Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 751–825

989 questions total · 14pages · All types, answers revealed

Page 10

Page 11 of 14

Page 12
751
MCQmedium

A network administrator needs to allow secure remote access for teleworkers. Which VPN protocol provides the best confidentiality and integrity while using a single UDP port?

A.PPTP
B.SSL/TLS (OpenVPN)
C.L2TP/IPsec
D.IKEv2
AnswerB

OpenVPN uses a single UDP port and provides strong encryption.

Why this answer

SSL/TLS (OpenVPN) is correct because it provides robust confidentiality and integrity through TLS encryption (e.g., AES-256-GCM) and HMAC authentication, while operating over a single UDP port (typically 1194). This makes it ideal for teleworkers as it can traverse NAT and firewalls easily, unlike protocols that require multiple ports or IPsec's complex port/protocol handling.

Exam trap

ISC2 often tests the misconception that L2TP/IPsec is the best for secure remote access because it is commonly used in site-to-site VPNs, but the key constraint here is 'single UDP port,' which eliminates L2TP/IPsec and IKEv2, and PPTP is insecure.

How to eliminate wrong answers

Option A (PPTP) is wrong because it uses MPPE for encryption, which is based on RC4 and is considered weak, and it does not provide strong integrity (no HMAC); it also uses TCP port 1723 and GRE protocol 47, not a single UDP port. Option C (L2TP/IPsec) is wrong because it requires two UDP ports (500 for IKE and 4500 for NAT-T) plus ESP (protocol 50) or AH, and while it offers strong security, it does not use a single UDP port. Option D (IKEv2) is wrong because it uses UDP ports 500 and 4500 for IKE and ESP for data, and although it can be efficient, it does not operate over a single UDP port; it also typically requires IPsec for encryption, not a standalone VPN protocol on one port.

752
MCQhard

An organization requires that two separate administrators approve and implement changes to firewall rules. This practice enforces which security principle?

A.Least privilege
B.Defense in depth
C.Need to know
D.Separation of duties
AnswerD

Separation of duties splits a sensitive transaction across two administrators so no single identity can both approve and implement a firewall change. Requiring two separate approvals prevents unilateral modification, satisfying the control that removes single-person authority over critical configuration.

Why this answer

Requiring two separate administrators to approve and implement firewall rule changes enforces separation of duties. This principle ensures that no single individual has the authority to both authorize and execute a change, reducing the risk of unauthorized modifications or errors. In firewall management, this prevents a single admin from introducing malicious or misconfigured rules without oversight.

Exam trap

ISC2 often tests separation of duties by describing a scenario involving multiple people for a single task, and the trap is confusing it with least privilege, which focuses on limiting permissions rather than splitting responsibilities.

How to eliminate wrong answers

Option A is wrong because least privilege restricts user access rights to the minimum necessary for their role, but it does not require multiple approvals for a single action. Option B is wrong because defense in depth involves multiple layers of security controls (e.g., firewalls, IDS, encryption), not administrative approval workflows. Option C is wrong because need to know limits access to information based on job requirements, not the process of approving changes.

753
MCQeasy

A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?

A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
AnswerA

Confidentiality ensures information is not disclosed to unauthorized individuals, entities, or processes. Restricting patient record access to on-shift nurses and physicians directly limits disclosure to authorized parties, which is the core of confidentiality. This scenario is about preventing unauthorized viewing, not about keeping data accurate or available, so confidentiality is the principle being enforced.

Why this answer

The requirement limits access to patient records so only authorized on-shift nurses and physicians can view them, which is a disclosure control. Confidentiality is the security principle that prevents information from being disclosed to unauthorized individuals. Integrity addresses unauthorized changes, availability addresses timely access, and non-repudiation addresses proof of actions, so confidentiality is the correct principle.

Exam trap

The trap here is assuming that any access control example must be about availability because authorized users need access, when the requirement actually focuses on preventing unauthorized disclosure.

754
MCQeasy

An organization implements a policy where users must swipe their ID card and enter a PIN to access a secure room. This is an example of which access control principle?

A.Biometric authentication
B.Single-factor authentication
C.Multifactor authentication
D.Role-based access control
AnswerC

Multifactor authentication combines two or more distinct credential categories: something you have (the ID card) and something you know (the PIN). Swiping alone proves possession; the PIN proves knowledge. Requiring both satisfies the scenario's two-step access control, since neither factor alone authenticates the user.

Why this answer

The policy requires two distinct factors: something you have (the ID card) and something you know (the PIN). This combination of multiple authentication factors from different categories is the defining characteristic of multifactor authentication (MFA).

Exam trap

ISC2 often tests the distinction between authentication factors and authorization models, so the trap here is confusing multifactor authentication (which is about verifying identity) with role-based access control (which is about granting permissions after identity is verified).

How to eliminate wrong answers

Option A is wrong because biometric authentication relies on unique physical characteristics like fingerprints or iris scans, not on possession of an ID card or knowledge of a PIN. Option B is wrong because single-factor authentication uses only one type of credential, whereas this scenario uses two distinct factors. Option D is wrong because role-based access control (RBAC) governs authorization based on job roles, not the authentication method used to verify identity.

755
MCQmedium

A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?

A.Fingerprint and retina scan
B.Smart card and PIN
C.Username and password
D.Password and security question
AnswerB

A smart card is a possession factor (something the user has), and a PIN is a knowledge factor (something the user knows). Combining these two satisfies the requirement of using something the user knows and something the user has. This is a classic example of multi-factor authentication that strengthens identity verification by requiring two different types of credentials.

Why this answer

Multi-factor authentication requires combining two or more different types of factors: something you know, something you have, something you are, somewhere you are, or something you do. The scenario explicitly requires something the user knows and something the user has. A smart card (possession) and a PIN (knowledge) meet this requirement, while the other options use factors of the same type or do not include a possession factor.

Exam trap

The trap here is assuming that any two authentication methods constitute multi-factor authentication, when they must be of different factor types.

756
MCQeasy

Refer to the exhibit. The security principle demonstrated by the default policy is:

A.Separation of duties
B.Defense in depth
C.Need to know
D.Least privilege
AnswerD

The default policy grants only the minimum access needed to perform intended tasks, denying everything else unless explicitly permitted. This embodies least privilege, restricting permissions to what is strictly required rather than granting broad access.

Why this answer

Correct: D - Least privilege. The default DROP policy denies all traffic by default, allowing only explicitly permitted services, which follows the principle of least privilege. Option A (Separation of duties) is about dividing responsibilities among multiple people.

Option B (Defense in depth) is about multiple layers of security. Option C (Need to know) is about limiting access to information necessary for a job. None of these describes a default deny policy.

757
MCQmedium

A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?

A.Least privilege
B.Governance
C.Defense in depth
D.Separation of duties
AnswerB

A mandated change control board with formal approval is an oversight and decision-rights mechanism, which is governance. It directs and controls the organisation through defined authority, policies and accountability rather than implementing a technical safeguard, so it maps to the governance principle.

Why this answer

Governance is the set of processes, policies, and controls that direct and oversee how an organization manages its systems and risks. A formal change management process with a change control board (CCB) that reviews and approves production changes is a textbook example of governance — it establishes oversight, accountability, and decision-making authority. The policy itself is the governance artifact, and the CCB is the governing body enforcing it.

Exam trap

The trap here is confusing governance (oversight/approval processes) with separation of duties (splitting a single task among people) — both involve multiple people, but only governance describes a formal policy and approval body.

How to eliminate wrong answers

Option A is wrong because least privilege concerns granting users only the minimum access rights needed to perform their jobs, not the process for approving changes. Option C is wrong because defense in depth is a layered security architecture strategy (multiple overlapping controls), not an approval workflow. Option D is wrong because separation of duties means splitting a sensitive task among multiple people so no single person can complete it alone — a change approval board is oversight, not task-splitting of a single transaction.

758
MCQeasy

Refer to the exhibit. A user with this policy tries to list objects in a container but gets an access denied error. What is the most likely reason?

A.The policy does not grant the List permission on the container.
B.The resource identifier should include the container itself.
C.The effect should be Deny.
D.The user lacks encryption keys.
AnswerA

Object listing in an object storage container requires an explicit List permission on that container. The policy grants other actions but omits List, so the authorisation check fails and access is denied, regardless of the user's other entitlements.

Why this answer

The policy shown grants Read permission, which allows reading individual objects, but does not include the List permission on the container. Listing objects requires the List action on the container resource. Without this permission, the user receives an access denied error when attempting to list objects, even if they can read objects directly.

Exam trap

Vendor-neutral certification exams often test the distinction between permissions on individual objects and permissions on the container, trapping candidates who assume that granting Read on objects automatically allows listing the container.

How to eliminate wrong answers

Option B is wrong because the resource ARN in the policy already specifies the bucket itself (arn:aws:s3:::bucket1/*), and adding the bucket without the wildcard would not grant ListBucket permission; the missing action is the core issue. Option C is wrong because changing the effect to Deny would explicitly block access, not resolve the denied error; the policy currently has an Allow effect, which is correct for granting permissions. Option D is wrong because encryption keys are unrelated to S3 bucket listing permissions; the error is due to missing IAM policy permissions, not encryption key access.

759
Multi-Selecthard

A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)

Select 2 answers
A.Vulnerability disclosure by researcher
B.Decommissioning the vulnerable system
C.Testing the patch in a staging environment
D.Deploying the patch to production systems after approval
E.Immediately deploying patches to all systems
AnswersC, D

Staging validation installs the patch in a non-production environment to confirm it remediates the vulnerability without breaking applications. This is a recognised patch lifecycle step, satisfying the stem's requirement for a standard lifecycle activity performed before production deployment.

Why this answer

Option C (Testing the patch in a staging environment) is correct because the standard patch lifecycle includes a validation phase where patches are applied to a representative non-production environment to verify functionality, compatibility, and absence of regressions before wide deployment. Option D (Deploying the patch to production systems after approval) is correct because the lifecycle's deployment phase requires formal change approval and controlled rollout to production, often staged in rings or waves to limit blast radius. Option A is not part of the patch lifecycle itself; vulnerability disclosure is an input from the vulnerability management/research process that may trigger patching but is not a lifecycle step.

Option B is incorrect because decommissioning a system is a risk remediation alternative, not a patch lifecycle step. Option E is incorrect because immediately deploying patches to all systems bypasses testing and approval, violating change management and increasing the risk of outages or failed patches.

Exam trap

CC often tests the patch lifecycle steps, and candidates may incorrectly include vulnerability disclosure or immediate deployment as steps; the trap is confusing triggers or emergency actions with standard lifecycle phases.

760
MCQhard

A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?

A.Malware is deleting logs
B.SIEM is consuming logs too quickly
C.Log rotation settings are misconfigured
D.Disk space is insufficient
AnswerC

Misconfigured log rotation overwrites older entries once size or age thresholds trigger, directly violating the retention period the analyst expects. Rotation controls when files are archived or deleted, so incorrect limits cause premature loss before the required retention window elapses, matching the stem's overwriting symptom precisely.

Why this answer

The most likely cause is that log rotation settings are misconfigured. Log rotation is designed to archive and remove old logs based on size or time. If the rotation settings are too aggressive (e.g., rotating too frequently or keeping too few files), logs may be overwritten or deleted before the retention period ends.

This is a common configuration issue, not necessarily malicious.

Exam trap

CC often tests log management; candidates may jump to security breaches or disk space, but misconfigured log rotation is a common cause of premature log loss.

How to eliminate wrong answers

Option A is wrong because while malware could delete logs, it is less likely than a misconfiguration, especially if the issue is systematic and not accompanied by other signs of compromise. Option B is wrong because a SIEM consuming logs too quickly would not cause logs to be overwritten; it would collect them, but the original logs would remain until rotated. Option D is wrong because insufficient disk space would cause logging to stop or errors, but not necessarily overwrite logs before retention; log rotation would typically handle disk space by deleting old logs, but if misconfigured, it could delete too soon.

761
Multi-Selecteasy

Which TWO are key outputs of a Business Impact Analysis (BIA)?

Select 2 answers
A.List of critical business processes
B.Password policy
C.Network diagram
D.Risk register
E.Recovery Time Objectives
AnswersA, E

A BIA identifies and documents the business processes whose disruption most affects the organisation, ranking them by criticality. This list drives subsequent recovery prioritisation, satisfying the BIA's core purpose of establishing what must be restored first after a disruptive incident.

Why this answer

A Business Impact Analysis (BIA) identifies and prioritizes the business functions whose disruption would most affect the organization, so option A, the list of critical business processes, is a core output because it establishes what must be protected and restored first. Option E, Recovery Time Objectives (RTOs), is also a key BIA output because the BIA determines the maximum tolerable downtime for each critical process, which then drives continuity and recovery planning targets. By contrast, option B (password policy) is an access-control/security governance artifact, not a BIA deliverable.

Option C (network diagram) is a technical architecture document produced by network or infrastructure teams, not by a BIA. Option D (risk register) is an output of risk assessment/risk management processes, where risks are logged and tracked; while a BIA may inform risk analysis, the risk register itself is not a primary BIA output.

Exam trap

The trap here is conflating BIA outputs with general risk-management or security artifacts; candidates often pick 'risk register' because BIA and risk assessment are frequently discussed together in BCP training.

762
MCQmedium

An organization has a policy that all servers must have security patches applied within 30 days of release. Which of the following is the best practice for patching?

A.Skip patches that have not been widely tested
B.Apply patches to all servers simultaneously
C.Test patches in a non-production environment before deploying to production
D.Only apply critical patches
AnswerC

Testing patches in a non-production environment first satisfies the 30-day policy while catching compatibility regressions before production deployment. This staged approach prevents patch-induced outages on critical servers, which is the best practise balancing the mandated deadline against operational risk.

Why this answer

Testing patches in a non-production environment first allows the organization to identify compatibility issues, performance regressions, or conflicts with existing software before risking production systems. This aligns with the change management principle of validating changes in a controlled setting, ensuring that the 30-day patching deadline can be met without introducing instability. Skipping testing (A) or applying patches simultaneously (B) could lead to widespread outages, while only applying critical patches (D) would leave the organization exposed to non-critical vulnerabilities that could be chained in an attack.

Exam trap

ISC2 often tests the misconception that 'all patches must be applied immediately' or that 'critical patches are the only priority,' but the trap here is that candidates overlook the necessity of a controlled testing phase to prevent production outages, even when a strict 30-day deadline exists.

How to eliminate wrong answers

Option A is wrong because skipping patches that have not been widely tested leaves the organization vulnerable to known exploits, and the policy requires all patches to be applied within 30 days, not just widely tested ones. Option B is wrong because applying patches to all servers simultaneously can cause cascading failures if a patch introduces a bug, and it violates the principle of staggered rollouts to maintain service availability. Option D is wrong because only applying critical patches ignores the policy's requirement for all security patches, and non-critical patches often address vulnerabilities that can be leveraged in multi-stage attacks (e.g., privilege escalation).

763
Multi-Selectmedium

An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)

Select 2 answers
A.Preparation
B.Business impact analysis
C.Recovery
D.Risk assessment
E.Vulnerability scanning
AnswersA, C

Preparation establishes the capabilities required before an incident occurs, including incident response policy, tooling, communications plans and trained personnel. NIST SP 800-61 places Preparation as the first lifecycle phase, directly satisfying the stem's requirement for a framework-defined phase that precedes detection and analysis, containment, eradication, recovery and post-incident activity.

Why this answer

Option A (Preparation) is correct because the NIST SP 800-61 incident response lifecycle begins with the Preparation phase, which covers establishing an IR capability, acquiring tools and resources, and developing policies and procedures before an incident occurs. Option C (Recovery) is correct because NIST defines Recovery as the phase in which systems are restored to normal operation, data is validated, and lessons learned are captured after containment and eradication. The other options do not belong: Business impact analysis (B) is part of business continuity planning, Risk assessment (D) is a risk management activity, and Vulnerability scanning (E) is a technical security control, none of which are named phases of the NIST incident response lifecycle.

Exam trap

The trap is that BIA and Risk Assessment sound like security lifecycle activities, so candidates pick them — but the exam is asking specifically for NIST SP 800-61 IR phases, not general security management activities.

764
MCQmedium

Which of the following is a security concern associated with the Telnet protocol?

A.It transmits data in cleartext.
B.It requires certificate management.
C.It is vulnerable to DNS poisoning.
D.It uses encryption that is too weak.
AnswerA

Telnet sends all session data, including credentials and commands, as unencrypted cleartext across the network. Anyone capturing traffic on the path can read or alter it, which is the fundamental security weakness distinguishing Telnet from SSH.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext, making it vulnerable to eavesdropping and credential theft. This lack of encryption is the primary security concern associated with Telnet. Other options do not accurately describe Telnet's security weaknesses.

Exam trap

CC often tests protocol security; candidates might confuse Telnet with protocols that use weak encryption, but Telnet uses no encryption at all, making 'cleartext' the correct concern.

How to eliminate wrong answers

Option B is wrong because Telnet does not use certificates; it has no built-in encryption or certificate management. Option C is wrong because while Telnet can be affected by DNS poisoning like any network protocol, it is not a specific security concern unique to Telnet; the core issue is cleartext transmission. Option D is wrong because Telnet does not use encryption at all, so it cannot be said to use weak encryption; it uses no encryption.

765
MCQeasy

A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?

A.Easier maintenance
B.Faster recovery time
C.Greater security
D.Lower cost
AnswerB

A hot site maintains fully configured, synchronised hardware and near-real-time data replication, so operations resume within hours rather than the days or weeks a cold site requires. This directly satisfies the stem's demand for the primary advantage: minimal recovery time.

Why this answer

A hot site is a fully operational duplicate of the primary data center, complete with live servers, storage, networking, and synchronized data. This eliminates the need to procure and configure hardware after a disaster, enabling recovery in minutes or hours rather than days or weeks. The primary advantage is therefore a significantly faster recovery time objective (RTO) compared to a cold site, which has no pre-installed equipment.

Exam trap

ISC2 often tests the distinction that a hot site's primary benefit is speed of recovery (RTO), not cost or security, and candidates mistakenly choose 'lower cost' because they confuse hot sites with warm sites or assume all DR sites are expensive.

How to eliminate wrong answers

Option A is wrong because hot sites require more complex maintenance, including continuous data replication and live system updates, whereas cold sites have minimal upkeep. Option C is wrong because a hot site does not inherently provide greater security; security depends on the specific controls implemented at each site, and both hot and cold sites can be equally secure. Option D is wrong because a hot site is far more expensive than a cold site due to the cost of maintaining duplicate hardware, software licenses, and ongoing data synchronization.

766
MCQmedium

A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?

A.Defense in depth
B.Fail-safe
C.Default deny
D.Least privilege
AnswerB

Fail-safe design ensures a component failure defaults to a secure, non-compromising state rather than an open one. This satisfies the stem's requirement that server failure must not cause a breach, because the system denies access instead of permitting it when the failure occurs.

Why this answer

Fail-safe ensures that when a server fails, it defaults to a secure state (e.g., closed ports, denied access) rather than an insecure one. This prevents a security breach by guaranteeing that failure does not inadvertently expose data or allow unauthorized access. In the CC exam, this principle is directly tied to designing systems that remain secure even under fault conditions.

Exam trap

ISC2 often tests fail-safe by contrasting it with 'fail-open' scenarios, where candidates mistakenly think a failed server should continue operating (e.g., allowing traffic) to maintain availability, but the principle prioritizes security over availability in failure states.

How to eliminate wrong answers

Option A is wrong because defense in depth is a layered security strategy (e.g., firewalls, IDS, encryption) that reduces risk but does not specifically address what happens when a server fails. Option C is wrong because default deny is an access control rule that denies all traffic unless explicitly allowed, which is a configuration policy, not a principle for handling server failure scenarios. Option D is wrong because least privilege limits user/process permissions to the minimum necessary, which reduces attack surface but does not dictate the system's behavior upon failure.

767
Drag & Dropmedium

Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Proper disposal includes identification, backup, sanitization, verification, and documentation.

768
MCQeasy

An organization wants to ensure that no single employee can both request and approve a payment. Which access control principle does this enforce?

A.Separation of duties
B.Least privilege
C.Need to know
D.Defense in depth
AnswerA

Separation of duties splits critical tasks across different individuals, so the same employee cannot both request and approve a payment. This directly enforces the stem's constraint by preventing one person from completing an entire sensitive transaction alone, thereby reducing fraud risk.

Why this answer

Separation of duties (SoD) is the access control principle that prevents a single individual from having conflicting permissions, such as both requesting and approving a payment. By splitting the payment lifecycle into distinct roles (e.g., requester vs. approver), the organization enforces a dual-control mechanism that reduces the risk of fraud or error. This is commonly implemented in financial systems using role-based access control (RBAC) where the 'payment request' and 'payment approval' roles are mutually exclusive.

Exam trap

ISC2 often tests the confusion between 'separation of duties' and 'least privilege' because both limit user capabilities, but the trap is that least privilege reduces the scope of permissions for a single user while separation of duties divides a critical process across multiple users.

How to eliminate wrong answers

Option B (Least privilege) is wrong because it focuses on granting only the minimum permissions necessary to perform a job function, not on splitting conflicting tasks across multiple people. Option C (Need to know) is wrong because it restricts access to data based on whether it is required for a specific task, not on preventing a single user from holding two conflicting functional roles. Option D (Defense in depth) is wrong because it describes a layered security architecture (e.g., firewalls, IDS, encryption) rather than a principle for segregating duties within a process.

769
MCQeasy

What is the primary purpose of identification in the context of access control?

A.To grant permissions to resources
B.To verify the identity of the user
C.To record user activities
D.To claim an identity
AnswerD

Identification is the process whereby a subject asserts an identity to a system, typically by presenting a username, smart card or biometric characteristic, without yet proving ownership. This claim satisfies the stem's requirement for the primary purpose: establishing who the subject purports to be, before authentication verifies that claim.

Why this answer

In access control, identification is the process by which a user claims an identity (e.g., by providing a username or account name). It is distinct from authentication, which verifies that claim. The primary purpose of identification is to assert who you are, not to prove it.

Exam trap

ISC2 often tests the distinction between identification (claiming an identity) and authentication (proving that identity), so candidates mistakenly select 'To verify the identity of the user' (Option B) because they conflate the two steps.

How to eliminate wrong answers

Option A is wrong because granting permissions to resources is the function of authorization, not identification. Option B is wrong because verifying the identity of the user is the purpose of authentication, which typically follows identification. Option C is wrong because recording user activities is the role of accounting (auditing), not identification.

770
MCQhard

During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?

A.Activate the disaster recovery plan
B.Contact the vendor
C.Restore from offsite tape
D.Order replacement hardware
AnswerA

The storage array failure has made backups unavailable, breaching the assumptions underpinning normal recovery. Escalating to the disaster recovery plan first invokes the documented alternate-site procedures and recovery team, rather than attempting in-place restoration against failed infrastructure.

Why this answer

When backup systems are unavailable due to a storage array failure, the first action must be to activate the disaster recovery plan (DRP). The DRP is the predefined, documented set of procedures that guides the organization through the recovery process, including escalation, communication, and alternative recovery methods. Without activating the plan, subsequent steps like contacting vendors or restoring from tape lack coordination and may violate recovery time objectives (RTOs) and recovery point objectives (RPOs).

Exam trap

ISC2 often tests the principle that the disaster recovery plan must be activated before any technical recovery action is taken, trapping candidates who jump to a specific recovery step like restoring from tape or contacting a vendor without first following the documented process.

How to eliminate wrong answers

Option B is wrong because contacting the vendor is a tactical step that should be performed after the DRP is activated, as the plan specifies when and how to engage vendors. Option C is wrong because restoring from offsite tape is a specific recovery action that must be directed by the DRP, which first requires assessing the situation and authorizing the restore process. Option D is wrong because ordering replacement hardware is a procurement action that occurs later in the recovery timeline, after the DRP has been activated and a gap analysis has been performed.

771
MCQhard

A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?

A.A fingerprint scan used alone to unlock the workstation
B.A password combined with a security question about the user's first pet
C.A password combined with a one-time code generated by a soft token app on the user's phone
D.A username and a strong password used together
AnswerC

A password is something the user knows, and a one-time code produced by an app on their enrolled phone is something the user possesses. Because the app runs on a device rather than dedicated hardware, this meets the two-factor requirement without smart cards or physical tokens. The two factors come from different categories, which is precisely what the scenario demands.

Why this answer

Two-factor authentication requires factors from different categories. A password supplies the knowledge factor, and a one-time code from an app on the user's enrolled phone supplies the possession factor. Because the app is software rather than dedicated hardware, no smart card or physical token is needed, which satisfies the constraint while still delivering genuine two-factor protection.

Exam trap

The trap here is counting two prompts as two factors, when a password plus a security question or two passwords are both knowledge-based and count as only one factor category.

772
Multi-Selectmedium

Which TWO of the following are valid types of disaster recovery tests?

Select 2 answers
A.Tabletop exercise.
B.Full-scale simulation without prior notification.
C.Unit testing of individual applications.
D.Vulnerability scan.
E.Parallel test between primary and backup site.
AnswersA, E

A tabletop exercise is a discussion-based test where stakeholders walk through recovery procedures without activating systems, satisfying the requirement for a valid disaster recovery test type. It validates plans, roles and decision-making cheaply, unlike full failover tests, and is formally recognised alongside simulation and parallel testing in DR planning frameworks.

Why this answer

A tabletop exercise (A) is a valid disaster recovery test in which the DR team walks through the plan in a discussion-based setting to validate roles, procedures, and decision-making without activating systems. A parallel test (E) is also valid: the backup site is brought online and run concurrently with the primary site to verify recovery capability while normal production continues, without a disruptive failover. The other options are not DR test types: a full-scale simulation without prior notification (B) is not a recognized test category (full-scale exercises are typically announced and planned), unit testing (C) verifies individual application components rather than end-to-end recovery, and a vulnerability scan (D) is a security assessment, not a DR test.

Exam trap

CC often tests the definitions of DR test types; candidates may confuse parallel tests with full-scale simulations, but the key is that parallel tests run both sites simultaneously, while full-scale simulations without notification are not standard.

773
MCQeasy

An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?

A.Maximum Tolerable Downtime (MTD)
B.Service Level Agreement (SLA)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerD

Recovery Time Objective defines the maximum acceptable duration to restore the database after disruption. Specifying an RTO of two hours directly translates the stated restoration constraint into a measurable target that drives backup, replication and failover design.

Why this answer

Recovery Time Objective (RTO) defines the maximum acceptable time to restore a system or service after a disruption. A requirement to restore a critical database within 2 hours is exactly an RTO. RTO drives backup, replication, and failover design decisions.

Exam trap

CC often tests the RTO vs RPO distinction — candidates pick RPO because both involve recovery, but RPO is about acceptable data loss (time), while RTO is about acceptable downtime duration.

How to eliminate wrong answers

Option A is wrong because Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable before unacceptable consequences occur — it is broader than the technical restore time and typically encompasses RTO plus other recovery activities. Option B is wrong because a Service Level Agreement is a contractual document specifying service expectations, not a specific recovery-time metric. Option C is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (how far back the last recoverable data point is), not how long restoration takes.

774
MCQhard

Which of the following best describes the difference between due care and due diligence in security governance?

A.Due care is proactive, due diligence is reactive
B.They are synonymous
C.Due care applies to vendors; due diligence applies to employees
D.Due care is the minimum standard of care; due diligence is the investigation and assessment
AnswerD

Due care is the minimum standard of care an organisation must exercise, while due diligence is the ongoing investigation and assessment underpinning it. This distinction separates the duty itself from the research activity that informs it.

Why this answer

Due care refers to the minimum standard of care that an organization must exercise to protect its assets, often defined by laws, regulations, or industry best practices. Due diligence is the ongoing process of investigation, assessment, and verification to ensure that due care is maintained. In security governance, due care is the baseline, while due diligence is the active effort to identify and mitigate risks.

Exam trap

The trap is that candidates often think due care and due diligence are interchangeable or that one is proactive and the other reactive; the exam tests the precise definitions.

How to eliminate wrong answers

Option A is wrong because due care is not inherently proactive or reactive; it is a standard, while due diligence involves proactive investigation. Option B is wrong because they are distinct concepts; due care is the standard, due diligence is the process. Option C is wrong because both due care and due diligence apply to all aspects of an organization, including vendors and employees, not exclusively one or the other.

775
Multi-Selectmedium

Which TWO are key components of an effective incident response plan? (Select TWO.)

Select 2 answers
A.Business continuity procedures
B.List of forensic tools
C.Backup verification schedule
D.Communication plan for stakeholders
E.Post-incident review process
AnswersD, E

A stakeholder communication plan defines who is notified, when, and through which channels during an incident, ensuring coordinated escalation and regulatory notification. This satisfies the stem's requirement for a key component of an effective incident response plan.

Why this answer

A communication plan for stakeholders (D) is a core component because an incident response plan must define who notifies executives, legal, PR, regulators, and customers, along with escalation paths, contact rosters, and approved messaging to control reputational and regulatory impact. A post-incident review process (E) is also essential because it establishes the lessons-learned/after-action review that captures root cause, timeline, and remediation items to improve future response. The other options, while valuable in related programs, are not the two key components of an incident response plan: business continuity procedures (A) belong to BC/DR planning, a list of forensic tools (B) is a supporting resource rather than a plan component, and a backup verification schedule (C) is an operational control within backup/recovery management.

Exam trap

ISC2 often tests the distinction between incident response and adjacent processes (like business continuity or disaster recovery) to see if candidates confuse overlapping but distinct security operations concepts.

776
MCQeasy

An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?

A.Phishing
B.Vishing
C.Spear phishing
D.Whaling
AnswerA

This is a classic phishing attempt: a fraudulent email impersonating IT, using a look-alike domain to trick the recipient into revealing credentials. The generic nature and the urgency of a mailbox upgrade are common phishing tactics. Phishing is the broad category that accurately describes this untargeted credential-harvesting attack.

Why this answer

The email impersonates IT, uses a deceptive domain, and requests credential verification, which are hallmarks of phishing. It is not targeted enough to be spear phishing or whaling, and it does not use voice communication. Phishing remains the most accurate classification for this generic credential-harvesting attempt.

Exam trap

The trap here is overcomplicating the classification by focusing on the employee recipient, when the attack lacks the personalization of spear phishing and is simply a generic phishing email.

777
MCQmedium

An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?

A.HTTP
B.SSH
C.Telnet
D.FTP
AnswerB

SSH encrypts the entire session, including credentials and commands, over TCP port 22, satisfying the requirement for secure remote command-line access. Unlike Telnet, which transmits data in plaintext, SSH provides confidentiality and integrity, making it the appropriate protocol for managing network devices from untrusted remote locations.

Why this answer

SSH (Secure Shell) provides encrypted command-line access to network devices, ensuring confidentiality and integrity of the session. It is the standard protocol for secure remote administration. The other protocols either lack encryption or are not designed for command-line access.

Exam trap

CC often tests secure alternatives; candidates might choose Telnet for command-line access due to familiarity, but the question emphasizes secure management, making SSH the correct choice.

How to eliminate wrong answers

Option A is wrong because HTTP is used for web traffic and does not provide command-line access; it is also unencrypted by default. Option C is wrong because Telnet provides command-line access but transmits data in cleartext, making it insecure for remote management. Option D is wrong because FTP is used for file transfer, not command-line access, and it also lacks encryption in its basic form.

778
Multi-Selectmedium

A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)

Select 2 answers
A.Endpoint detection and response (EDR) telemetry
B.Firewall deny logs
C.NetFlow records
D.DHCP lease logs
E.Operating system process accounting or audit logs
AnswersA, E

EDR collects process creation, command-line arguments, parent-child relationships, file and registry changes, and network connections from the endpoint. This telemetry directly shows what executed and how, making it the strongest source for spotting suspicious process behavior such as an office document spawning a scripting interpreter. It also supports historical hunting, so analysts can trace the full execution chain rather than only a single alert.

Why this answer

Detecting suspicious process execution requires host-based visibility into what actually ran. EDR telemetry provides rich process-level detail including command lines and parent-child relationships, while OS process accounting or audit logs offer a lighter but still direct record of executions. Network-oriented sources such as NetFlow, firewall deny logs, and DHCP lease logs describe traffic or addressing, not the processes on the endpoint, so they serve as supporting context rather than primary execution evidence.

Exam trap

The trap here is treating network metadata as equivalent to host telemetry; only sources that record executions on the endpoint directly answer what process ran.

779
MCQhard

A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?

A.Reduce RTO to 1 hour
B.Increase backup frequency
C.Implement synchronous replication
D.Perform restoration testing quarterly
AnswerC

Synchronous replication writes to both primary and secondary sites before acknowledging the transaction, giving near-zero data loss and rapid failover within the two-hour recovery time objective. It directly satisfies the maximum tolerable downtime constraint that the three-hour restore breaches.

Why this answer

The maximum tolerable downtime (MTD) is 2 hours, but the current restore process takes 3 hours, which exceeds the MTD. Synchronous replication writes data to both primary and secondary storage simultaneously, ensuring that the secondary copy is always current and can be failed over to in seconds or minutes, not hours. This reduces the recovery time objective (RTO) to well under the required 2 hours, directly addressing the gap.

Exam trap

ISC2 often tests the distinction between RTO and RPO, and the trap here is that candidates confuse backup frequency (which affects RPO) with restore speed (which affects RTO), leading them to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because reducing the RTO to 1 hour does not fix the underlying problem—the restore process still takes 3 hours, and simply changing a target number without improving the technology does not achieve compliance. Option B is wrong because increasing backup frequency reduces the recovery point objective (RPO), not the recovery time objective (RTO); the restore time remains 3 hours regardless of how often backups are taken. Option D is wrong because quarterly restoration testing validates that backups work but does not reduce the 3-hour restore time; testing alone cannot bring the RTO below the MTD.

780
MCQmedium

A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?

A.Something you know
B.Something you are
C.Something you have
D.Somewhere you are
AnswerC

Something you have is a possession factor, and the smart card is a physical token the employee holds and inserts into a reader. The card performs cryptographic operations with a private key that never leaves it, proving possession. This is the classic example of a possession factor used in multifactor authentication, distinct from memorized secrets or biometric traits.

Why this answer

A smart card is a possession factor because the employee must physically hold and present the token, and the embedded private key enables cryptographic proof that the token is present. It is commonly combined with a PIN or password to achieve multifactor authentication, pairing what the user has with what the user knows.

Exam trap

The trap here is treating the smart card as a knowledge factor simply because it may be unlocked with a PIN, when the device itself demonstrates possession rather than memorized knowledge.

781
Multi-Selecteasy

Which TWO of the following are common indicators of a phishing email?

Select 2 answers
A.Professional formatting with correct grammar
B.Presence of a file attachment
C.Use of the recipient's full name in the greeting
D.Unexpected sender or email address
E.Urgent language requesting immediate action
AnswersD, E

A sender address that does not match the purported organisation, or arrives unexpectedly, indicates spoofing or domain impersonation. This satisfies the stem's indicator criterion because legitimate correspondence normally originates from a recognisable, expected address, making the mismatch a reliable phishing signal.

Why this answer

Option D is correct because phishing emails frequently originate from spoofed or look-alike domains that the recipient does not recognize, so an unexpected sender or mismatched email address is a classic red flag. Option E is correct because attackers rely on social engineering that creates urgency—phrases like "act now" or "your account will be closed"—to pressure victims into clicking links or disclosing credentials before they scrutinize the message. In contrast, option A is not an indicator since professional formatting and correct grammar are typical of legitimate email and, if anything, poor grammar is the more common phishing clue.

Option B is not reliable because legitimate business email routinely carries attachments, so an attachment alone proves nothing. Option C is likewise not an indicator, as using the recipient's full name is normal, personalized behavior in genuine correspondence and does not by itself signal phishing.

Exam trap

The trap is selecting options that seem 'suspicious' in general (like attachments or full-name greetings) without recognizing that phishing indicators must be specific anomalies — attachments and personalization are common in legitimate email, so only the unexpected sender and urgency are reliable indicators.

782
MCQeasy

Which of the following is an example of a Type 2 authentication factor?

A.PIN
B.Password
C.Smart card
D.Fingerprint
AnswerC

A smart card is something the user possesses, which defines a Type 2 possession factor. It is not a knowledge factor (Type 1) nor an inherence factor (Type 3), so it satisfies the question's requirement for a possession-based example.

Why this answer

A Type 2 authentication factor is something you have, such as a physical device or token. A smart card is a physical object that a user possesses and inserts into a reader or taps, making it a classic example of a possession factor. Therefore, smart card is the correct answer.

Exam trap

The trap here is confusing something you have with something you know or are; candidates often misclassify a smart card as something you know because it may require a PIN, but the card itself is a possession factor.

How to eliminate wrong answers

Option A is wrong because a PIN is something you know, which is a Type 1 factor. Option B is wrong because a password is also something you know, a Type 1 factor. Option D is wrong because a fingerprint is something you are, a Type 3 factor (inherence).

783
MCQhard

A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?

A.Passive tap
B.Active tap
C.Regenerating tap
D.Aggregating tap
AnswerA

A passive tap, also known as a break-out tap, splits the signal optically or electrically without regenerating it. It forwards all traffic, including errored packets, because it does not interpret or filter the data. This makes it ideal for capturing a complete copy of traffic for analysis, including frames with errors.

Why this answer

A passive tap splits the signal without regeneration, ensuring that all traffic, including errored packets, is copied to the monitoring port. Active and regenerating taps may filter or drop errored frames. For complete traffic capture, a passive tap is the correct choice.

Exam trap

The trap here is confusing active and passive taps; active taps regenerate signals and may drop errors, while passive taps provide a true copy of all traffic, including errors.

784
MCQmedium

A company's security policy states that only staff in the finance department may access the general ledger, and that access must be reviewed every quarter. An auditor finds that two former finance employees still hold active accounts with ledger permissions. Which concept has the organization FAILED to apply?

A.Non-repudiation
B.Need to know
C.Integrity
D.Availability
AnswerB

Need to know means access to information is granted only to those who require it to perform their duties. The two former employees no longer work in finance, so they have no business need for ledger access, yet their permissions persist. The failure to remove access when the need ended is the essence of a need-to-know violation and a common audit finding.

Why this answer

Need to know restricts access to information strictly to individuals whose duties require it. Former finance employees have no current business justification for ledger permissions, so their active accounts violate this principle regardless of whether they have logged in. The quarterly review requirement exists precisely to catch and remove such stale entitlements before they become an insider threat.

Exam trap

The trap here is focusing on the missed quarterly review as the only failure, when the deeper issue is that people without a current business need retain access at all.

785
MCQmedium

Which of the following is an example of a Type 1 authentication factor?

A.One-time password (OTP) token
B.PIN code
C.Smart card
D.Fingerprint scan
AnswerB

A PIN code is something you know, which is the defining characteristic of a Type 1 authentication factor. Type 1 factors rely on knowledge, distinguishing them from Type 2 (possession) and Type 3 (inherence) factors.

Why this answer

A Type 1 authentication factor is something you know, such as a password, PIN, or passphrase. A PIN code is a memorized secret, so it is a classic example of a knowledge-based factor. The other options represent different factor types: OTP token and smart card are something you have (Type 2), and fingerprint scan is something you are (Type 3).

Exam trap

The trap here is confusing authentication factor types: candidates often mistake a PIN for a possession factor because it's used with a card, but it's actually a knowledge factor.

How to eliminate wrong answers

Option A is wrong because an OTP token is a physical device that generates one-time passwords, making it a possession factor (Type 2), not a knowledge factor. Option C is wrong because a smart card is a physical object you possess, which is a Type 2 factor. Option D is wrong because a fingerprint scan is a biometric characteristic, which is a Type 3 factor (something you are).

786
MCQmedium

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

A.Application logs
B.Firewall logs
C.System logs
D.Authentication logs
AnswerD

Authentication logs capture the granular Kerberos and NTLM events on the domain controller, recording each failed attempt (Event ID 4625) and the subsequent successful logon (Event ID 4624) with source IP, account name and logon type. This directly satisfies the stem's requirement for detailed evidence of the brute-force pattern.

Why this answer

Authentication logs record login attempts, successes, failures, source IP addresses, timestamps, and account names, making them the definitive source for investigating repeated failed logins followed by a successful login. Domain controllers log authentication events (e.g., Windows Security Event ID 4625 for failed logon and 4624 for successful logon) that directly capture this pattern. This is the primary evidence source for credential-based attacks like brute force or password spraying.

Exam trap

The trap is assuming firewall logs capture login activity because they show IP addresses and connection attempts — candidates must recognize that only authentication logs record the success/failure outcome of credential-based logon events.

How to eliminate wrong answers

Option A is wrong because application logs record events within a specific application (errors, transactions, user actions) and would not typically capture domain controller authentication events across the network. Option B is wrong because firewall logs record network traffic flows (allowed/blocked connections, ports, IPs) but do not show whether a login succeeded or failed at the authentication layer. Option C is wrong because system logs record OS-level events like service starts, driver loads, and hardware errors — not user authentication activity, which is captured in security/authentication logs.

787
MCQeasy

A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?

A.Need to know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties splits a sensitive task across multiple people so no single individual controls the whole transaction. Requiring two approvals for transfers over $10,000 enforces this by preventing unilateral action and reducing fraud risk.

Why this answer

Separation of duties (SoD) requires that a sensitive task be divided among multiple people so that no single individual can complete it alone. Requiring two employees to approve any financial transaction over $10,000 is a classic SoD control that prevents fraud and errors by ensuring one person cannot unilaterally authorize a payment.

Exam trap

The trap is confusing separation of duties with least privilege — both restrict what a user can do, but SoD specifically requires multiple people to complete a task, while least privilege limits a single user's permissions.

How to eliminate wrong answers

Option A is wrong because need to know limits access to information based on job requirements, not the number of approvers for a transaction. Option B is wrong because defense in depth is a layered control strategy, not a dual-approval requirement. Option C is wrong because least privilege limits the permissions a user has, but does not require two people to approve a single action.

788
MCQeasy

A small retail company is developing its first incident response plan. The owner asks which phase of the incident response lifecycle involves developing policies, assigning roles, and acquiring tools. Which phase should be recommended?

A.Containment, eradication, and recovery
B.Preparation
C.Post-incident activity
D.Detection and analysis
AnswerB

Preparation is the first phase of the incident response lifecycle. It involves establishing policies, defining roles and responsibilities, training personnel, and acquiring necessary tools and resources. For a small retail company, this phase ensures they are ready to handle incidents before they occur. Without preparation, response efforts are ad hoc and likely ineffective, making this the correct recommendation.

Why this answer

The preparation phase is where organizations develop incident response policies, define team roles, and acquire tools and resources. It is the foundation of the incident response lifecycle. Detection and analysis, containment/eradication/recovery, and post-incident activity are subsequent phases that depend on preparation.

For a small retail company starting from scratch, preparation is the essential first step.

Exam trap

The trap here is confusing the preparation phase with later phases, such as detection or post-incident activity, where policies and tools are used but not initially developed.

789
MCQhard

A security manager is assessing the risk of a new web application. The manager identifies that the application has a known SQL injection vulnerability, and that attackers frequently scan for such flaws. Which term best describes the SQL injection flaw itself?

A.Risk
B.Vulnerability
C.Impact
D.Threat
AnswerB

A vulnerability is a weakness in a system that can be exploited by a threat. The SQL injection flaw is a specific weakness in the web application's code that allows attackers to manipulate database queries. It is the vulnerability that, if exploited, could lead to data breaches. Thus, the flaw itself is correctly termed a vulnerability.

Why this answer

The correct answer is vulnerability. A vulnerability is a weakness or flaw in a system that can be exploited by a threat. The SQL injection flaw is a specific weakness in the web application.

Threat refers to the attacker or attack method, risk is the potential for loss, and impact is the resulting harm. Therefore, the flaw itself is a vulnerability.

Exam trap

The trap here is confusing vulnerability with risk, assuming that the flaw is the risk rather than the weakness that contributes to risk.

790
MCQmedium

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

A.Authentication
B.Availability
C.Integrity
D.Confidentiality
AnswerC

Hashing produces a fixed-length digest that changes if even one bit of the file is modified, so recomputing and comparing it detects tampering. This directly satisfies the integrity goal of ensuring the downloaded file has not been altered in transit or at rest.

Why this answer

Hashing ensures data integrity by detecting changes.

791
MCQeasy

An organization's security policy requires that all employees change their passwords every 90 days. This is an example of which type of security control?

A.Deterrent control
B.Detective control
C.Preventive control
D.Corrective control
AnswerC

Mandatory 90-day password rotation is an administrative preventive control: it enforces a policy before access occurs, reducing the window in which a compromised credential remains valid. It satisfies the stem's requirement to classify the control type, not to detect or correct incidents after they happen.

Why this answer

Password expiration policies, such as requiring a change every 90 days, are classified as preventive controls because they proactively reduce the risk of credential compromise by limiting the window of opportunity for an attacker to use a stolen or guessed password. This control enforces a security baseline before any unauthorized access can occur, directly preventing prolonged use of compromised credentials.

Exam trap

ISC2 often tests the distinction between preventive and deterrent controls, where candidates mistakenly classify password policies as deterrent because they 'discourage' sharing, but the key is that password expiration actively blocks access, not just discourages behavior.

How to eliminate wrong answers

Option A is wrong because a deterrent control is designed to discourage malicious behavior through the threat of consequences (e.g., warning banners, surveillance cameras), not to enforce a mandatory action like password rotation. Option B is wrong because a detective control identifies and logs security events after they occur (e.g., audit logs, intrusion detection systems), whereas password expiration proactively prevents stale credentials from being used. Option D is wrong because a corrective control remediates damage after an incident (e.g., restoring from backup, patching a vulnerability), not a scheduled administrative action to maintain security posture.

792
MCQhard

According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?

A.Recovery
B.Post-incident activity
C.Detection and analysis
D.Preparation
AnswerA

Recovery follows containment and eradication in the NIST 800-61 lifecycle, restoring affected systems to normal operation and validating they are free of residual threats before returning them to production. This directly satisfies the stem's sequencing constraint, as the standard orders the phases: preparation, detection and analysis, containment, eradication, recovery, then post-incident activity.

Why this answer

According to the NIST 800-61 incident response lifecycle, the phases are Preparation, Detection & Analysis, Containment/Eradication, and Recovery. After containment (isolating the threat) and eradication (removing malware, patching vulnerabilities), the next phase is Recovery, where systems are carefully restored to normal operations, often using clean backups and verifying system integrity before reconnecting to the network.

Exam trap

ISC2 often tests the exact NIST 800-61 phase order, and the trap here is that candidates confuse 'Post-incident activity' as the immediate next step after eradication, when in fact Recovery must occur first to restore operations before conducting the final review.

How to eliminate wrong answers

Option B is wrong because Post-incident activity is the final phase that occurs after Recovery, involving lessons learned, documentation, and evidence retention. Option C is wrong because Detection and analysis occurs before containment/eradication, not after. Option D is wrong because Preparation is the initial phase that happens before any incident occurs, establishing policies, tools, and training.

793
Multi-Selecthard

A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)

Select 3 answers
A.Requiring access badges to enter the building
B.Single sign-on (SSO) for all applications
C.Using a single firewall for all network traffic
D.Encrypting data at rest
E.Fencing around the building
AnswersA, D, E

Access badges enforce authentication at the building entry point, verifying identity before anyone reaches the data centre. It satisfies the defense in depth constraint by adding a physical access control layer that complements network, encryption and administrative safeguards.

Why this answer

Option A is correct because requiring access badges to enter the building is a physical (premises) access control that restricts who can reach the data center, forming the outermost layer of defense in depth. Option D is correct because encrypting data at rest protects stored data (e.g., AES-256 on disks or databases) so that even if physical or logical access is gained, the data remains unreadable. Option E is correct because fencing around the building is a perimeter physical control that deters and delays intrusion, complementing badge access as an additional defensive layer.

Option B does not belong because SSO centralizes authentication and can actually reduce the number of independent barriers, and it is an identity convenience/control rather than a distinct defense-in-depth layer. Option C does not belong because a single firewall for all network traffic is a single point of failure and contradicts defense in depth, which requires multiple, diverse, and redundant controls.

Exam trap

The trap is selecting convenient or familiar controls (SSO, a single firewall) that sound secure but actually reduce layering, while missing that defense in depth requires diverse physical and data-level controls.

794
MCQeasy

Which document outlines the procedures for maintaining critical business functions during a disruption?

A.Business Continuity Plan
B.Continuity of Operations Plan
C.Incident Response Plan
D.Disaster Recovery Plan
AnswerA

The Business Continuity Plan documents how critical business functions continue during and after a disruption, covering people, processes and alternate working arrangements. It is broader than disaster recovery, which addresses only restoring IT systems and infrastructure.

Why this answer

The Business Continuity Plan (BCP) is the correct answer because it specifically outlines the procedures and strategies to maintain critical business functions during a disruption. Unlike other plans that focus on IT recovery or incident response, the BCP ensures that essential business operations continue, often by leveraging alternate work sites, manual workarounds, or scaled-down processes, until normal operations can be restored.

Exam trap

ISC2 often tests the distinction between BCP and DRP, where candidates mistakenly choose Disaster Recovery Plan because they focus only on IT recovery, forgetting that BCP covers the broader business continuity including non-IT functions like manual order processing or alternate facilities.

How to eliminate wrong answers

Option B (Continuity of Operations Plan) is wrong because it is a U.S. government-specific framework (COOP) focused on maintaining essential government functions at an alternate facility, not a general business continuity document. Option C (Incident Response Plan) is wrong because it focuses on detecting, containing, and eradicating security incidents (e.g., malware outbreaks or data breaches), not on maintaining ongoing business functions during a disruption. Option D (Disaster Recovery Plan) is wrong because it is a subset of BCP that specifically addresses the recovery of IT infrastructure and systems after a disaster, not the broader maintenance of critical business functions.

795
MCQmedium

A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?

A.Fail-safe
B.Least privilege
C.Need to know
D.Defense in depth
AnswerD

Defense in depth layers multiple independent controls, so compromise of one factor does not defeat the whole system. That directly satisfies the stem's constraint that the system remains secure when a single authentication factor is compromised, unlike relying on one mechanism alone.

Why this answer

Defense in depth is the correct principle because it involves implementing multiple layers of security controls so that if one authentication factor is compromised, other layers still protect the system. In this scenario, requiring multiple authentication factors (e.g., password plus biometric or token) ensures that a single compromised factor does not grant full access, maintaining overall system security.

Exam trap

ISC2 often tests the distinction between defense in depth and fail-safe, where candidates mistakenly choose fail-safe because they think it means 'safe if one factor fails,' but fail-safe is about system failure modes, not layered authentication.

How to eliminate wrong answers

Option A is wrong because fail-safe refers to a system that defaults to a secure state when a failure occurs (e.g., locking all doors on power loss), not to layering multiple authentication factors. Option B is wrong because least privilege limits user access rights to only what is necessary for their role, but does not address the scenario of a compromised authentication factor. Option C is wrong because need to know restricts access to information based on job requirements, which is about data confidentiality, not about ensuring security when one factor is breached.

796
Multi-Selectmedium

An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)

Select 2 answers
A.Forward logs to a central repository with integrity protection and controlled access
B.Disable logging on high-traffic servers to reduce storage costs
C.Store all logs only on the local systems that generate them
D.Synchronize clocks across all systems using a consistent time source such as NTP
E.Allow every administrator to modify log settings without change control
AnswersA, D

Centralizing logs with integrity protection and restricted access preserves evidence and enables cross-system correlation. If a source host is compromised, its forwarded records remain intact elsewhere. Access controls prevent tampering or unauthorized viewing. This combination directly supports detection and investigation, making it a core practice for effective centralized log collection and analysis across a diverse environment.

Why this answer

Effective centralized logging depends on trustworthy, correlated data. Synchronized clocks make cross-source timelines reliable, while forwarding logs to a protected central repository preserves evidence even if a source host is compromised. Together these practices enable detection and investigation.

Local-only storage, disabled logging, and ungoverned configuration changes all create blind spots or permit tampering, defeating the purpose of centralization.

Exam trap

The trap here is focusing on storage cost or convenience and overlooking that clock synchronization and tamper-resistant central storage are what make logs usable as evidence.

797
MCQmedium

Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?

A.Stateful inspection
B.Packet filtering
C.Application proxy
D.NGFW
AnswerA

Stateful inspection maintains a connection-state table, recording each session's source, destination and port so return traffic is permitted automatically. This satisfies the stem's requirement to track active connections, unlike stateless packet filtering, which evaluates each packet in isolation against static rules alone.

Why this answer

Stateful inspection firewalls maintain a state table to track connections, allowing return traffic for permitted outbound connections.

798
MCQmedium

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

A.Biometric authentication
B.Single-factor authentication
C.Multi-factor authentication
D.Two-step authentication
AnswerC

Multi-factor authentication combines two or more different authentication factor categories: something you know (the password) and something you are (the fingerprint). Because the factors span knowledge and inherence, rather than two instances of the same category, this satisfies the stem's requirement for both a password and a biometric scan.

Why this answer

Multi-factor authentication (MFA) requires two or more factors from different categories: something you know (password), something you have (token), or something you are (biometric). Here, the password is a knowledge factor and the fingerprint is an inherence/biometric factor, so combining them satisfies MFA. Because the factors come from distinct categories, this is true MFA rather than a single-factor or same-category combination.

Exam trap

The trap here is confusing 'two-step authentication' with 'multi-factor authentication' — candidates see two prompts and pick two-step, missing that MFA specifically requires factors from different categories.

How to eliminate wrong answers

Option A is wrong because biometric authentication alone describes only the fingerprint factor and ignores the password, so it does not capture the combined requirement. Option B is wrong because single-factor authentication uses only one credential type, whereas this scenario uses two distinct factors. Option D is wrong because 'two-step authentication' typically refers to two methods from the same factor category (e.g., password plus a PIN), which is weaker than MFA and not the precise term for combining a password with a biometric.

799
MCQhard

A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Least privilege grants only the rights needed for the current task, so the administrator uses a standard account daily and elevates only for maintenance. This limits exposure from compromised sessions, matching the stem's separate-account practise.

Why this answer

The scenario describes using a separate administrative account with elevated privileges only for system maintenance, while using a standard user account for daily activities like email. This aligns with the principle of least privilege, which dictates that users should be granted only the minimum access rights necessary to perform their job functions, and only for the duration needed. By not using the admin account for routine tasks, the administrator reduces the attack surface and potential damage from accidental or malicious actions.

Exam trap

The trap here is confusing least privilege with separation of duties; candidates often think that using two different accounts is separation of duties, but separation of duties requires two people, not two accounts for one person.

How to eliminate wrong answers

Option A is wrong because need-to-know is about restricting access to information based on whether a person requires it to perform their duties, not about limiting privileges of accounts. Option B is wrong because defense in depth involves multiple layers of security controls, not specifically about using separate accounts for different tasks. Option D is wrong because separation of duties requires dividing critical tasks among multiple people to prevent fraud, not about an individual using different accounts for different activities.

800
Multi-Selectmedium

Which THREE of the following are best practices for privileged account management? (Select THREE.)

Select 3 answers
A.Use a Privileged Access Management (PAM) solution to monitor and control admin access
B.Use the same admin account for daily tasks to simplify management
C.Create a separate admin account for administrative tasks, distinct from daily use account
D.Grant administrators full access to all systems at all times for convenience
E.Apply the principle of least privilege to administrative accounts
AnswersA, C, E

A PAM solution vaults credentials, brokers sessions and logs administrative activity, directly satisfying the monitoring and control requirement for privileged account management. It removes standing access by checking out credentials per session, giving accountability and auditability that shared or unmanaged admin accounts lack.

Why this answer

Option A is correct because a Privileged Access Management (PAM) solution provides vaulting, session monitoring, recording, and just-in-time elevation of administrative credentials, which are core best practices for controlling and auditing privileged access. Option C is correct because separating administrative accounts from everyday user accounts prevents credential theft from routine activities like email and web browsing from directly yielding privileged access, and it supports non-repudiation of admin actions. Option E is correct because applying the principle of least privilege ensures administrators receive only the rights required for their specific role, reducing the attack surface and limiting lateral movement if an admin account is compromised.

Option B is not a best practice because reusing a single admin account for daily tasks exposes high-privilege credentials to phishing, malware, and credential-dumping attacks. Option D is not a best practice because granting permanent full access to all systems violates least privilege and removes accountability, making misuse or compromise far more damaging.

Exam trap

The trap is selecting convenience-based options (same account, full access) that sound efficient but violate least privilege and separation of duties, which are core to privileged account management.

801
Multi-Selectmedium

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Select 2 answers
A.Fingerprint and iris scan
B.Password and security questions
C.Password and SMS one-time code
D.Smart card and PIN
E.Two different passwords
AnswersC, D

A password plus an SMS one-time code combines two different authentication factors: something you know and something you possess. This satisfies the stem's requirement for multi-factor authentication on remote access, since possession of the registered phone is needed alongside the password.

Why this answer

Option C is correct because a password (something you know) combined with an SMS one-time code sent to a phone (something you have) combines two different authentication factors, satisfying MFA. Option D is correct because a smart card (something you have) plus a PIN (something you know) also combines two distinct factor types. Option A is not correct because a fingerprint and an iris scan are both inherence factors (something you are), so they are the same factor category.

Option B is not correct because a password and security questions are both knowledge factors (something you know). Option E is not correct because two different passwords are still both knowledge factors, not multiple factor types.

Exam trap

The trap is counting the number of authentication steps rather than the number of distinct factor categories — two biometrics or two passwords feel like MFA but are not.

802
Multi-Selecthard

A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)

Select 2 answers
A.Authorization
B.Identification
C.Non-repudiation
D.Authentication
E.Auditing
AnswersA, D

Authorization is a core AAA component: it determines what an authenticated subject may access, by evaluating permissions against requested resources. Alongside authentication and accounting, it forms the framework's three pillars, satisfying the stem's requirement for a core AAA element.

Why this answer

Authorization (A) is a core AAA component because it determines what resources and actions an authenticated identity is permitted to access, typically enforced through policies, roles, or permissions. Authentication (D) is also a core AAA component because it verifies the identity of a subject, usually via credentials such as passwords, tokens, or certificates, before access is granted. Together with Accounting, these form the AAA framework.

Identification (B) is a prerequisite step where a subject claims an identity, but it is not one of the three AAA components. Non-repudiation (C) is a security property often supported by auditing and digital signatures, not a core AAA component. Auditing (E) is related to accounting/logging but is not itself one of the AAA framework components.

Exam trap

ISC2 often tests that candidates confuse 'Identification' with 'Authentication' or think 'Auditing' is a core AAA component instead of 'Accounting', leading them to select B or E incorrectly.

803
MCQeasy

A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?

A.Business email compromise (BEC) using a look-alike domain
B.Vishing using caller ID spoofing
C.Watering hole attack
D.Spear phishing with a malicious attachment
AnswerA

The scenario describes an attacker impersonating an executive and using a deceptively similar domain to pressure the recipient into an unauthorized financial action. This matches business email compromise, which often relies on spoofed or look-alike domains and urgency to bypass scrutiny. The gift card request is a classic BEC cash-out method rather than a technical exploitation technique.

Why this answer

The message impersonates an executive, uses a domain that closely resembles the real one, and pressures the recipient into an urgent financial action. That combination is the hallmark of business email compromise, specifically using a look-alike domain. Spear phishing, watering hole, and vishing describe different delivery methods or objectives and do not capture the executive impersonation and fraudulent payment request.

Exam trap

The trap here is labeling any targeted email as spear phishing and overlooking the executive impersonation and look-alike domain that specifically define business email compromise.

804
Multi-Selecteasy

Which TWO of the following are common indicators of a ransomware attack?

Select 2 answers
A.New user accounts created.
B.Elevated system performance.
C.Sudden decrease in network traffic.
D.Files with .encrypted extension.
E.Ransom note displayed on screen.
AnswersD, E

Ransomware encrypts victim files and commonly appends a distinctive extension such as .encrypted, making mass file renaming a reliable host-based indicator. It reflects the encryption stage of the attack rather than mere delivery or lateral movement.

Why this answer

Option D is correct because ransomware typically encrypts victim files and appends a distinctive extension such as .encrypted (or .locked, .crypto, etc.) to each affected file, making it one of the most reliable file-system indicators of an active infection. Option E is correct because most ransomware families drop a ransom note — often in the form of a text file, HTML page, or a full-screen desktop wallpaper/message — demanding payment in cryptocurrency in exchange for the decryption key. Option A is not a typical ransomware indicator; new user accounts are more commonly associated with persistence or privilege-escalation techniques used by other malware or intruders.

Option B is incorrect because ransomware encryption and file I/O typically cause elevated CPU/disk usage and degraded performance, not improved system performance. Option C is incorrect because ransomware often increases network traffic (e.g., C2 communication, key exchange, exfiltration) rather than causing a sudden decrease.

Exam trap

ISC2 often tests the distinction between ransomware indicators and general malware or intrusion indicators, so candidates mistakenly associate user account creation (Option A) with ransomware when it is actually a lateral movement technique, not a direct ransomware artifact.

805
MCQeasy

An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?

A.Separation of duties
B.Defense in depth
C.Least privilege
D.Need-to-know
AnswerA

Separation of duties splits a critical transaction across two distinct individuals so no single person controls the whole process. Requiring one employee to initiate and a manager to approve enforces this split, preventing fraud or undetected error.

Why this answer

Separation of duties (SoD) is the principle that no single individual should have enough privileges to complete a sensitive transaction alone; it requires splitting critical tasks among multiple people. Here, one employee initiates and a different manager approves, which is the textbook definition of SoD. It prevents fraud and errors by ensuring collusion is needed to abuse the process.

Exam trap

The trap is confusing separation of duties with least privilege; both involve limiting access, but only SoD requires multiple distinct people to complete one sensitive action, which is the key differentiator the exam tests.

How to eliminate wrong answers

Option B is wrong because defense in depth refers to layering multiple security controls (firewalls, IDS, encryption) so that if one fails, others still protect the asset; it is not about splitting a single transaction between people. Option C is wrong because least privilege means granting users only the minimum access needed for their job, not requiring two people for one action. Option D is wrong because need-to-know restricts access to information based on job relevance, which is about data confidentiality, not about requiring dual approval for a transaction.

806
MCQeasy

A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?

A.Hot site
B.Mobile site
C.Cold site
D.Warm site
AnswerA

A hot site is a fully equipped alternate facility with hardware, connectivity and data already operational, enabling near-immediate resumption. It satisfies the full IT capabilities requirement because recovery needs no equipment provisioning or restoration from backup, unlike warm or cold sites.

Why this answer

A hot site is a fully equipped alternate work site with all necessary IT infrastructure—servers, networking, telecommunications, and power—ready to take over operations immediately. The question specifies 'full IT capabilities,' which aligns with the hot site's purpose of enabling rapid failover with minimal downtime, typically within hours.

Exam trap

ISC2 often tests the distinction between hot, warm, and cold sites by emphasizing the 'full IT capabilities' phrase—candidates may confuse a warm site (which has some equipment) with a hot site, but the key differentiator is that a hot site is fully operational and ready for immediate use, while a warm site requires additional setup.

How to eliminate wrong answers

Option B (Mobile site) is wrong because a mobile site is a portable, temporary facility (e.g., a trailer) that may not have full IT capabilities pre-installed and is used for short-term emergencies, not as a permanent alternate work site with full IT readiness. Option C (Cold site) is wrong because a cold site provides only basic physical infrastructure (space, power, cooling) but lacks IT equipment, requiring days or weeks to procure and configure systems, which contradicts 'full IT capabilities.' Option D (Warm site) is wrong because a warm site has some pre-installed hardware and connectivity but not full IT capabilities; it typically requires additional configuration and data restoration before operations can resume, making it slower than a hot site.

807
MCQmedium

A hospital's network team needs to provide secure remote access for clinicians who work from home. The clinicians must be able to reach internal medical records systems as if they were on the hospital LAN, but the hospital's security policy requires that all remote traffic be encrypted and that remote devices be prevented from directly accessing the public internet through the hospital network. Which technology best meets these requirements?

A.A full-tunnel VPN
B.Secure Shell (SSH) port forwarding
C.A remote desktop gateway
D.A split-tunnel VPN
AnswerA

A full-tunnel VPN routes all client traffic, including internet-bound traffic, through the encrypted tunnel to the hospital network. This satisfies both the encryption requirement and the policy that remote devices must not directly access the public internet through the hospital network, because the hospital's egress controls apply to the tunneled traffic.

Why this answer

A full-tunnel VPN is the only option that both encrypts remote access and forces all client traffic through the hospital network, satisfying the policy that remote devices must not reach the public internet directly. Split tunneling, SSH port forwarding, and remote desktop gateways each leave internet-bound traffic outside the hospital's control.

Exam trap

The trap here is assuming that any encrypted remote access method, such as a split-tunnel VPN, automatically satisfies a policy requiring all traffic to traverse the corporate network.

808
Multi-Selectmedium

A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)

Select 2 answers
A.Check threat intelligence feeds for the external IP address.
B.Increase logging for all traffic to that IP.
C.Disable the firewall rule that is blocking the connections.
D.Block all outbound traffic from the source system.
E.Identify the internal system generating the connections.
AnswersA, E

Querying threat intelligence feeds establishes whether the external IP is a known command-and-control server, malware host or scanner. This reputation data satisfies the stem's need to determine malicious intent before escalating, letting the analyst prioritise the blocked outbound connections correctly.

Why this answer

Investigating the source system helps determine if it is compromised; checking threat intelligence can reveal if the IP is known malicious.

809
Multi-Selectmedium

Which TWO of the following are types of security controls?

Select 2 answers
A.Network
B.Corrective
C.All of the above
D.Preventive
E.None of the above
AnswersB, D

Corrective controls act after an incident to restore systems and limit further damage, such as backups, patches or malware removal. They form one of the recognised control categories alongside preventive, detective, deterrent and compensating types, satisfying the question's request for a control type.

Why this answer

The question asks for types of security controls, and the standard control categories by function are preventive, detective, corrective, deterrent, compensating, and physical/administrative/technical. Option B (Corrective) is correct because corrective controls are a recognized functional category that acts after an incident to restore systems and reduce impact, such as backups, patches, or disaster recovery procedures. Option D (Preventive) is correct because preventive controls are a recognized functional category designed to stop incidents before they occur, such as firewalls, encryption, access controls, and security awareness training.

Option A (Network) is not a control type but rather a domain or scope where controls can be applied, so it does not fit the question. Option C (All of the above) is wrong because it would include the incorrect Network option, and Option E (None of the above) is wrong because two valid control types are listed.

Exam trap

CC often tests the confusion between control categories (preventive, detective, corrective) and control domains (network, physical, administrative), causing candidates to select 'Network' as a type.

810
Multi-Selecthard

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Select 3 answers
A.Notifying affected customers
B.Revealing technical details of the attack to the public
C.Complying with regulatory notification requirements
D.Informing the organization's executive management
E.Deleting all logs to prevent evidence leakage
AnswersA, C, D

Notifying affected customers is a core crisis communication duty, ensuring individuals can take protective action against identity theft or fraud. It satisfies the stem's requirement for essential breach communication components, complementing regulatory notification and executive briefing.

Why this answer

Option A (Notifying affected customers) is correct because crisis communications during a data breach must include timely, clear notification to the individuals whose personal data was compromised, enabling them to take protective steps such as changing passwords or monitoring accounts. Option C (Complying with regulatory notification requirements) is correct because laws and regulations such as GDPR, HIPAA, and state breach-notification statutes mandate specific disclosures to regulators and affected parties within defined timeframes, making compliance a core communications obligation. Option D (Informing the organization's executive management) is correct because executives need accurate, prompt situational awareness to authorize response actions, allocate resources, and serve as the organization's authoritative voice internally and externally.

Option B is not correct because publicly revealing technical attack details can expose unpatched vulnerabilities, aid attackers, and jeopardize ongoing forensic investigations. Option E is not correct because deleting logs destroys evidence, violates legal hold and retention obligations, and would obstruct incident response and regulatory compliance.

811
MCQmedium

A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?

A.Need-to-know
B.Defense in depth
C.Separation of duties
D.Least privilege
AnswerC

Separation of duties splits a sensitive transaction across two people so no single employee holds end-to-end authority. Requiring two managers to jointly approve orders above $10,000 enforces exactly this: the approval capability is divided, preventing one person from committing fraud or error unchecked.

Why this answer

Separation of duties is a security principle that prevents a single individual from having control over all aspects of a critical transaction. By requiring two managers to jointly approve a purchase order over $10,000, the company ensures that no single person can commit fraud or error without detection. This is a classic example of separation of duties, also known as segregation of duties.

Exam trap

The trap is that candidates may confuse separation of duties with least privilege or defense in depth, but the key differentiator is the requirement for multiple people to complete a task, which is the essence of separation of duties.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about splitting approval authority. Option B is wrong because defense in depth involves multiple layers of security controls, not specifically the division of responsibilities. Option D is wrong because least privilege means giving users only the minimum access necessary to perform their jobs, not requiring multiple approvals.

812
MCQhard

During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?

A.Data loss beyond the recovery point objective (RPO).
B.The recovery point objective (RPO) is not met.
C.The application is unavailable for 2 hours longer than acceptable.
D.No impact because RTO is only a guideline.
AnswerC

RTO defines the maximum tolerable downtime, so a 6-hour recovery against a 4-hour objective exceeds it by 2 hours. That gap represents unacceptable unavailability for the critical application, directly quantifying the shortfall against the stated objective.

Why this answer

The recovery time objective (RTO) defines the maximum acceptable downtime for an application. Since the RTO is 4 hours but the actual recovery took 6 hours, the application was unavailable for 2 hours beyond the acceptable threshold, directly impacting business continuity. This is a failure to meet the RTO, not the RPO, which concerns data loss.

Exam trap

ISC2 often tests the distinction between RTO and RPO, and the trap here is confusing the two metrics — candidates may incorrectly associate a recovery time failure with data loss (RPO) instead of availability (RTO).

How to eliminate wrong answers

Option A is wrong because data loss is measured by the recovery point objective (RPO), not the RTO; exceeding the RTO does not imply any data loss. Option B is wrong because the RPO is a separate metric that defines the maximum acceptable age of data in the recovery copy; the scenario does not mention any data loss or failure to meet the RPO. Option D is wrong because RTO is a contractual or policy-driven requirement, not a guideline; exceeding it represents a non-compliance that can have serious operational and financial consequences.

813
MCQhard

You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?

A.Report the incident to the regulatory authority immediately.
B.Perform a forensic analysis of the server to determine the scope of compromise.
C.Disconnect the server from the network and activate the manual process.
D.Keep the server online under close monitoring to minimize customer disruption.
AnswerC

Disconnecting the server immediately halts the active C2 channel, stopping potential data exfiltration while the unpatched legacy application cannot be remediated. The four-hour manual process comfortably covers containment and investigation, and rapid isolation supports the 72-hour breach reporting obligation.

Why this answer

The correct first action is to disconnect the server from the network and activate the manual process. This immediately stops potential data exfiltration to the C2 server and contains the incident, aligning with the NIST incident response lifecycle's containment phase. Since the server runs a legacy application that cannot be patched and the manual process can sustain operations for up to 4 hours, isolation is both feasible and necessary to prevent further compromise while maintaining business continuity.

Exam trap

ISC2 often tests the principle that containment must precede any other action, even when business pressure or regulatory deadlines exist, to prevent candidates from prioritizing reporting or analysis over stopping the active threat.

How to eliminate wrong answers

Option A is wrong because reporting to the regulatory authority immediately (within 72 hours) is a post-containment step; the priority is to stop the active C2 communication and data loss first. Option B is wrong because performing forensic analysis on a live, compromised server connected to a C2 server risks altering evidence and allows continued data exfiltration; containment must precede forensics. Option D is wrong because keeping the server online under close monitoring does not stop the active outbound traffic to the C2 server, allowing ongoing data exfiltration and potential lateral movement, which violates the containment principle.

814
Multi-Selecthard

Which THREE of the following are recognized security control types according to ISC2? (Choose three.)

Select 3 answers
A.Deterrent
B.Technical
C.Physical
D.Operational
E.Administrative
AnswersB, C, E

Technical controls include firewalls, encryption, etc.

Why this answer

(Technical) is correct because ISC2 recognizes technical controls as a primary security control type, encompassing mechanisms like firewalls, encryption, and intrusion detection systems that enforce security policies through technology. These controls operate at the system or network level to protect assets directly.

Exam trap

ISC2 often tests the distinction between control types and control functions (like deterrent, detective, preventive), causing candidates to mistakenly select 'deterrent' as a type instead of recognizing it as a function that can be fulfilled by any of the three recognized types.

815
MCQhard

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

A.Rotating logs daily
B.Encrypting logs with a symmetric key
C.Storing logs on the local system drive
D.Using write-once storage
AnswerD

Write-once storage enforces immutability at the media or object layer, so once a log entry is committed it cannot be altered or deleted, even by privileged accounts. This directly satisfies the requirement to prevent post-generation tampering rather than merely detecting it.

Why this answer

Write-once storage (WORM—write once, read many) prevents any modification or deletion of log data after it is written, which directly addresses tampering by making alteration physically or logically impossible. This is the strongest control because it enforces immutability at the storage layer rather than relying on cryptographic or procedural safeguards that can be bypassed if keys or access are compromised.

Exam trap

The trap is conflating confidentiality with integrity—candidates pick encryption because it sounds like a strong security control, but the question asks specifically about preventing tampering, which only immutability (write-once) guarantees.

How to eliminate wrong answers

Option A is wrong because rotating logs daily only manages file size and retention; it does not prevent an attacker with write access from modifying or deleting the current or archived log files. Option B is wrong because encrypting logs with a symmetric key protects confidentiality in transit or at rest, but anyone holding the key—or an attacker who compromises the host—can still decrypt, alter, and re-encrypt the logs, so integrity is not guaranteed. Option C is wrong because storing logs on the local system drive is the opposite of a protective measure; it makes logs vulnerable to local tampering, disk failure, and attacker deletion, which is why logs should be shipped to a remote, hardened log server.

816
MCQhard

During a security incident, a forensic analyst needs to acquire the contents of RAM from a live system. Which tool should be used?

A.Disk cloning tool like dd
B.Network monitoring tool like Wireshark
C.Memory dump tool like DumpIt
D.Antivirus scanner
AnswerC

DumpIt captures volatile memory contents on a running Windows host, preserving processes, network connections and injected code that vanish on shutdown. This satisfies the live-system RAM acquisition constraint, where disk imaging or static analysis tools would miss volatile artefacts entirely.

Why this answer

DumpIt is a purpose-built memory acquisition tool that captures the contents of volatile RAM on a live Windows system, preserving evidence such as running processes, encryption keys, and network connections. RAM contents are lost on power-off, so a live memory dump tool is required. Disk cloning, network capture, and antivirus scanning do not capture volatile memory.

Exam trap

The trap here is confusing forensic acquisition targets — candidates may pick dd because it is a well-known imaging tool, forgetting that RAM requires a live memory dumper, not a disk imager.

How to eliminate wrong answers

Option A is wrong because dd is a disk imaging tool that copies block-level storage (disk or partition) and cannot read volatile RAM contents. Option B is wrong because Wireshark captures network packets traversing an interface, not the contents of system memory. Option D is wrong because an antivirus scanner inspects files and processes for malware signatures but does not produce a forensic memory image.

817
MCQmedium

A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?

A.Technical access control
B.Physical access control
C.Administrative access control
D.Logical access control
AnswerB

Physical access control governs entry to premises and movement within them, matching the reception sign-in, badge issue and escort described. The badge acts as the credential enforcing that control, while the escort constrains where the visitor may go. Logical controls such as Microsoft Entra ID govern systems, not building entry.

Why this answer

The scenario describes a visitor signing in, receiving a badge, and being escorted, which are all physical measures to control access to the building. Physical access control encompasses mechanisms like badges, locks, guards, and escorts that restrict physical entry to facilities. Therefore, this process is part of physical access control.

Exam trap

The trap here is confusing physical access control with administrative or logical controls; candidates might think that because a policy is involved (signing in), it's administrative, but the actual controls are physical.

How to eliminate wrong answers

Option A is wrong because technical access control involves technology-based controls like firewalls, encryption, or authentication systems, not physical measures. Option C is wrong because administrative access control refers to policies, procedures, and training, such as background checks or security awareness, not the actual physical entry process. Option D is wrong because logical access control deals with access to digital resources like files, databases, or networks, not physical spaces.

818
MCQhard

A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?

A.Discretionary access control (DAC), because repository owners can set permissions as they see fit
B.Mandatory access control (MAC), because labels and clearances prevent unauthorized modifications
C.Rule-based access control, because conditions such as branch protection rules can restrict actions
D.Role-based access control (RBAC), because permissions are tied to job functions like developer and release manager
AnswerD

RBAC assigns permissions to roles and users to roles, so developers receive read and commit rights while the release manager receives tag creation rights. Because the rules are defined centrally by role rather than by repository ownership, they apply consistently to everyone. This matches the company's requirement that the separation be enforced regardless of who owns the repository.

Why this answer

Role-based access control defines permissions for roles and assigns users to those roles, so developers and the release manager receive exactly the rights their job functions require. Because the rules are centrally defined rather than owner-controlled, they are enforced consistently. Discretionary control would leave decisions to owners, mandatory control relies on labels, and rule-based control evaluates environmental conditions.

Exam trap

The trap here is selecting rule-based access control because branch protection sounds like a rule, when the scenario is really about permissions assigned by job function.

819
MCQmedium

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

A.Act honorably, honestly, justly, and responsibly
B.Protect society, the common good, and the public trust
C.Advance and protect the profession
D.Provide diligent and competent service to principals
AnswerB

The ISC2 Code of Ethics orders canons so that protect society, the common good, and the public trust ranks first, ahead of duties to principals and peers. Handling names, addresses and Social Security numbers therefore falls under this highest-priority canon.

Why this answer

The ISC2 Code of Ethics explicitly orders its canons by priority, with the protection of society, the common good, and the public trust as the highest. When handling sensitive data like SSNs, the potential harm to individuals and society from a breach outweighs obligations to clients or the profession. This canon ensures that security professionals prioritize the safety and well-being of the public above all else.

Exam trap

The trap here is that candidates often assume the canon about serving principals (employers/clients) is paramount, but ISC2 explicitly prioritizes public safety above all else.

How to eliminate wrong answers

Option A is wrong because 'Act honorably, honestly, justly, and responsibly' is the fourth and lowest priority canon, focusing on personal conduct rather than public welfare. Option C is wrong because 'Advance and protect the profession' is the third canon, which, while important, is subordinate to public trust. Option D is wrong because 'Provide diligent and competent service to principals' is the second canon, emphasizing duties to employers or clients, but it does not override the obligation to society.

820
MCQeasy

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

A.Non-repudiation
B.Availability
C.Integrity
D.Confidentiality
AnswerD

Confidentiality ensures data is readable only by authorised parties. Encryption at rest protects stored data and encryption in transit protects data on the wire, so both controls prevent unauthorised disclosure — the specific CIA principle the organisation is addressing.

Why this answer

Encryption ensures data is not readable by unauthorized parties, thereby protecting confidentiality.

821
MCQeasy

A company wants to implement a security control that ensures users are who they claim to be before granting access to a system. Which type of control should they prioritize?

A.Auditing
B.Authentication
C.Authorization
D.Accounting
AnswerB

Authentication verifies a user's claimed identity through credentials before access is granted, directly meeting the requirement to confirm users are who they claim to be. Authorisation, by contrast, governs what an authenticated identity may do.

Why this answer

Authentication is the security control that verifies a user's identity — proving they are who they claim to be — before granting system access. It typically involves credentials (passwords, biometrics, tokens) and is the prerequisite for authorization. In the AAA framework (Authentication, Authorization, Accounting), authentication is the first step and directly answers the question 'are you who you say you are?'

Exam trap

The trap here is conflating authentication (identity verification) with authorization (permission granting) — the exam expects you to recognize that 'proving who you are' is authentication, while 'what you can do' is authorization.

How to eliminate wrong answers

Option A is wrong because auditing is a detective control that reviews logs and activities after the fact — it does not verify identity at access time. Option C is wrong because authorization determines what an authenticated user is allowed to do (permissions, roles), which presupposes authentication has already occurred. Option D is wrong because accounting (or auditing) tracks user activities for accountability and billing — it records what happened, not who the user is.

822
MCQhard

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

A.Risk transfer
B.Due care
C.Data classification
D.Data retention
AnswerC

Assigning the 'Confidential' label is itself the act of categorising data by sensitivity, which is data classification. Encryption at rest and in transit are the handling controls that the classification drives, not the classification itself, so the label satisfies the scenario's requirement.

Why this answer

Labeling data as 'Confidential' with handling requirements like encryption at rest and in transit is the definition of data classification — assigning sensitivity levels that drive protective controls. Classification is the foundational step that determines which encryption, access, and retention policies apply.

Exam trap

The CC exam often tests whether candidates confuse data classification (labeling by sensitivity) with adjacent governance concepts like retention, due care, or risk transfer — the keyword 'labels' or 'classification levels' points to classification.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts financial impact to a third party (e.g., cyber insurance or outsourcing), which is unrelated to labeling data sensitivity. Option B is wrong because due care refers to the ongoing diligence an organization exercises to meet its security obligations; classification is one mechanism of due care, not the concept itself. Option D is wrong because data retention defines how long data is kept and when it is destroyed, not how it is labeled or protected based on sensitivity.

823
MCQmedium

A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?

A.Need-to-know
B.Least privilege
C.Separation of duties
D.Defense in depth
AnswerC

Separation of duties splits a sensitive transaction across two distinct identities so no single employee can complete it alone. The stem's constraint — one employee initiates, a different employee approves transfers over $10,000 — is satisfied precisely because authorisation is divided between separate people, preventing unilateral fraud.

Why this answer

The policy requires two different employees to approve wire transfers over $10,000, with one initiating and another approving. This is a classic example of separation of duties, which ensures that no single individual has the authority to complete a critical task alone, thereby reducing the risk of fraud or error. By splitting the task between two people, the organization enforces a system of checks and balances.

Exam trap

The trap here is confusing separation of duties with least privilege or need-to-know; candidates might think that because two people are involved, it's about limiting access, but it's specifically about dividing duties to prevent fraud.

How to eliminate wrong answers

Option A is wrong because need-to-know is about limiting access to information based on job requirements, not about dividing tasks between people. Option B is wrong because least privilege is about granting minimal permissions necessary for a role, not about requiring multiple approvals. Option D is wrong because defense in depth involves multiple layers of security controls, not specifically the division of duties among personnel.

824
Multi-Selecthard

A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)

Select 2 answers
A.Establish a chain of custody for all collected evidence.
B.Allow only senior management to access the incident response plan.
C.Immediately shut down all affected systems to prevent further data loss.
D.Delete all logs after 30 days to reduce storage costs.
E.Conduct regular training for incident responders on evidence handling procedures.
AnswersA, E

A chain of custody documents who handled evidence, when, and why, ensuring its integrity and admissibility in legal proceedings. For a multinational corporation, this is essential to prove that digital evidence from the breach was not tampered with. It should be part of the incident response plan so that responders know how to label, store, and transfer evidence properly from the moment it is collected.

Why this answer

Forensic readiness requires that evidence be preserved in a way that is admissible in legal proceedings. Establishing a chain of custody ensures evidence integrity, and training responders on evidence handling ensures that procedures are followed correctly. Together, these actions help a multinational corporation maintain credible evidence for potential litigation or regulatory investigations.

Exam trap

The trap here is assuming that immediate shutdown is a good containment step, when it actually destroys volatile evidence and undermines forensic readiness.

825
MCQmedium

According to the (ISC)² Code of Ethics, which principle has the highest priority?

A.Act honorably
B.Protect society
C.Advance the profession
D.Provide diligent service
AnswerB

The (ISC)² Code of Ethics canon ordering places the safety and welfare of society first, ahead of duties to principals, the profession, and colleagues. Protecting society therefore holds the highest priority, satisfying the stem's request for the top-ranked principle.

Why this answer

The (ISC)² Code of Ethics prioritizes protecting society, the common good, and public safety above all.

Page 10

Page 11 of 14

Page 12