Courseiva

CCNA Security Principles Questions

75 of 168 questions · Page 1/3 · Security Principles · Answers revealed

1
MCQeasy

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

A.Risk acceptance
B.Risk mitigation
C.Risk avoidance
D.Risk transfer
AnswerB

Risk mitigation applies controls that lower either the likelihood or the impact of a threat exploiting a vulnerability. It differs from avoidance, transference and acceptance, which respectively eliminate the activity, shift the loss, or retain the exposure.

Why this answer

Risk mitigation involves implementing security controls to reduce either the likelihood or the impact of a risk. This is the most common risk management strategy because it addresses the risk directly rather than shifting or avoiding it. Examples include patching vulnerabilities, deploying firewalls, or enforcing MFA to lower the probability of exploitation.

Exam trap

The trap here is confusing mitigation with avoidance or acceptance; candidates often pick 'avoidance' when the question mentions reducing likelihood, but avoidance means eliminating the activity altogether.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action, often when the cost of mitigation exceeds the potential loss. Option C is wrong because risk avoidance means eliminating the activity or asset that introduces the risk entirely, such as discontinuing a service. Option D is wrong because risk transfer shifts the financial impact to a third party, typically through insurance or outsourcing, without reducing the likelihood or impact itself.

2
Multi-Selectmedium

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Select 2 answers
A.Data may be posted on the public website
B.Access to data must be restricted to authorized personnel only
C.Data can be shared with any vendor without a contract
D.Data must be encrypted when stored on servers
E.Data must be deleted after 30 days regardless of business need
AnswersB, D

Confidential data demands need-to-know handling, so restricting access to authorised personnel only enforces least privilege and prevents unauthorised disclosure. This complements the encryption mandate by controlling who may reach the data at all, satisfying the policy's confidentiality requirement beyond cryptographic protection alone.

Why this answer

Option B is correct because Confidential data must be restricted to authorized personnel only, which is a fundamental access control requirement for this classification level. Option D is correct because the scenario explicitly states that Confidential data must be encrypted at rest, and encryption when stored on servers directly satisfies that at-rest requirement. Options A, C, and E do not belong: posting Confidential data on a public website would expose it to unauthorized disclosure, sharing it with any vendor without a contract violates third-party handling and confidentiality obligations, and deleting it after 30 days regardless of business need is an arbitrary retention rule not implied by the encryption or access-control requirements.

Exam trap

CC often tests data classification handling, and candidates might confuse retention requirements with confidentiality requirements, or incorrectly think that confidential data can be shared freely with vendors.

3
MCQmedium

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

A.Availability
B.Integrity
C.Accountability
D.Confidentiality
AnswerA

Redundant servers let a service continue functioning when one fails, directly satisfying the requirement that services remain operational despite failure. Availability is the principle concerned with uptime and continuous access, so eliminating single points of failure protects it rather than integrity, confidentiality or non-repudiation.

Why this answer

Redundant server infrastructure ensures that services remain operational even if one server fails, which directly supports the principle of availability. Availability ensures that systems and data are accessible to authorized users when needed.

Exam trap

The trap here is confusing availability with integrity or confidentiality, as candidates might think redundancy also protects data integrity, but it primarily ensures uptime.

How to eliminate wrong answers

Option B is wrong because integrity ensures data is not modified or altered without authorization, which is not the focus of redundancy. Option C is wrong because accountability ensures actions can be traced to a specific entity, which is unrelated to redundancy. Option D is wrong because confidentiality ensures data is not disclosed to unauthorized parties, which is not addressed by redundancy.

4
MCQmedium

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

A.Availability
B.Confidentiality
C.Non-repudiation
D.Integrity
AnswerD

Digital signatures use asymmetric cryptography to verify that software updates remain unaltered, detecting any modification between publisher and recipient. This directly addresses integrity, the CIA component concerned with data remaining accurate and trustworthy, rather than confidentiality or availability.

Why this answer

Digital signatures use cryptographic hashing and asymmetric encryption to verify that data has not been altered in transit or at rest, which directly addresses the Integrity pillar of the CIA triad. If even a single bit of the software update changes, the signature verification fails, proving tampering. While signatures also provide authentication and non-repudiation, the question specifically asks which CIA triad aspect is primarily addressed, and integrity is the correct mapping.

Exam trap

CC often tests the overlap between integrity and non-repudiation for digital signatures, tempting candidates to choose non-repudiation even though the question asks specifically about the CIA triad.

How to eliminate wrong answers

Option A is wrong because availability concerns ensuring systems and data are accessible when needed (e.g., redundancy, DDoS protection), which digital signatures do not provide. Option B is wrong because confidentiality involves preventing unauthorized disclosure, typically via encryption; digital signatures do not hide data, they verify it. Option C is wrong because non-repudiation is a security property (proving the signer cannot deny signing) but it is not one of the three CIA triad pillars, so it cannot be the 'aspect of the CIA triad' being addressed.

5
MCQmedium

What is the primary purpose of a digital signature?

A.Ensure data confidentiality
B.Control access to resources
C.Encrypt data at rest
D.Provide data integrity and non-repudiation
AnswerD

A digital signature uses the sender's private key to create a cryptographic hash of the message, letting the recipient verify the data was not altered and binding the sender to it. This satisfies the stem's requirement for both integrity and non-repudiation, since only the private key holder could have produced that signature.

Why this answer

Digital signatures provide integrity (detect tampering) and non-repudiation (proof of origin).

6
MCQmedium

A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerA

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. Encrypting patient records at rest and in transit, combined with role-based access controls, directly prevents unauthorized viewing or exposure of sensitive health data. This aligns with the architect's goal of protecting patient information from improper disclosure, making confidentiality the principle being addressed.

Why this answer

The architect's measures—encrypting patient records at rest and in transit and restricting access by job roles—are classic controls for protecting confidentiality. Confidentiality focuses on preventing unauthorized disclosure of information. While integrity and availability are also part of the CIA triad, the scenario's emphasis on encryption and access restrictions points specifically to confidentiality.

Exam trap

The trap here is confusing the CIA triad components by assuming that any security control automatically addresses all three, rather than identifying the specific principle targeted by encryption and access controls.

7
MCQmedium

A healthcare organization wants to ensure that only authorized clinicians can view patient records, while also maintaining a detailed log of every access for compliance audits. Which security principle is primarily being addressed by restricting access and recording all access attempts?

A.Confidentiality
B.Integrity
C.Accountability
D.Availability
AnswerA

Confidentiality ensures that information is not disclosed to unauthorized individuals. By restricting access to only authorized clinicians and logging all access, the organization is protecting patient records from unauthorized disclosure. The logging supports auditability but the core principle is confidentiality, as it directly prevents unauthorized viewing of sensitive data.

Why this answer

Confidentiality is the principle that ensures information is not disclosed to unauthorized individuals. Restricting access to authorized clinicians directly supports confidentiality by preventing unauthorized viewing of patient records. Logging access attempts supports accountability and auditability, but the core security objective here is to protect the confidentiality of sensitive health information.

Exam trap

The trap here is confusing confidentiality with accountability because logging is mentioned, but the primary goal is to prevent unauthorized disclosure, which is confidentiality.

8
MCQmedium

A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?

A.Separation of duties
B.Least privilege
C.Job rotation
D.Defense in depth
AnswerA

Separation of duties divides a critical task among multiple people so that no single individual can complete it without detection or collusion. Here, creating a vendor payment and approving it are deliberately assigned to two different employees, preventing one person from initiating and authorizing a fraudulent payment. This directly matches the policy's intent and is a classic detective and preventive administrative control in financial and security operations.

Why this answer

The policy prevents any single employee from completing a sensitive transaction end to end by requiring two different people to create and approve a vendor payment. That is separation of duties, an administrative control that limits the opportunity for fraud and error. Least privilege limits what each user can access, defense in depth layers controls, and job rotation changes assignments over time; none of those captures the requirement that two distinct people must be involved in one process.

Exam trap

The trap here is confusing separation of duties with least privilege, since both restrict what a user can do, but only separation of duties requires two different people in one workflow.

9
MCQmedium

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

A.Threat
B.Risk
C.Control
D.Vulnerability
AnswerB

Risk is the combination of a vulnerability (the known server flaw), a threat (the actor who could exploit it) and the resulting potential for loss. Neither element alone constitutes risk; their pairing with impact is what the stem describes, making risk the accurate term rather than vulnerability or threat in isolation.

Why this answer

Risk is the combination of a threat exploiting a vulnerability, potentially leading to harm. Here, a threat actor could exploit a known vulnerability to gain unauthorized access, which represents a risk.

Exam trap

CC often tests the distinction between threat, vulnerability, and risk, so candidates might choose 'vulnerability' or 'threat' instead of recognizing that the combination is risk.

How to eliminate wrong answers

Option A is wrong because a threat is a potential cause of an incident, but it does not include the vulnerability. Option C is wrong because a control is a safeguard that mitigates risk, not the combination of threat and vulnerability. Option D is wrong because a vulnerability is a weakness, but it alone does not constitute risk; risk requires a threat to exploit it.

10
MCQmedium

Which of the following best describes a vulnerability in the context of risk management?

A.The likelihood that a threat will exploit a weakness
B.A measure that reduces risk
C.A weakness that can be exploited by a threat
D.A potential cause of an unwanted incident
AnswerC

A vulnerability is an inherent weakness or flaw in a system, configuration or process that a threat actor could exploit to cause harm. It is distinct from a threat (the potential actor or event) and from risk, which combines likelihood and impact.

Why this answer

In risk management frameworks such as ISO 27005 and NIST SP 800-30, a vulnerability is formally defined as a weakness in an asset, system, or control that a threat can exploit to cause harm. Option C captures this exactly: it is the weakness itself, not the probability of exploitation, not a control, and not the threat source. This distinction matters because risk is typically calculated as a function of threat, vulnerability, and impact — the vulnerability is the intrinsic flaw, while likelihood arises from the interaction between threat and vulnerability.

Exam trap

The trap here is confusing the definition of a vulnerability with that of a threat or likelihood, as many candidates conflate 'weakness' with 'probability' or 'cause' under exam pressure.

How to eliminate wrong answers

Option A is wrong because it describes likelihood (or probability) of exploitation, which is a component of risk estimation, not the vulnerability itself. Option B is wrong because a measure that reduces risk is the definition of a security control or countermeasure, not a vulnerability. Option D is wrong because a potential cause of an unwanted incident describes a threat (or threat source), which is distinct from the vulnerability it may exploit.

11
MCQeasy

Which security principle ensures that data cannot be accessed by unauthorized individuals?

A.Integrity
B.Confidentiality
C.Non-repudiation
D.Availability
AnswerB

Confidentiality directly prevents unauthorised disclosure, ensuring data is readable only by approved parties. It is the principle that satisfies the stem's requirement that data cannot be accessed by unauthorised individuals, distinct from integrity, which protects accuracy, and availability, which protects timely access.

Why this answer

Confidentiality ensures that data is not disclosed to unauthorized individuals, systems, or processes.

12
MCQeasy

Which authentication type is a smart card an example of?

A.Type 1 (knowledge)
B.Type 2 (possession)
C.Type 3 (inherence)
D.Multi-factor
AnswerB

A smart card is a physical token you must possess and present, making it something you have. That possession factor satisfies the stem's Type 2 constraint, distinguishing it from knowledge (Type 1) and biometric (Type 3) authentication.

Why this answer

A smart card is a physical token that the user must possess, which maps directly to Type 2 authentication (something you have). The three classic authentication factors are Type 1 (something you know, like a password), Type 2 (something you have, like a smart card or token), and Type 3 (something you are, like a fingerprint). Because the smart card is a physical object held by the user, it is the canonical example of possession-based authentication.

Exam trap

The trap here is confusing a single authentication factor (possession) with multi-factor authentication, causing candidates to select 'Multi-factor' simply because smart cards are often used in MFA deployments.

How to eliminate wrong answers

Option A is wrong because Type 1 (knowledge) refers to something memorized such as a password or PIN, not a physical device. Option C is wrong because Type 3 (inherence) refers to a biometric trait such as a fingerprint or retina scan, which the smart card itself is not. Option D is wrong because multi-factor requires combining two or more different factor types (e.g., smart card plus PIN); a smart card alone is only a single factor, so it is not itself an example of multi-factor authentication.

13
MCQeasy

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

A.Confidential
B.Public
C.Internal
D.Restricted
AnswerD

Restricted classification applies to information whose disclosure would cause catastrophic harm, demanding the strictest controls. It sits above Confidential, Internal and Public in sensitivity, so it satisfies the stem's requirement for the highest protection level reserved for catastrophic-impact data.

Why this answer

'Restricted' is the highest data classification level in most frameworks, reserved for information whose unauthorized disclosure could cause catastrophic harm to an organization, such as trade secrets, national security data, or highly sensitive personal information. It typically mandates the strictest controls, including encryption, need-to-know access, and often regulatory compliance requirements.

Exam trap

The trap here is confusing 'Confidential' with 'Restricted'; many candidates assume Confidential is the highest level, but exam frameworks often place Restricted above it for catastrophic harm.

How to eliminate wrong answers

Option A is wrong because 'Confidential' is a high level but typically below 'Restricted'; confidential data may cause serious harm but not catastrophic harm. Option B is wrong because 'Public' data is intended for public consumption and requires minimal protection. Option C is wrong because 'Internal' data is for internal use only and requires moderate protection, far below the catastrophic-harm threshold.

14
Multi-Selecteasy

Which TWO of the following are examples of integrity controls? (Select TWO)

Select 2 answers
A.Redundancy
B.Digital signatures
C.Firewalls
D.Encryption
E.Hashing
AnswersB, E

Digital signatures verify that data has not been altered in transit and authenticate the signer, directly detecting unauthorised modification. This satisfies the stem's integrity-control criterion because any change to the signed content invalidates the signature, unlike confidentiality controls such as encryption.

Why this answer

Digital signatures (B) are an integrity control because they use asymmetric cryptography to create a verifiable value over a message, allowing the recipient to detect any modification to the data and confirm the signer's identity. Hashing (E) is also an integrity control because a cryptographic hash function such as SHA-256 produces a fixed-length digest that changes if even one bit of the input changes, enabling detection of unauthorized alteration. Redundancy (A) primarily supports availability by duplicating components or data, not by detecting modification.

Firewalls (C) are network access controls that enforce confidentiality and availability boundaries rather than data integrity. Encryption (D) is chiefly a confidentiality control, since it protects data from disclosure, although it may incidentally hinder tampering.

15
MCQmedium

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

A.Biometric authentication
B.Two-step verification using same factor
C.Multi-factor authentication
D.Single-factor authentication
AnswerC

Multi-factor authentication requires two or more distinct credential categories: something you know (the password) plus something you possess (the one-time passcode generated by the mobile authenticator app). Because the factors span separate categories rather than repeating one, the login satisfies the stem's definition of MFA.

Why this answer

Using a password (something you know) and a one-time passcode from a mobile authenticator app (something you have) combines two different authentication factors: knowledge and possession. This is the definition of multi-factor authentication (MFA).

Exam trap

CC often tests the difference between multi-factor authentication and two-step verification, where two-step verification might use the same factor twice, so candidates might incorrectly choose 'two-step verification using same factor'.

How to eliminate wrong answers

Option A is wrong because biometric authentication involves something you are (e.g., fingerprint), which is not used here. Option B is wrong because two-step verification using the same factor would mean both steps use the same factor type (e.g., two passwords), but here the factors are different. Option D is wrong because single-factor authentication uses only one factor, but here two factors are used.

16
MCQhard

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

A.Risk transfer
B.Risk avoidance
C.Risk mitigation
D.Risk acceptance
AnswerD

Accepting the risk means the organisation acknowledges the legacy system's unpatched exposure and consciously chooses to tolerate it because continued operation outweighs the potential loss. No control is applied to reduce it; the residual risk is formally retained.

Why this answer

Risk acceptance is the deliberate decision to acknowledge a risk and take no action to reduce it, typically because the cost of mitigation outweighs the benefit or because the risk is unavoidable. In this scenario, the organization recognizes the vulnerability in the legacy system but chooses to continue operating it due to critical business needs, which is a textbook example of risk acceptance. This is a formal risk response strategy where the organization documents the decision and may implement compensating controls, but does not eliminate or transfer the risk.

Exam trap

The trap here is confusing risk acceptance with risk mitigation or avoidance, especially when the scenario mentions 'cannot be patched'—candidates might think that doing nothing is negligence, but in risk management, a documented decision to accept is a valid strategy. The exam often tests whether you recognize that acceptance is a conscious choice, not a failure to act.

How to eliminate wrong answers

Option A is wrong because risk transfer involves shifting the risk to a third party, such as purchasing cyber insurance or outsourcing the risky activity, which is not happening here. Option B is wrong because risk avoidance means eliminating the risk by discontinuing the activity or system entirely, whereas the organization is continuing to use the legacy system. Option C is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of the risk, such as patching or adding compensating controls, but the scenario states the system cannot be patched and the organization is simply accepting the risk.

17
MCQmedium

A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?

A.Public data
B.Confidential business data
C.Internal data
D.Sensitive PII
AnswerD

Names and addresses alone are ordinary PII, but pairing them with Social Security numbers creates data that enables identity theft and financial fraud. That combination meets the definition of sensitive PII, so the breach compromised sensitive PII rather than merely personal or public information.

Why this answer

Names, addresses, and Social Security numbers are the textbook definition of Sensitive PII (Personally Identifiable Information) because they can uniquely identify an individual and, in the case of SSNs, enable identity theft. SSNs are considered highly sensitive regulated data under laws such as GLBA and various state breach notification statutes. Therefore the compromised data falls squarely into the Sensitive PII category rather than any business or public classification.

Exam trap

The trap is treating any customer name or address as merely 'internal' or 'confidential business data' and missing that the presence of SSNs elevates the classification to Sensitive PII with regulatory consequences.

How to eliminate wrong answers

Option A is wrong because public data is information intentionally released to the public (e.g., marketing materials, published reports) and carries no confidentiality obligation. Option B is wrong because confidential business data refers to internal trade secrets, financials, or strategy, not customer identity records. Option C is wrong because internal data is information meant only for employees (e.g., internal memos) and does not by itself include regulated personal identifiers like SSNs.

18
Multi-Selecthard

An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?

Select 3 answers
A.Patching known vulnerabilities
B.Installing a firewall
C.Purchasing cyber insurance
D.Conducting security awareness training
E.Discontinuing a business process
AnswersA, B, D

Patching known vulnerabilities removes an existing weakness an attacker could exploit, reducing the likelihood of a successful compromise. This is risk mitigation because it lowers inherent risk before any incident occurs, satisfying the stem's requirement for an action that reduces risk rather than transferring, avoiding or accepting it.

Why this answer

Patching known vulnerabilities (A) is a risk mitigation action because it reduces the likelihood that an attacker can exploit a known weakness, directly lowering the probability of a successful compromise. Installing a firewall (B) mitigates risk by filtering and controlling network traffic, thereby reducing exposure to unauthorized access and certain network-based attacks. Conducting security awareness training (D) mitigates risk by reducing the likelihood that users will fall for phishing, social engineering, or unsafe practices, which addresses the human factor in security incidents.

Purchasing cyber insurance (C) is risk transference, not mitigation, because it shifts financial impact to an insurer rather than reducing the likelihood or impact of the event itself. Discontinuing a business process (E) is risk avoidance, since it eliminates the activity that creates the risk instead of reducing it.

Exam trap

CC often tests the confusion between mitigation and transference/avoidance — candidates must remember insurance transfers risk and discontinuing a process avoids it, neither of which reduces the risk itself.

19
Multi-Selecthard

A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)

Select 3 answers
A.Risk ignorance
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
E.Risk mitigation
AnswersB, D, E

Eliminating the activity that introduces the risk, such as removing the vulnerable component.

Why this answer

Risk avoidance (B) is correct because it involves eliminating the vulnerability by not deploying the cloud application or removing the vulnerable component entirely, thus preventing any possibility of unauthorized access to sensitive data. This strategy is appropriate when the risk exceeds the organization's risk appetite and cannot be effectively reduced through other means.

Exam trap

A common trap is the distinction between risk acceptance and risk ignorance. Candidates mistakenly think 'doing nothing' is a valid strategy, but acceptance requires formal documentation and approval from management, not simply ignoring the risk.

20
MCQeasy

A hospital's IT department is choosing a security control to protect patient records. The control must render data unreadable to anyone who does not hold the cryptographic key, even if the storage media is stolen. Which type of control BEST meets this requirement?

A.Encryption of the data at rest
B.Role-based access control on the records
C.Full database activity monitoring
D.Daily offsite backup of the database
AnswerA

Encryption at rest transforms stored data into ciphertext using a cryptographic key, so stolen media reveals nothing usable without that key. This directly satisfies the hospital's requirement and supports the confidentiality objective of the CIA triad. It is a preventive, technical control applied to the data itself rather than to physical access or user behaviour.

Why this answer

The requirement is that stored records stay unreadable without the cryptographic key, which is precisely what encryption at rest delivers. Access control, monitoring, and backups all have security value, but none of them transform the data itself, so a thief holding the physical media could still read every record. Only encryption makes the stolen media useless to an attacker lacking the key.

Exam trap

The trap here is assuming that strong access control or monitoring protects data on stolen media, when only cryptographic transformation of the data itself does.

21
MCQeasy

An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Full-disk encryption renders stored data unreadable without the decryption key, so a stolen laptop's contents cannot be disclosed. This directly protects confidentiality, the CIA element concerned with preventing unauthorised disclosure, rather than integrity or availability.

Why this answer

Full-disk encryption protects data at rest so that if a laptop is lost or stolen, the data cannot be read without the decryption key. This directly safeguards confidentiality, ensuring only authorized parties can access the information. Encryption is fundamentally a confidentiality control.

Exam trap

The trap is assuming encryption covers integrity or availability — candidates must recall that encryption is a confidentiality control, and integrity requires hashing/signatures while availability requires redundancy and uptime measures.

How to eliminate wrong answers

Option A is wrong because non-repudiation is about proving that a party performed an action (typically via digital signatures), which encryption at rest does not provide. Option B is wrong because integrity ensures data has not been altered — encryption alone does not detect tampering (hashing or MACs do). Option C is wrong because availability ensures data and systems are accessible when needed; encryption can actually hinder availability if keys are lost, so it does not primarily address it.

22
MCQhard

An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:

A.Data classification
B.Data retention
C.Data obfuscation
D.Data masking
AnswerA

Assigning the Confidential label is itself the act of data classification, which then drives the mandated encryption controls. Classification categorises information by sensitivity so that handling requirements, such as encryption at rest and in transit, are applied proportionately.

Why this answer

Labeling data as 'Confidential' and applying handling requirements like encryption at rest and in transit is data classification — the process of categorizing data by sensitivity to determine appropriate protection. The label drives the controls, which is the essence of classification.

Exam trap

CC often tests the confusion between classification (categorizing by sensitivity) and the controls it triggers (encryption, masking, retention) — candidates must identify classification as the labeling/categorization act itself.

How to eliminate wrong answers

Option B is wrong because data retention defines how long data is kept and when it is destroyed, not how it is labeled or protected. Option C is wrong because data obfuscation is a technique to make data unintelligible (e.g., encryption, tokenization) — it is a control, not the act of categorizing sensitivity. Option D is wrong because data masking replaces sensitive values with fictitious ones (e.g., showing only the last four digits of a card), which is a specific protection technique, not the classification process itself.

23
MCQmedium

A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?

A.Password and security question
B.OTP token and mobile authenticator app
C.Smart card and PIN
D.Fingerprint and retina scan
AnswerC

A smart card supplies a possession factor, something the user has, while the PIN supplies a knowledge factor, something the user knows. Combining them pairs two genuinely distinct categories, which is what multi-factor authentication demands; two knowledge factors alone would not qualify.

Why this answer

MFA requires factors from different categories: something you know, something you have, and something you are. A smart card is something you have (a physical token), and a PIN is something you know — two distinct factor types, making this a valid MFA combination.

Exam trap

CC often tests whether candidates recognize that two items from the same factor category (two knowledge items, two possession items, or two biometrics) do not constitute MFA — the factors must be of different types.

How to eliminate wrong answers

Option A is wrong because a password and a security question are both 'something you know' — the same factor category, so it is single-factor, not MFA. Option B is wrong because an OTP token and a mobile authenticator app are both 'something you have' (possession factors), so they do not constitute two different factors. Option D is wrong because a fingerprint and a retina scan are both 'something you are' (biometric/inherence factors), again the same category.

24
MCQmedium

A security team decides to implement multi-factor authentication for all remote access. Which combination of factors would constitute multi-factor authentication?

A.Fingerprint scan and retina scan
B.Two different passwords
C.Password and PIN
D.Smart card and fingerprint scan
AnswerD

Multi-factor authentication requires factors from different categories: something you have, know, or are. A smart card (possession) plus a fingerprint scan (inherence) combines two distinct categories, satisfying the requirement. Two passwords or two biometrics would not qualify.

Why this answer

Multi-factor authentication requires combining factors from at least two different categories: something you know (password, PIN), something you have (smart card, token), and something you are (biometrics). A smart card (something you have) plus a fingerprint scan (something you are) satisfies this requirement by combining two distinct factor types. This is the only option that crosses factor categories.

Exam trap

CC often tests whether candidates understand that MFA requires different factor categories, tempting them to pick two biometrics or two passwords as valid MFA combinations.

How to eliminate wrong answers

Option A is wrong because a fingerprint scan and a retina scan are both biometrics — both are 'something you are' — so they represent the same factor category and do not constitute MFA. Option B is wrong because two different passwords are both 'something you know,' which is single-factor authentication repeated, not MFA. Option C is wrong because a password and a PIN are both knowledge-based factors ('something you know'), so they fall into the same category and do not satisfy MFA.

25
MCQmedium

A security manager is developing a disaster recovery plan for a critical database. The manager needs to determine the maximum tolerable downtime (MTD) for the database. Which of the following should the manager consider FIRST when establishing the MTD?

A.The business impact of the database being unavailable
B.The cost of implementing redundant hardware
C.The recovery time objective (RTO) of the database
D.The recovery point objective (RPO) of the database
AnswerA

The MTD is determined by analyzing the business impact of downtime. This includes financial losses, regulatory penalties, reputational damage, and operational disruptions. By understanding the consequences of unavailability, the manager can establish how long the organization can survive without the database. This business impact analysis is the foundation for setting MTD, which then drives the RTO and recovery strategies.

Why this answer

The maximum tolerable downtime (MTD) is the longest time an organization can tolerate a system being unavailable before unacceptable consequences occur. To establish MTD, the manager must first conduct a business impact analysis to understand the consequences of downtime. This includes financial, operational, and reputational impacts.

Once MTD is known, the recovery time objective (RTO) can be set to ensure recovery occurs within that window. Cost, RTO, and RPO are all important but are not the primary driver for MTD.

Exam trap

The trap here is confusing MTD with RTO or RPO, but MTD is a business-driven metric that defines the maximum tolerable downtime, not a technical recovery target.

26
MCQhard

A software development company wants to ensure that only authorized code changes are deployed to production. They implement a process where developers submit code changes, and a separate team reviews and approves them before deployment. Which security principle is BEST demonstrated by this process?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Non-repudiation
AnswerC

Separation of duties ensures that critical tasks are divided among multiple people to prevent fraud and errors. In this scenario, developers write code but cannot deploy it without approval from a separate team. This division prevents a single individual from making unauthorized changes, directly embodying separation of duties.

Why this answer

Separation of duties is a preventive control that requires more than one person to complete a task, reducing the risk of unauthorized actions. In this scenario, developers cannot deploy code without a separate team's approval, ensuring that no single person has end-to-end control over the deployment process. This aligns with the principle of separation of duties, which is fundamental in change management and fraud prevention.

Exam trap

The trap here is confusing separation of duties with least privilege; while both are access control principles, separation of duties specifically addresses splitting tasks, whereas least privilege focuses on minimizing access rights.

27
MCQmedium

A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?

A.Non-repudiation
B.Confidentiality
C.Availability
D.Integrity
AnswerC

A load balancer spreads requests across multiple web servers, removing any single point of failure and sustaining service when one node fails. This directly upholds availability, ensuring authorised users retain timely access to systems and data.

Why this answer

A load balancer distributes incoming traffic across multiple web servers so that no single server becomes a bottleneck or single point of failure, directly supporting the availability principle of the CIA triad. If one server fails, the load balancer routes traffic to healthy nodes, keeping the service reachable. This is a classic availability control, not a confidentiality or integrity mechanism.

Exam trap

The trap is that candidates see 'distribute traffic' and think of confidentiality (spreading load to hide data) or integrity (balancing writes), when the exam expects recognition that redundancy and failover map to availability.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures a party cannot deny having performed an action, typically achieved through digital signatures and audit logs — a load balancer provides no proof of origin or action. Option B is wrong because confidentiality protects data from unauthorized disclosure via encryption and access controls; a load balancer does not encrypt or restrict data access. Option D is wrong because integrity ensures data is not altered improperly, enforced through hashing, checksums, and digital signatures — load balancing does not detect or prevent data modification.

28
MCQhard

According to the (ISC)² Code of Ethics, which canon has the highest priority?

A.Provide diligent and competent service to principals
B.Advance and protect the profession
C.Act honorably, honestly, justly, responsibly, and legally
D.Protect society, the common good, necessary public trust and confidence, and the infrastructure
AnswerD

The (ISC)² Code of Ethics orders its canons so that protecting society, the common good, public trust and the infrastructure ranks first, above duties to principals, the profession and colleagues. This canon therefore takes precedence when obligations conflict, satisfying the stem's highest-priority requirement.

Why this answer

The (ISC)² Code of Ethics Canons are ordered by priority, and the first canon — 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' — takes precedence over all others. This reflects the profession's obligation to place the safety and welfare of society above client interests and professional advancement. When canons conflict, the higher-priority canon must guide the decision.

Exam trap

CC often tests the misconception that 'serving the client/principal' is the top ethical duty, when in fact protecting society and the common good always outranks obligations to principals or the profession.

How to eliminate wrong answers

Option A is wrong because 'Provide diligent and competent service to principals' is the third canon, subordinate to protecting society and acting honorably. Option B is wrong because 'Advance and protect the profession' is the fourth (lowest-priority) canon, applying only after all others are satisfied. Option C is wrong because 'Act honorably, honestly, justly, responsibly, and legally' is the second canon, important but still ranked below the duty to protect society and the common good.

29
MCQmedium

Which of the following is an example of a vulnerability?

A.An unlocked server room door
B.A malicious hacker attempting to gain access
C.A firewall blocking unauthorized traffic
D.The risk of data loss
AnswerA

A vulnerability is a weakness that could be exploited; an unlocked server room door is a physical weakness allowing unauthorised access to hardware. It is not a threat (an actor or event) nor a risk (likelihood combined with impact), so it fits the stem's request for a vulnerability example.

Why this answer

A vulnerability is a weakness or flaw that can be exploited by a threat. An unlocked server room door is a physical security weakness that could allow unauthorized access, making it a classic example of a vulnerability. The other options describe threats, controls, or risks, not vulnerabilities.

Exam trap

The trap is confusing vulnerabilities with threats or risks; candidates often pick 'a malicious hacker' as a vulnerability, but that is a threat actor, while the unlocked door is the actual weakness.

How to eliminate wrong answers

Option B is wrong because a malicious hacker is a threat actor, not a vulnerability; the vulnerability would be the weakness the hacker exploits. Option C is wrong because a firewall blocking traffic is a security control that mitigates risk, not a vulnerability. Option D is wrong because the risk of data loss is a potential outcome or risk, not the underlying weakness itself.

30
Multi-Selecthard

A security manager is mapping several controls to the categories of administrative, technical, and physical. Which TWO of the following are administrative controls? (Choose two.)

Select 2 answers
A.An acceptable use policy that employees must read and sign
B.A firewall rule set that blocks inbound traffic on unused ports
C.A biometric fingerprint reader controlling the data center door
D.A security awareness training program delivered each quarter
E.A bollard installed at the entrance to the loading dock
AnswersA, D

An acceptable use policy is a management directive that defines how employees may use organizational assets, and it is enforced through acknowledgment and disciplinary process. It governs behavior through rules rather than through hardware or software, which places it squarely in the administrative category. Signing the policy also establishes awareness and accountability, reinforcing its administrative nature within the security program.

Why this answer

Administrative controls govern people and processes through rules, policies, and training. The acceptable use policy and the recurring security awareness training both shape behavior through management action rather than through hardware or software. The bollard is a physical barrier, while the biometric reader and firewall enforce access through technology, so those three fall into the physical and technical categories instead.

Exam trap

The trap here is assuming that any control which expresses a management decision, such as a firewall rule, must itself be classified as administrative.

31
Multi-Selectmedium

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Select 2 answers
A.Load balancing
B.Encryption
C.Digital signatures
D.Hashing
E.Redundant servers
AnswersC, D

Digital signatures verify that database records or transactions have not been altered after signing, directly satisfying the integrity requirement. Any modification invalidates the signature, providing cryptographic tamper detection rather than mere access control. This mechanism detects unauthorised changes, unlike confidentiality or availability controls.

Why this answer

Digital signatures (C) are correct because they provide integrity and authenticity by allowing the recipient to verify that the data has not been altered and that it originated from a trusted source, using asymmetric cryptography to sign and verify a hash of the data. Hashing (D) is correct because it produces a fixed-length digest of the database contents, so any modification to the data changes the hash value, enabling detection of unauthorized or accidental changes and thereby protecting integrity. Encryption (B) primarily provides confidentiality, not integrity, since ciphertext can still be modified without detection unless combined with a MAC or signature.

Load balancing (A) and redundant servers (E) improve availability and performance through distribution and failover, but they do not detect or prevent unauthorized data modification, so they do not directly protect integrity.

Exam trap

The trap is that encryption is often assumed to cover integrity, but the exam expects candidates to distinguish confidentiality (encryption) from integrity (hashing and digital signatures) — picking encryption here is the classic CIA-triple confusion.

32
Multi-Selecthard

A security analyst is assessing the risk associated with a new web application. The analyst identifies that the application has a SQL injection vulnerability, and there is a known exploit available that could allow an attacker to extract sensitive data. The application is exposed to the internet and is used by customers. Which two factors are most directly involved in determining the level of risk? (Choose two.)

Select 2 answers
A.The likelihood of the vulnerability being exploited
B.The color scheme of the user interface
C.The number of lines of code in the application
D.The impact if the vulnerability is exploited
E.The programming language used to develop the application
AnswersA, D

Likelihood is a key factor in risk assessment. It estimates the probability that a threat will exploit a vulnerability. Here, the existence of a known exploit and internet exposure increases the likelihood of exploitation. Risk is often calculated as likelihood times impact, so likelihood is directly involved in determining the level of risk.

Why this answer

Risk is typically defined as the combination of the likelihood of a threat exploiting a vulnerability and the impact of that exploitation. In this scenario, the known exploit and internet exposure increase likelihood, while potential sensitive data extraction increases impact. These two factors are directly involved in determining the risk level, making them the correct choices.

Exam trap

The trap here is selecting factors that seem related to vulnerabilities, like programming language, instead of focusing on the core risk components: likelihood and impact.

33
MCQmedium

A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?

A.Federated identity
B.Single sign-on
C.Single-factor authentication
D.Multi-factor authentication
AnswerD

Multi-factor authentication requires two or more different factor types, such as something you know and something you have. A password is knowledge, and a code sent to a registered phone is possession of that device. Combining them satisfies the definition, so this proposal correctly illustrates multi-factor authentication.

Why this answer

Multi-factor authentication combines factors from different categories, such as something you know and something you have. The password represents knowledge, while the code sent to a registered mobile phone represents possession of that device. This pairing raises the difficulty for an attacker who steals only the password, so the proposal is best described as multi-factor authentication.

Exam trap

The trap here is assuming any two-step login is multi-factor, but two passwords or two codes from the same factor category would still be single-factor.

34
MCQhard

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

A.Purchasing cyber insurance
B.Performing a background check on a new vendor
C.Accepting the risk of a legacy system
D.Regularly updating antivirus software
AnswerD

Due care means taking reasonable, ongoing steps to protect assets, and regularly updating antivirus software demonstrates continuous diligence against known malware. It satisfies the stem by showing sustained protective action rather than a one-off measure, distinguishing due care from mere policy documentation or due diligence assessment.

Why this answer

Due care means taking reasonable steps to protect assets, such as implementing basic security controls like patch management.

35
Multi-Selecteasy

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Select 2 answers
A.OTP token
B.Smart card
C.Retina scan
D.Password
E.Fingerprint scan
AnswersC, E

A retina scan measures a physiological characteristic of the user's body, which is inherent and therefore a Type 3 inherence factor. It is not something the user knows or possesses, so it satisfies the requirement for an inherence-based example.

Why this answer

Type 3 (inherence) authentication factors are based on something the user is — a physical or behavioral biometric characteristic of the individual. Option C, retina scan, is correct because it measures the unique pattern of blood vessels in the user's retina, an inherent physiological trait that cannot be transferred or forgotten. Option E, fingerprint scan, is correct because it reads the distinct ridge and minutiae pattern of the user's finger, another inborn biometric attribute.

The remaining options do not belong: A (OTP token) and B (smart card) are Type 2 (possession) factors — something the user has — while D (password) is a Type 1 (knowledge) factor — something the user knows.

Exam trap

CC often tests the confusion between possession factors (smart card, token) and inherence factors (biometrics), so candidates might incorrectly select OTP token or smart card as inherence.

36
MCQhard

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

A.Confidentiality
B.Non-repudiation
C.Availability
D.Integrity
AnswerC

Availability ensures systems and data remain accessible to authorised users when required. Redundant internet connections and load balancers remove single points of failure, maintaining web service access during DDoS traffic floods. Confidentiality and integrity address disclosure and modification respectively, not uptime.

Why this answer

Redundancy and load balancing help maintain access for authorized users, supporting availability.

37
MCQeasy

A hospital's IT department wants to ensure that only authorized clinicians can view patient records, while also guaranteeing that those records have not been tampered with. Which security principle is primarily concerned with preventing unauthorized disclosure of the records?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. In this scenario, restricting patient record access to authorized clinicians directly addresses preventing unauthorized disclosure, which is the core goal of confidentiality. The integrity and availability aspects are separate concerns; the question specifically asks about preventing unauthorized disclosure, making confidentiality the correct principle.

Why this answer

Confidentiality is the security principle that ensures information is not made available or disclosed to unauthorized individuals, entities, or processes. In the hospital scenario, the goal is to restrict patient record access to authorized clinicians, which is a classic confidentiality objective. Integrity addresses unauthorized modification, availability addresses timely access, and non-repudiation addresses proof of actions.

Exam trap

The trap here is confusing confidentiality with integrity because the scenario also mentions tampering, but the question specifically asks about preventing unauthorized disclosure.

38
MCQmedium

An e-commerce company notices that its product reviews are being scraped by automated bots far more aggressively than expected, and the resulting traffic is degrading checkout performance for real customers. The security team wants a control that slows automated abuse without challenging legitimate buyers. Which security principle does this control primarily support?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerB

Availability ensures systems and data remain accessible to authorized users when needed. Rate limiting preserves checkout responsiveness for real customers by throttling bot traffic that would otherwise consume server capacity, directly protecting the ability of legitimate buyers to complete purchases. This is the primary principle at stake because the scenario is about sustained access to the storefront, not about keeping review data secret or unaltered.

Why this answer

The scenario centers on keeping the storefront usable for legitimate customers despite aggressive automated traffic. Rate limiting and similar anti-automation controls protect the ability of authorized users to reach and use the system, which is the definition of availability. Confidentiality, integrity, and non-repudiation address disclosure, modification, and proof of action respectively, none of which describes degraded checkout performance caused by resource consumption.

Exam trap

The trap here is assuming that blocking bots is always a confidentiality or integrity issue, when the observable harm in this scenario is loss of access for legitimate users.

39
MCQmedium

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

A.Type 3 – Inherence factor
B.Multi-factor authentication
C.Type 2 – Possession factor
D.Type 1 – Knowledge factor
AnswerA

Type 3 authentication verifies something the user is, through inherence factors such as fingerprints, iris patterns or facial geometry. The stem explicitly requires something the user 'is', ruling out Type 1 (knowledge) and Type 2 (ownership) factors. Biometrics therefore satisfy the high-security facility's requirement.

Why this answer

Type 3 – Inherence factor refers to something the user 'is', i.e., a biometric characteristic such as fingerprint, retina, or iris. The requirement explicitly states 'something the user is', which directly maps to inherence. Therefore, Type 3 is the correct authentication type.

Exam trap

CC often tests the distinction between authentication factor types (knowledge, possession, inherence) and multi-factor authentication, so candidates may mistakenly choose 'multi-factor authentication' when the question asks for a specific factor type.

How to eliminate wrong answers

Option B is wrong because multi-factor authentication combines two or more different factor types (knowledge, possession, inherence) and is not a single factor type. Option C is wrong because Type 2 – Possession factor refers to something the user 'has', such as a smart card or token. Option D is wrong because Type 1 – Knowledge factor refers to something the user 'knows', such as a password or PIN.

40
MCQeasy

A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?

A.Detective
B.Preventive
C.Compensating
D.Corrective
AnswerB

A preventive control stops an unwanted event before it occurs. Automatically disabling accounts on the last working day prevents the former employee from authenticating at all, closing off the possibility of unauthorized access. Because the control acts in advance of any attempted misuse, it is preventive in nature, even though it also supports other goals such as audit compliance.

Why this answer

Automated account deactivation on the last working day stops unauthorized access before it can happen, which defines a preventive control. Detective controls would only reveal misuse after the fact, corrective controls would remediate damage already done, and compensating controls are alternate measures when a primary control is not feasible. Since the control blocks the event itself, preventive is the correct classification.

Exam trap

The trap here is confusing timely deprovisioning with detective monitoring, when the control's defining feature is that it blocks access before any attempt occurs.

41
MCQeasy

Which data classification level typically requires the highest level of protection?

A.Internal
B.Confidential
C.Top secret
D.Public
AnswerC

Top secret is the highest classification tier, so it mandates the strongest controls: strict need-to-know access, enhanced encryption, and rigorous handling procedures. Lower tiers such as confidential or internal permit weaker safeguards, so this level satisfies the stem's requirement for maximum protection.

Why this answer

Top secret is the highest classification and requires strict controls.

42
MCQmedium

A financial services firm is classifying a risk by estimating how often a particular attack is likely to succeed in a given year. Which risk concept is the firm measuring?

A.Residual risk
B.Annualized loss expectancy (ALE)
C.Risk likelihood
D.Risk impact
AnswerC

Risk likelihood is the probability or frequency that a threat will exploit a vulnerability and cause harm within a defined period. By estimating how often an attack is likely to succeed in a year, the firm is directly quantifying likelihood, which is one of the two core dimensions of risk alongside impact. This estimate then feeds into risk analysis and prioritization, making it the concept the firm is measuring.

Why this answer

Risk combines the likelihood that a threat exploits a vulnerability with the impact if it does. The firm is estimating how often an attack succeeds per year, which is precisely the likelihood dimension. Annualized loss expectancy and impact deal with cost or severity, while residual risk refers to what remains after controls are applied, so likelihood is the concept being quantified.

Exam trap

The trap here is confusing the frequency of an event with its financial consequence, so that any risk term involving loss amounts is selected instead of the probability being estimated.

43
Multi-Selecthard

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Select 3 answers
A.Customer personally identifiable information (PII)
B.Public company press releases
C.Financial records and projections
D.Trade secrets and intellectual property
E.Marketing brochures
AnswersA, C, D

Customer PII uniquely identifies individuals and, if disclosed, enables identity theft and triggers breach-notification and privacy-law duties. That harm potential places it at Confidential or higher, satisfying the policy's requirement to protect data whose exposure causes legal, financial or reputational damage to individuals and the organisation.

Why this answer

Option A (customer PII) is correct because personally identifiable information is regulated by laws such as GDPR and CCPA and its exposure can cause identity theft, so it must be classified Confidential or higher. Option C (financial records and projections) is correct because unaudited financials, forecasts, and internal accounting data are material non-public information whose disclosure can harm the organization or violate securities regulations. Option D (trade secrets and intellectual property) is correct because trade secrets derive their value from secrecy, and unauthorized disclosure destroys legal protection and competitive advantage.

Option B (public company press releases) is not correct because press releases are intentionally published for public consumption and are therefore Public. Option E (marketing brochures) is not correct because marketing brochures are distributed externally to promote products and contain no sensitive data, making them Public as well.

Exam trap

The trap here is confusing 'internal use' with 'confidential' — candidates assume anything not published externally is automatically Confidential, but only data whose disclosure causes harm (PII, financials, IP) qualifies.

44
Multi-Selectmedium

A mid-sized accounting firm is drafting its first information security policy. The partners want the policy to address governance responsibilities clearly so that security decisions are made consistently at the right levels. Which TWO of the following are governance responsibilities that the policy should assign? (Choose two.)

Select 2 answers
A.Defining the organization's risk appetite and approving the overall security strategy
B.Performing vulnerability scans against internal servers each week
C.Resetting user passwords when employees call the service desk
D.Configuring firewall rules and tuning intrusion detection signatures daily
E.Assigning accountability for security outcomes to specific roles and ensuring oversight
AnswersA, E

Senior leadership and the board own risk appetite and strategic direction because they are accountable to stakeholders and can commit resources across the organization. A security policy that assigns this responsibility at the executive or board level ensures security decisions align with business objectives and regulatory obligations. This is a core governance function rather than a day-to-day operational task.

Why this answer

Governance is about direction, accountability, and oversight rather than hands-on control operation. Senior leadership defines risk appetite and approves strategy, while specific roles are made accountable for security outcomes and monitored through reporting. Firewall tuning, vulnerability scanning, and password resets are operational activities that implement governance decisions but do not themselves constitute governance.

Exam trap

The trap here is equating governance with any security-related activity, when governance specifically concerns decision rights, accountability, and strategic oversight.

45
MCQhard

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor plans to publish a hash of the patch file on its website alongside the download. A security consultant warns that this approach alone is insufficient. Why is publishing only a hash inadequate for this goal?

A.A hash cannot detect any changes to the file once it is downloaded
B.Publishing a hash violates the principle of least privilege for website visitors
C.Hashes are reversible, so an attacker can derive the original patch contents from the published value
D.If an attacker compromises the website, they can replace both the patch and the published hash
AnswerD

A hash only proves integrity relative to the hash value being trusted. If the attacker can alter the website, they can substitute a malicious patch and publish its matching hash, so the verification succeeds against a fraudulent reference. Without a trusted, independent distribution channel or a digital signature tied to a trusted certificate, the hash provides no assurance of origin.

Why this answer

A hash verifies integrity only against a trusted reference value. When the hash is published on the same website that distributes the patch, an attacker who compromises that site can swap both files together, and verification will still pass. Authenticity requires a digital signature from a trusted certificate or an independent, trusted channel for the hash, because hashing alone cannot prove who created the file.

Exam trap

The trap here is treating a matching hash as proof of origin, when a hash only proves the file matches whatever reference value the verifier already trusts.

46
MCQhard

After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:

A.Risk acceptance
B.Risk avoidance
C.Due diligence
D.Due care
AnswerC

Due diligence is the investigation and verification of a vendor's security posture, finances and background before contractual commitment. Performing this check after a breach satisfies the stem's requirement to assess risk prior to signing, distinguishing it from due care, which is ongoing maintenance of that obligation.

Why this answer

Due diligence involves investigating and verifying before acting.

47
MCQeasy

A hospital wants to ensure that patient records can only be viewed by authorized clinical staff, and that any modification to a record is traceable to the individual who made it. Which security principle directly supports both of these requirements?

A.Non-repudiation
B.Least privilege
C.Availability
D.Accountability
AnswerD

Accountability ties each action performed on patient records back to a specific authenticated identity, which is exactly what traceability of modifications requires. Because access is granted only to authenticated clinical staff and every change is logged against that identity, the hospital can both restrict viewing to authorized personnel and later determine who altered a record. It is the principle that makes the other controls enforceable.

Why this answer

The hospital needs two things: only authorized clinical staff can view records, and every modification is attributable to a person. Accountability supplies both, because actions are bound to authenticated identities and recorded in logs. Availability concerns uptime, non-repudiation concerns denying actions, and least privilege concerns permission scope, so none of them covers traceability as directly as accountability does.

Exam trap

The trap here is assuming that any access-control principle, such as least privilege, also provides the audit trail needed to trace who changed a record.

48
MCQhard

A company conducts a background check on a new vendor before signing a contract. This activity is an example of:

A.Due diligence
B.Risk avoidance
C.Due care
D.Risk transfer
AnswerA

Due diligence is the investigation and verification a company performs on a prospective vendor before contracting, assessing risks, finances, and compliance. The background check gathers evidence to inform the decision, matching the definition of due diligence rather than post-contract monitoring or contractual obligation.

Why this answer

Due diligence is the investigation and verification process an organization performs before entering a relationship or contract — such as a background check on a vendor — to assess risks and make an informed decision. It is the 'before you sign' activity that informs risk acceptance.

Exam trap

The trap is the classic due diligence vs. due care confusion — candidates pick due care because it sounds like 'taking care,' but the pre-contract investigation is always due diligence.

How to eliminate wrong answers

Option B is wrong because risk avoidance means eliminating the activity entirely to avoid the risk (e.g., deciding not to use vendors at all), not investigating them. Option C is wrong because due care is the ongoing responsibility to act reasonably and maintain controls after a decision is made — it is the 'after you sign' execution of safeguards. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance or contractual indemnification), not the investigation itself.

49
Multi-Selecthard

A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)

Select 2 answers
A.Administrative privileges are permanently assigned to senior management.
B.Users are granted only the minimum access rights necessary to perform their job functions.
C.All users are granted read-only access to all resources by default.
D.Users are given access only for the duration needed to complete a specific task.
E.Access rights are based on the user's role within the organization.
AnswersB, D

Least privilege dictates that users should have only the permissions required to complete their tasks, no more. This minimizes the attack surface and reduces the potential damage from accidental or malicious actions. Granting minimum access is the core definition of least privilege, making this a correct characteristic.

Why this answer

The correct answers are granting only minimum necessary access and limiting access duration to when needed. These directly reflect the principle of least privilege, which aims to restrict user rights to the bare minimum required for their duties and only for as long as necessary. Role-based access, default read-only access, and permanent admin rights do not embody least privilege.

Exam trap

The trap here is equating role-based access control with least privilege, when RBAC is merely a tool that can help implement least privilege but does not guarantee it.

50
MCQmedium

A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerC

Redundant servers with automated failover keep the website reachable when a server fails, so uptime is maintained rather than data secrecy or integrity. This directly satisfies the stem's accessibility-during-outage constraint, which maps to the availability principle of the CIA triad.

Why this answer

Availability ensures that systems and data are accessible to authorized users when needed. Redundant servers and automated failover directly address availability by eliminating single points of failure and enabling continuous service during outages. Integrity concerns data accuracy, confidentiality concerns unauthorized disclosure, and non-repudiation concerns proving an action occurred — none of which are addressed by redundancy.

Exam trap

The trap is conflating availability with integrity — candidates see 'redundant servers' and think 'data accuracy,' but redundancy addresses uptime, not data correctness.

How to eliminate wrong answers

Option A is wrong because non-repudiation is about proving that a party performed an action (via digital signatures or audit logs), not about keeping services online. Option B is wrong because integrity protects data from unauthorized modification, whereas redundancy/failover protects uptime. Option D is wrong because confidentiality prevents unauthorized disclosure through encryption and access controls, which is unrelated to failover.

51
MCQeasy

Which type of authentication factor involves something the user knows?

A.Type 1 (knowledge)
B.Type 2 (possession)
C.Type 4 (location)
D.Type 3 (inherence)
AnswerA

Type 1 factors are knowledge-based, covering passwords, PINs and passphrases that a user memorises. This matches the stem's requirement for something the user knows, distinguishing it from Type 2 (something possessed) and Type 3 (something inherent).

Why this answer

Type 1 authentication is 'something you know' — knowledge factors such as passwords, PINs, or security questions. This is the classic knowledge-based factor and is correctly identified as Type 1 in the standard authentication factor taxonomy.

Exam trap

The trap here is confusing Type 2 (possession) with Type 1 (knowledge) — candidates often assume 'something you have' is the most common factor, but the question explicitly asks for 'something you know.'

How to eliminate wrong answers

Option B is wrong because Type 2 is 'something you have' (possession) — tokens, smart cards, or authenticator apps. Option C is wrong because Type 4 (location) is a contextual factor (e.g., geolocation or network location), not a knowledge factor. Option D is wrong because Type 3 is 'something you are' (inherence) — biometrics like fingerprints or facial recognition.

52
Multi-Selectmedium

A security administrator is reviewing the organization's authentication controls and wants to strengthen them by adding factors from different categories. Which TWO of the following represent distinct authentication factor categories that can be combined to achieve multi-factor authentication? (Choose two.)

Select 2 answers
A.Two different passwords for the same account
B.Something you possess, such as a smart card or hardware token
C.Something you know, such as a password or PIN
D.A one-time passcode sent to the same device that is requesting access
E.A username and a password entered together
AnswersB, C

Possession factors are physical items the user has, including smart cards, hardware tokens, and registered mobile devices. Pairing a possession factor with a knowledge factor such as a PIN satisfies multi-factor authentication because the two factors come from different categories. Possession factors resist password guessing and replay because the attacker must also obtain the physical item. This is a standard factor category in authentication frameworks.

Why this answer

Multi-factor authentication requires two or more factors drawn from different categories: something you know, something you have, and something you are. A password or PIN represents knowledge, while a smart card or hardware token represents possession, so combining them satisfies the requirement. Usernames are identifiers rather than factors, two passwords remain knowledge-based, and a one-time passcode sent to the requesting device does not introduce a distinct factor category.

Exam trap

The trap here is treating any two credentials as multi-factor, when the factors must come from different categories such as knowledge and possession.

53
MCQmedium

A company performs background checks on potential employees before hiring. This action demonstrates which concept?

A.Due diligence
B.Risk avoidance
C.Due care
D.Risk transfer
AnswerA

Due diligence is the ongoing investigation and verification a company performs before entering an agreement or hiring, such as background checks, to identify risks. It satisfies the stem by demonstrating reasonable care before employment. Due care would instead describe the ongoing protective actions taken afterwards.

Why this answer

Due diligence is the investigation and verification process an organization performs before entering a relationship or making a decision — background checks on potential employees are a textbook example. It is the assessment step that informs risk decisions. Due care, by contrast, is the ongoing implementation of controls once a risk is identified.

Exam trap

CC often tests the due diligence vs. due care distinction — candidates pick due care because both sound like 'being responsible,' but due diligence is the pre-decision investigation, while due care is the ongoing protection.

How to eliminate wrong answers

Option B is wrong because risk avoidance means eliminating the activity entirely (e.g., not hiring remote staff at all), not screening candidates. Option C is wrong because due care refers to the ongoing actions taken to protect the organization (e.g., periodic re-screening, security training), not the pre-hire investigation. Option D is wrong because risk transfer shifts risk to a third party via insurance or contracts, which background checks do not do.

54
Multi-Selecthard

Which THREE of the following are considered risk management strategies? (Select THREE)

Select 3 answers
A.Risk acceptance
B.Risk assessment
C.Risk analysis
D.Risk transfer
E.Risk mitigation
AnswersA, D, E

Risk acceptance is a documented decision to tolerate a risk without applying further controls, typically when the cost of treatment exceeds the potential loss. It is one of the recognised risk management strategies alongside transfer, mitigation and avoidance, satisfying the question's requirement to identify them.

Why this answer

Risk acceptance (A) is a valid risk management strategy because the organization consciously decides to tolerate the identified risk without taking action, often when the cost of mitigation exceeds the potential impact. Risk transfer (D) is a strategy that shifts the financial impact of a risk to a third party, typically through insurance or outsourcing contracts. Risk mitigation (E) is a strategy that reduces the probability or impact of a risk by implementing controls, making it a core risk-handling approach.

Risk assessment (B) and risk analysis (C) are not strategies themselves; they are earlier processes used to identify, evaluate, and prioritize risks before a response strategy is selected.

Exam trap

CC often tests the confusion between risk process steps (assessment, analysis) and risk response strategies (accept, transfer, mitigate, avoid) — candidates must distinguish 'what you do to understand risk' from 'what you do about risk.'

55
Multi-Selectmedium

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Select 2 answers
A.Name
B.Medical records
C.Email address
D.IP address
E.Biometric data
AnswersB, E

Medical records qualify as sensitive PII because they contain health data, a special category requiring heightened protection under most privacy frameworks. This satisfies the stem's sensitivity constraint, distinguishing them from ordinary identifiers such as names or email addresses, which alone lack the elevated risk profile that triggers stricter handling obligations.

Why this answer

Sensitive PII includes medical records and biometrics. Name and email are general PII; IP address is not PII alone.

56
MCQhard

An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?

A.Defense in depth
B.Least privilege
C.Separation of duties
D.Data minimization
AnswerD

Data minimization means collecting and retaining only the personal data actually needed for a stated purpose. By keeping just the last four digits for customer reference and deleting the full card number after authorization, the retailer reduces the volume of sensitive data at risk and limits potential harm from a breach. This directly matches the principle of not holding more information than necessary.

Why this answer

The retailer chooses to store only the last four digits and remove the full card number once authorization completes. That reduces the amount of sensitive data held, which is data minimization. Separation of duties concerns dividing tasks, defense in depth concerns layered controls, and least privilege concerns limiting user access, so none of them captures the decision to collect and keep less information.

Exam trap

The trap here is equating any reduction in data exposure with least privilege, when the scenario is actually about how much data is collected and retained.

57
MCQmedium

When implementing multi-factor authentication, which combination of factors is considered strongest?

A.Password and PIN
B.Password and security question
C.Smart card and biometric
D.Biometric and fingerprint
AnswerC

A smart card is a possession factor and a biometric is an inherence factor, so pairing them combines two genuinely different factor categories. This is stronger than combining two knowledge factors or a knowledge factor with a possession factor, satisfying the requirement for the strongest combination.

Why this answer

Multi-factor authentication (MFA) requires combining factors from different categories: something you know (password, PIN), something you have (smart card, token), and something you are (biometric). The strongest combination uses factors from separate categories, such as a smart card (something you have) and a biometric (something you are). This provides defense in depth because compromising one factor does not compromise the other.

Exam trap

The trap is that candidates may think any two authentication methods constitute MFA, but the exam tests whether they recognize that factors must come from different categories, so combinations like password and PIN are not true MFA.

How to eliminate wrong answers

Option A is wrong because both a password and a PIN are 'something you know' factors, so they belong to the same category and do not constitute true MFA. Option B is wrong because a password and a security question are both knowledge-based factors, again the same category. Option D is wrong because a biometric and a fingerprint are both 'something you are' factors; a fingerprint is a type of biometric, so they are not distinct categories.

58
Multi-Selectmedium

An organization is reviewing its security governance framework. Which TWO of the following are primary objectives of security governance? (Choose two.)

Select 2 answers
A.Aligning security strategy with business objectives
B.Developing security awareness training
C.Implementing technical security controls
D.Conducting penetration testing
E.Ensuring accountability for security decisions
AnswersA, E

Security governance ensures that information security activities support and align with the organization's business goals. By aligning security strategy with business objectives, governance helps prioritize security investments and ensures that security enables rather than hinders business operations. This is a primary objective because it directs how security is managed to deliver value and manage risk in line with the organization's mission.

Why this answer

Security governance is the set of responsibilities and practices exercised by the board and executive management to provide strategic direction, ensure objectives are achieved, manage risks appropriately, and verify that resources are used responsibly. Aligning security strategy with business objectives and ensuring accountability for security decisions are core governance objectives. Technical controls, penetration testing, and awareness training are operational activities that support governance but are not primary objectives of governance itself.

Exam trap

The trap here is selecting operational activities like penetration testing or awareness training as governance objectives, when governance is about oversight and alignment.

59
MCQeasy

A small clinic stores patient records on a server. The IT administrator ensures that only authorized staff can view these records, and that the records remain accurate and available when needed. Which security principle is best illustrated by restricting access to the records?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality ensures information is not disclosed to unauthorized individuals. By restricting access to patient records to authorized staff only, the administrator directly protects the data from unauthorized viewing. This aligns with the principle of confidentiality, which is a core component of the CIA triad and a fundamental security objective.

Why this answer

The correct answer is confidentiality. Restricting access to patient records ensures that only authorized individuals can view them, directly supporting the confidentiality principle. Integrity, availability, and non-repudiation address different aspects of information security and are not the primary focus of the described action.

Confidentiality is a foundational concept in the CIA triad and is specifically about preventing unauthorized disclosure.

Exam trap

The trap here is confusing confidentiality with integrity, assuming that restricting access also ensures data accuracy, when in fact confidentiality is solely about preventing unauthorized disclosure.

60
MCQmedium

What is the difference between due care and due diligence in security governance?

A.Due care is proactive; due diligence is reactive
B.They are synonymous
C.Due care refers to implementing security controls; due diligence refers to investigating risks and verifying controls
D.Due diligence is required by law; due care is voluntary
AnswerC

Due care is the ongoing practice of applying controls, while due diligence is the investigative and verification activity that precedes and validates them. The option correctly separates implementation from risk investigation and control verification, matching the governance distinction the question demands.

Why this answer

Due care is the minimum standard of care (implementing basic security), while due diligence is investigating before acting (e.g., vendor assessments).

61
MCQhard

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

A.Risk acceptance
B.Risk mitigation
C.Due diligence
D.Risk transfer
AnswerC

Due diligence is the investigative process of verifying a provider's claims before contracting, exactly matching the site visits, certification reviews and reference checks described. It satisfies the stem's requirement to assess risk through pre-engagement scrutiny rather than transferring, avoiding or accepting it.

Why this answer

Reviewing a provider's security certifications, conducting a site visit, and checking references are all investigative activities performed before committing to a relationship — this is the definition of due diligence. Due diligence is the assessment phase of risk management that gathers evidence to inform a risk decision. It is distinct from mitigation (implementing controls), transfer (shifting risk via insurance/contracts), and acceptance (acknowledging risk without action).

Exam trap

CC often tests due diligence vs. risk mitigation — candidates see 'reviewing certifications' and pick mitigation, but investigation before a decision is due diligence, while mitigation is the control implementation that follows.

How to eliminate wrong answers

Option A is wrong because risk acceptance means acknowledging the risk and taking no action, whereas the company is actively investigating the provider. Option B is wrong because risk mitigation involves implementing controls to reduce risk (e.g., requiring encryption), not evaluating a vendor. Option D is wrong because risk transfer shifts financial impact to a third party via insurance or contractual indemnification, which the described activities do not accomplish.

62
Multi-Selectmedium

A security manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The manager needs to identify which of the following are considered threats rather than vulnerabilities or risks. (Choose two.)

Select 2 answers
A.Weak password policy allowing easy guessing
B.A hacker group known for targeting SaaS providers
C.The potential financial loss from a data breach
D.Unpatched software in the CRM application
E.A natural disaster causing data center outage
AnswersB, E

A hacker group is an external threat actor with the intent and capability to exploit vulnerabilities. In risk management, a threat is any circumstance or event with the potential to cause harm. This group represents a threat because it actively seeks to compromise systems, and its existence is independent of any specific weakness in the CRM.

Why this answer

In risk management, a threat is any actor or event with the potential to cause harm, such as a hacker group or a natural disaster. Vulnerabilities are weaknesses that can be exploited, like unpatched software or weak password policies. Risk is the potential for loss when a threat exploits a vulnerability.

The question asks for threats, so the hacker group and natural disaster are correct.

Exam trap

The trap here is mixing up vulnerabilities and risks with threats; unpatched software and weak password policy are vulnerabilities, and financial loss is a risk, not a threat.

63
Multi-Selecthard

Which THREE of the following are examples of risk mitigation? (Select THREE)

Select 3 answers
A.Implementing access controls to limit user permissions
B.Deciding not to fix a low-risk vulnerability due to cost
C.Encrypting sensitive data at rest
D.Installing antivirus software on all endpoints
E.Purchasing cyber insurance
AnswersA, C, D

Implementing access controls directly reduces the likelihood of unauthorised actions by enforcing least privilege, satisfying the stem's requirement for risk mitigation. Rather than transferring or accepting risk, it lowers inherent exposure through preventive technical controls such as role-based access assignments in Microsoft Entra ID.

Why this answer

Option A is correct because implementing access controls (e.g., role-based access control following least privilege) directly reduces the likelihood and impact of unauthorized actions, which is the essence of risk mitigation. Option C is correct because encrypting sensitive data at rest (e.g., AES-256) reduces the impact of a data breach by rendering stolen data unreadable, thereby lowering overall risk. Option D is correct because installing antivirus/anti-malware on all endpoints provides detective and preventive controls that reduce the likelihood of malware infections and their spread.

Option B is not mitigation but risk acceptance, since the organization consciously chooses to tolerate the vulnerability without applying controls. Option E is risk transference (sharing risk with an insurer via a financial mechanism), not mitigation, because it does not reduce the likelihood or impact of the risk itself.

Exam trap

CC often tests the distinction between risk mitigation and other risk responses like acceptance or transference; candidates must remember that insurance is transference, not mitigation.

64
MCQmedium

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

A.Non-repudiation
B.Availability
C.Confidentiality
D.Integrity
AnswerD

A digital signature verifies that the update has not been altered after signing, because any modification invalidates the hash encrypted with the signer's private key. This detects tampering, satisfying integrity; authenticity of the sender is a related but separate assurance.

Why this answer

A digital signature provides integrity by using a hash of the message encrypted with the sender's private key; the recipient decrypts the hash with the public key and compares it to a freshly computed hash. If the values match, the data has not been altered. While digital signatures also provide authentication and non-repudiation, the question asks which CIA triad element is supported — integrity is the correct CIA component.

Exam trap

The trap is confusing integrity with non-repudiation — digital signatures provide both, but the CIA triad question specifically asks which CIA element, and non-repudiation is not one of the three.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad; it is a separate security property (though digital signatures do provide it). Option B is wrong because availability concerns uptime and access, which digital signatures do not address. Option C is wrong because confidentiality requires encryption that hides data content, whereas digital signatures do not encrypt the message — they only verify it.

65
MCQmedium

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

A.Internal
B.Restricted
C.Public
D.Confidential
AnswerB

Restricted data demands the strongest controls because it carries the greatest potential harm if disclosed, satisfying the stem's requirement for the highest protection level. Public, Internal, and Confidential each warrant progressively less stringent safeguards, so Restricted sits at the top of this four-tier classification scheme.

Why this answer

In a four-tier classification scheme (Public, Internal, Confidential, Restricted), Restricted represents the most sensitive data — typically trade secrets, PII under regulation, or data whose breach causes severe legal/financial harm. It therefore requires the highest level of protection, including strict access controls, encryption, and audit logging.

Exam trap

The trap here is confusing 'Confidential' with 'Restricted' — candidates often assume Confidential is the top tier, but in most four-tier schemes Restricted is the highest sensitivity level.

How to eliminate wrong answers

Option A is wrong because Internal data is only meant for employees and has lower sensitivity than Confidential or Restricted. Option C is wrong because Public data is intentionally shareable and requires the least protection. Option D is wrong because Confidential is sensitive but typically one tier below Restricted — Confidential data might be shared under NDA, while Restricted data is need-to-know with the strictest controls.

66
MCQeasy

Which of the following is an example of Type 2 authentication?

A.Fingerprint scan
B.Password
C.PIN
D.Smart card
AnswerD

Correct. Smart card is a possession factor.

Why this answer

Type 2 authentication, also called 'something you have,' relies on a physical object the user possesses — a smart card is the classic example. Type 1 is 'something you know' (password, PIN), Type 2 is 'something you have' (smart card, token, phone), and Type 3 is 'something you are' (biometrics). The smart card fits Type 2 precisely.

Exam trap

The trap is confusing a PIN with a smart card — candidates see 'PIN' and think it is part of the smart card, but a PIN alone is Type 1 (knowledge), while the smart card itself is Type 2 (possession).

How to eliminate wrong answers

Option A is wrong because a fingerprint scan is a biometric factor, which is Type 3 ('something you are'), not Type 2. Option B is wrong because a password is knowledge-based, making it Type 1 ('something you know'). Option C is wrong because a PIN is also knowledge-based and therefore Type 1, even though it is often used alongside a smart card in two-factor authentication.

67
Multi-Selecthard

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Select 3 answers
A.Company cafeteria menu
B.Classified government intelligence
C.Marketing brochures
D.Trade secrets
E.Biometric data of employees
AnswersB, D, E

Government intelligence material is classified at the highest tier because unauthorised disclosure causes exceptional damage to national security. Its handling mandates the strictest controls, so it belongs in the restricted or top secret category rather than internal or public.

Why this answer

Option B (classified government intelligence) is correctly marked restricted/top secret because it is information whose unauthorized disclosure would cause exceptional damage to national security and is legally protected at the highest classification levels. Option D (trade secrets) is correct because trade secrets are proprietary intellectual property whose disclosure would cause severe competitive and financial harm, so best-practice data classification places them in the highest sensitivity tier. Option E (biometric data of employees) is correct because biometric identifiers are sensitive personal data (often special-category data under regimes like GDPR) that cannot be changed if compromised, warranting restricted handling.

The unmarked options do not belong: A (company cafeteria menu) and C (marketing brochures) are intended for public or internal distribution and carry negligible confidentiality impact, so they would be classified as public or internal, not restricted.

68
MCQhard

A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?

A.The risk is low because the backup can restore data quickly.
B.The risk is moderate because the backup reduces the impact, but likelihood remains high.
C.The risk is eliminated because the backup ensures full recovery.
D.The risk is high because the likelihood and impact are both high.
AnswerB

Risk is a function of likelihood and impact. Here, likelihood is high, but the backup reduces the impact from severe to moderate. The residual risk is therefore moderate. This classification acknowledges both the high likelihood and the mitigating effect of the backup, resulting in a balanced risk rating that reflects the remaining exposure.

Why this answer

The analyst should classify the risk as moderate. Although the likelihood of a ransomware attack is high, the reliable offline backup significantly reduces the potential impact by enabling rapid restoration. Risk is the combination of likelihood and impact; with high likelihood but reduced impact, the overall risk is moderate.

This reflects the residual risk after considering the mitigating control.

Exam trap

The trap here is ignoring the mitigating effect of the backup and rating risk solely on likelihood and impact, or conversely, assuming the backup eliminates risk entirely.

69
MCQmedium

A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?

A.Encrypt the backup tapes
B.Label the tapes with a classification marking
C.Store the tapes in a locked cabinet
D.Apply a checksum to each tape
AnswerA

Encrypting backup tapes renders the data unreadable without the appropriate keys, even if the physical media is lost or stolen. This directly satisfies the requirement that unauthorized parties cannot read the data. Therefore, encryption is the correct control for protecting data at rest on transported media in this scenario.

Why this answer

Encryption protects data confidentiality even when physical media is lost or stolen. By encrypting backup tapes, the company ensures that unauthorized parties cannot read customer data without the decryption keys. Checksums, labels, and locked cabinets may support handling or integrity, but none prevents a thief from reading the tape contents, so encryption is the required control.

Exam trap

The trap here is relying on physical controls like locked cabinets, which fail once the tape leaves the controlled environment.

70
MCQmedium

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

A.Authentication
B.Integrity
C.Confidentiality
D.Availability
AnswerB

Hashing detects unauthorised file modification because any change to the file's contents produces a different hash value, so comparison against the stored baseline reveals tampering. This directly satisfies the stem's requirement to detect unauthorised changes to critical files, supporting integrity rather than confidentiality or availability.

Why this answer

Hashing critical files and storing their hash values allows the administrator to later recompute the hash and compare it to the stored value. If the file contents change, the hash will differ, revealing unauthorized modification. This directly supports the security goal of integrity, which ensures data has not been altered in an unauthorized manner.

Authentication, confidentiality, and availability are not the primary goals addressed by this mechanism.

Exam trap

The trap here is confusing integrity with authentication because both involve verification; candidates may think hashing authenticates the file's source, but it only proves the file has not changed since the baseline was taken.

How to eliminate wrong answers

Option A is wrong because authentication verifies the identity of a user, system, or entity, not whether a file's contents have been altered; hashing files does not prove who accessed them. Option C is wrong because confidentiality ensures data is not disclosed to unauthorized parties, typically through encryption; hashing does not hide file contents. Option D is wrong because availability ensures systems and data are accessible when needed, often via redundancy or backups; hashing does not prevent downtime or ensure uptime.

71
MCQhard

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

A.Risk avoidance
B.Due care
C.Due diligence
D.Risk mitigation
AnswerC

Due diligence is the pre-contract investigation of a vendor's controls, plans and personnel, gathering evidence before commitment. Audits and penetration tests examine an existing relationship, whereas due diligence satisfies the consultant's need to assess risk prior to signing.

Why this answer

Due diligence involves investigating and verifying security practices before making a decision, such as vendor risk assessment.

72
MCQhard

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

A.Risk avoidance
B.Risk transfer
C.Risk acceptance
D.Risk mitigation
AnswerC

Risk acceptance means deliberately acknowledging a residual risk and proceeding without further controls because the upgrade cost exceeds the potential impact. This matches the stem's scenario of tolerating a known vulnerable software version rather than mitigating, transferring or avoiding it.

Why this answer

Risk acceptance is the deliberate decision to acknowledge a risk and take no action to reduce it, typically because the cost of mitigation outweighs the potential impact. In this scenario, the organization has evaluated the risk and consciously chosen to retain it, which is the definition of risk acceptance. This is a valid risk response when the risk falls within the organization's risk appetite or when mitigation is not cost-effective.

Exam trap

The trap here is confusing risk acceptance with risk mitigation or avoidance, especially when the scenario mentions cost-benefit analysis; candidates might think that any decision involving cost considerations implies mitigation, but acceptance is specifically about choosing to retain the risk without further action.

How to eliminate wrong answers

Option A is wrong because risk avoidance involves changing plans or activities to eliminate the risk entirely, such as discontinuing the use of the vulnerable software. Option B is wrong because risk transfer shifts the risk to a third party, such as purchasing insurance or outsourcing, which is not happening here. Option D is wrong because risk mitigation involves implementing controls to reduce the likelihood or impact of the risk, such as patching or applying compensating controls, which the organization has explicitly decided not to do.

73
Multi-Selectmedium

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Select 2 answers
A.One-time password token
B.Retina scan
C.Fingerprint recognition
D.Smart card
E.Password
AnswersB, C

Type 3 authentication relies on something you are — a biometric trait. A retina scan measures a physiological characteristic unique to the individual, satisfying that category rather than knowledge (Type 1) or possession (Type 2).

Why this answer

Type 3 authentication is "something you are," i.e., biometrics based on a physical or behavioral characteristic of the user. Option B, retina scan, is correct because it authenticates by measuring the unique pattern of blood vessels in the eye's retina, a physiological biometric trait. Option C, fingerprint recognition, is correct because it verifies identity from the unique ridge patterns of a finger, another physiological biometric.

The other options belong to different factors: A (one-time password token) and D (smart card) are Type 2, "something you have," while E (password) is Type 1, "something you know."

Exam trap

The trap here is confusing authentication factor types: many candidates mistakenly classify a one-time password token or smart card as 'something you are' because they are advanced technologies, but they are actually 'something you have' (Type 2).

74
MCQmedium

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

A.Due care
B.Governance
C.Due diligence
D.Risk acceptance
AnswerC

Due diligence is the investigation and verification of a vendor's controls before contracting, covering certification review, background checks and site visits. These activities assess the vendor's actual security posture, satisfying the evaluation described in the scenario.

Why this answer

Due diligence involves investigating and verifying before making a decision, such as vendor risk assessment.

75
MCQeasy

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

A.Confidentiality
B.Availability
C.Non-repudiation
D.Integrity
AnswerD

File integrity monitoring detects unauthorised changes to critical files by comparing hashes against a known baseline. This directly addresses integrity, ensuring data and system files remain unaltered and trustworthy, rather than focusing on confidentiality or availability.

Why this answer

File integrity monitoring detects unauthorized changes to files, ensuring data accuracy and completeness, which is the integrity element.

Page 1 of 3 · 168 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Principles questions.