Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 376–450

989 questions total · 14pages · All types, answers revealed

Page 5

Page 6 of 14

Page 7
376
MCQmedium

During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?

A.Capture the contents of RAM.
B.Make a bit-for-bit copy of all storage.
C.Create a forensic image of the hard drive.
D.Review system logs.
AnswerA

Capturing the contents of RAM is crucial because memory holds highly volatile data that would be irretrievably lost upon system shutdown or reboot. This includes active processes, network connections, loaded kernel modules, and potentially malicious code residing solely in memory. Preserving RAM contents directly addresses the requirement to collect 'volatile data' for forensic analysis, ensuring critical evidence is secured before it becomes ephemeral and unusable for potential legal action.

Why this answer

Volatile data in RAM is lost when power is removed. Capturing RAM preserves evidence that might contain running processes, network connections, and encryption keys. Disk images are non-volatile and can be collected later.

377
MCQhard

During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?

A.Antivirus console logs showing scan results on the file server.
B.Windows Security event logs on the file server, filtered for object access auditing events.
C.Domain controller Security logs filtered for Kerberos ticket-granting service events.
D.Firewall logs showing SMB traffic between the workstation and the file server.
AnswerB

When object access auditing is enabled, the file server's Security log records events such as 4663 for attempts to access an object, including the account name, object path, and access type. This directly answers whether the compromised account touched the sensitive share. It is the most specific and authoritative source for file share access on Windows.

Why this answer

To establish whether a specific account accessed a sensitive file share on Windows, the file server's Security log with object access auditing enabled is the authoritative source. Event 4663 and related object access events capture the account, object path, and access type. Domain controller Kerberos events, firewall SMB logs, and antivirus logs provide authentication or network context but cannot prove file-level access by the compromised account.

Exam trap

The trap here is assuming domain controller authentication logs are sufficient to prove file access, when they only show that a logon or ticket was issued, not which files were opened.

378
MCQhard

A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?

A.To disable the switch by sending fake VLAN tags
B.To overwhelm the network with broadcast traffic
C.To redirect traffic to the attacker's machine for eavesdropping or modification
D.To corrupt the DNS cache
AnswerC

ARP spoofing forges gratuitous ARP replies that bind the gateway's IP address to the attacker's MAC address, so victims forward their frames to the attacker. The attacker then relays traffic onward while capturing credentials and session data, or alters payloads in transit, satisfying the eavesdropping and modification goal.

Why this answer

ARP spoofing allows an attacker to intercept traffic by associating their MAC address with the IP address of a legitimate host.

379
Multi-Selectmedium

A security manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The manager needs to identify which of the following are considered threats rather than vulnerabilities or risks. (Choose two.)

Select 2 answers
A.Weak password policy allowing easy guessing
B.A hacker group known for targeting SaaS providers
C.The potential financial loss from a data breach
D.Unpatched software in the CRM application
E.A natural disaster causing data center outage
AnswersB, E

A hacker group is an external threat actor with the intent and capability to exploit vulnerabilities. In risk management, a threat is any circumstance or event with the potential to cause harm. This group represents a threat because it actively seeks to compromise systems, and its existence is independent of any specific weakness in the CRM.

Why this answer

In risk management, a threat is any actor or event with the potential to cause harm, such as a hacker group or a natural disaster. Vulnerabilities are weaknesses that can be exploited, like unpatched software or weak password policies. Risk is the potential for loss when a threat exploits a vulnerability.

The question asks for threats, so the hacker group and natural disaster are correct.

Exam trap

The trap here is mixing up vulnerabilities and risks with threats; unpatched software and weak password policy are vulnerabilities, and financial loss is a risk, not a threat.

380
MCQmedium

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

A.DMZ
B.VPN
C.VLAN
D.Subnet
AnswerA

A DMZ (demilitarised zone) sits between the internet-facing perimeter and the internal network, so public-facing servers are reachable from the internet while firewall rules block direct access to internal corporate systems. This satisfies the isolation requirement without exposing the internal network.

Why this answer

A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the internet. It adds an additional layer of security by isolating these services from the internal corporate network. Public web, email, and DNS servers are typically placed in a DMZ to allow external access while protecting the internal network.

Exam trap

The trap is confusing a DMZ with a VLAN or subnet. While a DMZ can be implemented using VLANs and subnets, the key is its purpose: isolating external-facing services from the internal network.

How to eliminate wrong answers

Option B is wrong because a VPN is used to create a secure connection over an untrusted network, not to isolate public servers. Option C is wrong because a VLAN is a logical segmentation at Layer 2, but it does not inherently provide isolation from the internal network; it can be used within a DMZ. Option D is wrong because a subnet is a logical subdivision of an IP network, but not all subnets are DMZs; a DMZ is a specific type of subnet designed for external-facing services.

381
MCQmedium

During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?

A.Plan testing and maintenance
B.Business Impact Analysis (BIA)
C.Recovery strategies
D.Communication plan
AnswerA

Updating plan testing and maintenance ensures recovery procedures are validated against actual backup formats before a disaster, exposing incompatibilities during exercises rather than live recovery. This directly addresses the stem's constraint: tapes failing to restore because format compatibility was never verified, so the maintenance schedule must mandate periodic restore testing.

Why this answer

The failure of backup tapes to restore data due to format incompatibility indicates that the recovery procedures and tools were not validated during testing. This directly points to a deficiency in the 'Plan testing and maintenance' element, which ensures that backup media formats, restoration tools, and procedures are regularly verified and updated to match the current production environment. Without scheduled testing and maintenance, format drift between backup software versions or hardware changes can render tapes unreadable.

Exam trap

ISC2 often tests the distinction between 'plan testing and maintenance' (which validates technical execution) and 'recovery strategies' (which are high-level design choices), leading candidates to mistakenly select recovery strategies when the root cause is a failure in validation and upkeep.

How to eliminate wrong answers

Option B is wrong because the Business Impact Analysis (BIA) identifies critical business functions, recovery time objectives (RTOs), and recovery point objectives (RPOs), but it does not address the technical compatibility of backup media or the validation of restoration procedures. Option C is wrong because recovery strategies define the high-level approach to restoring operations (e.g., hot site, cold site, cloud failover), not the specific testing of backup tape formats or restoration tools. Option D is wrong because the communication plan covers notification and escalation procedures during an incident, not the technical verification of backup media compatibility or the maintenance of restoration capabilities.

382
MCQmedium

A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?

A.Denial-of-service (DoS) attack
B.SQL injection
C.Remote Desktop Protocol (RDP) brute force
D.Ransomware encryption
AnswerC

TCP port 3389 is used by Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses suggest a brute-force attack attempting to guess credentials for RDP access. This is a common attack vector for gaining unauthorized remote access to Windows systems. Monitoring and blocking such attempts is critical to prevent compromise.

Why this answer

TCP port 3389 is the default port for Remote Desktop Protocol (RDP). Repeated inbound connection attempts from multiple external IP addresses indicate an RDP brute-force attack, where attackers try to guess credentials to gain remote access. This is a common and dangerous attack, as successful compromise can lead to full system control.

Other attack types do not match the described network behavior.

Exam trap

The trap here is assuming that any repeated connection attempts constitute a DoS attack, but the specific targeting of port 3389 points to RDP brute force rather than volumetric flooding.

383
Multi-Selecthard

Which THREE of the following are examples of risk mitigation? (Select THREE)

Select 3 answers
A.Implementing access controls to limit user permissions
B.Deciding not to fix a low-risk vulnerability due to cost
C.Encrypting sensitive data at rest
D.Installing antivirus software on all endpoints
E.Purchasing cyber insurance
AnswersA, C, D

Implementing access controls directly reduces the likelihood of unauthorised actions by enforcing least privilege, satisfying the stem's requirement for risk mitigation. Rather than transferring or accepting risk, it lowers inherent exposure through preventive technical controls such as role-based access assignments in Microsoft Entra ID.

Why this answer

Option A is correct because implementing access controls (e.g., role-based access control following least privilege) directly reduces the likelihood and impact of unauthorized actions, which is the essence of risk mitigation. Option C is correct because encrypting sensitive data at rest (e.g., AES-256) reduces the impact of a data breach by rendering stolen data unreadable, thereby lowering overall risk. Option D is correct because installing antivirus/anti-malware on all endpoints provides detective and preventive controls that reduce the likelihood of malware infections and their spread.

Option B is not mitigation but risk acceptance, since the organization consciously chooses to tolerate the vulnerability without applying controls. Option E is risk transference (sharing risk with an insurer via a financial mechanism), not mitigation, because it does not reduce the likelihood or impact of the risk itself.

Exam trap

CC often tests the distinction between risk mitigation and other risk responses like acceptance or transference; candidates must remember that insurance is transference, not mitigation.

384
MCQeasy

An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Need-to-know
AnswerA

Fencing, bollards, lighting, guards, and biometric readers are distinct control layers, each imposing a separate obstacle before the next. An attacker must defeat all layers sequentially, which is precisely the layered, delay-and-detect approach defence in depth describes.

Why this answer

Defense in depth is a layered security strategy where multiple overlapping controls are deployed so that if one fails, others still protect the asset. The scenario shows physical perimeter controls (fencing, bollards, lighting), personnel controls (guards), and logical/physical access controls (biometric readers) — clearly multiple layers. This matches the core definition of defense in depth.

Exam trap

The trap here is confusing defense in depth with least privilege or separation of duties because all are 'security best practices' — candidates must recognize that only defense in depth describes multiple layered controls protecting the same asset.

How to eliminate wrong answers

Option B is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or error by one individual — it is about role division, not layered physical and logical controls. Option C is wrong because least privilege means granting users only the minimum access needed to perform their job; the scenario describes layered barriers, not permission scoping. Option D is wrong because need-to-know restricts access to information based on job relevance, which is an information-classification principle, not a layered physical security architecture.

385
Drag & Dropmedium

Drag and drop the steps for the TCP three-way handshake into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The TCP three-way handshake is a three-step process used to establish a reliable connection. The client initiates by sending a SYN (synchronize) packet to the server. The server responds with a SYN-ACK (synchronize-acknowledge) packet, acknowledging the client's request and indicating its own synchronization.

Finally, the client sends an ACK (acknowledge) packet to confirm the connection establishment. This sequence ensures both sides agree on initial sequence numbers and that the connection is ready for data transfer.

386
MCQmedium

A company's security operations center (SOC) receives an alert about suspicious outbound traffic from a server in the DMZ to an external IP address known for command-and-control activity. The SOC analyst reviews the logs and sees that the source port is 443 and the destination port is 8080. Which of the following actions should the analyst take FIRST?

A.Notify the incident response team and management immediately
B.Isolate the server from the network and investigate further
C.Block the external IP address at the firewall
D.Modify the firewall rule to deny all outbound traffic from the DMZ
AnswerB

Isolation contains the threat and allows forensic analysis without risk of further damage.

Why this answer

The SOC analyst should first isolate the server from the network because the outbound traffic from a DMZ server to a known C2 IP address, using source port 443 (HTTPS) to destination port 8080 (HTTP alternate), indicates a potential compromise. Isolating the server stops the data exfiltration and prevents further C2 communication, allowing for a controlled forensic investigation without alerting the attacker. This aligns with the NIST SP 800-61 incident response process, where containment is prioritized before eradication or recovery.

Exam trap

ISC2 often tests the candidate's ability to prioritize containment over notification or broad blocking, trapping those who confuse 'first action' with 'escalation' or who apply overly aggressive firewall changes without considering service impact.

How to eliminate wrong answers

Option A is wrong because notifying the incident response team and management immediately is premature; the analyst must first contain the threat by isolating the server to prevent further damage, as notification can occur after initial containment. Option C is wrong because blocking the external IP address at the firewall is a reactive measure that does not stop the compromised server from communicating with other C2 IPs or using different ports, and it may alert the attacker to change tactics. Option D is wrong because modifying the firewall rule to deny all outbound traffic from the DMZ would disrupt legitimate services hosted in the DMZ (e.g., web servers, mail relays) and is an overly broad, non-surgical response that violates the principle of least disruption.

387
Multi-Selecthard

Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)

Select 3 answers
A.IP Source Guard
B.Port security
C.Dynamic ARP Inspection (DAI)
D.MAC address filtering
E.DHCP Snooping
AnswersA, C, E

Prevents IP spoofing by filtering traffic based on DHCP snooping bindings.

Why this answer

IP Source Guard (A) is correct because it uses DHCP snooping binding table entries to filter traffic on a per-port basis, dropping packets where the source IP address does not match the binding. This prevents an attacker from spoofing a legitimate host's IP address in ARP spoofing attacks by ensuring only valid IP-to-MAC mappings are allowed on the port.

Exam trap

ISC2 often tests the misconception that port security or MAC filtering can prevent ARP spoofing, but these only control MAC addresses, not the IP-to-MAC bindings that ARP spoofing exploits.

388
Multi-Selectmedium

A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)

Select 2 answers
A.Place the database server in a separate VLAN and configure firewall rules to allow traffic only from the application server's IP address.
B.Use network address translation (NAT) to hide the database server's IP address from other internal systems.
C.Enable port security on the switch port connected to the database server to restrict MAC addresses.
D.Deploy an intrusion detection system (IDS) to monitor traffic to the database server and alert on suspicious connections.
E.Implement a host-based firewall on the database server that allows connections only from the application server's IP address.
AnswersA, E

Segmenting the database server into its own VLAN isolates it at the network layer, and firewall rules restrict access to only the application server. This combination enforces least privilege and reduces the attack surface. It ensures that even if other systems are compromised, they cannot directly reach the database.

Why this answer

Combining network segmentation with firewall rules and a host-based firewall provides defense in depth. The VLAN and network firewall restrict access at the network perimeter, while the host firewall adds protection directly on the server. Together, they ensure only the application server can connect, aligning with least privilege.

Exam trap

The trap here is relying on detection or obscurity controls like IDS or NAT instead of preventive access controls that actually restrict connections.

389
MCQhard

The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?

A.The syslog-ng configuration uses TLS, but the firewall rule does not allow TLS traffic
B.The firewall rule restricts source port 6514, but the client uses a random ephemeral source port
C.The syslog-ng client uses UDP by default, but the firewall allows only TCP
D.The firewall rule does not include the client IP 192.168.1.100
AnswerB

Firewall rules filtering on source port 6514 break syslog-ng's TCP transport, because clients originate connections from random ephemeral ports; only the destination port is 6514. Since the stem's rule constrains the source port, the client's packets are dropped before reaching 10.0.0.10, preventing log delivery.

Why this answer

The firewall rule on the central logging server (10.0.0.10) specifies a source port of 6514. However, syslog-ng clients, when sending over TCP or TLS, typically use a random ephemeral source port (e.g., above 1024) rather than a fixed source port. Since the firewall restricts the source port to exactly 6514, the client's packets are dropped, preventing logs from reaching the server.

Exam trap

The trap here is that candidates assume the firewall rule's source port 6514 is irrelevant or that the client must use the same port as the server, when in fact the client uses an ephemeral source port, making the rule overly restrictive and the cause of the failure.

How to eliminate wrong answers

Option A is wrong because the exhibit does not indicate that the syslog-ng client is configured to use TLS; the default transport for syslog-ng is TCP or UDP, and the firewall rule allows TCP on destination port 6514, which is the standard syslog-over-TLS port, but the issue is the source port restriction, not the protocol. Option C is wrong because the syslog-ng client does not use UDP by default when configured for TCP-based logging; the firewall rule explicitly allows TCP on destination port 6514, so if the client were using UDP, it would be blocked, but the client's configuration (not shown) would specify the transport, and the core problem is the source port mismatch. Option D is wrong because the firewall rule does not include a source IP restriction; it only specifies source port 6514 and destination port 6514, so the client IP 192.168.1.100 is not filtered out by the rule.

390
Multi-Selectmedium

Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)

Select 2 answers
A.Create a separate admin account for privileged tasks
B.Use the same account for daily work and administrative tasks
C.Disable logging for admin activities to reduce overhead
D.Implement a Privileged Access Management (PAM) solution
E.Share admin passwords among team members for convenience
AnswersA, D

Separating administrative duties from everyday user activity prevents routine browsing, email and document handling from exposing highly privileged credentials to phishing or credential theft. This directly satisfies the least-privilege and separation-of-duties requirements for privileged account management, limiting the blast radius if a standard account is compromised.

Why this answer

Option A is correct because creating a separate admin account for privileged tasks enforces separation between a user's standard daily-use account and their elevated account, so routine activities like email and web browsing cannot be leveraged to compromise administrative rights, and it enables auditing of privileged actions to a distinct identity. Option D is correct because a Privileged Access Management (PAM) solution provides vaulting, credential rotation, session brokering, just-in-time elevation, and monitoring of privileged sessions, which are core controls for reducing standing administrative access and detecting misuse. Option B is not recommended because using one account for both daily work and administrative tasks grants excessive standing privilege and exposes admin credentials to everyday attack surfaces such as phishing and malicious websites.

Option C is wrong because disabling logging for admin activities destroys the audit trail needed for accountability, incident response, and compliance, and the overhead is not a valid reason to eliminate it. Option E is wrong because sharing admin passwords among team members eliminates individual accountability, prevents effective credential rotation, and violates the principle of least privilege and non-repudiation.

Exam trap

The trap is that 'convenience' options (shared passwords, single account, disabled logging) sound efficient to busy admins, but the exam expects you to recognize they all violate core security principles of accountability, least privilege, and auditability.

391
Multi-Selecteasy

Which TWO of the following are examples of security principles?

Select 2 answers
A.Encryption
B.Least privilege
C.Firewall
D.VLAN
E.Defense in depth
AnswersB, E

Least privilege grants users and processes only the permissions required to perform their tasks, limiting the blast radius of compromise or error. It is a foundational security principle, directly constraining access rights rather than merely detecting or responding to threats.

Why this answer

Least privilege (B) is a foundational security principle stating that users, processes, and systems should be granted only the minimum access rights and permissions necessary to perform their required tasks, reducing the attack surface and limiting potential damage from compromise. Defense in depth (E) is also a core security principle advocating for multiple layered controls (administrative, technical, and physical) so that if one control fails, others still provide protection. By contrast, encryption (A) is a specific technical control or mechanism used to protect data confidentiality, not a guiding principle.

A firewall (C) is a network security device or software that filters traffic based on rules, and a VLAN (D) is a network segmentation technology at Layer 2; both are implementation tools rather than overarching security principles.

Exam trap

ISC2 often tests the distinction between security principles (like least privilege and defense in depth) and security technologies (like encryption, firewalls, and VLANs), trapping candidates who confuse implementation tools with the underlying design concepts.

392
MCQeasy

Which of the following is the primary purpose of a security information and event management (SIEM) system?

A.Enforce access control policies.
B.Replace the need for manual log review.
C.Prevent malware infections.
D.Correlate and analyze log data to detect incidents.
AnswerD

SIEM platforms aggregate logs from disparate sources, then apply correlation rules and analytics to link related events across systems. This correlation is what surfaces multi-stage incidents that individual device logs would not reveal, satisfying the stem's requirement for detecting incidents rather than merely storing or forwarding raw log data.

Why this answer

The primary purpose of a SIEM system is to aggregate, correlate, and analyze log data from multiple sources (e.g., firewalls, servers, IDS/IPS) in real time to detect security incidents. By applying correlation rules and analytics, SIEM identifies patterns or anomalies that indicate malicious activity, enabling security teams to respond promptly.

Exam trap

ISC2 often tests the distinction between a SIEM's core function (correlation and detection) and other security tools' roles (prevention, enforcement, or replacement of manual tasks), leading candidates to mistakenly choose 'replace manual log review' because they overlook the primary purpose of incident detection.

How to eliminate wrong answers

Option A is wrong because enforcing access control policies is the function of dedicated systems like firewalls, identity and access management (IAM) solutions, or directory services (e.g., Active Directory), not a SIEM, which focuses on log analysis and monitoring. Option B is wrong because while SIEM automates log analysis and reduces manual effort, its primary purpose is not simply to replace manual log review but to provide correlation and incident detection; manual review is still needed for validation and complex investigations. Option C is wrong because preventing malware infections is the role of endpoint protection platforms (EPP), antivirus software, or intrusion prevention systems (IPS); a SIEM detects signs of infection through log correlation but does not actively block malware.

393
MCQhard

A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?

A.Mandatory access control, because the system enforces the restriction without user involvement.
B.Role-based access control, because tellers form a job role that shares the same permissions.
C.Rule-based access control, because access is granted or denied according to a defined condition rather than individual identity.
D.Discretionary access control, because a manager decides which tellers receive transaction access.
AnswerC

Rule-based access control evaluates administrator-defined conditions, and the time-of-day and day-of-week window is precisely such a condition. The policy applies uniformly regardless of who the teller is, and users cannot alter it. This matches the defining characteristic of rule-based control, where objective criteria govern the decision.

Why this answer

Rule-based access control makes decisions from objective, administrator-defined conditions rather than from individual identity or job role. Restricting transaction access to a fixed time window on business days is a textbook condition, and it applies to every teller identically while remaining outside user control. The uniformity and condition-driven nature distinguish it from role-based, discretionary, and mandatory approaches.

Exam trap

The trap here is assuming that because all tellers share a job title, the control must be role-based rather than condition-driven.

394
MCQmedium

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerD

A digital signature verifies that the update has not been altered after signing, because any modification invalidates the hash encrypted with the signer's private key. This detects tampering, satisfying integrity; authenticity of the sender is a related but separate assurance.

Why this answer

A digital signature provides integrity by using a hash of the message encrypted with the sender's private key; the recipient decrypts the hash with the public key and compares it to a freshly computed hash. If the values match, the data has not been altered. While digital signatures also provide authentication and non-repudiation, the question asks which CIA triad element is supported — integrity is the correct CIA component.

Exam trap

The trap is confusing integrity with non-repudiation — digital signatures provide both, but the CIA triad question specifically asks which CIA element, and non-repudiation is not one of the three.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad; it is a separate security property (though digital signatures do provide it). Option B is wrong because availability concerns uptime and access, which digital signatures do not address. Option C is wrong because confidentiality requires encryption that hides data content, whereas digital signatures do not encrypt the message — they only verify it.

395
Matchingmedium

Match each risk management term to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Weakness in a system

Potential cause of harm

Likelihood and impact of a threat exploiting a vulnerability

Control to mitigate risk

Why these pairings

Risk is the potential for loss when a threat exploits a vulnerability. A threat is a potential cause of harm. A vulnerability is a weakness.

Controls are measures to reduce risk.

396
MCQhard

A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?

A.Implement Quality of Service (QoS) policies to prioritize database replication traffic over other data transfers.
B.Increase the bandwidth on the replication link by ordering a faster circuit from the ISP.
C.Reschedule the next DR test to occur during a scheduled maintenance window with no other replication activity.
D.Revise the RTO for the customer database from 4 hours to 8 hours to account for current bandwidth limitations.
AnswerA

QoS policies prioritise database replication traffic, preventing bulk synchronisation jobs from saturating the link and causing failover failure. This addresses the root cause—unmanaged bandwidth contention—rather than merely adding capacity or relaxing RTOs, satisfying the stem's requirement to fix the underlying fault.

Why this answer

The root cause is that the replication link was saturated by a large data synchronization job, which delayed the critical database replication traffic needed to meet the 4-hour RTO. Implementing Quality of Service (QoS) policies directly addresses this by prioritizing database replication traffic over other data transfers, ensuring that critical replication gets the necessary bandwidth even during concurrent large jobs. This is the most effective solution because it resolves the contention without requiring additional bandwidth or changing RTOs.

Exam trap

ISC2 often tests the misconception that simply adding more bandwidth (Option B) solves all congestion issues, but the trap is that without traffic prioritization, the root cause of contention between different traffic types remains unaddressed.

How to eliminate wrong answers

Option B is wrong because simply increasing bandwidth does not guarantee that replication traffic will be prioritized; without QoS, other data transfers can still saturate the link, and it may not be cost-effective or timely. Option C is wrong because rescheduling the test avoids the problem rather than fixing it; the same issue could occur during a real disaster when other replication activity is unavoidable. Option D is wrong because revising the RTO to 8 hours accepts a degraded recovery capability instead of addressing the technical root cause of traffic prioritization, which could be solved with QoS.

397
MCQmedium

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

A.Internal
B.Restricted
C.Public
D.Confidential
AnswerB

Restricted data demands the strongest controls because it carries the greatest potential harm if disclosed, satisfying the stem's requirement for the highest protection level. Public, Internal, and Confidential each warrant progressively less stringent safeguards, so Restricted sits at the top of this four-tier classification scheme.

Why this answer

In a four-tier classification scheme (Public, Internal, Confidential, Restricted), Restricted represents the most sensitive data — typically trade secrets, PII under regulation, or data whose breach causes severe legal/financial harm. It therefore requires the highest level of protection, including strict access controls, encryption, and audit logging.

Exam trap

The trap here is confusing 'Confidential' with 'Restricted' — candidates often assume Confidential is the top tier, but in most four-tier schemes Restricted is the highest sensitivity level.

How to eliminate wrong answers

Option A is wrong because Internal data is only meant for employees and has lower sensitivity than Confidential or Restricted. Option C is wrong because Public data is intentionally shareable and requires the least protection. Option D is wrong because Confidential is sensitive but typically one tier below Restricted — Confidential data might be shared under NDA, while Restricted data is need-to-know with the strictest controls.

398
MCQmedium

A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?

A.UDP port 443
B.TCP port 80
C.TCP port 443
D.TCP port 22
AnswerC

HTTPS traffic uses TCP port 443, where TLS encapsulates HTTP. Permitting TCP 443 satisfies the secure web traffic requirement; port 80 carries unencrypted HTTP, and UDP 443 is used by HTTP/3 rather than standard secure browsing.

Why this answer

Secure web traffic uses HTTPS, which by default runs over TCP port 443. The question specifies 'secure web traffic,' so the correct protocol/port pairing is TCP 443. HTTPS encrypts HTTP using TLS, protecting confidentiality and integrity of web communications.

Exam trap

The trap is the UDP 443 distractor — candidates who know HTTP/3 uses QUIC may pick it, but the standard, expected answer for 'secure web traffic' is TCP 443.

How to eliminate wrong answers

Option A is wrong because UDP port 443 is used by HTTP/3 (QUIC), but the standard, universally supported secure web protocol is TCP 443 — and the question asks for the standard secure web traffic port, which is TCP-based. Option B is wrong because TCP port 80 is plain HTTP, which is unencrypted and therefore not 'secure' web traffic. Option D is wrong because TCP port 22 is SSH, used for secure remote administration, not web traffic.

399
MCQeasy

Which of the following is an example of Type 2 authentication?

A.Fingerprint scan
B.Password
C.PIN
D.Smart card
AnswerD

Correct. Smart card is a possession factor.

Why this answer

Type 2 authentication, also called 'something you have,' relies on a physical object the user possesses — a smart card is the classic example. Type 1 is 'something you know' (password, PIN), Type 2 is 'something you have' (smart card, token, phone), and Type 3 is 'something you are' (biometrics). The smart card fits Type 2 precisely.

Exam trap

The trap is confusing a PIN with a smart card — candidates see 'PIN' and think it is part of the smart card, but a PIN alone is Type 1 (knowledge), while the smart card itself is Type 2 (possession).

How to eliminate wrong answers

Option A is wrong because a fingerprint scan is a biometric factor, which is Type 3 ('something you are'), not Type 2. Option B is wrong because a password is knowledge-based, making it Type 1 ('something you know'). Option C is wrong because a PIN is also knowledge-based and therefore Type 1, even though it is often used alongside a smart card in two-factor authentication.

400
Multi-Selecthard

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Select 3 answers
A.Company cafeteria menu
B.Classified government intelligence
C.Marketing brochures
D.Trade secrets
E.Biometric data of employees
AnswersB, D, E

Government intelligence material is classified at the highest tier because unauthorised disclosure causes exceptional damage to national security. Its handling mandates the strictest controls, so it belongs in the restricted or top secret category rather than internal or public.

Why this answer

Option B (classified government intelligence) is correctly marked restricted/top secret because it is information whose unauthorized disclosure would cause exceptional damage to national security and is legally protected at the highest classification levels. Option D (trade secrets) is correct because trade secrets are proprietary intellectual property whose disclosure would cause severe competitive and financial harm, so best-practice data classification places them in the highest sensitivity tier. Option E (biometric data of employees) is correct because biometric identifiers are sensitive personal data (often special-category data under regimes like GDPR) that cannot be changed if compromised, warranting restricted handling.

The unmarked options do not belong: A (company cafeteria menu) and C (marketing brochures) are intended for public or internal distribution and carry negligible confidentiality impact, so they would be classified as public or internal, not restricted.

401
MCQhard

A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?

A.DNS tunneling
B.Domain hijacking
C.DNS amplification
D.DNS cache poisoning
AnswerD

DNS cache poisoning inserts false records into a resolver's cache so that legitimate domain names resolve to attacker-controlled addresses. Since the workstation uses the corporate resolver and no local configuration changed, a poisoned cache on that resolver would explain the incorrect answer. This enables redirection to malicious sites and is a classic man-in-the-middle enabler.

Why this answer

When a workstation uses the corporate resolver and suddenly receives an attacker-controlled IP for a legitimate banking domain, the most likely cause is that the resolver's cache has been poisoned with a forged record. DNS cache poisoning redirects users to malicious destinations without changing endpoint configuration. Tunneling, domain hijacking, and amplification do not match the observed symptom of a wrong but locally scoped resolution.

Exam trap

The trap here is attributing any DNS anomaly to domain hijacking, when a resolver-scoped wrong answer more strongly indicates cache poisoning.

402
MCQmedium

A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?

A.Increase password complexity requirements and change frequency to every 30 days
B.Conduct annual phishing awareness training
C.Deploy multi-factor authentication (MFA) for all remote access and critical systems
D.Implement a password manager for all employees
AnswerC

MFA defeats phishing because a stolen password alone is insufficient; the second factor blocks the attacker. It directly addresses willing credential disclosure across remote access and critical systems, satisfying the remote workforce constraint without relying on password complexity or rotation.

Why this answer

MFA directly mitigates credential phishing because even if an employee surrenders their username and password to a fake site, the attacker cannot complete authentication without the second factor. It addresses the root cause (credential compromise via phishing) rather than symptoms, and it works for the remote workforce described. Given Active Directory and budget for new tools, deploying MFA to remote access and critical systems is the highest-impact control.

Exam trap

CC often tests whether candidates recognize that stronger passwords and training do not stop credential phishing, so distractors that sound like 'more security hygiene' (complexity, rotation, password managers) lure candidates away from the control that actually breaks the phishing kill chain: MFA.

How to eliminate wrong answers

Option A is wrong because increasing password complexity and shortening rotation to 30 days does nothing against phishing — the employee willingly gives the password away, so stronger passwords are still stolen; frequent rotation also drives weaker human behavior (writing passwords down). Option B is wrong because annual phishing awareness training is too infrequent and has limited effectiveness against determined social engineering; it is a supporting control, not the best primary action. Option D is wrong because a password manager helps with password hygiene and reuse but does not stop a user from typing credentials into a phishing page, and it does not add a second authentication factor.

403
MCQmedium

A company deploys a web application firewall (WAF), performs regular vulnerability scans, and implements strict access controls. Which security principle is being applied?

A.Defense in depth
B.Accountability
C.Risk management
D.Least privilege
AnswerA

Layering a WAF, vulnerability scans and strict access controls applies defense in depth: multiple independent controls so one failure does not expose the application. This satisfies the stem's scenario, where several distinct protective mechanisms combine rather than a single restrictive entitlement.

Why this answer

Defense in depth is the security principle of layering multiple independent security controls so that if one fails, others still provide protection. The question describes three distinct layers: a WAF (application-layer filtering), vulnerability scanning (proactive detection), and strict access controls (preventive policy). This stacking of different types of controls across the network, host, and application layers is the textbook definition of defense in depth.

Exam trap

ISC2 often tests defense in depth by listing multiple security tools and expecting candidates to recognize the layering concept, but the trap here is that candidates confuse 'defense in depth' with 'least privilege' because both involve multiple controls, when in fact least privilege is just one layer within a defense-in-depth strategy.

How to eliminate wrong answers

Option B (Accountability) is wrong because accountability refers to tracking user actions through logging and auditing (e.g., syslog, auditd) to hold individuals responsible, not to deploying multiple protective layers. Option C (Risk management) is wrong because risk management is the broader process of identifying, assessing, and mitigating risks (e.g., via risk matrices or quantitative analysis), not the specific architectural strategy of layering controls. Option D (Least privilege) is wrong because least privilege is a specific access control principle that grants only the minimum permissions needed to perform a task (e.g., using RBAC with minimal roles), not the combination of WAF, scans, and access controls.

404
MCQhard

A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?

A.The risk is low because the backup can restore data quickly.
B.The risk is moderate because the backup reduces the impact, but likelihood remains high.
C.The risk is eliminated because the backup ensures full recovery.
D.The risk is high because the likelihood and impact are both high.
AnswerB

Risk is a function of likelihood and impact. Here, likelihood is high, but the backup reduces the impact from severe to moderate. The residual risk is therefore moderate. This classification acknowledges both the high likelihood and the mitigating effect of the backup, resulting in a balanced risk rating that reflects the remaining exposure.

Why this answer

The analyst should classify the risk as moderate. Although the likelihood of a ransomware attack is high, the reliable offline backup significantly reduces the potential impact by enabling rapid restoration. Risk is the combination of likelihood and impact; with high likelihood but reduced impact, the overall risk is moderate.

This reflects the residual risk after considering the mitigating control.

Exam trap

The trap here is ignoring the mitigating effect of the backup and rating risk solely on likelihood and impact, or conversely, assuming the backup eliminates risk entirely.

405
MCQmedium

A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?

A.Encrypt the backup tapes
B.Label the tapes with a classification marking
C.Store the tapes in a locked cabinet
D.Apply a checksum to each tape
AnswerA

Encrypting backup tapes renders the data unreadable without the appropriate keys, even if the physical media is lost or stolen. This directly satisfies the requirement that unauthorized parties cannot read the data. Therefore, encryption is the correct control for protecting data at rest on transported media in this scenario.

Why this answer

Encryption protects data confidentiality even when physical media is lost or stolen. By encrypting backup tapes, the company ensures that unauthorized parties cannot read customer data without the decryption keys. Checksums, labels, and locked cabinets may support handling or integrity, but none prevents a thief from reading the tape contents, so encryption is the required control.

Exam trap

The trap here is relying on physical controls like locked cabinets, which fail once the tape leaves the controlled environment.

406
MCQmedium

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

A.Authentication
B.Integrity
C.Confidentiality
D.Availability
AnswerB

Hashing detects unauthorised file modification because any change to the file's contents produces a different hash value, so comparison against the stored baseline reveals tampering. This directly satisfies the stem's requirement to detect unauthorised changes to critical files, supporting integrity rather than confidentiality or availability.

Why this answer

Hashing critical files and storing their hash values allows the administrator to later recompute the hash and compare it to the stored value. If the file contents change, the hash will differ, revealing unauthorized modification. This directly supports the security goal of integrity, which ensures data has not been altered in an unauthorized manner.

Authentication, confidentiality, and availability are not the primary goals addressed by this mechanism.

Exam trap

The trap here is confusing integrity with authentication because both involve verification; candidates may think hashing authenticates the file's source, but it only proves the file has not changed since the baseline was taken.

How to eliminate wrong answers

Option A is wrong because authentication verifies the identity of a user, system, or entity, not whether a file's contents have been altered; hashing files does not prove who accessed them. Option C is wrong because confidentiality ensures data is not disclosed to unauthorized parties, typically through encryption; hashing does not hide file contents. Option D is wrong because availability ensures systems and data are accessible when needed, often via redundancy or backups; hashing does not prevent downtime or ensure uptime.

407
MCQhard

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

A.Risk avoidance
B.Due care
C.Due diligence
D.Risk mitigation
AnswerC

Due diligence is the pre-contract investigation of a vendor's controls, plans and personnel, gathering evidence before commitment. Audits and penetration tests examine an existing relationship, whereas due diligence satisfies the consultant's need to assess risk prior to signing.

Why this answer

Due diligence involves investigating and verifying security practices before making a decision, such as vendor risk assessment.

408
MCQmedium

During a security audit, it is discovered that a single administrator can create user accounts, assign privileges, and review audit logs. Which principle is most likely being violated?

A.Separation of duties
B.Least privilege
C.Need to know
D.Defense in depth
AnswerA

Separation of duties requires splitting sensitive functions across different people so no single account controls an entire process. One administrator holding account creation, privilege assignment and audit review concentrates incompatible duties, removing the checks that would otherwise detect abuse.

Why this answer

Separation of duties requires that conflicting critical tasks be performed by different individuals to prevent fraud or error. The administrator has both operational and oversight roles, violating this principle.

409
MCQhard

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerC

Risk acceptance means deliberately acknowledging a residual risk and proceeding without further controls because the upgrade cost exceeds the potential impact. This matches the stem's scenario of tolerating a known vulnerable software version rather than mitigating, transferring or avoiding it.

Why this answer

Risk acceptance is the deliberate decision to acknowledge a risk and take no action to reduce it, typically because the cost of mitigation outweighs the potential impact. In this scenario, the organization has evaluated the risk and consciously chosen to retain it, which is the definition of risk acceptance. This is a valid risk response when the risk falls within the organization's risk appetite or when mitigation is not cost-effective.

Exam trap

The trap here is confusing risk acceptance with risk mitigation or avoidance, especially when the scenario mentions cost-benefit analysis; candidates might think that any decision involving cost considerations implies mitigation, but acceptance is specifically about choosing to retain the risk without further action.

How to eliminate wrong answers

Option A is wrong because risk avoidance involves changing plans or activities to eliminate the risk entirely, such as discontinuing the use of the vulnerable software. Option B is wrong because risk transfer shifts the risk to a third party, such as purchasing insurance or outsourcing, which is not happening here. Option D is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of the risk, such as patching or applying compensating controls, which the organization has explicitly decided not to do.

410
MCQmedium

A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?

A.IDS
B.Honeypot
C.IPS
D.Firewall
AnswerA

An IDS passively copies and analyses network traffic, comparing it against signatures or anomalies to raise alerts. Because it sits out-of-band rather than inline, it detects malicious activity without adding latency or dropping packets, satisfying the no-performance-impact constraint.

Why this answer

An IDS (Intrusion Detection System) monitors network traffic passively, typically via a SPAN port or network TAP, and generates alerts on suspicious activity without blocking traffic. Because it operates out-of-band and does not sit inline, it does not affect network performance or latency — exactly matching the requirement to detect without impacting performance.

Exam trap

The trap is the IDS vs. IPS distinction — candidates who focus only on 'detect' may overlook that IPS is inline and affects performance, while IDS is passive and does not.

How to eliminate wrong answers

Option B is wrong because a honeypot is a decoy system designed to attract and study attackers, not to monitor general network traffic for intrusions — it detects only activity directed at itself. Option C is wrong because an IPS (Intrusion Prevention System) sits inline and can block traffic, which introduces latency and potential throughput bottlenecks, violating the 'without affecting performance' requirement. Option D is wrong because a firewall enforces access control policy based on rules; while it may have some detection capability, its primary role is filtering, and inline enforcement can affect performance.

411
MCQhard

A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?

A.Verify whether the transfer is authorized.
B.Call the employee who owns the server.
C.Disconnect the affected server from the network.
D.Run an antivirus scan on the server.
AnswerA

Confirming whether the transfer was authorised distinguishes legitimate scheduled replication or backup traffic from genuine exfiltration. Acting before verification risks disrupting business operations or destroying evidence, so validation is the immediate step the alert scenario demands.

Why this answer

The correct answer is to verify whether the transfer is authorized. In incident response, the first step is to validate the alert to determine if it represents a true positive or a false positive. Large data transfers during non-business hours could be legitimate activities such as backups, software updates, or authorized data sharing.

Confirming authorization prevents unnecessary escalation and ensures that response efforts are focused on actual threats. This aligns with the 'Identification' phase of incident response, where the goal is to gather evidence and confirm the incident before taking disruptive actions.

Exam trap

The trap here is assuming that any anomalous data transfer is malicious and requires immediate containment, but the exam expects candidates to recognize that verification is the first step in incident response to avoid false positives.

How to eliminate wrong answers

Option B is wrong because calling the employee who owns the server is not the immediate priority; it may be part of verification, but it is not the most appropriate first step and could tip off a malicious insider. Option C is wrong because disconnecting the server is a containment action that should only be taken after confirming a real incident; premature disconnection can disrupt business operations and destroy evidence. Option D is wrong because running an antivirus scan is a remediation step that assumes malware involvement, but data exfiltration may not involve malware, and scanning does not address the immediate need to verify the alert.

412
MCQhard

A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?

A.Require multifactor authentication for anyone accessing financial reporting systems.
B.Increase the password complexity requirement for all Finance systems.
C.Perform a periodic access review and revoke entitlements that are no longer required for the employee's current role.
D.Enable account lockout after three failed login attempts on the financial reporting systems.
AnswerC

The root cause is that permissions were never re-evaluated when the employee changed roles, a failure of the access control lifecycle. A periodic access review, sometimes called recertification, compares current entitlements against what the job now requires and removes the excess. Revoking the stale Finance rights directly corrects the excessive privilege and prevents similar drift for other transfers.

Why this answer

Excessive access after a role change is a lifecycle failure: provisioning added Finance rights, but deprovisioning or modification never removed them when the employee moved to Marketing. A periodic access review compares entitlements with current job needs and revokes what is no longer required. Authentication hardening such as complexity, lockout, or multifactor authentication protects the login but leaves the stale authorization untouched, so it cannot fix the root cause.

Exam trap

The trap here is choosing an authentication hardening control for what is actually an authorization lifecycle problem, since the account logs in legitimately but holds outdated rights.

413
MCQeasy

Which control type is considered a physical security control?

A.Firewall rules
B.Security cameras
C.User training
D.Encryption
AnswerB

Cameras monitor and record activity in a physical space, so they satisfy the stem's requirement for a physical security control. Unlike logical controls such as access lists or encryption, they operate on the tangible environment, deterring and detecting intrusions at the perimeter or within a facility.

Why this answer

Security cameras are a physical security control because they deter, detect, and record unauthorized physical access or activity in a facility. They are deployed as part of a layered physical security strategy, often integrated with access control systems and monitored by security personnel. Unlike logical or administrative controls, cameras directly protect tangible assets and premises.

Exam trap

ISC2 often tests the distinction between physical, administrative, and technical controls, and the trap here is that candidates confuse 'security cameras' as a monitoring/logging control (which is technical) rather than recognizing that the camera hardware itself is a physical asset deployed for physical security.

How to eliminate wrong answers

Option A is wrong because firewall rules are a logical/technical control that filters network traffic based on IP addresses, ports, and protocols; they do not physically prevent access to hardware or facilities. Option C is wrong because user training is an administrative control that educates personnel on security policies and procedures, not a physical barrier or monitoring mechanism. Option D is wrong because encryption is a technical/cryptographic control that protects data confidentiality during storage or transmission, but it does not physically secure hardware or locations.

414
Multi-Selecteasy

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

Select 2 answers
A.HTTP
B.TCP
C.IP
D.Ethernet
E.UDP
AnswersB, E

TCP operates at the Transport layer, providing connection-oriented, reliable delivery with sequencing, acknowledgements and flow control. Its layer 4 port addressing and segmentation satisfy the question's requirement for protocols operating at the Transport layer of the OSI model.

Why this answer

TCP and UDP are the primary Transport layer protocols. IP is Network layer, Ethernet is Data Link, and HTTP is Application layer.

415
Drag & Dropmedium

Drag and drop the steps to perform a password reset on a Windows user account into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Password reset requires admin rights and is done via Local Users and Groups in Computer Management.

416
MCQmedium

Which is a key benefit of a cold site as a recovery location?

A.Real-time data synchronization
B.Low cost
C.Reduced need for testing
D.Fast recovery time
AnswerB

A cold site provides only basic space and power, with no pre-installed hardware or replicated data, so the organisation pays minimal ongoing facility costs. That low cost is the defining benefit, accepting lengthy activation and restoration times.

Why this answer

A cold site is a backup facility that provides only the physical infrastructure (power, cooling, and space) but no pre-installed hardware or live data. Because it lacks equipment and requires manual setup before recovery can begin, it has the lowest capital and operational costs among recovery site options, making low cost its key benefit.

Exam trap

ISC2 often tests the misconception that 'cold site' implies lower testing requirements, but in reality, cold sites demand more rigorous and frequent testing because the manual recovery process is error-prone and must be validated to avoid failure during an actual disaster.

How to eliminate wrong answers

Option A is wrong because real-time data synchronization requires active replication technologies like synchronous replication or database mirroring, which are not supported by a cold site that has no live systems or network connectivity until activated. Option C is wrong because cold sites actually increase the need for testing, as the recovery process involves manual installation and configuration of hardware and software, which must be validated through regular drills to ensure it works under pressure. Option D is wrong because cold sites have the slowest recovery time (often days or weeks) due to the absence of pre-configured equipment and data, whereas fast recovery is a benefit of hot or warm sites.

417
Multi-Selectmedium

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Select 2 answers
A.One-time password token
B.Retina scan
C.Fingerprint recognition
D.Smart card
E.Password
AnswersB, C

Type 3 authentication relies on something you are — a biometric trait. A retina scan measures a physiological characteristic unique to the individual, satisfying that category rather than knowledge (Type 1) or possession (Type 2).

Why this answer

Type 3 authentication is "something you are," i.e., biometrics based on a physical or behavioral characteristic of the user. Option B, retina scan, is correct because it authenticates by measuring the unique pattern of blood vessels in the eye's retina, a physiological biometric trait. Option C, fingerprint recognition, is correct because it verifies identity from the unique ridge patterns of a finger, another physiological biometric.

The other options belong to different factors: A (one-time password token) and D (smart card) are Type 2, "something you have," while E (password) is Type 1, "something you know."

Exam trap

The trap here is confusing authentication factor types: many candidates mistakenly classify a one-time password token or smart card as 'something you are' because they are advanced technologies, but they are actually 'something you have' (Type 2).

418
MCQmedium

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

A.Due care
B.Governance
C.Due diligence
D.Risk acceptance
AnswerC

Due diligence is the investigation and verification of a vendor's controls before contracting, covering certification review, background checks and site visits. These activities assess the vendor's actual security posture, satisfying the evaluation described in the scenario.

Why this answer

Due diligence involves investigating and verifying before making a decision, such as vendor risk assessment.

419
MCQeasy

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

A.Confidentiality
B.Availability
C.Non-repudiation
D.Integrity
AnswerD

File integrity monitoring detects unauthorised changes to critical files by comparing hashes against a known baseline. This directly addresses integrity, ensuring data and system files remain unaltered and trustworthy, rather than focusing on confidentiality or availability.

Why this answer

File integrity monitoring detects unauthorized changes to files, ensuring data accuracy and completeness, which is the integrity element.

420
MCQeasy

A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?

A.Two separate instances of something you know
B.Something you are combined with something you have
C.Something you have combined with somewhere you are
D.Something you know combined with something you have
AnswerD

The employee ID identifies the user, the password is something the nurse knows, and the one-time code from a hardware token is something the nurse has. Combining two different factors from separate categories satisfies multi-factor authentication. This accurately describes the hospital's login process and is the correct categorization.

Why this answer

Authentication factors fall into categories such as knowledge, possession, inherence, and location. The nurse's password represents knowledge, while the hardware token one-time code represents possession. Pairing factors from two different categories achieves multi-factor authentication, which is stronger than using two factors from the same category.

This combination directly matches the described login process.

Exam trap

The trap here is assuming that any two credentials count as multi-factor authentication when they may belong to the same factor category.

421
MCQhard

A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?

A.Expose the repositories through a jump host with SSH key authentication and no device checks.
B.Use a site-to-site IPsec tunnel between each developer's home router and the corporate gateway.
C.Publish the code repositories through a reverse proxy with HTTP basic authentication.
D.Deploy a remote access VPN that authenticates users and then performs a posture check before allowing access to the repository subnet.
AnswerD

A remote access VPN authenticates each developer and can integrate a posture or host-check step that evaluates device health before granting network access. The repositories remain on an internal subnet that is not directly reachable from the internet. This satisfies identity verification, device health assessment, and non-exposure of the repositories in one design.

Why this answer

A remote access VPN authenticates each developer and can enforce a posture check that verifies device health before allowing access to internal repositories. The repositories stay on an internal subnet and are not published to the internet. A reverse proxy with basic authentication, a site-to-site tunnel to home routers, and a jump host without device checks each fail at least one requirement.

Exam trap

The trap here is focusing only on user authentication and overlooking the explicit requirement to verify device health before granting access.

422
MCQmedium

A retail company's business continuity plan includes a requirement to test its disaster recovery capabilities annually. The IT team proposes conducting a tabletop exercise with key stakeholders. Which benefit does this type of test provide?

A.It verifies that the recovery site can handle the production workload within the RTO.
B.It provides a full-scale simulation of a disaster to test all technical recovery procedures.
C.It automatically updates the disaster recovery plan based on identified gaps during the exercise.
D.It evaluates the decision-making and communication processes without disrupting live operations.
AnswerD

A tabletop exercise is a discussion-based test where participants walk through a simulated emergency scenario. It allows stakeholders to practice roles, decision-making, and communication without affecting production systems. This makes it a low-risk, cost-effective way to identify gaps in plans and coordination. It does not validate technical recovery capabilities, but it is valuable for testing the human and procedural aspects of the plan.

Why this answer

A tabletop exercise is a discussion-based test that simulates an emergency scenario to evaluate plans, roles, and communication. It does not disrupt live operations and is relatively low-cost. It helps identify gaps in coordination and decision-making.

It is not a technical test of recovery systems; instead, it focuses on the human and procedural elements of business continuity and disaster recovery.

Exam trap

The trap here is assuming a tabletop exercise tests technical recovery, when it actually tests plans and communication without live failover.

423
Multi-Selecteasy

Which THREE of the following are common components of a disaster recovery plan?

Select 3 answers
A.Backup procedures
B.Restoration of operations in a secondary site
C.Password policy
D.Employee background checks
E.Business impact analysis
AnswersA, B, E

Backup procedures form a core disaster recovery component because they enable data restoration after loss, corruption or site failure. They directly satisfy the plan's recovery requirement by defining what data is copied, how frequently, where copies are stored, and how restoration is tested and performed within agreed recovery time objectives.

Why this answer

Option A (Backup procedures) is correct because a DR plan must define how data and systems are backed up — including backup types (full, incremental, differential), frequency, retention, and offsite/offline storage — so that recovery point objectives (RPO) can be met. Option B (Restoration of operations in a secondary site) is correct because a core element of disaster recovery is failover to an alternate site (hot, warm, or cold) and the documented steps to resume critical operations there when the primary site is unavailable. Option E (Business impact analysis) is correct because the BIA identifies critical business functions, dependencies, and acceptable downtime (RTO/RPO), which drives the priorities and scope of the DR plan.

Option C (Password policy) is not a DR component; it is an access-control/identity management artifact belonging to security policy. Option D (Employee background checks) is not a DR component; it is a personnel security control used in hiring and screening.

Exam trap

ISC2 often tests the distinction between disaster recovery components (backup, BIA, alternate sites) and general security controls (password policies, background checks), so candidates mistakenly include the latter because they are also part of overall security operations.

424
MCQmedium

Which incident category involves an attempt to make a system or network resource unavailable to its intended users?

A.Malware
B.Data breach
C.Denial of service
D.Social engineering
AnswerC

Denial-of-service attacks exhaust a system's capacity — flooding bandwidth, connection tables or CPU — so legitimate users cannot reach the resource, directly matching the stem's unavailability criterion. Unlike data-theft or intrusion categories, the objective here is disruption rather than access, making this the precise incident classification.

Why this answer

A denial-of-service (DoS) incident is defined as any attempt to make a system or network resource unavailable to its intended users, typically by flooding it with traffic or exploiting resource exhaustion. This matches the question's description exactly. Other categories like malware or data breach involve different objectives such as data theft or code execution.

Exam trap

The trap here is conflating 'availability' attacks with 'confidentiality' or 'integrity' attacks; candidates may pick 'data breach' because they associate all cyber incidents with data theft, missing the specific wording about making resources unavailable.

How to eliminate wrong answers

Option A is wrong because malware incidents involve malicious software designed to damage, disrupt, or gain unauthorized access, not necessarily to make a resource unavailable. Option B is wrong because a data breach focuses on unauthorized access to and exfiltration of sensitive data, not on service availability. Option D is wrong because social engineering manipulates people into revealing information or performing actions, which is a human-centric attack rather than a resource exhaustion attack.

425
MCQeasy

A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?

A.FTP on port 21
B.HTTP on port 80
C.SSH on port 22
D.Telnet on port 23
AnswerC

SSH encrypts the entire management session, including credentials and commands, preventing eavesdropping and man-in-the-middle interception. Port 22 is its assigned transport port. Telnet on port 23 sends everything in cleartext, failing the secure remote management constraint.

Why this answer

SSH on TCP port 22 provides encrypted, authenticated remote management of network devices, protecting credentials and session data from eavesdropping. It is the standard secure replacement for Telnet and is widely supported on routers and switches.

Exam trap

The trap is choosing HTTP because many routers have a web interface, but the question asks for secure remote management, and only SSH provides encrypted CLI access on its well-known port.

How to eliminate wrong answers

Option A is wrong because FTP on port 21 is an unencrypted file transfer protocol and does not provide interactive remote management of a router. Option B is wrong because HTTP on port 80 is unencrypted web traffic; while some devices offer a web GUI, it is not secure without HTTPS and is not the protocol/port pair for secure CLI management. Option D is wrong because Telnet on port 23 sends credentials and commands in cleartext, making it insecure for remote management.

426
Multi-Selectmedium

Which three ports are commonly used by secure protocols? (Choose THREE.)

Select 3 answers
A.80 (HTTP)
B.443 (HTTPS)
C.22 (SSH)
D.23 (Telnet)
E.636 (LDAPS)
AnswersB, C, E

Port 443 carries HTTPS, which wraps HTTP inside TLS, encrypting credentials and session data in transit. This directly satisfies the stem's requirement for a secure protocol port, unlike cleartext alternatives such as port 80. Microsoft Entra ID authentication traffic and most modern web APIs rely on 443 for this reason.

Why this answer

HTTPS uses 443, SSH uses 22, and LDAPS uses 636. HTTP (80), Telnet (23), and FTP (21) are insecure or unencrypted.

427
MCQhard

A company uses a mandatory access control (MAC) system where all files are labeled 'Confidential', 'Secret', or 'Top Secret'. A user with 'Secret' clearance tries to read a 'Top Secret' file. What is the outcome?

A.Access is allowed because the user has a legitimate need
B.Access is denied because the user's clearance is lower than the file's classification
C.Access is denied only if the file also has a category
D.Access is allowed because the user has Secret clearance
AnswerB

In mandatory access control, the no-read-up rule forbids reading data classified above the subject's clearance. A Secret-cleared user requesting a Top Secret file therefore fails the dominance check, and the reference monitor denies access regardless of need or ownership.

Why this answer

In a mandatory access control (MAC) system, access decisions are based on comparing the user's clearance level with the file's classification label. Since the user has 'Secret' clearance and the file is labeled 'Top Secret', the clearance is lower than the file's classification, so access is denied. This follows the fundamental MAC principle of 'no read up' (simple security property) in Bell-LaPadula model.

Exam trap

ISC2 often tests the misconception that 'need to know' or user role overrides clearance in MAC, but MAC strictly enforces clearance versus classification without considering discretionary permissions or need.

How to eliminate wrong answers

Option A is wrong because MAC does not consider 'need to know' or legitimate need; access is strictly based on clearance versus classification labels. Option C is wrong because categories are optional in MAC and their presence does not change the fact that clearance must meet or exceed the classification; denial occurs regardless of categories. Option D is wrong because 'Secret' clearance is lower than 'Top Secret', so access is denied, not allowed.

428
Multi-Selectmedium

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Select 2 answers
A.Confidentiality
B.Integrity
C.Authorization
D.Authentication
E.Non-repudiation
AnswersA, B

Confidentiality ensures information is disclosed only to authorised parties, typically enforced through encryption, access controls and classification. It forms one of the three pillars the policy must address, directly satisfying the stem's requirement for a core CIA triad component.

Why this answer

The CIA triad consists of Confidentiality, Integrity, and Availability. Authentication and Non-repudiation are related but not part of the core triad.

429
Multi-Selectmedium

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Select 2 answers
A.Password
B.Smart card
C.PIN
D.Fingerprint scan
E.Retina scan
AnswersD, E

A fingerprint scan is a biometric characteristic, placing it in Type 3 "something you are". It satisfies the stem's requirement for a Type 3 factor because the trait is inherent to the individual, unlike possession tokens or memorised passwords.

Why this answer

Type 3 authentication factors are based on something you are — biometric characteristics — so option D (fingerprint scan) is correct because it verifies a unique physical trait of the user, and option E (retina scan) is correct because it measures the distinct vascular pattern of the eye's retina. Both are biometric methods that cannot easily be shared or forgotten, which is the defining property of Type 3 factors. Option A (password) is wrong because it is a Type 1 factor (something you know), and option C (PIN) is also a Type 1 factor (something you know).

Option B (smart card) is wrong because it is a Type 2 factor (something you have).

430
MCQhard

A software development company wants to ensure that only authorized code changes are deployed to production. The security team proposes that developers should not have direct write access to the production environment, and that all code must be reviewed and approved by a different team member before deployment. Which security principle does this proposal primarily enforce?

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Non-repudiation
AnswerB

Separation of duties ensures that a critical task is divided among multiple people so that no single individual can complete it without oversight. By requiring code to be reviewed and approved by a different team member and denying developers direct production write access, the company prevents one person from both authoring and deploying changes. This directly enforces separation of duties in the software deployment process.

Why this answer

The proposal enforces separation of duties by requiring that code changes are reviewed and approved by someone other than the developer, and by preventing developers from directly writing to production. This ensures that no single person can both create and deploy code without oversight. Least privilege, defense in depth, and non-repudiation address different aspects of security and do not capture the dual-control requirement.

Exam trap

The trap here is focusing on the removal of direct write access as least privilege, when the more significant control is the mandatory review by a different person, which is separation of duties.

431
MCQhard

In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

A.Container Name
B.Common Name
C.Country Name
D.Context Name
AnswerB

CN is the attribute naming the entry itself within its container, holding the object's common name — here "John Smith". The stem's DN places CN as the leftmost, most specific relative distinguished name, with OU and DC components locating it hierarchically, so CN satisfies the question's request for the abbreviation's meaning.

Why this answer

In LDAP Distinguished Names (DNs), CN stands for Common Name, which identifies the specific object or entity within the directory hierarchy — in this case, the user 'John Smith'. LDAP DNs are read right-to-left, with the most specific attribute (CN) appearing first and the root domain components (DC) appearing last. CN is one of the most frequently used RDN (Relative Distinguished Name) attributes for naming users, groups, and other objects.

Exam trap

The trap here is that candidates confuse CN with other LDAP attributes like C (Country) or OU (Organizational Unit), or assume CN is a generic 'Container Name' — the exam tests whether you know the exact X.500 attribute abbreviations used in Distinguished Names.

How to eliminate wrong answers

Option A is wrong because 'Container Name' is not an LDAP attribute — containers are represented by OU (Organizational Unit) or other object classes, not CN. Option C is wrong because 'Country Name' is represented by the C attribute (e.g., C=US) in an LDAP DN, not CN. Option D is wrong because 'Context Name' is not a valid LDAP naming attribute; it is a fabricated term that does not exist in the X.500/LDAP schema.

432
MCQmedium

A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?

A.Only Tuesday incremental backup
B.Sunday full backup, Monday incremental, and Tuesday incremental
C.Only the Sunday full backup
D.Sunday full backup and Monday incremental backup
AnswerB

Incremental backups capture only changes since the previous backup, so restoration requires the last full backup plus every incremental in sequence. Sunday's full plus Monday's and Tuesday's incrementals reconstruct Tuesday's state; omitting either incremental loses intervening changes.

Why this answer

With a weekly full backup on Sunday and daily incrementals, each incremental captures only changes since the last backup. To restore to Tuesday's state you must apply the Sunday full backup first, then Monday's incremental, then Tuesday's incremental in sequence. Incrementals cannot be applied standalone because they depend on the previous backup chain.

Exam trap

The trap here is confusing incremental with differential backups — candidates who think each incremental is self-contained will pick 'only Tuesday incremental', but incrementals always require the full plus all prior incrementals.

How to eliminate wrong answers

Option A is wrong because a Tuesday incremental only contains changes since Monday's backup and cannot reconstruct the full system state on its own. Option C is wrong because the Sunday full backup only restores the state as of Sunday, losing all Monday and Tuesday changes. Option D is wrong because it stops at Monday's incremental and omits Tuesday's changes, so the restore would not reflect Tuesday's state.

433
MCQeasy

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

A.Honeypot
B.Subnetting
C.DMZ
D.VLAN
AnswerC

A DMZ sits between the internal network and the internet, exposing the web server to public traffic while firewalls restrict inbound connections to that segment alone. This satisfies the stem's requirement to isolate the server yet permit controlled access, preventing direct reach from the public internet into internal systems.

Why this answer

A DMZ (Demilitarized Zone) is a segmented network that sits between the internal trusted network and the untrusted internet, specifically designed to host publicly accessible services like web servers while isolating them from internal systems. Firewall rules control traffic between the internet, the DMZ, and the internal network, so if the web server is compromised, the attacker cannot directly reach internal resources.

Exam trap

The trap is confusing VLANs or subnetting with a DMZ — candidates pick VLAN because it 'segments,' but only a DMZ provides firewall-enforced isolation for public-facing services.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system meant to lure and observe attackers, not to host production web servers or provide controlled access. Option B is wrong because subnetting divides an IP network into smaller subnets for organization and routing efficiency, but it does not by itself create a security boundary or controlled access between public and internal networks. Option D is wrong because a VLAN segments traffic at Layer 2 within a network, but it does not provide the firewall-enforced isolation between a public-facing server and the internal network that a DMZ does — VLANs alone are not a security boundary.

434
Multi-Selecthard

A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)

Select 2 answers
A.The fingerprint and retina scans together demonstrate the principle of least privilege.
B.The fingerprint scan at the lab door is a biometric control that verifies a physiological characteristic of the individual.
C.The retina scan for the server cage is an inherence factor because it verifies a physical characteristic of the analyst.
D.Requiring both the fingerprint and retina scans for the server cage is an example of multifactor authentication.
E.Because both doors use biometrics, the facility has satisfied the requirement for two-factor authentication.
AnswersB, C

Fingerprint recognition measures a physiological trait, which classifies it as a biometric control. Because the scan is matched against an enrolled template to confirm the person's claimed identity, it functions as an authentication mechanism at the lab entrance, satisfying the requirement that a biometric verifies something the individual is.

Why this answer

Fingerprint and retina scans both measure physical characteristics of a person, so each is a biometric and an inherence factor. Pairing them strengthens verification but does not create multifactor authentication, because multifactor requires factors from separate categories such as knowledge, possession, and inherence. Least privilege concerns granted permissions, not the credentials presented at a door.

Exam trap

The trap here is counting two different biometric methods as two authentication factors, when both belong to the single inherence category.

435
MCQmedium

Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?

A.Denial of service
B.Social engineering
C.Malware
D.Data breach
AnswerA

Denial of service floods a system or network with traffic or malformed requests, exhausting bandwidth, connections or processing capacity so legitimate users cannot access the resource. Availability, rather than confidentiality or integrity, is the target of this incident type.

Why this answer

A Denial of Service (DoS) attack explicitly aims to disrupt the availability of a system or network resource, making it inaccessible to legitimate users. This aligns with the definition of a DoS incident, which focuses on overwhelming the target with traffic or exploiting vulnerabilities to exhaust resources. The other options describe different attack categories: social engineering targets human trust, malware is malicious software, and data breach involves unauthorized data access.

Exam trap

The trap here is confusing the goal of an attack with the method; candidates might select malware or social engineering because they are common attack types, but the question specifically asks for the incident type defined by the objective of making resources unavailable.

How to eliminate wrong answers

Option B is wrong because social engineering manipulates people into divulging confidential information or performing actions, not directly causing unavailability. Option C is wrong because malware is a broad category of malicious software that can have various goals, including data theft or disruption, but it is not specifically defined by the goal of denying service. Option D is wrong because a data breach involves unauthorized access to and exfiltration of sensitive data, not the disruption of service availability.

436
MCQmedium

A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?

A.Web Application Firewall (WAF)
B.Intrusion Detection System (IDS)
C.Intrusion Prevention System (IPS)
D.Next-Generation Firewall (NGFW)
AnswerB

An IDS passively inspects network traffic, matching signatures or anomalies to raise alerts without dropping packets. Because the stem specifies the device monitors and alerts but does not block, an Intrusion Detection System satisfies that non-preventive constraint; an IPS would actively block traffic inline.

Why this answer

An IDS (Intrusion Detection System) is passive and only alerts, while an IPS actively blocks.

437
Multi-Selecthard

A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)

Select 2 answers
A.Biometric reader on server room door
B.Cable locks on laptops
C.Session timeout settings
D.Password complexity policy
E.Role-based access control (RBAC)
AnswersA, B

A biometric reader authenticates identity through fingerprint or iris traits before granting entry, directly controlling who physically passes through the server room door. It is a preventive physical control restricting human access to the facility.

Why this answer

Option A (biometric reader on server room door) is correct because a biometric reader is a physical authentication mechanism that verifies a person's fingerprint, iris, or other biological trait before granting entry to the server room, making it a classic physical access control. Option B (cable locks on laptops) is correct because a cable lock is a physical restraint that tethers a laptop to a fixed object, deterring theft and unauthorized physical removal of the device. Option C (session timeout settings) is incorrect because it is a logical/technical control that terminates idle sessions, not a physical barrier.

Option D (password complexity policy) is incorrect because it is an administrative/logical control governing credential strength. Option E (role-based access control) is incorrect because RBAC is a logical access control model that grants permissions based on job roles, not physical access.

Exam trap

The trap is conflating logical access controls (RBAC, password policy, session timeout) with physical ones; candidates often select RBAC because it contains the word 'access,' but the question specifically asks for physical controls.

438
Multi-Selecthard

Which THREE of the following are considered essential security principles according to ISC2?

Select 3 answers
A.Separation of duties
B.Encryption
C.Non-repudiation
D.Biometrics
E.Least privilege
AnswersA, C, E

Separation of duties is an essential ISC2 security principle, splitting critical tasks across multiple people to prevent fraud and error. It satisfies the requirement by ensuring no single individual controls an entire process, enforcing checks and balances. ISC2 lists it alongside least privilege and defence in depth as foundational.

Why this answer

Correct: A, C, E. Separation of duties, non-repudiation, and least privilege are considered essential security principles according to ISC2. Encryption and biometrics are security mechanisms or controls, not foundational principles.

439
Multi-Selecthard

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

Select 3 answers
A.Static packet filtering based on IP and port
B.Application identification and control
C.User identity awareness
D.Stateful packet inspection
E.Integrated intrusion prevention system (IPS)
AnswersB, C, E

NGFWs inspect traffic to identify applications regardless of port, then allow, block, or shape them by category. This application-layer control directly addresses advanced threats that tunnel over permitted ports, a capability absent from traditional port-based firewalls.

Why this answer

Option B is correct because an NGFW performs deep packet inspection to identify applications (e.g., via App-ID) and enforce granular control based on the application rather than just port, which is essential against advanced threats that tunnel over allowed ports. Option C is correct because NGFWs integrate with directory services (e.g., Active Directory, LDAP) to map traffic to specific users and groups, enabling identity-based policies that traditional firewalls cannot enforce. Option E is correct because NGFWs bundle an integrated IPS that inspects traffic for known exploit signatures and behavioral anomalies, providing inline threat prevention without a separate appliance.

Option A is not correct because static packet filtering based on IP and port is a first-generation firewall capability, not a distinguishing NGFW feature. Option D is not correct because stateful packet inspection is a baseline capability of traditional stateful firewalls and is not unique to NGFWs.

Exam trap

The trap is including legacy firewall features like static packet filtering or stateful inspection as NGFW characteristics — candidates must distinguish first-, second-, and next-generation firewall capabilities.

440
Multi-Selecthard

A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)

Select 3 answers
A.Place only public-facing servers (e.g., web, email) in the DMZ.
B.Use a firewall to control traffic between the internet, DMZ, and internal network.
C.Configure the DMZ to communicate directly with the internal network without restrictions.
D.Allow all inbound traffic to the DMZ from the internet for ease of access.
E.Restrict inbound traffic to only required services (e.g., HTTP, SMTP).
AnswersA, B, E

Segregating public-facing web and email servers into the DMZ keeps them off the internal network, so a compromise cannot directly pivot inward. This satisfies the DMZ design constraint that only externally reachable services reside in that screened subnet.

Why this answer

Option A is correct because a DMZ is specifically designed to host public-facing services such as web and email servers, isolating them from the trusted internal network so that a compromise of these exposed hosts does not directly expose internal assets. Option B is correct because a firewall (or multiple firewalls) must mediate and filter traffic among the internet, the DMZ, and the internal network, enforcing distinct security policies for each zone rather than allowing unrestricted flows. Option E is correct because inbound traffic to the DMZ should be limited to only the ports and protocols required by the hosted services — for example TCP 80/443 for HTTP/HTTPS and TCP 25 for SMTP — following the principle of least privilege to minimize the attack surface.

Option C is incorrect because unrestricted DMZ-to-internal communication defeats the purpose of segmentation and would let a compromised DMZ host pivot directly into the internal network. Option D is incorrect because allowing all inbound internet traffic to the DMZ exposes unnecessary ports and services, greatly increasing the risk of exploitation.

Exam trap

The trap here is the 'convenience' distractor — options that promise easier access (allow all inbound, unrestricted DMZ-to-LAN) sound operationally appealing but violate the core DMZ principle of least privilege and defense in depth.

441
MCQmedium

An account lockout policy is implemented to protect against which type of attack?

A.Brute force
B.Man-in-the-middle
C.Social engineering
D.Phishing
AnswerA

An account lockout policy locks an account after a set number of failed authentication attempts, directly thwarting brute force attacks that rely on repeated password guessing. It satisfies the stem by halting the automated trial-and-error process before credentials are discovered.

Why this answer

An account lockout policy locks an account after a specified number of failed login attempts (e.g., 5 attempts), which directly thwarts brute-force attacks that rely on trying many password combinations. By locking the account, the attacker is prevented from continuing automated guessing, and the legitimate user or admin is alerted. This is the primary defensive purpose of account lockout.

Exam trap

The trap is that phishing and brute force both involve credential theft, but only brute force relies on repeated login attempts that lockout can stop — phishing yields valid credentials on the first try, bypassing lockout entirely.

How to eliminate wrong answers

Option B is wrong because man-in-the-middle attacks intercept communications between two parties (e.g., via ARP spoofing or rogue Wi-Fi) — account lockout does nothing to prevent session interception. Option C is wrong because social engineering manipulates people into revealing information or performing actions; lockout policies don't address human manipulation. Option D is wrong because phishing is a form of social engineering that tricks users into entering credentials on fake sites — the credentials are valid, so lockout won't trigger; anti-phishing requires user training, email filtering, and MFA.

442
Multi-Selecthard

Which THREE of the following are essential components of an incident response plan? (Select THREE.)

Select 3 answers
A.Preparation
B.Containment, Eradication, and Recovery
C.Business continuity plan activation
D.Detection and Analysis
E.Vulnerability scanning schedule
AnswersA, B, D

Preparation includes training and tools.

Why this answer

Preparation is the foundational phase of the NIST SP 800-61 incident response lifecycle, ensuring policies, tools, and trained personnel are in place before an incident occurs. Without preparation, subsequent phases like detection and containment cannot be executed effectively. The CC exam emphasizes that preparation includes establishing communication plans, acquiring forensic tools, and conducting tabletop exercises.

Exam trap

ISC2 often tests the distinction between incident response phases and adjacent operational processes (like BCP or vulnerability management) to see if candidates confuse proactive security tasks with the reactive incident response lifecycle.

443
Multi-Selecthard

A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)

Select 2 answers
A.It requires every service to maintain a local copy of all domain user passwords.
B.It provides mutual authentication, allowing both the client and the service to verify each other's identity.
C.It stores user passwords in a reversible encrypted format inside each service ticket.
D.It uses a trusted third party called the Key Distribution Center to issue tickets.
E.It transmits the user's password to each service in plaintext during authentication.
AnswersB, D

Kerberos supports mutual authentication because the service ticket is encrypted with the service's secret key, proving the ticket came from the Key Distribution Center, while the authenticator proves the client holds the session key. This lets both parties verify each other, which is valuable in domain environments where clients must be sure they are contacting a legitimate service and not an impostor.

Why this answer

Kerberos uses a trusted Key Distribution Center to issue ticket-granting and service tickets, and it supports mutual authentication because the service ticket is encrypted with the service key while the client's authenticator proves possession of the session key. Passwords are never sent to services or embedded in tickets, which is why the two selected characteristics accurately describe the protocol.

Exam trap

The trap here is assuming that because tickets grant access, they must carry the user's password, when in fact Kerberos deliberately keeps passwords out of tickets and off the wire.

444
MCQhard

During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?

A.Spoofing
B.Denial of Service (DoS)
C.Sniffing
D.Man-in-the-middle (MITM)
AnswerD

ARP spoofing lets the attacker position themselves between client and server, silently relaying and altering frames while both endpoints believe they hold a direct connection. That interception and modification of live traffic is precisely the man-in-the-middle condition the scenario describes, satisfying the requirement that communications pass through the attacker.

Why this answer

ARP poisoning lets an attacker send forged ARP replies so that the victim's traffic is redirected through the attacker's machine. Because the attacker sits between the client and the server, silently relaying and potentially altering packets, this is a classic man-in-the-middle (MITM) attack. The interception and modification of traffic is the defining characteristic that distinguishes MITM from mere spoofing or sniffing.

Exam trap

The trap is that ARP poisoning technically involves spoofing, so candidates pick 'Spoofing' — but the exam wants the attack category that describes the full outcome (interception plus modification), which is MITM.

How to eliminate wrong answers

Option A is wrong because spoofing only describes falsifying an identity (e.g., a MAC or IP address); ARP poisoning does involve spoofing, but the question emphasizes intercepting and modifying traffic, which is the MITM outcome, not spoofing alone. Option B is wrong because a DoS attack aims to disrupt availability, whereas here the attacker maintains the connection to eavesdrop and tamper. Option C is wrong because sniffing is passive capture of traffic; the scenario explicitly involves the attacker positioning themselves in the path and modifying data, which is active MITM behavior.

445
MCQmedium

During a security incident, the incident response team isolates a compromised workstation from the network. What is the primary purpose of this action?

A.To prevent further damage.
B.To comply with legal requirements.
C.To preserve forensic evidence.
D.To allow normal operations to continue.
AnswerA

Isolating the workstation severs the attacker's network path, containing the compromise so lateral movement, data exfiltration and further payload delivery cannot continue. This limits incident scope while forensic imaging and eradication proceed on the quarantined host.

Why this answer

Isolating a compromised workstation by disconnecting it from the network (e.g., disabling its switch port or unplugging the Ethernet cable) immediately stops all inbound and outbound traffic. This containment action prevents the attacker from moving laterally to other systems, exfiltrating data, or deploying additional malware, thereby limiting the scope and impact of the incident.

Exam trap

ISC2 often tests the distinction between containment (stopping the spread) and eradication (removing the threat); the trap here is that candidates confuse the secondary benefit of preserving evidence (Option C) with the primary purpose of isolation, which is to prevent further damage.

How to eliminate wrong answers

Option B is wrong because legal compliance (e.g., data breach notification laws) is a procedural requirement that follows containment, not the primary technical goal of isolation. Option C is wrong because while isolation can help preserve evidence by preventing tampering, the primary purpose is containment; forensic preservation is a secondary benefit and is better achieved by creating a forensic image before disconnection. Option D is wrong because isolation actually disrupts normal operations for the affected workstation; the goal is to stop malicious activity, not to allow continued normal operations.

446
MCQeasy

You are an IT administrator for a small business. The company has a backup system that performs nightly full backups of critical servers to an external hard drive. One morning, a user reports that they accidentally deleted an important file from a shared drive. You need to restore the file from last night's backup. However, when you connect the external hard drive to the backup server, the drive is not recognized, and you hear clicking sounds. The backup software shows that the most recent backup job completed successfully with no errors. What is the most likely cause of the problem?

A.The external hard drive has suffered a mechanical failure.
B.The backup software did not actually write the data.
C.The file was not included in the backup job.
D.The backup server has a driver issue.
AnswerA

Clicking sounds plus non-recognition indicate the drive's read/write heads or platters have physically failed. The successful backup job only confirms data was written earlier; mechanical failure now prevents the drive from spinning up, so the file cannot be restored from it.

Why this answer

The clicking sound from the external hard drive is a classic symptom of a mechanical failure, typically caused by a stuck read/write head or a failing spindle motor. Since the backup software reported a successful completion, the data was likely written to the drive, but the drive's physical components have since failed, preventing the system from recognizing it. This is a hardware-level issue that cannot be resolved by software or driver updates.

Exam trap

ISC2 often tests the distinction between software-reported success and actual hardware integrity, trapping candidates who assume a successful backup log guarantees recoverable data without considering post-backup physical failure.

How to eliminate wrong answers

Option B is wrong because the backup software logged a successful completion with no errors, indicating that the write process finished without issues; if the data had not been written, the software would have reported a failure or incomplete job. Option C is wrong because the user reported the file was on a shared drive, and the backup job was configured to perform full backups of critical servers, which typically includes all files on those drives; there is no evidence that the file was excluded. Option D is wrong because a driver issue would prevent the drive from being recognized but would not cause clicking sounds; clicking is a mechanical noise, not a software or driver symptom.

447
MCQeasy

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality directly addresses preventing unauthorised disclosure, which is the exact control objective stated in the stem. Encryption, access controls and data classification enforce confidentiality by restricting data access to authorised parties only. Integrity would concern unauthorised modification, and availability would concern timely access, neither of which matches the disclosure constraint.

Why this answer

Confidentiality is the element of the CIA triad that ensures information is not disclosed to unauthorized individuals, entities, or processes. The scenario explicitly states the goal is to prevent unauthorized disclosure of sensitive information, which is the definition of confidentiality. Controls such as encryption, access control lists, and data classification directly support confidentiality.

Therefore, option D is correct.

Exam trap

The trap here is confusing confidentiality with integrity or availability, especially when the question mentions 'controls' without specifying encryption or access controls; candidates might incorrectly associate 'prevent unauthorized disclosure' with integrity if they misread 'disclosure' as 'modification'.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad; it is a separate security property that ensures a party cannot deny having performed an action, often achieved through digital signatures and audit logs. Option B is wrong because integrity focuses on protecting data from unauthorized modification or alteration, not disclosure. Option C is wrong because availability ensures that systems and data are accessible to authorized users when needed, which is unrelated to preventing unauthorized disclosure.

448
Multi-Selectmedium

A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)

Select 2 answers
A.Install a host-based intrusion prevention system and configure it to alert only.
B.Enable full-disk encryption on the server's data volumes.
C.Enforce least privilege by removing unnecessary administrative rights and using dedicated service accounts with minimal permissions.
D.Remove or disable unnecessary services, daemons, and open ports that are not required for the server's role.
E.Schedule weekly full backups of the server to a remote location.
AnswersC, D

Limiting administrative rights and running services under dedicated low-privilege accounts constrains what an attacker can do after gaining a foothold. It reduces the number of accounts and processes capable of modifying the system or escalating privileges. This directly shrinks the exploitable surface and limits blast radius, making it a core hardening practice.

Why this answer

Reducing the operating system's attack surface means removing or disabling anything not required for the server's role and limiting the privileges available to users and services. Eliminating unnecessary daemons and ports removes entry points, while least privilege and dedicated service accounts constrain what an attacker can do if one is reached. Encryption, alert-only intrusion prevention, and backups address confidentiality, detection, or recovery rather than shrinking the exploitable surface.

Exam trap

The trap here is equating any security control, such as encryption or backups, with attack-surface reduction, when only removing exposed functionality and limiting privileges actually shrink what an attacker can target.

449
MCQmedium

A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?

A.Stateless packet filtering
B.Application proxy
C.Stateful inspection
D.Next-generation firewall (NGFW)
AnswerC

Stateful inspection tracks connection state in a session table, so it filters on source and destination IP addresses and ports while recognising established flows. Stateless packet filtering cannot track connection state, which the stem explicitly requires.

Why this answer

Stateful inspection firewalls maintain a state table that tracks the context of each connection (source/destination IP, ports, and TCP flags), allowing return traffic for established sessions without an explicit rule. This satisfies both requirements in the question: filtering by IP and port, and tracking connection state. Stateless filters can match IPs and ports but have no memory of sessions.

Exam trap

The trap is conflating 'stateful inspection' with 'NGFW' — candidates see 'control traffic by IP and port' and jump to NGFW, but the question's second clause ('tracking the state of connections') is the textbook definition of stateful inspection, and NGFW is a superset that isn't required here.

How to eliminate wrong answers

Option A is wrong because stateless packet filtering evaluates each packet in isolation using only header fields — it cannot track connection state, so return traffic must be explicitly permitted with broad rules. Option B is wrong because an application proxy operates at Layer 7, terminating and re-originating connections to inspect application payloads; while it can filter by IP/port, its defining feature is deep application inspection, not state tracking, and it adds latency. Option D is wrong because an NGFW includes stateful inspection plus additional capabilities like IPS, application awareness, and TLS inspection — it is overkill for the stated requirement and the question asks for the type defined by state tracking, which is stateful inspection.

450
Multi-Selectmedium

An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?

Select 2 answers
A.802.1X authentication
B.Firewall rules
C.Port security
D.NAT
E.VLAN segmentation
AnswersA, C

802.1X authentication requires a supplicant to authenticate against a RADIUS server via EAP before the switch grants port access, satisfying the authorised-devices-only constraint. Unauthenticated devices remain in an uncontrolled state and cannot pass traffic onto the wired network.

Why this answer

802.1X authentication (A) is correct because it enforces port-based network access control on wired switches, requiring devices to authenticate via EAPOL to a RADIUS server before the port is authorized to pass traffic. Port security (C) is correct because it restricts which MAC addresses may be learned on a switch port, limiting connections to known/authorized devices and taking action (shutdown, restrict, or protect) on violations. Firewall rules (B) filter traffic by IP/port but do not authenticate or identify devices at the access layer, so they cannot ensure only authorized devices connect.

NAT (D) merely translates addresses for routing/Internet access and provides no device authorization. VLAN segmentation (E) isolates traffic into logical groups but does not by itself verify or restrict which devices are permitted to connect.

Exam trap

The trap is choosing 'VLAN segmentation' or 'firewall rules' as access control — both provide logical separation or traffic filtering, but neither authenticates a device at the physical switch port, which is what 'only authorized devices can connect' requires.

Page 5

Page 6 of 14

Page 7