Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 451–525

989 questions total · 14pages · All types, answers revealed

Page 6

Page 7 of 14

Page 8
451
MCQeasy

A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?

A.Implement account lockout after a threshold of failed attempts.
B.Enable single sign-on (SSO).
C.Require complex passwords.
D.Disable the accounts after one failed attempt.
AnswerA

Mitigates brute-force attacks by locking accounts after multiple failures.

Why this answer

Implementing an account lockout policy after a defined threshold of failed attempts (e.g., 5 failed attempts within 15 minutes) directly mitigates brute-force password guessing attacks from a single source. This control prevents an attacker from continuously trying different passwords across multiple accounts, effectively rate-limiting the attack at the authentication layer.

Exam trap

ISC2 often tests the distinction between preventive controls (like account lockout) and deterrent controls (like complex passwords), and the trap here is that candidates choose complex passwords because they think stronger passwords stop brute-force attacks, but they fail to recognize that unlimited attempts still allow eventual guessing regardless of password complexity.

How to eliminate wrong answers

Option B is wrong because single sign-on (SSO) centralizes authentication but does not prevent repeated failed login attempts; it may even increase the blast radius if the SSO provider is compromised. Option C is wrong because requiring complex passwords makes individual passwords harder to guess but does not stop an attacker from making unlimited login attempts; it addresses password strength, not attack frequency. Option D is wrong because disabling an account after a single failed attempt would cause massive denial of service for legitimate users due to typos or forgotten passwords, and it is not a standard security practice; account lockout requires a reasonable threshold to balance security and usability.

452
Multi-Selecthard

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Select 2 answers
A.ARP spoofing
B.MAC flooding
C.Ping of death
D.SYN flood
E.DNS amplification
AnswersD, E

SYN floods exploit spoofed source addresses to conceal the attacker's identity while exhausting a server's half-open connection table. Each forged SYN forces the target to allocate resources and await a final ACK that never arrives, directly satisfying the stem's requirement for attacks that commonly employ IP spoofing.

Why this answer

SYN floods often spoof source IPs to hide the attacker, and DNS amplification attacks use spoofed source IPs to direct responses to the victim. ARP spoofing is local and does not involve IP spoofing in the same way, while MAC flooding and ping of death are different.

453
MCQeasy

Which of the following is a primary benefit of implementing network segmentation?

A.Reduced attack surface
B.Eliminates the need for firewalls
C.Increased bandwidth
D.Simplified IP address management
AnswerA

Segmenting the network into isolated zones limits lateral movement, so a compromised host cannot reach unrelated systems. This directly shrinks the number of exploitable entry points and reachable targets, satisfying the requirement to reduce the attack surface.

Why this answer

Network segmentation divides a network into smaller, isolated segments, which limits an attacker's ability to move laterally after compromising a single host. By restricting traffic between segments using VLANs, ACLs, or firewall rules, the attack surface is reduced because fewer systems are exposed to potential threats. This is a primary security benefit, as it contains breaches and minimizes the impact of malware or unauthorized access.

Exam trap

ISC2 often tests the misconception that segmentation eliminates the need for firewalls, but in reality, segmentation and firewalls are complementary—firewalls enforce the segmentation policy, and segmentation reduces the attack surface by limiting exposure.

How to eliminate wrong answers

Option B is wrong because network segmentation does not eliminate the need for firewalls; instead, it often relies on firewalls (or ACLs on routers/L3 switches) to enforce segmentation policies and filter traffic between segments. Option C is wrong because segmentation does not increase bandwidth; it can actually introduce overhead from inter-segment routing and may require careful design to avoid bottlenecks. Option D is wrong because segmentation often complicates IP address management by requiring separate subnets or VLANs, not simplifying it.

454
Multi-Selecthard

Which THREE components are part of the AAA framework?

Select 3 answers
A.Authentication
B.Accountability
C.Auditing
D.Accounting
E.Authorization
AnswersA, D, E

Authentication is the first component of the AAA framework: it verifies a subject's claimed identity, typically via credentials, certificates or tokens, before any access decision is made. Authorisation and accounting depend on this verified identity.

Why this answer

The AAA framework consists of Authentication, Authorization, and Accounting. Option A (Authentication) is correct because it verifies a user's or device's identity, typically via credentials such as passwords, certificates, or tokens, before granting access. Option E (Authorization) is correct because it determines what an authenticated identity is permitted to do, such as which resources, commands, or services it may access.

Option D (Accounting) is correct because it tracks and logs resource usage and activity, often recording session start/stop times, bytes transferred, and commands executed for billing, auditing, or security analysis. Option B (Accountability) is not one of the three AAA components, though it is a related security goal supported by accounting and auditing. Option C (Auditing) is also not part of the AAA acronym; auditing is a separate process that reviews logs and controls, often using the records produced by accounting.

Exam trap

ISC2 often tests the distinction between 'Accounting' and 'Auditing' — candidates confuse the two because both involve logs, but Accounting is the collection of data (e.g., start/stop records), while Auditing is the analysis of that data, which is not part of the AAA framework.

455
MCQeasy

An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?

A.Notify law enforcement
B.Eradicate the malware from the server
C.Restore from backup
D.Contain the affected system
AnswerD

Containment isolates the infected server, preventing lateral spread to other systems before eradication begins. The stem's constraint is sequencing: detection precedes containment, which must precede eradication and recovery. Containing first limits encryption scope and preserves evidence, satisfying the immediate priority of stopping propagation rather than remediating the already-compromised host.

Why this answer

Immediately after detection, the priority is to contain the ransomware to prevent it from spreading laterally to other systems. According to NIST SP 800-61 and standard incident response frameworks, containment is the first step after detection and analysis, as it limits damage and preserves evidence for forensic investigation.

Exam trap

The trap here is that candidates confuse the urgency of recovery actions (like restoring from backup) with the correct incident response sequence, forgetting that containment must always come first to stop the spread and preserve forensic evidence.

How to eliminate wrong answers

Option A is wrong because notifying law enforcement is a post-containment step, typically done after the scope is understood and evidence is preserved; premature notification can disrupt the response. Option B is wrong because eradicating the malware before containment risks alerting the attacker or causing the ransomware to trigger encryption of additional data; containment must precede eradication. Option C is wrong because restoring from backup before containment can reintroduce the infection if the backup is compromised or if the ransomware is still active on the network; containment ensures the environment is clean before recovery.

456
MCQmedium

A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?

A.Kerberos ticket granting
B.Remote Authentication Dial-In User Service (RADIUS)
C.Security Assertion Markup Language (SAML)
D.Lightweight Directory Access Protocol (LDAP) bind
AnswerC

SAML is an XML-based federation standard where an identity provider sends signed assertions to service providers, enabling single sign-on. The scenario's central identity provider asserting identity to email, code repository, and expense applications matches SAML's identity provider and service provider model, making this the correct technology.

Why this answer

Federation allows one trusted identity provider to authenticate a user and send signed assertions to multiple service providers, delivering single sign-on across separate systems. SAML is the standard that defines these assertions and the request-response flow. The described environment, where one login grants access to email, code repository, and expense applications, is a textbook SAML federation deployment.

Exam trap

The trap here is treating any single sign-on technology as interchangeable, when the identity provider asserting identity to separate applications specifically indicates federation.

457
MCQhard

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?

A.Non-repudiation and integrity
B.Confidentiality of the patch contents
C.Authorization of the customer
D.Availability of the download server
AnswerA

Signing with a private key and verifying with the corresponding public key proves the patch originated from the vendor and was not altered. This provides non-repudiation because the vendor cannot deny signing it, and integrity because any modification invalidates the signature. Thus it correctly describes the security property.

Why this answer

A digital signature created with a private key and verified with the corresponding public key provides authenticity, integrity, and non-repudiation. Customers can confirm the patch came from the vendor and was not modified, and the vendor cannot later deny signing it. Confidentiality, availability, and authorization are separate properties not delivered by this signing and verification process.

Exam trap

The trap here is assuming that signing also encrypts the patch, but signatures provide integrity and origin proof, not confidentiality.

458
MCQmedium

Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?

A.An external host is performing a port scan against internal systems.
B.The firewall is misconfigured and blocking legitimate traffic.
C.An internal host has been compromised and is exfiltrating data.
D.An external host is launching a denial-of-service (DoS) attack.
AnswerA

Repeated denied TCP packets from a single external address to multiple internal hosts, blocked inbound by the OUTSIDE_IN access-group, indicate reconnaissance. Sequential connection attempts across ports and hosts match port-scanning behaviour rather than legitimate traffic or misconfiguration.

Why this answer

The repeated denied TCP packets from 192.0.2.10 (an external IP) to multiple internal hosts indicate a port scan. The access-group 'OUTSIDE_IN' is applied to the outside interface, and the firewall is denying these packets because they match a deny ACE (access control entry) that blocks unsolicited inbound traffic. This pattern of multiple denied connections from a single external source to different internal destinations is characteristic of a reconnaissance scan, not a DoS attack or data exfiltration.

Exam trap

ISC2 often tests the distinction between a port scan and a DoS attack, where candidates mistakenly choose DoS because they see 'repeated denied packets' without recognizing the pattern of multiple destinations versus a single target flood.

How to eliminate wrong answers

Option B is wrong because the firewall is correctly blocking unsolicited inbound traffic as per the configured access-group; there is no misconfiguration indicated—the denials are expected behavior for a security policy that denies inbound connections by default. Option C is wrong because data exfiltration originates from an internal host sending data outbound, not from an external host sending packets inbound; the source IP 192.0.2.10 is external, so this is not an internal compromise scenario. Option D is wrong because a denial-of-service (DoS) attack typically involves a high volume of traffic aimed at overwhelming a single target, not repeated denied packets to multiple internal hosts; the pattern here is more consistent with a scan (low rate, multiple destinations) rather than a flood.

459
MCQmedium

In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?

A.Organizational Units (OUs)
B.Group Policy Objects (GPOs)
C.Domain controllers
D.LDAP
AnswerA

Organizational Units are containers within Active Directory that hold users, groups and computers hierarchically, letting administrators link Group Policy Objects at specific levels. This hierarchical structure satisfies the stem's requirement for organising directory objects so policies apply appropriately.

Why this answer

Organizational Units (OUs) are the container objects within Active Directory that provide the hierarchical structure used to organize users, groups, computers, and other objects. Because Group Policy can be linked directly to an OU, it is the primary mechanism for scoping policy application to a subset of the directory. This makes OUs the correct answer for organizing objects hierarchically for policy purposes.

Exam trap

The trap here is confusing the container (OU) with the policy content (GPO) or the protocol (LDAP); candidates often pick GPO because the question mentions policies, missing that the question asks what organizes objects hierarchically.

How to eliminate wrong answers

Option B is wrong because Group Policy Objects are the policy definitions themselves, not the containers that organize directory objects — GPOs are linked to sites, domains, or OUs. Option C is wrong because domain controllers are servers that host the AD database and authenticate users, not organizational containers. Option D is wrong because LDAP is an access protocol used to query and modify directory services, not a hierarchical organizational component within AD.

460
Multi-Selectmedium

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Select 2 answers
A.All affected customers immediately
B.General public via press release
C.Legal department
D.Executive management
E.Local law enforcement automatically
AnswersC, D

Legal counsel must be engaged immediately because they assess breach-notification duties, preserve attorney-client privilege over incident findings, and approve any external wording before disclosure. This satisfies the stem's constraint of notifying stakeholders without revealing sensitive details that could worsen the situation, since legal review gates what may lawfully and safely be communicated.

Why this answer

Option C (Legal department) is correct because incident response best practices require immediate legal counsel involvement to assess regulatory notification obligations (e.g., GDPR 72-hour breach reporting, HIPAA, SEC disclosure rules), preserve attorney-client privilege over incident findings, and guide controlled communications that avoid premature or legally risky disclosures. Option D (Executive management) is correct because senior leadership must be notified immediately to authorize containment actions, allocate resources, make strategic decisions about service shutdowns or customer impact, and serve as the approved channel for any external statements. Option A is not correct because notifying all affected customers immediately is premature before the scope, root cause, and legal notification requirements are established, and it risks amplifying the incident.

Option B is not correct because issuing a general public press release at the outset can worsen the situation by revealing sensitive details and tipping off attackers. Option E is not correct because law enforcement should be engaged selectively based on jurisdiction, legal guidance, and incident severity, not automatically in every case.

461
Multi-Selecthard

A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)

Select 2 answers
A.Deploying a wireless intrusion detection system to alert on rogue access points.
B.Requiring TLS for all internal application traffic between clients and servers.
C.Implementing MAC address filtering to admit only known corporate devices.
D.Enforcing WPA3-Enterprise with protected management frames on the wireless infrastructure.
E.Disabling SSID broadcast to make the corporate network harder to find.
AnswersB, D

TLS encrypts and integrity-protects application data end to end between the client and the server, so even if an attacker captures or manipulates wireless frames, the payload remains confidential and tampering is detected. This complements link-layer protections by securing the traffic above the wireless hop, directly addressing on-path confidentiality and integrity.

Why this answer

Protecting against an on-path attacker requires cryptography at both the wireless link and the application layer. WPA3-Enterprise with protected management frames secures the radio hop and prevents management-frame manipulation, while TLS secures application data end to end. Monitoring, SSID hiding, and MAC filtering may add visibility or friction but do not encrypt or integrity-protect the traffic itself, so they do not directly meet the stated goal.

Exam trap

The trap here is treating visibility or obscurity controls, such as wireless intrusion detection or hidden SSIDs, as if they provided cryptographic protection of traffic.

462
MCQeasy

Which of the following is a connectionless, unreliable transport protocol?

A.IP
B.TCP
C.UDP
D.ICMP
AnswerC

UDP sends datagrams without establishing a session, handshake or delivery acknowledgement, so packets may arrive out of order or not at all. This absence of connection state and retransmission makes it the connectionless, unreliable transport protocol.

Why this answer

UDP is connectionless and does not guarantee delivery.

463
MCQhard

A security auditor discovers that during a VLAN hopping attack, a threat actor was able to send frames from a workstation on VLAN 10 to a target on VLAN 20. Which configuration flaw is most likely responsible?

A.Dynamic Trunking Protocol (DTP) is enabled on access ports
B.The trunk port is set to native VLAN 1
C.The switch is using default VLAN 1 for management
D.Port security is not configured
AnswerA

DTP negotiates trunk links automatically; an access port left in dynamic auto or desirable mode can be persuaded to form a trunk, letting the attacker send 802.1Q-tagged frames that reach VLAN 20. Disabling DTP and hard-setting access mode prevents this VLAN hopping path.

Why this answer

A VLAN hopping attack exploits the Dynamic Trunking Protocol (DTP) to negotiate a trunk link between the attacker's workstation and the switch. If DTP is enabled on an access port, the attacker can send DTP frames to form a trunk, allowing frames from VLAN 10 to be tagged and forwarded to VLAN 20. Disabling DTP on all access ports with the 'switchport nonegotiate' command prevents this attack.

Exam trap

ISC2 often tests the distinction between VLAN hopping via DTP (trunk negotiation) and double-tagging attacks (native VLAN manipulation), so candidates may confuse the two and incorrectly choose the native VLAN option.

How to eliminate wrong answers

Option B is wrong because setting the native VLAN to 1 is a default configuration, but it does not directly enable VLAN hopping; native VLAN attacks (e.g., double-tagging) require the attacker to be on the native VLAN and the trunk to forward untagged frames, which is a different attack vector. Option C is wrong because using default VLAN 1 for management is a security best practice violation (it should be changed to a dedicated VLAN), but it does not allow a workstation to send frames across VLANs; management VLAN misconfiguration does not enable trunk negotiation. Option D is wrong because port security limits MAC addresses on a port but does not prevent DTP-based trunk negotiation; VLAN hopping can occur even with port security enabled if DTP is active.

464
MCQhard

A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?

A.Excessive privilege because engineers can manage production databases
B.Lack of accountability because shared credentials prevent tracing actions to an individual
C.Missing authorization because the account was never formally approved
D.Weak authentication because the shared account uses only a single password
AnswerB

Accountability requires that every action can be attributed to a specific identity through unique credentials and audit logs. When several engineers share one privileged account, the logs record only the shared identity, so no one can be held responsible for a given change, which is exactly the control failure the audit identified.

Why this answer

Accountability depends on unique identities so that logs can tie each action to one person. Sharing a single privileged credential collapses multiple engineers into one identity, making attribution impossible and undermining nonrepudiation. The remedy is individual named accounts with privileged access management, not merely stronger authentication or additional approvals.

Exam trap

The trap here is focusing on the password strength of the shared account, when the real defect is that one credential destroys individual attribution.

465
Multi-Selectmedium

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

Select 2 answers
A.Fencing around the building
B.Complex password policy
C.Cable locks on individual servers
D.Session timeout settings
E.Biometric reader on server room door
AnswersA, E

Perimeter fencing establishes the outermost physical boundary, deterring and delaying intruders before they reach the building housing the server room. It forms the first layer of a defence-in-depth strategy, complementing interior controls such as locks and cameras.

Why this answer

Fencing around the building (A) is a valid physical security layer because it establishes the outermost perimeter control, deterring and delaying unauthorized access before an attacker can reach the facility itself. A biometric reader on the server room door (E) is also correct because it enforces an authentication-based access control at the innermost physical layer, ensuring only authorized personnel can enter the room housing the servers. Together these represent defense-in-depth at the perimeter and at the asset boundary.

The remaining options are logical/technical controls rather than physical layers: a complex password policy (B) governs authentication credentials, cable locks on individual servers (C) are a device-level physical tether but not a room/building security layer in this context, and session timeout settings (D) are logical access controls that terminate idle sessions.

Exam trap

The trap here is confusing logical security controls (passwords, session timeouts) with physical security layers, and overlooking that cable locks, while physical, are not a primary layer for server room protection.

466
MCQhard

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

A.Confidential data
B.Internal data
C.Sensitive PII
D.Public data
AnswerC

Sensitive PII covers data elements whose exposure causes heightened harm, such as social security numbers and medical records, which is precisely what the stem lists. Ordinary PII alone would not capture the elevated protection these identifiers and health data demand under privacy principles.

Why this answer

Sensitive PII is the correct classification because it includes data elements like Social Security numbers and medical records that, if disclosed, could cause significant harm, discrimination, or identity theft. Under privacy frameworks such as NIST SP 800-122 and GDPR, these are explicitly categorized as sensitive PII requiring stricter protection. Unlike general confidential data, sensitive PII has specific regulatory and compliance implications, including breach notification laws and mandatory safeguards.

Exam trap

The trap here is confusing broad data classification terms like 'confidential' with the specific regulatory category of 'sensitive PII,' which carries distinct legal and compliance obligations.

How to eliminate wrong answers

Option A is wrong because 'confidential data' is a broader, less precise term that doesn't capture the specific legal and regulatory obligations tied to sensitive PII. Option B is wrong because 'internal data' refers to information not intended for public release but lacks the heightened sensitivity and compliance requirements of PII like SSNs and medical records. Option D is wrong because 'public data' is information freely available and poses no risk if disclosed, which directly contradicts the nature of SSNs and medical records.

467
MCQeasy

A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?

A.Enable two-factor authentication.
B.Disable the server's network interface.
C.Block the IP address at the firewall.
D.Change the server's IP address.
AnswerC

Blocking the source IP at the firewall immediately halts the brute-force attempts against the critical server, containing the threat while investigation continues. This satisfies the stem's requirement for the immediate action the analyst should take.

Why this answer

Blocking the IP address at the firewall is the immediate action because it stops the ongoing brute-force attack at the network perimeter without affecting the server's availability or internal operations. Firewall rules can be applied quickly using access control lists (ACLs) to deny traffic from the specific external IP, which is a standard first response to mitigate a single-source attack.

Exam trap

ISC2 often tests the distinction between immediate containment actions (like blocking an IP at the firewall) and long-term security improvements (like enabling 2FA), trapping candidates who confuse proactive hardening with reactive incident response.

How to eliminate wrong answers

Option A is wrong because enabling two-factor authentication (2FA) is a long-term security improvement that does not stop the current attack in progress; it requires configuration and user enrollment, leaving the server exposed during the delay. Option B is wrong because disabling the server's network interface would deny service to all legitimate users, causing a denial of service (DoS) and violating the principle of maintaining availability. Option D is wrong because changing the server's IP address is a reactive measure that does not prevent the attacker from scanning and finding the new IP, and it disrupts legitimate DNS and client connections without addressing the root cause.

468
MCQmedium

A security engineer is designing a DMZ for a web server that must be accessible from the internet. The web server needs to query an internal database server. Which network security approach best limits exposure?

A.Use a single firewall with rules that allow all traffic from the internet to the internal network.
B.Place both servers in the same subnet with a firewall allowing all traffic.
C.Place the database server in the DMZ with the web server.
D.Place the web server in the DMZ and the database server in the internal network, with a firewall allowing only specific traffic from the web server to the database.
AnswerD

Segregating tiers by trust level satisfies the constraint of limiting exposure: the DMZ host is internet-reachable, while the database stays shielded on the internal network. The firewall enforces least privilege by permitting only the specific web-to-database traffic required.

Why this answer

It implements a true DMZ architecture: the web server resides in the DMZ (a semi-trusted zone) while the database server remains in the internal network, protected by a firewall that permits only specific traffic (e.g., TCP/3306 for MySQL or TCP/1433 for MSSQL) from the web server. This minimizes the attack surface by ensuring that even if the web server is compromised, the database server is not directly reachable from the internet, and the firewall enforces strict stateful inspection and access control.

Exam trap

ISC2 often tests the misconception that placing both servers in the DMZ simplifies security, but the trap is that the database server should never be in the DMZ because it contains sensitive data and must be isolated behind an additional firewall layer to enforce defense in depth.

How to eliminate wrong answers

Option A is wrong because allowing all traffic from the internet to the internal network bypasses any security boundary, exposing the entire internal network to direct attack and violating the principle of least privilege. Option B is wrong because placing both servers in the same subnet with a firewall allowing all traffic eliminates network segmentation; if the web server is compromised, the database server is on the same broadcast domain and can be attacked laterally without any firewall restriction. Option C is wrong because placing the database server in the DMZ with the web server exposes the database to the internet (even if indirectly), as the DMZ is a less trusted zone; an attacker who compromises the web server can then directly access the database without traversing an additional firewall layer.

469
Multi-Selecteasy

Which TWO of the following are examples of preventive security controls?

Select 2 answers
A.Encryption
B.Backup
C.Antivirus software
D.Firewall
E.Intrusion detection system
AnswersC, D

Antivirus software is preventive because it blocks or quarantines malicious code before execution, stopping threats at the endpoint. This contrasts with detective controls such as logging or IDS, which only identify activity after it occurs.

Why this answer

Antivirus software (C) is a preventive control because it actively blocks, quarantines, or removes malicious code before it can execute or spread, stopping an incident from occurring. A firewall (D) is likewise preventive: it enforces ACL rules on ports, protocols, and IP addresses to deny unauthorized traffic at the network perimeter before it reaches protected hosts. By contrast, encryption (A) is primarily a protective/confidentiality mechanism that renders data unreadable rather than stopping an event, backup (B) is a corrective/recovery control used after data loss, and an intrusion detection system (E) is a detective control that only alerts on suspicious activity rather than blocking it.

Exam trap

The trap is that encryption is often assumed to be preventive, but the exam expects you to distinguish controls that block an event (firewall, antivirus) from those that protect data or detect/restore after the fact.

470
MCQeasy

Which of the following best describes the purpose of a session timeout?

A.To automatically log out inactive users
B.To enforce password complexity
C.To restrict access based on need-to-know
D.To prevent brute-force attacks
AnswerA

A session timeout is a crucial security mechanism designed to automatically terminate a user's active session after a specified period of inactivity. This process invalidates the session token or cookie, forcing re-authentication and preventing unauthorised access to an unattended workstation or application. Its primary purpose, as the stem asks, is to enhance security by ensuring inactive users are logged out, mitigating risks of session hijacking or data exposure.

Why this answer

A session timeout is a security control that automatically terminates a user's authenticated session after a defined period of inactivity. Its core purpose is to prevent unauthorized access when a user leaves a workstation unattended, reducing the window of opportunity for someone else to use the still-authenticated session. It does not enforce password rules, restrict data by need-to-know, or block brute-force attempts.

Exam trap

The trap here is confusing authentication hardening controls (password complexity, lockout) with session lifecycle controls (timeout), since all are 'security settings' but address different attack windows.

How to eliminate wrong answers

Option B is wrong because password complexity is enforced by password policy settings (length, character classes, history), not by session timeouts. Option C is wrong because need-to-know access restriction is implemented through authorization models such as RBAC, ABAC, or ACLs, not session expiration. Option D is wrong because brute-force protection is handled by account lockout thresholds, rate limiting, CAPTCHAs, or MFA, not by timing out idle sessions.

471
MCQeasy

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

A.Social engineering
B.Malware
C.Unauthorised access
D.Denial of service
AnswerA

Social engineering manipulates people into divulging confidential information; phishing emails impersonating trusted entities are its classic vector. The fraudulent email tricking an employee into revealing credentials is precisely this category, distinguishing it from technical exploits such as malware or network attacks.

Why this answer

Social engineering is the category of incident where an attacker manipulates a person into divulging confidential information such as login credentials, typically via phishing or pretexting. A fraudulent email tricking an employee into revealing credentials is the textbook definition of social engineering, which exploits human trust rather than technical vulnerabilities.

Exam trap

The trap is conflating the attack method (social engineering) with its consequence (unauthorised access) — candidates pick the outcome category instead of the technique category.

How to eliminate wrong answers

Option B is wrong because malware involves malicious software executing on a system (viruses, ransomware, trojans) — no code execution is described here, only deception of a human. Option C is wrong because unauthorised access is the outcome or effect of an attack, not the attack category itself; the credential theft may lead to unauthorised access, but the incident described is the deception. Option D is wrong because denial of service aims to disrupt availability of systems or services, which is unrelated to tricking a user into revealing credentials.

472
MCQmedium

A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?

A.Accounting
B.Authentication
C.Authorisation
D.Identification
AnswerD

Entering a username asserts a claimed identity to the system, which is the identification phase. Authentication would then verify that claim via the password. The username alone is an identifier, not proof, so it maps to identification within the access control process.

Why this answer

Entering a username is the act of claiming an identity to the system, which is the identification phase. Authentication is the subsequent step where the password is verified to prove that claimed identity.

Exam trap

The trap here is conflating identification with authentication — candidates see 'username and password' and pick authentication, forgetting that the username alone is the identification step.

How to eliminate wrong answers

Option A is wrong because accounting is the logging and tracking of user activity (e.g., audit trails, session records), not the act of presenting an identity. Option B is wrong because authentication is the verification of the credential (the password step), not the username entry itself. Option C is wrong because authorisation determines what resources the authenticated user may access, which occurs after both identification and authentication.

473
MCQeasy

Which layer of the OSI model is responsible for routing packets based on IP addresses?

A.Data Link layer
B.Transport layer
C.Network layer
D.Physical layer
AnswerC

The network layer handles logical addressing and path selection, forwarding packets between networks based on destination IP addresses. Data link addresses frames by MAC, transport segments by port, so routing decisions belong exclusively to layer 3.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing packets based on IP addresses. It determines the best path for data to travel across multiple networks, using routers to forward packets hop-by-hop. This layer encapsulates data into packets and handles fragmentation and reassembly when necessary.

Exam trap

The trap here is confusing the roles of Layer 2 and Layer 3: candidates often associate 'packets' with the Data Link layer because both deal with addressing, but only Layer 3 uses IP addresses for routing across networks.

How to eliminate wrong answers

Option A is wrong because the Data Link layer (Layer 2) handles physical addressing (MAC addresses) and framing for communication within a single network segment, not routing between networks. Option B is wrong because the Transport layer (Layer 4) provides end-to-end communication, segmentation, flow control, and error recovery (e.g., TCP/UDP), but does not route packets based on IP addresses. Option D is wrong because the Physical layer (Layer 1) deals with the transmission of raw bits over a physical medium, defining electrical, mechanical, and procedural specifications, and has no concept of IP addresses or routing.

474
MCQmedium

A company experiences a ransomware attack that encrypts its file servers. The security team restores operations from offline backups taken the previous night. Which security principle does the restoration from backups primarily support?

A.Availability
B.Integrity
C.Confidentiality
D.Non-repudiation
AnswerA

Availability ensures that systems and data are accessible to authorized users when needed. Ransomware encryption makes the file servers unusable, and restoring from offline backups taken the previous night returns the data and services to operation. This directly addresses the availability objective by minimizing downtime and data loss. Offline backups are especially valuable because they are not reachable by the malware, so they remain a reliable recovery source.

Why this answer

Ransomware encryption makes the file servers unavailable, and restoring from an offline backup taken the previous night brings the data and services back online with minimal loss. That is the availability objective of the CIA triad. Confidentiality protects against disclosure, integrity protects against unauthorized alteration, and non-repudiation proves actions; the recovery activity here is specifically about regaining access to systems and data.

Exam trap

The trap here is selecting integrity because ransomware alters files, but the restoration activity is aimed at restoring access, which is availability.

475
MCQmedium

An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?

A.A second external hard drive stored on-site
B.An incremental backup to a network share
C.A full backup on tape stored in the same room
D.A cloud backup stored offsite
AnswerD

A cloud backup stored offsite satisfies the 3-2-1 rule's offsite leg, since the existing external drive already provides the second copy on a different medium. The primary server plus daily external backup give two copies; only an offsite location remains outstanding, which cloud storage delivers without physical transport.

Why this answer

The 3-2-1 backup rule requires at least three copies of data, on two different media types, with one copy stored offsite. The organization currently has two copies (primary and external hard drive), both likely on-site and possibly the same media type. Adding a cloud backup provides the required third copy and satisfies the offsite requirement, making it the minimum additional requirement.

Exam trap

The trap here is confusing the components of 3-2-1: candidates might think adding any third copy suffices, but the offsite requirement is critical and often overlooked.

How to eliminate wrong answers

Option A is wrong because a second external hard drive stored on-site would provide a third copy but still lacks an offsite copy, violating the '1' in 3-2-1. Option B is wrong because an incremental backup to a network share may be on-site and does not guarantee a different media type or offsite storage. Option C is wrong because a full backup on tape stored in the same room is not offsite and may not meet the '2' media types if the primary and external drive are both disk-based.

476
MCQmedium

An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?

A.Primary storage and one tape backup stored offsite
B.Primary storage and two tape backups in the same room
C.Primary storage, backup server (disk), and a second backup server (disk) in the same building
D.Primary storage, backup server (disk), and cloud storage
AnswerD

Three copies exist (primary, disk backup, cloud), on two media types (disk and cloud), with one copy offsite in the cloud. This satisfies the 3-2-1 rule's requirement for an offsite copy, protecting against site-level loss.

Why this answer

The 3-2-1 rule requires three copies of data, on two different media types, with one copy stored offsite. Option D satisfies all three: the primary storage is copy one, the on-premises disk backup server is copy two on a different medium, and cloud storage is copy three stored offsite. This combination is the canonical textbook example of a compliant 3-2-1 implementation.

Exam trap

The trap here is confusing 'three backups' with 'three copies' — candidates count only the backup targets and forget that primary storage counts as one of the three copies.

How to eliminate wrong answers

Option A is wrong because it only provides two copies of the data (primary plus one tape), violating the '3' in 3-2-1. Option B is wrong because although it has three copies on two media types, both tape backups are in the same room, so there is no offsite copy — violating the '1'. Option C is wrong because all three copies (primary, disk backup, second disk backup) reside in the same building, again failing the offsite requirement and arguably using only one media type.

477
MCQhard

During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?

A.Analyze the original disk in place to avoid copying errors.
B.Delete non-relevant files from the image to reduce size before storage.
C.Compress the image with a password to prevent tampering.
D.Compute and document a cryptographic hash of the image immediately after acquisition.
AnswerD

Hashing the forensic image at acquisition creates a verifiable fingerprint. If the hash is recomputed later and matches, it demonstrates the image has not been altered. This supports admissibility and chain-of-custody requirements because any change would produce a different value. Documenting the hash alongside acquisition details lets independent examiners confirm the copy is a faithful representation of the original media.

Why this answer

Cryptographic hashing at the time of acquisition establishes a verifiable baseline for the forensic image. Any later modification changes the hash, so a match confirms integrity. This practice, combined with documented chain of custody, supports the reliability of evidence in legal contexts.

Working from a verified copy rather than the original also protects the source media, and preserving the full image without deletions ensures nothing is lost.

Exam trap

The trap here is assuming that encryption or access restrictions equal integrity, when only a hash comparison can demonstrate the evidence has not changed.

478
MCQmedium

Refer to the exhibit. A security analyst reviews this log entry. What type of attack is most likely occurring?

A.Pass-the-hash attack
B.Brute-force attack
C.Password spraying attack
D.Kerberos ticket attack
AnswerB

Repeated failed sign-in attempts against one account within a short window indicate an attacker systematically guessing credentials. This pattern, rather than a single failure, distinguishes brute-force from other attacks and satisfies the log evidence showing numerous authentication attempts.

Why this answer

The log entry shows repeated failed authentication attempts against a single username from a single source IP, trying numerous different passwords in a short period. This pattern is characteristic of a brute-force attack, where an attacker systematically tries many password guesses against one target account.

Exam trap

ISC2 often tests the distinction between brute-force and password spraying attacks, where the trap is that candidates confuse the target pattern—brute-force focuses on a single user with many passwords, while password spraying uses one password across many users.

How to eliminate wrong answers

Option A is wrong because a pass-the-hash attack involves capturing and reusing NTLM or LM password hashes from a compromised system, not repeated login attempts from a single source. Option C is wrong because a password spraying attack uses a single common password against many usernames across multiple accounts, not multiple passwords against a few usernames as shown in the log. Option D is wrong because a Kerberos ticket attack (e.g., Golden Ticket or Silver Ticket) exploits forged or stolen Kerberos TGTs or service tickets, not repeated authentication failures against local or network logins.

479
MCQeasy

A network administrator is configuring a new wireless network for a small office. The office has sensitive data and wants to ensure that all wireless traffic is encrypted and that users authenticate with unique credentials. Which security protocol should the administrator implement?

A.WPA2-Enterprise
B.Open authentication
C.WEP
D.WPA2-Personal
AnswerA

WPA2-Enterprise uses 802.1X authentication with an authentication server (e.g., RADIUS) to provide unique credentials for each user. It also uses strong encryption (AES-CCMP). This meets the requirements for encrypted traffic and unique user authentication, making it the appropriate choice for a small office with sensitive data.

Why this answer

WPA2-Enterprise provides both strong encryption and unique user authentication via 802.1X and a RADIUS server. This ensures that each user has distinct credentials and that wireless traffic is encrypted. The other options either lack unique authentication (WPA2-Personal, Open) or are insecure (WEP, Open).

Exam trap

The trap here is confusing WPA2-Personal with WPA2-Enterprise; the key differentiator is whether authentication is centralized and unique per user.

480
MCQhard

A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?

A.Attribute-Based Access Control (ABAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerC

MAC uses security labels assigned by a central authority and compares them against user clearances to make access decisions. Users cannot modify labels or pass access to others, which aligns exactly with the scenario. This centralized, non-discretionary enforcement is the hallmark of MAC and satisfies the firm's requirement to control access based on data sensitivity labels.

Why this answer

Mandatory Access Control relies on security labels assigned by a central authority and compares them with user clearances. Users cannot alter labels or delegate access, which matches the firm's requirement to enforce decisions based on data sensitivity. Discretionary Access Control and Role-Based Access Control allow owner or role-based discretion, and Attribute-Based Access Control is broader and policy-driven, so none of them captures the centralized, non-discretionary label enforcement described.

Exam trap

The trap here is confusing label-based access with role-based access, since both can restrict users, but only Mandatory Access Control requires centrally assigned labels that users cannot change.

481
MCQhard

A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?

A.Document the chain of custody for all evidence collected.
B.Create a forensic image of the employee's workstation hard drive.
C.Confront the employee and ask for an explanation.
D.Disable the employee's network access immediately.
AnswerA

Documenting the chain of custody is essential for evidence admissibility. It records who handled the evidence, when, and how, ensuring integrity. This should be done from the moment evidence is identified and collected. It is the first step to ensure that any evidence gathered later can be traced and trusted in legal proceedings.

Why this answer

For evidence to be admissible in a legal case, a proper chain of custody must be established and documented from the outset. This ensures that the evidence has not been tampered with and can be traced from collection to presentation. While imaging and containment are important, they come after initiating the chain of custody to maintain integrity.

Exam trap

The trap here is focusing on technical steps like imaging or containment, which are important, but overlooking that legal admissibility hinges first on a documented chain of custody.

482
Multi-Selecteasy

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Select 2 answers
A.Encryption
B.Redundant servers
C.Digital signature
D.Access control lists
E.Hashing
AnswersC, E

A digital signature uses the publisher's private key to sign the update, and verification with the corresponding public key confirms both origin and that the package was not altered. This satisfies the stem's integrity requirement by detecting any tampering before deployment.

Why this answer

Option C (Digital signature) is correct because a digital signature, created by the software publisher using their private key and verified with their public key, cryptographically proves both the integrity and authenticity of the update — any modification to the package invalidates the signature. Option E (Hashing) is correct because computing a hash (e.g., SHA-256) of the downloaded update and comparing it to the publisher's published hash value detects any alteration of the file's contents, confirming integrity. Option A (Encryption) is not correct because encryption provides confidentiality, not integrity verification, and does not by itself prove the file was unmodified.

Option B (Redundant servers) is not correct because redundancy only improves availability and fault tolerance, not data integrity. Option D (Access control lists) is not correct because ACLs restrict who may access a resource, which is an authorization control rather than a mechanism for verifying that a file's contents are intact.

Exam trap

The trap here is confusing confidentiality (encryption) with integrity (hashing/signatures) — candidates often pick encryption because it sounds security-related, but it does not verify that data was unmodified.

483
MCQhard

An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Need-to-know
AnswerA

Least privilege grants each account only the permissions its role requires, so a compromised user account exposes a narrow slice of resources rather than the whole environment. Limiting standing access directly caps the blast radius an attacker can reach after credential theft.

Why this answer

Least privilege is the principle of granting users only the minimum access rights necessary to perform their job functions. If an attacker compromises a user's account, the damage is limited because the account has restricted permissions. This directly addresses limiting damage from a compromised account.

Exam trap

CC often tests the application of security principles, and candidates may confuse least privilege with need-to-know or separation of duties, especially when the scenario involves limiting damage from a compromised account.

How to eliminate wrong answers

Option B is wrong because separation of duties divides tasks among multiple users to prevent fraud, but it does not directly limit damage from a single compromised account. Option C is wrong because defense in depth involves multiple layers of security, which can help but is not the most direct principle for limiting damage from a compromised account. Option D is wrong because need-to-know restricts access to information based on job requirements, similar to least privilege but more focused on data access; however, least privilege is broader and more directly applies to limiting account permissions.

484
MCQhard

A financial institution has a security operations center that monitors network traffic using a SIEM. The SIEM receives logs from all network devices, servers, and endpoints. One analyst notices an anomaly: a user account, 'jsmith', which is normally used during business hours (9 AM to 5 PM), has been logging in from a remote IP address at 2 AM every day for the past week. The logins are successful, and the user is accessing internal file shares. The user jsmith works in the accounting department and has access to sensitive financial reports. The analyst checks the user's workstation logs and finds that the workstation is powered off at the time of the remote logins. The company uses two-factor authentication, but the log entries show that only the password was used. Which of the following is the most likely explanation and the best immediate action?

A.The user is working overtime from home; no action needed
B.The two-factor authentication system is malfunctioning; reconfigure the 2FA server
C.The user's credentials have been stolen and are being used by an attacker; disable the account
D.The user's workstation is infected with a remote access trojan; run antivirus
AnswerC

This matches the indicators: off-hours, remote IP, no 2FA, workstation off.

Why this answer

The anomaly—successful logins at 2 AM from a remote IP while the user's workstation is powered off and only a password (bypassing 2FA) is used—strongly indicates credential theft and account takeover. The SIEM logs show authentication without the second factor, which means the attacker either obtained the password and bypassed 2FA (e.g., through a phishing attack that captured both factors or a session cookie) or the 2FA was not enforced for this specific remote login. Disabling the account immediately stops the unauthorized access to sensitive financial shares.

Exam trap

ISC2 often tests the distinction between a compromised account (where credentials are stolen and used remotely) and a compromised endpoint (where malware is present), and the trap here is that candidates may assume the user's workstation is infected (Option D) because the logins are successful, but the powered-off workstation proves the attacker is authenticating directly from a different device.

How to eliminate wrong answers

Option A is wrong because the workstation is powered off during the logins, so the user cannot be working from home; the remote logins are from an attacker. Option B is wrong because a 2FA malfunction would likely affect all users or generate error logs, not selectively allow only password-based logins for a single account at odd hours; the issue is credential compromise, not a system misconfiguration. Option D is wrong because the workstation is powered off, so a remote access trojan cannot be active on it; the attacker is logging in directly with stolen credentials, not via malware on the user's machine.

485
MCQeasy

An organization wants to ensure that system logs are tamper-proof after generation. Which control should be implemented?

A.Compress logs before archiving.
B.Use a write-once read-many (WORM) storage device.
C.Store logs on the local hard drive of each server.
D.Encrypt logs during transmission.
AnswerB

WORM storage physically prevents modification or deletion of written data for a retention period, so logs cannot be altered after generation. This immutability directly satisfies the stem's tamper-proof requirement, unlike standard file permissions or hashing, which detect but do not prevent alteration.

Why this answer

A WORM (write-once read-many) storage device enforces immutability at the hardware or storage-layer level, meaning once a log is written it cannot be altered or deleted for a defined retention period. This directly satisfies the requirement that logs be tamper-proof after generation, because even administrators with storage credentials cannot modify the data. It is the standard control for regulatory compliance frameworks such as SEC 17a-4, HIPAA, and PCI DSS that mandate immutable audit trails.

Exam trap

The trap here is confusing confidentiality controls (encryption in transit) with integrity controls (immutability), causing candidates to pick encryption when the question asks for tamper-proofing.

How to eliminate wrong answers

Option A is wrong because compression reduces storage size but does not prevent modification — a compressed log can be decompressed, altered, and recompressed. Option C is wrong because storing logs on a local hard drive of each server makes them vulnerable to tampering by anyone with server access and also creates a single point of failure; it provides no immutability. Option D is wrong because encrypting logs during transmission only protects data in transit (confidentiality) and does nothing to prevent post-generation modification at rest.

486
MCQmedium

A financial services company wants to ensure that a terminated employee cannot continue to use an active badge to enter the building after their last day. The security manager reviews physical access control procedures. Which control type is being applied when the badge is deactivated in the access control system?

A.Preventive control
B.Detective control
C.Corrective control
D.Compensating control
AnswerA

Deactivating a badge prevents the terminated employee from using it to gain entry, which is the goal of a preventive control. It stops the unauthorized action before it occurs. While it also supports other control categories, the immediate effect is to block access, making preventive the best classification for this scenario.

Why this answer

Deactivating a badge stops the terminated employee from entering the facility, which is the definition of a preventive control. Preventive controls aim to stop unauthorized actions before they happen. Detective controls identify events after the fact, corrective controls address incidents after they occur, and compensating controls substitute for missing controls.

Since the action blocks access in advance, preventive is correct.

Exam trap

The trap here is confusing preventive and corrective controls because both involve responding to a termination, but the timing of the action determines the classification.

487
Multi-Selecthard

A security officer at a healthcare provider is reviewing the organization's risk management program. The officer must distinguish between threats and vulnerabilities when documenting risks. Which two of the following are examples of vulnerabilities rather than threats? (Choose two.)

Select 2 answers
A.A ransomware group that is actively targeting healthcare organizations
B.A natural disaster such as a hurricane that could damage a data center
C.An unpatched web server that is missing a critical security update
D.A phishing campaign that delivers malicious attachments to employees
E.A database that stores patient records without encryption at rest
AnswersC, E

An unpatched web server is a weakness in the system that could be exploited, which is a vulnerability. It is a condition internal to the organization that increases the likelihood of a successful attack. Threats are potential causes of harm, while vulnerabilities are flaws or gaps. Missing a security update is a classic example of a vulnerability because it represents an exposure that attackers can leverage.

Why this answer

Vulnerabilities are weaknesses or gaps in protection that can be exploited, such as an unpatched web server and an unencrypted database. Threats are potential causes of harm, including ransomware groups, phishing campaigns, and natural disasters. The two correct choices describe internal weaknesses, while the other options describe threat actors or events that could exploit those weaknesses.

Exam trap

The trap here is treating any risky condition as a threat, when threats are sources of harm and vulnerabilities are the weaknesses those sources can exploit.

488
MCQhard

A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?

A.Application proxy firewall
B.Stateful inspection firewall
C.Next-generation firewall
D.Packet filtering firewall
AnswerB

Stateful inspection builds a state table of active connections and permits only return traffic matching an established entry, dropping unsolicited inbound packets. This matches the described behaviour of tracking sessions rather than evaluating each packet statelessly.

Why this answer

A stateful inspection firewall maintains a state table that tracks active connections and only allows packets that match an established connection. It inspects packet headers and maintains connection state, dropping packets that do not match. This is the definition of a stateful inspection firewall.

It operates at the network and transport layers and provides better security than simple packet filtering.

Exam trap

CC often tests the difference between stateful and stateless firewalls; candidates may confuse stateful inspection with packet filtering because both inspect headers, but stateful maintains connection state.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at the application layer and acts as an intermediary for specific applications, not just inspecting headers and maintaining state. Option C is wrong because a next-generation firewall (NGFW) includes additional features like application awareness, intrusion prevention, and deep packet inspection, but the description only mentions stateful inspection. Option D is wrong because a packet filtering firewall only inspects individual packets based on static rules (e.g., IP addresses, ports) without maintaining connection state.

489
MCQhard

A financial services firm has a data center that houses customer financial records. They have implemented a defense-in-depth strategy including firewalls, IDS/IPS, and encryption. Recently, an internal audit revealed that a junior administrator has been logging into the database server with a shared admin account and has made unauthorized changes to customer records. The company wants to prevent such incidents in the future while maintaining operational efficiency. The current environment uses Linux servers with PostgreSQL databases. There is no centralized authentication system. What is the BEST action to take?

A.Increase the frequency of password changes for the shared admin account
B.Disable all shared accounts and implement individual accounts with role-based access control and audit logging
C.Use database encryption to prevent unauthorized changes
D.Implement a network access control (NAC) solution to restrict database access to specific IP addresses
AnswerB

Eliminating shared accounts removes attribution ambiguity, while individual accounts with role-based access control and audit logging tie every database change to a named person. This satisfies the stem's constraint of preventing unauthorised changes on Linux PostgreSQL servers lacking centralised authentication.

Why this answer

The core issue is the lack of accountability due to a shared admin account. Disabling shared accounts and implementing individual accounts with role-based access control (RBAC) and audit logging directly addresses this by ensuring each action is tied to a specific user, enabling non-repudiation and precise forensic analysis. This aligns with the principle of least privilege and is the most effective way to prevent unauthorized changes while maintaining operational efficiency through granular permission management.

Exam trap

ISC2 often tests the misconception that encryption or network controls can solve insider threats, when in reality, only user-level accountability and audit trails can prevent and trace unauthorized actions by authenticated users.

How to eliminate wrong answers

Option A is wrong because increasing password change frequency for a shared account does not solve the lack of accountability; multiple users still share credentials, making it impossible to trace who made specific changes. Option C is wrong because database encryption protects data at rest or in transit from external interception, but it does not prevent an authenticated user (the junior admin) from making unauthorized modifications. Option D is wrong because network access control (NAC) restricts which IP addresses can connect to the database, but it does not address the internal threat of an authorized user with a shared account making unauthorized changes from an allowed IP.

490
MCQhard

In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?

A.DC=company, DC=com, OU=Sales, CN=John Smith
B.OU=Sales, CN=John Smith, DC=company, DC=com
C.CN=John Smith, OU=Sales, DC=company, DC=com
D.CN=John Smith, DC=Sales, DC=company, DC=com
AnswerC

CN=John Smith, OU=Sales, DC=company, DC=com satisfies LDAP's leaf-to-root ordering, placing the common name first, then the organizational unit, then each domain component separately. Splitting company.com into two DC attributes matches the stem's domain constraint, unlike a single DC=company.com entry.

Why this answer

An LDAP distinguished name is written from the most specific component (the leaf object) to the least specific (the root of the directory tree), separated by commas. For John Smith in the Sales OU of company.com, the correct order is CN=John Smith, OU=Sales, DC=company, DC=com. The CN identifies the user object, the OU identifies the organizational unit, and the DC components identify the domain.

Exam trap

The trap is ordering — candidates often write DNs top-down like a URL, but LDAP requires leaf-to-root ordering, and mixing up OU and DC attributes compounds the error.

How to eliminate wrong answers

Option A is wrong because it reverses the order, starting with the domain components and ending with the user, which is the opposite of LDAP DN syntax. Option B is wrong because it places OU=Sales before CN=John Smith, violating the leaf-to-root ordering rule. Option D is wrong because it uses DC=Sales instead of OU=Sales; 'Sales' is an organizational unit, not a domain component, so the attribute type is incorrect.

491
MCQmedium

A security engineer is designing a backup strategy for a critical database. The database must be recoverable within four hours in the event of a failure. Which security principle primarily drives this requirement?

A.Availability
B.Integrity
C.Non-repudiation
D.Confidentiality
AnswerA

Availability ensures systems and data remain accessible to authorised users when required. The four-hour recovery time objective is a uptime commitment, so the driving principle is availability, not integrity or confidentiality, which address alteration and disclosure respectively.

Why this answer

Availability ensures that systems and data are accessible when needed. The requirement to recover the database within four hours defines a Recovery Time Objective (RTO), which is an availability requirement. Therefore, Option A is correct.

Option B (Integrity) ensures data accuracy and protection from unauthorized modification, not recovery time. Option C (Non-repudiation) prevents denial of actions, which is unrelated. Option D (Confidentiality) protects data from unauthorized disclosure.

492
MCQmedium

A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?

A.Password complexity
B.Biometric authentication
C.Session timeout
D.Account lockout
AnswerC

Session timeout automatically locks or terminates an idle session after a defined inactivity period, so an unattended workstation cannot be used by an unauthorised person. It directly addresses the walk-away threat rather than authentication or authorisation at logon.

Why this answer

A session timeout automatically locks or logs out a user after a period of inactivity, directly addressing the risk of an unattended workstation being used by an unauthorized person. It is the standard control for this scenario because it terminates the authenticated session without requiring the user to manually log off. Password complexity, biometrics, and account lockout address different threats.

Exam trap

The trap is that multiple options are 'access controls,' so candidates must match the control to the specific threat — unattended workstation — rather than picking a generally strong control like biometrics.

How to eliminate wrong answers

Option A is wrong because password complexity strengthens credentials against guessing and brute force but does nothing to protect an already-authenticated session left open. Option B is wrong because biometric authentication verifies identity at login but does not automatically secure a session after the user walks away. Option D is wrong because account lockout disables an account after repeated failed logins, which mitigates brute-force attacks, not unattended-session abuse.

493
MCQhard

In a defense-in-depth strategy, which access control mechanism provides the most granular control over user permissions?

A.Network segmentation
B.Access control lists (ACLs) on files
C.Physical security controls
D.Firewall rules
AnswerB

ACLs specify permissions per individual user or group against each file, giving far finer granularity than role-based or mandatory models. This directly satisfies the stem's requirement for the most granular control over user permissions within defence in depth.

Why this answer

Access control lists (ACLs) on files provide the most granular control because they allow permissions to be set at the individual file or object level, specifying exactly which users or groups can read, write, execute, or modify that specific resource. This is in contrast to broader mechanisms like network segmentation or firewall rules, which operate at the network or subnet level and cannot distinguish between individual files within a system. ACLs are a fundamental component of discretionary access control (DAC) and are implemented in file systems such as NTFS, ext4, and ZFS.

Exam trap

ISC2 often tests the distinction between network-level controls (like firewall rules and segmentation) and system-level controls (like file ACLs), leading candidates to mistakenly choose a network mechanism when the question asks for the most granular control over user permissions on a resource.

How to eliminate wrong answers

Option A is wrong because network segmentation divides a network into smaller segments to limit lateral movement, but it does not control permissions on individual files or objects—it operates at Layer 2/3 and cannot enforce user-level granularity on a file. Option C is wrong because physical security controls (e.g., locks, biometrics, guards) protect the physical environment and assets, but they cannot differentiate between users accessing specific files on a system; they are a coarse, perimeter-level control. Option D is wrong because firewall rules filter traffic based on IP addresses, ports, and protocols at Layers 3/4 (and sometimes Layer 7), but they do not manage permissions on files or objects within an operating system—they control network access, not user permissions on resources.

494
Multi-Selectmedium

A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?

Select 2 answers
A.Defense in depth
B.Separation of duties
C.Privileged access management
D.Need-to-know
E.Least privilege
AnswersD, E

Need-to-know restricts access to information strictly required for a specific task, independent of seniority. Combined with least privilege, it satisfies the policy's minimum-permissions requirement by limiting data exposure, reducing impact if the account is compromised.

Why this answer

Option E, least privilege, is correct because the policy explicitly states that employees should be granted only the minimum permissions required to perform their job functions, which is the exact definition of the least privilege principle. Option D, need-to-know, is correct because it restricts access to information and resources only to those who require them for their job duties, complementing least privilege by limiting data exposure. Together, these principles reduce the attack surface and potential impact if an account is compromised.

Option A, defense in depth, is not correct because it refers to layering multiple security controls rather than limiting permissions. Option B, separation of duties, is not correct because it involves dividing tasks among different individuals to prevent fraud or error, not minimizing permissions. Option C, privileged access management, is not correct because it focuses on managing and monitoring elevated accounts, not on the general principle of minimum permissions for all employees.

Exam trap

The trap here is confusing least privilege with other access control principles like separation of duties or defense in depth, especially when the policy mentions 'minimum permissions' which directly points to least privilege, but candidates might overlook need-to-know as a complementary principle.

495
MCQhard

You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?

A.Remove the temporary firewall rule that allows RDP from any public IP
B.Disable RDP access on all servers
C.Conduct a full audit of all firewall rules
D.Implement a security awareness training program for all employees
AnswerA

Removing the firewall rule immediately closes the public RDP exposure that let the employee reach the internal server without VPN authentication, satisfying the requirement to eliminate the unauthorised access path before any forensic or policy follow-up.

Why this answer

The immediate exposure is the overly permissive firewall rule allowing RDP from any public IP to a sensitive server, so the fastest risk-reducing action is to remove or disable that rule. This closes the attack path instantly without disrupting other services. Only after containment should broader remediation (audits, training) be pursued.

Exam trap

The trap is choosing the 'most thorough' answer (full audit or training) when the question asks for the 'most immediate corrective action' — incident response prioritizes containment first.

How to eliminate wrong answers

Option B is wrong because disabling RDP on all servers is a broad, disruptive action that breaks legitimate administrative access and exceeds the scope of the incident; the problem is the firewall rule, not RDP itself. Option C is wrong because a full firewall audit is a longer-term governance activity, not an immediate corrective action, and delays closing the active exposure. Option D is wrong because security awareness training is a preventive, long-term control that does nothing to remediate the currently open RDP hole.

496
MCQmedium

A hospital's network team notices that a radiology workstation is receiving a duplicate IP address error. The DHCP server logs show the workstation was assigned 10.10.20.45, but the workstation is manually configured with that same address. Which DHCP feature should have been configured to prevent this conflict?

A.DHCP snooping
B.DHCP exclusion range
C.DHCP relay agent
D.DHCP reservation
AnswerB

An exclusion range defines IP addresses within the DHCP scope that the server must not assign to clients. By excluding 10.10.20.45, the DHCP server would never lease it, avoiding a conflict with the manually configured radiology workstation. This is the correct administrative control when static addresses exist inside a dynamic scope.

Why this answer

The conflict occurs because the DHCP server dynamically leases an address that is already statically assigned to another device. To prevent this, the address must be removed from the assignable pool using an exclusion range. This ensures the server never offers that address, eliminating the duplicate IP conflict without changing the workstation's static configuration.

Exam trap

The trap here is confusing DHCP reservations with exclusions; a reservation only affects DHCP clients, while an exclusion prevents the server from ever assigning a specific address, which is needed for statically configured hosts.

497
Multi-Selecthard

A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)

Select 2 answers
A.Contact law enforcement immediately.
B.Isolate the workstation from the network.
C.Analyze the macro code in a sandbox.
D.Block the malicious domain at the email gateway.
E.Delete the phishing email from all mailboxes.
AnswersB, D

Isolating the workstation halts the PowerShell download and prevents lateral movement or further command-and-control traffic. Containment is the immediate priority once compromise via the macro-enabled document is confirmed, preserving evidence while stopping the active threat.

Why this answer

Option B is correct because isolating the compromised workstation from the network immediately contains the incident, preventing the PowerShell-downloaded payload from establishing C2 communication or lateral movement to other hosts. Option D is correct because blocking the known malicious domain at the email gateway stops further phishing emails from that domain reaching other employees, addressing the initial infection vector. Option A is not an immediate containment step; law enforcement notification typically occurs later per legal/organizational policy.

Option C, sandboxing the macro, is useful for deeper analysis but is not an immediate containment action and can be done after isolation. Option E, deleting the email from all mailboxes, is a remediation step that may follow, but blocking the domain at the gateway is the more immediate preventive action.

Exam trap

ISC2 often tests the distinction between immediate containment actions (isolate, block at gateway) and later forensic or administrative steps (analyze macro, contact law enforcement, delete emails) to see if candidates understand the priority of stopping the threat first.

498
MCQhard

A financial services firm is designing a network that must allow inbound HTTPS from the internet to a public web application while preventing any direct inbound connections to its internal database servers. The security architect proposes placing the web application in a screened subnet and configuring rules so the database can be reached only from the web application. Which design element is the architect primarily relying on?

A.A hub-based network topology
B.A demilitarized zone (DMZ) with controlled access between zones
C.A flat network with a single perimeter firewall
D.Network address translation (NAT) alone
AnswerB

A DMZ hosts public-facing services in a screened subnet separate from internal systems, and firewall rules control traffic between the DMZ, the internet, and the internal network. This allows inbound HTTPS to the web application while preventing direct inbound access to database servers. The controlled inter-zone rules are the core of the design.

Why this answer

The architect needs a screened subnet for the public web application plus enforced rules controlling traffic between the internet, the DMZ, and internal systems. A DMZ with controlled access accomplishes this by allowing inbound HTTPS to the web tier while denying direct inbound access to database servers. A flat network, NAT alone, or a hub topology lacks the required separation and rule enforcement.

Exam trap

The trap here is believing that address translation or a perimeter firewall alone creates an internal security boundary, when zone separation and inter-zone rules are what actually restrict access.

499
MCQeasy

Which OSI layer is responsible for routing packets across networks using IP addresses?

A.Layer 1 - Physical
B.Layer 3 - Network
C.Layer 4 - Transport
D.Layer 2 - Data Link
AnswerB

Layer 3, the Network layer, handles logical addressing and path selection, so routers use IP addresses to forward packets between distinct networks. Layers 2 and 4 lack routable addressing, making Layer 3 the layer that satisfies the routing requirement in the stem.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing. It uses IP addresses to determine the best path for packets to travel from source to destination across different networks. Protocols like IP (IPv4/IPv6), OSPF, and BGP operate at this layer to perform routing decisions.

Exam trap

A common pitfall is confusing the Data Link layer's local delivery role (Layer 2) with the Network layer's internetwork routing function (Layer 3). Remember that routing across networks using IP addresses occurs at Layer 3.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) deals with the physical transmission of raw bits over media (e.g., cables, voltages, frequencies) and has no concept of IP addresses or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), but it does not perform routing or use IP addresses for path selection. Option D is wrong because Layer 2 (Data Link) handles frame delivery within a single network segment using MAC addresses and protocols like Ethernet, not IP routing across networks.

500
MCQmedium

A system administrator implements version control for all configuration files. Which principle is being strengthened?

A.Availability
B.Confidentiality
C.Accountability
D.Integrity
AnswerD

Version control tracks every change to configuration files, creating an auditable record that detects unauthorised or accidental modification. This directly strengthens integrity, since the stem's constraint is ensuring files remain accurate and unaltered, not restricting who may read them.

Why this answer

Version control helps ensure data accuracy and prevents unauthorized changes, supporting integrity.

501
MCQeasy

Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?

A.TCP
B.UDP
C.IP
D.HTTP
AnswerA

TCP operates at the Transport layer and provides reliable, connection-oriented delivery through handshaking, sequence numbers and acknowledgements. UDP, its Transport-layer counterpart, is connectionless and unreliable, so TCP uniquely satisfies both the layer and reliability constraints stated in the question.

Why this answer

TCP (Transmission Control Protocol) uses a three-way handshake, sequencing, and acknowledgments to ensure reliable delivery.

502
MCQeasy

A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?

A.Separation of duties
B.Need-to-know
C.Defense in depth
D.Least privilege
AnswerD

Least privilege grants each user only the minimum rights required for their job, exactly matching the stem's constraint. Unlike role-based or mandatory models, it limits permissions to necessity, reducing the attack surface and potential damage from compromised or misused accounts.

Why this answer

Least privilege means granting users only the minimum permissions required to perform their job functions — nothing more. The administrator is explicitly ensuring each user has only the rights needed, which is the textbook definition of least privilege. This principle limits the blast radius of compromised accounts and reduces accidental or malicious misuse of permissions.

Exam trap

The trap here is confusing least privilege with need-to-know — both limit access, but least privilege is about the minimum permissions to do the job, while need-to-know is about access to specific information.

How to eliminate wrong answers

Option A is wrong because separation of duties is about dividing critical tasks among multiple people so no single person can complete a sensitive action alone — it is not about minimizing each user's permission set. Option B is wrong because need-to-know refers specifically to limiting access to information based on whether the user requires it for their role, typically applied to data classification rather than general permission minimization. Option C is wrong because defense in depth is a layered security strategy using multiple overlapping controls, not a principle about individual user rights.

503
MCQmedium

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

A.Containment
B.Analysis
C.Lessons learned
D.Eradication
AnswerB

Analysis follows detection: the analyst must validate the alert, scope the exfiltration, and determine impact before escalating. This phase satisfies the stem's need to confirm and understand the suspicious outbound traffic prior to containment or eradication.

Why this answer

The analyst has detected unusual outbound traffic indicating potential data exfiltration. According to the incident response process, after detection and initial validation, the next phase is analysis, where the analyst investigates the scope, impact, and nature of the incident. Containment (A) would come after analysis to prevent further damage.

Eradication (D) and lessons learned (C) are later phases. Therefore, the analyst should initiate analysis next.

Exam trap

The trap here is confusing the order of incident response phases; candidates might jump to containment because it seems urgent, but the exam expects adherence to the standard sequence where analysis precedes containment.

How to eliminate wrong answers

Option A is wrong because containment is a response action taken after the incident has been analyzed to prevent spread; initiating containment without analysis could be premature. Option C is wrong because lessons learned is a post-incident activity conducted after eradication and recovery. Option D is wrong because eradication involves removing the root cause and is performed after containment, which follows analysis.

504
Multi-Selectmedium

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

Select 2 answers
A.Sensitivity of the data potentially compromised
B.Type of operating system involved
C.Number of users affected
D.Time of day the incident occurred
E.Color of the server room
AnswersA, C

Sensitivity of the data potentially compromised directly determines severity because exposure of regulated, confidential or personal information raises legal, financial and reputational impact. It satisfies the prioritisation criterion by weighting potential harm, alongside factors such as affected system criticality.

Why this answer

Option A is correct because the sensitivity of the data potentially compromised directly drives severity: exposure of regulated or high-classification data (e.g., PII, PHI, cardholder data under PCI DSS, or trade secrets) raises the potential impact and therefore the incident's severity rating. Option C is correct because the number of users affected measures the scope and blast radius of the incident, and broader impact across more accounts or systems generally elevates severity. The type of operating system involved (B) is not a primary severity factor, since impact depends on the affected assets and data rather than the OS platform itself.

The time of day the incident occurred (D) is contextual and may influence response logistics but not the intrinsic severity. The color of the server room (E) is irrelevant to incident severity.

Exam trap

CC often tests whether candidates confuse contextual response factors (time of day, OS type) with true impact drivers (data sensitivity, user count) — only the latter determine severity.

505
MCQmedium

An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?

A.Detection
B.Preparation
C.Recovery
D.Lessons learned
AnswerC

Recovery restores encrypted systems and data to normal operation, satisfying the phase that follows eradication in the standard incident response lifecycle. It involves validating backups, rebuilding affected hosts, and confirming services function before returning them to production, directly addressing the stem's sequence after containment and eradication.

Why this answer

The standard incident response phases are Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Lessons Learned. After containing the infection and eradicating the malware, the next phase is Recovery, where systems are restored to normal operation and validated before returning to production.

Exam trap

The trap here is confusing the order of phases, particularly placing Lessons Learned immediately after Eradication, when Recovery must occur first to restore operations before reviewing the incident.

How to eliminate wrong answers

Option A is wrong because Detection occurs before containment and eradication; it is the phase where the incident is identified. Option B is wrong because Preparation is the first phase, done before an incident occurs. Option D is wrong because Lessons Learned is the final phase, after recovery is complete; it involves reviewing the incident to improve future response.

506
MCQhard

You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?

A.Confront the employee directly to ask for an explanation.
B.Review the employee's system logs and DLP alerts in detail to establish a pattern.
C.Disable the employee's network access immediately to prevent data exfiltration.
D.Notify the employee's manager about the suspicion.
AnswerB

Logs and DLP alerts are already generated, so reviewing them is passive, discreet and non-disruptive, establishing a pattern without alerting the employee. This satisfies the policy constraint requiring the investigation remain covert while evidence is gathered.

Why this answer

The first step in any insider threat investigation is to gather and analyze available evidence discreetly, as required by policy. Reviewing system logs (e.g., Windows Event Logs, file server audit logs) and DLP alerts allows you to establish a behavioral pattern—such as anomalous access times, file rename operations, and email attachments—without alerting the employee. This evidence-based approach ensures you can confirm or refute the suspicion before taking any disruptive or confrontational actions.

Exam trap

ISC2 often tests the principle that investigative actions must be non-disruptive and evidence-driven first, tempting candidates to jump to containment (Option C) or escalation (Option D) before analysis.

How to eliminate wrong answers

Option A is wrong because confronting the employee directly violates the policy of conducting the investigation discreetly, may tip off a potential insider, and could lead to evidence tampering or escalation. Option C is wrong because immediately disabling network access is a reactive containment step that should only be taken after sufficient evidence is gathered; it also alerts the employee and may be premature if the behavior is benign. Option D is wrong because notifying the employee's manager without first establishing a pattern of suspicious activity could breach confidentiality, cause unnecessary alarm, and potentially compromise the investigation if the manager inadvertently alerts the employee.

507
MCQmedium

A security engineer is configuring a firewall to allow web traffic but block all other inbound connections. The firewall is set to deny all traffic by default and only allow specific ports. Which security principle is being applied?

A.Default deny
B.Defense in depth
C.Fail-safe
D.Least privilege
AnswerA

Default deny enforces an implicit drop for all traffic not explicitly permitted, so only the specified web ports are reachable. This directly satisfies the stem's constraint of blocking every other inbound connection while allowing web traffic, since the firewall's baseline posture rejects anything unmatched.

Why this answer

Default deny. The scenario describes a firewall configured to deny all traffic by default and then explicitly allow only specific ports (e.g., TCP 80/443 for web traffic). This directly implements the default deny security principle, where any traffic not explicitly permitted is blocked.

This contrasts with a default allow posture, which would permit all traffic unless explicitly denied.

Exam trap

ISC2 often tests the distinction between 'default deny' (a firewall ACL posture) and 'least privilege' (a user/process access control model), causing candidates to confuse network-level traffic filtering with user-level permissions.

How to eliminate wrong answers

Option B is wrong because defense in depth is a layered security strategy using multiple controls (e.g., firewall, IDS, antivirus), not a single rule about default traffic handling. Option C is wrong because fail-safe ensures a system defaults to a secure state upon failure (e.g., a firewall blocking all traffic if it crashes), not the initial configuration of allowing only specific ports. Option D is wrong because least privilege grants users or processes only the minimum access needed to function, which applies to user permissions, not to firewall rule sets that control network traffic.

508
MCQeasy

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

A.Public
B.Internal/Private
C.Confidential
D.Restricted/Top Secret
AnswerC

The stem states the organisation already classifies data as confidential and mandates encryption at rest and in transit for that level. Selecting confidential matches the label the scenario itself applies, satisfying the stated classification requirement rather than inventing a different tier.

Why this answer

The 'Confidential' classification level is the one that typically mandates encryption at rest and in transit. In standard data classification schemes, Confidential data is sensitive and requires strong protection, including encryption, to prevent unauthorized disclosure. The question states the organization classifies data as 'confidential' and requires encryption, so the level being used is Confidential.

Exam trap

CC often tests whether candidates can match a classification label to its typical handling requirements, causing confusion when a higher level (Restricted) is present but not the one explicitly named in the scenario.

How to eliminate wrong answers

Option A is wrong because Public data is intended for open disclosure and does not require encryption; it is the lowest classification. Option B is wrong because Internal/Private data may have some protections but typically does not mandate encryption at rest and in transit as a strict requirement; it is less sensitive than Confidential. Option D is wrong because Restricted/Top Secret is a higher classification than Confidential, but the question explicitly states the organization uses 'confidential' as the classification level, so the answer must match that label.

509
Multi-Selecthard

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

Select 3 answers
A.Legal department
B.Internal management
C.Affected customers
D.Law enforcement
E.Public relations
AnswersA, B, E

Legal must be notified immediately because initial breach communications can create legal obligations and privilege considerations. Involving counsel early preserves attorney-client privilege over incident findings and ensures notifications meet regulatory and contractual duties, satisfying the stem's requirement that crisis communications follow established best practise during a live security incident.

Why this answer

Legal department (A) must be included in initial notifications because they assess regulatory and contractual breach-notification obligations, preserve legal privilege, and guide the organization on disclosure requirements that may carry statutory deadlines. Internal management (B) is essential because executives and incident-response leadership need immediate situational awareness to authorize containment actions, allocate resources, and make business-impact decisions. Public relations (E) belongs in the initial notification group because they control the organization's external messaging, prepare holding statements, and prevent inconsistent or damaging communications while facts are still being verified.

Affected customers (C) are typically notified only after the scope and impact are confirmed and legal/PR messaging is prepared, so they are not part of the initial internal notification wave. Law enforcement (D) is engaged selectively depending on the incident type, jurisdiction, and whether criminal activity or regulatory reporting mandates apply, so it is not always an initial notification recipient.

Exam trap

CC often tests the ordering of incident notifications — candidates incorrectly include affected customers or law enforcement in the 'initial' tier, when best practice places them in later, post-assessment tiers.

510
MCQmedium

An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?

A.Common Name
B.Domain Component
C.Organizational Unit
D.Country Name
AnswerA

In an LDAP distinguished name, CN stands for Common Name, the leftmost relative distinguished name identifying the entry itself. Here it names the object "John Smith" within the Sales organisational unit, satisfying the stem's requirement to identify what the CN attribute represents in the DN hierarchy.

Why this answer

In an LDAP distinguished name (DN), 'CN' stands for Common Name. It is used to represent the name of an object, such as a user or a group. In the example 'CN=John Smith,OU=Sales,DC=company,DC=com', 'CN=John Smith' indicates the common name of the entry, which is typically the user's full name.

Exam trap

The trap here is confusing the abbreviations of LDAP DN components, especially CN with DC or OU, so candidates must memorize the standard abbreviations.

How to eliminate wrong answers

Option B is wrong because 'DC' stands for Domain Component, not 'CN'. Option C is wrong because 'OU' stands for Organizational Unit, not 'CN'. Option D is wrong because 'C' stands for Country Name, not 'CN'.

511
MCQmedium

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
AnswerC

Modifying a payroll database alters stored data, so its accuracy and trustworthiness are directly threatened. Integrity guarantees data remains unaltered by unauthorised parties; confidentiality concerns disclosure and availability concerns access, neither of which the modification attempt targets.

Why this answer

Integrity ensures that data remains accurate, complete, and unaltered unless modified by authorized parties. The unauthorized attempt to modify the payroll database directly threatens this principle because it aims to change data without permission, compromising its trustworthiness. Confidentiality, non-repudiation, and availability are not the primary concerns here, as the focus is on unauthorized modification, not disclosure, proof of origin, or access disruption.

Exam trap

The trap here is confusing integrity with confidentiality or non-repudiation, as candidates may focus on the 'unauthorized user' aspect and think of access control (confidentiality) rather than the modification attempt.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized disclosure of information, not modification. Option B is wrong because non-repudiation ensures that a party cannot deny having performed an action, which is not the primary issue in an unauthorized modification attempt. Option D is wrong because availability ensures timely and reliable access to data, which is not directly threatened by an attempt to modify data.

512
MCQhard

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerD

Declining the vendor eliminates the activity entirely, so the identified risk no longer exists. This satisfies the stem's scenario by removing the exposure rather than transferring it via insurance, mitigating it with controls, or accepting it.

Why this answer

Risk avoidance is the correct answer because the company eliminates the risk entirely by deciding not to engage with the vendor. By not hiring the vendor, the company removes the possibility of any security incidents or data breaches that could arise from the vendor's poor security practices. This is a classic example of risk avoidance, where the risk is sidestepped rather than managed or shared.

Exam trap

The trap here is confusing risk avoidance with risk mitigation, as both involve actions to address risk, but avoidance eliminates the risk entirely while mitigation reduces it.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves taking steps to reduce the impact or likelihood of a risk, such as implementing controls or safeguards, not eliminating the risk by avoiding the activity. Option B is wrong because risk acceptance means acknowledging the risk and choosing to proceed without taking action, which is not the case here since the company decided not to hire the vendor. Option C is wrong because risk transfer involves shifting the risk to a third party, such as through insurance or outsourcing, which is not what happened; the company simply avoided the risk altogether.

513
MCQmedium

A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?

A.Two: Sunday full and Thursday differential
B.One: Thursday differential only
C.Four: Monday through Thursday differentials
D.Five: Monday through Thursday differentials plus full
AnswerA

Restoring requires the Sunday full backup plus Thursday's differential, because differentials capture every change since that full. Wednesday's and earlier differentials are superseded, so only two sets are needed. This satisfies the stem's Thursday failure point, where the latest differential alone completes the chain.

Why this answer

With a full backup on Sunday and differential backups Monday through Saturday, a restore on Thursday requires the Sunday full backup and the most recent differential (Thursday). Differential backups capture all changes since the last full backup, so only the latest differential is needed along with the full.

Exam trap

The trap here is confusing differential and incremental backup restore requirements; candidates often think all daily backups are needed, but differential only requires the latest one plus the full.

How to eliminate wrong answers

Option B is wrong because a differential backup alone does not include the full backup data; you cannot restore from just a differential without the base full backup. Option C is wrong because differential backups are cumulative since the last full, so you do not need each day's differential; only the latest one is required. Option D is wrong because it describes the restore process for incremental backups (which require all incrementals since the last full), not differential backups.

514
MCQeasy

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

A.Eradication
B.Analysis
C.Containment
D.Detection
AnswerC

Containment limits an incident's spread by isolating affected systems, such as disconnecting compromised hosts from the network. This directly satisfies the stem's requirement to stop further damage, distinguishing it from eradication, which removes the threat's root cause after containment.

Why this answer

Containment is the incident response phase focused on limiting the scope and impact of an incident — isolating affected systems, disabling compromised accounts, and blocking malicious traffic to prevent further damage. It occurs after detection and analysis but before eradication and recovery. The goal is to stop the spread while preserving evidence for investigation.

Exam trap

The trap here is confusing containment with eradication — candidates often pick eradication because both 'stop the incident,' but containment limits spread while eradication removes the threat entirely.

How to eliminate wrong answers

Option A is wrong because eradication is the phase where the root cause (malware, backdoor, vulnerability) is removed from systems — it happens after containment, not as the initial damage-limiting step. Option B is wrong because analysis is the investigative phase where the scope and nature of the incident are determined, not the phase where systems are isolated. Option D is wrong because detection is the phase where the incident is first identified, preceding any response action.

515
MCQeasy

A security analyst receives an alert indicating multiple failed login attempts from a single IP address targeting a user account. Which action should the analyst take FIRST?

A.Disable the user account immediately
B.Verify the alert and check if the account is compromised
C.Escalate the alert to law enforcement
D.Block the IP address at the firewall
AnswerB

Triage demands validating the alert before acting, since a single-source brute-force pattern may be a false positive or authorised testing. Confirming whether the account is actually compromised determines whether containment, password reset or escalation follows, satisfying the stem's requirement to identify the FIRST action.

Why this answer

The first step in incident response is to validate the alert. The analyst must verify that the failed login attempts are not a false positive (e.g., a user mistyping their password) and then check if the account has been compromised by reviewing logs for successful logins from the same IP or anomalous behavior. Prematurely disabling the account or blocking the IP could disrupt legitimate access or alert an attacker, while escalation to law enforcement is premature without confirmation of a breach.

Exam trap

ISC2 often tests the principle that verification and analysis must precede any containment or eradication action, tempting candidates to jump to blocking the IP or disabling the account as a quick fix without confirming the alert's validity.

How to eliminate wrong answers

Option A is wrong because disabling the user account immediately without verifying the alert could lock out a legitimate user and does not address the root cause; the account may not be compromised. Option C is wrong because escalating to law enforcement is a drastic step that should only occur after confirming a security incident and following organizational policy, not as a first action. Option D is wrong because blocking the IP address at the firewall may be a reactive measure, but it could block a legitimate user (e.g., a shared IP) and does not confirm whether the account is compromised; verification must come first.

516
MCQmedium

An organization uses a SIEM to correlate logs from multiple sources. A rule triggers when a user logs in from two geographically distant locations within a short time. What type of attack does this rule primarily detect?

A.Denial of service attack
B.Brute-force attack
C.Credential theft or session hijacking
D.Man-in-the-middle attack
AnswerC

Impossible-travel correlation relies on the physical impossibility of one user authenticating in two distant locations within the elapsed time. That axis distinguishes credential theft or session hijacking from volumetric attacks, which the rule cannot infer from authentication logs alone.

Why this answer

The SIEM rule detects impossible travel — a user authenticating from two geographically distant locations within a time window too short for physical travel. This behavior strongly indicates that an attacker has stolen the user's credentials (credential theft) or taken over an active session (session hijacking) and is using them from a different location. The SIEM correlates authentication logs (e.g., from Active Directory, VPN, or web apps) with geolocation data (IP-to-location mapping) to flag this anomaly.

Exam trap

ISC2 often tests the concept of 'impossible travel' as a specific indicator of credential theft or session hijacking, and candidates mistakenly associate any unusual login pattern with brute-force attacks, failing to recognize that brute-force focuses on failed attempts, not successful logins from distant locations.

How to eliminate wrong answers

Option A is wrong because a denial of service attack aims to overwhelm a system with traffic or requests, not to generate geographically disparate login events; the rule focuses on authentication patterns, not resource exhaustion. Option B is wrong because a brute-force attack involves repeated login attempts from a single or few IPs, not two successful logins from distant locations; the rule triggers on successful authentications, not failed attempts. Option D is wrong because a man-in-the-middle attack intercepts communications between two parties without necessarily producing distinct login events from two far-apart IPs; the rule detects post-compromise lateral movement or credential misuse, not active interception.

517
MCQeasy

Maya is a security administrator at a healthcare company. She discovers that nurses can view patient billing records even though their job duties only require access to clinical treatment notes. She wants to apply the security principle that restricts users to only the data they need to perform their assigned tasks. Which principle should she implement?

A.Least privilege
B.Defense in depth
C.Non-repudiation
D.Separation of duties
AnswerA

Least privilege means granting users only the minimum access rights necessary to perform their job functions. Since the nurses only need clinical treatment notes, removing their access to billing records directly applies this principle and reduces the risk of unauthorized data exposure. It is the most appropriate control for restricting access based on job duties in this scenario.

Why this answer

Least privilege is the security principle that requires giving users only the access needed for their specific job tasks. Because the nurses only need clinical notes, removing their billing access aligns directly with that principle. Separation of duties, defense in depth, and non-repudiation address different concerns and would not correct the excessive permissions described.

Exam trap

The trap here is confusing least privilege with separation of duties, since both limit what users can do, but only least privilege restricts access based on the minimum necessary for the job.

518
MCQmedium

A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?

A.Subnetting
B.DMZ
C.VLAN
D.Honeypot
AnswerC

A VLAN applies 802.1Q tagging to logically segment switch ports into separate broadcast domains, so Accounting and HR traffic stays isolated despite sharing one physical switch. This directly satisfies the stem's constraint of logical separation on common hardware, without requiring additional switches or physical rewiring.

Why this answer

A VLAN (Virtual LAN, IEEE 802.1Q) logically segments a single physical switch into multiple isolated broadcast domains, allowing the Accounting and HR departments to share hardware while remaining logically separated at Layer 2. This is the standard technology for departmental segmentation on a common switch. Subnetting operates at Layer 3 and does not by itself isolate traffic on the same switch without VLANs or ACLs.

Exam trap

The trap is conflating Layer 3 subnetting with Layer 2 segmentation — CC candidates often pick 'subnetting' because it sounds like separation, but only VLANs isolate traffic on the same physical switch.

How to eliminate wrong answers

Option A is wrong because subnetting is a Layer 3 IP addressing technique; without VLANs or router ACLs, devices on different subnets on the same switch can still communicate at Layer 2. Option B is wrong because a DMZ is a perimeter network segment for externally facing services, not an internal departmental segmentation tool. Option D is wrong because a honeypot is a decoy system designed to attract and detect attackers, not to separate internal departments.

519
Multi-Selectmedium

A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)

Select 2 answers
A.Applying temporary firewall or access-control rules to block the attacker's known infrastructure
B.Deleting all logs from affected systems to prevent the attacker from covering their tracks
C.Isolating affected hosts from the network while preserving evidence
D.Closing the incident ticket and notifying customers that service has resumed
E.Rebuilding every server in the data center from scratch immediately
AnswersA, C

Blocking confirmed malicious addresses, domains, or ports at perimeter and internal controls is a standard containment measure. It raises the attacker's cost and cuts off command-and-control or exfiltration paths while the team investigates. Because these rules are temporary and reversible, they limit disruption. This directly reduces ongoing impact and is appropriate during containment rather than waiting for full eradication.

Why this answer

Containment stops the spread and limits damage while keeping evidence intact for analysis. Isolating affected hosts and blocking the attacker's known infrastructure both reduce ongoing impact and are reversible, temporary measures. Rebuilding everything, closing the incident, or deleting logs are recovery or destructive actions that either destroy evidence or prematurely end the response, so they do not belong in containment.

Exam trap

The trap here is confusing containment with recovery, so drastic actions like rebuilding all systems or closing the incident get chosen when the goal is only to stop the spread and preserve evidence.

520
MCQmedium

A payroll administrator can view salary records for all employees during normal business hours, but only after her manager approves each access request and the system logs the action. Which security principle is BEST illustrated by limiting her access to what her job requires and only when needed?

A.Non-repudiation
B.Least privilege
C.Defense in depth
D.Separation of duties
AnswerB

Least privilege grants users only the minimum access necessary for their job function and only for as long as it is needed. Restricting the payroll administrator to the salary records her role requires, gated by approval and time windows, is a textbook application. Logging the action adds accountability and supports later review of whether that minimum access was appropriate.

Why this answer

Least privilege means granting only the access required to perform a job and only when it is required. The payroll administrator sees salary data tied to her role, must obtain approval for each request, and works within defined hours, all of which narrow access to the minimum necessary. Approval and logging reinforce accountability but do not change the underlying principle being demonstrated.

Exam trap

The trap here is confusing least privilege with separation of duties, since both restrict users, but only least privilege limits access to job need rather than splitting a task between people.

521
MCQhard

During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

A.72 hours
B.7 days
C.48 hours
D.24 hours
AnswerA

72 hours is the maximum period under GDPR Article 33, running from awareness of the breach. This satisfies the stem's constraint: PII of EU residents was exfiltrated, triggering the controller's obligation to notify the supervisory authority without undue delay. Notification must occur within that window unless the breach is unlikely to result in risk.

Why this answer

GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

522
MCQhard

An organization is designing a security architecture for a cloud-based application. They implement firewalls, intrusion detection systems, and encryption, and also conduct regular security awareness training. This approach demonstrates which security principle?

A.Defense in depth
B.Security through obscurity
C.Least privilege
D.Separation of duties
AnswerA

Defense in depth uses multiple layers of security controls, both technical and administrative.

Why this answer

Defense in depth uses multiple layered controls. The combination of technical and administrative controls is key.

523
MCQmedium

A security operations center (SOC) analyst notices unusual outbound network traffic from a server that typically only receives connections. The traffic is encrypted and goes to an unknown external IP. Which step should the analyst perform FIRST?

A.Check the server's running processes and connections
B.Power off the server
C.Block the outbound traffic at the firewall
D.Notify the system owner
AnswerA

Checking running processes and active connections identifies which executable is generating the encrypted outbound traffic and where it is connecting, providing the host-level evidence needed before any containment or blocking. This triage step satisfies the requirement to determine what is actually happening on the server first.

Why this answer

The first step in incident response is to gather evidence and understand the scope without altering the system. Checking the server's running processes and connections (A) allows the analyst to identify the malicious process, its parent, and the remote endpoint, which informs containment and eradication. This aligns with the 'identification' phase of incident response.

Exam trap

CC often tests the order of incident response steps; candidates may choose containment actions like blocking or powering off because they seem urgent, but the first step is always to identify and understand the incident without destroying evidence.

How to eliminate wrong answers

Option B is wrong because powering off the server destroys volatile evidence (memory, running processes, network connections) and may alert the attacker, hindering investigation. Option C is wrong because blocking outbound traffic at the firewall is a containment action that should come after identification; doing it first may cut off the attacker but also lose the ability to observe and trace the compromise. Option D is wrong because notifying the system owner is important but not the first technical step; the analyst should first verify and scope the incident.

524
Multi-Selecthard

An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)

Select 3 answers
A.Use a single firewall to connect internet, DMZ, and internal network
B.Allow all traffic from the DMZ to the internal network for ease of management
C.Use a separate VLAN for DMZ servers to isolate traffic
D.Place a firewall between the internet and the DMZ, and another between the DMZ and the internal network
E.Configure strict access control rules to allow only necessary services
AnswersC, D, E

A dedicated VLAN segments DMZ broadcast domains from internal LAN traffic, so compromise of a public-facing server cannot sniff or directly reach internal hosts at layer 2. This isolation satisfies the requirement to contain any breach originating from internet-accessible servers.

Why this answer

Option C is correct because placing DMZ servers on a dedicated VLAN segments their broadcast domain and Layer 2 traffic from the internal LAN, so a compromised web or email host cannot directly reach internal systems at Layer 2 and lateral movement is constrained. Option D is correct because a dual-firewall (screened subnet) design puts one firewall between the internet and the DMZ and a second between the DMZ and the internal network, enforcing defense in depth so that even if a DMZ host is compromised, the internal firewall still blocks access to internal resources. Option E is correct because strict access control rules implementing least privilege—permitting only the specific ports and protocols required (for example, TCP 80/443 to the web server and TCP 25/587 to the mail server)—minimize the attack surface and prevent unnecessary services from being reachable.

Option A is not correct because a single firewall with three interfaces, while workable, does not provide the layered separation and defense in depth that a dual-firewall DMZ design offers. Option B is not correct because allowing all traffic from the DMZ to the internal network violates least privilege and would let a compromised DMZ host pivot freely into the internal network.

Exam trap

The trap here is that candidates pick 'single firewall' because it sounds simpler and cheaper, but CompTIA and security exams consistently reward defense-in-depth with separate firewall boundaries between trust zones.

525
Multi-Selectmedium

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Select 2 answers
A.Hashing
B.Load balancing
C.Access control lists
D.Database encryption
E.Redundant power supplies
AnswersC, D

Access control lists restrict database access to authorised identities, enforcing least privilege so only approved users reach customer PII. This satisfies the stem's confidentiality requirement by preventing unauthorised disclosure, unlike integrity-focused controls such as hashing or digital signatures.

Why this answer

Access control lists (C) are appropriate because they enforce authorization by restricting which users, roles, or hosts may read the PII records, directly limiting exposure to only approved principals. Database encryption (D) is appropriate because it protects confidentiality at rest and, when applied to columns or tablespaces, renders the PII unreadable if the storage or backups are compromised. Hashing (A) is not suitable here because it is a one-way integrity mechanism, not a reversible confidentiality control for data that must be read back.

Load balancing (B) and redundant power supplies (E) are availability controls and do nothing to prevent unauthorized disclosure of PII.

Exam trap

CC often tests the distinction between confidentiality, integrity, and availability controls; candidates may incorrectly select hashing (integrity) or load balancing/redundant power (availability) when asked for confidentiality controls.

Page 6

Page 7 of 14

Page 8