Courseiva

CISSP Security Architecture and Engineering Practice Question

A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?

⚠ Common exam trap

CISSP often tests the precise two-category taxonomy of covert channels — candidates pick 'side-channel' or 'emanations' because they sound like leakage, but the exam expects the classic storage/timing pair.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Covert timing channel

Option C, a covert timing channel, is correct because it leaks information by modulating the timing of events (e.g., CPU scheduling, packet delays, or response latencies) so that a high-security process signals bits to a low-security process without sharing a direct data object. Option E, a covert storage channel, is correct because it leaks information by writing to and reading from a shared storage resource (e.g., file locks, disk sectors, or memory locations) whose presence or value is observable across security levels. Option A, TOCTOU, is a race-condition vulnerability class, not a covert channel type, so it does not belong. Option B, emanations, refers to unintentional electromagnetic or acoustic leakage, which is a side-channel phenomenon rather than the intentional signaling mechanism of a covert channel. Option D, side-channel, is a broader category of information leakage (e.g., power, cache, or timing analysis) and is not one of the two standard covert channel types asked for here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TOCTOU

    Why it's wrong here

    Time-of-Check to Time-of-Use (TOCTOU) is a race condition where a system's state is checked, but then changes before the check's result is used, leading to a vulnerability. This typically involves an attacker exploiting a window between a security check and an action, rather than establishing a hidden communication path. Therefore, TOCTOU is a flaw in concurrency control, not a mechanism for covert information transfer.

  • ✗

    Emanations

    Why it's wrong here

    Emanations refer to unintentional physical emissions from electronic devices, such as electromagnetic radiation, acoustic noise, or thermal variations, which can inadvertently leak sensitive information. These are typically exploited via techniques like TEMPEST to reconstruct data without direct access to the system. Unlike covert channels, emanations are passive, unintended by the system's design, and do not involve active modulation by a sender to transmit data.

  • ✓

    Covert timing channel

    Why this is correct

    A covert timing channel transmits information by modulating the temporal characteristics of system events or resource access, such as the precise timing of CPU cycles, network packet delays, or disk I/O operations. A sender encodes data by introducing subtle, detectable delays or variations in these timings, which a receiver then observes and decodes. This method exploits shared system resources or observable event sequences to establish a hidden communication path, bypassing explicit security policies.

  • ✗

    Side-channel

    Why it's wrong here

    A side-channel attack exploits information leaked unintentionally through the physical implementation of a cryptosystem or other secure component, rather than through a logical flaw in its algorithm. Examples include analyzing power consumption, electromagnetic radiation, or execution time to infer secret keys or data. While covert channels are *intentional* hidden communication paths established by malicious actors, side-channels are *unintentional* information leakages that attackers merely observe and exploit.

  • ✓

    Covert storage channel

    Why this is correct

    A covert storage channel transmits information by writing data to and reading data from a shared system resource, where the resource's state or content is manipulated to encode messages. The sender modifies an attribute of a shared object, such as a file's existence, a lock's status, or a memory location's value, in a way that is not intended for communication. The receiver then observes these changes to reconstruct the hidden message, effectively using the shared resource as a clandestine bulletin board.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.