Courseiva

CCNA Security Principles Questions

75 of 168 questions · Page 2/3 · Security Principles · Answers revealed

76
Multi-Selectmedium

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Select 2 answers
A.Confidentiality
B.Integrity
C.Authorization
D.Authentication
E.Non-repudiation
AnswersA, B

Confidentiality ensures information is disclosed only to authorised parties, typically enforced through encryption, access controls and classification. It forms one of the three pillars the policy must address, directly satisfying the stem's requirement for a core CIA triad component.

Why this answer

The CIA triad consists of Confidentiality, Integrity, and Availability. Authentication and Non-repudiation are related but not part of the core triad.

77
Multi-Selectmedium

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Select 2 answers
A.Password
B.Smart card
C.PIN
D.Fingerprint scan
E.Retina scan
AnswersD, E

A fingerprint scan is a biometric characteristic, placing it in Type 3 "something you are". It satisfies the stem's requirement for a Type 3 factor because the trait is inherent to the individual, unlike possession tokens or memorised passwords.

Why this answer

Type 3 authentication factors are based on something you are — biometric characteristics — so option D (fingerprint scan) is correct because it verifies a unique physical trait of the user, and option E (retina scan) is correct because it measures the distinct vascular pattern of the eye's retina. Both are biometric methods that cannot easily be shared or forgotten, which is the defining property of Type 3 factors. Option A (password) is wrong because it is a Type 1 factor (something you know), and option C (PIN) is also a Type 1 factor (something you know).

Option B (smart card) is wrong because it is a Type 2 factor (something you have).

78
MCQhard

A software development company wants to ensure that only authorized code changes are deployed to production. The security team proposes that developers should not have direct write access to the production environment, and that all code must be reviewed and approved by a different team member before deployment. Which security principle does this proposal primarily enforce?

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Non-repudiation
AnswerB

Separation of duties ensures that a critical task is divided among multiple people so that no single individual can complete it without oversight. By requiring code to be reviewed and approved by a different team member and denying developers direct production write access, the company prevents one person from both authoring and deploying changes. This directly enforces separation of duties in the software deployment process.

Why this answer

The proposal enforces separation of duties by requiring that code changes are reviewed and approved by someone other than the developer, and by preventing developers from directly writing to production. This ensures that no single person can both create and deploy code without oversight. Least privilege, defense in depth, and non-repudiation address different aspects of security and do not capture the dual-control requirement.

Exam trap

The trap here is focusing on the removal of direct write access as least privilege, when the more significant control is the mandatory review by a different person, which is separation of duties.

79
MCQeasy

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality directly addresses preventing unauthorised disclosure, which is the exact control objective stated in the stem. Encryption, access controls and data classification enforce confidentiality by restricting data access to authorised parties only. Integrity would concern unauthorised modification, and availability would concern timely access, neither of which matches the disclosure constraint.

Why this answer

Confidentiality is the element of the CIA triad that ensures information is not disclosed to unauthorized individuals, entities, or processes. The scenario explicitly states the goal is to prevent unauthorized disclosure of sensitive information, which is the definition of confidentiality. Controls such as encryption, access control lists, and data classification directly support confidentiality.

Therefore, option D is correct.

Exam trap

The trap here is confusing confidentiality with integrity or availability, especially when the question mentions 'controls' without specifying encryption or access controls; candidates might incorrectly associate 'prevent unauthorized disclosure' with integrity if they misread 'disclosure' as 'modification'.

How to eliminate wrong answers

Option A is wrong because non-repudiation is not part of the CIA triad; it is a separate security property that ensures a party cannot deny having performed an action, often achieved through digital signatures and audit logs. Option B is wrong because integrity focuses on protecting data from unauthorized modification or alteration, not disclosure. Option C is wrong because availability ensures that systems and data are accessible to authorized users when needed, which is unrelated to preventing unauthorized disclosure.

80
MCQhard

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?

A.Non-repudiation and integrity
B.Confidentiality of the patch contents
C.Authorization of the customer
D.Availability of the download server
AnswerA

Signing with a private key and verifying with the corresponding public key proves the patch originated from the vendor and was not altered. This provides non-repudiation because the vendor cannot deny signing it, and integrity because any modification invalidates the signature. Thus it correctly describes the security property.

Why this answer

A digital signature created with a private key and verified with the corresponding public key provides authenticity, integrity, and non-repudiation. Customers can confirm the patch came from the vendor and was not modified, and the vendor cannot later deny signing it. Confidentiality, availability, and authorization are separate properties not delivered by this signing and verification process.

Exam trap

The trap here is assuming that signing also encrypts the patch, but signatures provide integrity and origin proof, not confidentiality.

81
MCQhard

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

A.Confidential data
B.Internal data
C.Sensitive PII
D.Public data
AnswerC

Sensitive PII covers data elements whose exposure causes heightened harm, such as social security numbers and medical records, which is precisely what the stem lists. Ordinary PII alone would not capture the elevated protection these identifiers and health data demand under privacy principles.

Why this answer

Sensitive PII is the correct classification because it includes data elements like Social Security numbers and medical records that, if disclosed, could cause significant harm, discrimination, or identity theft. Under privacy frameworks such as NIST SP 800-122 and GDPR, these are explicitly categorized as sensitive PII requiring stricter protection. Unlike general confidential data, sensitive PII has specific regulatory and compliance implications, including breach notification laws and mandatory safeguards.

Exam trap

The trap here is confusing broad data classification terms like 'confidential' with the specific regulatory category of 'sensitive PII,' which carries distinct legal and compliance obligations.

How to eliminate wrong answers

Option A is wrong because 'confidential data' is a broader, less precise term that doesn't capture the specific legal and regulatory obligations tied to sensitive PII. Option B is wrong because 'internal data' refers to information not intended for public release but lacks the heightened sensitivity and compliance requirements of PII like SSNs and medical records. Option D is wrong because 'public data' is information freely available and poses no risk if disclosed, which directly contradicts the nature of SSNs and medical records.

82
MCQmedium

A company experiences a ransomware attack that encrypts its file servers. The security team restores operations from offline backups taken the previous night. Which security principle does the restoration from backups primarily support?

A.Availability
B.Integrity
C.Confidentiality
D.Non-repudiation
AnswerA

Availability ensures that systems and data are accessible to authorized users when needed. Ransomware encryption makes the file servers unusable, and restoring from offline backups taken the previous night returns the data and services to operation. This directly addresses the availability objective by minimizing downtime and data loss. Offline backups are especially valuable because they are not reachable by the malware, so they remain a reliable recovery source.

Why this answer

Ransomware encryption makes the file servers unavailable, and restoring from an offline backup taken the previous night brings the data and services back online with minimal loss. That is the availability objective of the CIA triad. Confidentiality protects against disclosure, integrity protects against unauthorized alteration, and non-repudiation proves actions; the recovery activity here is specifically about regaining access to systems and data.

Exam trap

The trap here is selecting integrity because ransomware alters files, but the restoration activity is aimed at restoring access, which is availability.

83
Multi-Selecteasy

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Select 2 answers
A.Encryption
B.Redundant servers
C.Digital signature
D.Access control lists
E.Hashing
AnswersC, E

A digital signature uses the publisher's private key to sign the update, and verification with the corresponding public key confirms both origin and that the package was not altered. This satisfies the stem's integrity requirement by detecting any tampering before deployment.

Why this answer

Option C (Digital signature) is correct because a digital signature, created by the software publisher using their private key and verified with their public key, cryptographically proves both the integrity and authenticity of the update — any modification to the package invalidates the signature. Option E (Hashing) is correct because computing a hash (e.g., SHA-256) of the downloaded update and comparing it to the publisher's published hash value detects any alteration of the file's contents, confirming integrity. Option A (Encryption) is not correct because encryption provides confidentiality, not integrity verification, and does not by itself prove the file was unmodified.

Option B (Redundant servers) is not correct because redundancy only improves availability and fault tolerance, not data integrity. Option D (Access control lists) is not correct because ACLs restrict who may access a resource, which is an authorization control rather than a mechanism for verifying that a file's contents are intact.

Exam trap

The trap here is confusing confidentiality (encryption) with integrity (hashing/signatures) — candidates often pick encryption because it sounds security-related, but it does not verify that data was unmodified.

84
MCQmedium

A financial services company wants to ensure that a terminated employee cannot continue to use an active badge to enter the building after their last day. The security manager reviews physical access control procedures. Which control type is being applied when the badge is deactivated in the access control system?

A.Preventive control
B.Detective control
C.Corrective control
D.Compensating control
AnswerA

Deactivating a badge prevents the terminated employee from using it to gain entry, which is the goal of a preventive control. It stops the unauthorized action before it occurs. While it also supports other control categories, the immediate effect is to block access, making preventive the best classification for this scenario.

Why this answer

Deactivating a badge stops the terminated employee from entering the facility, which is the definition of a preventive control. Preventive controls aim to stop unauthorized actions before they happen. Detective controls identify events after the fact, corrective controls address incidents after they occur, and compensating controls substitute for missing controls.

Since the action blocks access in advance, preventive is correct.

Exam trap

The trap here is confusing preventive and corrective controls because both involve responding to a termination, but the timing of the action determines the classification.

85
Multi-Selecthard

A security officer at a healthcare provider is reviewing the organization's risk management program. The officer must distinguish between threats and vulnerabilities when documenting risks. Which two of the following are examples of vulnerabilities rather than threats? (Choose two.)

Select 2 answers
A.A ransomware group that is actively targeting healthcare organizations
B.A natural disaster such as a hurricane that could damage a data center
C.An unpatched web server that is missing a critical security update
D.A phishing campaign that delivers malicious attachments to employees
E.A database that stores patient records without encryption at rest
AnswersC, E

An unpatched web server is a weakness in the system that could be exploited, which is a vulnerability. It is a condition internal to the organization that increases the likelihood of a successful attack. Threats are potential causes of harm, while vulnerabilities are flaws or gaps. Missing a security update is a classic example of a vulnerability because it represents an exposure that attackers can leverage.

Why this answer

Vulnerabilities are weaknesses or gaps in protection that can be exploited, such as an unpatched web server and an unencrypted database. Threats are potential causes of harm, including ransomware groups, phishing campaigns, and natural disasters. The two correct choices describe internal weaknesses, while the other options describe threat actors or events that could exploit those weaknesses.

Exam trap

The trap here is treating any risky condition as a threat, when threats are sources of harm and vulnerabilities are the weaknesses those sources can exploit.

86
MCQmedium

A system administrator implements version control for all configuration files. Which principle is being strengthened?

A.Availability
B.Confidentiality
C.Accountability
D.Integrity
AnswerD

Version control tracks every change to configuration files, creating an auditable record that detects unauthorised or accidental modification. This directly strengthens integrity, since the stem's constraint is ensuring files remain accurate and unaltered, not restricting who may read them.

Why this answer

Version control helps ensure data accuracy and prevents unauthorized changes, supporting integrity.

87
MCQeasy

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

A.Public
B.Internal/Private
C.Confidential
D.Restricted/Top Secret
AnswerC

The stem states the organisation already classifies data as confidential and mandates encryption at rest and in transit for that level. Selecting confidential matches the label the scenario itself applies, satisfying the stated classification requirement rather than inventing a different tier.

Why this answer

The 'Confidential' classification level is the one that typically mandates encryption at rest and in transit. In standard data classification schemes, Confidential data is sensitive and requires strong protection, including encryption, to prevent unauthorized disclosure. The question states the organization classifies data as 'confidential' and requires encryption, so the level being used is Confidential.

Exam trap

CC often tests whether candidates can match a classification label to its typical handling requirements, causing confusion when a higher level (Restricted) is present but not the one explicitly named in the scenario.

How to eliminate wrong answers

Option A is wrong because Public data is intended for open disclosure and does not require encryption; it is the lowest classification. Option B is wrong because Internal/Private data may have some protections but typically does not mandate encryption at rest and in transit as a strict requirement; it is less sensitive than Confidential. Option D is wrong because Restricted/Top Secret is a higher classification than Confidential, but the question explicitly states the organization uses 'confidential' as the classification level, so the answer must match that label.

88
MCQmedium

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
AnswerC

Modifying a payroll database alters stored data, so its accuracy and trustworthiness are directly threatened. Integrity guarantees data remains unaltered by unauthorised parties; confidentiality concerns disclosure and availability concerns access, neither of which the modification attempt targets.

Why this answer

Integrity ensures that data remains accurate, complete, and unaltered unless modified by authorized parties. The unauthorized attempt to modify the payroll database directly threatens this principle because it aims to change data without permission, compromising its trustworthiness. Confidentiality, non-repudiation, and availability are not the primary concerns here, as the focus is on unauthorized modification, not disclosure, proof of origin, or access disruption.

Exam trap

The trap here is confusing integrity with confidentiality or non-repudiation, as candidates may focus on the 'unauthorized user' aspect and think of access control (confidentiality) rather than the modification attempt.

How to eliminate wrong answers

Option A is wrong because confidentiality focuses on preventing unauthorized disclosure of information, not modification. Option B is wrong because non-repudiation ensures that a party cannot deny having performed an action, which is not the primary issue in an unauthorized modification attempt. Option D is wrong because availability ensures timely and reliable access to data, which is not directly threatened by an attempt to modify data.

89
MCQhard

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerD

Declining the vendor eliminates the activity entirely, so the identified risk no longer exists. This satisfies the stem's scenario by removing the exposure rather than transferring it via insurance, mitigating it with controls, or accepting it.

Why this answer

Risk avoidance is the correct answer because the company eliminates the risk entirely by deciding not to engage with the vendor. By not hiring the vendor, the company removes the possibility of any security incidents or data breaches that could arise from the vendor's poor security practices. This is a classic example of risk avoidance, where the risk is sidestepped rather than managed or shared.

Exam trap

The trap here is confusing risk avoidance with risk mitigation, as both involve actions to address risk, but avoidance eliminates the risk entirely while mitigation reduces it.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves taking steps to reduce the impact or likelihood of a risk, such as implementing controls or safeguards, not eliminating the risk by avoiding the activity. Option B is wrong because risk acceptance means acknowledging the risk and choosing to proceed without taking action, which is not the case here since the company decided not to hire the vendor. Option C is wrong because risk transfer involves shifting the risk to a third party, such as through insurance or outsourcing, which is not what happened; the company simply avoided the risk altogether.

90
MCQeasy

Maya is a security administrator at a healthcare company. She discovers that nurses can view patient billing records even though their job duties only require access to clinical treatment notes. She wants to apply the security principle that restricts users to only the data they need to perform their assigned tasks. Which principle should she implement?

A.Least privilege
B.Defense in depth
C.Non-repudiation
D.Separation of duties
AnswerA

Least privilege means granting users only the minimum access rights necessary to perform their job functions. Since the nurses only need clinical treatment notes, removing their access to billing records directly applies this principle and reduces the risk of unauthorized data exposure. It is the most appropriate control for restricting access based on job duties in this scenario.

Why this answer

Least privilege is the security principle that requires giving users only the access needed for their specific job tasks. Because the nurses only need clinical notes, removing their billing access aligns directly with that principle. Separation of duties, defense in depth, and non-repudiation address different concerns and would not correct the excessive permissions described.

Exam trap

The trap here is confusing least privilege with separation of duties, since both limit what users can do, but only least privilege restricts access based on the minimum necessary for the job.

91
MCQmedium

A payroll administrator can view salary records for all employees during normal business hours, but only after her manager approves each access request and the system logs the action. Which security principle is BEST illustrated by limiting her access to what her job requires and only when needed?

A.Non-repudiation
B.Least privilege
C.Defense in depth
D.Separation of duties
AnswerB

Least privilege grants users only the minimum access necessary for their job function and only for as long as it is needed. Restricting the payroll administrator to the salary records her role requires, gated by approval and time windows, is a textbook application. Logging the action adds accountability and supports later review of whether that minimum access was appropriate.

Why this answer

Least privilege means granting only the access required to perform a job and only when it is required. The payroll administrator sees salary data tied to her role, must obtain approval for each request, and works within defined hours, all of which narrow access to the minimum necessary. Approval and logging reinforce accountability but do not change the underlying principle being demonstrated.

Exam trap

The trap here is confusing least privilege with separation of duties, since both restrict users, but only least privilege limits access to job need rather than splitting a task between people.

92
Multi-Selectmedium

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Select 2 answers
A.Hashing
B.Load balancing
C.Access control lists
D.Database encryption
E.Redundant power supplies
AnswersC, D

Access control lists restrict database access to authorised identities, enforcing least privilege so only approved users reach customer PII. This satisfies the stem's confidentiality requirement by preventing unauthorised disclosure, unlike integrity-focused controls such as hashing or digital signatures.

Why this answer

Access control lists (C) are appropriate because they enforce authorization by restricting which users, roles, or hosts may read the PII records, directly limiting exposure to only approved principals. Database encryption (D) is appropriate because it protects confidentiality at rest and, when applied to columns or tablespaces, renders the PII unreadable if the storage or backups are compromised. Hashing (A) is not suitable here because it is a one-way integrity mechanism, not a reversible confidentiality control for data that must be read back.

Load balancing (B) and redundant power supplies (E) are availability controls and do nothing to prevent unauthorized disclosure of PII.

Exam trap

CC often tests the distinction between confidentiality, integrity, and availability controls; candidates may incorrectly select hashing (integrity) or load balancing/redundant power (availability) when asked for confidentiality controls.

93
MCQhard

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

A.Availability
B.Confidentiality
C.Integrity
D.Non-repudiation
AnswerA

Geographically dispersed redundant servers plus load balancing keep services reachable despite outages or attacks, directly satisfying the availability concern named in the stem. This redundancy addresses uptime rather than confidentiality or integrity, which encryption and hashing would respectively protect.

Why this answer

Redundancy and load balancing ensure that systems remain accessible, supporting availability.

94
MCQhard

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

A.Risk mitigation
B.Risk acceptance
C.Risk transfer
D.Risk avoidance
AnswerC

Purchasing cyber insurance shifts the financial consequence of a breach to the insurer, which is the defining mechanism of risk transfer. The organisation retains the threat itself but transfers the monetary liability, directly satisfying the stem's scenario of covering potential breach losses rather than avoiding, mitigating or accepting the risk.

Why this answer

Purchasing cyber insurance transfers the financial impact of a data breach to a third party (the insurer) in exchange for a premium. The organization still owns the risk event, but the monetary loss is shifted to the insurer, which is the textbook definition of risk transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation — candidates see 'insurance' and think 'control,' but insurance shifts financial liability rather than reducing the probability or impact of the breach itself.

How to eliminate wrong answers

Option A is wrong because risk mitigation reduces the likelihood or impact of a risk through controls (e.g., firewalls, encryption), not by shifting financial liability. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, retaining the potential loss internally. Option D is wrong because risk avoidance eliminates the activity that creates the risk entirely (e.g., not storing the data at all), rather than offloading the consequence.

95
MCQeasy

Which of the following ensures that data has not been tampered with during transmission?

A.Redundancy
B.Encryption
C.Hashing
D.Authentication
AnswerC

Hashing produces a fixed-length digest from the transmitted data; any alteration changes the digest entirely, so comparing sender and receiver hashes detects tampering. This satisfies the stem's integrity requirement. Encryption provides confidentiality rather than modification detection, and checksums are weaker against deliberate changes.

Why this answer

Hashing ensures data integrity by producing a fixed-length digest from the original data; if even one bit changes during transmission, the resulting hash will differ, allowing the receiver to detect tampering. Common algorithms include SHA-256 and MD5 (though MD5 is deprecated for security). Hashing is specifically designed to verify that data has not been altered, which is the definition of integrity.

Exam trap

The trap is confusing integrity with confidentiality — candidates often pick 'encryption' because it sounds like it protects data, but encryption alone doesn't guarantee the data wasn't modified; hashing is the specific mechanism for integrity.

How to eliminate wrong answers

Option A is wrong because redundancy (e.g., RAID, redundant links) provides availability and fault tolerance, not integrity verification — it does not detect whether data was modified. Option B is wrong because encryption provides confidentiality by making data unreadable to unauthorized parties, but it does not inherently prove the data wasn't tampered with (though authenticated encryption modes like AES-GCM combine both). Option D is wrong because authentication verifies the identity of a user or system, not the integrity of the data itself — authentication answers 'who are you,' not 'was this data changed.'

96
MCQmedium

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

A.Advance the profession
B.Act honourably
C.Provide diligent service
D.Protect society
AnswerD

The (ISC)² Code of Ethics places the safety and welfare of society, the public trust, and the infrastructure above all other obligations. Duties to principals and employers rank lower, so protecting society takes precedence when interests conflict.

Why this answer

The (ISC)² Code of Ethics Canons are ordered by priority, and the first canon — 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' — takes precedence over all others. This means that when obligations conflict, the safety and welfare of society outweigh duties to employers, clients, or the profession. The remaining canons (act honorably, provide diligent service, advance the profession) are subordinate to this top-level obligation.

Exam trap

The trap here is that candidates often assume 'provide diligent service to your employer' is the top priority because it feels like the most immediate professional duty, but the (ISC)² Code explicitly ranks protecting society above all other obligations.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the fourth and lowest-priority canon, applying only after all higher obligations are satisfied. Option B is wrong because 'Act honourably, honestly, justly, responsibly, and legally' is the second canon, ranked below protecting society. Option C is wrong because 'Provide diligent and competent service to principals' is the third canon, which yields to the public-safety obligation when the two conflict.

97
MCQeasy

A healthcare provider must ensure that patient records remain unaltered during storage and transmission between clinics. Which security principle is being addressed when the organization implements hashing and digital signatures on those records?

A.Integrity
B.Non-repudiation
C.Confidentiality
D.Availability
AnswerA

Integrity ensures data is not modified or destroyed in an unauthorized manner. Hashing produces a digest that changes if even one bit is altered, and digital signatures bind the sender's identity to the data, so any tampering is detectable. In this scenario the healthcare provider's specific goal is to prevent and detect unauthorized alteration of patient records, which is exactly the integrity objective of the CIA triad.

Why this answer

The scenario centers on preventing and detecting unauthorized modification of patient records while they are stored and moved between clinics. Integrity controls such as hashing and digital signatures make any change detectable and bind the data to its source. Confidentiality hides contents, availability keeps data reachable, and non-repudiation proves who did something; none of those directly satisfies the requirement that the records stay unaltered.

Exam trap

The trap here is assuming that because the records are sensitive, confidentiality must be the answer, when the requirement actually concerns detecting alteration.

98
MCQeasy

Which of the following is considered Sensitive PII?

A.Email address
B.Social Security Number
C.Phone number
D.Name
AnswerB

A Social Security Number uniquely identifies an individual and is issued by the US government, so its exposure can directly enable identity theft. That inherent identifiability is what classifies it as Sensitive PII rather than ordinary personal data.

Why this answer

Sensitive PII is defined as personally identifiable information that, if disclosed, could cause harm or enable identity theft, and it typically includes data elements like Social Security Numbers, financial account numbers, and medical records. A Social Security Number is the canonical example because it is a unique government-issued identifier that can be used to open credit lines, file fraudulent tax returns, or impersonate the individual. Email addresses, phone numbers, and names are generally classified as non-sensitive PII because they are often publicly available and cannot alone be used to commit identity theft.

Exam trap

The trap here is that candidates confuse 'PII' with 'Sensitive PII' — all four options are PII, but only the Social Security Number rises to the sensitive classification because of its potential for identity theft and financial harm.

How to eliminate wrong answers

Option A is wrong because an email address is considered non-sensitive PII — it is routinely shared publicly and, by itself, cannot be used to impersonate someone or access financial accounts. Option C is wrong because a phone number is also non-sensitive PII; it is listed in public directories and does not uniquely authenticate an individual for financial or legal purposes. Option D is wrong because a name alone is non-sensitive PII — names are public information and only become sensitive when combined with other identifiers like an SSN or driver's license number.

99
MCQmedium

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

A.Integrity
B.Confidentiality
C.Availability
D.Authentication
AnswerB

Encryption such as TLS renders intercepted traffic unreadable to eavesdroppers, directly enforcing confidentiality. This principle guarantees data is disclosed only to authorised parties, matching the requirement that transmitted data cannot be read by unauthorised parties.

Why this answer

Confidentiality ensures that data is accessible only to authorized parties and is not disclosed to unauthorized individuals. Encrypting data in transit between two servers directly addresses confidentiality by rendering the data unreadable to eavesdroppers. This is the core goal of protocols like TLS, IPsec, and SSH, which the analyst would likely implement to satisfy this requirement.

Exam trap

The trap here is that candidates see 'cannot be read' and may overthink it, but the question is a straightforward mapping to the Confidentiality principle — the distractor 'Integrity' tempts those who confuse 'cannot be read' with 'cannot be modified.'

How to eliminate wrong answers

Option A is wrong because integrity ensures data has not been altered or tampered with — it is addressed by hashing and digital signatures, not by preventing unauthorized reading. Option C is wrong because availability ensures systems and data are accessible when needed — it is addressed by redundancy, backups, and DDoS mitigation, not by encryption of transmitted data. Option D is wrong because authentication verifies the identity of a user or system — it is a prerequisite for access control but does not by itself prevent an eavesdropper from reading intercepted traffic.

100
MCQeasy

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

A.Data encryption
B.Biometric authentication
C.Digital signatures
D.Redundant servers
AnswerD

Redundant servers directly sustain availability by eliminating single points of failure: if one server fails, others continue serving requests, so the service remains accessible. This satisfies the stem's availability constraint through hardware duplication, unlike logical controls such as backups or access policies, which address integrity or confidentiality instead.

Why this answer

Availability ensures systems are accessible when needed. Redundant servers provide failover capability, minimizing downtime.

101
Multi-Selectmedium

A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)

Select 2 answers
A.Calculating the annualized loss expectancy
B.Accepting the risk and documenting the decision
C.Identifying a vulnerability in a web application
D.Monitoring network traffic for anomalies
E.Transferring risk by purchasing cyber insurance
AnswersB, E

Risk acceptance is a deliberate treatment choice where the organization decides the potential loss is tolerable and documents that decision. It is one of the standard risk treatment options, along with avoidance, mitigation, and transfer. Therefore, accepting and documenting the risk is a correct example.

Why this answer

Risk treatment options include avoiding, mitigating, transferring, and accepting risk. Purchasing cyber insurance transfers financial risk to an insurer, while accepting and documenting risk is a conscious decision to tolerate it. Identifying vulnerabilities and calculating loss expectancy are assessment activities, and monitoring traffic is a control, so they are not treatment options themselves.

Exam trap

The trap here is treating risk analysis activities, such as calculating loss expectancy, as if they were risk treatment decisions.

102
MCQhard

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

A.Confidential
B.Restricted/Top Secret
C.Internal/Private
D.Public
AnswerA

Encryption at rest and in transit is the prescribed handling control for the Confidential classification, matching the stem's stated requirement exactly. Confidential data demands the strongest protective measures, whereas lower tiers such as Public or Internal do not mandate encryption in both states.

Why this answer

Confidential data typically requires strong protection like encryption; restricted/top secret may require even higher controls.

103
MCQeasy

An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?

A.Confidentiality
B.Availability
C.Integrity
D.Non-repudiation
AnswerB

Availability ensures that systems and data are accessible to authorized users when needed. Here, the power failure caused servers to shut down and data to become unavailable, directly violating availability. The UPS and generator were intended to maintain availability, but their failure resulted in a loss of access to critical data, making this the most directly compromised principle.

Why this answer

The power outage and subsequent generator failure led to servers shutting down and data becoming inaccessible. Availability ensures that systems and data are accessible to authorized users when needed. The failure of backup power directly compromised availability, as the organization could not access its critical data.

Confidentiality and integrity are not primarily affected because there is no unauthorized disclosure or modification, and non-repudiation is irrelevant to this physical infrastructure failure.

Exam trap

The trap here is assuming that data loss always equates to an integrity breach, when in fact a loss of access due to power failure is primarily an availability issue.

104
MCQhard

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerD

Risk mitigation reduces the likelihood or impact of a threat through controls. Deploying a firewall and intrusion detection system applies preventive and detective controls that lower breach probability, rather than transferring, avoiding or accepting the risk.

Why this answer

Risk mitigation reduces the likelihood or impact of a threat by implementing controls; a firewall and IDS are detective and preventive controls that lower the probability and severity of a network breach without eliminating the risk entirely. This is the textbook definition of mitigation — the risk still exists but is reduced to an acceptable level.

Exam trap

The trap here is confusing mitigation with avoidance — candidates see 'reduce the risk' and pick avoidance, forgetting that avoidance requires eliminating the underlying activity, not adding controls.

How to eliminate wrong answers

Option A is wrong because risk avoidance means eliminating the activity or asset that creates the risk entirely (e.g., disconnecting from the internet), which is not what deploying a firewall does. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, which contradicts the implementation of new controls. Option C is wrong because risk transfer shifts the financial impact to a third party, typically via cyber insurance or outsourcing — a firewall does not transfer risk.

105
MCQhard

A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?

A.It is the risk that materialized.
B.It is the impact of the security incident.
C.It is a weakness that was exploited by a threat.
D.It is the threat that exploited the system.
AnswerC

A vulnerability is a weakness or flaw in a system that can be exploited by a threat. In this case, the unpatched software is the vulnerability. The attacker (threat) exploited this weakness to gain access and deploy malware. This is the correct definition and role of the vulnerability in the incident. It is the specific flaw that allowed the breach to occur.

Why this answer

The unpatched vulnerability is a weakness in the system that was exploited by a threat (the attacker). In risk management, a vulnerability is a flaw or gap that can be leveraged to compromise security. The threat is the actor or event that exploits the vulnerability, and the risk is the potential for loss.

The impact is the resulting damage. Therefore, the vulnerability's role is that of a weakness exploited by a threat, making it the correct description.

Exam trap

The trap here is mixing up the definitions of threat, vulnerability, risk, and impact, especially when they appear together in a scenario.

106
MCQhard

A junior analyst reports that an attacker exploited an unpatched web server to steal customer data. The analyst labels the missing patch the 'risk'. According to standard risk terminology, how should the missing patch be classified?

A.As the impact, because data was stolen from the server
B.As the risk, because it is the condition that led to the loss
C.As the threat, because it enabled the compromise
D.As the vulnerability, because it is a weakness an attacker can exploit
AnswerD

A vulnerability is a weakness in a system, process, or control that a threat can exploit to cause harm. An unpatched web server is a textbook vulnerability: it is a defect in the environment, not an actor and not a measure of loss. Classifying it correctly lets the organisation prioritise patching and track the exposure until it is remediated.

Why this answer

In standard risk terminology, a vulnerability is a weakness that a threat can exploit, and the unpatched web server fits that definition precisely. Risk is the combination of the likelihood that a threat exploits a vulnerability and the resulting impact, while the threat is the actor or circumstance capable of causing harm. Naming the missing patch the vulnerability keeps cause, actor, and consequence distinct for remediation.

Exam trap

The trap here is collapsing vulnerability, threat, and risk into one label, when the unpatched server is specifically the weakness that a threat exploits to produce risk.

107
MCQhard

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

A.Discontinuing use of the vendor's software
B.Purchasing cyber insurance to cover potential losses
C.Installing a patch to fix the vulnerability
D.Accepting the risk and documenting the decision
AnswerB

Risk transfer shifts the financial consequence of a risk to a third party. Purchasing cyber insurance means the insurer absorbs potential breach losses, satisfying the stem's requirement for risk transfer, whereas patching, avoiding the vendor or accepting the exposure would not shift that financial burden.

Why this answer

Risk transfer involves shifting the financial impact of a risk to a third party, typically through insurance or contractual agreements. Purchasing cyber insurance explicitly transfers the potential financial losses from data exposure to the insurer, which is the definition of risk transfer. The other options represent risk avoidance (discontinuing use), risk mitigation (patching), or risk acceptance (accepting and documenting).

Exam trap

The trap here is confusing risk transfer with risk mitigation or avoidance; candidates often think that patching (mitigation) or discontinuing use (avoidance) transfers risk, but only shifting financial responsibility to a third party constitutes transfer.

How to eliminate wrong answers

Option A is wrong because discontinuing use of the software eliminates the risk entirely, which is risk avoidance, not transfer. Option C is wrong because installing a patch reduces the likelihood or impact of the vulnerability, which is risk mitigation, not transfer. Option D is wrong because accepting the risk and documenting it is risk acceptance, where the organization retains the potential losses.

108
MCQhard

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

A.Vulnerability
B.Control
C.Risk
D.Threat
AnswerC

Risk is the term combining the likelihood that a threat exploits a vulnerability with the resulting harm to an asset, satisfying the stem's definition. Threat alone denotes the potential cause, vulnerability the weakness, and exposure the susceptibility, none of which express probability multiplied by impact.

Why this answer

Risk is defined as the likelihood of a threat exploiting a vulnerability, resulting in harm to an asset.

109
MCQmedium

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

A.Multi-factor authentication
B.Type 3 authentication
C.Single-factor authentication
D.Type 2 authentication only
AnswerA

The smart card supplies a possession factor and the PIN supplies a knowledge factor, so two distinct factor types are combined. That combination satisfies the definition of multi-factor authentication rather than single-factor or same-category authentication.

Why this answer

Multi-factor authentication (MFA) requires two or more different authentication factors: something you have (smart card), something you know (PIN), and optionally something you are (biometric). Here, the smart card is a possession factor and the PIN is a knowledge factor, so combining them satisfies MFA. This is the correct classification because the two factors are of different types, not just two instances of the same type.

Exam trap

The trap here is confusing authentication factor types with authentication methods; candidates often think that a smart card and PIN together are still single-factor because they are both used in one process, but the key is that they represent different factor categories (possession and knowledge).

How to eliminate wrong answers

Option B is wrong because Type 3 authentication refers to 'something you are' (biometrics such as fingerprint or retina scan), which is not used here. Option C is wrong because single-factor authentication would involve only one factor (e.g., just a PIN or just a smart card), whereas the scenario uses two distinct factors. Option D is wrong because Type 2 authentication refers to 'something you have' (e.g., a smart card or token), but the scenario also includes a PIN (something you know), so it is not Type 2 only.

110
MCQhard

A security manager is documenting how the organization decides which safeguards to apply to a new customer database. The team identifies the value of the data, the threats that could exploit weaknesses, and the potential business impact, then selects controls that reduce risk to an acceptable level. Which concept best describes this activity?

A.Risk management
B.Vulnerability assessment
C.Business continuity planning
D.Security awareness training
AnswerA

Risk management is the ongoing process of identifying, assessing, and treating risk to an acceptable level. The scenario describes exactly that cycle: valuing the asset, identifying threats and vulnerabilities, evaluating business impact, and selecting controls to reduce risk. Risk treatment options include mitigation, transfer, avoidance, and acceptance. Because the team is deciding which safeguards to apply based on assessed risk, the activity is risk management rather than a single control or one-time audit.

Why this answer

The manager is following a structured process: identify and value the asset, determine threats and vulnerabilities, assess potential business impact, and choose safeguards that bring risk to an acceptable level. That end-to-end process is risk management, which includes risk identification, analysis, evaluation, and treatment. Business continuity planning addresses disruptions, awareness training changes user behavior, and vulnerability assessment only finds weaknesses; none of those encompasses the full decision cycle described.

Exam trap

The trap here is choosing vulnerability assessment because weaknesses are mentioned, but the scenario includes asset valuation, impact analysis, and control selection, which together define risk management.

111
MCQhard

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

A.Advance the profession
B.Act honorably
C.Protect society
D.Provide diligent service
AnswerC

The (ISC)² Code of Ethics canon places the safety and welfare of society and the common good above all else, including duties owed to an employer. Protecting society therefore takes precedence when the two obligations conflict, satisfying the stem's precedence requirement.

Why this answer

The (ISC)² Code of Ethics establishes a strict priority order among its canons, with 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' as the highest obligation. When this conflicts with providing diligent service to an employer or client, protecting society must take precedence. This hierarchy ensures that security professionals prioritize public safety over commercial or contractual interests.

Exam trap

The trap here is that candidates may pick 'Provide diligent service' because it feels like the most direct professional obligation, but the (ISC)² Code explicitly subordinates employer service to the protection of society.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the lowest-priority canon and only applies after all higher obligations are satisfied. Option B is wrong because 'Act honorably' is the second canon — important, but subordinate to protecting society. Option D is wrong because 'Provide diligent service' is the third canon; while professionals should serve their employers competently, this duty yields when it conflicts with the public good.

112
MCQmedium

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

A.Provide diligent and competent service to principals
B.Advance and protect the profession
C.Act honorably, honestly, justly, responsibly, and legally
D.Protect society, the common good, and the public trust
AnswerD

The (ISC)² Code of Ethics orders its canons so that the safety and welfare of society outranks all other duties, including obligations to principals or employers. Protecting society, the common good and the public trust therefore sits at the highest priority, satisfying the stem's demand for the top-ranked obligation.

Why this answer

The Code of Ethics states the highest priority is to protect society, the common good, and the public trust.

113
MCQeasy

Which of the following is a control that can reduce the risk of a DDoS attack?

A.Access control lists
B.Load balancing
C.Encryption
D.Digital signatures
AnswerB

Load balancing distributes incoming traffic across multiple servers, preventing any single node from being overwhelmed during a volumetric flood. This directly satisfies the stem's requirement to reduce DDoS risk by absorbing and spreading attack traffic, maintaining availability even when request volume spikes far beyond what one server could handle alone.

Why this answer

Load balancing helps mitigate DDoS attacks by distributing incoming traffic across multiple servers, preventing any single server from being overwhelmed by a flood of requests. This increases the capacity and resilience of the infrastructure, making it harder for an attacker to exhaust resources. While not a complete DDoS solution, load balancing is a foundational control that reduces the impact of volumetric and application-layer attacks.

Exam trap

The trap here is that candidates may choose 'Access control lists' because ACLs sound like a security control, but they are ineffective against distributed attacks with spoofed or rotating source IPs — load balancing is the control that actually absorbs and distributes the flood.

How to eliminate wrong answers

Option A is wrong because access control lists (ACLs) filter traffic based on IP addresses or ports, but they are ineffective against DDoS attacks that use spoofed or distributed source IPs — blocking one IP does not stop thousands of others. Option C is wrong because encryption protects data confidentiality in transit but does nothing to prevent or absorb a flood of malicious traffic. Option D is wrong because digital signatures provide integrity and non-repudiation for messages, not traffic absorption or rate limiting.

114
MCQmedium

A company's security policy states that employees must wear identification badges visibly at all times while on premises. A security guard checks badges at the entrance. Which type of control is the badge check?

A.Preventive control
B.Compensating control
C.Detective control
D.Corrective control
AnswerA

Preventive controls aim to stop security incidents before they occur. The security guard checking badges at the entrance prevents unauthorized individuals from entering the premises. This is a physical preventive control. By verifying identity before allowing access, it directly stops potential security breaches.

Why this answer

The badge check by a security guard is a preventive control because it stops unauthorized individuals from entering the premises. Preventive controls are designed to avoid incidents before they happen, and this is a classic example of a physical preventive control. Other control types like detective, corrective, or compensating do not fit the scenario.

Exam trap

The trap here is thinking that any human verification is detective, but it's actually preventive because it stops access before entry.

115
Multi-Selectmedium

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Select 2 answers
A.Hashing of passwords
B.Redundant network links
C.Encryption of data at rest
D.Regular data backups
E.Role-based access controls
AnswersC, E

Encryption of data at rest renders stored customer data unreadable without the correct cryptographic keys, directly satisfying the confidentiality requirement. If disks or backups are stolen, ciphertext remains protected, unlike plaintext storage. This control addresses the stem's constraint by preventing unauthorised disclosure of data while it resides on storage media.

Why this answer

Encryption of data at rest (C) is correct because it renders stored customer data unreadable to unauthorized parties, protecting confidentiality even if the storage media or database is compromised. Role-based access controls (E) are correct because RBAC enforces least privilege, ensuring only authorized users with the appropriate role can access customer data, directly limiting exposure. Hashing of passwords (A) protects password integrity/verification but is not a general confidentiality control for customer data, and hashes are one-way rather than reversible protection of data.

Redundant network links (B) address availability through fault tolerance, not confidentiality. Regular data backups (D) support availability and recovery, not confidentiality, since backups can themselves expose data if unprotected.

Exam trap

The trap here is confusing controls that support availability or integrity (backups, redundancy, hashing) with controls that specifically enforce confidentiality — candidates often pick backups or hashing because they 'sound secure' without mapping them to the CIA property being tested.

116
MCQhard

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

A.Risk acceptance
B.Risk transfer
C.Due care
D.Due diligence
AnswerD

Due diligence is the investigation and verification of a vendor's security controls, financial standing and background before entering a contract. The stem describes exactly that: assessing controls and performing background checks on a prospective processor. It satisfies the pre-engagement evaluation constraint, distinguishing it from ongoing monitoring or contractual enforcement.

Why this answer

Due diligence is the ongoing process of investigation, assessment, and verification — performing a thorough security assessment and background checks on a vendor before engaging them is the textbook definition of exercising due diligence. It demonstrates that the organization took reasonable steps to understand and evaluate the risks involved. Due care, by contrast, is the ongoing action of maintaining that standard once the relationship exists.

Exam trap

The trap is the classic due diligence vs. due care confusion — candidates often select due care because both sound like 'being careful,' but the exam expects you to recognize that investigation/assessment is due diligence and ongoing protection is due care.

How to eliminate wrong answers

Option A is wrong because risk acceptance is a deliberate decision to acknowledge a risk and take no action — the opposite of performing an assessment. Option B is wrong because risk transfer shifts the financial impact of a risk to a third party (e.g., via insurance or contract), which is not what an assessment accomplishes. Option C is wrong because due care refers to the ongoing duty to act reasonably and maintain safeguards after the decision is made, whereas the question describes the pre-engagement investigation phase.

117
MCQeasy

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

A.Availability
B.Authentication
C.Integrity
D.Confidentiality
AnswerC

Hashing produces a fixed-length digest from the transmitted data; any modification changes the digest, so the recipient can verify the data arrived unaltered. This directly satisfies the requirement to detect alteration during transmission, which is the integrity principle.

Why this answer

Hashing produces a fixed-length digest that acts as a fingerprint of the data. If even a single bit changes during transmission, the resulting hash will differ, allowing the receiver to detect any alteration. This directly enforces the security principle of integrity, which ensures data is not modified in an unauthorized or accidental manner.

Exam trap

The trap here is confusing integrity with authentication or confidentiality; candidates often think hashing provides authentication because it verifies data, but it only ensures the data hasn't changed, not who sent it.

How to eliminate wrong answers

Option A is wrong because availability ensures timely and reliable access to resources, typically addressed by redundancy, backups, and DDoS protection—not by hashing. Option B is wrong because authentication verifies the identity of a user or system, often using passwords, certificates, or biometrics, whereas hashing alone does not prove who sent the data. Option D is wrong because confidentiality protects data from unauthorized disclosure, usually through encryption (e.g., AES, TLS), not hashing, which does not hide the original data.

118
MCQhard

A security manager is reviewing the organization's approach to risk. The manager decides to purchase cyber insurance to transfer some of the financial risk associated with a data breach. Which risk management strategy is being used?

A.Risk acceptance
B.Risk avoidance
C.Risk transference
D.Risk mitigation
AnswerC

Risk transference shifts the financial impact of a risk to a third party, such as an insurance company. By purchasing cyber insurance, the organization transfers some of the financial risk of a data breach to the insurer. This is a classic example of risk transference.

Why this answer

Risk transference involves shifting the financial impact of a risk to another party, often through insurance or contracts. Cyber insurance is a common method of transferring the financial consequences of a data breach. The organization still owns the risk of the breach occurring, but the financial loss is partially borne by the insurer.

This strategy is distinct from avoidance, mitigation, and acceptance.

Exam trap

The trap here is confusing risk transference with mitigation because insurance is a control, but it does not reduce the likelihood or impact of the breach itself, only the financial aftermath.

119
MCQeasy

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

A.Authentication
B.Confidentiality
C.Integrity
D.Availability
AnswerB

Confidentiality directly prevents unauthorised disclosure by restricting data access to approved parties only. It is the CIA principle concerned with secrecy, unlike integrity (unauthorised modification) or availability (timely access). This satisfies the stem's requirement that data is not disclosed to unauthorised individuals.

Why this answer

Confidentiality is the CIA triad principle that ensures information is not disclosed to unauthorized individuals, systems, or processes. It is enforced through encryption, access controls, and data classification. Authentication verifies identity but does not itself guarantee confidentiality, and integrity and availability address different properties.

Exam trap

The trap is confusing authentication with confidentiality — candidates often pick authentication because it 'sounds like security,' but authentication is an identity-verification function, not the data-secrecy principle.

How to eliminate wrong answers

Option A is wrong because authentication is the process of verifying a claimed identity (e.g., via passwords, MFA) — it is a prerequisite for access control but not the confidentiality principle itself. Option C is wrong because integrity ensures data is accurate and unaltered, not that it is kept secret. Option D is wrong because availability ensures data and systems are accessible when needed, which is unrelated to preventing disclosure.

120
MCQmedium

An organization implements a defense-in-depth strategy by deploying firewalls, intrusion detection systems, and endpoint protection. Which security principle does this approach primarily demonstrate?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Zero trust
AnswerC

Defense in depth is a layered security approach where multiple controls are used to protect assets. By deploying firewalls, intrusion detection systems, and endpoint protection, the organization creates overlapping defenses that reduce the likelihood of a single point of failure. This directly exemplifies the defense-in-depth principle, which is a core security strategy.

Why this answer

The correct answer is defense in depth. This principle involves implementing multiple layers of security controls so that if one fails, others still provide protection. Firewalls, intrusion detection systems, and endpoint protection are classic examples of layered defenses.

Least privilege, separation of duties, and zero trust are related but distinct concepts that do not directly describe the scenario.

Exam trap

The trap here is confusing defense in depth with zero trust, assuming any multiple-control deployment is zero trust, when zero trust specifically requires continuous verification and no implicit trust.

121
MCQhard

A hospital's compliance officer is mapping controls for a new patient portal. The legal team wants documented assurance that a clinician cannot later deny having approved a medication order submitted through the portal. Which security principle is the legal team most directly requesting?

A.Integrity
B.Availability
C.Non-repudiation
D.Confidentiality
AnswerC

Non-repudiation provides irrefutable evidence that a specific identity performed a specific action, so the clinician cannot credibly deny approving the order. Digital signatures and tamper-evident audit logs bound to the clinician's authenticated identity deliver this proof. The legal team wants documented assurance of authorship and approval, which is precisely what non-repudiation supplies in a dispute.

Why this answer

The legal team needs proof of who performed an action so it cannot be denied later. That is non-repudiation, usually achieved with digital signatures, strong authentication, and tamper-evident audit logging tied to individual identities. Integrity protects against unauthorized changes, confidentiality protects against disclosure, and availability protects against loss of access; none of these establishes undeniable authorship of the medication order.

Exam trap

The trap here is choosing integrity because the order record must remain unchanged, when the actual requirement is proving which clinician performed the action.

122
MCQmedium

A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?

A.Deploy file integrity monitoring on the repositories
B.Enforce a password complexity policy for all accounts
C.Require multi-factor authentication for repository access
D.Revoke the contractor's access rights during offboarding
AnswerD

Revoking access rights is the administrative control that directly removes the contractor's ability to authenticate and reach internal repositories once the engagement ends. Timely offboarding, including disabling accounts and removing group memberships, closes the window in which former credentials remain usable. This matches the scenario because the goal is to prevent a dismissed contractor from using issued credentials, which only revocation accomplishes.

Why this answer

The scenario's core problem is that a former contractor retains valid credentials after the contract ends. Administrative controls govern people and processes, and timely revocation of access rights during offboarding removes the account's authority entirely. Monitoring detects but does not prevent, password complexity does not invalidate a known password, and MFA still lets the former contractor log in, so revocation is the correct control.

Exam trap

The trap here is treating a technical authentication hardening measure as a substitute for terminating a former worker's authorization.

123
MCQmedium

A software development team is designing a new application that will process credit card payments. The security architect recommends that the application should not store the card verification value (CVV) after the transaction is authorized. Which principle is the architect applying?

A.Least privilege
B.Data minimization
C.Separation of duties
D.Defense in depth
AnswerB

Data minimization means collecting and retaining only the data necessary for a specific purpose. Not storing the CVV after authorization reduces the amount of sensitive data at risk and aligns with the principle of limiting data retention to what is needed. This directly matches the architect's recommendation to avoid storing a sensitive element once it is no longer required.

Why this answer

The architect recommends not retaining the CVV after the transaction, which reduces the amount of sensitive data the application holds. This is data minimization, the practice of limiting collection and retention to what is necessary. Least privilege is about access rights, separation of duties is about dividing tasks, and defense in depth is about layered controls, so data minimization is the correct principle.

Exam trap

The trap here is selecting least privilege because it sounds security-related, when the scenario is actually about limiting what data is stored rather than who can access it.

124
MCQmedium

A financial services firm wants to ensure that a single employee cannot initiate and approve a large wire transfer alone. The firm implements a process where one employee creates the transfer and a different employee must approve it. Which security principle is being applied?

A.Least privilege
B.Separation of duties
C.Mandatory vacation
D.Job rotation
AnswerB

Separation of duties divides a critical task among multiple people so that no single individual can complete it alone, reducing the risk of fraud or error. Requiring one employee to create and another to approve the wire transfer directly implements this principle. It ensures that a single person cannot both initiate and authorize a high-risk financial action.

Why this answer

Separation of duties ensures that a critical task requires more than one person to complete, preventing a single individual from abusing the process. By having one employee create the wire transfer and another approve it, the firm applies this principle directly. Least privilege, job rotation, and mandatory vacation serve different purposes and do not enforce dual control over a single transaction.

Exam trap

The trap here is thinking that any control involving multiple people is separation of duties, when in fact mandatory vacation and job rotation also involve others but do not split a single task into separate authorizations.

125
MCQmedium

Which of the following controls is primarily designed to ensure availability?

A.Redundant servers
B.Encryption
C.Digital signatures
D.Access control lists
AnswerA

Redundant servers directly satisfy the availability requirement by eliminating single points of failure: if one server fails, another continues serving requests, so the service remains accessible. Unlike confidentiality or integrity controls, redundancy targets uptime specifically, matching the stem's availability constraint through failover rather than prevention of unauthorised access or data alteration.

Why this answer

Redundant servers ensure availability by eliminating single points of failure — if one server fails, another continues to provide the service. This directly supports the availability leg of the CIA triad.

Exam trap

The CC exam often tests whether candidates can map controls to the correct CIA triad element, and redundancy is sometimes confused with integrity or confidentiality controls.

How to eliminate wrong answers

Option B is wrong because encryption primarily ensures confidentiality by protecting data from unauthorized disclosure. Option C is wrong because digital signatures primarily ensure integrity and authenticity, not availability. Option D is wrong because access control lists primarily ensure confidentiality and integrity by restricting who can access resources.

126
Multi-Selecthard

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Select 3 answers
A.Probability of a data breach
B.Customer database
C.Vulnerability in software
D.Firewall
E.Employee expertise
AnswersB, D, E

A customer database is an information asset: it holds valuable data the organisation must protect, and it carries risk exposure if compromised, lost or corrupted. Risk assessments inventory such assets before identifying threats and vulnerabilities, making the database a legitimate asset in this scenario.

Why this answer

In risk assessment, an asset is anything of value to the organization that could be affected by a threat, so the customer database (B) qualifies because it holds valuable data whose loss or exposure would harm the business. The firewall (D) is a tangible asset—hardware or software that protects the network and represents a resource the organization owns and depends on. Employee expertise (E) is an intangible asset, since the knowledge, skills, and experience of staff are valuable resources that can be lost through turnover or social engineering.

The probability of a data breach (A) is not an asset but a likelihood or risk factor used to estimate how often a threat might occur. A vulnerability in software (C) is a weakness or gap in a control, not something of value, so it is a risk element rather than an asset.

Exam trap

The CC exam often tests whether candidates can distinguish assets (things of value) from vulnerabilities (weaknesses) and risks (probability/impact combinations), which are frequently mixed in the answer choices.

127
Multi-Selectmedium

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Select 2 answers
A.Smart card and OTP token
B.Fingerprint and password
C.Password and smart card
D.Fingerprint and retina scan
E.Password and PIN
AnswersB, C

A fingerprint is something you are (inherence), while a password is something you know (knowledge). Pairing them spans two separate factor categories, satisfying true multi-factor authentication. Two biometrics, or two passwords, would not qualify as genuine multi-factor.

Why this answer

Option B (fingerprint and password) is correct because it combines a biometric inherence factor (the fingerprint) with a knowledge factor (the password), satisfying true MFA by mixing two different factor categories. Option C (password and smart card) is correct because it pairs a knowledge factor (the password) with a possession factor (the smart card, something you have), which are distinct factor types. Option A (smart card and OTP token) is not true MFA because both are possession factors (something you have), even though they are different technologies.

Option D (fingerprint and retina scan) is not true MFA because both are biometric inherence factors (something you are). Option E (password and PIN) is not true MFA because both are knowledge factors (something you know).

Exam trap

The trap is that candidates see two different-looking authentication methods and assume MFA, without checking whether both factors belong to the same category (e.g., two biometrics or two knowledge factors).

128
MCQmedium

Which of the following is classified as sensitive PII?

A.Medical records
B.Email address
C.Telephone number
D.Date of birth
AnswerA

Medical records combine health information with identifying details, forming sensitive PII whose exposure causes harm or discrimination. Unlike names or email addresses alone, health data attracts stricter legal protection, making it the sensitive category here.

Why this answer

Sensitive PII is data that, if disclosed, could cause harm or discrimination — medical records qualify because they contain health information protected under HIPAA and similar regulations. Sensitive PII typically includes health data, financial account numbers, Social Security numbers, and biometric data. Email address, telephone number, and date of birth are considered non-sensitive PII because they are publicly available or low-risk in isolation.

Exam trap

The trap is assuming any personal identifier is 'sensitive' — candidates pick date of birth or email because they are personal, but the exam expects recognition that health, financial, and biometric data are the sensitive categories.

How to eliminate wrong answers

Option B is wrong because an email address alone is generally classified as non-sensitive PII — it is often public and does not reveal health, financial, or biometric information. Option C is wrong because a telephone number is non-sensitive PII; it is publicly listed in many directories and does not by itself cause harm if disclosed. Option D is wrong because date of birth, while personal, is typically non-sensitive PII unless combined with other identifiers like SSN or name — it is often available in public records.

129
MCQeasy

A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?

A.Confidentiality
B.Non-repudiation
C.Integrity
D.Availability
AnswerA

Confidentiality ensures information is not disclosed to unauthorized individuals, entities, or processes. Restricting patient record access to on-shift nurses and physicians directly limits disclosure to authorized parties, which is the core of confidentiality. This scenario is about preventing unauthorized viewing, not about keeping data accurate or available, so confidentiality is the principle being enforced.

Why this answer

The requirement limits access to patient records so only authorized on-shift nurses and physicians can view them, which is a disclosure control. Confidentiality is the security principle that prevents information from being disclosed to unauthorized individuals. Integrity addresses unauthorized changes, availability addresses timely access, and non-repudiation addresses proof of actions, so confidentiality is the correct principle.

Exam trap

The trap here is assuming that any access control example must be about availability because authorized users need access, when the requirement actually focuses on preventing unauthorized disclosure.

130
MCQmedium

A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?

A.Fingerprint and retina scan
B.Smart card and PIN
C.Username and password
D.Password and security question
AnswerB

A smart card is a possession factor (something the user has), and a PIN is a knowledge factor (something the user knows). Combining these two satisfies the requirement of using something the user knows and something the user has. This is a classic example of multi-factor authentication that strengthens identity verification by requiring two different types of credentials.

Why this answer

Multi-factor authentication requires combining two or more different types of factors: something you know, something you have, something you are, somewhere you are, or something you do. The scenario explicitly requires something the user knows and something the user has. A smart card (possession) and a PIN (knowledge) meet this requirement, while the other options use factors of the same type or do not include a possession factor.

Exam trap

The trap here is assuming that any two authentication methods constitute multi-factor authentication, when they must be of different factor types.

131
MCQhard

Which of the following best describes the difference between due care and due diligence in security governance?

A.Due care is proactive, due diligence is reactive
B.They are synonymous
C.Due care applies to vendors; due diligence applies to employees
D.Due care is the minimum standard of care; due diligence is the investigation and assessment
AnswerD

Due care is the minimum standard of care an organisation must exercise, while due diligence is the ongoing investigation and assessment underpinning it. This distinction separates the duty itself from the research activity that informs it.

Why this answer

Due care refers to the minimum standard of care that an organization must exercise to protect its assets, often defined by laws, regulations, or industry best practices. Due diligence is the ongoing process of investigation, assessment, and verification to ensure that due care is maintained. In security governance, due care is the baseline, while due diligence is the active effort to identify and mitigate risks.

Exam trap

The trap is that candidates often think due care and due diligence are interchangeable or that one is proactive and the other reactive; the exam tests the precise definitions.

How to eliminate wrong answers

Option A is wrong because due care is not inherently proactive or reactive; it is a standard, while due diligence involves proactive investigation. Option B is wrong because they are distinct concepts; due care is the standard, due diligence is the process. Option C is wrong because both due care and due diligence apply to all aspects of an organization, including vendors and employees, not exclusively one or the other.

132
MCQeasy

Which of the following is an example of a Type 2 authentication factor?

A.PIN
B.Password
C.Smart card
D.Fingerprint
AnswerC

A smart card is something the user possesses, which defines a Type 2 possession factor. It is not a knowledge factor (Type 1) nor an inherence factor (Type 3), so it satisfies the question's requirement for a possession-based example.

Why this answer

A Type 2 authentication factor is something you have, such as a physical device or token. A smart card is a physical object that a user possesses and inserts into a reader or taps, making it a classic example of a possession factor. Therefore, smart card is the correct answer.

Exam trap

The trap here is confusing something you have with something you know or are; candidates often misclassify a smart card as something you know because it may require a PIN, but the card itself is a possession factor.

How to eliminate wrong answers

Option A is wrong because a PIN is something you know, which is a Type 1 factor. Option B is wrong because a password is also something you know, a Type 1 factor. Option D is wrong because a fingerprint is something you are, a Type 3 factor (inherence).

133
MCQmedium

A company's security policy states that only staff in the finance department may access the general ledger, and that access must be reviewed every quarter. An auditor finds that two former finance employees still hold active accounts with ledger permissions. Which concept has the organization FAILED to apply?

A.Non-repudiation
B.Need to know
C.Integrity
D.Availability
AnswerB

Need to know means access to information is granted only to those who require it to perform their duties. The two former employees no longer work in finance, so they have no business need for ledger access, yet their permissions persist. The failure to remove access when the need ended is the essence of a need-to-know violation and a common audit finding.

Why this answer

Need to know restricts access to information strictly to individuals whose duties require it. Former finance employees have no current business justification for ledger permissions, so their active accounts violate this principle regardless of whether they have logged in. The quarterly review requirement exists precisely to catch and remove such stale entitlements before they become an insider threat.

Exam trap

The trap here is focusing on the missed quarterly review as the only failure, when the deeper issue is that people without a current business need retain access at all.

134
MCQmedium

Which of the following is an example of a Type 1 authentication factor?

A.One-time password (OTP) token
B.PIN code
C.Smart card
D.Fingerprint scan
AnswerB

A PIN code is something you know, which is the defining characteristic of a Type 1 authentication factor. Type 1 factors rely on knowledge, distinguishing them from Type 2 (possession) and Type 3 (inherence) factors.

Why this answer

A Type 1 authentication factor is something you know, such as a password, PIN, or passphrase. A PIN code is a memorized secret, so it is a classic example of a knowledge-based factor. The other options represent different factor types: OTP token and smart card are something you have (Type 2), and fingerprint scan is something you are (Type 3).

Exam trap

The trap here is confusing authentication factor types: candidates often mistake a PIN for a possession factor because it's used with a card, but it's actually a knowledge factor.

How to eliminate wrong answers

Option A is wrong because an OTP token is a physical device that generates one-time passwords, making it a possession factor (Type 2), not a knowledge factor. Option C is wrong because a smart card is a physical object you possess, which is a Type 2 factor. Option D is wrong because a fingerprint scan is a biometric characteristic, which is a Type 3 factor (something you are).

135
MCQhard

A security manager is assessing the risk of a new web application. The manager identifies that the application has a known SQL injection vulnerability, and that attackers frequently scan for such flaws. Which term best describes the SQL injection flaw itself?

A.Risk
B.Vulnerability
C.Impact
D.Threat
AnswerB

A vulnerability is a weakness in a system that can be exploited by a threat. The SQL injection flaw is a specific weakness in the web application's code that allows attackers to manipulate database queries. It is the vulnerability that, if exploited, could lead to data breaches. Thus, the flaw itself is correctly termed a vulnerability.

Why this answer

The correct answer is vulnerability. A vulnerability is a weakness or flaw in a system that can be exploited by a threat. The SQL injection flaw is a specific weakness in the web application.

Threat refers to the attacker or attack method, risk is the potential for loss, and impact is the resulting harm. Therefore, the flaw itself is a vulnerability.

Exam trap

The trap here is confusing vulnerability with risk, assuming that the flaw is the risk rather than the weakness that contributes to risk.

136
MCQmedium

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

A.Authentication
B.Availability
C.Integrity
D.Confidentiality
AnswerC

Hashing produces a fixed-length digest that changes if even one bit of the file is modified, so recomputing and comparing it detects tampering. This directly satisfies the integrity goal of ensuring the downloaded file has not been altered in transit or at rest.

Why this answer

Hashing ensures data integrity by detecting changes.

137
MCQmedium

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

A.Biometric authentication
B.Single-factor authentication
C.Multi-factor authentication
D.Two-step authentication
AnswerC

Multi-factor authentication combines two or more different authentication factor categories: something you know (the password) and something you are (the fingerprint). Because the factors span knowledge and inherence, rather than two instances of the same category, this satisfies the stem's requirement for both a password and a biometric scan.

Why this answer

Multi-factor authentication (MFA) requires two or more factors from different categories: something you know (password), something you have (token), or something you are (biometric). Here, the password is a knowledge factor and the fingerprint is an inherence/biometric factor, so combining them satisfies MFA. Because the factors come from distinct categories, this is true MFA rather than a single-factor or same-category combination.

Exam trap

The trap here is confusing 'two-step authentication' with 'multi-factor authentication' — candidates see two prompts and pick two-step, missing that MFA specifically requires factors from different categories.

How to eliminate wrong answers

Option A is wrong because biometric authentication alone describes only the fingerprint factor and ignores the password, so it does not capture the combined requirement. Option B is wrong because single-factor authentication uses only one credential type, whereas this scenario uses two distinct factors. Option D is wrong because 'two-step authentication' typically refers to two methods from the same factor category (e.g., password plus a PIN), which is weaker than MFA and not the precise term for combining a password with a biometric.

138
Multi-Selectmedium

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Select 2 answers
A.Fingerprint and iris scan
B.Password and security questions
C.Password and SMS one-time code
D.Smart card and PIN
E.Two different passwords
AnswersC, D

A password plus an SMS one-time code combines two different authentication factors: something you know and something you possess. This satisfies the stem's requirement for multi-factor authentication on remote access, since possession of the registered phone is needed alongside the password.

Why this answer

Option C is correct because a password (something you know) combined with an SMS one-time code sent to a phone (something you have) combines two different authentication factors, satisfying MFA. Option D is correct because a smart card (something you have) plus a PIN (something you know) also combines two distinct factor types. Option A is not correct because a fingerprint and an iris scan are both inherence factors (something you are), so they are the same factor category.

Option B is not correct because a password and security questions are both knowledge factors (something you know). Option E is not correct because two different passwords are still both knowledge factors, not multiple factor types.

Exam trap

The trap is counting the number of authentication steps rather than the number of distinct factor categories — two biometrics or two passwords feel like MFA but are not.

139
MCQmedium

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

A.Act honorably, honestly, justly, and responsibly
B.Protect society, the common good, and the public trust
C.Advance and protect the profession
D.Provide diligent and competent service to principals
AnswerB

The ISC2 Code of Ethics orders canons so that protect society, the common good, and the public trust ranks first, ahead of duties to principals and peers. Handling names, addresses and Social Security numbers therefore falls under this highest-priority canon.

Why this answer

The ISC2 Code of Ethics explicitly orders its canons by priority, with the protection of society, the common good, and the public trust as the highest. When handling sensitive data like SSNs, the potential harm to individuals and society from a breach outweighs obligations to clients or the profession. This canon ensures that security professionals prioritize the safety and well-being of the public above all else.

Exam trap

The trap here is that candidates often assume the canon about serving principals (employers/clients) is paramount, but ISC2 explicitly prioritizes public safety above all else.

How to eliminate wrong answers

Option A is wrong because 'Act honorably, honestly, justly, and responsibly' is the fourth and lowest priority canon, focusing on personal conduct rather than public welfare. Option C is wrong because 'Advance and protect the profession' is the third canon, which, while important, is subordinate to public trust. Option D is wrong because 'Provide diligent and competent service to principals' is the second canon, emphasizing duties to employers or clients, but it does not override the obligation to society.

140
MCQeasy

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

A.Non-repudiation
B.Availability
C.Integrity
D.Confidentiality
AnswerD

Confidentiality ensures data is readable only by authorised parties. Encryption at rest protects stored data and encryption in transit protects data on the wire, so both controls prevent unauthorised disclosure — the specific CIA principle the organisation is addressing.

Why this answer

Encryption ensures data is not readable by unauthorized parties, thereby protecting confidentiality.

141
MCQhard

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

A.Risk transfer
B.Due care
C.Data classification
D.Data retention
AnswerC

Assigning the 'Confidential' label is itself the act of categorising data by sensitivity, which is data classification. Encryption at rest and in transit are the handling controls that the classification drives, not the classification itself, so the label satisfies the scenario's requirement.

Why this answer

Labeling data as 'Confidential' with handling requirements like encryption at rest and in transit is the definition of data classification — assigning sensitivity levels that drive protective controls. Classification is the foundational step that determines which encryption, access, and retention policies apply.

Exam trap

The CC exam often tests whether candidates confuse data classification (labeling by sensitivity) with adjacent governance concepts like retention, due care, or risk transfer — the keyword 'labels' or 'classification levels' points to classification.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts financial impact to a third party (e.g., cyber insurance or outsourcing), which is unrelated to labeling data sensitivity. Option B is wrong because due care refers to the ongoing diligence an organization exercises to meet its security obligations; classification is one mechanism of due care, not the concept itself. Option D is wrong because data retention defines how long data is kept and when it is destroyed, not how it is labeled or protected based on sensitivity.

142
MCQmedium

According to the (ISC)² Code of Ethics, which principle has the highest priority?

A.Act honorably
B.Protect society
C.Advance the profession
D.Provide diligent service
AnswerB

The (ISC)² Code of Ethics canon ordering places the safety and welfare of society first, ahead of duties to principals, the profession, and colleagues. Protecting society therefore holds the highest priority, satisfying the stem's request for the top-ranked principle.

Why this answer

The (ISC)² Code of Ethics prioritizes protecting society, the common good, and public safety above all.

143
MCQmedium

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

A.Access control
B.Digital signature
C.Encryption
D.Load balancing
AnswerB

A digital signature is generated from a hash of the message encrypted with the sender's private key, so the recipient can verify integrity and confirm the content was not altered in transit, satisfying the tamper-detection requirement.

Why this answer

A digital signature uses the sender's private key to cryptographically sign the message hash, allowing the recipient to verify both the origin and that the message was not altered in transit. Any modification to the message invalidates the signature because the recomputed hash will not match. This provides integrity and non-repudiation, which is exactly what the organization needs.

Exam trap

The trap here is confusing encryption (confidentiality) with digital signatures (integrity/non-repudiation) — candidates often pick encryption because it sounds like it 'protects' the message, but it does not detect alteration.

How to eliminate wrong answers

Option A is wrong because access control governs who can access resources, not whether a message was modified during transmission. Option C is wrong because encryption provides confidentiality by hiding content but does not by itself prove the message was unaltered — an attacker could re-encrypt modified content. Option D is wrong because load balancing distributes traffic for availability and performance, and has no role in verifying message integrity.

144
MCQeasy

What is the primary purpose of hashing in information security?

A.To provide availability
B.To encrypt data for confidentiality
C.To ensure data integrity
D.To authenticate users
AnswerC

Hashing produces a fixed-length digest from input data; any alteration to that input yields a different digest, so recomputing and comparing hashes detects modification. This one-way property provides integrity verification, unlike encryption, which provides confidentiality by making data unreadable.

Why this answer

Hashing produces a fixed-length digest from input data, and any change to the input produces a completely different hash. This property makes hashing the standard mechanism for verifying data integrity, such as checking file downloads or validating message contents. It is a one-way function, so it does not provide confidentiality or authentication by itself.

Exam trap

The trap is assuming hashing provides confidentiality because it 'scrambles' data — but hashing is one-way and irreversible, so it cannot protect data confidentiality like encryption does.

How to eliminate wrong answers

Option A is wrong because availability concerns uptime and access to resources, which hashing does not address. Option B is wrong because hashing is one-way and not reversible — it is not encryption, which is designed to be decrypted with a key. Option D is wrong because authentication verifies identity, typically through credentials or certificates; hashing supports password storage but does not authenticate users on its own.

145
MCQhard

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

A.Risk avoidance
B.Risk acceptance
C.Risk transfer
D.Risk mitigation
AnswerB

Accepting the residual exposure because remediation cost outweighs potential loss is risk acceptance — the organisation acknowledges the threat and deliberately retains it. This differs from mitigation, transfer or avoidance, which alter or shift the risk instead.

Why this answer

Risk acceptance means acknowledging the risk and not taking further action.

146
Multi-Selecthard

A security manager is reviewing the organization's risk management approach. She wants to ensure that the team correctly distinguishes between threats, vulnerabilities, and risks. Which two of the following statements correctly describe these concepts? (Choose two.)

Select 2 answers
A.A vulnerability is the probability that a threat will occur.
B.A threat always results in a risk, regardless of whether a vulnerability exists.
C.A threat is any potential cause of an unwanted incident that could harm assets.
D.Risk is the same as the impact of a threat event, regardless of likelihood.
E.A vulnerability is a weakness that could be exploited by a threat.
AnswersC, E

A threat is any potential cause of an unwanted incident that could exploit a vulnerability and cause harm to assets. Threats can be natural (e.g., floods), human (e.g., hackers), or environmental. This definition is correct because it captures the external or internal actor or event that can act upon a vulnerability. Risk arises when a threat exploits a vulnerability, so this statement accurately describes a threat.

Why this answer

The two correct statements accurately define a vulnerability as a weakness that can be exploited and a threat as a potential cause of an unwanted incident. These definitions are foundational in risk management: risk arises when a threat exploits a vulnerability, leading to potential impact. The other statements incorrectly equate risk with impact alone, confuse vulnerability with probability, or claim threats always create risk without considering vulnerabilities.

Exam trap

The trap here is mixing up the definitions of threat, vulnerability, and risk, especially by assuming that a threat alone constitutes risk or that risk is solely about impact.

147
Multi-Selectmedium

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Select 2 answers
A.Smart card and RSA token
B.Password and SMS one-time code
C.Biometric and PIN
D.Fingerprint and retina scan
E.Password and security question
AnswersB, C

A password is something you know, while an SMS one-time code is delivered to something you possess, the enrolled phone. Combining two distinct factor categories satisfies multi-factor authentication, whereas two passwords or two possession tokens would not.

Why this answer

Option B (Password and SMS one-time code) is correct because it combines two different authentication factor categories: something you know (the password) and something you have (the SMS one-time code delivered to your phone), which is the definition of multi-factor authentication. Option C (Biometric and PIN) is correct because it pairs something you are (the biometric, such as a fingerprint) with something you know (the PIN), satisfying the requirement for multiple distinct factor types. Option A is not multi-factor because a smart card and an RSA token are both something you have, so they belong to the same factor category.

Option D is not multi-factor because a fingerprint and a retina scan are both inherence factors (something you are). Option E is not multi-factor because a password and a security question are both knowledge factors (something you know).

Exam trap

The trap here is that candidates often assume any two authentication methods constitute MFA, but the methods must belong to different factor categories (knowledge, possession, inherence).

148
Multi-Selecthard

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Select 3 answers
A.Risk acceptance
B.Risk transfer
C.Risk communication
D.Risk mitigation
E.Risk analysis
AnswersA, B, D

Risk acceptance is a valid treatment: the organisation acknowledges the risk and proceeds without action, typically when exposure falls within tolerance or mitigation costs exceed potential impact. It sits alongside avoidance, transfer and mitigation as recognised responses.

Why this answer

Risk acceptance (A) is a valid risk treatment option because the organization consciously decides to tolerate the risk without taking action, often when the cost of mitigation exceeds the potential impact. Risk transfer (B) is valid because the organization shifts the financial impact of a risk to a third party, typically through insurance, outsourcing, or contracts. Risk mitigation (D) is valid because it involves taking actions to reduce the probability or impact of a risk, such as implementing controls or safeguards.

Risk communication (C) is not a treatment option; it is an ongoing activity for sharing risk information among stakeholders. Risk analysis (E) is not a treatment option either; it is part of risk assessment, used to identify and evaluate risks before treatment decisions are made.

149
MCQmedium

Which of the following is considered sensitive personally identifiable information (PII)?

A.Date of birth
B.Telephone number
C.Medical records
D.Email address
AnswerC

Sensitive PII is data that, if disclosed, could cause harm or enable identity theft. Medical records uniquely combine health information with identifiers, so their exposure triggers legal, privacy and discrimination risks. Names or email addresses alone lack that harm potential, making medical records the sensitive category.

Why this answer

Medical records are classified as sensitive PII because they contain protected health information (PHI) that, if disclosed, can cause significant harm such as discrimination, identity theft, or privacy violations. Regulations like HIPAA and GDPR treat health data as a special category requiring stricter safeguards than ordinary identifiers. Date of birth, telephone number, and email address are direct identifiers but are not inherently sensitive on their own.

Exam trap

The trap here is confusing 'PII' with 'sensitive PII' — candidates see common identifiers like DOB or email and assume any personal data qualifies as sensitive, when the exam expects recognition that only categories like medical, financial, or biometric data are sensitive.

How to eliminate wrong answers

Option A is wrong because a date of birth is a basic identifier, not sensitive PII by itself — it only becomes sensitive when combined with other data like name or SSN. Option B is wrong because a telephone number is contact information, classified as ordinary PII, not sensitive PII. Option D is wrong because an email address is a standard identifier used for communication and is not considered sensitive PII under frameworks like HIPAA or GDPR.

150
MCQeasy

Which of the following best describes the purpose of due care in information security?

A.Implementing reasonable security measures to protect data
B.Prioritizing security incidents based on impact
C.Transferring risk to a third party
D.Investigating a vendor's background before contracting
AnswerA

Due care means implementing reasonable security measures to protect data, satisfying the question's focus on the purpose of due care. It reflects the ongoing obligation to identify risks and apply proportionate controls, distinguishing it from due diligence, which concerns the investigation and assessment of those risks before action.

Why this answer

Due care means exercising a minimum standard of care to protect information assets, such as implementing basic security controls.

← PreviousPage 2 of 3 · 168 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Principles questions.