Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 526–600

989 questions total · 14pages · All types, answers revealed

Page 7

Page 8 of 14

Page 9
526
MCQmedium

An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?

A.Phishing
B.Man-in-the-middle
C.Replay attack
D.DoS
AnswerB

The attacker terminates two separate TCP sessions — one with the client, one with the server — and relays traffic between them, so each endpoint authenticates against the attacker rather than the genuine peer. This active relay, not passive eavesdropping, defines the man-in-the-middle scenario described.

Why this answer

A man-in-the-middle (MITM) attack occurs when an adversary positions themselves between two communicating parties, establishing separate connections with each and relaying (or altering) traffic while both sides believe they are communicating directly. The scenario describes exactly this relay behavior. The attacker can eavesdrop, modify, or inject data because neither endpoint detects the intermediary.

Exam trap

The trap here is conflating MITM with sniffing or replay — candidates must recognize that MITM specifically requires the attacker to sit inline and relay traffic between two parties, not merely observe or retransmit it.

How to eliminate wrong answers

Option A is wrong because phishing is a social-engineering attack that tricks users into revealing credentials or clicking malicious links; it does not involve transparently relaying traffic between two hosts. Option C is wrong because a replay attack captures and retransmits previously valid data (such as an authentication token) to impersonate a legitimate party, rather than maintaining a live relay between client and server. Option D is wrong because a DoS attack aims to exhaust resources and deny availability, not to intercept and relay communications covertly.

527
MCQhard

Which statement best describes a warm site in disaster recovery?

A.It has replicated data but no active systems
B.It is fully operational with real-time data synchronization
C.It has hardware and network equipment but requires data restoration from backups
D.It has no hardware or infrastructure installed
AnswerC

Warm sites pre-stage hardware and network connectivity but hold no live replicated data, so operations resume only after backups are restored. This matches the scenario's requirement precisely: infrastructure exists, yet data restoration from backups remains necessary before systems become operational.

Why this answer

A warm site is a middle-ground disaster recovery option that has hardware and network infrastructure pre-installed but does not have live, synchronized data. Instead, data must be restored from backups (e.g., tape or disk snapshots) before operations can resume. This contrasts with a hot site, which maintains real-time data replication and fully active systems.

Exam trap

ISC2 often tests the distinction between warm and hot sites by making candidates confuse 'pre-installed hardware' (warm) with 'real-time data synchronization' (hot), so the trap is assuming that any site with hardware must also have live data.

How to eliminate wrong answers

Option A is wrong because a site with replicated data but no active systems describes a cold site with data replication, not a warm site; warm sites have hardware but require data restoration. Option B is wrong because a fully operational site with real-time data synchronization defines a hot site, which has zero recovery time objective (RTO) and continuous replication (e.g., synchronous SAN replication). Option D is wrong because a site with no hardware or infrastructure installed is a cold site, which requires full setup before recovery can begin.

528
MCQmedium

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

A.Implement a DMZ
B.Place the server on the internal LAN with a strong firewall rule
C.Use a VLAN to logically separate the server
D.Connect the server directly to the internet without firewall
AnswerA

A DMZ is specifically designed to host public-facing services with controlled access.

Why this answer

A DMZ (demilitarized zone) is a segmented network that sits between the untrusted internet and the trusted internal LAN, hosting public-facing services like web servers. It allows inbound internet access to the server while firewalls restrict traffic from the DMZ into the internal network, minimizing risk if the server is compromised. This directly satisfies the requirement to isolate the public server from internal networks.

Exam trap

The trap is assuming a VLAN alone provides security isolation — candidates must recognize that a DMZ requires firewall-enforced segmentation between internet, DMZ, and internal networks, not just logical separation.

How to eliminate wrong answers

Option B is wrong because placing a public-facing server on the internal LAN exposes the internal network to lateral movement if the server is compromised, even with strong firewall rules — a single misconfiguration can breach the whole LAN. Option C is wrong because a VLAN provides logical Layer 2 segmentation but does not by itself create a security boundary between the internet and internal resources; without firewall enforcement between VLANs, it is insufficient isolation. Option D is wrong because connecting the server directly to the internet with no firewall removes all filtering and exposes the server and any reachable internal resources to unrestricted attacks.

529
MCQmedium

An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?

A.Separation of duties
B.Diversity of defense
C.Least privilege
D.Defense in depth
AnswerD

Defense in depth layers independent controls so no single failure exposes the estate. Firewalls filter perimeter traffic, antivirus detects endpoint malware, and encryption protects data at rest if storage is compromised. Each addresses a distinct threat vector, satisfying the stem's requirement for multiple overlapping safeguards rather than reliance on one mechanism.

Why this answer

Defense in depth layers multiple independent controls — perimeter firewalls, endpoint antivirus, and encryption at rest — so that if one fails, others still protect the asset. This layered approach is the defining characteristic of defense in depth. The scenario explicitly describes multiple control types at different layers, which matches this principle.

Exam trap

The trap is confusing defense in depth with diversity of defense — both involve multiple controls, but depth means layering different control types, while diversity means using different products for the same control.

How to eliminate wrong answers

Option A is wrong because separation of duties divides critical tasks among different people to prevent fraud, which is not what the layered controls describe. Option B is wrong because diversity of defense means using different vendors or technologies for the same control layer to avoid a single flaw, not layering different control types. Option C is wrong because least privilege restricts access rights to the minimum necessary, which is about authorization, not layered perimeter/endpoint/data controls.

530
MCQhard

An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?

A.ARP spoofing
B.DNS poisoning
C.IP spoofing
D.MAC flooding
AnswerA

ARP spoofing floods the network with forged ARP replies that map the gateway's IP address to the attacker's MAC address, poisoning switch ARP caches so traffic destined for the default gateway is redirected to the attacker.

Why this answer

ARP spoofing (ARP poisoning) occurs when an attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway. Switches then populate their ARP caches with the attacker's MAC for the gateway IP, causing traffic to be redirected to the attacker. This matches the symptom of ARP cache entries pointing to an unknown MAC for the gateway.

Exam trap

The trap is confusing ARP spoofing with MAC flooding or IP spoofing — candidates see 'MAC address' and pick MAC flooding, but the key clue is the ARP cache being poisoned with a false gateway mapping.

How to eliminate wrong answers

Option B is wrong because DNS poisoning corrupts DNS resolver caches to redirect domain names, not ARP caches or MAC-to-IP mappings. Option C is wrong because IP spoofing forges source IP addresses in packets but does not alter ARP cache entries on switches. Option D is wrong because MAC flooding overwhelms the switch CAM table to force flooding, but it does not create ARP entries pointing to an unknown MAC for the gateway.

531
MCQmedium

A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?

A.Cloud-based recovery with daily snapshots
B.Warm site with weekly full backups
C.Hot site with continuous data replication
D.Cold site with daily full backups
AnswerC

Continuous replication keeps the standby site within minutes of the primary, comfortably satisfying the one-hour RPO, while a hot site runs pre-provisioned infrastructure ready to take over well inside the four-hour RTO. For a 24/7 EHR, this pairing is the only one meeting both recovery objectives simultaneously.

Why this answer

A hot site with continuous data replication best meets an RTO of 4 hours and RPO of 1 hour because a hot site is a fully operational duplicate facility that can take over almost immediately, and continuous replication keeps data loss well under 1 hour. This combination provides the lowest recovery time and data loss, aligning with the hospital's 24/7 availability requirement.

Exam trap

CC often tests RTO/RPO by pairing them with site types — the trap is that candidates pick a cheaper site (warm/cold) that fails the strict RTO, or a backup frequency that fails the RPO.

How to eliminate wrong answers

Option A is wrong because daily snapshots yield an RPO of up to 24 hours, far exceeding the 1-hour RPO requirement, even if cloud recovery could meet the RTO. Option B is wrong because weekly full backups produce an RPO of up to 7 days, massively violating the 1-hour RPO, and a warm site may not meet the 4-hour RTO reliably. Option D is wrong because a cold site lacks pre-installed infrastructure and can take days to become operational, failing the 4-hour RTO, and daily full backups fail the 1-hour RPO.

532
MCQeasy

Which of the following best describes a Disaster Recovery Plan (DRP)?

A.A plan to restore IT systems after a disruption
B.A plan to evacuate personnel during an emergency
C.A plan to identify critical business functions
D.A plan to keep the business running during a disruption
AnswerA

A DRP documents the procedures, roles and resources for recovering IT systems and data after an outage, disaster or cyber incident. Restoring IT systems after a disruption captures its core purpose, distinguishing it from business continuity planning, which covers broader operations during the event.

Why this answer

A Disaster Recovery Plan (DRP) is specifically focused on restoring IT systems, applications, and data after a disruption — it defines recovery time objectives (RTO), recovery point objectives (RPO), backup restoration procedures, and failover steps. It is a subset of the broader Business Continuity Plan (BCP).

Exam trap

CC often tests the distinction between DRP (IT system recovery) and BCP (business operations continuity) — candidates frequently swap the two definitions.

How to eliminate wrong answers

Option B is wrong because personnel evacuation is covered by an Emergency Response Plan or Occupant Emergency Plan, not a DRP. Option C is wrong because identifying critical business functions is part of Business Impact Analysis (BIA), which feeds into both BCP and DRP but is not the DRP itself. Option D is wrong because keeping the business running during a disruption is the definition of a Business Continuity Plan (BCP), which is broader than and distinct from a DRP.

533
MCQmedium

A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?

A.SYN flood
B.Smurf attack
C.ARP spoofing
D.DNS amplification
AnswerA

A SYN flood overwhelms a target by sending numerous TCP SYN packets without completing the three-way handshake, leaving connections half-open. This precisely matches the stem's observation of abnormally high incomplete TCP connection requests, exhausting the backlog queue and preventing legitimate connections from being established.

Why this answer

SYN flood attacks exploit the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting server resources.

534
MCQeasy

A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?

A.Separation of duties
B.Need to know
C.Defense in depth
D.Least privilege
AnswerD

Least privilege grants each user only the access rights necessary for their job, nothing more. This satisfies the stem's requirement by restricting permissions to the minimum needed, reducing the blast radius of compromised accounts or insider misuse.

Why this answer

Least privilege means granting users only the minimum access rights required to perform their job functions, nothing more. This directly matches the scenario where the administrator wants each user to have only the access necessary for their role. It reduces the attack surface and limits potential damage from compromised accounts.

Exam trap

The trap here is confusing least privilege with need to know or separation of duties; candidates often pick need to know because it sounds similar, but least privilege is specifically about minimum access rights for a job role.

How to eliminate wrong answers

Option A is wrong because separation of duties divides critical tasks among multiple people to prevent fraud or errors, rather than limiting each user to the minimum access for their job. Option B is wrong because need to know focuses on restricting access to information based on whether the user requires it for a specific task, which is a subset of least privilege but not the overarching principle described. Option C is wrong because defense in depth is a layered security strategy, not a principle about individual user permissions.

535
MCQeasy

A small business wants to prevent employees from visiting known malicious websites. The owner asks a technician to implement a control that blocks requests to a maintained list of bad domains before any connection is made to those sites. Which solution should the technician deploy?

A.A host-based antivirus scanner that quarantines downloaded files
B.An intrusion prevention system placed inline at the network edge
C.A next-generation firewall configured with application signatures
D.A DNS filtering service that refuses to resolve known malicious domains
AnswerD

DNS filtering intercepts name resolution requests and returns a block or sinkhole response for domains on a threat feed. Because the malicious domain is never resolved to an IP address, the client cannot initiate a connection to the site, which directly meets the owner's requirement to block requests before any connection is made.

Why this answer

DNS filtering is the only listed control that stops a malicious website visit at the name-resolution stage. By refusing to resolve the domain, it prevents the client from learning the destination IP address, so no connection can be initiated. Endpoint antivirus, application-aware firewalls, and intrusion prevention systems all operate later in the connection lifecycle.

Exam trap

The trap here is equating any security control that can eventually detect malicious traffic with one that prevents the initial connection from being made.

536
MCQhard

During a forensic investigation, an analyst acquires a live system memory dump. Which tool is most appropriate for capturing the contents of volatile memory on a Windows system?

A.DumpIt
B.Wireshark
C.FTK Imager
D.dd
AnswerA

DumpIt captures Windows volatile memory directly from a running system, preserving RAM contents before shutdown destroys them. It satisfies the live acquisition constraint by reading physical memory without installing agents or altering the system, unlike disk-imaging tools.

Why this answer

DumpIt is a lightweight, standalone tool designed specifically for capturing the full contents of volatile memory (RAM) on a Windows system. It creates a raw memory dump file without requiring installation or complex configuration, making it ideal for forensic acquisition of live system memory.

Exam trap

ISC2 often tests the distinction between tools for capturing volatile memory versus non-volatile storage, and candidates may mistakenly choose FTK Imager because it is a well-known forensic suite, but it is not the primary tool for live memory acquisition on Windows.

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer used for capturing and inspecting network traffic, not for acquiring system memory dumps. Option C is wrong because FTK Imager is primarily a disk imaging and forensic analysis tool; while it can capture a memory dump via a separate plugin (e.g., FTK Imager Lite), it is not the most appropriate or direct tool for live memory acquisition. Option D is wrong because dd is a Unix/Linux command-line utility for bit-for-bit disk cloning; it is not natively available on Windows and does not interface with Windows memory structures without additional drivers or wrappers.

537
MCQhard

A company is designing a new application that processes credit card payments. They want to ensure that no single administrator can bypass security controls to approve a fraudulent transaction. Which principle should be implemented?

A.Separation of duties
B.Defense in depth
C.Least privilege
D.Need to know
AnswerA

Separation of duties splits transaction authorisation across multiple people, so no single administrator holds enough privilege to approve a fraudulent payment alone. This directly satisfies the stem's requirement that one administrator cannot bypass security controls.

Why this answer

Separation of duties ensures that no single administrator has the authority to both initiate and approve a credit card transaction. By dividing critical functions among multiple individuals, the company prevents a single compromised account from authorizing fraudulent payments. This principle directly addresses the risk of insider threats or credential misuse in payment processing systems.

Exam trap

ISC2 often tests separation of duties by presenting a scenario about preventing fraud or abuse, and the trap is that candidates confuse it with least privilege, thinking limiting permissions alone solves the problem, when in fact the core issue is splitting conflicting tasks across different people.

How to eliminate wrong answers

Option B (Defense in depth) is wrong because it refers to multiple layers of security controls (e.g., firewalls, IDS, encryption) rather than dividing administrative responsibilities. Option C (Least privilege) is wrong because it limits access rights to the minimum necessary for a role, but does not prevent a single administrator from having both the ability to create and approve a transaction. Option D (Need to know) is wrong because it restricts access to information based on job function, not the separation of conflicting duties in a transaction workflow.

538
MCQmedium

After a security audit, a company discovers that several employees have access to financial systems that are not required for their job roles. Which access control model would best prevent this issue in the future?

A.Mandatory access control (MAC)
B.Discretionary access control (DAC)
C.Role-based access control (RBAC)
D.Attribute-based access control (ABAC)
AnswerC

Role-based access control assigns permissions to job roles rather than individuals, so employees inherit only the access their role requires. This enforces least privilege and prevents the excessive financial-system entitlements found in the audit, directly addressing the stem's requirement.

Why this answer

RBAC assigns permissions to roles rather than individuals, so access is granted only when a user's job role requires it. This directly enforces least privilege and prevents the audit finding where employees held unnecessary financial-system access. When roles are defined from job functions and reviewed periodically, orphaned or excessive entitlements are far easier to detect and remove.

Exam trap

The trap here is confusing DAC's owner-discretion model with least privilege; candidates often pick DAC because it sounds flexible, but flexibility is precisely what caused the excessive access.

How to eliminate wrong answers

Option A is wrong because MAC relies on system-enforced labels and clearances (e.g., Bell-LaPadula, SELinux) and is typically used in high-assurance military/government contexts, not for aligning business job roles to financial applications. Option B is wrong because DAC lets resource owners grant access at their discretion, which is exactly the loose model that allowed excessive entitlements in the first place. Option D is wrong because ABAC, while more granular, is policy- and attribute-driven and does not by itself solve role-to-entitlement alignment; it is also more complex to administer than needed for this job-role problem.

539
MCQmedium

A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?

A.Enable Telnet with strong password policies and disable the root account.
B.Implement a VPN for all server traffic and allow root logins only from the local console.
C.Configure a host-based firewall to allow only HTTP and HTTPS traffic and disable SSH.
D.Enable SSH with PermitRootLogin set to no and restrict access to the management subnet.
AnswerD

SSH provides encrypted administrative sessions, and setting PermitRootLogin to no prevents direct root logins over the network. Restricting access to the management subnet further reduces the attack surface. This combination directly addresses the requirements of encrypted management and no direct root access, making it the correct choice for securing the Linux web server.

Why this answer

The requirement is to allow only encrypted administrative sessions and prevent direct root logins. SSH is the standard encrypted remote administration protocol on Linux. Setting PermitRootLogin to no blocks direct root access over SSH, and restricting access to a management subnet adds defense in depth.

Together, these measures meet both conditions without disrupting necessary administration.

Exam trap

The trap here is assuming that any remote access method with strong passwords is sufficient, while overlooking that Telnet is unencrypted and thus fails the encryption requirement.

540
MCQhard

In a Bell-LaPadula MAC model, which of the following operations is prohibited?

A.A Top Secret subject reads a Confidential object
B.A Top Secret subject reads a Top Secret object
C.A Top Secret subject writes to a Top Secret object
D.A Top Secret subject writes to an Unclassified object
AnswerD

A Top Secret subject writing to an Unclassified object violates the *-property (star property), which forbids writing down to lower sensitivity levels. Bell-LaPadula permits no write-down, preventing high-classification data leaking into less protected objects. The no-read-up simple property is unaffected here; only the write-down is prohibited.

Why this answer

In the Bell-LaPadula model, the *-property (star property) prohibits a subject from writing to an object at a lower classification level. A Top Secret subject writing to an Unclassified object would cause a downgrade of sensitive information, violating this property. Therefore, option D is the prohibited operation.

Exam trap

ISC2 often tests the misconception that the *-property (no write down) applies to writing to higher-level objects, when in fact it only restricts writing to lower-level objects, and candidates may confuse it with the simple security property (no read up).

How to eliminate wrong answers

Option A is wrong because the simple security property (no read up) allows a Top Secret subject to read a Confidential object, as it reads down. Option B is wrong because reading an object at the same classification level (Top Secret) is permitted under both the simple security property and the *-property. Option C is wrong because writing to an object at the same classification level (Top Secret) is allowed by the *-property, as it does not involve a downgrade.

541
MCQeasy

A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?

A.TCP 53 and UDP 53
B.TCP 80 and TCP 443
C.TCP 21 and TCP 22
D.TCP 25 and TCP 110
AnswerB

HTTP uses TCP port 80, and HTTPS uses TCP port 443. Allowing these ports enables standard web browsing and secure web traffic. This is a common firewall configuration to permit outbound web access while blocking other potentially risky ports. The administrator should also consider application-layer filtering for additional security, but the correct port numbers are 80 and 443.

Why this answer

HTTP operates on TCP port 80, and HTTPS operates on TCP port 443. To allow only web traffic, the firewall must permit these ports. Other ports correspond to different services such as FTP, SSH, SMTP, POP3, or DNS, which are not required for web browsing.

Therefore, the correct ports are 80 and 443.

Exam trap

The trap here is selecting ports for common internet services like DNS or email, but the question specifically asks for HTTP and HTTPS, which are exclusively port 80 and 443.

542
MCQmedium

A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?

A.Biometric reader on server room door
B.Cable locks on laptops
C.Visitor badge policy
D.Fencing around the property
AnswerD

Fencing defines the outer physical boundary of a site, delaying or deterring intruders before they reach the building. It therefore operates as an external perimeter measure, satisfying the stem's requirement, whereas locks and badge readers sit at internal entry points.

Why this answer

Fencing around the property is an external perimeter security measure because it establishes the outermost physical boundary of the facility, deterring and delaying unauthorized entry before an attacker reaches the building. Perimeter controls focus on the site's outer edge, while the other options protect interior assets or personnel behavior. Fencing, bollards, lighting, and gates are classic examples of external perimeter defenses.

Exam trap

The trap is that candidates pick the most 'secure-sounding' control (biometrics) rather than the one that actually sits at the external perimeter — the exam tests whether you can distinguish perimeter from interior and administrative controls.

How to eliminate wrong answers

Option A is wrong because a biometric reader on a server room door is an interior access control protecting a specific high-value room, not the external perimeter. Option B is wrong because cable locks on laptops are endpoint-level physical controls that secure individual portable assets, not the facility perimeter. Option C is wrong because a visitor badge policy is an administrative control governing personnel movement inside the facility, not a physical external perimeter measure.

543
MCQhard

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

A.Availability
B.Confidentiality
C.Integrity
D.Non-repudiation
AnswerA

Geographically dispersed redundant servers plus load balancing keep services reachable despite outages or attacks, directly satisfying the availability concern named in the stem. This redundancy addresses uptime rather than confidentiality or integrity, which encryption and hashing would respectively protect.

Why this answer

Redundancy and load balancing ensure that systems remain accessible, supporting availability.

544
MCQmedium

What is the primary purpose of a Privileged Access Management (PAM) solution?

A.To provide single sign-on for all applications
B.To manage visitor access to the building
C.To enforce password complexity for all users
D.To control and monitor privileged access to critical systems
AnswerD

PAM brokers privileged sessions through a controlled vault, enforcing approval workflows, credential checkout and full session recording. This satisfies the scenario's need to both restrict who reaches critical systems and retain auditable evidence of every administrative action performed.

Why this answer

A Privileged Access Management (PAM) solution is specifically designed to secure, control, and monitor the use of privileged accounts—such as root, administrator, or service accounts—that have elevated access to critical systems. It typically provides features like credential vaulting, session recording, just-in-time access, and approval workflows to prevent misuse and detect malicious activity. Unlike general IAM or SSO tools, PAM focuses on the highest-risk accounts and enforces least privilege for administrative actions.

Thus, option D accurately captures its primary purpose.

Exam trap

The trap here is confusing PAM with general IAM or SSO solutions, as candidates may think any access management tool covers privileged access, but PAM specifically targets elevated accounts and their monitoring.

How to eliminate wrong answers

Option A is wrong because single sign-on (SSO) is an authentication convenience provided by Identity and Access Management (IAM) or federated identity solutions, not the core function of PAM; PAM may integrate with SSO but does not primarily provide it. Option B is wrong because managing visitor access to a building is a physical security function, unrelated to logical access controls for IT systems. Option C is wrong because enforcing password complexity for all users is a general password policy typically handled by directory services or IAM, whereas PAM focuses on privileged accounts and often uses vaulting and rotation rather than just complexity rules.

545
MCQhard

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerC

Purchasing cyber insurance shifts the financial consequence of a breach to the insurer, which is the defining mechanism of risk transfer. The organisation retains the threat itself but transfers the monetary liability, directly satisfying the stem's scenario of covering potential breach losses rather than avoiding, mitigating or accepting the risk.

Why this answer

Purchasing cyber insurance transfers the financial impact of a data breach to a third party (the insurer) in exchange for a premium. The organization still owns the risk event, but the monetary loss is shifted to the insurer, which is the textbook definition of risk transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation — candidates see 'insurance' and think 'control,' but insurance shifts financial liability rather than reducing the probability or impact of the breach itself.

How to eliminate wrong answers

Option A is wrong because risk mitigation reduces the likelihood or impact of a risk through controls (e.g., firewalls, encryption), not by shifting financial liability. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, retaining the potential loss internally. Option D is wrong because risk avoidance eliminates the activity that creates the risk entirely (e.g., not storing the data at all), rather than offloading the consequence.

546
MCQhard

A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?

A.Separation of duties
B.Defense in depth
C.Least privilege
D.Need to know
AnswerA

Separation of duties splits a sensitive transaction across two people so no single employee holds end-to-end control. Requiring one person to initiate and a different person to approve the wire transfer enforces exactly this split, preventing unilateral fraud.

Why this answer

Separation of duties is the security principle that requires multiple individuals to complete a task to prevent fraud and errors. By ensuring no single employee can both initiate and approve a wire transfer, the institution enforces this principle, reducing the risk of unauthorized transactions.

Exam trap

The trap is confusing separation of duties with least privilege or need to know; candidates must recognize that SoD specifically addresses the division of a single task among multiple people to prevent conflicts of interest.

How to eliminate wrong answers

Option B is wrong because defense in depth involves multiple layers of security controls, not the division of responsibilities among employees. Option C is wrong because least privilege means granting users only the minimum access necessary to perform their jobs, not splitting a task between two people. Option D is wrong because need to know restricts access to information based on job requirements, not the separation of transaction initiation and approval.

547
MCQeasy

Which of the following is a key component of the 3-2-1 backup rule?

A.Two copies on different media, one off-site
B.One copy on two different media, two off-site
C.Three copies on different media, two off-site
D.Three copies, two different media types, one off-site
AnswerD

Three copies of data, stored on two different media types, with one copy held off-site, directly satisfies the 3-2-1 rule's redundancy and geographic-separation constraints. The two-media requirement protects against media-specific failures, while the off-site copy survives local disasters affecting the primary and secondary copies.

Why this answer

The 3-2-1 backup rule specifies three copies of data (one primary plus two backups), stored on two different media types, with one copy kept off-site. Option D captures all three elements precisely, which is why it is the canonical definition used in CompTIA and vendor backup guidance.

Exam trap

The trap here is that candidates memorize '3-2-1' as a slogan without mapping each digit to its meaning, so they swap the '2 media' and '1 off-site' counts under time pressure.

How to eliminate wrong answers

Option A is wrong because it only accounts for two copies total and omits the requirement for three copies of data. Option B is wrong because it reverses the media and off-site counts — the rule requires two media types and one off-site copy, not one media type and two off-site copies. Option C is wrong because it states three copies on different media and two off-site, but the rule only requires one off-site copy, not two.

548
Multi-Selecteasy

Which TWO of the following are fundamental principles of information security that form the CIA triad?

Select 2 answers
A.Confidentiality
B.Integrity
C.Privacy
D.Non-repudiation
E.Accountability
AnswersA, B

Confidentiality ensures information is disclosed only to authorised parties, typically through encryption and access controls. It is one of the three CIA triad pillars, directly satisfying the stem's requirement for a fundamental information security principle.

Why this answer

Confidentiality (A) is a core CIA triad principle because it ensures information is not disclosed to unauthorized individuals, systems, or processes, typically enforced through encryption, access controls, and classification. Integrity (B) is also a core CIA triad principle because it ensures data and systems remain accurate, complete, and protected from unauthorized modification, whether in storage or transit, using mechanisms like hashing, checksums, and digital signatures. Together with Availability, these three form the CIA triad, the foundational model for information security.

Privacy (C) is a related concept concerning the appropriate handling of personal data, but it is not one of the three CIA triad principles. Non-repudiation (D) is a security property that prevents a party from denying an action, often achieved with digital signatures, but it is not part of the CIA triad. Accountability (E) supports security through auditing and traceability, but it is likewise not one of the three CIA triad pillars.

549
MCQeasy

Which of the following ensures that data has not been tampered with during transmission?

A.Redundancy
B.Encryption
C.Hashing
D.Authentication
AnswerC

Hashing produces a fixed-length digest from the transmitted data; any alteration changes the digest entirely, so comparing sender and receiver hashes detects tampering. This satisfies the stem's integrity requirement. Encryption provides confidentiality rather than modification detection, and checksums are weaker against deliberate changes.

Why this answer

Hashing ensures data integrity by producing a fixed-length digest from the original data; if even one bit changes during transmission, the resulting hash will differ, allowing the receiver to detect tampering. Common algorithms include SHA-256 and MD5 (though MD5 is deprecated for security). Hashing is specifically designed to verify that data has not been altered, which is the definition of integrity.

Exam trap

The trap is confusing integrity with confidentiality — candidates often pick 'encryption' because it sounds like it protects data, but encryption alone doesn't guarantee the data wasn't modified; hashing is the specific mechanism for integrity.

How to eliminate wrong answers

Option A is wrong because redundancy (e.g., RAID, redundant links) provides availability and fault tolerance, not integrity verification — it does not detect whether data was modified. Option B is wrong because encryption provides confidentiality by making data unreadable to unauthorized parties, but it does not inherently prove the data wasn't tampered with (though authenticated encryption modes like AES-GCM combine both). Option D is wrong because authentication verifies the identity of a user or system, not the integrity of the data itself — authentication answers 'who are you,' not 'was this data changed.'

550
Multi-Selectmedium

A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)

Select 2 answers
A.Update the incident response plan and detection signatures based on findings from the investigation
B.Eradicate the malware by removing malicious files and disabling the persistence mechanism
C.Conduct a lessons-learned review with stakeholders to identify root cause and improve future response
D.Activate the disaster recovery site so clinical applications continue to run during the outage
E.Isolate infected workstations from the network to prevent the malware from reaching other systems
AnswersA, C

Post-incident activity includes incorporating lessons learned into updated procedures, controls, and detection content so the same weakness is less likely to be exploited again. Revising the incident response plan and tuning detection signatures directly reflects the findings of the investigation. This closes the loop between response and preparation, improving the hospital's posture for the next incident.

Why this answer

Post-incident activity focuses on learning from the event and improving future response. Conducting a lessons-learned review identifies root cause and gaps, while updating the incident response plan and detection signatures institutionalizes those findings. Containment, eradication, and recovery actions occur earlier in the lifecycle, so isolating hosts, removing malware, or activating a recovery site do not belong in the post-incident phase.

Exam trap

The trap here is mixing actions from the containment, eradication, and recovery phases into the post-incident phase, when post-incident work is about review and improvement after systems are restored.

551
MCQhard

A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?

A.Cold site
B.Warm site
C.Reciprocal agreement
D.Hot site
AnswerC

Reciprocal agreements depend on a partner's facility remaining available, so a single regional disaster can incapacitate both sites simultaneously. This shared-fate exposure is the strategy's core weakness, directly satisfying the stem's constraint that the partner's facility was impacted by the same outage, leaving no viable recovery location.

Why this answer

A reciprocal agreement is a DR arrangement where two organizations agree to host each other's workloads during a disaster, typically at no or low cost. The scenario shows the classic failure mode: a regional disaster affects both parties simultaneously, so the partner site is unavailable exactly when it is needed.

Exam trap

The trap is that candidates see 'agreement with another organization' and assume it is a hot site or a formal DR contract, missing that the question is testing the specific weakness of reciprocal agreements — correlated disaster exposure.

How to eliminate wrong answers

Option A is wrong because a cold site is a company-owned or leased facility with power and connectivity but no pre-installed hardware; it would not be 'the partner's facility' and its disadvantage is slow activation, not shared-disaster impact. Option B is wrong because a warm site is a partially equipped company facility, again not a partner's site, and its disadvantage is longer RTO than a hot site. Option D is wrong because a hot site is a fully equipped, often commercially leased facility with near-zero RTO; its disadvantage is cost, not mutual disaster exposure.

552
MCQmedium

An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?

A.Conduct the restore test only during annual disaster recovery drills.
B.Reduce the recovery point objective (RPO) to minimize data loss.
C.Increase the RTO to 6 hours.
D.Automate the configuration and validation steps after restore.
AnswerD

Restore takes two hours, but manual reconfiguration and validation add three, totalling five hours and breaching the four-hour RTO. Automating those post-restore configuration and validation steps removes manual delay, bringing total recovery within the four-hour objective.

Why this answer

The RTO is 4 hours, but the actual recovery time is 2 hours (restore) + 3 hours (reconfigure and test) = 5 hours, exceeding the RTO by 1 hour. Automating the configuration and validation steps (option D) reduces the post-restore manual effort, bringing the total recovery time closer to or within the 4-hour RTO. This directly addresses the gap without altering the RTO or neglecting testing.

Exam trap

ISC2 often tests the distinction between RTO and RPO, and the trap here is that candidates confuse reducing RPO (data loss) with fixing a time-based gap, or they incorrectly assume that simply increasing the RTO is an acceptable solution without considering process improvement.

How to eliminate wrong answers

Option A is wrong because conducting the restore test only during annual drills does not fix the daily operational gap; it merely postpones validation, leaving the recovery process untested and potentially non-compliant with the RTO. Option B is wrong because reducing the RPO (recovery point objective) addresses data loss tolerance, not recovery time; it does not reduce the 5-hour total recovery duration. Option C is wrong because increasing the RTO to 6 hours accepts the inefficiency rather than fixing it; best practice is to improve the process to meet the original RTO, not relax the requirement.

553
MCQmedium

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

A.Isolate the application from the network and wait for a vendor patch.
B.Deploy an emergency patch without testing.
C.Implement a web application firewall (WAF) as a permanent solution.
D.Follow the standard patch lifecycle with testing.
AnswerB

Deploying an emergency patch without testing is the appropriate response due to the immediate and severe threat posed by a critical zero-day vulnerability actively being exploited in the wild. The paramount concern is to halt active exploitation and prevent further compromise as quickly as possible. While rigorous testing is normally crucial, the urgency of stopping an ongoing attack outweighs the risks associated with an untested deployment, directly addressing the constraint of mitigating an active, critical threat.

Why this answer

When a zero-day vulnerability is actively exploited in the wild against an internet-facing application, the risk of waiting for full testing outweighs the risk of deploying an untested emergency patch. An emergency patch (or vendor hotfix) is deployed immediately with expedited change approval, because the active exploitation represents an imminent, ongoing threat that standard change-management timelines cannot accommodate.

Exam trap

CC often tests whether candidates default to 'always test before deploying' — but when a zero-day is actively exploited, the correct answer is the emergency patch without full testing, because the standard lifecycle's delay is itself the greater risk.

How to eliminate wrong answers

Option A is wrong because isolating the application from the network may break business functionality and does not remediate the vulnerability — it only reduces exposure while leaving the system unpatched. Option C is wrong because a WAF is a compensating control, not a permanent fix; it can be bypassed and does not address the underlying code flaw, so it cannot replace patching. Option D is wrong because following the standard patch lifecycle with full testing introduces unacceptable delay when the vulnerability is being actively exploited — the standard lifecycle is for routine patches, not emergency zero-days.

554
MCQmedium

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

A.Advance the profession
B.Act honourably
C.Provide diligent service
D.Protect society
AnswerD

The (ISC)² Code of Ethics places the safety and welfare of society, the public trust, and the infrastructure above all other obligations. Duties to principals and employers rank lower, so protecting society takes precedence when interests conflict.

Why this answer

The (ISC)² Code of Ethics Canons are ordered by priority, and the first canon — 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' — takes precedence over all others. This means that when obligations conflict, the safety and welfare of society outweigh duties to employers, clients, or the profession. The remaining canons (act honorably, provide diligent service, advance the profession) are subordinate to this top-level obligation.

Exam trap

The trap here is that candidates often assume 'provide diligent service to your employer' is the top priority because it feels like the most immediate professional duty, but the (ISC)² Code explicitly ranks protecting society above all other obligations.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the fourth and lowest-priority canon, applying only after all higher obligations are satisfied. Option B is wrong because 'Act honourably, honestly, justly, responsibly, and legally' is the second canon, ranked below protecting society. Option C is wrong because 'Provide diligent and competent service to principals' is the third canon, which yields to the public-safety obligation when the two conflict.

555
Multi-Selecteasy

Which TWO of the following are examples of physical access controls?

Select 2 answers
A.Encryption
B.Biometric scanners
C.Smart cards
D.Intrusion Prevention Systems (IPS)
E.Firewalls
AnswersB, C

Biometric scanners verify identity through physical characteristics such as fingerprints or iris patterns, controlling entry at a physical boundary. They are hardware-based mechanisms that regulate who may physically enter a facility, satisfying the physical access control criterion rather than logical or administrative controls.

Why this answer

Biometric scanners (B) are physical access controls because they authenticate a person via a physical characteristic such as a fingerprint, iris, or retina before granting entry to a facility or device. Smart cards (C) are also physical access controls since they are tangible tokens used with a card reader to authenticate and unlock doors or restricted areas. Encryption (A) is a logical/technical control that protects data confidentiality, not physical entry.

Intrusion Prevention Systems (D) and firewalls (E) are network-based technical controls that monitor or filter traffic, so they are not physical access controls.

Exam trap

ISC2 often tests the distinction between physical controls (tangible, hardware-based mechanisms that restrict physical access) and logical/technical controls (software or network-based protections), causing candidates to mistakenly classify encryption or firewalls as physical controls.

556
MCQeasy

A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?

A.Vulnerability assessment
B.Business Impact Analysis (BIA)
C.Risk assessment
D.Gap analysis
AnswerB

The Business Impact Analysis is performed first, identifying critical business functions, their dependencies and tolerable downtime, which then inform recovery strategies and RTO/RPO targets. It satisfies the stem's requirement to identify functions and dependencies before plan creation.

Why this answer

A Business Impact Analysis (BIA) is the first step in BCP to identify critical functions, dependencies, and recovery requirements.

557
MCQeasy

A healthcare provider must ensure that patient records remain unaltered during storage and transmission between clinics. Which security principle is being addressed when the organization implements hashing and digital signatures on those records?

A.Integrity
B.Non-repudiation
C.Confidentiality
D.Availability
AnswerA

Integrity ensures data is not modified or destroyed in an unauthorized manner. Hashing produces a digest that changes if even one bit is altered, and digital signatures bind the sender's identity to the data, so any tampering is detectable. In this scenario the healthcare provider's specific goal is to prevent and detect unauthorized alteration of patient records, which is exactly the integrity objective of the CIA triad.

Why this answer

The scenario centers on preventing and detecting unauthorized modification of patient records while they are stored and moved between clinics. Integrity controls such as hashing and digital signatures make any change detectable and bind the data to its source. Confidentiality hides contents, availability keeps data reachable, and non-repudiation proves who did something; none of those directly satisfies the requirement that the records stay unaltered.

Exam trap

The trap here is assuming that because the records are sensitive, confidentiality must be the answer, when the requirement actually concerns detecting alteration.

558
MCQeasy

An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?

A.MAC address filtering
B.WPA3-SAE with a shared password
C.WPA2-Personal with a pre-shared key
D.802.1X with a RADIUS server
AnswerD

802.1X is an IEEE standard for port-based network access control that requires devices to authenticate via a RADIUS server before gaining network access. It supports per-device credentials, certificates, or other methods, ensuring only authorized devices connect. This is the appropriate solution for corporate Wi-Fi networks requiring strong authentication.

Why this answer

802.1X with a RADIUS server provides port-based network access control, requiring each device to authenticate before being granted access. It supports various authentication methods such as certificates or credentials, making it ideal for ensuring only authorized devices connect to corporate Wi-Fi. Other options like pre-shared keys or MAC filtering are weaker and not scalable for enterprise use.

Exam trap

The trap here is confusing WPA3-SAE, which is a strong encryption protocol, with network access control; it still uses a shared password and does not authenticate individual devices.

559
MCQhard

An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?

A.MAC flooding
B.DNS spoofing
C.IP spoofing
D.ARP spoofing
AnswerD

ARP spoofing sends forged ARP replies that map the attacker's MAC address to another host's IP, here the default gateway. The switch caches this false binding, redirecting traffic through the attacker. This satisfies the scenario's constraint of a forged ARP response poisoning the cache.

Why this answer

ARP spoofing (or ARP poisoning) involves sending fake ARP messages to associate the attacker's MAC with a legitimate IP, enabling man-in-the-middle attacks.

560
MCQeasy

A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?

A.Something you know and something you have
B.Something you know and something you are
C.Something you have and something you are
D.Something you know and somewhere you are
AnswerA

The password represents something the user knows, while the one-time code generated by the mobile authenticator app represents something the user has, namely the registered device. Combining these two distinct factor types satisfies multi-factor authentication. This pairing is the most common MFA implementation and directly matches the scenario's username/password plus app-generated code.

Why this answer

Multi-factor authentication requires combining factors from different categories. The password is a knowledge factor, and the one-time code from a registered mobile app is a possession factor. Together they form something you know plus something you have.

The other pairings involve biometrics or location, neither of which appears in the described login sequence, so they do not accurately describe the factors in use.

Exam trap

The trap here is treating a one-time code as a knowledge factor because the user reads and types it, rather than recognizing it as a possession factor tied to the device.

561
Multi-Selecthard

Which THREE are common indicators of a compromised system? (Select THREE.)

Select 3 answers
A.Unexpected software installations
B.Unusual outbound network connections
C.High CPU usage during business hours
D.System uptime greater than 30 days
E.Multiple failed login attempts leading to account lockout
AnswersA, B, E

Malware often installs without user consent.

Why this answer

Unexpected software installations are a common indicator of compromise because attackers often deploy malware, backdoors, or remote access tools (RATs) without user consent. In a CC context, this aligns with the principle that unauthorized software changes signal a breach, as legitimate installations typically follow change management processes. The presence of unknown executables or services in the system's process list or startup entries is a red flag.

Exam trap

ISC2 often tests the distinction between symptoms of normal operations (e.g., high CPU usage during business hours) and true indicators of compromise, tricking candidates into selecting benign metrics as signs of a breach.

562
MCQeasy

Which of the following is considered Sensitive PII?

A.Email address
B.Social Security Number
C.Phone number
D.Name
AnswerB

A Social Security Number uniquely identifies an individual and is issued by the US government, so its exposure can directly enable identity theft. That inherent identifiability is what classifies it as Sensitive PII rather than ordinary personal data.

Why this answer

Sensitive PII is defined as personally identifiable information that, if disclosed, could cause harm or enable identity theft, and it typically includes data elements like Social Security Numbers, financial account numbers, and medical records. A Social Security Number is the canonical example because it is a unique government-issued identifier that can be used to open credit lines, file fraudulent tax returns, or impersonate the individual. Email addresses, phone numbers, and names are generally classified as non-sensitive PII because they are often publicly available and cannot alone be used to commit identity theft.

Exam trap

The trap here is that candidates confuse 'PII' with 'Sensitive PII' — all four options are PII, but only the Social Security Number rises to the sensitive classification because of its potential for identity theft and financial harm.

How to eliminate wrong answers

Option A is wrong because an email address is considered non-sensitive PII — it is routinely shared publicly and, by itself, cannot be used to impersonate someone or access financial accounts. Option C is wrong because a phone number is also non-sensitive PII; it is listed in public directories and does not uniquely authenticate an individual for financial or legal purposes. Option D is wrong because a name alone is non-sensitive PII — names are public information and only become sensitive when combined with other identifiers like an SSN or driver's license number.

563
Multi-Selectmedium

A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?

Select 2 answers
A.Fencing around the property
B.Lighting in parking lots
C.Biometric reader on server room door
D.Cable locks on laptops
E.Chassis locks on servers
AnswersA, B

Fencing establishes a physical barrier at the property boundary, delaying or deterring intruders before they reach the building. It satisfies the external perimeter constraint by providing the outermost layer of physical protection, which lighting and interior controls then reinforce.

Why this answer

Fencing around the property (A) is a correct answer because it is a perimeter-layer physical control that establishes a physical boundary and delays or deters intruders before they reach the facility. Lighting in parking lots (B) is also correct because exterior lighting is a classic layered perimeter control that deters intruders, removes concealment, and supports CCTV or guard surveillance. Together, fencing and lighting represent complementary external perimeter defenses that support defense in depth.

The unmarked options do not belong because a biometric reader on a server room door (C) is an interior access control for a specific high-security room, not an external perimeter measure, while cable locks on laptops (D) and chassis locks on servers (E) are asset-level physical controls that protect individual devices rather than the external perimeter.

Exam trap

CC often tests whether candidates can distinguish between external perimeter controls and internal or endpoint controls, so the trap is selecting an internal control (like biometric readers) as an external perimeter measure.

564
MCQmedium

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

A.Integrity
B.Confidentiality
C.Availability
D.Authentication
AnswerB

Encryption such as TLS renders intercepted traffic unreadable to eavesdroppers, directly enforcing confidentiality. This principle guarantees data is disclosed only to authorised parties, matching the requirement that transmitted data cannot be read by unauthorised parties.

Why this answer

Confidentiality ensures that data is accessible only to authorized parties and is not disclosed to unauthorized individuals. Encrypting data in transit between two servers directly addresses confidentiality by rendering the data unreadable to eavesdroppers. This is the core goal of protocols like TLS, IPsec, and SSH, which the analyst would likely implement to satisfy this requirement.

Exam trap

The trap here is that candidates see 'cannot be read' and may overthink it, but the question is a straightforward mapping to the Confidentiality principle — the distractor 'Integrity' tempts those who confuse 'cannot be read' with 'cannot be modified.'

How to eliminate wrong answers

Option A is wrong because integrity ensures data has not been altered or tampered with — it is addressed by hashing and digital signatures, not by preventing unauthorized reading. Option C is wrong because availability ensures systems and data are accessible when needed — it is addressed by redundancy, backups, and DDoS mitigation, not by encryption of transmitted data. Option D is wrong because authentication verifies the identity of a user or system — it is a prerequisite for access control but does not by itself prevent an eavesdropper from reading intercepted traffic.

565
MCQmedium

A user reports that they are unable to access a shared network drive that they previously could access. The administrator checks permissions and finds the user's account is still a member of the correct group. What should the administrator check next?

A.Group membership inheritance
B.User account lockout status
C.Check for explicit deny permissions on the folder
D.Effective permissions
AnswerC

Explicit deny permissions override inherited group membership in NTFS access control. Since the user remains in the correct group, an explicit deny on the folder or file is the likely cause blocking access despite otherwise valid permissions.

Why this answer

Since the user's group membership is correct, the next thing to check is whether an explicit deny permission has been applied to the folder. Explicit deny entries in NTFS (or equivalent ACLs) override inherited allow permissions, so even though the user is in the correct group, a deny ACE on the folder or a parent could block access. Checking for explicit deny is the logical next diagnostic step.

Exam trap

The trap is assuming that correct group membership guarantees access — candidates must remember that explicit deny ACEs override inherited and group-based allow permissions, making deny the critical thing to check.

How to eliminate wrong answers

Option A is wrong because group membership inheritance is already implied to be correct — the user is a member of the correct group, and inheritance issues would typically manifest as missing allow permissions, which is less likely given the group is correct. Option B is wrong because account lockout would prevent all access, not just access to a specific shared drive, and the user reportedly can log in. Option D is wrong because 'effective permissions' is a tool/result, not a diagnostic step — checking effective permissions would reveal the deny, but the question asks what to check next, and the explicit deny is the specific cause to look for.

566
MCQhard

An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?

A.Administrative access control
B.Logical access control
C.Compensating control
D.Physical access control
AnswerB

Account lockout is enforced through Group Policy settings processed by the domain controller, restricting access via software configuration rather than physical barriers. This makes it a logical access control, satisfying the scenario's requirement to limit system entry after repeated failed authentication attempts.

Why this answer

Logical access controls are software-based mechanisms that govern access to systems. Account lockout policies are logical controls.

567
Multi-Selectmedium

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Select 3 answers
A.Web server
B.DHCP server
C.Mail server
D.Database server
E.DNS server
AnswersA, C, E

A web server must accept HTTP and HTTPS requests from untrusted internet clients, so it belongs in the DMZ. Hosting it there prevents direct external access to the internal network, satisfying the design constraint of segregating publicly reachable services.

Why this answer

Public-facing servers like web, mail, and DNS servers are typically placed in a DMZ to isolate them from the internal network. DHCP servers are usually internal, and database servers are kept internal for security.

568
Multi-Selectmedium

Which TWO are best practices for managing backup media?

Select 2 answers
A.Encrypt backup data
B.Keep backups on the same server for easy access
C.Store backups in a separate physical location
D.Use only tape media
E.Test backups annually
AnswersA, C

Encrypting backup data protects the confidentiality of information at rest on removable media, which is the specific control needed when tapes or drives leave a secured data centre. It satisfies the stem's media-handling constraint by ensuring that theft or loss of physical media does not expose the backed-up contents.

Why this answer

Option A (Encrypt backup data) is correct because backups contain sensitive data at rest, and encryption protects confidentiality if media is lost, stolen, or accessed by unauthorized parties, satisfying compliance and security best practices. Option C (Store backups in a separate physical location) is correct because offsite storage ensures survivability against site-wide disasters such as fire, flood, or theft, enabling recovery even if the primary site is destroyed. Option B is wrong because keeping backups only on the same server leaves them vulnerable to the same failure, ransomware, or disaster that affects the production system.

Option D is wrong because best practice is a tiered or diversified media strategy (disk, tape, cloud) based on RPO/RTO and cost, not reliance on a single media type. Option E is wrong because backups should be tested regularly — ideally after each backup cycle or at least quarterly — not just annually, since untested backups may be unusable when needed.

Exam trap

ISC2 often tests the 3-2-1 backup rule (three copies, two different media, one offsite) to trick candidates into thinking that keeping backups on the same server is acceptable for convenience, when it actually violates the core principle of redundancy.

569
MCQmedium

A hospital's security team wants to give remote clinicians access to internal patient systems without exposing those systems directly to the internet. The team requires strong encryption, per-user authentication, and the ability to log every session. Which solution best fits these requirements?

A.A remote desktop gateway that publishes the internal applications over HTTPS
B.A site-to-site IPsec tunnel between the hospital and each clinician's home router
C.A remote access VPN terminating on a VPN concentrator with user authentication and session logging
D.Publishing the patient systems through a reverse proxy with TLS
AnswerC

A remote access VPN encrypts traffic from the clinician's device to the concentrator, authenticates each user, and can log session start, stop, and assigned addresses. It keeps internal patient systems off the public internet while granting authenticated users access, matching every requirement in the scenario.

Why this answer

A remote access VPN provides the encrypted tunnel, individual user authentication, and auditable session records that the hospital requires, while keeping internal systems unreachable from the public internet. It scales to a distributed clinical workforce far better than fixed site-to-site links and gives the security team the visibility it needs.

Exam trap

The trap here is treating any TLS-protected path to an internal application as equivalent to a per-user encrypted tunnel, when only the VPN delivers authenticated, loggable network access for roaming users.

570
MCQeasy

A security team configures a system to record all user activities for audit purposes. Which principle is being applied?

A.Accountability
B.Integrity
C.Authentication
D.Confidentiality
AnswerA

Recording all user activities creates an auditable trail linking each action to a specific identity, which is precisely what accountability requires: users can be held responsible for their actions because their activity is attributable and traceable.

Why this answer

Accountability is the principle that ensures individuals can be held responsible for their actions. Recording all user activities for audit purposes creates a traceable record that can be used to attribute actions to specific users, thereby enforcing accountability. This is a core objective of audit logging.

Exam trap

CC often tests the confusion between accountability and authentication, where candidates think logging is about verifying identity rather than attributing actions to identities.

How to eliminate wrong answers

Option B is wrong because integrity ensures data is accurate and unaltered, which is supported by logging but not the primary principle being applied. Option C is wrong because authentication verifies identity, which is a prerequisite for accountability but not the same concept. Option D is wrong because confidentiality protects data from unauthorized disclosure, which is unrelated to recording activities for audit.

571
MCQeasy

A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?

A.Authentication
B.Identification
C.Authorization
D.Accounting
AnswerA

Authentication verifies that the claimed identity matches the person presenting the credential. The badge scan supplies a factor that the system validates against the enrolled identity for that nurse, confirming the user is who the username claims. Only after this verification succeeds can the system decide authorization, so the scan is the authentication step in this scenario.

Why this answer

Authentication is the verification of a claimed identity, and the badge scan validates that the nurse is the person associated with the enrolled credential. Identification only asserts who someone claims to be, while authorization decides what that verified identity may do. Because the scenario emphasizes proving identity before opening records, the scan is the authentication step.

Exam trap

The trap here is confusing the act of claiming an identity with the act of proving it, which leads candidates to select identification instead of authentication.

572
MCQmedium

An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?

A.Disable the account in the identity provider, then export the mailbox audit log and sign-in logs to a secure evidence repository.
B.Delete the mailbox and recreate it for the legitimate user, then reset the user's password.
C.Change the user's password and enable self-service password reset so the user can regain access quickly.
D.Add the attacker's IP address to the firewall block list and continue monitoring the mailbox for suspicious activity.
AnswerA

Disabling the account in the identity provider immediately revokes the attacker's ability to authenticate while leaving the mailbox and logs intact for forensic review. Exporting audit and sign-in logs to a secure repository preserves volatile evidence before it ages out or is altered. This combination contains the threat without destroying data needed to determine scope.

Why this answer

The most effective containment combines immediate revocation of access with preservation of forensic data. Disabling the account in the identity provider stops the attacker from authenticating again, while exporting audit and sign-in logs captures evidence before it rotates or is lost. Destructive actions like deleting the mailbox, or partial measures like a password change or IP block, either harm the investigation or fail to reliably stop the attacker.

Exam trap

The trap here is assuming that changing the user's password immediately terminates all active sessions and tokens, when many identity platforms allow existing sessions to persist until explicitly revoked.

573
Multi-Selectmedium

A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?

Select 1 answer
A.Separation of duties; risk of fraud
B.Defense in depth; risk of single point of failure
C.Need-to-know; risk of data exposure
D.Least privilege; risk of excessive permissions
E.Privileged access management; risk of account compromise
AnswersA

One employee both initiating and approving payments removes the independent check, letting fraudulent transactions pass unchallenged. Separation of duties requires these functions be split across different people, so the violation creates a direct fraud risk.

Why this answer

Separation of duties requires that critical tasks be split among multiple people so no single individual can complete a sensitive transaction end-to-end. Here, one employee can both initiate and approve a payment, violating that principle and creating a direct fraud risk since they could authorize unauthorized payments. This is a classic internal-controls failure in financial environments.

Exam trap

CC often tests the confusion between separation of duties and least privilege — both limit user power, but SoD is about splitting a workflow across people, while least privilege is about minimizing each person's permissions.

574
Multi-Selectmedium

A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)

Select 2 answers
A.Security guard at entrance
B.Smart card authentication for system access
C.Bollards at parking lot
D.Password policy enforcing complexity
E.Perimeter fence
AnswersB, D

Smart card authentication is a logical access control because it governs access through technical means — credentials and certificates validated by a system — rather than physical barriers. It satisfies the stem's requirement by restricting system access based on logical identity verification.

Why this answer

B is correct because smart card authentication is a logical (technical) access control that uses a credential and cryptographic verification to grant or deny access to systems and data. D is correct because a password policy enforcing complexity is a logical control that governs how users authenticate electronically, restricting access through technical rules. A is not correct because a security guard is a physical access control (personnel-based).

C is not correct because bollards are physical barriers used to control vehicle access. E is not correct because a perimeter fence is a physical access control.

Exam trap

CC often tests the physical-vs-logical distinction by including obvious physical controls (guards, fences, bollards) alongside subtle logical ones (smart cards, password policies) to see if candidates can classify correctly.

575
MCQeasy

Which of the following is an example of a detective control?

A.Security awareness training
B.Firewall
C.Encryption
D.Intrusion Detection System (IDS)
AnswerD

An Intrusion Detection System monitors network or host activity and raises alerts when it identifies malicious patterns. It detects and reports events after they occur rather than blocking them, which is precisely what defines a detective control.

Why this answer

A detective control is designed to identify and detect security incidents or violations after they occur. An Intrusion Detection System (IDS) monitors network traffic and system activities to identify malicious activities or policy violations, making it a classic example of a detective control. It alerts administrators to potential threats, allowing them to respond.

Exam trap

The trap is confusing detective controls with preventive controls. Candidates might think a firewall is detective because it logs traffic, but its primary function is prevention. Similarly, encryption is preventive, not detective.

The key is to focus on the primary purpose: detection after the fact.

How to eliminate wrong answers

Option A is wrong because security awareness training is a preventive control, as it aims to educate users to prevent incidents from happening. Option B is wrong because a firewall is a preventive control that blocks unauthorized access. Option C is wrong because encryption is a preventive control that protects data confidentiality by making it unreadable to unauthorized parties.

576
MCQmedium

An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?

A.A strict perimeter firewall without internal controls.
B.Encryption at rest only.
C.A firewall, intrusion detection system, and regular security awareness training.
D.A single strong password policy.
AnswerC

Layering a network perimeter control, a detection mechanism, and a human-focused control spans preventive, detective, and administrative domains. This diversity means no single failure exposes the application, which is precisely the layered redundancy defence in depth requires.

Why this answer

Defense in depth involves multiple layers of security controls so that if one fails, others still protect the asset. A firewall, IDS, and security awareness training represent network, host, and human layers, respectively, illustrating the principle.

Exam trap

CC often tests the confusion between a single strong control and multiple layered controls; candidates must recognize that defense in depth requires diversity of controls across layers.

How to eliminate wrong answers

Option A is wrong because a strict perimeter firewall alone is a single layer, not defense in depth. Option B is wrong because encryption at rest only protects data at rest, not other layers like network or human. Option D is wrong because a single strong password policy is one control, not multiple layers.

577
MCQhard

A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?

A.Separation of duties
B.Availability
C.Least privilege
D.Non-repudiation
AnswerC

Least privilege grants users only the access needed for their duties. Viewing confidential records unrelated to the job exceeds that granted scope, so the principle was breached. The employee's permissions were broader than the role required, enabling inappropriate access.

Why this answer

Least privilege means users should have only the minimum access necessary to perform their job. Viewing confidential records unrelated to their job violates this principle because the user had access beyond what was required.

Exam trap

CC often tests the confusion between least privilege and separation of duties; candidates must distinguish between access rights (least privilege) and task division (separation of duties).

How to eliminate wrong answers

Option A is wrong because separation of duties involves dividing tasks among different people to prevent fraud, not about accessing unrelated records. Option B is wrong because availability ensures data is accessible when needed, not about unauthorized access. Option D is wrong because non-repudiation ensures actions cannot be denied, not about access rights.

578
MCQeasy

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

A.Data encryption
B.Biometric authentication
C.Digital signatures
D.Redundant servers
AnswerD

Redundant servers directly sustain availability by eliminating single points of failure: if one server fails, others continue serving requests, so the service remains accessible. This satisfies the stem's availability constraint through hardware duplication, unlike logical controls such as backups or access policies, which address integrity or confidentiality instead.

Why this answer

Availability ensures systems are accessible when needed. Redundant servers provide failover capability, minimizing downtime.

579
MCQhard

An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?

A.Controls and monitors privileged access
B.Provides a single sign-on for all users
C.Eliminates the need for passwords
D.Automates user provisioning for all accounts
AnswerA

PAM brokers privileged accounts through vaulting, session isolation and credential checkout, so administrative actions are both restricted and recorded. This controls and monitors privileged access, satisfying the stem's requirement for a primary benefit rather than general authentication or endpoint protection.

Why this answer

PAM solutions are designed to secure, control, and monitor privileged accounts — the accounts with elevated access such as root, domain admin, and service accounts. Core PAM capabilities include credential vaulting, session recording, just-in-time access, and approval workflows for privileged actions. The primary benefit is therefore controlling and monitoring privileged access to reduce the risk of misuse or compromise.

Exam trap

CC often tests the confusion between PAM and IGA/SSO — candidates pick 'automates user provisioning' or 'single sign-on' because those sound like identity benefits, but PAM is specifically about privileged account control and monitoring.

How to eliminate wrong answers

Option B is wrong because single sign-on (SSO) is a separate identity feature that improves user convenience across applications; PAM may integrate with SSO but SSO is not its primary benefit. Option C is wrong because PAM does not eliminate passwords — it typically vaults, rotates, and manages them, and may add passwordless or certificate-based access for privileged users, but password elimination is not its defining benefit. Option D is wrong because automated user provisioning is the domain of Identity Governance and Administration (IGA) or Identity Lifecycle Management tools, not PAM, which focuses on privileged accounts rather than all accounts.

580
MCQeasy

A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?

A.Authentication
B.Authorization
C.Accounting
D.Identification
AnswerA

Authentication is the process of verifying that a subject's claimed identity is genuine, typically by validating something the subject knows, has, or is. Entering a username and password and having the directory confirm them is the classic example of authentication. The system is proving the employee is who they claim to be before any access decision is made.

Why this answer

When a user supplies a username and password and the system validates them against stored credentials, the system is verifying the claimed identity. That verification step is authentication. Identification alone is just the claim of an identity, and authorization and accounting happen after authentication succeeds, so authentication is the concept being exercised here.

Exam trap

The trap here is treating the username as the whole event and choosing identification, when the presence of a validated password makes the process authentication.

581
MCQmedium

A medium-sized company uses a SIEM solution to collect logs from firewalls, servers, and endpoints. The security team receives an alert indicating a possible data exfiltration: an employee's workstation is sending large amounts of data to an external IP address outside business hours. The employee works in the finance department and has access to sensitive financial records. The SIEM shows the connection is ongoing. The security team must respond immediately to contain the incident while preserving evidence. The company's incident response plan designates the security team as first responders. Which of the following is the BEST first action?

A.Block the external IP address at the firewall and disconnect the workstation from the network.
B.Notify the employee's manager and wait for further instructions.
C.Call the employee to ask if they are transferring files for a legitimate business purpose.
D.Take a forensic image of the workstation's hard drive before anything else.
AnswerA

Blocking the external IP at the firewall and isolating the workstation halts ongoing exfiltration immediately, satisfying the containment requirement. The workstation remains intact and unpowered-off, preserving volatile memory and forensic artefacts for later evidence collection.

Why this answer

The best first action because it immediately stops the ongoing data exfiltration and isolates the system, containing the incident and preserving evidence. Option B delays containment, Option C may alert a potential insider threat, and Option D should be performed after containment to avoid further data loss.

Exam trap

The trap is mistaking delayed containment for a better approach. Immediate isolation (Option A) is prioritized over investigation or notification to prevent further data loss.

582
MCQmedium

Which of the following is the most effective way to prevent tailgating in a secured facility?

A.Training employees to not hold doors open for unknown individuals.
B.Installing security cameras at all entrances.
C.Using keycard access for all doors.
D.Hiring security guards to monitor entrances.
AnswerA

Tailgating exploits social courtesy, so training employees to challenge or refuse entry to unfamiliar individuals removes the human behaviour attackers rely on. This directly addresses the unauthorised-follow-in vector, which locks and turnstiles alone cannot prevent.

Why this answer

Tailgating exploits social trust — an attacker follows an authorized person through a door. Training employees to challenge and not hold doors for unknown individuals directly addresses the human behavior that enables tailgating, making it the most effective preventive control. Technical controls alone cannot stop a person who is willingly allowed through.

Exam trap

The trap is choosing a technical control (cameras, keycards, guards) when the question asks for the 'most effective' prevention of a human-behavior attack — CC exams emphasize that training addresses the root cause.

How to eliminate wrong answers

Option B is wrong because cameras are detective, not preventive — they record the event but do not stop the tailgater, and footage is reviewed after the fact. Option C is wrong because keycard access controls who can open a door but does nothing to stop a second person from walking through behind an authorized user. Option D is wrong because security guards are effective only if they are physically positioned at every entrance and actively challenge people, which is costly and inconsistent; training scales better and addresses the root cause.

583
MCQmedium

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

A.The server is being used for remote desktop access
B.The server is performing a port scan
C.The server is a legitimate mail server
D.The server is infected with malware
AnswerD

Repeated outbound connections to external IPs on a non-standard port indicate beaconing or command-and-control traffic, characteristic of malware on the internal server. The stem's pattern of repeated attempts, rather than a single connection, distinguishes malicious callback behaviour from legitimate application traffic.

Why this answer

Repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port are a classic indicator of malware command-and-control (C2) activity. Malware often uses non-standard ports to evade detection and establish outbound communication with an external attacker. This behavior is not typical of legitimate services, which use well-known ports and protocols.

Exam trap

ISC2 often tests the distinction between outbound connection attempts (indicative of malware C2) and inbound connection attempts (indicative of remote access or scanning), leading candidates to mistakenly choose remote desktop or port scanning.

How to eliminate wrong answers

Option A is wrong because remote desktop access (e.g., RDP) uses TCP port 3389 by default, not a non-standard port, and would typically involve inbound connections, not repeated outbound attempts. Option B is wrong because a port scan involves sending packets to multiple ports on a target to discover open services, not repeated outbound connection attempts from a single server to external IPs on a single non-standard port. Option C is wrong because a legitimate mail server uses standard ports such as TCP 25 (SMTP), 587 (submission), or 993 (IMAPS), and would not repeatedly connect to arbitrary external IPs on a non-standard port.

584
MCQeasy

Which OSI layer is responsible for routing packets based on IP addresses?

A.Layer 3 – Network
B.Layer 1 – Physical
C.Layer 4 – Transport
D.Layer 2 – Data Link
AnswerA

Layer 3, the network layer, handles logical addressing and path selection, forwarding packets between networks according to IP addresses. This satisfies the stem's requirement by naming the layer whose protocol data unit is the packet and whose function is routing.

Why this answer

Layer 3, the Network layer, is responsible for logical addressing and routing packets based on IP addresses. It determines the best path across interconnected networks using routing protocols and forwarding tables.

Exam trap

The trap is confusing Layer 2 MAC-based switching with Layer 3 IP-based routing; the mention of IP addresses specifically points to Layer 3.

How to eliminate wrong answers

Option B is wrong because Layer 1 (Physical) deals with transmission of raw bits over media, not IP addressing. Option C is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and reliability (TCP/UDP), not routing based on IP. Option D is wrong because Layer 2 (Data Link) uses MAC addresses for node-to-node delivery within a local network, not IP-based routing.

585
Multi-Selectmedium

Which of the following are core principles of information security?

Select 3 answers
A.Authentication
B.Integrity
C.Confidentiality
D.Non-repudiation
E.Availability
AnswersB, C, E

Integrity ensures data remains accurate and unaltered unless changed by authorised processes, directly satisfying the core principles of information security alongside confidentiality and availability. It guards against unauthorised modification, whether accidental or malicious, making it a foundational pillar of the CIA triad that the question asks you to identify.

Why this answer

The CIA triad is the foundational model of information security, and its three core principles are Confidentiality, Integrity, and Availability. Option C (Confidentiality) is correct because it ensures data is disclosed only to authorized parties, typically enforced through encryption, access controls, and classification. Option B (Integrity) is correct because it guarantees data remains accurate, complete, and unaltered, protected via hashing, checksums, and digital signatures.

Option E (Availability) is correct because it ensures systems and data are accessible to authorized users when needed, supported by redundancy, backups, and DDoS mitigation. Options A (Authentication) and D (Non-repudiation) are not core principles of the CIA triad; authentication is an access-control mechanism that verifies identity, and non-repudiation is a security service that prevents denial of an action, often achieved with digital signatures.

Exam trap

ISC2 often tests whether candidates can distinguish between core principles (CIA triad) and supporting security services (authentication, non-repudiation), leading many to incorrectly select authentication or non-repudiation as core principles instead of availability.

586
MCQmedium

A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?

A.ICMP flood
B.UDP flood
C.Smurf attack
D.SYN flood
AnswerD

A SYN flood exploits the TCP three-way handshake by sending numerous SYN segments without completing the final ACK, exhausting the server's half-open connection table. This matches the stem's observation of many incomplete TCP connection requests.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending numerous SYN packets with spoofed source addresses, leaving the server with half-open connections that exhaust its backlog queue. The server responds with SYN-ACK to unreachable hosts and waits for the final ACK that never arrives, consuming resources until legitimate connections are refused. This matches the scenario of many incomplete TCP connection requests.

Exam trap

The trap here is confusing volumetric floods (ICMP/UDP) with protocol-level exhaustion attacks; candidates may pick 'ICMP flood' simply because it is a flood, missing that the question specifies incomplete TCP connection requests (SYN segments).

How to eliminate wrong answers

Option A is wrong because an ICMP flood sends large volumes of ICMP Echo Request packets (e.g., ping flood) to overwhelm bandwidth, not incomplete TCP handshakes. Option B is wrong because a UDP flood targets connectionless UDP services with high packet volume, and UDP has no handshake or SYN segments. Option C is wrong because a Smurf attack uses ICMP Echo Requests with a spoofed source address sent to a network's broadcast address, amplifying traffic to the victim, not TCP SYN segments.

587
MCQeasy

Which process involves verifying the identity of a user who claims to be a specific person?

A.Authorization
B.Authentication
C.Identification
D.Accounting
AnswerB

Authentication verifies a claimed identity by validating credentials such as passwords, tokens or biometrics against stored data. This directly satisfies the stem's requirement, distinguishing it from authorisation, which determines what an already-identified user may access.

Why this answer

Authentication is the process of verifying that a user's claimed identity is genuine, typically by validating credentials such as a password, token, or biometric factor against stored data. It answers the question 'Are you really who you say you are?' and occurs after identification but before authorization. This is the core definition tested in the CIA triad's access control model.

Exam trap

The trap here is confusing authentication with identification or authorization — candidates often pick 'identification' because both involve a user claiming an identity, but only authentication actually verifies it.

How to eliminate wrong answers

Option A is wrong because authorization determines what resources an authenticated user may access, not who they are. Option C is wrong because identification is merely the act of claiming an identity (e.g., entering a username), which precedes and does not verify authentication. Option D is wrong because accounting (auditing) tracks and logs user activity for accountability, not identity verification.

588
MCQeasy

Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?

A.Least privilege
B.Need-to-know
C.Separation of duties
D.Defense in depth
AnswerA

Least privilege restricts user access rights to the minimum set of permissions required to complete assigned job functions, directly satisfying the stem’s requirement to reduce the impact of a compromised account. By enforcing granular permission boundaries—such as read-only access to specific Microsoft Entra ID resources rather than full administrative roles—this principle limits lateral movement and data exposure if credentials are stolen.

Why this answer

Least privilege is the principle that users, processes, and systems should be granted only the minimum access rights required to perform their legitimate tasks, and no more. This limits the blast radius if an account is compromised, because the attacker inherits only the narrow permissions of that account. It is a foundational concept in access control and is explicitly required by standards like NIST SP 800-53 (AC-6).

Exam trap

The trap is conflating least privilege with need-to-know — both restrict access, but least privilege governs permissions/rights while need-to-know governs data classification access.

How to eliminate wrong answers

Option B is wrong because need-to-know is about restricting access to specific information based on job relevance, which is a subset of least privilege focused on data rather than permissions. Option C is wrong because separation of duties splits critical tasks among multiple people to prevent fraud, not to minimize individual permissions. Option D is wrong because defense in depth is a layered security strategy, not a permission-minimization principle.

589
MCQeasy

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

A.Phishing
B.DDoS attack
C.Man-in-the-middle
D.Insider threat
AnswerB

A DDoS attack floods a target with traffic from many distributed sources, exhausting bandwidth or connection tables so legitimate users cannot connect. The log's high-volume, multi-source pattern matches this volumetric signature, satisfying the scenario's requirement to identify an availability-focused attack rather than a credential or injection attempt.

Why this answer

The log snippet shows a massive volume of incoming traffic from multiple source IPs targeting a single destination, which is characteristic of a distributed denial-of-service (DDoS) attack. The high packet rate and diverse source addresses indicate an attempt to overwhelm the target's resources, such as bandwidth or server capacity, making services unavailable to legitimate users.

Exam trap

ISC2 often tests the distinction between DDoS and DoS by including logs with multiple source IPs, where candidates might mistakenly focus on the high traffic volume alone and overlook the distributed nature, leading them to choose a generic 'DoS' or another attack type.

How to eliminate wrong answers

Option A is wrong because phishing involves deceptive messages (e.g., emails) to trick users into revealing credentials or installing malware, not a flood of network traffic from many sources. Option C is wrong because a man-in-the-middle attack intercepts and potentially alters communications between two parties, which would show unusual traffic patterns or certificate anomalies, not a high-volume flood from multiple IPs. Option D is wrong because an insider threat originates from within the organization, typically involving unauthorized access or data exfiltration, not a distributed traffic flood from external sources.

590
MCQeasy

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

A.Phishing
B.Tailgating
C.USB drop attack
D.Piggybacking
AnswerA

The message impersonates the IT department and pressures the recipient to disclose credentials urgently, which is phishing: fraudulent email harvesting sensitive data. It satisfies the stem's description, distinguishing it from vishing or pretexting conducted by other channels.

Why this answer

Phishing is a social engineering attack where an attacker sends a fraudulent email, often impersonating a trusted entity like the IT department, to trick the recipient into revealing sensitive information such as passwords. The scenario describes an email from an unknown sender claiming to be from IT and requesting a password, which is a classic phishing attempt. The other options involve physical or direct access tactics.

Exam trap

The trap is confusing phishing with other social engineering methods like tailgating or USB drops; candidates may pick tailgating if they focus on 'unknown sender' but miss that the attack vector is email.

How to eliminate wrong answers

Option B is wrong because tailgating involves an unauthorized person following an authorized individual into a secure physical area, not an email-based attack. Option C is wrong because a USB drop attack relies on leaving infected USB drives for victims to plug in, not email deception. Option D is wrong because piggybacking is similar to tailgating, where someone gains physical access by following an authorized person, often with their consent, but still not an email attack.

591
Multi-Selectmedium

A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)

Select 2 answers
A.Calculating the annualized loss expectancy
B.Accepting the risk and documenting the decision
C.Identifying a vulnerability in a web application
D.Monitoring network traffic for anomalies
E.Transferring risk by purchasing cyber insurance
AnswersB, E

Risk acceptance is a deliberate treatment choice where the organization decides the potential loss is tolerable and documents that decision. It is one of the standard risk treatment options, along with avoidance, mitigation, and transfer. Therefore, accepting and documenting the risk is a correct example.

Why this answer

Risk treatment options include avoiding, mitigating, transferring, and accepting risk. Purchasing cyber insurance transfers financial risk to an insurer, while accepting and documenting risk is a conscious decision to tolerate it. Identifying vulnerabilities and calculating loss expectancy are assessment activities, and monitoring traffic is a control, so they are not treatment options themselves.

Exam trap

The trap here is treating risk analysis activities, such as calculating loss expectancy, as if they were risk treatment decisions.

592
MCQmedium

Which protocol is considered insecure because it transmits data, including credentials, in cleartext?

A.SFTP
B.SSH
C.Telnet
D.HTTPS
AnswerC

Telnet transmits all session data, including usernames and passwords, as unencrypted cleartext, so anyone capturing traffic on the network can read credentials directly. This satisfies the stem's constraint of a protocol insecure specifically because it sends credentials in cleartext, unlike SSH, which encrypts the entire session.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext over the network, making it trivial to intercept with packet sniffing. It lacks encryption and is considered insecure for any authentication or sensitive data. This is why Telnet has been replaced by SSH for remote administration.

Exam trap

The trap here is confusing similarly named protocols — candidates may pick SFTP or SSH assuming they are insecure because they sound like FTP, when in fact Telnet is the only cleartext option listed.

How to eliminate wrong answers

Option A is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts data and credentials in transit. Option B is wrong because SSH provides strong encryption and is the secure replacement for Telnet. Option D is wrong because HTTPS uses TLS to encrypt HTTP traffic, protecting credentials and data in transit.

593
MCQhard

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

A.Confidential
B.Restricted/Top Secret
C.Internal/Private
D.Public
AnswerA

Encryption at rest and in transit is the prescribed handling control for the Confidential classification, matching the stem's stated requirement exactly. Confidential data demands the strongest protective measures, whereas lower tiers such as Public or Internal do not mandate encryption in both states.

Why this answer

Confidential data typically requires strong protection like encryption; restricted/top secret may require even higher controls.

594
Matchingmedium

Match each phase of the incident response process to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Train and equip the team

Identify and scope the incident

Stop the spread and restore systems

Lessons learned and reporting

Why these pairings

The NIST SP 800-61 incident response process includes Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Options A, B, and C are correct; D and E swap definitions between the last two phases.

595
Multi-Selecthard

In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)

Select 2 answers
A.Hard drive contents
B.Network connections
C.Backup tapes
D.System logs
E.Memory contents
AnswersB, E

Network connections exist only in running memory and vanish on shutdown or reboot, so they must be captured before disk imaging. Collecting them first preserves evidence of active command-and-control, lateral movement and exfiltration that the stem's volatile-data ordering demands.

Why this answer

Option B (Network connections) is correct because active connections, ARP caches, routing tables, and open sockets reside only in memory and kernel state and are lost on shutdown or reboot, making them highly volatile and requiring immediate capture with tools like netstat, ss, or netflow. Option E (Memory contents) is correct because RAM holds running processes, encryption keys, injected code, and uncommitted data that vanish when power is removed, so it must be acquired first using a memory imager such as FTK Imager or WinPmem. Option A (Hard drive contents) is not the most volatile since disk data persists across reboots and is collected later in the order of volatility.

Option C (Backup tapes) is non-volatile offline media that retains data indefinitely and is not time-sensitive. Option D (System logs) may be stored on disk and, while useful, are less volatile than live network state and RAM, so they are not among the first two to collect.

Exam trap

ISC2 often tests the distinction between volatile and non-volatile data, and the trap here is that candidates mistakenly classify system logs as volatile because they change frequently, but logs are stored on disk and are not lost on power-off, whereas network connections and memory are lost immediately.

596
MCQmedium

An account lockout policy is designed to mitigate which type of attack?

A.SQL injection
B.Man-in-the-middle
C.Phishing
D.Brute force
AnswerD

Brute force attacks repeatedly submit password guesses until one succeeds. Locking the account after five failures within 15 minutes halts that iterative guessing, because further attempts are refused regardless of correctness, directly mitigating the attack's core mechanism.

Why this answer

An account lockout policy locks a user account after a specified number of failed login attempts, which mitigates brute force attacks by preventing attackers from making unlimited password guesses. Brute force attacks rely on trying many combinations; lockout stops this after a few attempts.

Exam trap

CC often tests the purpose of account lockout, and candidates might confuse it with mitigating phishing or other attacks, but the primary target is brute force.

How to eliminate wrong answers

Option A is wrong because SQL injection is an attack on database queries, not mitigated by account lockout. Option B is wrong because man-in-the-middle attacks intercept communications, not prevented by account lockout. Option C is wrong because phishing tricks users into revealing credentials, and account lockout does not prevent phishing; it may even cause denial of service if attackers intentionally lock accounts.

597
Multi-Selectmedium

A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)

Select 2 answers
A.A firewall rule that blocks inbound traffic to the server subnet from the corporate network.
B.A locked cabinet that houses backup tapes and requires a key held by the storage administrator.
C.A mantrap with interlocking doors that admits one authenticated person at a time into the server hall.
D.A badge reader at the server hall door that logs the identity and timestamp of each entry.
E.A privacy filter applied to the administrator's monitor so bystanders cannot read displayed data.
AnswersC, D

A mantrap uses two sets of doors with interlocking controls so that only one authenticated individual can pass at a time, preventing tailgating into the server hall. Combined with authentication, it restricts who enters and can be integrated with logging. This directly addresses the goal of controlling physical entry to the protected space.

Why this answer

Physical access controls govern movement into protected spaces and often produce an audit trail. A badge reader authenticates the person and logs the entry, while a mantrap enforces one-person-at-a-time passage and prevents tailgating. Together they restrict who reaches the servers and create records of when entry occurred.

Firewalls, locked media cabinets, and monitor privacy filters protect other assets or confidentiality but do not control doorway access.

Exam trap

The trap here is counting any physical safeguard, such as a locked cabinet or privacy filter, as an entry control even though it does not restrict or log who enters the server hall.

598
MCQmedium

A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?

A.DNS tunneling for command and control or data exfiltration
B.A cache poisoning attack against the internal DNS resolver
C.A distributed denial-of-service attack using DNS amplification
D.A zone transfer attempt from an internal host
AnswerA

DNS tunneling encodes data in DNS queries and responses, often using long, encoded subdomains to carry payloads. The regular interval and high volume of random-looking subdomains are characteristic of malware using DNS to exfiltrate data or receive commands, since DNS is often allowed through firewalls. This matches the observed pattern.

Why this answer

The high volume of DNS queries with long, random subdomains sent at regular intervals is a classic indicator of DNS tunneling, where data is encoded in DNS queries to bypass network controls. This technique is commonly used for command and control and data exfiltration. Other DNS-based attacks like amplification or cache poisoning do not produce this pattern.

Exam trap

The trap here is assuming that because DNS is a legitimate protocol, any DNS traffic is benign, when the pattern of encoded subdomains and regular timing reveals malicious tunneling.

599
MCQmedium

A company's security policy requires that all outbound web traffic be inspected for malware and that users be prevented from accessing known malicious domains. The security team wants a single appliance that can decrypt TLS sessions, apply content filters, and block threats inline. Which solution best meets these requirements?

A.A stateful packet-filtering firewall
B.A next-generation firewall with TLS inspection and threat prevention
C.A web application firewall (WAF) protecting internal servers
D.A standalone intrusion detection system (IDS)
AnswerB

A next-generation firewall combines stateful filtering with application awareness, TLS decryption, intrusion prevention, and reputation-based URL filtering. It can decrypt outbound TLS, inspect the plaintext for malware, and block known malicious domains inline. This matches the requirement for a single appliance that performs content inspection and threat blocking rather than just port-based filtering.

Why this answer

The policy requires inline inspection of encrypted outbound traffic, content filtering, and malware blocking in one appliance. A next-generation firewall with TLS inspection and threat prevention provides all of these capabilities. Stateful firewalls lack content inspection, IDS is passive, and WAFs focus on inbound application attacks rather than outbound browsing.

Exam trap

The trap here is assuming a traditional firewall or IDS can inspect encrypted traffic, when TLS decryption and inline content filtering require additional capabilities found in a next-generation firewall.

600
Matchingmedium

Match each network security concept to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Filters traffic based on rules

Segments public-facing servers

Maps private to public IPs

Encrypts data over public networks

Monitors for suspicious activity

Why these pairings

The correct matches are: Firewall filters traffic, IDS monitors and alerts, IPS blocks threats, VPN encrypts connections. Common confusions include swapping firewall and IPS functions, or confusing IDS with firewall capabilities.

Page 7

Page 8 of 14

Page 9