecting and analyzing logs (e.g., via SIEM correlation of Windows Event Logs, syslog, or audit trails) detects anomalous or unauthorized activity. C (Intrusion detection system (IDS) alerts) is correct because an IDS inspects network or host traffic (signature- or anomaly-based) and raises alerts when malicious or suspicious patterns are detected.

The unmarked options are preventive or corrective rather than detective: A (Data backup and restoration procedures) is primarily corrective/recovery, D (Encryption of sensitive data) is preventive by protecting confidentiality, and E (Firewall rules that block certain traffic) is preventive by denying traffic before it reaches systems.

Exam trap

CC often tests the distinction between preventive and detective controls — candidates misclassify encryption or firewalls as detective because they 'protect' data, when in fact they prevent rather than detect.

707
MCQmedium

A software development team is designing a new application that will process credit card payments. The security architect recommends that the application should not store the card verification value (CVV) after the transaction is authorized. Which principle is the architect applying?

A.Least privilege
B.Data minimization
C.Separation of duties
D.Defense in depth
AnswerB

Data minimization means collecting and retaining only the data necessary for a specific purpose. Not storing the CVV after authorization reduces the amount of sensitive data at risk and aligns with the principle of limiting data retention to what is needed. This directly matches the architect's recommendation to avoid storing a sensitive element once it is no longer required.

Why this answer

The architect recommends not retaining the CVV after the transaction, which reduces the amount of sensitive data the application holds. This is data minimization, the practice of limiting collection and retention to what is necessary. Least privilege is about access rights, separation of duties is about dividing tasks, and defense in depth is about layered controls, so data minimization is the correct principle.

Exam trap

The trap here is selecting least privilege because it sounds security-related, when the scenario is actually about limiting what data is stored rather than who can access it.

708
MCQeasy

Which of the following is a key function of a Security Information and Event Management (SIEM) system?

A.Blocking malicious network traffic
B.Correlating log data from multiple sources to identify security incidents
C.Enforcing password complexity requirements
D.Patching vulnerabilities in operating systems
AnswerB

SIEM platforms aggregate and normalise logs from disparate sources, then apply correlation rules to link related events across systems. This cross-source correlation is what surfaces incidents that isolated log review would miss, satisfying the question's requirement for a key SIEM function.

Why this answer

SIEM aggregates and correlates logs from various sources to detect patterns and generate alerts.

709
MCQmedium

A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?

A.Firewall
B.Regular backups
C.Intrusion detection system
D.Antivirus software
AnswerB

Regular backups preserve an unencrypted copy of data offline, so files can be restored without the attacker's decryption key. This directly satisfies the recovery requirement, whereas antivirus, patching or firewalls may block initial infection but cannot restore data already encrypted by ransomware.

Why this answer

Regular backups are the most effective control for recovering from ransomware because they allow restoration of data to a known-good state without paying the ransom. Ransomware encrypts files in place, so preventive controls like firewalls or antivirus may fail against new variants, but offline or immutable backups preserve a clean copy. The key is that backups must be isolated (offline, air-gapped, or immutable) to prevent the ransomware from encrypting them too.

Exam trap

The trap is assuming antivirus or firewall 'prevents' ransomware well enough to avoid the need for recovery; the exam wants the control that enables restoration, which is backups.

How to eliminate wrong answers

Option A is wrong because a firewall is a preventive network control that blocks unauthorized traffic but cannot restore encrypted files after a ransomware infection. Option C is wrong because an IDS detects and alerts on suspicious activity but does not provide data recovery; it is detective, not corrective. Option D is wrong because antivirus is preventive/detective and can be bypassed by new or fileless ransomware variants, and it does not restore encrypted data.

710
MCQhard

A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?

A.WPA2-Personal with a strong pre-shared key and MAC address filtering for known laptops.
B.An open wireless network with a captive portal that asks users to type their employee ID.
C.WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.
D.WPA2-Enterprise with EAP-TLS using a client certificate issued by the corporate PKI.
AnswerC

PEAP-MSCHAPv2 lets users authenticate with directory credentials without a client certificate on the personal laptop, satisfying the no-certificate constraint. The RADIUS or NAC layer can then apply authorization policies that map each user or group to a role, which controls access to internal applications. This combination meets both user authentication and role-based access.

Why this answer

PEAP-MSCHAPv2 authenticates users against the corporate directory using usernames and passwords, so no client certificate is needed on personal laptops. A RADIUS or NAC authorization policy then maps the authenticated identity to a role that governs access to internal applications. EAP-TLS requires certificates, WPA2-Personal has no per-user identity, and a captive portal lacks strong authentication and authorization.

Exam trap

The trap here is treating the choice between EAP-TLS and PEAP-MSCHAPv2 as only a security-strength decision while overlooking the constraint that personal devices cannot receive corporate certificates.

711
Multi-Selecthard

Which THREE are valid methods for authenticating a user in an access control system?

Select 3 answers
A.User ID
B.Fingerprint scan
C.Password
D.Smart card
E.Access control list
AnswersB, C, D

Fingerprint is inherence factor.

Why this answer

A fingerprint scan is a valid authentication method because it falls under 'something you are' (biometric authentication). In access control systems, biometrics like fingerprint scans provide a high level of assurance by verifying a unique physical characteristic of the user, making it a strong factor for authentication.

Exam trap

ISC2 often tests the distinction between identification (e.g., User ID) and authentication (e.g., password, biometric, smart card), and the trap here is that candidates mistakenly treat a User ID as an authentication factor rather than just an identifier.

712
Multi-Selecthard

Which THREE of the following are best practices for securing a network firewall? (Select THREE.)

Select 3 answers
A.Disable unused services and ports
B.Allow all traffic by default and block specific threats
C.Implement rule change management and review
D.Place the firewall outside the network perimeter
E.Use strong, complex passwords for firewall administration
AnswersA, C, E

Reduces the attack surface.

Why this answer

Disabling unused services and ports reduces the attack surface by eliminating potential entry points for attackers. A firewall should only have necessary ports (e.g., TCP 80/443 for web traffic) open, as each open service represents a vector for exploitation. This aligns with the principle of least privilege and is a fundamental hardening step.

Exam trap

ISC2 often tests the misconception that a firewall should be placed outside the network perimeter for better visibility, but the correct placement is at the perimeter to filter traffic before it enters the internal network.

713
MCQhard

After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?

A.Accountability
B.Confidentiality
C.Defense in depth
D.Non-repudiation
AnswerC

Defense in depth layers controls — network segmentation, least privilege, monitoring — so breaching the public application does not grant direct database access. The stem's impact limitation is satisfied because no single exploited vulnerability yields full internal reach.

Why this answer

Defense in depth is the principle of layering multiple security controls so that if one fails, others still protect the assets. In this scenario, a publicly accessible application was exploited to reach internal databases; defense in depth would have included network segmentation, least privilege, and additional controls that could have prevented or limited the attacker's lateral movement.

Exam trap

The trap here is that candidates may choose confidentiality or accountability because they sound relevant, but the question asks for the principle that would have most effectively limited the impact of a breach, which is defense in depth.

How to eliminate wrong answers

Option A is wrong because accountability ensures actions can be traced to individuals, but it does not prevent or limit the impact of an exploit. Option B is wrong because confidentiality protects data from unauthorized disclosure, but it is a goal rather than a principle that would have limited the breach's impact. Option D is wrong because non-repudiation prevents denial of actions, which is useful for investigations but does not limit the scope of a breach.

714
Multi-Selectmedium

Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)

Select 2 answers
A.Disable SSL/TLS on web servers
B.Use HTTPS with proper certificate validation
C.Use ARP spoofing detection tools
D.Implement a VPN for remote connections
E.Use Telnet for remote administration
AnswersB, D

HTTPS with proper certificate validation encrypts traffic and authenticates the server via a trusted certificate chain, preventing an attacker from silently intercepting or altering communications. This directly satisfies the stem's man-in-the-middle mitigation requirement by ensuring clients reject forged or untrusted certificates rather than trusting an impostor endpoint.

Why this answer

Option B is correct because HTTPS with proper certificate validation encrypts traffic with TLS and verifies the server's identity against a trusted CA chain, preventing an attacker from silently intercepting or impersonating the endpoint in a man-in-the-middle attack. Option D is correct because a VPN (e.g., IPsec or TLS-based) establishes an authenticated, encrypted tunnel between the remote client and the corporate network, so an attacker on the local network or internet path cannot read or alter the traffic. Option A is wrong because disabling SSL/TLS removes encryption and authentication, making MITM attacks easier, not harder.

Option C, while useful for detecting ARP poisoning on a LAN, is a detection/monitoring measure rather than a primary mitigation best practice for MITM, and it does not protect traffic on its own. Option E is wrong because Telnet transmits credentials and data in cleartext, which is exactly what enables MITM interception; SSH should be used instead.

Exam trap

The trap is selecting ARP spoofing detection as a general MITM mitigation; it only addresses LAN-based ARP spoofing, not the broader category of MITM attacks that HTTPS and VPNs address.

715
MCQhard

A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?

A.Implement Dynamic ARP Inspection
B.Enable STP
C.Use static ARP entries
D.Disable ICMP
AnswerA

Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table, dropping packets with spoofed IP-to-MAC mappings. This directly neutralises ARP spoofing on the switched segment, unlike encryption or static entries, satisfying the stem's mitigation requirement.

Why this answer

Dynamic ARP Inspection (DAI) is a security feature on switches that validates ARP packets in a network. It intercepts ARP requests and replies on untrusted ports, compares them against a trusted binding table (often built via DHCP snooping), and drops invalid or malicious ARP packets. This directly prevents ARP spoofing by ensuring only legitimate ARP mappings are allowed.

Exam trap

The trap is confusing ARP spoofing mitigation with general Layer 2 security features like STP or with host-based static entries; candidates must recognize that DAI is the specific switch-based defense against ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Spanning Tree Protocol (STP) prevents Layer 2 loops, not ARP spoofing. Option C is wrong because static ARP entries can prevent spoofing for specific hosts but are not scalable or practical in most networks, and they do not dynamically protect all hosts. Option D is wrong because disabling ICMP (e.g., ping) does not affect ARP spoofing, which operates at Layer 2 using ARP, not ICMP.

716
Multi-Selectmedium

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Select 3 answers
A.Implementing rate limiting on servers
B.Disabling all firewall rules
C.Allowing all inbound traffic to avoid blocking legitimate users
D.Filtering traffic based on IP reputation
E.Using a Content Delivery Network (CDN) to absorb traffic
AnswersA, D, E

Rate limiting caps the number of requests a server accepts per client within a time window, throttling floods before they exhaust connection or processing capacity. This directly satisfies the DoS mitigation requirement by preserving availability for legitimate users during volumetric or application-layer attacks.

Why this answer

DoS mitigation includes using DDoS protection services, rate limiting, and filtering traffic based on IP reputation.

717
MCQmedium

A financial services firm wants to ensure that a single employee cannot initiate and approve a large wire transfer alone. The firm implements a process where one employee creates the transfer and a different employee must approve it. Which security principle is being applied?

A.Least privilege
B.Separation of duties
C.Mandatory vacation
D.Job rotation
AnswerB

Separation of duties divides a critical task among multiple people so that no single individual can complete it alone, reducing the risk of fraud or error. Requiring one employee to create and another to approve the wire transfer directly implements this principle. It ensures that a single person cannot both initiate and authorize a high-risk financial action.

Why this answer

Separation of duties ensures that a critical task requires more than one person to complete, preventing a single individual from abusing the process. By having one employee create the wire transfer and another approve it, the firm applies this principle directly. Least privilege, job rotation, and mandatory vacation serve different purposes and do not enforce dual control over a single transaction.

Exam trap

The trap here is thinking that any control involving multiple people is separation of duties, when in fact mandatory vacation and job rotation also involve others but do not split a single task into separate authorizations.

718
MCQmedium

Refer to the exhibit. An administrator notices that external access to the MySQL database (port 3306) is blocked, but internal access should be allowed. What change should be made?

A.Change the DROP rule to ACCEPT for port 3306
B.Allow port 3306 in the FORWARD chain
C.Create a rule to allow traffic from internal IP range to port 3306
D.Remove the DROP rule for port 3306
AnswerC

Allowing the internal IP range inbound to TCP 3306 satisfies the stem's constraint that internal access should be permitted while external access stays blocked. A network security group rule scoped to the internal subnet permits only that source, leaving the existing deny for external traffic intact.

Why this answer

The exhibit shows a DROP rule for port 3306 in the INPUT chain, which blocks all incoming traffic to the MySQL database. To allow internal access while keeping external access blocked, a specific rule must be added to ACCEPT traffic from the internal IP range to port 3306, placed before the DROP rule. This ensures that internal packets are matched first and permitted, while external packets hit the DROP rule and are rejected.

Simply modifying or removing the DROP rule would allow all traffic, violating the requirement to block external access.

Exam trap

ISC2 often tests the distinction between INPUT and FORWARD chains, and the trap here is that candidates mistakenly think adding a rule to the FORWARD chain will fix the issue, not realizing that traffic to the local MySQL service is processed by the INPUT chain.

How to eliminate wrong answers

Option A is wrong because changing the DROP rule to ACCEPT for port 3306 would allow all traffic (both internal and external) to the MySQL database, which violates the requirement to block external access. Option B is wrong because the FORWARD chain is used for traffic passing through the firewall, not for traffic destined to the local system; MySQL traffic arriving at the firewall's own interface is processed by the INPUT chain, not FORWARD. Option D is wrong because removing the DROP rule for port 3306 would remove the block entirely, allowing all traffic (including external) to reach the MySQL database, which does not meet the requirement to block external access.

719
MCQhard

You are a forensic analyst responding to a reported compromise of a Linux web server. The server hosts a public-facing web application and is part of a DMZ. The initial investigation shows that unauthorized outbound connections were made to a known malicious IP address during the previous night. The server is still running and connected to the network, but the web application has been taken offline for maintenance. The incident response team wants to preserve evidence for potential legal action. You have a forensic workstation with tools like dd, netcat, and memory acquisition tools. Which of the following should be your FIRST step in the forensic acquisition process?

A.Create a bit-for-bit copy of the hard drive using dd and a write blocker.
B.Capture network traffic from the server for analysis.
C.Run a full antivirus scan to identify malware.
D.Capture the contents of volatile memory (RAM) using a memory acquisition tool.
AnswerD

RAM holds running processes, network connections and encryption keys that vanish on power-off, so capturing it first preserves volatile evidence the malicious outbound sessions left behind. Disk imaging can follow afterwards without losing this data, satisfying the legal preservation requirement.

Why this answer

Volatile memory (RAM) contains critical evidence such as running processes, network connections, encryption keys, and in-memory malware that would be lost when the system is powered off. In a forensic response, the order of volatility dictates that RAM must be captured first before any non-volatile data. Option D is correct because it follows the established forensic principle of preserving the most volatile data first.

Exam trap

ISC2 often tests the 'order of volatility' principle, and the trap here is that candidates mistakenly prioritize disk imaging (Option A) because it is a familiar step, ignoring that RAM holds the most ephemeral and critical evidence.

How to eliminate wrong answers

Option A is wrong because creating a bit-for-bit copy of the hard drive is important but should be done after volatile memory capture, as hard drive data is non-volatile and will not be lost on shutdown. Option B is wrong because capturing network traffic from the server is a live response step that can be performed after memory acquisition, but it is not the first priority since network traffic is also volatile but less critical than RAM contents. Option C is wrong because running an antivirus scan modifies the system state (e.g., file access times, writes to disk) and can destroy or alter evidence, violating forensic integrity.

720
MCQhard

A security engineer is designing a system that must ensure that any changes to a configuration file are logged with the identity of the person who made the change. Which principle is being implemented?

A.Accountability
B.Non-repudiation
C.Confidentiality
D.Integrity
AnswerA

Accountability binds each configuration change to a verified identity through logging, so any modification can be traced to the specific person responsible. This directly satisfies the requirement that changes are recorded alongside the actor's identity, distinguishing it from authentication, which merely verifies identity at access time.

Why this answer

Accountability means that every action can be traced back to a specific identity, so a person can be held responsible for their changes. Logging configuration changes with the identity of the person who made them is the textbook implementation of accountability — it links actions to actors.

Exam trap

The trap here is confusing accountability with non-repudiation — candidates see 'identity of the person' and jump to non-repudiation, but non-repudiation requires cryptographic proof, while plain identity logging is accountability.

How to eliminate wrong answers

Option B is wrong because non-repudiation prevents a party from denying that they performed an action (typically enforced with digital signatures), which is a stronger, cryptographic guarantee than simply logging identity. Option C is wrong because confidentiality ensures data is not disclosed to unauthorized parties (encryption, access control) — it has nothing to do with attributing changes. Option D is wrong because integrity ensures data has not been altered improperly (hashes, checksums); while logging supports integrity auditing, the specific requirement of tying changes to an identity is accountability.

721
MCQeasy

The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?

A.Fail-safe defaults
B.Defense in depth
C.Separation of duties
D.Least privilege
AnswerA

A default DROP policy denies all traffic that no explicit rule permits, so only expressly allowed flows pass. This directly enforces fail-safe defaults: access decisions fall back to denial rather than permission, satisfying the stem's requirement that the default policy itself embody the principle.

Why this answer

The default policy in iptables, typically DROP or REJECT for INPUT and FORWARD chains, enforces fail-safe defaults by denying all traffic that is not explicitly allowed. This security principle ensures that only permitted traffic passes, aligning with a deny-by-default posture.

Exam trap

The trap here is confusing fail-safe defaults with least privilege, as both involve restricting access, but fail-safe defaults specifically refers to the default deny posture of a policy.

How to eliminate wrong answers

Option B is wrong because defense in depth refers to multiple layers of security controls, not a single default policy. Option C is wrong because separation of duties involves dividing responsibilities among different roles, which is an organizational control, not a firewall policy. Option D is wrong because least privilege refers to granting minimal permissions to users or processes, which is related but not the specific principle enforced by a default deny policy.

722
MCQhard

A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?

A.Separation of duties; fix the configuration to require approvals from two different managers
B.Defense in depth; add a third approval for transactions over $50,000
C.Accountability; log all approvals and audit monthly
D.Least privilege; reduce the transaction limit to $5,000
AnswerA

Two distinct approvers from sales and finance enforce separation of duties, preventing one person completing the whole transaction. The IP-based bypass collapses both approvals into a single actor, so the control fails. Remediation is to correct the configuration so two different managers must approve, restoring the dual-authorisation constraint.

Why this answer

The scenario describes a situation where a single manager can approve a transaction that should require two separate approvals from different departments. This circumvents the separation of duties principle, which ensures that no single individual has the authority to complete a critical task alone. The best remediation is to fix the configuration so that two different managers must approve, restoring separation of duties.

Defense in depth (B) is about layered controls, accountability (C) is about logging, and least privilege (D) is about minimal access rights; none directly address the bypass of dual approval.

Exam trap

CC often tests the application of security principles to scenarios; candidates might confuse separation of duties with least privilege or defense in depth, but the key is recognizing that dual approval is a separation of duties control.

How to eliminate wrong answers

Option B is wrong because defense in depth involves multiple layers of security, but the issue is not a lack of layers; it's the failure to enforce separation of duties. Option C is wrong because accountability (logging and auditing) is a detective control, but it does not prevent the circumvention; the principle violated is separation of duties. Option D is wrong because least privilege is about granting minimal permissions, but the problem is that a single manager has too much approval power, which is a separation of duties issue.

723
MCQmedium

A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?

A.SFTP with a shared username and password for the radiology and clinic staff.
B.IPsec in tunnel mode with confidentiality and data origin authentication enabled.
C.A site-to-site VPN using GRE without encryption or authentication.
D.TLS 1.3 with a server certificate issued to the remote clinic.
AnswerB

IPsec tunnel mode encapsulates the entire original IP packet and can apply ESP encryption for confidentiality plus an authentication mechanism that provides data origin authentication and integrity. This protects the images from being read or altered in transit and lets the remote clinic verify the hospital as the source. It matches both requirements in a single, standard site-to-site design.

Why this answer

IPsec in tunnel mode with ESP confidentiality and authentication provides encryption for the images and cryptographically verifies the hospital as the origin. The remote clinic can validate the sender and detect any modification in transit. TLS with a certificate issued to the wrong party, shared SFTP credentials, and unencrypted GRE do not meet both requirements.

Exam trap

The trap here is confusing encryption with data origin authentication and assuming that any encrypted tunnel proves who sent the data.

724
MCQhard

Refer to the exhibit. A firewall rule set is shown (first match applies). An analyst reviews these rules. Which of the following best describes the traffic outcome for a packet from source IP 10.0.0.1 to destination 192.168.1.1?

A.The packet is permitted because the last rule permits any any.
B.The packet is denied because rule 1 matches and denies it.
C.The packet is permitted because rule 2 explicitly permits the traffic.
D.The packet is denied because there is no explicit permit for 10.0.0.0/8 to 192.168.1.0/24.
AnswerB

Firewall rulesets evaluate top-down and stop at the first match, so rule 1's deny for that source takes effect before any later permit is reached. The packet never reaches subsequent rules, making the outcome a denial rather than an allow.

Why this answer

Rule 1 matches the source IP 10.0.0.1 (which falls within the 10.0.0.0/8 range) and the destination 192.168.1.1 (within 192.168.1.0/24), and since the action is 'deny', the packet is denied immediately. Firewalls using 'first match applies' logic stop processing as soon as a matching rule is found, so subsequent rules are never evaluated. Therefore, the correct outcome is denial.

Exam trap

ISC2 often tests the 'first match applies' concept by placing a broad deny rule early in the rule set, leading candidates to incorrectly assume that a later permit rule will override it, when in fact the packet is denied immediately upon the first match.

How to eliminate wrong answers

Option A is wrong because the 'permit any any' rule is never reached; the packet is matched and denied by rule 1 before the last rule is evaluated. Option C is wrong because rule 2, even if it explicitly permits the traffic, is not evaluated since rule 1 already matched and denied the packet. Option D is wrong because the absence of an explicit permit for the specific source/destination pair is irrelevant; the packet is denied by an explicit deny rule (rule 1), not by a lack of a permit.

725
MCQeasy

A company wants to allow remote employees to securely access internal resources over the internet. Which technology is most appropriate?

A.NAT
B.VLAN
C.DMZ
D.VPN
AnswerD

A VPN builds an encrypted tunnel between the remote employee's device and the corporate network, so internal resources are reachable as if on-site. This satisfies the requirement for secure internet-based access, unlike a public-facing endpoint or unencrypted connection.

Why this answer

A VPN (Virtual Private Network) creates an encrypted tunnel over the internet, typically using protocols like IPsec or TLS, to securely connect remote users to internal resources. This ensures confidentiality, integrity, and authentication of data in transit, making it the standard solution for remote access security.

Exam trap

ISC2 often tests the misconception that NAT or a DMZ alone can secure remote access, but candidates must recognize that only VPN provides the required encryption and tunneling for secure internet-based connectivity.

How to eliminate wrong answers

Option A (NAT) is wrong because Network Address Translation only modifies IP addresses in packet headers to enable private-to-public address mapping; it does not provide encryption or secure remote access. Option B (VLAN) is wrong because a Virtual LAN segments a local network at Layer 2 to isolate traffic within a switch, but it cannot extend secure connectivity across the internet. Option C (DMZ) is wrong because a Demilitarized Zone is a perimeter network that hosts public-facing services (e.g., web servers) while isolating them from the internal LAN; it does not create encrypted tunnels for remote users.

726
MCQmedium

A company uses a SIEM to monitor network security events. The security analyst notices a high volume of alerts about suspicious outbound traffic to a known command-and-control server. The traffic is encrypted and uses non-standard ports. Which security control would best detect this activity if the SIEM relies only on network flow data?

A.Web application firewall (WAF) in reverse proxy mode
B.Host-based antivirus with heuristic scanning
C.Signature-based intrusion detection system (IDS)
D.Network flow analysis with anomaly detection
AnswerD

Network flow analysis examines metadata such as IP addresses, ports, byte counts, and timing without needing payload decryption. Anomaly detection can flag deviations like regular beaconing to a known C2 IP on non-standard ports. This approach works with the SIEM's flow data and can detect encrypted C2 traffic based on behavioral patterns.

Why this answer

Since the SIEM only has network flow data and the traffic is encrypted, payload inspection is impossible. Network flow analysis with anomaly detection uses metadata like IP, port, and timing to identify beaconing patterns to known C2 servers. Signature IDS, host antivirus, and WAFs either need payload visibility or do not monitor outbound flows.

Exam trap

The trap here is assuming that encrypted traffic cannot be detected, when flow-based anomaly detection can identify malicious behavior from metadata alone.

727
Multi-Selectmedium

Which TWO of the following are essential elements of an incident response plan?

Select 2 answers
A.A list of compliance standards.
B.Personal phone numbers of executives.
C.Step-by-step procedures for each incident type.
D.Contact information for all employees.
E.Defined roles and responsibilities.
AnswersC, E

Step-by-step procedures translate policy into executable actions, specifying exactly who does what, in which order, during each incident class. This satisfies the stem's demand for essential plan elements: without predefined playbooks, responders improvise under pressure, delaying containment and recovery. Procedures also enable consistent handling and post-incident review across the organisation.

Why this answer

Option C is correct because an incident response plan must include step-by-step procedures for each incident type, giving responders a documented, repeatable playbook (e.g., containment, eradication, recovery steps) so they can act quickly and consistently during an actual event. Option E is correct because defined roles and responsibilities establish who leads the response, who handles communications, who performs forensics, and who has authority to make decisions, which is essential for coordination and accountability under pressure. Options A, B, and D do not belong: a list of compliance standards is a governance/audit reference rather than a core response element, personal phone numbers of executives are too narrow and not a structural component of the plan, and contact information for all employees is an overly broad directory detail rather than an essential element of the incident response plan itself.

Exam trap

ISC2 often tests the distinction between 'essential operational elements' (like procedures and roles) and 'supporting documentation' (like compliance lists or full employee directories), causing candidates to mistake administrative details for core response components.

728
MCQmedium

A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?

A.Separation of duties
B.Need to know
C.Least privilege
D.Defense in depth
AnswerB

Need to know limits access to only the specific information a user requires to perform their duties. The teller needs records for their own branch's customers to serve them, but has no legitimate need to view customers at other branches. Restricting the teller's visibility to only the records necessary for their work is the essence of the need-to-know principle.

Why this answer

Need to know restricts access to only the information a user requires for their job, which is why the teller sees only their branch's customers. Least privilege limits the types of permissions granted, separation of duties splits tasks among users, and defense in depth layers controls. The record-level restriction described maps to need to know.

Exam trap

The trap here is choosing least privilege because access is limited, when the scenario is specifically about limiting which data records a user can see, which is need to know.

729
MCQmedium

Which of the following controls is primarily designed to ensure availability?

A.Redundant servers
B.Encryption
C.Digital signatures
D.Access control lists
AnswerA

Redundant servers directly satisfy the availability requirement by eliminating single points of failure: if one server fails, another continues serving requests, so the service remains accessible. Unlike confidentiality or integrity controls, redundancy targets uptime specifically, matching the stem's availability constraint through failover rather than prevention of unauthorised access or data alteration.

Why this answer

Redundant servers ensure availability by eliminating single points of failure — if one server fails, another continues to provide the service. This directly supports the availability leg of the CIA triad.

Exam trap

The CC exam often tests whether candidates can map controls to the correct CIA triad element, and redundancy is sometimes confused with integrity or confidentiality controls.

How to eliminate wrong answers

Option B is wrong because encryption primarily ensures confidentiality by protecting data from unauthorized disclosure. Option C is wrong because digital signatures primarily ensure integrity and authenticity, not availability. Option D is wrong because access control lists primarily ensure confidentiality and integrity by restricting who can access resources.

730
MCQhard

An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?

A.An IPS is placed inline and can automatically block malicious traffic.
B.An IPS is placed out of band and monitors traffic.
C.An IPS generates alerts but does not block traffic.
D.An IPS operates only at the application layer.
AnswerA

An IPS sits inline in the traffic path, so it can drop or reset malicious packets in real time rather than merely alerting. This satisfies the scenario's requirement to actively protect the network, whereas an IDS only monitors a copy of traffic and cannot block.

Why this answer

An IPS is deployed inline in the traffic path, so it can inspect packets in real time and actively drop or reset malicious sessions, whereas an IDS is passive and only alerts. This inline placement is what enables automatic blocking. The other options describe IDS behavior or overstate the IPS's scope.

Exam trap

The trap here is the common misconception that an IPS only alerts like an IDS, when the key differentiator is inline placement and active blocking.

How to eliminate wrong answers

Option B is wrong because out-of-band monitoring is the defining characteristic of an IDS, not an IPS — an out-of-band device cannot block traffic in real time. Option C is wrong because generating alerts without blocking is exactly what an IDS does; an IPS both detects and prevents. Option D is wrong because an IPS can operate at multiple layers (network, transport, application) depending on whether it is a network-based or host-based IPS, so limiting it to the application layer is incorrect.

731
Multi-Selecthard

Which TWO of the following are best practices for implementing the principle of least privilege?

Select 2 answers
A.Grant all users full administrative rights to reduce support calls
B.Assign permissions based on the minimum necessary to perform job functions
C.Use a single shared administrative account for all IT staff
D.Remove all default accounts from systems
E.Regularly review and revoke unnecessary privileges
AnswersB, E

Least privilege means granting only the access required for a user's job function, nothing broader. This directly limits the blast radius of compromised accounts and satisfies the principle's core constraint: permissions scoped to actual duties rather than convenience or role seniority.

Why this answer

Option B is correct because least privilege means granting each user only the access rights required to perform their specific job functions, nothing more, which directly limits the blast radius of compromised or misused accounts. Option E is correct because least privilege is not a one-time configuration; permissions tend to accumulate through role changes and project work, so periodic access reviews and revocation of unnecessary privileges keep entitlements aligned with current job duties. Option A is wrong because granting full administrative rights to all users is the opposite of least privilege and dramatically increases risk.

Option C is wrong because a single shared administrative account destroys individual accountability and prevents per-user privilege scoping. Option D is wrong because removing all default accounts is not a least-privilege practice; some default accounts may be required, and the proper approach is to rename, disable, or restrict them as appropriate.

Exam trap

The trap is that removing default accounts sounds like least privilege, but it is account hardening; candidates must focus on the two options that actually scope and review user permissions.

732
Multi-Selecthard

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Select 3 answers
A.Probability of a data breach
B.Customer database
C.Vulnerability in software
D.Firewall
E.Employee expertise
AnswersB, D, E

A customer database is an information asset: it holds valuable data the organisation must protect, and it carries risk exposure if compromised, lost or corrupted. Risk assessments inventory such assets before identifying threats and vulnerabilities, making the database a legitimate asset in this scenario.

Why this answer

In risk assessment, an asset is anything of value to the organization that could be affected by a threat, so the customer database (B) qualifies because it holds valuable data whose loss or exposure would harm the business. The firewall (D) is a tangible asset—hardware or software that protects the network and represents a resource the organization owns and depends on. Employee expertise (E) is an intangible asset, since the knowledge, skills, and experience of staff are valuable resources that can be lost through turnover or social engineering.

The probability of a data breach (A) is not an asset but a likelihood or risk factor used to estimate how often a threat might occur. A vulnerability in software (C) is a weakness or gap in a control, not something of value, so it is a risk element rather than an asset.

Exam trap

The CC exam often tests whether candidates can distinguish assets (things of value) from vulnerabilities (weaknesses) and risks (probability/impact combinations), which are frequently mixed in the answer choices.

733
MCQeasy

Which incident category involves an attacker tricking an employee into revealing credentials?

A.Data breach
B.Social engineering
C.Malware
D.Denial of service
AnswerB

Social engineering manipulates human trust rather than exploiting software flaws, using phishing, pretexting or impersonation to persuade an employee to hand over credentials. The attacker targets the person, not the system, which is the defining characteristic of this incident category.

Why this answer

Social engineering is the incident category that involves manipulating people into divulging confidential information, such as credentials. Attackers use psychological tactics like phishing, pretexting, or baiting to trick employees into revealing passwords or other sensitive data.

Exam trap

The trap here is conflating the attack method (social engineering) with its potential outcome (data breach); candidates may choose data breach because credentials were revealed, but the question asks for the incident category of the trickery itself.

How to eliminate wrong answers

Option A is wrong because a data breach is the outcome of unauthorized data access, not the method of tricking an employee; social engineering can lead to a data breach, but the category here is the attack technique. Option C is wrong because malware is malicious software, not a human manipulation tactic. Option D is wrong because denial of service disrupts availability, not credential theft through deception.

734
MCQmedium

A system administrator needs to grant a contractor temporary access to a server for patching. The contractor should only have access during the patching window. Which access control implementation method is most appropriate?

A.Time-based ACL (rule-based access control)
B.Group-based permissions with a recurring schedule
C.Discretionary access control (DAC)
D.Mandatory access control (MAC)
AnswerA

A time-based ACL enforces access windows directly on the server, so the contractor's permissions activate only during the patching period and lapse automatically afterwards. This satisfies the stem's constraint that access be limited to the patching window, without relying on manual revocation or account lifecycle management.

Why this answer

Time-based ACLs (rule-based access control) allow the administrator to define a specific time range during which the contractor's access is permitted. This directly matches the requirement for temporary access only during the patching window, as the ACL can be configured with a time-range object that automatically enables and disables the permit statement without manual intervention.

Exam trap

ISC2 often tests the distinction between rule-based access control (RBAC) with time-based ACLs and group-based permissions, where candidates mistakenly choose group-based permissions because they think 'recurring schedule' implies time control, but group-based permissions lack the precise time-range enforcement at the network layer.

How to eliminate wrong answers

Option B is wrong because group-based permissions with a recurring schedule typically apply to user group memberships and do not provide the granular, time-bound enforcement at the network or system level that a time-based ACL offers. Option C is wrong because discretionary access control (DAC) allows the resource owner to grant permissions arbitrarily, which does not inherently enforce a time-limited access window. Option D is wrong because mandatory access control (MAC) uses system-wide labels and security clearances, which are static and not designed for temporary, time-based access exceptions.

735
MCQeasy

An organization wants to ensure that data remains unaltered during transmission over the internet. Which security goal is being addressed?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerD

Integrity guarantees data is not altered in transit, detecting any modification between sender and receiver. Cryptographic hashes or MACs verify that received data matches what was sent, directly satisfying the requirement that data remains unaltered over the internet.

Why this answer

Integrity ensures that data is not altered during transmission, typically verified through cryptographic hash functions (e.g., SHA-256) or message authentication codes (MACs) such as HMAC. Protocols like TLS use integrity checks to detect any unauthorized modification of packets in transit, directly addressing the requirement that data remains unaltered.

Exam trap

ISC2 often tests the distinction between confidentiality and integrity by presenting a scenario about data alteration, where candidates mistakenly choose confidentiality because they associate encryption with all security, ignoring that encryption alone does not prevent tampering.

How to eliminate wrong answers

Option A is wrong because non-repudiation prevents a party from denying an action, usually via digital signatures (e.g., RSA or ECDSA), not by ensuring data is unchanged during transit. Option B is wrong because availability ensures systems and data are accessible when needed, often through redundancy or DDoS mitigation, not by protecting against alteration. Option C is wrong because confidentiality protects data from unauthorized disclosure via encryption (e.g., AES), but does not guarantee that data has not been tampered with during transmission.

736
Multi-Selectmedium

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Select 2 answers
A.Smart card and OTP token
B.Fingerprint and password
C.Password and smart card
D.Fingerprint and retina scan
E.Password and PIN
AnswersB, C

A fingerprint is something you are (inherence), while a password is something you know (knowledge). Pairing them spans two separate factor categories, satisfying true multi-factor authentication. Two biometrics, or two passwords, would not qualify as genuine multi-factor.

Why this answer

Option B (fingerprint and password) is correct because it combines a biometric inherence factor (the fingerprint) with a knowledge factor (the password), satisfying true MFA by mixing two different factor categories. Option C (password and smart card) is correct because it pairs a knowledge factor (the password) with a possession factor (the smart card, something you have), which are distinct factor types. Option A (smart card and OTP token) is not true MFA because both are possession factors (something you have), even though they are different technologies.

Option D (fingerprint and retina scan) is not true MFA because both are biometric inherence factors (something you are). Option E (password and PIN) is not true MFA because both are knowledge factors (something you know).

Exam trap

The trap is that candidates see two different-looking authentication methods and assume MFA, without checking whether both factors belong to the same category (e.g., two biometrics or two knowledge factors).

737
MCQeasy

Which metric defines the maximum acceptable amount of data loss measured in time?

A.Recovery Point Objective (RPO)
B.Mean Time Between Failures (MTBF)
C.Mean Time to Repair (MTTR)
D.Recovery Time Objective (RTO)
AnswerA

Recovery Point Objective (RPO) specifies the maximum tolerable data loss expressed as elapsed time before an incident, directly satisfying the stem's requirement for a time-measured loss threshold. It determines backup frequency, unlike Recovery Time Objective, which bounds service restoration duration instead.

Why this answer

The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, typically expressed in seconds, minutes, or hours. It represents the age of the most recent backup or replicated data that must be available to resume operations after a disaster, directly determining the frequency of backups or replication intervals.

Exam trap

ISC2 often tests the distinction between RPO and RTO, where candidates confuse 'data loss' (RPO) with 'downtime' (RTO); the trap is that both are time-based metrics, but RPO is about how far back in time you can recover data, while RTO is about how long it takes to restore service.

How to eliminate wrong answers

Option B is wrong because Mean Time Between Failures (MTBF) measures the average time between system failures, not data loss; it is a reliability metric used for hardware or component failure prediction. Option C is wrong because Mean Time to Repair (MTTR) measures the average time required to restore a failed system or component, not the acceptable data loss window. Option D is wrong because Recovery Time Objective (RTO) defines the maximum acceptable downtime after a disaster, not the amount of data loss measured in time; RTO focuses on service restoration speed, while RPO focuses on data currency.

738
MCQeasy

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

A.SMTP
B.FTP
C.DNS
D.HTTP
AnswerA

Port 25 is the standard TCP port for SMTP, used for sending and relaying email. Outbound traffic from an internal workstation to an external address on this port suggests the host is acting as a mail client or, more likely in this scenario, a compromised machine sending spam.

Why this answer

SMTP (Simple Mail Transfer Protocol) operates over TCP port 25 by default for relaying and receiving email. Unusual outbound traffic on port 25 from an internal workstation often indicates a compromised host sending spam or a malware infection attempting to exfiltrate data via email. The other protocols listed use different default ports: FTP uses 20/21, DNS uses 53, and HTTP uses 80.

Exam trap

CC often tests port number memorization; candidates may confuse port 25 with other common ports like 21 (FTP), 53 (DNS), or 80 (HTTP).

How to eliminate wrong answers

Option B is wrong because FTP uses ports 20 and 21 for data and control, not port 25. Option C is wrong because DNS primarily uses port 53 for queries and zone transfers. Option D is wrong because HTTP uses port 80 for unencrypted web traffic, not port 25.

739
Multi-Selectmedium

A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)

Select 2 answers
A.Use the USB drive only on a non-networked computer.
B.Never plug in a USB drive that you found lying around.
C.Always scan a found USB drive with antivirus before using.
D.Report any discovered USB drives to the security team.
E.Format the USB drive before using it.
AnswersB, D

Refusing to plug in found drives removes the attack vector entirely, since the malicious payload executes only on connection. This satisfies the stem's training-message requirement by targeting the physical action the USB drop attack depends upon, before any autorun or HID emulation can trigger.

Why this answer

Option B is correct because the core defense against USB drop attacks (such as BadUSB or HID-spoofing devices that emulate keyboards) is simply never inserting an unknown drive into any system, since malicious firmware can execute before any OS-level controls apply. Option D is correct because reporting found drives to the security team allows them to be safely collected and analyzed as potential threat indicators, and it removes the drive from the environment so others are not tempted to plug it in. Options A, C, and E do not belong: using the drive on a non-networked computer still exposes that host to malicious firmware or autorun payloads, antivirus scanning cannot detect firmware-level or HID-emulation attacks and may itself trigger the payload, and formatting a drive does not neutralize malicious controller firmware and requires plugging it in first.

Exam trap

CC often tests the misconception that scanning or formatting a found USB drive makes it safe; candidates may choose these options because they seem like reasonable precautions, but the only safe action is to not plug it in and report it.

740
MCQhard

Refer to the exhibit. Based on the JSON policy, what access does the SecurityAuditor role have?

A.No access to any S3 resources.
B.Read-only access to all objects in the critical-data bucket.
C.Write access to the critical-data bucket.
D.Full access to the S3 bucket critical-data.
AnswerB

The JSON policy grants `s3:GetObject` and `s3:ListBucket` on the critical-data bucket's ARN, permitting retrieval and enumeration of every object without write, delete or overwrite permissions. This satisfies the stem's read-only constraint, since no mutating actions such as `PutObject` or `DeleteObject` appear in the statement.

Why this answer

The JSON policy grants the SecurityAuditor role the `s3:GetObject` action on the `arn:aws:s3:::critical-data/*` resource, which provides read-only access to all objects in the critical-data bucket. The `Effect` is set to `Allow`, and no other actions like `s3:PutObject` or `s3:DeleteObject` are included, so the role cannot write or delete objects. This matches the correct answer B.

Exam trap

ISC2 often tests the distinction between bucket-level and object-level permissions, where candidates mistakenly assume that `s3:GetObject` on `/*` implies full access or write capabilities, but it only grants read access to objects.

How to eliminate wrong answers

Option A is wrong because the policy explicitly allows `s3:GetObject` on the critical-data bucket, so the role does have access to S3 resources. Option C is wrong because the policy does not include any write actions such as `s3:PutObject` or `s3:DeleteObject`, so write access is not granted. Option D is wrong because the policy only allows `s3:GetObject`, not full access (which would require actions like `s3:*` or `s3:PutObject`, `s3:DeleteObject`, `s3:ListBucket`, etc.).

741
MCQhard

During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?

A.Recovery Point Objective (RPO)
B.Recovery Time Objective (RTO)
C.Maximum Tolerable Downtime (MTD)
D.Work Recovery Time (WRT)
AnswerB

A warm site provides partially configured infrastructure, enabling systems to be operational within roughly two days. That timeframe directly defines the Recovery Time Objective, the maximum acceptable downtime, rather than data loss measured by RPO.

Why this answer

A warm site with partially configured servers and network infrastructure but lacking recent data is designed to bring systems online within a defined timeframe — in this case, 2 days. That timeframe is the Recovery Time Objective (RTO), which specifies the maximum acceptable time to restore operations after a disruption. The warm site's capabilities directly address how quickly recovery can occur, making RTO the metric most directly addressed.

Exam trap

The trap here is confusing RTO with RPO — candidates see 'lacks recent data' and jump to RPO, but the question emphasizes the 2-day operational timeframe, which is squarely an RTO concern.

How to eliminate wrong answers

Option A is wrong because RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — it relates to backup frequency and data currency, not how quickly systems can be brought back online. The warm site's lack of recent data actually highlights an RPO gap, but the question asks about the recovery timeframe. Option C is wrong because MTD (Maximum Tolerable Downtime) is the total time a business can survive a disruption before unacceptable consequences occur — it is a business-level constraint that encompasses both RTO and WRT, not a metric directly satisfied by the warm site's 2-day capability.

Option D is wrong because WRT (Work Recovery Time) is the time needed after systems are restored to verify data integrity and resume business processes — it is a component of MTD, not the primary metric addressed by the site's infrastructure readiness.

742
MCQhard

Which of the following is a potential security issue commonly found in firewall configurations?

A.Logging is not enabled at session start
B.Outbound traffic is not inspected for malicious content
C.The source is too restrictive
D.The policy does not specify a destination
AnswerB

Outbound traffic inspection is frequently neglected because many firewall rulesets focus on inbound threats, leaving internal hosts free to exfiltrate data or reach command-and-control servers. This satisfies the scenario's requirement for a commonly found misconfiguration, as unrestricted egress permits malware beaconing and data loss without triggering perimeter defences.

Why this answer

A common firewall misconfiguration is to inspect only inbound traffic while allowing outbound traffic without inspection. This can allow malicious content such as command-and-control traffic or data exfiltration to leave the network undetected. Outbound traffic inspection is often overlooked, making it a potential security issue.

Exam trap

ISC2 often tests the misconception that only inbound traffic needs inspection because threats come from the internet, but the trap is that outbound traffic can carry malicious payloads or exfiltrate data, making outbound inspection equally important for a defense-in-depth strategy.

How to eliminate wrong answers

Option A is wrong because logging at session start is not a mandatory security requirement; logging at session end is typically sufficient for auditing and troubleshooting, and the absence of session-start logging does not represent a security issue. Option C is wrong because the source being too restrictive would actually reduce the attack surface, not create a security issue; overly permissive sources are the concern. Option D is wrong because the policy does specify a destination (the internal network), and a missing destination would cause the policy to fail to match traffic, not create a security issue.

743
MCQmedium

Your organization is implementing a new access control system to protect a highly sensitive research database. The security policy mandates that no single individual should have the ability to both approve and execute changes to the database. This is to prevent fraud and errors. Which security principle does this policy enforce, and which of the following best implements it?

A.Defense in depth; require both parties to authenticate
B.Accountability; log all changes and have an auditor review them
C.Separation of duties; require that one person submits a change request and another person implements it
D.Least privilege; assign the same person as approver and executor but with limited permissions
AnswerC

Separation of duties splits authorisation from execution so no single person can both approve and perform a change. Requiring one individual to submit the change request and a different individual to implement it enforces that split, preventing fraud and errors in the sensitive research database.

Why this answer

Correct: Separation of duties; requiring two different people for approval and execution (C). This principle prevents a single individual from having conflicting responsibilities, reducing risk of fraud or error. Option A is wrong because defense in depth involves multiple layers of security, not separation of roles.

Option B is wrong because accountability through logging and auditing does not prevent a single person from both approving and executing changes. Option D is wrong because least privilege would still allow the same person to both approve and execute, albeit with limited permissions, violating the policy.

744
MCQmedium

You are a security engineer responsible for the company's intrusion detection system (IDS). The IDS has been generating an excessive number of false positive alerts related to a legitimate application that uses encrypted traffic. The alerts are based on network signatures that match certain patterns in the encrypted payload. The volume of alerts is overwhelming the SOC team, and they are beginning to ignore IDS alerts altogether. You have the ability to modify IDS signatures and tune the system. Which of the following is the BEST approach to reduce false positives while maintaining security?

A.Create custom exceptions for the specific signatures that are causing false positives for the legitimate application.
B.Add the application's source IP addresses to a whitelist to suppress all alerts from that host.
C.Increase the threshold for alert generation so fewer alerts fire.
D.Disable all signatures that trigger on encrypted traffic.
AnswerA

Custom exceptions suppress only the specific signatures matching the legitimate application's encrypted traffic, eliminating those false positives while leaving all other signatures active. This directly satisfies the stem's requirement to reduce false positives without weakening detection of genuine threats.

Why this answer

Creating custom exceptions for the specific signatures that trigger false positives allows you to suppress alerts for the legitimate application without disabling broader detection capabilities. This targeted approach preserves the IDS's ability to detect actual threats in encrypted traffic while reducing noise for the SOC team. It is the most precise tuning method, as it only excludes the known benign traffic pattern rather than broadly disabling signatures or whitelisting entire hosts.

Exam trap

The trap here is that candidates often choose IP whitelisting (Option B) because it seems quick and easy, but it is overly broad and can hide malicious activity from the same source, whereas signature-specific exceptions are the correct, surgical tuning method.

How to eliminate wrong answers

Option B is wrong because whitelisting the application's source IP addresses suppresses all alerts from that host, including those for potentially malicious activity that might originate from the same IP (e.g., if the host is compromised or used for lateral movement). This creates a dangerous blind spot. Option C is wrong because increasing the alert threshold reduces the sensitivity of the IDS globally, which can cause true positive alerts for real threats to be missed, especially in low-volume attacks.

Option D is wrong because disabling all signatures that trigger on encrypted traffic eliminates the IDS's ability to detect threats that use encryption (e.g., malware C2 over TLS), which is a common evasion technique and would severely weaken security posture.

745
MCQhard

A security architect is designing a system that must ensure that a sender cannot later deny having sent a message. Which cryptographic mechanism should be implemented?

A.Symmetric encryption
B.Access control lists
C.Hashing
D.Digital signatures
AnswerD

Digital signatures use the sender's private key to produce a value verifiable with their public key, binding the sender's identity to the message. This provides non-repudiation, the exact constraint in the stem, because only the private-key holder could have generated the signature, so the sender cannot later deny it.

Why this answer

Digital signatures provide non-repudiation by binding the sender's identity to the message using public key cryptography. The sender cannot deny because only they possess the private key used to sign.

746
MCQeasy

A small accounting firm has a flat network where all employee workstations and a guest Wi-Fi access point connect to the same switch. The owner asks a security consultant to keep guests from reaching the payroll server, which resides on the same subnet as employee devices. Which control should the consultant implement to meet this requirement with the least disruption?

A.Deploy an IPS between the guest access point and the switch to block attacks aimed at the payroll server.
B.Enable a host-based firewall on the payroll server that permits only the payroll application's TCP port.
C.Create a separate VLAN for guests and apply an access control list that denies guest subnet traffic to the payroll server.
D.Change the guest Wi-Fi pre-shared key every 30 days and publish it only to visitors.
AnswerC

Placing guests on a dedicated VLAN segments the guest broadcast domain from employee systems, and an ACL on the router or Layer 3 switch can explicitly deny guest-to-payroll traffic. This directly satisfies the requirement to keep guests from reaching the payroll server while preserving the existing flat employee network, resulting in minimal disruption to employee workflows.

Why this answer

Segmenting guest traffic into its own VLAN removes it from the employee broadcast domain, and an ACL on the Layer 3 device enforces the rule that guests cannot reach the payroll server. This addresses the requirement directly without redesigning the employee network. Host firewalls, key rotation, and intrusion prevention do not provide the same deterministic isolation.

Exam trap

The trap here is assuming that a security appliance such as an IPS or a host firewall provides the same deterministic traffic separation as network segmentation with an ACL.

747
MCQmedium

Which component of the AAA framework determines what resources an authenticated user can access?

A.Auditing
B.Accounting
C.Authorization
D.Authentication
AnswerC

Authorization defines the specific resources and actions an authenticated identity may use, satisfying the stem's requirement to determine access after authentication succeeds. It operates on permissions, group memberships and policies, unlike authentication (identity verification) or accounting (usage logging). Microsoft Entra ID enforces this through role assignments and conditional access.

Why this answer

Authorization is the component of the AAA (Authentication, Authorization, Accounting) framework that determines what resources an authenticated user can access. After authentication verifies the user's identity, authorization enforces policies—such as those defined in a local database or via RADIUS/TACACS+—to permit or deny access to specific network services, commands, or resources.

Exam trap

ISC2 often tests the distinction between authentication and authorization by presenting a scenario where a user is successfully logged in but cannot access a resource, and candidates mistakenly blame authentication instead of recognizing that authorization is the missing step.

How to eliminate wrong answers

Option A is wrong because auditing is not a separate AAA component; it is often part of accounting or logging, and it reviews past actions rather than controlling real-time access. Option B is wrong because accounting tracks and logs user activities (e.g., session time, data transfer) for billing or auditing, but it does not decide what resources a user can access. Option D is wrong because authentication only verifies identity (e.g., via username/password, certificate, or token) and does not grant or deny access to specific resources.

748
MCQeasy

Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Need-to-know
AnswerB

Least privilege grants each user only the minimum permissions their job requires, limiting blast radius if credentials are compromised. It directly satisfies the stem's constraint of minimum necessary access, unlike broader models such as role-based or discretionary access.

Why this answer

The principle of least privilege states that users (and processes) should be granted only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting the blast radius of a compromised account. It is a foundational access-control principle in cybersecurity and is explicitly tested in the ISC2 CC exam. Defense in depth, separation of duties, and need-to-know are related but distinct concepts.

Exam trap

The CC exam often tests the confusion between least privilege and need-to-know — both minimize access, but least privilege is about permissions/rights while need-to-know is about information access based on a specific requirement.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered-security strategy using multiple overlapping controls (firewalls, IDS, encryption, policies) rather than a permission-minimization principle. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error (e.g., one person approves, another pays), not about minimizing permissions. Option D is wrong because need-to-know restricts access to information based on whether a person requires it for a specific task — it is closely related but applies to data/information access rather than the broader permission scope of least privilege.

749
Multi-Selecthard

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

Select 3 answers
A.Document the breach, its effects, and the remedial actions taken.
B.Restore all affected systems from the latest full backup.
C.Communicate the breach to affected data subjects without undue delay if it poses a risk to their rights and freedoms.
D.Conduct a Business Impact Analysis (BIA) to determine the financial impact.
E.Notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
AnswersA, C, E

GDPR Article 33(5) requires controllers to document all breaches, including the facts, effects and remedial action taken. This record-keeping duty applies regardless of whether the breach is notifiable, satisfying the stem's requirement for a mandatory action following the PII incident.

Why this answer

Option A is correct because GDPR Article 33(5) requires the controller to document all personal data breaches, including the facts, effects, and remedial actions taken, so the supervisory authority can verify compliance. Option C is correct because GDPR Articles 33(1) and 34(1) require communication to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Option E is correct because GDPR Article 33(1) mandates notifying the relevant supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk.

Option B is not a GDPR requirement; restoring from backup is a general recovery practice, not a breach-notification obligation. Option D is not required by GDPR; a BIA is a business continuity tool, whereas GDPR requires a Data Protection Impact Assessment (DPIA) in certain cases, not a BIA for breach response.

Exam trap

The trap here is mixing general IT/BCP practices (backup restore, BIA) with GDPR-specific legal obligations — candidates who are strong in IT operations may pick B or D, but the exam expects the three explicit GDPR articles: 33(5) documentation, 34 communication, and 33(1) 72-hour notification.

750
MCQmedium

Which of the following is classified as sensitive PII?

A.Medical records
B.Email address
C.Telephone number
D.Date of birth
AnswerA

Medical records combine health information with identifying details, forming sensitive PII whose exposure causes harm or discrimination. Unlike names or email addresses alone, health data attracts stricter legal protection, making it the sensitive category here.

Why this answer

Sensitive PII is data that, if disclosed, could cause harm or discrimination — medical records qualify because they contain health information protected under HIPAA and similar regulations. Sensitive PII typically includes health data, financial account numbers, Social Security numbers, and biometric data. Email address, telephone number, and date of birth are considered non-sensitive PII because they are publicly available or low-risk in isolation.

Exam trap

The trap is assuming any personal identifier is 'sensitive' — candidates pick date of birth or email because they are personal, but the exam expects recognition that health, financial, and biometric data are the sensitive categories.

How to eliminate wrong answers

Option B is wrong because an email address alone is generally classified as non-sensitive PII — it is often public and does not reveal health, financial, or biometric information. Option C is wrong because a telephone number is non-sensitive PII; it is publicly listed in many directories and does not by itself cause harm if disclosed. Option D is wrong because date of birth, while personal, is typically non-sensitive PII unless combined with other identifiers like SSN or name — it is often available in public records.

Page 9

Page 10 of 14

Page 11