Courseiva

CC · domain

scenario questions

Practise ISC2 Certified in Cybersecurity CC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

989 questions261 easy432 medium296 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (989)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are principles of the CIA triad? (Select TWO.)

Easy
2

A company's security policy states that employees should only have access to the data necessary to perform their job functions. This is an example of which principle?

Easy
3

A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?

Hard
4

An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)

Medium
5

Which of the following is the primary purpose of a visitor log and escort policy?

Medium
6

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

Hard
7

A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?

Easy
8

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
9

The exhibit shows recent authentication logs. What type of attack is most likely indicated?

Easy
10

A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?

Hard
11

A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)

Hard
12

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Medium
13

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

Medium
14

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

Medium
15

A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?

Hard
16

A security analyst is reviewing an alert from the IDS that shows a large number of TCP SYN packets sent to a single port on multiple internal hosts from a single external IP address. The analyst suspects a reconnaissance attack. Which type of attack is this most likely?

Easy
17

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

Hard
18

A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured web server that exposed a database directly. Which principle was most lacking in this scenario?

Hard
19

What is the primary purpose of a digital signature?

Medium
20

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

Easy
21

An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?

Medium
22

A company's security policy requires that all sensitive data be encrypted both at rest and in transit. This is an example of applying which security principle?

Medium
23

A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?

Medium
24

A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?

Medium
25

A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?

Easy
26

A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?

Easy
27

A healthcare organization wants to ensure that only authorized clinicians can view patient records, while also maintaining a detailed log of every access for compliance audits. Which security principle is primarily being addressed by restricting access and recording all access attempts?

Medium
28

During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?

Medium
29

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

Hard
30

A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?

Medium
31

According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)

Hard
32

A security team discovers that an internal database server is sending large amounts of data to an unknown external IP address. The server is not supposed to communicate externally. Which security control should be implemented to prevent such data exfiltration?

Hard
33

A financial services company is designing a demilitarized zone (DMZ) for its public web and email relay servers. The security architect wants to reduce the attack surface and limit what an attacker can reach if a DMZ host is compromised. Which two design practices should be implemented? (Choose two.)

Medium
34

An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?

Medium
35

During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?

Medium
36

Which of the following is the best practice for managing cryptographic keys in a large organization?

Hard
37

A security auditor discovers that a user has been granted read and write access to a sensitive file, but the user's job only requires read access. Which access control principle has been violated?

Hard
38

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Medium
39

A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?

Medium
40

A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?

Medium
41

According to NIST SP 800-63, which password policy is most recommended?

Medium
42

A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?

Medium
43

In a typical Windows environment, which access control model is used for managing file permissions?

Hard
44

Which two of the following are examples of physical access controls? (Select TWO)

Easy
45

A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?

Hard
46

A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)

Medium
47

An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?

Easy
48

In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?

Medium
49

A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?

Easy
50

A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?

Medium
51

A university wants to provide guests with internet access through the same physical wireless infrastructure used by staff, but guests must not reach internal research servers. Staff must authenticate with institutional credentials. Which combination of controls best achieves this separation?

Medium
52

A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?

Hard
53

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

Hard
54

A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?

Medium
55

Which TWO of the following are fundamental security principles? (Select TWO.)

Medium
56

An organization wants to implement defense in depth for its server room. Which THREE controls should be included?

Hard
57

Which access control principle restricts access to data based on the user's job role and tasks?

Easy
58

A security analyst notices that a user's account has been used to access sensitive files outside of normal working hours from an unknown IP address. Which security principle is most directly violated?

Easy
59

An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?

Easy
60

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

Medium
61

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Hard
62

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

Easy
63

A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?

Easy
64

Based on the exhibit, which statement about the access control list is true?

Medium
65

An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:

Medium
66

Which of the following best describes a vulnerability in the context of risk management?

Medium
67

A company's network uses 802.1X authentication for wired and wireless access. Which component authenticates the user credentials against an identity store?

Medium
68

Which security principle ensures that data cannot be accessed by unauthorized individuals?

Easy
69

During a routine security audit, an analyst finds that several critical servers have misconfigured firewall rules allowing inbound SSH access from the entire internet. Which immediate action should the analyst take?

Medium
70

Which authentication type is a smart card an example of?

Easy
71

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

Easy
72

Which TWO of the following are examples of integrity controls? (Select TWO)

Easy
73

An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?

Medium
74

A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?

Medium
75

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

Medium
76

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

Hard
77

A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)

Hard
78

After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?

Easy
79

A security analyst notices repeated failed login attempts from a single external IP address targeting the company's VPN concentrator. Which type of attack is most likely occurring?

Easy
80

A security administrator notices that a user with standard privileges was able to modify a system file. Which security principle has been violated?

Easy
81

A small business wants to provide secure remote access to its internal file server for employees working from home. The company requires that all traffic between the employee's device and the file server be encrypted and that the internal network topology remain hidden. Which technology best meets these requirements?

Easy
82

A small accounting firm has a single flat network. During a risk review, the consultant recommends placing all wireless guest users on a separate logical network so they cannot reach the internal file server, even though both networks share the same physical switches and access points. Which technology best accomplishes this?

Easy
83

A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?

Medium
84

To protect the integrity of log files, which of the following is a best practice?

Easy
85

A defense contractor classifies documents as Confidential, Secret, or Top Secret and assigns each employee a clearance level. Access is permitted only when the employee's clearance meets or exceeds the document's classification, and users cannot change these labels. Which access control model is in use?

Hard
86

A retail chain wants to prevent customers on its guest wireless from reaching point-of-sale terminals on the corporate wired network, while still allowing guests to browse the internet. The chain already separates the two networks with a firewall. Which additional configuration most directly enforces this restriction?

Hard
87

An organization decides to implement multiple security controls, including firewalls, intrusion detection systems, and antivirus software. Which security principle does this represent?

Easy
88

A retail company issues managers a hardware token that generates a one-time code, which they enter after their password when signing in to the payroll system. A help desk technician asks why the company does not simply require longer passwords instead. Which statement best explains the security benefit of the token?

Medium
89

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
90

An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?

Hard
91

An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)

Hard
92

A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)

Medium
93

A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)

Hard
94

A security operations center (SOC) analyst is investigating an alert about a user downloading a suspicious file. The analyst opens the file on a sandboxed virtual machine and observes that it attempts to modify registry keys and establish persistence. This type of analysis is known as:

Hard
95

An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?

Hard
96

Which of the following is an indicator of a phishing email?

Easy
97

A hospital's IT department is choosing a security control to protect patient records. The control must render data unreadable to anyone who does not hold the cryptographic key, even if the storage media is stolen. Which type of control BEST meets this requirement?

Easy
98

An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?

Medium
99

During a security assessment, a penetration tester captures unencrypted credentials over the network. Which protocol is most likely being used?

Medium
100

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and a public DNS server. The requirement is to ensure that if either public server is compromised, it cannot initiate connections to the internal network. Which design approach best meets this requirement?

Hard
101

Drag and drop the steps for the incident response process according to NIST into the correct order.

Medium
102

Drag and drop the steps to create a new VLAN on a managed switch into the correct order.

Medium
103

An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?

Medium
104

A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?

Medium
105

Which of the following is an example of a logical access control?

Easy
106

A company uses a proxy server for internet access. Employees can browse websites (HTTP/HTTPS), but they cannot connect to external FTP servers using FTP client software (e.g., FileZilla). The proxy is configured to allow HTTP and HTTPS only. The security team wants to allow FTP while maintaining security (e.g., logging and filtering). The FTP traffic is used for occasional file transfers with partners. Which of the following is the BEST solution to meet both requirements?

Medium
107

A security analyst is reviewing network flow logs and sees periodic outbound connections from an internal server to an external IP address on TCP port 443 every 30 minutes. The connections transfer small amounts of data and the external IP resolves to a newly registered domain. The server has no business need for internet access. Which type of malicious activity is most consistent with this pattern?

Hard
108

A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?

Hard
109

Which of the following is a primary goal of security operations?

Easy
110

A system administrator needs to grant a user the ability to read files in a specific folder but not modify them. Which access control principle should be applied?

Easy
111

A company requires employees to use biometric authentication to access the data center. This is an example of which security principle?

Easy
112

In the identification and authentication process, which step occurs first?

Easy
113

A hospital's IT security team reviews how nurses access patient records. They find that a nurse who works in the cardiology unit can also open records for the oncology unit, even though the nurse never treats those patients. The team wants access decisions to be based on the department a nurse is assigned to plus the specific treatment relationship. Which access control model should they implement?

Medium
114

An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?

Easy
115

Which security control is most effective in preventing unauthorized physical access to a data center?

Easy
116

An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:

Hard
117

A security operations center receives an alert that a workstation is communicating with a known command-and-control IP address over HTTPS on port 443. The endpoint agent shows no malware signature match. Which containment action should the analyst take first to limit damage while preserving the ability to investigate?

Hard
118

A security administrator needs to ensure that only authorized personnel can access the server room. Which physical control is most appropriate?

Easy
119

During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?

Medium
120

Which access control model allows the owner of a resource to decide who can access it?

Easy
121

A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?

Medium
122

A hospital's network team must allow external vendors to reach a specific internal patient-monitoring system without exposing the rest of the clinical VLAN. The solution must enforce least privilege and terminate vendor sessions at a hardened appliance before any internal resource is contacted. Which technology best meets these requirements?

Medium
123

Which THREE of the following are core principles of the CIA triad?

Medium
124

Match each security control type to its description.

Medium
125

A security team decides to implement multi-factor authentication for all remote access. Which combination of factors would constitute multi-factor authentication?

Medium
126

Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)

Hard
127

A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?

Easy
128

What is the process of claiming an identity called?

Easy
129

Which of the following ports is used by HTTPS for secure web traffic?

Medium
130

A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)

Medium
131

A security manager is developing a disaster recovery plan for a critical database. The manager needs to determine the maximum tolerable downtime (MTD) for the database. Which of the following should the manager consider FIRST when establishing the MTD?

Medium
132

A software development company wants to ensure that only authorized code changes are deployed to production. They implement a process where developers submit code changes, and a separate team reviews and approves them before deployment. Which security principle is BEST demonstrated by this process?

Hard
133

Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?

Medium
134

A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)

Medium
135

Which TWO are examples of technical access controls?

Easy
136

An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?

Easy
137

Which TWO of the following are primary goals of the security principle of confidentiality?

Medium
138

Which OSI layer is responsible for logical addressing and routing?

Easy
139

A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?

Hard
140

Which of the following is an example of a detective control in a security operations context?

Easy
141

A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?

Easy
142

A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)

Medium
143

An organization wants to protect against man-in-the-middle attacks on a switched network. Which TWO measures should be implemented? (Choose two.)

Easy
144

A security analyst is reviewing endpoint logs and sees repeated entries showing that a process attempted to modify the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa and then attempted to read the SAM database file. The process is not a known administrative tool and was launched from a user's temporary folder. Which type of activity is MOST likely occurring?

Medium
145

A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?

Medium
146

A company needs to enforce access based on attributes such as time of day and location. Which access control model is most appropriate?

Medium
147

A company uses a stateful firewall. A user reports that an application requiring multiple dynamic ports is not working. The firewall logs show that packets from the server are being dropped. What is the most likely cause?

Hard
148

Which three of the following are benefits of using VLANs in a network? (Choose three.)

Medium
149

An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?

Medium
150

An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?

Medium
151

What is the primary difference between an IDS and an IPS?

Easy
152

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

Medium
153

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Hard
154

Which THREE of the following are key objectives of a security risk management program?

Medium
155

A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?

Medium
156

A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:

Hard
157

After a security incident, the incident response team closes the case. What is the MOST important final step to improve future security posture?

Hard
158

An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?

Easy
159

A help desk technician receives a report that a user cannot access a shared network drive. The technician checks the file server and sees that the disk is full. What is the most immediate action the technician should take?

Easy
160

During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?

Hard
161

Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?

Easy
162

A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?

Medium
163

A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?

Medium
164

A SOC analyst is reviewing logs from a web server and sees the following entry: GET /../../../../etc/passwd HTTP/1.1 Which type of attack is being attempted?

Medium
165

An organization wants to implement the principle of least privilege for its database administrators. Which approach best achieves this goal?

Medium
166

A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?

Medium
167

Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?

Easy
168

A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?

Medium
169

A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?

Medium
170

A financial services firm suffers a ransomware outbreak that encrypts file servers and the backup catalog. The incident response team must decide the immediate next step while the attack is still spreading. Which action BEST aligns with the containment objective of the incident response plan?

Medium
171

Which of the following is a benefit of using VLANs in a network?

Easy
172

An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?

Hard
173

An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?

Medium
174

A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:

Easy
175

A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?

Easy
176

An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?

Easy
177

A security administrator is concerned about MAC address spoofing on the network. Which technology can help mitigate this risk by associating a specific MAC address with a port?

Medium
178

A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?

Medium
179

An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)

Hard
180

An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?

Hard
181

A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?

Medium
182

An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?

Hard
183

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

Medium
184

A hospital's biomedical team connects a new MRI workstation to the clinical VLAN. The workstation must reach a PACS archive on a different subnet, but the team reports that no traffic leaves the workstation. A technician confirms the workstation has an IP address of 10.20.30.44/24 and the PACS archive is 10.20.40.10/24. Which device should the workstation be configured to use as its default gateway?

Easy
185

An organization implements an access control system where users are assigned to groups, and permissions are granted to groups rather than individuals. This is known as:

Easy
186

A financial services firm has a recovery time objective (RTO) of 2 hours for its trading platform and a recovery point objective (RPO) of 15 minutes. The disaster recovery team is evaluating whether a warm site can meet these requirements. Which statement best describes the limitation of a warm site in this scenario?

Hard
187

Which of the following is an example of a vulnerability?

Medium
188

During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?

Hard
189

An employee reports receiving a suspicious email with an attachment from an unknown sender. What is the first action the employee should take?

Easy
190

A security manager is mapping several controls to the categories of administrative, technical, and physical. Which TWO of the following are administrative controls? (Choose two.)

Hard
191

An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?

Hard
192

Refer to the exhibit. Based on the exhibit, why was the packet denied?

Easy
193

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Medium
194

A financial firm has a data center with strict access controls. Employees must use smart cards and PINs to enter a mantrapped entrance. Recently, an unauthorized person gained access by following an employee through the mantrapped door (tailgating). The security team reviews logs and finds that the door was opened twice in quick succession, indicating tailgating occurred. The firm wants to implement a solution that prevents tailgating without slowing down authorized access. Which action should they take?

Hard
195

A security analyst is assessing the risk associated with a new web application. The analyst identifies that the application has a SQL injection vulnerability, and there is a known exploit available that could allow an attacker to extract sensitive data. The application is exposed to the internet and is used by customers. Which two factors are most directly involved in determining the level of risk? (Choose two.)

Hard
196

A SOC analyst reviews an alert indicating a high number of failed login attempts from a single external IP address targeting multiple user accounts. Which security control is most effective at preventing this type of attack?

Easy
197

A company's security policy requires that all incident response activities be logged and that evidence be preserved for potential legal action. During an incident, a responder mistakenly uses a personal USB drive to copy log files. Which principle of forensic evidence handling has been violated?

Hard
198

An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?

Hard
199

A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)

Medium
200

Which of the following is a recommended practice for administrative accounts?

Easy
201

A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)

Hard
202

A security operations center (SOC) analyst receives an alert for a potential malware infection on a workstation. Which of the following is the first action the analyst should take?

Easy
203

Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?

Hard
204

According to NIST SP 800-63, which password policy is recommended to enhance security?

Medium
205

A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?

Hard
206

A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?

Medium
207

A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?

Medium
208

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

Medium
209

An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?

Medium
210

Which THREE of the following are examples of implementing defense in depth? (Select THREE.)

Hard
211

A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?

Easy
212

A security engineer is reviewing logs and notices that an internal server is receiving excessive SYN packets from an external IP, but never completing the three-way handshake. What type of attack is likely occurring?

Hard
213

Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?

Medium
214

Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?

Easy
215

Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?

Easy
216

Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)

Easy
217

A security operations center (SOC) analyst receives an alert for a high volume of outbound traffic from an internal server to a known malicious IP address. Which step should the analyst take next?

Medium
218

Which TWO of the following are core components of the ISC2 Code of Ethics? (Choose two.)

Medium
219

An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?

Medium
220

A software developer is designing a web application that will store user credentials. What is the most secure method for storing passwords?

Hard
221

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

Medium
222

A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?

Hard
223

A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?

Medium
224

A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?

Medium
225

An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)

Hard
226

A software company's incident response plan defines a severity level of 'Critical' for incidents that cause a complete outage of customer-facing services. A developer accidentally deploys a faulty update that crashes the production web servers, making the service unavailable to all customers. Which incident response phase should the team be in when they apply a rollback to the previous working version?

Medium
227

A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?

Hard
228

Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?

Medium
229

Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?

Easy
230

A user reports that they received a suspicious email with an attachment claiming to be an invoice. What should the user do?

Easy
231

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

Hard
232

A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?

Medium
233

A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)

Hard
234

A security analyst reviews firewall logs and sees a series of outbound connections from an internal server to a known command-and-control (C2) IP address at regular intervals. Which step should the analyst take first according to incident response best practices?

Hard
235

An organization's BCP identifies a customer-facing order system as critical. The BIA shows the business can tolerate 12 hours of downtime and 1 hour of data loss. The current architecture uses nightly full backups to tape with a 10-hour restore time. Which change BEST closes the gap between current capability and the stated requirements?

Hard
236

A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?

Easy
237

A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)

Medium
238

A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)

Hard
239

A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?

Easy
240

Which of the following is a common mitigation technique for a SYN flood attack?

Hard
241

Which TWO of the following are examples of implementing the principle of least privilege?

Hard
242

A small business wants to prevent employees from visiting known malicious websites. The owner asks for a solution that can block requests based on a constantly updated list of harmful domains without requiring software on each employee device. Which technology should be recommended?

Easy
243

An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?

Hard
244

Which protocol is considered insecure because it transmits data in cleartext, including passwords?

Easy
245

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Easy
246

A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)

Hard
247

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
248

A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?

Easy
249

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

Hard
250

An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)

Hard
251

A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?

Medium
252

A hospital's IT department wants to ensure that only authorized clinicians can view patient records, while also guaranteeing that those records have not been tampered with. Which security principle is primarily concerned with preventing unauthorized disclosure of the records?

Easy
253

A security analyst at a mid-sized company is reviewing network traffic logs and notices that an internal host is repeatedly sending TCP SYN packets to many different external IP addresses on port 443, but never completing the three-way handshake. The analyst suspects a malware infection. Which type of attack is most likely occurring?

Medium
254

A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?

Medium
255

During a phishing investigation, a security analyst identifies that an employee clicked a malicious link. The analyst isolates the workstation. What is the NEXT best step?

Medium
256

An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?

Medium
257

During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?

Medium
258

A company's network uses a perimeter firewall and an internal firewall. The DMZ sits between them. A new application server needs to be accessible from the internet on TCP port 8443 and must be able to make outbound HTTPS connections to an external license server. Which firewall rules should be implemented? (Assume default deny)

Hard
259

An e-commerce company notices that its product reviews are being scraped by automated bots far more aggressively than expected, and the resulting traffic is degrading checkout performance for real customers. The security team wants a control that slows automated abuse without challenging legitimate buyers. Which security principle does this control primarily support?

Medium
260

An organization implements a role-based access control (RBAC) system. To maintain the principle of least privilege, what should the administrator do when a user changes roles?

Hard
261

Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?

Easy
262

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
263

Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?

Medium
264

Which authentication factor does a smart card represent?

Easy
265

A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?

Easy
266

A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?

Hard
267

A Privileged Access Management (PAM) solution is used to:

Hard
268

A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?

Easy
269

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

Medium
270

A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?

Easy
271

A company's security policy mandates that all changes to the firewall configuration must be approved by two different administrators before implementation. This is an example of which security principle?

Medium
272

An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?

Hard
273

An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?

Medium
274

A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?

Easy
275

A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?

Medium
276

An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)

Hard
277

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

Hard
278

A small company with 50 employees uses a flat network with no VLANs. They recently experienced a ransomware attack that spread from an infected workstation to a file server. The IT manager wants to implement network segmentation to prevent future lateral movement. The company uses a single /24 subnet (192.168.1.0/24) with a single switch and a router/firewall. They have three departments: Sales, HR, and IT. Each department has about 15-20 computers. The file server is in the IT department. The company has a limited budget and cannot purchase new hardware. Which of the following is the MOST effective and practical approach to segment the network given these constraints?

Medium
279

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

Medium
280

A company's security policy states that sensitive data must be encrypted using AES-256. During an audit, it is found that some data is encrypted with AES-128. Which security objective is most directly compromised?

Hard
281

What is the primary purpose of a Security Information and Event Management (SIEM) system?

Easy
282

Which TWO are examples of logical access controls? (Select TWO.)

Easy
283

A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?

Medium
284

A security administrator notices that an employee is able to access files in a project folder they should not have access to. Which security principle is being violated?

Easy
285

A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?

Medium
286

A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?

Hard
287

Which data classification level typically requires the highest level of protection?

Easy
288

A network administrator notices unusual traffic from an internal workstation to an external IP address on port 443. The workstation has no business reason for such communication. Which action should the administrator take first?

Easy
289

A financial services firm is classifying a risk by estimating how often a particular attack is likely to succeed in a given year. Which risk concept is the firm measuring?

Medium
290

A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)

Medium
291

Which concept ensures that a user cannot deny having performed a specific action?

Easy
292

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Hard
293

A security operations center receives an alert that a workstation has been infected with ransomware. The infection is isolated to one machine. What is the first step in the containment phase of incident response?

Easy
294

A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)

Medium
295

A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?

Medium
296

Which three of the following are best practices for securing a network switch? (Choose three.)

Medium
297

After a reorganization, a company using RBAC finds that many users have accumulated permissions that no longer align with their job functions. What is the best practice to address this?

Medium
298

A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?

Medium
299

A mid-sized accounting firm is drafting its first information security policy. The partners want the policy to address governance responsibilities clearly so that security decisions are made consistently at the right levels. Which TWO of the following are governance responsibilities that the policy should assign? (Choose two.)

Medium
300

An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?

Medium
301

After a ransomware attack, the company wants to ensure that critical data can be restored. Which principle is being addressed?

Medium
302

Match each security policy type to its focus.

Medium
303

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor plans to publish a hash of the patch file on its website alongside the download. A security consultant warns that this approach alone is insufficient. Why is publishing only a hash inadequate for this goal?

Hard
304

A financial services firm conducts an annual test of its business continuity plan. Management wants to evaluate how well the team performs its roles and procedures during a simulated disruption without actually moving operations to alternate sites. Which type of exercise BEST meets this requirement?

Hard
305

During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?

Hard
306

Which TWO are essential elements of a business impact analysis (BIA)?

Medium
307

After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:

Hard
308

A healthcare provider's incident response team is handling a breach of patient records. The team has contained the breach and is now eradicating the threat. Which of the following activities is MOST appropriate during the eradication phase?

Medium
309

A hospital wants to ensure that patient records can only be viewed by authorized clinical staff, and that any modification to a record is traceable to the individual who made it. Which security principle directly supports both of these requirements?

Easy
310

An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?

Medium
311

A network administrator is configuring a new wireless network for a small office. The office manager wants to ensure that only authorized employees can connect and that traffic between wireless clients is encrypted. Which security protocol should the administrator implement?

Easy
312

A company conducts a background check on a new vendor before signing a contract. This activity is an example of:

Hard
313

In the context of identification and authentication, which of the following is an example of authentication?

Medium
314

After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?

Medium
315

A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?

Easy
316

A financial services firm classifies documents as Public, Internal, Confidential, and Restricted. Access to Restricted documents is determined solely by the document's classification label and the user's clearance level, and users cannot change either value. Which statement best describes this arrangement?

Medium
317

A company's web server is experiencing a high volume of traffic from thousands of different IP addresses, causing service degradation. The security team determines it is a distributed denial-of-service (DDoS) attack. Which mitigation strategy is most effective for this scenario?

Medium
318

A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?

Hard
319

An organization is implementing a patch management program. Which of the following is the BEST approach to minimize risk while maintaining operational stability?

Medium
320

A network administrator needs to provide secure remote access to internal resources for employees working from home. The solution must encrypt all traffic and authenticate users before granting access. Which protocol should be used?

Easy
321

A hospital's security team wants to detect when an attacker is probing its internal network for open ports, but the team must not block legitimate clinical traffic because doing so could interrupt patient care. The team decides to deploy a solution that only alerts on suspicious activity. Which type of solution best matches this requirement?

Medium
322

A company is planning its backup strategy and wants to balance storage efficiency with restore speed. Which TWO backup strategies should the company consider? (Select TWO)

Hard
323

A company wants to ensure that a message received was not altered in transit. Which principle is of primary concern?

Medium
324

A cloud-hosted retailer's disaster recovery plan relies on backups stored in the same cloud region as production. A regional outage takes the production environment offline. Which weakness does this scenario PRIMARILY expose in the disaster recovery strategy?

Medium
325

A security team wants to detect when an attacker is using a compromised account to move laterally between servers inside the network. Which monitoring approach would best surface this activity?

Medium
326

A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:

Medium
327

During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?

Medium
328

Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?

Easy
329

Which type of access control is implemented by a cable lock attached to a laptop?

Easy
330

A security analyst is reviewing network logs to detect potential intrusions. Which TWO of the following are examples of network-based indicators of compromise? (Choose two.)

Medium
331

A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?

Medium
332

A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)

Hard
333

A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?

Medium
334

Which type of authentication factor involves something the user knows?

Easy
335

A company has implemented a role-based access control (RBAC) system. A new employee in the finance department is granted the 'Finance User' role, which allows them to view invoices but not create payments. However, after a system upgrade, it is discovered that the 'Finance User' role now includes the ability to create payments due to a misconfiguration. The employee did not request this additional privilege and has not exploited it. The security team is notified. Which principle has been violated, and what is the most appropriate immediate action?

Hard
336

An organization's security policy requires that all access to sensitive data must be approved by a data owner. An administrator configures a system to enforce this. Which principle is being implemented?

Hard
337

A security administrator is reviewing the organization's authentication controls and wants to strengthen them by adding factors from different categories. Which TWO of the following represent distinct authentication factor categories that can be combined to achieve multi-factor authentication? (Choose two.)

Medium
338

A company performs background checks on potential employees before hiring. This action demonstrates which concept?

Medium
339

Which THREE of the following are considered risk management strategies? (Select THREE)

Hard
340

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Medium
341

Drag and drop the steps to recover a system from a verified backup after a ransomware attack into the correct order.

Medium
342

A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:

Hard
343

A system administrator accidentally grants a user full administrative rights instead of read-only. Which control would best detect this error?

Hard
344

An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?

Hard
345

A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?

Easy
346

An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?

Medium
347

When implementing multi-factor authentication, which combination of factors is considered strongest?

Medium
348

An organization is reviewing its security governance framework. Which TWO of the following are primary objectives of security governance? (Choose two.)

Medium
349

During a forensic investigation, it is crucial to preserve the original evidence. What is the first step the investigator should take when acquiring a hard drive?

Medium
350

An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?

Medium
351

A mid-sized hospital experiences a ransomware outbreak that encrypts its electronic health record (EHR) servers on a Friday night. The incident response plan designates a severity classification of 'Critical'. According to established incident response practices, which action should the incident response team take FIRST?

Medium
352

A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)

Hard
353

A multinational corporation has a policy that all sensitive emails must be digitally signed and encrypted. However, during a recent internal audit, it was discovered that many employees were not using digital signatures because the process was cumbersome. As a result, the company could not prove that certain emails were actually sent by the claimed sender. The security team needs to improve compliance without sacrificing security. Which of the following is the best approach?

Hard
354

A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)

Medium
355

In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?

Medium
356

An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)

Medium
357

Which TWO are appropriate methods to test a disaster recovery plan?

Hard
358

A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)

Medium
359

A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?

Medium
360

A security analyst reviews firewall logs and notices a large number of outbound connections from a single internal IP to a known malicious IP on port 445. The analyst quarantines the workstation and runs an antivirus scan, which finds no malware. What should the analyst do next?

Hard
361

A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?

Medium
362

A small clinic stores patient records on a server. The IT administrator ensures that only authorized staff can view these records, and that the records remain accurate and available when needed. Which security principle is best illustrated by restricting access to the records?

Easy
363

Which backup strategy offers the fastest restore time but requires the most storage space?

Medium
364

During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?

Hard
365

Which THREE are key components of Active Directory? (Select THREE.)

Medium
366

Which THREE are core components of the CIA triad? (Choose three.)

Easy
367

What is the difference between due care and due diligence in security governance?

Medium
368

An analyst reviews the exhibit. Which security principle is being violated by allowing root login via SSH?

Medium
369

Drag and drop the steps to configure a wireless access point with WPA2-PSK security into the correct order.

Medium
370

During an incident, a responder needs to capture the contents of volatile memory on a running Linux server before shutting it down, because encryption keys and running processes may only exist in RAM. Which action BEST preserves this volatile evidence?

Hard
371

A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?

Easy
372

A security administrator notices that a user's account has been used to access sensitive files at unusual hours. Which security principle would most effectively help detect this type of activity?

Easy
373

A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)

Medium
374

A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?

Easy
375

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

Hard
376

During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?

Medium
377

During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?

Hard
378

A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?

Hard
379

A security manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The manager needs to identify which of the following are considered threats rather than vulnerabilities or risks. (Choose two.)

Medium
380

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

Medium
381

During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?

Medium
382

A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?

Medium
383

Which THREE of the following are examples of risk mitigation? (Select THREE)

Hard
384

An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:

Easy
385

Drag and drop the steps for the TCP three-way handshake into the correct order.

Medium
386

A company's security operations center (SOC) receives an alert about suspicious outbound traffic from a server in the DMZ to an external IP address known for command-and-control activity. The SOC analyst reviews the logs and sees that the source port is 443 and the destination port is 8080. Which of the following actions should the analyst take FIRST?

Medium
387

Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)

Hard
388

A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)

Medium
389

The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?

Hard
390

Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)

Medium
391

Which TWO of the following are examples of security principles?

Easy
392

Which of the following is the primary purpose of a security information and event management (SIEM) system?

Easy
393

A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?

Hard
394

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

Medium
395

Match each risk management term to its meaning.

Medium
396

A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?

Hard
397

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

Medium
398

A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?

Medium
399

Which of the following is an example of Type 2 authentication?

Easy
400

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Hard
401

A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?

Hard
402

A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?

Medium
403

A company deploys a web application firewall (WAF), performs regular vulnerability scans, and implements strict access controls. Which security principle is being applied?

Medium
404

A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?

Hard
405

A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?

Medium
406

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

Medium
407

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

Hard
408

During a security audit, it is discovered that a single administrator can create user accounts, assign privileges, and review audit logs. Which principle is most likely being violated?

Medium
409

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

Hard
410

A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?

Medium
411

A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?

Hard
412

A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?

Hard
413

Which control type is considered a physical security control?

Easy
414

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

Easy
415

Drag and drop the steps to perform a password reset on a Windows user account into the correct order.

Medium
416

Which is a key benefit of a cold site as a recovery location?

Medium
417

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Medium
418

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

Medium
419

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

Easy
420

A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?

Easy
421

A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?

Hard
422

A retail company's business continuity plan includes a requirement to test its disaster recovery capabilities annually. The IT team proposes conducting a tabletop exercise with key stakeholders. Which benefit does this type of test provide?

Medium
423

Which THREE of the following are common components of a disaster recovery plan?

Easy
424

Which incident category involves an attempt to make a system or network resource unavailable to its intended users?

Medium
425

A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?

Easy
426

Which three ports are commonly used by secure protocols? (Choose THREE.)

Medium
427

A company uses a mandatory access control (MAC) system where all files are labeled 'Confidential', 'Secret', or 'Top Secret'. A user with 'Secret' clearance tries to read a 'Top Secret' file. What is the outcome?

Hard
428

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Medium
429

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Medium
430

A software development company wants to ensure that only authorized code changes are deployed to production. The security team proposes that developers should not have direct write access to the production environment, and that all code must be reviewed and approved by a different team member before deployment. Which security principle does this proposal primarily enforce?

Hard
431

In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

Hard
432

A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?

Medium
433

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

Easy
434

A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)

Hard
435

Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?

Medium
436

A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?

Medium
437

A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)

Hard
438

Which THREE of the following are considered essential security principles according to ISC2?

Hard
439

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

Hard
440

A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)

Hard
441

An account lockout policy is implemented to protect against which type of attack?

Medium
442

Which THREE of the following are essential components of an incident response plan? (Select THREE.)

Hard
443

A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)

Hard
444

During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?

Hard
445

During a security incident, the incident response team isolates a compromised workstation from the network. What is the primary purpose of this action?

Medium
446

You are an IT administrator for a small business. The company has a backup system that performs nightly full backups of critical servers to an external hard drive. One morning, a user reports that they accidentally deleted an important file from a shared drive. You need to restore the file from last night's backup. However, when you connect the external hard drive to the backup server, the drive is not recognized, and you hear clicking sounds. The backup software shows that the most recent backup job completed successfully with no errors. What is the most likely cause of the problem?

Easy
447

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

Easy
448

A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)

Medium
449

A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?

Medium
450

An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?

Medium
451

A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?

Easy
452

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Hard
453

Which of the following is a primary benefit of implementing network segmentation?

Easy
454

Which THREE components are part of the AAA framework?

Hard
455

An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?

Easy
456

A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?

Medium
457

A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?

Hard
458

Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?

Medium
459

In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?

Medium
460

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Medium
461

A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)

Hard
462

Which of the following is a connectionless, unreliable transport protocol?

Easy
463

A security auditor discovers that during a VLAN hopping attack, a threat actor was able to send frames from a workstation on VLAN 10 to a target on VLAN 20. Which configuration flaw is most likely responsible?

Hard
464

A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?

Hard
465

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

Medium
466

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

Hard
467

A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?

Easy
468

A security engineer is designing a DMZ for a web server that must be accessible from the internet. The web server needs to query an internal database server. Which network security approach best limits exposure?

Medium
469

Which TWO of the following are examples of preventive security controls?

Easy
470

Which of the following best describes the purpose of a session timeout?

Easy
471

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

Easy
472

A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?

Medium
473

Which layer of the OSI model is responsible for routing packets based on IP addresses?

Easy
474

A company experiences a ransomware attack that encrypts its file servers. The security team restores operations from offline backups taken the previous night. Which security principle does the restoration from backups primarily support?

Medium
475

An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?

Medium
476

An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?

Medium
477

During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?

Hard
478

Refer to the exhibit. A security analyst reviews this log entry. What type of attack is most likely occurring?

Medium
479

A network administrator is configuring a new wireless network for a small office. The office has sensitive data and wants to ensure that all wireless traffic is encrypted and that users authenticate with unique credentials. Which security protocol should the administrator implement?

Easy
480

A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?

Hard
481

A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?

Hard
482

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Easy
483

An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?

Hard
484

A financial institution has a security operations center that monitors network traffic using a SIEM. The SIEM receives logs from all network devices, servers, and endpoints. One analyst notices an anomaly: a user account, 'jsmith', which is normally used during business hours (9 AM to 5 PM), has been logging in from a remote IP address at 2 AM every day for the past week. The logins are successful, and the user is accessing internal file shares. The user jsmith works in the accounting department and has access to sensitive financial reports. The analyst checks the user's workstation logs and finds that the workstation is powered off at the time of the remote logins. The company uses two-factor authentication, but the log entries show that only the password was used. Which of the following is the most likely explanation and the best immediate action?

Hard
485

An organization wants to ensure that system logs are tamper-proof after generation. Which control should be implemented?

Easy
486

A financial services company wants to ensure that a terminated employee cannot continue to use an active badge to enter the building after their last day. The security manager reviews physical access control procedures. Which control type is being applied when the badge is deactivated in the access control system?

Medium
487

A security officer at a healthcare provider is reviewing the organization's risk management program. The officer must distinguish between threats and vulnerabilities when documenting risks. Which two of the following are examples of vulnerabilities rather than threats? (Choose two.)

Hard
488

A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?

Hard
489

A financial services firm has a data center that houses customer financial records. They have implemented a defense-in-depth strategy including firewalls, IDS/IPS, and encryption. Recently, an internal audit revealed that a junior administrator has been logging into the database server with a shared admin account and has made unauthorized changes to customer records. The company wants to prevent such incidents in the future while maintaining operational efficiency. The current environment uses Linux servers with PostgreSQL databases. There is no centralized authentication system. What is the BEST action to take?

Hard
490

In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?

Hard
491

A security engineer is designing a backup strategy for a critical database. The database must be recoverable within four hours in the event of a failure. Which security principle primarily drives this requirement?

Medium
492

A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?

Medium
493

In a defense-in-depth strategy, which access control mechanism provides the most granular control over user permissions?

Hard
494

A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?

Medium
495

You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?

Hard
496

A hospital's network team notices that a radiology workstation is receiving a duplicate IP address error. The DHCP server logs show the workstation was assigned 10.10.20.45, but the workstation is manually configured with that same address. Which DHCP feature should have been configured to prevent this conflict?

Medium
497

A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)

Hard
498

A financial services firm is designing a network that must allow inbound HTTPS from the internet to a public web application while preventing any direct inbound connections to its internal database servers. The security architect proposes placing the web application in a screened subnet and configuring rules so the database can be reached only from the web application. Which design element is the architect primarily relying on?

Hard
499

Which OSI layer is responsible for routing packets across networks using IP addresses?

Easy
500

A system administrator implements version control for all configuration files. Which principle is being strengthened?

Medium
501

Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?

Easy
502

A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?

Easy
503

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

Medium
504

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

Medium
505

An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?

Medium
506

You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?

Hard
507

A security engineer is configuring a firewall to allow web traffic but block all other inbound connections. The firewall is set to deny all traffic by default and only allow specific ports. Which security principle is being applied?

Medium
508

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

Easy
509

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

Hard
510

An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?

Medium
511

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

Medium
512

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

Hard
513

A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?

Medium
514

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

Easy
515

A security analyst receives an alert indicating multiple failed login attempts from a single IP address targeting a user account. Which action should the analyst take FIRST?

Easy
516

An organization uses a SIEM to correlate logs from multiple sources. A rule triggers when a user logs in from two geographically distant locations within a short time. What type of attack does this rule primarily detect?

Medium
517

Maya is a security administrator at a healthcare company. She discovers that nurses can view patient billing records even though their job duties only require access to clinical treatment notes. She wants to apply the security principle that restricts users to only the data they need to perform their assigned tasks. Which principle should she implement?

Easy
518

A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?

Medium
519

A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)

Medium
520

A payroll administrator can view salary records for all employees during normal business hours, but only after her manager approves each access request and the system logs the action. Which security principle is BEST illustrated by limiting her access to what her job requires and only when needed?

Medium
521

During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
522

An organization is designing a security architecture for a cloud-based application. They implement firewalls, intrusion detection systems, and encryption, and also conduct regular security awareness training. This approach demonstrates which security principle?

Hard
523

A security operations center (SOC) analyst notices unusual outbound network traffic from a server that typically only receives connections. The traffic is encrypted and goes to an unknown external IP. Which step should the analyst perform FIRST?

Medium
524

An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)

Hard
525

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Medium
526

An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?

Medium
527

Which statement best describes a warm site in disaster recovery?

Hard
528

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

Medium
529

An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?

Medium
530

An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?

Hard
531

A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?

Medium
532

Which of the following best describes a Disaster Recovery Plan (DRP)?

Easy
533

A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?

Medium
534

A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?

Easy
535

A small business wants to prevent employees from visiting known malicious websites. The owner asks a technician to implement a control that blocks requests to a maintained list of bad domains before any connection is made to those sites. Which solution should the technician deploy?

Easy
536

During a forensic investigation, an analyst acquires a live system memory dump. Which tool is most appropriate for capturing the contents of volatile memory on a Windows system?

Hard
537

A company is designing a new application that processes credit card payments. They want to ensure that no single administrator can bypass security controls to approve a fraudulent transaction. Which principle should be implemented?

Hard
538

After a security audit, a company discovers that several employees have access to financial systems that are not required for their job roles. Which access control model would best prevent this issue in the future?

Medium
539

A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?

Medium
540

In a Bell-LaPadula MAC model, which of the following operations is prohibited?

Hard
541

A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?

Easy
542

A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?

Medium
543

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

Hard
544

What is the primary purpose of a Privileged Access Management (PAM) solution?

Medium
545

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

Hard
546

A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?

Hard
547

Which of the following is a key component of the 3-2-1 backup rule?

Easy
548

Which TWO of the following are fundamental principles of information security that form the CIA triad?

Easy
549

Which of the following ensures that data has not been tampered with during transmission?

Easy
550

A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)

Medium
551

A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?

Hard
552

An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?

Medium
553

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

Medium
554

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

Medium
555

Which TWO of the following are examples of physical access controls?

Easy
556

A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
557

A healthcare provider must ensure that patient records remain unaltered during storage and transmission between clinics. Which security principle is being addressed when the organization implements hashing and digital signatures on those records?

Easy
558

An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?

Easy
559

An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?

Hard
560

A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?

Easy
561

Which THREE are common indicators of a compromised system? (Select THREE.)

Hard
562

Which of the following is considered Sensitive PII?

Easy
563

A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?

Medium
564

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

Medium
565

A user reports that they are unable to access a shared network drive that they previously could access. The administrator checks permissions and finds the user's account is still a member of the correct group. What should the administrator check next?

Medium
566

An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?

Hard
567

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Medium
568

Which TWO are best practices for managing backup media?

Medium
569

A hospital's security team wants to give remote clinicians access to internal patient systems without exposing those systems directly to the internet. The team requires strong encryption, per-user authentication, and the ability to log every session. Which solution best fits these requirements?

Medium
570

A security team configures a system to record all user activities for audit purposes. Which principle is being applied?

Easy
571

A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?

Easy
572

An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?

Medium
573

A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?

Medium
574

A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)

Medium
575

Which of the following is an example of a detective control?

Easy
576

An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?

Medium
577

A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?

Hard
578

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

Easy
579

An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?

Hard
580

A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?

Easy
581

A medium-sized company uses a SIEM solution to collect logs from firewalls, servers, and endpoints. The security team receives an alert indicating a possible data exfiltration: an employee's workstation is sending large amounts of data to an external IP address outside business hours. The employee works in the finance department and has access to sensitive financial records. The SIEM shows the connection is ongoing. The security team must respond immediately to contain the incident while preserving evidence. The company's incident response plan designates the security team as first responders. Which of the following is the BEST first action?

Medium
582

Which of the following is the most effective way to prevent tailgating in a secured facility?

Medium
583

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

Medium
584

Which OSI layer is responsible for routing packets based on IP addresses?

Easy
585

Which of the following are core principles of information security?

Medium
586

A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?

Medium
587

Which process involves verifying the identity of a user who claims to be a specific person?

Easy
588

Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?

Easy
589

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

Easy
590

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

Easy
591

A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)

Medium
592

Which protocol is considered insecure because it transmits data, including credentials, in cleartext?

Medium
593

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

Hard
594

Match each phase of the incident response process to its description.

Medium
595

In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)

Hard
596

An account lockout policy is designed to mitigate which type of attack?

Medium
597

A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)

Medium
598

A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?

Medium
599

A company's security policy requires that all outbound web traffic be inspected for malware and that users be prevented from accessing known malicious domains. The security team wants a single appliance that can decrypt TLS sessions, apply content filters, and block threats inline. Which solution best meets these requirements?

Medium
600

Match each network security concept to its purpose.

Medium
601

A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?

Medium
602

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

Hard
603

Which TWO of the following are components of the identification and authentication process? (Select TWO.)

Medium
604

A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?

Medium
605

Which THREE of the following are considered fundamental security principles? (Select three).

Easy
606

An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?

Medium
607

During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?

Easy
608

What is the primary purpose of using security baselines derived from CIS Benchmarks?

Medium
609

Which THREE of the following are essential components of a security baseline configuration for a server?

Hard
610

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

Hard
611

A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?

Easy
612

A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?

Medium
613

An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?

Easy
614

Which of the following ports is used by HTTPS?

Easy
615

A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?

Easy
616

A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?

Medium
617

A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?

Medium
618

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Hard
619

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

Hard
620

A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?

Hard
621

A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?

Hard
622

A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?

Medium
623

Which THREE are recommended practices for password policies according to current guidelines?

Medium
624

A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?

Hard
625

During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?

Medium
626

A junior analyst reports that an attacker exploited an unpatched web server to steal customer data. The analyst labels the missing patch the 'risk'. According to standard risk terminology, how should the missing patch be classified?

Hard
627

A company's security policy requires that all data at rest be encrypted. Which of the following is the BEST approach to ensure compliance while maintaining performance?

Medium
628

A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?

Hard
629

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

Hard
630

Which of the following ports is commonly used for secure web traffic (HTTPS)?

Easy
631

Which THREE of the following are best practices for securing a remote access VPN?

Hard
632

A system administrator must grant a help desk technician the ability to reset user passwords but not change user roles. Which security principle does this scenario enforce?

Easy
633

An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?

Easy
634

A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?

Hard
635

After a ransomware attack, which team is primarily responsible for coordinating the response?

Easy
636

An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?

Medium
637

A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?

Easy
638

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

Hard
639

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

Medium
640

A security manager is documenting how the organization decides which safeguards to apply to a new customer database. The team identifies the value of the data, the threats that could exploit weaknesses, and the potential business impact, then selects controls that reduce risk to an acceptable level. Which concept best describes this activity?

Hard
641

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

Hard
642

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

Medium
643

A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?

Medium
644

A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?

Medium
645

An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?

Medium
646

During an incident response, a forensics analyst captures a memory dump from a compromised server. The analyst needs to ensure the dump is not altered during analysis. Which practice best maintains integrity?

Hard
647

Refer to the exhibit. Which security principle is being supported by the logging of these events?

Hard
648

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

Medium
649

A network technician is setting up a remote access VPN for employees using IPsec. The company's firewall is configured to allow IPsec traffic. Employees report that they can successfully establish the VPN connection (tunnel appears up), but they cannot ping or access any internal resources (e.g., file servers). The firewall logs show that packets from the VPN client IP addresses are being dropped at the firewall interface. Which of the following is the MOST likely cause of this issue?

Easy
650

An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)

Hard
651

Which of the following is a control that can reduce the risk of a DDoS attack?

Easy
652

A company's security policy states that employees must wear identification badges visibly at all times while on premises. A security guard checks badges at the entrance. Which type of control is the badge check?

Medium
653

A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:

Medium
654

Refer to the exhibit. A user from the Auditors group is unable to access the folder. What is the most likely cause?

Hard
655

During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?

Hard
656

Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?

Easy
657

An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?

Hard
658

An organization implements a bring-your-own-device (BYOD) policy. Which security control is most important to enforce in the BYOD policy?

Medium
659

A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?

Easy
660

A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?

Medium
661

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

Medium
662

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Medium
663

Which of the following is a recommended practice for password security according to NIST SP 800-63?

Medium
664

When implementing a role-based access control (RBAC) system, what is the primary challenge organizations face?

Hard
665

An organization's business continuity plan (BCP) requires that its payroll system be operational within 8 hours of a disruption, but the system can tolerate losing up to 4 hours of payroll transaction data. Which pair of metrics BEST represents these two requirements?

Easy
666

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

Easy
667

You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?

Medium
668

A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?

Medium
669

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

Hard
670

A company uses WPA2-Enterprise for wireless authentication. What additional security measure should be implemented to protect against rogue access points?

Medium
671

A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)

Hard
672

A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?

Easy
673

An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?

Easy
674

Which THREE of the following are considered methods to ensure accountability in a system?

Hard
675

Which TCP segment is sent to initiate the three-way handshake?

Easy
676

A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?

Hard
677

A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?

Medium
678

Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?

Easy
679

A SOC analyst detects a series of failed login attempts from a single external IP address targeting multiple user accounts within a short time. Which action should the analyst take FIRST?

Medium
680

A small business owner wants to ensure that their company's data remains accurate and unaltered during transmission over the internet. They regularly send financial reports to their accountant via email. The owner is concerned that a hacker might intercept and modify the reports before they reach the accountant. Which security principle is most directly threatened in this scenario, and what is the best technical control to implement?

Easy
681

Refer to the exhibit. ``` C:\> netstat -an | find "LISTENING" TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?

Easy
682

A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?

Medium
683

A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?

Hard
684

A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?

Medium
685

A small accounting firm wants to let guests connect to the internet in its lobby without exposing the internal file server or the payroll system. The network administrator is told to add a separate wireless network that uses different IP addressing and cannot route to internal resources. Which security principle is the administrator primarily applying?

Easy
686

A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?

Hard
687

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

Easy
688

A security manager is reviewing the organization's approach to risk. The manager decides to purchase cyber insurance to transfer some of the financial risk associated with a data breach. Which risk management strategy is being used?

Hard
689

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

Medium
690

An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?

Hard
691

A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)

Medium
692

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

Easy
693

An organization implements a defense-in-depth strategy by deploying firewalls, intrusion detection systems, and endpoint protection. Which security principle does this approach primarily demonstrate?

Medium
694

A hospital's compliance officer is mapping controls for a new patient portal. The legal team wants documented assurance that a clinician cannot later deny having approved a medication order submitted through the portal. Which security principle is the legal team most directly requesting?

Hard
695

A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?

Hard
696

A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)

Medium
697

A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?

Medium
698

Based on the incident log, at which step did the incident response team contain the threat?

Easy
699

A company's security policy requires that all employees use strong passwords and change them every 90 days. An employee writes their password on a sticky note and attaches it to their monitor. Another employee sees it and uses it to log into the first employee's account to send a fake email. The security team is conducting a post-incident review. Which security principle failed, and what is the most effective long-term solution to prevent this type of incident?

Medium
700

Which TWO of the following are examples of administrative security controls? (Choose two.)

Medium
701

An organization is implementing a new system that processes financial transactions. To reduce the risk of fraud, they ensure that no single individual can both initiate and approve a transaction. Which security principle is this?

Hard
702

A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?

Easy
703

Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?

Medium
704

A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?

Hard
705

A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?

Medium
706

Which TWO of the following are examples of detective security controls? (Choose two.)

Hard
707

A software development team is designing a new application that will process credit card payments. The security architect recommends that the application should not store the card verification value (CVV) after the transaction is authorized. Which principle is the architect applying?

Medium
708

Which of the following is a key function of a Security Information and Event Management (SIEM) system?

Easy
709

A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?

Medium
710

A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?

Hard
711

Which THREE are valid methods for authenticating a user in an access control system?

Hard
712

Which THREE of the following are best practices for securing a network firewall? (Select THREE.)

Hard
713

After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?

Hard
714

Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)

Medium
715

A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?

Hard
716

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Medium
717

A financial services firm wants to ensure that a single employee cannot initiate and approve a large wire transfer alone. The firm implements a process where one employee creates the transfer and a different employee must approve it. Which security principle is being applied?

Medium
718

Refer to the exhibit. An administrator notices that external access to the MySQL database (port 3306) is blocked, but internal access should be allowed. What change should be made?

Medium
719

You are a forensic analyst responding to a reported compromise of a Linux web server. The server hosts a public-facing web application and is part of a DMZ. The initial investigation shows that unauthorized outbound connections were made to a known malicious IP address during the previous night. The server is still running and connected to the network, but the web application has been taken offline for maintenance. The incident response team wants to preserve evidence for potential legal action. You have a forensic workstation with tools like dd, netcat, and memory acquisition tools. Which of the following should be your FIRST step in the forensic acquisition process?

Hard
720

A security engineer is designing a system that must ensure that any changes to a configuration file are logged with the identity of the person who made the change. Which principle is being implemented?

Hard
721

The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?

Easy
722

A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?

Hard
723

A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?

Medium
724

Refer to the exhibit. A firewall rule set is shown (first match applies). An analyst reviews these rules. Which of the following best describes the traffic outcome for a packet from source IP 10.0.0.1 to destination 192.168.1.1?

Hard
725

A company wants to allow remote employees to securely access internal resources over the internet. Which technology is most appropriate?

Easy
726

A company uses a SIEM to monitor network security events. The security analyst notices a high volume of alerts about suspicious outbound traffic to a known command-and-control server. The traffic is encrypted and uses non-standard ports. Which security control would best detect this activity if the SIEM relies only on network flow data?

Medium
727

Which TWO of the following are essential elements of an incident response plan?

Medium
728

A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?

Medium
729

Which of the following controls is primarily designed to ensure availability?

Medium
730

An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?

Hard
731

Which TWO of the following are best practices for implementing the principle of least privilege?

Hard
732

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Hard
733

Which incident category involves an attacker tricking an employee into revealing credentials?

Easy
734

A system administrator needs to grant a contractor temporary access to a server for patching. The contractor should only have access during the patching window. Which access control implementation method is most appropriate?

Medium
735

An organization wants to ensure that data remains unaltered during transmission over the internet. Which security goal is being addressed?

Easy
736

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Medium
737

Which metric defines the maximum acceptable amount of data loss measured in time?

Easy
738

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

Easy
739

A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)

Medium
740

Refer to the exhibit. Based on the JSON policy, what access does the SecurityAuditor role have?

Hard
741

During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?

Hard
742

Which of the following is a potential security issue commonly found in firewall configurations?

Hard
743

Your organization is implementing a new access control system to protect a highly sensitive research database. The security policy mandates that no single individual should have the ability to both approve and execute changes to the database. This is to prevent fraud and errors. Which security principle does this policy enforce, and which of the following best implements it?

Medium
744

You are a security engineer responsible for the company's intrusion detection system (IDS). The IDS has been generating an excessive number of false positive alerts related to a legitimate application that uses encrypted traffic. The alerts are based on network signatures that match certain patterns in the encrypted payload. The volume of alerts is overwhelming the SOC team, and they are beginning to ignore IDS alerts altogether. You have the ability to modify IDS signatures and tune the system. Which of the following is the BEST approach to reduce false positives while maintaining security?

Medium
745

A security architect is designing a system that must ensure that a sender cannot later deny having sent a message. Which cryptographic mechanism should be implemented?

Hard
746

A small accounting firm has a flat network where all employee workstations and a guest Wi-Fi access point connect to the same switch. The owner asks a security consultant to keep guests from reaching the payroll server, which resides on the same subnet as employee devices. Which control should the consultant implement to meet this requirement with the least disruption?

Easy
747

Which component of the AAA framework determines what resources an authenticated user can access?

Medium
748

Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?

Easy
749

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

Hard
750

Which of the following is classified as sensitive PII?

Medium
751

A network administrator needs to allow secure remote access for teleworkers. Which VPN protocol provides the best confidentiality and integrity while using a single UDP port?

Medium
752

An organization requires that two separate administrators approve and implement changes to firewall rules. This practice enforces which security principle?

Hard
753

A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?

Easy
754

An organization implements a policy where users must swipe their ID card and enter a PIN to access a secure room. This is an example of which access control principle?

Easy
755

A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?

Medium
756

Refer to the exhibit. The security principle demonstrated by the default policy is:

Easy
757

A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?

Medium
758

Refer to the exhibit. A user with this policy tries to list objects in a container but gets an access denied error. What is the most likely reason?

Easy
759

A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)

Hard
760

A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?

Hard
761

Which TWO are key outputs of a Business Impact Analysis (BIA)?

Easy
762

An organization has a policy that all servers must have security patches applied within 30 days of release. Which of the following is the best practice for patching?

Medium
763

An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)

Medium
764

Which of the following is a security concern associated with the Telnet protocol?

Medium
765

A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?

Easy
766

A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?

Medium
767

Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.

Medium
768

An organization wants to ensure that no single employee can both request and approve a payment. Which access control principle does this enforce?

Easy
769

What is the primary purpose of identification in the context of access control?

Easy
770

During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?

Hard
771

A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?

Hard
772

Which TWO of the following are valid types of disaster recovery tests?

Medium
773

An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?

Easy
774

Which of the following best describes the difference between due care and due diligence in security governance?

Hard
775

Which TWO are key components of an effective incident response plan? (Select TWO.)

Medium
776

An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?

Easy
777

An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?

Medium
778

A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)

Medium
779

A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?

Hard
780

A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?

Medium
781

Which TWO of the following are common indicators of a phishing email?

Easy
782

Which of the following is an example of a Type 2 authentication factor?

Easy
783

A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?

Hard
784

A company's security policy states that only staff in the finance department may access the general ledger, and that access must be reviewed every quarter. An auditor finds that two former finance employees still hold active accounts with ledger permissions. Which concept has the organization FAILED to apply?

Medium
785

Which of the following is an example of a Type 1 authentication factor?

Medium
786

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

Medium
787

A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?

Easy
788

A small retail company is developing its first incident response plan. The owner asks which phase of the incident response lifecycle involves developing policies, assigning roles, and acquiring tools. Which phase should be recommended?

Easy
789

A security manager is assessing the risk of a new web application. The manager identifies that the application has a known SQL injection vulnerability, and that attackers frequently scan for such flaws. Which term best describes the SQL injection flaw itself?

Hard
790

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

Medium
791

An organization's security policy requires that all employees change their passwords every 90 days. This is an example of which type of security control?

Easy
792

According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?

Hard
793

A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)

Hard
794

Which document outlines the procedures for maintaining critical business functions during a disruption?

Easy
795

A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?

Medium
796

An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)

Medium
797

Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?

Medium
798

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

Medium
799

A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?

Hard
800

Which THREE of the following are best practices for privileged account management? (Select THREE.)

Medium
801

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Medium
802

A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)

Hard
803

A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?

Easy
804

Which TWO of the following are common indicators of a ransomware attack?

Easy
805

An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?

Easy
806

A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?

Easy
807

A hospital's network team needs to provide secure remote access for clinicians who work from home. The clinicians must be able to reach internal medical records systems as if they were on the hospital LAN, but the hospital's security policy requires that all remote traffic be encrypted and that remote devices be prevented from directly accessing the public internet through the hospital network. Which technology best meets these requirements?

Medium
808

A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)

Medium
809

Which TWO of the following are types of security controls?

Medium
810

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Hard
811

A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?

Medium
812

During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?

Hard
813

You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?

Hard
814

Which THREE of the following are recognized security control types according to ISC2? (Choose three.)

Hard
815

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

Hard
816

During a security incident, a forensic analyst needs to acquire the contents of RAM from a live system. Which tool should be used?

Hard
817

A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?

Medium
818

A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?

Hard
819

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

Medium
820

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
821

A company wants to implement a security control that ensures users are who they claim to be before granting access to a system. Which type of control should they prioritize?

Easy
822

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

Hard
823

A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?

Medium
824

A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)

Hard
825

According to the (ISC)² Code of Ethics, which principle has the highest priority?

Medium
826

Which access control model uses subject and object labels to enforce access based on a security policy?

Easy
827

A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?

Easy
828

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

Medium
829

Refer to the exhibit. What is the first action the incident responder should take?

Easy
830

What is the primary purpose of hashing in information security?

Easy
831

Which TWO are principles of access control?

Medium
832

A company's backup strategy requires daily full backups of all servers. The backup window is 4 hours. What is the primary risk if backups consistently take longer than the window?

Easy
833

An organization wants to ensure that its backup strategy can recover data within 2 hours after a system failure. Which metric should be defined in the disaster recovery plan?

Hard
834

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

Hard
835

A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?

Hard
836

A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?

Hard
837

A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?

Easy
838

A company's security policy requires that all sensitive data be encrypted during transfer. A security administrator discovers that an internal web application is using a self-signed TLS certificate. What vulnerability does this introduce?

Hard
839

A security manager is reviewing the organization's risk management approach. She wants to ensure that the team correctly distinguishes between threats, vulnerabilities, and risks. Which two of the following statements correctly describe these concepts? (Choose two.)

Hard
840

Which common port is used by DNS and which transport layer protocol does it primarily use?

Medium
841

An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?

Hard
842

A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?

Hard
843

A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)

Hard
844

You are implementing a security control to prevent unauthorized devices from connecting to the corporate wired network. Which network access control method should be used?

Hard
845

An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)

Medium
846

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Medium
847

Which THREE are phases of the incident response process according to NIST SP 800-61?

Easy
848

Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?

Medium
849

Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?

Easy
850

A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?

Medium
851

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Medium
852

After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?

Hard
853

An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?

Easy
854

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Hard
855

An analyst reviewing traffic captures sees a workstation repeatedly sending TCP packets with the SYN flag set to many different destination ports on a single server, but the workstation never completes the three-way handshake. The server's connection table is becoming exhausted. Which type of activity is most likely occurring?

Medium
856

A security administrator is reviewing network security controls. Which TWO of the following are examples of network segmentation technologies? (Select TWO)

Medium
857

During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?

Hard
858

Refer to the exhibit. What type of event is this?

Hard
859

What is the difference between identification and authentication?

Easy
860

During a security audit, you discover that a financial application stores passwords using MD5 hashing without salt. What is the primary security concern with this practice?

Medium
861

A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?

Medium
862

A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?

Medium
863

An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?

Easy
864

An analyst reviews the exhibit. What security principle is best demonstrated by this policy?

Hard
865

An organization has implemented a SIEM solution. The security team wants to detect when a user attempts to access a file they do not have permission to read. Which log source is most important for this detection?

Medium
866

Which of the following is considered sensitive personally identifiable information (PII)?

Medium
867

A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)

Medium
868

Which of the following best describes the purpose of due care in information security?

Easy
869

Which TWO of the following are core principles of the CIA triad?

Easy
870

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

Hard
871

A company's IDS generates an alert for a potential SQL injection attack on a web application. The analyst reviews the log and sees the following: "SELECT * FROM users WHERE username = 'admin' OR 1=1 --'". Which action should the analyst take next?

Hard
872

A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)

Hard
873

Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)

Easy
874

A security analyst discovers that a user's account has been used to access sensitive data outside of normal business hours from an unfamiliar IP address. The user claims they were not logged in at that time. Which security operations process should be initiated first?

Medium
875

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?

Easy
876

During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?

Medium
877

A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?

Medium
878

A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?

Medium
879

A company allows employees to connect to the corporate network from home using a VPN. The security team wants to ensure that a remote employee's device meets minimum security requirements, such as current antivirus and patched operating system, before granting access to internal applications. Which control should be implemented?

Medium
880

An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?

Hard
881

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Medium
882

A security analyst observes these SSH logs. What is the MOST likely attack?

Medium
883

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Hard
884

According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?

Medium
885

A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?

Medium
886

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

Hard
887

During which phase of the incident response process would the team identify the root cause of a security incident?

Easy
888

Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?

Easy
889

An organization wants to implement multi-factor authentication (MFA) for remote access by requiring a password and a smart card. Which two authentication factors are used in this MFA implementation? (Choose two.)

Easy
890

A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?

Medium
891

A financial institution wants to ensure that a wire transfer request cannot be denied by the sender later. The security team implements a mechanism where the sender's private key is used to sign the transaction. Which security principle does this primarily support?

Medium
892

A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?

Easy
893

A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?

Hard
894

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Medium
895

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

Hard
896

A company implements a policy where a financial transaction must be initiated by one employee and approved by a different employee. This is an example of which access control concept?

Medium
897

A security engineer is deploying a new VPN solution for remote employees. The company requires that the VPN provide strong encryption, support for multiple users, and the ability to traverse NAT devices. Which VPN protocol should the engineer choose?

Hard
898

Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)

Medium
899

A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?

Medium
900

A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?

Easy
901

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

Medium
902

A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?

Easy
903

Drag and drop the steps to configure a basic VPN (site-to-site) between two routers into the correct order.

Medium
904

A regional hospital's emergency department relies on a patient tracking system. The BIA shows the system's maximum tolerable downtime (MTD) is 2 hours. The recovery time objective (RTO) is currently 6 hours, and the recovery point objective (RPO) is 24 hours. Which action best aligns the recovery capability with the business requirement?

Medium
905

A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:

Hard
906

A government agency uses a multi-level security system with mandatory access control (MAC). A user with Secret clearance attempts to write data to a file classified as Confidential. Under the Bell-LaPadula model, which rule applies and what is the outcome?

Medium
907

A network administrator is designing a DMZ to host a public-facing web server and a database server that should only be accessible from the web server. Which of the following firewall rule sets best achieves this design?

Medium
908

A security manager is training new employees on the concept of risk. She explains that risk is composed of several elements. Which TWO of the following are components that directly contribute to risk? (Choose two.)

Medium
909

Which THREE of the following are examples of the principle of least privilege? (Select THREE.)

Medium
910

An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?

Medium
911

During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?

Hard
912

Which TWO of the following are common methods to authenticate users on a wireless network? (Select TWO)

Easy
913

An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?

Medium
914

A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?

Medium
915

A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)

Hard
916

Which port number is associated with HTTPS, and what protocol encrypts the communication?

Easy
917

A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?

Medium
918

During a security audit, a penetration tester captures network traffic and finds that some packets have the IP ID field set to 0 and the DF (Don't Fragment) flag set. What is this technique attempting to do?

Hard
919

A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?

Medium
920

An organization wants to implement a system that enforces access decisions based on a user's attributes (e.g., department, clearance, time) and environmental conditions. Which model is best?

Hard
921

A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?

Medium
922

A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?

Hard
923

An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?

Medium
924

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

Medium
925

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Medium
926

A security manager is designing a policy to prevent one person from both approving and disbursing payments. Which principle is being applied?

Medium
927

A medium-sized company uses a network with three VLANs: VLAN 10 (Users, 192.168.10.0/24), VLAN 20 (Servers, 192.168.20.0/24), and VLAN 30 (DMZ, 192.168.30.0/24). A Layer 3 switch with an ACL is used for inter-VLAN routing. The company has a web server in the DMZ that must be accessible from the internet (via a public IP mapped to 192.168.30.10). Users in VLAN 10 need to access the web server on its private IP (192.168.30.10) for internal testing. The ACL is applied inbound on the VLAN 10 SVI. The ACL currently has the following entries: permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255; deny ip any 192.168.20.0 0.0.0.255; permit ip any any. Recently, the security team noticed that users can access the web server on its private IP, but they cannot access the web server via the public IP (which goes through the firewall and then to the DMZ). The firewall logs show that traffic from the users to the public IP is allowed and reaches the DMZ web server, but the return traffic is blocked. The web server's default gateway is the Layer 3 switch (192.168.30.1). Which of the following is the most likely cause of the problem?

Hard
928

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

Medium
929

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Easy
930

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Hard
931

Which THREE are essential elements of a disaster recovery plan? (Select THREE.)

Easy
932

A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)

Hard
933

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

Medium
934

Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?

Easy
935

A company deploys a web application that stores user passwords using a salted hash. During a security review, an auditor recommends switching from SHA-1 to SHA-256. What is the primary security benefit of this change?

Medium
936

An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password due to a security breach. The link leads to a website that looks identical to the company's login page. Which type of attack is this?

Easy
937

Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?

Easy
938

An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?

Hard
939

A financial services company's business continuity plan includes a recovery time objective (RTO) of 4 hours for its trading platform. During a recent test, the platform was restored in 6 hours. Which of the following should be the PRIMARY focus of the after-action review?

Medium
940

What is the primary goal of data classification?

Easy
941

Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?

Hard
942

Which TWO of the following are core components of the CIA triad?

Easy
943

Which of the following are examples of sensitive PII? (Select all that apply.)

Medium
944

A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)

Medium
945

A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?

Medium
946

Drag and drop the steps to implement a firewall rule allowing inbound HTTPS traffic into the correct order.

Medium
947

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

Medium
948

Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?

Hard
949

Which TWO actions are appropriate during the identification phase of incident response?

Hard
950

Which of the following best describes the principle of confidentiality in the CIA triad?

Easy
951

An organization is implementing a new identity management system. They want to ensure that users can only access resources necessary for their job roles. Which principle should guide the access control design?

Hard
952

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Medium
953

Refer to the exhibit. A security engineer applies this storage access policy to restrict access. Users outside the 10.0.0.0/16 network report being denied access, which is expected. However, users inside that network also report access denied. What is the likely issue?

Medium
954

An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)

Easy
955

An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?

Hard
956

Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?

Hard
957

Which TWO are true about a differential backup? (Select two.)

Medium
958

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
959

A security engineer is reviewing firewall logs and notices that an internal host is making repeated outbound connections to a known malicious IP address on port 443. The firewall is configured to allow all outbound traffic to port 443. The engineer wants to block this specific traffic without disrupting other legitimate HTTPS traffic. Which action should the engineer take?

Hard
960

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

Hard
961

A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?

Hard
962

During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?

Hard
963

Which THREE are differences between a hot site and a cold site? (Select three.)

Hard
964

After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?

Medium
965

A hospital's compliance officer must decide how to protect patient records. The records must remain readable only to authorized clinicians while in storage and in transit. Which security principle is the compliance officer primarily applying?

Easy
966

A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)

Hard
967

Which TWO of the following are examples of administrative security controls?

Easy
968

An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?

Hard
969

Which TWO of the following are recognized as benefits of network segmentation?

Hard
970

An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?

Easy
971

An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?

Medium
972

Which THREE of the following are recognized security principles according to NIST and ISC2?

Medium
973

A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?

Medium
974

A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?

Hard
975

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

Medium
976

Which of the following protocols provides secure remote administration of a network device over an untrusted network?

Easy
977

A financial services firm wants to allow employees to securely access internal applications from home without exposing those applications directly to the internet. The security team proposes using a VPN that encrypts traffic at the network layer and can carry non-web protocols. Which VPN technology best meets this requirement?

Medium
978

A hospital uses role-based access control (RBAC) for its electronic health records. Nurses can view patient records; doctors can view and edit; administrators can only view administrative data. Recently, a nurse was able to edit a patient's record, which should only be allowed for doctors. The investigation finds that the nurse's role was incorrectly assigned a 'doctor' role due to a misconfiguration. To prevent recurrence, the access control system should be reviewed. Which is the best long-term solution?

Medium
979

Which of the following is a best practice for securing physical access to a data center?

Easy
980

Which layer of the OSI model is responsible for routing packets across networks?

Easy
981

Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?

Medium
982

A software-as-a-service (SaaS) provider is developing its business continuity plan (BCP). The company wants to ensure it can continue operating during a prolonged power outage at its primary data center. Which element of the BCP should address the alternate power source and its regular testing?

Medium
983

During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?

Hard
984

Which security control would best mitigate the risk of network sniffing on a wired LAN segment?

Medium
985

Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?

Easy
986

An organization requires that two different administrators approve changes to firewall rules. This is an example of which security principle?

Easy
987

A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?

Medium
988

Which TWO of the following are common indicators of a phishing email? (Select TWO.)

Medium
989

A security team implements a policy that requires all access to sensitive data to be logged and audited. Which principle is being enforced?

Easy

Frequently asked questions

What does the scenario questions domain cover on the CC exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 989 scenario questions questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.