Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: A healthcare organization recently experienced a…

A healthcare organization recently experienced a data breach. The incident response team traced the breach to a compromised third-party vendor that had remote access to the organization's network. The vendor's credentials were stolen via a phishing attack. The organization's security policy requires that all third-party remote access be monitored and logged. During the investigation, it was discovered that the vendor's session traffic was not logged because the logging system was misconfigured. The security team needs to prevent similar incidents in the future. Which of the following is the MOST effective remediation?

⚠ Common exam trap

Many exam-takers confuse authentication controls (MFA) with monitoring/logging controls, overlooking that the specific failure was a logging misconfiguration, not a lack of authentication strength.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a privileged access management (PAM) solution with session recording.

A Privileged Access Management (PAM) solution with session recording directly addresses the root cause: the logging system was misconfigured and failed to capture third-party remote access traffic. PAM enforces centralized control, vaulting credentials, and recording all sessions (e.g., via RDP, SSH) in a tamper-proof audit trail, ensuring that even if credentials are stolen, every keystroke and screen activity is logged and monitored. This provides the forensic evidence needed to detect and investigate unauthorized actions, closing the gap left by the misconfigured logging system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require multi-factor authentication for all third-party access.

    Why it's wrong here

    While multi-factor authentication (MFA) significantly strengthens the authentication process by requiring multiple verification factors, thereby reducing the risk of credential theft and unauthorized logins, it does not provide visibility into user actions post-authentication. MFA secures access to the system but does not monitor or record the specific activities performed during a third-party session, which is crucial for detecting misuse of legitimate access or for forensic analysis after a breach.

  • Conduct regular phishing simulations for third-party vendors.

    Why it's wrong here

    Conducting regular phishing simulations is an effective strategy for enhancing the security awareness of third-party vendors and reducing their susceptibility to social engineering attacks. However, this measure primarily addresses human vulnerabilities and does not implement technical controls for managing, monitoring, or restricting access privileges once a third party has successfully authenticated. It fails to provide the necessary oversight or control over the actual access and actions performed within the organization's systems.

  • Implement a privileged access management (PAM) solution with session recording.

    Why this is correct

    Implementing a Privileged Access Management (PAM) solution with session recording is a robust control that centralizes, secures, and monitors all privileged accounts and access, enforcing the principle of least privilege for third parties. The integrated session recording feature provides an immutable, video-like audit trail of all actions performed during a privileged session, offering critical forensic data, real-time visibility into activity, and accountability, which directly addresses the need to prevent, detect, and respond to unauthorized actions following a data breach.

  • Disable all third-party remote access until a new vendor vetting process is established.

    Why it's wrong here

    Completely disabling all third-party remote access is an extreme and often impractical measure that would likely cause severe operational disruption and business continuity issues for the healthcare organization. While it eliminates the immediate risk associated with third-party access, it is not a sustainable or balanced long-term solution. A more proportionate and effective response focuses on enhancing controls and monitoring for necessary access rather than a blanket prohibition that could cripple essential services.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.