Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 976–989

989 questions total · 14pages · All types, answers revealed

Page 13

Page 14 of 14

976
MCQeasy

Which of the following protocols provides secure remote administration of a network device over an untrusted network?

A.SNMPv1
B.Telnet
C.HTTP
D.SSH
AnswerD

SSH encrypts the entire session, including authentication credentials and commands, using strong ciphers over TCP port 22. This satisfies the stem's untrusted-network constraint, unlike Telnet, which transmits everything in cleartext. It also supports key-based authentication and tunnelling, making it the standard for secure remote administration of network devices.

Why this answer

SSH (Secure Shell) is correct because it encrypts all traffic, including authentication credentials and commands, using strong cryptographic algorithms, making it safe for remote administration over untrusted networks. It operates on TCP port 22 and provides confidentiality, integrity, and authentication, unlike cleartext protocols. SSH is the standard for secure CLI access to network devices such as routers and switches.

Exam trap

ISC2 often tests the distinction between 'secure' and 'insecure' protocols, and the trap here is that candidates may confuse Telnet with SSH because both provide remote CLI access, forgetting that Telnet lacks encryption entirely.

How to eliminate wrong answers

Option A is wrong because SNMPv1 uses community strings in cleartext and lacks encryption or authentication, making it insecure for remote administration over untrusted networks. Option B is wrong because Telnet transmits all data, including usernames and passwords, in plaintext, allowing anyone with packet capture access to intercept credentials and commands. Option C is wrong because HTTP transmits data unencrypted, and while HTTPS exists, the question specifies HTTP, which provides no security for remote administration.

977
MCQmedium

A financial services firm wants to allow employees to securely access internal applications from home without exposing those applications directly to the internet. The security team proposes using a VPN that encrypts traffic at the network layer and can carry non-web protocols. Which VPN technology best meets this requirement?

A.TLS-based web VPN portal
B.RADIUS authentication with 802.1X
C.IPsec in tunnel mode
D.SSH port forwarding
AnswerC

IPsec in tunnel mode encapsulates entire IP packets, encrypting the payload and original headers, so remote clients can reach internal applications over any IP-based protocol. It operates at the network layer, providing confidentiality and integrity for non-web traffic, which matches the firm's need to avoid exposing applications directly while supporting diverse internal services.

Why this answer

IPsec in tunnel mode encrypts and encapsulates entire IP packets, enabling remote users to securely reach internal applications over any IP-based protocol. Unlike browser-based TLS VPNs or SSH port forwarding, it provides transparent network-layer connectivity without exposing applications to the internet. RADIUS with 802.1X handles LAN access control, not remote traffic encryption, so it cannot meet the stated requirement.

Exam trap

The trap here is assuming any encrypted remote access method, such as a TLS web portal or SSH tunnel, provides the same broad network-layer VPN coverage as IPsec tunnel mode.

978
MCQmedium

A hospital uses role-based access control (RBAC) for its electronic health records. Nurses can view patient records; doctors can view and edit; administrators can only view administrative data. Recently, a nurse was able to edit a patient's record, which should only be allowed for doctors. The investigation finds that the nurse's role was incorrectly assigned a 'doctor' role due to a misconfiguration. To prevent recurrence, the access control system should be reviewed. Which is the best long-term solution?

A.Implement mandatory access control (MAC) with security labels
B.Remove the nurse's ability to edit records
C.Implement user behavior analytics to detect anomalies
D.Conduct quarterly role reviews and recertification
AnswerD

Quarterly role reviews and recertification directly address the misconfiguration by periodically validating that each user's assigned role matches their actual job function, catching privilege drift before it is exploited. This satisfies the stem's long-term prevention requirement, since detective controls like reviews correct the assignment errors that RBAC's static role mappings cannot self-detect.

Why this answer

The root cause is a role misconfiguration, and the best long-term solution is to implement a process of periodic role reviews and recertification. This ensures that role assignments are regularly audited and validated against current job responsibilities, preventing role creep and unauthorized privilege accumulation. In RBAC, the principle of least privilege is maintained through ongoing governance, not through a one-time fix.

Exam trap

ISC2 often tests the distinction between reactive fixes (like removing a single user's permission) and systemic governance processes (like periodic recertification), trapping candidates who choose a quick technical fix instead of a long-term administrative control.

How to eliminate wrong answers

Option A is wrong because mandatory access control (MAC) uses system-enforced security labels (e.g., classification levels) and is not designed to fix a role misconfiguration in an RBAC system; it would require a complete architectural change and does not address the need for periodic role validation. Option B is wrong because removing the nurse's ability to edit records is a reactive, short-term fix that does not prevent future misconfigurations or other role assignment errors; it treats the symptom, not the systemic issue. Option C is wrong because user behavior analytics (UBA) can detect anomalous activity after it occurs, but it does not prevent the underlying misconfiguration or ensure correct role assignments; it is a detective control, not a preventive or corrective control for role management.

979
MCQeasy

Which of the following is a best practice for securing physical access to a data center?

A.Allow employees to use personal badges for entry.
B.Implement mantrap entry with biometric verification.
C.Install CCTV only at the main entrance.
D.Use a single-factor authentication for all doors.
AnswerB

Mantrap entry with biometric verification enforces single-person authentication at each interlocking door, preventing tailgating and unauthorised entry. This directly satisfies the stem's requirement for securing physical access, since biometrics bind access to an individual rather than a shared credential, and the mantrap physically constrains anyone attempting to follow through.

Why this answer

Implementing mantrap entry with biometric verification is a best practice because it enforces two-factor authentication (something you have, like a badge, and something you are, like a fingerprint) and prevents tailgating. Mantraps are interlocking doors that allow only one person at a time, enhancing physical security.

Exam trap

CC often tests the difference between single-factor and multi-factor authentication, and the misconception that CCTV alone is sufficient for physical security.

How to eliminate wrong answers

Option A is wrong because allowing personal badges for entry is not a best practice; badges should be issued and controlled by the organization. Option C is wrong because CCTV only at the main entrance is insufficient; coverage should be comprehensive. Option D is wrong because single-factor authentication (e.g., a badge) is weaker than multi-factor; best practice requires at least two factors.

980
MCQeasy

Which layer of the OSI model is responsible for routing packets across networks?

A.Network layer
B.Physical layer
C.Transport layer
D.Data Link layer
AnswerA

The network layer handles logical addressing and path selection, forwarding packets between networks via routers using layer 3 addresses. This satisfies the stem's routing requirement, distinguishing it from the data link layer, which forwards frames within a single network segment.

Why this answer

The Network layer (Layer 3) of the OSI model is responsible for logical addressing and routing packets across networks. Protocols like IP, ICMP, and routing protocols (OSPF, BGP) operate at this layer, using IP addresses to determine the best path between networks. Routers are the classic Layer 3 devices that forward packets based on routing tables.

Exam trap

CC often tests OSI layer responsibilities, and the trap is confusing the Transport layer (end-to-end delivery, TCP/UDP) with the Network layer (routing, IP addressing) — candidates may pick Transport because it 'delivers' data, but routing specifically belongs to Layer 3.

How to eliminate wrong answers

Option B is wrong because the Physical layer (Layer 1) deals with the transmission of raw bits over physical media — cables, connectors, voltages, and signaling — not routing. Option C is wrong because the Transport layer (Layer 4) handles end-to-end communication, segmentation, flow control, and reliability via TCP/UDP, but it does not route packets between networks. Option D is wrong because the Data Link layer (Layer 2) handles framing, MAC addressing, and error detection on the local link, and switches operate here — it does not perform inter-network routing.

981
MCQmedium

Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?

A.Add world read permission.
B.Change group permissions to rw-r--.
C.Change the file mode to 640.
D.Change the owner to user2.
AnswerC

Mode 640 grants read and write to user1 and read-only to the developers group, removing the execute bits and the world-readable permission currently present. This enforces least privilege, restricting access to exactly the owner and group members the policy names.

Why this answer

The current mode -rw-r-x--- gives the owner rw, the group r-x, and others no access. The policy requires only the owner and group members to read the file, so group should be r-- (read only, no execute) and others should have no permissions. Mode 640 (rw-r-----) achieves exactly this: owner rw, group r, others none.

Exam trap

The trap here is misreading the symbolic mode string and thinking 'r-x' for group is acceptable because it includes read — but the x bit grants execute, which violates least privilege; candidates must translate the symbolic string to octal (640) correctly.

How to eliminate wrong answers

Option A is wrong because adding world read permission (-rw-r-xr--) grants read access to all users, directly violating least privilege. Option B is wrong because 'rw-r--' is not a valid symbolic mode for the group field; the group field only has three positions (r, w, x), and 'rw-' would give the group write access, which is more than the policy requires. Option D is wrong because changing the owner to user2 transfers ownership away from user1, contradicting the policy that user1 must retain owner access.

982
MCQmedium

A software-as-a-service (SaaS) provider is developing its business continuity plan (BCP). The company wants to ensure it can continue operating during a prolonged power outage at its primary data center. Which element of the BCP should address the alternate power source and its regular testing?

A.Incident response plan (IRP)
B.Continuity strategies
C.Disaster recovery plan (DRP)
D.Business impact analysis (BIA)
AnswerB

Continuity strategies describe the specific approaches and resources, such as alternate power sources, that will be used to maintain critical functions during a disruption. For a prolonged power outage, the strategy would include details on generators, uninterruptible power supplies, fuel contracts, and testing schedules. This element directly addresses how the SaaS provider will keep operating and ensures the power solution is documented and exercised.

Why this answer

Continuity strategies are the component of the business continuity plan that outlines how critical functions will be maintained during disruptions, including the use of alternate power sources. They specify the resources, responsibilities, and testing required to ensure the strategy works. The BIA identifies the need, but the strategy provides the solution.

Exam trap

The trap here is confusing the business impact analysis, which identifies the need for power continuity, with the continuity strategy, which actually documents the alternate power source and its testing.

983
MCQhard

During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?

A.Report to CERT/CC
B.Rebuild all affected systems
C.Apply a vendor patch
D.Implement compensating controls
AnswerD

No patch exists for a zero-day, so patching cannot remove the exposure. Compensating controls—such as network segmentation, tightened firewall rules or enhanced monitoring—reduce exploitability or impact immediately, containing the threat while the vendor develops a fix. This directly addresses the stem's demand for the best immediate action.

Why this answer

When a zero-day vulnerability is the root cause, no vendor patch exists yet (option C is impossible). Rebuilding systems (option B) without addressing the vulnerability leaves them re-exposed. The best immediate action is to implement compensating controls—such as firewall rules, IDS/IPS signatures, or application-layer filtering—to mitigate the risk until a permanent fix is available.

This aligns with incident response containment strategies that prioritize reducing impact while preserving forensic evidence.

Exam trap

ISC2 often tests the misconception that 'rebuilding systems' or 'applying a patch' are immediate actions for a zero-day, when in reality the absence of a patch and the need for containment make compensating controls the only viable first step.

How to eliminate wrong answers

Option A is wrong because reporting to CERT/CC is a post-incident coordination step, not an immediate containment action; it does not stop the ongoing attack. Option B is wrong because rebuilding affected systems without first containing the vulnerability will result in immediate re-infection, as the zero-day exploit vector remains active. Option C is wrong because a zero-day vulnerability, by definition, has no vendor patch available at the time of discovery; applying a non-existent patch is impossible.

984
MCQmedium

Which security control would best mitigate the risk of network sniffing on a wired LAN segment?

A.Using encryption protocols (e.g., IPsec, TLS)
B.Implementing VLANs
C.Disabling unused ports on the switch
D.Deploying an intrusion detection system
AnswerA

IPsec and TLS encrypt payloads end-to-end, so frames captured by a sniffer on the wired segment appear as ciphertext rather than readable credentials or data. Encryption directly defeats sniffing, whereas segmentation or port security only limit where an attacker can capture traffic.

Why this answer

Encrypting traffic (e.g., using HTTPS, VPN) makes sniffed data unreadable.

985
MCQeasy

Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?

A.Differential backup
B.Full backup
C.Synthetic full backup
D.Incremental backup
AnswerD

Incremental backups copy only data changed since the last backup, so daily runs are quick. Restores require the last full backup plus every subsequent incremental in sequence, making full recovery the slowest of the strategies.

Why this answer

An incremental backup only captures data changed since the last backup of any type, so each daily run is very fast and small. However, a full restore requires the last full backup plus every incremental since then, applied in sequence—making restore the slowest of all strategies.

Exam trap

The trap is mixing up differential and incremental—candidates often remember 'incremental is fast' but forget that fast backups mean slow, chain-dependent restores.

How to eliminate wrong answers

Option A is wrong because differential backups capture everything changed since the last full, so daily backups grow larger and slower over time, though restore is faster (full + latest differential). Option B is wrong because a full backup is the slowest to perform daily but the fastest to restore—the exact opposite of the question. Option C is wrong because a synthetic full is constructed from previous backups on the backup server, which is efficient for the source but still yields a single-restore image, not the slowest restore.

986
MCQeasy

An organization requires that two different administrators approve changes to firewall rules. This is an example of which security principle?

A.Least privilege
B.Defense in depth
C.Separation of duties
D.Need-to-know
AnswerC

Separation of duties splits a sensitive task across multiple people so no single administrator can unilaterally change firewall rules. Requiring two distinct approvers enforces this principle, preventing one person from both initiating and authorising the change.

Why this answer

Requiring two different administrators to approve firewall changes is separation of duties, which splits a critical task among multiple people so no single individual can complete it alone. This prevents fraud, error, and unilateral abuse of privileged access.

Exam trap

The trap is confusing separation of duties with least privilege; both limit privilege, but only separation of duties requires multiple people to complete one critical action.

How to eliminate wrong answers

Option A is wrong because least privilege limits what each person can access, but it does not require two people to act together. Option B is wrong because defense in depth layers multiple controls; it does not describe dual approval of a single action. Option D is wrong because need-to-know restricts access to information based on job necessity, not the requirement for two-person authorization.

987
MCQmedium

A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?

A.A network access control (NAC) solution
B.A remote access VPN terminating on a VPN concentrator
C.A reverse proxy published in the DMZ
D.A site-to-site IPsec tunnel between two data centers
AnswerB

A remote access VPN lets individual clients establish an encrypted tunnel to a VPN concentrator, and split-tunnel or full-tunnel policies can restrict which internal resources are reachable. Because the client initiates the connection, internal application servers never need to initiate connections back to the client, satisfying the requirement. This design keeps internal applications off the public internet while giving employees authenticated access.

Why this answer

Remote employees need an encrypted path into the internal network that they initiate, so internal servers never connect back to them. A remote access VPN terminated on a concentrator provides exactly this client-initiated tunnel and can be scoped to specific internal resources. Site-to-site tunnels, reverse proxies, and NAC address different problems and do not meet both stated constraints.

Exam trap

The trap here is conflating site-to-site VPNs with remote access VPNs, even though only the latter is designed for individual clients initiating connections from outside the network.

988
Multi-Selectmedium

Which TWO of the following are common indicators of a phishing email? (Select TWO.)

Select 2 answers
A.The email contains an attachment with a .txt extension
B.The email contains a sense of urgency, such as 'Your account will be closed.'
C.The email has a high-importance flag set by the sender
D.The email is sent to multiple recipients in the 'To' field
E.The sender's email address is similar but not identical to a legitimate domain
AnswersB, E

Urgency is a common social engineering tactic.

Why this answer

Phishing emails commonly exploit urgency to bypass rational decision-making. Attackers use phrases like 'Your account will be closed' to pressure recipients into clicking malicious links or providing credentials without verifying the source. This social engineering tactic is a hallmark of phishing campaigns.

Exam trap

ISC2 often tests the distinction between technical indicators (e.g., file extensions, headers) and behavioral indicators (e.g., urgency, domain spoofing), and the trap here is that candidates mistake common email features like high-importance flags or bulk addressing as phishing indicators when they are not inherently suspicious.

989
MCQeasy

A security team implements a policy that requires all access to sensitive data to be logged and audited. Which principle is being enforced?

A.Accountability
B.Non-repudiation
C.Integrity
D.Least privilege
AnswerA

Accountability requires that every action against sensitive data is attributable to a specific identity. Logging and auditing create the traceable record that enforces this, satisfying the policy's requirement that all access be recorded and reviewable.

Why this answer

Accountability is enforced because logging and auditing create a traceable record of who accessed sensitive data and what actions they performed. This allows security teams to hold individuals responsible for their actions by correlating log entries with specific user identities, typically via authentication systems like LDAP or SAML. The policy directly supports the principle that users must be answerable for their access to protected resources.

Exam trap

ISC2 often tests the distinction between accountability (tracking and attributing actions) and non-repudiation (cryptographic proof of origin), leading candidates to confuse logging with the stronger assurance provided by digital signatures.

How to eliminate wrong answers

Option B is wrong because non-repudiation ensures that a party cannot deny having performed an action, typically achieved through digital signatures or cryptographic proof (e.g., HMAC, RSA signatures), not through logging and auditing alone. Option C is wrong because integrity focuses on protecting data from unauthorized modification (e.g., via checksums, hashing like SHA-256, or access controls), not on tracking who accessed it. Option D is wrong because least privilege restricts access rights to the minimum necessary for a role, whereas logging and auditing are about monitoring and reviewing access after it has occurred, not about limiting permissions upfront.

Page 13

Page 14 of 14