Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 901–975

989 questions total · 14pages · All types, answers revealed

Page 12

Page 13 of 14

Page 14
901
MCQmedium

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk mitigation
D.Risk transfer
AnswerB

Risk acceptance means acknowledging a risk and choosing to bear its potential impact without further mitigation, which matches the decision to tolerate the unpatched legacy system because isolation and compensating controls reduce exposure to an acceptable level.

Why this answer

Risk acceptance means the organization acknowledges the risk and chooses to retain it without taking further action, often because the cost of mitigation outweighs the potential impact or because compensating controls reduce it to an acceptable level. Here, the legacy system is isolated with compensating controls, so the organization formally accepts the residual risk.

Exam trap

CC often tests the distinction between acceptance and mitigation; candidates see 'compensating controls' and pick mitigation, but the key phrase is 'decides to accept the risk' — the controls justify acceptance, not further action.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or system that introduces the risk entirely, not keeping it. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact, which the organization has already done via isolation and compensating controls; the decision to not do more is acceptance. Option D is wrong because risk transfer shifts the risk to a third party, such as through insurance or outsourcing, which is not described here.

902
MCQeasy

A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?

A.A brute-force vulnerability, because the clerk's account retained credentials that could be attacked repeatedly.
B.Privilege creep caused by failing to remove access rights when job responsibilities change.
C.An implicit deny failure, because the access control system did not block the finance permissions by default.
D.A separation of duties conflict, because one person now holds finance and HR access simultaneously.
AnswerB

Privilege creep occurs when a user accumulates access rights over time as roles change and old entitlements are never revoked. The clerk's finance permissions should have been removed when the transfer occurred. The residual rights create unnecessary exposure and violate least privilege, making this the accurate description of the weakness.

Why this answer

When employees change roles, their previous entitlements must be revoked so that access always matches current duties. Retaining finance permissions after moving to HR creates privilege creep, a gradual accumulation of rights that violates least privilege and expands the attack surface. Periodic access reviews and prompt deprovisioning during transfers are the standard controls that prevent this situation.

Exam trap

The trap here is confusing accumulated stale permissions with a deliberately designed separation of duties control.

903
Drag & Dropmedium

Drag and drop the steps to configure a basic VPN (site-to-site) between two routers into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Configuring a site-to-site VPN between two routers requires a specific sequence: first establish IKE policy and pre-shared keys for authentication, then define the IPsec transform set for encryption and integrity, then specify interesting traffic via a crypto ACL, then create and apply the crypto map to the outgoing interface, and finally verify the tunnel. This order ensures all security parameters are correctly bound and operational.

904
MCQmedium

A regional hospital's emergency department relies on a patient tracking system. The BIA shows the system's maximum tolerable downtime (MTD) is 2 hours. The recovery time objective (RTO) is currently 6 hours, and the recovery point objective (RPO) is 24 hours. Which action best aligns the recovery capability with the business requirement?

A.Increase the MTD to 6 hours so it matches the existing RTO.
B.Implement a hot site that can recover the system within 24 hours, matching the RPO.
C.Reduce the RTO to 2 hours or less and reduce the RPO to a level that meets clinical data loss tolerance.
D.Maintain the current RTO and RPO because the MTD is only a guideline and not a strict requirement.
AnswerC

The MTD of 2 hours is the absolute limit the hospital can tolerate without unacceptable patient safety risk. The RTO must be less than or equal to the MTD to ensure recovery occurs within that window. Additionally, the RPO must be reviewed to ensure the acceptable data loss aligns with clinical needs, because a 24-hour RPO could mean losing a full day of patient records. This option directly addresses both the time to recover and the data loss tolerance.

Why this answer

The MTD is the maximum time a business process can be unavailable. For the patient tracking system, the MTD is 2 hours. The RTO, which is the target time to restore the system, must be less than or equal to the MTD.

The current RTO of 6 hours exceeds the MTD, so it must be reduced. The RPO must also be evaluated to ensure data loss is acceptable. Reducing the RTO and reassessing the RPO ensures recovery aligns with the business requirement.

Exam trap

The trap here is confusing the MTD with the RTO, or assuming the MTD can be changed to match an existing RTO, when the MTD is a fixed business requirement.

905
MCQhard

A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:

A.Web Application Firewall (WAF)
B.Intrusion Detection System (IDS)
C.Intrusion Prevention System (IPS)
D.Stateful firewall
AnswerB

Correct. IDS is passive, alerting only.

Why this answer

An Intrusion Detection System (IDS) passively monitors network traffic, analyzes it against signatures or behavioral baselines, and generates alerts on suspicious activity without blocking or modifying traffic. The question explicitly states the device 'does not take any action,' which is the defining characteristic of an IDS versus an IPS. A WAF and stateful firewall both enforce policy and can block traffic, so they do not fit the passive description.

Exam trap

The trap here is confusing IDS with IPS — candidates see 'monitors traffic and generates alerts' and pick IPS because they associate detection with prevention, but the key phrase 'does not take any action' locks in IDS.

How to eliminate wrong answers

Option A is wrong because a WAF actively inspects and blocks HTTP/HTTPS requests based on rules (e.g., OWASP Top 10), so it takes action rather than being passive. Option C is wrong because an IPS sits inline and actively drops or resets malicious traffic — the opposite of the passive behavior described. Option D is wrong because a stateful firewall maintains connection state and enforces allow/deny rules, which is an active enforcement function, not passive monitoring.

906
MCQmedium

A government agency uses a multi-level security system with mandatory access control (MAC). A user with Secret clearance attempts to write data to a file classified as Confidential. Under the Bell-LaPadula model, which rule applies and what is the outcome?

A.The simple security property (no read up) denies the operation
B.The *-property allows the operation because the user is writing down
C.The simple security property allows the operation because the user's clearance is higher
D.The *-property (no write down) denies the operation
AnswerD

The Bell-LaPadula model's \*-property (star property) specifically enforces "no write down", a critical rule for maintaining confidentiality. This property dictates that a subject cannot write to an object with a lower security classification. Here, the user with Secret clearance attempts to write to a Confidential file. As Secret is a higher classification than Confidential, this operation is a write-down, which the \*-property consequently denies to prevent information flow to lower levels.

Why this answer

The Bell-LaPadula model enforces mandatory access control (MAC) with two primary rules: the simple security property (no read up) and the *-property (no write down). In this scenario, a user with Secret clearance attempts to write to a Confidential file, which is a write-down operation. The *-property prohibits writing to a lower classification to prevent the leakage of higher-classified information, so the operation is denied.

Option D correctly identifies this rule and outcome.

Exam trap

ISC2 often tests the confusion between the simple security property (no read up) and the *-property (no write down), leading candidates to mistakenly apply the read rule to a write operation or assume that higher clearance allows writing down.

How to eliminate wrong answers

Option A is wrong because the simple security property (no read up) governs read operations, not write operations, and here the user is writing, not reading. Option B is wrong because the *-property does not allow write-down; it explicitly prohibits writing to a lower classification to maintain confidentiality. Option C is wrong because the simple security property allows read-down, not write-down, and it does not permit writing to a lower classification based on clearance level.

907
MCQmedium

A network administrator is designing a DMZ to host a public-facing web server and a database server that should only be accessible from the web server. Which of the following firewall rule sets best achieves this design?

A.Allow inbound HTTP/HTTPS to web server; allow web server to database on port 3306; deny all else
B.Allow web server to initiate outbound connections to internet; allow database to initiate connections to web server; deny all else
C.Allow inbound HTTP/HTTPS to web server; allow all traffic from web server to database; deny all else
D.Allow inbound HTTP/HTTPS to web server; allow inbound SQL from internet to database; deny all else
AnswerA

This rule set enforces least privilege: public traffic reaches only the web server, the database accepts connections solely from that web server on port 3306, and everything else is denied. The database therefore remains unreachable directly from the internet, satisfying the DMZ segmentation requirement.

Why this answer

It implements the principle of least privilege for a DMZ: it allows inbound HTTP/HTTPS traffic (ports 80/443) to the public-facing web server, then permits only the web server to initiate outbound connections to the database server on port 3306 (MySQL/MariaDB default), and denies all other traffic. This ensures the database is not directly accessible from the internet, reducing the attack surface while still supporting the required application flow.

Exam trap

ISC2 often tests the principle of least privilege by including options that allow overly broad access (like 'all traffic' from web to database) or reverse the direction of connections, so the trap here is assuming that any traffic between the web server and database is acceptable without specifying the exact protocol and port.

How to eliminate wrong answers

Option B is wrong because it allows the web server to initiate outbound connections to the internet, which is unnecessary and could be used for data exfiltration or command-and-control traffic; it also incorrectly allows the database to initiate connections to the web server, which violates the design requirement that the database should only be accessible from the web server. Option C is wrong because it allows all traffic from the web server to the database, not just the specific SQL port (3306), which could permit other protocols or services to reach the database, increasing the attack surface. Option D is wrong because it allows inbound SQL traffic from the internet directly to the database server, which directly contradicts the requirement that the database should only be accessible from the web server and exposes the database to external attacks.

908
Multi-Selectmedium

A security manager is training new employees on the concept of risk. She explains that risk is composed of several elements. Which TWO of the following are components that directly contribute to risk? (Choose two.)

Select 2 answers
A.Policy
B.Control
C.Threat
D.Vulnerability
E.Audit
AnswersC, D

A threat is any potential cause of an unwanted incident that could harm an asset. In risk management, threat is a core component because risk exists only when there is a threat that can exploit a vulnerability. Without a threat, a vulnerability alone does not create risk. Therefore, threat directly contributes to risk and is one of the correct elements.

Why this answer

Risk is commonly defined as the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact. Threat and vulnerability are the two essential components that must be present for risk to exist. Policy, audit, and control are important security concepts, but they are not direct constituents of risk; rather, they are mechanisms used to govern, verify, or mitigate risk.

Exam trap

The trap here is including controls or policies as components of risk, when actually they are responses to risk and not part of its fundamental definition.

909
Multi-Selectmedium

Which THREE of the following are examples of the principle of least privilege? (Select THREE.)

Select 3 answers
A.Granting a user only the permissions needed to perform their job
B.Giving all employees full access to the file server
C.Allowing a contractor access only during their contract period
D.Providing read-only access to a database for a reporting analyst
E.Assigning administrator rights to all employees by default
AnswersA, C, D

Least privilege means granting the minimum access required for a task. Restricting a user to only the permissions their job demands directly satisfies this, since no excess rights are assigned beyond the specific work functions they must perform.

Why this answer

Option A is correct because least privilege means granting a user only the specific permissions required to perform their job functions, nothing more. Option C is correct because limiting a contractor's access to the duration of their contract enforces least privilege by ensuring access is revoked when no longer needed (time-bound access). Option D is correct because giving a reporting analyst read-only access to a database restricts them to the minimum access necessary for reporting, preventing unnecessary write or administrative capabilities.

Options B and E are incorrect because granting all employees full file server access or administrator rights by default violates least privilege by providing excessive, broad permissions beyond what any individual role requires.

Exam trap

ISC2 often tests the principle of least privilege by including options that sound reasonable but grant excessive access, such as 'full access to the file server' or 'administrator rights to all employees,' to see if candidates recognize that even temporary or role-based access must be strictly limited to the minimum necessary.

910
MCQmedium

An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?

A.Intrusion Detection System (IDS)
B.Intrusion Prevention System (IPS)
C.Packet filtering firewall
D.Honeypot
AnswerB

Correct. IPS is inline and can block.

Why this answer

An IPS is designed to sit inline in the traffic path, inspect packets in real time, and actively block malicious traffic by dropping or resetting connections. This matches the requirement to both detect and block attacks inline. An IDS only detects and alerts; it cannot block because it is not inline.

Exam trap

The trap here is confusing detection with prevention: candidates see 'detect' and pick IDS, ignoring the requirement to 'block' inline, which only an IPS can satisfy.

How to eliminate wrong answers

Option A is wrong because an IDS is typically deployed out-of-band via a SPAN port or TAP and can only detect and alert, not block. Option C is wrong because a packet filtering firewall makes allow/deny decisions based on headers (IP, port, protocol) and lacks deep packet inspection or signature-based attack detection. Option D is wrong because a honeypot is a decoy system used to lure and study attackers, not to block production traffic inline.

911
MCQhard

During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?

A.The standby site's network connectivity was not tested
B.The database replication configuration was incorrect
C.The database failover procedure was not documented
D.The DR plan did not include role-based access for failover operations
AnswerD

Failover stalled because the application team lacked privileges to promote the replica, so the DR plan omitted the role-based access assignments needed for that operation. Documenting those permissions satisfies the stem's requirement that failover steps be executable during a primary-site outage.

Why this answer

The scenario explicitly states that the application team lacks the necessary privileges to promote the standby database. This indicates that the disaster recovery plan did not define role-based access controls (RBAC) or assign failover permissions to specific personnel or groups. Without documented roles and privileges, even a fully replicated standby database cannot be promoted, causing a failover gap.

Exam trap

ISC2 often tests the distinction between a missing procedure (documentation gap) and missing authorization (access control gap), leading candidates to pick 'procedure not documented' when the real issue is that the team lacks the privileges to execute any procedure.

How to eliminate wrong answers

Option A is wrong because network connectivity, while important for replication and access, is not the root cause here—the standby site has a replica, implying connectivity exists. Option B is wrong because the replication configuration is correct (the standby has a replica), so the issue is not with replication setup but with authorization to promote. Option C is wrong because while the failover procedure may not be documented, the core problem is the lack of privileges to execute any documented procedure—documentation alone does not grant access rights.

912
Multi-Selecteasy

Which TWO of the following are common methods to authenticate users on a wireless network? (Select TWO)

Select 2 answers
A.WEP
B.WPA3-SAE
C.802.1X with RADIUS
D.WPA2-PSK
E.MAC address filtering
AnswersB, C

WPA3-SAE provides secure password-based authentication for personal mode.

Why this answer

WPA3-SAE (Simultaneous Authentication of Equals) is a common method to authenticate users on a wireless network because it replaces the pre-shared key (PSK) exchange with a secure password-based authentication protocol that is resistant to offline dictionary attacks. It uses a Diffie-Hellman key exchange combined with a shared password to derive a Pairwise Master Key (PMK), ensuring forward secrecy and mutual authentication.

Exam trap

ISC2 often tests the distinction between encryption protocols (like WEP and WPA2-PSK) and actual authentication methods, leading candidates to mistakenly select WPA2-PSK or MAC address filtering as user authentication mechanisms when they are only device-based access controls.

913
MCQmedium

An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?

A.OU=Sales
B.DC=com
C.CN=John Smith
D.DC=company
AnswerA

OU=Sales identifies the organizational unit, since the OU attribute type in a distinguished name denotes a container within the directory hierarchy. The stem asks specifically which component represents the organizational unit, and this value directly satisfies that constraint, distinguishing it from CN (common name) and DC (domain component) elements.

Why this answer

In an LDAP distinguished name (DN), each component is identified by its attribute type. The organizational unit (OU) is represented by the 'OU=' attribute. In the given DN, 'OU=Sales' explicitly designates the organizational unit named 'Sales'.

Exam trap

The trap here is confusing domain components (DC) with organizational units (OU). Candidates might incorrectly select DC=company as the OU because it sounds like an organizational name, but DC always denotes a domain component, not an OU.

How to eliminate wrong answers

Option B is wrong because 'DC=com' represents a domain component, not an organizational unit. Option C is wrong because 'CN=John Smith' represents a common name, typically a user or object. Option D is wrong because 'DC=company' also represents a domain component, not an organizational unit.

914
MCQmedium

A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?

A.Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets
B.Configure the guest SSID to use a captive portal for user registration
C.Enable WPA3-Personal on the guest SSID with a strong pre-shared key
D.Set the guest SSID to broadcast on a different wireless channel than the corporate SSID
AnswerA

Placing guest traffic on a dedicated VLAN and applying firewall rules that deny access to internal subnets enforces isolation at the network layer. Even if a guest device is compromised or misconfigured, it cannot route to corporate resources because the policy explicitly blocks that traffic, satisfying the stated requirement.

Why this answer

Guest isolation requires a logical network boundary, which is achieved by assigning the guest SSID to a dedicated VLAN and enforcing firewall rules that deny access to internal subnets. Wireless encryption, captive portals, and channel selection do not create that boundary. Without the VLAN and firewall policy, guest devices may reach corporate resources.

Exam trap

The trap here is assuming that a separate SSID, or strong wireless encryption on that SSID, automatically isolates guest traffic from the internal network.

915
Multi-Selecthard

A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)

Select 2 answers
A.Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall
B.Allowing all outbound traffic from the DMZ to the internal network
C.Connecting all servers to a single flat VLAN for simplified management
D.Placing public web servers in a screened subnet (DMZ) with strict firewall rules
E.Disabling host-based firewalls on internal servers to avoid application conflicts
AnswersA, D

Segmenting internal systems into VLANs and enforcing firewall policy between them prevents a compromised host from freely reaching other systems. Even within the internal network, lateral movement is constrained because traffic between segments must pass through a policy enforcement point. This reduces the blast radius of an incident and supports least-privilege access.

Why this answer

Defense in depth relies on segmentation and policy enforcement at multiple points. A screened subnet keeps public services away from internal systems, and internal VLANs with firewall-controlled inter-VLAN traffic limit lateral movement. Flat networks, unrestricted DMZ outbound access, and disabled host firewalls all weaken these protections and increase the impact of a compromise.

Exam trap

The trap here is choosing convenience-oriented options such as a flat network or disabled host firewalls, which simplify management but directly undermine segmentation and least privilege.

916
MCQeasy

Which port number is associated with HTTPS, and what protocol encrypts the communication?

A.Port 80, SSL/TLS
B.Port 8080, SSL/TLS
C.Port 443, SSL/TLS
D.Port 443, SSH
AnswerC

HTTPS is assigned TCP port 443 by IANA, and the transport encryption is provided by SSL/TLS, with TLS being the modern successor to SSL. This pairing satisfies both the port and encryption protocol elements of the question.

Why this answer

HTTPS uses TCP port 443 by default, and the communication is encrypted using SSL/TLS (with TLS 1.2/1.3 being the modern versions). Port 443 is the IANA-assigned port for HTTP over TLS, and SSL/TLS provides the encryption, integrity, and server authentication for the session.

Exam trap

CC often tests the pairing of port number and protocol — candidates sometimes confuse 8080 with 443 or assume SSH encrypts HTTPS, but the correct mapping is 443 + SSL/TLS.

How to eliminate wrong answers

Option A is wrong because port 80 is the default for plain HTTP, which is unencrypted — SSL/TLS is not used on port 80 by default. Option B is wrong because port 8080 is a common alternative HTTP port (often used for proxies or app servers) and is not the standard HTTPS port. Option D is wrong because SSH (port 22) is a secure remote shell protocol, not the encryption protocol used by HTTPS; HTTPS uses SSL/TLS, not SSH.

917
MCQmedium

A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?

A.The entire sequence is authorization, because the workstation validates a digital certificate.
B.The username provides identification, while the smart card and password together provide authentication.
C.The smart card performs identification, while the username and password perform authentication.
D.The smart card and password together perform identification, while the username performs authentication.
AnswerB

The user states who they claim to be by entering a username, which is identification. The system then verifies that claim through the smart card (something you have) and the password (something you know), which constitute authentication. This two-factor validation matches the classic definition of authentication as proving a claimed identity before authorization is evaluated.

Why this answer

Identification is the act of claiming an identity, and authentication is the act of proving that claim. Typing a username claims an identity, while the smart card and password independently verify it using possession and knowledge factors. Because two distinct factor types are required, the workflow is multi-factor authentication, and authorization would only follow once verification succeeds.

Exam trap

The trap here is assuming that any second credential automatically becomes the identification step rather than remaining part of authentication.

918
MCQhard

During a security audit, a penetration tester captures network traffic and finds that some packets have the IP ID field set to 0 and the DF (Don't Fragment) flag set. What is this technique attempting to do?

A.Spoof the source IP address of the attacker's machine
B.Launch a denial-of-service attack against the target
C.Perform a stealth scan using a zombie host to hide the attacker's identity
D.Evade a firewall by fragmenting packets
AnswerC

Idle scan uses IP ID to map a zombie's activity and infer port states.

Why this answer

Setting the IP ID field to 0 and the DF flag in packets is characteristic of an idle scan (also known as a stealth scan). This technique uses a zombie host (with an incremental IP ID) to probe a target; by sending packets with DF set and IP ID 0 to the zombie, the attacker can observe changes in the zombie's IP ID to infer open ports on the target, thereby hiding the attacker's true IP address.

Exam trap

ISC2 often tests the idle scan by focusing on the combination of IP ID 0 and DF flag, leading candidates to mistakenly think it is about fragmentation evasion or simple spoofing, rather than the stealthy reconnaissance technique using a zombie host.

How to eliminate wrong answers

Option A is wrong because spoofing the source IP address does not require setting the IP ID to 0 or the DF flag; spoofing simply falsifies the source address field in the IP header. Option B is wrong because a denial-of-service attack aims to overwhelm a target with traffic, not to stealthily probe ports using a zombie's IP ID behavior. Option D is wrong because evading a firewall by fragmenting packets would involve setting the MF (More Fragments) flag or using small fragment sizes, not setting DF (which prevents fragmentation) and IP ID 0.

919
MCQmedium

A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?

A.A demilitarized zone (DMZ)
B.A proxy server
C.A virtual private network (VPN)
D.A virtual local area network (VLAN)
AnswerC

A VPN establishes an encrypted tunnel between the remote employee and the corporate network, protecting data in transit over the public internet. It also authenticates users before allowing access to internal applications, which matches the policy. This makes it the appropriate technology for secure remote access in this scenario.

Why this answer

The policy requires an encrypted tunnel over the public internet plus user authentication for internal application access. A VPN provides exactly that by encapsulating traffic and terminating at the corporate edge after verifying credentials. DMZs isolate public services, VLANs segment local networks, and proxies forward specific requests, but none deliver the encrypted authenticated remote-access tunnel described.

Exam trap

The trap here is treating any technology that hides or forwards traffic, such as a proxy, as equivalent to an encrypted authenticated remote-access tunnel.

920
MCQhard

An organization wants to implement a system that enforces access decisions based on a user's attributes (e.g., department, clearance, time) and environmental conditions. Which model is best?

A.Role-based access control (RBAC)
B.Attribute-based access control (ABAC)
C.Discretionary access control (DAC)
D.Mandatory access control (MAC)
AnswerB

ABAC evaluates policies against any combination of subject, resource, action and environmental attributes, such as department, clearance and time. This dynamic, fine-grained evaluation satisfies the requirement to enforce decisions on user attributes plus environmental conditions.

Why this answer

Attribute-based access control (ABAC) is the correct model because it evaluates access decisions based on a combination of user attributes (e.g., department, clearance), resource attributes, and environmental conditions (e.g., time of day, location). Unlike RBAC, which relies solely on predefined roles, ABAC uses policies that can incorporate dynamic factors like current time or threat level, making it ideal for fine-grained, context-aware enforcement.

Exam trap

ISC2 often tests the misconception that RBAC can handle dynamic conditions like time or location, but RBAC only maps users to roles with static permissions, whereas ABAC explicitly evaluates environmental attributes as part of the access decision.

How to eliminate wrong answers

Option A is wrong because RBAC assigns permissions based on static roles, not on user attributes or environmental conditions, so it cannot enforce time-based or clearance-level decisions dynamically. Option C is wrong because DAC allows resource owners to set permissions at their discretion, lacking centralized policy control and the ability to incorporate environmental attributes like time. Option D is wrong because MAC enforces access based on fixed security labels (e.g., classification levels) and system-wide rules, not on user-specific attributes or environmental conditions, making it inflexible for attribute-driven policies.

921
MCQmedium

A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?

A.Incremental backup
B.Synthetic full backup
C.Full backup
D.Differential backup
AnswerD

A differential backup captures all data changed since the last full backup, not since the previous incremental. Wednesday's backup therefore includes Monday's and Tuesday's changes, satisfying the stem's constraint that it contains everything modified since Monday's full backup.

Why this answer

A differential backup captures all data changed since the last full backup, regardless of how many incremental or differential backups have occurred since. Since Monday's full backup is the baseline and Wednesday's backup includes everything changed since Monday, it is a differential backup. It does not reset the baseline, so Thursday's differential would also include Tuesday's and Wednesday's changes.

Exam trap

The trap here is confusing 'changed since the last backup' (incremental) with 'changed since the last full backup' (differential) — the phrase 'since Monday' is the giveaway.

How to eliminate wrong answers

Option A is wrong because an incremental backup only captures changes since the last backup of any type (full or incremental); Wednesday's incremental would only contain Tuesday-to-Wednesday changes, not everything since Monday. Option B is wrong because a synthetic full backup is constructed by combining a previous full with subsequent incrementals on the backup server — it does not describe a client-side changed-since-full capture. Option C is wrong because a full backup copies all data, not just data changed since Monday; the scenario explicitly limits scope to changed data.

922
MCQhard

A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?

A.Need to know
B.Accountability
C.Separation of duties
D.Least privilege
AnswerA

Need to know limits access to data strictly required for a task, regardless of rank. The analyst must judge whether the project genuinely required those files, so this principle directly tests whether the access was appropriate rather than merely permitted.

Why this answer

The 'need to know' principle restricts access to information based on the specific requirements of a user's role or project. In this scenario, the analyst must verify if the user's project actually required access to those specific files, not just if the user had the technical ability to access them. This principle is a subset of least privilege, focusing on data access rather than system permissions.

Exam trap

ISC2 often tests the distinction between 'least privilege' (permissions assigned to a role) and 'need to know' (justification for accessing specific data at a specific time), causing candidates to pick 'least privilege' when the scenario involves a user who already has the permission but needs to justify the access.

How to eliminate wrong answers

Option B (Accountability) is wrong because accountability refers to the ability to trace actions back to an individual (e.g., via audit logs), not to determine if the access was justified. Option C (Separation of duties) is wrong because it prevents a single individual from performing conflicting tasks (e.g., initiating and approving a payment) to reduce fraud risk, which is unrelated to cross-departmental file access. Option D (Least privilege) is wrong because while it grants the minimum permissions needed for a role, the user already had access; the question is about whether that access was appropriate for a specific task, which is the definition of 'need to know'.

923
MCQmedium

An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?

A.A firewall rule set that permits database access only from the storefront server's address and denies all other sources
B.A network-based intrusion prevention system placed inline between the LAN and the screened subnet
C.A host-based antivirus agent installed on each employee workstation
D.Full-disk encryption on the database server's storage volumes
AnswerA

An explicit rule that allows only the storefront server's address to reach the database and denies everything else enforces least privilege at the network layer. It directly implements the stated goal: the application can query the database, while employee workstations are blocked regardless of the protocol or port they attempt.

Why this answer

Reachability between network segments is governed by filtering rules on a firewall or router ACL, so the only control listed that actually limits which sources may open sessions to the database is a rule permitting the storefront and denying everything else. This enforces least privilege and shrinks the attack surface without disrupting the application's legitimate path.

Exam trap

The trap here is confusing inspection or endpoint protection with access control, when only a source-restricting filter rule actually removes the unauthorized network path.

924
MCQmedium

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

A.Authentication
B.Integrity
C.Availability
D.Confidentiality
AnswerC

Redundant servers with immediate failover keep services accessible when one server fails, directly addressing the availability principle. Availability ensures authorised users can access systems and data when required, which is precisely the uptime guarantee the redundant design delivers.

Why this answer

Redundant servers ensure that if one fails, another takes over immediately, maintaining uptime and continuous access to resources. This directly addresses the security principle of availability, which ensures systems and data are accessible when needed.

Exam trap

The trap is confusing availability with integrity or confidentiality; candidates may think redundancy protects data from tampering, but it primarily ensures uptime.

How to eliminate wrong answers

Option A is wrong because authentication verifies identity, which is not addressed by redundancy. Option B is wrong because integrity ensures data is not altered, which is unrelated to server failover. Option D is wrong because confidentiality ensures data is not disclosed to unauthorized parties, which is not the focus of redundancy.

925
Multi-Selectmedium

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Select 2 answers
A.Using a vendor's software without a license to test its security
B.Sharing a colleague's password with a manager without the colleague's consent to improve efficiency
C.Reporting a discovered vulnerability to the software vendor promptly
D.Refusing to share a confidential client password with an unauthorized third party
E.Concealing a security breach to avoid negative publicity
AnswersC, D

Prompt disclosure to the vendor lets the flaw be fixed before attackers exploit it, upholding the canon to advance the profession and protect the public. This satisfies the stem's requirement for an action aligned with the (ISC)² Code's canons.

Why this answer

Option C is correct because the (ISC)² Code of Ethics requires members to act honorably, honestly, justly, responsibly, and legally, and responsibly disclosing a discovered vulnerability to the software vendor reflects the canon to protect society and the infrastructure. Option D is correct because safeguarding confidential client information and refusing to release a password to an unauthorized third party upholds the canon to advance the profession and act responsibly toward clients and employers. Option A is wrong because using unlicensed software is illegal and unethical, violating the canon to act legally and avoid conflicts with laws.

Option B is wrong because sharing a colleague's password without consent violates privacy, confidentiality, and the canon to act honorably and responsibly. Option E is wrong because concealing a breach is dishonest and harms stakeholders, contradicting the canons to act honestly and protect society.

Exam trap

The CC exam often tests the Code of Ethics by presenting actions that sound efficient or loyal to the employer (sharing passwords, hiding breaches) — candidates who prioritize organizational loyalty over the Code's canons pick the wrong answers.

926
MCQmedium

A security manager is designing a policy to prevent one person from both approving and disbursing payments. Which principle is being applied?

A.Separation of duties
B.Need to know
C.Least privilege
D.Defense in depth
AnswerA

Separation of duties splits critical tasks between different people so no single individual controls an entire transaction. Requiring separate approvers and disbursers satisfies the stem's constraint, preventing fraud or error, unlike least privilege or job rotation.

Why this answer

Separation of duties ensures that no single individual has control over two or more phases of a critical transaction, such as both approving and disbursing payments. By splitting these responsibilities, the organization reduces the risk of fraud or error because collusion between two or more people would be required to bypass controls. In payment systems, this is often enforced through dual-authorization workflows in ERP or financial management software.

Exam trap

ISC2 often tests separation of duties by pairing it with 'least privilege' in the same question, and the trap is that candidates confuse the two because both limit access, but separation of duties specifically prevents conflicting task combinations, not just reducing permissions.

How to eliminate wrong answers

Option B (Need to know) is wrong because it restricts access to information only to those who require it for their job, not to prevent a single person from completing conflicting tasks. Option C (Least privilege) is wrong because it limits users to the minimum permissions necessary to perform their role, but does not inherently separate conflicting duties like approval and disbursement. Option D (Defense in depth) is wrong because it describes a layered security approach using multiple controls, not the specific segregation of incompatible functions.

927
MCQhard

A medium-sized company uses a network with three VLANs: VLAN 10 (Users, 192.168.10.0/24), VLAN 20 (Servers, 192.168.20.0/24), and VLAN 30 (DMZ, 192.168.30.0/24). A Layer 3 switch with an ACL is used for inter-VLAN routing. The company has a web server in the DMZ that must be accessible from the internet (via a public IP mapped to 192.168.30.10). Users in VLAN 10 need to access the web server on its private IP (192.168.30.10) for internal testing. The ACL is applied inbound on the VLAN 10 SVI. The ACL currently has the following entries: permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255; deny ip any 192.168.20.0 0.0.0.255; permit ip any any. Recently, the security team noticed that users can access the web server on its private IP, but they cannot access the web server via the public IP (which goes through the firewall and then to the DMZ). The firewall logs show that traffic from the users to the public IP is allowed and reaches the DMZ web server, but the return traffic is blocked. The web server's default gateway is the Layer 3 switch (192.168.30.1). Which of the following is the most likely cause of the problem?

A.The web server's default gateway should be set to the firewall, not the Layer 3 switch
B.The ACL on the DMZ SVI (VLAN 30) is blocking the return traffic from the web server to the firewall
C.The ACL on the VLAN 10 SVI is blocking the traffic to the public IP because it only allows private IP ranges
D.The firewall is blocking the return traffic due to a stateful inspection rule
AnswerA

The web server's default gateway is the switch, which is correct for reaching other internal subnets; the firewall is for external traffic, but the server can still send reply to the firewall via the switch.

Why this answer

The most likely cause is that the DMZ web server's default gateway is misconfigured. Because it points to the Layer 3 switch instead of the firewall, replies to public-IP requests are routed toward the L3 switch rather than back through the firewall. This breaks the firewall's stateful inspection/NAT path, so the return traffic is blocked or never completes.

Private-IP access works because the L3 switch can route directly to VLAN 10. The VLAN 10 ACL is inbound and does not block the outbound request; no DMZ SVI ACL is described.

Exam trap

ISC2 often tests asymmetric routing and the need for DMZ servers to use the firewall as their default gateway. Candidates may focus on the VLAN 10 ACL or assume a DMZ-side ACL, but the stated cause is the server's default gateway pointing to the L3 switch.

How to eliminate wrong answers

Option A is wrong because the web server's default gateway should remain the Layer 3 switch for internal routing; changing it to the firewall would break internal access from VLAN 10 to the web server's private IP, which is currently working. Option C is wrong because the ACL on the VLAN 10 SVI permits traffic from 192.168.10.0/24 to 192.168.30.0/24, which includes the public IP traffic that is NATed to the private IP; the issue is not with the inbound ACL on VLAN 10 but with the return path. Option D is wrong because the firewall logs show that traffic from users to the public IP is allowed and reaches the DMZ web server, and the firewall is stateful, so it would expect return traffic; the blockage is occurring after the traffic leaves the firewall, specifically on the Layer 3 switch's DMZ SVI ACL.

928
MCQmedium

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

A.Risk transfer
B.Risk avoidance
C.Risk acceptance
D.Risk mitigation
AnswerC

Accepting the risk means the organisation acknowledges the vulnerability but chooses to tolerate it because remediation costs outweigh the potential financial loss. This deliberate decision to absorb the residual risk, rather than mitigate, transfer or avoid it, is the defining characteristic of risk acceptance within the risk management process.

Why this answer

Risk acceptance means acknowledging the risk and choosing not to mitigate it, often due to cost-benefit analysis.

929
Multi-Selecteasy

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Select 2 answers
A.Inspects application-layer data
B.Tracks connection state
C.Operates only at Layer 3
D.Filters packets based on static rules only
E.Blocks unsolicited inbound traffic by default
AnswersB, E

A stateful firewall maintains a connection table recording each flow's source, destination and port, so return traffic is matched against established sessions rather than inspected in isolation. This per-session tracking is precisely the defining characteristic the stem asks for, distinguishing it from stateless packet filters that evaluate each packet independently.

Why this answer

A stateful firewall tracks the state of active connections and can block unsolicited inbound traffic. Packet filtering is stateless, and application inspection is typical of proxy firewalls.

930
Multi-Selecthard

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Select 3 answers
A.Enable rate limiting on network devices
B.Disable ICMP on all devices
C.Change the public IP address of the server
D.Use a content delivery network (CDN) to absorb traffic
E.Implement traffic filtering at the perimeter
AnswersA, D, E

Rate limiting caps the packet or connection rate accepted per source or interface, preventing a flood from consuming all available bandwidth. This directly satisfies the stem's bandwidth-overwhelm constraint by throttling excessive traffic at network devices.

Why this answer

Traffic filtering, rate limiting, and using a CDN can help absorb DDoS traffic. Changing IP addresses is reactive and not a standard mitigation; disabling ICMP may help against some attacks but is not a primary mitigation.

931
Multi-Selecteasy

Which THREE are essential elements of a disaster recovery plan? (Select THREE.)

Select 3 answers
A.Recovery time objectives (RTOs)
B.Communication plan for employees
C.Business impact analysis results
D.Alternate processing site details
E.Backup procedures and schedules
AnswersA, D, E

Define target restoration times.

Why this answer

Recovery time objectives (RTOs) define the maximum acceptable downtime for a system or application after a disaster. They are essential because they directly drive the design of the recovery strategy, including resource allocation and technology choices, ensuring that critical services are restored within the business's tolerance for interruption.

Exam trap

ISC2 often tests the distinction between a disaster recovery plan (which focuses on IT systems and data recovery) and a business continuity plan (which includes broader organizational elements like employee communication and crisis management), causing candidates to mistakenly select the communication plan as a DRP essential.

932
Multi-Selecthard

A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)

Select 2 answers
A.Authorization determines what an authenticated cashier is permitted to do within the point-of-sale application.
B.Authentication alone ensures that a cashier cannot perform unauthorized transactions.
C.Least privilege supports limiting each cashier to only the point-of-sale functions required for the assigned duties.
D.Access control decisions should be based solely on the cashier's password complexity.
E.Role-based access control requires each cashier to be assigned permissions individually rather than through a shared role.
AnswersA, C

Authorization occurs after authentication and defines the resources and actions available to an identity. Restricting voids above a threshold and limiting inventory adjustments are authorization decisions applied to an authenticated cashier. This statement correctly describes authorization as the mechanism enforcing these granular permissions in the point-of-sale design.

Why this answer

Authorization defines what an authenticated identity may do, and least privilege limits that access to what the job requires. Together they support the proposed point-of-sale restrictions on voids and inventory adjustments. Authentication merely establishes identity, while role-based access control assigns permissions through roles rather than individual assignments, and password complexity addresses authentication strength only.

Exam trap

The trap here is conflating authentication with authorization, assuming that a verified login automatically prevents actions the user should not perform.

933
MCQmedium

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

A.Due diligence
B.Risk transfer
C.Risk avoidance
D.Due care
AnswerA

Due diligence is the systematic investigation a company performs before engaging a provider, covering security controls, compliance certifications and risk posture. It directly satisfies the stem's requirement to thoroughly investigate the provider's practices and standards conformance, distinguishing it from ongoing monitoring or contractual assurance obtained after selection.

Why this answer

Due diligence involves investigating and assessing risks before making decisions, such as vendor selection.

934
MCQeasy

Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?

A.Warm site
B.Cloud-based recovery
C.Cold site
D.Hot site
AnswerA

A warm site ships with installed hardware and software but lacks replicated live data, so it needs days of configuration and data restoration before production use. That places it between a cold site and a hot site.

Why this answer

A warm site is a recovery facility that is pre-configured with hardware, software, and network connectivity but lacks live, up-to-date data, so it typically takes days to become fully operational after data restoration and configuration. This matches the question's description exactly. Warm sites balance cost and recovery speed between cold and hot sites.

Exam trap

The trap is confusing warm and cold sites — candidates pick cold because 'no live data' sounds cold, but cold sites also lack hardware and software, while warm sites have them pre-installed.

How to eliminate wrong answers

Option B is wrong because cloud-based recovery is a broad category, not a specific site tier, and modern cloud DR can often be provisioned in hours, not days — it does not fit the 'pre-configured but no live data' definition. Option C is wrong because a cold site has only basic infrastructure (power, cooling, space) with no pre-installed hardware or software, requiring weeks to become operational. Option D is wrong because a hot site is fully mirrored with live data and can take over within minutes to hours, not days.

935
MCQmedium

A company deploys a web application that stores user passwords using a salted hash. During a security review, an auditor recommends switching from SHA-1 to SHA-256. What is the primary security benefit of this change?

A.It improves system availability
B.It provides encryption of the passwords at rest
C.It increases collision resistance
D.It enhances non-repudiation
AnswerC

SHA-256 produces a 256-bit digest versus SHA-1's 160-bit output, raising the computational effort needed to find two inputs with identical hashes. This collision resistance gain is the primary benefit; salting already addresses rainbow-table and precomputation attacks.

Why this answer

SHA-256 produces a 256-bit digest versus SHA-1's 160-bit digest, dramatically increasing the computational effort required to find two different inputs that hash to the same value. SHA-1 has known practical collision attacks (e.g., SHAttered in 2017), so migrating to SHA-256 strengthens the integrity of the stored password hashes against collision-based attacks. The salting still protects against rainbow tables, but the hash algorithm upgrade specifically addresses collision resistance.

Exam trap

The trap here is confusing hashing with encryption — candidates see 'SHA-256' and pick 'encryption of passwords at rest' because both sound like data protection, but hashing is one-way and provides integrity/collision resistance, not confidentiality.

How to eliminate wrong answers

Option A is wrong because hashing algorithm choice has no bearing on system availability — availability concerns uptime, redundancy, and failover, not cryptographic digest size. Option B is wrong because SHA-256 is a one-way hash, not an encryption algorithm; it does not provide reversible encryption of passwords at rest (salting plus hashing is the correct pattern, not encryption). Option D is wrong because non-repudiation is provided by digital signatures and PKI, not by password hashing algorithms.

936
MCQeasy

An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password due to a security breach. The link leads to a website that looks identical to the company's login page. Which type of attack is this?

A.Vishing
B.Whaling
C.Phishing
D.Spear phishing
AnswerC

Phishing is a social engineering attack where an attacker sends fraudulent messages, often via email, to trick recipients into revealing sensitive information or clicking malicious links. In this scenario, the email impersonates the IT department and directs the employee to a fake login page, which is a classic phishing attempt.

Why this answer

The attack uses email to impersonate the IT department and lure the employee to a fake login page, which is the definition of phishing. While spear phishing and whaling are subsets, the scenario does not indicate a targeted or executive-focused attack, and vishing involves voice, not email.

Exam trap

The trap here is overclassifying the attack as spear phishing or whaling when the scenario lacks evidence of targeting or executive involvement.

937
MCQeasy

Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?

A.Reciprocal agreement
B.Hot site
C.Warm site
D.Cold site
AnswerB

A hot site maintains a fully mirrored, continuously synchronised replica of production infrastructure, including live data replication and pre-configured compute. This satisfies the stem's requirement for recovery within hours, since failover needs only traffic redirection rather than hardware provisioning or data restoration, unlike warm or cold alternatives.

Why this answer

A hot site is a fully mirrored recovery facility with live, synchronized data and duplicate hardware, software, and network infrastructure, enabling failover within minutes to hours. It provides the fastest recovery time among traditional site strategies and is ready to take over operations immediately. This matches the question's description of a fully mirrored, immediately available environment.

Exam trap

The trap is confusing hot and warm sites — candidates pick warm because it sounds 'ready,' but only a hot site has live data and can take over within minutes, while warm sites need days.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement is an arrangement where two organizations agree to share each other's facilities in a disaster — it is informal, untested, and typically slow, with no guarantee of availability. Option C is wrong because a warm site has hardware and software but no live data, requiring days to become operational. Option D is wrong because a cold site has only basic infrastructure and no pre-installed systems, requiring weeks to become operational.

938
Multi-Selecthard

An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?

Select 3 answers
A.Cable locks on laptop computers
B.Password complexity requirements
C.Visitor sign-in log
D.Biometric reader at the server room door
E.Fencing and bollards around the building
AnswersA, D, E

Cable locks physically tether laptops to a fixed anchor, preventing opportunistic theft of endpoint devices. This satisfies the layered strategy by extending physical protection beyond the data centre perimeter to the assets themselves, complementing door, fence and bollard controls.

Why this answer

Option A (cable locks on laptop computers) is correct because a cable lock is a physical deterrent that secures a portable asset to a fixed object, adding a layer of physical defense against theft. Option D (biometric reader at the server room door) is correct because it is a physical access control that authenticates identity via a biological characteristic before granting entry to a restricted area. Option E (fencing and bollards around the building) is correct because perimeter barriers such as fences and bollards are classic physical controls that deter, delay, and prevent unauthorized access or vehicle-borne threats.

Option B (password complexity requirements) is not a physical control but a logical/administrative authentication control, and Option C (visitor sign-in log) is an administrative control that records entry rather than physically preventing or deterring access.

Exam trap

The trap here is confusing logical/administrative controls (like passwords and logs) with physical controls; candidates often select password complexity because it sounds like security, but it does not address physical access.

939
MCQmedium

A financial services company's business continuity plan includes a recovery time objective (RTO) of 4 hours for its trading platform. During a recent test, the platform was restored in 6 hours. Which of the following should be the PRIMARY focus of the after-action review?

A.Increasing the frequency of full-scale disaster recovery tests
B.Identifying the causes of the delay and implementing improvements
C.Updating the RTO to 6 hours to match actual performance
D.Replacing the entire disaster recovery team
AnswerB

The after-action review should analyze why recovery took longer than the RTO and recommend corrective actions. This might involve additional training, better documentation, more frequent backups, or infrastructure upgrades. The goal is to close the gap between actual and target recovery times, ensuring the trading platform can be restored within 4 hours in a real event. This directly addresses the shortfall.

Why this answer

When a recovery test exceeds the RTO, the after-action review must identify the root causes of the delay and implement corrective measures. This ensures the trading platform can meet its 4-hour RTO in a real disruption. Adjusting the RTO, replacing the team, or merely increasing test frequency does not address the specific performance gap revealed by the test.

Exam trap

The trap here is thinking that the RTO should be adjusted to match actual recovery time, rather than improving recovery capabilities to meet the business requirement.

940
MCQeasy

What is the primary goal of data classification?

A.To improve data access speed
B.To comply with marketing requirements
C.To determine the appropriate level of security controls
D.To reduce storage costs
AnswerC

Data classification assigns sensitivity labels that directly dictate which security controls apply, satisfying the stem's requirement for a primary goal. By categorising information according to its value and sensitivity, organisations can apply proportionate protection, ensuring Microsoft Entra ID access policies and encryption align with each data type's risk profile.

Why this answer

Data classification is the process of categorizing data based on its sensitivity, value, and regulatory requirements so that appropriate security controls (encryption, access control, retention, handling procedures) can be applied proportionally. Its primary purpose is to ensure that protection levels match the data's risk profile. This is the foundational step in any data governance or security program.

Exam trap

The trap here is confusing the primary goal of classification (determining appropriate security controls) with secondary benefits like cost reduction or compliance with a specific function (marketing) — candidates pick a plausible-sounding but narrow outcome instead of the core security purpose.

How to eliminate wrong answers

Option A is wrong because data classification does not improve access speed — it may actually add controls that affect access, but performance is not its goal. Option B is wrong because marketing compliance is a narrow, secondary use case; classification is driven by security, privacy, and regulatory needs, not marketing. Option D is wrong because reducing storage costs is a possible byproduct of retention policies informed by classification, but it is not the primary goal — cost optimization is downstream of the security and governance purpose.

941
Multi-Selecthard

Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?

Select 3 answers
A.Risk mitigation
B.Risk duplication
C.Risk transfer
D.Risk identification
E.Risk acceptance
AnswersA, C, E

Mitigation reduces risk by applying controls that lower likelihood or impact, and it is one of the NIST SP 800-30 treatment options alongside transfer, avoid and accept. It satisfies the stem's requirement for an acceptable treatment response.

Why this answer

Risk avoidance, mitigation, transfer, and acceptance are standard. Risk identification is a step, not treatment. Risk duplication is not a term.

942
Multi-Selecteasy

Which TWO of the following are core components of the CIA triad?

Select 2 answers
A.Authentication
B.Non-repudiation
C.Confidentiality
D.Authorization
E.Availability
AnswersC, E

Confidentiality is a core CIA triad component, ensuring data is disclosed only to authorised parties. It satisfies the stem's requirement by naming one of the three foundational security objectives, alongside integrity and availability. Encryption, access controls and classification enforce it, preventing unauthorised disclosure across Microsoft Entra ID and other systems.

Why this answer

The CIA triad is the foundational information security model consisting of Confidentiality, Integrity, and Availability, so option C (Confidentiality) is correct because it ensures data is disclosed only to authorized parties through mechanisms such as encryption, access controls, and classification. Option E (Availability) is also correct because it ensures systems and data are accessible to authorized users when needed, supported by controls like redundancy, backups, and DDoS mitigation. The unmarked options do not belong because Authentication (A), Authorization (D), and Non-repudiation (B) are distinct security services and principles that support or extend beyond the CIA triad rather than being its core components.

Exam trap

The trap here is conflating security services (Authentication, Authorization, Non-repudiation) with the CIA triad components — candidates pick Authentication or Non-repudiation because they sound foundational, but only Confidentiality, Integrity, and Availability are the triad.

943
MCQmedium

Which of the following are examples of sensitive PII? (Select all that apply.)

A.Phone number
B.Medical records
C.Social Security number
D.Name and email address
AnswerB, C

Medical records are sensitive PII because they combine an identifier with health data, revealing diagnoses, treatments or conditions. This falls within special-category data under GDPR and triggers stricter handling than ordinary personal data, satisfying the stem's requirement for sensitive rather than generic PII.

Why this answer

Sensitive PII includes data that, if disclosed, could cause harm or be used for identity theft. Medical records and Social Security numbers are classic examples of sensitive PII because they contain highly confidential information. Phone numbers and name/email address are generally considered PII but not necessarily sensitive PII on their own.

Exam trap

CC often tests the distinction between PII and sensitive PII; candidates may incorrectly select phone number or name/email as sensitive, not realizing that sensitivity depends on the potential for harm and regulatory definitions.

How to eliminate wrong answers

Option A is wrong because a phone number alone is typically considered standard PII, not sensitive PII, unless combined with other data. Option D is wrong because a name and email address are also standard PII; they are not inherently sensitive without additional context.

944
Multi-Selectmedium

A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)

Select 2 answers
A.Media Access Control (MAC) address filtering
B.Wired Equivalent Privacy (WEP)
C.WPA3 with strong authentication
D.Service Set Identifier (SSID) broadcasting disabled
E.IEEE 802.1X port-based network access control
AnswersC, E

WPA3 provides strong encryption for wireless traffic and supports authentication methods that verify authorized users or devices. This prevents casual eavesdropping by someone nearby and helps ensure only approved devices associate. It directly addresses both the confidentiality and access-control goals in the scenario.

Why this answer

Strong wireless encryption with robust authentication, such as WPA3, protects traffic from nearby eavesdropping, while 802.1X ensures only authenticated devices or users can associate. Together they address confidentiality and access control. WEP is broken, SSID hiding is easily defeated, and MAC filtering can be bypassed through spoofing, so none of those reliably satisfy the requirements.

Exam trap

The trap here is relying on obscurity controls like hidden SSIDs or spoofable MAC address lists instead of cryptographic authentication and encryption.

945
Multi-Selectmedium

A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?

Select 2 answers
A.Requiring password changes every 90 days
B.Account lockout threshold (e.g., 5 failed attempts)
C.Lockout duration (e.g., 30 minutes) or administrator unlock
D.Password history of 10 remembered passwords
E.Password minimum length of 8 characters
AnswersB, C

The lockout threshold defines how many consecutive failed authentication attempts trigger the lockout, directly throttling brute-force guessing. Setting it low, such as five, limits an attacker's attempts per account before the account is disabled, satisfying the requirement to mitigate brute-force attacks.

Why this answer

Option B, the account lockout threshold (e.g., 5 failed attempts), is correct because it directly limits how many incorrect password guesses an attacker can make before the account is disabled, which is the core mechanism that stops brute-force attempts. Option C, lockout duration (e.g., 30 minutes) or administrator unlock, is correct because it determines how long the account stays locked; without a duration or manual unlock requirement, the lockout either never ends or can be trivially bypassed, so it works together with the threshold to make brute-forcing impractical. The unmarked options do not belong because A (90-day password changes), D (password history of 10), and E (minimum length of 8) are password policy settings that improve password strength and prevent reuse, but they do not detect or block repeated failed authentication attempts, which is what account lockout specifically addresses.

Exam trap

The trap is selecting password policy settings (length, history, expiration) as critical for lockout, when the question specifically asks about lockout policies to mitigate brute-force attacks.

946
Drag & Dropmedium

Drag and drop the steps to implement a firewall rule allowing inbound HTTPS traffic into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to implement a firewall rule for inbound HTTPS traffic is: first define the source and destination zones to control traffic direction, then specify the protocol (TCP) and destination port (443) for HTTPS, next set the action to 'allow', and finally save and apply the rule. Zones provide context, the port identifies the service, the action permits the traffic, and saving ensures the rule is active. Common mistakes include swapping the order of zones and port specification, setting the action prematurely, or saving before defining the action.

947
MCQmedium

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

A.Integrity
B.Availability
C.Non-repudiation
D.Confidentiality
AnswerD

Unencrypted email content is readable by anyone capturing the traffic, so unauthorised parties gain access to information they should not see. Confidentiality is the goal protecting data from disclosure, making it the property directly breached; integrity and availability remain intact.

Why this answer

Confidentiality ensures that data is only readable by authorized parties. When an attacker captures unencrypted email traffic in Wireshark and reads the contents, the confidentiality of the email is directly compromised because the data was exposed in plaintext to an unauthorized party.

Exam trap

CC often tests whether candidates can distinguish confidentiality (secrecy/reading) from integrity (modification) and non-repudiation (proof of origin) — eavesdropping is always a confidentiality violation, not integrity.

How to eliminate wrong answers

Option A is wrong because integrity refers to data being unaltered — the attacker read the email but did not necessarily modify it, so integrity is not the primary goal compromised. Option B is wrong because availability refers to data/services being accessible — reading traffic does not deny access. Option C is wrong because non-repudiation ensures a sender cannot deny sending a message — it is about proof of origin, not secrecy, and is not directly violated by passive eavesdropping.

948
MCQhard

Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?

A.Restore table from backup
B.Verify data integrity on primary
C.Reseed replication
D.Fail over to standby
AnswerB

Before altering replication configuration, confirm the primary's data is intact. If corruption exists on the source, resynchronising replicas propagates bad data. Verifying integrity establishes whether the fault lies in the primary or the replication channel.

Why this answer

When investigating a replication issue, the first step should be to verify data integrity on the primary database. This ensures that the source data is consistent and not corrupted, which could be the root cause of replication failures. Checking the primary helps determine whether the issue is with the data itself or with the replication process.

Exam trap

The trap here is that candidates may jump to corrective actions like reseeding or failover without first diagnosing the root cause, which is a common mistake in troubleshooting questions.

How to eliminate wrong answers

Option A is wrong because restoring a table from backup is a drastic action that should only be taken after diagnosing the issue; it could cause data loss and does not address the root cause. Option C is wrong because reseeding replication is a corrective action that should be performed after identifying the problem, not as a first step. Option D is wrong because failing over to a standby is a high-availability action that does not fix replication issues and may complicate diagnosis.

949
Multi-Selecthard

Which TWO actions are appropriate during the identification phase of incident response?

Select 2 answers
A.Conduct a post-mortem analysis.
B.Correlate alerts from multiple sources.
C.Review system logs for anomalies.
D.Restore data from backups.
E.Disconnect affected systems from the network.
AnswersB, C

Correlating alerts from multiple sources consolidates indicators during identification, distinguishing genuine incidents from isolated noise. This satisfies the phase's goal of scoping and validating what occurred, enabling accurate classification before containment or eradication activities begin.

Why this answer

During the identification phase, responders must determine whether an incident has actually occurred and scope it, so option B (correlate alerts from multiple sources) is correct because aggregating and cross-referencing alerts from SIEM, IDS/IPS, EDR, and other telemetry helps confirm a true positive and establish the incident's extent. Option C (review system logs for anomalies) is also correct because examining OS, application, and security logs for unusual events, timestamps, and indicators of compromise is a core identification activity that validates and characterizes the suspected incident. Option A (post-mortem analysis) belongs to the lessons-learned/ post-incident phase after containment, eradication, and recovery.

Option D (restore data from backups) is a recovery-phase action, and option E (disconnect affected systems from the network) is a containment action, both of which occur after the incident has been identified.

Exam trap

ISC2 often tests the distinction between identification and containment, so the trap here is that candidates mistake disconnecting systems (a containment step) for an identification action, when in fact identification must occur first to confirm the incident.

950
MCQeasy

Which of the following best describes the principle of confidentiality in the CIA triad?

A.Ensuring data is accurate and complete
B.Verifying the identity of users
C.Preventing unauthorized disclosure of information
D.Ensuring systems and data are accessible when needed
AnswerC

Confidentiality directly addresses unauthorised disclosure, ensuring information remains accessible only to those with legitimate access rights. This satisfies the stem's requirement by naming the specific security objective that prevents exposure of data to unauthorised parties, distinguishing it from integrity (unauthorised modification) and availability (disruption of access).

Why this answer

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encryption and access controls are primary mechanisms to enforce confidentiality.

951
MCQhard

An organization is implementing a new identity management system. They want to ensure that users can only access resources necessary for their job roles. Which principle should guide the access control design?

A.Separation of duties
B.Least privilege
C.Need to know
D.Defense in depth
AnswerB

Least privilege grants each user only the permissions their role requires, nothing more. This directly enforces the stated goal that access is limited to resources necessary for job functions, reducing standing privilege and blast radius.

Why this answer

The principle of least privilege dictates that users should be granted only the permissions necessary to perform their job functions and nothing more. In an identity management system, this is implemented by assigning minimal access rights to resources, reducing the attack surface and limiting potential damage from compromised accounts. This directly aligns with the scenario of ensuring users can only access resources essential for their roles.

Exam trap

ISC2 often tests least privilege versus need to know, where candidates mistakenly choose need to know because it sounds more specific, but least privilege is the broader, correct principle for general access control design in identity management.

How to eliminate wrong answers

Option A is wrong because separation of duty is a principle that prevents fraud by requiring multiple users to complete a sensitive task (e.g., one user creates a purchase order, another approves it), not about limiting individual access to job-necessary resources. Option C is wrong because need to know is a subset of least privilege focused specifically on access to classified or sensitive information on a per-case basis, not the broader principle of limiting all resource access to job-role requirements. Option D is wrong because defense in depth is a layered security strategy using multiple controls (firewalls, IDS, encryption) to protect assets, not a principle for designing user access rights.

952
Multi-Selectmedium

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Select 2 answers
A.Asset inventory
B.Vulnerability assessment
C.Business Impact Analysis (BIA)
D.Recovery Time Objective (RTO)
E.Network diagram
AnswersC, D

The Business Impact Analysis identifies critical business functions, their dependencies and the consequences of disruption, establishing the maximum tolerable downtime. It supplies the foundational data from which recovery priorities, strategies and objectives within the BCP are derived.

Why this answer

Option C, Business Impact Analysis (BIA), is essential because it identifies critical business functions, quantifies the operational and financial impact of their disruption, and establishes the priorities and dependencies that drive the entire BCP strategy. Option D, Recovery Time Objective (RTO), is essential because it defines the maximum acceptable downtime for each critical process, directly shaping the recovery strategies, resource allocation, and backup/replication design documented in the BCP. Options A, B, and E are supporting inputs rather than mandatory BCP components: an asset inventory and network diagram are useful technical references, and a vulnerability assessment belongs to risk assessment activities that inform, but are not part of, the core BCP structure.

Exam trap

ISC2 often tests the distinction between components that are 'essential' to the BCP itself versus supporting documents or risk management activities, causing candidates to select asset inventory or vulnerability assessment as core BCP elements.

953
MCQmedium

Refer to the exhibit. A security engineer applies this storage access policy to restrict access. Users outside the 10.0.0.0/16 network report being denied access, which is expected. However, users inside that network also report access denied. What is the likely issue?

A.The condition syntax is incorrect and causes all requests to be evaluated incorrectly.
B.The Deny statement overrides the Allow statement for all requests.
C.The policy only allows read access; users likely need list or other actions.
D.The resource identifier includes a wildcard, causing a mismatch.
AnswerC

The storage policy only grants the read action, but users inside the 10.0.0.0/16 network are likely performing other actions such as list or write. Even though the source IP condition allows access from the trusted network, the explicit Allow statement is scoped solely to read. Any request for a different action (like list) will be implicitly denied by default, as IAM and storage policies are deny-by-default unless an explicit Allow exists for that specific action.

Why this answer

The storage policy only grants the read action, but users inside the 10.0.0.0/16 network are likely performing other actions such as list or write. Even though the source IP condition allows access from the trusted network, the explicit Allow statement is scoped solely to read. Any request for a different action (like list) will be implicitly denied by default, as IAM and storage policies are deny-by-default unless an explicit Allow exists for that specific action.

Exam trap

ISC2 often tests the misconception that a single Allow statement for one action (like read) implicitly permits all other actions for users who satisfy the condition, when in reality each action requires its own explicit Allow.

How to eliminate wrong answers

Option A is wrong because the condition syntax (IpAddress with aws:SourceIp) is valid and correctly structured; an incorrect syntax would cause a policy parsing error, not a selective denial for both inside and outside users. Option B is wrong because the Deny statement only applies to requests originating outside the 10.0.0.0/16 network (due to the NotIpAddress condition), so it does not override the Allow for internal users; the Deny is scoped correctly and does not affect internal traffic. Option D is wrong because the resource ARN 'arn:aws:s3:::example-bucket/*' with a wildcard is standard for matching all objects in the bucket; it does not cause a mismatch with the bucket name, and the bucket name itself is explicitly stated.

954
Multi-Selecteasy

An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)

Select 2 answers
A.Disconnect affected servers from the network
B.Filter malicious traffic at the firewall
C.Restore systems from backup
D.Notify law enforcement
E.Conduct a root cause analysis
AnswersA, B

Disconnecting affected servers from the network severs the attacker's path and halts ongoing traffic, preventing further damage or lateral movement. This isolation contains the DoS while preserving evidence, satisfying the containment phase before eradication and recovery begin.

Why this answer

Option A is correct because disconnecting the affected servers from the network immediately stops the flood of attack traffic from reaching those hosts, preventing further resource exhaustion and limiting the blast radius during containment. Option B is correct because filtering malicious traffic at the firewall (e.g., blocking offending source IPs, rate-limiting, or applying ACLs) mitigates the DoS at the network perimeter while keeping legitimate services reachable, which is a standard containment technique. Option C is not a containment action; restoring from backup is part of eradication and recovery, performed after the threat is removed.

Option D is not a containment step; notifying law enforcement is an external communication/coordination activity that may occur later. Option E is not containment; root cause analysis is a post-incident activity conducted after the incident is resolved.

Exam trap

CC often tests the phase boundaries — candidates pick 'restore from backup' or 'root cause analysis' because they sound like response actions, but those belong to recovery and post-incident phases, not containment.

955
MCQhard

An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?

A.Intrusion Detection System (IDS)
B.Next-Generation Firewall (NGFW)
C.Web Application Firewall (WAF)
D.Intrusion Prevention System (IPS)
AnswerC

A Web Application Firewall operates at Layer 7, inspecting HTTP request payloads against rule sets such as the OWASP Core Rule Set to block SQL injection, cross-site scripting and similar attacks. This directly satisfies the stem's requirement for application-layer inspection and malicious HTTP request blocking, unlike packet-filtering or stateful firewalls.

Why this answer

A Web Application Firewall (WAF) operates at Layer 7, inspects HTTP/HTTPS payloads, blocks malicious requests such as SQL injection and XSS, and commonly uses rule sets like the OWASP ModSecurity Core Rule Set. The question's emphasis on application-layer payload inspection, HTTP request blocking, and OWASP rules maps directly to WAF capabilities. WAFs are typically deployed in front of web servers or via cloud services (AWS WAF, Cloud Armor, Azure WAF).

Exam trap

CC often tests the distinction between detection (IDS) and prevention (IPS/WAF) and between network-layer firewalls (NGFW) and application-layer firewalls (WAF), tempting candidates to pick NGFW because it sounds 'next-gen' and comprehensive.

How to eliminate wrong answers

Option A is wrong because an IDS is passive — it detects and alerts on suspicious traffic but does not block it, and it is not specifically focused on HTTP/OWASP rules. Option B is wrong because an NGFW adds application awareness, IPS, and user identity to a traditional firewall, but it is not defined by OWASP rule sets or HTTP payload inspection as its primary function; NGFWs operate across many protocols, not just web. Option D is wrong because an IPS blocks intrusions at the network/transport layer based on signatures or anomalies, but it is not specifically an HTTP/OWASP-focused device and does not typically parse web application payloads with OWASP rules.

956
MCQhard

Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?

A.Isolate the internal host from the network
B.Ignore the alert as it is a false positive
C.Block the destination IP at the firewall
D.Run a full antivirus scan on the internal host
AnswerA

Isolating the internal host immediately severs command-and-control traffic to the SpyEye infrastructure, containing potential data exfiltration or further malware propagation while forensic investigation proceeds. It is the fastest containment step for a confirmed botnet check-in alert.

Why this answer

Isolating the internal host immediately stops the potential command-and-control (C2) communication with the SpyEye botnet, preventing data exfiltration or further compromise. This is the first step in incident response (containment) before any forensic analysis or remediation, as per NIST SP 800-61 guidelines. Delaying containment could allow the botnet to receive new instructions or spread laterally.

Exam trap

ISC2 often tests the principle that containment (isolation) must precede remediation (scanning or blocking) in incident response, tricking candidates into choosing a reactive firewall block or a delayed scan instead of immediate host isolation.

How to eliminate wrong answers

Option B is wrong because ignoring the alert assumes a false positive without verification; SpyEye check-ins are rarely benign and require investigation. Option C is wrong because blocking the destination IP at the firewall only disrupts communication to that specific IP, but botnets often use domain flux or multiple fallback IPs, and the internal host remains compromised and could beacon to other C2 servers. Option D is wrong because running a full antivirus scan is a remediation step that should occur after containment; the immediate priority is to stop the active C2 traffic, not to scan while the host is still communicating with the botnet.

957
Multi-Selectmedium

Which TWO are true about a differential backup? (Select two.)

Select 2 answers
A.It copies files changed since the last backup of any type
B.It requires a full backup to be restored first
C.It copies files changed since the last full backup
D.It resets the archive bit on backed-up files
E.It is faster to restore than a full backup
AnswersB, C

A differential backup captures only changes since the last full backup, so it cannot be applied alone. Restoring requires the originating full backup first, then the latest differential, which is why this dependency is a defining characteristic.

Why this answer

Option B is correct because a differential backup only contains data changed since the last full backup, so restoring requires the original full backup plus the most recent differential backup to reconstruct the complete data set. Option C is correct because a differential backup by definition copies all files that have changed since the last full backup, not since the last incremental or differential backup. Option A is incorrect because copying files changed since the last backup of any type describes an incremental backup, not a differential backup.

Option D is incorrect because resetting the archive bit is characteristic of incremental backups (and some full backups), whereas differential backups do not reset the archive bit, which is why each successive differential grows larger. Option E is incorrect because a differential restore requires two restore operations (full plus differential) and is therefore not faster than restoring a single full backup.

Exam trap

ISC2 often tests the distinction between differential and incremental backups by making candidates confuse 'changed since last full' (differential) with 'changed since last backup of any type' (incremental), and by implying that differential backups reset the archive bit when they do not.

958
MCQeasy

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

A.Availability
B.Non-repudiation
C.Integrity
D.Confidentiality
AnswerD

Encryption at rest and in transit renders data unreadable to unauthorised parties, directly preventing disclosure. Confidentiality is the CIA principle concerned with restricting data access to approved subjects, so encrypting sensitive data satisfies that constraint rather than integrity or availability.

Why this answer

Encryption of data at rest and in transit directly protects data from unauthorized disclosure, which is the definition of confidentiality in the CIA triad. Encryption ensures that even if data is intercepted or accessed without authorization, it remains unreadable without the proper decryption key. This is the textbook control for the confidentiality principle.

Exam trap

The trap here is confusing confidentiality with integrity because encryption is sometimes described as 'protecting' data — candidates who do not distinguish between preventing unauthorized reading (confidentiality) and preventing unauthorized modification (integrity) may select the wrong principle.

How to eliminate wrong answers

Option A is wrong because availability concerns ensuring data and systems are accessible to authorized users when needed — encryption does not address uptime, redundancy, or denial-of-service resilience. Option B is wrong because non-repudiation is not part of the CIA triad at all; it is a separate security property typically addressed through digital signatures and audit logging. Option C is wrong because integrity concerns ensuring data has not been altered — while encryption can support integrity through authenticated encryption modes, the primary purpose of encrypting data at rest and in transit is confidentiality, not tamper detection.

959
MCQhard

A security engineer is reviewing firewall logs and notices that an internal host is making repeated outbound connections to a known malicious IP address on port 443. The firewall is configured to allow all outbound traffic to port 443. The engineer wants to block this specific traffic without disrupting other legitimate HTTPS traffic. Which action should the engineer take?

A.Implement a URL filtering rule to block the domain name associated with the malicious IP.
B.Enable intrusion prevention system (IPS) signatures to detect and block the malicious traffic.
C.Create an outbound rule to block all traffic to the malicious IP address on any port.
D.Configure a quality of service (QoS) policy to throttle traffic to the malicious IP address.
AnswerC

Blocking all traffic to the specific malicious IP address effectively stops the communication while allowing other HTTPS traffic to proceed. Since the malicious IP is known, a targeted block rule is precise and does not disrupt legitimate traffic to other destinations. This is the most direct and least disruptive mitigation.

Why this answer

A targeted outbound block rule for the specific malicious IP address stops the communication without affecting legitimate HTTPS traffic. This approach is precise, does not require deep packet inspection, and is effective regardless of the port used. Other methods either do not guarantee a block or require additional capabilities like SSL decryption.

Exam trap

The trap here is overcomplicating the solution with application-layer inspection when a simple network-layer block is sufficient and less disruptive.

960
MCQhard

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

A.Risk transfer
B.Risk acceptance
C.Risk avoidance
D.Risk mitigation
AnswerB

Risk acceptance means acknowledging a risk and choosing to bear the potential loss rather than mitigate it. The organisation identified the vulnerability but declined to patch it because of downtime concerns, deliberately retaining the exposure, which matches acceptance rather than avoidance, transference or mitigation.

Why this answer

Risk acceptance is the strategy of acknowledging a risk and choosing to take no action to prevent it, often because the cost of mitigation outweighs the potential impact. Here, the organization identified the vulnerability but consciously decided not to patch it due to downtime concerns, which is the textbook definition of accepting the risk. The breach that followed is the realized consequence of that accepted risk.

Exam trap

The trap here is confusing risk acceptance with risk mitigation, because candidates see that the organization 'identified' the vulnerability and assume any awareness implies action; the key is that no action was taken, which is acceptance.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the financial impact to a third party, typically through insurance or outsourcing, which did not occur here. Option C is wrong because risk avoidance means eliminating the activity or system that creates the risk entirely, such as decommissioning the web server, which the organization did not do. Option D is wrong because risk mitigation involves taking action to reduce the likelihood or impact of the risk, such as patching, applying compensating controls, or segmenting the network, none of which the organization performed.

961
MCQhard

A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?

A.Log all emails without any alerts
B.Block all emails containing keywords like 'confidential'
C.Encrypt all outgoing emails automatically
D.Alert on policy violations and allow user to override with manager approval
AnswerD

Alerting on violations while permitting manager-approved overrides satisfies the stem's balance requirement: sensitive data triggers detection, yet business-critical email is not blocked outright. This human-in-the-loop workflow preserves productivity through a documented approval path, unlike hard blocking, which halts legitimate communication, or silent logging, which fails to prevent exfiltration.

Why this answer

It balances security and productivity by alerting on policy violations while allowing users to override the block with manager approval. This approach ensures that legitimate business communications are not disrupted, while still enforcing DLP policies through a secondary review process. In a DLP solution, this is often implemented via a 'justify and override' workflow, where the user must provide a reason and receive approval from a manager before the email is sent.

Exam trap

ISC2 often tests the concept that DLP is not just about blocking or encrypting data, but about applying policy with context and user feedback to balance security and productivity, leading candidates to mistakenly choose overly restrictive options like B.

How to eliminate wrong answers

Option A is wrong because logging all emails without any alerts provides no active enforcement or notification, failing to prevent data loss in real time and offering only passive auditing. Option B is wrong because blocking all emails containing keywords like 'confidential' is overly restrictive and lacks context, leading to high false positive rates that disrupt legitimate business communications and reduce productivity. Option C is wrong because encrypting all outgoing emails automatically does not prevent data loss; encryption protects data in transit but does not stop sensitive data from being sent to unauthorized recipients, which is the core function of DLP.

962
MCQhard

During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?

A.Potential lack of capacity when both parties need resources simultaneously
B.Long RTO due to data transfer
C.High cost of maintaining duplicate infrastructure
D.Incompatible hardware
AnswerA

Reciprocal agreements share another organisation's standby facilities, so simultaneous disasters create contention for the same equipment, workspace and processing capacity. This resource-contention risk is the primary weakness distinguishing reciprocal agreements from dedicated alternate sites or commercial hot sites.

Why this answer

A reciprocal agreement (also called a mutual aid pact) is a disaster recovery arrangement where two organizations agree to share each other's computing facilities in an emergency. The primary risk is that a disaster may affect both parties simultaneously—such as a regional event like a hurricane, earthquake, or widespread power outage—leaving neither with spare capacity to host the other's workloads. Because neither party maintains dedicated redundant resources for the other, resource contention during a shared crisis is the defining weakness of this strategy.

Exam trap

The trap here is confusing the primary risk of a reciprocal agreement with the drawbacks of other DR strategies—candidates often pick 'high cost' (which actually describes hot sites) or 'long RTO' (which describes cold sites), missing that the unique weakness of reciprocity is simultaneous demand from both parties.

How to eliminate wrong answers

Option B is wrong because reciprocal agreements typically involve pre-staged or quickly shippable resources and do not inherently impose a long RTO due to data transfer—data transfer time depends on bandwidth and data volume, not on the agreement type itself. Option C is wrong because the entire appeal of a reciprocal agreement is that it avoids the high cost of maintaining duplicate infrastructure; that cost is a drawback of a hot site or redundant data center, not of reciprocity. Option D is wrong because incompatible hardware is a general risk of any shared or outsourced recovery arrangement and is not the primary, defining risk unique to reciprocal agreements; compatibility can be addressed contractually and technically, whereas simultaneous demand cannot.

963
Multi-Selecthard

Which THREE are differences between a hot site and a cold site? (Select three.)

Select 3 answers
A.Hot site is more expensive to maintain
B.Cold site has pre-installed software and applications
C.Hot site has real-time data synchronization
D.Both have the same recovery time objective (RTO)
E.Cold site has no hardware or infrastructure installed
AnswersA, C, E

A hot site duplicates production infrastructure with live systems, so maintaining it demands continuous hardware, software, connectivity and staffing costs. A cold site holds basic space and power only, making it markedly cheaper to maintain.

Why this answer

Option A is correct because a hot site requires fully redundant, continuously powered hardware, software licenses, and network connectivity that mirror production, making its ongoing maintenance and operational costs significantly higher than a cold site's. Option C is correct because a hot site maintains real-time or near-real-time replication of data (e.g., via synchronous or asynchronous replication) so it can take over almost immediately, whereas a cold site has no such synchronization. Option E is correct because a cold site is essentially an empty facility with power, cooling, and network cabling but no pre-installed hardware or infrastructure, requiring equipment to be brought in and configured after a disaster.

Option B is incorrect because pre-installed software and applications are characteristic of a hot site (or at least a warm site), not a cold site. Option D is incorrect because a hot site typically has a much lower RTO (minutes to hours) than a cold site (days to weeks), so their RTOs are not the same.

Exam trap

ISC2 often tests the misconception that a cold site has some pre-installed infrastructure or software, when in fact it is a completely empty facility with only power and cooling, and that RTO is identical across site types, whereas RTO is a key differentiator between hot, warm, and cold sites.

964
MCQmedium

After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?

A.Conduct a post-incident review
B.Reinstall the operating system
C.Disable the affected user accounts
D.Delete all incident-related logs
AnswerA

A post-incident review examines what happened, why, and how controls failed, producing documented lessons and remediation actions. It directly satisfies the stem's requirement to improve future incident response after containment and eradication, feeding updates back into plans, playbooks and defences.

Why this answer

A post-incident review (also called a lessons-learned meeting) is the correct next step after containment and eradication because it systematically analyzes what went wrong, what worked, and what can be improved in the incident response plan. This review directly feeds into updating playbooks, refining detection rules, and adjusting security controls to prevent recurrence. Without this step, the organization misses the opportunity to close the loop on the incident lifecycle and may repeat the same mistakes.

Exam trap

The trap here is that candidates confuse post-incident review with immediate remediation actions like reinstalling OS or disabling accounts, thinking they are 'improvements' rather than part of containment/eradication.

How to eliminate wrong answers

Option B is wrong because reinstalling the operating system is a remediation step that should have already been performed during the eradication phase, not after the incident is closed; doing it afterward indicates the incident was not properly contained. Option C is wrong because disabling affected user accounts is a containment action that should have been executed during the containment phase, not after eradication; leaving accounts enabled until after the incident is over would risk further compromise. Option D is wrong because deleting all incident-related logs destroys forensic evidence needed for legal proceedings, regulatory compliance, and the post-incident review itself; logs must be preserved per retention policies (e.g., NIST SP 800-61).

965
MCQeasy

A hospital's compliance officer must decide how to protect patient records. The records must remain readable only to authorized clinicians while in storage and in transit. Which security principle is the compliance officer primarily applying?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerC

Confidentiality ensures information is not disclosed to unauthorized individuals, which directly matches the requirement that only authorized clinicians can read patient records. Protecting data in storage and transit through encryption and access controls is the classic application of this principle, so it is the correct choice for this scenario.

Why this answer

Confidentiality is the security principle that prevents unauthorized disclosure of information. The scenario requires that patient records remain readable only to authorized clinicians, both at rest and in transit, which is exactly what confidentiality controls such as encryption and access control provide. The other principles address availability, proof of origin, or protection from modification, none of which is the primary requirement described.

Exam trap

The trap here is confusing confidentiality with integrity, because both often use encryption, but only confidentiality addresses preventing unauthorized reading rather than unauthorized changes.

966
Multi-Selecthard

A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)

Select 2 answers
A.Disable ICMP redirects on hosts.
B.Enable DHCP snooping with Dynamic ARP Inspection.
C.Use MAC address filtering on switches.
D.Enable STP BPDU guard.
E.Configure static ARP entries on critical servers.
AnswersB, E

Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table, dropping replies that map an IP to the wrong MAC. This detects and blocks ARP spoofing, satisfying the requirement to identify forged ARP traffic on the local network.

Why this answer

Option B is correct because Dynamic ARP Inspection (DAI), working together with DHCP snooping, validates ARP packets against the trusted DHCP snooping binding table and drops ARP packets with spoofed IP-to-MAC mappings, directly detecting and preventing ARP spoofing on the local network. Option E is correct because configuring static ARP entries on critical servers hard-codes the legitimate IP-to-MAC mappings, so the servers ignore forged ARP replies and cannot be poisoned by an attacker on the same segment. Option A does not belong because disabling ICMP redirects only prevents hosts from accepting forged redirect messages for routing manipulation, not ARP cache poisoning.

Option C does not belong because MAC address filtering on switches only restricts which MAC addresses may appear on a port and does not validate ARP payloads, so an attacker can still spoof ARP for an allowed MAC. Option D does not belong because STP BPDU guard protects against rogue switches sending spanning-tree BPDUs and has no role in detecting or preventing ARP spoofing.

Exam trap

ISC2 often tests the distinction between Layer 2 security features (like DAI and DHCP snooping) and Layer 3 or other mitigation techniques (like ICMP redirects or BPDU guard), leading candidates to confuse unrelated security controls with ARP-specific defenses.

967
Multi-Selecteasy

Which TWO of the following are examples of administrative security controls?

Select 2 answers
A.Firewall rule sets
B.Data encryption
C.Biometric access controls
D.Security policies and procedures
E.Security awareness training
AnswersD, E

Policies and procedures are administrative controls because they govern behaviour through documented rules rather than technical enforcement or physical barriers. They satisfy the stem's requirement by directing personnel actions, defining acceptable use and mandating compliance across the organisation.

Why this answer

Administrative security controls are the management-oriented, people-and-process controls that govern how an organization operates, so D (Security policies and procedures) is correct because written policies, standards, and procedures define required behavior and are classic administrative controls. E (Security awareness training) is also correct because it is a management-driven program that educates personnel on policy and safe practices, which is administrative in nature. By contrast, A (Firewall rule sets) is a technical/logical control implemented in network devices, B (Data encryption) is a technical control that protects data confidentiality via cryptographic algorithms, and C (Biometric access controls) is a physical control using physiological characteristics for authentication, so none of these belong to the administrative category.

Exam trap

The trap is misclassifying biometrics as administrative because it involves a 'system'; biometrics are physical controls, and only policies/procedures and training are administrative here.

968
MCQhard

An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?

A.2 hours
B.3 hours
C.4 hours
D.1 hour
AnswerA

MTD equals RTO plus WRT. With an MTD of 4 hours and an RTO of 2 hours, the remaining allowance for work recovery is 2 hours. RPO governs data loss, not this calculation, so it does not affect the result.

Why this answer

The Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable. It is composed of the Recovery Time Objective (RTO) plus the Work Recovery Time (WRT). Given MTD = 4 hours and RTO = 2 hours, WRT = MTD - RTO = 2 hours.

Exam trap

The trap is confusing RTO and WRT, or forgetting that MTD includes both, leading to selecting RTO or MTD directly.

How to eliminate wrong answers

Option B is wrong because 3 hours would exceed the MTD when added to RTO (2+3=5 > 4). Option C is wrong because 4 hours would equal the MTD, leaving no time for recovery, and WRT must be less than MTD. Option D is wrong because 1 hour is less than the calculated WRT, but the question asks for the maximum allowed, which is 2 hours.

969
Multi-Selecthard

Which TWO of the following are recognized as benefits of network segmentation?

Select 2 answers
A.Reduced attack surface
B.Easier monitoring
C.Increased broadcast domains
D.Simplified IP address management
E.Containment of breaches
AnswersA, E

Segmenting the network into isolated zones limits lateral movement, so a compromised host cannot reach unrelated systems. This directly shrinks the reduced attack surface constraint by removing reachable targets and blocking worm-like propagation between segments.

Why this answer

Network segmentation is recognized for reducing the attack surface (A) because dividing the network into isolated zones limits which hosts and services are reachable from any given segment, so an attacker on one segment cannot directly probe or exploit systems in other segments. It also provides containment of breaches (E), since a compromise in one segment is confined by the segmentation controls (e.g., firewalls, VLANs, ACLs) and cannot freely spread laterally to other segments. The unmarked options do not belong: easier monitoring (B) is not a guaranteed benefit because segmentation adds more boundaries and traffic paths to instrument, increased broadcast domains (C) is the opposite of segmentation, which shrinks broadcast domains, and simplified IP address management (D) is not inherent to segmentation and can actually become more complex with multiple subnets.

Exam trap

CC often tests whether candidates confuse segmentation's security benefits (reduced attack surface, breach containment) with operational side effects (more complex monitoring and IP management) that are not benefits.

970
MCQeasy

An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?

A.Enable full disk encryption on all endpoints.
B.Deploy antivirus software with signature-based detection.
C.Use a blacklist of known malicious applications and allow all others.
D.Implement a whitelist of approved applications and block all others.
AnswerD

A whitelist (allowlist) explicitly permits only approved applications to run, blocking all others by default. This directly enforces the requirement that only authorized software executes. It is the most effective method for application control because it takes a deny-by-default stance, reducing the attack surface from unauthorized or malicious software.

Why this answer

The requirement is to allow only authorized software to execute. An application whitelist (allowlist) enforces this by permitting only explicitly approved applications and blocking all others. This deny-by-default approach is the most effective way to prevent unauthorized or malicious software from running, unlike blacklisting or antivirus, which rely on known signatures.

Exam trap

The trap here is confusing antivirus or blacklisting with application control; those methods do not ensure only authorized software runs, as they allow unknown or new software.

971
MCQmedium

An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?

A.Vulnerability scanner
B.Packet sniffer
C.Intrusion Detection System (IDS)
D.Intrusion Prevention System (IPS)
AnswerD

An IPS is inline and can block traffic.

Why this answer

An Intrusion Prevention System (IPS) is deployed inline in the traffic path and can actively block malicious traffic in real time by dropping or resetting malicious packets. Because it sits inline, it can make blocking decisions on live traffic, which is exactly what the requirement specifies. This distinguishes it from detection-only or passive tools.

Exam trap

CC often tests the IDS vs IPS distinction — candidates see 'block malicious traffic' and pick IDS, forgetting that only an inline IPS can actually block; IDS is detect-and-alert only.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner is an assessment tool that probes systems for known weaknesses on a schedule — it does not sit inline or block live traffic. Option B is wrong because a packet sniffer is a passive capture tool that copies and analyzes traffic but cannot block anything. Option C is wrong because an Intrusion Detection System (IDS) is typically deployed out-of-band (via a SPAN port or TAP) and can only detect and alert — it cannot block traffic because it is not in the traffic path.

972
Multi-Selectmedium

Which THREE of the following are recognized security principles according to NIST and ISC2?

Select 3 answers
A.Separation of duties
B.Security through obscurity
C.Least privilege
D.Defense in depth
E.Single point of failure
AnswersA, C, D

Separation of duties is a recognised NIST and ISC2 security principle: it splits critical tasks across multiple individuals so no single person controls an entire sensitive process, reducing fraud and error risk. ISC2's CISSP domains and NIST SP 800-53 both codify it.

Why this answer

Separation of duties (A) is a recognized NIST and ISC2 security principle because it divides critical functions among multiple individuals so that no single person can execute a fraudulent or damaging action alone, providing built-in checks and balances. Least privilege (C) is endorsed by both NIST and ISC2 as the practice of granting users, processes, and systems only the minimum access rights necessary to perform their authorized tasks, thereby limiting the blast radius of compromise or error. Defense in depth (D) is a core principle in both frameworks, layering multiple overlapping controls (physical, technical, administrative) so that the failure of one control does not result in total compromise.

Security through obscurity (B) is not a recognized principle because it relies on secrecy of design or implementation rather than sound security controls, and it fails once the hidden detail is discovered. Single point of failure (E) is not a principle but an anti-pattern or risk condition that security design seeks to eliminate through redundancy and diversity.

Exam trap

The trap here is that 'security through obscurity' sounds plausible to candidates who conflate it with legitimate techniques like obfuscation, but NIST and ISC2 explicitly reject it as a standalone principle — and 'single point of failure' is a design flaw, not a principle.

973
MCQmedium

A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?

A.Separation of duties enforced through constrained RBAC
B.Rule-based access control
C.Mandatory access control (MAC)
D.Role-based access control (RBAC)
AnswerA

Separation of duties splits sensitive tasks among different people, and constrained RBAC enforces it by defining mutually exclusive roles so one account cannot hold both the initiating and approving permissions. This directly prevents a manager from approving their own refund while still allowing them to approve transactions created by others.

Why this answer

The requirement is that one person must not both create and approve a refund, which is the principle of separation of duties. Constrained RBAC enforces it by making the refund initiation and refund approval roles mutually exclusive, so no single account can hold both. Label-based, role-only, and global rule models cannot express that interpersonal conflict.

Exam trap

The trap here is choosing role-based access control alone, when plain RBAC grants permissions by role without preventing one person from holding conflicting roles.

974
MCQhard

A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?

A.Application proxy firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Stateful inspection firewall
AnswerC

A next-generation firewall performs SSL/TLS inspection by acting as a man-in-the-middle proxy: it decrypts traffic using a trusted certificate, examines payloads for threats and policy violations, then re-encrypts before forwarding. This satisfies the stem's requirement for content inspection of encrypted sessions, which traditional packet-filtering or stateful firewalls cannot achieve.

Why this answer

A Next-Generation Firewall (NGFW) includes SSL/TLS decryption and inspection capabilities, allowing it to decrypt encrypted traffic, inspect the plaintext for threats or policy violations, and then re-encrypt it before forwarding. This is a defining feature that separates NGFWs from traditional firewalls. The other firewall types lack the deep packet inspection and decryption engine required.

Exam trap

CC often tests whether candidates know that only NGFWs (and dedicated TLS inspection appliances) can decrypt and re-encrypt SSL/TLS — candidates may incorrectly attribute this to application proxy or stateful inspection firewalls because those sound more 'advanced.'

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at the application layer but traditionally does not perform SSL/TLS decryption and re-encryption of arbitrary traffic — it proxies specific application protocols and lacks the integrated TLS inspection engine. Option B is wrong because a packet filtering firewall only examines packet headers (source/destination IP, port, protocol) and cannot see inside encrypted payloads at all. Option D is wrong because a stateful inspection firewall tracks connection state but still only inspects headers and cannot decrypt TLS to examine content.

975
MCQmedium

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

A.Confidentiality
B.Integrity
C.Authentication
D.Availability
AnswerD

Redundant servers and failover maintain uptime when a component or power source fails, directly preserving access to systems and data. Availability is the CIA goal concerned with ensuring authorised users can reach resources when required.

Why this answer

Availability ensures that systems and data are accessible to authorized users when needed, and redundant servers with failover mechanisms directly support continuous operation during outages. This is the core goal of the availability pillar of the CIA triad. Confidentiality and integrity address different concerns, so availability is the correct answer.

Exam trap

The trap is that candidates may associate redundancy with integrity or confidentiality because both involve protecting data, but the question's focus on continuous operation during an outage clearly points to availability.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized access to data, typically through encryption, access controls, and classification, not on ensuring uptime. Option B is wrong because integrity ensures data is accurate and unaltered, using hashing, checksums, and digital signatures, which is unrelated to failover and redundancy. Option C is wrong because authentication verifies identity through credentials, MFA, or certificates, and is not one of the three CIA triad goals at all, making it a distractor.

Page 12

Page 13 of 14

Page 14