Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 751–816

816 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

A security team is performing a quantitative risk analysis for a server valued at $100,000. The exposure factor is 0.4 and the annual rate of occurrence is 2. What is the annualized loss expectancy (ALE)?

A.$40,000
B.$200,000
C.$160,000
D.$80,000
AnswerD

This is the correct Annualized Loss Expectancy (ALE), derived from accurately applying the quantitative risk analysis formula. First, the Single Loss Expectancy (SLE) is calculated as the Asset Value ($100,000) multiplied by the Exposure Factor (0.4), yielding $40,000. This SLE is then correctly multiplied by the Annualized Rate of Occurrence (2) to determine the total expected financial loss over a year, which is $80,000.

Why this answer

The ALE is calculated as SLE × ARO, where SLE = Asset Value × Exposure Factor. Here, SLE = $100,000 × 0.4 = $40,000, and ARO = 2, so ALE = $40,000 × 2 = $80,000. This represents the expected annual monetary loss from the risk event.

Exam trap

CISSP often tests the distinction between SLE and ALE, and candidates frequently stop at SLE ($40,000) or forget to apply the exposure factor when computing ALE.

How to eliminate wrong answers

Option A is wrong because $40,000 is the Single Loss Expectancy (SLE), not the annualized figure — it omits the ARO multiplier. Option B is wrong because $200,000 incorrectly multiplies the full asset value by the ARO without applying the exposure factor. Option C is wrong because $160,000 results from multiplying the asset value by 0.4 and then by 4 (or some other misapplied factor), not the correct ARO of 2.

752
Multi-Selecthard

A company is deploying a VPN solution for remote employees using SSL/TLS VPN. Which TWO security considerations are important when implementing this type of VPN? (Select two.)

Select 2 answers
A.Use IPsec in transport mode for better performance
B.Implement strong authentication mechanisms such as multi-factor authentication
C.Ensure the SSL VPN gateway is patched and hardened against web application attacks
D.Use pre-shared keys for authentication
E.Disable encryption to improve speed
AnswersB, C

Implementing strong authentication, such as multi-factor authentication (MFA), is paramount for SSL VPNs because the gateway often presents an internet-facing web portal, making it a prime target for credential-based attacks. MFA adds a crucial layer of security by requiring users to provide two or more verification factors, significantly reducing the risk of unauthorized access even if a user's password is compromised. This protection is vital for safeguarding the internal network resources accessible via the VPN.

Why this answer

SSL/TLS VPNs operate at the application layer and are exposed to the internet, making them vulnerable to web-based attacks such as SQL injection and cross-site scripting. Strong authentication, including multi-factor authentication (MFA), is critical to prevent unauthorized access even if credentials are compromised. Patching and hardening the SSL VPN gateway against web application attacks is equally important to mitigate vulnerabilities in the underlying web server or VPN appliance.

Exam trap

The trap here is that candidates confuse SSL/TLS VPNs with IPsec VPNs, leading them to select IPsec-specific options like transport mode or pre-shared keys, when the question explicitly focuses on SSL/TLS VPN security considerations.

753
MCQhard

A SOC analyst receives an alert for a suspicious outbound connection from a server in the DMZ to an external IP on port 443. The server is a web application server that should only communicate internally. The analyst checks the process and finds it is 'svchost.exe' running from a non-standard path. What is the most appropriate immediate action?

A.Isolate the server from the network
B.Initiate a full incident response investigation
C.Disregard the alert because svchost.exe is a legitimate Windows process
D.Terminate the suspicious process
AnswerA

Isolating the server from the network is the immediate and most effective containment strategy. This action severs the malicious outbound connection, preventing further data exfiltration, command-and-control communication, and potential lateral movement to other systems. By containing the threat, the analyst preserves the compromised system's state for subsequent forensic analysis, allowing for a thorough investigation without the risk of ongoing damage or evidence tampering. This critical first step minimizes the incident's overall impact.

Why this answer

Isolating the server immediately contains the threat, preventing potential data exfiltration or lateral movement from a compromised host. The suspicious outbound connection from a DMZ server to an external IP on port 443 (HTTPS) combined with 'svchost.exe' running from a non-standard path strongly indicates malware masquerading as a legitimate Windows process. In security operations, containment is the priority before investigation to minimize damage.

Exam trap

The trap here is that candidates may think terminating the process (Option D) is sufficient, but the CISSP emphasizes containment over eradication to prevent further compromise, and they may also mistakenly trust svchost.exe as always legitimate without verifying its path.

How to eliminate wrong answers

Option B is wrong because initiating a full incident response investigation without first containing the threat could allow the attacker to continue exfiltrating data or move laterally while the investigation proceeds; containment must come first. Option C is wrong because while svchost.exe is a legitimate Windows process, it should only run from C:\Windows\System32 or C:\Windows\SysWOW64, and a non-standard path is a classic indicator of malware impersonation; disregarding the alert would be negligent. Option D is wrong because terminating the suspicious process alone does not prevent the malware from restarting or other persistence mechanisms from activating, and it does not address the network-level threat; isolation is more comprehensive.

754
Multi-Selectmedium

In the context of identity management, which TWO of the following are risks associated with orphaned accounts? (Choose two.)

Select 2 answers
A.Compliance violations
B.Reduced system performance
C.Unauthorized access by former employees
D.Enhanced audit logging
E.Increased help desk calls
AnswersA, C

Regulatory frameworks such as HIPAA, PCI-DSS, and SOX mandate strict access control policies, including the prompt deprovisioning of inactive or terminated user accounts. Failing to identify and disable these orphaned accounts directly violates compliance requirements, potentially resulting in severe financial penalties, failed audits, and legal liabilities for the organization.

Why this answer

Option A (Compliance violations) is correct because orphaned accounts—accounts with no valid owner or associated active user—violate regulatory requirements such as SOX, HIPAA, and GDPR, which mandate that access be attributable to a known, authorized individual and that accounts be reviewed and revoked promptly; auditors treat unowned accounts as a control failure. Option C (Unauthorized access by former employees) is correct because orphaned accounts often persist after an employee leaves or changes roles, and since the credentials may still be valid and unmonitored, a former employee (or anyone who obtains those credentials) can use them to access systems without authorization. Option B (Reduced system performance) is not a typical identity-management risk of orphaned accounts; performance impact is not the concern here.

Option D (Enhanced audit logging) is the opposite of a risk—orphaned accounts actually degrade auditability rather than enhance it. Option E (Increased help desk calls) is not a recognized risk category for orphaned accounts; it is unrelated to the access-control and compliance issues at stake.

Exam trap

CISSP often tests the difference between a risk caused by a weakness (orphaned accounts → unauthorized access, compliance violations) and a control that mitigates it (audit logging) — candidates who pick 'enhanced audit logging' confuse a detective control with a risk.

755
MCQeasy

A health records system requires that doctors can write new records but cannot modify existing ones, and integrity is maintained through separation of duties. Which security model best fits this requirement?

A.Brewer-Nash
B.Biba
C.Clark-Wilson
D.Bell-LaPadula
AnswerC

The Clark-Wilson integrity model is specifically designed for commercial applications requiring strong data integrity through well-formed transactions and separation of duties. It distinguishes between Constrained Data Items (CDIs) and Unconstrained Data Items (UDIs), enforcing that all modifications to CDIs must occur through certified Transformation Procedures (TPs). These TPs are executed by subjects under strict access control rules, ensuring that data integrity is maintained through controlled operations and preventing unauthorized or erroneous data manipulation, perfectly aligning with the need for doctors to write new, valid health records.

Why this answer

The Clark-Wilson model enforces integrity through well-formed transactions and separation of duties, which directly matches the requirement that doctors can write new records but cannot modify existing ones. It uses constrained data items (CDIs), transformation procedures (TPs), and integrity verification procedures (IVPs) to ensure that only authorized users can perform specific operations, preventing unauthorized modifications.

Exam trap

The trap here is that candidates often confuse the Biba model with integrity enforcement, but Biba only prevents unauthorized data flow based on integrity levels, not the specific separation of duties and well-formed transaction constraints that Clark-Wilson provides for this scenario.

How to eliminate wrong answers

Option A is wrong because the Brewer-Nash model (also known as the Chinese Wall model) is designed to prevent conflicts of interest by controlling access to datasets based on previously accessed data, not for enforcing write-once or separation of duties for integrity. Option B is wrong because the Biba model focuses on preventing data flow from lower integrity levels to higher integrity levels (no write up, no read down), but it does not inherently enforce separation of duties or the specific constraint that new records can be written but existing ones cannot be modified. Option D is wrong because the Bell-LaPadula model enforces confidentiality through no read up and no write down, and it does not address integrity constraints like preventing modification of existing records or separation of duties.

756
MCQeasy

Which type of firewall operates at Layer 7 and can inspect application payloads, such as blocking specific SQL commands or HTTP methods?

A.Stateful inspection
B.Application proxy
C.Packet filter
D.Circuit-level gateway
AnswerB

An application proxy terminates the client connection and rebuilds it to the server, fully parsing Layer 7 payloads. This lets it inspect HTTP methods and SQL statements and block specific commands, satisfying the requirement to filter application content rather than merely ports and addresses.

Why this answer

An application proxy firewall (also known as an application-level gateway) operates at Layer 7 (Application Layer) of the OSI model. It can inspect the full application payload, allowing it to block specific SQL commands, HTTP methods (e.g., PUT, DELETE), or other application-layer content by terminating the connection and re-establishing it after deep inspection.

Exam trap

The trap here is that candidates often confuse 'stateful inspection' (Layer 4) with application-layer inspection, assuming stateful firewalls can inspect payloads, but they only track session state, not application content.

How to eliminate wrong answers

Option A is wrong because a stateful inspection firewall operates at Layers 3 and 4, tracking connection state (SYN, ACK) but not inspecting application payloads. Option C is wrong because a packet filter firewall works at Layers 3 and 4, filtering based on source/destination IPs, ports, and protocols, without any payload inspection. Option D is wrong because a circuit-level gateway operates at Layer 5 (Session Layer), validating TCP handshakes and session establishment (e.g., SOCKS proxy) but does not examine application data.

757
MCQhard

A security engineer is troubleshooting an authentication failure for a Windows domain user. The user receives 'Access denied' when trying to access a file server. The Kerberos ticket-granting ticket was successfully obtained. What is the most likely issue?

A.The file server is not trusted for delegation
B.The user does not have permission to the file server resource
C.The user account is locked out
D.Time skew between client and domain controller
AnswerB

This scenario describes an authorization failure, not a Kerberos authentication failure. The user successfully obtained a Service Ticket from the Key Distribution Center (KDC) for the file server, indicating successful authentication. However, when the user presented this valid ticket to the file server, the server's Access Control Lists (ACLs) for the requested resource denied access, resulting in an "Access Denied" message.

Why this answer

Since the Kerberos ticket-granting ticket (TGT) was successfully obtained, the user has authenticated to the domain and the Kerberos authentication process is functioning correctly. The 'Access denied' error at the file server indicates that the user lacks the necessary permissions on the specific resource (share or NTFS), which is a separate authorization step after successful authentication.

Exam trap

The trap here is that candidates confuse authentication (Kerberos TGT success) with authorization (resource permissions), assuming a successful TGT implies full access, when in fact Kerberos only proves identity and does not grant resource-level rights.

How to eliminate wrong answers

Option A is wrong because 'trusted for delegation' is a Kerberos extension used for service impersonation (e.g., when a service needs to act on behalf of a user to access another resource), not for basic file server access; a file server does not need to be trusted for delegation to grant or deny resource permissions. Option C is wrong because if the user account were locked out, the TGT request would fail with a specific Kerberos error (e.g., KDC_ERR_CLIENT_REVOKED), and the user would not have obtained a TGT. Option D is wrong because time skew between client and domain controller would prevent TGT acquisition entirely (Kerberos requires clock synchronization within 5 minutes by default, per RFC 4120), so a successful TGT proves time is synchronized.

758
MCQeasy

What is the PRIMARY purpose of a chain of custody in digital forensics?

A.To document the tools used during investigation
B.To identify the perpetrator of a cybercrime
C.To speed up the forensic analysis process
D.To maintain evidence integrity and admissibility in court
AnswerD

The primary purpose of a chain of custody in digital forensics is to establish an unbroken, documented chronological record of the possession, handling, transfer, and analysis of digital evidence. This meticulous record demonstrates that the evidence has not been altered, substituted, or tampered with from the moment of its collection until its presentation in court, thereby preserving its integrity. By proving the evidence's authenticity and reliability, the chain of custody is absolutely critical for ensuring its legal admissibility and weight in any judicial proceeding.

Why this answer

A chain of custody is a chronological record documenting who collected, handled, transferred, and analyzed evidence, along with when and why each action occurred. Its primary purpose is to preserve evidence integrity and prove in court that the evidence was not tampered with, making it admissible under rules such as the Federal Rules of Evidence (FRE 901). Without an unbroken chain, opposing counsel can challenge authenticity and the evidence may be excluded.

Exam trap

CISSP often tests the distinction between the investigative goal (identifying the attacker) and the evidentiary requirement (proving integrity), so candidates who focus on 'catching the criminal' pick option B instead of the admissibility-focused answer.

How to eliminate wrong answers

Option A is wrong because documenting tools used is part of forensic reporting and methodology, not the purpose of chain of custody — tools documentation does not establish who had control of the evidence. Option B is wrong because identifying the perpetrator is the overall investigative goal, not the function of chain of custody; the chain proves evidence integrity, not guilt. Option C is wrong because chain of custody adds administrative overhead and does not speed up analysis — it can actually slow the process by requiring signatures and logs at each transfer.

759
MCQmedium

An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?

A.GDPR
B.PCI DSS
C.SOX
D.HIPAA
AnswerA

The General Data Protection Regulation (GDPR) explicitly mandates that organizations report personal data breaches to the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This strict timeline applies unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It also requires notification to affected data subjects if the breach poses a high risk.

Why this answer

The GDPR (General Data Protection Regulation) Article 33 mandates that controllers notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms. This 72-hour window is a signature GDPR requirement. No other listed regulation imposes this specific timeline for personal data breaches.

Exam trap

CISSP often tests the confusion between GDPR's 72-hour supervisory authority notification and HIPAA's 60-day HHS notification, or PCI DSS's contractual breach reporting — candidates must anchor on the exact 72-hour figure.

How to eliminate wrong answers

Option B is wrong because PCI DSS governs payment card data security and does not mandate a 72-hour breach notification to a supervisory authority; it has its own incident response requirements. Option C is wrong because SOX (Sarbanes-Oxley) focuses on financial reporting controls and does not address personal data breach notification timelines. Option D is wrong because HIPAA requires breach notification to HHS without unreasonable delay and no later than 60 days, not 72 hours, and applies to protected health information in the US.

760
MCQmedium

A web application exposes an API that allows users to fetch data from internal network resources based on a URL parameter. An attacker discovers they can use this API to access internal servers that are not meant to be public. Which vulnerability is being exploited?

A.Insecure direct object reference (IDOR)
B.Remote code execution (RCE)
C.Cross-site request forgery (CSRF)
D.Server-side request forgery (SSRF)
AnswerD

SSRF is exactly this pattern: the API accepts a user-supplied URL or parameter and the server-side code then fetches that resource on the caller's behalf. Because the request originates from the server, it inherits the server's network position and often bypasses firewall rules that would block a direct external request. Attackers abuse this to reach internal-only services, cloud metadata endpoints, or other systems that were never intended to be reachable from outside the network perimeter.

Why this answer

SSRF allows an attacker to induce the server to make requests to internal or external resources, bypassing firewalls and access controls.

761
MCQeasy

A company's data classification policy labels information as 'Internal Use Only' and 'Confidential.' An employee emails a 'Confidential' document to an external partner without authorization. Which type of data security objective has been violated?

A.Non-repudiation
B.Confidentiality
C.Availability
D.Integrity
AnswerB

Confidentiality is the principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. Data classification policies directly support confidentiality by categorizing information based on its sensitivity and value, thereby dictating the necessary controls to prevent unauthorized access and disclosure. Labeling information as 'confidential' explicitly aims to restrict its viewing to approved parties, making unauthorized disclosure a direct violation of this principle.

Why this answer

Confidentiality ensures information is not disclosed to unauthorized parties. Emailing a 'Confidential' document to an external partner without authorization is a direct unauthorized disclosure, which is precisely the confidentiality objective being violated. The classification label itself signals the data was meant to be restricted to authorized internal recipients.

Exam trap

The trap here is that candidates sometimes conflate 'unauthorized disclosure' with 'integrity' because both involve unauthorized action, but CISSP expects you to map disclosure specifically to confidentiality.

How to eliminate wrong answers

Option A is wrong because non-repudiation concerns proving that a party performed an action (e.g., via digital signatures or audit logs) and preventing them from denying it — no denial of action is at issue here. Option C is wrong because availability concerns ensuring data and systems are accessible to authorized users when needed; the document being emailed does not make it unavailable. Option D is wrong because integrity concerns preventing unauthorized modification of data; the document was disclosed, not altered.

762
MCQmedium

A company uses Docker containers for microservices. What is the most important security measure for container images?

A.Use minimal base images and scan them for vulnerabilities
B.Use the latest version of base image to ensure patches
C.Hardcode secrets into the image
D.Run containers as root for easier privilege management
AnswerA

Using minimal base images significantly reduces the attack surface by including only essential components, thereby limiting potential vulnerabilities from unnecessary software packages or services. Regularly scanning these images for vulnerabilities, often through tools like Clair or Trivy, is critical to identify and remediate known Common Vulnerabilities and Exposures (CVEs) before deployment. This proactive approach ensures that the deployed microservices are built upon a secure and well-vetted foundation, minimizing exposure to exploits.

Why this answer

The most important security measure for container images is to use minimal base images and scan them for vulnerabilities. Minimal images reduce the attack surface by including only necessary components, and regular scanning identifies known vulnerabilities in dependencies. This aligns with the principle of least functionality and helps prevent exploitation.

Exam trap

CISSP often tests container security best practices, and candidates may think using the latest base image is best, but the trap is that 'latest' does not mean secure and can introduce instability.

How to eliminate wrong answers

Option B is wrong because using the latest version of a base image does not guarantee security; it may introduce new vulnerabilities or break compatibility, and 'latest' tags are mutable and can change unexpectedly. Option C is wrong because hardcoding secrets into the image exposes sensitive data in the image layers, which can be extracted by anyone with access to the image. Option D is wrong because running containers as root violates the principle of least privilege and increases the impact of a container escape; containers should run as non-root users whenever possible.

763
MCQeasy

An auditor finds that a system uses the same service account for multiple applications. Which risk does this pose?

A.Increased attack surface due to multiple passwords
B.Difficulty in auditing because all applications share one account
C.Inability to rotate passwords without affecting all applications
D.Single point of failure for authentication
AnswerB

While a single service account used by multiple applications will indeed lead to mixed audit trails, making it difficult to attribute specific actions to individual applications, this is a secondary consequence. The primary operational challenge and security risk stemming from shared accounts is not merely the complexity of log analysis, but rather the inability to manage credentials effectively and securely. The difficulty in auditing is a symptom, not the root operational problem this question targets.

Why this answer

Sharing a service account across multiple applications destroys accountability. When an action is logged under a shared service account, it is impossible to determine which specific application initiated the action, severely hindering auditing and incident response. While password rotation (Option C) is an operational challenge, the loss of accountability and auditability is a much more critical security risk.

Exam trap

Candidates often focus on operational inconveniences like password rotation (Option C) or technical terms like 'single point of failure' (Option D). However, CISSP questions written from an auditor's perspective prioritize core security principles such as accountability, non-repudiation, and auditability (Option B).

How to eliminate wrong answers

Option A is wrong because using the same service account reduces the attack surface (fewer passwords to manage), not increases it; the risk is about credential sharing, not multiple passwords. Option B is wrong because auditing is actually easier with a single account (fewer logs to correlate), though it reduces granularity; the primary risk is operational, not audit difficulty. Option D is wrong because a single point of failure for authentication refers to a centralized authentication server (e.g., a single LDAP or Kerberos KDC) failing, not to a shared service account; the account itself is not an authentication mechanism.

764
MCQmedium

A developer is tasked with securely storing user passwords in a database. Which of the following is the most secure approach?

A.Do not store passwords; use federated identity
B.Hash the password with bcrypt using a unique salt per user
C.Encrypt the password using AES and store the ciphertext
D.Hash the password with MD5 and store the hash
AnswerB

Hashing the password with bcrypt using a unique salt per user is the industry-standard best practice for secure password storage. Bcrypt is an adaptive, slow hashing algorithm specifically designed to be computationally intensive, making brute-force and rainbow table attacks extremely difficult and time-consuming, even with powerful hardware. The unique salt ensures that identical passwords result in different hashes, preventing pre-computation attacks and making dictionary attacks against multiple users impractical.

Why this answer

Bcrypt is a computationally expensive, adaptive hashing algorithm designed specifically for password storage. It incorporates a unique salt per user to prevent rainbow table attacks and its work factor can be increased over time to counter faster hardware, making it the most secure option among those listed.

Exam trap

The trap here is that candidates often confuse encryption with hashing, assuming that encrypting passwords with a strong algorithm like AES is equally secure, but they fail to recognize that encryption is reversible if the key is compromised, whereas hashing is a one-way function designed for password verification.

How to eliminate wrong answers

Option A is wrong because federated identity (e.g., SAML, OAuth) does not eliminate the need to store credentials; the relying party still must store a persistent identifier or token, and the identity provider itself must securely store passwords. Option C is wrong because encryption is a two-way function; if the encryption key is compromised (e.g., via server breach, key leakage), all stored passwords can be decrypted in plaintext, whereas hashing is one-way and prevents recovery of the original password. Option D is wrong because MD5 is a broken, fast hash with known collision vulnerabilities and no built-in salting mechanism, making it trivial to crack with modern GPU-based attacks and rainbow tables.

765
MCQeasy

A security architect is designing a physical security system for a data center. Which of the following is an example of a layered physical control at the perimeter?

A.Biometric access to server room
B.Locked server cabinets
C.CCTV in the lobby
D.Fencing around the property
AnswerD

Fencing around the property is a primary perimeter physical security control, establishing the outermost boundary of the secured area. Its purpose is to deter unauthorized entry, define the property line, and delay intruders before they can reach the building itself. This initial barrier provides the first line of defense against external threats, making it a foundational perimeter measure.

Why this answer

Fencing around the property is a perimeter-layer physical control that provides a first line of defense by deterring and delaying intruders before they reach the building. In a layered defense-in-depth model, perimeter controls (fencing, bollards, lighting, gates) sit at the outermost ring, ahead of building entry controls and interior controls. This makes fencing the only option that operates at the perimeter layer.

Exam trap

CISSP often tests whether candidates can distinguish perimeter-layer controls from interior or asset-layer controls, since all four options are legitimate physical controls but only one sits at the outermost boundary.

How to eliminate wrong answers

Option A is wrong because biometric access to a server room is an interior access control at the asset/room layer, not the perimeter. Option B is wrong because locked server cabinets are an innermost asset-level control protecting individual hardware, not the perimeter. Option C is wrong because CCTV in the lobby is a detective control inside the building envelope, not a perimeter barrier.

766
MCQmedium

A security analyst notices repeated failed login attempts from an internal IP address on the domain controller. After enabling account lockout, the lockouts continue but the source IP changes. What is the best next step?

A.Analyze the log events to identify the attack pattern and implement additional controls such as MFA
B.Increase the account lockout threshold
C.Ignore the event as it is likely a false positive
D.Disable the user account being targeted
AnswerA

Analyzing log events is the foundational step in incident response, providing crucial intelligence about the attacker's methods, source IPs, and targeted accounts. This forensic analysis enables security teams to identify specific attack patterns, such as brute-force or credential stuffing, and determine the scope and nature of the threat. Implementing additional controls like Multi-Factor Authentication (MFA) directly addresses the risk of compromised credentials by requiring a second verification factor, significantly enhancing account security even if a password is breached. This targeted approach ensures effective mitigation while minimizing disruption.

Why this answer

The changing source IP indicates a distributed attack, likely a password spraying or brute-force attempt from multiple compromised hosts. Analyzing log events helps identify the attack pattern (e.g., timing, targeted accounts, source IP ranges) so you can implement additional controls like MFA, which mitigates credential-based attacks regardless of source IP changes. Account lockout alone is insufficient when attackers rotate IPs, as lockout policies are per-account and per-source, not adaptive to distributed sources.

Exam trap

The trap here is that candidates assume account lockout is sufficient and focus on tweaking lockout thresholds (Option B), but the changing source IP reveals a distributed attack that requires a different control like MFA, not just adjusting lockout parameters.

How to eliminate wrong answers

Option B is wrong because increasing the lockout threshold would allow more failed attempts before lockout, making the attack more successful and increasing the risk of account compromise; it does not address the root cause of distributed IPs. Option C is wrong because repeated failed login attempts from changing IPs are a clear indicator of an active brute-force or password spraying attack, not a false positive; ignoring it could lead to unauthorized access. Option D is wrong because disabling the targeted user account is a reactive, temporary measure that does not stop the attacker from targeting other accounts or using different credentials; it also disrupts legitimate user access without addressing the underlying attack vector.

767
Multi-Selectmedium

Which THREE of the following are valid risk response strategies?

Select 3 answers
A.Transfer
B.Eliminate
C.Avoid
D.Mitigate
E.Ignore
AnswersA, C, D

Risk transfer is a strategic approach where the financial liability or responsibility for a specific risk is contractually shifted to a third party. This does not eliminate the underlying risk event itself, but rather reallocates the potential financial impact or operational burden. Common methods include purchasing insurance policies, outsourcing functions to vendors who assume associated risks, or incorporating indemnification clauses into service level agreements, thereby protecting the organization from direct financial loss.

Why this answer

Common risk responses include Avoid, Transfer, Mitigate, and Accept.

768
MCQhard

You are the security architect for a global financial firm. The organization has recently deployed a new cloud-based application that requires low-latency connections between data centers in New York, London, and Tokyo. The existing WAN uses MPLS L3 VPNs with IPsec encryption. However, the application team reports excessive latency and packet loss during peak hours. The network team confirms that the MPLS links are underutilized, but the IPsec tunnels show high CPU usage on the edge routers. Additionally, the security policy mandates that all inter-data center traffic must be encrypted and authenticated. The firm has a budget for hardware upgrades but wants to minimize operational changes. Which of the following is the BEST course of action?

A.Reduce the IPsec encryption algorithm to AES-128 and the hash to SHA-1 to lower CPU usage.
B.Replace MPLS with dedicated point-to-point circuits and remove IPsec encryption.
C.Increase the MTU on the WAN interfaces to reduce packet fragmentation.
D.Upgrade the edge routers to models that support hardware-accelerated IPsec encryption.
AnswerD

Upgrading edge routers to models equipped with hardware-accelerated IPsec encryption is the most effective solution for high CPU utilization caused by cryptographic processing. Hardware acceleration offloads the computationally intensive encryption and decryption tasks from the main CPU to specialized co-processors or ASICs. This significantly reduces the CPU load, allowing the router to handle higher volumes of encrypted traffic with lower latency and improved overall network performance, without compromising security.

Why this answer

The high CPU usage on edge routers is a classic symptom of software-based IPsec encryption overwhelming the router's CPU. Hardware-accelerated IPsec offloads the cryptographic operations to dedicated ASICs or crypto engines, reducing CPU load and eliminating the latency and packet loss caused by processing bottlenecks. This directly addresses the root cause without changing the security policy or requiring major operational changes.

Exam trap

The trap here is that candidates mistakenly think reducing encryption strength (Option A) will solve CPU issues, but the CISSP exam tests that hardware offload is the proper solution when CPU is the bottleneck, not the algorithm choice.

How to eliminate wrong answers

Option A is wrong because reducing encryption to AES-128 and hash to SHA-1 still leaves the processing burden on the CPU; the issue is not the algorithm strength but the lack of hardware offload, and SHA-1 is deprecated per NIST and RFC 6194, potentially violating security policy. Option B is wrong because removing IPsec encryption violates the mandatory security policy that all inter-data center traffic must be encrypted and authenticated, and dedicated circuits do not inherently provide encryption. Option C is wrong because increasing MTU does not address CPU exhaustion from IPsec encryption; fragmentation is not the reported issue, and larger MTUs can actually increase latency if packets are dropped and retransmitted.

769
Multi-Selectmedium

A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)

Select 3 answers
A.Perimeter fence
B.Server rack locks
C.Mantrap at the entrance to the secure area
D.Single-factor authentication for all doors
E.Unsecured windows on ground floor
AnswersA, B, C

A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.

Why this answer

The question asks for layered physical security controls, meaning multiple defensive measures at different depths. Option A, a perimeter fence, is correct because it establishes the outermost physical boundary and deters or delays unauthorized access before an intruder reaches the building. Option B, server rack locks, is correct because it provides an inner layer of protection directly at the asset, restricting access to the servers even after someone has entered the facility.

Option C, a mantrap at the entrance to the secure area, is correct because it is a physical access control vestibule that allows only one person through at a time and prevents tailgating, adding a controlled transition layer between zones. Option D, single-factor authentication for all doors, is not a layered physical control; single-factor authentication is weak and does not add defense in depth, and authentication is more of an access control mechanism than a physical barrier. Option E, unsecured windows on the ground floor, is not a control at all but a vulnerability, since unlocked or unprotected windows provide an easy bypass of other physical defenses.

Exam trap

CISSP often tests the distinction between actual layered controls and single points of failure or vulnerabilities, so candidates must recognize that unsecured windows and single-factor auth are weaknesses, not layers.

770
MCQhard

An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?

A.Privileged Access Management (PAM)
B.Identity as a Service (IDaaS)
C.Single Sign-On (SSO)
D.Role-Based Access Control (RBAC)
AnswerA

Privileged Access Management (PAM) solutions are specifically engineered to secure, manage, and monitor highly sensitive administrative accounts and access to critical systems. They enforce just-in-time (JIT) access, granting elevated permissions only when an administrator needs them for a specific task and for a limited duration, thereby significantly minimizing the attack surface. PAM also typically includes essential features like session recording, password vaulting, and comprehensive audit trails, which are crucial for compliance and incident response related to high-risk administrative operations.

Why this answer

PAM (Privileged Access Management) solutions are purpose-built to broker, vault, and record privileged sessions — providing just-in-time elevation, credential checkout, and full session recording for administrative access to servers. Tools like CyberArk, BeyondTrust, and Delinea implement these controls natively, matching every requirement in the scenario. The other options address authentication or authorization but lack session recording and password vaulting capabilities.

Exam trap

CISSP often tests the distinction between authentication/authorization controls (SSO, RBAC) and privileged session management — candidates pick SSO or RBAC because they sound like access control, missing the vaulting and recording requirements unique to PAM.

How to eliminate wrong answers

Option B is wrong because IDaaS provides cloud-based identity federation and SSO for applications, not privileged session brokering, vaulting, or recording. Option C is wrong because SSO only centralizes authentication across apps — it does not vault privileged credentials or record administrative sessions. Option D is wrong because RBAC is an authorization model that assigns permissions by role; it does not provide just-in-time elevation, credential vaulting, or session recording.

771
MCQeasy

Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?

A.MAC
B.RBAC
C.ABAC
D.DAC
AnswerD

Discretionary Access Control (DAC) is an access control model where the owner of a resource (or an authorized administrator) has the discretion to grant or revoke access permissions to other users. This is typically implemented using Access Control Lists (ACLs) or capabilities, allowing owners to specify who can perform specific actions (read, write, execute) on their owned objects. DAC is highly flexible and widely used in commercial operating systems because it empowers data owners to manage access to their own data.

Why this answer

Discretionary Access Control (DAC) lets the owner of a resource decide who can access it and with what permissions, typically implemented through Access Control Lists (ACLs) on files and objects. Because the data owner grants or revokes access at their discretion, DAC matches the scenario exactly.

Exam trap

CISSP often tests whether candidates can distinguish DAC (owner-controlled, ACL-based) from MAC (system-enforced labels) and RBAC (role-based), since all three are access control models but only DAC centers on owner discretion.

How to eliminate wrong answers

Option A is wrong because Mandatory Access Control (MAC) uses system-enforced labels and clearances (e.g., SELinux, Trusted Solaris) where owners cannot override policy — access is determined by the system, not the data owner. Option B is wrong because Role-Based Access Control (RBAC) grants permissions based on organizational roles rather than per-object owner discretion, and it does not rely on ACLs as its defining mechanism. Option C is wrong because Attribute-Based Access Control (ABAC) evaluates policies combining user, resource, action, and environment attributes — it is more dynamic and policy-driven than owner-controlled ACLs.

772
MCQeasy

A security analyst is configuring a firewall to allow HTTP traffic (TCP port 80) from the internet to a web server in the DMZ. The firewall should also allow return traffic from the server back to the internet. Which type of firewall is best suited to handle this traffic while maintaining security?

A.Application proxy firewall
B.Circuit-level gateway
C.Stateful inspection firewall
D.Packet filter firewall
AnswerC

A stateful inspection firewall maintains a dynamic state table that tracks the context of active network connections, including TCP handshakes, sequence numbers, and connection direction. This allows it to automatically permit return traffic for established outbound connections, such as HTTP responses, without requiring explicit inbound rules for ephemeral ports. This capability significantly enhances security by only allowing expected return traffic and simplifies rule management for common protocols like HTTP.

Why this answer

A stateful inspection firewall (C) is best suited because it tracks the state of active connections, allowing return traffic for established sessions (e.g., HTTP responses from the server to the internet) while blocking unsolicited inbound packets. It inspects packets at Layers 3 and 4, maintaining a state table that matches return packets to the original outbound request, ensuring only legitimate responses are permitted. This provides better security than a simple packet filter by preventing spoofed or out-of-context packets.

Exam trap

The trap here is that candidates often choose packet filter firewalls (D) because they are simpler and can technically allow HTTP traffic on port 80, but they fail to recognize that stateful inspection is required to securely handle return traffic without manually creating complex, insecure rules for ephemeral ports.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at Layer 7, terminating and re-establishing connections, which adds latency and complexity for simple HTTP traffic; it is overkill and not the best fit for just allowing HTTP with return traffic. Option B is wrong because a circuit-level gateway operates at Layer 5 (session layer), validating TCP handshakes but not inspecting packet contents or maintaining state for individual HTTP requests; it cannot reliably handle return traffic for dynamic ports or session tracking. Option D is wrong because a packet filter firewall only examines packet headers (source/destination IP, port, protocol) without maintaining connection state, making it vulnerable to spoofed return packets and unable to distinguish legitimate responses from malicious traffic.

773
MCQmedium

A DevOps team is implementing a DevSecOps pipeline. Which of the following should be introduced first in the pipeline to catch security issues early and reduce remediation cost?

A.Container vulnerability scanning after image build
B.Static application security testing (SAST) during the build stage
C.Pre-commit hooks that run linters and secret scanners
D.Dynamic application security testing (DAST) in staging environment
AnswerC

Pre-commit hooks are scripts configured to execute automatically on a developer's local machine before the `git commit` command successfully completes. By integrating linters, which enforce coding standards and identify syntax errors, and secret scanners, which detect hardcoded credentials or sensitive information, these hooks provide immediate feedback. This mechanism ensures that security issues and quality concerns are identified and remediated at the absolute earliest possible stage, preventing flawed code from ever entering the shared repository.

Why this answer

Pre-commit hooks run linters and secret scanners before code is even committed to the repository, catching issues like hardcoded credentials, insecure patterns, or syntax errors at the earliest possible point in the development lifecycle. This aligns with the DevSecOps principle of 'shift left'—finding defects earlier dramatically reduces remediation cost compared to post-build or post-deployment testing. Unlike later stages, pre-commit hooks prevent vulnerable code from entering the shared codebase, stopping issues before they propagate.

Exam trap

ISC2 often tests the concept of 'shift left' by making candidates think SAST is the earliest security test, but pre-commit hooks execute even before the commit, making them the true first line of defense in a DevSecOps pipeline.

How to eliminate wrong answers

Option A is wrong because container vulnerability scanning after image build occurs after the code is compiled and packaged, which is later in the pipeline than pre-commit hooks, so it does not catch issues as early and remediation costs are higher. Option B is wrong because SAST during the build stage runs after code is committed and built, missing the opportunity to catch issues before they reach the repository; while valuable, it is not as early as pre-commit hooks. Option D is wrong because DAST in staging environment tests running applications much later in the pipeline, after deployment, making it the least effective for early detection and cost reduction.

774
MCQmedium

A database administrator (DBA) is responsible for implementing access controls and backup procedures for a customer database containing PII. The DBA reports to the data owner regarding security measures. Which role best describes the DBA's responsibilities?

A.Data steward
B.Data owner
C.Data custodian
D.Data processor
AnswerC

The data custodian, such as a Database Administrator (DBA), is responsible for the practical implementation and maintenance of security controls and data management tasks. They perform day-to-day operations like backups, access control enforcement, patching, and monitoring, ensuring the data's confidentiality, integrity, and availability as directed by the data owner. This role involves the technical execution of policies and procedures to safeguard the data assets.

Why this answer

A data custodian is the role responsible for the day-to-day operational handling of data, including implementing access controls, backups, and technical safeguards, while acting under the direction of the data owner. The DBA in this scenario performs exactly these operational duties and reports to the data owner, which matches the custodian role. The data owner retains ultimate accountability and sets policy, while the custodian executes it.

Exam trap

CISSP often tests the distinction between accountability (data owner) and operational responsibility (data custodian), tricking candidates into selecting 'data owner' simply because the DBA 'reports to' the owner or is described as responsible for security measures.

How to eliminate wrong answers

Option A is wrong because a data steward focuses on data quality, metadata, and business-level governance of data definitions, not on implementing technical access controls and backups. Option B is wrong because the data owner is the senior accountable role that determines classification and policy, not the one implementing operational controls; the DBA reports to the owner, so the DBA cannot be the owner. Option D is wrong because a data processor is an external entity (e.g., a third-party service provider) that processes data on behalf of the controller under GDPR, not an internal DBA implementing controls.

775
MCQeasy

Which of the following is a process that ensures users periodically confirm they still need access to systems and data?

A.Deprovisioning
B.Separation of duties
C.Recertification
D.Provisioning
AnswerC

Recertification is the essential periodic process of formally reviewing and validating that users' current access rights and privileges remain appropriate and necessary for their assigned job functions. This proactive measure ensures adherence to the principle of least privilege over time, identifying and remediating instances of 'privilege creep' where users accumulate excessive permissions. It significantly reduces the organization's attack surface by eliminating unnecessary access.

Why this answer

Recertification is the process where users periodically confirm that they still require access to systems and data. It involves reviewing user accounts and permissions to ensure they remain appropriate, often as part of access control audits. This directly matches the description.

Exam trap

CISSP often tests the confusion between recertification and deprovisioning; candidates may think deprovisioning includes periodic reviews, but deprovisioning is the actual removal of access, while recertification is the review that may trigger it.

How to eliminate wrong answers

Option A (Deprovisioning) is wrong because it is the removal of access when no longer needed, not the periodic confirmation of need. Option B (Separation of duties) is wrong because it is a preventive control that divides tasks among multiple users to prevent fraud, not an access review process. Option D (Provisioning) is wrong because it is the initial granting of access, not the periodic review.

776
MCQmedium

An organization is preparing for an ISO 27001 certification audit. The audit will be performed by an external body. This type of audit is classified as:

A.Self-assessment
B.External audit
C.Peer review
D.Internal audit
AnswerB

An external audit is a formal, systematic examination performed by an independent, accredited third-party certification body to verify an organization's conformity with the ISO 27001 standard. This impartial assessment ensures objectivity and credibility, providing the necessary assurance for official certification. It is the definitive step required to achieve and maintain ISO 27001 compliance, as only an external body can grant the certification.

Why this answer

An external audit is performed by an independent third-party organization, such as a certification body, to assess compliance against a standard like ISO 27001. In this scenario, the audit is conducted by an external body specifically for certification purposes, which directly matches the definition of an external audit. This type of audit provides an unbiased evaluation of the Information Security Management System (ISMS) and is required for formal certification.

Exam trap

The trap here is confusing an internal audit (conducted by the organization's own staff) with an external audit (conducted by an independent third party), especially when the question emphasizes 'preparing for certification' — candidates may mistakenly think internal audits are sufficient for certification, but only an external audit by an accredited body can grant ISO 27001 certification.

How to eliminate wrong answers

Option A is wrong because a self-assessment is an internal evaluation performed by the organization's own staff, not by an external certification body. Option C is wrong because a peer review typically involves a review by colleagues or other organizations in a non-certification context, not a formal audit by an accredited external body. Option D is wrong because an internal audit is conducted by the organization's own internal audit team or employees, not by an independent external auditor.

777
MCQmedium

A company is implementing a hot site as a disaster recovery option. Which of the following best describes a hot site?

A.A facility with basic infrastructure but no equipment
B.A reciprocal agreement with another company to share space
C.A facility with some equipment but not fully operational
D.A facility that is fully configured and ready to operate within hours
AnswerD

A hot site is a fully operational and configured disaster recovery facility, mirroring the primary site with all necessary hardware, software, and up-to-date data. It is designed for immediate activation, allowing critical business operations to resume within hours or even minutes, minimizing downtime and data loss. This level of readiness is crucial for systems with very low recovery time objectives (RTOs).

Why this answer

A hot site is a fully configured disaster recovery facility that is ready to operate within hours (or immediately). It contains all necessary hardware, software, data, and network connectivity, often with near-real-time replication, allowing the organization to resume operations quickly after a disaster.

Exam trap

CISSP often tests the differences between hot, warm, and cold sites, so candidates must remember hot site = fully configured and ready within hours, not just basic infrastructure or reciprocal agreements.

How to eliminate wrong answers

Option A is wrong because a facility with basic infrastructure but no equipment describes a cold site. Option B is wrong because a reciprocal agreement is a mutual arrangement to share space, not a dedicated hot site. Option C is wrong because a facility with some equipment but not fully operational describes a warm site, which requires some setup before use.

778
MCQmedium

A software developer is concerned about buffer overflow vulnerabilities. Which combination of mitigations makes it most difficult for an attacker to exploit a stack-based buffer overflow?

A.Using a privileged account to run the application
B.Disabling stack protection
C.Stack canaries and NOP sleds
D.Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR)
AnswerD

Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are fundamental and effective mitigations against buffer overflow vulnerabilities. DEP marks memory regions, such as the stack and heap, as non-executable, preventing an attacker from executing injected shellcode directly from these areas. ASLR randomizes the memory locations of key program components, making it significantly more difficult for an attacker to predict the exact addresses needed to launch successful return-oriented programming (ROP) attacks or jump to injected code.

Why this answer

DEP marks memory pages as non-executable, so even if an attacker successfully overwrites the return address and injects shellcode onto the stack, the CPU will refuse to execute it. ASLR randomizes the base addresses of the stack, heap, and libraries, forcing the attacker to guess memory locations, which dramatically reduces the reliability of return-to-libc or ROP-style exploits. Together they block both code injection and reliable redirection, making exploitation far harder than either mitigation alone.

Exam trap

CISSP often tests the misconception that any single mitigation (like stack canaries) fully prevents buffer overflow exploitation, when in reality layered defenses such as DEP plus ASLR are needed to defeat both code injection and address guessing.

How to eliminate wrong answers

Option A is wrong because running the application with a privileged account actually amplifies the impact of a successful buffer overflow, granting the attacker elevated rights rather than mitigating the vulnerability. Option B is wrong because disabling stack protection removes compiler-level defenses such as stack canaries and safe exception handlers, directly increasing exploitability. Option C is wrong because while stack canaries detect return-address overwrites, NOP sleds are an attacker technique used to increase exploit reliability, not a defensive mitigation.

779
MCQmedium

A security architect is evaluating hypervisor security for a multi-tenant cloud environment. Which type of hypervisor is considered more secure because it runs directly on the hardware without a host operating system, reducing the attack surface?

A.Virtual machine monitor
B.Containers
C.Type 1 hypervisor
D.Type 2 hypervisor
AnswerC

A Type 1 hypervisor, also known as a bare-metal hypervisor, runs directly on the host hardware without an intervening operating system. This architecture provides a significantly reduced attack surface because it has a minimal codebase and fewer dependencies than a hypervisor running on a host OS. Its direct control over hardware resources and strong isolation capabilities make it the most secure choice for critical infrastructure and sensitive workloads.

Why this answer

A Type 1 hypervisor (also called a bare-metal hypervisor) runs directly on the host's physical hardware, with no intervening host operating system. Because there is no general-purpose OS layer to exploit, the attack surface is significantly smaller than a Type 2 hypervisor, which depends on a full host OS. This architectural reduction in exploitable code is why Type 1 hypervisors are preferred in multi-tenant cloud environments.

Exam trap

CISSP often tests the distinction between Type 1 and Type 2 hypervisors by rewarding the 'bare-metal equals more secure' heuristic, while distractors like 'virtual machine monitor' tempt candidates who confuse the generic term with a specific architecture.

How to eliminate wrong answers

Option A is wrong because 'virtual machine monitor' is simply the generic technical term for a hypervisor, not a specific type that distinguishes security posture. Option B is wrong because containers share the host kernel and are an OS-level virtualization technology, not a hypervisor type, so they do not match the question's framing. Option D is wrong because a Type 2 hypervisor runs on top of a host operating system, which adds an entire OS layer to the attack surface and makes it less secure for multi-tenant use.

780
Multi-Selectmedium

A security architect is designing a system to protect against side-channel attacks that exploit electromagnetic emanations. Which TWO controls are most effective?

Select 2 answers
A.Data encryption at rest
B.TEMPEST shielding
C.Intrusion detection system
D.Time-based access controls
E.Faraday cage
AnswersB, E

TEMPEST shielding involves applying specialized materials, filters, and design principles directly to electronic equipment to suppress compromising electromagnetic emanations. This standard prevents adversaries from intercepting and reconstructing sensitive data processed by the system through transient electromagnetic pulse emanations.

Why this answer

TEMPEST shielding (B) is correct because TEMPEST is the standard for reducing compromising emanations, including electromagnetic radiation from monitors, cables, and processors, that can leak data to nearby receivers; shielding enclosures and filtered power/communications lines directly mitigate this side-channel. A Faraday cage (E) is also correct because it blocks external electromagnetic fields and contains internal emissions, preventing EM leakage from being intercepted, which is the core defense against emanation-based side-channel attacks. Data encryption at rest (A) protects stored data but does not stop electromagnetic emissions from a running system.

An intrusion detection system (C) monitors network or host activity for malicious behavior and does not address physical EM leakage. Time-based access controls (D) restrict when users may access resources and are irrelevant to electromagnetic side-channel exploitation.

Exam trap

CISSP often tests the confusion between logical and physical controls for side-channel attacks, leading candidates to choose encryption or IDS instead of recognizing that electromagnetic emanation protection requires physical shielding like TEMPEST or Faraday cages.

781
MCQmedium

A security analyst detects an attack where the attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. Which OSI layer is primarily targeted by this attack?

A.Layer 4 – Transport
B.Layer 3 – Network
C.Layer 1 – Physical
D.Layer 2 – Data Link
AnswerD

The Data Link layer, Layer 2, is responsible for node-to-node data transfer within the same local network segment, using Media Access Control (MAC) addresses for frame delivery. ARP (Address Resolution Protocol) directly facilitates this by resolving an IP address (Layer 3) to its corresponding MAC address (Layer 2), enabling devices to communicate directly on the local network.

Why this answer

ARP operates at Layer 2 (Data Link) because it maps IP addresses (Layer 3) to MAC addresses (Layer 2) within a single broadcast domain. By forging ARP replies, the attacker poisons the ARP cache of hosts, causing frames destined for the default gateway to be sent to the attacker's MAC address. This directly targets the address resolution process that bridges Layer 2 and Layer 3, but the attack itself is executed at the Data Link layer.

Exam trap

The trap here is that candidates see 'IP address' in the question and immediately think Layer 3 (Network), forgetting that ARP is a Layer 2 protocol that resolves Layer 3 addresses to Layer 2 addresses.

How to eliminate wrong answers

Option A is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and flow control (e.g., TCP/UDP ports), and ARP has no involvement with transport-layer headers or port numbers. Option B is wrong because Layer 3 (Network) deals with logical addressing and routing (e.g., IP packets), but ARP is not a routed protocol; it is confined to a single subnet and operates below IP. Option C is wrong because Layer 1 (Physical) concerns the physical transmission of bits over media (e.g., cables, signals), and ARP is a protocol that uses frames, not raw bit-level manipulation.

782
MCQmedium

A financial institution is migrating its customer data to a cloud environment. The cloud provider offers encryption at rest and in transit using AES-256 and TLS 1.2+. The compliance team requires that the organization maintain full control of encryption keys to meet regulatory obligations such as PCI DSS and local banking laws. The data is highly sensitive and includes personally identifiable information (PII). Which solution should the security architect recommend?

A.Implement client-side encryption with keys stored on-premises
B.Use tokenization instead of encryption
C.Use the cloud provider's default encryption with their key management service
D.Accept the provider's encryption without additional controls
AnswerA

Implementing client-side encryption ensures that the financial institution encrypts its customer data *before* it ever leaves their on-premises environment and is transmitted to the cloud provider. This critical step means the cloud provider only ever receives ciphertext, never the sensitive plaintext data. Furthermore, by storing the encryption keys exclusively on-premises, the institution maintains absolute control over the decryption process, preventing any unauthorized access by the cloud provider or external entities, which is paramount for data sovereignty and regulatory compliance.

Why this answer

Client-side encryption with keys held on-premises ensures the organization retains sole custody of the encryption keys, satisfying PCI DSS and banking regulations that mandate control over cryptographic material protecting cardholder data and PII. Because the cloud provider never possesses the plaintext keys, it cannot decrypt the data even if compelled or breached. This preserves the organization's ability to revoke access, rotate keys, and demonstrate key custody to auditors.

Exam trap

The trap here is conflating 'encryption is enabled' with 'the organization controls the keys' — CISSP frequently tests that regulatory key-custody requirements cannot be met by provider-managed KMS encryption alone, no matter how strong the algorithm (AES-256) or transport (TLS 1.2+) is.

How to eliminate wrong answers

Option B is wrong because tokenization replaces sensitive data with non-sensitive surrogates but does not provide the same cryptographic protection or key-custody model required for all data types, and it typically requires a tokenization service that may itself be cloud-hosted. Option C is wrong because using the provider's KMS means the provider manages the key material, which fails the requirement for full organizational control of keys. Option D is wrong because accepting provider encryption without additional controls leaves key custody entirely with the provider, violating PCI DSS and local banking law requirements for key ownership.

783
Multi-Selecthard

Which three BGP security mechanisms help protect against route hijacking? (Choose THREE.)

Select 3 answers
A.Resource Public Key Infrastructure (RPKI)
B.BGP Flowspec
C.Prefix filtering on edge routers
D.BGP MED attribute
E.MD5 authentication between BGP peers
AnswersA, C, E

Resource Public Key Infrastructure (RPKI) provides a cryptographic framework for verifying the legitimate origin of IP address blocks. It allows IP address holders to create cryptographically signed statements, called Route Origin Authorizations (ROAs), which specify which Autonomous Systems (ASes) are authorized to originate their prefixes. BGP routers can then validate incoming route announcements against these ROAs, rejecting any routes that are not authorized, thereby directly mitigating route hijacking and mis-origination.

Why this answer

RPKI (A) is correct because it creates a cryptographically signed mapping between IP prefixes and their authorized origin ASes, allowing routers to validate BGP origin announcements via Route Origin Authorizations (ROAs) and reject or deprioritize hijacked routes. Prefix filtering on edge routers (C) is correct because explicitly permitting only known, legitimate prefixes (and their expected prefix lengths) blocks unauthorized or more-specific announcements that a hijacker would use to attract traffic. MD5 authentication between BGP peers (E) is correct because it uses a shared secret and TCP MD5 signature option to authenticate each BGP segment, preventing an attacker from injecting forged BGP updates or resetting the session by spoofing a peer.

BGP Flowspec (B) is not a route-hijacking protection; it distributes traffic-flow filtering rules to mitigate DDoS and similar attacks, not to validate prefix ownership. The BGP MED attribute (D) is merely a non-transitive, optional path-selection metric for influencing inbound traffic, and it provides no authentication or anti-hijacking capability.

Exam trap

ISC2 often tests the distinction between BGP security mechanisms that prevent hijacking (RPKI, prefix filtering, MD5 authentication) versus those that influence routing policy or traffic engineering (MED, Flowspec), leading candidates to mistakenly select MED or Flowspec as hijacking protections.

784
MCQeasy

During a code review, a developer identifies a SQL injection vulnerability. What is the most effective fix?

A.Use stored procedures exclusively.
B.Use an ORM framework.
C.Escape all input.
D.Implement parameterized queries.
AnswerD

Parameterised queries separate SQL code from user-supplied data, so input is treated as a value rather than executable syntax. This eliminates the injection vector at its source, unlike input sanitisation or escaping, which are bypassable and error-prone.

Why this answer

Parameterized queries (prepared statements) ensure user input is treated as data, not executable code. Stored procedures can still be vulnerable if dynamically built. Escaping input is error-prone.

ORMs often use SQL underneath and may not prevent injection if misused.

785
MCQhard

Refer to the exhibit. A security analyst reviews this event log entry. What does this event indicate? Event Log Entry: Log Name: Security Source: Microsoft-Windows-Security-Auditing Event ID: 4625 Task Category: Logon Level: Information Keywords: Audit Failure User: N/A Computer: SRV01 Description: An account failed to log on. Subject: Security ID: SYSTEM Account Name: SRV01$ Account Domain: CORP Logon ID: 0x3E7 Logon Type: 3 Account For Which Logon Failed: Security ID: S-1-5-21-... Account Name: jdoe Account Domain: CORP Failure Information: Failure Reason: Account locked out. Status: 0xC0000234 Sub Status: 0x0

A.A successful logon by the SYSTEM account
B.A successful logon by a user account
C.An attempted exploit of a privilege escalation vulnerability
D.A failed logon attempt due to account lockout
AnswerD

Event ID 4625 is the definitive Windows Security Event ID for a failed logon attempt. Within the event details, a specific 'Sub Status' or 'Failure Code' (e.g., 0xC0000234, which translates to `STATUS_ACCOUNT_LOCKED_OUT`) precisely indicates the reason for the logon failure. If the exhibit shows this particular sub-status, it directly confirms that the logon failed because the account was locked out, typically due to exceeding the maximum number of incorrect password attempts as defined by account lockout policy.

Why this answer

The event log entry shows Event ID 4625 (an account failed to log on) with Status 0xC0000234, which is the code for 'Account locked out.' This indicates a failed logon attempt because the account is locked out, not a successful logon and not a privilege escalation exploit.

Exam trap

The trap here is that candidates see 'Logon Type 3' and assume it is a successful network logon, ignoring the failure status and lockout reason, or they misinterpret the lockout as a privilege escalation attempt.

How to eliminate wrong answers

Option A is wrong because the event shows a failure status (0xC0000234) and a failure reason of 'Account locked out', not a successful logon by any account including SYSTEM. Option B is wrong because the event explicitly indicates failure, not success, and the user account referenced is locked. Option C is wrong because this event does not show any privilege escalation exploit; it is a standard authentication failure due to account lockout, not an attack pattern like token manipulation or SeDebugPrivilege abuse.

786
MCQmedium

In LDAP, which attribute uniquely identifies an entry within the directory information tree?

A.Distinguished Name (DN)
B.Relative Distinguished Name (RDN)
C.Organizational Unit (OU)
D.Common Name (CN)
AnswerA

The Distinguished Name (DN) serves as the absolute and unambiguous identifier for every entry within an LDAP directory. It is a sequence of Relative Distinguished Names (RDNs) that traces a unique path from the root of the directory information tree (DIT) down to the specific entry. This hierarchical structure ensures that no two entries can possess the exact same DN, guaranteeing global uniqueness across the entire LDAP directory service.

Why this answer

The Distinguished Name (DN) is the full path from the root of the directory information tree to the entry, uniquely identifying it across the entire directory. It includes the RDN plus all superior entries, ensuring global uniqueness.

Exam trap

CISSP often tests the confusion between DN and RDN; candidates may think RDN is globally unique, but it's only unique within its parent, so the full DN is required for global uniqueness.

How to eliminate wrong answers

Option B is wrong because the Relative Distinguished Name (RDN) is only unique within its immediate parent and does not provide a full path. Option C is wrong because an Organizational Unit (OU) is a container object, not an attribute that uniquely identifies an entry. Option D is wrong because a Common Name (CN) is just one component of an RDN and may not be unique across the directory.

787
MCQmedium

An organization is implementing a new access control system. They want to ensure that users are who they claim to be, that actions can be traced to individuals, and that access rights are managed appropriately. Which framework encompasses all three of these goals?

A.COBIT 2019
B.AAA framework
C.CIA triad
D.ISO/IEC 27001
AnswerB

The AAA (Authentication, Authorization, and Accounting) framework is the fundamental model for implementing access control systems, directly addressing the core requirements for managing user access. Authentication verifies a user's identity, ensuring only legitimate entities can attempt access to resources. Authorization then determines what specific actions the authenticated user is permitted to perform, based on defined policies and privileges. Finally, Accounting tracks user activities and resource consumption, providing an essential audit trail for accountability, billing, and compliance purposes.

Why this answer

The AAA framework directly addresses the three stated goals: Authentication verifies that users are who they claim to be, Authorization determines what resources they can access and manages their rights, and Accounting (or Auditing) ensures that actions can be traced back to individuals through logging and auditing. This triad of functions is the foundational model for access control in information security, making it the exact match for the question's requirements.

Exam trap

CISSP often tests the confusion between overarching security frameworks (like COBIT or ISO 27001) and the specific AAA framework that directly implements identity verification, access control, and accountability.

How to eliminate wrong answers

Option A is wrong because COBIT 2019 is a governance and management framework for enterprise IT, focusing on aligning IT with business objectives, not specifically on authentication, authorization, and accountability mechanisms. Option C is wrong because the CIA triad (Confidentiality, Integrity, Availability) describes core security objectives for data and systems, but does not encompass identity verification, access rights management, or traceability of actions. Option D is wrong because ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS); it provides a systematic approach to managing sensitive information but does not itself define the AAA functions.

788
MCQmedium

A developer uses a tool that analyzes source code for potential security flaws without executing the program. This is an example of:

A.DAST
B.IAST
C.RASP
D.SAST
AnswerD

SAST (Static Application Security Testing) directly examines an application's source code, bytecode, or binary code without executing it, making it a 'white-box' testing method. It identifies potential vulnerabilities such as buffer overflows, SQL injection flaws, or insecure coding practices by analyzing the code's structure, data flow, and control flow statically. This approach is ideal for developers to find and fix security flaws early in the Software Development Life Cycle (SDLC) before deployment.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. This matches the description of a tool that inspects code statically, making D the correct answer.

Exam trap

The trap here is confusing SAST with DAST because both are application security testing types, but the key differentiator is execution: SAST is static (no execution) while DAST is dynamic (requires execution).

How to eliminate wrong answers

Option A is wrong because DAST (Dynamic Application Security Testing) tests a running application by sending inputs and observing responses, not by analyzing source code without execution. Option B is wrong because IAST (Interactive Application Security Testing) combines static and dynamic analysis, requiring the application to be executed and instrumented, not purely static analysis. Option C is wrong because RASP (Runtime Application Self-Protection) is a runtime security control embedded in the application environment that monitors and blocks attacks during execution, not a source code analysis tool.

789
Multi-Selectmedium

An organization is selecting security metrics to report to the board. Which THREE metrics would best demonstrate the effectiveness of the vulnerability management program?

Select 3 answers
A.Open vulnerability count by severity
B.Number of employees in IT security
C.Budget for security tools
D.Mean time to remediate critical vulnerabilities
E.Patch compliance percentage
AnswersA, D, E

Tracking open vulnerabilities segmented by severity (critical, high, medium, low) gives the board a direct, current-state view of unremediated risk exposure. Because it's broken out by severity rather than a single aggregate number, it lets leadership see whether the highest-risk items are being prioritized correctly, and trends over time reveal whether the program is keeping pace with new findings or falling behind.

Why this answer

These three metrics cover remediation speed, current risk posture, and compliance with patching policies, which are key indicators.

790
MCQeasy

Which of the following is the primary purpose of the CIA triad in information security?

A.To establish a framework for risk management
B.To ensure compliance with regulatory requirements
C.To balance security controls with usability
D.To define the core objectives of information security
AnswerD

The CIA triad fundamentally defines the three paramount objectives that information security strives to achieve: Confidentiality, Integrity, and Availability. This foundational model provides a universal language and framework for understanding, categorizing, and prioritizing security goals across all aspects of information systems and data protection.

Why this answer

The CIA triad—Confidentiality, Integrity, and Availability—provides a foundational model for developing security policies and ensuring that data is protected from unauthorized access, tampering, and downtime.

791
MCQmedium

A security engineer is troubleshooting a network where internal users can access internet websites but cannot reach the company's external VPN server (IP 203.0.113.50, UDP port 500). The firewall rule for VPN traffic is correctly configured. What is the most likely cause?

A.The VPN server is using TCP port 443 instead of UDP 500.
B.The firewall rule is applied to the wrong interface.
C.The firewall is stateful and blocking the return traffic.
D.The VPN server is not listening on UDP port 500.
AnswerD

For a VPN client to successfully initiate a connection, the VPN server must have its VPN service actively running and configured to listen for incoming connection requests on the expected port, typically UDP port 500 for IKE. If the service is stopped, crashed, or misconfigured to listen on a different port or interface, the server will not respond to client connection attempts on UDP port 500. This lack of response will cause the client to time out, indicating a server-side availability issue.

Why this answer

The symptom—internal users can reach internet websites but cannot reach the external VPN server—indicates a host-level issue rather than a network or firewall problem. Since the firewall rule for VPN traffic is correctly configured and other traffic flows normally, the most likely cause is that the VPN server itself is not listening on UDP port 500, which is the standard port for IPsec IKE (Internet Key Exchange) traffic. This could be due to a misconfiguration, service failure, or the server being configured to use a different port or protocol.

Exam trap

The trap here is that candidates often assume a firewall misconfiguration (like stateful blocking or wrong interface) is the cause, but the question explicitly states the firewall rule is correctly configured, forcing you to look at the endpoint itself—a classic CISSP test of reading comprehension and layered troubleshooting.

How to eliminate wrong answers

Option A is wrong because if the VPN server were using TCP port 443 instead of UDP 500, the firewall rule would still need to match that traffic, but the question states the rule is correctly configured for VPN traffic (implying UDP 500), and the symptom would be different (e.g., HTTPS-based VPNs like SSL VPN would work). Option B is wrong because if the firewall rule were applied to the wrong interface, internal users would likely have broader connectivity issues (e.g., inability to reach any external services), not just the VPN server, and the question explicitly states the rule is correctly configured. Option C is wrong because a stateful firewall automatically tracks UDP sessions and allows return traffic if the outbound rule permits the initial packet; blocking return traffic would affect all UDP-based services, not just the VPN server, and the question confirms other internet access works.

792
MCQhard

A global technology firm has implemented a continuous integration/continuous deployment (CI/CD) pipeline for its flagship software product. The security testing team is tasked with integrating security testing into the pipeline. The team has decided to use a static application security testing (SAST) tool and a software composition analysis (SCA) tool. They are currently running both tools every night against the entire codebase, but the developers complain that the reports are too long and often contain false positives. The team wants to improve the efficiency without sacrificing security coverage. Which of the following is the BEST strategy?

A.Decrease the scan frequency to weekly to reduce noise.
B.Implement a developers' feedback loop for false positives and tune the tools.
C.Replace SAST with dynamic application security testing (DAST) for more accurate results.
D.Run SAST and SCA only on new code changes committed to the main branch.
AnswerB

Implementing a developers' feedback loop for false positives is crucial for refining security tools and processes. This mechanism allows developers to report inaccurate alerts, providing essential data for security teams to tune SAST and SCA tools effectively. Tuning involves creating custom rules, adjusting sensitivity, or suppressing known benign patterns, which significantly reduces alert fatigue, improves the signal-to-noise ratio, and ensures that legitimate vulnerabilities are prioritized and addressed efficiently without sacrificing comprehensive scanning.

Why this answer

Tuning the SAST and SCA tools based on developer feedback directly addresses the false positive issue while maintaining security coverage. By establishing a feedback loop, the team can adjust rule sets, suppress known false positives, and reduce report noise without reducing scan frequency or scope. This approach aligns with the principle of continuous improvement in DevSecOps, ensuring that security testing remains efficient and actionable.

Exam trap

The trap here is that candidates may choose Option D (scan only new code) because it seems efficient, but they overlook the need for continuous scanning of the entire codebase to catch regressions and vulnerabilities in unchanged code, which is a core requirement for maintaining security coverage in CI/CD pipelines.

How to eliminate wrong answers

Option A is wrong because decreasing scan frequency to weekly reduces the frequency of security feedback, potentially allowing vulnerabilities to persist longer in the pipeline, which sacrifices security coverage and does not address the false positive problem. Option C is wrong because replacing SAST with DAST is not a direct solution; DAST analyzes running applications and has different strengths (e.g., runtime issues), but it does not replace the need for static analysis and SCA for dependency vulnerabilities, and it may introduce its own false positives. Option D is wrong because running SAST and SCA only on new code changes to the main branch misses vulnerabilities in existing code and dependencies that could be introduced through configuration changes or updates, and it fails to provide comprehensive coverage of the entire codebase.

793
Multi-Selectmedium

During a security audit of a web application, the following issues are found: (1) Session tokens are included in URLs, (2) The application does not invalidate session tokens after logout, and (3) Session tokens are predictable. Which THREE of the following controls are most appropriate to address these issues?

Select 3 answers
A.Regenerate session tokens after login
B.Store session tokens in cookies with Secure and HttpOnly flags
C.Invalidate session tokens on logout and set short expiration times
D.Use a cryptographically secure random number generator for token generation
E.Implement IP address binding for session tokens
AnswersB, C, D

Storing session tokens in cookies with the Secure flag ensures they are only transmitted over encrypted HTTPS connections, preventing passive network eavesdropping. The HttpOnly flag prevents client-side scripts, such as JavaScript, from accessing the cookie's content, significantly mitigating the risk of session token theft via Cross-Site Scripting (XSS) attacks. These flags collectively enhance the confidentiality and integrity of session tokens during transit and storage.

Why this answer

Option B is correct because storing session tokens in cookies with Secure and HttpOnly flags addresses the issue of tokens being included in URLs by keeping them out of URLs and providing additional protections. Option C is correct because invalidating session tokens on logout and setting short expiration times directly addresses the lack of invalidation. Option D is correct because using a cryptographically secure random number generator directly addresses the predictability of session tokens.

Option A is incorrect because regenerating session tokens after login is primarily a control against session fixation, not directly addressing predictability, exposure in URLs, or lack of invalidation. Option E is incorrect because IP address binding is fragile and does not protect against token exposure or poor invalidation.

Exam trap

ISC2 often tests the misconception that IP binding is a strong session management control, but in reality it is fragile and not a primary defense against session token exposure, predictability, or improper invalidation.

794
MCQmedium

A healthcare organization implements a policy requiring all employees to use biometric fingerprint scanners to access patient records. Which of the following is the MOST significant risk associated with this authentication method?

A.Biometric data cannot be revoked or changed if compromised
B.High false acceptance rate leading to unauthorized access
C.Low user acceptance due to privacy concerns
D.Increased login time compared to password authentication
AnswerA

Unlike passwords or tokens that can be reset or reissued, a compromised biometric template, derived from immutable physical characteristics like fingerprints or iris patterns, cannot be revoked or changed. This permanence means that once an attacker obtains a biometric template, that specific biometric trait is permanently compromised for authentication purposes, posing a significant long-term security risk. Organizations must implement robust template protection mechanisms, such as encryption and tokenization, to mitigate this inherent vulnerability.

Why this answer

Biometric data, such as fingerprint templates, is immutable and permanently tied to the individual. Once compromised, the user cannot simply 'reset' their fingerprint like a password, rendering the authentication factor permanently insecure for that user across all systems where it is used. This non-repudiation and revocation failure represents the most significant long-term risk to the organization's identity management infrastructure.

Exam trap

The trap here is that candidates focus on the immediate operational risks (FAR, user acceptance, or speed) rather than the fundamental, long-term security property of biometrics: the inability to revoke or change the credential, which is the most critical risk in identity and access management.

How to eliminate wrong answers

Option B is wrong because modern fingerprint scanners (e.g., capacitive or ultrasonic) have very low false acceptance rates (FAR), typically below 0.001%, making unauthorized access via FAR a less significant risk than the permanent compromise of biometric data. Option C is wrong because while privacy concerns may affect user acceptance, they are a secondary operational issue, not the most significant security risk; the primary risk is the irreversible loss of the authentication factor itself. Option D is wrong because increased login time is a usability inconvenience, not a security risk, and modern scanners authenticate in under one second, making this negligible compared to the revocation problem.

795
MCQmedium

Under the GDPR, which role is responsible for determining the purposes and means of processing personal data?

A.Data processor
B.Data controller
C.Data subject
D.Data protection officer
AnswerB

The data controller is the entity that, alone or jointly with others, determines the purposes (why data is processed) and the means (how data is processed) of personal data processing. This fundamental responsibility establishes their primary accountability under GDPR for compliance and safeguarding data subjects' rights. Their decision-making power over the processing lifecycle directly aligns with the question's premise.

Why this answer

Under the GDPR, the data controller is the entity (natural or legal person, public authority, agency, or other body) that alone or jointly with others determines the purposes and means of processing personal data. This role carries primary accountability for GDPR compliance, including lawful basis, data subject rights, and breach notification. The controller decides 'why' and 'how' data is processed, which is the defining characteristic of the role.

Exam trap

CISSP often tests the distinction between controller and processor, and candidates frequently confuse the two because both handle personal data; the key is that only the controller determines the purposes and means.

How to eliminate wrong answers

Option A is wrong because a data processor processes personal data on behalf of the controller and does not determine the purposes or means; the processor acts only on documented instructions from the controller. Option C is wrong because the data subject is the individual to whom the personal data relates, not an organizational role responsible for processing decisions. Option D is wrong because the Data Protection Officer (DPO) is an advisory and monitoring role that ensures compliance but does not determine the purposes and means of processing; the DPO may be mandatory in certain cases but is not the decision-maker.

796
MCQhard

A company's security team discovers that an employee inadvertently shared sensitive customer data via a public cloud storage link. The incident response team contains the breach and notifies affected customers. Which of the following risk management strategies would BEST prevent recurrence?

A.Block all access to public cloud storage services from corporate devices.
B.Implement mandatory security awareness training focusing on data handling procedures.
C.Deploy a Data Loss Prevention (DLP) solution that monitors and controls sharing of sensitive data.
D.Encrypt all sensitive data at rest and in transit to render shared data useless.
AnswerC

Deploying a Data Loss Prevention (DLP) solution directly addresses the problem by providing automated, policy-driven controls to monitor, identify, and prevent the unauthorized or accidental sharing of sensitive data. DLP systems can inspect data in motion (network traffic), data at rest (storage), and data in use (endpoints), blocking transfers that violate predefined security policies. This proactive technical control ensures that sensitive information, regardless of its format or destination, is not inadvertently or maliciously exfiltrated from the corporate environment.

Why this answer

A Data Loss Prevention (DLP) solution provides automated, policy-based monitoring and control of sensitive data being shared via public cloud storage links. Unlike awareness training (which relies on human behavior) or blanket blocking (which hinders productivity), DLP can inspect content in real time using pattern matching, fingerprinting, or exact data matching to prevent unauthorized sharing before it occurs, directly addressing the root cause of inadvertent exposure.

Exam trap

The trap here is that candidates often choose awareness training (Option B) because it seems like a logical first step, but the question asks for the BEST strategy to PREVENT recurrence, and DLP provides a technical control that actively blocks the action rather than relying on human behavior change.

How to eliminate wrong answers

Option A is wrong because blocking all access to public cloud storage services is an overly restrictive technical control that can severely impact business operations and collaboration; it does not address the underlying issue of improper data handling and may drive users to unapproved shadow IT solutions. Option B is wrong because while security awareness training is important, it is a preventive administrative control that relies on human memory and compliance; it cannot prevent recurrence of inadvertent sharing in real time, as human error can still occur despite training. Option D is wrong because encryption protects data confidentiality if the data is intercepted, but it does not prevent the authorized user from inadvertently sharing the encrypted data via a public link; if the recipient has the decryption key (or the key is shared with the link), the data remains exposed, so encryption alone is not a preventive control against the act of sharing.

797
MCQmedium

A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?

A.Enable SELinux in enforcing mode on each server and audit the resulting AVC denials daily.
B.Deploy a host-based intrusion detection agent that alerts the SOC whenever a failed logon threshold is exceeded.
C.Increase the local /var/log/secure rotation interval and set the file permissions to 600 on each server.
D.Configure rsyslog to forward authpriv facility messages to a remote log server that stores them on WORM media.
AnswerD

The authpriv facility carries authentication and authorization messages on Linux, so forwarding it to a hardened remote collector preserves the events. Writing to write-once media plus remote shipping makes the record tamper-evident and supports the one-year retention the auditor demands, because local compromise cannot silently rewrite already-archived entries.

Why this answer

Authentication events on Linux flow through the authpriv facility, so shipping those messages to a separate collector addresses both integrity and retention. Storing them on write-once media means a compromised server cannot alter history, and centralizing them satisfies the one-year retention demand. Local-only controls, SELinux auditing, and alerting tools each miss either the completeness or the tamper-evidence requirement.

Exam trap

The trap here is assuming that stronger local file permissions or SELinux enforcement make logs tamper-evident, when only off-host, append-only storage actually prevents a compromised server from rewriting its own history.

798
MCQeasy

An organization wants to protect sensitive data stored on laptops. Which of the following is the MOST effective control to prevent data loss if a laptop is stolen?

A.BIOS password
B.Asset tracking software
C.Full-disk encryption (FDE)
D.Remote wipe capability
AnswerC

Full-disk encryption (FDE) provides comprehensive data protection by encrypting all data stored on the entire hard drive, including the operating system, applications, and user files. This ensures that even if a stolen laptop's hard drive is removed and connected to another system, the data remains unreadable and inaccessible without the correct decryption key or passphrase. FDE is a robust control for protecting data at rest, making it the most effective solution for preventing unauthorized access to sensitive information on a lost or stolen device.

Why this answer

Full-disk encryption (FDE) renders the data on the laptop unreadable without the decryption key, even if the storage drive is removed and analyzed. This is the most effective preventive control against data loss from theft because it protects data at rest regardless of physical access to the device.

Exam trap

The trap here is that candidates often choose remote wipe (D) because it sounds proactive, but they overlook that it requires network connectivity and is a corrective control, whereas full-disk encryption is a preventive control that works even offline.

How to eliminate wrong answers

Option A is wrong because a BIOS password only prevents unauthorized booting of the system, but the hard drive can be removed and accessed directly via another machine, exposing all data. Option B is wrong because asset tracking software helps locate a stolen laptop but does not prevent data access or loss if the device is not recovered. Option D is wrong because remote wipe capability can delete data after theft, but it relies on network connectivity and may fail if the thief immediately disconnects the device; it is a reactive control, not a preventive one.

799
Multi-Selectmedium

A financial services firm is deploying a customer-facing mobile banking app and wants to delegate limited access to account balances and transaction history to third-party budgeting apps without sharing the customer's banking credentials. The security architect must select controls that implement this delegation securely. (Choose two.)

Select 2 answers
A.Use OAuth 2.0 authorization code grant with PKCE so the budgeting app obtains a scoped access token without receiving the customer's password.
B.Configure the budgeting app to store the customer's banking username and password in its local keystore for future API calls.
C.Rely on SAML 2.0 bearer assertions issued to the budgeting app so it can impersonate the customer for all banking operations.
D.Issue refresh tokens with long lifetimes and broad scopes so budgeting apps can maintain access without repeated customer consent.
E.Define granular OAuth 2.0 scopes such as read:balances and read:transactions and require the customer to consent to them during authorization.
AnswersA, E

The authorization code grant with PKCE lets the budgeting app obtain a limited access token after the customer authenticates directly with the bank, so credentials are never shared. PKCE protects the code exchange from interception on public clients such as mobile apps, matching the delegation and security requirements of this scenario.

Why this answer

OAuth 2.0 authorization code grant with PKCE lets the budgeting app receive a scoped token without ever handling the customer's credentials, and granular scopes plus explicit consent constrain that token to balances and transaction history. Together these controls implement least-privilege delegation for a public mobile client while keeping the bank's authentication boundary intact.

Exam trap

The trap here is confusing authentication with authorization delegation, leading to choices that share credentials or issue overly broad tokens instead of scoped OAuth access.

800
Multi-Selectmedium

Which THREE of the following are examples of data at rest?

Select 3 answers
A.Data stored on a hard drive
B.Data in an email in transit
C.Data in a database
D.Data on a backup tape
E.Data on a network cable
AnswersA, C, D

A hard drive (HDD) or solid-state drive (SSD) stores data persistently when not actively being read from or written to. This includes files, operating system components, and applications residing on the disk, awaiting access. Such data is considered "at rest" because it is static and not actively traversing a network or being processed by a CPU, making it a prime target for encryption.

Why this answer

Data at rest refers to data that is physically stored on a persistent medium and is not currently moving across a network or being processed. Data stored on a hard drive is a classic example because the data resides on a non-volatile storage device, whether it is an internal HDD, SSD, or external drive. The data remains on the medium until it is read, modified, or deleted, and it is typically protected by encryption mechanisms such as BitLocker or FileVault.

Exam trap

The trap here is that candidates often confuse data in a database as data in use or data in motion, but a database stores data persistently on disk, making it data at rest unless it is being actively queried or transferred.

801
MCQmedium

A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?

A.Update the SIEM correlation rule to ignore similar alerts
B.Escalate the incident to Tier 2 analyst for further investigation
C.Disconnect the workstation from the network immediately
D.Perform a deep forensic analysis of the workstation
AnswerB

Escalating the incident to a Tier 2 analyst for further investigation is the correct and standard procedure for a Tier 1 SOC analyst who has identified a potential malware infection. Tier 1 analysts are primarily responsible for initial alert triage, basic investigation, and confirming the legitimacy of an alert. If the incident requires more advanced analysis, specialized tools, or decision-making beyond their scope, proper escalation ensures the incident is handled by personnel with the appropriate expertise and authority, following established incident response playbooks.

Why this answer

Tier 1 analysts typically triage alerts and escalate if they cannot resolve them.

802
MCQhard

During a security assessment, a penetration tester successfully performed a VLAN hopping attack from a host in VLAN 10 to a host in VLAN 20. The switches are configured with IEEE 802.1Q trunking. Which misconfiguration likely allowed this attack?

A.The native VLAN is not used on any trunk ports
B.Spanning Tree Protocol is disabled
C.Port security is disabled on all ports
D.Dynamic Trunking Protocol (DTP) is enabled on access ports
AnswerD

When Dynamic Trunking Protocol (DTP) is enabled on an access port, it allows the port to actively negotiate its trunking status with a connected device. An attacker can leverage this by sending DTP frames from their connected machine, tricking the switch port into establishing a trunk link. Once a trunk is formed, the attacker can then send specially crafted 802.1Q tagged frames, allowing them to access and communicate with any VLAN configured on that trunk, thereby successfully performing a VLAN hopping attack. This misconfiguration directly enables the vulnerability.

Why this answer

D is correct because VLAN hopping attacks exploit Dynamic Trunking Protocol (DTP) to negotiate a trunk link between an attacker's host and a switch port. If DTP is enabled on an access port, the attacker can spoof DTP messages to form a trunk, gaining access to traffic from multiple VLANs, including VLAN 20 from VLAN 10.

Exam trap

ISC2 often tests the distinction between the two types of VLAN hopping (switch spoofing vs. double-tagging), and the trap here is that candidates confuse disabling STP or port security as relevant mitigations, when the core issue is DTP-enabled access ports allowing trunk negotiation.

How to eliminate wrong answers

Option A is wrong because the native VLAN is used on trunk ports by default in IEEE 802.1Q, and not using it would not prevent VLAN hopping; in fact, a misconfigured native VLAN can be exploited for double-tagging attacks, but the question describes a switch spoofing attack, not double-tagging. Option B is wrong because disabling Spanning Tree Protocol (STP) can cause network loops but does not directly enable VLAN hopping; VLAN hopping relies on trunk negotiation, not STP state. Option C is wrong because disabling port security limits MAC address filtering but does not prevent an attacker from negotiating a trunk via DTP; port security is a separate control for MAC flooding and unauthorized devices, not for trunk negotiation.

803
MCQmedium

A financial institution requires that no single employee can approve a transaction and also reconcile the account. This is an example of which security principle?

A.Separation of duties
B.Least privilege
C.Defense in depth
D.Need to know
AnswerA

Separation of duties is a control designed to prevent fraud, error, and abuse by ensuring that no single individual has complete control over a critical process from start to finish. It mandates that different individuals perform distinct parts of a sensitive task, such as authorizing, recording, and reconciling transactions. This structure prevents a single employee from both initiating and approving a financial transaction, thereby mitigating the risk of unauthorized actions.

Why this answer

Separation of duties (SoD) is the security principle that prevents a single individual from having conflicting responsibilities, such as both approving a transaction and reconciling the account. This reduces the risk of fraud or error by requiring collusion between two or more people to subvert a process. In a financial system, SoD is enforced through access control mechanisms that assign distinct roles (e.g., 'Transaction Approver' and 'Account Reconciler') with mutually exclusive permissions, often implemented via Role-Based Access Control (RBAC) or attribute-based policies.

Exam trap

The trap here is that candidates confuse 'separation of duties' with 'least privilege' because both involve limiting access, but separation of duties specifically addresses conflicting tasks to prevent fraud, not just minimizing permissions.

How to eliminate wrong answers

Option B (Least privilege) is wrong because it focuses on granting only the minimum permissions necessary to perform a job function, not on preventing conflicts of interest or fraud through role separation. Option C (Defense in depth) is wrong because it describes a layered security strategy using multiple controls (e.g., firewalls, IDS, encryption), not a principle that divides critical tasks among different individuals. Option D (Need to know) is wrong because it restricts access to data based on whether it is required for a specific task, but does not address the segregation of conflicting duties like approval and reconciliation.

804
MCQhard

A network architect is designing a secure connection between two data centers across an untrusted WAN. The requirement is to encrypt all traffic and authenticate both endpoints. Which protocol should be used?

A.SSH
B.IPsec tunnel mode
C.MPLS
D.SSL/TLS
AnswerB

IPsec tunnel mode encrypts the entire original packet and encapsulates it, providing confidentiality and mutual endpoint authentication via IKE. This satisfies the requirement to protect all traffic across the untrusted WAN while verifying both data-centre gateways.

Why this answer

IPsec tunnel mode is the correct choice because it encrypts the entire IP packet, including the original IP header, and encapsulates it within a new IP header for secure transport across an untrusted WAN. It also provides mutual authentication of both endpoints using IKE (Internet Key Exchange) with pre-shared keys or certificates, satisfying the requirement for encrypting all traffic and authenticating both data centers.

Exam trap

ISC2 often tests the distinction between IPsec tunnel mode and transport mode, and candidates may confuse SSL/TLS (which secures individual sessions) with a full network-layer VPN solution, missing that IPsec tunnel mode is the only option that encrypts all traffic and authenticates both endpoints at the network layer.

How to eliminate wrong answers

Option A is wrong because SSH is a protocol for secure remote login and command execution, not designed for site-to-site VPN encryption of all traffic between networks; it operates at the application layer and cannot encrypt arbitrary IP traffic between two data centers. Option C is wrong because MPLS is a label-switching technology for traffic engineering and QoS, not an encryption protocol; it provides no confidentiality or authentication, and traffic traversing an MPLS WAN is typically sent in the clear unless combined with IPsec or another encryption layer. Option D is wrong because SSL/TLS operates at the transport layer and is designed for securing individual connections (e.g., HTTPS), not for encrypting all IP traffic between two networks; it cannot encapsulate and protect non-TCP/UDP traffic or provide the same level of network-layer authentication and encryption as IPsec tunnel mode.

805
MCQhard

A DevSecOps team wants to integrate security into the CI/CD pipeline without slowing down development. Which approach best achieves this?

A.Perform comprehensive security tests only on major releases
B.Conduct a security review after each release and fix issues retrospectively
C.Require manual security sign-off before each production deployment
D.Implement automated security scanning with gating (pass/fail) in the pipeline
AnswerD

Automated scanning with pass/fail gating embeds security checks directly into the pipeline, so vulnerabilities halt builds without manual review stages. This enforces security consistently while preserving development velocity, unlike periodic or advisory-only scanning that adds friction or delays.

Why this answer

Option D is correct because implementing automated security scanning with gating (pass/fail) in the pipeline embeds security checks directly into CI/CD, catching vulnerabilities early via SAST/DAST/SCA tools while keeping feedback fast and non-blocking for compliant builds. This 'shift-left' approach satisfies DevSecOps goals by making security continuous and repeatable without adding manual delays. Option A is wrong because testing only on major releases leaves vulnerabilities undetected for long periods and is not continuous.

Option B is wrong because post-release reviews and retrospective fixes are reactive, not preventive, and expose production to risk. Option C is wrong because mandatory manual sign-off before every deployment creates a bottleneck that slows development, contradicting the goal.

806
Multi-Selectmedium

An organization is conducting a Business Impact Analysis (BIA) as part of its business continuity planning. Which THREE of the following are essential components of a BIA? (Choose three.)

Select 3 answers
A.Criticality prioritization
B.Recovery Time Objective (RTO)
C.Mean Time Between Failures (MTBF)
D.Single point of failure identification
E.Maximum Tolerable Downtime (MTD)
AnswersA, B, E

Criticality prioritization is a core activity within a Business Impact Analysis (BIA), where business processes and assets are systematically evaluated and ranked based on their importance to the organization's mission and the potential impact of their disruption. This ranking helps allocate recovery resources effectively, ensuring that the most vital functions receive immediate attention during a disruptive event. It directly informs the development of recovery strategies and objectives.

Why this answer

Option A (Criticality prioritization) is correct because a BIA must rank business processes and supporting assets by their importance to the organization, so recovery efforts and resources are directed to the most vital functions first. Option B (Recovery Time Objective, RTO) is correct because the BIA establishes the maximum acceptable time to restore a process or system after disruption, which drives continuity and recovery strategies. Option E (Maximum Tolerable Downtime, MTD) is correct because the BIA defines the total time a business process can be unavailable before unacceptable consequences occur, and RTO must be set within the MTD.

Option C (MTBF) is not a BIA component; it is a reliability metric for hardware or components and does not establish business impact or recovery requirements. Option D (Single point of failure identification) is not an essential BIA component; it is a risk assessment or architecture review activity that may follow the BIA but is not one of its core outputs.

Exam trap

CISSP often tests the confusion between BIA deliverables (criticality, RTO, MTD, RPO) and general reliability/architecture metrics like MTBF or SPOF analysis, which are supporting inputs rather than essential BIA components.

807
Multi-Selectmedium

A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?

Select 2 answers
A.Change request
B.Denial of Service (DoS)
C.Patch management failure
D.Insider threat
E.Business continuity exercise
AnswersB, D

Denial of Service (DoS) is a critical incident category because it directly impacts the availability of systems and services, often rendering them inaccessible to legitimate users. This type of attack involves overwhelming a target with traffic or requests, consuming resources, and preventing normal operation. Such an event requires immediate incident response to restore service and mitigate ongoing impact.

Why this answer

Option B, Denial of Service (DoS), is a valid incident category because standard IR frameworks such as NIST SP 800-61 and SANS categorize attacks that degrade or block availability of systems and networks (e.g., volumetric floods, SYN floods, application-layer exhaustion) as a distinct incident type requiring specific detection and containment playbooks. Option D, Insider threat, is also a valid category because incidents involving authorized users—whether malicious, negligent, or compromised—such as data exfiltration, privilege abuse, or credential misuse are treated as a separate class due to their unique investigative and legal handling needs. The remaining options are not incident categories: A, Change request, is an ITIL change-management artifact, not an incident type; C, Patch management failure, is a vulnerability or configuration management issue that may contribute to an incident but is not itself a standard IR category; and E, Business continuity exercise, is a planned testing activity, not a security incident.

Exam trap

CISSP often tests whether candidates can distinguish actual incident categories from routine IT processes or preparedness activities, so they mistakenly select change requests or BC exercises as incident types.

808
Multi-Selectmedium

An organization is implementing a defense-in-depth strategy for a data center. Which THREE of the following are examples of physical security controls that align with layered defense?

Select 3 answers
A.Antivirus software
B.Intrusion detection system on the network
C.Card reader at building entrance
D.Server cage locks
E.Perimeter fencing
AnswersC, D, E

A card reader at a building entrance is a definitive physical access control mechanism, serving as a critical layer in a defense-in-depth strategy. It enforces authentication and authorization requirements before granting physical entry to a facility, directly restricting human movement and protecting all assets within from unauthorized personnel.

Why this answer

Option C (card reader at building entrance) is correct because it is a physical access control that authenticates individuals before they can enter the facility, forming an outer layer of defense. Option D (server cage locks) is correct because locking cages around server racks physically restrict access to the most sensitive hardware, adding an inner layer of protection even after someone has entered the building. Option E (perimeter fencing) is correct because fencing establishes the outermost physical boundary of the data center, deterring and delaying unauthorized entry.

Options A (antivirus software) and B (network intrusion detection system) are logical/technical controls, not physical security controls, so they do not belong in this layered physical defense scenario.

Exam trap

CISSP often tests control classification — candidates see 'intrusion detection' and 'antivirus' as security controls and incorrectly include them as physical controls, forgetting that physical controls must restrict or monitor physical access to facilities and assets.

809
Multi-Selecthard

A security team is planning to integrate security testing into the software development lifecycle. They want to identify vulnerabilities early and often. Which TWO of the following testing methods should be implemented during the development phase (before deployment) to catch code-level vulnerabilities?

Select 2 answers
A.Interactive Application Security Testing (IAST)
B.Penetration testing
C.Vulnerability scanning
D.Static Application Security Testing (SAST)
E.Dynamic Application Security Testing (DAST)
AnswersA, D

IAST is a modern security testing method that instruments the application code and observes its behavior from within during automated or manual functional tests. It provides real-time analysis of application interactions, identifying vulnerabilities with high accuracy by understanding both code execution and data flow. This integration into existing testing processes makes it highly effective for finding flaws early in the development lifecycle.

Why this answer

Option A, Interactive Application Security Testing (IAST), is correct because it instruments the running application (often via agents during automated tests) to analyze code execution in real time, detecting code-level vulnerabilities such as injection flaws early in the development phase before deployment. Option D, Static Application Security Testing (SAST), is correct because it performs white-box analysis of source code, bytecode, or binaries without executing the program, allowing developers to find flaws like SQL injection or hardcoded secrets directly in the code during development. Penetration testing (B) is typically conducted against a deployed, running system and simulates real-world attacks, so it occurs later than the development phase.

Vulnerability scanning (C) identifies known weaknesses in deployed hosts, services, and configurations rather than code-level defects during development. Dynamic Application Security Testing (E) tests a running application from the outside (black-box) and is generally performed after deployment or in a staging environment, not as an early code-level check.

Exam trap

CISSP often tests the phase confusion between SAST/IAST (development-time, code-level) and DAST/pen testing/vulnerability scanning (deployment-time, runtime or infrastructure), so candidates must map each tool to the correct SDLC phase.

810
Matchingmedium

Match each security assessment type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Automated check for known vulnerabilities

Simulated attack to exploit vulnerabilities

Systematic evaluation of compliance with policies

Identification and analysis of risks

Why these pairings

Correct matches: Vulnerability Assessment uses automated scans; Penetration Test involves exploitation; Security Audit reviews policies; Risk Assessment evaluates risks. Common confusions mix vulnerability assessments with penetration tests.

811
MCQmedium

An organization's security policy requires that privileged accounts have their passwords changed every 30 days and be monitored. Which solution effectively manages these requirements?

A.Role-based access control
B.Enterprise password manager
C.Privileged Access Management (PAM) solution
D.Single sign-on for administrators
AnswerC

A Privileged Access Management (PAM) solution is purpose-built to secure, manage, and monitor all forms of privileged access within an organization. It provides essential capabilities such as automated password rotation for privileged accounts, secure credential vaulting, just-in-time access provisioning, and comprehensive session recording and monitoring. PAM solutions generate detailed audit trails of all privileged activities, ensuring accountability, enforcing the principle of least privilege, and significantly reducing the attack surface associated with high-risk accounts.

Why this answer

A Privileged Access Management (PAM) solution is specifically designed to manage privileged accounts, enforce password rotation policies (e.g., every 30 days), and provide detailed monitoring and auditing of privileged sessions. It automates password changes, vaults credentials, and logs all access, directly meeting the policy requirements for privileged accounts.

Exam trap

The trap here is that candidates confuse a general password manager (Option B) with a PAM solution, overlooking that PAM adds session monitoring, auditing, and just-in-time access for privileged accounts, which are critical for compliance.

How to eliminate wrong answers

Option A is wrong because Role-Based Access Control (RBAC) manages access rights based on roles, not password lifecycle or monitoring of privileged accounts. Option B is wrong because an enterprise password manager typically stores and rotates passwords for general users, but lacks the session monitoring, auditing, and just-in-time access controls required for privileged accounts. Option D is wrong because Single Sign-On (SSO) for administrators simplifies authentication but does not enforce password rotation or provide the granular monitoring and vaulting needed for privileged accounts.

812
MCQmedium

A security analyst is reviewing access rights and discovers an active account belonging to a former employee who left six months ago. This is an example of:

A.Orphaned account
B.Separation of duties violation
C.Account lockout
D.Privilege escalation
AnswerA

An orphaned account is a user or service account that no longer has an active, accountable owner or associated employee, often due to an employee's departure without proper deprovisioning. When a security analyst discovers such an account during an access rights review, it represents a significant security vulnerability as it could be exploited without detection or used to maintain unauthorized access. These accounts pose a risk because they lack oversight and may retain elevated privileges, making them prime targets for malicious actors. Identifying them is a critical part of regular access reviews and identity lifecycle management.

Why this answer

An orphaned account is one that remains active after its owner no longer needs it — typically because the employee left, changed roles, or the account was never deprovisioned. A former employee's account still active six months after departure is the textbook definition of an orphaned account. It represents a significant access control failure because the account can be used without legitimate ownership.

Exam trap

The trap is conflating 'orphaned account' with 'insider threat' or 'privilege escalation'; the exam wants you to identify the specific access-control condition (unmanaged leftover account) rather than the broader risk category.

How to eliminate wrong answers

Option B is wrong because separation of duties violations involve one person holding conflicting responsibilities, not an unmanaged leftover account. Option C is wrong because account lockout is a state where an account is temporarily disabled after failed logins, which is unrelated to a departed employee's active account. Option D is wrong because privilege escalation refers to gaining higher privileges than authorized, not to the mere existence of an unmanaged account.

813
MCQmedium

A security team is conducting a penetration test on a web application. They identify that the application is vulnerable to reflected cross-site scripting (XSS). Which of the following is the most effective mitigation?

A.Using HTTPS to encrypt traffic
B.Implementing a Content Security Policy (CSP) with strict directives
C.Validating input against a whitelist of allowed characters
D.Encoding all user-supplied data before reflecting it in the response
AnswerD

Encoding all user-supplied data before reflecting it in the response is the primary and most effective defense against reflected Cross-Site Scripting (XSS) attacks. This process transforms potentially malicious characters (e.g., '<', '>', '&') into their safe, non-executable HTML entity equivalents (e.g., '&lt;', '&gt;', '&amp;'). By ensuring the browser interprets user input as inert data rather than executable code, this practice directly prevents the injection and execution of malicious scripts within the user's browser.

Why this answer

Reflecting user-supplied data without proper encoding allows an attacker to inject arbitrary HTML/JavaScript that executes in the victim's browser. Output encoding (e.g., HTML entity encoding for context like <script> to &lt;script&gt;) neutralizes the injected script by treating it as data rather than executable code. This directly addresses the root cause of reflected XSS—failure to separate user input from executable content in the response.

Exam trap

The trap here is that candidates often confuse input validation (Option C) with output encoding, but the CISSP emphasizes that output encoding is the definitive control for injection flaws because it ensures data is treated as data regardless of input validation failures.

How to eliminate wrong answers

Option A is wrong because HTTPS encrypts data in transit but does not prevent the server from reflecting malicious input in the response; the XSS payload still executes in the browser after decryption. Option B is wrong because while CSP can mitigate XSS by restricting script sources, it is a defense-in-depth control and not the most effective primary mitigation—it can be bypassed if the application reflects user input into inline script contexts or if CSP is misconfigured (e.g., using 'unsafe-inline'). Option C is wrong because input validation against a whitelist is effective for input validation but does not guarantee safety when data is reflected; an attacker may bypass the whitelist or inject via other input channels, and output encoding is required regardless of input validation.

814
MCQmedium

An organization wants to test its web application for vulnerabilities by running the application and probing it with malicious inputs. Which tool is BEST suited for this purpose?

A.OWASP ZAP
B.Checkmarx
C.SonarQube
D.Veracode
AnswerA

OWASP ZAP is a leading open-source Dynamic Application Security Testing (DAST) tool specifically designed to find vulnerabilities in running web applications. It actively proxies HTTP/S traffic, allowing it to scan for common web vulnerabilities like SQL injection, Cross-Site Scripting (XSS), and broken authentication by interacting with the application as a real user would. This makes it ideal for identifying security flaws that manifest at runtime, after the application has been deployed.

Why this answer

OWASP ZAP (Zed Attack Proxy) is a dynamic application security testing (DAST) tool that runs the application and actively probes it with malicious inputs, making it the correct choice for runtime vulnerability testing. It intercepts and modifies HTTP/S traffic, performs active scanning for injection, XSS, and misconfigurations, and is specifically designed for testing running web applications.

Exam trap

CISSP often tests the SAST vs. DAST distinction — candidates pick Checkmarx or Veracode because they recognize them as security tools, forgetting those analyze code statically rather than probing a running application.

How to eliminate wrong answers

Option B is wrong because Checkmarx is a static application security testing (SAST) tool that analyzes source code without executing the application, so it cannot probe a running app with malicious inputs. Option C is wrong because SonarQube is a code quality and static analysis platform that inspects source code for bugs and code smells, not a runtime DAST scanner. Option D is wrong because Veracode is primarily a SAST and software composition analysis (SCA) platform (with some DAST capability) that analyzes binaries and source rather than running the application and probing it interactively.

815
MCQhard

A company's security team uses a tool that instruments the application at runtime to monitor and block attacks. This is an example of:

A.IAST
B.RASP
C.SAST
D.DAST
AnswerB

RASP (Runtime Application Self-Protection) directly integrates with the application's runtime environment, actively monitoring its execution, data inputs, and outputs in real-time. By instrumenting the application, RASP can detect and immediately block malicious requests or anomalous behavior that indicates an attempted exploit, such as SQL injection or cross-site scripting. Its core purpose is to provide continuous, self-contained protection against attacks in live production systems.

Why this answer

RASP (Runtime Application Self-Protection) instruments the application at runtime, embedding security checks inside the application to detect and block attacks in real time. It operates within the application's execution context, allowing it to monitor data flow, method calls, and user input.

Exam trap

CISSP often tests the distinction between testing tools (SAST, DAST, IAST) and runtime protection (RASP) — the trap is selecting IAST because it also instruments the application, but IAST is used during testing, not for blocking attacks in production.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) is a testing methodology that combines static and dynamic analysis during QA/testing; it identifies vulnerabilities but does not block attacks in production. Option C is wrong because SAST (Static Application Security Testing) analyzes source code without executing it, typically during development, and cannot block runtime attacks. Option D is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside (black-box) to find vulnerabilities, but it does not instrument the application or block attacks in real time.

816
Multi-Selecthard

A security architect is defining security requirements for a new software development project that will use an Agile methodology. The organization wants to ensure that security is integrated throughout the development lifecycle. Which TWO of the following practices BEST support this goal? (Choose two.)

Select 2 answers
A.Document security requirements in a large specification document at the project start.
B.Require the security team to manually review all code changes before deployment.
C.Integrate automated static analysis security testing (SAST) into the CI/CD pipeline.
D.Conduct threat modeling sessions at the beginning of each sprint for new features.
E.Perform a full penetration test only at the end of the project before release.
AnswersC, D

Automated SAST in the CI/CD pipeline provides continuous code analysis, catching vulnerabilities as code is committed. This aligns with Agile's fast iterations and enables developers to fix issues immediately. It scales security across the team without slowing down delivery, making it a best practice for integrating security into the development lifecycle.

Why this answer

Threat modeling at each sprint and automated SAST in the CI/CD pipeline both embed security into Agile's iterative cycles. Threat modeling addresses design flaws early, while SAST provides continuous code-level checks. Together, they enable rapid feedback and remediation, which are essential for integrating security throughout the development lifecycle without impeding Agile delivery.

Exam trap

The trap here is assuming that a single end-of-project penetration test or manual code reviews constitute sufficient security integration in Agile.

Page 10

Page 11 of 11

All pages