Courseiva

CC · domain

scenario questions

Practise ISC2 Certified in Cybersecurity CC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

976 questions260 easy423 medium293 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (976)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are principles of the CIA triad? (Select TWO.)

Easy
2

A company's security policy states that employees should only have access to the data necessary to perform their job functions. This is an example of which principle?

Easy
3

A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?

Hard
4

An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)

Medium
5

An organization is implementing backup strategies. Which THREE are characteristics of differential backups? (Select THREE)

Medium
6

Which of the following is the primary purpose of a visitor log and escort policy?

Medium
7

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

Hard
8

A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?

Easy
9

Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
10

The exhibit shows recent authentication logs. What type of attack is most likely indicated?

Easy
11

A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?

Hard
12

Refer to the exhibit. What does this indicate?

Medium
13

A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)

Medium
14

An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?

Medium
15

A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?

Medium
16

A security analyst is reviewing an alert from the IDS that shows a large number of TCP SYN packets sent to a single port on multiple internal hosts from a single external IP address. The analyst suspects a reconnaissance attack. Which type of attack is this most likely?

Easy
17

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

Hard
18

A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured web server that exposed a database directly. Which principle was most lacking in this scenario?

Hard
19

What is the primary purpose of a digital signature?

Medium
20

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

Easy
21

An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?

Medium
22

A company's security policy requires that all sensitive data be encrypted both at rest and in transit. This is an example of applying which security principle?

Medium
23

A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?

Easy
24

During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?

Medium
25

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

Hard
26

Which THREE are examples of administrative access controls?

Hard
27

According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)

Hard
28

A security team discovers that an internal database server is sending large amounts of data to an unknown external IP address. The server is not supposed to communicate externally. Which security control should be implemented to prevent such data exfiltration?

Hard
29

An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?

Medium
30

During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?

Medium
31

Which of the following is the best practice for managing cryptographic keys in a large organization?

Hard
32

A security auditor discovers that a user has been granted read and write access to a sensitive file, but the user's job only requires read access. Which access control principle has been violated?

Hard
33

A security administrator needs to ensure that a user cannot view the contents of a file but can execute it. Which access control principle should be applied?

Easy
34

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Medium
35

A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?

Medium
36

According to NIST SP 800-63, which password policy is most recommended?

Medium
37

In a typical Windows environment, which access control model is used for managing file permissions?

Hard
38

Which two of the following are examples of physical access controls? (Select TWO)

Easy
39

A small business wants to minimize backup storage space and backup time, knowing that restoration may be slower. Which backup strategy should they choose?

Medium
40

A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)

Medium
41

An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?

Easy
42

In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?

Medium
43

A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?

Medium
44

A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?

Hard
45

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

Hard
46

A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?

Medium
47

Which TWO of the following are fundamental security principles? (Select TWO.)

Medium
48

An organization wants to implement defense in depth for its server room. Which THREE controls should be included?

Hard
49

Which access control principle restricts access to data based on the user's job role and tasks?

Easy
50

A security analyst notices that a user's account has been used to access sensitive files outside of normal working hours from an unknown IP address. Which security principle is most directly violated?

Easy
51

A security policy requires that all changes to production systems be approved by a change management board. Which THREE of the following principles best support this requirement?

Medium
52

A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:

Medium
53

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Hard
54

A mid-sized e-commerce company has a primary data center in New York and a disaster recovery site in Dallas. The application stack includes a web server, application server, and a PostgreSQL database. The database uses synchronous replication to the DR site. During a routine failover test, the IT team discovers that after failing over to Dallas, the web servers in New York continue to attempt connections to the original database IP, causing application errors. The DNS records have been updated to point to the DR database IP, but the web servers are not refreshing their DNS cache. The company uses a standard TTL of 300 seconds. The IT manager needs a solution that ensures minimal disruption during future failovers. Which action should be taken?

Easy
55

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

Easy
56

Based on the exhibit, which statement about the access control list is true?

Medium
57

An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:

Medium
58

Which of the following best describes a vulnerability in the context of risk management?

Medium
59

A company's network uses 802.1X authentication for wired and wireless access. Which component authenticates the user credentials against an identity store?

Medium
60

Which security principle ensures that data cannot be accessed by unauthorized individuals?

Easy
61

During a routine security audit, an analyst finds that several critical servers have misconfigured firewall rules allowing inbound SSH access from the entire internet. Which immediate action should the analyst take?

Medium
62

Which TWO of the following are common indicators of a potential data breach? (Choose two.)

Easy
63

Which authentication type is a smart card an example of?

Easy
64

Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?

Easy
65

Which TWO of the following are examples of integrity controls? (Select TWO)

Easy
66

An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?

Medium
67

A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?

Medium
68

A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:

Medium
69

An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:

Hard
70

After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?

Easy
71

A security analyst notices repeated failed login attempts from a single external IP address targeting the company's VPN concentrator. Which type of attack is most likely occurring?

Easy
72

A security administrator notices that a user with standard privileges was able to modify a system file. Which security principle has been violated?

Easy
73

A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?

Medium
74

To protect the integrity of log files, which of the following is a best practice?

Easy
75

An organization decides to implement multiple security controls, including firewalls, intrusion detection systems, and antivirus software. Which security principle does this represent?

Easy
76

Which THREE of the following are valid security control categories based on function? (Select three).

Hard
77

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
78

An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?

Hard
79

An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)

Hard
80

A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)

Medium
81

A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)

Hard
82

A security operations center (SOC) analyst is investigating an alert about a user downloading a suspicious file. The analyst opens the file on a sandboxed virtual machine and observes that it attempts to modify registry keys and establish persistence. This type of analysis is known as:

Hard
83

An analyst is reviewing a series of failed login attempts from multiple IP addresses targeting a single user account. This pattern is indicative of what type of attack?

Hard
84

An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?

Hard
85

A security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?

Hard
86

Which of the following is an indicator of a phishing email?

Easy
87

After a security breach, it was discovered that an attacker used a stolen certificate to sign malicious code. Which security principle was compromised?

Medium
88

An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?

Medium
89

An employee is assigned a user account with read-only access to the sales database. However, the employee's job requires viewing only customer contact information, not sales figures. Which access control principle is being violated?

Hard
90

During a security assessment, a penetration tester captures unencrypted credentials over the network. Which protocol is most likely being used?

Medium
91

You are a SOC analyst for a financial institution. At 2:00 AM, your SIEM generates a critical alert from the email security gateway indicating that an internal user received a phishing email with a malicious attachment. The email was delivered to the user's inbox, and the user's account activity logs show that the attachment was opened 10 minutes ago. The user is a junior accountant who works in the accounts payable department. You have access to endpoint detection tools, email logs, and network traffic data. The organization's incident response policy requires containment within 30 minutes of detection. Which action should you take FIRST?

Medium
92

Drag and drop the steps for the incident response process according to NIST into the correct order.

Medium
93

Drag and drop the steps to create a new VLAN on a managed switch into the correct order.

Medium
94

An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?

Medium
95

A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?

Medium
96

Your organization runs a critical e-commerce platform on a private cloud. The database server is located in a data center in a seismic zone. The current DR plan uses a warm site with daily differential backups and a 12-hour RTO. A recent earthquake caused a power outage but no physical damage. The database corruption was discovered after 6 hours. The backups from last night are intact but restoring involves applying transaction logs. The RTO is now at risk. What should be done FIRST?

Hard
97

Which of the following is an example of a logical access control?

Easy
98

Refer to the exhibit. Given the ACL shown, which traffic is allowed to reach 10.0.0.1?

Medium
99

A company uses a proxy server for internet access. Employees can browse websites (HTTP/HTTPS), but they cannot connect to external FTP servers using FTP client software (e.g., FileZilla). The proxy is configured to allow HTTP and HTTPS only. The security team wants to allow FTP while maintaining security (e.g., logging and filtering). The FTP traffic is used for occasional file transfers with partners. Which of the following is the BEST solution to meet both requirements?

Medium
100

A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?

Hard
101

Which of the following is a primary goal of security operations?

Easy
102

A system administrator needs to grant a user the ability to read files in a specific folder but not modify them. Which access control principle should be applied?

Easy
103

An organization is implementing a patch management policy. Which THREE steps are part of the standard patch lifecycle?

Medium
104

Refer to the exhibit. An analyst sees many alerts from this IDS rule. What is a likely cause?

Medium
105

A company requires employees to use biometric authentication to access the data center. This is an example of which security principle?

Easy
106

An organization is re-evaluating its disaster recovery site options. Which TWO of the following describe characteristics of a warm site?

Medium
107

In the identification and authentication process, which step occurs first?

Easy
108

An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?

Easy
109

Which security control is most effective in preventing unauthorized physical access to a data center?

Easy
110

Refer to the exhibit. What is the effect of this ACL?

Medium
111

Which TWO technologies provide network segmentation? (Choose two.)

Medium
112

Refer to the exhibit. A security analyst sees this log entry from a firewall. What is the most likely reason for this denial?

Easy
113

An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:

Hard
114

A security administrator needs to ensure that only authorized personnel can access the server room. Which physical control is most appropriate?

Easy
115

A system administrator configured the sudoers file as shown. What is the primary security risk of this configuration?

Hard
116

During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?

Medium
117

A company is implementing an access control system to protect sensitive data. Employees in the finance department must access financial records, but only during business hours and from company-issued devices. Which access control model best supports these requirements?

Medium
118

A company experiences a ransomware attack that encrypts all files on a file server. The IT team decides to restore the server from the most recent full backup taken 24 hours ago, followed by all differential backups taken since then. If the last full backup was on Sunday at midnight, and the attack occurs on Wednesday at 6:00 AM, with differential backups taken daily at noon, how many differential backups must be restored?

Hard
119

Refer to the exhibit. The network administrator configured NAT as shown. Internal hosts can access the internet, but no external hosts can access the company's web server (192.168.1.10). What is the issue?

Hard
120

Which access control model allows the owner of a resource to decide who can access it?

Easy
121

A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?

Medium
122

Which THREE of the following are core principles of the CIA triad?

Medium
123

Match each security control type to its description.

Medium
124

Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)

Hard
125

A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?

Easy
126

What is the process of claiming an identity called?

Easy
127

Which of the following ports is used by HTTPS for secure web traffic?

Medium
128

Which TWO of the following are primary objectives of an incident response plan? (Choose two.)

Hard
129

A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)

Medium
130

Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?

Medium
131

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Medium
132

Which TWO are examples of technical access controls?

Easy
133

An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?

Easy
134

Which TWO of the following are primary goals of the security principle of confidentiality?

Medium
135

Match each cryptographic concept to its definition.

Medium
136

Which OSI layer is responsible for logical addressing and routing?

Easy
137

A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?

Hard
138

Which of the following is an example of a detective control in a security operations context?

Easy
139

A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)

Medium
140

A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?

Medium
141

A company needs to enforce access based on attributes such as time of day and location. Which access control model is most appropriate?

Medium
142

A company uses a stateful firewall. A user reports that an application requiring multiple dynamic ports is not working. The firewall logs show that packets from the server are being dropped. What is the most likely cause?

Hard
143

Which three of the following are benefits of using VLANs in a network? (Choose three.)

Medium
144

An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?

Medium
145

An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?

Medium
146

What is the primary difference between an IDS and an IPS?

Easy
147

An employee uses a password and a one-time code from a mobile authenticator app to log in. Which authentication type is being used?

Medium
148

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

Medium
149

According to the (ISC)² Code of Ethics, which canon has the highest priority?

Hard
150

Which of the following is an example of a Type 2 authentication factor?

Medium
151

A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?

Medium
152

A financial company requires that any transaction over $10,000 must be approved by two different managers before being processed. This is an example of which access control principle?

Medium
153

A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:

Hard
154

After a security incident, the incident response team closes the case. What is the MOST important final step to improve future security posture?

Hard
155

An organization wants to protect its internal network from unsolicited inbound traffic while allowing responses to outbound connections. Which TWO firewall features or types are best suited for this? (Select TWO)

Medium
156

A help desk technician receives a report that a user cannot access a shared network drive. The technician checks the file server and sees that the disk is full. What is the most immediate action the technician should take?

Easy
157

During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?

Hard
158

Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?

Easy
159

Refer to the exhibit. ``` { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*" } ] } ``` A security analyst reviews this AWS S3 bucket policy. The policy currently allows anyone to read objects. Which change would implement the principle of least privilege?

Hard
160

A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?

Medium
161

A SOC analyst is reviewing logs from a web server and sees the following entry: GET /../../../../etc/passwd HTTP/1.1 Which type of attack is being attempted?

Medium
162

An organization wants to implement the principle of least privilege for its database administrators. Which approach best achieves this goal?

Medium
163

A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?

Medium
164

Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?

Easy
165

Refer to the exhibit. Which security principle is this policy primarily enforcing?

Medium
166

A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?

Medium
167

Which of the following is a benefit of using VLANs in a network?

Easy
168

An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?

Hard
169

An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?

Medium
170

A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:

Easy
171

An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?

Easy
172

A security administrator is concerned about MAC address spoofing on the network. Which technology can help mitigate this risk by associating a specific MAC address with a port?

Medium
173

A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?

Medium
174

An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)

Hard
175

An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?

Hard
176

A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?

Medium
177

An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?

Hard
178

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

Medium
179

An organization implements an access control system where users are assigned to groups, and permissions are granted to groups rather than individuals. This is known as:

Easy
180

What is the primary purpose of a digital signature?

Hard
181

Which of the following is an example of a vulnerability?

Medium
182

During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?

Hard
183

An employee reports receiving a suspicious email with an attachment from an unknown sender. What is the first action the employee should take?

Easy
184

A system administrator runs `iptables -L INPUT` and sees this rule. What is the immediate effect on the system?

Hard
185

A help desk technician needs to reset a user's password, but the security policy requires that the technician does not know the new password. Which access control concept prevents the technician from knowing the password?

Easy
186

An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?

Hard
187

Refer to the exhibit. Based on the exhibit, why was the packet denied?

Easy
188

A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?

Medium
189

A financial firm has a data center with strict access controls. Employees must use smart cards and PINs to enter a mantrapped entrance. Recently, an unauthorized person gained access by following an employee through the mantrapped door (tailgating). The security team reviews logs and finds that the door was opened twice in quick succession, indicating tailgating occurred. The firm wants to implement a solution that prevents tailgating without slowing down authorized access. Which action should they take?

Hard
190

A SOC analyst reviews an alert indicating a high number of failed login attempts from a single external IP address targeting multiple user accounts. Which security control is most effective at preventing this type of attack?

Easy
191

A company's security policy requires that all incident response activities be logged and that evidence be preserved for potential legal action. During an incident, a responder mistakenly uses a personal USB drive to copy log files. Which principle of forensic evidence handling has been violated?

Hard
192

A company recently experienced a DoS attack targeting their web server. They want to implement a solution that can differentiate between legitimate traffic and attack traffic based on behavior patterns. Which technology should they deploy?

Medium
193

An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?

Hard
194

Which of the following is an example of a logical access control?

Easy
195

A security architect is designing access controls for a new application. The requirement is that only managers can approve expense reports above $10,000. Which control model best fits this requirement?

Medium
196

Which of the following is a recommended practice for administrative accounts?

Easy
197

An organization's backup schedule: Full backup every Sunday, incremental backups Monday-Saturday. If a failure occurs on Thursday, how many backup sets are needed to restore the data?

Medium
198

A security operations center (SOC) analyst receives an alert for a potential malware infection on a workstation. Which of the following is the first action the analyst should take?

Easy
199

Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?

Hard
200

According to NIST SP 800-63, which password policy is recommended to enhance security?

Medium
201

A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?

Hard
202

A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?

Medium
203

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

Medium
204

An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?

Medium
205

Which THREE of the following are examples of implementing defense in depth? (Select THREE.)

Hard
206

A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?

Easy
207

A security engineer is reviewing logs and notices that an internal server is receiving excessive SYN packets from an external IP, but never completing the three-way handshake. What type of attack is likely occurring?

Hard
208

Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?

Medium
209

During a disaster recovery test, the IT team discovers that restoring all data from full backups takes 48 hours, exceeding the RTO. Which backup strategy would reduce restore time while maintaining a similar backup window?

Medium
210

Refer to the exhibit. A network administrator configured the above on a switch port. After connecting a single workstation, the port goes into err-disabled state within minutes. What is the most likely cause?

Easy
211

Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?

Easy
212

Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?

Easy
213

Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)

Easy
214

A security operations center (SOC) analyst receives an alert for a high volume of outbound traffic from an internal server to a known malicious IP address. Which step should the analyst take next?

Medium
215

Which TWO of the following are core components of the ISC2 Code of Ethics? (Choose two.)

Medium
216

An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?

Medium
217

A software developer is designing a web application that will store user credentials. What is the most secure method for storing passwords?

Hard
218

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

Medium
219

A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?

Hard
220

A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?

Medium
221

An organization implements a policy requiring employees to use a separate administrator account for privileged tasks and a different account for daily activities. Which principle does this support?

Hard
222

An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)

Hard
223

Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?

Medium
224

Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?

Easy
225

A user reports that they received a suspicious email with an attachment claiming to be an invoice. What should the user do?

Easy
226

A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?

Hard
227

A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?

Medium
228

A network security team is implementing a defense-in-depth strategy. Which TWO of the following controls are examples of network segmentation? (Choose two.)

Easy
229

A security analyst reviews firewall logs and sees a series of outbound connections from an internal server to a known command-and-control (C2) IP address at regular intervals. Which step should the analyst take first according to incident response best practices?

Hard
230

A company is developing a disaster recovery plan for its database server. The database is updated transactionally and cannot tolerate any data loss. Which backup strategy meets this requirement?

Medium
231

A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)

Hard
232

Which of the following is a common mitigation technique for a SYN flood attack?

Hard
233

Which TWO of the following are examples of implementing the principle of least privilege?

Hard
234

Which TWO of the following correctly describe components of a directory service distinguished name (DN) in LDAP? (Select two.)

Medium
235

An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?

Hard
236

Which TWO of the following controls are examples of defense in depth?

Medium
237

Which protocol is considered insecure because it transmits data in cleartext, including passwords?

Easy
238

Which TWO of the following are examples of Type 3 (inherence) authentication factors?

Easy
239

A legacy system cannot be patched due to vendor unavailability. Which compensating control would be most effective in reducing the risk of exploitation?

Hard
240

Which of the following is an example of a logical access control?

Medium
241

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
242

Refer to the exhibit. Based on the log entries, what type of attack is most likely occurring?

Easy
243

An online retailer has a DR plan that includes active-active data centers. During a major DDoS attack, one data center's external connectivity is saturated. The internal network is operational. The security team has identified the attack traffic pattern and is working with the ISP to filter. To maintain service availability, what action should be taken?

Medium
244

After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?

Hard
245

A company discovers a critical vulnerability in a widely used software application. The vendor has released a patch, but the company's patch management policy requires testing before deployment. What is the best course of action?

Medium
246

An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)

Hard
247

A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?

Medium
248

An organization requires employees to enter a password and then approve a push notification on their mobile device to access the corporate network. What type of authentication is this?

Medium
249

Which TWO of the following are commonly used techniques to detect phishing emails? (Choose two.)

Medium
250

A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?

Medium
251

During a phishing investigation, a security analyst identifies that an employee clicked a malicious link. The analyst isolates the workstation. What is the NEXT best step?

Medium
252

An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?

Medium
253

A company's network uses a perimeter firewall and an internal firewall. The DMZ sits between them. A new application server needs to be accessible from the internet on TCP port 8443 and must be able to make outbound HTTPS connections to an external license server. Which firewall rules should be implemented? (Assume default deny)

Hard
254

An organization implements a role-based access control (RBAC) system. To maintain the principle of least privilege, what should the administrator do when a user changes roles?

Hard
255

Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?

Easy
256

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
257

Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?

Medium
258

A security team is designing a network for a hospital. They need to ensure that patient data is accessible to doctors only when needed, but also protected from unauthorized access. Which principle BEST balances these requirements?

Medium
259

Which authentication factor does a smart card represent?

Easy
260

A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?

Easy
261

A security operations team is implementing a new SIEM solution. They want to ensure that logs from all critical systems are collected and analyzed in real time. Which of the following is the MOST important consideration when designing the log collection architecture?

Easy
262

A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?

Hard
263

A Privileged Access Management (PAM) solution is used to:

Hard
264

A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?

Easy
265

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

Medium
266

A company's security policy mandates that all changes to the firewall configuration must be approved by two different administrators before implementation. This is an example of which security principle?

Medium
267

An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?

Hard
268

An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?

Medium
269

A network administrator configures the ACL on a router as shown. What is the effect of this access list?

Easy
270

A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?

Medium
271

An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)

Hard
272

A security analyst investigates a possible data exfiltration. The analyst sees a large amount of data being sent to an external IP address at regular intervals. Which of the following is the most likely technique being used?

Hard
273

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

Hard
274

A small company with 50 employees uses a flat network with no VLANs. They recently experienced a ransomware attack that spread from an infected workstation to a file server. The IT manager wants to implement network segmentation to prevent future lateral movement. The company uses a single /24 subnet (192.168.1.0/24) with a single switch and a router/firewall. They have three departments: Sales, HR, and IT. Each department has about 15-20 computers. The file server is in the IT department. The company has a limited budget and cannot purchase new hardware. Which of the following is the MOST effective and practical approach to segment the network given these constraints?

Medium
275

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

Medium
276

An organization's security policy mandates that data must be encrypted both at rest and in transit. Which combination of controls meets this requirement?

Easy
277

Refer to the exhibit. Which security control is MOST likely triggered?

Easy
278

A company's security policy states that sensitive data must be encrypted using AES-256. During an audit, it is found that some data is encrypted with AES-128. Which security objective is most directly compromised?

Hard
279

Which of the following is an example of a logical access control?

Easy
280

What is the primary purpose of a Security Information and Event Management (SIEM) system?

Easy
281

Which TWO are examples of logical access controls? (Select TWO.)

Easy
282

A security analyst is investigating a potential man-in-the-middle attack. Which two techniques are commonly used by attackers to perform MITM attacks? (Choose two.)

Medium
283

A security administrator notices that an employee is able to access files in a project folder they should not have access to. Which security principle is being violated?

Easy
284

A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?

Medium
285

Which data classification level typically requires the highest level of protection?

Easy
286

A network administrator notices unusual traffic from an internal workstation to an external IP address on port 443. The workstation has no business reason for such communication. Which action should the administrator take first?

Easy
287

A critical vulnerability is discovered in a widely used VPN appliance that is actively being exploited in the wild. The vendor has released an emergency patch. However, the organization's patch management policy requires testing in a staging environment before production deployment. What should the security team do?

Hard
288

An AWS administrator attached this IAM policy to a user. What is the effect of this policy?

Medium
289

A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)

Medium
290

Which concept ensures that a user cannot deny having performed a specific action?

Easy
291

An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)

Hard
292

A security operations center receives an alert that a workstation has been infected with ransomware. The infection is isolated to one machine. What is the first step in the containment phase of incident response?

Easy
293

A company has a Recovery Point Objective (RPO) of 1 hour for its financial database. It performs full backups every night at 11 PM and incremental backups every 4 hours. If the system fails at 2:30 PM, what is the maximum data loss in terms of time?

Hard
294

A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?

Medium
295

Which three of the following are best practices for securing a network switch? (Choose three.)

Medium
296

After a reorganization, a company using RBAC finds that many users have accumulated permissions that no longer align with their job functions. What is the best practice to address this?

Medium
297

Which TWO of the following are best practices for securing a wireless network? (Select exactly two.)

Medium
298

An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?

Medium
299

After a ransomware attack, the company wants to ensure that critical data can be restored. Which principle is being addressed?

Medium
300

Match each security policy type to its focus.

Medium
301

An organization's business continuity plan designates a maximum tolerable downtime (MTD) of 8 hours for its order processing system. The system's recovery time objective (RTO) is set at 4 hours, and work recovery time (WRT) is estimated at 2 hours. If a disaster occurs at 10:00 AM and the system is restored at 2:00 PM, but additional configuration and data validation take until 3:30 PM to complete, what is the total downtime and is the MTD met?

Hard
302

During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?

Hard
303

Which TWO are essential elements of a business impact analysis (BIA)?

Medium
304

After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:

Hard
305

An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?

Medium
306

During a disaster recovery test, the team discovers that the backup generator fails to start. What is the BEST immediate action?

Easy
307

A Security Operations Center (SOC) Tier 1 analyst notices an alert for a failed login attempt from an unusual geographic location. What is the primary responsibility of a Tier 1 analyst in this scenario?

Easy
308

A company conducts a background check on a new vendor before signing a contract. This activity is an example of:

Hard
309

In the context of identification and authentication, which of the following is an example of authentication?

Medium
310

During a ransomware incident, the incident response team has completed the containment and eradication phases. According to the NIST incident response framework, which THREE of the following activities are part of the post-incident activity phase?

Hard
311

After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?

Medium
312

A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?

Easy
313

An organization is implementing a patch management program. Which of the following is the BEST approach to minimize risk while maintaining operational stability?

Medium
314

A network administrator needs to provide secure remote access to internal resources for employees working from home. The solution must encrypt all traffic and authenticate users before granting access. Which protocol should be used?

Easy
315

During a penetration test, an analyst discovers that a company's internal network has a switch configured with port security that allows only one MAC address per port. However, the analyst is able to plug a rogue device into a wall jack and successfully gain network access. What is the most likely weakness in this configuration?

Hard
316

A company wants to ensure that a message received was not altered in transit. Which principle is of primary concern?

Medium
317

A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:

Medium
318

During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?

Medium
319

Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?

Easy
320

Which type of access control is implemented by a cable lock attached to a laptop?

Easy
321

Which TWO are primary objectives of a Business Continuity Plan (BCP)? (Select two.)

Medium
322

A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?

Medium
323

A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?

Medium
324

Which type of authentication factor involves something the user knows?

Easy
325

A company has implemented a role-based access control (RBAC) system. A new employee in the finance department is granted the 'Finance User' role, which allows them to view invoices but not create payments. However, after a system upgrade, it is discovered that the 'Finance User' role now includes the ability to create payments due to a misconfiguration. The employee did not request this additional privilege and has not exploited it. The security team is notified. Which principle has been violated, and what is the most appropriate immediate action?

Hard
326

An organization's security policy requires that all access to sensitive data must be approved by a data owner. An administrator configures a system to enforce this. Which principle is being implemented?

Hard
327

During an incident, the security team detects unusual outbound traffic from a server that normally does not communicate externally. The traffic appears to be encrypted and is sent to an unknown IP address. Which incident category best describes this scenario?

Hard
328

A company performs background checks on potential employees before hiring. This action demonstrates which concept?

Medium
329

Which TWO principles are essential for ensuring accountability in an information system? (Choose two.)

Hard
330

Which THREE of the following are considered risk management strategies? (Select THREE)

Hard
331

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Medium
332

Drag and drop the steps to recover a system from a verified backup after a ransomware attack into the correct order.

Medium
333

A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:

Hard
334

A system administrator accidentally grants a user full administrative rights instead of read-only. Which control would best detect this error?

Hard
335

A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?

Easy
336

An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?

Medium
337

You are a security analyst at a medium-sized company with 500 employees. The company uses a centralized log management system that collects logs from all servers and network devices. For the past week, you have noticed a pattern: every night at 2:00 AM, a series of failed login attempts occurs on the domain controller from an internal IP address (10.10.50.100). The attempts use the username "Administrator" and are always from the same workstation in the accounting department. The accounting department operates 9 AM to 6 PM, so no one is in the office at 2 AM. You have checked the workstation's physical security; it is in a locked office with access only by authorized accounting staff. The workstation is running Windows 10 with up-to-date antivirus and has no signs of compromise. You also checked the network switch logs and see that the workstation is connected to a specific port. You suspect the workstation might be compromised or being used remotely. What is the most appropriate next step?

Hard
338

When implementing multi-factor authentication, which combination of factors is considered strongest?

Medium
339

During a forensic investigation, it is crucial to preserve the original evidence. What is the first step the investigator should take when acquiring a hard drive?

Medium
340

An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?

Medium
341

A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)

Hard
342

Which TWO of the following are methods to ensure non-repudiation? (Select two).

Medium
343

According to the NIST incident response lifecycle, which three phases are considered the core phases?

Medium
344

A multinational corporation has a policy that all sensitive emails must be digitally signed and encrypted. However, during a recent internal audit, it was discovered that many employees were not using digital signatures because the process was cumbersome. As a result, the company could not prove that certain emails were actually sent by the claimed sender. The security team needs to improve compliance without sacrificing security. Which of the following is the best approach?

Hard
345

A small business has a single server that hosts critical applications. The server's hard drive fails, and the most recent backup is 3 days old. The backup is stored on an external drive that is kept in the same room as the server. The server is also the domain controller and file server. After replacing the drive and restoring from backup, the IT administrator discovers that some user files are missing because they were created after the backup. The administrator needs to minimize data loss in the future. Which of the following should be implemented?

Easy
346

A company experiences a data breach where customer PII was exfiltrated. The incident response team contains the breach and restores systems. Which step in the risk management process should the company prioritize next to prevent recurrence?

Medium
347

A company's critical database must be recovered within 4 hours after a disaster, and they can tolerate losing up to 1 hour of data. During a disaster, after the systems are restored, it takes an additional 30 minutes to verify data integrity and resume normal operations. Which metric is represented by the 4-hour requirement?

Medium
348

A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)

Medium
349

In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?

Medium
350

An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)

Medium
351

Which TWO are appropriate methods to test a disaster recovery plan?

Hard
352

A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)

Medium
353

A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?

Medium
354

A security analyst reviews firewall logs and notices a large number of outbound connections from a single internal IP to a known malicious IP on port 445. The analyst quarantines the workstation and runs an antivirus scan, which finds no malware. What should the analyst do next?

Hard
355

A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?

Medium
356

Which backup strategy offers the fastest restore time but requires the most storage space?

Medium
357

An organization's backup strategy includes daily full backups. However, recovery tests show that restoring from tape takes 6 hours longer than expected. What is the most likely cause?

Medium
358

During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?

Hard
359

Which THREE are key components of Active Directory? (Select THREE.)

Medium
360

Which THREE are core components of the CIA triad? (Choose three.)

Easy
361

What is the difference between due care and due diligence in security governance?

Medium
362

Refer to the exhibit. What is the effect of this ACL?

Hard
363

An analyst reviews the exhibit. Which security principle is being violated by allowing root login via SSH?

Medium
364

Drag and drop the steps to configure a wireless access point with WPA2-PSK security into the correct order.

Medium
365

A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?

Easy
366

A security administrator notices that a user's account has been used to access sensitive files at unusual hours. Which security principle would most effectively help detect this type of activity?

Easy
367

A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?

Hard
368

During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?

Medium
369

A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?

Hard
370

Which THREE elements are essential components of a business continuity plan (BCP)?

Medium
371

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

Medium
372

A SOC analyst is reviewing a security alert about a potential brute-force attack on the company's VPN server. The analyst sees multiple failed login attempts from different IP addresses within a short time frame. Which TWO actions should the analyst take to verify and respond to this incident? (Choose two.)

Medium
373

During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?

Medium
374

When designing a secure network, which TWO of the following are fundamental security principles that should be applied?

Hard
375

Which THREE of the following are examples of risk mitigation? (Select THREE)

Hard
376

An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:

Easy
377

Drag and drop the steps for the TCP three-way handshake into the correct order.

Medium
378

A company's security operations center (SOC) receives an alert about suspicious outbound traffic from a server in the DMZ to an external IP address known for command-and-control activity. The SOC analyst reviews the logs and sees that the source port is 443 and the destination port is 8080. Which of the following actions should the analyst take FIRST?

Medium
379

Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)

Hard
380

The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?

Hard
381

Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)

Medium
382

Which TWO of the following are examples of security principles?

Easy
383

Which of the following is the primary purpose of a security information and event management (SIEM) system?

Easy
384

A medium-sized enterprise uses a Cisco ASA firewall configured with multiple security zones (Inside, Outside, DMZ). The DMZ hosts a web server that must be accessible from the Internet on TCP 443. The Inside network (10.0.0.0/24) hosts internal clients. The web server has IP 172.16.0.10. The firewall's current rules: allow any from Outside to DMZ on TCP 443; allow any from Inside to Outside; deny all else. Recently, the security team noticed that an attacker compromised the web server and used it to launch an attack against an internal database server at 10.0.0.50. The attack was successful because the firewall allowed traffic from the DMZ to the Inside. The firewall's default behavior is to deny traffic from lower security zones to higher security zones (DMZ is lower than Inside). What is the MOST likely reason this traffic was allowed?

Hard
385

An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?

Medium
386

Match each risk management term to its meaning.

Medium
387

A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?

Hard
388

A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

Medium
389

A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?

Medium
390

Which of the following is an example of Type 2 authentication?

Easy
391

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Hard
392

A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?

Medium
393

A company deploys a web application firewall (WAF), performs regular vulnerability scans, and implements strict access controls. Which security principle is being applied?

Medium
394

A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?

Medium
395

A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:

Hard
396

During a security audit, it is discovered that a single administrator can create user accounts, assign privileges, and review audit logs. Which principle is most likely being violated?

Medium
397

An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:

Hard
398

A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?

Medium
399

A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?

Hard
400

Which control type is considered a physical security control?

Easy
401

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

Easy
402

Drag and drop the steps to perform a password reset on a Windows user account into the correct order.

Medium
403

Which is a key benefit of a cold site as a recovery location?

Medium
404

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Medium
405

A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:

Medium
406

A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?

Easy
407

Which THREE of the following are common components of a disaster recovery plan?

Easy
408

An organization wants to implement a policy where employees must use a smart card and a PIN to access sensitive data. This is an example of:

Hard
409

Which incident category involves an attempt to make a system or network resource unavailable to its intended users?

Medium
410

A SOC analyst notices a large spike in outbound traffic from a workstation that is not scheduled for any data transfers. Upon checking the SIEM, the analyst sees that the workstation's antivirus was disabled 30 minutes ago. What type of logs should the analyst examine first to understand the sequence of events?

Medium
411

A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?

Easy
412

Which three ports are commonly used by secure protocols? (Choose THREE.)

Medium
413

A company uses a mandatory access control (MAC) system where all files are labeled 'Confidential', 'Secret', or 'Top Secret'. A user with 'Secret' clearance tries to read a 'Top Secret' file. What is the outcome?

Hard
414

An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?

Medium
415

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Medium
416

In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

Hard
417

A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?

Medium
418

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

Easy
419

Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?

Medium
420

Match each access control model to its key characteristic.

Medium
421

A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?

Medium
422

A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)

Hard
423

During a forensic investigation, the analyst needs to acquire a memory image from a live Windows system without altering evidence. Which tool is MOST appropriate?

Hard
424

Which THREE of the following are considered essential security principles according to ISC2?

Hard
425

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

Hard
426

A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)

Hard
427

An account lockout policy is implemented to protect against which type of attack?

Medium
428

A SOC analyst is investigating a potential data exfiltration incident. The logs show that an internal user transferred a large volume of data to a cloud storage service using HTTPS. The analyst finds that the user's workstation has BitLocker Drive Encryption enabled, and the user has administrative privileges. Which of the following best describes the PRIMARY challenge in investigating this incident?

Hard
429

Which THREE of the following are essential components of an incident response plan? (Select THREE.)

Hard
430

During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?

Hard
431

During a security incident, the incident response team isolates a compromised workstation from the network. What is the primary purpose of this action?

Medium
432

You are an IT administrator for a small business. The company has a backup system that performs nightly full backups of critical servers to an external hard drive. One morning, a user reports that they accidentally deleted an important file from a shared drive. You need to restore the file from last night's backup. However, when you connect the external hard drive to the backup server, the drive is not recognized, and you hear clicking sounds. The backup software shows that the most recent backup job completed successfully with no errors. What is the most likely cause of the problem?

Easy
433

A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?

Easy
434

A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?

Medium
435

An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?

Medium
436

A security analyst is troubleshooting an access control issue where a user cannot access a file even though they seem to have the correct permissions. Which three of the following should the analyst investigate? (Select THREE)

Hard
437

Which of the following is an indicator of a phishing email?

Easy
438

A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?

Easy
439

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Hard
440

Which of the following is a primary benefit of implementing network segmentation?

Easy
441

Which THREE components are part of the AAA framework?

Hard
442

An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?

Easy
443

Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?

Medium
444

In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?

Medium
445

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Medium
446

Which of the following is a connectionless, unreliable transport protocol?

Easy
447

A security auditor discovers that during a VLAN hopping attack, a threat actor was able to send frames from a workstation on VLAN 10 to a target on VLAN 20. Which configuration flaw is most likely responsible?

Hard
448

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

Medium
449

A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:

Hard
450

A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?

Easy
451

A security engineer is designing a DMZ for a web server that must be accessible from the internet. The web server needs to query an internal database server. Which network security approach best limits exposure?

Medium
452

Which TWO of the following are examples of preventive security controls?

Easy
453

Which of the following best describes the purpose of a session timeout?

Easy
454

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

Easy
455

A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?

Medium
456

Which layer of the OSI model is responsible for routing packets based on IP addresses?

Easy
457

An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?

Medium
458

An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?

Medium
459

Refer to the exhibit. A security analyst reviews this log entry. What type of attack is most likely occurring?

Medium
460

An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)

Easy
461

An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?

Hard
462

An organization wants to ensure that critical security events are not missed during off-hours. What is the best practice?

Easy
463

A financial institution has a security operations center that monitors network traffic using a SIEM. The SIEM receives logs from all network devices, servers, and endpoints. One analyst notices an anomaly: a user account, 'jsmith', which is normally used during business hours (9 AM to 5 PM), has been logging in from a remote IP address at 2 AM every day for the past week. The logins are successful, and the user is accessing internal file shares. The user jsmith works in the accounting department and has access to sensitive financial reports. The analyst checks the user's workstation logs and finds that the workstation is powered off at the time of the remote logins. The company uses two-factor authentication, but the log entries show that only the password was used. Which of the following is the most likely explanation and the best immediate action?

Hard
464

An organization is developing a data classification policy. Which THREE of the following are common classification levels?

Hard
465

Which TWO are phases of the NIST incident response life cycle? (Select exactly 2.)

Easy
466

An organization wants to ensure that system logs are tamper-proof after generation. Which control should be implemented?

Easy
467

A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?

Hard
468

A financial services firm has a data center that houses customer financial records. They have implemented a defense-in-depth strategy including firewalls, IDS/IPS, and encryption. Recently, an internal audit revealed that a junior administrator has been logging into the database server with a shared admin account and has made unauthorized changes to customer records. The company wants to prevent such incidents in the future while maintaining operational efficiency. The current environment uses Linux servers with PostgreSQL databases. There is no centralized authentication system. What is the BEST action to take?

Hard
469

In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?

Hard
470

An organization determines that its critical financial application has a maximum tolerable downtime (MTD) of 8 hours. The recovery time objective (RTO) is set to 6 hours, and the work recovery time (WRT) is 2 hours. If the application is restored from backup in 5 hours, but additional configuration takes 3 hours, what is the total downtime, and is the MTD met?

Medium
471

A security engineer is designing a backup strategy for a critical database. The database must be recoverable within four hours in the event of a failure. Which security principle primarily drives this requirement?

Medium
472

A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?

Medium
473

In a defense-in-depth strategy, which access control mechanism provides the most granular control over user permissions?

Hard
474

A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?

Medium
475

You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?

Hard
476

A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)

Hard
477

Which OSI layer is responsible for routing packets across networks using IP addresses?

Easy
478

A system administrator implements version control for all configuration files. Which principle is being strengthened?

Medium
479

Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?

Easy
480

A cloud security engineer reviews a cloud storage bucket policy that grants read access to all users, including anonymous users. What is the primary security risk?

Hard
481

A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?

Easy
482

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

Medium
483

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

Medium
484

An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?

Medium
485

You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?

Hard
486

A security engineer is configuring a firewall to allow web traffic but block all other inbound connections. The firewall is set to deny all traffic by default and only allow specific ports. Which security principle is being applied?

Medium
487

An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?

Easy
488

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

Hard
489

An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?

Medium
490

A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?

Medium
491

An organization is developing a security policy that defines the rules for acceptable use of company resources. Which principle should guide the creation of this policy to ensure it is enforceable and effective?

Easy
492

A security analyst notices that an internal web server is receiving a high volume of TCP SYN packets from a single external IP address, but the server is not sending SYN-ACK replies. The server's CPU and memory usage are normal. What is the most likely cause?

Easy
493

During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:

Hard
494

A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?

Medium
495

A company implements two-factor authentication (2FA) for all remote access. Which primary security goal is this enhancing?

Medium
496

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

Easy
497

A security analyst receives an alert indicating multiple failed login attempts from a single IP address targeting a user account. Which action should the analyst take FIRST?

Easy
498

An organization uses a SIEM to correlate logs from multiple sources. A rule triggers when a user logs in from two geographically distant locations within a short time. What type of attack does this rule primarily detect?

Medium
499

A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?

Medium
500

During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
501

An organization is designing a security architecture for a cloud-based application. They implement firewalls, intrusion detection systems, and encryption, and also conduct regular security awareness training. This approach demonstrates which security principle?

Hard
502

A security operations center (SOC) analyst notices unusual outbound network traffic from a server that typically only receives connections. The traffic is encrypted and goes to an unknown external IP. Which step should the analyst perform FIRST?

Medium
503

During a patch management cycle, a new vulnerability is disclosed in a widely used web server software. What is the first step an organization should take in the patch lifecycle?

Easy
504

An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)

Hard
505

A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?

Medium
506

Which THREE are commonly defined in a disaster recovery plan? (Select exactly 3.)

Medium
507

According to NIST SP 800-63, which password policy is most effective for user authentication?

Medium
508

An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?

Medium
509

An organization's backup strategy includes daily full backups and hourly incremental backups. During a restoration, they discover that a critical file was corrupted 6 hours ago. Which backup set is required for the restoration?

Hard
510

Which statement best describes a warm site in disaster recovery?

Hard
511

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

Medium
512

An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?

Medium
513

An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?

Hard
514

A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?

Medium
515

Which of the following best describes a Disaster Recovery Plan (DRP)?

Easy
516

A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?

Medium
517

A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?

Easy
518

Refer to the exhibit. A security analyst sees these logs from a Linux server. Which security control should the analyst recommend to address this pattern?

Medium
519

During a forensic investigation, an analyst acquires a live system memory dump. Which tool is most appropriate for capturing the contents of volatile memory on a Windows system?

Hard
520

A company is designing a new application that processes credit card payments. They want to ensure that no single administrator can bypass security controls to approve a fraudulent transaction. Which principle should be implemented?

Hard
521

After a security audit, a company discovers that several employees have access to financial systems that are not required for their job roles. Which access control model would best prevent this issue in the future?

Medium
522

In a Bell-LaPadula MAC model, which of the following operations is prohibited?

Hard
523

A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?

Medium
524

A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?

Hard
525

What is the primary purpose of a Privileged Access Management (PAM) solution?

Medium
526

An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?

Hard
527

A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?

Hard
528

Which of the following is a key component of the 3-2-1 backup rule?

Easy
529

Which TWO of the following are fundamental principles of information security that form the CIA triad?

Easy
530

Which of the following ensures that data has not been tampered with during transmission?

Easy
531

A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?

Hard
532

An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?

Medium
533

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

Medium
534

Which TWO of the following are best practices for password management in a corporate environment?

Easy
535

According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?

Medium
536

Which TWO of the following are examples of physical access controls?

Easy
537

A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
538

An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?

Hard
539

A security professional is evaluating a system that uses a trust model where every component authenticates to each other before communicating. Which security principle does this model exemplify?

Hard
540

An organization needs to prioritize recovery of systems after a disaster. Which metric directly indicates the maximum acceptable outage time for a business function?

Medium
541

During a BIA, the maximum tolerable downtime for a critical application is determined to be 4 hours. The IT team estimates system recovery will take 2 hours, but additional manual work to reconcile data will take 1 hour. What is the Recovery Time Objective (RTO)?

Medium
542

Which THREE are common indicators of a compromised system? (Select THREE.)

Hard
543

Refer to the exhibit. Based on the exhibit, which traffic will be permitted?

Medium
544

Which of the following is considered Sensitive PII?

Easy
545

A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?

Medium
546

A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?

Medium
547

Refer to the exhibit. An access control policy is shown. Which action is permitted by this policy?

Easy
548

A user reports that they are unable to access a shared network drive that they previously could access. The administrator checks permissions and finds the user's account is still a member of the correct group. What should the administrator check next?

Medium
549

An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?

Hard
550

Refer to the exhibit. Based on the report, which improvement is most appropriate?

Medium
551

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Medium
552

Which TWO are best practices for managing backup media?

Medium
553

A security team configures a system to record all user activities for audit purposes. Which principle is being applied?

Easy
554

Which THREE are primary phases of the incident response lifecycle?

Hard
555

A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?

Medium
556

A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)

Medium
557

Which of the following is an example of a detective control?

Easy
558

An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?

Medium
559

A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?

Hard
560

Which of the following is an example of a physical control that supports the availability principle of the CIA triad?

Easy
561

An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?

Hard
562

A medium-sized company uses a SIEM solution to collect logs from firewalls, servers, and endpoints. The security team receives an alert indicating a possible data exfiltration: an employee's workstation is sending large amounts of data to an external IP address outside business hours. The employee works in the finance department and has access to sensitive financial records. The SIEM shows the connection is ongoing. The security team must respond immediately to contain the incident while preserving evidence. The company's incident response plan designates the security team as first responders. Which of the following is the BEST first action?

Medium
563

Which of the following is the most effective way to prevent tailgating in a secured facility?

Medium
564

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

Medium
565

Which OSI layer is responsible for routing packets based on IP addresses?

Easy
566

Which of the following are core principles of information security?

Medium
567

Which two of the following are common types of security controls?

Easy
568

A healthcare organization uses a legacy application that stores patient records in plain text. The IT team is planning to upgrade the system but needs to ensure compliance with HIPAA. The new system will be hosted on-premises and accessed by doctors and nurses via a web portal. The security team proposes implementing a VPN for remote access, but the CEO wants to allow access from any device without VPN for convenience. Which principle should guide the decision?

Medium
569

A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?

Medium
570

Which process involves verifying the identity of a user who claims to be a specific person?

Easy
571

Refer to the exhibit. A security analyst notices that a user with the Finance role is able to write to /finance/data from a macOS device at 10:00 AM. The policy shown is the only policy affecting this resource. What is the most likely reason for this behavior?

Hard
572

Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?

Easy
573

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

Easy
574

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

Easy
575

You are the lead SOC analyst for a medium-sized financial services company. The company uses a hybrid infrastructure with on-premises servers and cloud services (AWS). The SIEM is Splunk Enterprise, collecting logs from firewalls, IDS/IPS, endpoints (Windows and Linux), and AWS CloudTrail. Recently, the company experienced a ransomware attack that encrypted critical file servers. The initial infection vector was a phishing email that led to the download of a malicious macro-enabled document. The document was executed on a Windows workstation, which then established a C2 connection to an external IP. The C2 traffic was over HTTPS, and the workstation was part of the domain. After the attack, the forensic team found that the workstation had Windows Event Logs cleared, and the local admin account had been used to disable the antivirus. The C2 IP was later blocked, but the ransomware had already spread to file servers via SMB. As part of the lessons learned, you need to recommend improvements to prevent and detect such attacks in the future. Which of the following is the BEST course of action to address the specific weaknesses exploited in this incident?

Hard
576

Which protocol is considered insecure because it transmits data, including credentials, in cleartext?

Medium
577

An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?

Hard
578

Match each phase of the incident response process to its description.

Medium
579

Refer to the exhibit. What action did the firewall take on the traffic from 10.0.1.15 to 10.0.2.10?

Medium
580

A company wants to mitigate the risk of a man-in-the-middle (MITM) attack. Which three measures are effective? (Choose THREE.)

Hard
581

In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)

Hard
582

An account lockout policy is designed to mitigate which type of attack?

Medium
583

A government agency stores classified documents on a secure server. The server is connected to the internet, but access is restricted using a firewall and requires two-factor authentication. An auditor discovers that the server's operating system has not been patched for over a year, making it vulnerable to remote code execution attacks. Which security principle is most directly compromised by this missing patch, and what is the best corrective action?

Easy
584

Based on the backup schedule, what is the maximum potential data loss?

Medium
585

Match each network security concept to its purpose.

Medium
586

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

Hard
587

Which TWO of the following are components of the identification and authentication process? (Select TWO.)

Medium
588

Which THREE of the following are considered fundamental security principles? (Select three).

Easy
589

A security team is designing a visitor management policy. Which TWO of the following are essential components? (Select TWO.)

Medium
590

An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?

Medium
591

During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?

Easy
592

What is the primary purpose of using security baselines derived from CIS Benchmarks?

Medium
593

Which THREE of the following are essential components of a security baseline configuration for a server?

Hard
594

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

Hard
595

A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?

Easy
596

A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?

Medium
597

Which of the following ports is used by HTTPS?

Easy
598

A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?

Medium
599

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Hard
600

A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:

Hard
601

Refer to the exhibit. A network administrator configured the following firewall rules. After implementation, users from the internal network cannot browse the internet. Which element is causing the issue?

Medium
602

Which THREE are recommended practices for password policies according to current guidelines?

Medium
603

During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?

Medium
604

A company's security policy requires that all data at rest be encrypted. Which of the following is the BEST approach to ensure compliance while maintaining performance?

Medium
605

A company's primary data center experiences a complete power failure, and operations are shifted to a secondary site. The failover process takes 4 hours, but the recovery point objective (RPO) is set to 1 hour. Which of the following is the most likely consequence of this incident?

Medium
606

A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?

Hard
607

Which of the following ports is commonly used for secure web traffic (HTTPS)?

Easy
608

Which THREE of the following are best practices for securing a remote access VPN?

Hard
609

A system administrator must grant a help desk technician the ability to reset user passwords but not change user roles. Which security principle does this scenario enforce?

Easy
610

An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?

Easy
611

A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?

Hard
612

After a ransomware attack, which team is primarily responsible for coordinating the response?

Easy
613

An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?

Medium
614

In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?

Hard
615

Which THREE of the following are best practices for securing a wireless network?

Hard
616

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

Medium
617

An administrator reviews the exhibit. Which security principle is being violated?

Easy
618

According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?

Hard
619

A security analyst reviews this firewall log entry. What type of activity is most likely being attempted?

Hard
620

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

Medium
621

A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?

Medium
622

A company's security policy requires that employees must change their passwords every 90 days and passwords must be at least 12 characters. Which security principle is being enforced?

Easy
623

An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?

Medium
624

During an incident response, a forensics analyst captures a memory dump from a compromised server. The analyst needs to ensure the dump is not altered during analysis. Which practice best maintains integrity?

Hard
625

Refer to the exhibit. Which security principle is being supported by the logging of these events?

Hard
626

According to the (ISC)² Code of Ethics, which obligation has the highest priority?

Medium
627

A network technician is setting up a remote access VPN for employees using IPsec. The company's firewall is configured to allow IPsec traffic. Employees report that they can successfully establish the VPN connection (tunnel appears up), but they cannot ping or access any internal resources (e.g., file servers). The firewall logs show that packets from the VPN client IP addresses are being dropped at the firewall interface. Which of the following is the MOST likely cause of this issue?

Easy
628

A small manufacturing company's IT infrastructure consists of a single server running ERP and file services, with a nightly backup to an external hard drive. The server fails due to hardware failure. The company's BCP states that the ERP system must be restored within 8 hours. The backup is 12 hours old. The IT administrator has a spare server of similar configuration. What is the BEST course of action?

Easy
629

An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)

Hard
630

An organization uses a warm site for disaster recovery. Which of the following is the MOST significant risk of this approach?

Hard
631

Which of the following is a control that can reduce the risk of a DDoS attack?

Easy
632

An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?

Medium
633

A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:

Medium
634

Refer to the exhibit. A user from the Auditors group is unable to access the folder. What is the most likely cause?

Hard
635

During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?

Hard
636

Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?

Easy
637

An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?

Hard
638

A company's remote access VPN uses IPsec with pre-shared keys. Employees report that they cannot connect from home. The VPN server logs show 'IKE authentication failed.' The help desk confirms the pre-shared keys are correct. Which of the following is the most likely cause?

Medium
639

An organization implements a bring-your-own-device (BYOD) policy. Which security control is most important to enforce in the BYOD policy?

Medium
640

A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?

Easy
641

A company has implemented a security information and event management (SIEM) system. The SOC team notices that the SIEM is generating a high volume of false positive alerts from a specific web application firewall (WAF). The WAF logs show many requests with SQL injection patterns, but the application is not vulnerable. Which of the following actions would BEST reduce false positives without compromising security?

Medium
642

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

Medium
643

A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).

Medium
644

Which of the following is a recommended practice for password security according to NIST SP 800-63?

Medium
645

A company wants to protect its internal web server from common web application attacks. Which two security measures are most appropriate? (Choose TWO.)

Medium
646

Which TWO are characteristics of Role-Based Access Control (RBAC)?

Medium
647

When implementing a role-based access control (RBAC) system, what is the primary challenge organizations face?

Hard
648

A company is evaluating backup strategies for its critical database. Which TWO of the following are correct statements about backup types?

Easy
649

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

Easy
650

You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?

Medium
651

A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?

Medium
652

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

Hard
653

A company uses WPA2-Enterprise for wireless authentication. What additional security measure should be implemented to protect against rogue access points?

Medium
654

A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?

Easy
655

An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?

Easy
656

Which TCP segment is sent to initiate the three-way handshake?

Easy
657

A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?

Hard
658

A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?

Medium
659

Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?

Easy
660

A SOC analyst detects a series of failed login attempts from a single external IP address targeting multiple user accounts within a short time. Which action should the analyst take FIRST?

Medium
661

A small business owner wants to ensure that their company's data remains accurate and unaltered during transmission over the internet. They regularly send financial reports to their accountant via email. The owner is concerned that a hacker might intercept and modify the reports before they reach the accountant. Which security principle is most directly threatened in this scenario, and what is the best technical control to implement?

Easy
662

Refer to the exhibit. ``` C:\> netstat -an | find "LISTENING" TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?

Easy
663

A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?

Medium
664

A SOC team is reviewing security controls for a new critical application. Which THREE of the following are essential components of a security operations capability?

Medium
665

A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?

Hard
666

An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?

Easy
667

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

Medium
668

A medium-sized e-commerce company operates a web application on three virtual servers behind a load balancer. The application handles credit card payments and stores customer data in a database server. The company has a security operations team that monitors logs from firewalls, IDS, and servers. One morning, the IDS generates a critical alert indicating a SQL injection attempt from an external IP to the web application. The alert shows that the injection string was ' OR '1'='1' -- . The web server logs confirm that the request returned a 200 OK status and a large response size. The database logs show a query that returned multiple rows. The security analyst needs to determine the best immediate course of action. The company has a documented incident response plan that includes containment, eradication, and recovery phases. Which action should the analyst take first?

Hard
669

An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?

Hard
670

During a security audit, it is found that a database administrator can access payroll data. The company policy states that administrators should not have access to sensitive HR data. Which security principle is being violated?

Hard
671

A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)

Medium
672

Refer to the exhibit. The file is readable and writable by everyone. A user from the marketing team, user2, needs to be able to read the file but not write to it. Which command should the administrator use to achieve this?

Medium
673

Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?

Easy
674

A company's network uses 802.1X authentication with PEAP-MSCHAPv2 on wired ports. Users report that after a recent switch firmware update, some workstations fail to authenticate intermittently, while others work fine. The authentication server logs show 'Authentication failed: Unknown CA certificate' for affected workstations. What is the most likely cause?

Hard
675

A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?

Hard
676

A company experiences a ransomware attack that encrypts all files on a critical server. The backup strategy includes nightly backups stored on a separate network. What should be the first action during recovery?

Medium
677

Based on the incident log, at which step did the incident response team contain the threat?

Easy
678

A company implements a visitor management policy requiring all visitors to sign in, wear a badge, and be escorted. Which access control principle does this primarily support?

Medium
679

A security engineer is designing a network for a small business that needs to segregate guest Wi-Fi from the internal corporate network. The guest network should have internet access only, with no access to internal resources. Which of the following is the BEST design approach?

Medium
680

Which TWO of the following are examples of administrative security controls? (Choose two.)

Medium
681

An organization is implementing a new system that processes financial transactions. To reduce the risk of fraud, they ensure that no single individual can both initiate and approve a transaction. Which security principle is this?

Hard
682

A security analyst discovers that an organization's firewall rule set allows all inbound traffic on TCP port 443 from any source to a single web server. Additionally, the server has a known critical vulnerability in its TLS implementation. Which principle of security architecture is most directly violated by this configuration?

Hard
683

A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?

Easy
684

Match each OSI layer to its function.

Medium
685

Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?

Medium
686

A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?

Hard
687

A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?

Medium
688

You are the cybersecurity lead for a mid-sized retail company. One morning, employees report that they cannot access files on the shared drive, and a ransom note appears on several screens demanding $50,000 in Bitcoin. The company has a formal incident response plan that was last updated two years ago and has never been tested. Backups are taken nightly to an on-premises tape library and also replicated to a cloud storage service but have not been verified recently. The CEO is insisting on paying the ransom to avoid business disruption. Which of the following is the MOST appropriate first course of action?

Easy
689

Which TWO of the following are examples of detective security controls? (Choose two.)

Hard
690

Which of the following is a key function of a Security Information and Event Management (SIEM) system?

Easy
691

A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?

Medium
692

Which THREE are valid methods for authenticating a user in an access control system?

Hard
693

A company's primary data center is located in a region prone to hurricanes. The IT team is designing a disaster recovery plan to ensure critical applications resume within 4 hours of a declared disaster. Which of the following is the MOST appropriate recovery strategy?

Easy
694

Which THREE are best practices for password management according to modern guidelines? (Select THREE.)

Medium
695

An organization has a legacy system that cannot be patched due to vendor end-of-life. Which compensating control is most effective at reducing the risk of exploitation via network-based attacks?

Hard
696

Which THREE of the following are best practices for securing a network firewall? (Select THREE.)

Hard
697

After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?

Hard
698

Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)

Medium
699

A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?

Hard
700

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Medium
701

Refer to the exhibit. An administrator notices that external access to the MySQL database (port 3306) is blocked, but internal access should be allowed. What change should be made?

Medium
702

You are a forensic analyst responding to a reported compromise of a Linux web server. The server hosts a public-facing web application and is part of a DMZ. The initial investigation shows that unauthorized outbound connections were made to a known malicious IP address during the previous night. The server is still running and connected to the network, but the web application has been taken offline for maintenance. The incident response team wants to preserve evidence for potential legal action. You have a forensic workstation with tools like dd, netcat, and memory acquisition tools. Which of the following should be your FIRST step in the forensic acquisition process?

Hard
703

A security engineer is designing a system that must ensure that any changes to a configuration file are logged with the identity of the person who made the change. Which principle is being implemented?

Hard
704

The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?

Easy
705

An organization is choosing a backup strategy to minimize restore time. Which TWO backup types require only the most recent full backup and the latest differential backup to restore?

Medium
706

A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?

Hard
707

A company is implementing a backup strategy. Which TWO of the following are characteristics of incremental backups? (Choose two.)

Medium
708

Refer to the exhibit. A firewall rule set is shown (first match applies). An analyst reviews these rules. Which of the following best describes the traffic outcome for a packet from source IP 10.0.0.1 to destination 192.168.1.1?

Hard
709

A company wants to allow remote employees to securely access internal resources over the internet. Which technology is most appropriate?

Easy
710

Which TWO of the following are essential elements of an incident response plan?

Medium
711

Which of the following controls is primarily designed to ensure availability?

Medium
712

An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?

Hard
713

Which TWO of the following are best practices for implementing the principle of least privilege?

Hard
714

You are the network security lead for a medium-sized financial firm with 500 employees. The network consists of a core switch, distribution switches, and access switches. There are three main VLANs: VLAN 10 (Management - 192.168.10.0/24), VLAN 20 (Finance - 192.168.20.0/24), and VLAN 30 (Guest Wi-Fi - 192.168.30.0/24). The network uses a single firewall with three interfaces: inside (trusted), outside (untrusted), and DMZ. The firewall is configured with default-deny rules. Recently, the helpdesk reported that employees in the Finance VLAN cannot access a web-based accounting application hosted on a server at 10.0.0.5, which is in the DMZ. The server's default gateway is the firewall's DMZ interface (10.0.0.1). The accounting application runs on HTTPS (TCP 443). Employees in the Management VLAN can access the application without issue. You have verified that the Finance VLAN has connectivity to the firewall's inside interface (192.168.20.1). The firewall's inside interface has an IP of 192.168.20.1. There is no ACL on the inside interface. The firewall's DMZ interface has an ACL permitting TCP/443 from any to 10.0.0.5. The firewall's routing table shows a route to 10.0.0.0/24 via DMZ interface. What is the most likely cause of the issue?

Hard
715

Refer to the exhibit. Based on the backup log, what is the most likely corrective action?

Medium
716

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

Hard
717

Which incident category involves an attacker tricking an employee into revealing credentials?

Easy
718

A system administrator needs to grant a contractor temporary access to a server for patching. The contractor should only have access during the patching window. Which access control implementation method is most appropriate?

Medium
719

An organization wants to ensure that data remains unaltered during transmission over the internet. Which security goal is being addressed?

Easy
720

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

Medium
721

Which metric defines the maximum acceptable amount of data loss measured in time?

Easy
722

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

Easy
723

A SOC analyst notices that a large volume of outbound traffic is occurring from a single workstation to an external IP address known to be associated with a command-and-control server. What is the most likely conclusion?

Easy
724

A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)

Medium
725

Refer to the exhibit. Based on the JSON policy, what access does the SecurityAuditor role have?

Hard
726

During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?

Hard
727

Which of the following is a potential security issue commonly found in firewall configurations?

Hard
728

Your organization is implementing a new access control system to protect a highly sensitive research database. The security policy mandates that no single individual should have the ability to both approve and execute changes to the database. This is to prevent fraud and errors. Which security principle does this policy enforce, and which of the following best implements it?

Medium
729

A security architect is designing a system that must ensure that a sender cannot later deny having sent a message. Which cryptographic mechanism should be implemented?

Hard
730

Which component of the AAA framework determines what resources an authenticated user can access?

Medium
731

Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?

Easy
732

An organization's security policy requires that all network traffic logs be retained for at least one year. The SIEM system is running low on storage, and the administrator must decide which data to archive first. Which data set is the least critical for ongoing security monitoring and can be archived earliest?

Hard
733

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

Hard
734

Which of the following is classified as sensitive PII?

Medium
735

A network administrator needs to allow secure remote access for teleworkers. Which VPN protocol provides the best confidentiality and integrity while using a single UDP port?

Medium
736

An organization requires that two separate administrators approve and implement changes to firewall rules. This practice enforces which security principle?

Hard
737

An organization implements a policy where users must swipe their ID card and enter a PIN to access a secure room. This is an example of which access control principle?

Easy
738

Refer to the exhibit. The security principle demonstrated by the default policy is:

Easy
739

A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?

Medium
740

A small e-commerce company hosts its web application on a single server with a public IP address. The server runs a Linux OS with Apache, MySQL, and PHP. The company recently experienced a data breach where an attacker gained access to the customer database. The investigation reveals that the attacker exploited a vulnerability in the PHP application to execute arbitrary commands. The server logs show that the attacker used an unauthenticated HTTP POST request to a legacy script that should have been removed. Additionally, the server had default firewall rules allowing all inbound traffic on ports 80 and 443. The company wants to prevent future breaches without redesigning the entire application. Which course of action is the most effective?

Hard
741

A security analyst observes the log entries on an SSH server as shown. What is the most likely type of attack in progress?

Medium
742

A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)

Hard
743

A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?

Hard
744

Which TWO are key outputs of a Business Impact Analysis (BIA)?

Easy
745

An organization has a policy that all servers must have security patches applied within 30 days of release. Which of the following is the best practice for patching?

Medium
746

An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)

Medium
747

Which of the following is a security concern associated with the Telnet protocol?

Medium
748

A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?

Easy
749

A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?

Medium
750

Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.

Medium
751

In a directory service such as Active Directory, which component is responsible for storing information about users, groups, and computers in a hierarchical structure?

Hard
752

An incident response team is analyzing a data breach. Which THREE actions are part of the 'Lessons Learned' phase? (Select THREE)

Hard
753

Which of the following is an example of a logical access control?

Easy
754

An organization wants to ensure that no single employee can both request and approve a payment. Which access control principle does this enforce?

Easy
755

What is the primary purpose of identification in the context of access control?

Easy
756

During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?

Hard
757

Which TWO of the following are valid types of disaster recovery tests?

Medium
758

An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?

Easy
759

Which of the following best describes the difference between due care and due diligence in security governance?

Hard
760

You are the security administrator for a mid-sized e-commerce company. The company uses a Linux-based web server running Apache, with a MySQL database backend. User authentication is handled via LDAP. Recently, the security team discovered that a former employee's account was used to access the customer database two weeks after the employee was terminated. The account had not been disabled. The database contains personally identifiable information (PII). The incident was traced to an internal IP address from the marketing department. The marketing department's network segment is not segregated from the database server. Additionally, the database server's firewall rules allow any internal IP to connect to the MySQL port (3306). The company has a written policy that accounts must be disabled within 24 hours of termination, but the HR department did not notify IT in a timely manner. Which combination of controls would BEST prevent a recurrence of this incident?

Hard
761

Which TWO are key components of an effective incident response plan? (Select TWO.)

Medium
762

An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?

Medium
763

A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?

Hard
764

Which TWO of the following are common indicators of a phishing email?

Easy
765

Which of the following is an example of a Type 2 authentication factor?

Easy
766

Which of the following is an example of a Type 1 authentication factor?

Medium
767

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

Medium
768

A company implements a policy where users must swipe their access card and then enter a PIN to enter the data center. This is an example of:

Medium
769

A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?

Easy
770

A company's backup strategy involves daily full backups only. What is the primary risk associated with this approach?

Easy
771

A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?

Medium
772

An organization's security policy requires that all employees change their passwords every 90 days. This is an example of which type of security control?

Easy
773

According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?

Hard
774

A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)

Hard
775

Which document outlines the procedures for maintaining critical business functions during a disruption?

Easy
776

A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?

Medium
777

A company has implemented a policy where all employees must use a smart card and PIN to access the data center. Which security principle does this practice support?

Easy
778

Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?

Medium
779

An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:

Medium
780

A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?

Hard
781

Which THREE of the following are best practices for privileged account management? (Select THREE.)

Medium
782

An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)

Medium
783

A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)

Hard
784

Which TWO of the following are common indicators of a ransomware attack?

Easy
785

An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?

Easy
786

A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?

Easy
787

A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)

Medium
788

Which TWO of the following are types of security controls?

Medium
789

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Hard
790

A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?

Medium
791

A company is selecting a recovery site strategy. Which TWO factors should be considered when choosing between a hot site and a warm site? (Select TWO.)

Medium
792

During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?

Hard
793

You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?

Hard
794

Refer to the exhibit. A security analyst runs the above iptables command on a Linux server. The server is configured with a default policy of DROP on the INPUT chain. Users report they can SSH to the server but cannot ping it. What is the most likely reason?

Hard
795

Which THREE of the following are recognized security control types according to ISC2? (Choose three.)

Hard
796

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

Hard
797

During a security incident, a forensic analyst needs to acquire the contents of RAM from a live system. Which tool should be used?

Hard
798

A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?

Medium
799

A small financial firm has a single server that hosts a critical database and also runs a web application. The server is located in a closet with a simple lock. An intern accidentally left the closet door open, and an unauthorized person gained physical access, connected a laptop to the server, and copied the database. The company wants to prevent such incidents in the future. Which of the following is the most effective course of action?

Easy
800

A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?

Medium
801

A security analyst discovers that an employee shared their password with a colleague to complete a task. Which security principle has been violated?

Easy
802

An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
803

A company wants to implement a security control that ensures users are who they claim to be before granting access to a system. Which type of control should they prioritize?

Easy
804

An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:

Hard
805

A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?

Medium
806

An organization uses a primary data center and a backup site 500 miles away. The backup site replicates data synchronously. Which risk is MOST likely introduced by this configuration?

Medium
807

According to the (ISC)² Code of Ethics, which principle has the highest priority?

Medium
808

Which access control model uses subject and object labels to enforce access based on a security policy?

Easy
809

An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?

Medium
810

Refer to the exhibit. What is the first action the incident responder should take?

Easy
811

What is the primary purpose of hashing in information security?

Easy
812

Which TWO are principles of access control?

Medium
813

A company's backup strategy requires daily full backups of all servers. The backup window is 4 hours. What is the primary risk if backups consistently take longer than the window?

Easy
814

An organization wants to ensure that its backup strategy can recover data within 2 hours after a system failure. Which metric should be defined in the disaster recovery plan?

Hard
815

A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:

Hard
816

A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?

Hard
817

A security architect is evaluating a biometric authentication system. The system's false positive rate is 0.1%, and the false negative rate is 2%. Which security principle is most compromised if the organization prioritizes user convenience over security?

Hard
818

Match each authentication factor to an example.

Medium
819

Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?

Medium
820

A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?

Easy
821

A company's security policy requires that all sensitive data be encrypted during transfer. A security administrator discovers that an internal web application is using a self-signed TLS certificate. What vulnerability does this introduce?

Hard
822

In a MAC environment implementing Bell-LaPadula, a subject with Secret clearance attempts to read an object classified as Confidential and write to an object classified as Top Secret. Which operations are permitted?

Hard
823

Which common port is used by DNS and which transport layer protocol does it primarily use?

Medium
824

An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?

Hard
825

A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)

Hard
826

You are implementing a security control to prevent unauthorized devices from connecting to the corporate wired network. Which network access control method should be used?

Hard
827

An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)

Medium
828

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Medium
829

Which THREE are phases of the incident response process according to NIST SP 800-61?

Easy
830

Which type of log should be monitored to detect a user account that has been granted administrative privileges unexpectedly?

Medium
831

Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?

Medium
832

A company is classifying data and wants to ensure that personally identifiable information (PII) receives appropriate protection. Which two of the following are considered PII? (Choose two.)

Medium
833

Which of the following is an example of a Type 2 authentication factor?

Easy
834

Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?

Easy
835

An organization wants to implement a physical access control that requires two different credentials to enter a high-security server room. Which concept does this best represent?

Hard
836

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
837

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

Medium
838

After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?

Hard
839

A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)

Hard
840

A security administrator is reviewing network security controls. Which TWO of the following are examples of network segmentation technologies? (Select TWO)

Medium
841

During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?

Hard
842

Refer to the exhibit. What type of event is this?

Hard
843

What is the difference between identification and authentication?

Easy
844

Refer to the exhibit. A security engineer reviews this firewall ACL. Which of the following best describes the security posture?

Medium
845

During a security audit, you discover that a financial application stores passwords using MD5 hashing without salt. What is the primary security concern with this practice?

Medium
846

A company wants to implement account lockout to prevent brute-force attacks. Which lockout threshold is most appropriate according to common best practices?

Hard
847

An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?

Easy
848

An analyst reviews the exhibit. What security principle is best demonstrated by this policy?

Hard
849

An organization has implemented a SIEM solution. The security team wants to detect when a user attempts to access a file they do not have permission to read. Which log source is most important for this detection?

Medium
850

Which of the following is considered sensitive personally identifiable information (PII)?

Medium
851

A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)

Medium
852

Which of the following best describes the purpose of due care in information security?

Easy
853

Which TWO of the following are core principles of the CIA triad?

Easy
854

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

Hard
855

A company's IDS generates an alert for a potential SQL injection attack on a web application. The analyst reviews the log and sees the following: "SELECT * FROM users WHERE username = 'admin' OR 1=1 --'". Which action should the analyst take next?

Hard
856

A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)

Hard
857

Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)

Easy
858

A security analyst discovers that a user's account has been used to access sensitive data outside of normal business hours from an unfamiliar IP address. The user claims they were not logged in at that time. Which security operations process should be initiated first?

Medium
859

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?

Easy
860

During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?

Medium
861

A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?

Medium
862

An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?

Hard
863

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Medium
864

During an incident, the incident response team discovers that an attacker has exfiltrated sensitive customer data. According to incident response best practices, whose approval is REQUIRED before contacting law enforcement?

Easy
865

A security analyst observes these SSH logs. What is the MOST likely attack?

Medium
866

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Hard
867

A security analyst is reviewing data handling procedures. Which THREE of the following are considered sensitive PII?

Hard
868

According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?

Medium
869

A company's security policy requires that all privileged access to critical servers be logged and monitored. The IT team has implemented a jump server (bastion host) for administrators to connect to critical servers. All SSH connections to the jump server are logged, and from there, administrators connect to target servers. The security team notices that some administrators are bypassing the jump server and connecting directly to critical servers from their workstations. The direct connections are not logged. The security team needs to enforce the policy without disrupting operations. Which of the following is the BEST solution?

Medium
870

A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?

Hard
871

During which phase of the incident response process would the team identify the root cause of a security incident?

Easy
872

Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?

Easy
873

A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?

Medium
874

A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?

Easy
875

The exhibit shows a snippet of /var/log/auth.log on a Linux server. Which security principle is most likely violated if the failed attempts continue without action?

Hard
876

A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?

Hard
877

A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)

Medium
878

According to the (ISC)² Code of Ethics, which of the following has the highest priority?

Hard
879

A company implements a policy where a financial transaction must be initiated by one employee and approved by a different employee. This is an example of which access control concept?

Medium
880

Which of the following is considered sensitive Personally Identifiable Information (PII)?

Easy
881

Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)

Medium
882

A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?

Medium
883

A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?

Easy
884

A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:

Medium
885

Drag and drop the steps to configure a basic VPN (site-to-site) between two routers into the correct order.

Medium
886

A company implements a policy that after an employee leaves, their account must be disabled within 24 hours. Which principle is this policy primarily intended to support?

Hard
887

A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:

Hard
888

A government agency uses a multi-level security system with mandatory access control (MAC). A user with Secret clearance attempts to write data to a file classified as Confidential. Under the Bell-LaPadula model, which rule applies and what is the outcome?

Medium
889

A network administrator is designing a DMZ to host a public-facing web server and a database server that should only be accessible from the web server. Which of the following firewall rule sets best achieves this design?

Medium
890

Which THREE of the following are examples of the principle of least privilege? (Select THREE.)

Medium
891

An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?

Medium
892

During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?

Hard
893

Which TWO of the following are common methods to authenticate users on a wireless network? (Select TWO)

Easy
894

Which TWO scenarios best illustrate the principle of least privilege?

Medium
895

A healthcare organization suffers a data breach involving protected health information (PHI). The incident occurred on Monday, and the organization discovers it on Wednesday. Under GDPR, if the breach affects EU residents, what is the deadline for notifying the supervisory authority?

Hard
896

An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?

Medium
897

A company's network has multiple VLANs. An attacker on VLAN 10 sends a frame with a forged source MAC address to a switch, hoping to intercept traffic intended for the default gateway. Which attack is being executed?

Hard
898

Which port number is associated with HTTPS, and what protocol encrypts the communication?

Easy
899

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
900

Refer to the exhibit. An administrator configures the above ACLs on a router. The goal is to allow internal users (192.168.1.0/24) to browse the web, and to allow SSH management from the internet to a server at 10.0.0.10. However, users report that they cannot browse external websites. What is the most likely reason?

Medium
901

An analyst reviews the firewall log exhibit. The source IP 10.0.1.100 is an internal web server. The destination IP 203.0.113.50 is an external host. What does this log pattern MOST likely indicate?

Medium
902

During a security audit, a penetration tester captures network traffic and finds that some packets have the IP ID field set to 0 and the DF (Don't Fragment) flag set. What is this technique attempting to do?

Hard
903

An organization wants to implement a system that enforces access decisions based on a user's attributes (e.g., department, clearance, time) and environmental conditions. Which model is best?

Hard
904

A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?

Medium
905

Which of the following best describes a vulnerability in the context of risk management?

Medium
906

Refer to the exhibit. A security analyst observes that users from the 192.168.1.0/24 network cannot access HTTPS websites, but HTTP access works fine. What is the most likely cause?

Easy
907

A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?

Hard
908

Match each type of malware to its primary behavior.

Medium
909

A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?

Medium
910

A financial institution is implementing data classification to protect customer information. They have identified data that includes medical records and financial account numbers. Which three labels are most appropriate for this data? (Choose three.)

Hard
911

A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)

Medium
912

A security manager is designing a policy to prevent one person from both approving and disbursing payments. Which principle is being applied?

Medium
913

A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:

Medium
914

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Easy
915

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Hard
916

Which THREE are essential elements of a disaster recovery plan? (Select THREE.)

Easy
917

A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:

Medium
918

Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?

Easy
919

Which of the following is an example of Type 2 (possession) authentication?

Easy
920

A company deploys a web application that stores user passwords using a salted hash. During a security review, an auditor recommends switching from SHA-1 to SHA-256. What is the primary security benefit of this change?

Medium
921

Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?

Easy
922

An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?

Hard
923

What is the primary goal of data classification?

Easy
924

Refer to the exhibit. A user from IP 10.0.1.5 attempts to download an object from example-bucket. What will happen?

Hard
925

Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?

Hard
926

Which TWO of the following are core components of the CIA triad?

Easy
927

Which of the following are examples of sensitive PII? (Select all that apply.)

Medium
928

A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?

Medium
929

Drag and drop the steps to implement a firewall rule allowing inbound HTTPS traffic into the correct order.

Medium
930

Refer to the exhibit. An analyst sees these logs. What type of attack is occurring?

Medium
931

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

Medium
932

Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?

Hard
933

A primary data center is destroyed. The disaster recovery plan calls for activation of a hot standby site. If the RTO is 2 hours, what is the expected recovery time?

Medium
934

Which of the following is an example of a Type 2 authentication factor?

Medium
935

Which TWO actions are appropriate during the identification phase of incident response?

Hard
936

Which of the following best describes the principle of confidentiality in the CIA triad?

Easy
937

An organization is implementing a new identity management system. They want to ensure that users can only access resources necessary for their job roles. Which principle should guide the access control design?

Hard
938

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Medium
939

An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)

Easy
940

An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?

Hard
941

Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?

Hard
942

During a vulnerability scan, the security team discovers a critical vulnerability on a public-facing server. According to best practices, what should the team do next?

Medium
943

A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)

Medium
944

Which TWO are true about a differential backup? (Select two.)

Medium
945

A helpdesk technician receives a report that a user in the finance department cannot access a shared folder on the server. The same server is accessible from other departments. What is the most likely cause?

Easy
946

An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?

Easy
947

A network administrator is configuring a DMZ for a company's web and email servers. Which firewall rule is most appropriate for traffic from the internet to the DMZ?

Medium
948

After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?

Hard
949

A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?

Hard
950

During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?

Hard
951

Which THREE are differences between a hot site and a cold site? (Select three.)

Hard
952

You are the IT security officer for a hospital that handles protected health information (PHI). The hospital uses an electronic health record (EHR) system. You receive a report that a nurse accessed the medical records of a celebrity patient without a legitimate medical reason. The access was logged. The hospital policy requires all employees to access only the minimum necessary information for their job duties. The nurse claims they were just curious. This is a violation of which security principle, and what is the best course of action?

Medium
953

A company wants to segment its network into separate broadcast domains to improve performance and security. Which device should be used to achieve this?

Easy
954

A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)

Hard
955

Which TWO of the following are examples of administrative security controls?

Easy
956

A small company has a single flat network with no segmentation. They recently experienced a malware outbreak that spread quickly across all devices. The IT manager wants to implement network segmentation to contain future outbreaks with minimal cost and complexity. The company currently has a single switch and a router/firewall appliance. The network consists of three departments: Sales, HR, and Engineering. After analyzing the requirements, what is the best course of action?

Easy
957

An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?

Hard
958

Which TWO of the following are recognized as benefits of network segmentation?

Hard
959

Based on the exhibit, what is the most likely result of the client's HTTP request?

Medium
960

An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?

Medium
961

Which THREE of the following are recognized security principles according to NIST and ISC2?

Medium
962

A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?

Hard
963

An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?

Medium
964

Which of the following protocols provides secure remote administration of a network device over an untrusted network?

Easy
965

A hospital uses role-based access control (RBAC) for its electronic health records. Nurses can view patient records; doctors can view and edit; administrators can only view administrative data. Recently, a nurse was able to edit a patient's record, which should only be allowed for doctors. The investigation finds that the nurse's role was incorrectly assigned a 'doctor' role due to a misconfiguration. To prevent recurrence, the access control system should be reviewed. Which is the best long-term solution?

Medium
966

Which of the following is a best practice for securing physical access to a data center?

Easy
967

Which layer of the OSI model is responsible for routing packets across networks?

Easy
968

Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?

Medium
969

During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?

Hard
970

Which of the following is an example of a physical access control at the building entrance?

Easy
971

Which security control would best mitigate the risk of network sniffing on a wired LAN segment?

Medium
972

A small business with limited budget wants to ensure critical business functions can resume within 24 hours of a disaster. Their data changes infrequently. Which recovery solution is MOST cost-effective?

Medium
973

Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?

Easy
974

An organization requires that two different administrators approve changes to firewall rules. This is an example of which security principle?

Easy
975

Which TWO of the following are common indicators of a phishing email? (Select TWO.)

Medium
976

A security team implements a policy that requires all access to sensitive data to be logged and audited. Which principle is being enforced?

Easy

Frequently asked questions

What does the scenario questions domain cover on the CC exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 976 scenario questions questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.