Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 676–750

816 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQmedium

Refer to the exhibit. A user named Alice has encrypted files using EFS. What is a potential risk associated with the current configuration?

A.The user's certificate is self-signed, which may not be recoverable if lost.
B.The encryption algorithm is weak; AES-256 is not recommended.
C.The key length is insufficient; 256 bits is too short.
D.The files are encrypted only on the local drive; they are not protected if moved to a network share.
AnswerA

A self-signed EFS certificate has no trusted CA or key recovery agent backing it, so if the certificate and private key are lost the encrypted files become permanently unrecoverable. Enterprise PKI-issued certificates support recovery and escrow, which self-signed ones lack.

Why this answer

The correct answer is A: the user's certificate is self-signed, which may not be recoverable if lost. In EFS, file encryption keys are protected by the user's EFS certificate and private key; if that certificate is self-signed and not backed up or escrowed (for example, via a recovery agent or CA-issued certificate), losing the private key makes the encrypted files permanently inaccessible. Option B is wrong because AES-256 is a strong, recommended EFS algorithm, not weak.

Option C is wrong because a 256-bit key is more than sufficient for EFS. Option D is wrong because EFS protection travels with the file when it is moved within the same NTFS environment, so it is not limited to the local drive.

677
MCQhard

An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?

A.Forensic investigator
B.Communications lead
C.Incident manager
D.Security analyst
AnswerA

The forensic investigator is specifically tasked with the meticulous collection, preservation, and analysis of digital evidence from compromised systems. This role ensures that all evidence is handled according to strict chain-of-custody protocols and forensic best practices, making it admissible in legal proceedings and crucial for understanding the full scope and impact of an incident.

Why this answer

The forensic investigator is specifically trained to identify, collect, preserve, and document digital evidence using forensically sound methods that maintain chain of custody and evidentiary integrity. This role ensures evidence is admissible in legal or disciplinary proceedings. Other incident response roles focus on coordination, communication, or analysis rather than legal evidence handling.

Exam trap

CISSP often tests role differentiation within incident response, so candidates who assume the incident manager or security analyst handles all technical tasks pick C or D instead of the specialized forensic investigator.

How to eliminate wrong answers

Option B is wrong because the communications lead manages internal and external messaging and stakeholder communication during an incident, not evidence collection. Option C is wrong because the incident manager coordinates the overall response effort, assigns tasks, and escalates, but does not personally handle forensic evidence preservation. Option D is wrong because a security analyst monitors and triages alerts and may support investigations, but evidence collection for legal proceedings requires forensic specialization and chain-of-custody discipline.

678
MCQhard

Your organization, a multinational e-commerce company, has suffered a ransomware attack that encrypted critical database servers and file shares. The ransom note demands payment in cryptocurrency within 48 hours or the data will be permanently destroyed. The company has a backup strategy that includes daily full backups and hourly incremental backups, stored both on-site and off-site. However, during the incident response, you discover that the most recent on-site backups are also encrypted because the backup server was connected to the network and affected by the same ransomware. Off-site backups are on tape and were last rotated out 72 hours ago. The CEO is pressuring to pay the ransom to restore operations quickly. Which option should the incident response team prioritize to minimize data loss and reputational damage?

A.Pay the ransom and hope the attackers provide a working decryption key.
B.Restore data from the off-site tape backups taken 72 hours ago.
C.Rebuild servers from scratch using latest known good configurations without restoring data.
D.Attempt to negotiate with the attackers for a lower ransom and more time.
AnswerB

Restoring from off-site tape backups is the most reliable and recommended strategy for ransomware recovery, leveraging a fundamental principle of data availability and disaster recovery. Off-site backups are physically or logically isolated from the production network, ensuring they are unaffected by the encryption event and remain uncompromised. While accepting a 72-hour data loss is a business decision, it is a controlled and predictable recovery method that avoids funding criminals and provides a clean slate for operations. This minimizes long-term impact by restoring known good data.

Why this answer

Restoring from the off-site tape backups taken 72 hours ago is the only option that recovers data from a known-clean source unaffected by the ransomware, bounding data loss to at most 72 hours. Paying the ransom is discouraged by law enforcement and does not guarantee decryption, and rebuilding without data would cause total data loss. The off-site tapes were rotated out before the compromise, so they are the most reliable recovery point.

Exam trap

CISSP often tests the misconception that paying the ransom or negotiating is a legitimate incident response priority, when the correct answer is always restoring from a verified clean backup that minimizes data loss.

How to eliminate wrong answers

Option A is wrong because paying the ransom funds criminal activity, does not guarantee a working decryptor, and may violate sanctions/OFAC regulations — it is a last resort, not a priority action. Option C is wrong because rebuilding servers without restoring data results in complete loss of business data, which is worse than a 72-hour rollback. Option D is wrong because negotiating prolongs the outage, does not restore data, and still leaves the organization dependent on attacker goodwill.

679
MCQeasy

A development team heavily uses third-party libraries. What is the most effective way to manage vulnerabilities in these libraries?

A.Only use libraries from sources with no known vulnerabilities
B.Ignore vulnerabilities unless a known exploit exists
C.Manually review each library's source code for flaws
D.Use a Software Composition Analysis (SCA) tool and monitor CVE databases
AnswerD

Utilizing a Software Composition Analysis (SCA) tool combined with continuous monitoring of CVE databases represents the most effective and practical strategy for managing third-party library vulnerabilities. SCA tools automate the process of identifying all third-party components within an application, cross-referencing them against comprehensive vulnerability databases like the National Vulnerability Database (NVD) for known Common Vulnerabilities and Exposures (CVEs). This proactive approach ensures that newly disclosed vulnerabilities in integrated libraries are promptly identified, enabling timely patching or mitigation before they can be exploited.

Why this answer

Software Composition Analysis (SCA) tools automate the identification of third-party libraries and their versions, cross-referencing them against known vulnerability databases such as the National Vulnerability Database (NVD) and Common Vulnerabilities and Exposures (CVE) lists. This provides continuous monitoring and alerting for newly disclosed vulnerabilities, which is the most effective and scalable approach for managing the large number of dependencies in modern development. Manual review or ignoring vulnerabilities is impractical and insecure, while relying on 'no known vulnerabilities' is a false premise.

Exam trap

The trap here is that candidates may choose Option A, mistakenly believing that 'trusted sources' are vulnerability-free, when in fact all libraries can have undiscovered vulnerabilities, and the CISSP exam emphasizes continuous risk management over static trust.

How to eliminate wrong answers

Option A is wrong because no library source can guarantee zero known vulnerabilities; vulnerabilities are discovered over time, and even widely trusted sources like Maven Central or npm have had critical CVEs. Option B is wrong because ignoring vulnerabilities until an exploit exists violates the principle of proactive defense and leaves the system exposed to zero-day attacks or exploits that can be weaponized quickly after disclosure. Option C is wrong because manually reviewing each library's source code is infeasible for large codebases, error-prone, and does not scale; it also fails to account for transitive dependencies and version-specific vulnerabilities that SCA tools can detect automatically.

680
MCQmedium

An organization's security team is drafting a document that defines the organization's intent to protect information assets and assigns responsibilities to the information security manager. The document must align with ISO/IEC 27001 requirements and be approved by executive management. Which type of document is being created?

A.Information security policy
B.Information security guideline
C.Information security procedure
D.Information security standard
AnswerA

An information security policy is a high-level document that expresses management's intent to protect information assets, assigns roles and responsibilities, and aligns with frameworks like ISO/IEC 27001. It requires executive approval and sets the foundation for all other security documents. This scenario matches that definition exactly, making it the correct choice.

Why this answer

The correct answer is the information security policy because it is the only document type that expresses management's intent, assigns security responsibilities, and requires executive approval to align with ISO/IEC 27001. Standards, procedures, and guidelines are more detailed or advisory and do not fulfill this strategic role.

Exam trap

The trap here is confusing a policy with a standard or procedure, assuming that any security document approved by management qualifies as a policy.

681
MCQmedium

A security team is reviewing application security and needs to analyze source code without executing the application. Which technique should they use?

A.Dynamic Application Security Testing (DAST)
B.Interactive Application Security Testing (IAST)
C.Static Application Security Testing (SAST)
D.Runtime Application Self-Protection (RASP)
AnswerC

Static Application Security Testing (SAST) directly analyzes an application's source code, bytecode, or binary code without actually executing the program. This method allows security teams to identify potential vulnerabilities, such as buffer overflows, SQL injection flaws, or insecure cryptographic practices, early in the Software Development Life Cycle (SDLC). SAST is ideal for reviewing application security during development, enabling developers to fix issues before the application is even compiled or deployed.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, looking for vulnerabilities such as injection flaws, hardcoded secrets, and insecure patterns. Because it operates on the code itself, it can be run early in the SDLC and integrated into CI/CD pipelines. This matches the requirement to analyze source code without executing the application.

Exam trap

CISSP often tests the distinction between testing techniques that require execution (DAST, IAST, RASP) and those that do not (SAST), so the trap is selecting a runtime technique when the question explicitly says the application is not executed.

How to eliminate wrong answers

Option A is wrong because DAST tests a running application from the outside, sending requests and analyzing responses, which requires execution. Option B is wrong because IAST instruments a running application (often via an agent) and analyzes behavior during execution, so it also requires the app to run. Option D is wrong because RASP runs inside a live application at runtime to detect and block attacks, which by definition requires execution.

682
MCQhard

During a security audit, it is discovered that the database server is also accepting connections from the web server. Which of the following is the most likely misconfiguration?

A.The application server is not properly authenticated
B.The network segmentation is not enforcing strict controls
C.The TLS configuration is incorrect
D.The firewall on the database server allows all traffic from the DMZ
AnswerB

Network segmentation is a fundamental security control that logically divides a network into distinct security zones, enforcing strict communication policies between them, often using firewalls or VLANs. If a web server, typically residing in a less trusted DMZ, can directly establish a connection to a database server, which should be in a highly protected internal zone, it indicates a critical failure in these segmentation controls. This allows unauthorized network pathways, violating the principle of least privilege and exposing sensitive assets.

Why this answer

The database server accepting connections from the web server indicates a lack of proper network segmentation. In a secure architecture, the web server should be in a DMZ and the database server in a private network segment, with strict access controls enforced by a firewall or router ACLs. The misconfiguration is that the network segmentation is not enforcing strict controls, allowing traffic that should be blocked.

Exam trap

The trap here is that candidates may focus on authentication or encryption (options A or C) as the primary issue, but the core problem is the lack of network segmentation, which is a fundamental security architecture control.

How to eliminate wrong answers

Option A is wrong because the application server not being properly authenticated is an identity and access management issue, not the direct cause of the database server accepting connections from the web server; the core problem is network-level access, not authentication. Option C is wrong because an incorrect TLS configuration would affect encryption of data in transit, not the fundamental ability of the web server to establish a TCP connection to the database server. Option D is wrong because while a permissive firewall rule could allow traffic, the question states the database server is 'accepting connections' from the web server, which implies the firewall is allowing it, but the most likely root misconfiguration is the lack of network segmentation (e.g., placing the database server in the same VLAN as the web server or not using a firewall to restrict traffic between zones), not just a single firewall rule.

683
MCQhard

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

A.Change management process for the financial system
B.Data encryption for customer PII
C.Firewall rule to block unauthorized traffic
D.Automated calculation of interest on loans
AnswerA

Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.

Why this answer

Under SOX, IT general controls (ITGCs) are the foundational controls that ensure the reliability, integrity, and security of the IT environment supporting financial reporting. A change management process for the financial system is a classic ITGC because it ensures that modifications to applications affecting financial data are authorized, tested, approved, and documented — directly protecting the accuracy and completeness of financial statements. SOX Section 404 requires management to assess and auditors to attest to the effectiveness of these internal controls over financial reporting (ICFR), and ITGCs like change management are a core part of that assessment.

Exam trap

CISSP often tests the distinction between IT general controls (which govern the IT environment and support financial reporting under SOX) and application/business controls (which operate within a specific application) — candidates frequently pick the automated business calculation (Option D) because it sounds financial, missing that it is an application control, not an ITGC.

How to eliminate wrong answers

Option B is wrong because data encryption for customer PII is a data protection/privacy control (relevant to GDPR, CCPA, or PCI DSS) rather than an ITGC specifically supporting the integrity of financial reporting — encryption of PII does not directly ensure financial data accuracy or authorization. Option C is wrong because a firewall rule blocking unauthorized traffic is a network perimeter security control; while it contributes to overall security, it is not a financial-reporting ITGC and does not address the authorization, completeness, or accuracy of financial transactions. Option D is wrong because automated calculation of interest on loans is an application (business) control — an automated process embedded in the application logic — not an IT general control, which governs the IT environment across applications.

684
MCQmedium

A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?

A.Hot site
B.Cold site
C.Reciprocal agreement
D.Warm site
AnswerA

A hot site is a fully equipped, mirrored facility with identical hardware, software, and network connectivity to the primary data center. It maintains real-time or near real-time data synchronization, enabling immediate failover and operational resumption within minutes to a few hours. This capability is essential for critical systems requiring a very low Recovery Time Objective (RTO), such as the 4-hour RTO implied for critical company systems, making it the most suitable choice.

Why this answer

A hot site is fully configured with hardware, software, network connectivity, and real-time data replication, enabling recovery within minutes to hours and minimal data loss. This matches the requirement of restoring critical applications within 4 hours with minimal data loss, as hot sites maintain near-synchronous or synchronous replication (e.g., using synchronous replication over Fibre Channel or iSCSI with RPOs in seconds).

Exam trap

The trap here is that candidates confuse 'warm site' with 'hot site' because both have pre-installed hardware, but warm sites lack real-time data replication and automated failover, making them unsuitable for RTOs under 4 hours with minimal data loss.

How to eliminate wrong answers

Option B is wrong because a cold site provides only physical infrastructure (power, cooling, space) with no pre-installed hardware or data, requiring days or weeks to restore, far exceeding the 4-hour RTO. Option C is wrong because a reciprocal agreement relies on another organization's spare capacity, which is not guaranteed, lacks dedicated hardware, and typically has no real-time data replication, leading to RTOs of days and significant data loss. Option D is wrong because a warm site has partially configured hardware and software but lacks real-time data replication, often using periodic backups (e.g., daily tape or disk snapshots), resulting in RTOs of 12-24 hours and RPOs of hours to a day, failing the 4-hour RTO and minimal data loss requirement.

685
MCQhard

An organization is implementing federated identity to allow partners to access its web application. The solution must support single logout and attribute exchange. Which protocol is most appropriate?

A.SAML 2.0
B.OpenID Connect
C.LDAP
D.OAuth 2.0
AnswerA

SAML 2.0 is the industry standard for federated identity management, specifically designed for cross-domain single sign-on (SSO) and robust attribute exchange. Its XML-based assertions securely convey authentication and authorization information between an Identity Provider (IdP) and a Service Provider (SP). SAML's mature framework includes well-defined mechanisms for single logout, attribute queries, and cryptographic signing, making it highly suitable for complex enterprise federation scenarios requiring comprehensive identity services.

Why this answer

SAML 2.0 is the most appropriate protocol because it natively supports both single logout (SLO) and attribute exchange as core features. It uses XML-based assertions to transfer identity and attribute data between an identity provider (IdP) and a service provider (SP), and its SLO mechanism ensures that when a user logs out from one application, all sessions across participating services are terminated simultaneously.

Exam trap

The trap here is that candidates often confuse OAuth 2.0 with OpenID Connect or assume that OAuth 2.0 alone can handle authentication and logout, but OAuth 2.0 is strictly an authorization protocol and lacks the session management and attribute exchange features required for federated identity.

How to eliminate wrong answers

Option B (OpenID Connect) is wrong because, while it supports single logout via RP-initiated logout, it does not natively support attribute exchange in the same structured manner as SAML; it relies on scopes and claims, which are less suited for complex enterprise attribute sharing. Option C (LDAP) is wrong because it is a directory access protocol for querying and modifying directory services, not a federated identity protocol; it lacks built-in support for single logout and cross-domain attribute exchange. Option D (OAuth 2.0) is wrong because it is an authorization framework, not an authentication protocol; it does not provide single logout or attribute exchange—those are handled by OpenID Connect when layered on top, but OAuth 2.0 alone is insufficient.

686
MCQmedium

A security architect is designing a system that must enforce the principle of least privilege at the operating system level. Which mechanism should be implemented to grant processes only the minimal permissions required for their tasks?

A.Mandatory Access Control (MAC) using SELinux policies
B.Role-Based Access Control (RBAC) with fine-grained roles
C.Discretionary Access Control (DAC) with user permissions
D.Mandatory Integrity Control (Biba)
AnswerA

Mandatory Access Control (MAC), as implemented by SELinux policies, is the most effective model for enforcing strict, system-wide security policies that cannot be overridden by users or applications. SELinux assigns security contexts to all system resources and processes, defining precisely what each process is permitted to do, regardless of user identity or traditional Unix permissions. This granular, kernel-level enforcement ensures strict confinement and adherence to the principle of least privilege, preventing unauthorized actions even if a process is compromised.

Why this answer

SELinux implements Mandatory Access Control (MAC) by enforcing a system-wide security policy that overrides user and process permissions. This allows the security architect to define precise rules (e.g., via Type Enforcement) that grant each process only the minimal set of resources it needs, effectively enforcing least privilege at the OS level regardless of user identity.

Exam trap

The trap here is that candidates often confuse RBAC with process-level least privilege, but RBAC is user-centric and does not constrain process permissions at the OS kernel level like MAC does.

How to eliminate wrong answers

Option B is wrong because Role-Based Access Control (RBAC) manages access based on user roles, not process-level permissions; it does not inherently restrict processes to minimal rights at the OS level. Option C is wrong because Discretionary Access Control (DAC) allows users to control permissions on their own objects, which can lead to privilege escalation and violates the principle of least privilege when users grant excessive rights. Option D is wrong because Mandatory Integrity Control (Biba) focuses on preventing data corruption by controlling information flow based on integrity levels, not on granting minimal permissions to processes.

687
Multi-Selectmedium

An organization is planning an external audit for SOC 2 Type II compliance. Which TWO of the following are true about this type of audit?

Select 2 answers
A.It reports on controls over a period of time, typically 6–12 months
B.It is a third-party audit that evaluates controls for security, availability, processing integrity, confidentiality, and privacy
C.It is an internal audit performed by the organization's staff
D.It focuses solely on financial reporting controls
E.It is a public document available to anyone
AnswersA, B

A SOC 2 Type II report provides an in-depth assessment of a service organization's controls over a specified period, typically spanning six to twelve months. This extended observation period allows the auditor to test the operating effectiveness of controls, demonstrating their consistent application and reliability over time. This contrasts sharply with a Type I report, which only describes controls at a specific point in time without testing their effectiveness.

Why this answer

Option A is correct because a SOC 2 Type II audit reports on the design and operating effectiveness of controls over a period of time, typically a 6–12 month observation window, rather than a single point in time as in a Type I report. Option B is correct because SOC 2 is an independent third-party examination against the AICPA Trust Services Criteria, which cover security (common criteria) plus availability, processing integrity, confidentiality, and privacy. Option C is incorrect because SOC 2 is performed by an independent CPA firm, not by the organization's own internal staff.

Option D is incorrect because SOC 2 addresses the Trust Services Criteria, not financial reporting controls, which are the domain of SOC 1 (SSAE 18/ISAE 3402). Option E is incorrect because SOC 2 reports are restricted-use documents distributed under NDA to management, customers, and other specified parties, not public documents.

Exam trap

CISSP often tests the SOC 1 vs SOC 2 vs SOC 3 distinction — candidates confuse SOC 2 (Trust Services Criteria, restricted use) with SOC 1 (financial reporting) or SOC 3 (general-use, no detail), and mislabel Type II as a point-in-time or internal audit.

688
MCQeasy

Which type of covert channel uses the timing of events or operations to transmit information?

A.Emanations channel
B.Side channel
C.Timing channel
D.Storage channel
AnswerC

A timing channel is a specific type of covert channel that modulates information by altering the temporal characteristics of system events or operations. This involves varying the time taken for a process to complete, the delay between two events, or the order of operations, to encode and transmit data between processes that are not supposed to communicate directly. The receiver deciphers the secret message by observing these temporal variations.

Why this answer

A timing channel is a covert channel that conveys information by modulating the timing of events or operations — for example, varying the delay between packets or CPU bursts so a receiver can decode bits from the timing pattern. It is a type of side channel where the shared resource is time itself.

Exam trap

CISSP often tests the distinction between storage and timing covert channels — candidates pick 'side channel' because it sounds broader, but the question asks for the specific type defined by timing.

How to eliminate wrong answers

Option A is wrong because an emanations channel refers to unintentional electromagnetic or acoustic radiation that leaks information, not deliberate timing modulation. Option B is wrong because 'side channel' is the broader category that includes timing, power, cache, and electromagnetic channels — it is not the specific type defined by timing of events. Option D is wrong because a storage channel uses a shared storage location (e.g., a file, memory location, or disk sector) to pass information, not timing.

689
MCQmedium

An organization's data retention policy specifies that customer records must be retained for five years after the end of the business relationship. After that period, what should be done with the data according to best practices?

A.Continue retaining the data indefinitely for future use
B.Securely destroy the data
C.Archive the data to offline storage
D.Anonymize the data and keep it
AnswerB

Securely destroying the data is the correct action when its defined retention period has expired, as mandated by the organization's policy. This process involves irreversible sanitization methods, such as degaussing, cryptographic erasure, or physical destruction, to ensure the data cannot be reconstructed or accessed. This minimizes the organization's attack surface, reduces legal and regulatory compliance risks, and upholds data minimization principles by eliminating unnecessary data holdings.

Why this answer

Once the retention period expires, data should be securely destroyed to prevent unauthorized access and comply with privacy regulations.

690
MCQeasy

A security tester needs to test a new application for vulnerabilities but is concerned about contaminating the production database with test data. What is the best practice for conducting such tests?

A.Perform the test on the production environment during off-hours
B.Create a separate test environment with anonymized production data
C.Test only from the network perimeter to avoid data exposure
D.Use synthetic data that mimics production but is not real
AnswerB

Establishing a dedicated test environment that accurately mirrors the production architecture ensures comprehensive and realistic vulnerability assessment without impacting live systems. Utilizing anonymized or de-identified production data provides a representative dataset for testing data handling, access controls, and potential data leakage vulnerabilities, while mitigating the risk of exposing sensitive information during the testing process. This approach balances realism with robust risk management.

Why this answer

Creating a separate test environment with anonymized production data ensures that testing does not affect the integrity or availability of the production database while still using realistic data to uncover vulnerabilities. Anonymization techniques, such as data masking or tokenization, remove personally identifiable information (PII) while preserving referential integrity and data distribution, allowing for accurate security testing without contaminating production systems.

Exam trap

The trap here is that candidates often confuse 'synthetic data' (Option D) with 'anonymized production data' (Option B), not realizing that synthetic data may not accurately reflect real-world data complexity, while anonymized production data preserves the necessary characteristics for thorough vulnerability testing without risking data contamination.

How to eliminate wrong answers

Option A is wrong because performing tests on the production environment during off-hours still risks contaminating the production database with test data, potentially corrupting live data, causing availability issues, or violating compliance requirements (e.g., GDPR, PCI DSS). Option C is wrong because testing only from the network perimeter does not address the core concern of database contamination; it focuses on network-level controls rather than data integrity, and internal application vulnerabilities may remain undetected. Option D is wrong because synthetic data that mimics production but is not real often lacks the complexity, edge cases, and statistical distributions of real data, which can lead to missed vulnerabilities that only manifest with actual production-like data patterns.

691
MCQeasy

A security architect is designing a system that must continue to function even when a component fails. The architect implements multiple layers of security controls so that if one fails, others still provide protection. Which principle is being applied?

A.Separation of duties
B.Defense in depth
C.Fail-secure
D.Least privilege
AnswerB

This robust security strategy involves implementing multiple, independent, and overlapping security controls across various layers of an information system's architecture. By integrating administrative, technical, and physical safeguards, it ensures that if one control fails or is circumvented, other controls are still in place to detect, delay, or prevent an attack. This layered approach significantly increases the complexity and resources required for an adversary to achieve their objectives.

Why this answer

Defense in depth (B) is the correct principle because it involves implementing multiple layers of security controls (e.g., firewalls, intrusion detection systems, encryption, access controls) so that if one layer fails or is bypassed, other layers continue to provide protection, ensuring the system remains functional. This directly matches the scenario where the architect designs for continued operation despite component failure by layering controls.

Exam trap

The trap here is that candidates confuse 'defense in depth' with 'fail-secure' because both involve planning for failure, but fail-secure prioritizes security over availability (e.g., locking down on failure) whereas defense in depth prioritizes continued operation through redundancy of controls.

How to eliminate wrong answers

Option A is wrong because separation of duty is a principle that prevents fraud or error by requiring multiple individuals to complete a sensitive task (e.g., one person authorizes, another executes), not by layering controls for resilience. Option C is wrong because fail-secure means that when a component fails, the system defaults to a secure state (e.g., locking all doors on power loss), which may actually halt functionality rather than ensure continued operation. Option D is wrong because least privilege restricts users or processes to only the minimum permissions needed to perform their tasks, which is a access control principle unrelated to maintaining function during component failures.

692
MCQmedium

Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?

A.Resource owner password credentials grant
B.Authorization code grant with PKCE
C.Implicit grant
D.Client credentials grant
AnswerB

The Authorization Code Grant with Proof Key for Code Exchange (PKCE) is the recommended flow for public clients, such as mobile and single-page applications. PKCE mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and a `code_challenge` derived from it. This ensures that only the legitimate client that initiated the authorization request can exchange the authorization code for an access token, even if the code is intercepted.

Why this answer

Authorization Code grant with PKCE (Proof Key for Code Exchange, RFC 7636) is the OAuth 2.0 best current practice for public clients like SPAs and mobile apps that cannot keep a client secret confidential. PKCE adds a dynamically generated code_verifier and its hashed code_challenge to the authorization request, so even if the authorization code is intercepted, it cannot be exchanged without the verifier. This mitigates authorization code interception attacks that plague public clients.

Exam trap

CISSP often tests the outdated belief that the Implicit grant is appropriate for SPAs — the trap is selecting Implicit because it was historically recommended for browser apps, when modern guidance (RFC 8252, OAuth 2.1) mandates Authorization Code with PKCE.

How to eliminate wrong answers

Option A is wrong because the Resource Owner Password Credentials grant requires the app to handle the user's username and password directly, which is deprecated in OAuth 2.1 and violates the principle that credentials should only be entered into the authorization server's UI. Option C is wrong because the Implicit grant returns tokens directly in the URL fragment, exposing them to browser history, referrer headers, and XSS; it is deprecated in favor of Authorization Code + PKCE. Option D is wrong because the Client Credentials grant is for machine-to-machine (confidential) clients with no user context — it cannot be used by a public SPA acting on behalf of a user.

693
MCQhard

A financial institution is required to perform regular penetration tests on its online banking platform. The testing must be as realistic as possible while minimizing risk to production data. Which of the following approaches BEST meets these requirements?

A.Conduct the test on the production environment using anonymized production data.
B.Use an automated vulnerability scanner on the production environment.
C.Perform the test during off-peak hours on the production system with read-only access.
D.Build a replica of the production environment and test against it with realistic attack scenarios.
AnswerD

Building a high-fidelity replica of the production environment provides a safe, isolated sandbox to conduct aggressive, full-scope penetration tests without jeopardizing the stability, availability, or integrity of the live production system or its sensitive data. This approach enables testers to simulate realistic, multi-vector attack scenarios, including exploitation and post-exploitation activities, to thoroughly assess defenses and identify vulnerabilities under conditions mirroring actual threats, ensuring comprehensive security validation.

Why this answer

Building a replica (staging) environment allows the penetration test to simulate realistic attack scenarios without any risk to production data or system availability. This approach ensures the test can include destructive or disruptive techniques (e.g., SQL injection, privilege escalation) that would be unsafe on a live system, while still accurately reflecting the production architecture and configurations.

Exam trap

The trap here is that candidates often choose Option A or C because they focus on 'realistic' testing and assume production is the only way to achieve realism, overlooking that a well-constructed replica provides identical attack surfaces without the unacceptable risk to production integrity.

How to eliminate wrong answers

Option A is wrong because using anonymized production data in the production environment still exposes the live system to potential service disruption or data corruption from active exploitation attempts, and anonymization does not eliminate the risk of data leakage or system instability. Option B is wrong because an automated vulnerability scanner only identifies known vulnerabilities and lacks the manual, creative exploitation techniques required for a realistic penetration test; it also cannot safely simulate advanced attack chains. Option C is wrong because read-only access prevents the tester from performing many essential penetration testing activities (e.g., writing files, modifying configurations, escalating privileges), and off-peak hours do not eliminate the risk of production impact from active attacks.

694
Multi-Selectmedium

An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)

Select 3 answers
A.Cloud DR
B.Hot site
C.Cold site
D.Warm site
E.Reciprocal agreement
AnswersB, C, D

A hot site is a fully operational, geographically separate duplicate of the primary data center, equipped with all necessary hardware, software, and up-to-date data. It is designed to allow critical business operations to resume almost instantaneously, minimizing both Recovery Time Objective (RTO) and Recovery Point Objective (RPO) to near zero. This high level of readiness makes it the most expensive but also the most resilient DR site option.

Why this answer

The three recognized recovery site types are the hot site (B), cold site (C), and warm site (D), which differ by readiness and cost: a hot site is a fully equipped, mirrored facility with near-zero RTO, a warm site has hardware and connectivity but requires data restoration and configuration (moderate RTO), and a cold site provides only basic space and power with no pre-installed systems (longest RTO). These three form the standard tiered continuum of alternate processing sites in disaster recovery planning. Cloud DR (A) is a recovery strategy or deployment approach rather than a site type in the classic tiered model, and a reciprocal agreement (E) is a mutual aid arrangement between organizations to share resources, not a dedicated recovery site type.

Exam trap

CISSP often tests the classic three recovery site types, and candidates may be tempted to include 'cloud DR' or 'reciprocal agreement' as site types; the trap is confusing recovery strategies with site classifications.

695
MCQhard

During an audit, it is discovered that several users have inherited permissions through nested group memberships that violate least privilege. What is the best approach to correct this?

A.Implement periodic access reviews and attestation
B.Re-certify group memberships quarterly
C.Provide training on least privilege
D.Revoke all group memberships and assign individually
AnswerA

Implementing periodic access reviews and attestation directly addresses the discovery of excessive permissions by mandating regular validation. Managers or data owners review assigned access rights, including those inherited through nested groups, to confirm they align with current job functions and the principle of least privilege. This process requires explicit attestation, ensuring accountability for the continued necessity of each permission and facilitating the revocation of unnecessary access.

Why this answer

Periodic access reviews and attestation (Option A) are the best approach because they establish a continuous governance process where data owners or managers formally confirm that inherited permissions from nested group memberships remain appropriate. This directly addresses the root cause—unchecked group nesting—by enforcing regular validation of access rights against the principle of least privilege, rather than relying on a one-time fix or training.

Exam trap

The trap here is that candidates often choose a one-time technical fix (like revoking all memberships) or a generic training option, failing to recognize that the CISSP exam emphasizes governance processes like periodic attestation as the sustainable solution for ongoing compliance with least privilege.

How to eliminate wrong answers

Option B is wrong because re-certifying group memberships quarterly is a subset of periodic access reviews but lacks the attestation component; attestation requires explicit confirmation of necessity, whereas re-certification may only verify membership without evaluating the underlying permissions inherited through nesting. Option C is wrong because training on least privilege, while valuable for awareness, does not correct existing misconfigurations or remove inherited permissions that violate the principle; it is a preventive measure, not a corrective one. Option D is wrong because revoking all group memberships and assigning individually is overly disruptive, ignores the legitimate need for group-based access management, and violates the principle of manageability; it also fails to address the underlying issue of nested group inheritance, which would require re-engineering the group structure rather than a blanket revocation.

696
MCQmedium

A security team is analyzing logs from multiple sources and notices anomalous outbound traffic to a known command-and-control server. What is the most likely conclusion?

A.A misconfigured firewall is causing traffic
B.A host is compromised and is beaconing
C.An employee is streaming video to a personal server
D.The network is under a DDoS attack
AnswerB

This is the correct explanation. When a host is compromised by malware, it frequently establishes and maintains communication with its Command and Control (C2) server through a process known as beaconing. This involves sending small, periodic outbound packets to a specific external IP address or domain, often at regular intervals, to check for new instructions or exfiltrate data. This behavior is a strong indicator of compromise and is precisely what security teams look for in logs.

Why this answer

Anomalous outbound traffic to a known command-and-control (C2) server is a classic indicator of compromise (IoC). Compromised hosts often beacon outbound to C2 infrastructure using HTTP, HTTPS, or DNS tunnels to receive instructions or exfiltrate data. This pattern is distinct from normal traffic and is a primary focus of network security monitoring and intrusion detection systems (IDS).

Exam trap

The trap here is that candidates may confuse anomalous outbound traffic with a network misconfiguration or a benign user activity, failing to recognize that beaconing to a known malicious destination is a definitive sign of compromise, not a configuration error or a DDoS symptom.

How to eliminate wrong answers

Option A is wrong because a misconfigured firewall would typically cause blocked or dropped traffic, not specifically targeted outbound connections to a known C2 server; firewall misconfigurations rarely produce beaconing behavior to a single external IP. Option C is wrong because streaming video to a personal server would generate high-bandwidth, continuous traffic to a likely consumer CDN or IP, not periodic, low-and-slow beaconing to a known malicious C2 server. Option D is wrong because a DDoS attack involves a flood of traffic from many sources to a target, not anomalous outbound traffic from a single internal host to a specific C2 server.

697
Multi-Selectmedium

During a code review, a developer identifies that the application uses a custom encryption algorithm for storing sensitive data. Which THREE of the following are secure cryptographic practices that should be recommended instead?

Select 3 answers
A.Using industry-standard algorithms (e.g., AES-256)
B.Implementing proper key management practices
C.Using authenticated encryption (e.g., AES-GCM)
D.Hashing the data with MD5 for faster performance
E.Using a static IV for simplicity
AnswersA, B, C

Industry-standard cryptographic algorithms like AES-256 undergo extensive public scrutiny and cryptanalysis by experts worldwide. This rigorous vetting process helps identify and mitigate potential vulnerabilities, ensuring their robustness against known attack methods and providing a high level of confidence in their security. Relying on such well-established algorithms is fundamental for achieving strong confidentiality and integrity in data protection, as opposed to proprietary or unproven methods.

Why this answer

Option A is correct because industry-standard, peer-reviewed algorithms such as AES-256 have undergone extensive cryptanalysis and are the accepted baseline for symmetric encryption, unlike custom algorithms that typically contain undiscovered weaknesses. Option B is correct because even a strong algorithm like AES is useless if keys are hardcoded, reused, or stored insecurely; proper key management (secure generation, rotation, storage in HSMs/KMS, and separation of duties) is essential to protect sensitive data. Option C is correct because authenticated encryption such as AES-GCM provides both confidentiality and integrity/authenticity, preventing tampering and padding-oracle style attacks that unauthenticated modes like AES-CBC are vulnerable to.

Option D is not recommended because MD5 is a broken hash (collisions demonstrated) and hashing is not encryption—it is unsuitable for protecting data that must be retrieved. Option E is not recommended because a static IV causes identical plaintexts to produce identical ciphertexts, leaking patterns and enabling replay or chosen-plaintext attacks; IVs must be unique/random per encryption operation.

Exam trap

The trap here is that candidates may think 'any encryption is better than none' or that 'hashing is a form of encryption,' but the CISSP exam emphasizes that custom algorithms and broken hashes like MD5 are never acceptable for protecting sensitive data, and that proper cryptographic practices require standards, key management, and authenticated modes.

698
MCQhard

A security architect is designing a secure enclave for processing highly sensitive data. The architecture must ensure that even if the operating system is compromised, the enclave's memory contents remain confidential and integrity-protected. Which technology should be used?

A.Full disk encryption (FDE) with a strong passphrase
B.Trusted Platform Module (TPM)
C.Hypervisor-based isolation
D.Intel Software Guard Extensions (SGX)
AnswerD

Intel Software Guard Extensions (SGX) enables applications to create hardware-enforced secure enclaves, which are isolated regions of memory and CPU execution. These enclaves protect code and data from unauthorized access or modification by any other software on the system, including the operating system, hypervisor, and even BIOS/firmware. This robust isolation ensures the confidentiality and integrity of sensitive processing, even on a potentially compromised host.

Why this answer

Intel Software Guard Extensions (SGX) is the correct choice because it provides hardware-enforced isolation of memory regions (enclaves) that remain confidential and integrity-protected even if the operating system or hypervisor is compromised. SGX encrypts enclave memory on-die and decrypts it only within the CPU, preventing any privileged software from reading or tampering with the data.

Exam trap

The trap here is that candidates confuse TPM's boot-time integrity measurement with runtime memory protection, or assume hypervisor isolation is sufficient against a compromised OS, not realizing SGX provides hardware-enforced enclave isolation that persists even when the OS is untrusted.

How to eliminate wrong answers

Option A is wrong because full disk encryption (FDE) protects data at rest on the storage device but does not protect memory contents; once the OS is booted and data is loaded into RAM, FDE offers no confidentiality or integrity protection against a compromised OS. Option B is wrong because the Trusted Platform Module (TPM) is a hardware security chip that provides secure storage for keys and attestation of boot integrity, but it does not isolate runtime memory or protect enclave contents from a compromised OS. Option C is wrong because hypervisor-based isolation relies on the hypervisor being trusted; if the OS is compromised, the hypervisor could also be attacked or bypassed, and it does not provide hardware-level memory encryption to protect against privileged software.

699
MCQmedium

A security analyst is evaluating the risk of a data breach in a healthcare organization. The asset value of the patient database is $500,000, and the exposure factor is 0.2. The annual rate of occurrence is estimated at 0.1. What is the annualized loss expectancy (ALE)?

A.$10,000
B.$5,000
C.$50,000
D.$100,000
AnswerA

This option correctly calculates the Annualized Loss Expectancy (ALE) using the formula ALE = SLE × ARO. With an Asset Value (AV) of $500,000 and an Exposure Factor (EF) of 0.20, the Single Loss Expectancy (SLE) is $100,000. Multiplying this SLE by the Annualized Rate of Occurrence (ARO) of 0.10 yields the correct annualized risk value of $10,000.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE = Asset Value × Exposure Factor = $500,000 × 0.2 = $100,000. ALE = SLE × ARO = $100,000 × 0.1 = $10,000.

Therefore, the ALE is $10,000.

Exam trap

CISSP often tests whether candidates can correctly sequence the formulas — the trap is stopping at SLE ($100,000) or misapplying ARO, so candidates must remember ALE = AV × EF × ARO.

How to eliminate wrong answers

Option B is wrong because $5,000 results from incorrectly multiplying asset value by ARO and exposure factor in the wrong order or using a different formula (e.g., $500,000 × 0.1 × 0.1). Option C is wrong because $50,000 is the asset value multiplied by ARO ($500,000 × 0.1), omitting the exposure factor. Option D is wrong because $100,000 is the SLE (asset value × exposure factor) but not annualized — it ignores the ARO of 0.1.

700
MCQhard

A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?

A.RAM contents
B.CPU registers
C.Hard disk contents
D.Network connections
AnswerB

CPU registers represent the absolute most volatile data on a live system, holding the processor's current operational state, including instructions, memory addresses, and data actively being processed. Any interruption of power or even a context switch can instantly alter or erase this information. Capturing CPU registers first is paramount because they provide the most immediate and granular insight into what the system was doing at the precise moment of forensic interest, making them the highest priority in the order of volatility.

Why this answer

The order of volatility ranks evidence by how quickly it disappears, and CPU registers/cache are the most volatile — they change with every instruction cycle and are lost the instant power is cut or the process is preempted. Capturing CPU registers first preserves the most perishable evidence before it is overwritten. RAM, disk, and network connections are progressively less volatile by comparison.

Exam trap

The trap here is assuming RAM is always the most volatile — candidates forget that CPU registers and cache sit above RAM in the RFC 3227 order of volatility and must be captured first.

How to eliminate wrong answers

Option A is wrong because RAM contents, while highly volatile, are less volatile than CPU registers and cache — RAM persists as long as power is maintained, whereas registers change every clock cycle. Option C is wrong because hard disk contents are the least volatile of the listed items and should be captured last, after all memory and network state. Option D is wrong because network connections (and their associated state) are more volatile than disk but less volatile than RAM and registers; they should be captured after registers and RAM but before disk.

701
MCQhard

An organization develops a SaaS platform that integrates with multiple third-party services via APIs. The platform handles authentication tokens and user data. A security review reveals that the platform uses hardcoded API keys in the source code. What is the most secure way to manage these secrets in a cloud-native environment?

A.Use environment variables in the deployment configuration.
B.Use .gitignore to prevent them from being committed.
C.Encrypt the secrets and store them in the database.
D.Store secrets in a dedicated secrets management service like AWS Secrets Manager or Azure Key Vault.
AnswerD

Storing secrets in a dedicated secrets management service like AWS Secrets Manager or Azure Key Vault is the most secure and recommended practice. These services provide centralized, highly secure storage, isolating secrets from application code and infrastructure. They offer robust access control mechanisms, comprehensive audit trails, automatic rotation capabilities, and often integrate with hardware security modules (HSMs) for key protection, significantly reducing the attack surface and operational burden of managing sensitive credentials.

Why this answer

Dedicated secrets management services like AWS Secrets Manager or Azure Key Vault provide secure storage, automatic rotation, and fine-grained access control for API keys and tokens. They eliminate the risk of hardcoded secrets in source code or configuration files, which is critical in a cloud-native SaaS platform that integrates with multiple third-party services.

Exam trap

The trap here is that candidates often choose environment variables (Option A) thinking they are secure enough, but the CISSP exam emphasizes that environment variables are not a secure storage solution because they can be leaked through debugging, logging, or container orchestration tools.

How to eliminate wrong answers

Option A is wrong because environment variables can be exposed through process dumps, logs, or container inspection, and they do not provide encryption at rest or rotation capabilities. Option B is wrong because .gitignore only prevents files from being committed to version control but does not protect secrets already in the environment or prevent them from being exposed through other means. Option C is wrong because storing encrypted secrets in the database still requires managing the encryption key within the application, which reintroduces the same secret management problem and increases the attack surface.

702
MCQhard

An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?

A.Privileged access management
B.Access recertification
C.Deprovisioning
D.Separation of duties
AnswerC

Deprovisioning is the critical phase within the identity and access management (IAM) lifecycle that systematically revokes all access rights and disables or deletes user accounts when an individual's relationship with the organization ends or their role changes significantly. This process ensures that former employees or contractors can no longer access corporate resources, mitigating the risk of unauthorized access and data breaches. Effective deprovisioning involves removing access across all connected systems, applications, and physical access controls in a timely and comprehensive manner.

Why this answer

Deprovisioning is the process of removing user accounts and access rights when an employee leaves the organization. It directly addresses the requirement to promptly revoke all access, ensuring that the former employee cannot authenticate or authorize any actions within the system. This process typically involves disabling or deleting the user object in the directory service (e.g., Active Directory) and removing associated permissions from all resources.

Exam trap

The trap here is that candidates may confuse 'Access Recertification' (a periodic review) with the immediate revocation action required for a leaver, or think 'Privileged Access Management' covers all account removal, when it only addresses high-privilege accounts.

How to eliminate wrong answers

Option A is wrong because Privileged Access Management (PAM) focuses on controlling and monitoring access for privileged accounts (e.g., administrators), not on the general removal of all accounts for a leaver. Option B is wrong because Access Recertification is a periodic review process to validate that existing access rights are still appropriate, not an immediate action to remove access upon termination. Option D is wrong because Separation of Duties is a control principle that prevents conflicts of interest by dividing critical tasks among multiple people, not a process for revoking accounts.

703
MCQmedium

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

A.Transfer
B.Accept
C.Avoid
D.Mitigate
AnswerA

Purchasing cyber insurance is a classic example of risk transfer. This strategy involves shifting the financial responsibility for potential losses, such as those arising from data breaches, ransomware attacks, or business interruption, to a third party—the insurance provider. While the underlying operational risk itself still exists, the financial impact on the company is significantly reduced, as the insurer assumes the cost of recovery, legal fees, and other covered damages. This allows the organization to mitigate the severe financial consequences of a cyber incident without eliminating the threat entirely.

Why this answer

Purchasing cyber insurance shifts the financial impact of a breach to a third party (the insurer), which is the definition of risk transfer. The organization still owns the risk event but transfers the financial consequence. Accept, Avoid, and Mitigate describe retaining, eliminating, or reducing risk, respectively.

Exam trap

CISSP often tests whether candidates equate insurance with mitigation — insurance transfers financial impact, it does not reduce the likelihood or technical impact of the risk.

How to eliminate wrong answers

Option B (Accept) is wrong because acceptance means acknowledging the risk and bearing the loss without action — no third party absorbs the impact. Option C (Avoid) is wrong because avoidance means eliminating the activity that creates the risk entirely (e.g., not storing the data), which insurance does not do. Option D (Mitigate) is wrong because mitigation reduces the likelihood or impact via controls (e.g., encryption, MFA), whereas insurance does not reduce the probability or technical impact — it only compensates financially.

704
Multi-Selecthard

Which TWO of the following are essential components of a quantitative risk analysis formula? (Choose two.)

Select 2 answers
A.Annual Rate of Occurrence (ARO)
B.Exposure Factor (EF)
C.Residual Risk
D.Single Loss Expectancy (SLE)
E.Control Frequency (CF)
AnswersA, D

Annual Rate of Occurrence (ARO) quantifies the expected number of times a specific risk event is projected to occur within a single year. It is a critical input for calculating the Annual Loss Expectancy (ALE), where ALE = SLE × ARO. Without an estimated frequency, the annual financial impact of a risk cannot be accurately projected, making it an indispensable element for quantitative risk assessment.

Why this answer

In quantitative risk analysis, the formula for calculating Annualized Loss Expectancy (ALE) is ALE = SLE × ARO. The Single Loss Expectancy (SLE) represents the monetary loss expected from a single occurrence of a risk, calculated as Asset Value × Exposure Factor (EF). The Annual Rate of Occurrence (ARO) is the expected frequency of that risk occurring per year.

Both SLE and ARO are direct, essential multipliers in the core ALE formula, making them fundamental components of the quantitative risk analysis equation.

Exam trap

The trap here is that candidates often confuse Exposure Factor (EF) as a direct component of the final formula, when in fact it is an intermediate input to SLE, not a standalone variable in the ALE equation; similarly, Residual Risk is a post-control metric, not a formula component, and Control Frequency is a fabricated term not found in any standard risk analysis framework.

705
Multi-Selectmedium

An organization is implementing role-based access control (RBAC). Which two components are fundamental to the RBAC model? (Select TWO.)

Select 2 answers
A.Access control lists (ACLs)
B.Subjects, objects, and operations
C.Constraints such as separation of duties
D.Roles, permissions, and user assignments
E.Security labels and clearances
AnswersC, D

Constraints are an integral and advanced feature of robust RBAC implementations, designed to enforce organizational security policies beyond simple permission grants. Separation of duties (SoD), for example, is a critical constraint that prevents a single user from being assigned conflicting roles or permissions that could lead to fraud or error. These constraints ensure that the accumulation of privileges by any individual is carefully controlled, thereby enhancing the overall security posture.

Why this answer

Constraints such as separation of duties are fundamental to RBAC because they enforce organizational policies by preventing conflicts of interest (e.g., a user cannot both create and approve a purchase order). This is a core component of the RBAC model as defined in the NIST RBAC standard (ANSI INCITS 359-2004), which includes core RBAC, hierarchical RBAC, and constrained RBAC. Constraints ensure that role assignments and permissions adhere to security rules beyond simple role-user mapping.

Exam trap

The trap here is that candidates often confuse the generic components of access control (subjects, objects, operations) with the specific fundamental components of the RBAC model, leading them to select Option B instead of recognizing that roles, permissions, user assignments, and constraints are the unique building blocks of RBAC.

706
MCQeasy

An organization needs to ensure that backup tapes containing sensitive data are protected during transportation between sites. What is the most effective control?

A.Applying tamper-evident seals
B.Encrypting the backup tapes
C.Using a chain of custody log
D.Using a bonded courier service
AnswerB

Encrypting backup tapes is the most effective method to ensure data confidentiality, both when the tapes are at rest and during transit. This process transforms the data into an unreadable format, making it unintelligible to anyone without the proper decryption key. Even if a tape is lost or stolen, the sensitive information remains protected from unauthorized disclosure, directly addressing the need to prevent data exposure.

Why this answer

Encrypting the backup tapes ensures that even if the physical media is lost, stolen, or intercepted during transit, the sensitive data remains unreadable without the decryption key. This provides a strong, data-centric security control that protects confidentiality regardless of the physical security measures in place. Encryption is the most effective control because it directly addresses the risk of unauthorized access to the data itself.

Exam trap

The trap here is that candidates often choose a physical security control (like tamper-evident seals or bonded couriers) thinking it is sufficient, but the CISSP exam emphasizes that data-centric controls (encryption) are the most effective for protecting data in transit, as physical controls can be bypassed or fail.

How to eliminate wrong answers

Option A is wrong because tamper-evident seals only indicate whether the tape has been physically opened or tampered with; they do not protect the data from being read if the seal is bypassed or the tape is accessed through other means. Option C is wrong because a chain of custody log provides an audit trail of who handled the tape and when, but it does not prevent unauthorized access to the data if the tape is lost or stolen. Option D is wrong because a bonded courier service reduces the risk of theft or loss during transit, but it does not protect the data if the courier is compromised or the tape is intercepted; encryption is still needed to ensure confidentiality.

707
MCQeasy

Which VPN technology operates at Layer 2 of the OSI model and is often used in combination with IPsec to provide encryption?

A.L2TP
B.WireGuard
C.IPsec
D.PPTP
AnswerA

Layer 2 Tunneling Protocol (L2TP) operates at Layer 2 (Data Link Layer) of the OSI model, encapsulating PPP frames to create a tunnel. It provides tunneling capabilities for various network protocols, effectively extending the Layer 2 network across an IP network. While L2TP itself does not provide encryption, it is commonly paired with IPsec (which operates at Layer 3) to secure the encapsulated data, forming an L2TP/IPsec VPN. This combination allows for secure, multi-protocol traffic over an IP network.

Why this answer

L2TP (Layer 2 Tunneling Protocol) operates at Layer 2 of the OSI model, encapsulating PPP frames to create a virtual point-to-point link. It is commonly combined with IPsec (specifically ESP in tunnel mode) to provide encryption, authentication, and integrity, as L2TP itself offers no confidentiality. This combination is defined in RFC 3193 and is widely used for remote-access VPNs.

Exam trap

A common misconception in the CISSP exam is that IPsec is a Layer 2 protocol when it actually operates at Layer 3. Additionally, candidates often mistakenly believe that L2TP provides encryption, but it does not—it relies on IPsec for security. Remember that L2TP is a tunneling protocol at Layer 2 and must be combined with IPsec for confidentiality.

How to eliminate wrong answers

Option B (WireGuard) is wrong because it operates at Layer 3 (network layer) and uses its own cryptographic protocol (Noise_IK) for encryption, not Layer 2, and is not typically combined with IPsec. Option C (IPsec) is wrong because it operates at Layer 3 and provides encryption natively; it is the security layer added to L2TP, not the Layer 2 tunneling protocol itself. Option D (PPTP) is wrong because, although it operates at Layer 2, it uses MPPE for encryption and is not commonly combined with IPsec; it is considered deprecated due to known security vulnerabilities (e.g., MS-CHAPv2 weaknesses).

708
Multi-Selectmedium

A security manager is planning a penetration test and needs to ensure proper rules of engagement are established. Which TWO of the following are essential components of the rules of engagement?

Select 2 answers
A.Vulnerability scoring methodology
B.Scope definition including in-scope systems
C.Written authorization from management
D.Previous test results
E.List of tools to be used
AnswersB, C

Defining the scope, including specific in-scope systems, IP ranges, applications, and excluded assets, is absolutely foundational for any penetration test. This critical step establishes the precise boundaries of the engagement, preventing unauthorized testing of systems and ensuring legal and ethical compliance. Without a clear scope, testers risk legal repercussions for exceeding authorization, and the client risks unexpected disruption to critical out-of-scope services.

Why this answer

Scope definition (B) is essential because it explicitly lists in-scope systems, IP ranges, and exclusions, preventing unauthorized access and legal liability. Written authorization from management (C) provides the legal and contractual basis for the test, ensuring the penetration test is conducted with informed consent and documented approval.

Exam trap

The trap here is that candidates confuse 'rules of engagement' with the broader 'penetration testing methodology' and mistakenly include operational details like tool lists or scoring methods, which are not required for defining the legal and authorization boundaries.

709
MCQmedium

Which of the following is a primary advantage of using a hardware security module (HSM) over software-based key storage?

A.Easier key backup
B.Lower cost
C.Tamper-resistant physical security
D.Faster key generation
AnswerC

A primary advantage of Hardware Security Modules (HSMs) is their robust tamper-resistant physical security, which is paramount for protecting cryptographic keys. HSMs are engineered with physical safeguards such as tamper-evident seals, tamper-responsive circuitry that can zeroize keys upon detection of an attack, and secure enclosures to prevent unauthorized access or extraction. This physical hardening provides a level of protection against direct physical manipulation that software-only solutions cannot match, ensuring key integrity even in compromised physical environments.

Why this answer

A hardware security module (HSM) provides tamper-resistant physical security by storing cryptographic keys in a dedicated, hardened appliance that resists physical tampering, probing, and extraction. Unlike software-based key storage, which relies on the operating system's file system or memory and is vulnerable to malware or direct memory access attacks, an HSM ensures that keys never leave the secure boundary in plaintext, even if the host system is compromised.

Exam trap

The trap here is that candidates confuse 'faster key generation' (a performance benefit) with the primary security advantage of HSMs, or they assume that software-based key backup is inherently more difficult, when in fact HSMs introduce additional complexity for backup to maintain security.

How to eliminate wrong answers

Option A is wrong because key backup from an HSM is typically more complex than software-based storage, often requiring secure key-wrapping or cloning procedures to maintain the same level of protection, whereas software keys can be easily copied as files. Option B is wrong because HSMs are significantly more expensive than software-based storage due to specialized hardware, certifications (e.g., FIPS 140-2 Level 3/4), and lifecycle management costs. Option D is wrong because while HSMs can accelerate key generation using dedicated hardware random number generators, software-based key generation can also be fast using CPU-based RDRAND or similar instructions, and speed is not the primary security advantage of an HSM.

710
Multi-Selectmedium

Which THREE of the following are key practices in the OWASP ASVS (Application Security Verification Standard) for secure software? (Select exactly three.)

Select 3 answers
A.Secure error handling and logging
B.Integration with password managers
C.Authentication and session management
D.Network segmentation between tiers
E.Input validation and sanitization
AnswersA, C, E

Secure error handling and logging are critical OWASP practices that prevent applications from leaking sensitive system information, such as stack traces or database errors, which attackers could exploit. Concurrently, robust logging captures security-relevant events, including failed authentication attempts and access violations, enabling timely detection and response to security incidents. This aligns directly with OWASP ASVS V7 requirements for comprehensive error handling and logging mechanisms.

Why this answer

Option A (Secure error handling and logging) is correct because ASVS V7 requires applications to handle errors safely and log security-relevant events without leaking sensitive data such as stack traces, credentials, or internal paths. Option C (Authentication and session management) is correct because ASVS V2 and V3 define requirements for credential storage, password policies, MFA, session token entropy, and session invalidation. Option E (Input validation and sanitization) is correct because ASVS V5 mandates server-side input validation and output encoding to prevent injection flaws like SQLi and XSS.

Option B (Integration with password managers) is not an ASVS practice; ASVS addresses password handling requirements, not client-side password manager integration. Option D (Network segmentation between tiers) is not part of ASVS, which focuses on application-level security requirements rather than infrastructure network architecture.

Exam trap

Candidates often confuse general security best practices (like network segmentation or password manager integration) with the specific, application-focused requirements of OWASP ASVS, which is strictly about software security verification at the code and design level, not infrastructure or external tool integration.

711
MCQmedium

A financial institution is implementing a data retention policy to comply with regulatory requirements. The policy must ensure that transaction records are retained for 7 years and then securely destroyed. Which of the following is the BEST approach to implement this policy?

A.Encrypt all records and destroy the encryption keys after 7 years
B.Automatically purge records using a data management tool that overwrites data after the retention period
C.Move records to a separate archive and delete the directory pointers
D.Manually review and delete records after 7 years
AnswerB

This method provides the most robust and compliant approach to data destruction. Automated data management tools can reliably identify records past their retention period and apply secure overwriting techniques, such as multiple passes with random data, to render the original data unrecoverable. This minimizes human error, ensures consistent application of the policy, and meets regulatory requirements for data sanitization.

Why this answer

Automated purging using a data management tool that overwrites data ensures that the records are securely destroyed at the end of the retention period, meeting both regulatory compliance and data sanitization requirements. Overwriting (e.g., using DoD 5220.22-M or NIST SP 800-88 standards) prevents data recovery by replacing the storage media's bits with patterns, making it a reliable method for secure destruction in a financial institution's automated environment.

Exam trap

The trap here is that candidates often confuse 'cryptographic erasure' (Option A) with secure destruction, but the CISSP exam emphasizes that destroying encryption keys does not physically destroy the data and is not considered a secure destruction method for regulatory compliance unless combined with other controls.

How to eliminate wrong answers

Option A is wrong because encrypting records and destroying the encryption keys after 7 years does not securely destroy the underlying data; the ciphertext remains on the media and could potentially be decrypted in the future if the encryption algorithm is broken or if key recovery is possible, violating the 'secure destruction' requirement. Option C is wrong because moving records to a separate archive and deleting directory pointers only removes the file system references, leaving the actual data intact on the storage media, which can be recovered using forensic tools and does not constitute secure destruction. Option D is wrong because manual review and deletion after 7 years is prone to human error, lacks audit trails, and does not guarantee that data is securely overwritten or destroyed, failing to meet the policy's requirement for reliable and verifiable destruction.

712
Multi-Selectmedium

During a penetration testing engagement, which TWO of the following are essential components of the rules of engagement document?

Select 2 answers
A.Vulnerability severity ratings
B.Emergency stop criteria
C.Detailed exploit code
D.Scope definition including target systems
E.Written authorization from management
AnswersB, D

Emergency stop criteria are a fundamental component of the Rules of Engagement (ROE), meticulously outlining specific conditions under which all penetration testing activities must immediately cease. These conditions typically include critical system instability, unauthorized data exfiltration, detection by the client's security operations center leading to incident response, or any activity that risks legal or ethical boundaries. Their inclusion is paramount for effective risk management, safeguarding client systems, and preventing unintended harm during the engagement.

Why this answer

In penetration testing, the rules of engagement (ROE) document defines the operational parameters, including emergency stop criteria (Option B) and scope definition (Option D). Written authorization from management (Option E) is a separate prerequisite document granting legal permission to test; it is not part of the ROE. Vulnerability severity ratings (Option A) are found in the final report, and detailed exploit code (Option C) is a technical artifact not included in the ROE.

Exam trap

In the CISSP exam, candidates often mistakenly include 'written authorization from management' as a component of the rules of engagement (ROE) when it is actually a separate prerequisite document. The ROE contains operational constraints like emergency stop criteria and scope definition, while authorization is a distinct legal permission to test.

713
MCQeasy

You are the lead security analyst at a mid-sized financial services firm. At 2:15 PM, the SIEM alerts on multiple failed login attempts from an external IP address against the VPN gateway. The attempts stopped at 2:20 PM, but at 2:30 PM, a user reports that their account was used to send a phishing email to internal employees. You confirm that the user's account has been compromised. The CEO asks for an immediate update. What should be your FIRST action according to the incident response framework your company follows (based on NIST SP 800-61)?

A.Preserve forensic evidence by creating a disk image of the user's workstation.
B.Validate the incident and assess its scope and impact.
C.Immediately notify the legal and compliance teams.
D.Isolate the compromised workstation from the network.
AnswerB

Validating the incident is the crucial first step, confirming that a genuine security event has occurred rather than a false alarm or operational issue. Concurrently, assessing the scope identifies affected systems and data, while impact assessment quantifies potential damage, guiding the prioritization of subsequent response activities. This dual action ensures resources are effectively allocated and prevents unnecessary disruption from non-incidents, establishing a solid foundation for the entire response process.

Why this answer

According to NIST SP 800-61, the first phase of incident response is preparation, followed by detection and analysis. The SIEM alert and user report indicate a potential incident, but you must first validate the incident and assess its scope and impact before taking containment, eradication, or recovery actions. This ensures that resources are not wasted on a false positive and that the response is proportional to the actual threat.

Exam trap

The trap here is that candidates confuse containment actions (like isolation) with the first step, but NIST SP 800-61 mandates validation and scoping before any containment to ensure the response is appropriate and not disruptive.

How to eliminate wrong answers

Option A is wrong because preserving forensic evidence (e.g., creating a disk image) is a step that occurs after the incident has been validated and scoped; performing it prematurely could waste resources if the incident is a false positive or if the scope extends beyond that single workstation. Option C is wrong because notifying legal and compliance teams is a communication step that typically follows validation and initial containment, not the first action; immediate notification without confirmed scope could cause unnecessary escalation or legal exposure. Option D is wrong because isolating the compromised workstation is a containment action that should be taken after the incident is validated and its scope assessed; premature isolation could disrupt business operations or alert an attacker before full understanding of the incident.

714
MCQhard

An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?

A.Integrating patch deployment with change management
B.Applying patches as soon as they are released
C.Scanning for vulnerabilities weekly
D.Using automated patch tools
AnswerA

Integrating patch deployment with change management ensures that all updates undergo a formal process of planning, testing, scheduling, and approval before implementation. This structured approach minimizes the risk of introducing new vulnerabilities, system instability, or service disruptions by verifying compatibility and functionality in a controlled environment. It also provides a clear audit trail and rollback plan, which are critical for maintaining system integrity and operational continuity.

Why this answer

Integrating patch deployment with change management ensures patches are assessed, approved, scheduled, and rolled back if needed, which is the most critical step to avoid disrupting critical business operations. Change management provides the governance and risk review that prevents untested patches from breaking production.

Exam trap

CISSP often tests the tension between speed and stability, so the trap is choosing immediate patching or automation when the question emphasizes avoiding disruption to critical operations.

How to eliminate wrong answers

Option B is wrong because applying patches immediately without testing or approval can introduce regressions and outages. Option C is wrong because weekly vulnerability scanning identifies gaps but does not control how patches are deployed. Option D is wrong because automated patch tools improve efficiency but do not by themselves prevent business disruption without change control.

715
MCQhard

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

A.A cloud service provider hosting ePHI
B.A janitorial service that cleans the office
C.A government regulator conducting an audit
D.A patient requesting their medical records
AnswerA

A cloud service provider that hosts electronic Protected Health Information (ePHI) on behalf of a covered entity is unequivocally a Business Associate under HIPAA. By storing or processing ePHI, the CSP creates, receives, maintains, or transmits this data, making them directly subject to HIPAA's Security Rule and certain aspects of the Privacy Rule. A Business Associate Agreement (BAA) is mandatory to define their responsibilities and ensure appropriate safeguards are in place for the ePHI.

Why this answer

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with a cloud service provider that hosts electronic protected health information (ePHI). This is because the cloud provider is a business associate, as it creates, receives, maintains, or transmits ePHI on behalf of the covered entity. The BAA ensures the business associate safeguards the ePHI and complies with HIPAA.

Exam trap

CISSP often tests the definition of a business associate, and candidates may incorrectly include entities that do not handle PHI, such as janitorial services or patients themselves.

How to eliminate wrong answers

Option B is wrong because a janitorial service that cleans the office does not typically access ePHI, so it is not a business associate. Option C is wrong because a government regulator conducting an audit is not a business associate; they are an oversight entity. Option D is wrong because a patient requesting their medical records is the subject of the records, not a business associate; they have rights to access but are not performing functions on behalf of the covered entity.

716
MCQeasy

Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

A.BCP ensures continuity of business operations; DRP restores IT infrastructure
B.BCP only addresses natural disasters; DRP addresses all disasters
C.BCP is tested annually; DRP is tested monthly
D.BCP focuses on IT restoration; DRP focuses on business processes
AnswerA

The Business Continuity Plan (BCP) is a strategic, high-level plan focused on ensuring the continued operation of critical business functions and processes during and after a disruptive event. Its primary objective is to maintain essential organizational activities, people, and facilities. In contrast, the Disaster Recovery Plan (DRP) is a tactical subset of the BCP, specifically detailing the procedures for restoring an organization's technology infrastructure, including systems, applications, and data, to an operational state.

Why this answer

The key difference is that a Business Continuity Plan (BCP) ensures the continuity of critical business operations during and after a disruption, while a Disaster Recovery Plan (DRP) focuses specifically on restoring IT infrastructure and systems. BCP is broader, encompassing processes, people, and facilities, whereas DRP is a subset of BCP that deals with technical recovery.

Exam trap

CISSP often tests the confusion between BCP and DRP, where candidates might think BCP is IT-focused and DRP is business-focused, but it's the opposite; also, testing frequency is not a defining characteristic.

How to eliminate wrong answers

Option B is wrong because BCP addresses all types of disruptions, not just natural disasters; DRP also addresses all disasters, so the distinction is incorrect. Option C is wrong because testing frequency is not a defining difference; both plans are tested based on organizational requirements, not fixed schedules. Option D is wrong because it reverses the roles: BCP focuses on business processes, while DRP focuses on IT restoration.

717
Multi-Selectmedium

A security engineer is hardening a system against side-channel attacks that exploit variations in execution time or power consumption. Which TWO mitigations are specifically designed to counter such attacks? Select two.

Select 2 answers
A.Data Execution Prevention (DEP)
B.Address Space Layout Randomization (ASLR)
C.Input validation
D.Constant-time algorithms
E.Noise injection in power consumption
AnswersD, E

Constant-time algorithms are specifically designed to execute in a predictable amount of time, regardless of the secret data being processed or the input values. By eliminating data-dependent branches, memory access patterns, or loop iterations, these algorithms prevent timing variations that could otherwise be observed by an attacker to infer sensitive information, such as cryptographic keys. This approach directly counters timing side-channel attacks by removing the observable timing differences.

Why this answer

Constant-time programming ensures operations take the same time regardless of inputs, and noise injection obscures power consumption patterns.

718
MCQmedium

A security architect is designing controls for a cloud-based file storage service that stores personally identifiable information (PII). Which control best ensures that data remains encrypted at rest without involving the cloud provider's key management?

A.Tokenization of PII fields
B.Transport Layer Security (TLS) for data in transit
C.Client-side encryption
D.Server-side encryption with customer-managed keys
AnswerC

Client-side encryption involves encrypting data on the user's device before it is transmitted to or stored in the cloud. The encryption keys are generated and retained exclusively by the client, ensuring that the cloud provider never receives or has access to the plaintext data or the keys required to decrypt it. This approach provides the strongest assurance of data confidentiality against the cloud provider, as they only ever store encrypted ciphertext.

Why this answer

Client-side encryption ensures data is encrypted before it leaves the client device, so the cloud provider never has access to the plaintext or the encryption keys. This guarantees that the data remains encrypted at rest in the cloud storage without relying on the provider's key management infrastructure, meeting the requirement of keeping the provider out of the key management loop.

Exam trap

The trap here is that candidates often confuse server-side encryption with customer-managed keys (Option D) as being fully independent of the provider, but in reality, the provider's key management service still handles the encryption/decryption operations, which does not satisfy the 'without involving the cloud provider's key management' requirement.

How to eliminate wrong answers

Option A is wrong because tokenization replaces PII with non-sensitive tokens, but the original data is still stored elsewhere (often in a token vault) and does not inherently encrypt the data at rest in the cloud storage; it is a data masking technique, not an encryption control. Option B is wrong because Transport Layer Security (TLS) protects data in transit between the client and server, but it does not address encryption at rest; once data reaches the cloud storage, it is decrypted and stored in plaintext unless another mechanism is applied. Option D is wrong because server-side encryption with customer-managed keys still involves the cloud provider's key management service (e.g., AWS KMS, Azure Key Vault) to encrypt/decrypt data; the provider manages the encryption process, even if the customer supplies the key material, which violates the requirement of not involving the provider's key management.

719
MCQeasy

In IPsec, which protocol provides both authentication and encryption for the packet payload, but does not encrypt the IP header?

A.IKE (Internet Key Exchange)
B.ISAKMP (Internet Security Association and Key Management Protocol)
C.ESP (Encapsulating Security Payload)
D.AH (Authentication Header)
AnswerC

Encapsulating Security Payload (ESP) is an IPSec protocol specifically designed to provide both confidentiality and integrity for data packets. It achieves confidentiality through encryption of the data payload and provides integrity and authentication through a Message Authentication Code (MAC) or digital signature. ESP can operate in either transport mode, encrypting only the payload, or tunnel mode, encrypting the entire original IP packet, making it the correct choice for both services.

Why this answer

ESP (Encapsulating Security Payload) provides both authentication and encryption for the packet payload, while leaving the IP header unencrypted. This allows intermediate routers to process the packet normally, as the header remains in plaintext, but the payload is protected for confidentiality and integrity.

Exam trap

A common pitfall in CISSP is confusing ESP and AH: ESP provides encryption and optionally authentication, while AH provides authentication only. ESP encrypts the payload but leaves the IP header unencrypted; AH authenticates the entire packet (including header) but provides no encryption. Candidates often mistakenly choose AH when encryption is required.

How to eliminate wrong answers

Option A is wrong because IKE (Internet Key Exchange) is a protocol used to establish security associations (SAs) and exchange cryptographic keys, not to directly encrypt or authenticate packet payloads. Option B is wrong because ISAKMP (Internet Security Association and Key Management Protocol) provides a framework for SA negotiation and key management, but does not itself perform payload encryption or authentication. Option D is wrong because AH (Authentication Header) provides integrity and authentication for the entire packet (including the IP header) but does not offer encryption, so it cannot encrypt the payload.

720
MCQeasy

A company needs to provide secure remote access to employees using company-issued laptops. The solution must support both web applications and legacy client-server apps without installing client software on the laptops. Which VPN technology is best?

A.SSL VPN with clientless web access and port forwarding
B.L2TP over IPsec
C.MPLS Layer 3 VPN
D.IPsec tunnel mode
AnswerA

SSL VPNs with clientless web access leverage standard web browsers to provide secure, encrypted access to web-based applications without requiring dedicated client software installation. For legacy or non-web applications, they can utilize port forwarding, often through a lightweight browser plugin or a small downloadable client, to securely tunnel traffic. This hybrid approach offers significant flexibility, meeting diverse remote access needs by supporting both clientless browser-based access and client-assisted access for other protocols.

Why this answer

SSL VPN with clientless web access and port forwarding is the best choice because it meets the requirement of supporting both web applications and legacy client-server apps without installing client software. Clientless web access provides secure HTTPS-based access to internal web applications via a browser, while port forwarding allows legacy TCP-based client-server applications to be tunneled through the SSL VPN without requiring a full VPN client on the laptop. This approach leverages the existing browser and OS capabilities, eliminating the need for additional software installation.

Exam trap

The trap here is that candidates often assume IPsec (Option D) is the only 'secure' VPN option and overlook that SSL VPNs can provide equivalent security with clientless access, or they confuse MPLS (Option C) as a remote access solution when it is actually a WAN technology for site-to-site connectivity.

How to eliminate wrong answers

Option B (L2TP over IPsec) is wrong because it requires a native VPN client or OS-level configuration on the laptop, which contradicts the 'without installing client software' requirement; it also does not natively support clientless web access. Option C (MPLS Layer 3 VPN) is wrong because it is a service provider technology for connecting entire networks at Layer 3, not a remote access VPN for individual endpoints, and it requires MPLS-capable routers and no user-level authentication or clientless access. Option D (IPsec tunnel mode) is wrong because it requires a dedicated IPsec client or OS-level VPN stack to be installed or configured on the laptop, and it does not provide clientless web access or port forwarding for legacy apps without additional software.

721
MCQmedium

During a digital forensics investigation, which of the following data sources has the highest order of volatility?

A.CPU registers
B.Remote logging server
C.Network packets in transit
D.Hard disk drive
AnswerA

CPU registers represent the absolute highest level of data volatility in a system. These tiny, high-speed storage locations are integral to the CPU's operation, holding data and instructions actively being processed. Their contents are transient, changing with every clock cycle and being completely lost the moment power is interrupted or the operating system performs a context switch, making them critical to capture first in a forensic investigation.

Why this answer

CPU registers have the highest order of volatility because they hold the most transient data — values change with every instruction cycle and are lost when power is removed or the process is context-switched. In digital forensics, the order of volatility (RFC 3227) dictates that you collect the most volatile data first, starting with CPU registers and cache, then memory, then network state, then disk.

Exam trap

The trap is confusing 'network packets in transit' as highly volatile — they are volatile, but CPU registers are at the very top of the RFC 3227 order, and candidates often overlook registers in favor of more familiar network data.

How to eliminate wrong answers

Option B is wrong because a remote logging server stores data persistently on disk and is one of the least volatile sources — it may even survive the incident. Option C is wrong because network packets in transit are more volatile than disk but less volatile than CPU registers; they can be captured with tools like tcpdump but are not the highest order. Option D is wrong because a hard disk drive is non-volatile storage — data persists after power-off, making it the least volatile of the listed sources.

722
MCQeasy

A security analyst detects repeated failed login attempts from a single external IP address targeting a user account. What is the best IMMEDIATE action?

A.Investigate the source IP's history
B.Block the IP address at the perimeter firewall
C.Disable the targeted user account
D.Enable account lockout after three failures
AnswerB

Blocking the IP address at the perimeter firewall is the most immediate and effective containment action to stop repeated failed login attempts. This network-level control directly prevents further malicious traffic from reaching internal systems, thereby halting the brute-force or credential-stuffing attack in progress. It effectively mitigates the immediate threat without disrupting legitimate users or requiring extensive analysis before action.

Why this answer

Blocking the IP address at the perimeter firewall is the best immediate action because it stops the ongoing brute-force attack at the network boundary, preventing further authentication attempts without affecting the legitimate user's access. This aligns with the principle of containment in incident response, prioritizing rapid mitigation over investigation or configuration changes that could delay the response.

Exam trap

The trap here is that candidates confuse 'immediate action' with 'long-term fix' and choose to investigate the IP (A) or implement a policy change (D), failing to recognize that containment (B) must come first in the incident response process.

How to eliminate wrong answers

Option A is wrong because investigating the source IP's history is a forensic step that should follow containment, not precede it; delaying action allows the attack to continue. Option C is wrong because disabling the targeted user account would deny service to the legitimate user and does not address the external threat, which could simply pivot to another account. Option D is wrong because enabling account lockout after three failures is a preventive configuration change that takes time to implement and does not stop the current attack in progress; it also risks locking out the legitimate user if the attacker triggers the threshold.

723
MCQhard

An organization is adopting a microservices architecture. Which security control is most effective for ensuring that inter-service communication is authenticated and authorized?

A.Implementing mutual TLS (mTLS) between services
B.Relying on network segmentation and IP allowlisting
C.Using JSON Web Tokens (JWT) in the HTTP header
D.Using pre-shared API keys for each service pair
AnswerA

Implementing mutual TLS (mTLS) between services establishes a robust security foundation by requiring both the client and server services to present and validate cryptographic certificates during connection establishment. This ensures strong, bidirectional identity verification, preventing unauthorized services from communicating. Furthermore, mTLS encrypts all data in transit, protecting sensitive information from eavesdropping and tampering, which is critical for maintaining confidentiality and integrity across a distributed microservices landscape.

Why this answer

Mutual TLS (mTLS) is the most effective control because it provides both authentication and encryption for inter-service communication. In a microservices architecture, mTLS ensures that each service presents a valid X.509 certificate, and both sides verify each other's identity before any data exchange, preventing unauthorized or spoofed services from communicating. This aligns with the principle of zero trust, where no implicit trust is granted based on network location.

Exam trap

The trap here is that candidates often pick JWT (Option C) because it is commonly used for user authentication, but they overlook that JWT alone does not encrypt the channel or provide mutual authentication between services, which is critical for inter-service communication in a microservices architecture.

How to eliminate wrong answers

Option B is wrong because network segmentation and IP allowlisting only control access at the network layer and do not authenticate the identity of the calling service; IP addresses can be spoofed or changed in dynamic environments like containers. Option C is wrong because JWT in the HTTP header provides authentication of the token issuer but does not encrypt the communication channel, leaving it vulnerable to interception or replay attacks unless combined with TLS; it also does not provide mutual authentication. Option D is wrong because pre-shared API keys for each service pair are static credentials that are difficult to rotate at scale, lack built-in encryption, and are vulnerable to leakage or compromise without a secure channel.

724
Multi-Selecthard

Which THREE of the following are key components of a disaster recovery plan for a hot site? (Select three)

Select 3 answers
A.Pre-installed servers and workstations
B.Empty space with power and cooling only
C.Real-time data replication from primary site
D.Network connectivity with bandwidth to support operations
E.Long lead time to activate (e.g., weeks)
AnswersA, C, D

A hot site's defining characteristic is its immediate operational readiness. This means all necessary computing hardware, including servers, storage, and end-user workstations, must be pre-installed, configured, and often pre-loaded with essential operating systems and applications. This readiness minimizes recovery time objectives (RTO) by eliminating the need for hardware procurement and setup during a crisis, allowing for rapid business resumption.

Why this answer

A hot site is a fully equipped alternate facility that is ready to operate almost immediately, so pre-installed servers and workstations (A) are essential components because they eliminate procurement and build time during failover. Real-time data replication from the primary site (C) is also required so the hot site holds current, usable data with minimal RPO, typically achieved through synchronous or asynchronous replication. Network connectivity with sufficient bandwidth to support operations (D) is likewise critical, since the hot site must carry production traffic and connect users, systems, and replicated data without performance degradation.

Option B describes a cold site, which provides only space, power, and cooling with no pre-installed equipment, and option E describes a cold or warm site characteristic, since a hot site is designed for rapid activation, often within minutes or hours, not weeks.

Exam trap

CISSP often tests the distinction between hot, warm, and cold sites, and candidates may confuse the characteristics of a hot site with those of a warm or cold site, especially regarding activation time and data replication.

725
MCQeasy

An organization's data retention policy requires that financial records be kept for seven years. After that period, the records must be destroyed in a manner that prevents reconstruction. Which of the following is the best sanitization method for paper records containing sensitive financial data?

A.Cross-cut shredding
B.Overwriting with random patterns multiple times
C.Cryptographic erasure
D.Degaussing with a strong magnetic field
AnswerA

Cross-cut shredding is the most appropriate physical destruction method for paper records containing sensitive financial data. This process cuts paper into small, irregular, confetti-like pieces, making reconstruction practically impossible, unlike strip-cut shredding which leaves longer strips. It ensures that the information cannot be recovered or deciphered, thereby meeting stringent data retention and destruction policy requirements for physical documents.

Why this answer

Cross-cut shredding is the best sanitization method for paper records because it physically destroys the paper into small, unreadable pieces, making reconstruction extremely difficult. It is a widely accepted method for destroying sensitive paper documents. Option A is correct as it meets the requirement to prevent reconstruction.

Exam trap

CISSP often tests the applicability of sanitization methods to different media types, and candidates may incorrectly choose degaussing or overwriting for paper records because they are familiar with those methods for electronic media.

How to eliminate wrong answers

Option B is wrong because overwriting with random patterns is a method for sanitizing magnetic media, not paper; it cannot be applied to paper records. Option C is wrong because cryptographic erasure involves destroying encryption keys for encrypted data, which is not applicable to paper records. Option D is wrong because degaussing uses a strong magnetic field to erase data on magnetic storage media, not paper.

726
MCQhard

A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?

A.Patch compliance percentage
B.ROI of security controls
C.Mean time to remediate critical vulnerabilities
D.Number of open vulnerabilities by severity
AnswerC

Mean time to remediate critical vulnerabilities is a direct and highly effective metric for measuring the operational speed and efficiency of an organization's vulnerability response program. It quantifies the average duration from the initial detection of a critical vulnerability to its complete resolution, including patching, configuration changes, or architectural redesigns. This metric precisely reflects how quickly the security team and supporting IT functions can address the most significant risks, directly indicating the effectiveness of their remediation processes.

Why this answer

Mean time to remediate (MTTR) critical vulnerabilities directly measures how quickly the organization closes its highest-risk exposures, which is the clearest indicator of response speed and program effectiveness. It captures both detection-to-triage and triage-to-fix intervals, so a shrinking MTTR demonstrates improving operational capability. CISSP exam objectives emphasize metrics that reflect responsiveness and risk reduction, not just volume or compliance.

Exam trap

CISSP often tests the difference between coverage/compliance metrics (patch percentage) and responsiveness metrics (MTTR) — candidates pick patch compliance because it sounds like a strong indicator, but the question specifically asks about speed of response.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures coverage (how many systems are patched) rather than speed of response — a system can be 99% compliant yet still take months to patch a newly disclosed critical CVE. Option B is wrong because ROI of security controls is a financial efficiency metric, not a responsiveness or effectiveness measure for vulnerability management. Option D is wrong because the number of open vulnerabilities by severity is a snapshot/backlog metric — it shows exposure volume but says nothing about how fast the team remediates, and a large backlog could still coexist with fast remediation if intake is high.

727
MCQeasy

Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?

A.Media analysis
B.Log analysis
C.Network forensics
D.Memory forensics
AnswerC

Network forensics is the specialized discipline of digital forensics that focuses on monitoring, capturing, storing, and analyzing network traffic to detect intrusions, identify malicious activity, and reconstruct communication events. It involves the examination of network packets, communication protocols, and flow data to understand the origin, nature, and impact of security incidents. This type of forensics directly addresses the capturing and analysis of data in transit across a network, making it the correct answer for examining network traffic.

Why this answer

Network forensics involves capturing, recording, and analyzing network traffic to investigate security incidents, identify intrusions, and gather evidence. It focuses on data in transit, such as packet captures, flow records, and network logs. This distinguishes it from host-based forensics.

Exam trap

CISSP often tests the distinction between network forensics and other types like memory or media forensics; candidates may confuse log analysis with network forensics because logs can be network-related, but the question specifies capturing and analyzing network traffic.

How to eliminate wrong answers

Option A is wrong because media analysis (or disk forensics) involves examining storage media like hard drives for artifacts, not network traffic. Option B is wrong because log analysis examines logs from various sources, which may include network devices, but it is not specifically about capturing and analyzing network traffic; it is a broader category. Option D is wrong because memory forensics analyzes volatile memory (RAM) for artifacts like running processes and encryption keys, not network traffic.

728
Multi-Selecteasy

A security analyst is reviewing the authentication mechanism of a web application. Which TWO of the following are examples of broken authentication vulnerabilities?

Select 2 answers
A.Insecure direct object reference in profile URLs
B.Verbose error messages disclosing user IDs
C.Lack of multi-factor authentication for sensitive actions
D.Session timeout set to 60 minutes
E.Allowing weak passwords without complexity requirements
AnswersC, E

The absence of multi-factor authentication (MFA) for sensitive actions constitutes a significant broken authentication vulnerability. MFA requires users to provide two or more distinct verification factors to gain access, substantially increasing the difficulty for unauthorized users to compromise an account even if one factor (like a password) is stolen. Without MFA, a single compromised credential can grant full access to critical functions, directly weakening the authentication process for high-value operations.

Why this answer

Option C is correct because the absence of multi-factor authentication for sensitive actions is a classic broken authentication weakness: it means a stolen or guessed password alone is sufficient to perform high-risk operations, which OWASP categorizes under broken authentication (e.g., credential stuffing and brute-force success). Option E is correct because permitting weak passwords without complexity or length requirements directly enables brute-force, dictionary, and credential-stuffing attacks against the authentication mechanism, another core broken authentication flaw. Option A is not a broken authentication issue but an access control flaw (IDOR), which falls under broken access control.

Option B describes information disclosure via verbose errors, which is a misconfiguration/information-leakage issue rather than an authentication weakness. Option D, a 60-minute session timeout, is a session management hardening consideration but is not inherently a broken authentication vulnerability, since it is a configurable policy choice rather than a defect in the authentication process itself.

Exam trap

CISSP often tests whether candidates can distinguish authentication failures from access control failures, so they incorrectly select IDOR or verbose errors as broken authentication.

729
MCQeasy

Which type of firewall is capable of inspecting application-layer data, performing SSL decryption, and integrating intrusion prevention capabilities?

A.Packet filter firewall
B.Next-generation firewall
C.Application proxy firewall
D.Stateful firewall
AnswerB

A Next-generation firewall (NGFW) is specifically engineered to perform deep packet inspection up to Layer 7 (application layer) of the OSI model, providing comprehensive application awareness and control. It integrates advanced security features such as intrusion prevention systems (IPS), SSL/TLS decryption, and user identity awareness. This allows NGFWs to identify, classify, and control specific applications and their content, regardless of the port or protocol they use, effectively inspecting application-level traffic for threats and policy violations.

Why this answer

A next-generation firewall (NGFW) goes beyond traditional stateful inspection by incorporating deep packet inspection (DPI) of application-layer data, the ability to decrypt and inspect SSL/TLS traffic, and integrated intrusion prevention system (IPS) capabilities. This convergence allows NGFWs to identify and block threats within encrypted sessions and enforce policies based on application identity rather than just ports and protocols.

Exam trap

The trap here is that candidates often confuse an application proxy firewall with an NGFW, but the key differentiator is that an NGFW integrates SSL decryption and IPS into a single engine, whereas a proxy firewall typically handles only specific application protocols without inline threat prevention.

How to eliminate wrong answers

Option A is wrong because a packet filter firewall operates only at Layers 3 and 4, inspecting source/destination IP addresses and port numbers without any application-layer awareness or SSL decryption capability. Option C is wrong because an application proxy firewall can inspect application-layer data but typically does not perform SSL decryption natively at line rate and lacks integrated intrusion prevention; it acts as an intermediary for specific protocols (e.g., HTTP, FTP) rather than providing unified threat management. Option D is wrong because a stateful firewall tracks connection state (e.g., TCP handshake) at Layers 3 and 4 but cannot inspect application payloads, decrypt SSL, or run an IPS engine.

730
Multi-Selectmedium

A security analyst is reviewing a web application that handles financial transactions. Which TWO of the following are effective controls against Cross-Site Request Forgery (CSRF)?

Select 2 answers
A.Setting cookies with the SameSite attribute to Strict
B.Using anti-CSRF tokens in forms
C.Using HTTPS for all pages
D.Enforcing strong password policies
E.Implementing input validation on all user inputs
AnswersA, B

The SameSite=Strict attribute on cookies ensures that the browser will only send the cookie with requests originating from the same site as the cookie's domain. This effectively prevents a malicious third-party site from tricking a user's browser into sending authenticated requests to the legitimate application, thereby mitigating Cross-Site Request Forgery (CSRF) attacks. It provides a robust defense by restricting cookie transmission to first-party contexts only.

Why this answer

Option A is correct because setting cookies with the SameSite attribute to Strict prevents the browser from sending the session cookie on cross-site requests, which blocks the CSRF attack vector since the attacker's forged request lacks the victim's authentication cookie. Option B is correct because anti-CSRF tokens (synchronizer tokens) are unique, unpredictable values embedded in forms and validated server-side, ensuring that a request originates from the legitimate application page rather than a forged cross-site request. Option C is not correct because HTTPS only encrypts data in transit and does not prevent a browser from automatically attaching credentials to a forged request.

Option D is not correct because strong password policies address credential guessing and brute-force attacks, not the abuse of an already-authenticated session. Option E is not correct because input validation mitigates injection flaws like XSS or SQLi, but does not stop a forged request that contains valid, expected input.

Exam trap

CISSP often tests the misconception that HTTPS or input validation prevents CSRF — candidates must recognize that CSRF is an origin/authorization problem, not a confidentiality or injection problem, so only token-based and SameSite controls address it.

731
Multi-Selecteasy

A penetration tester is planning an engagement. Which of the following rules of engagement should be defined before testing begins? (Select TWO.)

Select 2 answers
A.The exact exploits to be used
B.Emergency contact procedures
C.The scope of systems to be tested
D.The tester's personal compensation
E.The names of employees to be targeted
AnswersB, C

Emergency contact procedures establish whom the tester and client notify if testing causes an outage, data loss or law-enforcement involvement, and how to halt the engagement. Defining these before testing begins ensures rapid escalation and containment, which is why they are a mandatory rules-of-engagement element.

Why this answer

Option B (Emergency contact procedures) is correct because rules of engagement must establish who to contact and how to halt testing immediately if a critical system outage or unintended impact occurs, ensuring safety and rapid escalation. Option C (The scope of systems to be tested) is correct because ROE must explicitly define in-scope and out-of-scope IP ranges, domains, and assets to prevent unauthorized testing and legal exposure. Option A is not required in the ROE because specific exploits are chosen during execution based on findings, not pre-defined in the engagement contract.

Option D is irrelevant to ROE since compensation is a business/contractual matter, not a testing boundary or safety control. Option E is inappropriate because naming specific employees to target is not a standard ROE element and could raise ethical or legal concerns; targeting is defined by scope, not individuals.

Exam trap

The trap here is that candidates confuse 'Rules of Engagement' with a detailed test plan or contract, leading them to select options like 'exact exploits' (A) or 'compensation' (D), which are operational or financial details, not the high-level boundaries that define what is allowed and how to handle emergencies.

732
Multi-Selectmedium

An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?

Select 3 answers
A.Roles and responsibilities
B.Vendor product list
C.Employee performance reviews
D.Communication plan
E.Recovery procedures
AnswersA, D, E

Establishing clearly defined roles and responsibilities is a foundational requirement of an incident response plan. It ensures that the incident response team members, such as the incident commander, technical leads, and legal liaisons, understand their specific duties, preventing chaos and ensuring coordinated execution during a high-pressure security event.

Why this answer

Option A (Roles and responsibilities) is correct because an incident response plan must define who does what during an incident, assigning clear ownership of tasks such as detection, triage, containment, eradication, and recovery so that actions are not duplicated or missed. Option D (Communication plan) is correct because it specifies internal and external notification paths, escalation thresholds, contact trees, and stakeholder/customer/regulator messaging, which is essential for coordinated response and meeting breach-notification obligations. Option E (Recovery procedures) is correct because the plan must document the steps to restore affected systems and services to normal operation, including validation, prioritization, and return-to-production criteria.

Option B (Vendor product list) is not a required component; while asset and vendor inventories can support response, a mere product list is not part of the core plan structure. Option C (Employee performance reviews) is unrelated to incident response and belongs to HR performance management, not the IR plan.

Exam trap

CISSP often tests the confusion between core incident response plan components and ancillary documents like asset inventories or HR records, so candidates must recognize the three essential elements.

733
MCQhard

A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?

A.Hot site
B.Warm site
C.Cold site
D.Reciprocal agreement
AnswerA

A hot site represents a fully operational, mirror image of the primary production environment, complete with all necessary hardware, software, and up-to-date data. This configuration allows for near-instantaneous failover and activation, typically within 1-2 hours, minimizing both downtime (RTO) and data loss (RPO). Its readiness ensures business continuity for critical systems requiring the lowest possible recovery times.

Why this answer

A hot site is a fully equipped, mirrored facility with hardware, software, data replication, and network connectivity already in place, allowing operations to resume within minutes to a couple of hours. Because everything is pre-provisioned and continuously synchronized, it is the only DR site type that reliably meets a 2-hour RTO. Warm and cold sites require additional setup time that exceeds this window.

Exam trap

The trap here is confusing RTO with RPO — candidates who see '2 hours' may pick warm site thinking of backup frequency, but the question specifies operational recovery time, which demands a hot site.

How to eliminate wrong answers

Option B is wrong because a warm site has hardware and connectivity but requires restoring data and reconfiguring systems, typically taking 12-72 hours — too slow for a 2-hour RTO. Option C is wrong because a cold site is essentially empty space with power and cooling, requiring days to weeks to become operational. Option D is wrong because a reciprocal agreement relies on another organization's facility, which offers no guaranteed availability, no pre-staged equipment, and no defined RTO — it is the least reliable option.

734
MCQhard

Refer to the exhibit. A SAML response is received by the service provider. Which security issue is present?

A.The NameID format is incorrect
B.The assertion is not signed
C.The validity window is too short
D.The subject confirmation method is insecure
AnswerB

A critical security requirement for SAML assertions is that they must be digitally signed by the Identity Provider (IdP). The absence of a digital signature on the assertion itself renders the entire SAML response vulnerable to tampering and repudiation. Without this cryptographic integrity check, a malicious actor could intercept the assertion, alter its contents—such as the user's identity or attributes—and then forward it to the Service Provider (SP) without detection. This fundamental flaw undermines the trust relationship between the IdP and SP, making the assertion unreliable and potentially dangerous.

Why this answer

The SAML response shown in the exhibit lacks a digital signature on the assertion itself. Without the assertion being signed, a man-in-the-middle attacker could modify the assertion content (e.g., change the user identifier or attributes) after the response leaves the identity provider but before it reaches the service provider. SAML Core specification (OASIS SAML 2.0) requires that either the entire response or the individual assertion be signed to ensure integrity and non-repudiation; here, neither is signed, making the assertion vulnerable to tampering.

Exam trap

The trap here is that candidates often assume the 'bearer' subject confirmation method is the security flaw, but the real issue is the absence of a digital signature on the assertion, which is a distinct and critical integrity control.

How to eliminate wrong answers

Option A is wrong because the NameID format (e.g., 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress') is syntactically correct and commonly used; there is no indication of an incorrect format in the exhibit. Option C is wrong because the validity window (NotBefore and NotOnOrAfter) appears reasonable (e.g., a 5-minute window) and is not inherently insecure; a short window actually reduces risk, not introduces it. Option D is wrong because the subject confirmation method (e.g., 'bearer') is standard for Web SSO and is not inherently insecure; the issue is the lack of signing, not the confirmation method itself.

735
Multi-Selecthard

A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?

Select 2 answers
A.Hot site
B.Reciprocal agreement
C.Warm site
D.Cloud DR with pre-configured instances
E.Cold site
AnswersA, D

A hot site is a fully equipped, mirrored data center with real-time or near real-time data replication from the primary site. It includes all necessary hardware, software, and network connectivity, allowing for immediate failover and minimal downtime. This strategy ensures the lowest possible Recovery Time Objective (RTO) by being continuously operational and ready for activation, making it ideal for mission-critical systems.

Why this answer

A hot site (A) is correct because it is a fully operational duplicate of the primary data center with hardware, software, and near-real-time replicated data already in place, so failover can occur in minutes or even seconds, yielding the shortest RTO. Cloud DR with pre-configured instances (D) is also correct because pre-provisioned, ready-to-launch compute instances and replicated data in the cloud allow rapid failover, typically within minutes, matching the low RTO requirement. By contrast, a reciprocal agreement (B) depends on another organization's spare capacity that may not be available or compatible during a widespread disaster, and a warm site (C) requires some configuration and data restoration before going live, while a cold site (E) provides only basic facilities with no pre-installed systems or data, resulting in the longest RTO of all options.

Exam trap

Candidates often overlook cloud-based disaster recovery options, but modern CISSP exams recognize Cloud DR (especially with pre-configured, warm, or hot standby instances) as a highly efficient, low-RTO alternative to traditional physical hot sites.

736
MCQhard

A large hospital uses a wireless LAN (WLAN) for mobile medical devices and staff tablets. Recently, nurses reported intermittent connectivity drops and high retransmission rates specifically in the east wing near the elevator banks. The WLAN is based on 802.11ac in the 5 GHz band. The hospital's IT team has already checked for channel overlap, and the APs are configured to use non-overlapping channels with automatic channel selection. Signal strength in the area is adequate (-65 dBm). However, the retransmission rate spikes during peak hours. Which approach should the network team take FIRST to diagnose and resolve the issue?

A.Conduct a spectrum analysis to identify sources of interference and reposition APs away from the elevator shafts.
B.Enable frequency hopping on the APs to avoid interference.
C.Increase the transmit power of the APs in the east wing to improve signal-to-noise ratio.
D.Deploy additional APs in the elevator area to provide more capacity and redundancy.
AnswerA

Conducting a spectrum analysis is the most effective initial step to diagnose wireless performance issues, especially near potential sources of electromagnetic interference like elevator shafts. A spectrum analyzer can identify non-802.11 interference from sources such as elevator motors, microwave ovens, or cordless phones, which standard Wi-Fi tools cannot detect. By pinpointing the exact frequencies and strength of this interference, administrators can strategically reposition Access Points (APs) to minimize its impact, ensuring optimal signal-to-noise ratio and reliable connectivity for mobile medical devices.

Why this answer

The symptoms—intermittent connectivity drops and high retransmission rates near elevator banks during peak hours—strongly suggest external RF interference, likely from the elevator motors or other electrical equipment. A spectrum analysis is the correct first step because it can identify non-Wi-Fi interference sources (e.g., microwave ovens, motors, or radar) that cause packet corruption and retransmissions, even when signal strength is adequate and channels are non-overlapping. Repositioning APs away from the elevator shafts after identifying the interference source directly mitigates the physical cause.

Exam trap

The trap here is that candidates often assume retransmissions are caused by congestion or weak signal and jump to adding APs or increasing power, but the specific location (elevator banks) and intermittent nature point to external interference, which requires spectrum analysis first.

How to eliminate wrong answers

Option B is wrong because frequency hopping is not supported in 802.11ac (which uses OFDM with fixed channels); it is a legacy technique from Bluetooth or older 802.11 FHSS standards and would not resolve interference from continuous sources like elevator motors. Option C is wrong because increasing transmit power would only amplify the signal but also potentially amplify the interference or cause co-channel interference with other APs, and the issue is not weak signal (-65 dBm is adequate) but corrupted packets due to interference. Option D is wrong because deploying additional APs in the elevator area would add capacity but not address the root cause of interference; more APs could even worsen retransmissions if they contend for the same medium or pick up the same interference.

737
MCQhard

During a security audit, it is discovered that a network firewall is allowing traffic based on source IP address only, without inspecting application-layer data. Which type of firewall is this?

A.Packet filter
B.Circuit-level gateway
C.Application gateway
D.Stateful inspection
AnswerA

Packet filters operate at the network and transport layers (OSI Layers 3 and 4), making filtering decisions based solely on information contained within the packet header. This includes source and destination IP addresses, port numbers, and protocol types. They are stateless, meaning each packet is evaluated independently without regard for previous packets or the overall connection state, providing a fundamental but limited form of network security.

Why this answer

A packet filter firewall operates at Layer 3 (Network) and Layer 4 (Transport) of the OSI model, making decisions solely based on source and destination IP addresses, ports, and protocols. It does not inspect application-layer data (Layer 7), which matches the scenario where traffic is allowed based on source IP address only. This is the simplest and fastest type of firewall, but it lacks the ability to block attacks embedded in application payloads.

Exam trap

The trap here is that candidates often confuse 'stateful inspection' with 'packet filtering' because both examine IP addresses, but stateful inspection also tracks connection state, whereas the question explicitly states no application-layer inspection and only source IP filtering.

How to eliminate wrong answers

Option B is wrong because a circuit-level gateway operates at Layer 5 (Session layer) and validates TCP handshakes and session establishment (e.g., SOCKS proxy), not just source IP addresses. Option C is wrong because an application gateway (application-layer proxy) inspects application-layer data (Layer 7) such as HTTP headers or FTP commands, which contradicts the scenario of no application-layer inspection. Option D is wrong because stateful inspection tracks the state of active connections (e.g., TCP sequence numbers) and makes decisions based on both packet headers and connection state, not just source IP addresses.

738
MCQeasy

A software development team is adopting secure coding practices. They decide to implement input validation for all user-supplied data. Which approach is recommended as the most effective for preventing injection attacks?

A.Encoding input before processing
B.Using regular expressions to sanitize input
C.Blacklist validation to block known malicious patterns
D.Whitelist validation to allow only known good patterns
AnswerD

Whitelist validation is considered the most robust and secure approach for handling user input. This method explicitly defines and permits only a specific set of known-good, expected characters, formats, or values that the application is designed to accept. Any input that deviates from this precisely defined safe set is rejected by default. This proactive "allow-by-default" strategy effectively prevents unknown or novel attack vectors, as anything not explicitly allowed is implicitly denied, making it highly resilient against various injection and manipulation attempts.

Why this answer

Whitelist (allowlist) validation defines exactly what input is acceptable and rejects everything else, which is the most robust defense against injection because it does not depend on enumerating every possible attack pattern. Attackers constantly invent new encodings and payload variants, so an allowlist of known-good characters, formats, or values is far more reliable than trying to block known-bad input.

Exam trap

CISSP often tests the allowlist-versus-blacklist distinction by offering plausible-sounding alternatives like encoding or regex sanitization — the trap is choosing a mechanism (encoding, regex) over the correct validation strategy (positive/allowlist validation).

How to eliminate wrong answers

Option A is wrong because encoding is an output-handling defense applied at the point of use (e.g., HTML/URL/SQL encoding) to neutralize special characters — it is not input validation and does not by itself prevent injection if the data is later used unsafely. Option B is wrong because regular expressions are a mechanism, not a strategy; regex-based sanitization that strips 'bad' characters is still blacklist-style and is prone to bypass via encoding, Unicode normalization, or regex flaws. Option C is wrong because blacklist validation only blocks patterns the developer already knows about, so any novel or obfuscated payload evades it — it is explicitly discouraged by OWASP.

739
MCQhard

During a penetration test, the tester successfully gains access to a server and then attempts to move laterally to other systems. This phase is known as:

A.Scanning and enumeration
B.Exploitation
C.Reconnaissance
D.Post-exploitation and lateral movement
AnswerD

Post-exploitation begins immediately after initial access to a system is achieved, focusing on maintaining persistence, escalating privileges, and gathering further intelligence from the compromised host. Lateral movement is a critical component of this phase, where the tester utilizes the initial foothold to pivot and gain access to other systems and network segments, expanding their control and understanding of the target environment's internal defenses.

Why this answer

After initial access is gained, the phase where the tester moves from the compromised host to other systems within the network is specifically called post-exploitation and lateral movement. This involves using the foothold to pivot, escalate privileges, and access additional resources, which is distinct from the initial exploitation step.

Exam trap

The trap here is that candidates confuse 'exploitation' (the initial breach) with the broader post-exploitation phase, forgetting that lateral movement is a distinct activity that occurs after the initial foothold is established.

How to eliminate wrong answers

Option A is wrong because scanning and enumeration occur before exploitation to identify open ports, services, and potential vulnerabilities, not after gaining access. Option B is wrong because exploitation is the act of leveraging a vulnerability to gain initial access, not the subsequent movement to other systems. Option C is wrong because reconnaissance is the initial information-gathering phase (passive or active) performed before any access is obtained, such as DNS lookups or network mapping.

740
MCQhard

A large healthcare organization is subject to both HIPAA and GDPR. They are creating a data retention policy for electronic protected health information (ePHI) concerning European patients. HIPAA requires retention for 6 years from creation or last effective date, while GDPR requires that personal data not be kept longer than necessary for the purpose, with a general guideline of retaining for the duration of the relationship plus a reasonable period. The organization wants to minimize storage costs while ensuring compliance. Which approach should they take?

A.Retain data for the longer of the two regulatory requirements (HIPAA 6 years)
B.Implement a tiered retention policy based on data classification
C.Retain all data indefinitely
D.Retain data for the shorter requirement (GDPR-defined necessity period)
AnswerB

Implementing a tiered retention policy based on data classification is the most effective and compliant strategy for organizations operating under multiple regulatory frameworks like HIPAA and GDPR. This approach allows for granular, specific retention periods to be applied to different data types based on their sensitivity, purpose, and the most stringent applicable legal or business requirements. For example, ePHI might adhere to HIPAA's 6-year rule, while marketing data for EU citizens could be deleted much sooner, optimizing resources and ensuring compliance with both regulations.

Why this answer

A tiered retention policy based on data classification allows the organization to apply different retention periods to different categories of ePHI, satisfying both HIPAA's 6-year minimum for medical records and GDPR's principle of storage limitation. This approach minimizes storage costs by deleting data that is no longer necessary for the original purpose (e.g., billing records after the statutory period) while retaining data that must be kept longer (e.g., patient treatment records). It avoids the all-or-nothing trap of picking a single regulatory timeline, which would either violate GDPR (if retaining too long) or HIPAA (if deleting too soon).

Exam trap

The trap here is that candidates assume they must choose a single retention period (the longer or shorter) to satisfy both regulations, rather than recognizing that a tiered classification approach is the only way to meet conflicting requirements simultaneously.

How to eliminate wrong answers

Option A is wrong because retaining all ePHI for the longer HIPAA 6-year period without considering data classification violates GDPR's Article 5(1)(e) storage limitation principle, which mandates that personal data be kept no longer than necessary for the purpose, and could result in fines for excessive retention. Option C is wrong because retaining all data indefinitely directly contradicts GDPR's right to erasure (Article 17) and storage limitation, and also increases storage costs and security risks unnecessarily. Option D is wrong because retaining data for only the GDPR-defined necessity period (which may be shorter than 6 years) would violate HIPAA's 45 CFR 164.316(b)(2)(i) requirement to retain ePHI for at least 6 years from creation or last effective date, leading to non-compliance and potential penalties.

741
MCQhard

In a PKI hierarchy, a relying party needs to verify a certificate's validity. To reduce latency and improve privacy, which mechanism allows the relying party to obtain the revocation status without contacting the CA directly for each verification?

A.Certificate Transparency (CT) logs
B.Certificate pinning
C.Certificate Revocation List (CRL)
D.OCSP stapling
AnswerD

OCSP stapling, formally known as the TLS Certificate Status Request extension, allows the web server itself to query the Certificate Authority's (CA) Online Certificate Status Protocol (OCSP) responder for the revocation status of its own certificate. The server then caches this signed OCSP response and "staples" it to the TLS handshake, sending it directly to the client. This method significantly improves performance by eliminating the need for each client to contact the OCSP responder directly and enhances privacy by preventing the OCSP responder from tracking client requests.

Why this answer

OCSP stapling allows the certificate holder (web server) to periodically query the CA's OCSP responder and cache a signed, time-stamped OCSP response, which it then 'staples' to the TLS handshake. The relying party receives the revocation status directly from the server during the handshake, eliminating a separate round-trip to the CA and hiding the client's browsing activity from the CA. This reduces latency and improves privacy compared to traditional OCSP or CRL retrieval.

Exam trap

CISSP often tests the confusion between OCSP stapling (server-provided, privacy-preserving, low-latency) and traditional OCSP/CRL (client-initiated, privacy-leaking, higher-latency), so candidates who only remember 'OCSP' without the 'stapling' qualifier pick the wrong mechanism.

How to eliminate wrong answers

Option A is wrong because Certificate Transparency logs are append-only public logs of issued certificates used to detect mis-issuance, not a revocation-status mechanism. Option B is wrong because certificate pinning hardcodes a specific certificate or public key to prevent MITM attacks; it does not provide revocation status. Option C is wrong because a CRL is a CA-published list of revoked certificates that the relying party must download and parse, which increases latency and leaks the client's certificate-checking behavior to the CA.

742
Multi-Selectmedium

A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?

Select 2 answers
A.Wireshark
B.EnCase
C.Volatility
D.Rekall
E.FTK Imager
AnswersC, D

Volatility is an industry-leading, open-source memory forensics framework specifically engineered to extract digital artifacts from volatile memory (RAM) samples. It allows security analysts to inspect the runtime state of a compromised system, identifying active processes, network connections, loaded kernel modules, and even extracting cached files, cryptographic keys, or injected code. Its extensive plugin architecture makes it indispensable for incident response, malware analysis, and advanced threat hunting by providing deep visibility into system memory.

Why this answer

Volatility (C) is the de facto open-source framework for memory forensics, designed to parse raw memory images and extract artifacts such as processes, network connections, and injected code via plugins. Rekall (D) is another memory forensics framework, originally forked from Volatility, that analyzes RAM dumps for malware and rootkit indicators. Both operate directly on memory captures, which is exactly what the analyst needs.

Wireshark (A) is a network protocol analyzer that inspects packet captures, not RAM dumps. EnCase (B) and FTK Imager (E) are disk imaging and file-system forensic tools, not memory analysis frameworks.

Exam trap

The trap here is that candidates confuse network forensics tools (Wireshark) or disk imaging tools (EnCase, FTK Imager) with memory-specific analysis tools, forgetting that RAM analysis requires specialized frameworks like Volatility or Rekall.

743
MCQmedium

Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

Article 33(1) of the GDPR requires data controllers to notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This timeframe applies specifically when the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, ensuring prompt action to mitigate potential harm and facilitate regulatory oversight.

Why this answer

Article 33 of the GDPR requires that, in the case of a personal data breach, the controller notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. This 72-hour window is the maximum time frame specified by the regulation. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.

Exam trap

The trap is mixing up the 72-hour supervisory authority notification with the 'without undue delay' data subject notification, or recalling a different regulation's timeline (e.g., 24 or 48 hours) and selecting it under pressure.

How to eliminate wrong answers

Option B is wrong because 7 days is not a GDPR notification deadline — it is a common misconception, possibly confused with other regulatory timelines. Option C is wrong because 24 hours is shorter than the GDPR requirement and is sometimes mistakenly cited from other breach-notification regimes or internal policies. Option D is wrong because 48 hours is not a GDPR deadline; the regulation explicitly sets 72 hours as the outer limit.

744
MCQhard

A company deploys DNSSEC to protect its DNS infrastructure. Which cryptographic operation does DNSSEC primarily use to ensure the authenticity and integrity of DNS data?

A.Hashing of DNS responses without keys
B.Digital signatures of DNS records
C.Transport Layer Security for DNS
D.Symmetric encryption of DNS queries
AnswerB

DNSSEC fundamentally relies on digital signatures to provide data origin authentication and integrity for DNS records. Authoritative DNS servers sign their zone data using a private key, creating RRSIG (Resource Record Signature) records. Resolvers then use the corresponding public key, chained through the DNSSEC trust anchor, to verify these signatures, confirming that the DNS data is authentic and has not been altered since it was signed by the zone owner.

Why this answer

DNSSEC primarily uses digital signatures to ensure the authenticity and integrity of DNS data. Each DNS zone is signed with a private key, and resolvers verify the signatures using the corresponding public key, which is published as a DNSKEY record. This process allows the resolver to cryptographically confirm that the data has not been modified in transit and originates from the authoritative source.

Exam trap

The trap here is confusing DNSSEC's use of digital signatures for data origin authentication with encryption or transport-layer security, leading candidates to incorrectly select TLS or symmetric encryption options.

How to eliminate wrong answers

Option A is wrong because hashing without keys provides integrity but not authenticity; an attacker can modify both the data and the hash, so DNSSEC requires asymmetric cryptography (digital signatures) to bind the hash to the signer. Option C is wrong because DNSSEC operates at the DNS protocol layer using resource records (RRSIG, DNSKEY, DS) and does not rely on Transport Layer Security (TLS); TLS secures the transport channel (e.g., DNS over TLS), not the DNS data itself. Option D is wrong because DNSSEC uses asymmetric cryptography (public/private key pairs) for signing, not symmetric encryption; symmetric encryption would require shared secrets and does not provide non-repudiation or scalable key distribution for DNS.

745
MCQmedium

A security manager is conducting a risk assessment for a new cloud application. The manager needs to estimate the potential financial loss from a data breach. Which approach should be used?

A.Scenario-based risk analysis with ordinal scales
B.Qualitative risk analysis using high/medium/low ratings
C.Benchmarking against industry standards
D.Quantitative risk analysis using annualized loss expectancy (ALE)
AnswerD

Quantitative risk analysis directly assigns monetary values to assets, threats, and vulnerabilities to calculate potential financial losses. This method precisely determines the Single Loss Expectancy (SLE), which is the monetary loss from a single occurrence of a threat, and the Annualized Rate of Occurrence (ARO), which is how often the threat is expected to occur per year. Multiplying SLE by ARO yields the Annualized Loss Expectancy (ALE), providing a clear monetary estimate of expected losses over a year, which is essential for financial decision-making.

Why this answer

Quantitative risk analysis using Annualized Loss Expectancy (ALE) provides a specific monetary estimate of potential financial loss, which is exactly what the security manager needs for a data breach scenario. ALE is calculated as Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO), enabling data-driven budgeting and cost-benefit analysis for cloud application security controls.

Exam trap

The trap here is that candidates often confuse qualitative methods (which are faster but yield ordinal rankings) with quantitative methods (which require numerical data but produce the monetary loss estimate explicitly requested in the question).

How to eliminate wrong answers

Option A is wrong because scenario-based risk analysis with ordinal scales (e.g., 1-5) produces relative rankings, not a financial loss estimate in dollars, and ordinal scales lack the mathematical precision needed for monetary calculations. Option B is wrong because qualitative risk analysis using high/medium/low ratings yields subjective categories rather than a specific dollar amount, making it unsuitable for estimating exact financial loss. Option C is wrong because benchmarking against industry standards provides comparative metrics (e.g., average breach cost per record) but does not incorporate the organization's specific asset values, threat frequencies, or control effectiveness required to estimate the potential financial loss for this particular cloud application.

746
MCQmedium

A company wants to implement 802.1X authentication on their wired network. Which components are required?

A.Supplicant and authenticator
B.Authenticator and authentication server
C.Supplicant, authenticator, and authentication server
D.Supplicant and authentication server
AnswerC

This option is correct because all three components are absolutely essential for a functional 802.1X implementation. The supplicant (the client device) initiates the authentication process, the authenticator (the network access device like a switch or wireless AP) acts as a gatekeeper, relaying authentication messages and enforcing access policies, and the authentication server (typically a RADIUS server) validates the supplicant's credentials against its database and informs the authenticator of the access decision.

Why this answer

802.1X requires three distinct roles to function: the supplicant (client software requesting access), the authenticator (network device like a switch that enforces port-based access control), and the authentication server (typically a RADIUS server that validates credentials). Without all three, the EAP (Extensible Authentication Protocol) exchange cannot complete, as the authenticator acts as a proxy between the supplicant and the authentication server. Option C is correct because it lists all three mandatory components.

Exam trap

The trap here is that candidates often assume the authenticator (switch) performs the actual authentication, leading them to pick Option B, but in 802.1X the authenticator only controls port state and relays messages—it never validates credentials itself.

How to eliminate wrong answers

Option A is wrong because omitting the authentication server leaves no entity to validate the supplicant's credentials; the authenticator alone cannot perform authentication. Option B is wrong because it omits the supplicant, which is the endpoint that initiates the authentication request and provides credentials; without a supplicant, there is no client to authenticate. Option D is wrong because it omits the authenticator, which is the network device (e.g., switch) that blocks or allows traffic on the port based on the authentication result and relays EAP frames between the supplicant and the authentication server.

747
MCQhard

A company is considering outsourcing its customer support operations to a third-party vendor. Which of the following should be the PRIMARY risk management activity before finalizing the contract?

A.Conduct a thorough vendor risk assessment including security audits.
B.Negotiate a lower price to offset potential security investments.
C.Purchase cyber liability insurance to cover potential breaches.
D.Require the vendor to sign a non-disclosure agreement (NDA).
AnswerA

Conducting a thorough vendor risk assessment, including security audits, is the most critical proactive step in managing third-party risk. This process involves evaluating the vendor's security posture, controls, compliance frameworks, and operational resilience to ensure they can adequately protect the company's data and systems. Security audits, such as SOC 2 reports or independent penetration tests, provide objective evidence of their capabilities, identifying potential vulnerabilities and compliance gaps before any commitment is made. This due diligence is essential for mitigating risks and ensuring the vendor meets the organization's security requirements.

Why this answer

Before outsourcing critical operations, the primary risk management activity is to conduct a thorough vendor risk assessment, including security audits. This evaluates the vendor's security posture, compliance with standards (e.g., ISO 27001), and ability to protect sensitive customer data, directly addressing risks like data breaches or service disruptions before contractual obligations are locked in.

Exam trap

ISC2 often tests the misconception that risk transfer (insurance) or legal agreements (NDAs) are primary risk management activities, when in fact proactive assessment and due diligence must occur first to identify and treat risks before any contractual commitment.

How to eliminate wrong answers

Option B is wrong because negotiating a lower price does not mitigate security risks; it may even incentivize the vendor to cut corners on security controls, increasing exposure. Option C is wrong because purchasing cyber liability insurance transfers financial risk after a breach but does not prevent or reduce the likelihood of a security incident, making it a secondary, not primary, activity. Option D is wrong because requiring an NDA only addresses confidentiality of shared information but fails to assess the vendor's actual security capabilities, processes, or vulnerabilities, leaving critical risks unexamined.

748
Multi-Selectmedium

An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?

Select 3 answers
A.Checking license compliance for open source components
B.Reviewing the vendor's security certifications (e.g., SOC 2, ISO 27001)
C.Requesting a Software Bill of Materials (SBOM)
D.Assessing the vendor's incident response process
E.Requiring employee security training records
AnswersB, C, D

Reviewing a vendor's security certifications, such as SOC 2 or ISO 27001, provides independent assurance that the vendor has implemented and maintains robust security controls. These certifications indicate that an external auditor has verified the effectiveness of the vendor's information security management system (ISMS) against recognized standards. This offers critical insight into the vendor's commitment to security, data protection, and operational resilience, significantly reducing the acquiring organization's due diligence burden.

Why this answer

Option B is correct because reviewing the vendor's security certifications such as SOC 2 and ISO 27001 provides independent attestation that the SaaS provider has implemented and audited controls for security, availability, and confidentiality, which is essential when entrusting customer data to a third party. Option C is correct because requesting a Software Bill of Materials (SBOM) gives visibility into the open source and third-party components in the SaaS application, enabling the organization to assess supply chain risk and quickly identify exposure to known vulnerabilities such as those tracked in CVE databases. Option D is correct because assessing the vendor's incident response process verifies that the provider has defined detection, notification, containment, and recovery procedures, which is critical for meeting the organization's own breach notification and business continuity obligations.

Option A is not included because license compliance for open source components is a legal and procurement concern rather than a core vendor security control assessment. Option E is not included because requiring employee security training records is an internal personnel control and does not directly evaluate the security posture of the SaaS vendor's service.

Exam trap

CISSP often tests the distinction between security-relevant vendor due diligence (certifications, SBOM, IR) and tangential operational or legal items (license compliance, employee training records) that sound plausible but are not part of a security assessment.

749
MCQmedium

A company is preparing for an external audit to comply with PCI DSS. Which type of auditor is typically required to perform this assessment?

A.System administrator
B.Internal auditor
C.Certified Public Accountant (CPA)
D.Qualified Security Assessor (QSA)
AnswerD

A Qualified Security Assessor (QSA) is an individual certified by the PCI Security Standards Council (PCI SSC) to conduct formal PCI DSS compliance assessments. QSAs possess specialized expertise in the technical and procedural requirements of the standard, ensuring an independent and objective evaluation of an entity's cardholder data environment. Their external validation is mandatory for organizations required to submit a Report on Compliance (ROC) or validate their Self-Assessment Questionnaire (SAQ) with a QSA attestation, providing the necessary assurance to payment brands.

Why this answer

PCI DSS requires assessments to be conducted by a Qualified Security Assessor (QSA) because QSAs are certified by the PCI Security Standards Council to validate compliance with the standard's technical and procedural controls. Unlike internal or general external auditors, QSAs have specific training in PCI DSS requirements, including network segmentation, encryption protocols (e.g., TLS 1.2+), and logging mechanisms (e.g., audit trails per Requirement 10).

Exam trap

The trap here is that candidates confuse 'external auditor' with any certified accountant or general IT auditor, overlooking that PCI DSS mandates a specifically certified QSA for compliance validation, not just any third-party assessor.

How to eliminate wrong answers

Option A is wrong because a system administrator lacks the independent, certified authority required for PCI DSS compliance validation and would create a conflict of interest by assessing their own systems. Option B is wrong because internal auditors, while independent within the organization, are not recognized by the PCI Security Standards Council to issue a formal Report on Compliance (ROC) for Level 1 merchants or service providers. Option C is wrong because a Certified Public Accountant (CPA) may perform financial audits but does not hold the specialized PCI DSS technical expertise (e.g., firewall rule reviews, vulnerability scanning per ASV standards) required for a QSA assessment.

750
MCQhard

A security team is evaluating the results of a penetration test. The test revealed that a low-privileged user could escalate privileges to domain administrator. This is a critical finding. Which of the following should be the immediate next step?

A.Conduct a full incident response
B.Re-image all affected systems
C.Terminate the user's account
D.Implement patch management for the exploited vulnerability
AnswerD

Implementing patch management directly addresses the root cause identified by the penetration test. By applying security patches or configuration changes for the exploited vulnerability, the attack vector is eliminated, preventing future exploitation. This proactive remediation is the most effective and targeted response to a discovered security flaw, enhancing the system's overall security posture.

Why this answer

The immediate priority after discovering a privilege escalation vulnerability is to remediate the root cause—typically a missing patch or misconfiguration—to prevent further exploitation. In a penetration test context, the finding indicates a technical flaw (e.g., a missing security update for CVE-2021-42287 or a misconfigured Active Directory ACL) that must be patched or hardened first. Full incident response (A) is premature without evidence of active compromise, and re-imaging (B) or account termination (C) are reactive measures that do not address the underlying vulnerability.

Exam trap

The trap here is that candidates confuse a penetration test finding (a vulnerability) with an active security incident, leading them to choose incident response (A) instead of the correct remediation step (D), which is to patch the exploited vulnerability first.

How to eliminate wrong answers

Option A is wrong because conducting a full incident response assumes a confirmed breach or ongoing malicious activity, but a penetration test finding alone does not indicate active exploitation—it identifies a vulnerability that should be remediated first. Option B is wrong because re-imaging all affected systems is a drastic, resource-intensive step that does not fix the root cause (e.g., an unpatched domain controller or misconfigured Group Policy); the vulnerability would persist if the same image or configuration is reapplied. Option C is wrong because terminating the user's account only removes one low-privileged account but does not prevent another user or attacker from exploiting the same privilege escalation path (e.g., a Kerberos delegation flaw or SeBackupPrivilege abuse).

Page 9

Page 10 of 11

Page 11

All pages