Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 226–300

989 questions total · 14pages · All types, answers revealed

Page 3

Page 4 of 14

Page 5
226
MCQmedium

A software company's incident response plan defines a severity level of 'Critical' for incidents that cause a complete outage of customer-facing services. A developer accidentally deploys a faulty update that crashes the production web servers, making the service unavailable to all customers. Which incident response phase should the team be in when they apply a rollback to the previous working version?

A.Preparation
B.Containment
C.Recovery
D.Eradication
AnswerC

The recovery phase involves restoring systems to normal operation after an incident has been contained and eradicated. Applying a rollback to a previous working version is a recovery action because it brings the production web servers back to a functional state. This phase focuses on implementing the fix and verifying that the service is fully operational. It follows containment and eradication, where the faulty update would have been identified and removed.

Why this answer

The recovery phase focuses on restoring systems to normal operation after an incident has been contained and eradicated. Applying a rollback to a previous working version is a recovery action because it brings the production web servers back online and functional. This phase ensures the service is fully restored and verified.

It follows containment (limiting impact) and eradication (removing the cause).

Exam trap

The trap here is confusing the recovery phase with eradication, as both involve actions to fix the issue, but recovery specifically restores normal operations.

227
MCQhard

A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?

A.The VPN concentrator has failed and the logs are unreliable, so the account is safe
B.The alert is a false positive caused by NTP drift and should be closed immediately
C.The account is likely compromised and the impossible-travel indicator warrants immediate investigation
D.The user must be sharing credentials with a colleague and should only be reminded of policy
AnswerC

Simultaneous successful authentications from geographically distant locations within an impossibly short window strongly suggest the credentials were used by someone other than the legitimate user, especially since the user confirms only one session. Treating impossible travel as a compromise indicator prompts containment steps such as session termination, password reset, and review of accessed resources, which is the appropriate response.

Why this answer

Successful authentications from two distant countries within five minutes, combined with the user confirming a single session, form a classic impossible-travel indicator of credential compromise. The analyst should treat the account as potentially compromised and act quickly to contain it, rather than dismissing the alert, assuming benign credential sharing, or blaming infrastructure. Prompt investigation limits any attacker's access.

Exam trap

The trap here is rationalizing the anomaly as clock drift, credential sharing, or device failure instead of recognizing impossible travel as a likely compromise indicator.

228
MCQmedium

Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?

A.Application proxy firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Stateful inspection firewall
AnswerC

A next-generation firewall performs deep packet inspection, examining payload and application-layer data rather than only headers and ports. It also integrates with directory services to enforce rules based on user identity, satisfying both constraints in the stem, unlike packet-filtering or stateful inspection firewalls.

Why this answer

A Next-Generation Firewall (NGFW) goes beyond traditional port/protocol inspection by performing deep packet inspection (DPI) up to Layer 7, identifying applications regardless of port, and integrating user identity awareness (via LDAP, Active Directory, or captive portal) to enforce policies based on who the user is. It combines stateful inspection, application control, IPS, and identity-based rules in a single platform. This matches the question's requirement of inspecting application data and enforcing rules based on user identity.

Exam trap

The trap is assuming 'application proxy firewall' equals 'NGFW' because both inspect application data — but the CC exam distinguishes that only NGFW adds user-identity-based enforcement and integrated Layer 7 inspection across all applications.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall inspects application-layer data but typically operates as a proxy per application and does not natively enforce rules based on user identity across all traffic types. Option B is wrong because a packet filtering firewall only examines headers (source/destination IP, port, protocol) at Layers 3–4 and cannot inspect application data or identify users. Option D is wrong because a stateful inspection firewall tracks connection state (Layer 4) but does not perform deep application-layer inspection or user-identity-based enforcement — those are NGFW capabilities.

229
MCQeasy

Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?

A.Cold site
B.Warm site
C.Hot site
D.Cloud-based recovery
AnswerC

A hot site maintains a fully operational, mirrored environment with current data and ready hardware, enabling failover within hours. This satisfies the stem's fastest-RTO constraint, unlike warm or cold sites, which require longer setup and data restoration.

Why this answer

A hot site is a fully operational duplicate of the primary data center with mirrored hardware, data replication, and network connectivity, enabling failover typically within minutes to hours. Because it maintains real-time or near-real-time synchronization, it delivers the fastest Recovery Time Objective (RTO) among the traditional site strategies. This makes it the correct choice when the business cannot tolerate extended downtime.

Exam trap

The trap here is conflating 'cloud-based recovery' with a hot site — candidates assume anything cloud is automatically fastest, but the exam wants the classic hot/warm/cold classification where 'fully operational mirrored environment' maps specifically to hot site.

How to eliminate wrong answers

Option A is wrong because a cold site provides only basic infrastructure (space, power, cooling) with no pre-installed hardware or data, resulting in RTO measured in days or weeks. Option B is wrong because a warm site has some pre-configured hardware and periodic backups but still requires restoration and configuration, yielding an RTO of hours to days — slower than a hot site. Option D is wrong because 'cloud-based recovery' is not one of the three classic recovery site categories (hot/warm/cold); while cloud DR can be fast, the question asks for the strategy that maintains a fully operational mirrored environment, which is the definition of a hot site.

230
MCQeasy

A user reports that they received a suspicious email with an attachment claiming to be an invoice. What should the user do?

A.Report the email to the security team without opening the attachment
B.Reply to the email and ask for confirmation
C.Delete the email immediately
D.Open the attachment to check what it contains
AnswerA

Reporting preserves the original message and headers for the security team to analyse, block the sender and warn other recipients, while avoiding attachment execution prevents malware detonation. Opening or forwarding the attachment risks compromise and destroys forensic evidence.

Why this answer

The user should immediately report the suspicious email to the security team without opening the attachment. Opening the attachment could trigger a malicious payload, such as a macro-enabled document or executable, that exploits vulnerabilities in the email client or operating system. The security team can analyze the email headers, attachment hash, and sender domain using tools like sandboxing or threat intelligence feeds to determine if it is a phishing attempt or malware delivery.

Exam trap

ISC2 often tests the misconception that deleting a suspicious email is sufficient, but the correct incident response procedure requires preserving evidence and reporting to the security team for analysis and containment.

How to eliminate wrong answers

Option B is wrong because replying to the email confirms the user's email address as active to the attacker, potentially leading to targeted follow-up attacks or social engineering. Option C is wrong because deleting the email immediately removes forensic evidence (e.g., email headers, attachment metadata) that the security team needs to investigate and block the threat across the organization. Option D is wrong because opening the attachment risks executing malware, such as ransomware or a trojan, that could compromise the user's endpoint and spread laterally within the network.

231
MCQhard

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

A.Purchasing cyber insurance
B.Performing a background check on a new vendor
C.Accepting the risk of a legacy system
D.Regularly updating antivirus software
AnswerD

Due care means taking reasonable, ongoing steps to protect assets, and regularly updating antivirus software demonstrates continuous diligence against known malware. It satisfies the stem by showing sustained protective action rather than a one-off measure, distinguishing due care from mere policy documentation or due diligence assessment.

Why this answer

Due care means taking reasonable steps to protect assets, such as implementing basic security controls like patch management.

232
MCQmedium

A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?

A.IPS
B.Firewall
C.WAF
D.IDS
AnswerA

An IPS inspects packet payloads and application-layer data inline, blocking malicious traffic in real time. Its signature-based detection can flag benign activity as malicious, producing false positives that block legitimate traffic — exactly the occasional over-blocking described. A firewall filtering only headers could not inspect payloads, so it fails the stem's inspection constraint.

Why this answer

An IPS (Intrusion Prevention System) inspects packet payloads and application data in real time and can actively block malicious traffic. The fact that it occasionally blocks legitimate traffic is a classic false-positive behavior of IPS devices, which is why tuning is required.

Exam trap

The trap is confusing IDS and IPS — the key differentiator is that IPS blocks in real time (and can cause false positives), while IDS only detects and alerts.

How to eliminate wrong answers

Option B is wrong because a traditional firewall filters based on IP addresses, ports, and protocols — it does not inspect payloads or application data for malicious content. Option C is wrong because a WAF specifically protects web applications at the HTTP/HTTPS layer and would not be described as inspecting general packet payloads across all traffic. Option D is wrong because an IDS only detects and alerts; it does not block traffic in real time.

233
Multi-Selecthard

A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)

Select 2 answers
A.Granting one senior manager both the ability to create vendors and the ability to approve payments to those vendors
B.Allowing any employee with payment approval rights to also modify the approval limits assigned to their own account
C.Assigning all payment-related duties to a single trusted administrator to simplify the process
D.Applying a system constraint that prevents the same user account from both entering and approving a payment
E.Requiring one employee to initiate a payment and a different employee to approve it
AnswersD, E

A technical constraint that blocks one account from performing both steps enforces separation of duties automatically rather than relying on policy alone. It removes the possibility of a single user completing the whole transaction, which is exactly what the firm needs. This makes the control reliable and auditable in the payment system.

Why this answer

Separation of duties ensures no single person can complete a sensitive transaction end to end. Requiring different employees to initiate and approve payments, and enforcing that split with a system constraint that blocks one account from doing both, both create an independent check. The other practices concentrate or allow circumvention of those duties, which undermines the control.

Exam trap

The trap here is equating trust in a specific person with an effective control, which leads candidates to accept consolidating payment duties as a reasonable simplification.

234
MCQhard

A security analyst reviews firewall logs and sees a series of outbound connections from an internal server to a known command-and-control (C2) IP address at regular intervals. Which step should the analyst take first according to incident response best practices?

A.Isolate the server from the network immediately.
B.Check if the IP address is associated with known malware or threats.
C.Quarantine the server and begin forensic analysis.
D.Terminate the outbound connections by blocking the IP.
AnswerB

Checking the IP address against current threat intelligence feeds is the crucial first step. While the IP is identified as 'known command-and-control', verifying its specific associations with malware families or active campaigns provides essential context. This enrichment confirms the nature of the threat and informs subsequent incident response phases, satisfying the need for initial validation before proceeding with containment or eradication.

Why this answer

According to incident response best practices, the first step after detecting a potential incident is to verify and validate the alert by checking if the IP is associated with known threats. This confirms whether it is a true positive before taking disruptive actions. Isolation, quarantine, and blocking are subsequent steps.

Exam trap

CC often tests the order of incident response steps, and candidates might jump to containment (isolation) first, but the correct first step is always verification and analysis.

How to eliminate wrong answers

Option A is wrong because isolating the server immediately is a containment step that should be taken after verification, not first, to avoid unnecessary disruption if the alert is a false positive. Option C is wrong because quarantining and forensic analysis are later steps in the incident response process, after verification. Option D is wrong because terminating connections by blocking the IP is a containment action that should follow verification.

235
MCQhard

An organization's BCP identifies a customer-facing order system as critical. The BIA shows the business can tolerate 12 hours of downtime and 1 hour of data loss. The current architecture uses nightly full backups to tape with a 10-hour restore time. Which change BEST closes the gap between current capability and the stated requirements?

A.Implement continuous replication to a secondary site with automated failover to meet the 12-hour RTO and 1-hour RPO
B.Document a manual workaround in the BCP that allows order entry staff to record transactions on paper until systems return
C.Increase backup frequency to every hour while keeping the nightly tape full backup and 10-hour restore process
D.Move backups from tape to disk to reduce restore time, keeping the nightly full backup schedule
AnswerA

Continuous replication addresses the RPO by keeping data loss well under one hour, and automated failover at a secondary site brings the order system back online far faster than a 10-hour tape restore, comfortably meeting the 12-hour RTO. This solution targets both metrics simultaneously and provides a resilient architecture rather than incremental tweaks to a slow tape process.

Why this answer

The stated requirements are a 12-hour RTO and a 1-hour RPO. Nightly tape backups with a 10-hour restore already meet the RTO but leave up to 24 hours of potential data loss, violating the RPO. Continuous replication to a secondary site with automated failover reduces data loss to minutes and restores service quickly, satisfying both the recovery point and recovery time objectives in one architectural change.

Exam trap

The trap here is treating backup frequency as a fix for recovery time, when backup frequency primarily governs the recovery point objective and does not by itself speed up restoration.

236
MCQeasy

A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?

A.Least privilege
B.Mandatory access control
C.Need to know
D.Separation of duties
AnswerD

Separation of duties splits a sensitive transaction across more than one person so no single individual controls the entire process. Because the clerk processes reimbursements, letting her also approve her own claim would give her unchecked control over a payment to herself. Requiring a different approver for her own reimbursement prevents that conflict and is the textbook application of separation of duties.

Why this answer

Separation of duties ensures that a single person cannot complete a sensitive transaction alone, reducing the risk of fraud or undetected error. Since the clerk can process reimbursements but is barred from approving her own, the organization has split control of the payment process across multiple people, which is exactly what separation of duties accomplishes.

Exam trap

The trap here is choosing least privilege simply because a restriction exists, when the real reason is preventing one person from controlling both sides of a sensitive transaction.

237
Multi-Selectmedium

A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)

Select 2 answers
A.Smart card reader
B.Proximity badge
C.Personal identification number (PIN) pad
D.Retina scanner
E.Fingerprint scanner
AnswersD, E

A retina scanner analyzes the unique pattern of blood vessels in the eye, which is a biological characteristic. This makes it a biometric control that verifies identity based on inherence. It is well suited for high-security environments like data centers because the trait is difficult to replicate, and it directly matches the requirement for biological verification.

Why this answer

Biometric access controls verify identity using unique biological traits. Retina scanners and fingerprint scanners both measure inherent physical characteristics, making them valid biometric controls for the data center. Smart cards, PIN pads, and proximity badges rely on possession or knowledge factors instead, so they do not satisfy the requirement for biological verification even though they may be used alongside biometrics in a layered design.

Exam trap

The trap here is assuming that any electronic access device, such as a smart card or badge reader, counts as biometric because it is used for access control.

238
Multi-Selecthard

A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)

Select 2 answers
A.Implementing data classification labels
B.Using a single sign-on solution
C.Requiring two-factor authentication
D.Granting all employees access to the company directory
E.Providing access to customer data only for customer support staff
AnswersA, E

Data classification labels tag information by sensitivity, enabling need-to-know enforcement because access decisions can be tied to clearance and label matching. Without labels, administrators cannot determine who legitimately requires specific data, so this practice directly supports least-privilege need-to-know access.

Why this answer

Option A is correct because implementing data classification labels (e.g., Public, Internal, Confidential, Restricted) tags information with its sensitivity level, which is the foundation for need-to-know decisions—users are only granted access to data whose classification matches their role and clearance. Option E is correct because restricting customer data access to only customer support staff is a direct application of need-to-know: access is limited to those whose job function requires that data, excluding other employees. Option B (single sign-on) is an authentication convenience that centralizes login but does not by itself limit access to only what a user needs.

Option C (two-factor authentication) strengthens identity verification but addresses authentication assurance, not authorization scope. Option D (granting all employees access to the company directory) violates need-to-know by giving broad access regardless of job requirement.

Exam trap

The trap here is confusing authentication controls (SSO, 2FA) with authorization controls — candidates pick B or C because they sound like security best practices, but need-to-know is strictly about limiting data access based on job function.

239
MCQeasy

A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?

A.A web application firewall protecting the file server.
B.A remote access VPN using TLS or IPsec.
C.A host-based intrusion prevention system on each laptop.
D.A network access control solution enforcing 802.1X on the office switches.
AnswerB

A remote access VPN authenticates the user and encrypts the entire session between the remote device and the corporate gateway, so file-share traffic is protected in transit without requiring per-application agents. It is well suited to a small business because it uses standard client software or a browser-based portal and centralizes access control at the VPN concentrator, meeting the authentication and encryption goals.

Why this answer

A remote access VPN is designed exactly for this need: it authenticates the user at a central gateway and encrypts traffic between the remote device and the corporate network. The other choices address endpoint protection, local network admission control, or web application defense, none of which establish an authenticated, encrypted path to internal file shares for off-site workers.

Exam trap

The trap here is confusing endpoint security controls, such as host intrusion prevention, with the transport security and authentication that a remote access VPN actually provides.

240
MCQhard

Which of the following is a common mitigation technique for a SYN flood attack?

A.SYN cookies
B.Use UDP instead of TCP
C.Disable TCP timestamps
D.Increase the TCP backlog queue
AnswerA

SYN cookies let the server avoid allocating state for half-open connections: it encodes connection details in the sequence number of the SYN-ACK, so the backlog cannot be exhausted by spoofed SYNs. This directly mitigates the resource-exhaustion constraint of a SYN flood.

Why this answer

SYN cookies are the canonical mitigation for SYN flood attacks. When the SYN backlog is exhausted or under stress, the server encodes connection state into the initial sequence number (ISN) of the SYN-ACK rather than allocating a half-open socket, so no state is consumed until the client returns the final ACK. This defeats the attacker's ability to exhaust the backlog with spoofed SYNs.

Exam trap

The trap here is confusing 'increase the backlog' with an actual mitigation — candidates reason that a bigger queue absorbs the flood, but it only raises the resource ceiling the attacker must exhaust.

How to eliminate wrong answers

Option B is wrong because switching to UDP is not a mitigation — it abandons TCP's reliability and handshake entirely, and UDP itself is trivially spoofable and floodable (e.g., UDP amplification). Option C is wrong because disabling TCP timestamps has no bearing on SYN flood handling; timestamps are an RFC 1323/7323 performance and PAWS mechanism, not a defense against half-open connection exhaustion. Option D is wrong because increasing the TCP backlog queue only raises the ceiling of half-open connections an attacker must fill — it delays but does not prevent exhaustion, and can worsen memory pressure.

241
Multi-Selecthard

Which TWO of the following are examples of implementing the principle of least privilege?

Select 2 answers
A.Installing a security camera at the data center entrance
B.Assigning a database administrator only the permissions required for their specific tasks
C.Requiring two-factor authentication for system administrators
D.Implementing a firewall to block all incoming traffic except on port 443
E.Granting a user read-only access to a file they need to view
AnswersB, E

Granting the database administrator only the permissions their specific tasks demand directly enacts least privilege, which requires limiting each identity to the minimum access necessary. This satisfies the stem's constraint by scoping rights to job function rather than granting broad, standing database privileges, thereby reducing the blast radius of compromised or misused credentials.

Why this answer

Option B is correct because least privilege means granting an identity only the minimum access rights needed to perform its job function; giving a database administrator just the permissions required for their specific tasks directly enforces that restriction. Option E is correct because granting a user read-only access to a file they only need to view limits them to the least access necessary (read) rather than granting write or modify rights. Option A is not least privilege because a security camera is a physical monitoring control, not an access-rights restriction.

Option C is not least privilege because two-factor authentication strengthens authentication assurance but does not limit the permissions an administrator holds. Option D is not least privilege because a firewall filtering inbound traffic to port 443 is a network access control, not the assignment of minimal permissions to a user or role.

Exam trap

CC often tests the difference between least privilege and other security principles like defense in depth or authentication — candidates may select two-factor authentication or firewalls as least privilege, but those are separate controls.

242
MCQeasy

A small business wants to prevent employees from visiting known malicious websites. The owner asks for a solution that can block requests based on a constantly updated list of harmful domains without requiring software on each employee device. Which technology should be recommended?

A.Stateful packet inspection firewall
B.DNS filtering
C.Network access control (NAC)
D.Host-based antivirus
AnswerB

DNS filtering intercepts domain name resolution requests and blocks those matching a threat intelligence list of malicious domains. It requires no endpoint software, works network-wide, and is easy to update centrally. This directly prevents users from reaching harmful sites by returning a block response before any connection to the malicious IP is made.

Why this answer

DNS filtering blocks malicious domains by intercepting DNS queries and checking them against a threat intelligence feed. It requires no endpoint agent, applies network-wide, and updates centrally. Host-based antivirus needs per-device installation, stateful firewalls lack domain awareness, and NAC governs device admission rather than web content, so none satisfy the stated constraints.

Exam trap

The trap here is confusing network admission control or firewall filtering with DNS-layer security, which specifically blocks domains before a connection is established.

243
MCQhard

An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?

A.OU = Organizational Unit; DC = Domain Component
B.OU = Organizational Unit; DC = Domain Controller
C.OU = Organizational Unit; DC = Distinguished Component
D.OU = Object Unit; DC = Domain Component
AnswerA

In LDAP distinguished names, OU identifies the Organizational Unit container holding the object, while DC marks each Domain Component of the DNS-based directory namespace. Reading right to left, DC=com and DC=company define the domain hierarchy, and OU=Sales places John Smith within the Sales organisational unit.

Why this answer

In LDAP distinguished names, OU stands for Organizational Unit and DC stands for Domain Component. These are the standard RDN attribute types defined in RFC 4519 and used to build hierarchical directory paths, so option A is the correct expansion.

Exam trap

The trap is the DC acronym collision — candidates who work with Active Directory reflexively read DC as Domain Controller instead of Domain Component.

How to eliminate wrong answers

Option B is wrong because DC does not mean Domain Controller in LDAP DN syntax — Domain Controller is an Active Directory server role, not a DN attribute, and conflating the two is a classic naming trap. Option C is wrong because DC is not 'Distinguished Component'; the term 'distinguished' refers to the DN as a whole, not to the DC attribute. Option D is wrong because OU is not 'Object Unit' — the correct expansion is Organizational Unit, and misnaming it signals a misunderstanding of the X.500 directory model.

244
MCQeasy

Which protocol is considered insecure because it transmits data in cleartext, including passwords?

A.SFTP
B.SSH
C.HTTPS
D.Telnet
AnswerD

Telnet transmits all session data, including login credentials, as unencrypted cleartext across the network, so anyone capturing traffic can read passwords directly. This satisfies the stem's constraint of a protocol deemed insecure precisely because it lacks encryption, unlike SSH, which tunnels the same terminal access within an encrypted channel.

Why this answer

Telnet is considered insecure because it transmits all data — including usernames and passwords — in cleartext over the network, with no encryption whatsoever. Anyone with access to the traffic path (via packet capture or MITM) can read credentials directly. This is why Telnet has been replaced by SSH for remote administration.

Exam trap

The trap here is confusing 'file transfer' protocols with 'remote login' protocols — candidates may pick SFTP thinking it is insecure because it sounds like FTP, when in fact SFTP is encrypted and FTP is the cleartext one.

How to eliminate wrong answers

Option A is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts all data in transit, so it is not a cleartext protocol. Option B is wrong because SSH provides strong encryption and authentication for remote sessions, making it the secure replacement for Telnet. Option C is wrong because HTTPS wraps HTTP inside TLS, encrypting credentials and session data, so it is not cleartext.

245
Multi-Selecteasy

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Select 2 answers
A.OTP token
B.Smart card
C.Retina scan
D.Password
E.Fingerprint scan
AnswersC, E

A retina scan measures a physiological characteristic of the user's body, which is inherent and therefore a Type 3 inherence factor. It is not something the user knows or possesses, so it satisfies the requirement for an inherence-based example.

Why this answer

Type 3 (inherence) authentication factors are based on something the user is — a physical or behavioral biometric characteristic of the individual. Option C, retina scan, is correct because it measures the unique pattern of blood vessels in the user's retina, an inherent physiological trait that cannot be transferred or forgotten. Option E, fingerprint scan, is correct because it reads the distinct ridge and minutiae pattern of the user's finger, another inborn biometric attribute.

The remaining options do not belong: A (OTP token) and B (smart card) are Type 2 (possession) factors — something the user has — while D (password) is a Type 1 (knowledge) factor — something the user knows.

Exam trap

CC often tests the confusion between possession factors (smart card, token) and inherence factors (biometrics), so candidates might incorrectly select OTP token or smart card as inherence.

246
Multi-Selecthard

A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)

Select 2 answers
A.ABAC decisions are made by comparing the user's security clearance against the classification label of the object, with no other inputs considered.
B.ABAC policies can be expressed so that access is granted only when the department matches the record's owning business unit, the classification is permitted for that department, the request occurs during approved hours, and the device is managed.
C.ABAC removes the need for authentication because attribute values alone are sufficient to prove a user's identity.
D.ABAC evaluates policies built from attributes of the subject, the object, the action, and the environment, allowing the firm to combine department, classification, time, and device posture in a single decision.
E.ABAC requires that each user be assigned exactly one static role, and all access is then determined solely by that role membership.
AnswersB, D

ABAC supports compound policy conditions that must all evaluate true before access is granted. Expressing the department match, classification allowance, approved hours, and managed-device requirement as a combined policy directly implements the auditors' four conditions. This is a correct description of how attribute-driven rules translate business requirements into enforceable access decisions.

Why this answer

ABAC makes decisions by evaluating policies over attributes of the subject, object, action, and environment, which allows department, data classification, time, and device posture to be combined into a single enforceable rule. The two correct statements capture that multi-attribute evaluation and the ability to express compound conditions that must all hold before access is granted.

Exam trap

The trap here is confusing ABAC with role-based or label-based models, since role membership and clearance labels can be attributes, but neither alone can express the time and device conditions required.

247
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

A.Determine the cost of implementing security controls
B.List all IT assets
C.Identify critical business processes and their recovery priorities
D.Assign incident response roles
AnswerC

A BIA determines which business processes are most critical and sets their recovery priorities, typically through impact ratings over time. This directly satisfies the stem's focus on prioritisation, distinguishing it from risk assessment or purely technical recovery sequencing activities.

Why this answer

The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the impact of their disruption, which directly determines recovery priorities and objectives (RTO/RPO). This output drives the business continuity and disaster recovery strategy, not asset inventory or cost estimation.

Exam trap

ISC2 often tests the distinction between a BIA (which identifies critical processes and their recovery priorities) and a risk assessment (which identifies threats and vulnerabilities), leading candidates to confuse the BIA's purpose with asset listing or cost analysis.

How to eliminate wrong answers

Option A is wrong because determining the cost of implementing security controls is a function of risk management and cost-benefit analysis, not the BIA, which focuses on impact quantification rather than solution pricing. Option B is wrong because listing all IT assets is an inventory management or configuration management task (e.g., CMDB), whereas the BIA prioritizes business processes and their dependencies, not a simple asset list. Option D is wrong because assigning incident response roles is part of the incident response plan (IRP) development, not the BIA, which identifies recovery priorities before any roles are assigned.

248
MCQeasy

A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?

A.Conduct a lessons-learned meeting to identify improvements in the DDoS response process.
B.Notify law enforcement and press charges against the attackers.
C.Immediately reconfigure the firewall to block the attacking IP addresses.
D.Restore the online store from the most recent backup.
AnswerA

The post-incident activity phase is designed to review the incident, gather feedback from responders, and update plans and controls. A lessons-learned meeting helps the retail company understand how the DDoS was detected, what worked well, and what needs improvement. This aligns with the goal of continuous improvement and is a core activity after the incident is closed.

Why this answer

After an incident is contained and systems are restored, the post-incident activity phase involves reviewing the event to improve future response. A lessons-learned meeting allows the team to document what happened, identify gaps, and update the incident response plan. This is the key activity that distinguishes post-incident work from ongoing operational tasks.

Exam trap

The trap here is choosing a technical remediation step like firewall changes or backups, when the question specifically asks for a post-incident activity, which is about review and improvement.

249
MCQhard

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

A.Confidentiality
B.Non-repudiation
C.Availability
D.Integrity
AnswerC

Availability ensures systems and data remain accessible to authorised users when required. Redundant internet connections and load balancers remove single points of failure, maintaining web service access during DDoS traffic floods. Confidentiality and integrity address disclosure and modification respectively, not uptime.

Why this answer

Redundancy and load balancing help maintain access for authorized users, supporting availability.

250
Multi-Selecthard

An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)

Select 3 answers
A.Allowing remote desktop access from any IP address.
B.Disabling unnecessary services and ports.
C.Enabling automatic login for administrators.
D.Enforcing strong password policies.
E.Installing all available security patches.
AnswersB, D, E

Disabling unnecessary services and ports shrinks the attack surface by removing listening daemons and open sockets that are not required for the server's role. This is a core hardening step, directly satisfying the baseline requirement to minimise exploitable entry points on new servers.

Why this answer

Option B is correct because a hardened baseline minimizes the attack surface by disabling unnecessary services and closing unused ports, reducing the number of exploitable entry points on a new server. Option D is correct because enforcing strong password policies (for example, minimum length, complexity, and expiration requirements) strengthens authentication and mitigates brute-force and credential-guessing attacks. Option E is correct because installing all available security patches ensures known vulnerabilities in the OS and applications are remediated before the server is placed into production.

Option A does not belong because allowing RDP from any IP address exposes the server to unauthorized remote access and should instead be restricted to trusted management networks. Option C does not belong because automatic login for administrators bypasses authentication entirely, directly undermining the purpose of a security baseline.

Exam trap

The trap is selecting convenience features like automatic login or unrestricted RDP because they seem efficient, but hardening always prioritizes security over convenience—candidates must recognize that these are anti-patterns.

251
MCQmedium

A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?

A.Tier 3
B.Tier 2
C.Tier 1
D.Incident Response Team
AnswerB

Tier 2 analysts handle deeper investigation, correlating the malicious-IP indicator against threat intelligence, historical logs and endpoint telemetry. Tier 1 performs initial triage only, so escalation to Tier 2 satisfies the requirement for a deeper investigation of confirmed malicious outbound traffic.

Why this answer

Tier 2 analysts handle escalated alerts that require deeper investigation, correlation across data sources, and threat hunting beyond the initial triage performed by Tier 1. An outbound connection to a known malicious IP is a confirmed suspicious indicator that exceeds Tier 1's scope of basic validation and false-positive filtering, so it escalates to Tier 2. Tier 3 is reserved for advanced threat hunting, malware reverse engineering, and major incidents.

Exam trap

The trap is assuming any malicious-IP alert is automatically an incident requiring the IR team, when the correct answer is the tier that performs deeper investigation, not the team that handles confirmed incidents.

How to eliminate wrong answers

Option A is wrong because Tier 3 is for the most complex, advanced investigations such as reverse engineering or APT hunting, which is beyond a single malicious-IP alert. Option C is wrong because Tier 1 performs initial triage and alert validation; escalating to Tier 1 would be a downgrade, not an escalation. Option D is wrong because the Incident Response Team is engaged for confirmed incidents requiring containment and recovery, not for the initial deeper investigation of a suspicious alert.

252
MCQeasy

A hospital's IT department wants to ensure that only authorized clinicians can view patient records, while also guaranteeing that those records have not been tampered with. Which security principle is primarily concerned with preventing unauthorized disclosure of the records?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. In this scenario, restricting patient record access to authorized clinicians directly addresses preventing unauthorized disclosure, which is the core goal of confidentiality. The integrity and availability aspects are separate concerns; the question specifically asks about preventing unauthorized disclosure, making confidentiality the correct principle.

Why this answer

Confidentiality is the security principle that ensures information is not made available or disclosed to unauthorized individuals, entities, or processes. In the hospital scenario, the goal is to restrict patient record access to authorized clinicians, which is a classic confidentiality objective. Integrity addresses unauthorized modification, availability addresses timely access, and non-repudiation addresses proof of actions.

Exam trap

The trap here is confusing confidentiality with integrity because the scenario also mentions tampering, but the question specifically asks about preventing unauthorized disclosure.

253
MCQmedium

A security analyst at a mid-sized company is reviewing network traffic logs and notices that an internal host is repeatedly sending TCP SYN packets to many different external IP addresses on port 443, but never completing the three-way handshake. The analyst suspects a malware infection. Which type of attack is most likely occurring?

A.MAC flooding
B.SYN flood
C.Smurf attack
D.Ping flood
AnswerB

A SYN flood is a type of denial-of-service attack where the attacker sends a large number of TCP SYN packets to a target but does not complete the handshake, exhausting the target's connection resources. In this scenario, the internal host is sending SYN packets to many external IPs on port 443 without completing the handshake, which is characteristic of a SYN flood. The host is likely compromised and participating in a botnet.

Why this answer

The host is sending numerous TCP SYN packets to various external IP addresses on port 443 without completing the three-way handshake. This pattern indicates a SYN flood attack, where the attacker attempts to exhaust connection resources on targets. The host is likely part of a botnet.

The other options describe different attack types that do not match the observed traffic pattern.

Exam trap

The trap here is assuming that any flood of packets is a ping flood or Smurf attack, but the key differentiator is the protocol and handshake behavior.

254
MCQmedium

A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?

A.Subnetting
B.Full mesh topology
C.Virtual LAN (VLAN)
D.DMZ
AnswerD

A DMZ sits between the internet-facing firewall and the internal network, so public web and email servers are reachable externally while internal hosts stay shielded. This satisfies the stem's requirement to host public services and protect the internal network, since inbound traffic terminates in the DMZ rather than crossing into the trusted zone.

Why this answer

A DMZ (demilitarized zone) is a segmented network that sits between the internet and the internal network, hosting public-facing servers while allowing controlled access from both sides.

255
MCQmedium

During a phishing investigation, a security analyst identifies that an employee clicked a malicious link. The analyst isolates the workstation. What is the NEXT best step?

A.Capture a memory image of the workstation for analysis
B.Update the company's acceptable use policy
C.Notify all employees about phishing risks
D.Reimage the workstation
AnswerA

Isolating the workstation preserves volatile evidence, but memory contents such as running processes and network connections are lost on shutdown or reboot. Capturing a memory image next secures that volatile data before any remediation or power-off destroys it.

Why this answer

After isolating the workstation, the next best step is to capture a memory image (RAM) to preserve volatile evidence such as running processes, network connections, and malware artifacts that would be lost on shutdown. This follows the order of volatility (RFC 3227) and is critical for forensic analysis to determine the scope of the compromise.

Exam trap

ISC2 often tests the order of volatility (RFC 3227) and the principle that volatile data (memory) must be captured before non-volatile data (disk), so the trap here is that candidates may choose to reimage the workstation immediately to 'clean' it, not realizing that destroys forensic evidence needed for attribution and prevention.

How to eliminate wrong answers

Option B is wrong because updating the acceptable use policy is a long-term administrative control, not an immediate incident response step; it does not preserve evidence or contain the threat. Option C is wrong because notifying all employees about phishing risks is a general awareness activity that should occur after the investigation, not before evidence is collected, and it could cause unnecessary panic or tip off an attacker. Option D is wrong because reimaging the workstation destroys all volatile and non-volatile evidence, making it impossible to perform a root-cause analysis or identify indicators of compromise (IOCs) that could prevent future incidents.

256
MCQmedium

An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?

A.The IPS is not receiving traffic due to a tap failure.
B.The IPS is placed behind the firewall instead of in front.
C.The IPS is configured in promiscuous mode.
D.The IPS signature set is too aggressive or includes false positives.
AnswerD

Inline IPS blocks traffic matching enabled signatures. If legitimate web traffic is dropped, the signature set is likely too aggressive or contains false positives, so tuning or disabling those signatures restores legitimate traffic while preserving genuine threat detection.

Why this answer

An inline IPS actively inspects and can block traffic based on its signature database. If the signature set is too aggressive or contains false positives, legitimate traffic matching those signatures will be incorrectly blocked. This is the most direct cause of blocking legitimate web traffic after deployment.

Exam trap

ISC2 often tests the distinction between inline and promiscuous modes, where candidates mistakenly think promiscuous mode can block traffic, but only inline mode allows active blocking.

How to eliminate wrong answers

Option A is wrong because a tap failure would cause the IPS to not receive traffic at all, resulting in no blocking (legitimate or otherwise), not the selective blocking of legitimate web traffic. Option B is wrong because placing the IPS behind the firewall does not inherently cause false positives; it affects traffic flow and security posture, but the blocking of legitimate traffic is a signature issue, not a placement issue. Option C is wrong because promiscuous mode means the IPS monitors traffic passively without being inline, so it cannot block traffic at all; blocking requires inline mode.

257
MCQmedium

During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?

A.The Security log, because object access auditing records file creation events there.
B.The Application log, because file operations are generated by applications writing to disk.
C.The Setup log, because it tracks changes to files installed by administrators.
D.The System log, because it records all file system changes performed by services and users.
AnswerA

When object access auditing is enabled, file creation and access events are written to the Windows Security log with event IDs such as 4663 and 4656, including the account name and object path. This makes the Security log the authoritative source for attribution of file operations. Reviewing it requires the appropriate audit policy and sufficient log retention.

Why this answer

Attribution of file activity requires object access auditing, which writes events to the Security log when enabled through audit policy. Those events include the account, object name, and access type, which directly answers who created the file and when. The System, Application, and Setup logs serve other purposes and do not capture user file operations, so they cannot provide the needed evidence.

Exam trap

The trap here is assuming that the System or Application log tracks all activity on the machine, when file-level attribution depends on object access auditing in the Security log.

258
MCQhard

A company's network uses a perimeter firewall and an internal firewall. The DMZ sits between them. A new application server needs to be accessible from the internet on TCP port 8443 and must be able to make outbound HTTPS connections to an external license server. Which firewall rules should be implemented? (Assume default deny)

A.Allow inbound from internet to server on 8443; allow outbound from server to internet on 443; allow inbound from internet to server on 443 for license server response
B.Allow inbound from internet to server on 8443; allow outbound from server to internet on 443 with stateful inspection
C.Allow inbound from internet to server on 8443; allow outbound from server to internet on 443
D.Allow inbound from internet to server on 8443 and 443; allow outbound from server to internet on any
AnswerB

Stateful inspection permits the server's outbound HTTPS session to the licence server and returns replies, while the inbound rule exposes only TCP 8443 from the internet. This satisfies both the public accessibility and outbound licensing requirements under default deny.

Why this answer

It allows inbound traffic on TCP 8443 to the server and outbound traffic on TCP 443 from the server to the internet. Stateful inspection automatically tracks the outbound HTTPS connection and permits the return traffic (the license server's response) without needing an explicit inbound rule. This matches the requirement while maintaining a default-deny posture.

Exam trap

ISC2 often tests the misconception that return traffic for outbound connections requires an explicit inbound allow rule, when in fact stateful inspection automatically permits the reply packets.

How to eliminate wrong answers

Option A is wrong because it adds an unnecessary explicit inbound rule for TCP 443 from the internet to the server for license server responses; stateful inspection handles return traffic automatically, and this rule would expose the server to unsolicited inbound connections on 443. Option C is wrong because it lacks stateful inspection; without stateful tracking, the firewall would drop the return packets from the license server, breaking the outbound HTTPS connection. Option D is wrong because it opens inbound ports 8443 and 443 (unnecessarily exposing the server) and allows outbound traffic on any port, violating the principle of least privilege and default-deny.

259
MCQmedium

An e-commerce company notices that its product reviews are being scraped by automated bots far more aggressively than expected, and the resulting traffic is degrading checkout performance for real customers. The security team wants a control that slows automated abuse without challenging legitimate buyers. Which security principle does this control primarily support?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerB

Availability ensures systems and data remain accessible to authorized users when needed. Rate limiting preserves checkout responsiveness for real customers by throttling bot traffic that would otherwise consume server capacity, directly protecting the ability of legitimate buyers to complete purchases. This is the primary principle at stake because the scenario is about sustained access to the storefront, not about keeping review data secret or unaltered.

Why this answer

The scenario centers on keeping the storefront usable for legitimate customers despite aggressive automated traffic. Rate limiting and similar anti-automation controls protect the ability of authorized users to reach and use the system, which is the definition of availability. Confidentiality, integrity, and non-repudiation address disclosure, modification, and proof of action respectively, none of which describes degraded checkout performance caused by resource consumption.

Exam trap

The trap here is assuming that blocking bots is always a confidentiality or integrity issue, when the observable harm in this scenario is loss of access for legitimate users.

260
MCQhard

An organization implements a role-based access control (RBAC) system. To maintain the principle of least privilege, what should the administrator do when a user changes roles?

A.Remove the previous role's access and assign the new role's access.
B.Keep all access and let the manager manually remove as needed.
C.Use a single role for all users to simplify management.
D.Add the new role's access while keeping the previous role's access.
AnswerA

This ensures the user has only the permissions needed for their new role, following least privilege.

261
MCQeasy

Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?

A.HTTP
B.TCP
C.IP
D.UDP
AnswerB

TCP establishes a connection via a three-way handshake and uses sequence numbers, acknowledgements and retransmissions to guarantee ordered, error-free delivery. This connection-oriented reliability at the Transport layer satisfies the stem's requirement, unlike connectionless UDP, which offers no delivery guarantees.

Why this answer

TCP provides reliable delivery via acknowledgments and retransmissions, and uses a three-way handshake to establish a connection. UDP is connectionless and unreliable.

262
MCQeasy

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

A.Risk Assessment
B.Business Impact Analysis
C.Vulnerability Assessment
D.Gap Analysis
AnswerB

A Business Impact Analysis identifies critical business functions and maps their dependencies, plus tolerable downtime and recovery priorities. It is performed first because its output — the RTO and RPO figures — drives every subsequent BCP and recovery strategy decision.

Why this answer

The Business Impact Analysis (BIA) is the foundational step in BCP development because it systematically identifies critical business functions, their dependencies, and the impact of their disruption over time. It quantifies the consequences of downtime, helping prioritize recovery objectives like RTO and RPO. Without a BIA, subsequent risk assessment and recovery strategies lack a business-driven focus.

Exam trap

The trap here is confusing the sequence of BCP steps: many candidates assume Risk Assessment comes first because it sounds like the starting point for security planning, but in BCP, the BIA must precede risk assessment to identify what is critical.

How to eliminate wrong answers

Option A is wrong because Risk Assessment identifies threats and vulnerabilities to assets, but it does not determine which business functions are critical or their dependencies; it typically follows the BIA. Option C is wrong because Vulnerability Assessment focuses on technical weaknesses in systems, not on business processes or their interdependencies. Option D is wrong because Gap Analysis compares current capabilities against desired recovery objectives, which can only be defined after a BIA has established those objectives.

263
MCQmedium

Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?

A.The retention policy deleted it
B.The schedule was incorrect
C.The backup source did not include that file
D.The encryption key changed
AnswerC

Successful backup logs only confirm the job ran; they do not prove the file was selected. If the backup source or selection list omitted that database file, no restore point exists, regardless of job status.

Why this answer

The backup log only records the success or failure of the backup job as a whole, not the inclusion of every individual file. If the database file was not selected in the backup source configuration (e.g., a file-level backup job that excluded the database directory or a volume shadow copy that did not include the file), the backup would complete successfully without backing up that file. When the administrator attempts to restore, the file is missing from the backup set, even though the job log shows success.

Exam trap

ISC2 often tests the misconception that a successful backup log guarantees all intended data was backed up, when in reality the backup source configuration determines what is actually captured.

How to eliminate wrong answers

Option A is wrong because a retention policy deletes backup sets after a specified period, but the question states the backup log shows success from two weeks ago, implying the backup set still exists; if the retention policy had deleted it, the restore would fail with a 'backup set not found' error, not a missing file error. Option B is wrong because an incorrect schedule would cause the backup to run at the wrong time or not run at all, but the log shows a successful backup, so the schedule executed correctly. Option D is wrong because an encryption key change would affect the ability to decrypt the backup data, not the presence of the file in the backup; the restore would fail with a decryption error, not a missing file error.

264
MCQeasy

Which authentication factor does a smart card represent?

A.Something you know
B.Something you have
C.Somewhere you are
D.Something you are
AnswerB

A smart card is a physical token the user possesses, so it satisfies the possession factor. Authentication factors split into something you know, have, or are; the card's stored certificate proves possession, not knowledge or inherence.

Why this answer

A smart card is a physical device that stores cryptographic keys or certificates, making it a classic 'something you have' factor. It requires possession of the card to authenticate, even if the user knows a PIN, because the PIN unlocks the card but does not replace the physical possession requirement.

Exam trap

ISC2 often tests the distinction between 'something you have' and 'something you know' by including a PIN as part of smart card usage, leading candidates to mistakenly classify it as 'something you know' instead of recognizing the card itself as the primary factor.

How to eliminate wrong answers

Option A is wrong because 'something you know' refers to knowledge-based factors like passwords or PINs, not a physical device. Option C is wrong because 'somewhere you are' is a location-based factor typically verified via GPS or IP geolocation, not a smart card. Option D is wrong because 'something you are' refers to biometric traits like fingerprints or iris scans, which are inherent to the user, not a separate physical token.

265
MCQeasy

A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?

A.3389
B.22
C.80
D.443
AnswerD

Port 443 carries HTTPS over TLS, satisfying the stem's requirement for inbound secure web traffic. The firewall must permit TCP 443 so clients can establish encrypted sessions with the web server; port 80 would only serve unencrypted HTTP. This directly matches the HTTPS constraint rather than any alternative service.

Why this answer

HTTPS (HTTP Secure) uses TLS/SSL encryption over TCP port 443 by default. To allow inbound HTTPS traffic to a web server, the firewall rule must permit TCP destination port 443. Port 80 is used for unencrypted HTTP, not HTTPS.

Exam trap

ISC2 often tests the distinction between HTTP (port 80) and HTTPS (port 443), and the trap here is that candidates confuse the two or assume HTTPS uses port 80 because both are web protocols.

How to eliminate wrong answers

Option A is wrong because port 3389 is used by Remote Desktop Protocol (RDP) for remote desktop access, not for web traffic. Option B is wrong because port 22 is used by SSH for secure remote administration, not for HTTPS. Option C is wrong because port 80 is used for HTTP (unencrypted web traffic), not HTTPS; HTTPS requires TLS encryption on port 443.

266
MCQhard

A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Defense in depth
AnswerA

Granting full financial database access to a user who only views quarterly reports exceeds their job requirements. Least privilege requires granting only the minimum access needed for assigned duties, so this excessive entitlement violates that principle most directly.

Why this answer

Least privilege requires granting only the minimum permissions necessary to perform job functions.

267
MCQhard

A Privileged Access Management (PAM) solution is used to:

A.Control and monitor privileged accounts and sessions
B.Encrypt data at rest
C.Manage user passwords and enforce complexity
D.Provide single sign-on for all applications
AnswerA

PAM brokers access to privileged credentials, vaulting them and injecting sessions through a controlled jump host. This delivers both control (least privilege, approval workflows, credential rotation) and monitoring (keystroke and command logging), satisfying the requirement to govern administrative accounts rather than ordinary user identities.

Why this answer

PAM solutions control, monitor, and audit privileged access to critical systems.

268
Multi-Selecteasy

A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?

Select 2 answers
A.Disable the user account immediately.
B.Escalate to the incident response team.
C.Investigate the source IP address for malicious activity.
D.Block the IP address at the firewall.
E.Reset the password for the affected account.
AnswersB, C

A successful login after many failures suggests a breached account, so the incident response team must be engaged to contain and investigate. Escalation satisfies the scenario's requirement to act on probable credential compromise rather than treating it as routine noise.

Why this answer

Option B is correct because a failed-login-then-success pattern is a classic indicator of a brute-force or credential-stuffing compromise, which is a security incident that must be escalated to the incident response team for containment, eradication, and forensic analysis. Option C is correct because the analyst must investigate the source IP address (e.g., via WHOIS, threat-intel reputation lookups, or checking it against known IoC feeds) to determine whether it is a known malicious host, a compromised internal system, or part of a botnet before deciding on further containment. Option A is not the best next step because disabling the account before confirming compromise could disrupt a legitimate user and destroy forensic evidence; account lockout/disable is a containment action taken after validation.

Option D is also premature, since blocking the IP at the firewall without investigation could block a legitimate proxy, NAT gateway, or shared egress point and does not address the already-successful login. Option E is not appropriate yet because resetting the password before confirming the compromise and scoping the incident could tip off the attacker and erase useful artifacts; password reset is a remediation step performed after escalation and investigation.

Exam trap

The trap is jumping to containment actions like disabling the account or blocking the IP without first escalating and investigating, which could lead to incomplete remediation or business disruption.

269
MCQmedium

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

A.Type 3 – Inherence factor
B.Multi-factor authentication
C.Type 2 – Possession factor
D.Type 1 – Knowledge factor
AnswerA

Type 3 authentication verifies something the user is, through inherence factors such as fingerprints, iris patterns or facial geometry. The stem explicitly requires something the user 'is', ruling out Type 1 (knowledge) and Type 2 (ownership) factors. Biometrics therefore satisfy the high-security facility's requirement.

Why this answer

Type 3 – Inherence factor refers to something the user 'is', i.e., a biometric characteristic such as fingerprint, retina, or iris. The requirement explicitly states 'something the user is', which directly maps to inherence. Therefore, Type 3 is the correct authentication type.

Exam trap

CC often tests the distinction between authentication factor types (knowledge, possession, inherence) and multi-factor authentication, so candidates may mistakenly choose 'multi-factor authentication' when the question asks for a specific factor type.

How to eliminate wrong answers

Option B is wrong because multi-factor authentication combines two or more different factor types (knowledge, possession, inherence) and is not a single factor type. Option C is wrong because Type 2 – Possession factor refers to something the user 'has', such as a smart card or token. Option D is wrong because Type 1 – Knowledge factor refers to something the user 'knows', such as a password or PIN.

270
MCQeasy

A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?

A.Detective
B.Preventive
C.Compensating
D.Corrective
AnswerB

A preventive control stops an unwanted event before it occurs. Automatically disabling accounts on the last working day prevents the former employee from authenticating at all, closing off the possibility of unauthorized access. Because the control acts in advance of any attempted misuse, it is preventive in nature, even though it also supports other goals such as audit compliance.

Why this answer

Automated account deactivation on the last working day stops unauthorized access before it can happen, which defines a preventive control. Detective controls would only reveal misuse after the fact, corrective controls would remediate damage already done, and compensating controls are alternate measures when a primary control is not feasible. Since the control blocks the event itself, preventive is the correct classification.

Exam trap

The trap here is confusing timely deprovisioning with detective monitoring, when the control's defining feature is that it blocks access before any attempt occurs.

271
MCQmedium

A company's security policy mandates that all changes to the firewall configuration must be approved by two different administrators before implementation. This is an example of which security principle?

A.Defense in depth
B.Need to know
C.Separation of duties
D.Least privilege
AnswerC

Requiring two different administrators to approve each firewall change splits authority over one sensitive action, preventing any single person from both authoring and authorising it. That division of duties is precisely the separation of duties principle.

Why this answer

The requirement for two different administrators to approve firewall configuration changes enforces separation of duties. This principle ensures that no single individual has the authority to make unilateral changes, reducing the risk of unauthorized or malicious modifications. In firewall management, this prevents a single admin from bypassing security controls or introducing backdoors without oversight.

Exam trap

ISC2 often tests separation of duties by presenting scenarios that involve dual approval or task division, and the trap here is confusing it with least privilege, as both limit individual power but least privilege focuses on permissions scope rather than collaborative authorization.

How to eliminate wrong answers

Option A is wrong because defense in depth involves multiple layers of security controls (e.g., firewall, IDS, encryption) to protect assets, not administrative approval workflows. Option B is wrong because need to know restricts access to information based on job requirements, not the authorization process for changes. Option D is wrong because least privilege limits users to the minimum permissions necessary for their role, but does not inherently require dual approval for actions; separation of duties specifically addresses the division of critical tasks among multiple individuals.

272
MCQhard

An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?

A.Need-to-know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerB

Layering fencing, badge readers, biometrics and cable locks creates successive independent barriers, so defeating one control still leaves others. This matches defence in depth, which the stem's layered approach exemplifies, rather than single-mechanism concepts such as least privilege or separation of duties.

Why this answer

Defense in depth is the practice of layering multiple independent security controls so that if one fails, others continue to protect the asset. The scenario describes physical controls at progressively deeper levels — perimeter fencing, badge readers at entrances, biometric scanners in server rooms, and cable locks on laptops — each adding a distinct barrier. This layered approach is the textbook definition of defense in depth.

Exam trap

The trap here is confusing defense in depth with least privilege or need-to-know, since all three involve restricting access — but only defense in depth describes layering multiple independent controls.

How to eliminate wrong answers

Option A is wrong because need-to-know is an information access principle that restricts data to individuals whose job requires it, and it does not describe physical barriers like fences or cable locks. Option C is wrong because least privilege refers to granting users only the minimum permissions necessary to perform their job functions, which is an authorization concept rather than a layered physical security strategy. Option D is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error, which is unrelated to the physical security layers described.

273
MCQmedium

An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?

A.Separation of duties
B.Defense in depth
C.Need to know
D.Least privilege
AnswerA

Separation of duties splits a sensitive transaction across two distinct approvers, so no single manager can authorise a payment alone. Requiring two different managers for transactions above $10,000 directly enforces this principle by preventing unilateral action and creating mutual oversight.

Why this answer

Separation of duties ensures that no single individual has complete control over a critical action, reducing the risk of fraud or error.

274
MCQeasy

A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?

A.Establishing identification of the nurse to the access control system
B.Preventing tailgating by allowing only one person to pass at a time
C.Providing non-repudiation of the nurse's badge transaction
D.Enforcing least privilege for staff entering the data center
AnswerB

A mantrap uses interlocked doors so the second door cannot open until the first is secured, and typically only one person fits in the vestibule. This physically separates individuals, defeating the common practice of an unauthorized person following an authorized badge holder through a single door. That is precisely the anti-tailgating function the scenario describes.

Why this answer

The interlocked-door vestibule is a classic anti-tailgating control: it forces a one-person-at-a-time transition between security zones so an unauthorized individual cannot slip in behind an authorized badge holder. The nurse's badge handles identification and authentication; the mantrap's distinct contribution is preventing piggybacking through the doorway.

Exam trap

The trap here is assuming any physical entry control automatically enforces least privilege rather than recognizing the mantrap's specific role in stopping tailgating.

275
MCQmedium

A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?

A.VLAN
B.DMZ
C.Honeypot
D.Subnet
AnswerB

A DMZ is a perimeter subnetwork exposing public-facing services such as web and email servers to the internet while firewall rules block direct access to the internal LAN, limiting exposure if those hosts are compromised.

Why this answer

A DMZ (demilitarized zone) is a perimeter network segment that hosts internet-facing services such as web and email servers while keeping them isolated from the trusted internal LAN. It creates a buffer zone so that if a public-facing server is compromised, the attacker cannot directly pivot into internal systems. This matches the scenario exactly: internet-accessible but separated from the internal network.

Exam trap

The trap here is confusing a DMZ with a generic subnet or VLAN — candidates pick 'subnet' because a DMZ is technically implemented as one, but the question is testing the security concept of an isolated internet-facing buffer zone, not the addressing construct.

How to eliminate wrong answers

Option A is wrong because a VLAN is a Layer 2 logical segmentation mechanism for grouping devices within a switched network — it does not by itself define an internet-facing isolated zone with firewall-enforced separation from the LAN. Option C is wrong because a honeypot is a decoy system designed to lure and observe attackers, not to host production web and email services. Option D is wrong because a subnet is simply an IP addressing subdivision (a Layer 3 range); while a DMZ is often implemented as a subnet, 'subnet' alone does not convey the security isolation and internet-facing purpose described.

276
Multi-Selecthard

An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)

Select 3 answers
A.Restoring data from backups
B.Notifying law enforcement
C.Conducting tabletop exercises
D.Acquiring forensic analysis tools
E.Creating an incident response team
AnswersC, D, E

Tabletop exercises rehearse the plan against simulated scenarios, exposing gaps in roles, escalation paths and communications before a real incident. This validates readiness during preparation, satisfying the requirement to test and refine response capabilities rather than improvise them live.

Why this answer

Option C (Conducting tabletop exercises) is correct because tabletop exercises are a preparation-phase activity that validates and rehearses the incident response plan, roles, and communication paths before a real incident occurs. Option D (Acquiring forensic analysis tools) is correct because procuring and maintaining forensic toolkits (e.g., disk imaging, memory capture, and analysis utilities) is part of building the resources and capabilities needed during preparation. Option E (Creating an incident response team) is correct because establishing the CSIRT/IR team, defining its roles, and assigning responsibilities is a foundational preparation-phase element.

Option A (Restoring data from backups) belongs to the recovery/eradication-and-recovery phase, since restoration happens after containment and eradication, not during preparation. Option B (Notifying law enforcement) is a coordination/communication action taken during or after detection and response, not a preparation-phase element.

277
MCQhard

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

A.NIDS
B.HIDS
C.WAF
D.IPS
AnswerC

A Web Application Firewall inspects HTTP and HTTPS request content, applying signatures and rules to detect and block injection, cross-site scripting and similar attacks. Network firewalls filter by port and address only, so they cannot inspect application-layer payloads.

Why this answer

A Web Application Firewall (WAF) operates at Layer 7 and inspects HTTP/HTTPS requests specifically to detect and block web application attacks such as SQL injection, XSS, and malicious payloads. It is purpose-built to understand HTTP semantics (headers, cookies, parameters, body) and apply rules like OWASP ModSecurity Core Rule Set. This directly matches the requirement to prevent malicious HTTP requests targeting a web application.

Exam trap

The trap is conflating a general-purpose IPS with a WAF — candidates pick IPS because it 'prevents' attacks, but the question specifically targets HTTP application-layer protection, which is the WAF's specialized domain.

How to eliminate wrong answers

Option A is wrong because a NIDS (Network Intrusion Detection System) monitors network traffic for suspicious patterns but is passive/detection-oriented and does not specifically parse HTTP to block web application attacks — and it's an IDS, not a prevention device. Option B is wrong because a HIDS (Host Intrusion Detection System) monitors host-level activity (file integrity, logs, processes) on a server, not HTTP request content at the application layer. Option D is wrong because an IPS (Intrusion Prevention System) is a broader network-layer prevention device; while some IPS products include web attack signatures, a WAF is the device specifically designed for HTTP application-layer protection, and the question asks for the device 'specifically designed' for this purpose.

278
MCQmedium

A small company with 50 employees uses a flat network with no VLANs. They recently experienced a ransomware attack that spread from an infected workstation to a file server. The IT manager wants to implement network segmentation to prevent future lateral movement. The company uses a single /24 subnet (192.168.1.0/24) with a single switch and a router/firewall. They have three departments: Sales, HR, and IT. Each department has about 15-20 computers. The file server is in the IT department. The company has a limited budget and cannot purchase new hardware. Which of the following is the MOST effective and practical approach to segment the network given these constraints?

A.Replace the switch with three separate physical switches, each connected to a separate router interface.
B.Create three VLANs on the switch, one for each department, and configure ACLs on the router to allow only necessary inter-VLAN traffic.
C.Implement MAC address filtering on the switch to only allow authorized devices to communicate with the file server.
D.Install a software firewall on each workstation to block traffic from other subnets.
AnswerB

VLANs logically separate traffic, and ACLs enforce policy; uses existing hardware if the switch supports VLANs (most do).

Why this answer

Creating three VLANs on the existing switch segments the flat /24 network into separate broadcast domains, preventing lateral movement by default. Configuring ACLs on the router allows only necessary inter-VLAN traffic (e.g., Sales and HR can access the file server in IT), which stops the ransomware from spreading across departments without requiring new hardware.

Exam trap

ISC2 often tests the misconception that physical separation (Option A) is always required for segmentation, when in fact VLANs provide logical separation at no extra cost, and that MAC filtering (Option C) or host-based firewalls (Option D) can substitute for network-level segmentation, which they cannot because they fail to isolate broadcast domains or prevent Layer 2 attacks.

How to eliminate wrong answers

Option A is wrong because replacing the switch with three separate physical switches violates the budget constraint (no new hardware) and would require additional router interfaces or subinterfaces, which is more expensive and less practical than using VLANs. Option C is wrong because MAC address filtering only controls which devices can communicate with the file server at Layer 2, but it does not segment the network; all devices remain in the same broadcast domain, so ransomware can still spread laterally via ARP spoofing or broadcast-based attacks. Option D is wrong because installing a software firewall on each workstation is impractical to manage across 50 machines, does not prevent Layer 2 lateral movement within the same subnet, and adds no segmentation at the network level—traffic between departments still traverses the flat network without restriction.

279
MCQmedium

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

A.Recovery
B.Detection
C.Containment
D.Eradication
AnswerC

Isolation halts the malware's spread and external communication while the environment is still compromised, which is the containment phase's defining action. It sits between detection and eradication, satisfying the stem's need to stop ongoing impact before recovery begins.

Why this answer

Isolating the server is a containment action to prevent spread.

280
MCQhard

A company's security policy states that sensitive data must be encrypted using AES-256. During an audit, it is found that some data is encrypted with AES-128. Which security objective is most directly compromised?

A.Integrity
B.Availability
C.Confidentiality
D.Non-repudiation
AnswerC

AES-128 still provides confidentiality, but the policy mandates AES-256 specifically. The compromised objective is compliance with the stated cryptographic standard, not confidentiality itself. Since the question asks which security objective is most directly affected, weaker-than-mandated encryption weakens the assurance level the policy requires, making confidentiality the closest fit.

Why this answer

AES-256 offers a higher security margin than AES-128. Using weaker encryption (AES-128) directly reduces the confidentiality protection, making it easier for an attacker to decrypt the data.

281
MCQeasy

What is the primary purpose of a Security Information and Event Management (SIEM) system?

A.Encrypt sensitive data at rest
B.Manage user passwords and access controls
C.Aggregate and correlate logs to generate alerts
D.Block malicious network traffic in real time
AnswerC

A SIEM collects log and event data from across the estate, then correlates it to detect patterns indicating incidents and raises alerts. This aggregation and correlation capability is its primary purpose, satisfying the stem's requirement.

Why this answer

A SIEM's core function is to aggregate log and event data from many sources, normalize it, and correlate events across systems to detect and alert on security incidents. Correlation is what distinguishes a SIEM from simple log collection — it identifies patterns spanning multiple events that individually look benign.

Exam trap

The trap here is confusing SIEM (detect and alert via correlation) with tools that block or encrypt — candidates pick 'block malicious traffic' because they conflate SIEM with IPS/firewall.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest is handled by disk encryption, key management, or database encryption features — not by a SIEM. Option B is wrong because password and access control management is the domain of IAM, PAM, or directory services, not SIEM. Option D is wrong because blocking malicious traffic in real time is the function of firewalls, IPS, or EDR — a SIEM detects and alerts, it does not sit inline to block traffic.

282
Multi-Selecteasy

Which TWO are examples of logical access controls? (Select TWO.)

Select 2 answers
A.Fencing around the property
B.Password complexity requirements
C.Guard at building entrance
D.Biometric door lock
E.Account lockout policy
AnswersB, E

Password complexity requirements are a logical access control because they govern authentication through software-enforced rules on the credential itself, restricting who can gain system access. No physical barrier is involved, satisfying the question's requirement for a logical, rather than physical, control.

Why this answer

Password complexity requirements (B) are a logical access control because they are enforced in software by the operating system or directory service (e.g., via Group Policy password policy or /etc/security/pwquality.conf) to govern how a user authenticates, not to physically restrict movement. Account lockout policy (E) is likewise logical: it is a software-enforced setting that disables an account after a defined number of failed logon attempts within a set window, mitigating brute-force attacks against the authentication process. Both operate on the logical layer of identity and authentication rather than on physical barriers.

By contrast, fencing around the property (A), a guard at the building entrance (C), and a biometric door lock (D) are physical access controls, since they restrict who can physically enter a location or structure.

Exam trap

CC often tests the confusion between physical and logical controls by including biometrics, which can be either depending on context — the trap is assuming biometrics is always logical when the scenario describes a door lock.

283
MCQmedium

A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerC

Detection and Analysis is the phase where monitoring tools, alerts, and staff identify that an incident is occurring and determine its scope. A 36-hour gap between the start of the ransomware attack and its discovery is a direct failure of this phase. The organization did not detect the unauthorized encryption activity in a timely manner, delaying the entire response effort.

Why this answer

The 36-hour gap between the onset of the ransomware attack and its discovery points directly to a failure in the Detection and Analysis phase, where monitoring and alerting should identify malicious activity quickly. While preparation, containment, and post-incident review all matter, the scenario describes a delay in recognizing the incident, which is the defining activity of detection and analysis. Improving detection capabilities would most directly address this gap.

Exam trap

The trap here is assuming that a slow response is always a containment failure, when the scenario actually describes a delay in noticing the incident, which belongs to Detection and Analysis.

284
MCQeasy

A security administrator notices that an employee is able to access files in a project folder they should not have access to. Which security principle is being violated?

A.Least privilege
B.Non-repudiation
C.Separation of duties
D.Defense in depth
AnswerA

Least privilege grants users only the access required for their role. The employee reaching files outside their project folder shows permissions exceeding that minimum, so the principle is breached regardless of whether the access was intentional.

Why this answer

The scenario describes an employee accessing files they should not have access to, which directly violates the principle of least privilege. This principle mandates that users and processes should be granted only the minimum permissions necessary to perform their job functions. The administrator's observation indicates that the employee's access rights exceed what is required, leading to unauthorized file access.

Exam trap

ISC2 often tests least privilege by presenting a scenario where a user has more access than needed, and candidates may confuse it with separation of duties because both involve access control, but the key distinction is that least privilege focuses on the level of access per user, while separation of duties focuses on dividing responsibilities among multiple users.

How to eliminate wrong answers

Option B is wrong because non-repudiation ensures that a party cannot deny the authenticity of their actions (e.g., via digital signatures or audit logs), but it does not address the assignment or restriction of access permissions. Option C is wrong because separation of duties divides critical tasks among multiple individuals to prevent fraud or error (e.g., one person requests access, another approves), but the issue here is excessive permissions for a single user, not a lack of task division. Option D is wrong because defense in depth is a layered security strategy (e.g., firewalls, IDS, encryption) that provides multiple controls, but it does not specifically govern the granularity of user permissions; the violation is about over-provisioned access, not insufficient layers.

285
MCQmedium

A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?

A.24 hours
B.48 hours
C.72 hours
D.7 days
AnswerC

72 hours is the maximum period under GDPR Article 33(1) for notifying a supervisory authority of a personal data breach, counted from awareness. This satisfies the stem's PHI breach scenario, since the regulation sets a single deadline regardless of sector; healthcare organisations must also document the breach internally.

Why this answer

Under GDPR Article 33, a controller must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. PHI constitutes personal data under GDPR, so the 72-hour clock applies. This deadline is a maximum; notification should occur as soon as possible within that window.

Exam trap

The trap here is confusing GDPR's 72-hour supervisory authority notification with other breach-notification timelines (such as 24 hours under some sectoral rules or 30/60 days under HIPAA), causing candidates to select a shorter or longer window than Article 33 actually specifies.

How to eliminate wrong answers

Option A is wrong because 24 hours is the notification window used by some other regimes (e.g., certain NIS2 sectoral rules) and is not the GDPR Article 33 deadline. Option B is wrong because 48 hours has no basis in GDPR breach notification provisions. Option D is wrong because 7 days is far too long and does not correspond to any GDPR notification timeline; GDPR requires 72 hours, and data subjects must be notified without undue delay when high risk exists.

286
MCQhard

A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?

A.Immediately restore the most recent full backup to the primary data center.
B.Rebuild the primary data center from scratch using the original installation media.
C.Notify all customers about the data breach and provide credit monitoring services.
D.Validate that the most recent backups are free from malware and can be restored.
AnswerD

Before restoring any data, the recovery team must ensure that the backups are not compromised. Ransomware often attempts to encrypt or delete backups, and restoring an infected backup could reintroduce the malware. Validating the integrity and cleanliness of backups is a critical first step to prevent reinfection. This aligns with incident response best practices, which emphasize verifying the trustworthiness of recovery sources before initiating restoration.

Why this answer

In a ransomware recovery scenario, the first step is to ensure that backups are clean and restorable. Ransomware often targets backups, so validating their integrity prevents restoring malicious code. Once backups are verified, the team can proceed with restoration.

This approach aligns with the incident response principle of containing and eradicating the threat before recovery. Skipping validation risks reinfection and further downtime.

Exam trap

The trap here is prioritizing speed over security by immediately restoring backups without first verifying they are malware-free.

287
MCQeasy

Which data classification level typically requires the highest level of protection?

A.Internal
B.Confidential
C.Top secret
D.Public
AnswerC

Top secret is the highest classification tier, so it mandates the strongest controls: strict need-to-know access, enhanced encryption, and rigorous handling procedures. Lower tiers such as confidential or internal permit weaker safeguards, so this level satisfies the stem's requirement for maximum protection.

Why this answer

Top secret is the highest classification and requires strict controls.

288
MCQeasy

A network administrator notices unusual traffic from an internal workstation to an external IP address on port 443. The workstation has no business reason for such communication. Which action should the administrator take first?

A.Disable the workstation's network port.
B.Block all outbound traffic from that workstation immediately.
C.Investigate the workstation for possible malware.
D.Configure a firewall rule to allow the traffic and log it.
AnswerC

Unusual outbound port 443 traffic from a workstation with no business justification suggests command-and-control or exfiltration activity. Investigating the host for malware establishes the cause before containment, satisfying the requirement to act first on a suspected compromised endpoint.

Why this answer

The first priority when encountering unexpected outbound traffic to an external IP on port 443 (HTTPS) is to investigate the workstation for possible malware. This traffic could indicate a command-and-control (C2) beacon or data exfiltration, and immediate investigation allows the administrator to gather forensic evidence before taking disruptive actions. Disabling the port or blocking traffic without investigation could destroy evidence or alert an attacker, while allowing the traffic would be negligent.

Exam trap

ISC2 often tests the principle of 'investigate before acting' to avoid destroying evidence, and the trap here is that candidates may choose a reactive security measure (like blocking or disabling) instead of following proper incident response procedures.

How to eliminate wrong answers

Option A is wrong because disabling the network port immediately may destroy volatile evidence (e.g., active network connections, running processes) and could alert an attacker if malware is present, preventing further forensic analysis. Option B is wrong because blocking all outbound traffic without investigation is overly disruptive and may also destroy evidence; a more targeted approach (e.g., using ACLs to log but not block) is preferred initially. Option D is wrong because configuring a firewall rule to allow the traffic and log it would permit potentially malicious communication to continue, increasing risk of data exfiltration or further compromise, and is not a secure first step.

289
MCQmedium

A financial services firm is classifying a risk by estimating how often a particular attack is likely to succeed in a given year. Which risk concept is the firm measuring?

A.Residual risk
B.Annualized loss expectancy (ALE)
C.Risk likelihood
D.Risk impact
AnswerC

Risk likelihood is the probability or frequency that a threat will exploit a vulnerability and cause harm within a defined period. By estimating how often an attack is likely to succeed in a year, the firm is directly quantifying likelihood, which is one of the two core dimensions of risk alongside impact. This estimate then feeds into risk analysis and prioritization, making it the concept the firm is measuring.

Why this answer

Risk combines the likelihood that a threat exploits a vulnerability with the impact if it does. The firm is estimating how often an attack succeeds per year, which is precisely the likelihood dimension. Annualized loss expectancy and impact deal with cost or severity, while residual risk refers to what remains after controls are applied, so likelihood is the concept being quantified.

Exam trap

The trap here is confusing the frequency of an event with its financial consequence, so that any risk term involving loss amounts is selected instead of the probability being estimated.

290
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)

Select 2 answers
A.Firewall logs
B.Patch management logs
C.Proxy logs
D.System logs
E.Authentication logs
AnswersA, C

Firewall logs capture allowed and denied connections with source and destination IP addresses, ports and byte counts, revealing large or anomalous outbound flows to external hosts. This satisfies the exfiltration scenario by exposing volume and destination of egress traffic crossing the network perimeter.

Why this answer

Firewall logs (A) are correct because they record allowed and denied connections with source/destination IP addresses, ports, and byte/packet counts, letting the analyst spot large or anomalous outbound transfers to external hosts. Proxy logs (C) are correct because they capture HTTP/HTTPS requests, URLs, user agents, and often the volume of data uploaded or downloaded, which is essential for identifying web-based exfiltration channels. Patch management logs (B) only track software update deployment and compliance, so they reveal nothing about network data flows.

System logs (D) contain OS, service, and application events but generally lack the destination and transfer-volume detail needed to confirm outbound exfiltration. Authentication logs (E) show logon, logoff, and failed-access events, which help with account compromise analysis but not with tracing data leaving the network.

Exam trap

The trap here is confusing 'system logs' or 'authentication logs' with network visibility — candidates pick them because they sound security-relevant, but only firewall and proxy logs actually show outbound data flows.

291
MCQeasy

Which concept ensures that a user cannot deny having performed a specific action?

A.Non-repudiation
B.Availability
C.Integrity
D.Authorization
AnswerA

Non-repudiation provides cryptographic proof of origin and integrity, binding a user to an action through digital signatures or audit trails. This satisfies the stem's requirement that a user cannot later deny performing a specific action, as the evidence is verifiable and tamper-evident.

Why this answer

Non-repudiation ensures that a user cannot deny having performed a specific action, typically by using cryptographic mechanisms such as digital signatures or audit logs. In the context of the CC exam, this is most commonly achieved through public key infrastructure (PKI) where a private key signs an action, and the corresponding public key verifies the signature, providing irrefutable proof of origin. This prevents a user from later claiming they did not send a message or perform a transaction.

Exam trap

ISC2 often tests the confusion between non-repudiation and integrity, where candidates mistakenly think that ensuring data hasn't changed (integrity) also proves who changed it, but non-repudiation specifically requires a binding identity proof like a digital signature.

How to eliminate wrong answers

Option B (Availability) is wrong because it ensures that systems and data are accessible when needed, often through redundancy and fault tolerance, not by preventing denial of actions. Option C (Integrity) is wrong because it guarantees that data has not been altered or tampered with, typically via hashing or checksums, but does not provide proof of who performed an action. Option D (Authorization) is wrong because it controls what resources a user can access or what actions they can perform, based on policies or permissions, but does not create an irrefutable record of those actions.

292
Multi-Selecthard

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Select 3 answers
A.Customer personally identifiable information (PII)
B.Public company press releases
C.Financial records and projections
D.Trade secrets and intellectual property
E.Marketing brochures
AnswersA, C, D

Customer PII uniquely identifies individuals and, if disclosed, enables identity theft and triggers breach-notification and privacy-law duties. That harm potential places it at Confidential or higher, satisfying the policy's requirement to protect data whose exposure causes legal, financial or reputational damage to individuals and the organisation.

Why this answer

Option A (customer PII) is correct because personally identifiable information is regulated by laws such as GDPR and CCPA and its exposure can cause identity theft, so it must be classified Confidential or higher. Option C (financial records and projections) is correct because unaudited financials, forecasts, and internal accounting data are material non-public information whose disclosure can harm the organization or violate securities regulations. Option D (trade secrets and intellectual property) is correct because trade secrets derive their value from secrecy, and unauthorized disclosure destroys legal protection and competitive advantage.

Option B (public company press releases) is not correct because press releases are intentionally published for public consumption and are therefore Public. Option E (marketing brochures) is not correct because marketing brochures are distributed externally to promote products and contain no sensitive data, making them Public as well.

Exam trap

The trap here is confusing 'internal use' with 'confidential' — candidates assume anything not published externally is automatically Confidential, but only data whose disclosure causes harm (PII, financials, IP) qualifies.

293
MCQeasy

A security operations center receives an alert that a workstation has been infected with ransomware. The infection is isolated to one machine. What is the first step in the containment phase of incident response?

A.Restore the workstation from a recent backup
B.Disconnect the workstation from the network
C.Reboot the workstation in safe mode
D.Run a full antivirus scan
AnswerB

Disconnecting the workstation from the network immediately severs the ransomware's command-and-control channel and blocks lateral movement to shared drives or other hosts, satisfying the stem's requirement to contain an infection isolated to one machine before eradication or recovery begins.

Why this answer

The first step in the containment phase is to disconnect the workstation from the network. This immediately stops the ransomware from spreading laterally to other systems via SMB, RDP, or other network protocols. Containment prioritizes preventing further damage over remediation or analysis.

Exam trap

ISC2 often tests the distinction between containment and eradication/recovery phases, and the trap here is that candidates mistake a recovery action (restore from backup) or a detection action (antivirus scan) for the first containment step.

How to eliminate wrong answers

Option A is wrong because restoring from backup is a recovery-phase action, not a containment step; attempting recovery before containment risks re-infection if the ransomware is still active on the network. Option C is wrong because rebooting in safe mode may allow the ransomware to execute its payload during startup or trigger persistence mechanisms, and it does not stop network-based propagation. Option D is wrong because running a full antivirus scan is a detection/eradication step that can take significant time, during which the ransomware could encrypt additional shares or spread to other hosts.

294
Multi-Selectmedium

A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)

Select 2 answers
A./var/log/kern.log
B./var/log/syslog
C./var/log/secure
D./var/log/auth.log
E./var/log/dpkg.log
AnswersC, D

On Red Hat-based Linux distributions, /var/log/secure serves the same purpose as /var/log/auth.log on Debian-based systems. It records authentication and security-related events, including failed logins and sudo usage. Monitoring this file is critical for detecting unauthorized access attempts on those systems. It is a primary source for security auditing.

Why this answer

On Linux systems, authentication events are logged in /var/log/auth.log (Debian-based) or /var/log/secure (Red Hat-based). These files record failed and successful login attempts, sudo usage, and SSH access, making them critical for detecting unauthorized access. Other logs like syslog, kern.log, or dpkg.log serve different purposes and are less directly relevant to access attempts.

Exam trap

The trap here is assuming that syslog contains all security events, but authentication logs are specifically separated into auth.log or secure depending on the distribution.

295
MCQmedium

A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?

A.Separation of duties
B.Defense in depth
C.Need-to-know
D.Least privilege
AnswerD

Default-deny firewall rules permit only explicitly required services, embodying least privilege by granting the minimum access necessary. This satisfies the stem's constraint of blocking all inbound traffic except specific necessary services, rather than relying on implicit trust.

Why this answer

Blocking all inbound traffic except explicitly required services is the definition of least privilege applied to network access control — granting only the minimum access necessary for business function. The firewall default-deny with specific allow rules embodies this principle by minimizing the attack surface.

Exam trap

CC often tests the confusion between least privilege (minimum necessary access) and defense in depth (layered controls) — candidates pick 'defense in depth' whenever a firewall is mentioned, even when the scenario is about minimizing allowed access.

How to eliminate wrong answers

Option A is wrong because separation of duties is an administrative control that divides critical tasks among different people to prevent fraud or error, not a network traffic filtering concept. Option B is wrong because defense in depth means layering multiple independent controls (firewall, IDS, endpoint, MFA); the scenario describes a single filtering philosophy, not layered defenses. Option C is wrong because need-to-know governs access to information based on job relevance, typically for data classification, not which network services are permitted through a firewall.

296
Multi-Selectmedium

Which three of the following are best practices for securing a network switch? (Choose three.)

Select 3 answers
A.Enable Telnet for remote management.
B.Disable unused ports.
C.Use VLANs to segment traffic.
D.Enable STP protection features like BPDU guard.
E.Set all ports to trunk mode by default.
AnswersB, C, D

Reduces attack surface.

Why this answer

Disabling unused ports on a network switch prevents unauthorized physical access and eliminates the risk of an attacker connecting to an open port to launch attacks such as ARP spoofing or DHCP starvation. This is a fundamental security best practice that reduces the attack surface by ensuring that only necessary ports are active and can be administratively controlled.

Exam trap

ISC2 often tests the misconception that Telnet is acceptable for management if a password is set, but the exam expects you to recognize that Telnet lacks encryption and is therefore never a best practice for securing a switch.

297
MCQmedium

After a reorganization, a company using RBAC finds that many users have accumulated permissions that no longer align with their job functions. What is the best practice to address this?

A.Assign permissions directly to each user based on their manager's request
B.Create new roles for each new position and assign users to them
C.Conduct a quarterly review and recertification of role memberships and permissions
D.Delete all existing permissions and re-add them based on current job descriptions
AnswerC

Scheduled recertification forces role owners to confirm each membership and permission remains justified, stripping entitlements left over from previous job functions. This directly addresses accumulated drift after reorganisation, which RBAC alone cannot prevent once assignments persist.

Why this answer

Conducting a quarterly review and recertification of role memberships and permissions is the industry-standard practice for maintaining the principle of least privilege in an RBAC system. This process ensures that role assignments are periodically validated against current job functions, removing accumulated permissions that no longer align with user responsibilities. It directly addresses permission creep by enforcing a formal, auditable lifecycle for role membership.

Exam trap

ISC2 often tests the misconception that a one-time cleanup (Option D) or ad-hoc direct assignments (Option A) are sufficient, when the real requirement is a continuous, auditable recertification process to maintain least privilege over time.

How to eliminate wrong answers

Option A is wrong because assigning permissions directly to each user bypasses the RBAC model entirely, leading to user-specific permission assignments that are difficult to audit, manage, and revoke, which exacerbates permission creep rather than resolving it. Option B is wrong because creating new roles for each new position without reviewing existing roles leads to role explosion, increasing administrative overhead and making the RBAC model less scalable and harder to maintain. Option D is wrong because deleting all existing permissions and re-adding them based on current job descriptions is a disruptive, high-risk approach that can cause immediate access outages and does not provide a sustainable, recurring process for managing role membership changes.

298
MCQmedium

A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?

A.Cross-site scripting (XSS)
B.SQL injection
C.Business email compromise (BEC)
D.Distributed denial-of-service (DDoS) attack
AnswerC

The scenario describes a spoofed executive identity, an urgent financial request, and a newly registered look-alike domain. These are hallmarks of business email compromise, where attackers impersonate executives to trick employees into transferring funds or revealing sensitive data. The message passing authentication checks suggests the attacker may have compromised a legitimate account or used a carefully crafted domain that bypasses some filters.

Why this answer

Business email compromise (BEC) is a social engineering attack where cybercriminals impersonate executives or trusted partners to trick employees into transferring funds or sharing sensitive information. The combination of an urgent wire transfer request, a spoofed CEO identity, and a newly registered look-alike domain strongly indicates BEC. Other attack types do not align with the described email-based deception and financial motive.

Exam trap

The trap here is confusing BEC with generic phishing, but BEC specifically targets financial transactions through executive impersonation, often without malicious attachments or links to credential-harvesting sites.

299
Multi-Selectmedium

A mid-sized accounting firm is drafting its first information security policy. The partners want the policy to address governance responsibilities clearly so that security decisions are made consistently at the right levels. Which TWO of the following are governance responsibilities that the policy should assign? (Choose two.)

Select 2 answers
A.Defining the organization's risk appetite and approving the overall security strategy
B.Performing vulnerability scans against internal servers each week
C.Resetting user passwords when employees call the service desk
D.Configuring firewall rules and tuning intrusion detection signatures daily
E.Assigning accountability for security outcomes to specific roles and ensuring oversight
AnswersA, E

Senior leadership and the board own risk appetite and strategic direction because they are accountable to stakeholders and can commit resources across the organization. A security policy that assigns this responsibility at the executive or board level ensures security decisions align with business objectives and regulatory obligations. This is a core governance function rather than a day-to-day operational task.

Why this answer

Governance is about direction, accountability, and oversight rather than hands-on control operation. Senior leadership defines risk appetite and approves strategy, while specific roles are made accountable for security outcomes and monitored through reporting. Firewall tuning, vulnerability scanning, and password resets are operational activities that implement governance decisions but do not themselves constitute governance.

Exam trap

The trap here is equating governance with any security-related activity, when governance specifically concerns decision rights, accountability, and strategic oversight.

300
MCQmedium

An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?

A.Phishing
B.Brute-force attack
C.Social engineering
D.Man-in-the-middle attack
AnswerB

Lockout thresholds directly throttle repeated authentication failures, so an attacker cannot iterate passwords indefinitely. The 5-attempts-in-15-minutes constraint caps the guessing rate, defeating brute-force attempts while allowing legitimate users to retry after the lockout window expires.

Why this answer

Account lockout after 5 failed attempts within 15 minutes is a classic defense against brute-force attacks, which rely on rapidly submitting many password guesses until one succeeds. By locking the account after a small number of failures, the control drastically reduces the number of attempts an attacker can make in a given time window, making automated guessing impractical. This is a standard mitigation recommended by frameworks like NIST and CIS.

Exam trap

The trap here is confusing brute-force with other credential-related attacks; candidates may pick phishing because both involve passwords, but only brute-force is mitigated by limiting failed attempts.

How to eliminate wrong answers

Option A is wrong because phishing is a social-engineering technique that tricks users into revealing credentials voluntarily; account lockout does not prevent a user from handing over a password. Option C is wrong because social engineering targets human trust and manipulation, not automated authentication attempts, so lockout thresholds have no effect. Option D is wrong because a man-in-the-middle attack intercepts or alters traffic between two parties; account lockout does not address session hijacking or credential interception.

Page 3

Page 4 of 14

Page 5