Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 151–225

989 questions total · 14pages · All types, answers revealed

Page 2

Page 3 of 14

Page 4
151
MCQeasy

What is the primary difference between an IDS and an IPS?

A.IDS is faster than IPS
B.IDS is hardware, IPS is software
C.IDS monitors only hosts, IPS monitors network
D.IDS only alerts, IPS can block traffic
AnswerD

An IDS passively monitors copies of traffic and raises alerts, leaving response to administrators. An IPS sits inline on the traffic path, so it can drop malicious packets or reset connections in real time. That inline blocking capability, absent from an alert-only IDS, is the defining difference the question asks for.

Why this answer

The primary difference is that an IDS (Intrusion Detection System) is passive and only alerts on suspicious activity, while an IPS (Intrusion Prevention System) is inline and can actively block or drop malicious traffic. Both can monitor network or host activity, but the key distinction is the response capability: detect vs. detect and prevent.

Exam trap

The trap is confusing the deployment mode (inline vs. out-of-band) with the response capability; the exam tests that the key difference is alert-only vs. block, not speed, form factor, or scope.

How to eliminate wrong answers

Option A is wrong because speed is not the defining difference; both can operate at similar speeds, and an IPS may introduce latency due to inline processing. Option B is wrong because both IDS and IPS can be hardware or software; the deployment form factor is not the primary difference. Option C is wrong because both IDS and IPS can monitor hosts or networks (HIDS/NIDS, HIPS/NIPS); the scope is not the defining difference.

152
Multi-Selectmedium

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

Select 2 answers
A.Increased DNS query responses
B.High number of ICMP echo replies
C.Unusual outbound traffic on port 80
D.Large number of half-open connections
E.High number of SYN packets with no ACK
AnswersD, E

Each spoofed SYN packet forces the server to allocate a connection table entry and reply with SYN-ACK, then wait for a response that never arrives. These half-open connections accumulate until the backlog queue is exhausted, which is the defining resource-exhaustion symptom of a SYN flood.

Why this answer

Options D and E are both correct indicators of a SYN flood attack. Option D is correct because a SYN flood sends many SYN packets to initiate TCP connections but never completes the three-way handshake, leaving numerous half-open connections in the SYN_RECEIVED state on the server, which exhausts resources. Option E is correct because the attack generates a high number of SYN packets from the attacker, and since the handshake is never completed, the corresponding ACK packets are absent.

Both symptoms—half-open connections and SYN packets without ACK—are characteristic of a SYN flood.

Exam trap

A common pitfall in the ISC2 CC exam is distinguishing between the symptom of 'half-open connections' (server-side resource exhaustion) and the traffic pattern of 'SYN packets with no ACK' (attacker behavior). Both are correct indicators of a SYN flood.

153
MCQhard

According to the (ISC)² Code of Ethics, which canon has the highest priority?

A.Provide diligent and competent service to principals
B.Advance and protect the profession
C.Act honorably, honestly, justly, responsibly, and legally
D.Protect society, the common good, necessary public trust and confidence, and the infrastructure
AnswerD

The (ISC)² Code of Ethics orders its canons so that protecting society, the common good, public trust and the infrastructure ranks first, above duties to principals, the profession and colleagues. This canon therefore takes precedence when obligations conflict, satisfying the stem's highest-priority requirement.

Why this answer

The (ISC)² Code of Ethics Canons are ordered by priority, and the first canon — 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' — takes precedence over all others. This reflects the profession's obligation to place the safety and welfare of society above client interests and professional advancement. When canons conflict, the higher-priority canon must guide the decision.

Exam trap

CC often tests the misconception that 'serving the client/principal' is the top ethical duty, when in fact protecting society and the common good always outranks obligations to principals or the profession.

How to eliminate wrong answers

Option A is wrong because 'Provide diligent and competent service to principals' is the third canon, subordinate to protecting society and acting honorably. Option B is wrong because 'Advance and protect the profession' is the fourth (lowest-priority) canon, applying only after all others are satisfied. Option C is wrong because 'Act honorably, honestly, justly, responsibly, and legally' is the second canon, important but still ranked below the duty to protect society and the common good.

154
Multi-Selectmedium

Which THREE of the following are key objectives of a security risk management program?

Select 3 answers
A.Assess risks
B.Identify risks
C.Implement intrusion detection systems
D.Encrypt all data at rest
E.Mitigate risks
AnswersA, B, E

Assessing risks identifies, analyses and evaluates threats and vulnerabilities against organisational assets, establishing the likelihood and impact baseline that every subsequent treatment decision depends on. Without this evaluation step, risk cannot be prioritised or mitigated meaningfully, making it a foundational objective of any security risk management programme.

Why this answer

The three key objectives of a security risk management program are to identify risks (B), assess risks (A), and mitigate risks (E). Identifying risks means discovering and documenting threats, vulnerabilities, and potential adverse events that could affect the organization's assets. Assessing risks involves analyzing the likelihood and impact of those identified risks, often through qualitative or quantitative methods, to determine their severity and priority.

Mitigating risks means applying controls, such as administrative, technical, or physical safeguards, to reduce risk to an acceptable level. Options C and D are not key objectives of risk management itself; implementing intrusion detection systems and encrypting all data at rest are specific security controls or countermeasures that may be selected during risk mitigation, not the overarching objectives of the program.

Exam trap

The trap here is confusing specific security controls (like IDS or encryption) with the overarching objectives of risk management; candidates often pick controls because they sound security-related, but the question asks for key objectives, not implementations.

155
MCQmedium

A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?

A.Separation of duties
B.Need-to-know
C.Least privilege
D.Defense in depth
AnswerC

Least privilege means granting only the access needed for a task, so routine email and browsing run without administrative rights. Separating the privileged account limits exposure: compromise of the daily-use account cannot yield administrative control over the system.

Why this answer

Using a separate non-privileged account for daily tasks like email and web browsing while reserving the admin account for administrative work is a direct application of least privilege. Least privilege means users should have only the minimum access necessary for their current task, and separating admin from daily use reduces the attack surface of privileged credentials. This practice limits exposure of administrative rights to routine activities that could be compromised.

Exam trap

The trap is conflating least privilege with separation of duties; both involve splitting access, but least privilege is about minimizing rights for a task, while separation of duties is about distributing critical functions across people.

How to eliminate wrong answers

Option A is wrong because separation of duties divides critical functions among different people to prevent fraud, not the practice of using separate accounts for admin versus daily tasks by the same person. Option B is wrong because need-to-know governs access to information based on job requirements, not the separation of privileged and non-privileged accounts. Option D is wrong because defense in depth is a layered security strategy, not the specific principle of minimizing privileges for daily activities.

156
MCQhard

A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:

A.Stateful firewall
B.Web application firewall (WAF)
C.Honeypot
D.Network-based IPS
AnswerB

A web application firewall inspects HTTP and HTTPS requests, applying signatures and rules to block SQL injection and cross-site scripting. It operates at the application layer, distinguishing it from network firewalls that filter by IP, port, or protocol.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block application-layer attacks like SQL injection and cross-site scripting (XSS). It operates at Layer 7 and understands web protocols, making it the correct choice for protecting web applications from these threats.

Exam trap

The trap is confusing a WAF with a network IPS or stateful firewall; the exam tests that only a WAF is purpose-built for HTTP/HTTPS application-layer attack prevention like SQLi and XSS.

How to eliminate wrong answers

Option A is wrong because a stateful firewall operates at Layers 3-4 and tracks connection state but does not inspect HTTP payloads for SQL injection or XSS. Option C is wrong because a honeypot is a decoy system designed to attract attackers, not to inspect and block web traffic. Option D is wrong because a network-based IPS can detect some web attacks via signatures, but it is not specialized for HTTP/HTTPS application-layer inspection and may not decode web traffic as deeply as a WAF.

157
MCQhard

After a security incident, the incident response team closes the case. What is the MOST important final step to improve future security posture?

A.Revoke all compromised credentials
B.Patch all systems
C.Restore all systems from backup
D.Conduct a post-incident review and update policies
AnswerD

A post-incident review extracts root cause and control gaps while evidence is fresh, then feeds them into updated policies — satisfying the stem's demand for improved future posture. Closing without this step leaves systemic weaknesses unaddressed, so the same attack path recurs. Microsoft Entra ID conditional access tuning often emerges from such reviews.

Why this answer

The post-incident review (often called a lessons-learned meeting) is the final step that analyzes root causes, identifies gaps in detection or response, and drives updates to policies, playbooks, and security controls. Without this review, the same vulnerability or misconfiguration could be exploited again, even if immediate containment steps like credential revocation or patching were performed. The goal is to close the incident with a feedback loop that improves the overall security posture, not just restore operations.

Exam trap

ISC2 often tests the distinction between immediate remediation steps (like patching or credential revocation) and the final continuous improvement step (post-incident review), trapping candidates who confuse containment/recovery with the ultimate goal of preventing future incidents.

How to eliminate wrong answers

Option A is wrong because revoking compromised credentials is a containment step performed during the early stages of incident response, not the final step; it does not address underlying vulnerabilities or process improvements. Option B is wrong because patching all systems is a remediation action that may be necessary but is not the final step—it focuses on technical fixes without analyzing why the incident occurred or updating policies to prevent recurrence. Option C is wrong because restoring systems from backup is a recovery step that returns operations to normal but does not provide any insight into the incident's root cause or lead to long-term security improvements.

158
MCQeasy

An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?

A.A logic bomb
B.A keylogger
C.A rootkit
D.Ransomware
AnswerD

Ransomware encrypts files, often appends unfamiliar extensions, and displays a ransom demand for decryption keys, which matches every symptom described. The cryptocurrency payment demand is a hallmark of this malware class. Even without a recent link click, delivery can occur through exploits, malicious documents, or compromised remote services, making ransomware the most likely culprit.

Why this answer

The combination of encrypted files, altered extensions, and a cryptocurrency ransom demand is the classic signature of ransomware. Delivery does not require a recent link click, since exploits, malicious attachments, and exposed services are common vectors. Recognizing these indicators lets responders isolate the host quickly, preserve evidence, and avoid paying, while restoring from offline backups if available.

Exam trap

The trap here is assuming ransomware always requires a recent link click, which overlooks exploit-based and service-based delivery methods.

159
MCQeasy

A help desk technician receives a report that a user cannot access a shared network drive. The technician checks the file server and sees that the disk is full. What is the most immediate action the technician should take?

A.Reboot the file server
B.Free up space by deleting unnecessary files or moving data
C.Run antivirus scan
D.Increase disk quota
AnswerB

Freeing space directly resolves the full disk, the constraint blocking the share. Deleting unnecessary files or relocating data restores write capacity so the server can serve the network drive again. This is the fastest remediation, taking precedence over permission checks or reboots, which would not address the exhausted storage.

Why this answer

A full disk on the file server is the direct cause of the user's inability to access the shared drive, so the most immediate remediation is to reclaim space by deleting unnecessary files or relocating data. This restores write capability and resolves the symptom without unnecessary disruption. It is the fastest, least invasive action that addresses the root cause identified during triage.

Exam trap

The trap here is choosing a dramatic action like rebooting or running antivirus when the scenario clearly identifies a specific root cause (disk full) that has a direct, simple remediation.

How to eliminate wrong answers

Option A is wrong because rebooting the file server does not free disk space and would cause an outage, potentially worsening the situation without fixing the underlying capacity issue. Option C is wrong because an antivirus scan is unrelated to a disk-full condition and would consume additional I/O and time without addressing the cause. Option D is wrong because increasing a disk quota does not help when the physical or logical volume itself is full; quotas govern per-user limits, not total volume capacity.

160
MCQhard

During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?

A.Notify the contractor's manager
B.Revoke the contractor's access immediately
C.Perform a risk assessment
D.Log the access for evidence
AnswerB

Revoking the contractor's access immediately closes the excessive-permission exposure, satisfying least privilege before any investigation. Removing the unneeded database rights first eliminates the active risk; reviewing the contract or auditing logs afterwards addresses root cause without leaving the vulnerability open.

Why this answer

The immediate priority is to revoke the contractor's access to the unauthorized customer databases to stop any potential data exfiltration or misuse. Access controls follow the principle of least privilege, and any discovered over-provisioning must be corrected instantly to contain the risk. Delaying revocation for notification, assessment, or logging leaves the sensitive data exposed to an unauthorized user.

Exam trap

ISC2 often tests the candidate's ability to prioritize containment over investigation or notification, trapping those who choose risk assessment or logging first instead of immediate access revocation.

How to eliminate wrong answers

Option A is wrong because notifying the contractor's manager does not remove the active access; the contractor can still query or exfiltrate data while the notification is processed. Option C is wrong because performing a risk assessment is a secondary step that should occur after access is revoked; leaving access in place during assessment violates the security principle of containment. Option D is wrong because logging access for evidence is important for forensics but does not mitigate the ongoing risk; the access must be terminated first to prevent further unauthorized actions.

161
MCQeasy

Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?

A.Stateful inspection firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Application proxy firewall
AnswerB

Packet filtering firewalls inspect only Layer 3 and Layer 4 headers, permitting or denying traffic by source and destination IP addresses and port numbers. They perform no application-layer inspection, which matches the stated decision criteria exactly.

Why this answer

A packet filtering firewall operates at Layer 3 (Network) and Layer 4 (Transport) of the OSI model, examining source and destination IP addresses and port numbers to allow or deny traffic. It is stateless and makes decisions per packet based on configured ACLs.

Exam trap

The trap is confusing stateless packet filtering with stateful inspection; the key phrase 'solely based on source/destination IP and port numbers' signals a stateless Layer 3/4 filter.

How to eliminate wrong answers

Option A is wrong because a stateful inspection firewall tracks connection state (e.g., TCP handshake) and makes decisions based on the state table, not solely on IP and port. Option C is wrong because an NGFW adds application-layer inspection, intrusion prevention, and user identity awareness, going well beyond Layer 3/4 headers. Option D is wrong because an application proxy firewall operates at Layer 7, terminating and inspecting application protocols, not just IP and port.

162
MCQmedium

A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?

A.Cross-site request forgery
B.Cross-site scripting
C.Directory traversal
D.SQL injection
AnswerC

Directory traversal uses sequences like '../' to escape the intended directory and read files elsewhere on the host. The encoded and literal dot-dot-slash patterns targeting passwd and system32 files are classic traversal attempts against a file-download endpoint. The attacker is trying to make the application return files it should never expose, which matches this attack exactly.

Why this answer

The dot-dot-slash sequences, including the URL-encoded form, are attempts to climb out of the intended directory and read sensitive files such as the password file or Windows system binaries. This is textbook directory traversal against a file-download function. The attacker is not injecting script, SQL, or forging a session request, but manipulating the path the application resolves.

Exam trap

The trap here is treating any encoded or unusual input as SQL injection, when the specific dot-dot-slash and system-file targets clearly point to filesystem path manipulation.

163
MCQmedium

A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?

A.Data confidentiality issues
B.Both organizations may be impacted by the same disaster
C.Slow recovery due to lack of equipment
D.High cost of maintaining the agreement
AnswerB

Reciprocal agreements rely on each party hosting the other's workloads, so a disaster affecting one organisation's region or infrastructure can simultaneously hit the partner's site. That shared geographic or environmental exposure defeats the purpose of offsite recovery, which is the primary risk the stem asks about.

Why this answer

A reciprocal agreement is an arrangement where two organizations agree to host each other's workloads in the event of a disaster. The primary risk is geographic and correlated failure: if both organizations are in the same disaster zone (flood, hurricane, regional power outage), the same event can disable both sites simultaneously, leaving neither able to host the other.

Exam trap

The trap is focusing on cost or confidentiality as the headline risk — the exam expects candidates to recognize that reciprocal agreements fail primarily because both parties can be hit by the same disaster.

How to eliminate wrong answers

Option A is wrong because while confidentiality is a legitimate concern when sharing facilities, it is a secondary risk managed by access controls and NDAs — not the primary structural weakness of reciprocal agreements. Option C is wrong because reciprocal agreements typically assume the partner has spare capacity, but the real issue is not slowness from lack of equipment; it is that the equipment may be unavailable because the partner is also affected. Option D is wrong because reciprocal agreements are generally low-cost (often just formalized goodwill), so high cost is not the defining risk.

164
MCQmedium

A SOC analyst is reviewing logs from a web server and sees the following entry: GET /../../../../etc/passwd HTTP/1.1 Which type of attack is being attempted?

A.Cross-site scripting
B.SQL injection
C.Directory traversal
D.Cross-site request forgery
AnswerC

The sequence of ../ directory sequences climbing to /etc/passwd attempts to escape the web root and read a file outside the intended directory. This manipulation of path traversal characters is the defining mechanism of directory traversal, directly matching the logged GET request in the stem.

Why this answer

The log entry shows a GET request with '../' sequences attempting to navigate outside the web root to access the '/etc/passwd' file. This is the classic signature of a directory traversal attack, which exploits insufficient path sanitization to read arbitrary files on the server. The correct answer is C because the attack targets the file system, not the application's data layer or client-side scripts.

Exam trap

ISC2 often tests directory traversal by including a file path like '/etc/passwd' in the URL, which candidates may mistakenly associate with SQL injection or XSS due to the presence of 'passwd' or the GET method, but the key indicator is the '../' sequence indicating file system navigation.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) involves injecting malicious scripts into web pages viewed by other users, not manipulating file paths in HTTP requests. Option B is wrong because SQL injection targets database queries by inserting SQL commands into input fields, whereas this request is a simple GET with path traversal sequences and no SQL syntax. Option D is wrong because cross-site request forgery (CSRF) tricks a user's browser into making unintended requests on their behalf, but the log shows a direct attacker-controlled request, not a forged one.

165
MCQmedium

An organization wants to implement the principle of least privilege for its database administrators. Which approach best achieves this goal?

A.Implement mandatory access control (MAC) with labels for all data.
B.Use role-based access control (RBAC) to grant permissions specific to each administrator's duties.
C.Allow administrators to self-assign permissions as needed.
D.Assign each administrator full database admin rights for simplicity.
AnswerB

RBAC maps permissions to defined job roles rather than individuals, so each database administrator receives only the privileges their duties require. This enforces least privilege at scale and simplifies revocation when duties change, unlike broad shared accounts or standing administrative rights.

Why this answer

Role-based access control (RBAC) directly enforces the principle of least privilege by granting database administrators only the permissions required for their specific job functions. Unlike MAC, which focuses on data classification labels, RBAC maps roles (e.g., backup admin, security admin) to precise sets of privileges, ensuring no user has unnecessary access.

Exam trap

ISC2 often tests the distinction between MAC (which controls access based on data labels) and RBAC (which controls access based on job roles), and the trap here is that candidates mistakenly choose MAC because they associate 'least privilege' with strict classification systems, not realizing that RBAC is the practical, role-specific mechanism for limiting database administrator permissions.

How to eliminate wrong answers

Option A is wrong because mandatory access control (MAC) enforces system-wide security labels (e.g., Top Secret, Secret) and is typically used in military or high-security environments; it does not granularly restrict permissions based on an administrator's specific duties, and it can be overly complex for database administration. Option C is wrong because allowing administrators to self-assign permissions violates the principle of least privilege entirely, as it gives them unchecked authority to escalate their own access. Option D is wrong because assigning full database admin rights to every administrator directly contradicts least privilege by granting excessive, unrestricted access to all database resources, increasing the risk of accidental or malicious damage.

166
MCQmedium

A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?

A.WPA2-PSK with AES
B.WPA3-Enterprise with 802.1X
C.Open with MAC address filtering
D.WEP with TKIP
AnswerA

WPA2-PSK with AES satisfies both stated requirements: pre-shared key authentication and strong encryption through the AES-CCMP cipher. Older WEP and TKIP options are cryptographically broken, and enterprise modes require a RADIUS server rather than a pre-shared key.

Why this answer

WPA2-PSK with AES is the correct choice because it provides strong encryption (AES-CCMP) and uses a pre-shared key for authentication, meeting the requirements for a small office without a RADIUS server. WPA2-PSK is widely supported and offers robust security against common attacks when a strong passphrase is used.

Exam trap

ISC2 often tests the distinction between PSK and Enterprise modes, where candidates mistakenly choose WPA3-Enterprise because it is newer, ignoring the explicit requirement for pre-shared key authentication.

How to eliminate wrong answers

Option B is wrong because WPA3-Enterprise with 802.1X requires a RADIUS server for authentication, which is unnecessary and overcomplicated for a small office using pre-shared key authentication. Option C is wrong because Open with MAC address filtering provides no encryption and can be easily bypassed by MAC spoofing, failing the strong encryption requirement. Option D is wrong because WEP with TKIP is deprecated and insecure—WEP uses RC4 encryption that can be cracked in minutes, and TKIP is a legacy protocol that does not meet strong encryption standards.

167
MCQeasy

Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?

A.Least privilege
B.Need-to-know
C.Defense in depth
D.Separation of duties
AnswerA

Least privilege grants users only the minimum permissions required for their job functions, directly satisfying the stem's constraint. Unlike role-based access control, which assigns permissions by role, least privilege limits each user's access to precisely what their tasks demand, reducing the attack surface and preventing unnecessary privilege accumulation.

Why this answer

The principle of least privilege dictates that users are granted only the minimum permissions necessary to perform their job functions. This reduces the attack surface and limits potential damage from accidental or malicious actions.

Exam trap

The trap is confusing least privilege with need-to-know, which is a subset of least privilege focused on information access rather than all permissions.

How to eliminate wrong answers

Option B is wrong because need-to-know is about restricting access to information based on necessity, but it is more specific to data confidentiality and does not encompass all permissions. Option C is wrong because defense in depth is a layered security strategy, not a principle for granting permissions. Option D is wrong because separation of duties involves dividing tasks among multiple people to prevent fraud, not about minimizing permissions.

168
MCQmedium

A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?

A.User provisioning
B.Separation of duties
C.Access review or recertification
D.Least privilege
AnswerC

An access review, also called recertification, periodically examines existing accounts and entitlements to confirm they are still required and to revoke those that are not. Reviewing all active accounts each quarter to remove unneeded ones is precisely this practice. It complements the automatic expiration of temporary accounts by catching access that outlives its business need.

Why this answer

Periodically reviewing active accounts to confirm each is still needed and removing those that are not is an access review, also known as recertification. It works alongside automated expiration of temporary accounts by catching entitlements that persist beyond their business justification, helping the company keep access aligned with current needs and supporting least privilege over time.

Exam trap

The trap here is naming the goal rather than the activity, so candidates pick least privilege when the scenario describes the recurring review process itself.

169
MCQmedium

A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?

A.Subnetting
B.VLAN
C.VPN
D.DMZ
AnswerB

VLANs create logically separate broadcast domains on a single Layer 2 switch, satisfying the no-additional-hardware constraint. Each department's traffic stays isolated at Layer 2 through distinct VLAN IDs and 802.1Q tagging, without requiring routers or extra switches.

Why this answer

VLANs (Virtual LANs) allow a single Layer 2 switch to be logically partitioned into multiple broadcast domains, separating traffic between departments without buying additional hardware. Each VLAN behaves like a separate physical switch, and inter-VLAN traffic must be routed.

Exam trap

The trap is confusing logical separation at Layer 2 (VLAN) with Layer 3 segmentation (subnetting) or with security zones like DMZ/VPN; the key phrase 'on a Layer 2 switch' points to VLAN.

How to eliminate wrong answers

Option A is wrong because subnetting is a Layer 3 IP addressing technique that divides an IP network; by itself it does not logically separate traffic on a Layer 2 switch without VLANs or routing. Option C is wrong because a VPN creates an encrypted tunnel over an untrusted network (e.g., the internet) and is not a Layer 2 switch segmentation technology. Option D is wrong because a DMZ is a network segment for exposing public-facing services, typically implemented with firewalls and separate subnets, not a Layer 2 logical separation feature on a switch.

170
MCQmedium

A financial services firm suffers a ransomware outbreak that encrypts file servers and the backup catalog. The incident response team must decide the immediate next step while the attack is still spreading. Which action BEST aligns with the containment objective of the incident response plan?

A.Notify regulators and affected customers about the data breach before taking any technical action
B.Immediately restore encrypted file servers from the most recent offline backup to shorten downtime
C.Rebuild all servers from scratch using the original installation media and reapply the latest patches
D.Disconnect affected network segments and disable compromised accounts to stop lateral movement
AnswerD

Containment focuses on stopping the spread of the incident and limiting damage. Isolating affected network segments prevents the ransomware from reaching additional hosts, and disabling compromised accounts blocks further authenticated lateral movement. These actions preserve evidence and buy time for eradication and recovery. This is the textbook containment step for an active ransomware outbreak.

Why this answer

Containment aims to stop an incident from spreading and to limit its damage. With ransomware actively propagating, isolating affected network segments and disabling compromised accounts halts lateral movement and preserves the environment for eradication and recovery. Restoring, notifying, or rebuilding before the threat is contained risks reinfection, destroys evidence, and expands the breach rather than limiting it.

Exam trap

The trap here is confusing recovery actions, such as restoring backups or rebuilding servers, with containment, when containment must happen first to stop an active threat from spreading.

171
MCQeasy

Which of the following is a benefit of using VLANs in a network?

A.Logical segmentation without additional hardware
B.Elimination of all broadcast traffic
C.Faster data transfer speeds
D.Increased physical security
AnswerA

VLANs deliver logical segmentation by partitioning a single physical switch into isolated broadcast domains, satisfying the stem's benefit requirement without buying extra switches or routers. This reduces hardware cost and administrative overhead, while containing broadcast traffic and enabling policy separation between departments on shared infrastructure.

Why this answer

VLANs allow logical segmentation of a network at Layer 2, improving security and reducing broadcast traffic without requiring additional physical switches.

172
MCQhard

An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?

A.COBIT
B.ISO 27001
C.NIST SP 800-63
D.PCI DSS
AnswerC

NIST SP 800-63 mandates an eight-character minimum and screens new passwords against breach corpora, directly satisfying both the length floor and the ban on compromised credentials. Its guidance also favours length over forced complexity and rotation, matching the policy's emphasis on breached-password blocking rather than composition rules.

Why this answer

NIST SP 800-63 (Digital Identity Guidelines) explicitly addresses authenticator and memorized-secret requirements, including minimum length and screening against breached-password lists (e.g., in SP 800-63B, section 5.1.1.2). The described policy — 8-character minimum plus blocklist of common/breached passwords — mirrors NIST's guidance almost verbatim.

Exam trap

The trap here is confusing governance/management frameworks (COBIT, ISO 27001) with technical identity guidelines — candidates often pick ISO 27001 because it 'sounds like security policy,' missing that only NIST SP 800-63B prescribes the specific password rules described.

How to eliminate wrong answers

Option A is wrong because COBIT is an IT governance and control framework focused on aligning IT with business objectives, not on specific password composition rules. Option B is wrong because ISO 27001 is an information security management system standard that mandates a policy framework but does not prescribe exact password length or breach-list screening. Option D is wrong because PCI DSS focuses on protecting cardholder data and specifies requirements like password complexity and length (Req 8), but does not specifically mandate screening against breach databases the way NIST SP 800-63B does.

173
MCQmedium

An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?

A.18 months retention, 6 months immediately available
B.12 months retention, 3 months immediately available
C.6 months retention, 1 month immediately available
D.24 months retention, 12 months immediately available
AnswerB

PCI DSS requires audit logs to be retained for at least 12 months, with the most recent three months immediately available for analysis. This satisfies both the retention and availability constraints stated in the scenario.

Why this answer

PCI DSS Requirement 10.7 mandates retaining audit logs for at least 12 months, with a minimum of the most recent 3 months immediately available for analysis. This ensures organizations can investigate recent incidents quickly while still having historical data for forensic and compliance reviews.

Exam trap

CC often tests the exact PCI DSS retention numbers — candidates confuse the 12-month total retention with the 3-month immediate availability requirement, or pick a larger number thinking 'more is safer.'

How to eliminate wrong answers

Option A is wrong because 18 months retention with 6 months immediately available exceeds the PCI DSS minimum and is not the specified requirement. Option C is wrong because 6 months retention with 1 month available is below the PCI DSS minimum. Option D is wrong because 24 months retention with 12 months available is a stricter internal policy, not the PCI DSS baseline.

174
MCQeasy

A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:

A.Application proxy
B.Stateless firewall
C.Stateful firewall
D.Next-generation firewall
AnswerB

A stateless firewall inspects each packet in isolation against static rules for source and destination IP addresses and ports, maintaining no connection table. This directly satisfies the stem's constraint of filtering without considering connection state, unlike stateful firewalls that track sessions via a state table.

Why this answer

A stateless firewall inspects each packet in isolation, matching only on source/destination IP addresses and ports (Layer 3/4 headers) without maintaining any connection state table. Because it does not track TCP handshakes or session context, it cannot distinguish a legitimate return packet from a spoofed one. This is the defining characteristic described in the question.

Exam trap

The trap here is confusing 'stateless' with 'stateful' — candidates see 'filters traffic' and default to the more familiar stateful firewall, missing the key phrase 'without considering the state of connections.'

How to eliminate wrong answers

Option A is wrong because an application proxy operates at Layer 7, terminating and re-originating connections to inspect application payloads, which is the opposite of simple header-only filtering. Option C is wrong because a stateful firewall maintains a connection state table and evaluates packets against established sessions, which the question explicitly excludes. Option D is wrong because a next-generation firewall adds application identification, user awareness, and threat inspection on top of stateful filtering, far beyond simple IP/port matching.

175
MCQeasy

A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?

A.Multifactor authentication (MFA)
B.Single sign-on (SSO)
C.Federated identity management
D.Role-based access control (RBAC)
AnswerB

SSO lets a user authenticate once to a central identity provider and then access multiple independent applications without re-entering credentials for each one. In this scenario, the marketing firm wants one credential set to reach email, CRM, and file services, which is exactly the problem SSO solves through token or assertion exchange between the identity provider and each relying application.

Why this answer

The firm's goal is one credential set that unlocks several independent applications, which is the defining purpose of single sign-on. SSO relies on a central identity provider that authenticates the user once and then issues assertions or tokens to each connected application, removing repeated password prompts while still allowing each application to make its own authorization decisions.

Exam trap

The trap here is confusing a login-convenience technology with an authorization model, so candidates pick role-based access control when the scenario is really about reducing the number of authentication events.

176
MCQeasy

An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?

A.VLAN segmentation with ACLs
B.Intrusion Detection System (IDS)
C.Proxy server
D.Honeypot
AnswerA

VLANs logically separate the accounting, HR and engineering segments at layer 2, and ACLs on the router or switch filter inter-VLAN traffic, permitting only authorised flows. This satisfies the constraint of blocking unauthorised traffic between segments while allowing necessary communication, which flat subnetting cannot achieve.

Why this answer

VLAN segmentation with ACLs is the correct choice because VLANs create separate broadcast domains at Layer 2, isolating traffic between network segments (accounting, HR, engineering). ACLs applied to the Layer 3 interface (SVI) or trunk ports then enforce granular rules to permit only necessary inter-VLAN communication, such as allowing HR to access a shared server while blocking all other cross-segment traffic.

Exam trap

ISC2 often tests the distinction between passive detection (IDS) and active prevention (firewall/ACL), so candidates mistakenly choose IDS thinking it blocks traffic, but it only alerts.

How to eliminate wrong answers

Option B (Intrusion Detection System) is wrong because an IDS is a passive monitoring tool that detects and alerts on malicious activity but does not actively block or prevent unauthorized traffic between segments. Option C (Proxy server) is wrong because a proxy operates at Layer 7 (application layer) to mediate client-server requests, not to enforce Layer 2/3 segmentation or access control between network segments. Option D (Honeypot) is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not a control to prevent unauthorized inter-segment traffic.

177
MCQmedium

A security administrator is concerned about MAC address spoofing on the network. Which technology can help mitigate this risk by associating a specific MAC address with a port?

A.Port security
B.Dynamic ARP inspection
C.DHCP snooping
D.VLAN hopping prevention
AnswerA

Port security binds specific MAC addresses to individual switch ports, so frames arriving with a spoofed source MAC from an unauthorised device trigger a violation action such as shutdown or restrict. This directly satisfies the requirement to associate a MAC address with a port.

Why this answer

Port security is the correct answer because it directly mitigates MAC address spoofing by allowing an administrator to statically or dynamically associate a specific MAC address with a switch port. When a device with a different MAC address attempts to use that port, port security can either disable the port (errdisable) or drop the traffic, preventing unauthorized access. This is a Layer 2 security feature that enforces MAC-to-port binding.

Exam trap

ISC2 often tests the distinction between features that prevent MAC spoofing (port security) versus features that prevent ARP spoofing (DAI) or DHCP attacks (DHCP snooping), leading candidates to confuse the purpose of each technology.

How to eliminate wrong answers

Option B (Dynamic ARP inspection) is wrong because it validates ARP packets based on DHCP snooping bindings to prevent ARP spoofing, not MAC address spoofing on a port. Option C (DHCP snooping) is wrong because it filters DHCP messages to prevent rogue DHCP servers and builds a binding table, but it does not directly associate a MAC address with a specific switch port. Option D (VLAN hopping prevention) is wrong because it protects against attacks that allow a device to jump to a different VLAN (e.g., via DTP or double tagging), not against MAC address spoofing on a single port.

178
MCQmedium

A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?

A.Block malicious traffic in real time.
B.Detect and alert on potential security incidents.
C.Encrypt sensitive data at rest.
D.Prevent unauthorized access to the network.
AnswerB

An IDS passively inspects mirrored traffic and generates alerts on suspicious patterns, satisfying the detection requirement without sitting inline. It identifies and notifies; it does not block, which distinguishes it from an IPS. Prevention and quarantine fall outside its primary purpose.

Why this answer

An intrusion detection system (IDS) is a passive monitoring technology that analyzes network traffic or system activity for signs of malicious behavior or policy violations. Unlike an intrusion prevention system (IPS), an IDS does not take inline action to block traffic; its primary purpose is to detect suspicious activity and generate alerts for security personnel to investigate and respond.

Exam trap

ISC2 often tests the distinction between IDS and IPS, where candidates mistakenly assume an IDS can block traffic because they conflate detection with prevention.

How to eliminate wrong answers

Option A is wrong because blocking malicious traffic in real time is the function of an intrusion prevention system (IPS), not an IDS; an IDS operates out-of-band and cannot actively block traffic. Option C is wrong because encrypting sensitive data at rest is a data protection mechanism typically handled by encryption tools, file-level encryption, or full-disk encryption, not by an IDS. Option D is wrong because preventing unauthorized access to the network is the role of firewalls, access control lists (ACLs), or authentication systems, whereas an IDS only monitors and alerts on potential threats without enforcing access controls.

179
Multi-Selecthard

An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)

Select 3 answers
A.Background checks for all visitors
B.Issuance of temporary visitor badges
C.Visitor sign-in with host notification
D.Escort policy requiring visitors to be accompanied
E.Biometric authentication for visitors
AnswersB, C, D

Temporary visitor badges give each visitor a visible, time-bound credential that distinguishes them from staff and supports accountability. This satisfies the visitor management policy's need to identify and track non-employees on site, complementing sign-in and escort controls.

Why this answer

Option B (issuance of temporary visitor badges) is correct because a visitor management policy must provide a means of visually identifying non-employees, and temporary badges with expiration dates or distinct colors let staff distinguish visitors from employees and enforce access limits. Option C (visitor sign-in with host notification) is correct because logging each visitor's identity, time of entry, and purpose, then alerting the internal host, creates an audit trail and ensures visitors are expected and accounted for. Option D (escort policy requiring visitors to be accompanied) is correct because requiring visitors to remain with an authorized employee prevents unescorted access to sensitive areas and is a standard physical security control.

Option A is not appropriate because background checks for all visitors are disproportionate and operationally impractical for routine guests such as delivery personnel or interview candidates. Option E is not appropriate because biometric authentication for visitors is costly, raises privacy and consent concerns, and is unnecessary when badges, sign-in, and escorts already provide adequate control.

Exam trap

The trap is over-engineering the policy — candidates select background checks or biometrics because they sound 'more secure,' but the exam expects proportionate, standard visitor controls: badges, sign-in, and escorts.

180
MCQhard

An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?

A.The tape backup
B.The local NAS backup
C.The cloud backup
D.A new full backup from production data
AnswerC

The 3-2-1 strategy keeps one copy offsite and offline from the primary environment. Since both the local NAS and the offsite tape library were encrypted, only the cloud copy remains intact and uninfected, so recovery must draw from that isolated third copy.

Why this answer

The cloud backup is the only copy that was not compromised by the ransomware attack, since both the local NAS and the offsite tape library were encrypted. In a 3-2-1 strategy, the offsite copy is specifically intended to survive local disasters, but here the attacker reached both on-premises copies. The cloud copy, being isolated and typically immutable or versioned, is the correct recovery source.

Exam trap

The trap is assuming that the offsite tape copy is automatically safe — the question explicitly states it was encrypted, testing whether you read the scenario carefully rather than applying the 3-2-1 rule blindly.

How to eliminate wrong answers

Option A is wrong because the tape library was explicitly encrypted by the ransomware, so the tape backup is compromised and cannot be trusted for recovery. Option B is wrong because the local NAS was also encrypted and is therefore unusable. Option D is wrong because generating a new full backup from production data would capture the ransomware-encrypted or corrupted state, and production data may itself be compromised — this is a classic mistake that reintroduces the threat.

181
MCQmedium

A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?

A.Detection
B.Recovery
C.Eradication
D.Containment
AnswerD

Filtering malicious source IPs at the perimeter firewall blocks the attack's traffic, limiting its scope and impact while remediation continues. This matches containment, which stops the spread rather than eradicating the root cause or restoring normal operations.

Why this answer

Containment involves limiting the scope and impact of an incident — in this case, implementing firewall filtering rules to block attack source IPs and prevent further damage while the team investigates. This phase focuses on stopping the spread and isolating affected systems, which matches the described action. Eradication would involve removing the root cause (e.g., patching vulnerabilities), and recovery would restore normal operations.

Exam trap

CC often tests the boundaries between containment and eradication, and candidates pick eradication because blocking IPs feels like 'fixing' the problem, when in fact it is a temporary containment measure that does not remove the root cause.

How to eliminate wrong answers

Option A is wrong because detection is the phase where the incident is identified and analyzed — the team has already identified the attack and source IPs, so detection is complete. Option B is wrong because recovery involves restoring systems and services to normal operation after the threat is eliminated, which has not yet occurred. Option C is wrong because eradication is the phase where the root cause is removed, such as patching a vulnerability or deleting malware — blocking IPs is a temporary containment measure, not a permanent fix.

182
MCQhard

An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?

A.Neither the RTO nor RPO was met.
B.The RPO was met, but the RTO was not.
C.Both the RTO and RPO were met.
D.The RTO was met, but the RPO was not.
AnswerD

Recovery completed in 3 hours, inside the 4-hour RTO, so the availability target was satisfied. However, the restored data was 2 hours old, exceeding the 1-hour RPO, meaning up to an hour of transactions was lost.

Why this answer

The RTO of 4 hours was met because the system became operational in 3 hours, which is within the 4-hour target. However, the RPO of 1 hour was not met because the restored data was 2 hours old, meaning up to 2 hours of data was lost, exceeding the 1-hour maximum tolerable data loss. Therefore, the RTO was met but the RPO was not.

Exam trap

The trap is confusing RTO and RPO — candidates often swap the definitions or assume that meeting one metric implies meeting the other, when they measure entirely different things (downtime vs. data loss).

How to eliminate wrong answers

Option A is wrong because the RTO was clearly met (3 hours < 4 hours), so claiming neither was met is incorrect. Option B is wrong because it reverses the metrics — the RPO was violated (2 hours > 1 hour) and the RTO was satisfied, not the other way around. Option C is wrong because the RPO was exceeded (2-hour-old data vs. 1-hour RPO), so both were not met.

183
MCQmedium

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

A.Subnet
B.Honeypot
C.VLAN
D.DMZ
AnswerD

A DMZ is a screened subnet placed between the internet and the internal LAN. It hosts internet-facing services such as the public web server while firewall rules restrict traffic from the DMZ into the internal network, providing the required isolation.

Why this answer

A DMZ (demilitarized zone) is a network segment that sits between the internet and the internal LAN, hosting public-facing services while isolating them from internal resources. It is accessible from the internet but separated from the internal network by firewalls, exactly as described. This architecture limits the blast radius if a public server is compromised.

Exam trap

The trap is selecting 'subnet' or 'VLAN' because they describe network segmentation — candidates must recognize that the question describes a security architecture (DMZ), not just a logical grouping.

How to eliminate wrong answers

Option A is wrong because a subnet is simply a logical subdivision of an IP network for addressing and routing — it does not imply any security isolation or internet-facing role. Option B is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not a segment hosting legitimate public services. Option C is wrong because a VLAN is a Layer 2 broadcast domain segmentation technique; while VLANs may be used within a DMZ, a VLAN alone does not provide the internet-facing isolation described.

184
MCQeasy

A hospital's biomedical team connects a new MRI workstation to the clinical VLAN. The workstation must reach a PACS archive on a different subnet, but the team reports that no traffic leaves the workstation. A technician confirms the workstation has an IP address of 10.20.30.44/24 and the PACS archive is 10.20.40.10/24. Which device should the workstation be configured to use as its default gateway?

A.A router interface on the 10.20.30.0/24 subnet
B.The PACS archive server itself at 10.20.40.10
C.The DNS server address assigned by DHCP
D.A Layer 2 switch's management IP address on the 10.20.30.0/24 subnet
AnswerA

A default gateway must be an address on the same local subnet as the sending host, so the workstation can ARP for it and hand off off-subnet traffic. A router interface in 10.20.30.0/24 satisfies this, and the router then forwards the packet to the 10.20.40.0/24 network. Pointing to any device outside the local subnet would leave the workstation unable to deliver the frame.

Why this answer

The workstation needs a next-hop address inside its own subnet so it can ARP for that device and hand off traffic destined for 10.20.40.0/24. Only a router interface on 10.20.30.0/24 provides a reachable Layer 2 next hop that can also route to the PACS subnet. The other candidates either sit outside the local subnet or cannot perform IP routing.

Exam trap

The trap here is assuming any reachable IP address can serve as a default gateway, when the gateway must be on the same local subnet as the sending host.

185
MCQeasy

An organization implements an access control system where users are assigned to groups, and permissions are granted to groups rather than individuals. This is known as:

A.Mandatory Access Control (MAC)
B.Role-Based Access Control (RBAC)
C.Discretionary Access Control (DAC)
D.Attribute-Based Access Control (ABAC)
AnswerB

Role-Based Access Control grants permissions to roles or groups rather than to individual users, so members inherit access through their group membership. This directly satisfies the stem's constraint that permissions are assigned to groups, not individuals, centralising administration and simplifying revocation when users change roles within the organization.

Why this answer

Role-Based Access Control (RBAC) assigns permissions to roles (or groups) rather than to individual users. Users are then made members of these roles, inheriting the permissions associated with the role. This matches the description in the question, where users are assigned to groups and permissions are granted to those groups.

Exam trap

ISC2 often tests the distinction between RBAC and ABAC by describing group-based assignment (RBAC) versus policy-based evaluation of multiple attributes (ABAC), leading candidates to confuse the two when the question mentions 'attributes' or 'policies'.

How to eliminate wrong answers

Option A is wrong because Mandatory Access Control (MAC) enforces access based on system-wide security labels (e.g., classification levels) and is not based on user group membership. Option C is wrong because Discretionary Access Control (DAC) allows individual resource owners to set permissions on their objects, typically using Access Control Lists (ACLs), not by assigning users to groups with predefined permissions. Option D is wrong because Attribute-Based Access Control (ABAC) evaluates policies based on multiple attributes (user, resource, environment) at the time of access, not on static group membership.

186
MCQhard

A financial services firm has a recovery time objective (RTO) of 2 hours for its trading platform and a recovery point objective (RPO) of 15 minutes. The disaster recovery team is evaluating whether a warm site can meet these requirements. Which statement best describes the limitation of a warm site in this scenario?

A.A warm site cannot meet the RPO because it does not support data replication from the primary site.
B.A warm site can meet the RTO because it only requires switching network routes to the standby environment.
C.A warm site is identical to a hot site and can meet both the RTO and RPO without any additional configuration.
D.A warm site cannot meet the RTO because it requires manual data restoration and configuration, which typically takes longer than 2 hours.
AnswerD

A warm site has hardware and connectivity pre-installed but lacks live data and may need manual restoration and configuration. For a trading platform with a 2-hour RTO, the time to restore data, apply configurations, and validate systems often exceeds that window. This makes a warm site unsuitable unless extensive automation and replicated data are added, which would effectively turn it into a hot site.

Why this answer

A warm site provides pre-installed hardware and network connectivity but requires data restoration and system configuration before it can operate. For a trading platform with a 2-hour RTO, this manual effort typically exceeds the acceptable outage window. While the 15-minute RPO could be addressed with replication, the RTO is the binding constraint that makes a warm site a poor fit without substantial automation.

Exam trap

The trap here is focusing on the RPO and assuming replication alone makes a warm site adequate, when the 2-hour RTO is the more demanding constraint that a warm site usually cannot satisfy.

187
MCQmedium

Which of the following is an example of a vulnerability?

A.An unlocked server room door
B.A malicious hacker attempting to gain access
C.A firewall blocking unauthorized traffic
D.The risk of data loss
AnswerA

A vulnerability is a weakness that could be exploited; an unlocked server room door is a physical weakness allowing unauthorised access to hardware. It is not a threat (an actor or event) nor a risk (likelihood combined with impact), so it fits the stem's request for a vulnerability example.

Why this answer

A vulnerability is a weakness or flaw that can be exploited by a threat. An unlocked server room door is a physical security weakness that could allow unauthorized access, making it a classic example of a vulnerability. The other options describe threats, controls, or risks, not vulnerabilities.

Exam trap

The trap is confusing vulnerabilities with threats or risks; candidates often pick 'a malicious hacker' as a vulnerability, but that is a threat actor, while the unlocked door is the actual weakness.

How to eliminate wrong answers

Option B is wrong because a malicious hacker is a threat actor, not a vulnerability; the vulnerability would be the weakness the hacker exploits. Option C is wrong because a firewall blocking traffic is a security control that mitigates risk, not a vulnerability. Option D is wrong because the risk of data loss is a potential outcome or risk, not the underlying weakness itself.

188
MCQhard

During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?

A.Insufficient off-site storage
B.Single point of failure
C.Lack of redundancy
D.Inadequate segregation of duties
AnswerA

Storing tapes in the same building as the servers creates a single point of failure: any incident destroying the site, such as fire or flood, would destroy both production data and its backups. This directly violates the off-site storage requirement, since no geographically separate copy survives to enable recovery.

Why this answer

Storing backup tapes in the same building as the primary servers violates the fundamental principle of geographic separation for disaster recovery. If a fire, flood, or physical security breach destroys the building, both the primary data and the backup tapes are lost simultaneously, rendering the backups useless. This directly indicates a lack of off-site storage, which is a core requirement for a viable backup strategy.

Exam trap

ISC2 often tests the distinction between 'lack of redundancy' (duplicate hardware) and 'insufficient off-site storage' (geographic separation of backups), trapping candidates who confuse high-availability concepts with disaster recovery requirements.

How to eliminate wrong answers

Option B is wrong because 'single point of failure' typically refers to a component (like a power supply or network link) whose failure stops the entire system, not to the physical co-location of backups. Option C is wrong because 'lack of redundancy' implies missing duplicate components (e.g., a second server or disk array), whereas the issue here is the absence of geographic separation for existing backups. Option D is wrong because 'inadequate segregation of duties' is a security control related to separating administrative roles (e.g., backup operator vs. system admin), not a physical storage location problem.

189
MCQeasy

An employee reports receiving a suspicious email with an attachment from an unknown sender. What is the first action the employee should take?

A.Open the attachment to check its content.
B.Report the email to the security team.
C.Forward the email to all employees as a warning.
D.Delete the email immediately.
AnswerB

Reporting to the security team lets specialists analyse the message, quarantine it and check other recipients, while preserving evidence. Deleting or opening the attachment risks execution and loses indicators, so reporting is the safe first action.

Why this answer

Reporting the email to the security team allows professionals to analyze and respond appropriately. Deleting the email or opening the attachment can be dangerous; forwarding may spread the threat.

190
Multi-Selecthard

A security manager is mapping several controls to the categories of administrative, technical, and physical. Which TWO of the following are administrative controls? (Choose two.)

Select 2 answers
A.An acceptable use policy that employees must read and sign
B.A firewall rule set that blocks inbound traffic on unused ports
C.A biometric fingerprint reader controlling the data center door
D.A security awareness training program delivered each quarter
E.A bollard installed at the entrance to the loading dock
AnswersA, D

An acceptable use policy is a management directive that defines how employees may use organizational assets, and it is enforced through acknowledgment and disciplinary process. It governs behavior through rules rather than through hardware or software, which places it squarely in the administrative category. Signing the policy also establishes awareness and accountability, reinforcing its administrative nature within the security program.

Why this answer

Administrative controls govern people and processes through rules, policies, and training. The acceptable use policy and the recurring security awareness training both shape behavior through management action rather than through hardware or software. The bollard is a physical barrier, while the biometric reader and firewall enforce access through technology, so those three fall into the physical and technical categories instead.

Exam trap

The trap here is assuming that any control which expresses a management decision, such as a firewall rule, must itself be classified as administrative.

191
MCQhard

An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?

A.DMZ
B.Honeypot
C.Subnetting
D.VLAN
AnswerD

VLANs logically partition one physical switch into isolated Layer 2 broadcast domains, so broadcasts stay within each segment rather than flooding every port. This directly satisfies the stem's requirement for separate broadcast domains on a single switch, unlike subnetting (Layer 3) or physical segmentation, which would need additional hardware.

Why this answer

A VLAN (Virtual Local Area Network) logically partitions a single physical switch into multiple separate broadcast domains. Each VLAN operates as its own Layer 2 network, and broadcast traffic from one VLAN is not forwarded to another without a Layer 3 device. This is the standard technology for network segmentation at Layer 2.

Exam trap

The trap here is confusing Layer 2 segmentation (VLAN) with Layer 3 segmentation (subnetting) — candidates often pick 'Subnetting' because both provide logical separation, but only VLANs create separate broadcast domains on a single switch.

How to eliminate wrong answers

Option A is wrong because a DMZ (Demilitarized Zone) is a perimeter network segment that exposes external-facing services to an untrusted network — it is a security architecture concept, not a Layer 2 segmentation technology on a single switch. Option B is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not a broadcast domain segmentation mechanism. Option C is wrong because subnetting is a Layer 3 (IP) concept that divides an IP network into smaller subnets — while it can align with VLANs, it does not create separate broadcast domains on a switch by itself.

192
MCQeasy

Refer to the exhibit. Based on the exhibit, why was the packet denied?

A.Source IP is internal
B.The packet was blocked by an outbound access list
C.Destination IP is external
D.The packet was blocked by an inbound access list
AnswerD

The message specifies 'due to access-group INTERNET_IN', which is applied inbound.

Why this answer

The exhibit shows an inbound access list applied to the interface, and the packet is denied because its source IP matches a deny entry in that inbound ACL. Inbound access lists filter traffic before it is processed by the router, so the packet is dropped upon arrival. The correct answer is D because the packet was blocked by an inbound access list, as indicated by the ACL configuration and the deny action.

Exam trap

ISC2 often tests the distinction between inbound and outbound ACLs, and the trap here is that candidates may confuse the direction of the ACL application (inbound vs. outbound) or assume that a packet is denied because of the source or destination IP alone, rather than focusing on the ACL rule that explicitly denies the traffic.

How to eliminate wrong answers

Option A is wrong because the source IP being internal is not a reason for denial; ACLs filter based on configured rules, not the mere fact that an IP is internal. Option B is wrong because the packet was blocked by an inbound access list, not an outbound one; outbound ACLs filter traffic leaving the interface, but the exhibit shows the ACL is applied inbound. Option C is wrong because the destination IP being external is irrelevant; ACLs can permit or deny traffic regardless of destination being internal or external, and the denial is due to the ACL rule, not the destination's location.

193
Multi-Selectmedium

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Select 2 answers
A.Load balancing
B.Encryption
C.Digital signatures
D.Hashing
E.Redundant servers
AnswersC, D

Digital signatures verify that database records or transactions have not been altered after signing, directly satisfying the integrity requirement. Any modification invalidates the signature, providing cryptographic tamper detection rather than mere access control. This mechanism detects unauthorised changes, unlike confidentiality or availability controls.

Why this answer

Digital signatures (C) are correct because they provide integrity and authenticity by allowing the recipient to verify that the data has not been altered and that it originated from a trusted source, using asymmetric cryptography to sign and verify a hash of the data. Hashing (D) is correct because it produces a fixed-length digest of the database contents, so any modification to the data changes the hash value, enabling detection of unauthorized or accidental changes and thereby protecting integrity. Encryption (B) primarily provides confidentiality, not integrity, since ciphertext can still be modified without detection unless combined with a MAC or signature.

Load balancing (A) and redundant servers (E) improve availability and performance through distribution and failover, but they do not detect or prevent unauthorized data modification, so they do not directly protect integrity.

Exam trap

The trap is that encryption is often assumed to cover integrity, but the exam expects candidates to distinguish confidentiality (encryption) from integrity (hashing and digital signatures) — picking encryption here is the classic CIA-triple confusion.

194
MCQhard

A financial firm has a data center with strict access controls. Employees must use smart cards and PINs to enter a mantrapped entrance. Recently, an unauthorized person gained access by following an employee through the mantrapped door (tailgating). The security team reviews logs and finds that the door was opened twice in quick succession, indicating tailgating occurred. The firm wants to implement a solution that prevents tailgating without slowing down authorized access. Which action should they take?

A.Require employees to log access requests in advance
B.Install a biometric scanner that requires fingerprint and retina scan
C.Implement a turnstile that allows only one person per smart card authentication
D.Increase the number of security guards at the entrance
AnswerC

A turnstile physically enforces single-person entry per smart card authentication, eliminating the tailgating window that mantrap logs merely detect. It satisfies the requirement to prevent unauthorised entry without impeding authorised staff, since each valid authentication admits exactly one person.

Why this answer

A turnstile physically enforces one-person-per-authentication by rotating only after a valid smart card read and allowing a single passage, then locking until the next authentication. This directly prevents tailgating without adding delay, as each authorized user passes through at their own pace without needing additional steps like biometric scans or pre-approval.

Exam trap

ISC2 often tests the distinction between detection (e.g., logs, cameras) and prevention (e.g., turnstiles, mantrap doors), so candidates mistakenly choose biometric or procedural options that only detect or deter rather than physically block tailgating.

How to eliminate wrong answers

Option A is wrong because requiring advance access logs does not physically prevent tailgating; it only creates an audit trail after the fact, and the unauthorized person could still follow an employee through the door. Option B is wrong because biometric scanners (fingerprint and retina) add significant authentication time and user friction, slowing down authorized access, and they still do not prevent a second person from slipping through immediately after the first is authenticated. Option D is wrong because increasing security guards is a personnel-based solution that is costly, inconsistent, and still relies on human vigilance to spot tailgating, which can fail during busy periods or distraction.

195
Multi-Selecthard

A security analyst is assessing the risk associated with a new web application. The analyst identifies that the application has a SQL injection vulnerability, and there is a known exploit available that could allow an attacker to extract sensitive data. The application is exposed to the internet and is used by customers. Which two factors are most directly involved in determining the level of risk? (Choose two.)

Select 2 answers
A.The likelihood of the vulnerability being exploited
B.The color scheme of the user interface
C.The number of lines of code in the application
D.The impact if the vulnerability is exploited
E.The programming language used to develop the application
AnswersA, D

Likelihood is a key factor in risk assessment. It estimates the probability that a threat will exploit a vulnerability. Here, the existence of a known exploit and internet exposure increases the likelihood of exploitation. Risk is often calculated as likelihood times impact, so likelihood is directly involved in determining the level of risk.

Why this answer

Risk is typically defined as the combination of the likelihood of a threat exploiting a vulnerability and the impact of that exploitation. In this scenario, the known exploit and internet exposure increase likelihood, while potential sensitive data extraction increases impact. These two factors are directly involved in determining the risk level, making them the correct choices.

Exam trap

The trap here is selecting factors that seem related to vulnerabilities, like programming language, instead of focusing on the core risk components: likelihood and impact.

196
MCQeasy

A SOC analyst reviews an alert indicating a high number of failed login attempts from a single external IP address targeting multiple user accounts. Which security control is most effective at preventing this type of attack?

A.Deploying a web application firewall
B.Enabling verbose logging for authentication events
C.Increasing password complexity requirements
D.Implementing account lockout policies
AnswerD

Account lockout policies limit the number of failed attempts, preventing continued brute-force attacks.

Why this answer

Account lockout policies directly mitigate brute-force attacks by temporarily disabling an account after a defined number of failed login attempts (e.g., 5 failures within 15 minutes). This prevents the attacker from continuing to guess passwords for multiple user accounts from a single external IP, without affecting legitimate users who can be unlocked after a lockout duration or via an administrative reset.

Exam trap

ISC2 often tests the misconception that a WAF (Option A) can stop brute-force attacks, but the trap is that WAFs operate at Layer 7 for web traffic and do not control authentication attempts against native OS or directory service logins.

How to eliminate wrong answers

Option A is wrong because a web application firewall (WAF) inspects HTTP/HTTPS traffic for application-layer attacks (e.g., SQL injection, XSS), not authentication brute-force attempts against a directory service or operating system login. Option B is wrong because enabling verbose logging for authentication events only improves visibility and forensic analysis; it does not prevent the attack from succeeding. Option C is wrong because increasing password complexity requirements makes passwords harder to guess but does not stop an attacker from making unlimited login attempts; brute-force tools can still try millions of complex passwords over time.

197
MCQhard

A company's security policy requires that all incident response activities be logged and that evidence be preserved for potential legal action. During an incident, a responder mistakenly uses a personal USB drive to copy log files. Which principle of forensic evidence handling has been violated?

A.Integrity
B.Chain of custody
C.Availability
D.Confidentiality
AnswerB

Copying evidence to an unlogged personal USB drive breaks the documented, unbroken record of who handled the evidence, when and how. Chain of custody demands every transfer and access be recorded; this undocumented handling makes the logs inadmissible, failing the policy's legal-preservation requirement.

Why this answer

The chain of custody is a documented record that tracks the seizure, control, transfer, analysis, and disposition of evidence. By using a personal USB drive to copy log files, the responder introduces an unverified and uncontrolled storage medium, breaking the documented chain and making it impossible to prove that the evidence was not tampered with or contaminated. This directly violates the requirement to preserve evidence for potential legal action.

Exam trap

ISC2 often tests the distinction between chain of custody and integrity by presenting a scenario where evidence is copied to an unauthorized device, leading candidates to mistakenly choose 'Integrity' because they focus on potential data alteration rather than the lack of documented control over the evidence.

How to eliminate wrong answers

Option A is wrong because integrity refers to the assurance that data has not been altered or destroyed in an unauthorized manner; while using a personal USB drive could potentially affect integrity, the core violation here is the lack of documented control over the evidence, not the alteration of the data itself. Option C is wrong because availability concerns ensuring that data and systems are accessible when needed; the responder was able to copy the log files, so availability was not compromised. Option D is wrong because confidentiality involves preventing unauthorized disclosure of information; although using a personal USB drive might raise confidentiality concerns, the primary forensic principle violated is the broken chain of custody, not the exposure of the data.

198
MCQhard

An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?

A.Organization Unit
B.Object Unit
C.Operating Unit
D.Organizational Unit
AnswerD

In LDAP distinguished names, OU stands for Organizational Unit — a container object used to group directory entries, typically by department or function. Here OU=Sales places John Smith within the Sales organisational unit beneath the company's domain components.

Why this answer

Option D is correct because in LDAP distinguished names, OU stands for 'Organizational Unit'. An OU is a container object within a directory that is used to organize entries such as users, groups, and computers. In the DN 'CN=John Smith,OU=Sales,DC=company,DC=com', the OU=Sales indicates that John Smith resides in the Sales organizational unit within the company.com domain.

Exam trap

The trap here is the subtle wording difference between 'Organizational Unit' (correct) and 'Organization Unit' (incorrect) — candidates who know the concept but not the exact term may pick the wrong option.

How to eliminate wrong answers

Option A is wrong because 'Organization Unit' is not a standard LDAP term; the correct term is 'Organizational Unit'. Option B is wrong because 'Object Unit' is not an LDAP concept — objects are individual entries, not units. Option C is wrong because 'Operating Unit' is a business term, not an LDAP directory component.

199
Multi-Selectmedium

A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)

Select 2 answers
A.Place a sign on the door stating that the area is restricted to authorized personnel only.
B.Disable the door alarm and logging functions to speed up employee entry during peak hours.
C.Require employees to display a visible badge at all times while inside the facility.
D.Install a mantrap that admits one authenticated person at a time between two interlocking doors.
E.Publish the entrance door code on the company intranet so employees can memorize it.
AnswersC, D

Visible badges let staff and security personnel quickly distinguish authorized individuals from visitors or intruders, which reinforces the effectiveness of the entrance control. Badge display supports accountability and makes unauthorized presence easier to challenge. It is a widely accepted physical control that complements authentication at the door without impeding normal employee movement.

Why this answer

Effective physical access control combines preventive enforcement with accountability. A mantrap ensures each entrant authenticates individually, eliminating tailgating, while mandatory visible badges let anyone on site verify that a person is authorized. Together they admit legitimate employees efficiently while making unauthorized entry difficult to conceal, which is exactly what a well-designed entrance control should achieve.

Exam trap

The trap here is accepting signage or convenience shortcuts as equivalent to actual access enforcement mechanisms.

200
MCQeasy

Which of the following is a recommended practice for administrative accounts?

A.Use the same account for daily work and admin tasks
B.Grant admin rights to all users for convenience
C.Use a separate admin account distinct from daily use account
D.Disable all admin accounts to improve security
AnswerC

Separating administrative credentials from daily-use accounts enforces least privilege and limits blast radius: routine browsing, email and phishing exposure cannot compromise privileged access. This directly satisfies the recommended practise of isolating elevated permissions from everyday activity.

Why this answer

Using a separate administrative account distinct from a daily-use account enforces least privilege and separation of duties. If the daily account is compromised via phishing or malware, the attacker does not automatically gain administrative rights. This practice also ensures accountability, as administrative actions are logged under a dedicated identity.

Exam trap

The trap here is the misconception that convenience (using one account) or extreme measures (disabling all admin accounts) are acceptable; the exam expects recognition that separation of duties and least privilege are key.

How to eliminate wrong answers

Option A is wrong because using the same account for daily work and admin tasks violates least privilege and increases the blast radius of a compromise. Option B is wrong because granting admin rights to all users for convenience is a direct violation of least privilege and dramatically increases risk. Option D is wrong because disabling all admin accounts would prevent legitimate administrative tasks and is not a recommended practice; instead, admin accounts should be secured and monitored.

201
Multi-Selecthard

A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)

Select 2 answers
A.Analyzing network flow records for unusual volumes of outbound traffic to external IP addresses
B.Enabling full packet capture and storing all network traffic for later analysis
C.Reviewing DNS query logs for lookups of known malicious domains
D.Monitoring endpoint logs for processes that compress and archive large numbers of files
E.Deploying SSL/TLS inspection to decrypt and examine all outbound web traffic
AnswersA, D

Network flow records, such as NetFlow or IPFIX, provide metadata about connections without payload inspection. Large or anomalous outbound data transfers to external IPs can indicate exfiltration even when traffic is encrypted. This approach is effective because it focuses on behavior and volume rather than content, making it suitable for detecting encrypted exfiltration.

Why this answer

Detecting encrypted exfiltration requires focusing on behavior and metadata rather than payload content. Network flow analysis identifies anomalous outbound volumes, while endpoint monitoring detects staging activities like archiving. Together, they provide complementary visibility without relying on decryption, making them effective for this scenario.

Exam trap

The trap here is assuming that decrypting all traffic is necessary or always feasible, when in fact behavioral and metadata analysis often provide better detection for encrypted exfiltration.

202
MCQeasy

A security operations center (SOC) analyst receives an alert for a potential malware infection on a workstation. Which of the following is the first action the analyst should take?

A.Reimage the workstation
B.Run a full antivirus scan
C.Isolate the workstation from the network to prevent spread
D.Notify law enforcement
AnswerC

Isolation contains the threat before it can spread laterally or exfiltrate data, satisfying the containment-first requirement of incident response. Because the alert is unconfirmed, the analyst must still preserve volatile evidence, so network isolation is preferred over powering off, which would destroy memory-resident artefacts.

Why this answer

When a potential malware infection is detected, the immediate priority is containment to prevent lateral movement and further compromise. Isolating the workstation from the network (e.g., disabling the network interface or disconnecting the cable) stops the malware from communicating with command-and-control servers or spreading to other hosts. This aligns with the NIST incident response framework's containment phase, which precedes eradication and recovery actions.

Exam trap

ISC2 often tests the principle that containment (isolation) must come before eradication (scanning or reimaging), and candidates mistakenly choose a remediation step like running a scan or reimaging as the first action.

How to eliminate wrong answers

Option A is wrong because reimaging the workstation destroys forensic evidence and is a recovery step that should only occur after containment and investigation. Option B is wrong because running a full antivirus scan while the system is still connected to the network may alert the malware, trigger destructive behavior, or allow continued data exfiltration during the scan. Option D is wrong because notifying law enforcement is a post-containment, post-investigation step that is not the first action; it is typically reserved for incidents involving sensitive data or legal requirements, not initial triage.

203
MCQhard

Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?

A.An attacker is performing an SSL stripping attack, downgrading the connection to SSLv3
B.The server is experiencing a buffer overflow attack
C.The server's certificate has expired and the client is falling back to SSLv3
D.The server has been misconfigured to use SSLv3 instead of TLS
AnswerA

The alert signature suggests SSL stripping, and the use of SSLv3 is a red flag.

Why this answer

The alert indicates a downgrade from TLS 1.2 to SSLv3, which is the hallmark of an SSL stripping attack. In this attack, an adversary intercepts the client's TLS handshake request and forces the connection to use the weaker SSLv3 protocol, often by manipulating the ClientHello message to remove TLS options. This allows the attacker to exploit known vulnerabilities in SSLv3, such as POODLE, to decrypt or hijack the session.

Exam trap

ISC2 often tests the distinction between a server-side misconfiguration (which would cause consistent use of SSLv3) and an active downgrade attack (which shows a change from TLS to SSLv3), tricking candidates into choosing the misconfiguration answer when the evidence points to an attack.

How to eliminate wrong answers

Option B is wrong because a buffer overflow attack typically involves sending malformed data to exploit memory corruption, not a protocol version downgrade, and would not generate an alert specifically about SSLv3 usage. Option C is wrong because certificate expiration causes browser warnings or handshake failures, not a fallback to SSLv3; modern clients do not automatically downgrade to SSLv3 due to expired certificates. Option D is wrong because if the server were misconfigured to use SSLv3, it would consistently use that protocol, not suddenly switch from TLS 1.2 to SSLv3, and the alert would not indicate a downgrade event.

204
MCQmedium

According to NIST SP 800-63, which password policy is recommended to enhance security?

A.Allow passwords as short as 4 characters
B.Enforce maximum complexity with special characters and numbers
C.Require frequent password changes every 30 days
D.Favor length over complexity and check against breached password lists
AnswerD

NIST SP 800-63 favours password length over composition rules, since complexity encourages predictable patterns and reuse. Breached-list screening blocks credentials already exposed in leaks, directly satisfying the guidance's requirement to reject compromised secrets rather than merely enforcing character classes.

Why this answer

NIST SP 800-63B recommends favoring password length over complexity and screening new passwords against lists of commonly used and breached passwords. Length increases entropy far more effectively than forcing special characters, and breach-list checks block credentials attackers already possess. The same guidance also discourages forced periodic rotation absent evidence of compromise.

Exam trap

The trap is the legacy mindset that 'more complexity and frequent rotation equals more secure' — candidates raised on old policy templates pick complexity or 30-day rotation, missing NIST's modern length-and-breach-check stance.

How to eliminate wrong answers

Option A is wrong because allowing 4-character passwords is far below NIST's recommended minimum of 8 characters (with 15 recommended for memorized secrets in some contexts) and drastically reduces the search space. Option B is wrong because NIST explicitly moved away from mandatory composition rules (mixed case, digits, symbols), which push users toward predictable patterns like 'Password1!' and increase help-desk burden. Option C is wrong because NIST no longer recommends arbitrary periodic expiration (e.g., every 30 days); frequent changes degrade password quality and are only warranted when compromise is suspected.

205
Multi-Selecthard

A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?

Select 2 answers
A.Large number of failed login attempts
B.Frequent DNS queries to known malicious domains
C.Unexpected large file transfers via FTP
D.Multiple antivirus alerts
E.Unusual outbound traffic to a foreign IP
AnswersC, E

Exfiltration requires outbound data movement, and unusually large FTP transfers to external or unfamiliar hosts indicate bulk data leaving the network. This volume and direction anomaly distinguishes exfiltration from routine inbound traffic or normal file access, directly satisfying the stem's requirement for a likely sign of data exfiltration.

Why this answer

Option C is correct because unexpected large file transfers via FTP are a classic exfiltration indicator: FTP (ports 20/21) is a cleartext file-transfer protocol, and a sudden, high-volume upload to an external server strongly suggests data being moved out of the environment. Option E is correct because unusual outbound traffic to a foreign IP indicates beaconing or bulk data transfer to an external command-and-control or staging host, which is a hallmark of exfiltration, especially when the destination is atypical for the organization. Option A is not correct because a large number of failed login attempts indicates brute-force or password-spraying activity against authentication, which is an intrusion attempt rather than evidence of data leaving the network.

Option B is not correct because frequent DNS queries to known malicious domains point to malware beaconing, command-and-control communication, or domain generation algorithm activity, which is a precursor or concurrent compromise indicator, not exfiltration itself. Option D is not correct because multiple antivirus alerts indicate malware detection or endpoint compromise, which may precede exfiltration but does not by itself demonstrate that data was transferred out.

Exam trap

ISC2 often tests the distinction between indicators of compromise (IOCs) for different attack phases—candidates confuse C2 beaconing (DNS queries) with data exfiltration (large file transfers), or mistake authentication failures for exfiltration activity.

206
MCQmedium

A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?

A.Federated identity
B.Single sign-on
C.Single-factor authentication
D.Multi-factor authentication
AnswerD

Multi-factor authentication requires two or more different factor types, such as something you know and something you have. A password is knowledge, and a code sent to a registered phone is possession of that device. Combining them satisfies the definition, so this proposal correctly illustrates multi-factor authentication.

Why this answer

Multi-factor authentication combines factors from different categories, such as something you know and something you have. The password represents knowledge, while the code sent to a registered mobile phone represents possession of that device. This pairing raises the difficulty for an attacker who steals only the password, so the proposal is best described as multi-factor authentication.

Exam trap

The trap here is assuming any two-step login is multi-factor, but two passwords or two codes from the same factor category would still be single-factor.

207
MCQmedium

A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?

A.DNS logs.
B.Authentication logs.
C.Firewall logs.
D.Application logs.
AnswerB

Authentication logs record repeated failed logon attempts against accounts, revealing the volume and source pattern characteristic of brute-force activity. This satisfies the stem's requirement for the most critical data source for detecting an ongoing brute-force attack.

Why this answer

Authentication logs record successful and failed login attempts, which are directly indicative of brute-force attacks. Other logs may provide supporting information but are not as directly tied to the attack.

208
MCQmedium

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

A.Isolate affected systems
B.Pay the ransom
C.Run antivirus scans
D.Report to law enforcement
AnswerA

Isolating affected systems immediately contains the ransomware, preventing lateral spread to file shares and other hosts while forensic evidence is preserved. Containment precedes eradication and recovery, satisfying the stem's requirement for the first incident response step: stopping active encryption before it reaches further assets.

Why this answer

Isolating affected systems is the correct first step because containment stops the ransomware from spreading laterally to other hosts and encrypting additional data, preserving evidence and limiting blast radius. In standard incident response frameworks such as NIST SP 800-61, containment immediately follows detection and precedes eradication, recovery, and any external reporting.

Exam trap

The trap is choosing 'run antivirus scans' because it feels like an immediate technical fix, but the exam tests the NIST ordering where containment must precede eradication to prevent further spread.

How to eliminate wrong answers

Option B is wrong because paying the ransom is never a recommended response step, does not guarantee decryption, funds criminal activity, and may violate sanctions or regulatory guidance. Option C is wrong because running antivirus scans before containment allows the malware to continue spreading and may alter or destroy forensic evidence. Option D is wrong because reporting to law enforcement is important but occurs after containment and internal escalation, not as the immediate first technical action.

209
Multi-Selectmedium

An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?

Select 2 answers
A.Recognizing phishing emails
B.Awareness of tailgating and piggybacking
C.Understanding encryption algorithms
D.Configuring firewall rules
E.Proper password management using a password manager
AnswersA, B

Phishing recognition teaches staff to spot fraudulent emails, the most common social-engineering vector, satisfying the stem's requirement to address common attacks. It covers spoofed senders, urgent lures, and malicious links, reducing credential theft and payload execution.

Why this answer

Option A (Recognizing phishing emails) is correct because phishing is one of the most common social engineering attacks, and training users to identify suspicious senders, spoofed domains, urgent language, and malicious links or attachments directly reduces the risk of credential theft and malware infection. Option B (Awareness of tailgating and piggybacking) is correct because these are physical social engineering techniques in which an attacker follows an authorized person into a restricted area, so awareness training helps employees enforce badge checks and challenge unknown individuals. Option C is not a social engineering topic; understanding encryption algorithms is a technical cryptographic concept rather than a human-focused attack vector.

Option D is also technical rather than social engineering, since configuring firewall rules is an administrative network security task performed by IT staff. Option E, while valuable for overall security, addresses credential hygiene rather than the manipulation tactics that define social engineering attacks.

Exam trap

The trap is selecting technical topics (encryption, firewall rules) because they sound security-related, but the question specifically asks for social engineering topics—candidates must distinguish between technical controls and human-focused awareness.

210
Multi-Selecthard

Which THREE of the following are examples of implementing defense in depth? (Select THREE.)

Select 3 answers
A.Enabling single sign-on for all applications
B.Using a firewall to filter traffic
C.Allowing all traffic by default
D.Implementing access control lists
E.Encrypting data at rest
AnswersB, D, E

A firewall enforces perimeter filtering of inbound and outbound traffic, forming one independent layer within a defence-in-depth strategy. It satisfies the layered-controls requirement by blocking unauthorised network access before it reaches internal hosts, complementing host, application and data safeguards rather than replacing them.

Why this answer

Defense in depth layers multiple independent security controls so that no single failure exposes the whole system. Option B is correct because a firewall filtering traffic enforces a network-perimeter control, inspecting and permitting or denying packets based on rules, which is a classic layered defense. Option D is correct because access control lists (ACLs) restrict which subjects can reach specific resources, adding an authorization layer that limits lateral movement even if perimeter defenses are bypassed.

Option E is correct because encrypting data at rest protects confidentiality of stored data, so a breach of storage media or a database does not automatically expose plaintext, forming a data-level control. Option A does not belong: single sign-on centralizes authentication and can actually concentrate risk rather than add a defensive layer. Option C does not belong: allowing all traffic by default is a permissive posture that removes filtering, the opposite of defense in depth.

Exam trap

ISC2 often tests the concept that defense in depth requires multiple independent layers of security, so candidates mistakenly select options that improve convenience (like SSO) or violate security principles (like allowing all traffic) instead of recognizing that each correct option adds a distinct security control at a different layer.

211
MCQeasy

A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerD

Separation of duties splits a critical task across multiple identities so no single person controls it end to end. Requiring two distinct managers to approve each financial transaction enforces this by preventing one individual from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.

Why this answer

Separation of duties (SoD) requires that critical tasks be divided among multiple people so that no single individual can complete a sensitive transaction alone. Requiring two managers to approve financial transactions is the textbook example: it prevents fraud and errors by ensuring collusion is needed to bypass the control. SoD is a foundational principle in ISC2's access control domain.

Exam trap

The trap is confusing separation of duties with least privilege — both limit what a user can do, but SoD specifically requires multiple people to complete a task, while least privilege limits the scope of a single user's access.

How to eliminate wrong answers

Option A is wrong because need-to-know restricts access to information based on job requirements, not on splitting approval authority across people. Option B is wrong because defense in depth is the layering of multiple controls (physical, technical, administrative) so that no single failure compromises security — it is a strategy, not a specific approval rule. Option C is wrong because least privilege grants users only the minimum access needed to perform their jobs; it limits permissions but does not require two-person approval.

212
MCQhard

A security engineer is reviewing logs and notices that an internal server is receiving excessive SYN packets from an external IP, but never completing the three-way handshake. What type of attack is likely occurring?

A.Smurf attack
B.Ping of death
C.ARP poisoning
D.SYN flood
AnswerD

A SYN flood sends numerous TCP SYN packets, often spoofed, without completing the three-way handshake, exhausting the server's half-open connection backlog. The observed pattern of excessive SYNs from an external IP with no completed handshakes matches this denial-of-service attack precisely.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to a target server without completing the handshake (i.e., not sending the final ACK). This exhausts the server's connection table resources, preventing legitimate connections. The log evidence—excessive SYN packets from an external IP with no handshake completion—is the classic signature of a SYN flood.

Exam trap

ISC2 often tests the distinction between attacks that use ICMP (Smurf, Ping of death) versus TCP (SYN flood), so candidates may confuse the protocol layer or misremember that a Smurf attack involves SYN packets instead of ICMP echo requests.

How to eliminate wrong answers

Option A is wrong because a Smurf attack uses ICMP echo requests (pings) sent to a network's broadcast address with a spoofed source IP, causing all hosts to reply to the victim, overwhelming it with ICMP traffic—not TCP SYN packets. Option B is wrong because a Ping of death involves sending a malformed ICMP packet larger than the maximum allowed size (65535 bytes) to cause a buffer overflow or crash, not excessive SYN packets. Option C is wrong because ARP poisoning is a local network attack that manipulates ARP tables to intercept traffic between hosts on the same subnet; it does not involve external IPs sending TCP SYN packets.

213
MCQmedium

Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?

A.Layer 2 – Data Link
B.Layer 1 – Physical
C.Layer 3 – Network
D.Layer 4 – Transport
AnswerC

Layer 3, the Network layer, handles logical addressing and path determination, with IP addresses operating here to identify hosts across networks. Routers forward packets between subnets using these addresses, satisfying the stem's requirement for routing and forwarding, unlike Layer 2's MAC-based switching or Layer 4's port-based delivery.

Why this answer

Layer 3 (Network) handles IP addresses, routing, and packet forwarding.

214
MCQeasy

Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?

A.Warm site
B.Reciprocal agreement
C.Cold site
D.Hot site
AnswerD

A hot site maintains fully mirrored hardware, software and near-live data replication, so operations resume within hours rather than days. This directly satisfies the stem's shortest-RTO constraint, unlike warm or cold sites, which require restoration or configuration before activation.

Why this answer

A hot site is fully configured with hardware, software, and real-time data replication, enabling recovery within hours.

215
MCQeasy

Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?

A.SSH
B.SFTP
C.HTTPS
D.Telnet
AnswerD

Telnet sends all session traffic, including login credentials, as unencrypted cleartext across the network, so anyone capturing packets reads them directly. SSH replaces it by encrypting the same terminal access, which is why Telnet should be disabled on managed devices.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext over the network, making it trivial to intercept with packet capture. It lacks encryption and integrity protection, so it is considered insecure and should be replaced by SSH for remote administration. This is why Telnet is the correct answer.

Exam trap

The trap is picking a protocol that sounds old or file-related (like SFTP) instead of recognizing that Telnet is the classic cleartext remote-access protocol.

How to eliminate wrong answers

Option A is wrong because SSH encrypts the entire session, including authentication, using strong ciphers and is the recommended replacement for Telnet. Option B is wrong because SFTP runs over SSH and provides encrypted file transfer, not cleartext. Option C is wrong because HTTPS uses TLS to encrypt HTTP traffic, protecting credentials and data in transit.

216
Multi-Selecteasy

Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)

Select 2 answers
A.Detective controls
B.Corrective controls
C.Compensating controls
D.Administrative controls
E.Preventive controls
AnswersA, E

Detective controls identify attacks, e.g., IDS.

Why this answer

Detective controls are a core type of security control in a defense-in-depth strategy, designed to identify and alert on ongoing or past security incidents. Examples include intrusion detection systems (IDS) like Snort or Suricata, which analyze network traffic for malicious patterns, and security information and event management (SIEM) systems that correlate logs to detect anomalies. These controls provide visibility into the security posture, enabling timely response to threats that bypass preventive measures.

Exam trap

ISC2 often tests the distinction between control categories by including 'Administrative controls' as a distractor, leading candidates to confuse governance-level controls (policies, awareness training) with the operational control types (preventive, detective, corrective) that form the core of defense in depth.

217
MCQmedium

A security operations center (SOC) analyst receives an alert for a high volume of outbound traffic from an internal server to a known malicious IP address. Which step should the analyst take next?

A.Shut down the server.
B.Disregard the alert as a false positive.
C.Block all outbound traffic from the server.
D.Isolate the server from the network.
AnswerD

Isolation contains the threat immediately, preventing the compromised server from exfiltrating data or communicating with the command-and-control infrastructure. Containment precedes investigation, so this stops active harm while evidence is preserved for later forensic analysis. Blocking the IP alone would leave the host compromised and able to reach other malicious destinations.

Why this answer

Isolating the server from the network is the correct next step because it contains the potential compromise while preserving volatile evidence (memory, running processes) for forensic analysis. It stops further command-and-control communication and lateral movement without destroying the system state. Shutting down or blocking all outbound traffic are either too destructive or insufficient.

Exam trap

CC often tests the misconception that shutting down or blocking all traffic is the best containment; the exam expects isolation to preserve evidence and maintain control.

How to eliminate wrong answers

Option A is wrong because shutting down the server destroys volatile memory and running process data, hindering incident response, and may not be necessary if isolation is sufficient. Option B is wrong because disregarding the alert as a false positive is dangerous; outbound traffic to a known malicious IP is a high-fidelity indicator of compromise. Option C is wrong because blocking all outbound traffic from the server may disrupt legitimate business functions and does not prevent inbound lateral movement or other attack vectors; isolation is more comprehensive.

218
Multi-Selectmedium

Which TWO of the following are core components of the ISC2 Code of Ethics? (Choose two.)

Select 2 answers
A.Advance and protect the profession.
B.Disclose all confidential information to law enforcement.
C.Protect society, the common good, necessary public trust and confidence, and the infrastructure.
D.Ensure maximum profitability for the organization.
E.Always follow orders from management.
AnswersA, C

This is the fourth canon.

Why this answer

The ISC2 Code of Ethics explicitly requires members to 'advance and protect the profession' as one of its four mandatory canons. This means acting honorably, maintaining competence, and not engaging in conduct that brings discredit upon the profession. It is a core ethical duty for all certified professionals.

Exam trap

ISC2 often tests the distinction between ethical duties and legal obligations, where candidates mistakenly believe that always following management orders or maximizing profit are ethical requirements, when in fact the Code prioritizes societal protection and professional integrity.

219
MCQmedium

An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?

A.System performance metrics
B.User authentication attempts
C.Personal identifiable information (PII)
D.Network traffic patterns
AnswerC

Excluding personally identifiable information satisfies privacy regulations because PII directly identifies individuals, such as names, addresses, or government identifiers. Logging such data creates regulatory exposure under GDPR and similar frameworks, so it must be filtered before ingestion. This directly meets the stem's compliance constraint rather than merely reducing storage or noise.

Why this answer

Personal Identifiable Information (PII) should be excluded from logs to comply with privacy regulations like GDPR. Options A, B, and D are typically safe to log and important for security monitoring.

220
MCQhard

A software developer is designing a web application that will store user credentials. What is the most secure method for storing passwords?

A.Hash passwords using a strong algorithm like bcrypt with a unique salt
B.Use a tokenization service to replace passwords with tokens
C.Encrypt passwords using AES-256 and store the key separately
D.Store passwords in a secure database with access controls
AnswerA

bcrypt is a deliberately slow adaptive hashing function, and a unique per-password salt defeats rainbow tables and identical-hash correlation. This satisfies secure credential storage: even full database compromise leaves attackers unable to reverse hashes or reuse precomputed cracking sets.

Why this answer

Hashing with salt protects passwords even if database is compromised. Encryption is reversible, so less secure for passwords.

221
MCQmedium

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

A.24 months retention, 12 months immediately available
B.6 months retention, 1 month immediately available
C.12 months retention, 3 months immediately available
D.12 months retention, 6 months immediately available
AnswerC

PCI DSS requires audit logs retained for at least 12 months, with the most recent 3 months immediately available for analysis. This satisfies the stem's two-part constraint, balancing forensic history against the cost of keeping older logs readily searchable.

Why this answer

PCI DSS requires logs to be retained for at least 12 months, with the most recent 3 months immediately available for review.

222
MCQhard

A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?

A.Require Tier 2 analysts to review all alerts before Tier 1.
B.Increase the number of Tier 1 analysts to handle the volume.
C.Implement automated playbooks for low-severity alerts to perform initial investigation and closure if benign.
D.Disable all low-severity alert rules in the EDR.
AnswerC

Automated playbooks let Tier 1 offload repetitive low-severity triage, performing initial investigation and closing benign alerts without human effort. This preserves analyst capacity for genuine threats, directly reducing alert fatigue while maintaining detection of true positives.

Why this answer

Automated playbooks (SOAR-style) let the SOC enrich, correlate, and close low-severity alerts without human intervention, freeing Tier 1 and Tier 2 analysts to focus on genuine threats. This directly reduces alert fatigue while preserving detection coverage, because the rules remain enabled and only the triage step is automated. It is the only option that scales without degrading detection or analyst workload.

Exam trap

The trap here is the instinct to either throw more people at the problem or silence noisy rules; the exam expects you to recognize that automation of triage, not headcount or rule suppression, is the scalable fix for alert fatigue.

How to eliminate wrong answers

Option A is wrong because routing every alert to Tier 2 first inverts the tiered model, increases Tier 2 workload, and delays response to true positives rather than reducing fatigue. Option B is wrong because adding Tier 1 analysts treats the symptom (volume) rather than the cause (manual triage of benign alerts) and does not scale economically. Option D is wrong because disabling low-severity EDR rules creates detection blind spots and violates the requirement to not miss critical threats, since low-severity alerts can be precursors to real incidents.

223
MCQmedium

A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?

A.Digital signatures
B.SHA-256
C.TLS 1.3
D.AES-256
AnswerC

TLS 1.3 encrypts data in transit between client and server, providing confidentiality over untrusted internet paths. It satisfies the in-transit confidentiality requirement, and its removal of legacy ciphers and RSA key exchange strengthens forward secrecy compared with earlier TLS versions.

Why this answer

TLS 1.3 is the correct choice because it is a transport-layer cryptographic protocol specifically designed to provide confidentiality (encryption) and integrity for data in transit over untrusted networks like the internet. It negotiates ephemeral session keys via a handshake and encrypts application traffic using AEAD ciphers such as AES-GCM or ChaCha20-Poly1305. The other options address different security goals or operate at different layers.

Exam trap

The trap is conflating encryption algorithms (AES) or integrity primitives (SHA-256, digital signatures) with the transport protocol (TLS) that actually secures data in transit — candidates often pick AES-256 because it sounds like 'strong encryption' without realizing it lacks the transport framing and key exchange.

How to eliminate wrong answers

Option A is wrong because digital signatures provide authenticity, integrity, and non-repudiation — they do not encrypt data, so they cannot keep financial data confidential in transit. Option B is wrong because SHA-256 is a one-way hashing algorithm used for integrity checks and digital signatures; it is not an encryption mechanism and provides no confidentiality. Option D is wrong because AES-256 is a symmetric block cipher used to encrypt data at rest or as a component inside protocols like TLS; by itself it does not secure data in transit across a network without a transport protocol to manage key exchange and framing.

224
MCQmedium

A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?

A.Discretionary access control (DAC)
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Rule-based access control
AnswerB

RBAC grants permissions to roles, and users receive rights by being assigned to a role. When the employee moves from the Teller role to the Loan Officer role, the old role's permissions drop away and the new role's permissions apply, exactly as described. This role-to-permission mapping with automatic reassignment is the defining behavior of role-based access control.

Why this answer

Assigning rights to roles and then placing users into those roles is the essence of role-based access control. The transfer scenario shows the key benefit: permissions follow the job function, so moving an employee between departments automatically strips old rights and applies new ones without editing each user's individual access list.

Exam trap

The trap here is treating any centrally managed permission scheme as mandatory access control when the scenario actually describes role assignment without security labels.

225
Multi-Selecthard

An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)

Select 3 answers
A.Fencing and bollards around the property
B.Biometric reader on server room door
C.Encryption of data at rest
D.Intrusion detection system on the network
E.Access badge system at building entrance
AnswersA, B, E

Fencing and bollards form the outermost deterrent layer, delaying or preventing physical approach to the facility. They satisfy defence in depth by forcing attackers through successive boundaries before reaching internal controls such as locks or biometrics.

Why this answer

Option A (fencing and bollards around the property) is correct because these are perimeter physical controls that create the outermost defensive layer, deterring or blocking vehicles and intruders before they reach the building. Option B (biometric reader on server room door) is correct because it is an interior physical access control that authenticates a person's unique biological trait, adding a stronger layer protecting the high-value server room beyond the building entrance. Option E (access badge system at building entrance) is correct because it is a physical access control at the facility boundary, verifying authorized personnel and forming a layer between the perimeter and the server room.

Option C (encryption of data at rest) is not a physical control but a logical/cryptographic control protecting data confidentiality. Option D (intrusion detection system on the network) is a logical/technical monitoring control, not a physical security layer.

Exam trap

The trap is mixing logical and physical controls — candidates see 'encryption' and 'IDS' as security measures and include them, forgetting the question specifically asks for layered PHYSICAL controls.

Page 2

Page 3 of 14

Page 4