Courseiva

ISC2 Certified in Cybersecurity CC (CC) — Questions 601–675

989 questions total · 14pages · All types, answers revealed

Page 8

Page 9 of 14

Page 10
601
MCQmedium

A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?

A.Account recertification
B.Least privilege
C.Separation of duties
D.Access revocation during offboarding
AnswerD

When an employee leaves, all access rights should be revoked as part of offboarding. Disabling the account is not sufficient if permissions remain on resources, because the account could be re-enabled or the permissions could be inherited by another account. The scenario shows that read and write permissions persisted, so the offboarding process failed to remove access properly.

Why this answer

Offboarding should include disabling the account and removing or transferring all associated permissions. The scenario shows that the account was disabled but its read and write permissions on the file server remained, indicating that access revocation was incomplete. Least privilege, separation of duties, and account recertification are valuable controls, but they do not directly describe the failure to strip permissions when the employee departed.

Exam trap

The trap here is assuming that disabling an account automatically removes its permissions, when in fact permissions often persist and must be explicitly revoked.

602
Multi-Selecthard

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

Select 3 answers
A.Using HTTP instead of HTTPS
B.Educating users to verify certificates
C.Disabling ARP
D.Implementing HTTPS with proper certificate validation
E.Using a VPN to encrypt all traffic
AnswersB, D, E

User education to verify certificates counters MitM interception by prompting rejection of forged or unexpected certificates before credentials are submitted. This satisfies the scenario's need for a defence against credential interception, complementing technical controls. However, it relies on human vigilance, so pairing with certificate pinning or Microsoft Entra ID token protections strengthens the overall posture.

Why this answer

Option B is correct because user education to verify certificates helps detect MITM attacks where an attacker presents a forged or self-signed certificate, prompting users to check the certificate's issuer, validity, and hostname match before trusting a connection. Option D is correct because HTTPS with proper certificate validation uses TLS to authenticate the server and encrypt traffic, and validating the certificate chain against trusted CAs prevents an attacker from impersonating the server with a fraudulent certificate. Option E is correct because a VPN encrypts all traffic between the client and the VPN gateway using protocols such as IPsec or TLS, which prevents an on-path attacker from reading or modifying the traffic and can authenticate the tunnel endpoints.

Option A is not correct because HTTP is unencrypted and provides no authentication, making MITM attacks easier, not harder. Option C is not correct because disabling ARP is not a practical or effective defense; ARP is required for normal IPv4 LAN communication, and the proper mitigation for ARP spoofing is dynamic ARP inspection or static ARP entries, not disabling ARP entirely.

Exam trap

The trap here is that candidates might think disabling ARP (Option C) is a valid defense against ARP-based MITM attacks, but it's not a practical solution; also, they might overlook user education as a defense, focusing only on technical controls.

603
Multi-Selectmedium

Which TWO of the following are components of the identification and authentication process? (Select TWO.)

Select 2 answers
A.Password
B.Username
C.Group policy
D.Access control list (ACL)
E.Role-based access control (RBAC)
AnswersA, B

A password is the credential a subject supplies to prove claimed identity, making it the authentication component of the process. Identification occurs when the user presents a username or similar identifier, which the password then verifies against stored data.

Why this answer

The identification and authentication process consists of two distinct steps: identification, where a subject claims an identity, and authentication, where that claim is verified. Option B (Username) is correct because the username is the identifier — the claim of identity presented during the identification step. Option A (Password) is correct because the password is the authenticator — the secret credential verified against the stored value during the authentication step.

Option C (Group policy) is incorrect because it is a management mechanism for enforcing configuration and security settings, not a component of identification or authentication. Option D (Access control list, ACL) is incorrect because an ACL is an authorization mechanism that specifies which subjects may access which objects, operating after authentication completes. Option E (Role-based access control, RBAC) is incorrect because RBAC is an authorization model that grants permissions based on roles, not part of proving identity.

Exam trap

CC often tests the confusion between authentication components (username/password) and authorization mechanisms (ACL, RBAC, group policy), causing candidates to select authorization tools as authentication components.

604
MCQmedium

A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?

A.The file share permissions were not updated to remove the former employee's access.
B.The account was not disabled in the directory service after termination.
C.The file share was configured to allow anonymous access.
D.The former employee's password was not changed before termination.
AnswerB

If the account was not disabled in the directory service, it remains active and can be used to authenticate and access resources. This directly explains how the former employee's account could access the file share after termination. The most likely explanation is a failure in the account deprovisioning process.

Why this answer

The access logs show the former employee's account was used after termination. The most direct explanation is that the account was not disabled in the directory service, allowing authentication. While file share permissions and password changes are part of offboarding, the failure to disable the account is the root cause that enabled the access.

Exam trap

The trap here is focusing on file share permissions or password changes, while overlooking that an active account is the prerequisite for any authenticated access.

605
Multi-Selecteasy

Which THREE of the following are considered fundamental security principles? (Select three).

Select 3 answers
A.Separation of duties
B.Single sign-on
C.Hashing
D.Least privilege
E.Defense in depth
AnswersA, D, E

Correct. Separation of duties is a key principle to prevent fraud and error.

Why this answer

Separation of duties is a fundamental security principle that prevents any single individual from having excessive control over critical processes by dividing responsibilities among multiple people. This reduces the risk of fraud, error, or abuse, as collusion would be required to bypass controls. It is a core concept in access control models and compliance frameworks like SOX and PCI DSS.

Exam trap

ISC2 often tests the distinction between a security principle (a high-level design guideline) and a security mechanism (a specific tool or technology), so candidates mistakenly select SSO or hashing because they are security-related, but they are not fundamental principles.

606
MCQmedium

An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?

A.IDS
B.WAF
C.Honeypot
D.IPS
AnswerB

A web application firewall inspects HTTP/HTTPS request payloads at layer 7, matching signatures for SQL injection, cross-site scripting and similar attacks. It satisfies the stem's requirement to inspect HTTP traffic for malicious payloads, which a network firewall cannot decode.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block malicious payloads such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attacks. It operates at the application layer (Layer 7) and can enforce custom rules based on HTTP request contents. An IDS or IPS may detect or block some attacks but is not purpose-built for web application protection.

Exam trap

The trap is choosing IDS or IPS because they sound like security devices that inspect traffic; candidates must remember that a WAF is the specialized tool for HTTP application-layer attacks like SQL injection.

How to eliminate wrong answers

Option A is wrong because an IDS (Intrusion Detection System) monitors network traffic for suspicious activity and alerts, but it does not actively inspect and block HTTP payloads like SQL injection; it is passive. Option C is wrong because a honeypot is a decoy system designed to attract attackers and study their behavior, not to protect production web traffic. Option D is wrong because an IPS (Intrusion Prevention System) can block attacks but is typically signature-based at the network layer and less effective at parsing HTTP for application-specific attacks like SQL injection compared to a WAF.

607
MCQeasy

During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?

A.Preserve forensic evidence from the isolated systems.
B.Wipe and rebuild all affected systems.
C.Notify law enforcement immediately.
D.Pay the ransom to restore operations quickly.
AnswerA

Isolation halts propagation but volatile evidence such as memory and running processes degrades quickly. Capturing forensic artefacts from the isolated hosts before remediation preserves the timeline and attacker indicators, satisfying the need to understand the intrusion while preventing further encryption.

Why this answer

After isolating affected systems during a ransomware incident, the next best step is to preserve forensic evidence from those systems. This ensures that data such as memory dumps, logs, and encrypted files are captured intact for analysis, which is critical for understanding the attack vector, identifying the ransomware variant, and potentially recovering data without paying the ransom. Forensic preservation must occur before any remediation steps like wiping or rebuilding, as those actions would destroy the evidence needed for investigation and legal proceedings.

Exam trap

ISC2 often tests the misconception that containment (isolation) is the final step, but the trap here is that candidates skip forensic preservation and jump to remediation (wipe/rebuild) or external actions (law enforcement/payment), failing to recognize that evidence must be secured first to support both investigation and potential recovery.

How to eliminate wrong answers

Option B is wrong because wiping and rebuilding all affected systems destroys forensic evidence and prevents analysis of the ransomware's behavior, encryption keys, or entry point, which is essential for preventing future incidents and potentially recovering data. Option C is wrong because notifying law enforcement immediately is not the next operational step; while it may be required later, the immediate priority is preserving evidence to support any law enforcement investigation, and premature notification without evidence could hinder the response. Option D is wrong because paying the ransom does not guarantee data recovery, encourages further attacks, and violates many organizational policies and legal guidelines; the incident response team should never recommend payment as a first step.

608
MCQmedium

What is the primary purpose of using security baselines derived from CIS Benchmarks?

A.To ensure all systems have the same software versions
B.To monitor network traffic for anomalies
C.To automate patch deployment
D.To establish a secure starting point for system configuration
AnswerD

CIS Benchmarks encode consensus hardening settings, so applying them yields a documented, secure starting configuration rather than a bespoke one. This satisfies the stem's aim of a repeatable baseline against which drift and deviations can be measured and remediated.

Why this answer

CIS Benchmarks provide consensus-based, prescriptive hardening guidance for operating systems, applications, and cloud platforms. Applying them establishes a known-secure baseline configuration from which deviations can be detected and remediated, reducing the attack surface before systems go into production. The baseline is a starting point, not a version-control or monitoring mechanism.

Exam trap

The trap here is confusing 'baseline' with 'standardization' — candidates pick the software-version answer because it sounds like consistency, but a security baseline is about configuration hardening, not version parity.

How to eliminate wrong answers

Option A is wrong because CIS Benchmarks do not enforce identical software versions across systems — that is a configuration management or golden-image concern, and version uniformity is neither the goal nor a requirement of benchmarking. Option B is wrong because traffic anomaly monitoring is the role of IDS/IPS or SIEM tooling, not configuration baselines. Option C is wrong because patch deployment is handled by patch management systems (WSUS, SCCM, Ansible); CIS Benchmarks define secure settings, not patch orchestration.

609
Multi-Selecthard

Which THREE of the following are essential components of a security baseline configuration for a server?

Select 3 answers
A.Disable unnecessary services.
B.Enable auditing and logging.
C.Apply the latest security patches.
D.Install all optional software for functionality.
E.Grant administrative rights to all users.
AnswersA, B, C

Disabling unnecessary services shrinks the attack surface by removing listening daemons and their associated vulnerabilities, directly satisfying the baseline requirement to eliminate non-essential functionality. Each disabled service removes potential entry points that attackers could exploit, ensuring only required roles run on the server.

Why this answer

A security baseline configuration for a server must minimize the attack surface, so option A (Disable unnecessary services) is correct because every running service is a potential entry point and removing unneeded ones reduces exploitable ports and daemons. Option B (Enable auditing and logging) is correct because it provides the visibility needed to detect, investigate, and respond to security events, and is a standard hardening requirement in frameworks like CIS Benchmarks and NIST SP 800-123. Option C (Apply the latest security patches) is correct because unpatched software is a primary vector for exploitation, and timely patching of the OS and applications is a foundational baseline control.

Option D (Install all optional software for functionality) is not part of a security baseline because installing unnecessary software expands the attack surface and contradicts the principle of least functionality. Option E (Grant administrative rights to all users) is not part of a security baseline because it violates least privilege and dramatically increases the risk of privilege abuse and compromise.

Exam trap

ISC2 often tests the principle of least functionality by making candidates think that installing all optional software ensures compatibility, when in reality it violates the core security baseline goal of reducing the attack surface.

610
MCQhard

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

A.Patch the backup site immediately
B.Shut down the backup site
C.Document the finding and assess risk
D.Continue the exercise and note the issue
AnswerC

Discovering missing patches at the backup site is a risk finding, not an immediate remediation trigger. Documenting it and assessing risk first determines severity and prioritisation, avoiding unplanned changes during the exercise that could invalidate results.

Why this answer

The first step in any incident or exercise finding is to document the issue and assess the risk it poses. Patching the backup site immediately (Option A) could introduce instability or conflicts with the current exercise, while shutting it down (Option B) would disrupt the DR test. By documenting and assessing risk first, the team can determine the appropriate remediation priority based on the backup site's role and the criticality of the missing patches.

Exam trap

ISC2 often tests the principle that 'document and assess' must precede any corrective action, even in an exercise, to avoid impulsive changes that could invalidate the test results or introduce new risks.

How to eliminate wrong answers

Option A is wrong because applying patches without first assessing the risk could break the backup site's configuration or introduce new vulnerabilities during the exercise, and it may not be the highest priority action. Option B is wrong because shutting down the backup site would halt the disaster recovery exercise and potentially leave the organization without any failover capability, which is counterproductive. Option D is wrong because simply continuing the exercise without documenting or assessing the issue ignores the security gap and could lead to a false sense of readiness, violating standard incident response procedures (NIST SP 800-61).

611
MCQeasy

A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?

A.Spoofing
B.DoS
C.Sniffing / Eavesdropping
D.Man-in-the-middle
AnswerC

Sniffing passively captures frames traversing a shared segment, letting the attacker read unencrypted payloads without altering traffic. This matches the stem's evidence: Wireshark shows data being read, not modified or blocked. Eavesdropping requires no injection or spoofing, only promiscuous-mode capture on the segment.

Why this answer

Sniffing or eavesdropping involves capturing network traffic to read data. In this scenario, unencrypted data is being read, which is characteristic of sniffing.

612
MCQmedium

A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?

A.Separation of duties
B.Need-to-know
C.Defense in depth
D.Least privilege
AnswerD

Separating a standard account from an elevated one limits privileged access to tasks that genuinely require it, applying least privilege. This satisfies the stem's scenario by preventing daily activities, such as browsing email, from running with administrative rights.

Why this answer

The principle of least privilege states that users should be granted only the minimum levels of access—or permissions—necessary to perform their job functions. By using a regular account for daily work and a separate elevated account only when needed, the administrator is limiting the exposure of privileged access, thus applying least privilege.

Exam trap

The trap is that candidates might confuse least privilege with separation of duties; both involve limiting access, but least privilege is about minimizing permissions, while separation of duties is about dividing tasks among multiple people.

How to eliminate wrong answers

Option A is wrong because separation of duties involves dividing responsibilities among different individuals to prevent fraud or errors, not about using separate accounts for different privilege levels. Option B is wrong because need-to-know is about limiting access to information based on necessity, typically in security clearances, not about account privileges. Option C is wrong because defense in depth is a layered security approach, not a specific principle about account usage.

613
MCQeasy

An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerB

Availability ensures that systems and data are accessible to authorized users when needed. Here, the power failure caused servers to shut down and data to become unavailable, directly violating availability. The UPS and generator were intended to maintain availability, but their failure resulted in a loss of access to critical data, making this the most directly compromised principle.

Why this answer

The power outage and subsequent generator failure led to servers shutting down and data becoming inaccessible. Availability ensures that systems and data are accessible to authorized users when needed. The failure of backup power directly compromised availability, as the organization could not access its critical data.

Confidentiality and integrity are not primarily affected because there is no unauthorized disclosure or modification, and non-repudiation is irrelevant to this physical infrastructure failure.

Exam trap

The trap here is assuming that data loss always equates to an integrity breach, when in fact a loss of access due to power failure is primarily an availability issue.

614
MCQeasy

Which of the following ports is used by HTTPS?

A.80
B.21
C.25
D.443
AnswerD

HTTPS uses TCP port 443 by default, carrying HTTP traffic encrypted with TLS. Port 80 serves plain HTTP, while 22 and 3389 handle SSH and RDP respectively. Browsers and servers therefore negotiate secure web sessions on 443 unless an administrator configures a non-standard port.

Why this answer

HTTPS (Hypertext Transfer Protocol Secure) operates over TCP port 443 by default, using TLS to encrypt HTTP traffic between client and server. This is the IANA-assigned well-known port for HTTPS, so any browser request to https:// implicitly targets port 443 unless overridden. Port 80 is the counterpart for unencrypted HTTP, which is why the two are so often confused.

Exam trap

The trap here is confusing port 80 (HTTP) with port 443 (HTTPS); candidates who memorize only 'web = 80' pick A without noticing the 'S' in HTTPS.

How to eliminate wrong answers

Option A is wrong because port 80 is the default for plain HTTP, which transmits data in cleartext and is not the secure variant. Option B is wrong because port 21 is assigned to FTP control commands, not web traffic. Option C is wrong because port 25 is used for SMTP mail relay, unrelated to HTTPS.

615
MCQeasy

A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?

A.To define penalties for employees who violate security policies
B.To identify and classify information assets by their sensitivity
C.To restore IT infrastructure and critical data after a disruption
D.To outline steps for communicating with the media during a crisis
AnswerC

A disaster recovery plan focuses specifically on restoring IT systems, applications, and data after an incident. In this ransomware scenario, the plan would guide steps to recover the encrypted document management system from backups, rebuild affected servers, and validate data integrity so the firm can resume work. It directly addresses the technical recovery of technology assets, which is the core objective here.

Why this answer

A disaster recovery plan is specifically designed to restore IT infrastructure, applications, and data after a disruption. In a ransomware scenario, the plan details how to recover encrypted systems from backups, rebuild servers, and verify data integrity. The other options describe asset classification, HR discipline, and media communication, which are not the primary focus of disaster recovery.

Exam trap

The trap here is confusing disaster recovery with broader business continuity or incident response activities, such as crisis communication or asset classification.

616
MCQmedium

A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?

A.Rule-based access control
B.Role-based access control (RBAC)
C.Mandatory access control (MAC)
D.Discretionary access control (DAC)
AnswerB

RBAC assigns permissions to roles such as Tax Preparer or Auditor, and users receive access by being placed in the appropriate role. The firm wants access determined by department membership, which maps directly to role assignment, so permissions stay consistent as individuals move. This satisfies the requirement without per-user permission management.

Why this answer

Role-based access control grants permissions to roles and then assigns users to those roles, so access follows a person's function rather than being set individually. Because the firm wants tax software access determined by department membership, defining roles and assigning users to them delivers the required consistency and reduces administrative effort when staff change positions.

Exam trap

The trap here is assuming any centralized permission scheme is role-based, when discretionary and rule-based models also centralize some control but not through role membership.

617
MCQmedium

A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?

A.Use the most recent incremental backup to restore files directly.
B.Assume all backups are compromised and rebuild systems from scratch.
C.First verify the integrity of the backups by scanning them on an isolated system, then restore the full backup and apply the most recent clean incremental backups.
D.Restore the weekly full backup and then apply all incremental backups from the past 5 days.
AnswerC

Scanning backups on an isolated host confirms they are free of the ransomware before anything is written back, and restoring the five-day-old full set plus the clean incrementals recovers all data up to the last good backup, minimising loss without reintroducing the payload.

Why this answer

The correct approach is to verify backup integrity on an isolated system before restoring, because the backup server may be compromised by the same ransomware. Once verified clean, the team restores the weekly full backup and then applies the most recent clean incremental backups to minimize data loss. This balances recovery point objective (RPO) with security assurance.

Exam trap

The trap here is assuming that because backups are stored on a separate network segment they are automatically safe, leading candidates to skip verification and choose direct restore options.

How to eliminate wrong answers

Option A is wrong because restoring directly from an incremental backup on a potentially compromised backup server risks reintroducing malware or restoring corrupted data. Option B is wrong because assuming all backups are compromised and rebuilding from scratch causes unnecessary data loss and downtime when verification could prove backups are clean. Option D is wrong because it skips the critical verification step and blindly applies all incremental backups, including any that may be infected, and also incorrectly assumes all 5 days of incrementals are needed when only the most recent clean ones are required.

618
Multi-Selecthard

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Select 3 answers
A.Subnetting
B.DMZs
C.Firewalls
D.VLANs
E.Intrusion Detection Systems
AnswersA, B, D

Subnetting divides an IP network into smaller logical ranges at Layer 3, using the subnet mask to separate address blocks. Each subnet forms its own broadcast domain, and inter-subnet traffic must route through a gateway, enabling policy enforcement and limiting breach propagation.

Why this answer

Subnetting (A) is correct because dividing a larger IP network into smaller logical subnets using CIDR and subnet masks creates distinct broadcast domains and limits lateral movement between segments. DMZs (B) are correct because a demilitarized zone places internet-facing services such as web, mail, or DNS servers in a separate screened segment, isolating them from the internal trusted network. VLANs (D) are correct because IEEE 802.1Q VLANs logically segment a switched network at Layer 2, allowing departments or device groups to be separated without physical rewiring and enforcing traffic isolation via trunk and access port configuration.

Firewalls (C) are not a segmentation method themselves; they are policy enforcement devices that control traffic between segments, so they are typically deployed to secure segmentation rather than create it. Intrusion Detection Systems (E) are monitoring tools that detect malicious activity and generate alerts, but they do not divide or isolate network segments.

Exam trap

The trap here is confusing security controls (firewalls, IDS) with segmentation techniques — candidates often select firewalls because they 'segment' traffic, but the question asks for methods that create the segments themselves.

619
MCQhard

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation reduces the likelihood or impact of a threat through controls. Deploying a firewall and intrusion detection system applies preventive and detective controls that lower breach probability, rather than transferring, avoiding or accepting the risk.

Why this answer

Risk mitigation reduces the likelihood or impact of a threat by implementing controls; a firewall and IDS are detective and preventive controls that lower the probability and severity of a network breach without eliminating the risk entirely. This is the textbook definition of mitigation — the risk still exists but is reduced to an acceptable level.

Exam trap

The trap here is confusing mitigation with avoidance — candidates see 'reduce the risk' and pick avoidance, forgetting that avoidance requires eliminating the underlying activity, not adding controls.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or asset that creates the risk entirely (e.g., disconnecting from the internet), which is not what deploying a firewall does. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, which contradicts the implementation of new controls. Option C is wrong because risk transfer shifts the financial impact to a third party, typically via cyber insurance or outsourcing — a firewall does not transfer risk.

620
MCQhard

A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?

A.Distributed denial of service (DDoS)
B.SQL injection
C.Brute force attack leading to privilege escalation
D.Cross-site scripting (XSS)
AnswerC

The multiple failed SSH logins for root from various IPs indicate a brute force attempt. The subsequent successful login from a foreign IP and creation of a new sudo-enabled account show that the attacker gained access and escalated privileges. This pattern is classic for a brute force attack followed by persistence establishment.

Why this answer

The sequence of multiple failed SSH logins followed by a successful login from a foreign IP and the creation of a sudo-enabled account strongly indicates a brute force attack that succeeded, leading to privilege escalation. This is a common attack chain where initial access is gained through weak credentials, and persistence is established via a new privileged user.

Exam trap

The trap here is focusing on the failed logins alone and missing the subsequent successful login and account creation, which together reveal a successful brute force and privilege escalation.

621
MCQhard

A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?

A.It is the risk that materialized.
B.It is the impact of the security incident.
C.It is a weakness that was exploited by a threat.
D.It is the threat that exploited the system.
AnswerC

A vulnerability is a weakness or flaw in a system that can be exploited by a threat. In this case, the unpatched software is the vulnerability. The attacker (threat) exploited this weakness to gain access and deploy malware. This is the correct definition and role of the vulnerability in the incident. It is the specific flaw that allowed the breach to occur.

Why this answer

The unpatched vulnerability is a weakness in the system that was exploited by a threat (the attacker). In risk management, a vulnerability is a flaw or gap that can be leveraged to compromise security. The threat is the actor or event that exploits the vulnerability, and the risk is the potential for loss.

The impact is the resulting damage. Therefore, the vulnerability's role is that of a weakness exploited by a threat, making it the correct description.

Exam trap

The trap here is mixing up the definitions of threat, vulnerability, risk, and impact, especially when they appear together in a scenario.

622
MCQmedium

A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?

A.Administrative control
B.Physical control
C.Technical control
D.Compensating control
AnswerC

Technical controls are implemented through systems and devices, such as firewalls, intrusion prevention systems, and access control lists. Placing firewalls between segments and permitting only necessary ports and protocols is a technical enforcement mechanism. It limits lateral movement automatically based on configured rules, which is characteristic of a technical rather than administrative or physical safeguard, and it directly reduces the blast radius of an infected workstation.

Why this answer

Network segmentation enforced by firewalls and port restrictions is implemented through technology, making it a technical control. It limits how malware can move laterally from workstations to critical servers by permitting only required traffic. Unlike administrative controls that depend on policies and training, or physical controls that restrict access to facilities, this approach enforces boundaries automatically.

Segmenting systems and minimizing allowed protocols reduces the attack surface and contains incidents.

Exam trap

The trap here is assuming segmentation is administrative because a policy may mandate it, when the actual enforcement mechanism is a technical device applying rules to traffic.

623
Multi-Selectmedium

Which THREE are recommended practices for password policies according to current guidelines?

Select 3 answers
A.Check passwords against lists of known breached passwords
B.Require passwords at least 8 characters long
C.Require at least one uppercase letter, one number, and one special character
D.Allow passwords up to 64 characters
E.Force password changes every 30 days
AnswersA, B, D

Checking passwords against breached-password lists blocks credentials already exposed in known data breaches, directly satisfying the guideline to screen for compromised passwords. Microsoft Entra ID implements this natively through its banned-password list, which is populated from breach data and automatically rejects matching entries during password set or reset.

Why this answer

Option A is correct because current NIST SP 800-63B guidance requires screening new passwords against lists of known compromised or breached passwords (such as those from Have I Been Pwned) and rejecting any that match. Option B is correct because NIST sets the minimum password length at 8 characters when a password is used as a single-factor authenticator. Option D is correct because NIST recommends permitting passwords up to at least 64 characters, allowing the use of long passphrases and password managers.

Option C is not recommended because composition rules (mixing uppercase, numbers, and special characters) are now discouraged as they push users toward predictable patterns. Option E is not recommended because arbitrary periodic rotation (for example, every 30 days) is discouraged; changes should only be forced when there is evidence of compromise.

Exam trap

The trap here is that many candidates still believe traditional complexity and frequent expiration are best practices, but current guidelines (e.g., NIST) explicitly advise against them, favoring length and breach checks instead.

624
MCQhard

A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?

A.Role-based access control combined with discretionary access control
B.Account lockout thresholds combined with password complexity requirements
C.Time-based account expiration combined with periodic access reviews
D.Single sign-on combined with multifactor authentication
AnswerC

Account expiration enforces a hard stop date, so the contractor's credentials stop working when the 90-day engagement ends without anyone needing to remember to disable them. Periodic access reviews require the manager to reconfirm that the access remains justified, catching situations where the engagement is extended unnecessarily or where the scope has drifted. Together they address both automatic termination and ongoing validation of need.

Why this answer

Temporary access should be bounded in time and periodically justified. An account expiration date guarantees the access ends automatically at the close of the engagement, while periodic access reviews force the manager to reconfirm that the contractor still needs the trading application. The other combinations improve authentication strength or permission structure but do not provide automatic expiry or ongoing attestation.

Exam trap

The trap here is treating strong authentication controls as if they also manage the access lifecycle, when expiry and recertification are separate administrative controls.

625
MCQmedium

During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?

A.Backup tapes
B.Memory contents
C.Hard drive contents
D.Network logs
AnswerB

Memory contents are the most volatile, lost on power-off or reboot, so they must be captured before disk or logs. Order of volatility dictates collecting RAM first to preserve evidence such as running processes and encryption keys.

Why this answer

Volatile data is lost when the system loses power. Memory content is the most volatile.

626
MCQhard

A junior analyst reports that an attacker exploited an unpatched web server to steal customer data. The analyst labels the missing patch the 'risk'. According to standard risk terminology, how should the missing patch be classified?

A.As the impact, because data was stolen from the server
B.As the risk, because it is the condition that led to the loss
C.As the threat, because it enabled the compromise
D.As the vulnerability, because it is a weakness an attacker can exploit
AnswerD

A vulnerability is a weakness in a system, process, or control that a threat can exploit to cause harm. An unpatched web server is a textbook vulnerability: it is a defect in the environment, not an actor and not a measure of loss. Classifying it correctly lets the organisation prioritise patching and track the exposure until it is remediated.

Why this answer

In standard risk terminology, a vulnerability is a weakness that a threat can exploit, and the unpatched web server fits that definition precisely. Risk is the combination of the likelihood that a threat exploits a vulnerability and the resulting impact, while the threat is the actor or circumstance capable of causing harm. Naming the missing patch the vulnerability keeps cause, actor, and consequence distinct for remediation.

Exam trap

The trap here is collapsing vulnerability, threat, and risk into one label, when the unpatched server is specifically the weakness that a threat exploits to produce risk.

627
MCQmedium

A company's security policy requires that all data at rest be encrypted. Which of the following is the BEST approach to ensure compliance while maintaining performance?

A.Deploy full disk encryption on all endpoints and servers.
B.Use database encryption to protect sensitive data.
C.Apply network encryption using TLS for all data transfers.
D.Implement file-level encryption for sensitive files only.
AnswerA

Full disk encryption satisfies the data-at-rest requirement by encrypting the entire volume, including temporary and swap files, so no plaintext persists on lost or stolen media. Encryption occurs at the storage layer via hardware or OS drivers, adding negligible latency compared with application-level or database encryption, thus preserving performance.

Why this answer

Full disk encryption (FDE) encrypts the entire storage volume, including the operating system, applications, and all data at rest, ensuring compliance with a policy requiring all data at rest to be encrypted. FDE operates at the block level, typically using AES-256, with minimal performance overhead because encryption and decryption are handled by the disk controller or CPU with hardware acceleration (e.g., AES-NI), making it the best approach for maintaining performance while meeting the broad requirement.

Exam trap

ISC2 often tests the distinction between 'data at rest' and 'data in transit' encryption, and the trap here is that candidates may choose database or file-level encryption because they think it is more targeted, but they overlook the policy's explicit 'all data at rest' requirement, which only full disk encryption satisfies comprehensively.

How to eliminate wrong answers

Option B is wrong because database encryption only protects data within the database, leaving other data at rest (e.g., OS files, logs, temp files) unencrypted, failing the 'all data at rest' requirement. Option C is wrong because network encryption (TLS) protects data in transit, not data at rest, so it does not address the policy requirement at all. Option D is wrong because file-level encryption only encrypts specific files, leaving other data at rest (e.g., system files, swap space, unencrypted directories) exposed, and it often introduces higher performance overhead due to per-file cryptographic operations and key management.

628
MCQhard

A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?

A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Discretionary Access Control (DAC)
D.Attribute-Based Access Control (ABAC)
AnswerB

MAC enforces access decisions from system-controlled labels rather than from user discretion. Subjects receive clearances and objects receive classifications, and the system permits access only when the clearance dominates the label. Because users cannot alter labels or extend access to others, this precisely matches the described enforcement, including the dominance rule for reading.

Why this answer

The system bases every access decision on system-assigned classification labels and user clearances, and users cannot modify those labels or delegate access. That combination of non-discretionary, label-driven enforcement is Mandatory Access Control. The dominance rule described, where clearance must dominate the object label for read access, is a hallmark of mandatory models such as Bell-LaPadula.

Exam trap

The trap here is focusing on the word 'clearance' and picking role-based control, when the decisive clue is that labels are system-enforced and users cannot delegate access.

629
MCQhard

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

A.Discontinuing use of the vendor's software
B.Purchasing cyber insurance to cover potential losses
C.Installing a patch to fix the vulnerability
D.Accepting the risk and documenting the decision
AnswerB

Risk transfer shifts the financial consequence of a risk to a third party. Purchasing cyber insurance means the insurer absorbs potential breach losses, satisfying the stem's requirement for risk transfer, whereas patching, avoiding the vendor or accepting the exposure would not shift that financial burden.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual agreements. Purchasing cyber insurance explicitly transfers the potential financial losses from data exposure to the insurer, which is the definition of risk transfer. The other options represent risk avoidance (discontinuing use), risk mitigation (patching), or risk acceptance (accepting and documenting).

Exam trap

The trap here is confusing risk transfer with risk mitigation or avoidance; candidates often think that patching (mitigation) or discontinuing use (avoidance) transfers risk, but only shifting financial responsibility to a third party constitutes transfer.

How to eliminate wrong answers

Option A is wrong because discontinuing use of the software eliminates the risk entirely, which is risk avoidance, not transfer. Option C is wrong because installing a patch reduces the likelihood or impact of the vulnerability, which is risk mitigation, not transfer. Option D is wrong because accepting the risk and documenting it is risk acceptance, where the organization retains the potential losses.

630
MCQeasy

Which of the following ports is commonly used for secure web traffic (HTTPS)?

A.53
B.80
C.22
D.443
AnswerD

Port 443 is the IANA-assigned default for HTTPS, carrying HTTP over TLS to encrypt web traffic. Port 80 handles unencrypted HTTP, while 22 and 3389 serve SSH and RDP respectively, so 443 satisfies the secure web traffic requirement.

Why this answer

HTTPS uses TCP port 443 by default, wrapping HTTP inside a TLS tunnel so credentials, cookies, and page content are encrypted in transit. Port 443 is the IANA-registered well-known port for HTTPS and is what browsers assume when no port is specified in an https:// URL. This is why secure web traffic is universally associated with 443.

Exam trap

The trap here is that both 80 and 443 are 'web' ports; candidates who skim the question and see 'web traffic' pick 80, missing the word 'secure' that points to 443.

How to eliminate wrong answers

Option A is wrong because port 53 is used by DNS for name resolution over UDP and TCP, not for web traffic. Option B is wrong because port 80 carries unencrypted HTTP, which is the insecure counterpart to HTTPS. Option C is wrong because port 22 is assigned to SSH for secure remote shell access, not for serving web content.

631
Multi-Selecthard

Which THREE of the following are best practices for securing a remote access VPN?

Select 3 answers
A.Enable multi-factor authentication.
B.Keep VPN client software up to date.
C.Use pre-shared keys for authentication.
D.Enforce strong password policies.
E.Implement split tunneling by default.
AnswersA, B, D

Multi-factor authentication (MFA) satisfies the "best practices for securing a remote access VPN" constraint by enforcing a second verification factor—such as a time-based one-time password (TOTP) from an authenticator app or a biometric check—beyond the primary username and password. This mitigates credential theft risks inherent in VPN gateways exposed to the internet, as an attacker compromising a password still cannot authenticate without the second factor, which is typically validated against a directory service like Microsoft Entra ID.

Why this answer

Option A (Enable multi-factor authentication) is correct because MFA adds a second verification factor beyond a password, so stolen or guessed credentials alone cannot establish a VPN session, directly mitigating credential-based attacks on remote access. Option B (Keep VPN client software up to date) is correct because VPN clients such as AnyConnect, GlobalProtect, or OpenVPN frequently receive patches for vulnerabilities (e.g., buffer overflows, TLS flaws), and running current versions closes known exploit paths on endpoints that terminate the tunnel. Option D (Enforce strong password policies) is correct because strong, complex, and rotated passwords reduce the risk of brute-force, credential-stuffing, and dictionary attacks against VPN authentication, complementing MFA as a defense-in-depth control.

Option C (Use pre-shared keys for authentication) is not a best practice because PSKs are static secrets shared across users or devices, are difficult to rotate, and are vulnerable to theft and offline cracking, so they should be replaced by certificate-based or MFA-backed authentication. Option E (Implement split tunneling by default) is not a best practice because split tunneling lets remote traffic bypass the VPN and the corporate security stack, exposing the endpoint and internal network to threats; full tunneling or selective, policy-driven split tunneling is preferred.

Exam trap

ISC2 often tests the misconception that pre-shared keys are acceptable for remote access VPNs because they are simple to configure, but the exam expects you to recognize that PSKs are a weak, shared secret that should be replaced with certificate-based or EAP authentication for secure remote access.

632
MCQeasy

A system administrator must grant a help desk technician the ability to reset user passwords but not change user roles. Which security principle does this scenario enforce?

A.Accountability
B.Principle of least privilege
C.Need-to-know
D.Non-repudiation
AnswerB

Granting only password-reset rights, while withholding role-assignment permissions, enforces least privilege: each identity receives the minimum access needed for its tasks. Microsoft Entra ID supports this through scoped administrative roles such as Password Administrator, which cannot modify role memberships, satisfying the stem's constraint that role changes remain blocked.

Why this answer

The principle of least privilege dictates that users are granted only the minimum access rights necessary to perform their job functions — no more. Granting the help desk technician the ability to reset passwords but explicitly withholding the ability to change user roles is a textbook application of this principle, because role changes are a more privileged operation than password resets. This limits the blast radius if the technician's account is compromised.

Exam trap

The trap here is confusing least privilege (limiting what actions a user can perform) with need-to-know (limiting what data a user can access) — both sound similar but apply to different dimensions of access control.

How to eliminate wrong answers

Option A is wrong because accountability refers to the ability to trace actions back to a specific individual (typically via logging and unique credentials), not to restricting permissions. Option C is wrong because need-to-know is a data-classification concept about limiting access to specific information based on job requirements, not about limiting system capabilities or functions. Option D is wrong because non-repudiation is a cryptographic property ensuring a party cannot deny having performed an action (e.g., via digital signatures), which is unrelated to permission scoping.

633
MCQeasy

An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?

A.Honeypot
B.Subnet
C.DMZ
D.VLAN
AnswerC

A DMZ is a screened subnet placed between the internal network and the internet, hosting public-facing servers while enforcing firewall rules that block inbound traffic from reaching internal users. This directly satisfies the requirement to isolate public-facing servers from the internal network.

Why this answer

A DMZ (demilitarized zone) is a perimeter subnetwork that hosts public-facing services such as web, mail, and DNS servers while keeping them separated from the internal trusted network. Traffic from the internet reaches the DMZ, but the DMZ is firewalled off from the internal LAN, so a compromised public server cannot pivot directly into internal systems. This is the standard architecture for isolating externally accessible servers.

Exam trap

The trap is confusing DMZ with VLAN; candidates think any network segmentation equals a DMZ, but a VLAN alone does not create the internet-facing, firewalled isolation a DMZ provides.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system designed to attract and study attackers, not to host production public services. Option B is wrong because a subnet is a generic Layer 3 address range; by itself it does not enforce the security separation between public and internal zones that a DMZ provides. Option D is wrong because a VLAN is a Layer 2 broadcast-domain segmentation tool used mainly for internal traffic separation, not for hosting internet-facing servers behind a perimeter firewall.

634
MCQhard

A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?

A.Visitor sign-in and escort policy only
B.A single high-tech lock on the server room door
C.A strong password policy for all employees
D.Perimeter fencing, access badges at building entrance, biometric reader on server room, and cable locks on servers
AnswerD

Each layer compensates if an earlier one fails: fencing delays intrusion, badges filter entrants, biometrics restrict the server room, and cable locks stop physical theft. This satisfies the defence-in-depth requirement by combining deterrence, detection and delay across independent boundaries.

Why this answer

Defense in depth involves implementing multiple layers of security controls so that if one layer fails, others still provide protection. The combination of perimeter fencing, access badges at the building entrance, biometric reader on the server room, and cable locks on servers represents multiple physical security layers, from the outer perimeter to the individual server level. This is a classic example of defense in depth.

Exam trap

The trap is that candidates might choose a single strong control (like a high-tech lock) thinking it is sufficient, but defense in depth requires multiple, diverse layers; also, they might confuse logical controls with physical controls.

How to eliminate wrong answers

Option A is wrong because a visitor sign-in and escort policy only is a single layer of control and does not provide depth. Option B is wrong because a single high-tech lock on the server room door is a single point of failure and does not represent multiple layers. Option C is wrong because a strong password policy is a logical control, not a physical security control, and does not address physical defense in depth.

635
MCQeasy

After a ransomware attack, which team is primarily responsible for coordinating the response?

A.Executive Management
B.Incident Response Team
C.IT Support
D.Legal Department
AnswerB

The Incident Response Team owns coordination during a ransomware attack, executing the containment, eradication and recovery phases while liaising with legal, communications and management. This satisfies the stem's coordination constraint, since neither the security operations centre alone nor business units hold that cross-functional mandate.

Why this answer

The Incident Response Team (IRT) is primarily responsible for coordinating the response to a ransomware attack because it follows a predefined incident response plan (IRP) that includes containment, eradication, and recovery procedures. The IRT typically includes security analysts, forensic experts, and system administrators who execute technical steps such as isolating affected systems, analyzing the ransomware strain, and restoring from backups. This team operates under the NIST SP 800-61 framework, ensuring a structured and rapid response to minimize damage.

Exam trap

ISC2 often tests the misconception that Executive Management or Legal should lead the response due to their authority or compliance role, but the exam emphasizes that technical coordination belongs to the Incident Response Team as defined in the CC curriculum's incident response process.

How to eliminate wrong answers

Option A is wrong because Executive Management provides strategic oversight and approves budget/resource allocation, but they lack the technical expertise to coordinate hands-on incident response activities like network isolation or forensic analysis. Option C is wrong because IT Support focuses on routine user troubleshooting and system maintenance, not on executing the specialized containment and eradication steps required during a ransomware incident, such as analyzing malware indicators of compromise (IOCs) or applying firewall rules. Option D is wrong because the Legal Department handles regulatory compliance, breach notification, and liability issues, but they do not perform the technical coordination of response actions like system restoration or evidence preservation.

636
MCQmedium

An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?

A.Incremental backup strategy
B.Differential backup strategy
C.Full backup strategy
D.3-2-1 backup rule
AnswerD

The 3-2-1 rule requires three copies of data, on two different media types, with one copy held offsite. Tape and cloud storage satisfy the two-media requirement, while cloud replication provides the offsite copy, directly matching the stem's onsite tape plus cloud arrangement.

Why this answer

The 3-2-1 backup rule states that you should keep at least three copies of data, on two different media types, with one copy stored offsite. Storing backups on tape (onsite) plus replicating critical data to cloud storage satisfies the multiple-media and offsite requirements, making it the textbook example of the rule.

Exam trap

The trap here is confusing backup methods (full, incremental, differential) with the 3-2-1 rule, which is about copy count, media diversity, and offsite placement rather than how changes are captured.

How to eliminate wrong answers

Option A is wrong because incremental backup is a backup method that only captures changes since the last backup, not a rule about copy count, media, or location. Option B is wrong because differential backup captures changes since the last full backup — again a method, not the 3-2-1 principle. Option C is wrong because full backup copies all data every time; it describes a backup type, not the multi-copy/offsite strategy illustrated.

637
MCQeasy

A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?

A.Reciprocity, because the caller previously helped the administrator with a ticket and now expects a favor in return.
B.Consensus, because the caller claims that other administrators have already shared their codes to fix the same problem.
C.Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.
D.Scarcity, because the caller implies that only a limited number of support slots are available for the server repair.
AnswerC

The caller claims to be help desk staff and invents a critical server issue to create time pressure. This is a classic pretext that leverages authority and urgency so the victim bypasses normal verification. Because the administrator did not initiate the MFA challenge, sharing the code would hand over a second factor and allow account takeover. Recognizing unsolicited authority claims is a core security operations skill.

Why this answer

The caller fabricates a critical server problem while posing as help desk personnel, which combines impersonated authority with manufactured urgency. Because the administrator never initiated an MFA challenge, no legitimate support process would require the code to be read aloud. The correct response is to refuse, hang up, and verify through a known internal channel.

This scenario tests recognition of pretexting and MFA code theft.

Exam trap

The trap here is treating any request for an MFA code as routine support activity instead of recognizing that unsolicited code requests are a hallmark of social engineering.

638
MCQhard

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

A.Vulnerability
B.Control
C.Risk
D.Threat
AnswerC

Risk is the term combining the likelihood that a threat exploits a vulnerability with the resulting harm to an asset, satisfying the stem's definition. Threat alone denotes the potential cause, vulnerability the weakness, and exposure the susceptibility, none of which express probability multiplied by impact.

Why this answer

Risk is defined as the likelihood of a threat exploiting a vulnerability, resulting in harm to an asset.

639
MCQmedium

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

A.Multi-factor authentication
B.Type 3 authentication
C.Single-factor authentication
D.Type 2 authentication only
AnswerA

The smart card supplies a possession factor and the PIN supplies a knowledge factor, so two distinct factor types are combined. That combination satisfies the definition of multi-factor authentication rather than single-factor or same-category authentication.

Why this answer

Multi-factor authentication (MFA) requires two or more different authentication factors: something you have (smart card), something you know (PIN), and optionally something you are (biometric). Here, the smart card is a possession factor and the PIN is a knowledge factor, so combining them satisfies MFA. This is the correct classification because the two factors are of different types, not just two instances of the same type.

Exam trap

The trap here is confusing authentication factor types with authentication methods; candidates often think that a smart card and PIN together are still single-factor because they are both used in one process, but the key is that they represent different factor categories (possession and knowledge).

How to eliminate wrong answers

Option B is wrong because Type 3 authentication refers to 'something you are' (biometrics such as fingerprint or retina scan), which is not used here. Option C is wrong because single-factor authentication would involve only one factor (e.g., just a PIN or just a smart card), whereas the scenario uses two distinct factors. Option D is wrong because Type 2 authentication refers to 'something you have' (e.g., a smart card or token), but the scenario also includes a PIN (something you know), so it is not Type 2 only.

640
MCQhard

A security manager is documenting how the organization decides which safeguards to apply to a new customer database. The team identifies the value of the data, the threats that could exploit weaknesses, and the potential business impact, then selects controls that reduce risk to an acceptable level. Which concept best describes this activity?

A.Risk management
B.Vulnerability assessment
C.Business continuity planning
D.Security awareness training
AnswerA

Risk management is the ongoing process of identifying, assessing, and treating risk to an acceptable level. The scenario describes exactly that cycle: valuing the asset, identifying threats and vulnerabilities, evaluating business impact, and selecting controls to reduce risk. Risk treatment options include mitigation, transfer, avoidance, and acceptance. Because the team is deciding which safeguards to apply based on assessed risk, the activity is risk management rather than a single control or one-time audit.

Why this answer

The manager is following a structured process: identify and value the asset, determine threats and vulnerabilities, assess potential business impact, and choose safeguards that bring risk to an acceptable level. That end-to-end process is risk management, which includes risk identification, analysis, evaluation, and treatment. Business continuity planning addresses disruptions, awareness training changes user behavior, and vulnerability assessment only finds weaknesses; none of those encompasses the full decision cycle described.

Exam trap

The trap here is choosing vulnerability assessment because weaknesses are mentioned, but the scenario includes asset valuation, impact analysis, and control selection, which together define risk management.

641
MCQhard

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

A.Advance the profession
B.Act honorably
C.Protect society
D.Provide diligent service
AnswerC

The (ISC)² Code of Ethics canon places the safety and welfare of society and the common good above all else, including duties owed to an employer. Protecting society therefore takes precedence when the two obligations conflict, satisfying the stem's precedence requirement.

Why this answer

The (ISC)² Code of Ethics establishes a strict priority order among its canons, with 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' as the highest obligation. When this conflicts with providing diligent service to an employer or client, protecting society must take precedence. This hierarchy ensures that security professionals prioritize public safety over commercial or contractual interests.

Exam trap

The trap here is that candidates may pick 'Provide diligent service' because it feels like the most direct professional obligation, but the (ISC)² Code explicitly subordinates employer service to the protection of society.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the lowest-priority canon and only applies after all higher obligations are satisfied. Option B is wrong because 'Act honorably' is the second canon — important, but subordinate to protecting society. Option D is wrong because 'Provide diligent service' is the third canon; while professionals should serve their employers competently, this duty yields when it conflicts with the public good.

642
MCQmedium

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

A.Stateful firewall
B.Web Application Firewall (WAF)
C.Intrusion Detection System (IDS)
D.Packet filtering firewall
AnswerB

A Web Application Firewall operates at Layer 7, inspecting HTTP/HTTPS request content against rule sets to block SQL injection, cross-site scripting and similar exploits. This directly satisfies the stem's requirement to inspect web traffic and block malicious requests, unlike packet-filtering firewalls that cannot parse application payloads.

Why this answer

A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at Layer 7 and applies rules to block attacks like SQL injection, cross-site scripting (XSS), and malicious bots. It understands web protocols and can examine request bodies, headers, and cookies, which is exactly what is needed to protect internal web applications exposed to external users. This makes WAF the purpose-built device for the scenario.

Exam trap

The trap is confusing a stateful firewall with a WAF; candidates assume 'firewall' means it inspects everything, but only a WAF understands HTTP/HTTPS application-layer content.

How to eliminate wrong answers

Option A is wrong because a stateful firewall tracks connection state at Layers 3-4 but does not parse HTTP payloads, so it cannot detect application-layer attacks like XSS or SQLi. Option C is wrong because an IDS detects and alerts on suspicious traffic but does not sit inline to block malicious HTTP requests by default. Option D is wrong because a packet-filtering firewall only examines IP addresses, ports, and protocol types with no awareness of HTTP content.

643
MCQmedium

A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?

A.Excessive permissions
B.Segregation of duties conflict
C.Authorization creep
D.Incomplete revocation
AnswerA

Granting read and write when only read is required exceeds the user's legitimate need, breaching least privilege. This is excessive permissions: the access control issue is that rights granted are broader than the role demands, not a misconfigured or missing permission.

Why this answer

Excessive permissions occur when a user or group is granted more privileges than necessary for their role. In this scenario, the user has read and write access to a folder but should only have read access, meaning the write permission is unnecessary and violates the principle of least privilege. This is a classic example of excessive permissions, as the user has been over-provisioned beyond their job requirements.

Exam trap

ISC2 often tests the distinction between authorization creep (gradual accumulation over time) and excessive permissions (a one-time over-provisioning), so candidates may confuse the two when the scenario describes a single incorrect assignment.

How to eliminate wrong answers

Option B is wrong because segregation of duties conflicts involve splitting critical tasks among multiple users to prevent fraud or error, not a single user having extra permissions. Option C is wrong because authorization creep refers to the gradual accumulation of permissions over time due to role changes or transfers, not a one-time misassignment of write access. Option D is wrong because incomplete revocation occurs when permissions are not fully removed after a user no longer needs them, whereas here the user was never supposed to have write access in the first place.

644
MCQmedium

A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?

A.Ransomware encryption
B.Privilege escalation
C.Beaconing
D.SQL injection
AnswerC

Beaconing is periodic, regular communication with a C2 server, exactly matching the 60-second intervals observed here. Malware uses this heartbeat to receive commands and exfiltrate data while blending into normal traffic. Because no malicious file was flagged, the network pattern is the strongest indicator, making beaconing the correct characterization of this activity.

Why this answer

Regular, fixed-interval outbound connections to a known malicious address indicate beaconing, the heartbeat malware uses to maintain C2 communications. Because EDR found no malicious files, the network timing pattern becomes the key detection signal. Recognizing beaconing helps analysts identify stealthy implants that have evaded file-based detection and initiate containment before data theft or lateral movement occurs.

Exam trap

The trap here is assuming that because the EDR agent found no malicious files, no malware is present, overlooking the network-level beaconing pattern.

645
MCQmedium

An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?

A.HTTP
B.FTP
C.SNMP
D.LDAP
AnswerD

LDAP is the directory access protocol Active Directory natively speaks, providing the query and modify operations the stem requires. Clients bind to the directory and issue search, add, modify, and delete requests over TCP port 389 or 636. Kerberos handles authentication, but LDAP performs the directory read and write operations.

Why this answer

Active Directory primarily uses LDAP (Lightweight Directory Access Protocol) to query and modify its directory services. LDAP defines the structure and operations for accessing directory information, and AD implements LDAP v3 as its core access protocol on port 389 (and 636 for LDAPS). Administrative tools and applications use LDAP queries to read and write user, group, and computer objects.

Exam trap

The trap is confusing LDAP with Kerberos — candidates may know AD uses Kerberos for authentication and incorrectly select a different protocol for directory queries, but LDAP is specifically the query/modify protocol.

How to eliminate wrong answers

Option A is wrong because HTTP is the protocol for web traffic, not directory queries, though AD does expose some web-based services like AD FS and Web Enrollment. Option B is wrong because FTP transfers files and has no role in directory service queries. Option C is wrong because SNMP is used for monitoring and managing network devices, not for querying directory objects.

646
MCQhard

During an incident response, a forensics analyst captures a memory dump from a compromised server. The analyst needs to ensure the dump is not altered during analysis. Which practice best maintains integrity?

A.Encrypt the memory dump file
B.Maintain a chain of custody log
C.Restrict access to the dump to authorized personnel only
D.Generate a cryptographic hash of the dump before analysis
AnswerD

Hashing the dump with a cryptographic algorithm such as SHA-256 produces a fixed digest; re-hashing after analysis proves the bits are unchanged. This satisfies the stem's integrity constraint, since any alteration during examination would yield a different hash value.

Why this answer

Generating a cryptographic hash of the memory dump before analysis creates a fixed-length digest that acts as a unique fingerprint of the data. Any subsequent modification, even a single bit flip, will produce a completely different hash value, allowing the analyst to verify the dump has not been altered. This is the standard method for proving integrity in forensic investigations, as required by evidence handling procedures.

Exam trap

The trap here is confusing confidentiality controls (encryption, access restriction) with integrity controls (hashing), and assuming that a chain of custody log alone proves integrity, when it only documents handling.

How to eliminate wrong answers

Option A is wrong because encryption provides confidentiality, not integrity verification; an encrypted file can still be modified without detection if the attacker has the key. Option B is wrong because a chain of custody log documents who handled the evidence and when, but it does not technically detect or prevent alteration of the data itself. Option C is wrong because restricting access is an access control measure that reduces the opportunity for tampering, but it does not provide a means to verify that the dump remains unaltered.

647
MCQhard

Refer to the exhibit. Which security principle is being supported by the logging of these events?

A.Availability
B.Authentication
C.Non-repudiation
D.Accountability
AnswerD

Logging ties each recorded action to an authenticated identity, so activity can later be attributed to a specific user or process. That traceable attribution is what supports accountability, the principle the exhibited event records demonstrate.

Why this answer

Correct: D - Accountability. Logging provides a record of events that can be traced to specific sources, enabling accountability. Non-repudiation involves proof of actions by a user, but these logs do not prove user identity.

Authentication and availability are not directly supported.

648
MCQmedium

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

A.Provide diligent and competent service to principals
B.Advance and protect the profession
C.Act honorably, honestly, justly, responsibly, and legally
D.Protect society, the common good, and the public trust
AnswerD

The (ISC)² Code of Ethics orders its canons so that the safety and welfare of society outranks all other duties, including obligations to principals or employers. Protecting society, the common good and the public trust therefore sits at the highest priority, satisfying the stem's demand for the top-ranked obligation.

Why this answer

The Code of Ethics states the highest priority is to protect society, the common good, and the public trust.

649
MCQeasy

A network technician is setting up a remote access VPN for employees using IPsec. The company's firewall is configured to allow IPsec traffic. Employees report that they can successfully establish the VPN connection (tunnel appears up), but they cannot ping or access any internal resources (e.g., file servers). The firewall logs show that packets from the VPN client IP addresses are being dropped at the firewall interface. Which of the following is the MOST likely cause of this issue?

A.The VPN client is not assigned a correct IP address from the pool.
B.The firewall's access control list does not permit traffic from the VPN subnet to the internal network.
C.The firewall's intrusion prevention system is blocking the traffic.
D.The IPsec encryption algorithm is incompatible between client and firewall.
AnswerB

The firewall's ACL lacks a rule permitting traffic from the VPN client subnet to internal resources, so packets are dropped at the interface despite the tunnel being up. This satisfies the stem's constraint: IPsec negotiation succeeds, but the separate policy governing post-decryption traffic flow is missing.

Why this answer

The VPN tunnel is established, meaning Phase 1 and Phase 2 of IPsec are complete and the client has a valid IP from the pool. However, packets from the VPN subnet are being dropped at the firewall interface, which indicates that the firewall's access control list (ACL) does not include a permit statement for traffic sourced from the VPN client subnet destined to the internal network. Without this ACL entry, the firewall will drop the traffic even though the tunnel is up.

Exam trap

ISC2 often tests the distinction between tunnel establishment (IPsec Phase 1 and Phase 2) and traffic forwarding (ACL/permit rules), leading candidates to mistakenly blame encryption mismatches or client IP assignment when the real issue is a missing firewall rule.

How to eliminate wrong answers

Option A is wrong because if the VPN client were not assigned a correct IP address from the pool, the tunnel would not establish successfully (the client would fail Phase 2 or not receive a usable IP), and the logs would show authentication or address assignment failures, not dropped packets at the firewall interface. Option C is wrong because an intrusion prevention system (IPS) typically blocks traffic based on signatures or anomalies, not by default for all traffic from a VPN subnet; the logs would show IPS alerts, not simple drops at the interface. Option D is wrong because if the IPsec encryption algorithm were incompatible, the tunnel would fail to establish (Phase 2 would fail), and the VPN connection would not appear up.

650
Multi-Selecthard

An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)

Select 3 answers
A.A SOC manager who oversees daily operations and reporting
B.A dedicated threat intelligence team that provides context on indicators
C.Tier 2 analysts who conduct in-depth analysis and incident response
D.Tier 1 analysts who monitor alerts and perform initial triage
E.Tier 3 analysts who focus on threat hunting and advanced forensics
AnswersC, D, E

Tier 2 provides the escalation layer where alerts triaged by Tier 1 receive deeper investigation, correlation and containment. Without this escalation capability, incidents stall at triage, so it is essential to a tiered SOC model.

Why this answer

The tiered SOC model is built around escalating analyst responsibilities, so option D is correct because Tier 1 analysts are the first line of defense, continuously monitoring SIEM alerts and performing initial triage to filter false positives before escalation. Option C is correct because Tier 2 analysts take escalated incidents, conduct in-depth analysis, correlate events across multiple data sources, and drive the incident response process. Option E is correct because Tier 3 analysts handle the most complex work, including proactive threat hunting, advanced digital forensics, and malware reverse engineering, often feeding new detection logic back to lower tiers.

Options A and B are not essential components of the tiered analyst structure itself: a SOC manager is an administrative/leadership role rather than a tier, and a dedicated threat intelligence team is a supporting function that may be separate from or feed into the tiered model.

Exam trap

ISC2 often tests the distinction between SOC tiers and supporting roles; the trap here is that candidates mistake management or intelligence functions as part of the tiered analyst hierarchy, when only Tier 1, Tier 2, and Tier 3 analysts constitute the core escalation model.

651
MCQeasy

Which of the following is a control that can reduce the risk of a DDoS attack?

A.Access control lists
B.Load balancing
C.Encryption
D.Digital signatures
AnswerB

Load balancing distributes incoming traffic across multiple servers, preventing any single node from being overwhelmed during a volumetric flood. This directly satisfies the stem's requirement to reduce DDoS risk by absorbing and spreading attack traffic, maintaining availability even when request volume spikes far beyond what one server could handle alone.

Why this answer

Load balancing helps mitigate DDoS attacks by distributing incoming traffic across multiple servers, preventing any single server from being overwhelmed by a flood of requests. This increases the capacity and resilience of the infrastructure, making it harder for an attacker to exhaust resources. While not a complete DDoS solution, load balancing is a foundational control that reduces the impact of volumetric and application-layer attacks.

Exam trap

The trap here is that candidates may choose 'Access control lists' because ACLs sound like a security control, but they are ineffective against distributed attacks with spoofed or rotating source IPs — load balancing is the control that actually absorbs and distributes the flood.

How to eliminate wrong answers

Option A is wrong because access control lists (ACLs) filter traffic based on IP addresses or ports, but they are ineffective against DDoS attacks that use spoofed or distributed source IPs — blocking one IP does not stop thousands of others. Option C is wrong because encryption protects data confidentiality in transit but does nothing to prevent or absorb a flood of malicious traffic. Option D is wrong because digital signatures provide integrity and non-repudiation for messages, not traffic absorption or rate limiting.

652
MCQmedium

A company's security policy states that employees must wear identification badges visibly at all times while on premises. A security guard checks badges at the entrance. Which type of control is the badge check?

A.Preventive control
B.Compensating control
C.Detective control
D.Corrective control
AnswerA

Preventive controls aim to stop security incidents before they occur. The security guard checking badges at the entrance prevents unauthorized individuals from entering the premises. This is a physical preventive control. By verifying identity before allowing access, it directly stops potential security breaches.

Why this answer

The badge check by a security guard is a preventive control because it stops unauthorized individuals from entering the premises. Preventive controls are designed to avoid incidents before they happen, and this is a classic example of a physical preventive control. Other control types like detective, corrective, or compensating do not fit the scenario.

Exam trap

The trap here is thinking that any human verification is detective, but it's actually preventive because it stops access before entry.

653
MCQmedium

A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:

A.Least privilege
B.Defense in depth
C.Separation of duties
D.Need-to-know
AnswerA

RBAC enforces least privilege by granting only the permissions each job role requires, directly satisfying the stem's constraint that users hold solely the access necessary for their duties. Unlike broader models such as discretionary access control, it scopes entitlements to role definitions rather than individual discretion, minimising standing privileges.

Why this answer

RBAC grants users only the permissions required for their job roles, which is the definition of least privilege — the principle that subjects should have the minimum access necessary to perform their function.

Exam trap

CC often tests the confusion between least privilege (minimum permissions) and need-to-know (minimum information), which sound similar but apply to different domains.

How to eliminate wrong answers

Option B is wrong because defense in depth is a layered security strategy, not a permission model. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud, which is different from limiting permissions per role. Option D is wrong because need-to-know applies to information access based on relevance, whereas least privilege is broader and applies to all permissions.

654
MCQhard

Refer to the exhibit. A user from the Auditors group is unable to access the folder. What is the most likely cause?

A.The user is not a member of the Auditors group
B.A deny entry for Auditors overrides the allow
C.The Auditors group has only read permission, which is insufficient
D.The folder is encrypted
AnswerB

A deny entry for the Auditors group overrides any allow permissions granted to that user, whether directly or through other group memberships. In Windows ACL evaluation, explicit deny entries take precedence over all allow entries, so the user's effective access is blocked despite otherwise sufficient permissions.

Why this answer

In NTFS permissions, a Deny entry explicitly blocks access and takes precedence over any Allow entries, regardless of the order in which they are applied. Since the user is a member of the Auditors group, the Deny entry for that group overrides any Allow permissions the user might have individually or through other group memberships. This is the most likely cause of the access failure.

Exam trap

ISC2 often tests the principle that Deny entries override Allow entries in NTFS permissions, and the trap here is that candidates mistakenly think the order of permission entries or the most specific permission wins, rather than recognizing that Deny always takes precedence.

How to eliminate wrong answers

Option A is wrong because the user is explicitly stated to be from the Auditors group, so they are a member. Option C is wrong because even if the Auditors group has only Read permission, that would still allow the user to access the folder (read contents), but the user cannot access it at all, indicating a Deny is in effect. Option D is wrong because encryption (e.g., EFS) would not prevent access if the user has the proper decryption key; the scenario points to a permission conflict, not encryption.

655
MCQhard

During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?

A.DNS spoofing
B.ARP spoofing
C.MAC spoofing
D.IP spoofing
AnswerD

IP spoofing forges the source address field in packet headers so traffic appears to originate from a different network, matching the observed foreign source addresses. It is distinct from MAC spoofing, which alters Layer 2 addresses.

Why this answer

IP spoofing involves forging the source IP address field in packet headers so the traffic appears to originate from a different network or host. The scenario explicitly describes source IP addresses appearing to come from a different network, which is the defining symptom of IP spoofing. Attackers use it for reflection/amplification DDoS, evasion, and impersonation.

Exam trap

The trap here is confusing Layer 2 address manipulation (ARP/MAC spoofing) with Layer 3 source-address forgery (IP spoofing) — the question's phrase 'source IP address' is the decisive clue.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS responses to redirect name resolution, not the source IP in packet headers. Option B is wrong because ARP spoofing poisons the ARP cache to associate an attacker's MAC with a legitimate IP on the local subnet, affecting Layer 2 resolution rather than the IP header's source field. Option C is wrong because MAC spoofing alters the Layer 2 source MAC address, not the Layer 3 source IP address observed in captured packets.

656
MCQeasy

Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?

A.Standard user account
B.Service account
C.Admin/root account
D.Guest account
AnswerC

Admin and root accounts hold unrestricted control over systems and data, so their compromise yields immediate full impact. Separate daily-use accounts ensure routine browsing and email never expose these credentials, satisfying the strict-control requirement for the highest-risk account type.

Why this answer

Admin/root accounts have unrestricted privileges over systems, data, and configurations, making them the highest-value target for attackers — compromise grants full control. Best practice is to protect them with strict controls (MFA, privileged access workstations, just-in-time elevation) and use separate, non-privileged accounts for daily tasks like email and browsing.

Exam trap

The trap is overthinking 'service account' as the highest risk — while service accounts are risky, the exam expects admin/root as the top-tier account requiring separate daily-use accounts and strict controls.

How to eliminate wrong answers

Option A is wrong because standard user accounts have limited privileges and, while still targets, do not grant the broad control that admin/root accounts do. Option B is wrong because service accounts are high-risk in a different way (often non-interactive, hard-coded credentials), but they are not the top-tier risk that admin/root represents. Option D is wrong because guest accounts have minimal privileges by design and are typically disabled; they are not the highest-risk account type.

657
MCQhard

An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?

A.Ignore the deviation since it was done for a valid reason
B.Revert the change immediately without discussion
C.Update the baseline to match the new configuration
D.Document the change and submit it through the change control process
AnswerD

The deviation was a deliberate, justified performance fix, so reverting it blindly risks reintroducing the issue. Documenting the change and routing it through change control preserves the audit trail while allowing the baseline exception to be formally reviewed and approved.

Why this answer

The correct answer is D. When a deviation from a security baseline is introduced for a legitimate operational reason, the proper governance response is to document the change and route it through the change control process. This preserves the integrity of the baseline while allowing a formally reviewed and approved exception, ensuring the deviation is tracked, justified, and periodically reassessed rather than silently accepted or blindly reverted.

Exam trap

The trap here is the temptation to treat a 'valid reason' as sufficient justification to either ignore the deviation or update the baseline, when the exam expects recognition that any deviation must go through formal change control.

How to eliminate wrong answers

Option A is wrong because ignoring the deviation leaves an undocumented, unapproved configuration change in place, undermining the baseline's authority and auditability. Option B is wrong because reverting immediately without discussion ignores the valid performance justification and may reintroduce the original performance issue without proper review. Option C is wrong because updating the baseline to match a single server's ad-hoc change bypasses change control and could weaken the security posture for all systems if the change is not appropriate as a standard.

658
MCQmedium

An organization implements a bring-your-own-device (BYOD) policy. Which security control is most important to enforce in the BYOD policy?

A.Require complex passwords
B.Install a firewall on each device
C.Enable full disk encryption
D.Implement mobile device management (MDM) for remote wipe and policy enforcement
AnswerD

Mobile device management enforces configuration baselines, encryption and passcode requirements on personally owned devices, and provides remote wipe of corporate data when a device is lost or an employee leaves. This directly satisfies the BYOD constraint of securing organisational data on hardware the organisation does not own or fully control.

Why this answer

Mobile device management (MDM) is the most important control for a BYOD policy because it provides centralized policy enforcement, remote wipe capabilities, and device compliance monitoring. Unlike isolated controls like passwords or encryption, MDM allows the organization to enforce security policies dynamically and revoke access or wipe corporate data if a device is lost, stolen, or non-compliant.

Exam trap

ISC2 often tests the misconception that a single technical control (like encryption or passwords) is sufficient for BYOD security, when the real exam focus is on centralized management and the ability to enforce and revoke policies remotely via MDM.

How to eliminate wrong answers

Option A is wrong because requiring complex passwords alone does not protect data if the device is lost or stolen; passwords can be bypassed or guessed, and they do not provide remote wipe or policy enforcement. Option B is wrong because installing a firewall on each device is impractical in BYOD scenarios (users may disable it, and it does not protect against data leakage or device loss), and it does not address the core need for centralized control and data separation. Option C is wrong because full disk encryption protects data at rest but does not enable remote wipe, policy enforcement, or the ability to selectively wipe corporate data without affecting personal data, which is critical in BYOD environments.

659
MCQeasy

A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?

A.Risk Management Plan
B.Incident Response Plan (IRP)
C.Disaster Recovery Plan (DRP)
D.Business Continuity Plan (BCP)
AnswerC

A DRP is the documented, tested process that governs failover and activation of a standby site after a disruptive event, covering roles, sequencing and communication. It directly satisfies the stem's requirement to activate the synchronised backup site, unlike backup or continuity planning alone.

Why this answer

The Disaster Recovery Plan (DRP) specifically outlines the procedures for activating a backup site after a primary data center failure. In this scenario, the backup site is fully synchronized but requires activation, which involves steps like DNS changes, storage array failover (e.g., using synchronous replication with a quorum witness), and network reconfiguration. The DRP is the document that contains these technical recovery steps, distinguishing it from broader continuity or incident response plans.

Exam trap

ISC2 often tests the distinction between BCP and DRP by presenting a scenario where the backup site is already synchronized but needs activation, leading candidates to incorrectly choose BCP because they confuse business continuity with technical disaster recovery.

How to eliminate wrong answers

Option A is wrong because a Risk Management Plan identifies, assesses, and mitigates risks before an incident occurs; it does not contain the step-by-step activation procedures for a backup site. Option B is wrong because an Incident Response Plan (IRP) focuses on immediate containment, eradication, and recovery from security incidents (e.g., malware, data breaches), not on activating a backup data center after a natural disaster. Option D is wrong because a Business Continuity Plan (BCP) addresses maintaining critical business functions during a disruption, often through alternative work arrangements or manual processes, but it does not provide the technical failover steps for activating a backup data center.

660
MCQmedium

A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Rule-Based Access Control
AnswerB

RBAC grants permissions to roles rather than to individual users, and users receive permissions by being assigned to a role. Creating a 'Pediatric Nurse' role and assigning nurses to it directly solves the rotation and administration problem described. When a nurse moves departments, only the role assignment changes, and permissions follow automatically, reducing errors.

Why this answer

The hospital needs permissions tied to job functions rather than to individual accounts. Role-Based Access Control creates roles, assigns permissions to those roles, and then assigns users to roles, so rotating staff only requires changing the role assignment. This reduces administrative errors, supports least privilege at the role level, and scales cleanly as departments and duties change.

Exam trap

The trap here is assuming that any centralized or administrator-managed model automatically groups permissions by job function, when only RBAC assigns permissions to roles that users then occupy.

661
MCQmedium

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

A.ICMP flood
B.SYN flood
C.UDP flood
D.ARP spoofing
AnswerB

A SYN flood exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, so the server allocates half-open connection resources awaiting final ACKs that never arrive, exhausting its backlog and rendering it unresponsive.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that are never completed. This exhausts the server's connection table and backlog, making it unresponsive to legitimate traffic. It is a classic denial-of-service attack.

Exam trap

The trap here is confusing SYN flood with other flood attacks — candidates may pick UDP or ICMP flood because they see 'flood,' but only SYN flood specifically abuses the TCP three-way handshake and half-open connections.

How to eliminate wrong answers

Option A is wrong because an ICMP flood sends large volumes of ICMP echo requests (pings) to overwhelm bandwidth, not to exhaust TCP connection state. Option C is wrong because a UDP flood sends UDP packets to random ports, consuming bandwidth and forcing ICMP port-unreachable responses, but it does not involve the TCP handshake. Option D is wrong because ARP spoofing is a man-in-the-middle technique that maps an attacker's MAC to a legitimate IP, not a resource-exhaustion flood.

662
Multi-Selectmedium

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Select 2 answers
A.Hashing of passwords
B.Redundant network links
C.Encryption of data at rest
D.Regular data backups
E.Role-based access controls
AnswersC, E

Encryption of data at rest renders stored customer data unreadable without the correct cryptographic keys, directly satisfying the confidentiality requirement. If disks or backups are stolen, ciphertext remains protected, unlike plaintext storage. This control addresses the stem's constraint by preventing unauthorised disclosure of data while it resides on storage media.

Why this answer

Encryption of data at rest (C) is correct because it renders stored customer data unreadable to unauthorized parties, protecting confidentiality even if the storage media or database is compromised. Role-based access controls (E) are correct because RBAC enforces least privilege, ensuring only authorized users with the appropriate role can access customer data, directly limiting exposure. Hashing of passwords (A) protects password integrity/verification but is not a general confidentiality control for customer data, and hashes are one-way rather than reversible protection of data.

Redundant network links (B) address availability through fault tolerance, not confidentiality. Regular data backups (D) support availability and recovery, not confidentiality, since backups can themselves expose data if unprotected.

Exam trap

The trap here is confusing controls that support availability or integrity (backups, redundancy, hashing) with controls that specifically enforce confidentiality — candidates often pick backups or hashing because they 'sound secure' without mapping them to the CIA property being tested.

663
MCQmedium

Which of the following is a recommended practice for password security according to NIST SP 800-63?

A.Require frequent password changes every 30 days
B.Use a minimum of 8 characters and check against breached password lists
C.Set maximum password age to 90 days
D.Enforce complex passwords with special characters
AnswerB

NIST SP 800-63 recommends an eight-character minimum and screening new passwords against breached-password lists, blocking compromised credentials. This satisfies the stem's requirement by reflecting current guidance that favours length and breach checking over forced periodic rotation and composition rules.

Why this answer

NIST SP 800-63B recommends a minimum of 8 characters and checking new passwords against lists of commonly used or breached passwords. It also advises against arbitrary complexity rules and frequent expiration, focusing instead on length and breach checks. This approach balances usability with security by preventing weak, compromised passwords.

Exam trap

The trap is the common belief that frequent password changes and complexity requirements are best practices; the exam tests knowledge of updated NIST guidance that discourages these in favor of length and breach checks.

How to eliminate wrong answers

Option A is wrong because NIST SP 800-63B explicitly discourages frequent password changes (e.g., every 30 days) as they lead to weaker passwords and user frustration. Option C is wrong because setting a maximum password age of 90 days is also discouraged by NIST for the same reason. Option D is wrong because enforcing complex passwords with special characters is not a NIST recommendation; NIST advises against composition rules and instead promotes length and breach checks.

664
MCQhard

When implementing a role-based access control (RBAC) system, what is the primary challenge organizations face?

A.Managing password complexity
B.Ensuring users do not share passwords
C.Role explosion
D.Defining roles that align with job functions
AnswerC

As organisations accumulate roles for every permutation of job function, department and application, the number of distinct roles grows unmanageably, making assignment, review and auditing impractical. Role explosion is the primary RBAC implementation challenge, driven by attempting to model every access combination as a discrete role.

Why this answer

Role explosion is the primary challenge in RBAC because as organizations grow, the number of distinct roles can proliferate rapidly, leading to administrative overhead, complexity in role management, and potential security gaps. This occurs when roles are defined too granularly or for every unique combination of permissions, making it difficult to maintain least privilege and audit access. Proper RBAC design requires careful role engineering to minimize the number of roles while still mapping to job functions.

Exam trap

ISC2 often tests the misconception that the main difficulty in RBAC is defining roles themselves, when in fact the real operational challenge is controlling role proliferation (role explosion) after initial implementation.

How to eliminate wrong answers

Option A is wrong because managing password complexity is a concern of authentication mechanisms, not RBAC, which focuses on authorization after authentication. Option B is wrong because ensuring users do not share passwords is an authentication policy issue, unrelated to the role-based access control model. Option D is wrong because defining roles that align with job functions is actually a fundamental requirement of RBAC, not a primary challenge; the challenge arises when too many roles are created (role explosion), not from the initial definition itself.

665
MCQeasy

An organization's business continuity plan (BCP) requires that its payroll system be operational within 8 hours of a disruption, but the system can tolerate losing up to 4 hours of payroll transaction data. Which pair of metrics BEST represents these two requirements?

A.RPO = 8 hours; MTD = 4 hours
B.RTO = 4 hours; RPO = 8 hours
C.MTD = 8 hours; RTO = 4 hours
D.RTO = 8 hours; RPO = 4 hours
AnswerD

The recovery time objective (RTO) defines the maximum acceptable time to restore the payroll system after a disruption, which matches the 8-hour requirement. The recovery point objective (RPO) defines the maximum acceptable data loss measured in time, which matches the 4-hour tolerance. Together they correctly capture both the downtime and data-loss constraints stated in the BCP.

Why this answer

The recovery time objective (RTO) is the maximum acceptable time to restore a system after disruption, so the 8-hour restoration requirement maps to RTO. The recovery point objective (RPO) is the maximum acceptable data loss expressed in time, so the 4-hour data-loss tolerance maps to RPO. These two metrics together define how quickly the payroll system must return and how much payroll data the organization can afford to lose.

Exam trap

The trap here is assuming the larger time value must be the RPO, when in fact the metric is determined by what is being measured (downtime versus data loss), not by which number is bigger.

666
MCQeasy

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

A.SOC Manager
B.Tier 3
C.Tier 2
D.Tier 1
AnswerD

Tier 1 analysts perform initial alert triage, validating whether an alert is a true positive and deciding escalation to Tier 2. This matches the stem's requirement for the tier that triages and determines escalation, distinguishing it from Tier 2 investigation and Tier 3 threat hunting.

Why this answer

Tier 1 analysts are the first line of defense in a SOC, responsible for monitoring incoming alerts, performing initial triage, and deciding whether to escalate to Tier 2. They follow predefined playbooks to filter false positives and validate true positives. This role is explicitly designed for rapid alert assessment, not deep investigation or management.

Exam trap

The trap here is confusing the roles of different SOC tiers, especially assuming that higher tiers (Tier 2 or 3) handle initial triage because they are more skilled, when in fact Tier 1 is specifically designed for that first-line responsibility.

How to eliminate wrong answers

Option A is wrong because the SOC Manager oversees the entire SOC, including staffing, processes, and reporting, but does not perform hands-on alert triage. Option B is wrong because Tier 3 analysts are the most advanced, focusing on threat hunting, malware analysis, and complex incident response, not initial triage. Option C is wrong because Tier 2 analysts handle escalated incidents requiring deeper investigation, not the first-pass triage of raw alerts.

667
MCQmedium

You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?

A.Service Level Agreement (SLA)
B.Mean Time Between Failures (MTBF)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerC

Recovery Point Objective defines the maximum tolerable data loss measured in time, directly satisfying the 15-minute constraint. Because it governs backup frequency, an RPO of 15 minutes or less ensures no more than a quarter-hour of transactions is lost. Recovery Time Objective instead addresses downtime duration, which the stem does not specify.

Why this answer

Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. A requirement that data loss must not exceed 15 minutes directly translates to an RPO of 15 minutes. RPO determines how frequently backups or snapshots must be taken to meet the business continuity requirement.

Exam trap

The trap is confusing RPO with RTO; candidates often mix up the two, but RPO is about data loss (how much data you can afford to lose), while RTO is about downtime (how long you can afford to be down).

How to eliminate wrong answers

Option A is wrong because an SLA is a broader contract that defines service expectations, including uptime, performance, and support, but it does not specifically address data loss tolerance. Option B is wrong because MTBF (Mean Time Between Failures) is a reliability metric that predicts the average time between system failures, not the amount of data that can be lost. Option D is wrong because RTO (Recovery Time Objective) defines the maximum acceptable downtime after a failure, i.e., how quickly the system must be restored, not how much data can be lost.

668
MCQmedium

A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?

A.Wipe the host and reinstall OS
B.Preserve forensic evidence and analyze
C.Reimage the host from backup
D.Notify law enforcement
AnswerB

Preserving volatile memory and disk artefacts captures command-and-control indicators, persistence mechanisms and lateral-movement evidence before remediation destroys them. This satisfies the stem's sequencing constraint: after containment, evidence collection must precede eradication, otherwise attribution and scope assessment become impossible.

Why this answer

Preserving forensic evidence and analyzing the host is the correct next step because incident response methodology (e.g., NIST SP 800-61) requires containment followed by evidence collection and analysis to determine the scope of compromise, identify indicators of compromise (IOCs), and understand the attack vector. Wiping or reimaging destroys volatile data (e.g., memory, running processes, network connections) and artifacts (e.g., registry keys, prefetch files, event logs) that are critical for attribution and remediation. Analysis may involve memory forensics (using tools like Volatility) and disk forensics to extract malware samples, C2 communication logs, and lateral movement traces.

Exam trap

ISC2 often tests the misconception that immediate containment (like wiping or reimaging) is the priority, but the trap here is that the CC exam emphasizes the incident response process order: isolate, then preserve evidence, then analyze, then remediate — skipping evidence preservation violates standard forensic procedures.

How to eliminate wrong answers

Option A is wrong because wiping the host and reinstalling the OS destroys all forensic evidence, preventing root cause analysis and potentially allowing the attacker to persist if the infection vector is not identified. Option C is wrong because reimaging from backup may reintroduce the same vulnerability or malware if the backup is also compromised, and it skips the critical step of evidence preservation and analysis. Option D is wrong because notifying law enforcement is premature before internal investigation confirms the incident's nature and scope; law enforcement involvement typically occurs after evidence is preserved and a decision is made to pursue legal action, not as an immediate next step.

669
MCQhard

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

A.Risk acceptance
B.Risk transfer
C.Due care
D.Due diligence
AnswerD

Due diligence is the investigation and verification of a vendor's security controls, financial standing and background before entering a contract. The stem describes exactly that: assessing controls and performing background checks on a prospective processor. It satisfies the pre-engagement evaluation constraint, distinguishing it from ongoing monitoring or contractual enforcement.

Why this answer

Due diligence is the ongoing process of investigation, assessment, and verification — performing a thorough security assessment and background checks on a vendor before engaging them is the textbook definition of exercising due diligence. It demonstrates that the organization took reasonable steps to understand and evaluate the risks involved. Due care, by contrast, is the ongoing action of maintaining that standard once the relationship exists.

Exam trap

The trap is the classic due diligence vs. due care confusion — candidates often select due care because both sound like 'being careful,' but the exam expects you to recognize that investigation/assessment is due diligence and ongoing protection is due care.

How to eliminate wrong answers

Option A is wrong because risk acceptance is a deliberate decision to acknowledge a risk and take no action — the opposite of performing an assessment. Option B is wrong because risk transfer shifts the financial impact of a risk to a third party (e.g., via insurance or contract), which is not what an assessment accomplishes. Option C is wrong because due care refers to the ongoing duty to act reasonably and maintain safeguards after the decision is made, whereas the question describes the pre-engagement investigation phase.

670
MCQmedium

A company uses WPA2-Enterprise for wireless authentication. What additional security measure should be implemented to protect against rogue access points?

A.Enable MAC filtering
B.Deploy a wireless intrusion prevention system (WIPS)
C.Implement 802.1X with mutual authentication
D.Use WPA3
AnswerB

A WIPS continuously monitors the radio spectrum, detects rogue and evil-twin access points, and can automatically contain them. WPA2-Enterprise only authenticates legitimate clients to authorised APs, so it cannot detect or block rogue APs, which the WIPS satisfies.

Why this answer

WPA2-Enterprise uses 802.1X for authentication, but it does not inherently detect or block rogue access points (APs) that mimic legitimate SSIDs. A Wireless Intrusion Prevention System (WIPS) continuously monitors the RF spectrum, identifies unauthorized APs by analyzing beacon frames, probe responses, and MAC addresses, and can automatically contain them by sending deauthentication frames or alerting administrators. This is the most direct and effective measure to protect against rogue APs in an enterprise WLAN.

Exam trap

ISC2 often tests the misconception that WPA2-Enterprise or 802.1X alone can prevent rogue APs, but the trap is that these protocols authenticate users and servers, not the physical AP device itself, leaving the network vulnerable to rogue APs that broadcast the same SSID.

How to eliminate wrong answers

Option A is wrong because MAC filtering is a weak, static access control that can be easily bypassed by MAC spoofing and does not detect or prevent rogue APs from operating. Option C is wrong because 802.1X with mutual authentication (EAP-TLS, for example) already authenticates both the client and the RADIUS server, but it does not monitor the airwaves for unauthorized APs; a rogue AP can still broadcast the same SSID and trick clients into connecting before any 802.1X exchange completes. Option D is wrong because WPA3, while more secure than WPA2, still does not include built-in rogue AP detection or containment; it only improves encryption and authentication (e.g., SAE) but does not replace the need for a dedicated WIPS.

671
Multi-Selecthard

A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)

Select 2 answers
A.The traffic uses domain fronting to hide the true destination.
B.The connections are initiated by a server process running as a system service.
C.The traffic is encrypted and uses a self-signed certificate.
D.The traffic occurs at regular intervals with consistent packet sizes.
E.The external IP address is associated with a known cloud service provider.
AnswersA, D

Domain fronting is a technique where the SNI and HTTP Host header differ, allowing traffic to appear as if it is destined for a legitimate domain while actually communicating with a different server. This is commonly used by malware to evade detection. Its presence is a strong indicator of malicious C2 activity, making this a correct characteristic.

Why this answer

Beaconing behavior, such as regular intervals with consistent packet sizes, is a hallmark of automated C2 communication. Domain fronting, which disguises the true destination by manipulating SNI and Host headers, is another technique frequently used by malware to evade network defenses. Both are strong indicators of malicious C2 activity, whereas cloud-hosted IPs, service-initiated connections, and self-signed certificates can also be legitimate.

Exam trap

The trap here is assuming that any encrypted traffic to an unfamiliar IP is malicious, when encryption and self-signed certificates are also common in legitimate internal and cloud services.

672
MCQeasy

A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?

A.Least privilege
B.Authentication
C.Non-repudiation
D.Accountability
AnswerA

Least privilege grants users only the minimum access needed for their role. Granting access beyond job function directly violates this principle, since permissions exceed what the user's duties require. The other principles address different concerns, such as separation of duties or defence in depth, not excessive entitlement.

Why this answer

The principle of least privilege states that users should be granted only the minimum access rights necessary to perform their job functions. Granting access to files beyond that scope directly violates this principle. This is a foundational access control concept in security frameworks like ISO 27001 and NIST.

Exam trap

The trap here is confusing least privilege with accountability or authentication; candidates may pick accountability because they associate 'access' with logging, but the question is about the scope of permissions granted.

How to eliminate wrong answers

Option B is wrong because authentication is the process of verifying a user's identity (e.g., via password, biometrics), not about the scope of access granted after identity is confirmed. Option C is wrong because non-repudiation ensures a party cannot deny having performed an action, typically via digital signatures or audit logs, which is unrelated to excessive access rights. Option D is wrong because accountability refers to tracing actions to a specific individual through logging and monitoring, not to limiting the breadth of permissions.

673
MCQeasy

An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?

A.Incident Response Plan (IRP)
B.Disaster Recovery Plan (DRP)
C.Risk Assessment
D.Business Impact Analysis (BIA)
AnswerD

A Business Impact Analysis identifies critical business functions and quantifies the operational and financial impact of their disruption, plus dependencies and recovery priorities. It is the BCP process that satisfies the stem's requirement to identify functions and disruption impact.

Why this answer

A Business Impact Analysis (BIA) identifies critical business functions, dependencies, and the impact of disruptions, providing metrics like MTD, RTO, and RPO.

674
Multi-Selecthard

Which THREE of the following are considered methods to ensure accountability in a system?

Select 3 answers
A.Data encryption
B.Audit logs
C.Digital signatures
D.Intrusion prevention system
E.User authentication
AnswersB, C, E

Audit logs record who performed which action, when and from where, creating a traceable record that attributes activity to specific identities. This traceability is what enforces accountability, satisfying the requirement for a method that ensures users can be held responsible.

Why this answer

Accountability means being able to attribute actions to a specific identity and prove what occurred, so audit logs (B) are correct because they record who did what, when, and where, providing the traceable evidence needed to hold users responsible. Digital signatures (C) are correct because they provide non-repudiation, cryptographically binding a signer to a message or transaction so they cannot later deny having performed it. User authentication (E) is correct because verifying a user's identity via credentials, tokens, or biometrics is the prerequisite that ties subsequent actions to a specific accountable principal.

Data encryption (A) protects confidentiality of data at rest or in transit but does not by itself attribute actions to an identity, so it does not ensure accountability. An intrusion prevention system (D) detects and blocks malicious traffic to protect availability and integrity, but it is a preventive/detective control rather than a mechanism for attributing and proving user actions.

675
MCQeasy

Which TCP segment is sent to initiate the three-way handshake?

A.ACK
B.SYN-ACK
C.FIN
D.SYN
AnswerD

SYN initiates the three-way handshake by carrying the synchronise flag with an initial sequence number, prompting the server to reply with SYN-ACK before the client's ACK completes connection setup. This directly satisfies the stem's requirement for the segment that starts the handshake, distinguishing it from data or teardown segments.

Why this answer

The TCP three-way handshake begins with the client sending a SYN segment to the server to request a connection and synchronize sequence numbers. The server responds with SYN-ACK, and the client completes with ACK. Therefore, the segment that initiates the handshake is SYN.

Exam trap

The trap is confusing the order of the handshake: candidates may pick SYN-ACK because it contains 'SYN', but the question asks for the segment that initiates the handshake, which is the pure SYN from the client.

How to eliminate wrong answers

Option A is wrong because ACK is the final segment in the handshake (and is used throughout the session for acknowledgment), not the initiator. Option B is wrong because SYN-ACK is the server's response to the initial SYN, not the first segment. Option C is wrong because FIN is used to gracefully terminate an established TCP connection, not to start one.

Page 8

Page 9 of 14

Page 10