Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 826–900

989 questions total · 14pages · All types, answers revealed

Page 11

Page 12 of 14

Page 13
826
MCQeasy

Which access control model uses subject and object labels to enforce access based on a security policy?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Role-Based Access Control (RBAC)
AnswerC

Mandatory Access Control assigns sensitivity labels to subjects and objects, and the system enforces access strictly from the security policy rather than owner discretion. This label-based, policy-driven enforcement is the defining mechanism that distinguishes MAC from discretionary or role-based models.

Why this answer

Mandatory Access Control (MAC) enforces access decisions based on security labels assigned to subjects (users/processes) and objects (files/resources). The system, not the user, controls access by comparing these labels against a security policy, such as Bell-LaPadula or Biba. This is why MAC is the correct answer for label-based enforcement.

Exam trap

ISC2 often tests the misconception that ABAC uses labels (since attributes can be labels), but the key distinction is that MAC uses mandatory, system-enforced labels tied to a security policy, whereas ABAC evaluates attribute-based rules dynamically without fixed subject/object labels.

How to eliminate wrong answers

Option A is wrong because Discretionary Access Control (DAC) allows the owner of an object to set permissions at their discretion, using Access Control Lists (ACLs) or owner-based rights, not system-enforced labels. Option B is wrong because Attribute-Based Access Control (ABAC) uses attributes (e.g., user role, time, location) evaluated against policies, but it does not rely on fixed subject/object labels as the primary enforcement mechanism. Option D is wrong because Role-Based Access Control (RBAC) assigns permissions based on predefined roles (e.g., 'admin', 'viewer'), not on security labels that compare subject and object classifications.

827
MCQeasy

A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?

A.A captive portal that displays an acceptable-use policy before granting access
B.WPA2-Personal with a longer and more complex pre-shared key
C.MAC address filtering on the wireless access points
D.WPA2-Enterprise with 802.1X authentication
AnswerD

WPA2-Enterprise with 802.1X gives each user a unique credential validated by a RADIUS server before the client is granted network access, so a departing employee can be disabled individually. This directly replaces the shared passphrase model described in the scenario and satisfies the consultant's requirement for per-user domain authentication.

Why this answer

Enterprise-mode wireless security couples the 802.1X framework with a RADIUS server so each user presents unique credentials, commonly their domain logon, before access is granted. This eliminates the shared-secret weakness, enables per-user revocation, and produces authentication logs tied to individuals, which is exactly what the consultant was asked to deliver for the accounting firm.

Exam trap

The trap here is assuming that strengthening the pre-shared key or adding a portal page solves the shared-credential problem, when only per-user authentication through a RADIUS-backed 802.1X exchange actually does.

828
MCQmedium

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

A.Access control
B.Digital signature
C.Encryption
D.Load balancing
AnswerB

A digital signature is generated from a hash of the message encrypted with the sender's private key, so the recipient can verify integrity and confirm the content was not altered in transit, satisfying the tamper-detection requirement.

Why this answer

A digital signature uses the sender's private key to cryptographically sign the message hash, allowing the recipient to verify both the origin and that the message was not altered in transit. Any modification to the message invalidates the signature because the recomputed hash will not match. This provides integrity and non-repudiation, which is exactly what the organization needs.

Exam trap

The trap here is confusing encryption (confidentiality) with digital signatures (integrity/non-repudiation) — candidates often pick encryption because it sounds like it 'protects' the message, but it does not detect alteration.

How to eliminate wrong answers

Option A is wrong because access control governs who can access resources, not whether a message was modified during transmission. Option C is wrong because encryption provides confidentiality by hiding content but does not by itself prove the message was unaltered — an attacker could re-encrypt modified content. Option D is wrong because load balancing distributes traffic for availability and performance, and has no role in verifying message integrity.

829
MCQeasy

Refer to the exhibit. What is the first action the incident responder should take?

A.Disable the web application
B.Block the source IP in firewall
C.Ignore the alert as false positive
D.Investigate the web server at 192.168.1.10
AnswerD

The exhibit shows the web server as the likely compromised host, so containing or examining it first stops further spread. Investigating 192.168.1.10 directly addresses the identified source of malicious activity before other remediation steps, satisfying the incident response priority of scoping the affected system.

Why this answer

The incident responder must first investigate the web server at 192.168.1.10 to confirm whether the alert is a true positive or a false positive. Jumping to containment actions like disabling the application or blocking the IP without verification could disrupt legitimate services or overlook the root cause. The initial step in any incident response process (as per NIST SP 800-61) is to validate the alert through analysis of logs, processes, and system state.

Exam trap

ISC2 often tests the candidate's understanding that the first step in incident response is always to investigate and validate the alert, not to immediately contain or dismiss it, tempting candidates to jump to a reactive action like blocking the IP or disabling the application.

How to eliminate wrong answers

Option A is wrong because disabling the web application immediately could cause unnecessary business disruption and may destroy volatile evidence (e.g., running processes, memory contents) before the incident is confirmed. Option B is wrong because blocking the source IP in the firewall is a containment action that should only occur after the alert is verified and the scope of the incident is understood; premature blocking could also block legitimate traffic if the IP is spoofed or shared. Option C is wrong because ignoring the alert as a false positive without investigation violates the fundamental incident response principle of 'trust but verify' and could allow an actual breach to go undetected.

830
MCQeasy

What is the primary purpose of hashing in information security?

A.To provide availability
B.To encrypt data for confidentiality
C.To ensure data integrity
D.To authenticate users
AnswerC

Hashing produces a fixed-length digest from input data; any alteration to that input yields a different digest, so recomputing and comparing hashes detects modification. This one-way property provides integrity verification, unlike encryption, which provides confidentiality by making data unreadable.

Why this answer

Hashing produces a fixed-length digest from input data, and any change to the input produces a completely different hash. This property makes hashing the standard mechanism for verifying data integrity, such as checking file downloads or validating message contents. It is a one-way function, so it does not provide confidentiality or authentication by itself.

Exam trap

The trap is assuming hashing provides confidentiality because it 'scrambles' data — but hashing is one-way and irreversible, so it cannot protect data confidentiality like encryption does.

How to eliminate wrong answers

Option A is wrong because availability concerns uptime and access to resources, which hashing does not address. Option B is wrong because hashing is one-way and not reversible — it is not encryption, which is designed to be decrypted with a key. Option D is wrong because authentication verifies identity, typically through credentials or certificates; hashing supports password storage but does not authenticate users on its own.

831
Multi-Selectmedium

Which TWO are principles of access control?

Select 2 answers
A.Separation of duties
B.Security through obscurity
C.Multifactor authentication
D.Single sign-on (SSO)
E.Least privilege
AnswersA, E

Separation of duties splits critical tasks across multiple people so no single individual controls an entire process, preventing fraud and error. It is a foundational access control principle governing how permissions are assigned and reviewed, not a technical mechanism or physical control.

Why this answer

Separation of duties (A) is a fundamental access control principle because it divides critical tasks among multiple people so that no single individual has enough authority to compromise the system, thereby preventing fraud and error. Least privilege (E) is also a core access control principle, requiring that users be granted only the minimum permissions necessary to perform their job functions, which limits the potential damage from accidents or malicious activity. In contrast, security through obscurity (B) is a discouraged practice of relying on secrecy of design rather than sound security controls, not an access control principle.

Multifactor authentication (C) and single sign-on (D) are authentication mechanisms or convenience technologies, not foundational access control principles.

Exam trap

ISC2 often tests the distinction between access control principles (like least privilege and separation of duties) and access control mechanisms or technologies (like multifactor authentication and SSO), causing candidates to confuse a method for a principle.

832
MCQeasy

A company's backup strategy requires daily full backups of all servers. The backup window is 4 hours. What is the primary risk if backups consistently take longer than the window?

A.Compliance requirements may be violated
B.Backup media may fill up
C.Backups may interfere with production operations
D.Backups may be corrupted
AnswerC

Overrunning the four-hour window pushes backup I/O into business hours, where disk and network contention degrades production workloads. The stem's constraint is the fixed window; exceeding it removes the isolation that protects live operations, making interference the primary risk rather than backup failure itself.

Why this answer

When backups consistently exceed the 4-hour window, they overlap with production hours, causing resource contention (CPU, I/O, network bandwidth) that degrades application performance and user experience. This directly risks production operations, as backup jobs compete with live workloads for system resources.

Exam trap

ISC2 often tests the misconception that exceeding a backup window is a compliance or storage issue, when the core risk is operational interference with production workloads.

How to eliminate wrong answers

Option A is wrong because compliance requirements typically mandate that backups exist, not that they complete within a specific window; exceeding the window does not inherently violate compliance unless the backup itself fails or is absent. Option B is wrong because backup media filling up is a capacity planning issue unrelated to the backup window duration; it occurs when retention policies or data growth are mismanaged, not when backups run long. Option D is wrong because backups being corrupted is a data integrity issue caused by hardware faults, software bugs, or network errors, not by the backup taking longer than the window.

833
MCQhard

An organization wants to ensure that its backup strategy can recover data within 2 hours after a system failure. Which metric should be defined in the disaster recovery plan?

A.Mean Time Between Failures (MTBF)
B.Recovery Point Objective (RPO)
C.Service Level Agreement (SLA)
D.Recovery Time Objective (RTO)
AnswerD

Recovery Time Objective (RTO) defines the maximum acceptable downtime after a failure, directly matching the two-hour recovery constraint. Unlike Recovery Point Objective, which governs tolerable data loss measured in time, RTO specifies how quickly service must be restored, making it the metric that validates the disaster recovery plan against this requirement.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time to restore systems and data after a disaster, directly addressing the 2-hour recovery requirement. In the context of backup strategy, RTO drives decisions on failover mechanisms, replication speed, and restoration procedures to meet the specified downtime limit.

Exam trap

ISC2 often tests the distinction between RTO and RPO, where candidates mistakenly choose RPO because they confuse 'recovery of data' with 'time to recover' rather than 'point in time to which data is recovered'.

How to eliminate wrong answers

Option A is wrong because Mean Time Between Failures (MTBF) measures the average time between system failures, not recovery time, and is used for reliability planning rather than disaster recovery timelines. Option B is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (e.g., 15 minutes of lost transactions), not the time to restore operations. Option C is wrong because a Service Level Agreement (SLA) is a contractual commitment that may include RTO/RPO targets but is not itself a metric; it is an agreement, not a specific recovery time measurement.

834
MCQhard

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerB

Accepting the residual exposure because remediation cost outweighs potential loss is risk acceptance — the organisation acknowledges the threat and deliberately retains it. This differs from mitigation, transfer or avoidance, which alter or shift the risk instead.

Why this answer

Risk acceptance means acknowledging the risk and not taking further action.

835
MCQhard

A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?

A.Storing logs on the same server as the application
B.Using a separate log server with read-only access
C.Implementing write-once storage for log files
D.Encrypting logs with a symmetric key
AnswerC

Write-once storage enforces immutability at the media or object layer, so once log data is written it cannot be modified or overwritten, even by compromised accounts. This directly satisfies the stem's requirement that log data cannot be altered after being written.

Why this answer

Write-once storage (WORM) physically prevents modification or deletion of log data after it is written, which is the strongest guarantee of log integrity. Because the media enforces immutability at the storage layer, even a compromised application or administrator cannot alter historical records.

Exam trap

The trap is equating encryption or read-only access with integrity; only write-once/immutable storage actually prevents post-write modification.

How to eliminate wrong answers

Option A is wrong because storing logs on the same server as the application means an attacker who compromises the host can modify or delete the logs. Option B is wrong because read-only access controls who can read but does not prevent an administrator or attacker with write privileges from altering the files. Option D is wrong because symmetric encryption protects confidentiality in transit or at rest but does not prevent someone with the key from decrypting, modifying, and re-encrypting the logs.

836
MCQhard

A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?

A.A cross-site scripting flaw in the intranet application
B.A denial-of-service flood against the intranet web server
C.A brute-force attack against the wireless authentication server
D.An on-path attacker intercepting and modifying traffic
AnswerD

An on-path attacker positioned between the wireless clients and the intranet can intercept requests and return a fraudulent login page. The untrusted certificate is consistent with the attacker terminating TLS with a self-signed or otherwise untrusted certificate. Because the access point is legitimate, the attacker is likely using techniques such as ARP spoofing, rogue DHCP, or a malicious proxy to insert themselves into the path.

Why this answer

The untrusted certificate and fraudulent login page indicate that traffic between wireless clients and the intranet is being intercepted and altered. An on-path attacker can redirect requests and present a fake page, especially if users ignore certificate warnings. The legitimate access point rules out a rogue AP, but other interception techniques such as ARP or DHCP manipulation remain plausible.

Exam trap

The trap here is focusing on the wireless access point being legitimate and overlooking that interception can occur at other points on the path, such as through ARP or DHCP manipulation.

837
MCQeasy

A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?

A.Physical access control
B.Logical access control
C.Administrative control
D.Technical control
AnswerA

Signing in, presenting identification and wearing a visitor badge are tangible measures regulating who enters the building. They restrict human movement through the facility, which defines physical access control rather than logical or administrative control.

Why this answer

Physical access control governs access to tangible facilities, buildings, rooms, and equipment, and the scenario describes exactly that: a visitor signing in, showing ID, and wearing a badge to enter a company building. These are physical safeguards designed to control who can enter a physical space. Logical, administrative, and technical controls address different domains such as systems, policies, and technology enforcement.

Exam trap

The trap here is conflating physical controls with administrative or technical controls because visitor sign-in involves a procedure (administrative) and a badge system (technical), but the scenario's core is controlling physical entry.

How to eliminate wrong answers

Option B is wrong because logical access control governs access to digital resources such as networks, applications, and data, not physical entry to a building. Option C is wrong because administrative controls are policy and procedure-based (e.g., security awareness training, background checks, separation of duties) rather than the physical sign-in and badge process itself. Option D is wrong because technical controls are technology-enforced mechanisms like firewalls, encryption, and authentication systems, which do not describe a visitor sign-in and badge procedure.

838
MCQhard

A company's security policy requires that all sensitive data be encrypted during transfer. A security administrator discovers that an internal web application is using a self-signed TLS certificate. What vulnerability does this introduce?

A.Data corruption
B.Increased latency
C.Replay attacks because TLS is not used
D.Man-in-the-middle attacks because the certificate cannot be verified
AnswerD

Self-signed certificates lack a trusted certification authority signature, so clients cannot validate the server's identity against a trusted chain. This allows an attacker to intercept and decrypt traffic by presenting their own certificate, directly violating the policy requirement that sensitive data be encrypted during transfer.

Why this answer

A self-signed TLS certificate is not signed by a trusted Certificate Authority (CA), so clients cannot verify the certificate's authenticity. This allows an attacker to intercept the TLS handshake, present their own self-signed certificate, and perform a man-in-the-middle (MITM) attack, decrypting and reading or modifying the data in transit.

Exam trap

ISC2 often tests the misconception that self-signed certificates mean TLS is not used, but the trap here is that TLS is still active; the real issue is the lack of certificate validation, which opens the door to MITM attacks.

How to eliminate wrong answers

Option A is wrong because data corruption refers to accidental bit flips or storage errors, not to the security weakness introduced by an untrusted certificate. Option B is wrong because increased latency is a performance issue, not a security vulnerability; self-signed certificates do not inherently cause more network delay than CA-signed certificates. Option C is wrong because TLS is still used with a self-signed certificate; the vulnerability is not the absence of TLS but the inability to verify the server's identity, which enables MITM attacks, not replay attacks (which are prevented by TLS sequence numbers and timestamps).

839
Multi-Selecthard

A security manager is reviewing the organization's risk management approach. She wants to ensure that the team correctly distinguishes between threats, vulnerabilities, and risks. Which two of the following statements correctly describe these concepts? (Choose two.)

Select 2 answers
A.A vulnerability is the probability that a threat will occur.
B.A threat always results in a risk, regardless of whether a vulnerability exists.
C.A threat is any potential cause of an unwanted incident that could harm assets.
D.Risk is the same as the impact of a threat event, regardless of likelihood.
E.A vulnerability is a weakness that could be exploited by a threat.
AnswersC, E

A threat is any potential cause of an unwanted incident that could exploit a vulnerability and cause harm to assets. Threats can be natural (e.g., floods), human (e.g., hackers), or environmental. This definition is correct because it captures the external or internal actor or event that can act upon a vulnerability. Risk arises when a threat exploits a vulnerability, so this statement accurately describes a threat.

Why this answer

The two correct statements accurately define a vulnerability as a weakness that can be exploited and a threat as a potential cause of an unwanted incident. These definitions are foundational in risk management: risk arises when a threat exploits a vulnerability, leading to potential impact. The other statements incorrectly equate risk with impact alone, confuse vulnerability with probability, or claim threats always create risk without considering vulnerabilities.

Exam trap

The trap here is mixing up the definitions of threat, vulnerability, and risk, especially by assuming that a threat alone constitutes risk or that risk is solely about impact.

840
MCQmedium

Which common port is used by DNS and which transport layer protocol does it primarily use?

A.Port 53, UDP only
B.Port 161, UDP
C.Port 53, both UDP and TCP
D.Port 53, TCP only
AnswerC

DNS queries and responses travel over port 53. UDP carries ordinary lookups for speed, while TCP handles zone transfers and responses exceeding 512 bytes, or when truncation occurs. The protocol choice therefore depends on the query type, not a single transport.

Why this answer

DNS uses port 53 for both UDP and TCP: UDP is used for standard queries and responses because it is fast and low-overhead, while TCP is used for zone transfers, DNSSEC responses, and queries with responses larger than 512 bytes (or EDNS0-negotiated sizes). This dual-protocol design is why the correct answer must include both.

Exam trap

The trap is the assumption that DNS is 'UDP only' because most queries use UDP; the exam tests whether you know TCP/53 is also required for zone transfers and large responses.

How to eliminate wrong answers

Option A is wrong because it claims UDP only, ignoring TCP's role in zone transfers (AXFR/IXFR) and large responses. Option B is wrong because port 161 is used by SNMP, not DNS, and SNMP is a management protocol unrelated to name resolution. Option D is wrong because it claims TCP only, ignoring the fact that the vast majority of DNS queries are UDP for performance reasons.

841
MCQhard

An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?

A.Passwords should be exactly 8 characters with at least one special character
B.Passwords should be changed every 30 days
C.Complexity requirements are more important than length
D.Length over complexity and no periodic changes
AnswerD

NIST guidance favours longer passphrases over forced complexity and drops mandatory periodic rotation, since length resists cracking while frequent changes push users toward predictable patterns. A 15-character minimum with no complexity rules and no expiry matches this modern approach.

Why this answer

Current NIST SP 800-63B guidance recommends favoring password length over complexity and eliminating forced periodic rotation, because long passphrases resist brute-force and dictionary attacks better than short complex strings, and frequent changes lead users to predictable patterns (e.g., Password1!, Password2!). A 15-character minimum with no complexity rules and no forced expiration aligns with this modern best practice.

Exam trap

CC often tests whether candidates still hold the legacy belief that complexity and frequent rotation are the gold standard, when current NIST guidance explicitly reverses that in favor of length and no forced expiration.

How to eliminate wrong answers

Option A is wrong because 8 characters with one special character is far below current minimum length recommendations and reflects outdated complexity-first thinking. Option B is wrong because forcing changes every 30 days contradicts NIST guidance, which found periodic rotation degrades security by encouraging weak, predictable increments. Option C is wrong because it inverts the modern recommendation — length, not complexity, is the dominant factor in resisting offline cracking and guessing attacks.

842
MCQhard

A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?

A.Rule-based access control, because a fixed rule set decides every access request.
B.Role-based access control, because permissions follow the user's assigned job role.
C.Mandatory access control, because access is determined by comparing the subject's clearance to the object's classification label.
D.Discretionary access control, because the document owner decides who may read each file.
AnswerC

Mandatory access control bases every decision on labels assigned to subjects and objects, and the operating system enforces those labels regardless of user intent. Clearance must dominate classification for read access, which explains why Secret cannot read Top Secret while Top Secret can read Secret. This label-driven dominance rule is the hallmark of mandatory access control.

Why this answer

Mandatory access control relies on sensitivity labels attached to objects and clearances assigned to subjects, with the system enforcing the relationship. A subject may read an object only when their clearance dominates the object's classification, which is exactly why Secret cannot reach Top Secret and Top Secret can reach Secret. Users cannot alter these labels, making enforcement mandatory rather than discretionary.

Exam trap

The trap here is treating any hierarchical permission scheme as role-based access control when the deciding factor is actually data classification labels.

843
Multi-Selecthard

A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)

Select 3 answers
A.Virtual Private Network (VPN)
B.Intrusion Detection System (IDS)
C.Full disk encryption
D.Network firewall
E.Antivirus software
AnswersA, B, D

VPN provides encrypted tunnels for secure communication over untrusted networks, a network security control.

Why this answer

A Virtual Private Network (VPN) is a network security control because it creates an encrypted tunnel (using protocols such as IPsec or TLS) between a remote user and the corporate network, ensuring data confidentiality and integrity over untrusted networks like the internet. This protects data in transit and authenticates endpoints, which is a core network-layer security function.

Exam trap

ISC2 often tests the distinction between network-layer controls (VPN, IDS, firewall) and host/endpoint controls (disk encryption, antivirus), so the trap is that candidates mistakenly classify host-based security measures as network security controls.

844
MCQhard

You are implementing a security control to prevent unauthorized devices from connecting to the corporate wired network. Which network access control method should be used?

A.VLAN segmentation
B.MAC address filtering
C.Network Access Control (NAC) only
D.802.1X authentication
AnswerD

802.1X enforces port-based authentication before granting network access, requiring devices to authenticate via a supplicant to a RADIUS server. This directly satisfies the requirement to block unauthorised devices from connecting to the corporate wired network, since unauthenticated devices are denied access at the switch port.

Why this answer

802.1X is the IEEE standard for port-based network access control that authenticates devices and/or users before granting access to a wired or wireless LAN port. It uses EAP over LAN (EAPOL) between the supplicant and authenticator, and RADIUS between the authenticator and authentication server, providing strong, credential-based admission control. This directly addresses preventing unauthorized devices from connecting to the wired network.

Exam trap

The trap is selecting MAC address filtering because it sounds like device control — but MAC filtering is easily spoofed and is not a real authentication mechanism, whereas 802.1X provides cryptographic, port-based admission control.

How to eliminate wrong answers

Option A is wrong because VLAN segmentation isolates traffic logically but does not authenticate devices — an unauthorized device plugged into an access port still joins its assigned VLAN. Option B is wrong because MAC address filtering is trivially bypassed by spoofing a permitted MAC and does not scale or authenticate the user. Option C is wrong because 'NAC only' is too vague and, without specifying 802.1X or a comparable enforcement mechanism, does not describe a concrete standard-based control; 802.1X is the specific NAC method for wired port authentication.

845
Multi-Selectmedium

An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)

Select 2 answers
A.Cost
B.Geographic diversity
C.Number of employees
D.Recovery time objective (RTO)
E.Regulatory compliance
AnswersA, D

Hot sites duplicate production with live data and near-instant failover, while warm sites hold hardware without current data; that capability gap drives the substantial cost difference. Cost is therefore a decisive factor when choosing between the two.

Why this answer

Option A (Cost) is correct because a hot site is fully equipped with duplicate hardware, live data replication, and staff ready to take over almost instantly, making it far more expensive to build and maintain than a warm site, which has hardware but requires data restoration and configuration—so budget is a primary decision factor between the two. Option D (Recovery time objective, RTO) is correct because the RTO defines the maximum tolerable downtime, and a hot site typically delivers near-zero to minutes of recovery while a warm site may take hours or days; the required RTO therefore directly dictates which site type is appropriate. Geographic diversity (B) matters for any alternate site to avoid a shared disaster, but it does not distinguish a hot site from a warm site.

The number of employees (C) affects capacity sizing and seat counts but is not the deciding factor between hot and warm configurations. Regulatory compliance (E) imposes requirements on the overall DR strategy but does not by itself determine whether a hot or warm site is chosen.

Exam trap

CC often tests the cost-versus-RTO trade-off for recovery sites — candidates are drawn to plausible distractors like 'geographic diversity' or 'regulatory compliance', which apply to all tiers and do not distinguish hot from warm.

846
Multi-Selectmedium

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Select 3 answers
A.It is a decoy system to attract attackers
B.It provides early warning of attacks
C.It contains sensitive production data
D.It is used for legitimate network traffic
E.It allows analysis of attacker tactics
AnswersA, B, E

A honeypot is deliberately deployed as a decoy system to attract attackers, luring them away from production assets while recording their behaviour. This satisfies the analyst's goal of detecting and analysing attacker behaviour through a decoy.

Why this answer

Honeypots are decoy systems designed to attract attackers, provide early warning, and allow analysis of attacker techniques. They do not contain real production data and are not used for legitimate traffic.

847
Multi-Selecteasy

Which THREE are phases of the incident response process according to NIST SP 800-61?

Select 3 answers
A.Containment, Eradication, and Recovery
B.Risk Assessment
C.Detection and Analysis
D.Preparation
E.Vendor Management
AnswersA, C, D

Containment, Eradication, and Recovery form one combined phase in NIST SP 800-61, covering limiting incident spread, removing the root cause, and restoring normal operations. Naming this phase satisfies the question's requirement for a documented stage within the four-phase incident response lifecycle.

Why this answer

NIST SP 800-61 defines the incident response life cycle with four phases, three of which appear here. Option D, Preparation, is the first phase, covering establishing an incident response capability, acquiring tools and resources, and developing policies before incidents occur. Option C, Detection and Analysis, is the second phase, where events are monitored, indicators are validated, and incidents are confirmed and scoped.

Option A, Containment, Eradication, and Recovery, is the third phase, where the incident is limited, the root cause removed, and systems restored to normal operation. The remaining options are not phases in the NIST SP 800-61 life cycle: Risk Assessment (B) is a broader risk management activity, and Vendor Management (E) is an organizational/procurement practice, neither of which is one of the defined incident response phases.

Exam trap

ISC2 often tests whether candidates recognize that 'Containment, Eradication, and Recovery' is a single phase in NIST SP 800-61, not three separate phases, and that 'Risk Assessment' and 'Vendor Management' are common distractors because they appear in other security frameworks but are not part of the incident response process.

848
MCQmedium

Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?

A.ICMP
B.SCTP
C.TCP
D.UDP
AnswerD

UDP is connectionless and omits retransmission, handshaking and ordering overhead, so it delivers the low latency VoIP requires. Its tolerance of packet loss suits real-time voice, where retransmitting delayed packets would harm call quality more than dropping them.

Why this answer

UDP is connectionless and has no retransmission, ordering, or congestion-control overhead, which minimizes latency—exactly what VoIP needs. It tolerates some packet loss because voice codecs can interpolate or conceal minor gaps, and retransmitting lost voice packets would arrive too late to be useful anyway.

Exam trap

The trap is equating reliability with quality—candidates pick TCP because it is 'reliable,' but for real-time voice, reliability via retransmission is actually harmful, and UDP's speed and loss tolerance win.

How to eliminate wrong answers

Option A is wrong because ICMP is a control and error-reporting protocol (ping, traceroute), not a transport protocol for carrying voice media. Option B is wrong because SCTP, while designed for message-oriented transport with multi-homing and is used in telecom signaling (SS7 over IP, Diameter), is not the standard transport for VoIP media streams and is not widely supported in enterprise VoIP deployments. Option C is wrong because TCP's retransmissions, three-way handshake, and head-of-line blocking introduce jitter and delay that degrade real-time voice quality.

849
MCQeasy

Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?

A.Recovery
B.Detection
C.Containment
D.Eradication
AnswerA

Recovery restores affected systems to normal operations and verifies they function correctly, directly satisfying the stem's requirement. Unlike eradication, which removes the threat, or lessons learned, which reviews the incident afterwards, recovery focuses on validated restoration. It confirms services are operational before returning to normal business activity.

Why this answer

Recovery is the phase after eradication where systems are restored and tested.

850
MCQmedium

A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?

A.Separation of duties
B.Account lifecycle management
C.Defense in depth
D.Least privilege
AnswerB

Account lifecycle management covers provisioning, periodic review, and timely deprovisioning of accounts. When an employee is terminated, their account must be disabled or removed promptly. Leaving it enabled for weeks creates an unauthorized access path. The violation is specifically that the deprovisioning step of the lifecycle failed, leaving a live credential set for someone who no longer works there.

Why this answer

Proper account lifecycle management ensures accounts are created, reviewed, and removed in step with a person's employment status. A terminated employee retaining an enabled account violates the deprovisioning requirement. Even though the account shows no recent logins, the credential remains a live risk because it could be used by the former employee or anyone who obtained the password.

Timely disablement closes that exposure.

Exam trap

The trap here is assuming that because there were no recent logins the account is harmless, when the real issue is that an active credential for a non-employee should not exist at all.

851
Multi-Selectmedium

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Select 2 answers
A.Smart card and RSA token
B.Password and SMS one-time code
C.Biometric and PIN
D.Fingerprint and retina scan
E.Password and security question
AnswersB, C

A password is something you know, while an SMS one-time code is delivered to something you possess, the enrolled phone. Combining two distinct factor categories satisfies multi-factor authentication, whereas two passwords or two possession tokens would not.

Why this answer

Option B (Password and SMS one-time code) is correct because it combines two different authentication factor categories: something you know (the password) and something you have (the SMS one-time code delivered to your phone), which is the definition of multi-factor authentication. Option C (Biometric and PIN) is correct because it pairs something you are (the biometric, such as a fingerprint) with something you know (the PIN), satisfying the requirement for multiple distinct factor types. Option A is not multi-factor because a smart card and an RSA token are both something you have, so they belong to the same factor category.

Option D is not multi-factor because a fingerprint and a retina scan are both inherence factors (something you are). Option E is not multi-factor because a password and a security question are both knowledge factors (something you know).

Exam trap

The trap here is that candidates often assume any two authentication methods constitute MFA, but the methods must belong to different factor categories (knowledge, possession, inherence).

852
Multi-Selecthard

After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?

Select 2 answers
A.DNS logs
B.Authentication logs
C.Firewall logs
D.System logs
E.Application logs
AnswersB, C

Authentication logs record sign-in events, credential use and directory queries, capturing the account and timestamp of each hop between systems. Microsoft Entra ID sign-in and audit logs therefore satisfy the timeline constraint directly, revealing when compromised credentials were reused against other hosts during lateral movement.

Why this answer

Authentication logs (B) are correct because they record logon events such as successful and failed authentications, Kerberos ticket requests, and remote logon types (e.g., Type 3 network logons in Windows Security event 4624), which directly reveal an attacker moving from one host to another using compromised credentials. Firewall logs (C) are correct because they capture allowed and denied connections between internal hosts and across network segments, letting an investigator trace internal-to-internal traffic and identify the source and destination of lateral movement. DNS logs (A) can show name resolution but do not by themselves prove a session or movement between hosts.

System logs (D) and application logs (E) may contain related events, but they are less directly indicative of network-based lateral movement than authentication and firewall records.

Exam trap

The trap is selecting DNS or system logs because they are commonly monitored; candidates must recognize that lateral movement is proven by authentication events plus internal network connections, not by name resolution or local OS events.

853
MCQeasy

An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?

A.Smishing
B.Tailgating
C.Vishing
D.Whaling
AnswerC

Vishing is voice phishing conducted over the telephone. The attacker impersonated IT support and tried to extract a password through a phone call. Because the attempt occurred by voice rather than email or text, vishing is the precise term. The employee correctly recognized that help desk staff never need a password and reported the call instead of complying.

Why this answer

Vishing uses voice communication, typically a phone call, to manipulate a target into revealing sensitive information or performing an action. The attacker posed as IT support and requested a password, which legitimate help desk personnel should never do. Recognizing the pretext and refusing to provide credentials is the correct response.

Reporting the call also helps security teams warn others about the active campaign.

Exam trap

The trap here is confusing the delivery channel, since the caller pretends to be IT support; the defining characteristic is that the request came by voice, not that the impersonation occurred.

854
Multi-Selecthard

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Select 3 answers
A.Risk acceptance
B.Risk transfer
C.Risk communication
D.Risk mitigation
E.Risk analysis
AnswersA, B, D

Risk acceptance is a valid treatment: the organisation acknowledges the risk and proceeds without action, typically when exposure falls within tolerance or mitigation costs exceed potential impact. It sits alongside avoidance, transfer and mitigation as recognised responses.

Why this answer

Risk acceptance (A) is a valid risk treatment option because the organization consciously decides to tolerate the risk without taking action, often when the cost of mitigation exceeds the potential impact. Risk transfer (B) is valid because the organization shifts the financial impact of a risk to a third party, typically through insurance, outsourcing, or contracts. Risk mitigation (D) is valid because it involves taking actions to reduce the probability or impact of a risk, such as implementing controls or safeguards.

Risk communication (C) is not a treatment option; it is an ongoing activity for sharing risk information among stakeholders. Risk analysis (E) is not a treatment option either; it is part of risk assessment, used to identify and evaluate risks before treatment decisions are made.

855
MCQmedium

An analyst reviewing traffic captures sees a workstation repeatedly sending TCP packets with the SYN flag set to many different destination ports on a single server, but the workstation never completes the three-way handshake. The server's connection table is becoming exhausted. Which type of activity is most likely occurring?

A.A man-in-the-middle attack intercepting session traffic
B.A smurf amplification attack using ICMP
C.A SYN flood denial-of-service attack
D.A brute-force password attack against the server
AnswerC

The half-open connections with SYN set and no completed handshake are the signature of a SYN flood, where the attacker exhausts the server's backlog of pending connections. Because the source addresses are often spoofed, the final ACK never arrives, leaving resources tied up until timeouts occur. This matches the scenario of many SYNs to varied ports with no handshake completion.

Why this answer

The repeated SYN packets without completed handshakes indicate a SYN flood, a denial-of-service technique that exhausts a server's pending connection queue. The server cannot complete legitimate connections because its backlog is full. Other attacks would involve different protocols or completed sessions, so the half-open TCP pattern is the key differentiator.

Exam trap

The trap here is assuming any flood of packets is a bandwidth exhaustion attack, when the incomplete TCP handshakes specifically point to resource exhaustion of the connection table.

856
Multi-Selectmedium

A security administrator is reviewing network security controls. Which TWO of the following are examples of network segmentation technologies? (Select TWO)

Select 2 answers
A.Proxy servers
B.Honeypots
C.Subnetting
D.VLANs
E.Firewalls
AnswersC, D

Subnetting divides a network into smaller IP subnetworks, providing Layer 3 segmentation.

Why this answer

Subnetting divides a larger network into smaller, logical subnetworks by manipulating the subnet mask (e.g., using VLSM or CIDR). This creates separate broadcast domains at Layer 3, allowing administrators to isolate traffic and apply distinct security policies between subnets, which is a core function of network segmentation.

Exam trap

ISC2 often tests the distinction between technologies that create segmentation (subnetting, VLANs) and technologies that enforce security policies between segments (firewalls, ACLs), leading candidates to mistakenly select firewalls as a segmentation technology.

857
MCQhard

During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?

A.Detection
B.Analysis
C.Containment
D.Eradication
AnswerC

Containment limits the scope and spread of an incident once detected. Isolating the workstation stops further data exfiltration to the external IP address and prevents lateral movement, while preserving evidence for the later eradication and recovery phases.

Why this answer

Isolation of an affected workstation is a containment action because it stops the spread of the incident and prevents further data exfiltration while the investigation continues. Containment is the phase in the NIST/SANS incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident) where the goal is to limit damage and prevent the incident from expanding. Detection and analysis involve identifying and validating the event; eradication removes the root cause.

Exam trap

The trap here is confusing Containment with Eradication — candidates see 'isolate the workstation' and think of removing the threat, but isolation only limits spread; removal of the root cause is Eradication.

How to eliminate wrong answers

Option A is wrong because Detection is the phase where the analyst first identifies the unusual traffic — it precedes any response action. Option B is wrong because Analysis is where the analyst investigates and scopes the incident (e.g., determining what data was exfiltrated), not where the workstation is isolated. Option D is wrong because Eradication involves removing malware, closing the attack vector, and remediating the root cause — it happens after containment, not at the moment of isolation.

858
MCQhard

Refer to the exhibit. What type of event is this?

A.Account lockout
B.Successful remote login
C.Failed network login
D.Failed local login
AnswerC

A failed network login event records an authentication attempt rejected by a system, such as a domain controller or VPN gateway, typically showing a logon failure reason code. This matches the exhibit's event type rather than a successful logon, account change or process execution.

Why this answer

The event shows a failed network logon (Logon Type 3) with a failure status code. Option A is incorrect because an account lockout event would have a different event ID (e.g., 4740), not a Logon Type 3 failure. Option B is incorrect because the event indicates a failure (e.g., status 0xC000006D), not a successful login.

Option D is incorrect because Logon Type 3 indicates a network logon, whereas a local logon would be Type 2 or 10.

859
MCQeasy

What is the difference between identification and authentication?

A.Identification proves identity; authentication claims identity
B.They are the same thing
C.Identification uses passwords; authentication uses biometrics
D.Identification claims identity; authentication proves identity
AnswerD

Identification presents a claimed identity, such as a username, while authentication verifies that claim through credentials or factors, proving the subject genuinely owns that identity. This distinction satisfies the stem's requirement to separate the assertion of identity from its cryptographic or knowledge-based validation, matching how Microsoft Entra ID processes sign-ins.

Why this answer

Identification is the process of claiming an identity, such as providing a username. Authentication is the process of proving that claimed identity, typically by providing a password, token, or biometric. Therefore, identification claims identity, and authentication proves it.

Exam trap

The trap is the common misconception that identification and authentication are interchangeable or that identification proves identity. Candidates may confuse the two, especially under time pressure.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: identification does not prove identity; it claims it. Option B is wrong because identification and authentication are distinct steps in access control. Option C is wrong because it incorrectly associates identification with passwords and authentication with biometrics; both can use various factors, and the distinction is about claiming versus proving.

860
MCQmedium

During a security audit, you discover that a financial application stores passwords using MD5 hashing without salt. What is the primary security concern with this practice?

A.MD5 is reversible, allowing attackers to recover plaintext passwords
B.MD5 is too slow, causing performance issues during authentication
C.Without salting, the hashes are vulnerable to precomputed rainbow table attacks
D.Storing hashes violates PCI DSS compliance, but does not affect security
AnswerC

Unsalted MD5 lets attackers hash every candidate password once and reuse the resulting lookup table across all accounts. Rainbow tables exploit this by trading precomputation for fast cracking, so identical passwords yield identical hashes, undermining the credential store's resistance to offline attack.

Why this answer

MD5 is a fast hash, making it susceptible to brute-force and rainbow table attacks. Without salting, identical passwords produce identical hashes, allowing precomputed rainbow tables to quickly reverse them. Hashing is one-way, so MD5 is not reversible in the true sense.

Speed is a vulnerability, not a benefit. Compliance is secondary but not the primary security concern.

861
MCQmedium

A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?

A.Accounting
B.Authorization
C.Authentication
D.Identification
AnswerC

Authentication verifies that a claimed identity is genuine. Inserting the smart card supplies something the doctor has, and validating its embedded certificate against the hospital's internal certificate authority proves the credential is trusted. This process confirms the doctor is who the card claims, which is precisely the definition of authentication in the access control lifecycle.

Why this answer

The smart card provides a possession factor, and the certificate authority validates that the credential is genuine and trusted. This verification of a claimed identity is the definition of authentication. Authorization and accounting occur later in the process, while identification is only the initial claim of an identity without proof.

Exam trap

The trap here is confusing identification with authentication, assuming that presenting a card or claiming an identity by itself constitutes proof of who the user is.

862
MCQmedium

A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?

A.Discretionary Access Control (DAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Role-Based Access Control (RBAC)
AnswerB

ABAC evaluates attributes of the subject, object, action, and environment, including time-of-day and shift schedule. By defining a policy that permits access only when the current time falls within the nurse's assigned shift, ABAC directly enforces the temporal restriction. This makes it the appropriate model for dynamic, context-aware conditions such as shift-based access.

Why this answer

Attribute-Based Access Control evaluates environmental attributes such as current time and shift assignment alongside subject and object attributes. This allows the hospital to enforce a policy that grants patient-record access only during a nurse's scheduled shift, even when credentials remain valid. Role-Based Access Control, Mandatory Access Control, and Discretionary Access Control do not natively enforce time-of-day conditions, so they fail to meet the requirement.

Exam trap

The trap here is assuming that Role-Based Access Control automatically includes time-of-day restrictions because roles are tied to job functions.

863
Multi-Selecteasy

An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?

Select 2 answers
A.Identification and authentication
B.Need-to-know
C.Separation of duties
D.Least privilege
E.Defense in depth
AnswersB, D

Need-to-know restricts access to information strictly required to perform a role. The employee's job role did not require the confidential document, yet their account held read access to its folder, so access was granted beyond job necessity, violating this principle.

Why this answer

The scenario describes an employee who could read a confidential document unrelated to their job role, which directly violates the need-to-know principle (B) because access to information should be granted only to those who require it to perform their duties. It also violates the principle of least privilege (D), since the account was granted read access to a folder beyond the minimum permissions necessary for the employee's role. Identification and authentication (A) is not violated because the employee's account was properly identified and authenticated; the issue is authorization, not proving identity.

Separation of duties (C) is not implicated because no single individual was given control over multiple conflicting tasks or stages of a critical process. Defense in depth (E) is not violated because the scenario does not describe a failure of layered controls; it describes excessive permissions granted to an account.

Exam trap

The trap is confusing need-to-know with least privilege or selecting unrelated concepts like separation of duties. Candidates might think authentication was violated, but the employee used their own credentials.

864
MCQhard

An analyst reviews the exhibit. What security principle is best demonstrated by this policy?

A.Separation of duties
B.Defense in depth
C.Non-repudiation
D.Least privilege
AnswerD

The policy restricts access to only what each role requires, which is the definition of least privilege. This satisfies the stem's requirement to identify the principle demonstrated, since the exhibit limits entitlements rather than layering controls or verifying identity repeatedly.

Why this answer

The policy grants users only the permissions necessary to perform their job functions, which is the core definition of least privilege. By restricting access to only required resources, the policy minimizes the attack surface and limits potential damage from compromised accounts.

Exam trap

ISC2 often tests least privilege by describing a policy that restricts access to only what is needed, and the trap is confusing it with separation of duties because both involve limiting actions, but separation of duties focuses on dividing tasks among multiple people to prevent collusion, not on minimizing individual permissions.

How to eliminate wrong answers

Option A is wrong because separation of duty requires splitting critical tasks among multiple people to prevent fraud, not simply limiting individual permissions. Option B is wrong because defense in depth involves multiple layers of security controls (e.g., firewall, IDS, encryption), not a single access restriction policy. Option C is wrong because non-repudiation ensures that an action cannot be denied later, typically via digital signatures or logging, not by limiting permissions.

865
MCQmedium

An organization has implemented a SIEM solution. The security team wants to detect when a user attempts to access a file they do not have permission to read. Which log source is most important for this detection?

A.Windows security event logs
B.Web server access logs
C.DNS logs
D.Firewall logs
AnswerA

Security event logs include audit events for file access and can show access denied events.

Why this answer

Windows security event logs (specifically Event ID 4663) record every attempt to access an object, including files, and include the user's security identifier (SID) and the requested access mask. This allows the SIEM to correlate the user's identity with the file's discretionary access control list (DACL) to detect an 'Access Denied' result, making it the definitive source for detecting unauthorized file access attempts.

Exam trap

ISC2 often tests the misconception that network-level logs (firewall, DNS) or application-level logs (web server) can detect OS-level file access, when in fact only the operating system's security audit subsystem can capture such granular user-to-object access attempts.

How to eliminate wrong answers

Option B is wrong because web server access logs record HTTP requests to web resources, not local file system access on a Windows server or workstation; they cannot detect a user attempting to open a file via SMB or local Explorer. Option C is wrong because DNS logs only contain domain name resolution queries and responses, with no information about file paths, user identities, or access control decisions. Option D is wrong because firewall logs track network traffic based on IP addresses and ports, not user-level file access attempts within an operating system.

866
MCQmedium

Which of the following is considered sensitive personally identifiable information (PII)?

A.Date of birth
B.Telephone number
C.Medical records
D.Email address
AnswerC

Sensitive PII is data that, if disclosed, could cause harm or enable identity theft. Medical records uniquely combine health information with identifiers, so their exposure triggers legal, privacy and discrimination risks. Names or email addresses alone lack that harm potential, making medical records the sensitive category.

Why this answer

Medical records are classified as sensitive PII because they contain protected health information (PHI) that, if disclosed, can cause significant harm such as discrimination, identity theft, or privacy violations. Regulations like HIPAA and GDPR treat health data as a special category requiring stricter safeguards than ordinary identifiers. Date of birth, telephone number, and email address are direct identifiers but are not inherently sensitive on their own.

Exam trap

The trap here is confusing 'PII' with 'sensitive PII' — candidates see common identifiers like DOB or email and assume any personal data qualifies as sensitive, when the exam expects recognition that only categories like medical, financial, or biometric data are sensitive.

How to eliminate wrong answers

Option A is wrong because a date of birth is a basic identifier, not sensitive PII by itself — it only becomes sensitive when combined with other data like name or SSN. Option B is wrong because a telephone number is contact information, classified as ordinary PII, not sensitive PII. Option D is wrong because an email address is a standard identifier used for communication and is not considered sensitive PII under frameworks like HIPAA or GDPR.

867
Multi-Selectmedium

A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)

Select 2 answers
A.Access badges at building entrance
B.Biometric reader on server room door
C.Cable locks on laptops
D.Fencing around the property
E.Lighting in the parking lot
AnswersD, E

Fencing around the property is a perimeter physical control because it establishes the outermost boundary of the site, deterring and delaying unauthorised access before an intruder reaches the building. It satisfies the scenario's requirement for controls operating at the external perimeter, unlike interior measures such as locks on server-room doors.

Why this answer

Option D (fencing around the property) is correct because fencing is a classic perimeter control that establishes a physical boundary and deters or delays unauthorized entry to the site. Option E (lighting in the parking lot) is correct because exterior lighting is a perimeter control that illuminates the outer grounds, deterring intruders and enabling surveillance of approaches to the facility. Option A (access badges at building entrance) is not a perimeter control but an access control at a building entry point, which is a more interior layer of defense.

Option B (biometric reader on server room door) is an interior access control protecting a high-value asset, not the site perimeter. Option C (cable locks on laptops) is an asset-level physical control for portable devices, not a perimeter control.

Exam trap

The trap here is conflating 'physical control' with 'perimeter control' — badges, biometrics, and cable locks are all physical, but only fencing and exterior lighting sit at the property perimeter, so candidates who just scan for 'physical' pick the wrong two.

868
MCQeasy

Which of the following best describes the purpose of due care in information security?

A.Implementing reasonable security measures to protect data
B.Prioritizing security incidents based on impact
C.Transferring risk to a third party
D.Investigating a vendor's background before contracting
AnswerA

Due care means implementing reasonable security measures to protect data, satisfying the question's focus on the purpose of due care. It reflects the ongoing obligation to identify risks and apply proportionate controls, distinguishing it from due diligence, which concerns the investigation and assessment of those risks before action.

Why this answer

Due care means exercising a minimum standard of care to protect information assets, such as implementing basic security controls.

869
Multi-Selecteasy

Which TWO of the following are core principles of the CIA triad?

Select 2 answers
A.Integrity
B.Non-repudiation
C.Confidentiality
D.Authorization
E.Authentication
AnswersA, C

Integrity ensures data remains accurate and unaltered unless changed by authorised processes, directly satisfying the CIA triad's requirement for trustworthy information. It guards against unauthorised modification, whether accidental or malicious, complementing confidentiality and availability as one of the three foundational security principles the question asks you to identify.

Why this answer

The CIA triad consists of Confidentiality, Integrity, and Availability. Options A and C are correct. Option B (Non-repudiation) is separate.

Option D (Authentication) is separate. Option E (Authorization) is separate.

870
MCQhard

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

A.It can decrypt SSL traffic
B.It examines each packet in isolation
C.It uses a state table to track connections
D.It can filter based on application-layer data
AnswerC

A state table records each flow's source, destination, ports and TCP session state, so return traffic is permitted automatically without a matching inbound rule. Stateless firewalls inspect each packet in isolation against static ACLs, offering no connection awareness. This satisfies the stem's requirement for a distinguishing characteristic.

Why this answer

A stateful firewall maintains a state table that tracks active connections (source/destination IP, ports, sequence numbers, TCP flags), allowing it to make decisions based on the context of a session rather than each packet in isolation. This lets it automatically permit return traffic for established connections without explicit rules.

Exam trap

The trap is conflating 'stateful' with 'next-gen' — candidates pick A or D because they associate advanced inspection with stateful firewalls, but statefulness is specifically about connection tracking.

How to eliminate wrong answers

Option A is wrong because SSL/TLS decryption is a function of next-generation firewalls (NGFW) or SSL inspection proxies, not a defining characteristic of stateful firewalls — a stateful firewall can operate purely at layers 3-4. Option B is wrong because examining each packet in isolation describes a stateless (packet-filtering) firewall, which is the opposite of stateful behavior. Option D is wrong because application-layer filtering is a feature of layer 7 firewalls or NGFWs, not the distinguishing trait of stateful firewalls, which primarily track connection state at layers 3-4.

871
MCQhard

A company's IDS generates an alert for a potential SQL injection attack on a web application. The analyst reviews the log and sees the following: "SELECT * FROM users WHERE username = 'admin' OR 1=1 --'". Which action should the analyst take next?

A.Submit a change request to patch the application
B.Conduct a forensic analysis of the database
C.Verify if the WAF blocked the attack
D.Block the source IP immediately
AnswerC

The log shows a classic tautology-based SQL injection payload, but detection alone does not confirm exploit success. Checking whether the WAF blocked the request establishes whether the attack reached the database, determining if escalation to incident response is required.

Why this answer

The analyst's first priority is to determine whether the attack was actually successful or was already mitigated. A Web Application Firewall (WAF) sits in front of the web application and can inspect and block SQL injection payloads before they reach the database. By verifying the WAF logs, the analyst can confirm if the attack was blocked, which dictates the next steps—if blocked, no immediate escalation is needed; if not blocked, further investigation is required.

Exam trap

ISC2 often tests the candidate's ability to follow a proper incident response triage process—specifically, the trap is that candidates jump to a reactive action (like blocking IPs or patching) instead of first verifying whether existing controls (like a WAF) already mitigated the threat.

How to eliminate wrong answers

Option A is wrong because submitting a change request to patch the application is premature without first confirming that the attack was successful; patching is a long-term fix, not an immediate triage step. Option B is wrong because conducting a forensic analysis of the database is an invasive and time-consuming step that should only be taken if there is evidence that the attack actually reached and compromised the database, which is not yet known. Option D is wrong because blocking the source IP immediately could be an overreaction—the IP might be spoofed, part of a legitimate scan, or the attack might have already been blocked by the WAF; blocking without verification can cause unnecessary disruption and is not the standard first response in a security operations workflow.

872
Multi-Selecthard

A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)

Select 3 answers
A.Geographic diversity
B.Vendor lock-in risks
C.Cost of the facility and equipment
D.Recovery time objective (RTO)
E.Data synchronization capabilities
AnswersC, D, E

Hot sites duplicate all infrastructure with real-time replication, warm sites keep scaled-down hardware ready, and cold sites provide only space and power. Facility and equipment cost rises sharply across that spectrum, directly satisfying the stem's requirement to balance cost against recovery time when selecting a strategy.

Why this answer

Option C is correct because the cost of the facility and equipment is the primary differentiator among hot, warm, and cold sites: a hot site duplicates all hardware and is fully operational (highest cost), a warm site has partial infrastructure and some pre-installed equipment (moderate cost), and a cold site provides only basic space and power (lowest cost), so this factor directly addresses the stated need to balance cost. Option D is correct because the recovery time objective (RTO) determines how quickly operations must be restored, and the site type must match that target: hot sites deliver near-zero RTO, warm sites typically hours to days, and cold sites days to weeks, making RTO the key recovery-time factor in the decision. Option E is correct because data synchronization capabilities differ by site type and affect both recovery point objective (RPO) and readiness: hot sites require real-time replication or mirroring, warm sites may use periodic backups or asynchronous replication, and cold sites rely on restoring from offsite backups, so synchronization directly influences the cost-versus-recovery-time tradeoff.

Option A is not among the marked answers because geographic diversity is a general resilience and site-separation consideration that applies regardless of whether the site is hot, warm, or cold, and it is not the factor that distinguishes these three strategies. Option B is not among the marked answers because vendor lock-in risk concerns procurement and portability of technology choices, not the cost-versus-recovery-time characteristics that define hot, warm, and cold site selection.

Exam trap

The trap here is confusing site-selection criteria (geographic diversity, vendor risk) with tier-selection criteria (cost, RTO, data sync), causing candidates to pick plausible-sounding but category-mismatched options.

873
Multi-Selecteasy

Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)

Select 3 answers
A.Detection and Analysis
B.Vulnerability scanning
C.Containment, Eradication, and Recovery
D.Preparation
E.Post-incident auditing
AnswersA, C, D

Detection and Analysis is a core NIST SP 800-61 phase, covering monitoring, alert triage and validating whether an event is genuinely an incident. It satisfies the framework's requirement to identify and investigate suspicious activity before containment, eradication and recovery steps are undertaken.

Why this answer

The NIST SP 800-61 incident response lifecycle defines four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Option D (Preparation) is correct because it is the first phase, covering establishing an IR capability, tools, communications, and training before incidents occur. Option A (Detection and Analysis) is correct because it is the phase where events are validated as incidents and their scope, impact, and root cause are analyzed.

Option C (Containment, Eradication, and Recovery) is correct because it is the phase where the incident is limited, the threat removed, and systems restored to normal operation. Option B (Vulnerability scanning) is not a distinct NIST IR phase; it is a proactive security control that may feed Preparation or Detection but is not one of the defined steps. Option E (Post-incident auditing) is not the NIST phase name; the correct fourth phase is Post-Incident Activity, which includes lessons learned and evidence retention rather than a standalone 'auditing' step.

Exam trap

The trap is that candidates might confuse proactive security activities like vulnerability scanning with incident response phases. The NIST framework is specific, and 'Post-incident auditing' is a distractor that sounds similar to 'Post-Incident Activity' but is not the exact phase name.

874
MCQmedium

A security analyst discovers that a user's account has been used to access sensitive data outside of normal business hours from an unfamiliar IP address. The user claims they were not logged in at that time. Which security operations process should be initiated first?

A.Perform a forensic analysis of the user's workstation
B.Reset the user's password and enforce multi-factor authentication
C.Disable the user account immediately
D.Initiate the incident response process
AnswerD

Anomalous access from an unfamiliar IP outside business hours, with the user denying it, indicates possible credential compromise. Initiating incident response first enables containment, evidence preservation and scoping before any account remediation, satisfying the need to handle a suspected security incident systematically.

Why this answer

The scenario describes a potential security incident—unauthorized access to sensitive data from an unfamiliar IP address outside business hours—which requires immediate activation of the incident response process. The first step in any security operations workflow is to follow the organization's incident response plan (NIST SP 800-61) to contain, analyze, and remediate the threat. Jumping to forensic analysis, password resets, or account disabling without a coordinated incident response can destroy evidence or fail to address the root cause.

Exam trap

ISC2 often tests the misconception that immediate account disabling or password reset is the correct first response, but the CC exam emphasizes that initiating the incident response process is the foundational step to ensure proper handling, evidence preservation, and coordination.

How to eliminate wrong answers

Option A is wrong because performing forensic analysis of the user's workstation is a later step in the incident response process, not the first action; it could also be irrelevant if the compromise originated from a remote attacker without local artifacts. Option B is wrong because resetting the password and enforcing MFA addresses only credential hygiene but does not investigate the extent of the breach, identify the attack vector, or preserve evidence—potentially alerting the attacker prematurely. Option C is wrong because disabling the user account immediately might disrupt legitimate business operations and could tip off an attacker, whereas a coordinated incident response includes controlled containment actions based on investigation.

875
MCQeasy

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?

A.Full backup
B.Synthetic full backup
C.Differential backup
D.Incremental backup
AnswerC

A differential backup captures every change made since the last full backup, accumulating data across days regardless of intervening backups. Incremental backups instead capture only changes since the previous backup of any type, so they fail the stem's "since the last full backup" constraint.

Why this answer

A differential backup captures all data changed since the last full backup, so each successive differential grows larger until the next full backup resets the baseline. This differs from an incremental backup, which only captures changes since the last backup of any type. The key characteristic in the question — 'regardless of subsequent incremental or differential backups' — matches the differential model, where the reference point remains the last full backup.

Exam trap

The trap is the wording 'since the last full backup' — candidates often pick Incremental, but incrementals reset their baseline after every backup, while differentials always reference the last full.

How to eliminate wrong answers

Option A is wrong because a Full backup copies all data every time, not just changes since the last full backup. Option B is wrong because a Synthetic full backup is constructed by combining a full backup with subsequent incremental backups on the backup server, not a method that copies changes since the last full backup. Option D is wrong because an Incremental backup copies only data changed since the most recent backup (full or incremental), so its baseline shifts with each run rather than staying anchored to the last full.

876
MCQmedium

During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?

A.Separation of duties
B.Defense in depth
C.Least privilege
D.Need-to-know
AnswerA

Separation of duties requires that no single person controls both authorisation and custody of an asset. One employee approving purchase orders and receiving the goods enables concealed fraudulent purchases, so splitting those responsibilities is the control being violated.

Why this answer

Separation of duties (SoD) requires that no single individual controls all parts of a critical transaction or process. In this scenario, one employee can both approve purchase orders and receive the goods, meaning they could create a fictitious vendor, approve the payment, and confirm receipt of goods that never arrived — a classic fraud vector. SoD mandates that these two functions be split between different people so that collusion is required to commit fraud.

Exam trap

The trap here is confusing separation of duties with least privilege — candidates see 'one employee can do two things' and jump to least privilege, but the issue is the combination of conflicting duties, not excessive permissions.

How to eliminate wrong answers

Option B is wrong because defense in depth refers to layering multiple independent security controls (firewalls, IDS, encryption, physical security) so that no single control failure compromises the system — it does not address the concentration of conflicting duties in one person. Option C is wrong because least privilege means granting users only the minimum access rights needed to perform their job; the employee here may well have exactly the permissions their role requires, but the problem is that two incompatible roles are combined. Option D is wrong because need-to-know governs access to information based on whether the person requires that information for their duties — it is about data confidentiality, not about segregating transaction-authorizing functions.

877
MCQmedium

A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Need-to-know
AnswerA

Layering firewalls, intrusion detection systems and access control lists creates overlapping, independent controls so that no single failure exposes the network. This deliberate stacking of complementary safeguards across the architecture is precisely the defence-in-depth principle the proposal applies.

Why this answer

Defense in depth is the principle of layering multiple independent security controls so that if one fails, others still protect the asset. Firewalls, IDS, and ACLs are complementary layers at different points in the network, which is the textbook definition of defense in depth. The other options describe different principles that are not about layering controls.

Exam trap

The trap is confusing defense in depth with least privilege or separation of duties — candidates see 'multiple controls' and may pick least privilege, but the defining feature here is layering independent controls.

How to eliminate wrong answers

Option B is wrong because separation of duties is about dividing responsibilities among different people to prevent fraud or error, not about layering technical controls. Option C is wrong because least privilege is about granting only the minimum permissions needed for a task, which is a single-control principle, not a layering strategy. Option D is wrong because need-to-know is about restricting access to information based on job requirements, again a single-principle access control concept, not multi-layered defense.

878
MCQmedium

A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?

A.Mandatory access control (MAC)
B.Rule-based access control
C.Discretionary access control (DAC)
D.Role-based access control (RBAC)
AnswerD

Role-based access control grants permissions to roles, and users receive permissions by being assigned to a role. In this scenario the job title acts as the role, and changing the title automatically changes access. This central administration of permissions through roles, rather than per-user grants, is the defining characteristic of RBAC.

Why this answer

Role-based access control assigns permissions to roles and then assigns users to those roles, so access changes automatically when a user's role changes. The hospital's job-title-driven permissions match this model. Discretionary control lets owners set permissions, mandatory control uses labels and clearances, and rule-based control evaluates conditions rather than job functions.

Exam trap

The trap here is confusing role-based access control with rule-based access control because both can be automated, but only RBAC ties permissions to a job function or role.

879
MCQmedium

A company allows employees to connect to the corporate network from home using a VPN. The security team wants to ensure that a remote employee's device meets minimum security requirements, such as current antivirus and patched operating system, before granting access to internal applications. Which control should be implemented?

A.Network access control (NAC) with posture assessment
B.Multi-factor authentication (MFA) for VPN logins
C.Full-disk encryption on employee laptops
D.Role-based access control (RBAC) on internal applications
AnswerA

NAC with posture assessment evaluates a device's security state, such as antivirus status, patch level, and firewall configuration, before or during network access. If the device fails the check, access can be denied or restricted to a remediation network. This directly enforces the minimum security requirements for remote employees connecting through the VPN.

Why this answer

NAC with posture assessment checks the endpoint's security state before granting network access, which is exactly what is needed to enforce antivirus and patch requirements for remote VPN users. RBAC governs user permissions, MFA verifies identity, and disk encryption protects data at rest; none of them validate the device's health at connection time.

Exam trap

The trap here is equating strong authentication with endpoint compliance, when MFA proves who the user is but not whether the device is healthy.

880
MCQhard

An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?

A.Separation of duties
B.Least privilege
C.Need-to-know
D.Defense in depth
AnswerA

Separation of duties splits a sensitive task across multiple people so no single individual holds end-to-end authority. Requiring a second manager's approval for transactions above $10,000 enforces this by preventing one employee from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

Why this answer

Requiring two separate approvals for a high-value transaction is the classic definition of separation of duties: no single individual has enough authority to complete a sensitive action alone. This prevents fraud and error by distributing control across multiple people.

Exam trap

CC often tests the overlap between separation of duties and least privilege, so candidates see 'restrict access' language and pick least privilege when the scenario is really about splitting authority across two people.

How to eliminate wrong answers

Option B is wrong because least privilege means granting users only the minimum access needed for their role, not requiring multiple approvers for one action. Option C is wrong because need-to-know restricts access to information based on job relevance, which is about data confidentiality, not transaction authorization. Option D is wrong because defense in depth layers multiple independent controls (firewalls, encryption, MFA) to protect an asset, whereas this scenario is a single dual-approval control.

881
Multi-Selectmedium

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Select 3 answers
A.Service Level Agreement (SLA) – the contractual uptime percentage guaranteed to customers.
B.Recovery Time Objective (RTO) – the maximum amount of time to restore a business function after a disruption.
C.Maximum Tolerable Downtime (MTD) – the total time a business function can be unavailable before causing irreparable harm.
D.Annualized Loss Expectancy (ALE) – the expected monetary loss per year from a risk.
E.Recovery Point Objective (RPO) – the maximum acceptable amount of data loss measured in time.
AnswersB, C, E

RTO defines the maximum tolerable downtime before a business function's disruption causes unacceptable impact, so it correctly bounds restoration time for the online banking platform. This matches the BIA metric definition, distinct from RPO, which measures tolerable data loss rather than recovery duration.

Why this answer

Option B is correct because the Recovery Time Objective (RTO) is a core BIA metric defining the maximum acceptable time to restore a business function or process after a disruption before unacceptable consequences occur. Option C is correct because the Maximum Tolerable Downtime (MTD), also called Maximum Acceptable Outage (MAO), defines the total time a business function can be unavailable before causing irreparable harm to the organization, and it typically bounds the RTO. Option E is correct because the Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, determining the required backup or replication frequency.

Option A is not a BIA metric but a contractual service commitment, and Option D is a risk-analysis quantitative value (SLE × ARO) rather than a BIA recovery metric.

Exam trap

The trap is mixing risk-analysis metrics (ALE, SLE, ARO) with BIA recovery metrics (RTO, RPO, MTD) — candidates see 'metric' and pick ALE because it sounds quantitative and important.

882
MCQmedium

A security analyst observes these SSH logs. What is the MOST likely attack?

A.Brute force attack on SSH service
B.Session hijacking via SSH
C.Phishing attack targeting root and admin accounts
D.Denial of service attack on port 22
AnswerA

Repeated authentication failures across many usernames from one source indicate automated credential guessing against the SSH daemon. A brute force attack systematically tries password combinations until one succeeds, matching the pattern of numerous failed logins in the captured logs.

Why this answer

The SSH logs show repeated failed authentication attempts from the same or multiple source IPs against common accounts (root, admin), which is the signature of a brute force attack. Automated tools like Hydra or Medusa cycle through username/password combinations, generating a high volume of 'Failed password' entries in a short time window. This pattern distinguishes brute force from other SSH-related attacks.

Exam trap

CC often tests whether candidates can differentiate brute force from DoS or session hijacking based on log evidence — the trap is seeing 'SSH' and 'attack' and jumping to DoS because of volume, when the actual indicator is authentication failure repetition.

How to eliminate wrong answers

Option B is wrong because session hijacking requires an established session to be stolen (e.g., via cookie theft or MITM) — the logs would show a successful login followed by anomalous activity, not repeated failed authentications. Option C is wrong because phishing targets users via email or fake sites to harvest credentials; while phished credentials could be used in SSH, the log pattern itself reflects automated guessing, not phishing. Option D is wrong because a DoS attack on port 22 would show connection floods, timeouts, or resource exhaustion — not authentication failures against specific accounts.

883
Multi-Selecthard

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Select 3 answers
A.A statement that a disaster has been declared
B.Details of the vulnerability exploited
C.Contact information for the incident response team
D.Instructions for employees to work remotely
E.Names of affected customers
AnswersA, C, D

The initial crisis communication must formally announce that a disaster has been declared, triggering DRP activation and mobilising response teams. Without this declaration, staff and stakeholders lack the authoritative signal that normal operations are suspended and recovery procedures now govern.

Why this answer

Option A is correct because the initial crisis communication must explicitly state that a disaster has been declared, which formally triggers the DRP and informs stakeholders that recovery procedures are now in effect. Option C is correct because providing contact information for the incident response team ensures that responders and key personnel can be reached immediately to coordinate recovery activities. Option D is correct because instructing employees to work remotely helps maintain business continuity and safety by directing staff away from potentially affected facilities.

Option B is not included because details of the exploited vulnerability are typically investigated and disclosed later by security or forensic teams, not in the initial crisis notification. Option E is also not included because naming affected customers raises privacy and legal concerns and is not part of the immediate internal crisis communication.

Exam trap

CC often tests the boundaries of what should be included in initial crisis communication, and candidates may incorrectly include technical details or customer information, confusing the need for transparency with the need for confidentiality and security.

884
MCQmedium

According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?

A.Requiring a mix of uppercase, lowercase, numbers, and special characters
B.Using randomly generated passwords
C.Changing passwords every 30 days
D.Enforcing a minimum length of at least 8 characters
AnswerD

NIST SP 800-63 prioritises length as the primary strength factor, since each added character multiplies guessing resistance far more than complexity rules. An 8-character minimum satisfies this by raising the search space, though verifiers should also screen against breached-password lists and rate-limit failed attempts.

Why this answer

NIST SP 800-63B explicitly recommends enforcing a minimum password length of at least 8 characters (and encourages longer, up to 64) as the primary strength control, while deprecating composition rules and mandatory rotation. Length is the dominant factor in resisting brute-force and dictionary attacks because it exponentially increases the search space. The guidance prioritizes memorized secrets that are long and unique over complex-but-short passwords.

Exam trap

The trap is that candidates apply legacy password-policy intuition (complexity + rotation = secure) instead of the modern NIST guidance, which inverts those assumptions and elevates length as the primary control.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-63B explicitly advises against requiring composition rules (uppercase, lowercase, numbers, special characters) since they encourage predictable patterns like 'Password1!' and reduce usability without meaningfully improving entropy. Option B is wrong because while randomly generated passwords are strong, NIST guidance focuses on requirements that verifiers should enforce — random generation is a recommendation for password managers, not the primary requirement factor. Option C is wrong because NIST recommends against forced periodic rotation, which leads to predictable incremental changes (e.g., Password1 → Password2) and weakens security; rotation should only occur on evidence of compromise.

885
MCQmedium

A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?

A.Restore the encrypted files from the most recent backup.
B.Pay the ransom to obtain the decryption key and recover the files quickly.
C.Rebuild the laptop from scratch and return it to the user.
D.Identify the scope of the incident and preserve evidence.
AnswerD

After isolating the infected system, the next step is to determine how many other systems are affected and to preserve volatile evidence such as memory and logs. This aligns with the containment, eradication, and recovery phases of incident response. Identifying scope prevents further spread and informs subsequent eradication and recovery actions.

Why this answer

Once an infected system is isolated, the next critical step is to determine the full scope of the compromise and preserve evidence. This allows the organization to understand how the ransomware entered, what else may be affected, and how to eradicate it properly. Recovery actions such as restoring backups or rebuilding systems should come after containment and scoping are complete.

Exam trap

The trap here is assuming that recovery or eradication should happen immediately after isolation, when in fact the next step is to identify scope and preserve evidence to avoid incomplete containment.

886
MCQhard

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

A.Symmetric encryption
B.Digital signature
C.Access control list
D.Hashing
AnswerB

A digital signature uses asymmetric cryptography: the signer's private key creates a hash-based value that any verifier can check with the public key. Altering the document invalidates that value, directly satisfying the requirement to detect changes since signing.

Why this answer

A digital signature uses asymmetric cryptography to sign a document's hash with the signer's private key, allowing anyone with the public key to verify both the signer's identity and that the document has not been altered. This provides integrity and non-repudiation, directly satisfying the requirement.

Exam trap

The trap is confusing hashing with digital signatures — hashing detects alteration but does not prove who signed, so candidates who pick hashing miss the non-repudiation requirement.

How to eliminate wrong answers

Option A is wrong because symmetric encryption provides confidentiality, not integrity verification or proof of origin. Option C is wrong because an ACL controls access permissions to resources, not document integrity. Option D is wrong because hashing alone detects alteration but does not bind the hash to a signer, so it cannot prove who signed or prevent an attacker from replacing both the document and its hash.

887
MCQeasy

During which phase of the incident response process would the team identify the root cause of a security incident?

A.Eradication
B.Preparation
C.Analysis
D.Detection
AnswerC

Analysis is the phase where investigators examine evidence to determine how the incident occurred, establishing root cause and scope. This directly satisfies the stem's requirement to identify root cause, distinguishing it from containment or eradication, which address the incident itself rather than understanding its origin.

Why this answer

The Analysis phase (also called Investigation) is where the incident response team examines all available data—logs, memory dumps, network captures—to determine how the incident occurred, what systems were affected, and the root cause. This phase follows Detection and precedes Eradication. Identifying the root cause is essential to ensure the same vulnerability isn't exploited again after containment and recovery.

Exam trap

The trap here is confusing the Analysis phase with Eradication, because many candidates think root cause is identified while removing the threat; however, eradication is purely about elimination, and analysis must precede it.

How to eliminate wrong answers

Option A is wrong because Eradication focuses on removing the threat (e.g., deleting malware, patching vulnerabilities) after the root cause has already been identified during Analysis. Option B is wrong because Preparation involves establishing policies, tools, and training before an incident occurs; no root cause analysis happens here. Option D is wrong because Detection is the phase where the incident is first discovered and confirmed, not where in-depth root cause investigation takes place.

888
MCQeasy

Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?

A.RTO
B.RPO
C.SLA
D.MTBF
AnswerB

RPO (Recovery Point Objective) defines the maximum tolerable data loss, measured backwards from the disruption to the last recoverable copy. It directly satisfies the stem's constraint by quantifying acceptable data loss in time, unlike RTO, which bounds downtime instead.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time, such as seconds, minutes, or hours. It determines the age of the backup or replication data that must be restored to resume normal operations after a disaster. For example, an RPO of 1 hour means the organization can tolerate losing up to 1 hour's worth of data.

Exam trap

ISC2 often tests the distinction between RTO and RPO, where candidates mistakenly select RTO because they confuse 'time to recover' with 'time of data loss' — remember RTO is about downtime, RPO is about data loss.

How to eliminate wrong answers

Option A (RTO) is wrong because RTO (Recovery Time Objective) defines the maximum acceptable downtime, not data loss; it measures how quickly systems must be restored after a disaster. Option C (SLA) is wrong because SLA (Service Level Agreement) is a contractual commitment between a provider and customer covering performance metrics like uptime, not a specific measure of tolerable data loss. Option D (MTBF) is wrong because MTBF (Mean Time Between Failures) is a reliability metric that predicts the average time between system failures, not a measure of data loss tolerance.

889
Multi-Selecteasy

An organization wants to implement multi-factor authentication (MFA) for remote access by requiring a password and a smart card. Which two authentication factors are used in this MFA implementation? (Choose two.)

Select 2 answers
A.Password
B.Smart card
C.Retina scan
D.Fingerprint scan
E.OTP token
AnswersA, B

Password is a knowledge factor (Type 1). Combining it with a possession factor like a smart card meets the definition of MFA.

Why this answer

Multi-factor authentication requires at least two different types of factors. A password is Type 1 (knowledge) and a smart card is Type 2 (possession), so combining them qualifies as MFA.

890
MCQmedium

A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerB

WRT is the time needed after systems are restored to verify data integrity and resume normal operations. The 30-minute verification period fits this definition, sitting separately from the 1-hour recovery time within the 2-hour tolerance.

Why this answer

The 30-minute verification period represents Work Recovery Time (WRT), which is the time needed after systems are technically restored to validate data integrity and confirm normal operations can resume. WRT is distinct from RTO because RTO covers only the time to bring systems back online, while WRT accounts for the post-recovery validation phase. Together, RTO + WRT must fit within the Maximum Tolerable Downtime (MTD) of 2 hours, which in this case is satisfied (1 hour RTO + 30 min WRT = 1.5 hours).

Exam trap

The trap here is confusing WRT with RTO — candidates see 'time to restore' and 'time to verify' and lump them together, but the exam specifically tests whether you know WRT is the post-restoration validation phase that sits between RTO completion and full business resumption.

How to eliminate wrong answers

Option A is wrong because RPO defines the maximum acceptable data loss measured in time (how far back the last good backup can be), not the verification period after restoration. Option C is wrong because MTD is the total maximum time the business can tolerate the system being unavailable (2 hours here), which encompasses both RTO and WRT rather than representing just the verification window. Option D is wrong because RTO is the target time to restore the system from backups (1 hour here), not the additional time needed to verify data integrity and resume normal operations.

891
MCQmedium

A financial institution wants to ensure that a wire transfer request cannot be denied by the sender later. The security team implements a mechanism where the sender's private key is used to sign the transaction. Which security principle does this primarily support?

A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerC

Non-repudiation ensures that a party cannot deny the authenticity of their signature on a document or the sending of a message. By signing the wire transfer with a private key, the sender cannot later claim they did not authorize it. This directly supports non-repudiation, which is crucial for financial transactions to prevent fraud and disputes.

Why this answer

The correct answer is non-repudiation. Using a private key to sign a wire transfer provides proof of origin and prevents the sender from denying the transaction. While digital signatures also support integrity, the specific requirement to prevent denial makes non-repudiation the primary principle.

Confidentiality and availability are unrelated to this scenario's goal.

Exam trap

The trap here is assuming that digital signatures only provide integrity, overlooking that they also deliver non-repudiation, which is the key requirement in this scenario.

892
MCQeasy

A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?

A.Disable all external sharing
B.Require authentication for shared links
C.Use watermarking on documents
D.Encrypt all files
AnswerB

Requiring authentication for shared links forces recipients to sign in, typically via Microsoft Entra ID, before accessing files. This satisfies the constraint of preventing anonymous public exposure while preserving legitimate external sharing, since links still work for authenticated users. Anonymous access, the root cause of the leak, is eliminated without disabling sharing entirely.

Why this answer

Requiring authentication for shared links ensures that only authorized users can access the shared content, preventing public exposure of sensitive data while still allowing legitimate sharing with specific individuals. This balances security with the need to share files externally.

Exam trap

The trap is choosing encryption or watermarking as a preventive measure: candidates may think encrypting files prevents unauthorized access, but encryption does not stop someone with the link from accessing the decrypted content if the service handles decryption; authentication is the direct control for link access.

How to eliminate wrong answers

Option A is wrong because disabling all external sharing would block legitimate sharing, which the business wants to avoid. Option C is wrong because watermarking deters unauthorized distribution but does not prevent access to the data in the first place. Option D is wrong because encrypting files protects data at rest but does not control who can access the shared link; if the link is public, the recipient can still decrypt if they have access.

893
MCQhard

A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?

A.Logical access control
B.Compensating control
C.Physical access control
D.Administrative control
AnswerA

Account lockout after repeated failed logins is a logical access control: a software-enforced restriction on authentication attempts. It mitigates brute-force or password-guessing attacks from a single source by temporarily denying access, unlike physical or administrative controls.

Why this answer

Account lockout after repeated failed logins is enforced by software (the operating system or application authentication logic), making it a logical access control. Logical controls govern access to systems and data through technical means such as passwords, lockout policies, and permissions, as opposed to physical or administrative controls.

Exam trap

CC often tests the distinction between control types (logical/technical vs. physical vs. administrative) and control functions (preventive vs. compensating), tricking candidates who focus on the attack rather than the control category.

How to eliminate wrong answers

Option B is wrong because a compensating control is an alternative safeguard used when a primary control cannot be implemented (e.g., compensating for missing encryption with network segmentation) — lockout is a primary preventive control, not a substitute. Option C is wrong because physical access controls involve tangible barriers like locks, badges, and guards, not authentication logic. Option D is wrong because administrative controls are policy, procedure, and training-based (e.g., acceptable use policies), not automated technical enforcement.

894
Multi-Selectmedium

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Select 2 answers
A.A PIN
B.A hardware OTP token
C.A fingerprint
D.A password
E.A smart card
AnswersB, E

A hardware OTP token is a physical device issued to the user, so presenting its generated code demonstrates possession. That tangible-device characteristic is precisely what qualifies it as a Type 2 factor rather than knowledge or inherence.

Why this answer

A hardware OTP token (B) is correct because it is a physical device the user must possess, and it generates one-time passcodes, making it a classic Type 2 possession factor. A smart card (E) is also correct because it is a physical object the user holds and inserts or taps to authenticate, fitting the possession category. In contrast, a PIN (A) and a password (D) are knowledge factors (Type 1) because they rely on something the user knows, and a fingerprint (C) is an inherence factor (Type 3) because it relies on a biometric characteristic of the user.

Exam trap

CC often tests the confusion between knowledge and possession factors; candidates mistakenly classify a PIN or password as 'something you have' because it's stored on a device, or mislabel biometrics as possession.

895
MCQhard

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

A.Provide diligent and competent service to principals
B.Act honorably, honestly, justly, responsibly, and legally
C.Protect society, the common good, necessary public trust and confidence, and the infrastructure
D.Advance and protect the profession
AnswerC

The Code of Ethics ranks obligations to the public above duties to clients and employers. Protecting society, the common good, public trust and the infrastructure is the paramount imperative, so it takes precedence over all other canons when interests conflict.

Why this answer

The (ISC)² Code of Ethics canons are ordered by priority, and the first canon is to protect society, the common good, necessary public trust and confidence, and the infrastructure. This takes precedence over duties to principals, the profession, and self. The other canons follow in descending order.

Exam trap

CC often tests the order of the (ISC)² canons; candidates frequently assume duty to the client (principal) is paramount, but the exam emphasizes society and public trust as the highest priority.

How to eliminate wrong answers

Option A is wrong because providing diligent and competent service to principals is the third canon, lower priority than protecting society. Option B is wrong because acting honorably, honestly, justly, responsibly, and legally is the second canon, not the highest. Option D is wrong because advancing and protecting the profession is the fourth and lowest-priority canon.

896
MCQmedium

A company implements a policy where a financial transaction must be initiated by one employee and approved by a different employee. This is an example of which access control concept?

A.Need-to-know
B.Separation of duties
C.Least privilege
D.Job rotation
AnswerB

Splitting initiation and approval between two distinct employees prevents one person from completing the entire transaction alone. This enforces separation of duties, a preventive control that reduces fraud risk by requiring collusion to circumvent the process.

Why this answer

Separation of duties (SoD) is an access control concept that requires a critical task, such as a financial transaction, to be split into multiple steps performed by different individuals. This prevents any single employee from having the authority to both initiate and approve a transaction, thereby reducing the risk of fraud or error. In this scenario, the policy directly enforces SoD by ensuring that no one person can complete the entire process alone.

Exam trap

ISC2 often tests candidates by confusing separation of duties with least privilege, as both involve limiting user actions, but the key distinction is that separation of duties requires multiple people to complete a task, while least privilege only limits the permissions of a single user.

How to eliminate wrong answers

Option A is wrong because need-to-know restricts access to information based on an individual's job requirements, not on splitting tasks among multiple people. Option C is wrong because least privilege grants users only the minimum permissions necessary to perform their job, but it does not require a second person to approve an action. Option D is wrong because job rotation moves employees between roles over time to cross-train and reduce boredom, but it does not enforce a dual-authority requirement for a single transaction.

897
MCQhard

A security engineer is deploying a new VPN solution for remote employees. The company requires that the VPN provide strong encryption, support for multiple users, and the ability to traverse NAT devices. Which VPN protocol should the engineer choose?

A.PPTP
B.IPsec in transport mode
C.L2TP/IPsec
D.SSTP
AnswerC

L2TP/IPsec combines L2TP for tunneling with IPsec for strong encryption and authentication. It supports multiple users and can traverse NAT devices when NAT-T (NAT Traversal) is enabled. This makes it a suitable choice for remote access VPNs requiring strong security and NAT compatibility.

Why this answer

L2TP/IPsec provides strong encryption through IPsec, supports multiple users, and can traverse NAT with NAT-T. It is a widely supported standard for remote access VPNs. The other options either lack strong encryption (PPTP), are platform-specific (SSTP), or are not designed for remote access tunneling (IPsec transport mode).

Exam trap

The trap here is assuming that any VPN protocol with encryption is sufficient, but NAT traversal and multi-user support are critical for remote access.

898
Multi-Selectmedium

Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)

Select 2 answers
A.ICMP
B.LDAP
C.SSL/TLS
D.SNMP
E.IPsec
AnswersC, E

SSL/TLS is used for secure web-based VPNs.

Why this answer

SSL/TLS is a common method to secure VPN connections, typically used in SSL VPNs. It operates at the transport layer (Layer 4) and provides encryption, authentication, and integrity for data transmitted over the internet, often using port 443 to bypass firewalls. This makes it ideal for remote access VPNs where clients connect via a web browser or a lightweight client.

Exam trap

ISC2 often tests the distinction between VPN security protocols (IPsec, SSL/TLS) and unrelated network protocols (ICMP, SNMP, LDAP) to see if candidates confuse management or authentication protocols with encryption/tunneling mechanisms.

899
MCQmedium

A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?

A.Data tampering
B.Unauthorized disclosure
C.Denial of service
D.Repudiation
AnswerB

Encryption at rest and in transit directly counters unauthorised disclosure by rendering intercepted or exfiltrated data unreadable without decryption keys. This satisfies the policy's confidentiality requirement, addressing the threat of data being read by parties lacking authorisation, whether during network transmission or while stored on disk.

Why this answer

Encryption at rest and in transit protects data confidentiality by rendering it unreadable to unauthorized parties, directly mitigating unauthorized disclosure. Encryption ensures that even if data is intercepted or accessed, it cannot be understood without the decryption key. This control is a fundamental safeguard against data breaches and privacy violations.

Exam trap

The trap here is confusing encryption with other security goals like integrity or availability; candidates might think encryption also prevents tampering or repudiation, but it primarily ensures confidentiality.

How to eliminate wrong answers

Option A is wrong because data tampering is addressed by integrity controls such as hashing, digital signatures, or checksums, not encryption alone. Option C is wrong because denial of service is mitigated by availability controls like redundancy, rate limiting, and DDoS protection, not encryption. Option D is wrong because repudiation is addressed by non-repudiation mechanisms such as digital signatures and audit logs, not encryption.

900
MCQeasy

A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?

A.The results of a recent vulnerability scan
B.The normal traffic patterns during peak business hours
C.The latest attack signatures from the vendor
D.The firewall logs from the past 24 hours
AnswerB

Baselining normal peak-hour traffic patterns establishes what legitimate activity looks like, so the NIDS can flag only deviations. This directly satisfies the stem's constraint of minimising false positives, since signatures tuned to a known baseline avoid alerting on routine business traffic.

Why this answer

Baselining normal traffic patterns during peak business hours establishes a reference of legitimate network behavior, which is essential for a NIDS to distinguish benign anomalies from actual threats. Without this baseline, the NIDS may generate false positives by flagging legitimate peak-hour traffic spikes as malicious. This aligns with the principle that anomaly-based detection relies on a statistical model of normal activity to reduce noise.

Exam trap

ISC2 often tests the distinction between anomaly-based and signature-based detection, and the trap here is that candidates mistakenly think vulnerability scans or firewall logs provide a sufficient baseline, when in fact only observed normal traffic patterns during representative periods (like peak hours) can minimize false positives in an anomaly-based NIDS.

How to eliminate wrong answers

Option A is wrong because vulnerability scan results identify known weaknesses but do not define normal traffic behavior, so they cannot help the NIDS differentiate benign from malicious traffic patterns. Option C is wrong because attack signatures are used for signature-based detection, not for establishing a baseline to minimize false positives in anomaly-based detection; relying solely on signatures can miss novel attacks and still generate false positives if traffic matches signatures incorrectly. Option D is wrong because firewall logs from the past 24 hours provide only a limited snapshot of traffic and may not capture the full range of normal patterns, especially during peak hours, leading to an incomplete baseline.

Page 11

Page 12 of 14

Page 13