CC · domain
scenario questions
Practise ISC2 Certified in Cybersecurity CC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (976)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are principles of the CIA triad? (Select TWO.)
Easy2A company's security policy states that employees should only have access to the data necessary to perform their job functions. This is an example of which principle?
Easy3A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?
Hard4An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)
Medium5An organization is implementing backup strategies. Which THREE are characteristics of differential backups? (Select THREE)
Medium6Which of the following is the primary purpose of a visitor log and escort policy?
Medium7An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?
Hard8A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?
Easy9Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?
Easy10The exhibit shows recent authentication logs. What type of attack is most likely indicated?
Easy11A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?
Hard12Refer to the exhibit. What does this indicate?
Medium13A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)
Medium14An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?
Medium15A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?
Medium16A security analyst is reviewing an alert from the IDS that shows a large number of TCP SYN packets sent to a single port on multiple internal hosts from a single external IP address. The analyst suspects a reconnaissance attack. Which type of attack is this most likely?
Easy17Refer to the exhibit. Which statement best describes compliance with the recovery objectives?
Hard18A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured web server that exposed a database directly. Which principle was most lacking in this scenario?
Hard19What is the primary purpose of a digital signature?
Medium20An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?
Easy21An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?
Medium22A company's security policy requires that all sensitive data be encrypted both at rest and in transit. This is an example of applying which security principle?
Medium23A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?
Easy24During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?
Medium25A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
Hard26Which THREE are examples of administrative access controls?
Hard27According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)
Hard28A security team discovers that an internal database server is sending large amounts of data to an unknown external IP address. The server is not supposed to communicate externally. Which security control should be implemented to prevent such data exfiltration?
Hard29An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?
Medium30During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?
Medium31Which of the following is the best practice for managing cryptographic keys in a large organization?
Hard32A security auditor discovers that a user has been granted read and write access to a sensitive file, but the user's job only requires read access. Which access control principle has been violated?
Hard33A security administrator needs to ensure that a user cannot view the contents of a file but can execute it. Which access control principle should be applied?
Easy34During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)
Medium35A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?
Medium36According to NIST SP 800-63, which password policy is most recommended?
Medium37In a typical Windows environment, which access control model is used for managing file permissions?
Hard38Which two of the following are examples of physical access controls? (Select TWO)
Easy39A small business wants to minimize backup storage space and backup time, knowing that restoration may be slower. Which backup strategy should they choose?
Medium40A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)
Medium41An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?
Easy42In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?
Medium43A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?
Medium44A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?
Hard45During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?
Hard46A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?
Medium47Which TWO of the following are fundamental security principles? (Select TWO.)
Medium48An organization wants to implement defense in depth for its server room. Which THREE controls should be included?
Hard49Which access control principle restricts access to data based on the user's job role and tasks?
Easy50A security analyst notices that a user's account has been used to access sensitive files outside of normal working hours from an unknown IP address. Which security principle is most directly violated?
Easy51A security policy requires that all changes to production systems be approved by a change management board. Which THREE of the following principles best support this requirement?
Medium52A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:
Medium53A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?
Hard54A mid-sized e-commerce company has a primary data center in New York and a disaster recovery site in Dallas. The application stack includes a web server, application server, and a PostgreSQL database. The database uses synchronous replication to the DR site. During a routine failover test, the IT team discovers that after failing over to Dallas, the web servers in New York continue to attempt connections to the original database IP, causing application errors. The DNS records have been updated to point to the DR database IP, but the web servers are not refreshing their DNS cache. The company uses a standard TTL of 300 seconds. The IT manager needs a solution that ensures minimal disruption during future failovers. Which action should be taken?
Easy55A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?
Easy56Based on the exhibit, which statement about the access control list is true?
Medium57An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:
Medium58Which of the following best describes a vulnerability in the context of risk management?
Medium59A company's network uses 802.1X authentication for wired and wireless access. Which component authenticates the user credentials against an identity store?
Medium60Which security principle ensures that data cannot be accessed by unauthorized individuals?
Easy61During a routine security audit, an analyst finds that several critical servers have misconfigured firewall rules allowing inbound SSH access from the entire internet. Which immediate action should the analyst take?
Medium62Which TWO of the following are common indicators of a potential data breach? (Choose two.)
Easy63Which authentication type is a smart card an example of?
Easy64Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?
Easy65Which TWO of the following are examples of integrity controls? (Select TWO)
Easy66An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?
Medium67A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?
Medium68A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:
Medium69An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:
Hard70After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?
Easy71A security analyst notices repeated failed login attempts from a single external IP address targeting the company's VPN concentrator. Which type of attack is most likely occurring?
Easy72A security administrator notices that a user with standard privileges was able to modify a system file. Which security principle has been violated?
Easy73A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?
Medium74To protect the integrity of log files, which of the following is a best practice?
Easy75An organization decides to implement multiple security controls, including firewalls, intrusion detection systems, and antivirus software. Which security principle does this represent?
Easy76Which THREE of the following are valid security control categories based on function? (Select three).
Hard77Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy78An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?
Hard79An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)
Hard80A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)
Medium81A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)
Hard82A security operations center (SOC) analyst is investigating an alert about a user downloading a suspicious file. The analyst opens the file on a sandboxed virtual machine and observes that it attempts to modify registry keys and establish persistence. This type of analysis is known as:
Hard83An analyst is reviewing a series of failed login attempts from multiple IP addresses targeting a single user account. This pattern is indicative of what type of attack?
Hard84An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?
Hard85A security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?
Hard86Which of the following is an indicator of a phishing email?
Easy87After a security breach, it was discovered that an attacker used a stolen certificate to sign malicious code. Which security principle was compromised?
Medium88An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?
Medium89An employee is assigned a user account with read-only access to the sales database. However, the employee's job requires viewing only customer contact information, not sales figures. Which access control principle is being violated?
Hard90During a security assessment, a penetration tester captures unencrypted credentials over the network. Which protocol is most likely being used?
Medium91You are a SOC analyst for a financial institution. At 2:00 AM, your SIEM generates a critical alert from the email security gateway indicating that an internal user received a phishing email with a malicious attachment. The email was delivered to the user's inbox, and the user's account activity logs show that the attachment was opened 10 minutes ago. The user is a junior accountant who works in the accounts payable department. You have access to endpoint detection tools, email logs, and network traffic data. The organization's incident response policy requires containment within 30 minutes of detection. Which action should you take FIRST?
Medium92Drag and drop the steps for the incident response process according to NIST into the correct order.
Medium93Drag and drop the steps to create a new VLAN on a managed switch into the correct order.
Medium94An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?
Medium95A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?
Medium96Your organization runs a critical e-commerce platform on a private cloud. The database server is located in a data center in a seismic zone. The current DR plan uses a warm site with daily differential backups and a 12-hour RTO. A recent earthquake caused a power outage but no physical damage. The database corruption was discovered after 6 hours. The backups from last night are intact but restoring involves applying transaction logs. The RTO is now at risk. What should be done FIRST?
Hard97Which of the following is an example of a logical access control?
Easy98Refer to the exhibit. Given the ACL shown, which traffic is allowed to reach 10.0.0.1?
Medium99A company uses a proxy server for internet access. Employees can browse websites (HTTP/HTTPS), but they cannot connect to external FTP servers using FTP client software (e.g., FileZilla). The proxy is configured to allow HTTP and HTTPS only. The security team wants to allow FTP while maintaining security (e.g., logging and filtering). The FTP traffic is used for occasional file transfers with partners. Which of the following is the BEST solution to meet both requirements?
Medium100A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?
Hard101Which of the following is a primary goal of security operations?
Easy102A system administrator needs to grant a user the ability to read files in a specific folder but not modify them. Which access control principle should be applied?
Easy103An organization is implementing a patch management policy. Which THREE steps are part of the standard patch lifecycle?
Medium104Refer to the exhibit. An analyst sees many alerts from this IDS rule. What is a likely cause?
Medium105A company requires employees to use biometric authentication to access the data center. This is an example of which security principle?
Easy106An organization is re-evaluating its disaster recovery site options. Which TWO of the following describe characteristics of a warm site?
Medium107In the identification and authentication process, which step occurs first?
Easy108An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?
Easy109Which security control is most effective in preventing unauthorized physical access to a data center?
Easy110Refer to the exhibit. What is the effect of this ACL?
Medium111Which TWO technologies provide network segmentation? (Choose two.)
Medium112Refer to the exhibit. A security analyst sees this log entry from a firewall. What is the most likely reason for this denial?
Easy113An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:
Hard114A security administrator needs to ensure that only authorized personnel can access the server room. Which physical control is most appropriate?
Easy115A system administrator configured the sudoers file as shown. What is the primary security risk of this configuration?
Hard116During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?
Medium117A company is implementing an access control system to protect sensitive data. Employees in the finance department must access financial records, but only during business hours and from company-issued devices. Which access control model best supports these requirements?
Medium118A company experiences a ransomware attack that encrypts all files on a file server. The IT team decides to restore the server from the most recent full backup taken 24 hours ago, followed by all differential backups taken since then. If the last full backup was on Sunday at midnight, and the attack occurs on Wednesday at 6:00 AM, with differential backups taken daily at noon, how many differential backups must be restored?
Hard119Refer to the exhibit. The network administrator configured NAT as shown. Internal hosts can access the internet, but no external hosts can access the company's web server (192.168.1.10). What is the issue?
Hard120Which access control model allows the owner of a resource to decide who can access it?
Easy121A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?
Medium122Which THREE of the following are core principles of the CIA triad?
Medium123Match each security control type to its description.
Medium124Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)
Hard125A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?
Easy126What is the process of claiming an identity called?
Easy127Which of the following ports is used by HTTPS for secure web traffic?
Medium128Which TWO of the following are primary objectives of an incident response plan? (Choose two.)
Hard129A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)
Medium130Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?
Medium131According to the (ISC)² Code of Ethics, which canon has the highest priority?
Medium132Which TWO are examples of technical access controls?
Easy133An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?
Easy134Which TWO of the following are primary goals of the security principle of confidentiality?
Medium135Match each cryptographic concept to its definition.
Medium136Which OSI layer is responsible for logical addressing and routing?
Easy137A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?
Hard138Which of the following is an example of a detective control in a security operations context?
Easy139A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)
Medium140A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?
Medium141A company needs to enforce access based on attributes such as time of day and location. Which access control model is most appropriate?
Medium142A company uses a stateful firewall. A user reports that an application requiring multiple dynamic ports is not working. The firewall logs show that packets from the server are being dropped. What is the most likely cause?
Hard143Which three of the following are benefits of using VLANs in a network? (Choose three.)
Medium144An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?
Medium145An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?
Medium146What is the primary difference between an IDS and an IPS?
Easy147An employee uses a password and a one-time code from a mobile authenticator app to log in. Which authentication type is being used?
Medium148A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)
Medium149According to the (ISC)² Code of Ethics, which canon has the highest priority?
Hard150Which of the following is an example of a Type 2 authentication factor?
Medium151A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?
Medium152A financial company requires that any transaction over $10,000 must be approved by two different managers before being processed. This is an example of which access control principle?
Medium153A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:
Hard154After a security incident, the incident response team closes the case. What is the MOST important final step to improve future security posture?
Hard155An organization wants to protect its internal network from unsolicited inbound traffic while allowing responses to outbound connections. Which TWO firewall features or types are best suited for this? (Select TWO)
Medium156A help desk technician receives a report that a user cannot access a shared network drive. The technician checks the file server and sees that the disk is full. What is the most immediate action the technician should take?
Easy157During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?
Hard158Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?
Easy159Refer to the exhibit. ``` { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*" } ] } ``` A security analyst reviews this AWS S3 bucket policy. The policy currently allows anyone to read objects. Which change would implement the principle of least privilege?
Hard160A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?
Medium161A SOC analyst is reviewing logs from a web server and sees the following entry: GET /../../../../etc/passwd HTTP/1.1 Which type of attack is being attempted?
Medium162An organization wants to implement the principle of least privilege for its database administrators. Which approach best achieves this goal?
Medium163A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?
Medium164Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?
Easy165Refer to the exhibit. Which security principle is this policy primarily enforcing?
Medium166A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?
Medium167Which of the following is a benefit of using VLANs in a network?
Easy168An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?
Hard169An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?
Medium170A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:
Easy171An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?
Easy172A security administrator is concerned about MAC address spoofing on the network. Which technology can help mitigate this risk by associating a specific MAC address with a port?
Medium173A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?
Medium174An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)
Hard175An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?
Hard176A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?
Medium177An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?
Hard178A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?
Medium179An organization implements an access control system where users are assigned to groups, and permissions are granted to groups rather than individuals. This is known as:
Easy180What is the primary purpose of a digital signature?
Hard181Which of the following is an example of a vulnerability?
Medium182During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?
Hard183An employee reports receiving a suspicious email with an attachment from an unknown sender. What is the first action the employee should take?
Easy184A system administrator runs `iptables -L INPUT` and sees this rule. What is the immediate effect on the system?
Hard185A help desk technician needs to reset a user's password, but the security policy requires that the technician does not know the new password. Which access control concept prevents the technician from knowing the password?
Easy186An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?
Hard187Refer to the exhibit. Based on the exhibit, why was the packet denied?
Easy188A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?
Medium189A financial firm has a data center with strict access controls. Employees must use smart cards and PINs to enter a mantrapped entrance. Recently, an unauthorized person gained access by following an employee through the mantrapped door (tailgating). The security team reviews logs and finds that the door was opened twice in quick succession, indicating tailgating occurred. The firm wants to implement a solution that prevents tailgating without slowing down authorized access. Which action should they take?
Hard190A SOC analyst reviews an alert indicating a high number of failed login attempts from a single external IP address targeting multiple user accounts. Which security control is most effective at preventing this type of attack?
Easy191A company's security policy requires that all incident response activities be logged and that evidence be preserved for potential legal action. During an incident, a responder mistakenly uses a personal USB drive to copy log files. Which principle of forensic evidence handling has been violated?
Hard192A company recently experienced a DoS attack targeting their web server. They want to implement a solution that can differentiate between legitimate traffic and attack traffic based on behavior patterns. Which technology should they deploy?
Medium193An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?
Hard194Which of the following is an example of a logical access control?
Easy195A security architect is designing access controls for a new application. The requirement is that only managers can approve expense reports above $10,000. Which control model best fits this requirement?
Medium196Which of the following is a recommended practice for administrative accounts?
Easy197An organization's backup schedule: Full backup every Sunday, incremental backups Monday-Saturday. If a failure occurs on Thursday, how many backup sets are needed to restore the data?
Medium198A security operations center (SOC) analyst receives an alert for a potential malware infection on a workstation. Which of the following is the first action the analyst should take?
Easy199Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?
Hard200According to NIST SP 800-63, which password policy is recommended to enhance security?
Medium201A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?
Hard202A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?
Medium203An organization has detected a ransomware infection. What is the FIRST step in the incident response process?
Medium204An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?
Medium205Which THREE of the following are examples of implementing defense in depth? (Select THREE.)
Hard206A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?
Easy207A security engineer is reviewing logs and notices that an internal server is receiving excessive SYN packets from an external IP, but never completing the three-way handshake. What type of attack is likely occurring?
Hard208Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?
Medium209During a disaster recovery test, the IT team discovers that restoring all data from full backups takes 48 hours, exceeding the RTO. Which backup strategy would reduce restore time while maintaining a similar backup window?
Medium210Refer to the exhibit. A network administrator configured the above on a switch port. After connecting a single workstation, the port goes into err-disabled state within minutes. What is the most likely cause?
Easy211Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?
Easy212Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?
Easy213Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)
Easy214A security operations center (SOC) analyst receives an alert for a high volume of outbound traffic from an internal server to a known malicious IP address. Which step should the analyst take next?
Medium215Which TWO of the following are core components of the ISC2 Code of Ethics? (Choose two.)
Medium216An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?
Medium217A software developer is designing a web application that will store user credentials. What is the most secure method for storing passwords?
Hard218An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
Medium219A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?
Hard220A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?
Medium221An organization implements a policy requiring employees to use a separate administrator account for privileged tasks and a different account for daily activities. Which principle does this support?
Hard222An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)
Hard223Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?
Medium224Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?
Easy225A user reports that they received a suspicious email with an attachment claiming to be an invoice. What should the user do?
Easy226A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?
Hard227A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?
Medium228A network security team is implementing a defense-in-depth strategy. Which TWO of the following controls are examples of network segmentation? (Choose two.)
Easy229A security analyst reviews firewall logs and sees a series of outbound connections from an internal server to a known command-and-control (C2) IP address at regular intervals. Which step should the analyst take first according to incident response best practices?
Hard230A company is developing a disaster recovery plan for its database server. The database is updated transactionally and cannot tolerate any data loss. Which backup strategy meets this requirement?
Medium231A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)
Hard232Which of the following is a common mitigation technique for a SYN flood attack?
Hard233Which TWO of the following are examples of implementing the principle of least privilege?
Hard234Which TWO of the following correctly describe components of a directory service distinguished name (DN) in LDAP? (Select two.)
Medium235An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?
Hard236Which TWO of the following controls are examples of defense in depth?
Medium237Which protocol is considered insecure because it transmits data in cleartext, including passwords?
Easy238Which TWO of the following are examples of Type 3 (inherence) authentication factors?
Easy239A legacy system cannot be patched due to vendor unavailability. Which compensating control would be most effective in reducing the risk of exploitation?
Hard240Which of the following is an example of a logical access control?
Medium241Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy242Refer to the exhibit. Based on the log entries, what type of attack is most likely occurring?
Easy243An online retailer has a DR plan that includes active-active data centers. During a major DDoS attack, one data center's external connectivity is saturated. The internal network is operational. The security team has identified the attack traffic pattern and is working with the ISP to filter. To maintain service availability, what action should be taken?
Medium244After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?
Hard245A company discovers a critical vulnerability in a widely used software application. The vendor has released a patch, but the company's patch management policy requires testing before deployment. What is the best course of action?
Medium246An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)
Hard247A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?
Medium248An organization requires employees to enter a password and then approve a push notification on their mobile device to access the corporate network. What type of authentication is this?
Medium249Which TWO of the following are commonly used techniques to detect phishing emails? (Choose two.)
Medium250A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?
Medium251During a phishing investigation, a security analyst identifies that an employee clicked a malicious link. The analyst isolates the workstation. What is the NEXT best step?
Medium252An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?
Medium253A company's network uses a perimeter firewall and an internal firewall. The DMZ sits between them. A new application server needs to be accessible from the internet on TCP port 8443 and must be able to make outbound HTTPS connections to an external license server. Which firewall rules should be implemented? (Assume default deny)
Hard254An organization implements a role-based access control (RBAC) system. To maintain the principle of least privilege, what should the administrator do when a user changes roles?
Hard255Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?
Easy256An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?
Easy257Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?
Medium258A security team is designing a network for a hospital. They need to ensure that patient data is accessible to doctors only when needed, but also protected from unauthorized access. Which principle BEST balances these requirements?
Medium259Which authentication factor does a smart card represent?
Easy260A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?
Easy261A security operations team is implementing a new SIEM solution. They want to ensure that logs from all critical systems are collected and analyzed in real time. Which of the following is the MOST important consideration when designing the log collection architecture?
Easy262A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?
Hard263A Privileged Access Management (PAM) solution is used to:
Hard264A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?
Easy265A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?
Medium266A company's security policy mandates that all changes to the firewall configuration must be approved by two different administrators before implementation. This is an example of which security principle?
Medium267An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?
Hard268An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?
Medium269A network administrator configures the ACL on a router as shown. What is the effect of this access list?
Easy270A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?
Medium271An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)
Hard272A security analyst investigates a possible data exfiltration. The analyst sees a large amount of data being sent to an external IP address at regular intervals. Which of the following is the most likely technique being used?
Hard273An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?
Hard274A small company with 50 employees uses a flat network with no VLANs. They recently experienced a ransomware attack that spread from an infected workstation to a file server. The IT manager wants to implement network segmentation to prevent future lateral movement. The company uses a single /24 subnet (192.168.1.0/24) with a single switch and a router/firewall. They have three departments: Sales, HR, and IT. Each department has about 15-20 computers. The file server is in the IT department. The company has a limited budget and cannot purchase new hardware. Which of the following is the MOST effective and practical approach to segment the network given these constraints?
Medium275A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?
Medium276An organization's security policy mandates that data must be encrypted both at rest and in transit. Which combination of controls meets this requirement?
Easy277Refer to the exhibit. Which security control is MOST likely triggered?
Easy278A company's security policy states that sensitive data must be encrypted using AES-256. During an audit, it is found that some data is encrypted with AES-128. Which security objective is most directly compromised?
Hard279Which of the following is an example of a logical access control?
Easy280What is the primary purpose of a Security Information and Event Management (SIEM) system?
Easy281Which TWO are examples of logical access controls? (Select TWO.)
Easy282A security analyst is investigating a potential man-in-the-middle attack. Which two techniques are commonly used by attackers to perform MITM attacks? (Choose two.)
Medium283A security administrator notices that an employee is able to access files in a project folder they should not have access to. Which security principle is being violated?
Easy284A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?
Medium285Which data classification level typically requires the highest level of protection?
Easy286A network administrator notices unusual traffic from an internal workstation to an external IP address on port 443. The workstation has no business reason for such communication. Which action should the administrator take first?
Easy287A critical vulnerability is discovered in a widely used VPN appliance that is actively being exploited in the wild. The vendor has released an emergency patch. However, the organization's patch management policy requires testing in a staging environment before production deployment. What should the security team do?
Hard288An AWS administrator attached this IAM policy to a user. What is the effect of this policy?
Medium289A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)
Medium290Which concept ensures that a user cannot deny having performed a specific action?
Easy291An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)
Hard292A security operations center receives an alert that a workstation has been infected with ransomware. The infection is isolated to one machine. What is the first step in the containment phase of incident response?
Easy293A company has a Recovery Point Objective (RPO) of 1 hour for its financial database. It performs full backups every night at 11 PM and incremental backups every 4 hours. If the system fails at 2:30 PM, what is the maximum data loss in terms of time?
Hard294A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?
Medium295Which three of the following are best practices for securing a network switch? (Choose three.)
Medium296After a reorganization, a company using RBAC finds that many users have accumulated permissions that no longer align with their job functions. What is the best practice to address this?
Medium297Which TWO of the following are best practices for securing a wireless network? (Select exactly two.)
Medium298An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?
Medium299After a ransomware attack, the company wants to ensure that critical data can be restored. Which principle is being addressed?
Medium300Match each security policy type to its focus.
Medium301An organization's business continuity plan designates a maximum tolerable downtime (MTD) of 8 hours for its order processing system. The system's recovery time objective (RTO) is set at 4 hours, and work recovery time (WRT) is estimated at 2 hours. If a disaster occurs at 10:00 AM and the system is restored at 2:00 PM, but additional configuration and data validation take until 3:30 PM to complete, what is the total downtime and is the MTD met?
Hard302During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?
Hard303Which TWO are essential elements of a business impact analysis (BIA)?
Medium304After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:
Hard305An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
Medium306During a disaster recovery test, the team discovers that the backup generator fails to start. What is the BEST immediate action?
Easy307A Security Operations Center (SOC) Tier 1 analyst notices an alert for a failed login attempt from an unusual geographic location. What is the primary responsibility of a Tier 1 analyst in this scenario?
Easy308A company conducts a background check on a new vendor before signing a contract. This activity is an example of:
Hard309In the context of identification and authentication, which of the following is an example of authentication?
Medium310During a ransomware incident, the incident response team has completed the containment and eradication phases. According to the NIST incident response framework, which THREE of the following activities are part of the post-incident activity phase?
Hard311After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?
Medium312A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?
Easy313An organization is implementing a patch management program. Which of the following is the BEST approach to minimize risk while maintaining operational stability?
Medium314A network administrator needs to provide secure remote access to internal resources for employees working from home. The solution must encrypt all traffic and authenticate users before granting access. Which protocol should be used?
Easy315During a penetration test, an analyst discovers that a company's internal network has a switch configured with port security that allows only one MAC address per port. However, the analyst is able to plug a rogue device into a wall jack and successfully gain network access. What is the most likely weakness in this configuration?
Hard316A company wants to ensure that a message received was not altered in transit. Which principle is of primary concern?
Medium317A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:
Medium318During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?
Medium319Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?
Easy320Which type of access control is implemented by a cable lock attached to a laptop?
Easy321Which TWO are primary objectives of a Business Continuity Plan (BCP)? (Select two.)
Medium322A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?
Medium323A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?
Medium324Which type of authentication factor involves something the user knows?
Easy325A company has implemented a role-based access control (RBAC) system. A new employee in the finance department is granted the 'Finance User' role, which allows them to view invoices but not create payments. However, after a system upgrade, it is discovered that the 'Finance User' role now includes the ability to create payments due to a misconfiguration. The employee did not request this additional privilege and has not exploited it. The security team is notified. Which principle has been violated, and what is the most appropriate immediate action?
Hard326An organization's security policy requires that all access to sensitive data must be approved by a data owner. An administrator configures a system to enforce this. Which principle is being implemented?
Hard327During an incident, the security team detects unusual outbound traffic from a server that normally does not communicate externally. The traffic appears to be encrypted and is sent to an unknown IP address. Which incident category best describes this scenario?
Hard328A company performs background checks on potential employees before hiring. This action demonstrates which concept?
Medium329Which TWO principles are essential for ensuring accountability in an information system? (Choose two.)
Hard330Which THREE of the following are considered risk management strategies? (Select THREE)
Hard331Which TWO of the following are examples of sensitive PII? (Select TWO.)
Medium332Drag and drop the steps to recover a system from a verified backup after a ransomware attack into the correct order.
Medium333A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:
Hard334A system administrator accidentally grants a user full administrative rights instead of read-only. Which control would best detect this error?
Hard335A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?
Easy336An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?
Medium337You are a security analyst at a medium-sized company with 500 employees. The company uses a centralized log management system that collects logs from all servers and network devices. For the past week, you have noticed a pattern: every night at 2:00 AM, a series of failed login attempts occurs on the domain controller from an internal IP address (10.10.50.100). The attempts use the username "Administrator" and are always from the same workstation in the accounting department. The accounting department operates 9 AM to 6 PM, so no one is in the office at 2 AM. You have checked the workstation's physical security; it is in a locked office with access only by authorized accounting staff. The workstation is running Windows 10 with up-to-date antivirus and has no signs of compromise. You also checked the network switch logs and see that the workstation is connected to a specific port. You suspect the workstation might be compromised or being used remotely. What is the most appropriate next step?
Hard338When implementing multi-factor authentication, which combination of factors is considered strongest?
Medium339During a forensic investigation, it is crucial to preserve the original evidence. What is the first step the investigator should take when acquiring a hard drive?
Medium340An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?
Medium341A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)
Hard342Which TWO of the following are methods to ensure non-repudiation? (Select two).
Medium343According to the NIST incident response lifecycle, which three phases are considered the core phases?
Medium344A multinational corporation has a policy that all sensitive emails must be digitally signed and encrypted. However, during a recent internal audit, it was discovered that many employees were not using digital signatures because the process was cumbersome. As a result, the company could not prove that certain emails were actually sent by the claimed sender. The security team needs to improve compliance without sacrificing security. Which of the following is the best approach?
Hard345A small business has a single server that hosts critical applications. The server's hard drive fails, and the most recent backup is 3 days old. The backup is stored on an external drive that is kept in the same room as the server. The server is also the domain controller and file server. After replacing the drive and restoring from backup, the IT administrator discovers that some user files are missing because they were created after the backup. The administrator needs to minimize data loss in the future. Which of the following should be implemented?
Easy346A company experiences a data breach where customer PII was exfiltrated. The incident response team contains the breach and restores systems. Which step in the risk management process should the company prioritize next to prevent recurrence?
Medium347A company's critical database must be recovered within 4 hours after a disaster, and they can tolerate losing up to 1 hour of data. During a disaster, after the systems are restored, it takes an additional 30 minutes to verify data integrity and resume normal operations. Which metric is represented by the 4-hour requirement?
Medium348A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)
Medium349In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
Medium350An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)
Medium351Which TWO are appropriate methods to test a disaster recovery plan?
Hard352A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)
Medium353A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?
Medium354A security analyst reviews firewall logs and notices a large number of outbound connections from a single internal IP to a known malicious IP on port 445. The analyst quarantines the workstation and runs an antivirus scan, which finds no malware. What should the analyst do next?
Hard355A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?
Medium356Which backup strategy offers the fastest restore time but requires the most storage space?
Medium357An organization's backup strategy includes daily full backups. However, recovery tests show that restoring from tape takes 6 hours longer than expected. What is the most likely cause?
Medium358During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?
Hard359Which THREE are key components of Active Directory? (Select THREE.)
Medium360Which THREE are core components of the CIA triad? (Choose three.)
Easy361What is the difference between due care and due diligence in security governance?
Medium362Refer to the exhibit. What is the effect of this ACL?
Hard363An analyst reviews the exhibit. Which security principle is being violated by allowing root login via SSH?
Medium364Drag and drop the steps to configure a wireless access point with WPA2-PSK security into the correct order.
Medium365A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?
Easy366A security administrator notices that a user's account has been used to access sensitive files at unusual hours. Which security principle would most effectively help detect this type of activity?
Easy367A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?
Hard368During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?
Medium369A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?
Hard370Which THREE elements are essential components of a business continuity plan (BCP)?
Medium371An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?
Medium372A SOC analyst is reviewing a security alert about a potential brute-force attack on the company's VPN server. The analyst sees multiple failed login attempts from different IP addresses within a short time frame. Which TWO actions should the analyst take to verify and respond to this incident? (Choose two.)
Medium373During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?
Medium374When designing a secure network, which TWO of the following are fundamental security principles that should be applied?
Hard375Which THREE of the following are examples of risk mitigation? (Select THREE)
Hard376An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:
Easy377Drag and drop the steps for the TCP three-way handshake into the correct order.
Medium378A company's security operations center (SOC) receives an alert about suspicious outbound traffic from a server in the DMZ to an external IP address known for command-and-control activity. The SOC analyst reviews the logs and sees that the source port is 443 and the destination port is 8080. Which of the following actions should the analyst take FIRST?
Medium379Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)
Hard380The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?
Hard381Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)
Medium382Which TWO of the following are examples of security principles?
Easy383Which of the following is the primary purpose of a security information and event management (SIEM) system?
Easy384A medium-sized enterprise uses a Cisco ASA firewall configured with multiple security zones (Inside, Outside, DMZ). The DMZ hosts a web server that must be accessible from the Internet on TCP 443. The Inside network (10.0.0.0/24) hosts internal clients. The web server has IP 172.16.0.10. The firewall's current rules: allow any from Outside to DMZ on TCP 443; allow any from Inside to Outside; deny all else. Recently, the security team noticed that an attacker compromised the web server and used it to launch an attack against an internal database server at 10.0.0.50. The attack was successful because the firewall allowed traffic from the DMZ to the Inside. The firewall's default behavior is to deny traffic from lower security zones to higher security zones (DMZ is lower than Inside). What is the MOST likely reason this traffic was allowed?
Hard385An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?
Medium386Match each risk management term to its meaning.
Medium387A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?
Hard388A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?
Medium389A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?
Medium390Which of the following is an example of Type 2 authentication?
Easy391A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).
Hard392A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?
Medium393A company deploys a web application firewall (WAF), performs regular vulnerability scans, and implements strict access controls. Which security principle is being applied?
Medium394A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?
Medium395A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:
Hard396During a security audit, it is discovered that a single administrator can create user accounts, assign privileges, and review audit logs. Which principle is most likely being violated?
Medium397An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:
Hard398A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?
Medium399A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?
Hard400Which control type is considered a physical security control?
Easy401Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)
Easy402Drag and drop the steps to perform a password reset on a Windows user account into the correct order.
Medium403Which is a key benefit of a cold site as a recovery location?
Medium404Which TWO of the following are examples of Type 3 authentication? (Select TWO).
Medium405A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:
Medium406A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?
Easy407Which THREE of the following are common components of a disaster recovery plan?
Easy408An organization wants to implement a policy where employees must use a smart card and a PIN to access sensitive data. This is an example of:
Hard409Which incident category involves an attempt to make a system or network resource unavailable to its intended users?
Medium410A SOC analyst notices a large spike in outbound traffic from a workstation that is not scheduled for any data transfers. Upon checking the SIEM, the analyst sees that the workstation's antivirus was disabled 30 minutes ago. What type of logs should the analyst examine first to understand the sequence of events?
Medium411A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?
Easy412Which three ports are commonly used by secure protocols? (Choose THREE.)
Medium413A company uses a mandatory access control (MAC) system where all files are labeled 'Confidential', 'Secret', or 'Top Secret'. A user with 'Secret' clearance tries to read a 'Top Secret' file. What is the outcome?
Hard414An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?
Medium415An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?
Medium416In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?
Hard417A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?
Medium418An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?
Easy419Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?
Medium420Match each access control model to its key characteristic.
Medium421A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?
Medium422A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)
Hard423During a forensic investigation, the analyst needs to acquire a memory image from a live Windows system without altering evidence. Which tool is MOST appropriate?
Hard424Which THREE of the following are considered essential security principles according to ISC2?
Hard425An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)
Hard426A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)
Hard427An account lockout policy is implemented to protect against which type of attack?
Medium428A SOC analyst is investigating a potential data exfiltration incident. The logs show that an internal user transferred a large volume of data to a cloud storage service using HTTPS. The analyst finds that the user's workstation has BitLocker Drive Encryption enabled, and the user has administrative privileges. Which of the following best describes the PRIMARY challenge in investigating this incident?
Hard429Which THREE of the following are essential components of an incident response plan? (Select THREE.)
Hard430During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?
Hard431During a security incident, the incident response team isolates a compromised workstation from the network. What is the primary purpose of this action?
Medium432You are an IT administrator for a small business. The company has a backup system that performs nightly full backups of critical servers to an external hard drive. One morning, a user reports that they accidentally deleted an important file from a shared drive. You need to restore the file from last night's backup. However, when you connect the external hard drive to the backup server, the drive is not recognized, and you hear clicking sounds. The backup software shows that the most recent backup job completed successfully with no errors. What is the most likely cause of the problem?
Easy433A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?
Easy434A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?
Medium435An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?
Medium436A security analyst is troubleshooting an access control issue where a user cannot access a file even though they seem to have the correct permissions. Which three of the following should the analyst investigate? (Select THREE)
Hard437Which of the following is an indicator of a phishing email?
Easy438A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?
Easy439An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)
Hard440Which of the following is a primary benefit of implementing network segmentation?
Easy441Which THREE components are part of the AAA framework?
Hard442An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?
Easy443Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?
Medium444In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?
Medium445During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)
Medium446Which of the following is a connectionless, unreliable transport protocol?
Easy447A security auditor discovers that during a VLAN hopping attack, a threat actor was able to send frames from a workstation on VLAN 10 to a target on VLAN 20. Which configuration flaw is most likely responsible?
Hard448A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)
Medium449A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:
Hard450A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?
Easy451A security engineer is designing a DMZ for a web server that must be accessible from the internet. The web server needs to query an internal database server. Which network security approach best limits exposure?
Medium452Which TWO of the following are examples of preventive security controls?
Easy453Which of the following best describes the purpose of a session timeout?
Easy454Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?
Easy455A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?
Medium456Which layer of the OSI model is responsible for routing packets based on IP addresses?
Easy457An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?
Medium458An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?
Medium459Refer to the exhibit. A security analyst reviews this log entry. What type of attack is most likely occurring?
Medium460An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)
Easy461An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?
Hard462An organization wants to ensure that critical security events are not missed during off-hours. What is the best practice?
Easy463A financial institution has a security operations center that monitors network traffic using a SIEM. The SIEM receives logs from all network devices, servers, and endpoints. One analyst notices an anomaly: a user account, 'jsmith', which is normally used during business hours (9 AM to 5 PM), has been logging in from a remote IP address at 2 AM every day for the past week. The logins are successful, and the user is accessing internal file shares. The user jsmith works in the accounting department and has access to sensitive financial reports. The analyst checks the user's workstation logs and finds that the workstation is powered off at the time of the remote logins. The company uses two-factor authentication, but the log entries show that only the password was used. Which of the following is the most likely explanation and the best immediate action?
Hard464An organization is developing a data classification policy. Which THREE of the following are common classification levels?
Hard465Which TWO are phases of the NIST incident response life cycle? (Select exactly 2.)
Easy466An organization wants to ensure that system logs are tamper-proof after generation. Which control should be implemented?
Easy467A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?
Hard468A financial services firm has a data center that houses customer financial records. They have implemented a defense-in-depth strategy including firewalls, IDS/IPS, and encryption. Recently, an internal audit revealed that a junior administrator has been logging into the database server with a shared admin account and has made unauthorized changes to customer records. The company wants to prevent such incidents in the future while maintaining operational efficiency. The current environment uses Linux servers with PostgreSQL databases. There is no centralized authentication system. What is the BEST action to take?
Hard469In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?
Hard470An organization determines that its critical financial application has a maximum tolerable downtime (MTD) of 8 hours. The recovery time objective (RTO) is set to 6 hours, and the work recovery time (WRT) is 2 hours. If the application is restored from backup in 5 hours, but additional configuration takes 3 hours, what is the total downtime, and is the MTD met?
Medium471A security engineer is designing a backup strategy for a critical database. The database must be recoverable within four hours in the event of a failure. Which security principle primarily drives this requirement?
Medium472A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?
Medium473In a defense-in-depth strategy, which access control mechanism provides the most granular control over user permissions?
Hard474A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?
Medium475You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?
Hard476A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)
Hard477Which OSI layer is responsible for routing packets across networks using IP addresses?
Easy478A system administrator implements version control for all configuration files. Which principle is being strengthened?
Medium479Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?
Easy480A cloud security engineer reviews a cloud storage bucket policy that grants read access to all users, including anonymous users. What is the primary security risk?
Hard481A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?
Easy482A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?
Medium483A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?
Medium484An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?
Medium485You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?
Hard486A security engineer is configuring a firewall to allow web traffic but block all other inbound connections. The firewall is set to deny all traffic by default and only allow specific ports. Which security principle is being applied?
Medium487An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?
Easy488During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)
Hard489An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?
Medium490A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?
Medium491An organization is developing a security policy that defines the rules for acceptable use of company resources. Which principle should guide the creation of this policy to ensure it is enforceable and effective?
Easy492A security analyst notices that an internal web server is receiving a high volume of TCP SYN packets from a single external IP address, but the server is not sending SYN-ACK replies. The server's CPU and memory usage are normal. What is the most likely cause?
Easy493During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:
Hard494A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?
Medium495A company implements two-factor authentication (2FA) for all remote access. Which primary security goal is this enhancing?
Medium496Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?
Easy497A security analyst receives an alert indicating multiple failed login attempts from a single IP address targeting a user account. Which action should the analyst take FIRST?
Easy498An organization uses a SIEM to correlate logs from multiple sources. A rule triggers when a user logs in from two geographically distant locations within a short time. What type of attack does this rule primarily detect?
Medium499A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?
Medium500During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard501An organization is designing a security architecture for a cloud-based application. They implement firewalls, intrusion detection systems, and encryption, and also conduct regular security awareness training. This approach demonstrates which security principle?
Hard502A security operations center (SOC) analyst notices unusual outbound network traffic from a server that typically only receives connections. The traffic is encrypted and goes to an unknown external IP. Which step should the analyst perform FIRST?
Medium503During a patch management cycle, a new vulnerability is disclosed in a widely used web server software. What is the first step an organization should take in the patch lifecycle?
Easy504An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)
Hard505A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?
Medium506Which THREE are commonly defined in a disaster recovery plan? (Select exactly 3.)
Medium507According to NIST SP 800-63, which password policy is most effective for user authentication?
Medium508An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?
Medium509An organization's backup strategy includes daily full backups and hourly incremental backups. During a restoration, they discover that a critical file was corrupted 6 hours ago. Which backup set is required for the restoration?
Hard510Which statement best describes a warm site in disaster recovery?
Hard511A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?
Medium512An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?
Medium513An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?
Hard514A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?
Medium515Which of the following best describes a Disaster Recovery Plan (DRP)?
Easy516A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?
Medium517A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?
Easy518Refer to the exhibit. A security analyst sees these logs from a Linux server. Which security control should the analyst recommend to address this pattern?
Medium519During a forensic investigation, an analyst acquires a live system memory dump. Which tool is most appropriate for capturing the contents of volatile memory on a Windows system?
Hard520A company is designing a new application that processes credit card payments. They want to ensure that no single administrator can bypass security controls to approve a fraudulent transaction. Which principle should be implemented?
Hard521After a security audit, a company discovers that several employees have access to financial systems that are not required for their job roles. Which access control model would best prevent this issue in the future?
Medium522In a Bell-LaPadula MAC model, which of the following operations is prohibited?
Hard523A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
Medium524A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?
Hard525What is the primary purpose of a Privileged Access Management (PAM) solution?
Medium526An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?
Hard527A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?
Hard528Which of the following is a key component of the 3-2-1 backup rule?
Easy529Which TWO of the following are fundamental principles of information security that form the CIA triad?
Easy530Which of the following ensures that data has not been tampered with during transmission?
Easy531A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?
Hard532An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?
Medium533A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?
Medium534Which TWO of the following are best practices for password management in a corporate environment?
Easy535According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?
Medium536Which TWO of the following are examples of physical access controls?
Easy537A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?
Easy538An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?
Hard539A security professional is evaluating a system that uses a trust model where every component authenticates to each other before communicating. Which security principle does this model exemplify?
Hard540An organization needs to prioritize recovery of systems after a disaster. Which metric directly indicates the maximum acceptable outage time for a business function?
Medium541During a BIA, the maximum tolerable downtime for a critical application is determined to be 4 hours. The IT team estimates system recovery will take 2 hours, but additional manual work to reconcile data will take 1 hour. What is the Recovery Time Objective (RTO)?
Medium542Which THREE are common indicators of a compromised system? (Select THREE.)
Hard543Refer to the exhibit. Based on the exhibit, which traffic will be permitted?
Medium544Which of the following is considered Sensitive PII?
Easy545A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?
Medium546A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?
Medium547Refer to the exhibit. An access control policy is shown. Which action is permitted by this policy?
Easy548A user reports that they are unable to access a shared network drive that they previously could access. The administrator checks permissions and finds the user's account is still a member of the correct group. What should the administrator check next?
Medium549An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?
Hard550Refer to the exhibit. Based on the report, which improvement is most appropriate?
Medium551A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)
Medium552Which TWO are best practices for managing backup media?
Medium553A security team configures a system to record all user activities for audit purposes. Which principle is being applied?
Easy554Which THREE are primary phases of the incident response lifecycle?
Hard555A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?
Medium556A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)
Medium557Which of the following is an example of a detective control?
Easy558An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?
Medium559A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?
Hard560Which of the following is an example of a physical control that supports the availability principle of the CIA triad?
Easy561An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?
Hard562A medium-sized company uses a SIEM solution to collect logs from firewalls, servers, and endpoints. The security team receives an alert indicating a possible data exfiltration: an employee's workstation is sending large amounts of data to an external IP address outside business hours. The employee works in the finance department and has access to sensitive financial records. The SIEM shows the connection is ongoing. The security team must respond immediately to contain the incident while preserving evidence. The company's incident response plan designates the security team as first responders. Which of the following is the BEST first action?
Medium563Which of the following is the most effective way to prevent tailgating in a secured facility?
Medium564Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?
Medium565Which OSI layer is responsible for routing packets based on IP addresses?
Easy566Which of the following are core principles of information security?
Medium567Which two of the following are common types of security controls?
Easy568A healthcare organization uses a legacy application that stores patient records in plain text. The IT team is planning to upgrade the system but needs to ensure compliance with HIPAA. The new system will be hosted on-premises and accessed by doctors and nurses via a web portal. The security team proposes implementing a VPN for remote access, but the CEO wants to allow access from any device without VPN for convenience. Which principle should guide the decision?
Medium569A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?
Medium570Which process involves verifying the identity of a user who claims to be a specific person?
Easy571Refer to the exhibit. A security analyst notices that a user with the Finance role is able to write to /finance/data from a macOS device at 10:00 AM. The policy shown is the only policy affecting this resource. What is the most likely reason for this behavior?
Hard572Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?
Easy573Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?
Easy574An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?
Easy575You are the lead SOC analyst for a medium-sized financial services company. The company uses a hybrid infrastructure with on-premises servers and cloud services (AWS). The SIEM is Splunk Enterprise, collecting logs from firewalls, IDS/IPS, endpoints (Windows and Linux), and AWS CloudTrail. Recently, the company experienced a ransomware attack that encrypted critical file servers. The initial infection vector was a phishing email that led to the download of a malicious macro-enabled document. The document was executed on a Windows workstation, which then established a C2 connection to an external IP. The C2 traffic was over HTTPS, and the workstation was part of the domain. After the attack, the forensic team found that the workstation had Windows Event Logs cleared, and the local admin account had been used to disable the antivirus. The C2 IP was later blocked, but the ransomware had already spread to file servers via SMB. As part of the lessons learned, you need to recommend improvements to prevent and detect such attacks in the future. Which of the following is the BEST course of action to address the specific weaknesses exploited in this incident?
Hard576Which protocol is considered insecure because it transmits data, including credentials, in cleartext?
Medium577An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?
Hard578Match each phase of the incident response process to its description.
Medium579Refer to the exhibit. What action did the firewall take on the traffic from 10.0.1.15 to 10.0.2.10?
Medium580A company wants to mitigate the risk of a man-in-the-middle (MITM) attack. Which three measures are effective? (Choose THREE.)
Hard581In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)
Hard582An account lockout policy is designed to mitigate which type of attack?
Medium583A government agency stores classified documents on a secure server. The server is connected to the internet, but access is restricted using a firewall and requires two-factor authentication. An auditor discovers that the server's operating system has not been patched for over a year, making it vulnerable to remote code execution attacks. Which security principle is most directly compromised by this missing patch, and what is the best corrective action?
Easy584Based on the backup schedule, what is the maximum potential data loss?
Medium585Match each network security concept to its purpose.
Medium586Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)
Hard587Which TWO of the following are components of the identification and authentication process? (Select TWO.)
Medium588Which THREE of the following are considered fundamental security principles? (Select three).
Easy589A security team is designing a visitor management policy. Which TWO of the following are essential components? (Select TWO.)
Medium590An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?
Medium591During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?
Easy592What is the primary purpose of using security baselines derived from CIS Benchmarks?
Medium593Which THREE of the following are essential components of a security baseline configuration for a server?
Hard594During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?
Hard595A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?
Easy596A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?
Medium597Which of the following ports is used by HTTPS?
Easy598A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?
Medium599An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)
Hard600A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:
Hard601Refer to the exhibit. A network administrator configured the following firewall rules. After implementation, users from the internal network cannot browse the internet. Which element is causing the issue?
Medium602Which THREE are recommended practices for password policies according to current guidelines?
Medium603During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?
Medium604A company's security policy requires that all data at rest be encrypted. Which of the following is the BEST approach to ensure compliance while maintaining performance?
Medium605A company's primary data center experiences a complete power failure, and operations are shifted to a secondary site. The failover process takes 4 hours, but the recovery point objective (RPO) is set to 1 hour. Which of the following is the most likely consequence of this incident?
Medium606A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?
Hard607Which of the following ports is commonly used for secure web traffic (HTTPS)?
Easy608Which THREE of the following are best practices for securing a remote access VPN?
Hard609A system administrator must grant a help desk technician the ability to reset user passwords but not change user roles. Which security principle does this scenario enforce?
Easy610An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?
Easy611A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?
Hard612After a ransomware attack, which team is primarily responsible for coordinating the response?
Easy613An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?
Medium614In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?
Hard615Which THREE of the following are best practices for securing a wireless network?
Hard616An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?
Medium617An administrator reviews the exhibit. Which security principle is being violated?
Easy618According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?
Hard619A security analyst reviews this firewall log entry. What type of activity is most likely being attempted?
Hard620An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
Medium621A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?
Medium622A company's security policy requires that employees must change their passwords every 90 days and passwords must be at least 12 characters. Which security principle is being enforced?
Easy623An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?
Medium624During an incident response, a forensics analyst captures a memory dump from a compromised server. The analyst needs to ensure the dump is not altered during analysis. Which practice best maintains integrity?
Hard625Refer to the exhibit. Which security principle is being supported by the logging of these events?
Hard626According to the (ISC)² Code of Ethics, which obligation has the highest priority?
Medium627A network technician is setting up a remote access VPN for employees using IPsec. The company's firewall is configured to allow IPsec traffic. Employees report that they can successfully establish the VPN connection (tunnel appears up), but they cannot ping or access any internal resources (e.g., file servers). The firewall logs show that packets from the VPN client IP addresses are being dropped at the firewall interface. Which of the following is the MOST likely cause of this issue?
Easy628A small manufacturing company's IT infrastructure consists of a single server running ERP and file services, with a nightly backup to an external hard drive. The server fails due to hardware failure. The company's BCP states that the ERP system must be restored within 8 hours. The backup is 12 hours old. The IT administrator has a spare server of similar configuration. What is the BEST course of action?
Easy629An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)
Hard630An organization uses a warm site for disaster recovery. Which of the following is the MOST significant risk of this approach?
Hard631Which of the following is a control that can reduce the risk of a DDoS attack?
Easy632An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?
Medium633A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:
Medium634Refer to the exhibit. A user from the Auditors group is unable to access the folder. What is the most likely cause?
Hard635During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?
Hard636Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?
Easy637An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?
Hard638A company's remote access VPN uses IPsec with pre-shared keys. Employees report that they cannot connect from home. The VPN server logs show 'IKE authentication failed.' The help desk confirms the pre-shared keys are correct. Which of the following is the most likely cause?
Medium639An organization implements a bring-your-own-device (BYOD) policy. Which security control is most important to enforce in the BYOD policy?
Medium640A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?
Easy641A company has implemented a security information and event management (SIEM) system. The SOC team notices that the SIEM is generating a high volume of false positive alerts from a specific web application firewall (WAF). The WAF logs show many requests with SQL injection patterns, but the application is not vulnerable. Which of the following actions would BEST reduce false positives without compromising security?
Medium642An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?
Medium643A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).
Medium644Which of the following is a recommended practice for password security according to NIST SP 800-63?
Medium645A company wants to protect its internal web server from common web application attacks. Which two security measures are most appropriate? (Choose TWO.)
Medium646Which TWO are characteristics of Role-Based Access Control (RBAC)?
Medium647When implementing a role-based access control (RBAC) system, what is the primary challenge organizations face?
Hard648A company is evaluating backup strategies for its critical database. Which TWO of the following are correct statements about backup types?
Easy649Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
Easy650You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?
Medium651A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?
Medium652An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:
Hard653A company uses WPA2-Enterprise for wireless authentication. What additional security measure should be implemented to protect against rogue access points?
Medium654A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?
Easy655An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?
Easy656Which TCP segment is sent to initiate the three-way handshake?
Easy657A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?
Hard658A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?
Medium659Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?
Easy660A SOC analyst detects a series of failed login attempts from a single external IP address targeting multiple user accounts within a short time. Which action should the analyst take FIRST?
Medium661A small business owner wants to ensure that their company's data remains accurate and unaltered during transmission over the internet. They regularly send financial reports to their accountant via email. The owner is concerned that a hacker might intercept and modify the reports before they reach the accountant. Which security principle is most directly threatened in this scenario, and what is the best technical control to implement?
Easy662Refer to the exhibit. ``` C:\> netstat -an | find "LISTENING" TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?
Easy663A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?
Medium664A SOC team is reviewing security controls for a new critical application. Which THREE of the following are essential components of a security operations capability?
Medium665A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?
Hard666An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?
Easy667A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)
Medium668A medium-sized e-commerce company operates a web application on three virtual servers behind a load balancer. The application handles credit card payments and stores customer data in a database server. The company has a security operations team that monitors logs from firewalls, IDS, and servers. One morning, the IDS generates a critical alert indicating a SQL injection attempt from an external IP to the web application. The alert shows that the injection string was ' OR '1'='1' -- . The web server logs confirm that the request returned a 200 OK status and a large response size. The database logs show a query that returned multiple rows. The security analyst needs to determine the best immediate course of action. The company has a documented incident response plan that includes containment, eradication, and recovery phases. Which action should the analyst take first?
Hard669An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?
Hard670During a security audit, it is found that a database administrator can access payroll data. The company policy states that administrators should not have access to sensitive HR data. Which security principle is being violated?
Hard671A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)
Medium672Refer to the exhibit. The file is readable and writable by everyone. A user from the marketing team, user2, needs to be able to read the file but not write to it. Which command should the administrator use to achieve this?
Medium673Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?
Easy674A company's network uses 802.1X authentication with PEAP-MSCHAPv2 on wired ports. Users report that after a recent switch firmware update, some workstations fail to authenticate intermittently, while others work fine. The authentication server logs show 'Authentication failed: Unknown CA certificate' for affected workstations. What is the most likely cause?
Hard675A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?
Hard676A company experiences a ransomware attack that encrypts all files on a critical server. The backup strategy includes nightly backups stored on a separate network. What should be the first action during recovery?
Medium677Based on the incident log, at which step did the incident response team contain the threat?
Easy678A company implements a visitor management policy requiring all visitors to sign in, wear a badge, and be escorted. Which access control principle does this primarily support?
Medium679A security engineer is designing a network for a small business that needs to segregate guest Wi-Fi from the internal corporate network. The guest network should have internet access only, with no access to internal resources. Which of the following is the BEST design approach?
Medium680Which TWO of the following are examples of administrative security controls? (Choose two.)
Medium681An organization is implementing a new system that processes financial transactions. To reduce the risk of fraud, they ensure that no single individual can both initiate and approve a transaction. Which security principle is this?
Hard682A security analyst discovers that an organization's firewall rule set allows all inbound traffic on TCP port 443 from any source to a single web server. Additionally, the server has a known critical vulnerability in its TLS implementation. Which principle of security architecture is most directly violated by this configuration?
Hard683A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?
Easy684Match each OSI layer to its function.
Medium685Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?
Medium686A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?
Hard687A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?
Medium688You are the cybersecurity lead for a mid-sized retail company. One morning, employees report that they cannot access files on the shared drive, and a ransom note appears on several screens demanding $50,000 in Bitcoin. The company has a formal incident response plan that was last updated two years ago and has never been tested. Backups are taken nightly to an on-premises tape library and also replicated to a cloud storage service but have not been verified recently. The CEO is insisting on paying the ransom to avoid business disruption. Which of the following is the MOST appropriate first course of action?
Easy689Which TWO of the following are examples of detective security controls? (Choose two.)
Hard690Which of the following is a key function of a Security Information and Event Management (SIEM) system?
Easy691A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?
Medium692Which THREE are valid methods for authenticating a user in an access control system?
Hard693A company's primary data center is located in a region prone to hurricanes. The IT team is designing a disaster recovery plan to ensure critical applications resume within 4 hours of a declared disaster. Which of the following is the MOST appropriate recovery strategy?
Easy694Which THREE are best practices for password management according to modern guidelines? (Select THREE.)
Medium695An organization has a legacy system that cannot be patched due to vendor end-of-life. Which compensating control is most effective at reducing the risk of exploitation via network-based attacks?
Hard696Which THREE of the following are best practices for securing a network firewall? (Select THREE.)
Hard697After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?
Hard698Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)
Medium699A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?
Hard700Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?
Medium701Refer to the exhibit. An administrator notices that external access to the MySQL database (port 3306) is blocked, but internal access should be allowed. What change should be made?
Medium702You are a forensic analyst responding to a reported compromise of a Linux web server. The server hosts a public-facing web application and is part of a DMZ. The initial investigation shows that unauthorized outbound connections were made to a known malicious IP address during the previous night. The server is still running and connected to the network, but the web application has been taken offline for maintenance. The incident response team wants to preserve evidence for potential legal action. You have a forensic workstation with tools like dd, netcat, and memory acquisition tools. Which of the following should be your FIRST step in the forensic acquisition process?
Hard703A security engineer is designing a system that must ensure that any changes to a configuration file are logged with the identity of the person who made the change. Which principle is being implemented?
Hard704The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?
Easy705An organization is choosing a backup strategy to minimize restore time. Which TWO backup types require only the most recent full backup and the latest differential backup to restore?
Medium706A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?
Hard707A company is implementing a backup strategy. Which TWO of the following are characteristics of incremental backups? (Choose two.)
Medium708Refer to the exhibit. A firewall rule set is shown (first match applies). An analyst reviews these rules. Which of the following best describes the traffic outcome for a packet from source IP 10.0.0.1 to destination 192.168.1.1?
Hard709A company wants to allow remote employees to securely access internal resources over the internet. Which technology is most appropriate?
Easy710Which TWO of the following are essential elements of an incident response plan?
Medium711Which of the following controls is primarily designed to ensure availability?
Medium712An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?
Hard713Which TWO of the following are best practices for implementing the principle of least privilege?
Hard714You are the network security lead for a medium-sized financial firm with 500 employees. The network consists of a core switch, distribution switches, and access switches. There are three main VLANs: VLAN 10 (Management - 192.168.10.0/24), VLAN 20 (Finance - 192.168.20.0/24), and VLAN 30 (Guest Wi-Fi - 192.168.30.0/24). The network uses a single firewall with three interfaces: inside (trusted), outside (untrusted), and DMZ. The firewall is configured with default-deny rules. Recently, the helpdesk reported that employees in the Finance VLAN cannot access a web-based accounting application hosted on a server at 10.0.0.5, which is in the DMZ. The server's default gateway is the firewall's DMZ interface (10.0.0.1). The accounting application runs on HTTPS (TCP 443). Employees in the Management VLAN can access the application without issue. You have verified that the Finance VLAN has connectivity to the firewall's inside interface (192.168.20.1). The firewall's inside interface has an IP of 192.168.20.1. There is no ACL on the inside interface. The firewall's DMZ interface has an ACL permitting TCP/443 from any to 10.0.0.5. The firewall's routing table shows a route to 10.0.0.0/24 via DMZ interface. What is the most likely cause of the issue?
Hard715Refer to the exhibit. Based on the backup log, what is the most likely corrective action?
Medium716An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)
Hard717Which incident category involves an attacker tricking an employee into revealing credentials?
Easy718A system administrator needs to grant a contractor temporary access to a server for patching. The contractor should only have access during the patching window. Which access control implementation method is most appropriate?
Medium719An organization wants to ensure that data remains unaltered during transmission over the internet. Which security goal is being addressed?
Easy720A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)
Medium721Which metric defines the maximum acceptable amount of data loss measured in time?
Easy722A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
Easy723A SOC analyst notices that a large volume of outbound traffic is occurring from a single workstation to an external IP address known to be associated with a command-and-control server. What is the most likely conclusion?
Easy724A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)
Medium725Refer to the exhibit. Based on the JSON policy, what access does the SecurityAuditor role have?
Hard726During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?
Hard727Which of the following is a potential security issue commonly found in firewall configurations?
Hard728Your organization is implementing a new access control system to protect a highly sensitive research database. The security policy mandates that no single individual should have the ability to both approve and execute changes to the database. This is to prevent fraud and errors. Which security principle does this policy enforce, and which of the following best implements it?
Medium729A security architect is designing a system that must ensure that a sender cannot later deny having sent a message. Which cryptographic mechanism should be implemented?
Hard730Which component of the AAA framework determines what resources an authenticated user can access?
Medium731Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
Easy732An organization's security policy requires that all network traffic logs be retained for at least one year. The SIEM system is running low on storage, and the administrator must decide which data to archive first. Which data set is the least critical for ongoing security monitoring and can be archived earliest?
Hard733An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?
Hard734Which of the following is classified as sensitive PII?
Medium735A network administrator needs to allow secure remote access for teleworkers. Which VPN protocol provides the best confidentiality and integrity while using a single UDP port?
Medium736An organization requires that two separate administrators approve and implement changes to firewall rules. This practice enforces which security principle?
Hard737An organization implements a policy where users must swipe their ID card and enter a PIN to access a secure room. This is an example of which access control principle?
Easy738Refer to the exhibit. The security principle demonstrated by the default policy is:
Easy739A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?
Medium740A small e-commerce company hosts its web application on a single server with a public IP address. The server runs a Linux OS with Apache, MySQL, and PHP. The company recently experienced a data breach where an attacker gained access to the customer database. The investigation reveals that the attacker exploited a vulnerability in the PHP application to execute arbitrary commands. The server logs show that the attacker used an unauthenticated HTTP POST request to a legacy script that should have been removed. Additionally, the server had default firewall rules allowing all inbound traffic on ports 80 and 443. The company wants to prevent future breaches without redesigning the entire application. Which course of action is the most effective?
Hard741A security analyst observes the log entries on an SSH server as shown. What is the most likely type of attack in progress?
Medium742A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)
Hard743A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?
Hard744Which TWO are key outputs of a Business Impact Analysis (BIA)?
Easy745An organization has a policy that all servers must have security patches applied within 30 days of release. Which of the following is the best practice for patching?
Medium746An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)
Medium747Which of the following is a security concern associated with the Telnet protocol?
Medium748A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?
Easy749A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?
Medium750Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.
Medium751In a directory service such as Active Directory, which component is responsible for storing information about users, groups, and computers in a hierarchical structure?
Hard752An incident response team is analyzing a data breach. Which THREE actions are part of the 'Lessons Learned' phase? (Select THREE)
Hard753Which of the following is an example of a logical access control?
Easy754An organization wants to ensure that no single employee can both request and approve a payment. Which access control principle does this enforce?
Easy755What is the primary purpose of identification in the context of access control?
Easy756During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?
Hard757Which TWO of the following are valid types of disaster recovery tests?
Medium758An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?
Easy759Which of the following best describes the difference between due care and due diligence in security governance?
Hard760You are the security administrator for a mid-sized e-commerce company. The company uses a Linux-based web server running Apache, with a MySQL database backend. User authentication is handled via LDAP. Recently, the security team discovered that a former employee's account was used to access the customer database two weeks after the employee was terminated. The account had not been disabled. The database contains personally identifiable information (PII). The incident was traced to an internal IP address from the marketing department. The marketing department's network segment is not segregated from the database server. Additionally, the database server's firewall rules allow any internal IP to connect to the MySQL port (3306). The company has a written policy that accounts must be disabled within 24 hours of termination, but the HR department did not notify IT in a timely manner. Which combination of controls would BEST prevent a recurrence of this incident?
Hard761Which TWO are key components of an effective incident response plan? (Select TWO.)
Medium762An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?
Medium763A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?
Hard764Which TWO of the following are common indicators of a phishing email?
Easy765Which of the following is an example of a Type 2 authentication factor?
Easy766Which of the following is an example of a Type 1 authentication factor?
Medium767A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Medium768A company implements a policy where users must swipe their access card and then enter a PIN to enter the data center. This is an example of:
Medium769A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?
Easy770A company's backup strategy involves daily full backups only. What is the primary risk associated with this approach?
Easy771A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?
Medium772An organization's security policy requires that all employees change their passwords every 90 days. This is an example of which type of security control?
Easy773According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?
Hard774A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)
Hard775Which document outlines the procedures for maintaining critical business functions during a disruption?
Easy776A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?
Medium777A company has implemented a policy where all employees must use a smart card and PIN to access the data center. Which security principle does this practice support?
Easy778Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?
Medium779An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:
Medium780A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?
Hard781Which THREE of the following are best practices for privileged account management? (Select THREE.)
Medium782An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)
Medium783A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)
Hard784Which TWO of the following are common indicators of a ransomware attack?
Easy785An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?
Easy786A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?
Easy787A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)
Medium788Which TWO of the following are types of security controls?
Medium789A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)
Hard790A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?
Medium791A company is selecting a recovery site strategy. Which TWO factors should be considered when choosing between a hot site and a warm site? (Select TWO.)
Medium792During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?
Hard793You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?
Hard794Refer to the exhibit. A security analyst runs the above iptables command on a Linux server. The server is configured with a default policy of DROP on the INPUT chain. Users report they can SSH to the server but cannot ping it. What is the most likely reason?
Hard795Which THREE of the following are recognized security control types according to ISC2? (Choose three.)
Hard796A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
Hard797During a security incident, a forensic analyst needs to acquire the contents of RAM from a live system. Which tool should be used?
Hard798A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?
Medium799A small financial firm has a single server that hosts a critical database and also runs a web application. The server is located in a closet with a simple lock. An intern accidentally left the closet door open, and an unauthorized person gained physical access, connected a laptop to the server, and copied the database. The company wants to prevent such incidents in the future. Which of the following is the most effective course of action?
Easy800A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?
Medium801A security analyst discovers that an employee shared their password with a colleague to complete a task. Which security principle has been violated?
Easy802An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?
Easy803A company wants to implement a security control that ensures users are who they claim to be before granting access to a system. Which type of control should they prioritize?
Easy804An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:
Hard805A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?
Medium806An organization uses a primary data center and a backup site 500 miles away. The backup site replicates data synchronously. Which risk is MOST likely introduced by this configuration?
Medium807According to the (ISC)² Code of Ethics, which principle has the highest priority?
Medium808Which access control model uses subject and object labels to enforce access based on a security policy?
Easy809An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?
Medium810Refer to the exhibit. What is the first action the incident responder should take?
Easy811What is the primary purpose of hashing in information security?
Easy812Which TWO are principles of access control?
Medium813A company's backup strategy requires daily full backups of all servers. The backup window is 4 hours. What is the primary risk if backups consistently take longer than the window?
Easy814An organization wants to ensure that its backup strategy can recover data within 2 hours after a system failure. Which metric should be defined in the disaster recovery plan?
Hard815A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:
Hard816A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?
Hard817A security architect is evaluating a biometric authentication system. The system's false positive rate is 0.1%, and the false negative rate is 2%. Which security principle is most compromised if the organization prioritizes user convenience over security?
Hard818Match each authentication factor to an example.
Medium819Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?
Medium820A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?
Easy821A company's security policy requires that all sensitive data be encrypted during transfer. A security administrator discovers that an internal web application is using a self-signed TLS certificate. What vulnerability does this introduce?
Hard822In a MAC environment implementing Bell-LaPadula, a subject with Secret clearance attempts to read an object classified as Confidential and write to an object classified as Top Secret. Which operations are permitted?
Hard823Which common port is used by DNS and which transport layer protocol does it primarily use?
Medium824An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?
Hard825A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)
Hard826You are implementing a security control to prevent unauthorized devices from connecting to the corporate wired network. Which network access control method should be used?
Hard827An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)
Medium828A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)
Medium829Which THREE are phases of the incident response process according to NIST SP 800-61?
Easy830Which type of log should be monitored to detect a user account that has been granted administrative privileges unexpectedly?
Medium831Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?
Medium832A company is classifying data and wants to ensure that personally identifiable information (PII) receives appropriate protection. Which two of the following are considered PII? (Choose two.)
Medium833Which of the following is an example of a Type 2 authentication factor?
Easy834Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?
Easy835An organization wants to implement a physical access control that requires two different credentials to enter a high-security server room. Which concept does this best represent?
Hard836Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy837Which TWO of the following are examples of multi-factor authentication? (Select TWO.)
Medium838After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?
Hard839A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)
Hard840A security administrator is reviewing network security controls. Which TWO of the following are examples of network segmentation technologies? (Select TWO)
Medium841During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?
Hard842Refer to the exhibit. What type of event is this?
Hard843What is the difference between identification and authentication?
Easy844Refer to the exhibit. A security engineer reviews this firewall ACL. Which of the following best describes the security posture?
Medium845During a security audit, you discover that a financial application stores passwords using MD5 hashing without salt. What is the primary security concern with this practice?
Medium846A company wants to implement account lockout to prevent brute-force attacks. Which lockout threshold is most appropriate according to common best practices?
Hard847An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?
Easy848An analyst reviews the exhibit. What security principle is best demonstrated by this policy?
Hard849An organization has implemented a SIEM solution. The security team wants to detect when a user attempts to access a file they do not have permission to read. Which log source is most important for this detection?
Medium850Which of the following is considered sensitive personally identifiable information (PII)?
Medium851A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)
Medium852Which of the following best describes the purpose of due care in information security?
Easy853Which TWO of the following are core principles of the CIA triad?
Easy854Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?
Hard855A company's IDS generates an alert for a potential SQL injection attack on a web application. The analyst reviews the log and sees the following: "SELECT * FROM users WHERE username = 'admin' OR 1=1 --'". Which action should the analyst take next?
Hard856A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)
Hard857Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)
Easy858A security analyst discovers that a user's account has been used to access sensitive data outside of normal business hours from an unfamiliar IP address. The user claims they were not logged in at that time. Which security operations process should be initiated first?
Medium859Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?
Easy860During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?
Medium861A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?
Medium862An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
Hard863A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?
Medium864During an incident, the incident response team discovers that an attacker has exfiltrated sensitive customer data. According to incident response best practices, whose approval is REQUIRED before contacting law enforcement?
Easy865A security analyst observes these SSH logs. What is the MOST likely attack?
Medium866After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?
Hard867A security analyst is reviewing data handling procedures. Which THREE of the following are considered sensitive PII?
Hard868According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?
Medium869A company's security policy requires that all privileged access to critical servers be logged and monitored. The IT team has implemented a jump server (bastion host) for administrators to connect to critical servers. All SSH connections to the jump server are logged, and from there, administrators connect to target servers. The security team notices that some administrators are bypassing the jump server and connecting directly to critical servers from their workstations. The direct connections are not logged. The security team needs to enforce the policy without disrupting operations. Which of the following is the BEST solution?
Medium870A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?
Hard871During which phase of the incident response process would the team identify the root cause of a security incident?
Easy872Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?
Easy873A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?
Medium874A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?
Easy875The exhibit shows a snippet of /var/log/auth.log on a Linux server. Which security principle is most likely violated if the failed attempts continue without action?
Hard876A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?
Hard877A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)
Medium878According to the (ISC)² Code of Ethics, which of the following has the highest priority?
Hard879A company implements a policy where a financial transaction must be initiated by one employee and approved by a different employee. This is an example of which access control concept?
Medium880Which of the following is considered sensitive Personally Identifiable Information (PII)?
Easy881Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)
Medium882A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?
Medium883A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?
Easy884A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:
Medium885Drag and drop the steps to configure a basic VPN (site-to-site) between two routers into the correct order.
Medium886A company implements a policy that after an employee leaves, their account must be disabled within 24 hours. Which principle is this policy primarily intended to support?
Hard887A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:
Hard888A government agency uses a multi-level security system with mandatory access control (MAC). A user with Secret clearance attempts to write data to a file classified as Confidential. Under the Bell-LaPadula model, which rule applies and what is the outcome?
Medium889A network administrator is designing a DMZ to host a public-facing web server and a database server that should only be accessible from the web server. Which of the following firewall rule sets best achieves this design?
Medium890Which THREE of the following are examples of the principle of least privilege? (Select THREE.)
Medium891An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?
Medium892During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?
Hard893Which TWO of the following are common methods to authenticate users on a wireless network? (Select TWO)
Easy894Which TWO scenarios best illustrate the principle of least privilege?
Medium895A healthcare organization suffers a data breach involving protected health information (PHI). The incident occurred on Monday, and the organization discovers it on Wednesday. Under GDPR, if the breach affects EU residents, what is the deadline for notifying the supervisory authority?
Hard896An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?
Medium897A company's network has multiple VLANs. An attacker on VLAN 10 sends a frame with a forged source MAC address to a switch, hoping to intercept traffic intended for the default gateway. Which attack is being executed?
Hard898Which port number is associated with HTTPS, and what protocol encrypts the communication?
Easy899Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy900Refer to the exhibit. An administrator configures the above ACLs on a router. The goal is to allow internal users (192.168.1.0/24) to browse the web, and to allow SSH management from the internet to a server at 10.0.0.10. However, users report that they cannot browse external websites. What is the most likely reason?
Medium901An analyst reviews the firewall log exhibit. The source IP 10.0.1.100 is an internal web server. The destination IP 203.0.113.50 is an external host. What does this log pattern MOST likely indicate?
Medium902During a security audit, a penetration tester captures network traffic and finds that some packets have the IP ID field set to 0 and the DF (Don't Fragment) flag set. What is this technique attempting to do?
Hard903An organization wants to implement a system that enforces access decisions based on a user's attributes (e.g., department, clearance, time) and environmental conditions. Which model is best?
Hard904A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?
Medium905Which of the following best describes a vulnerability in the context of risk management?
Medium906Refer to the exhibit. A security analyst observes that users from the 192.168.1.0/24 network cannot access HTTPS websites, but HTTP access works fine. What is the most likely cause?
Easy907A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?
Hard908Match each type of malware to its primary behavior.
Medium909A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?
Medium910A financial institution is implementing data classification to protect customer information. They have identified data that includes medical records and financial account numbers. Which three labels are most appropriate for this data? (Choose three.)
Hard911A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)
Medium912A security manager is designing a policy to prevent one person from both approving and disbursing payments. Which principle is being applied?
Medium913A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:
Medium914Which two of the following are characteristics of a stateful firewall? (Choose TWO.)
Easy915A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?
Hard916Which THREE are essential elements of a disaster recovery plan? (Select THREE.)
Easy917A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:
Medium918Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?
Easy919Which of the following is an example of Type 2 (possession) authentication?
Easy920A company deploys a web application that stores user passwords using a salted hash. During a security review, an auditor recommends switching from SHA-1 to SHA-256. What is the primary security benefit of this change?
Medium921Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?
Easy922An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?
Hard923What is the primary goal of data classification?
Easy924Refer to the exhibit. A user from IP 10.0.1.5 attempts to download an object from example-bucket. What will happen?
Hard925Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?
Hard926Which TWO of the following are core components of the CIA triad?
Easy927Which of the following are examples of sensitive PII? (Select all that apply.)
Medium928A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?
Medium929Drag and drop the steps to implement a firewall rule allowing inbound HTTPS traffic into the correct order.
Medium930Refer to the exhibit. An analyst sees these logs. What type of attack is occurring?
Medium931An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?
Medium932Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?
Hard933A primary data center is destroyed. The disaster recovery plan calls for activation of a hot standby site. If the RTO is 2 hours, what is the expected recovery time?
Medium934Which of the following is an example of a Type 2 authentication factor?
Medium935Which TWO actions are appropriate during the identification phase of incident response?
Hard936Which of the following best describes the principle of confidentiality in the CIA triad?
Easy937An organization is implementing a new identity management system. They want to ensure that users can only access resources necessary for their job roles. Which principle should guide the access control design?
Hard938A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?
Medium939An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)
Easy940An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?
Hard941Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?
Hard942During a vulnerability scan, the security team discovers a critical vulnerability on a public-facing server. According to best practices, what should the team do next?
Medium943A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)
Medium944Which TWO are true about a differential backup? (Select two.)
Medium945A helpdesk technician receives a report that a user in the finance department cannot access a shared folder on the server. The same server is accessible from other departments. What is the most likely cause?
Easy946An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?
Easy947A network administrator is configuring a DMZ for a company's web and email servers. Which firewall rule is most appropriate for traffic from the internet to the DMZ?
Medium948After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?
Hard949A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?
Hard950During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?
Hard951Which THREE are differences between a hot site and a cold site? (Select three.)
Hard952You are the IT security officer for a hospital that handles protected health information (PHI). The hospital uses an electronic health record (EHR) system. You receive a report that a nurse accessed the medical records of a celebrity patient without a legitimate medical reason. The access was logged. The hospital policy requires all employees to access only the minimum necessary information for their job duties. The nurse claims they were just curious. This is a violation of which security principle, and what is the best course of action?
Medium953A company wants to segment its network into separate broadcast domains to improve performance and security. Which device should be used to achieve this?
Easy954A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)
Hard955Which TWO of the following are examples of administrative security controls?
Easy956A small company has a single flat network with no segmentation. They recently experienced a malware outbreak that spread quickly across all devices. The IT manager wants to implement network segmentation to contain future outbreaks with minimal cost and complexity. The company currently has a single switch and a router/firewall appliance. The network consists of three departments: Sales, HR, and Engineering. After analyzing the requirements, what is the best course of action?
Easy957An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?
Hard958Which TWO of the following are recognized as benefits of network segmentation?
Hard959Based on the exhibit, what is the most likely result of the client's HTTP request?
Medium960An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?
Medium961Which THREE of the following are recognized security principles according to NIST and ISC2?
Medium962A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?
Hard963An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?
Medium964Which of the following protocols provides secure remote administration of a network device over an untrusted network?
Easy965A hospital uses role-based access control (RBAC) for its electronic health records. Nurses can view patient records; doctors can view and edit; administrators can only view administrative data. Recently, a nurse was able to edit a patient's record, which should only be allowed for doctors. The investigation finds that the nurse's role was incorrectly assigned a 'doctor' role due to a misconfiguration. To prevent recurrence, the access control system should be reviewed. Which is the best long-term solution?
Medium966Which of the following is a best practice for securing physical access to a data center?
Easy967Which layer of the OSI model is responsible for routing packets across networks?
Easy968Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?
Medium969During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?
Hard970Which of the following is an example of a physical access control at the building entrance?
Easy971Which security control would best mitigate the risk of network sniffing on a wired LAN segment?
Medium972A small business with limited budget wants to ensure critical business functions can resume within 24 hours of a disaster. Their data changes infrequently. Which recovery solution is MOST cost-effective?
Medium973Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?
Easy974An organization requires that two different administrators approve changes to firewall rules. This is an example of which security principle?
Easy975Which TWO of the following are common indicators of a phishing email? (Select TWO.)
Medium976A security team implements a policy that requires all access to sensitive data to be logged and audited. Which principle is being enforced?
EasyOther domains
All CC exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CC exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 976 scenario questions questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.