Courseiva

CISSP Security Architecture and Engineering Practice Question

A security analyst is investigating a potential data leak via covert channels. Which of the following is an example of a timing covert channel?

⚠ Common exam trap

CISSP often tests whether candidates can distinguish storage covert channels (data hidden in fields/files) from timing covert channels (data encoded in event timing), since both are covert but use different mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Varying the spacing between keystrokes

A timing covert channel conveys information by modulating the timing of events rather than the content of messages. Varying the spacing between keystrokes encodes bits through inter-keystroke delays, which an observer can decode — this is a classic timing channel. The other options describe storage covert channels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modifying unused fields in network packets

    Why it's wrong here

    Modifying unused fields within network packets constitutes a storage covert channel because the information is encoded by altering a specific, albeit often ignored, part of a data structure. The secret data is "stored" by changing the state of these fields, which are then transmitted. This method relies on the recipient being able to read and interpret the modified state of these fields, effectively using them as a temporary storage medium across the network.

  • ✗

    Encoding data in the TCP sequence number

    Why it's wrong here

    Encoding data within the TCP sequence number field represents a storage covert channel because the sequence number is a stateful component of a TCP connection. Information is conveyed by manipulating the numerical value of this field, which is maintained and tracked by both communicating endpoints. The secret data is "stored" within the sequence number's value, leveraging a legitimate protocol field to carry unauthorized information through its persistent state.

  • ✗

    Writing data to a shared disk file

    Why it's wrong here

    Writing data to a shared disk file is a quintessential example of a storage covert channel. In this scenario, the information is explicitly "stored" on a persistent medium accessible to both the sender and receiver. The covert communication occurs by encoding data directly into the file's content or metadata, which the receiver can then read, bypassing standard security controls designed for direct communication channels.

  • ✓

    Varying the spacing between keystrokes

    Why this is correct

    Varying the spacing between keystrokes is a classic example of a timing covert channel. The secret information is not stored in any persistent state or modified data field, but rather conveyed through the temporal relationship between events. By subtly altering the inter-event delay, such as the time between keystrokes, the sender encodes data that the receiver can decode by observing these timing variations.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.