CISSP Security Architecture and Engineering Practice Question
A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?
⚠ Common exam trap
CISSP often tests TOCTOU by describing a race condition in plain language — candidates who don't recognize the check/use timing gap may incorrectly pick side-channel or covert channel based on surface keywords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TOCTOU
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability occurs when a resource's state is verified (check) and then used (use) in separate operations, allowing an attacker to alter the resource between the two steps. The scenario — reading a file before integrity verification completes — is a textbook TOCTOU race condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Covert channel
Why it's wrong here
A covert channel is a method for an entity to transfer information in a manner that violates the system's security policy but is not designed for information transfer. These channels exploit legitimate system resources, such as file locks or CPU timing, to surreptitiously communicate data between processes that are not supposed to interact. While they leak information, the question describes an application allowing a user to do something, which typically points to an authorization or race condition flaw, not a hidden communication path.
- ✗
Buffer overflow
Why it's wrong here
A buffer overflow occurs when a program attempts to write data to a fixed-size memory buffer, but the input data exceeds the buffer's capacity. This excess data then overwrites adjacent memory locations, potentially corrupting data, altering program control flow, or executing arbitrary code. The scenario described, where an application "allows a user" to perform an action, typically indicates a logical flaw in authorization or state management, not a memory boundary violation.
- ✓
TOCTOU
Why this is correct
TOCTOU, or Time-of-Check to Time-of-Use, is a specific type of race condition vulnerability that occurs when there is a delay between the time a security check is performed on a resource and the time that resource is actually used. An attacker can exploit this window by modifying the resource or its attributes after the check but before the use, thereby bypassing the intended security control. This allows the application to "allow a user" to perform an unauthorized action by manipulating the system state during the vulnerable interval.
- ✗
Side-channel attack
Why it's wrong here
A side-channel attack involves extracting sensitive information by observing the physical implementation of a cryptosystem or other secure computation, rather than directly attacking the algorithm itself. Attackers analyze characteristics such as power consumption, electromagnetic emissions, acoustic emanations, or execution timing to infer secret keys or data. The question describes a direct application vulnerability where a user is "allowed" an action, which is a logical flaw, not an inference based on physical characteristics.
Go deeper
Related to this question
Learn chapter
Security Operations Foundations
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.