CC · domain
scenario questions
Practise ISC2 Certified in Cybersecurity CC scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (989)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are principles of the CIA triad? (Select TWO.)
Easy2A company's security policy states that employees should only have access to the data necessary to perform their job functions. This is an example of which principle?
Easy3A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?
Hard4An organization is implementing a new access control system based on the principle of least privilege. Which two of the following practices are essential to achieving least privilege? (Select TWO)
Medium5Which of the following is the primary purpose of a visitor log and escort policy?
Medium6An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?
Hard7A security administrator is configuring access rights for a new employee. Which principle ensures the employee is granted only the minimum permissions necessary to perform their job duties?
Easy8Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?
Easy9The exhibit shows recent authentication logs. What type of attack is most likely indicated?
Easy10A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?
Hard11A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)
Hard12A security policy requires that data classified as 'Confidential' must be encrypted both at rest and in transit. Which TWO of the following are likely data handling requirements for 'Confidential' data? (Select TWO)
Medium13An organization implements a redundant server infrastructure to ensure that services remain operational even if one server fails. This is an example of protecting which principle?
Medium14A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?
Medium15A software company allows developers to access production servers only during an approved change window, and only after a manager approves a request that includes a ticket number and expiration time. Access is automatically revoked when the window closes. Which access control approach is being used?
Hard16A security analyst is reviewing an alert from the IDS that shows a large number of TCP SYN packets sent to a single port on multiple internal hosts from a single external IP address. The analyst suspects a reconnaissance attack. Which type of attack is this most likely?
Easy17Refer to the exhibit. Which statement best describes compliance with the recovery objectives?
Hard18A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured web server that exposed a database directly. Which principle was most lacking in this scenario?
Hard19What is the primary purpose of a digital signature?
Medium20An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?
Easy21An organization wants to detect and alert on potential network intrusions but does not want to risk blocking legitimate traffic. Which system should they deploy?
Medium22A company's security policy requires that all sensitive data be encrypted both at rest and in transit. This is an example of applying which security principle?
Medium23A hospital's IT department is designing a new electronic health record system. The security architect proposes that all patient records be encrypted both at rest and in transit, and that access be restricted based on job roles. Which security principle is the architect primarily addressing?
Medium24A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?
Medium25A system administrator is configuring permissions for a new file server. To adhere to the principle of least privilege, which approach should the administrator take?
Easy26A hospital's IT department issues every nurse a unique smart card that must be inserted into a workstation before the nurse types a password. The smart card alone does not grant access to patient records. Which access control concept does the smart card insertion represent?
Easy27A healthcare organization wants to ensure that only authorized clinicians can view patient records, while also maintaining a detailed log of every access for compliance audits. Which security principle is primarily being addressed by restricting access and recording all access attempts?
Medium28During a security incident, the incident response team needs to preserve evidence. Which of the following actions should be performed first?
Medium29A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
Hard30A security analyst reviews server logs and sees that a single service account performed a login from an office workstation at 09:00 and then, two minutes later, executed administrative commands from an external IP address in another country. The account's password is long and complex. Which access control weakness does this pattern most likely indicate?
Medium31According to NIST SP 800-63 recommendations for password policies, which THREE practices are recommended? (Select THREE.)
Hard32A security team discovers that an internal database server is sending large amounts of data to an unknown external IP address. The server is not supposed to communicate externally. Which security control should be implemented to prevent such data exfiltration?
Hard33A financial services company is designing a demilitarized zone (DMZ) for its public web and email relay servers. The security architect wants to reduce the attack surface and limit what an attacker can reach if a DMZ host is compromised. Which two design practices should be implemented? (Choose two.)
Medium34An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?
Medium35During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?
Medium36Which of the following is the best practice for managing cryptographic keys in a large organization?
Hard37A security auditor discovers that a user has been granted read and write access to a sensitive file, but the user's job only requires read access. Which access control principle has been violated?
Hard38During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)
Medium39A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?
Medium40A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?
Medium41According to NIST SP 800-63, which password policy is most recommended?
Medium42A retail company's security policy states that no single employee should be able to both create a vendor payment and approve it. The company assigns these duties to two different people. Which security principle is the policy enforcing?
Medium43In a typical Windows environment, which access control model is used for managing file permissions?
Hard44Which two of the following are examples of physical access controls? (Select TWO)
Easy45A government contractor stores documents with classification labels, and users receive clearances that determine which labels they may access. No user, including administrators, can change a document's label or bypass the label checks. Which access control model does this describe?
Hard46A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)
Medium47An organization implements a rule that an employee cannot approve their own expenses. This is an example of which security principle?
Easy48In Active Directory, a GPO is used to enforce a policy that automatically locks user sessions after 15 minutes of inactivity. This is an example of which type of access control?
Medium49A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?
Easy50A security analyst notices multiple failed login attempts from a single IP address within a short period. Which control would best mitigate this brute force attack?
Medium51A university wants to provide guests with internet access through the same physical wireless infrastructure used by staff, but guests must not reach internal research servers. Staff must authenticate with institutional credentials. Which combination of controls best achieves this separation?
Medium52A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?
Hard53During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?
Hard54A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?
Medium55Which TWO of the following are fundamental security principles? (Select TWO.)
Medium56An organization wants to implement defense in depth for its server room. Which THREE controls should be included?
Hard57Which access control principle restricts access to data based on the user's job role and tasks?
Easy58A security analyst notices that a user's account has been used to access sensitive files outside of normal working hours from an unknown IP address. Which security principle is most directly violated?
Easy59An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?
Easy60A security team identifies that a server has a known vulnerability. A threat actor could exploit it to gain unauthorized access. The combination of these factors represents:
Medium61A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?
Hard62A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?
Easy63A hospital's IT team issues each nurse a unique smart card that is inserted into a workstation before the nurse types a password. The nurse then accesses patient records permitted for the assigned ward. Which combination of access control concepts is being demonstrated?
Easy64Based on the exhibit, which statement about the access control list is true?
Medium65An organisation implements an account lockout policy that locks an account after 5 failed login attempts within 15 minutes. This control is designed to prevent:
Medium66Which of the following best describes a vulnerability in the context of risk management?
Medium67A company's network uses 802.1X authentication for wired and wireless access. Which component authenticates the user credentials against an identity store?
Medium68Which security principle ensures that data cannot be accessed by unauthorized individuals?
Easy69During a routine security audit, an analyst finds that several critical servers have misconfigured firewall rules allowing inbound SSH access from the entire internet. Which immediate action should the analyst take?
Medium70Which authentication type is a smart card an example of?
Easy71Which data classification level typically requires the highest level of protection and is reserved for information that could cause catastrophic harm if disclosed?
Easy72Which TWO of the following are examples of integrity controls? (Select TWO)
Easy73An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?
Medium74A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?
Medium75A user logs into a system using a password and a one-time passcode from a mobile authenticator app. This is an example of:
Medium76An organization decides to accept the risk of using a legacy system that cannot be patched due to critical business operations. This is an example of:
Hard77A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)
Hard78After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?
Easy79A security analyst notices repeated failed login attempts from a single external IP address targeting the company's VPN concentrator. Which type of attack is most likely occurring?
Easy80A security administrator notices that a user with standard privileges was able to modify a system file. Which security principle has been violated?
Easy81A small business wants to provide secure remote access to its internal file server for employees working from home. The company requires that all traffic between the employee's device and the file server be encrypted and that the internal network topology remain hidden. Which technology best meets these requirements?
Easy82A small accounting firm has a single flat network. During a risk review, the consultant recommends placing all wireless guest users on a separate logical network so they cannot reach the internal file server, even though both networks share the same physical switches and access points. Which technology best accomplishes this?
Easy83A data breach exposed customers' names, addresses, and Social Security numbers. Which type of data was compromised?
Medium84To protect the integrity of log files, which of the following is a best practice?
Easy85A defense contractor classifies documents as Confidential, Secret, or Top Secret and assigns each employee a clearance level. Access is permitted only when the employee's clearance meets or exceeds the document's classification, and users cannot change these labels. Which access control model is in use?
Hard86A retail chain wants to prevent customers on its guest wireless from reaching point-of-sale terminals on the corporate wired network, while still allowing guests to browse the internet. The chain already separates the two networks with a firewall. Which additional configuration most directly enforces this restriction?
Hard87An organization decides to implement multiple security controls, including firewalls, intrusion detection systems, and antivirus software. Which security principle does this represent?
Easy88A retail company issues managers a hardware token that generates a one-time code, which they enter after their password when signing in to the payroll system. A help desk technician asks why the company does not simply require longer passwords instead. Which statement best explains the security benefit of the token?
Medium89Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy90An organization is implementing a risk management strategy for a new system. Which THREE actions are examples of risk mitigation?
Hard91An organization is designing a privileged access management (PAM) solution. Which THREE of the following are best practices for managing privileged accounts? (Select three.)
Hard92A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)
Medium93A security team is conducting a risk assessment for a new cloud application. They have identified a vulnerability in the application that could allow unauthorized access to sensitive data. Which three risk management strategies should they consider? (Choose three.)
Hard94A security operations center (SOC) analyst is investigating an alert about a user downloading a suspicious file. The analyst opens the file on a sandboxed virtual machine and observes that it attempts to modify registry keys and establish persistence. This type of analysis is known as:
Hard95An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?
Hard96Which of the following is an indicator of a phishing email?
Easy97A hospital's IT department is choosing a security control to protect patient records. The control must render data unreadable to anyone who does not hold the cryptographic key, even if the storage media is stolen. Which type of control BEST meets this requirement?
Easy98An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?
Medium99During a security assessment, a penetration tester captures unencrypted credentials over the network. Which protocol is most likely being used?
Medium100A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and a public DNS server. The requirement is to ensure that if either public server is compromised, it cannot initiate connections to the internal network. Which design approach best meets this requirement?
Hard101Drag and drop the steps for the incident response process according to NIST into the correct order.
Medium102Drag and drop the steps to create a new VLAN on a managed switch into the correct order.
Medium103An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?
Medium104A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?
Medium105Which of the following is an example of a logical access control?
Easy106A company uses a proxy server for internet access. Employees can browse websites (HTTP/HTTPS), but they cannot connect to external FTP servers using FTP client software (e.g., FileZilla). The proxy is configured to allow HTTP and HTTPS only. The security team wants to allow FTP while maintaining security (e.g., logging and filtering). The FTP traffic is used for occasional file transfers with partners. Which of the following is the BEST solution to meet both requirements?
Medium107A security analyst is reviewing network flow logs and sees periodic outbound connections from an internal server to an external IP address on TCP port 443 every 30 minutes. The connections transfer small amounts of data and the external IP resolves to a newly registered domain. The server has no business need for internet access. Which type of malicious activity is most consistent with this pattern?
Hard108A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?
Hard109Which of the following is a primary goal of security operations?
Easy110A system administrator needs to grant a user the ability to read files in a specific folder but not modify them. Which access control principle should be applied?
Easy111A company requires employees to use biometric authentication to access the data center. This is an example of which security principle?
Easy112In the identification and authentication process, which step occurs first?
Easy113A hospital's IT security team reviews how nurses access patient records. They find that a nurse who works in the cardiology unit can also open records for the oncology unit, even though the nurse never treats those patients. The team wants access decisions to be based on the department a nurse is assigned to plus the specific treatment relationship. Which access control model should they implement?
Medium114An organization implements full-disk encryption on all laptops. Which element of the CIA triad is primarily being addressed?
Easy115Which security control is most effective in preventing unauthorized physical access to a data center?
Easy116An organization labels its financial reports as "Confidential" and requires encryption at rest and in transit. This is an example of:
Hard117A security operations center receives an alert that a workstation is communicating with a known command-and-control IP address over HTTPS on port 443. The endpoint agent shows no malware signature match. Which containment action should the analyst take first to limit damage while preserving the ability to investigate?
Hard118A security administrator needs to ensure that only authorized personnel can access the server room. Which physical control is most appropriate?
Easy119During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?
Medium120Which access control model allows the owner of a resource to decide who can access it?
Easy121A company is deploying a multi-factor authentication (MFA) solution. Which combination represents two different authentication factors?
Medium122A hospital's network team must allow external vendors to reach a specific internal patient-monitoring system without exposing the rest of the clinical VLAN. The solution must enforce least privilege and terminate vendor sessions at a hardened appliance before any internal resource is contacted. Which technology best meets these requirements?
Medium123Which THREE of the following are core principles of the CIA triad?
Medium124Match each security control type to its description.
Medium125A security team decides to implement multi-factor authentication for all remote access. Which combination of factors would constitute multi-factor authentication?
Medium126Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)
Hard127A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?
Easy128What is the process of claiming an identity called?
Easy129Which of the following ports is used by HTTPS for secure web traffic?
Medium130A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)
Medium131A security manager is developing a disaster recovery plan for a critical database. The manager needs to determine the maximum tolerable downtime (MTD) for the database. Which of the following should the manager consider FIRST when establishing the MTD?
Medium132A software development company wants to ensure that only authorized code changes are deployed to production. They implement a process where developers submit code changes, and a separate team reviews and approves them before deployment. Which security principle is BEST demonstrated by this process?
Hard133Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?
Medium134A security team is reviewing how access control is enforced across a corporate environment. Which two statements accurately describe the relationship between identification, authentication, and authorization? (Choose two.)
Medium135Which TWO are examples of technical access controls?
Easy136An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?
Easy137Which TWO of the following are primary goals of the security principle of confidentiality?
Medium138Which OSI layer is responsible for logical addressing and routing?
Easy139A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?
Hard140Which of the following is an example of a detective control in a security operations context?
Easy141A small design studio stores client files on a shared server. Each project folder is owned by the designer who created it, and that designer decides which colleagues may open the folder by granting permissions directly to individual accounts. Which access control model is the studio using?
Easy142A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)
Medium143An organization wants to protect against man-in-the-middle attacks on a switched network. Which TWO measures should be implemented? (Choose two.)
Easy144A security analyst is reviewing endpoint logs and sees repeated entries showing that a process attempted to modify the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa and then attempted to read the SAM database file. The process is not a known administrative tool and was launched from a user's temporary folder. Which type of activity is MOST likely occurring?
Medium145A security team implements a load balancer to distribute traffic across multiple web servers. This control primarily supports which principle?
Medium146A company needs to enforce access based on attributes such as time of day and location. Which access control model is most appropriate?
Medium147A company uses a stateful firewall. A user reports that an application requiring multiple dynamic ports is not working. The firewall logs show that packets from the server are being dropped. What is the most likely cause?
Hard148Which three of the following are benefits of using VLANs in a network? (Choose three.)
Medium149An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?
Medium150An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?
Medium151What is the primary difference between an IDS and an IPS?
Easy152A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)
Medium153According to the (ISC)² Code of Ethics, which canon has the highest priority?
Hard154Which THREE of the following are key objectives of a security risk management program?
Medium155A system administrator has an account with full administrative privileges. To reduce risk, the organization implements a policy requiring the admin to use a separate, non-privileged account for daily tasks like email and web browsing. This practice aligns with which principle?
Medium156A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:
Hard157After a security incident, the incident response team closes the case. What is the MOST important final step to improve future security posture?
Hard158An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?
Easy159A help desk technician receives a report that a user cannot access a shared network drive. The technician checks the file server and sees that the disk is full. What is the most immediate action the technician should take?
Easy160During a security audit, it is discovered that a contractor has access to customer databases that were not required for their project. Which step should be taken first to mitigate the risk?
Hard161Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?
Easy162A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?
Medium163A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?
Medium164A SOC analyst is reviewing logs from a web server and sees the following entry: GET /../../../../etc/passwd HTTP/1.1 Which type of attack is being attempted?
Medium165An organization wants to implement the principle of least privilege for its database administrators. Which approach best achieves this goal?
Medium166A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?
Medium167Which access control principle ensures that a user is granted only the minimum permissions necessary to perform their job functions?
Easy168A retail company issues contract workers temporary accounts that automatically expire after 30 days, and it reviews all active accounts each quarter to remove those no longer needed. Which access control administration practice does the quarterly review represent?
Medium169A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?
Medium170A financial services firm suffers a ransomware outbreak that encrypts file servers and the backup catalog. The incident response team must decide the immediate next step while the attack is still spreading. Which action BEST aligns with the containment objective of the incident response plan?
Medium171Which of the following is a benefit of using VLANs in a network?
Easy172An organization's password policy requires passwords to be at least 8 characters long and prohibits common passwords found in breach databases. This policy aligns with which guideline?
Hard173An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?
Medium174A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:
Easy175A small marketing firm wants to give each employee a single set of credentials that works for the corporate email system, the cloud CRM, and the internal file share. The IT manager proposes using a central identity store so users do not have to remember separate passwords. Which concept is the IT manager describing?
Easy176An organization has multiple network segments for accounting, HR, and engineering. They want to prevent unauthorized traffic between segments while allowing necessary communication. Which security control should be implemented?
Easy177A security administrator is concerned about MAC address spoofing on the network. Which technology can help mitigate this risk by associating a specific MAC address with a port?
Medium178A company deploys a new intrusion detection system (IDS) on the internal network. Which of the following best describes the primary purpose of this system?
Medium179An organization is implementing a visitor management policy. Which THREE should be included? (Select THREE.)
Hard180An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?
Hard181A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?
Medium182An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?
Hard183A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?
Medium184A hospital's biomedical team connects a new MRI workstation to the clinical VLAN. The workstation must reach a PACS archive on a different subnet, but the team reports that no traffic leaves the workstation. A technician confirms the workstation has an IP address of 10.20.30.44/24 and the PACS archive is 10.20.40.10/24. Which device should the workstation be configured to use as its default gateway?
Easy185An organization implements an access control system where users are assigned to groups, and permissions are granted to groups rather than individuals. This is known as:
Easy186A financial services firm has a recovery time objective (RTO) of 2 hours for its trading platform and a recovery point objective (RPO) of 15 minutes. The disaster recovery team is evaluating whether a warm site can meet these requirements. Which statement best describes the limitation of a warm site in this scenario?
Hard187Which of the following is an example of a vulnerability?
Medium188During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?
Hard189An employee reports receiving a suspicious email with an attachment from an unknown sender. What is the first action the employee should take?
Easy190A security manager is mapping several controls to the categories of administrative, technical, and physical. Which TWO of the following are administrative controls? (Choose two.)
Hard191An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?
Hard192Refer to the exhibit. Based on the exhibit, why was the packet denied?
Easy193A security analyst is implementing controls to protect the integrity of a database. Which TWO of the following controls would best achieve this goal?
Medium194A financial firm has a data center with strict access controls. Employees must use smart cards and PINs to enter a mantrapped entrance. Recently, an unauthorized person gained access by following an employee through the mantrapped door (tailgating). The security team reviews logs and finds that the door was opened twice in quick succession, indicating tailgating occurred. The firm wants to implement a solution that prevents tailgating without slowing down authorized access. Which action should they take?
Hard195A security analyst is assessing the risk associated with a new web application. The analyst identifies that the application has a SQL injection vulnerability, and there is a known exploit available that could allow an attacker to extract sensitive data. The application is exposed to the internet and is used by customers. Which two factors are most directly involved in determining the level of risk? (Choose two.)
Hard196A SOC analyst reviews an alert indicating a high number of failed login attempts from a single external IP address targeting multiple user accounts. Which security control is most effective at preventing this type of attack?
Easy197A company's security policy requires that all incident response activities be logged and that evidence be preserved for potential legal action. During an incident, a responder mistakenly uses a personal USB drive to copy log files. Which principle of forensic evidence handling has been violated?
Hard198An LDAP distinguished name is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. What does OU represent?
Hard199A data center manager wants to strengthen physical access control at the main entrance while keeping the process practical for employees arriving each morning. Which two measures BEST align with sound physical access control practices? (Choose two.)
Medium200Which of the following is a recommended practice for administrative accounts?
Easy201A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)
Hard202A security operations center (SOC) analyst receives an alert for a potential malware infection on a workstation. Which of the following is the first action the analyst should take?
Easy203Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?
Hard204According to NIST SP 800-63, which password policy is recommended to enhance security?
Medium205A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?
Hard206A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?
Medium207A company is implementing a security information and event management (SIEM) system. Which data source is most critical for detecting an ongoing brute-force attack?
Medium208An organization has detected a ransomware infection. What is the FIRST step in the incident response process?
Medium209An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?
Medium210Which THREE of the following are examples of implementing defense in depth? (Select THREE.)
Hard211A company requires that financial transactions be approved by two different managers before execution. This is an example of which access control principle?
Easy212A security engineer is reviewing logs and notices that an internal server is receiving excessive SYN packets from an external IP, but never completing the three-way handshake. What type of attack is likely occurring?
Hard213Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?
Medium214Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?
Easy215Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?
Easy216Which TWO of the following are types of security controls used in defense in depth? (Select TWO.)
Easy217A security operations center (SOC) analyst receives an alert for a high volume of outbound traffic from an internal server to a known malicious IP address. Which step should the analyst take next?
Medium218Which TWO of the following are core components of the ISC2 Code of Ethics? (Choose two.)
Medium219An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?
Medium220A software developer is designing a web application that will store user credentials. What is the most secure method for storing passwords?
Hard221An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
Medium222A large organization has implemented a Security Operations Center (SOC) with a tiered incident response model. Tier 1 analysts triage alerts and escalate confirmed incidents to Tier 2 for deeper analysis. Recently, the SOC has been overwhelmed by a high volume of low-severity alerts from endpoint detection and response (EDR) tools, causing delays in handling true positive incidents. The SOC manager wants to reduce alert fatigue without missing critical threats. Which of the following strategies would be MOST effective?
Hard223A network administrator needs to ensure that sensitive financial data remains confidential while in transit over the internet. Which technology should they implement?
Medium224A financial services firm assigns permissions based on the department a user belongs to, such as 'Teller', 'Loan Officer', or 'Auditor'. When an employee transfers from Teller to Loan Officer, their Teller permissions are removed and Loan Officer permissions are added automatically. Which access control model is being used?
Medium225An organization is designing a defense-in-depth strategy for physical security. Which of the following are examples of layered physical controls? (Choose THREE.)
Hard226A software company's incident response plan defines a severity level of 'Critical' for incidents that cause a complete outage of customer-facing services. A developer accidentally deploys a faulty update that crashes the production web servers, making the service unavailable to all customers. Which incident response phase should the team be in when they apply a rollback to the previous working version?
Medium227A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?
Hard228Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?
Medium229Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?
Easy230A user reports that they received a suspicious email with an attachment claiming to be an invoice. What should the user do?
Easy231A security manager is advised to implement 'due care' in their organization. Which action best exemplifies due care?
Hard232A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?
Medium233A financial services firm is designing controls to enforce separation of duties in its payment approval process. Which two practices support this goal? (Choose two.)
Hard234A security analyst reviews firewall logs and sees a series of outbound connections from an internal server to a known command-and-control (C2) IP address at regular intervals. Which step should the analyst take first according to incident response best practices?
Hard235An organization's BCP identifies a customer-facing order system as critical. The BIA shows the business can tolerate 12 hours of downtime and 1 hour of data loss. The current architecture uses nightly full backups to tape with a 10-hour restore time. Which change BEST closes the gap between current capability and the stated requirements?
Hard236A payroll clerk can view and edit employee salary records but cannot approve her own expense reimbursements, even though she processes reimbursements for other staff. Which access control principle does the restriction on approving her own reimbursements best illustrate?
Easy237A security team is designing a physical access control system for a data center. They want to implement controls that verify a person's identity based on unique biological characteristics. Which two of the following are examples of biometric access controls? (Choose two.)
Medium238A security architect is designing an access control policy based on the principle of need-to-know. Which TWO practices support this principle? (Select TWO.)
Hard239A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?
Easy240Which of the following is a common mitigation technique for a SYN flood attack?
Hard241Which TWO of the following are examples of implementing the principle of least privilege?
Hard242A small business wants to prevent employees from visiting known malicious websites. The owner asks for a solution that can block requests based on a constantly updated list of harmful domains without requiring software on each employee device. Which technology should be recommended?
Easy243An LDAP distinguished name is written as: CN=John Smith,OU=Sales,DC=company,DC=com. What do the 'OU' and 'DC' components represent?
Hard244Which protocol is considered insecure because it transmits data in cleartext, including passwords?
Easy245Which TWO of the following are examples of Type 3 (inherence) authentication factors?
Easy246A financial services firm is deploying a new customer portal. Auditors have required that access decisions consider the user's department, the data classification of the record, the time of day, and whether the request originates from a managed corporate device. The security architect proposes Attribute-Based Access Control (ABAC). Which two statements correctly describe how ABAC satisfies these requirements? (Choose two.)
Hard247Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy248A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?
Easy249After a major DDoS attack, a company deploys redundant internet connections and load balancers to ensure continued access to its web services. Which principle of the CIA triad is being strengthened?
Hard250An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)
Hard251A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?
Medium252A hospital's IT department wants to ensure that only authorized clinicians can view patient records, while also guaranteeing that those records have not been tampered with. Which security principle is primarily concerned with preventing unauthorized disclosure of the records?
Easy253A security analyst at a mid-sized company is reviewing network traffic logs and notices that an internal host is repeatedly sending TCP SYN packets to many different external IP addresses on port 443, but never completing the three-way handshake. The analyst suspects a malware infection. Which type of attack is most likely occurring?
Medium254A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?
Medium255During a phishing investigation, a security analyst identifies that an employee clicked a malicious link. The analyst isolates the workstation. What is the NEXT best step?
Medium256An organization has implemented a network-based intrusion prevention system (IPS) in inline mode. After deployment, users report that legitimate web traffic is being blocked. What is the most likely cause?
Medium257During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?
Medium258A company's network uses a perimeter firewall and an internal firewall. The DMZ sits between them. A new application server needs to be accessible from the internet on TCP port 8443 and must be able to make outbound HTTPS connections to an external license server. Which firewall rules should be implemented? (Assume default deny)
Hard259An e-commerce company notices that its product reviews are being scraped by automated bots far more aggressively than expected, and the resulting traffic is degrading checkout performance for real customers. The security team wants a control that slows automated abuse without challenging legitimate buyers. Which security principle does this control primarily support?
Medium260An organization implements a role-based access control (RBAC) system. To maintain the principle of least privilege, what should the administrator do when a user changes roles?
Hard261Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?
Easy262An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?
Easy263Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?
Medium264Which authentication factor does a smart card represent?
Easy265A network engineer is configuring a firewall rule to allow inbound HTTPS traffic to a web server. Which port must be opened?
Easy266A security auditor discovers that a user's account has been granted full access to all financial databases, even though the user only needs to view quarterly reports. Which access control principle has been violated most directly?
Hard267A Privileged Access Management (PAM) solution is used to:
Hard268A security analyst is reviewing event logs and notices multiple failed login attempts from a single IP address followed by a successful login. Which TWO actions should the analyst take next?
Easy269A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?
Medium270A retail chain wants to reduce the chance that a former employee can still access the point-of-sale system weeks after leaving the company. The security manager proposes a control that automatically disables accounts on the employee's last working day. Which type of control is this?
Easy271A company's security policy mandates that all changes to the firewall configuration must be approved by two different administrators before implementation. This is an example of which security principle?
Medium272An organization uses a layered security approach: perimeter fencing, access badge readers at building entrances, biometric scanners in server rooms, and cable locks on laptops. This strategy best exemplifies which access control concept?
Hard273An organization requires that financial transactions over $10,000 be approved by two different managers. This is an example of which access control principle?
Medium274A hospital's data center uses a mantrap at its main entrance. A nurse badges in at the outer door, steps into a small glass vestibule, and the outer door locks before the inner door unlocks. What security goal does this design primarily achieve?
Easy275A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?
Medium276An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)
Hard277An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?
Hard278A small company with 50 employees uses a flat network with no VLANs. They recently experienced a ransomware attack that spread from an infected workstation to a file server. The IT manager wants to implement network segmentation to prevent future lateral movement. The company uses a single /24 subnet (192.168.1.0/24) with a single switch and a router/firewall. They have three departments: Sales, HR, and IT. Each department has about 15-20 computers. The file server is in the IT department. The company has a limited budget and cannot purchase new hardware. Which of the following is the MOST effective and practical approach to segment the network given these constraints?
Medium279A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?
Medium280A company's security policy states that sensitive data must be encrypted using AES-256. During an audit, it is found that some data is encrypted with AES-128. Which security objective is most directly compromised?
Hard281What is the primary purpose of a Security Information and Event Management (SIEM) system?
Easy282Which TWO are examples of logical access controls? (Select TWO.)
Easy283A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?
Medium284A security administrator notices that an employee is able to access files in a project folder they should not have access to. Which security principle is being violated?
Easy285A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?
Medium286A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?
Hard287Which data classification level typically requires the highest level of protection?
Easy288A network administrator notices unusual traffic from an internal workstation to an external IP address on port 443. The workstation has no business reason for such communication. Which action should the administrator take first?
Easy289A financial services firm is classifying a risk by estimating how often a particular attack is likely to succeed in a given year. Which risk concept is the firm measuring?
Medium290A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)
Medium291Which concept ensures that a user cannot deny having performed a specific action?
Easy292An organization is developing a data classification policy. Which THREE of the following should be classified as Confidential or higher? (Select THREE)
Hard293A security operations center receives an alert that a workstation has been infected with ransomware. The infection is isolated to one machine. What is the first step in the containment phase of incident response?
Easy294A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)
Medium295A company configures its firewall to block all inbound traffic except for specific necessary services. This approach aligns with which access control principle?
Medium296Which three of the following are best practices for securing a network switch? (Choose three.)
Medium297After a reorganization, a company using RBAC finds that many users have accumulated permissions that no longer align with their job functions. What is the best practice to address this?
Medium298A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?
Medium299A mid-sized accounting firm is drafting its first information security policy. The partners want the policy to address governance responsibilities clearly so that security decisions are made consistently at the right levels. Which TWO of the following are governance responsibilities that the policy should assign? (Choose two.)
Medium300An organization configures account lockout after 5 failed login attempts within 15 minutes. This control is designed to mitigate which type of attack?
Medium301After a ransomware attack, the company wants to ensure that critical data can be restored. Which principle is being addressed?
Medium302Match each security policy type to its focus.
Medium303A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor plans to publish a hash of the patch file on its website alongside the download. A security consultant warns that this approach alone is insufficient. Why is publishing only a hash inadequate for this goal?
Hard304A financial services firm conducts an annual test of its business continuity plan. Management wants to evaluate how well the team performs its roles and procedures during a simulated disruption without actually moving operations to alternate sites. Which type of exercise BEST meets this requirement?
Hard305During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?
Hard306Which TWO are essential elements of a business impact analysis (BIA)?
Medium307After a security breach, the organization conducts a background check on a new vendor before signing a contract. This practice is known as:
Hard308A healthcare provider's incident response team is handling a breach of patient records. The team has contained the breach and is now eradicating the threat. Which of the following activities is MOST appropriate during the eradication phase?
Medium309A hospital wants to ensure that patient records can only be viewed by authorized clinical staff, and that any modification to a record is traceable to the individual who made it. Which security principle directly supports both of these requirements?
Easy310An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
Medium311A network administrator is configuring a new wireless network for a small office. The office manager wants to ensure that only authorized employees can connect and that traffic between wireless clients is encrypted. Which security protocol should the administrator implement?
Easy312A company conducts a background check on a new vendor before signing a contract. This activity is an example of:
Hard313In the context of identification and authentication, which of the following is an example of authentication?
Medium314After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?
Medium315A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?
Easy316A financial services firm classifies documents as Public, Internal, Confidential, and Restricted. Access to Restricted documents is determined solely by the document's classification label and the user's clearance level, and users cannot change either value. Which statement best describes this arrangement?
Medium317A company's web server is experiencing a high volume of traffic from thousands of different IP addresses, causing service degradation. The security team determines it is a distributed denial-of-service (DDoS) attack. Which mitigation strategy is most effective for this scenario?
Medium318A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?
Hard319An organization is implementing a patch management program. Which of the following is the BEST approach to minimize risk while maintaining operational stability?
Medium320A network administrator needs to provide secure remote access to internal resources for employees working from home. The solution must encrypt all traffic and authenticate users before granting access. Which protocol should be used?
Easy321A hospital's security team wants to detect when an attacker is probing its internal network for open ports, but the team must not block legitimate clinical traffic because doing so could interrupt patient care. The team decides to deploy a solution that only alerts on suspicious activity. Which type of solution best matches this requirement?
Medium322A company is planning its backup strategy and wants to balance storage efficiency with restore speed. Which TWO backup strategies should the company consider? (Select TWO)
Hard323A company wants to ensure that a message received was not altered in transit. Which principle is of primary concern?
Medium324A cloud-hosted retailer's disaster recovery plan relies on backups stored in the same cloud region as production. A regional outage takes the production environment offline. Which weakness does this scenario PRIMARILY expose in the disaster recovery strategy?
Medium325A security team wants to detect when an attacker is using a compromised account to move laterally between servers inside the network. Which monitoring approach would best surface this activity?
Medium326A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:
Medium327During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?
Medium328Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?
Easy329Which type of access control is implemented by a cable lock attached to a laptop?
Easy330A security analyst is reviewing network logs to detect potential intrusions. Which TWO of the following are examples of network-based indicators of compromise? (Choose two.)
Medium331A company's physical security includes fencing, security guards, access badges, and biometric locks on server room doors. This layered approach is an example of which access control concept?
Medium332A security analyst is reviewing access control models. Which two of the following are characteristics of the principle of least privilege? (Choose two.)
Hard333A company uses redundant servers and automated failover to ensure that its website remains accessible during a server outage. Which principle of the CIA triad is being addressed?
Medium334Which type of authentication factor involves something the user knows?
Easy335A company has implemented a role-based access control (RBAC) system. A new employee in the finance department is granted the 'Finance User' role, which allows them to view invoices but not create payments. However, after a system upgrade, it is discovered that the 'Finance User' role now includes the ability to create payments due to a misconfiguration. The employee did not request this additional privilege and has not exploited it. The security team is notified. Which principle has been violated, and what is the most appropriate immediate action?
Hard336An organization's security policy requires that all access to sensitive data must be approved by a data owner. An administrator configures a system to enforce this. Which principle is being implemented?
Hard337A security administrator is reviewing the organization's authentication controls and wants to strengthen them by adding factors from different categories. Which TWO of the following represent distinct authentication factor categories that can be combined to achieve multi-factor authentication? (Choose two.)
Medium338A company performs background checks on potential employees before hiring. This action demonstrates which concept?
Medium339Which THREE of the following are considered risk management strategies? (Select THREE)
Hard340Which TWO of the following are examples of sensitive PII? (Select TWO.)
Medium341Drag and drop the steps to recover a system from a verified backup after a ransomware attack into the correct order.
Medium342A session timeout automatically logs out a user after a period of inactivity. This control primarily protects against:
Hard343A system administrator accidentally grants a user full administrative rights instead of read-only. Which control would best detect this error?
Hard344An online retailer stores customer credit card numbers. Management decides to retain only the last four digits and delete the full numbers after payment authorization. Which security principle does this decision best illustrate?
Hard345A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?
Easy346An employee uses their username to claim an identity and then enters a password to prove it. What is the term for the process of proving the claimed identity?
Medium347When implementing multi-factor authentication, which combination of factors is considered strongest?
Medium348An organization is reviewing its security governance framework. Which TWO of the following are primary objectives of security governance? (Choose two.)
Medium349During a forensic investigation, it is crucial to preserve the original evidence. What is the first step the investigator should take when acquiring a hard drive?
Medium350An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?
Medium351A mid-sized hospital experiences a ransomware outbreak that encrypts its electronic health record (EHR) servers on a Friday night. The incident response plan designates a severity classification of 'Critical'. According to established incident response practices, which action should the incident response team take FIRST?
Medium352A company is implementing separation of duties for financial transactions. Which of the following are examples of this principle? (Choose TWO.)
Hard353A multinational corporation has a policy that all sensitive emails must be digitally signed and encrypted. However, during a recent internal audit, it was discovered that many employees were not using digital signatures because the process was cumbersome. As a result, the company could not prove that certain emails were actually sent by the claimed sender. The security team needs to improve compliance without sacrificing security. Which of the following is the best approach?
Hard354A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)
Medium355In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
Medium356An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)
Medium357Which TWO are appropriate methods to test a disaster recovery plan?
Hard358A security administrator is configuring a session timeout policy. Which of the following are valid reasons for implementing session timeouts? (Choose TWO.)
Medium359A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?
Medium360A security analyst reviews firewall logs and notices a large number of outbound connections from a single internal IP to a known malicious IP on port 445. The analyst quarantines the workstation and runs an antivirus scan, which finds no malware. What should the analyst do next?
Hard361A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?
Medium362A small clinic stores patient records on a server. The IT administrator ensures that only authorized staff can view these records, and that the records remain accurate and available when needed. Which security principle is best illustrated by restricting access to the records?
Easy363Which backup strategy offers the fastest restore time but requires the most storage space?
Medium364During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?
Hard365Which THREE are key components of Active Directory? (Select THREE.)
Medium366Which THREE are core components of the CIA triad? (Choose three.)
Easy367What is the difference between due care and due diligence in security governance?
Medium368An analyst reviews the exhibit. Which security principle is being violated by allowing root login via SSH?
Medium369Drag and drop the steps to configure a wireless access point with WPA2-PSK security into the correct order.
Medium370During an incident, a responder needs to capture the contents of volatile memory on a running Linux server before shutting it down, because encryption keys and running processes may only exist in RAM. Which action BEST preserves this volatile evidence?
Hard371A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?
Easy372A security administrator notices that a user's account has been used to access sensitive files at unusual hours. Which security principle would most effectively help detect this type of activity?
Easy373A retail company is designing its access control program and wants to rely on attributes such as the user's department, the sensitivity label of the data, and the current time of day to make access decisions. Which TWO of the following statements accurately describe attribute-based access control (ABAC)? (Choose two.)
Medium374A new employee at a marketing firm receives a company laptop, a proximity badge, and a one-time password token on their first day. Before being allowed to log in, the employee must enter their employee ID, then a code from the token, then scan the badge. Which access control concept does the employee ID represent in this sequence?
Easy375A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?
Hard376During a security incident, the incident response team needs to preserve evidence for potential legal action. Which of the following is the most important action to take when collecting volatile data from a compromised server?
Medium377During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?
Hard378A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?
Hard379A security manager is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The manager needs to identify which of the following are considered threats rather than vulnerabilities or risks. (Choose two.)
Medium380An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?
Medium381During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?
Medium382A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?
Medium383Which THREE of the following are examples of risk mitigation? (Select THREE)
Hard384An organization uses fencing, bollards, and lighting around the perimeter, guards at the main entrance, and biometric readers on server room doors. This approach is an example of:
Easy385Drag and drop the steps for the TCP three-way handshake into the correct order.
Medium386A company's security operations center (SOC) receives an alert about suspicious outbound traffic from a server in the DMZ to an external IP address known for command-and-control activity. The SOC analyst reviews the logs and sees that the source port is 443 and the destination port is 8080. Which of the following actions should the analyst take FIRST?
Medium387Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)
Hard388A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)
Medium389The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?
Hard390Which TWO of the following are recommended practices for managing privileged accounts? (Select TWO.)
Medium391Which TWO of the following are examples of security principles?
Easy392Which of the following is the primary purpose of a security information and event management (SIEM) system?
Easy393A financial services firm grants tellers access to the transaction system only between 8:00 a.m. and 6:00 p.m. on business days, regardless of the teller's role. Access requests outside that window are automatically denied, and the restriction is enforced by a centrally managed policy that tellers cannot modify. Which access control approach is being applied?
Hard394An organization uses a digital signature to verify the authenticity of a software update. This supports which part of the CIA triad?
Medium395Match each risk management term to its meaning.
Medium396A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?
Hard397A company classifies its data into four categories: Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?
Medium398A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?
Medium399Which of the following is an example of Type 2 authentication?
Easy400A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).
Hard401A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?
Hard402A mid-sized company has a network with 200 employees. The security team has implemented a policy that requires all employees to use complex passwords and change them every 60 days. However, the company has experienced multiple phishing attacks where employees have willingly provided their credentials to fake websites. The CEO wants to implement a more robust authentication method. The company uses Microsoft Active Directory and has a budget for new security tools. They also have a remote workforce. Which of the following is the BEST course of action to address the phishing risk?
Medium403A company deploys a web application firewall (WAF), performs regular vulnerability scans, and implements strict access controls. Which security principle is being applied?
Medium404A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?
Hard405A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?
Medium406A security administrator is configuring a system to detect unauthorized changes to critical files by calculating and storing a hash value for each file. Which security goal is primarily supported?
Medium407A security consultant is evaluating a vendor's security practices before signing a contract. The consultant reviews the vendor's security policies, incident response plans, and conducts background checks on key personnel. This activity is an example of:
Hard408During a security audit, it is discovered that a single administrator can create user accounts, assign privileges, and review audit logs. Which principle is most likely being violated?
Medium409An organization decides to accept the risk of using an older software version known to have vulnerabilities because the cost of upgrading outweighs the potential impact. This is an example of:
Hard410A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?
Medium411A security analyst receives an alert from the SIEM indicating a potential data exfiltration event. The alert shows a large volume of data being transferred to an external IP address during non-business hours. What is the MOST appropriate immediate action?
Hard412A security analyst notices that an employee who transferred from Finance to Marketing still has full access to financial reporting systems six months later. The analyst wants to correct this through the access control lifecycle. Which action best addresses the root cause?
Hard413Which control type is considered a physical security control?
Easy414Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)
Easy415Drag and drop the steps to perform a password reset on a Windows user account into the correct order.
Medium416Which is a key benefit of a cold site as a recovery location?
Medium417Which TWO of the following are examples of Type 3 authentication? (Select TWO).
Medium418A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:
Medium419A security professional is implementing a file integrity monitoring (FIM) system on critical servers. Which element of the CIA triad does this primarily address?
Easy420A hospital IT team is reviewing how staff access patient records. A nurse logs in with a unique employee ID, then enters a password plus a one-time code from a hardware token. The team wants to document which access control category this login process represents. Which category BEST describes this approach?
Easy421A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?
Hard422A retail company's business continuity plan includes a requirement to test its disaster recovery capabilities annually. The IT team proposes conducting a tabletop exercise with key stakeholders. Which benefit does this type of test provide?
Medium423Which THREE of the following are common components of a disaster recovery plan?
Easy424Which incident category involves an attempt to make a system or network resource unavailable to its intended users?
Medium425A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?
Easy426Which three ports are commonly used by secure protocols? (Choose THREE.)
Medium427A company uses a mandatory access control (MAC) system where all files are labeled 'Confidential', 'Secret', or 'Top Secret'. A user with 'Secret' clearance tries to read a 'Top Secret' file. What is the outcome?
Hard428An organization is developing a security policy. Which TWO of the following are core components of the CIA triad?
Medium429An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?
Medium430A software development company wants to ensure that only authorized code changes are deployed to production. The security team proposes that developers should not have direct write access to the production environment, and that all code must be reviewed and approved by a different team member before deployment. Which security principle does this proposal primarily enforce?
Hard431In an LDAP directory, an entry is represented as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?
Hard432A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?
Medium433An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?
Easy434A defense contractor runs a facility where entry to the secure lab requires a fingerprint scan, and entry to the adjacent server cage additionally requires a retina scan. A security analyst is documenting the access control design for an audit. Which two statements accurately describe these controls? (Choose two.)
Hard435Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?
Medium436A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?
Medium437A security architect is designing controls to protect a data center. Which TWO of the following are examples of physical access controls? (Select TWO.)
Hard438Which THREE of the following are considered essential security principles according to ISC2?
Hard439An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)
Hard440A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)
Hard441An account lockout policy is implemented to protect against which type of attack?
Medium442Which THREE of the following are essential components of an incident response plan? (Select THREE.)
Hard443A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)
Hard444During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?
Hard445During a security incident, the incident response team isolates a compromised workstation from the network. What is the primary purpose of this action?
Medium446You are an IT administrator for a small business. The company has a backup system that performs nightly full backups of critical servers to an external hard drive. One morning, a user reports that they accidentally deleted an important file from a shared drive. You need to restore the file from last night's backup. However, when you connect the external hard drive to the backup server, the drive is not recognized, and you hear clicking sounds. The backup software shows that the most recent backup job completed successfully with no errors. What is the most likely cause of the problem?
Easy447A security analyst is implementing controls to prevent unauthorized disclosure of sensitive information. Which element of the CIA triad is being addressed?
Easy448A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)
Medium449A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?
Medium450An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?
Medium451A security analyst notices repeated failed login attempts from a single IP address targeting multiple user accounts. Which security control should be implemented to mitigate this attack?
Easy452An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)
Hard453Which of the following is a primary benefit of implementing network segmentation?
Easy454Which THREE components are part of the AAA framework?
Hard455An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?
Easy456A software company uses a central identity provider so employees can sign in once and access email, the code repository, and the expense system without entering credentials again during the workday. The security team wants to describe the mechanism that lets the identity provider assert the user's identity to each application. Which technology is being used?
Medium457A software vendor wants customers to verify that a downloadable patch truly came from the vendor and was not modified in transit. The vendor signs the patch with its private key. Which security property does this provide to customers who verify the signature with the vendor's public key?
Hard458Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?
Medium459In a directory service like Active Directory, which component is used to organize users, groups, and computers into a hierarchical structure for applying policies?
Medium460During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)
Medium461A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)
Hard462Which of the following is a connectionless, unreliable transport protocol?
Easy463A security auditor discovers that during a VLAN hopping attack, a threat actor was able to send frames from a workstation on VLAN 10 to a target on VLAN 20. Which configuration flaw is most likely responsible?
Hard464A cloud administrator notices that several engineers share one privileged account with a single set of credentials for managing production databases. An audit finds no way to attribute a specific change to a specific engineer. Which access control weakness does this represent?
Hard465A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)
Medium466A company stores customer PII including social security numbers and medical records. Under privacy principles, these data elements are best described as:
Hard467A security analyst notices repeated failed login attempts to a critical server from a single external IP address. Which immediate action should the analyst take?
Easy468A security engineer is designing a DMZ for a web server that must be accessible from the internet. The web server needs to query an internal database server. Which network security approach best limits exposure?
Medium469Which TWO of the following are examples of preventive security controls?
Easy470Which of the following best describes the purpose of a session timeout?
Easy471Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?
Easy472A user enters a username and password to access a system. Which phase of the access control process does entering the username represent?
Medium473Which layer of the OSI model is responsible for routing packets based on IP addresses?
Easy474A company experiences a ransomware attack that encrypts its file servers. The security team restores operations from offline backups taken the previous night. Which security principle does the restoration from backups primarily support?
Medium475An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?
Medium476An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?
Medium477During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?
Hard478Refer to the exhibit. A security analyst reviews this log entry. What type of attack is most likely occurring?
Medium479A network administrator is configuring a new wireless network for a small office. The office has sensitive data and wants to ensure that all wireless traffic is encrypted and that users authenticate with unique credentials. Which security protocol should the administrator implement?
Easy480A financial services firm must enforce access decisions based on data sensitivity labels assigned by a central authority, and users cannot change these labels or grant access to others. Which access control model is the firm implementing?
Hard481A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?
Hard482An organization wants to ensure the integrity of a software update before deployment. Which two methods can be used to verify integrity? (Choose two.)
Easy483An organization wants to ensure that even if an attacker compromises a user's account, the damage is limited. Which principle is most directly applied?
Hard484A financial institution has a security operations center that monitors network traffic using a SIEM. The SIEM receives logs from all network devices, servers, and endpoints. One analyst notices an anomaly: a user account, 'jsmith', which is normally used during business hours (9 AM to 5 PM), has been logging in from a remote IP address at 2 AM every day for the past week. The logins are successful, and the user is accessing internal file shares. The user jsmith works in the accounting department and has access to sensitive financial reports. The analyst checks the user's workstation logs and finds that the workstation is powered off at the time of the remote logins. The company uses two-factor authentication, but the log entries show that only the password was used. Which of the following is the most likely explanation and the best immediate action?
Hard485An organization wants to ensure that system logs are tamper-proof after generation. Which control should be implemented?
Easy486A financial services company wants to ensure that a terminated employee cannot continue to use an active badge to enter the building after their last day. The security manager reviews physical access control procedures. Which control type is being applied when the badge is deactivated in the access control system?
Medium487A security officer at a healthcare provider is reviewing the organization's risk management program. The officer must distinguish between threats and vulnerabilities when documenting risks. Which two of the following are examples of vulnerabilities rather than threats? (Choose two.)
Hard488A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?
Hard489A financial services firm has a data center that houses customer financial records. They have implemented a defense-in-depth strategy including firewalls, IDS/IPS, and encryption. Recently, an internal audit revealed that a junior administrator has been logging into the database server with a shared admin account and has made unauthorized changes to customer records. The company wants to prevent such incidents in the future while maintaining operational efficiency. The current environment uses Linux servers with PostgreSQL databases. There is no centralized authentication system. What is the BEST action to take?
Hard490In a directory service using LDAP, what is the distinguished name (DN) for a user named John Smith in the Sales organizational unit of the company domain company.com?
Hard491A security engineer is designing a backup strategy for a critical database. The database must be recoverable within four hours in the event of a failure. Which security principle primarily drives this requirement?
Medium492A security administrator is configuring a system to prevent unauthorized access after a user leaves their workstation unattended. Which access control mechanism should be implemented?
Medium493In a defense-in-depth strategy, which access control mechanism provides the most granular control over user permissions?
Hard494A company's security policy requires that employees use only the minimum permissions needed to perform their job functions. This practice reduces the potential impact if an account is compromised. Which TWO access control principles are being applied?
Medium495You are a security analyst at a mid-sized financial firm. The company has a policy that all remote access must be secured using a VPN. Recently, an employee reported that they were able to connect to the internal network from a coffee shop without using the VPN client. The employee accidentally left the client running but it was not authenticating. Upon investigation, you find that the network administrator had configured a rule on the firewall to allow RDP traffic from any public IP to a specific internal server for maintenance purposes. The rule was supposed to be temporary but was never removed. The server contains sensitive customer data. The incident has been reported to management. Which of the following is the most immediate corrective action you should take?
Hard496A hospital's network team notices that a radiology workstation is receiving a duplicate IP address error. The DHCP server logs show the workstation was assigned 10.10.20.45, but the workstation is manually configured with that same address. Which DHCP feature should have been configured to prevent this conflict?
Medium497A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)
Hard498A financial services firm is designing a network that must allow inbound HTTPS from the internet to a public web application while preventing any direct inbound connections to its internal database servers. The security architect proposes placing the web application in a screened subnet and configuring rules so the database can be reached only from the web application. Which design element is the architect primarily relying on?
Hard499Which OSI layer is responsible for routing packets across networks using IP addresses?
Easy500A system administrator implements version control for all configuration files. Which principle is being strengthened?
Medium501Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?
Easy502A security administrator is configuring user permissions and ensures that each user has only the minimum rights needed to perform their job. Which access control principle is the administrator applying?
Easy503A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?
Medium504A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?
Medium505An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?
Medium506You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?
Hard507A security engineer is configuring a firewall to allow web traffic but block all other inbound connections. The firewall is set to deny all traffic by default and only allow specific ports. Which security principle is being applied?
Medium508An organization classifies data as 'confidential' and requires encryption at rest and in transit. Which data classification level is likely being used?
Easy509During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)
Hard510An LDAP distinguished name (DN) is written as 'CN=John Smith,OU=Sales,DC=company,DC=com'. What does 'CN' represent?
Medium511A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?
Medium512During a vendor risk assessment, a company discovers that a potential vendor has poor security practices. The company decides not to hire the vendor. This is an example of:
Hard513A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?
Medium514Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?
Easy515A security analyst receives an alert indicating multiple failed login attempts from a single IP address targeting a user account. Which action should the analyst take FIRST?
Easy516An organization uses a SIEM to correlate logs from multiple sources. A rule triggers when a user logs in from two geographically distant locations within a short time. What type of attack does this rule primarily detect?
Medium517Maya is a security administrator at a healthcare company. She discovers that nurses can view patient billing records even though their job duties only require access to clinical treatment notes. She wants to apply the security principle that restricts users to only the data they need to perform their assigned tasks. Which principle should she implement?
Easy518A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?
Medium519A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)
Medium520A payroll administrator can view salary records for all employees during normal business hours, but only after her manager approves each access request and the system logs the action. Which security principle is BEST illustrated by limiting her access to what her job requires and only when needed?
Medium521During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?
Hard522An organization is designing a security architecture for a cloud-based application. They implement firewalls, intrusion detection systems, and encryption, and also conduct regular security awareness training. This approach demonstrates which security principle?
Hard523A security operations center (SOC) analyst notices unusual outbound network traffic from a server that typically only receives connections. The traffic is encrypted and goes to an unknown external IP. Which step should the analyst perform FIRST?
Medium524An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)
Hard525A security administrator is selecting controls to protect the confidentiality of a database containing customer PII. Which TWO controls are most appropriate?
Medium526An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?
Medium527Which statement best describes a warm site in disaster recovery?
Hard528A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?
Medium529An organization deploys firewalls at the network perimeter, antivirus on endpoints, and encryption for data at rest. This approach best exemplifies which security principle?
Medium530An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?
Hard531A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?
Medium532Which of the following best describes a Disaster Recovery Plan (DRP)?
Easy533A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?
Medium534A security administrator is configuring user permissions and wants to ensure that each user has only the access rights necessary to perform their job. Which principle is being applied?
Easy535A small business wants to prevent employees from visiting known malicious websites. The owner asks a technician to implement a control that blocks requests to a maintained list of bad domains before any connection is made to those sites. Which solution should the technician deploy?
Easy536During a forensic investigation, an analyst acquires a live system memory dump. Which tool is most appropriate for capturing the contents of volatile memory on a Windows system?
Hard537A company is designing a new application that processes credit card payments. They want to ensure that no single administrator can bypass security controls to approve a fraudulent transaction. Which principle should be implemented?
Hard538After a security audit, a company discovers that several employees have access to financial systems that are not required for their job roles. Which access control model would best prevent this issue in the future?
Medium539A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?
Medium540In a Bell-LaPadula MAC model, which of the following operations is prohibited?
Hard541A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?
Easy542A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
Medium543A multinational corporation deploys redundant servers in geographically diverse data centers and uses a load balancer to distribute traffic. This setup primarily addresses which security concern?
Hard544What is the primary purpose of a Privileged Access Management (PAM) solution?
Medium545An organization decides to purchase cyber insurance to cover potential losses from a data breach. This is an example of which risk treatment strategy?
Hard546A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?
Hard547Which of the following is a key component of the 3-2-1 backup rule?
Easy548Which TWO of the following are fundamental principles of information security that form the CIA triad?
Easy549Which of the following ensures that data has not been tampered with during transmission?
Easy550A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)
Medium551A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?
Hard552An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?
Medium553A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?
Medium554According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?
Medium555Which TWO of the following are examples of physical access controls?
Easy556A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?
Easy557A healthcare provider must ensure that patient records remain unaltered during storage and transmission between clinics. Which security principle is being addressed when the organization implements hashing and digital signatures on those records?
Easy558An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?
Easy559An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?
Hard560A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?
Easy561Which THREE are common indicators of a compromised system? (Select THREE.)
Hard562Which of the following is considered Sensitive PII?
Easy563A security analyst is reviewing physical security controls. Which TWO are considered layered physical security measures for external perimeter protection?
Medium564A security analyst is implementing a solution to ensure that data transmitted between two servers cannot be read by unauthorized parties. Which security principle is the analyst primarily addressing?
Medium565A user reports that they are unable to access a shared network drive that they previously could access. The administrator checks permissions and finds the user's account is still a member of the correct group. What should the administrator check next?
Medium566An administrator configures a Group Policy Object (GPO) in Active Directory to enforce account lockout after 5 failed attempts within 15 minutes. Which type of control is this?
Hard567A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)
Medium568Which TWO are best practices for managing backup media?
Medium569A hospital's security team wants to give remote clinicians access to internal patient systems without exposing those systems directly to the internet. The team requires strong encryption, per-user authentication, and the ability to log every session. Which solution best fits these requirements?
Medium570A security team configures a system to record all user activities for audit purposes. Which principle is being applied?
Easy571A hospital issues each nurse a unique username and a badge that is scanned at a workstation to prove the nurse's identity before any patient records can be opened. Which access control concept does scanning the badge to prove identity represent?
Easy572An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?
Medium573A security auditor is reviewing access controls at a financial institution. The auditor identifies a scenario where one employee can initiate a payment transaction, and the same employee can also approve it. Which access control principle is being violated, and what is the primary risk?
Medium574A security analyst is reviewing access control mechanisms. Which TWO of the following are examples of logical access controls? (Select two.)
Medium575Which of the following is an example of a detective control?
Easy576An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?
Medium577A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?
Hard578Which of the following is an example of a physical control that supports the availability principle of the CIA triad?
Easy579An organization uses a Privileged Access Management (PAM) solution. Which of the following is a primary benefit of PAM?
Hard580A new employee logs in to the corporate network for the first time by entering a username and password. The system checks the credentials against the directory and grants access. Which security concept does entering the username and password represent?
Easy581A medium-sized company uses a SIEM solution to collect logs from firewalls, servers, and endpoints. The security team receives an alert indicating a possible data exfiltration: an employee's workstation is sending large amounts of data to an external IP address outside business hours. The employee works in the finance department and has access to sensitive financial records. The SIEM shows the connection is ongoing. The security team must respond immediately to contain the incident while preserving evidence. The company's incident response plan designates the security team as first responders. Which of the following is the BEST first action?
Medium582Which of the following is the most effective way to prevent tailgating in a secured facility?
Medium583Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?
Medium584Which OSI layer is responsible for routing packets based on IP addresses?
Easy585Which of the following are core principles of information security?
Medium586A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?
Medium587Which process involves verifying the identity of a user who claims to be a specific person?
Easy588Which principle ensures that a user is granted only the permissions necessary to perform their job functions, thereby reducing the potential impact of a compromised account?
Easy589Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?
Easy590An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?
Easy591A security analyst is reviewing the organization's risk management process. The analyst must identify which items are examples of risk treatment options. (Choose two.)
Medium592Which protocol is considered insecure because it transmits data, including credentials, in cleartext?
Medium593An organization classifies data as 'Confidential' and requires encryption both at rest and in transit. Which data classification level best fits this requirement?
Hard594Match each phase of the incident response process to its description.
Medium595In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)
Hard596An account lockout policy is designed to mitigate which type of attack?
Medium597A retail company is reviewing physical access controls at its data center. Management wants to document measures that restrict who can enter the server hall and record when entries occur. Which TWO of the following are physical access controls that meet these goals? (Choose two.)
Medium598A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?
Medium599A company's security policy requires that all outbound web traffic be inspected for malware and that users be prevented from accessing known malicious domains. The security team wants a single appliance that can decrypt TLS sessions, apply content filters, and block threats inline. Which solution best meets these requirements?
Medium600Match each network security concept to its purpose.
Medium601A security analyst is reviewing an access control list on a file server and notices that a former employee's account still has read and write permissions, even though the account was disabled three months ago. Which access control practice failed in this situation?
Medium602Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)
Hard603Which TWO of the following are components of the identification and authentication process? (Select TWO.)
Medium604A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?
Medium605Which THREE of the following are considered fundamental security principles? (Select three).
Easy606An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?
Medium607During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?
Easy608What is the primary purpose of using security baselines derived from CIS Benchmarks?
Medium609Which THREE of the following are essential components of a security baseline configuration for a server?
Hard610During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?
Hard611A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?
Easy612A system administrator has a regular user account for daily work and a separate account with elevated privileges. Which principle is being applied?
Medium613An organization's data center experiences a power outage. The uninterruptible power supply (UPS) maintains power long enough for the backup generator to start, but the generator fails to start due to a fuel line blockage. The servers shut down, and critical data is lost. Which security principle was MOST directly compromised?
Easy614Which of the following ports is used by HTTPS?
Easy615A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?
Easy616A small accounting firm wants to grant access to its tax software based on the department a user belongs to, rather than assigning permissions to each person individually. Which access control model should the firm implement to meet this requirement?
Medium617A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?
Medium618An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)
Hard619A company implements a new firewall and intrusion detection system to reduce the risk of network breaches. This is an example of:
Hard620A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?
Hard621A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?
Hard622A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?
Medium623Which THREE are recommended practices for password policies according to current guidelines?
Medium624A financial services firm grants a contractor temporary access to a trading application for a 90-day engagement. The security team wants the access to expire automatically without manual intervention, and also wants the contractor's manager to periodically confirm the access is still required. Which combination of access control practices best satisfies both requirements?
Hard625During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?
Medium626A junior analyst reports that an attacker exploited an unpatched web server to steal customer data. The analyst labels the missing patch the 'risk'. According to standard risk terminology, how should the missing patch be classified?
Hard627A company's security policy requires that all data at rest be encrypted. Which of the following is the BEST approach to ensure compliance while maintaining performance?
Medium628A defense contractor classifies documents as Confidential, Secret, or Top Secret and requires that access decisions be based on these labels. Users receive clearances, and the system itself enforces that a user may read a document only if the user's clearance dominates the document's label. Users cannot change labels or grant access to others. Which access control model is being enforced?
Hard629A security analyst discovers that a vendor's software contains a known vulnerability that could lead to data exposure. The analyst reports this to management. According to risk management principles, which action represents risk transfer?
Hard630Which of the following ports is commonly used for secure web traffic (HTTPS)?
Easy631Which THREE of the following are best practices for securing a remote access VPN?
Hard632A system administrator must grant a help desk technician the ability to reset user passwords but not change user roles. Which security principle does this scenario enforce?
Easy633An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?
Easy634A security engineer is designing a physical security plan. Which combination of controls best represents defense in depth for a data center?
Hard635After a ransomware attack, which team is primarily responsible for coordinating the response?
Easy636An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?
Medium637A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?
Easy638In risk management, which term describes the probability that a threat will exploit a vulnerability and cause harm to an asset?
Hard639An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?
Medium640A security manager is documenting how the organization decides which safeguards to apply to a new customer database. The team identifies the value of the data, the threats that could exploit weaknesses, and the potential business impact, then selects controls that reduce risk to an acceptable level. Which concept best describes this activity?
Hard641According to the (ISC)² Code of Ethics, if a conflict arises between protecting society and providing diligent service to your employer, which should take precedence?
Hard642An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
Medium643A system administrator notices that a user has been granted read and write permissions to a folder but should only have read access. Which type of access control issue does this represent?
Medium644A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?
Medium645An organization uses Active Directory to manage user accounts. Which protocol does Active Directory primarily use to query and modify directory services?
Medium646During an incident response, a forensics analyst captures a memory dump from a compromised server. The analyst needs to ensure the dump is not altered during analysis. Which practice best maintains integrity?
Hard647Refer to the exhibit. Which security principle is being supported by the logging of these events?
Hard648According to the (ISC)² Code of Ethics, which obligation has the highest priority?
Medium649A network technician is setting up a remote access VPN for employees using IPsec. The company's firewall is configured to allow IPsec traffic. Employees report that they can successfully establish the VPN connection (tunnel appears up), but they cannot ping or access any internal resources (e.g., file servers). The firewall logs show that packets from the VPN client IP addresses are being dropped at the firewall interface. Which of the following is the MOST likely cause of this issue?
Easy650An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)
Hard651Which of the following is a control that can reduce the risk of a DDoS attack?
Easy652A company's security policy states that employees must wear identification badges visibly at all times while on premises. A security guard checks badges at the entrance. Which type of control is the badge check?
Medium653A company implements role-based access control (RBAC) to ensure users have only the permissions necessary for their job roles. This is an example of:
Medium654Refer to the exhibit. A user from the Auditors group is unable to access the folder. What is the most likely cause?
Hard655During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?
Hard656Which account type is considered highest risk and should be protected with strict controls, including separate daily use accounts?
Easy657An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?
Hard658An organization implements a bring-your-own-device (BYOD) policy. Which security control is most important to enforce in the BYOD policy?
Medium659A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?
Easy660A hospital's IT team is reviewing its access control model. Administrators currently assign permissions to each nurse individually, which has caused errors and delays when staff rotate between departments. The team wants to simplify administration by assigning permissions to a role such as 'Pediatric Nurse' and then assigning nurses to that role. Which access control model should they implement?
Medium661An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?
Medium662A security analyst is evaluating controls to protect the confidentiality of customer data. Which TWO of the following are effective controls? (Select TWO).
Medium663Which of the following is a recommended practice for password security according to NIST SP 800-63?
Medium664When implementing a role-based access control (RBAC) system, what is the primary challenge organizations face?
Hard665An organization's business continuity plan (BCP) requires that its payroll system be operational within 8 hours of a disruption, but the system can tolerate losing up to 4 hours of payroll transaction data. Which pair of metrics BEST represents these two requirements?
Easy666Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
Easy667You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?
Medium668A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?
Medium669An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:
Hard670A company uses WPA2-Enterprise for wireless authentication. What additional security measure should be implemented to protect against rogue access points?
Medium671A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)
Hard672A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?
Easy673An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?
Easy674Which THREE of the following are considered methods to ensure accountability in a system?
Hard675Which TCP segment is sent to initiate the three-way handshake?
Easy676A mid-sized financial services company has recently experienced a security incident where an attacker gained access to the internal network through a compromised VPN account. The account belonged to a remote employee who had been granted full network access. The company's security team is now reviewing their security principles to prevent a recurrence. The company has 500 employees, with 50 remote workers. They use a traditional perimeter-based firewall and VPN for remote access. The incident revealed that the compromised account had access to the entire internal network, including sensitive financial databases. The security team is considering implementing a new access control model. They have identified the following requirements: (1) Remote workers should only access specific applications necessary for their roles, (2) Access should be granted based on identity and device posture, (3) Network segmentation should be enforced regardless of location. Which of the following approaches BEST addresses these requirements?
Hard677A security analyst notices that a user is accessing files in a department they do not work in. Which principle is being violated?
Medium678Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?
Easy679A SOC analyst detects a series of failed login attempts from a single external IP address targeting multiple user accounts within a short time. Which action should the analyst take FIRST?
Medium680A small business owner wants to ensure that their company's data remains accurate and unaltered during transmission over the internet. They regularly send financial reports to their accountant via email. The owner is concerned that a hacker might intercept and modify the reports before they reach the accountant. Which security principle is most directly threatened in this scenario, and what is the best technical control to implement?
Easy681Refer to the exhibit. ``` C:\> netstat -an | find "LISTENING" TCP 0.0.0.0:80 0.0.0.0:0 LISTENING TCP 0.0.0.0:443 0.0.0.0:0 LISTENING TCP 192.168.1.10:3389 0.0.0.0:0 LISTENING ``` A server administrator runs this command and sees the output. Which service is listening on a port that should typically be disabled to reduce the attack surface?
Easy682A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?
Medium683A software company wants contractors to access an internal code repository only during their contracted hours and only from company-managed laptops. The repository administrator should implement which type of access control to meet these conditions?
Hard684A financial services firm assigns permissions based on each employee's role in the HR system. When an employee transfers from accounting to marketing, the HR record changes and the employee's access is automatically updated to match the marketing role. Which access control model is the firm using?
Medium685A small accounting firm wants to let guests connect to the internet in its lobby without exposing the internal file server or the payroll system. The network administrator is told to add a separate wireless network that uses different IP addressing and cannot route to internal resources. Which security principle is the administrator primarily applying?
Easy686A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?
Hard687An organization uses hashing to ensure that data has not been altered during transmission. Which security principle is being implemented?
Easy688A security manager is reviewing the organization's approach to risk. The manager decides to purchase cyber insurance to transfer some of the financial risk associated with a data breach. Which risk management strategy is being used?
Hard689A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)
Medium690An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?
Hard691A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)
Medium692Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?
Easy693An organization implements a defense-in-depth strategy by deploying firewalls, intrusion detection systems, and endpoint protection. Which security principle does this approach primarily demonstrate?
Medium694A hospital's compliance officer is mapping controls for a new patient portal. The legal team wants documented assurance that a clinician cannot later deny having approved a medication order submitted through the portal. Which security principle is the legal team most directly requesting?
Hard695A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?
Hard696A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)
Medium697A software development company wants to prevent a dismissed contractor from using credentials that were issued during the contract period to access internal code repositories. Which administrative control should the company apply?
Medium698Based on the incident log, at which step did the incident response team contain the threat?
Easy699A company's security policy requires that all employees use strong passwords and change them every 90 days. An employee writes their password on a sticky note and attaches it to their monitor. Another employee sees it and uses it to log into the first employee's account to send a fake email. The security team is conducting a post-incident review. Which security principle failed, and what is the most effective long-term solution to prevent this type of incident?
Medium700Which TWO of the following are examples of administrative security controls? (Choose two.)
Medium701An organization is implementing a new system that processes financial transactions. To reduce the risk of fraud, they ensure that no single individual can both initiate and approve a transaction. Which security principle is this?
Hard702A company uses encryption to protect data at rest and in transit. This primarily addresses which aspect of the CIA triad?
Easy703Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?
Medium704A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?
Hard705A security administrator is implementing controls to prevent a single employee from approving and disbursing payments. Which principle is being applied?
Medium706Which TWO of the following are examples of detective security controls? (Choose two.)
Hard707A software development team is designing a new application that will process credit card payments. The security architect recommends that the application should not store the card verification value (CVV) after the transaction is authorized. Which principle is the architect applying?
Medium708Which of the following is a key function of a Security Information and Event Management (SIEM) system?
Easy709A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?
Medium710A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?
Hard711Which THREE are valid methods for authenticating a user in an access control system?
Hard712Which THREE of the following are best practices for securing a network firewall? (Select THREE.)
Hard713After a security breach, investigators find that an attacker exploited a vulnerability in a publicly accessible application to gain access to internal databases. Which security principle would have most effectively limited the impact?
Hard714Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)
Medium715A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?
Hard716Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?
Medium717A financial services firm wants to ensure that a single employee cannot initiate and approve a large wire transfer alone. The firm implements a process where one employee creates the transfer and a different employee must approve it. Which security principle is being applied?
Medium718Refer to the exhibit. An administrator notices that external access to the MySQL database (port 3306) is blocked, but internal access should be allowed. What change should be made?
Medium719You are a forensic analyst responding to a reported compromise of a Linux web server. The server hosts a public-facing web application and is part of a DMZ. The initial investigation shows that unauthorized outbound connections were made to a known malicious IP address during the previous night. The server is still running and connected to the network, but the web application has been taken offline for maintenance. The incident response team wants to preserve evidence for potential legal action. You have a forensic workstation with tools like dd, netcat, and memory acquisition tools. Which of the following should be your FIRST step in the forensic acquisition process?
Hard720A security engineer is designing a system that must ensure that any changes to a configuration file are logged with the identity of the person who made the change. Which principle is being implemented?
Hard721The exhibit shows the current iptables rules. Which security principle is most clearly enforced by the default policy?
Easy722A financial institution is implementing a new transaction approval process. The process requires that for any transaction over $10,000, two managers must approve: one from the sales department and one from the finance department. However, due to a system configuration error, a single manager can approve the entire transaction if they are logged in from a specific IP address. This error is discovered during a routine audit. Which security principle has been circumvented, and what is the best remediation?
Hard723A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?
Medium724Refer to the exhibit. A firewall rule set is shown (first match applies). An analyst reviews these rules. Which of the following best describes the traffic outcome for a packet from source IP 10.0.0.1 to destination 192.168.1.1?
Hard725A company wants to allow remote employees to securely access internal resources over the internet. Which technology is most appropriate?
Easy726A company uses a SIEM to monitor network security events. The security analyst notices a high volume of alerts about suspicious outbound traffic to a known command-and-control server. The traffic is encrypted and uses non-standard ports. Which security control would best detect this activity if the SIEM relies only on network flow data?
Medium727Which TWO of the following are essential elements of an incident response plan?
Medium728A financial services firm stores customer records in a database. A teller can read and update records for customers assigned to their branch but cannot view records belonging to other branches. A branch manager can view all records within their region. Which access control principle best explains why the teller's access is limited to their own branch's customers?
Medium729Which of the following controls is primarily designed to ensure availability?
Medium730An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?
Hard731Which TWO of the following are best practices for implementing the principle of least privilege?
Hard732An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)
Hard733Which incident category involves an attacker tricking an employee into revealing credentials?
Easy734A system administrator needs to grant a contractor temporary access to a server for patching. The contractor should only have access during the patching window. Which access control implementation method is most appropriate?
Medium735An organization wants to ensure that data remains unaltered during transmission over the internet. Which security goal is being addressed?
Easy736A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)
Medium737Which metric defines the maximum acceptable amount of data loss measured in time?
Easy738A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
Easy739A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)
Medium740Refer to the exhibit. Based on the JSON policy, what access does the SecurityAuditor role have?
Hard741During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?
Hard742Which of the following is a potential security issue commonly found in firewall configurations?
Hard743Your organization is implementing a new access control system to protect a highly sensitive research database. The security policy mandates that no single individual should have the ability to both approve and execute changes to the database. This is to prevent fraud and errors. Which security principle does this policy enforce, and which of the following best implements it?
Medium744You are a security engineer responsible for the company's intrusion detection system (IDS). The IDS has been generating an excessive number of false positive alerts related to a legitimate application that uses encrypted traffic. The alerts are based on network signatures that match certain patterns in the encrypted payload. The volume of alerts is overwhelming the SOC team, and they are beginning to ignore IDS alerts altogether. You have the ability to modify IDS signatures and tune the system. Which of the following is the BEST approach to reduce false positives while maintaining security?
Medium745A security architect is designing a system that must ensure that a sender cannot later deny having sent a message. Which cryptographic mechanism should be implemented?
Hard746A small accounting firm has a flat network where all employee workstations and a guest Wi-Fi access point connect to the same switch. The owner asks a security consultant to keep guests from reaching the payroll server, which resides on the same subnet as employee devices. Which control should the consultant implement to meet this requirement with the least disruption?
Easy747Which component of the AAA framework determines what resources an authenticated user can access?
Medium748Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
Easy749An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?
Hard750Which of the following is classified as sensitive PII?
Medium751A network administrator needs to allow secure remote access for teleworkers. Which VPN protocol provides the best confidentiality and integrity while using a single UDP port?
Medium752An organization requires that two separate administrators approve and implement changes to firewall rules. This practice enforces which security principle?
Hard753A junior security administrator at a hospital is told that only nurses and physicians on the current shift should be able to view patient records, and that records must be protected from disclosure to anyone else. Which security principle is this requirement primarily enforcing?
Easy754An organization implements a policy where users must swipe their ID card and enter a PIN to access a secure room. This is an example of which access control principle?
Easy755A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?
Medium756Refer to the exhibit. The security principle demonstrated by the default policy is:
Easy757A security policy requires that all changes to a production system go through a formal change management process with approval from a change control board. This is an example of which security principle?
Medium758Refer to the exhibit. A user with this policy tries to list objects in a container but gets an access denied error. What is the most likely reason?
Easy759A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)
Hard760A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?
Hard761Which TWO are key outputs of a Business Impact Analysis (BIA)?
Easy762An organization has a policy that all servers must have security patches applied within 30 days of release. Which of the following is the best practice for patching?
Medium763An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)
Medium764Which of the following is a security concern associated with the Telnet protocol?
Medium765A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?
Easy766A company wants to ensure that if a server fails, it does not cause a security breach. Which principle should guide the design?
Medium767Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.
Medium768An organization wants to ensure that no single employee can both request and approve a payment. Which access control principle does this enforce?
Easy769What is the primary purpose of identification in the context of access control?
Easy770During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?
Hard771A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?
Hard772Which TWO of the following are valid types of disaster recovery tests?
Medium773An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?
Easy774Which of the following best describes the difference between due care and due diligence in security governance?
Hard775Which TWO are key components of an effective incident response plan? (Select TWO.)
Medium776An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?
Easy777An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?
Medium778A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)
Medium779A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?
Hard780A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?
Medium781Which TWO of the following are common indicators of a phishing email?
Easy782Which of the following is an example of a Type 2 authentication factor?
Easy783A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?
Hard784A company's security policy states that only staff in the finance department may access the general ledger, and that access must be reviewed every quarter. An auditor finds that two former finance employees still hold active accounts with ledger permissions. Which concept has the organization FAILED to apply?
Medium785Which of the following is an example of a Type 1 authentication factor?
Medium786A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Medium787A company implements a policy that requires two employees to approve any financial transaction over $10,000. Which security principle is being applied?
Easy788A small retail company is developing its first incident response plan. The owner asks which phase of the incident response lifecycle involves developing policies, assigning roles, and acquiring tools. Which phase should be recommended?
Easy789A security manager is assessing the risk of a new web application. The manager identifies that the application has a known SQL injection vulnerability, and that attackers frequently scan for such flaws. Which term best describes the SQL injection flaw itself?
Hard790A security analyst implements a hashing algorithm to verify that a downloaded file has not been altered. Which security goal is being achieved?
Medium791An organization's security policy requires that all employees change their passwords every 90 days. This is an example of which type of security control?
Easy792According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?
Hard793A company wants to implement defense in depth for its data center. Which THREE of the following controls should be included? (Select THREE.)
Hard794Which document outlines the procedures for maintaining critical business functions during a disruption?
Easy795A company is designing a new authentication system for remote employees. They want to ensure that if one authentication factor is compromised, the system remains secure. Which security principle should they apply?
Medium796An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)
Medium797Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?
Medium798An organization requires both a password and a fingerprint scan to access a secure system. This is an example of:
Medium799A system administrator uses a separate administrative account with elevated privileges only when performing system maintenance, and uses a standard user account for daily activities like email. This practice aligns with which principle?
Hard800Which THREE of the following are best practices for privileged account management? (Select THREE.)
Medium801An organization wants to implement multi-factor authentication for remote access. Which TWO of the following would provide multi-factor authentication? (Select TWO)
Medium802A security administrator is reviewing the principles of access control. Which TWO of the following are core components of the AAA framework? (Select TWO.)
Hard803A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?
Easy804Which TWO of the following are common indicators of a ransomware attack?
Easy805An organization requires that a financial transaction must be initiated by one employee and approved by a manager before processing. Which access control principle does this enforce?
Easy806A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?
Easy807A hospital's network team needs to provide secure remote access for clinicians who work from home. The clinicians must be able to reach internal medical records systems as if they were on the hospital LAN, but the hospital's security policy requires that all remote traffic be encrypted and that remote devices be prevented from directly accessing the public internet through the hospital network. Which technology best meets these requirements?
Medium808A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)
Medium809Which TWO of the following are types of security controls?
Medium810A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)
Hard811A company implements a policy where no single employee can approve a purchase order over $10,000. Instead, two managers must jointly approve it. Which security principle does this practice exemplify?
Medium812During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?
Hard813You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?
Hard814Which THREE of the following are recognized security control types according to ISC2? (Choose three.)
Hard815A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
Hard816During a security incident, a forensic analyst needs to acquire the contents of RAM from a live system. Which tool should be used?
Hard817A visitor signs in at a company's reception, receives a badge, and is escorted throughout the building. This process is part of which type of access control?
Medium818A software company wants to protect its source code repository. Developers may read and commit code, but only the release manager may create release tags, and the release manager cannot modify the protected branch directly. The company wants a model that enforces these rules consistently regardless of who owns the repository. Which access control model is most appropriate?
Hard819A company stores customer records that include names, addresses, and Social Security numbers. According to ISC2 Code of Ethics, which canon has the highest priority when handling this sensitive data?
Medium820An organization implements encryption for data at rest and in transit. Which principle of the CIA triad is primarily being addressed?
Easy821A company wants to implement a security control that ensures users are who they claim to be before granting access to a system. Which type of control should they prioritize?
Easy822An organization labels data as 'Confidential' and requires encryption both at rest and in transit. This classification is an example of:
Hard823A bank implements a policy that requires two different employees to approve any wire transfer over $10,000. One employee initiates the transfer, and another approves it. This is an example of which access control principle?
Medium824A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)
Hard825According to the (ISC)² Code of Ethics, which principle has the highest priority?
Medium826Which access control model uses subject and object labels to enforce access based on a security policy?
Easy827A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?
Easy828An organization wants to ensure that an email message has not been altered during transmission. Which security control should be used?
Medium829Refer to the exhibit. What is the first action the incident responder should take?
Easy830What is the primary purpose of hashing in information security?
Easy831Which TWO are principles of access control?
Medium832A company's backup strategy requires daily full backups of all servers. The backup window is 4 hours. What is the primary risk if backups consistently take longer than the window?
Easy833An organization wants to ensure that its backup strategy can recover data within 2 hours after a system failure. Which metric should be defined in the disaster recovery plan?
Hard834A company decides to accept the risk of using a legacy system because the cost of replacing it exceeds potential losses. This is an example of:
Hard835A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?
Hard836A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?
Hard837A visitor enters a company building and is required to sign in, present identification, and wear a visitor badge. This is an example of which type of access control?
Easy838A company's security policy requires that all sensitive data be encrypted during transfer. A security administrator discovers that an internal web application is using a self-signed TLS certificate. What vulnerability does this introduce?
Hard839A security manager is reviewing the organization's risk management approach. She wants to ensure that the team correctly distinguishes between threats, vulnerabilities, and risks. Which two of the following statements correctly describe these concepts? (Choose two.)
Hard840Which common port is used by DNS and which transport layer protocol does it primarily use?
Medium841An organization enforces a password policy requiring a minimum of 15 characters with no complexity requirements, and does not force periodic changes. This policy aligns with which current best practice?
Hard842A defense contractor classifies documents as Public, Internal, Secret, and Top Secret. A user with Secret clearance attempts to open a Top Secret document and is denied, while a user with Top Secret clearance can open both Top Secret and Secret documents. Which access control model does this behavior describe?
Hard843A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)
Hard844You are implementing a security control to prevent unauthorized devices from connecting to the corporate wired network. Which network access control method should be used?
Hard845An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)
Medium846A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)
Medium847Which THREE are phases of the incident response process according to NIST SP 800-61?
Easy848Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?
Medium849Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?
Easy850A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?
Medium851Which TWO of the following are examples of multi-factor authentication? (Select TWO.)
Medium852After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?
Hard853An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?
Easy854A company is implementing risk management for a new project. Which THREE of the following are valid risk treatment options? (Select THREE.)
Hard855An analyst reviewing traffic captures sees a workstation repeatedly sending TCP packets with the SYN flag set to many different destination ports on a single server, but the workstation never completes the three-way handshake. The server's connection table is becoming exhausted. Which type of activity is most likely occurring?
Medium856A security administrator is reviewing network security controls. Which TWO of the following are examples of network segmentation technologies? (Select TWO)
Medium857During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?
Hard858Refer to the exhibit. What type of event is this?
Hard859What is the difference between identification and authentication?
Easy860During a security audit, you discover that a financial application stores passwords using MD5 hashing without salt. What is the primary security concern with this practice?
Medium861A hospital's IT team assigns each doctor a unique smart card that must be inserted before the workstation unlocks, and the card's embedded certificate is validated against the hospital's internal certificate authority. Which access control process does the smart card insertion and certificate validation represent?
Medium862A hospital's IT team wants to ensure that nurses can access patient records only during their assigned 12-hour shifts, even if their credentials are valid around the clock. Which access control model should the team implement to enforce this time-based restriction?
Medium863An employee claims to have accessed a confidential document that is not related to their job role. The security team investigates and finds that the employee's account had read access to the folder containing the document. Which TWO access control concepts were likely violated?
Easy864An analyst reviews the exhibit. What security principle is best demonstrated by this policy?
Hard865An organization has implemented a SIEM solution. The security team wants to detect when a user attempts to access a file they do not have permission to read. Which log source is most important for this detection?
Medium866Which of the following is considered sensitive personally identifiable information (PII)?
Medium867A security analyst is reviewing physical security controls. Which TWO are examples of perimeter physical controls? (Select TWO.)
Medium868Which of the following best describes the purpose of due care in information security?
Easy869Which TWO of the following are core principles of the CIA triad?
Easy870Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?
Hard871A company's IDS generates an alert for a potential SQL injection attack on a web application. The analyst reviews the log and sees the following: "SELECT * FROM users WHERE username = 'admin' OR 1=1 --'". Which action should the analyst take next?
Hard872A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)
Hard873Which THREE of the following are important steps in the incident response process as defined by the NIST framework? (Choose three.)
Easy874A security analyst discovers that a user's account has been used to access sensitive data outside of normal business hours from an unfamiliar IP address. The user claims they were not logged in at that time. Which security operations process should be initiated first?
Medium875Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?
Easy876During a security audit, it is discovered that a single employee can approve purchase orders and also receive the goods. Which security principle is being violated?
Medium877A company is designing a secure network architecture for its new headquarters. The security team proposes implementing multiple layers of security controls, including firewalls, intrusion detection systems, and access control lists. Which security principle is being primarily applied?
Medium878A hospital's billing application assigns permissions based on each employee's job title, such as nurse, billing clerk, or department manager. When an employee changes roles, the administrator updates the job title and the application automatically adjusts the employee's access. Which access control model is being used?
Medium879A company allows employees to connect to the corporate network from home using a VPN. The security team wants to ensure that a remote employee's device meets minimum security requirements, such as current antivirus and patched operating system, before granting access to internal applications. Which control should be implemented?
Medium880An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
Hard881A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?
Medium882A security analyst observes these SSH logs. What is the MOST likely attack?
Medium883After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?
Hard884According to modern password guidance from NIST SP 800-63, which of the following is the most important factor when setting password requirements?
Medium885A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?
Medium886A security professional is asked to ensure that a document has not been altered since it was signed. Which technology best supports this requirement?
Hard887During which phase of the incident response process would the team identify the root cause of a security incident?
Easy888Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?
Easy889An organization wants to implement multi-factor authentication (MFA) for remote access by requiring a password and a smart card. Which two authentication factors are used in this MFA implementation? (Choose two.)
Easy890A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?
Medium891A financial institution wants to ensure that a wire transfer request cannot be denied by the sender later. The security team implements a mechanism where the sender's private key is used to sign the transaction. Which security principle does this primarily support?
Medium892A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?
Easy893A security analyst notices repeated failed login attempts from a single IP address. The account is locked after 10 failed attempts. This is an example of which type of control?
Hard894A security professional is reviewing authentication methods. Which TWO are examples of Type 2 (possession) factors? (Select TWO)
Medium895According to the (ISC)² Code of Ethics, which of the following has the highest priority?
Hard896A company implements a policy where a financial transaction must be initiated by one employee and approved by a different employee. This is an example of which access control concept?
Medium897A security engineer is deploying a new VPN solution for remote employees. The company requires that the VPN provide strong encryption, support for multiple users, and the ability to traverse NAT devices. Which VPN protocol should the engineer choose?
Hard898Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)
Medium899A company's security policy states that all sensitive data must be encrypted both at rest and in transit. Which threat model does this control primarily address?
Medium900A security engineer is configuring a network intrusion detection system (NIDS) to monitor traffic on a critical subnet. To minimize false positives, which of the following should the engineer baseline first?
Easy901A vulnerability assessment reveals that a legacy system has unpatched software. The organization decides to accept the risk because the system is isolated and has compensating controls. This decision is an example of:
Medium902A payroll clerk changes roles within the same company, moving from the finance department to the human resources department. The security team discovers months later that the clerk still retains all the finance application permissions from the previous position in addition to the new HR permissions. Which access control weakness does this situation illustrate?
Easy903Drag and drop the steps to configure a basic VPN (site-to-site) between two routers into the correct order.
Medium904A regional hospital's emergency department relies on a patient tracking system. The BIA shows the system's maximum tolerable downtime (MTD) is 2 hours. The recovery time objective (RTO) is currently 6 hours, and the recovery point objective (RPO) is 24 hours. Which action best aligns the recovery capability with the business requirement?
Medium905A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:
Hard906A government agency uses a multi-level security system with mandatory access control (MAC). A user with Secret clearance attempts to write data to a file classified as Confidential. Under the Bell-LaPadula model, which rule applies and what is the outcome?
Medium907A network administrator is designing a DMZ to host a public-facing web server and a database server that should only be accessible from the web server. Which of the following firewall rule sets best achieves this design?
Medium908A security manager is training new employees on the concept of risk. She explains that risk is composed of several elements. Which TWO of the following are components that directly contribute to risk? (Choose two.)
Medium909Which THREE of the following are examples of the principle of least privilege? (Select THREE.)
Medium910An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?
Medium911During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?
Hard912Which TWO of the following are common methods to authenticate users on a wireless network? (Select TWO)
Easy913An LDAP distinguished name (DN) is formatted as: CN=John Smith,OU=Sales,DC=company,DC=com. Which component represents the organizational unit?
Medium914A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?
Medium915A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)
Hard916Which port number is associated with HTTPS, and what protocol encrypts the communication?
Easy917A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?
Medium918During a security audit, a penetration tester captures network traffic and finds that some packets have the IP ID field set to 0 and the DF (Don't Fragment) flag set. What is this technique attempting to do?
Hard919A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?
Medium920An organization wants to implement a system that enforces access decisions based on a user's attributes (e.g., department, clearance, time) and environmental conditions. Which model is best?
Hard921A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?
Medium922A security analyst is reviewing logs and finds that a user accessed files outside of their department. The user claims it was necessary for a project. Which principle should the analyst use to assess whether this was appropriate?
Hard923An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?
Medium924A company implements redundant servers to ensure that if one server fails, another can take over immediately. Which security principle is primarily being addressed?
Medium925A security professional is advising a company on adherence to the (ISC)² Code of Ethics. Which two of the following actions align with the Code's canons? (Choose two.)
Medium926A security manager is designing a policy to prevent one person from both approving and disbursing payments. Which principle is being applied?
Medium927A medium-sized company uses a network with three VLANs: VLAN 10 (Users, 192.168.10.0/24), VLAN 20 (Servers, 192.168.20.0/24), and VLAN 30 (DMZ, 192.168.30.0/24). A Layer 3 switch with an ACL is used for inter-VLAN routing. The company has a web server in the DMZ that must be accessible from the internet (via a public IP mapped to 192.168.30.10). Users in VLAN 10 need to access the web server on its private IP (192.168.30.10) for internal testing. The ACL is applied inbound on the VLAN 10 SVI. The ACL currently has the following entries: permit ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255; deny ip any 192.168.20.0 0.0.0.255; permit ip any any. Recently, the security team noticed that users can access the web server on its private IP, but they cannot access the web server via the public IP (which goes through the firewall and then to the DMZ). The firewall logs show that traffic from the users to the public IP is allowed and reaches the DMZ web server, but the return traffic is blocked. The web server's default gateway is the Layer 3 switch (192.168.30.1). Which of the following is the most likely cause of the problem?
Hard928A security team identifies a vulnerability in a web application that could allow attackers to steal customer data. The team decides to accept the risk because the cost to fix exceeds the potential loss. This is an example of:
Medium929Which two of the following are characteristics of a stateful firewall? (Choose TWO.)
Easy930A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?
Hard931Which THREE are essential elements of a disaster recovery plan? (Select THREE.)
Easy932A retail company is designing access controls for its point-of-sale systems. The security architect proposes controls that restrict what authenticated cashiers can do after they log in, such as preventing voids above a threshold and limiting access to inventory adjustments. Which TWO statements correctly describe access control concepts relevant to this design? (Choose two.)
Hard933A company is evaluating a new cloud service provider and performs a thorough investigation of the provider's security practices and compliance with industry standards. This activity is best described as:
Medium934Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?
Easy935A company deploys a web application that stores user passwords using a salted hash. During a security review, an auditor recommends switching from SHA-1 to SHA-256. What is the primary security benefit of this change?
Medium936An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password due to a security breach. The link leads to a website that looks identical to the company's login page. Which type of attack is this?
Easy937Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?
Easy938An organization wants to implement layered physical security for its data center. Which THREE of the following controls would be considered part of a defense-in-depth physical security strategy?
Hard939A financial services company's business continuity plan includes a recovery time objective (RTO) of 4 hours for its trading platform. During a recent test, the platform was restored in 6 hours. Which of the following should be the PRIMARY focus of the after-action review?
Medium940What is the primary goal of data classification?
Easy941Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?
Hard942Which TWO of the following are core components of the CIA triad?
Easy943Which of the following are examples of sensitive PII? (Select all that apply.)
Medium944A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)
Medium945A system administrator is configuring account lockout policies to mitigate brute-force attacks. Which TWO settings are most critical for this purpose?
Medium946Drag and drop the steps to implement a firewall rule allowing inbound HTTPS traffic into the correct order.
Medium947An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?
Medium948Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?
Hard949Which TWO actions are appropriate during the identification phase of incident response?
Hard950Which of the following best describes the principle of confidentiality in the CIA triad?
Easy951An organization is implementing a new identity management system. They want to ensure that users can only access resources necessary for their job roles. Which principle should guide the access control design?
Hard952A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?
Medium953Refer to the exhibit. A security engineer applies this storage access policy to restrict access. Users outside the 10.0.0.0/16 network report being denied access, which is expected. However, users inside that network also report access denied. What is the likely issue?
Medium954An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)
Easy955An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?
Hard956Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?
Hard957Which TWO are true about a differential backup? (Select two.)
Medium958An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?
Easy959A security engineer is reviewing firewall logs and notices that an internal host is making repeated outbound connections to a known malicious IP address on port 443. The firewall is configured to allow all outbound traffic to port 443. The engineer wants to block this specific traffic without disrupting other legitimate HTTPS traffic. Which action should the engineer take?
Hard960After a data breach, an organization discovers that an attacker exploited a known vulnerability in an outdated web server. The organization had previously identified the vulnerability but decided not to patch it due to potential downtime. Which risk management strategy did the organization employ?
Hard961A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?
Hard962During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?
Hard963Which THREE are differences between a hot site and a cold site? (Select three.)
Hard964After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?
Medium965A hospital's compliance officer must decide how to protect patient records. The records must remain readable only to authorized clinicians while in storage and in transit. Which security principle is the compliance officer primarily applying?
Easy966A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)
Hard967Which TWO of the following are examples of administrative security controls?
Easy968An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?
Hard969Which TWO of the following are recognized as benefits of network segmentation?
Hard970An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?
Easy971An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?
Medium972Which THREE of the following are recognized security principles according to NIST and ISC2?
Medium973A retail chain wants store managers to approve refunds above $500, but the managers should not be able to approve their own refund transactions. The security team must enforce this separation in the point-of-sale system. Which access control model best fits this requirement?
Medium974A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?
Hard975An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?
Medium976Which of the following protocols provides secure remote administration of a network device over an untrusted network?
Easy977A financial services firm wants to allow employees to securely access internal applications from home without exposing those applications directly to the internet. The security team proposes using a VPN that encrypts traffic at the network layer and can carry non-web protocols. Which VPN technology best meets this requirement?
Medium978A hospital uses role-based access control (RBAC) for its electronic health records. Nurses can view patient records; doctors can view and edit; administrators can only view administrative data. Recently, a nurse was able to edit a patient's record, which should only be allowed for doctors. The investigation finds that the nurse's role was incorrectly assigned a 'doctor' role due to a misconfiguration. To prevent recurrence, the access control system should be reviewed. Which is the best long-term solution?
Medium979Which of the following is a best practice for securing physical access to a data center?
Easy980Which layer of the OSI model is responsible for routing packets across networks?
Easy981Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?
Medium982A software-as-a-service (SaaS) provider is developing its business continuity plan (BCP). The company wants to ensure it can continue operating during a prolonged power outage at its primary data center. Which element of the BCP should address the alternate power source and its regular testing?
Medium983During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?
Hard984Which security control would best mitigate the risk of network sniffing on a wired LAN segment?
Medium985Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?
Easy986An organization requires that two different administrators approve changes to firewall rules. This is an example of which security principle?
Easy987A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?
Medium988Which TWO of the following are common indicators of a phishing email? (Select TWO.)
Medium989A security team implements a policy that requires all access to sensitive data to be logged and audited. Which principle is being enforced?
EasyOther domains
All CC exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CC exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 989 scenario questions questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.