Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 76–150

816 questions total · 11pages · All types, answers revealed

Page 1

Page 2 of 11

Page 3
76
MCQhard

A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?

A.Use
B.Share
C.Archive
D.Destroy
AnswerD

Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.

Why this answer

The destroy phase of the data lifecycle explicitly governs the secure disposal of data once its retention period ends. In this scenario, after 7 years, the policy mandates destruction, so the action falls under the Destroy phase. This phase ensures data is irrecoverable and compliant with legal and regulatory requirements.

Exam trap

CISSP often tests the confusion between archiving and destruction; candidates may think archiving implies eventual destruction, but archiving is a separate phase focused on long-term retention, while destruction is the final, irreversible step.

How to eliminate wrong answers

Option A (Use) is wrong because it refers to the active utilization of data during its lifecycle, not its disposal. Option B (Share) is wrong because it involves distributing data to authorized parties, not destroying it. Option C (Archive) is wrong because archiving is the long-term storage of data for retention, not its final destruction.

77
Multi-Selecteasy

Which TWO of the following are examples of Type 3 authentication factors? (Choose two.)

Select 2 answers
A.Password
B.Fingerprint
C.Smart card
D.One-time password token
E.Retina scan
AnswersB, E

A fingerprint scan is a classic example of Type 3 authentication, which relies on "something you are." This biometric factor captures unique physiological patterns from an individual's finger to verify identity, providing a high level of non-repudiation compared to knowledge or possession factors.

Why this answer

Type 3 authentication factors are "something you are" — biometric characteristics unique to an individual — so B (Fingerprint) is correct because a fingerprint is a physical biometric trait verified by matching minutiae patterns, and E (Retina scan) is correct because it analyzes the unique blood-vessel pattern of the retina, another physiological biometric. The remaining options are not Type 3: A (Password) is a Type 1 factor (something you know), while C (Smart card) and D (One-time password token) are Type 2 factors (something you have), since they rely on possession of a physical device or generated token rather than an inherent biological trait.

Exam trap

CISSP often tests whether candidates can correctly categorize authentication factors — the trap is confusing Type 2 (something you have, like a smart card or OTP token) with Type 3 (something you are, like a fingerprint).

78
MCQmedium

A multinational corporation with a hybrid cloud infrastructure has recently experienced a series of security incidents involving unauthorized access to sensitive customer data. The incidents were traced to compromised credentials of privileged users. The company has implemented multi-factor authentication (MFA) for all privileged accounts, but the attacks persisted. A security assessment team is brought in to evaluate the environment. During the assessment, they discover that some privileged accounts do not require MFA when accessing systems via API calls, and that session tokens for these APIs have a long expiration time of 24 hours. Additionally, the team finds that the logging and monitoring system does not capture API calls from privileged accounts, making it difficult to detect anomalous behavior. The company wants to remediate these issues effectively. Which of the following is the BEST course of action to address the root cause of the incidents?

A.Implement a SIEM system to analyze logs from all sources and create alerts for anomalous API activity.
B.Conduct a full audit of privileged account usage and revoke access for any accounts with suspicious activity.
C.Require MFA for all privileged access methods, including APIs, and reduce session token expiration to 15 minutes.
D.Replace API tokens with certificate-based authentication for all privileged accounts.
AnswerC

This option directly addresses two critical vulnerabilities in privileged access and API security. Requiring Multi-Factor Authentication (MFA) significantly enhances security by ensuring that even if an attacker compromises credentials, they cannot gain access without the second factor. Simultaneously, reducing session token expiration to 15 minutes drastically limits the window of opportunity for an attacker to exploit a stolen or compromised session token, thereby minimizing potential damage from unauthorized access.

Why this answer

The root cause is that privileged accounts can bypass MFA when accessing systems via API calls, and long-lived session tokens (24 hours) provide a wide window for attackers to reuse stolen tokens. Requiring MFA for all privileged access methods, including APIs, closes the authentication gap, and reducing session token expiration to 15 minutes minimizes the impact of token theft by limiting the reuse window. This directly addresses the two key vulnerabilities identified in the assessment.

Exam trap

The trap here is that candidates often choose a detective control (like SIEM) or a reactive measure (like auditing) instead of a preventive control that directly closes the authentication gap, because they overlook that the root cause is the MFA bypass on API calls and long-lived tokens, not a lack of monitoring or account hygiene.

How to eliminate wrong answers

Option A is wrong because implementing a SIEM system to analyze logs and create alerts is a detective control, not a preventive one; it does not address the root cause of missing MFA on API calls and long-lived tokens, and without capturing API calls from privileged accounts, the SIEM would have no data to analyze. Option B is wrong because conducting a full audit and revoking access for suspicious accounts is a reactive, one-time cleanup that does not prevent future credential compromise or token reuse; it ignores the systemic gaps in authentication and session management. Option D is wrong because replacing API tokens with certificate-based authentication, while more secure, does not inherently enforce MFA for every API call and does not address the long session token expiration issue; it also introduces complexity without directly solving the MFA bypass problem.

79
MCQhard

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

A.A memorandum of understanding (MOU)
B.A data processing agreement under GDPR
C.A consent form from each patient
D.A business associate agreement (BAA)
AnswerD

A Business Associate Agreement (BAA) is a legally mandated contract under HIPAA that must be established between a covered entity and its business associates before Protected Health Information (PHI) is shared. This agreement obligates the business associate to implement specific administrative, physical, and technical safeguards to protect PHI, adhering to the HIPAA Security and Privacy Rules. The BAA ensures accountability and extends the covered entity's compliance responsibilities to third parties handling PHI on its behalf, making it the correct and essential mechanism for such sharing.

Why this answer

Under HIPAA, a covered entity sharing PHI with a third-party vendor that performs a function involving PHI must have a Business Associate Agreement (BAA) in place. The BAA contractually obligates the business associate to safeguard PHI and comply with HIPAA Privacy and Security Rules. This is a legal requirement, not optional.

Exam trap

CISSP often tests whether candidates confuse HIPAA's BAA with GDPR's DPA or generic MOUs; the trap is picking a plausible-sounding agreement that does not carry HIPAA's specific legal obligations.

How to eliminate wrong answers

Option A is wrong because an MOU is a general non-binding or loosely binding agreement that does not satisfy HIPAA's specific contractual requirements for business associates. Option B is wrong because GDPR's Data Processing Agreement applies to EU personal data and does not fulfill HIPAA obligations for PHI in the US. Option C is wrong because individual patient consent does not replace the BAA requirement; HIPAA permits certain disclosures for treatment, payment, and operations without consent, but the BAA is still mandatory for business associates.

80
MCQhard

A security engineer is troubleshooting a site-to-site IPsec VPN between two firewalls. The tunnel status shows Phase 1 is up but Phase 2 is not. Which of the following is the most likely cause?

A.Incorrect pre-shared key
B.Mismatched authentication algorithm
C.Firewall rule blocking IKE traffic
D.Mismatched proxy IDs (traffic selectors)
AnswerD

Mismatched proxy IDs, also known as traffic selectors, are a common cause for IKE Phase 2 failures. Proxy IDs define the specific source and destination IP addresses, subnets, and protocols that are permitted to traverse the IPSec tunnel and will be protected by the IPSec Security Association (SA). If the local and remote proxy IDs do not precisely match, the Phase 2 SA cannot be successfully established, even if Phase 1 completed, thus preventing the actual data encryption tunnel from forming.

Why this answer

Phase 1 (IKE SA) establishes a secure channel for key exchange, while Phase 2 (IPsec SA) negotiates the specific traffic to be encrypted. If Phase 1 is up but Phase 2 fails, the most common cause is a mismatch in proxy IDs (traffic selectors), such as local/remote subnets or ports, which prevents the two peers from agreeing on which traffic to protect. This is distinct from authentication or encryption mismatches, which would typically cause Phase 1 to fail.

Exam trap

ISC2 often tests the distinction between Phase 1 and Phase 2 failures, and the trap here is that candidates mistakenly attribute Phase 2 failures to authentication or encryption mismatches, which actually affect Phase 1, not the traffic selector negotiation in Phase 2.

How to eliminate wrong answers

Option A is wrong because an incorrect pre-shared key would cause Phase 1 authentication to fail, preventing the IKE SA from being established. Option B is wrong because a mismatched authentication algorithm (e.g., SHA-1 vs SHA-256) would also cause Phase 1 negotiation to fail during the IKE proposal exchange. Option C is wrong because a firewall rule blocking IKE traffic (UDP 500/4500) would prevent Phase 1 from completing, not just Phase 2.

81
MCQmedium

A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?

A.Network DLP
B.Cloud DLP
C.Endpoint DLP
D.Classification-based controls
AnswerA

Network DLP solutions are strategically deployed at network egress points, such as internet gateways or email servers, to inspect all outbound network traffic in real-time. This technology analyzes data streams for sensitive information based on predefined policies, identifying and preventing unauthorized transmission of confidential data via protocols like HTTP, HTTPS, FTP, and SMTP. Its primary function is to stop data leakage as it attempts to leave the organizational boundary.

Why this answer

Network DLP is designed to monitor and control data in transit across network boundaries, including email and web traffic. It inspects packets leaving the corporate network to detect and block sensitive data exfiltration. Therefore, it is best suited for monitoring and blocking sensitive data leaving via email or web traffic.

Exam trap

Candidates often confuse network DLP with endpoint DLP; the key is that network DLP focuses on data in motion across the network perimeter, while endpoint DLP focuses on data at rest or in use on devices.

How to eliminate wrong answers

Option B is wrong because Cloud DLP focuses on data stored in or moving to cloud services (e.g., SaaS, IaaS), not on general network egress. Option C is wrong because Endpoint DLP monitors data at rest and in use on endpoints (e.g., USB, local email clients), but it does not comprehensively cover network egress channels like web traffic. Option D is wrong because classification-based controls are a method of labeling data, not a DLP deployment type; they can complement DLP but do not themselves monitor network traffic.

82
MCQhard

A red team exercise is planned to simulate a sophisticated adversary. The blue team is aware of the exercise but not the exact methods. The red team is given a budget to acquire attack tools. What is the primary advantage of this approach over a traditional penetration test?

A.It ensures that the blue team is not alerted to the test
B.It provides comprehensive vulnerability coverage
C.It evaluates the organization's detection and response capabilities
D.It is more cost-effective than a penetration test
AnswerC

The core objective of a red team exercise is to rigorously test and evaluate the organization's security operations center (SOC), incident response procedures, and defensive technologies against a simulated sophisticated adversary. It assesses the blue team's ability to detect, analyze, contain, eradicate, and recover from advanced persistent threats (APTs) in a real-world scenario. This provides invaluable insights into the organization's operational readiness and the effectiveness of its security controls and personnel.

Why this answer

A red team exercise with a known-but-not-detailed blue team specifically tests the organization's detection and response capabilities under realistic adversarial conditions. Unlike a traditional penetration test, which focuses on identifying vulnerabilities, this approach evaluates how well the blue team can detect, analyze, and respond to stealthy, multi-stage attacks that mimic a sophisticated adversary. The red team's budget for attack tools allows them to simulate advanced persistent threats (APTs) that challenge the blue team's security operations center (SOC) processes and incident response procedures.

Exam trap

The trap here is that candidates confuse the purpose of a red team exercise (evaluating detection and response) with a penetration test (finding vulnerabilities), leading them to select Option B, which describes the latter's goal rather than the primary advantage of the former.

How to eliminate wrong answers

Option A is wrong because the blue team is explicitly aware of the exercise, so the test is not covert; the advantage is not about avoiding alerts but about evaluating detection under known-threat conditions. Option B is wrong because comprehensive vulnerability coverage is the goal of a traditional penetration test, not a red team exercise, which focuses on simulating adversary behavior rather than enumerating all possible vulnerabilities. Option D is wrong because red team exercises are typically more expensive than penetration tests due to the specialized skills, custom tools, and extended duration required to simulate sophisticated adversaries.

83
MCQeasy

Which document is mandatory, high-level, and sets the direction for security within an organization?

A.Policy
B.Standard
C.Procedure
D.Baseline
AnswerA

A policy is a mandatory, high-level statement approved by management, articulating the organization's strategic intent and overarching requirements for information security. It establishes the fundamental rules and direction for protecting assets, often driven by legal, regulatory, or business imperatives, without specifying technical details. Policies are foundational, setting the broad scope and purpose of security efforts across the enterprise.

Why this answer

A security policy is a mandatory, high-level document that defines an organization's security objectives, principles, and management intent. It sets direction and assigns responsibility without prescribing specific technical implementations. Standards, procedures, and baselines all derive from and must comply with the policy, making policy the authoritative top-level document.

Exam trap

CISSP often tests the distinction between mandatory vs. advisory and high-level vs. detailed, since policy, standard, procedure, and baseline are all part of the same hierarchy but differ in authority, specificity, and audience.

How to eliminate wrong answers

Option B is wrong because a standard is a mandatory, more detailed document that specifies uniform technical or operational requirements to support the policy — it is lower-level and more prescriptive. Option C is wrong because a procedure is a step-by-step operational instruction for performing a task, which is tactical rather than directional. Option D is wrong because a baseline is a minimum set of security configurations for a specific system or category, derived from standards, and is technical rather than high-level.

84
MCQmedium

A security analyst is investigating a potential covert timing channel in a system. Which of the following characteristics best describes this type of channel?

A.It requires high bandwidth to be effective
B.It modulates the time between events to encode information
C.It uses storage locations not normally accessible to the sender and receiver
D.It uses encryption to hide the content of the communication
AnswerB

A covert timing channel encodes information by precisely modulating the temporal relationship between observable events within a shared system. This involves a sender manipulating the timing of an action, like delaying a process or altering packet transmission intervals, which a receiver then observes and decodes based on the temporal variations. For example, a short delay might represent a '0' bit, while a longer delay signifies a '1' bit, transmitting data without using explicit storage or direct communication channels.

Why this answer

A covert timing channel encodes information by varying the timing of observable events—such as packet inter-arrival times, CPU scheduling delays, or response latencies—rather than by writing to a shared storage location. The receiver measures these timing variations to reconstruct the hidden message. This is the defining characteristic that distinguishes timing channels from storage channels.

Exam trap

The trap here is confusing covert timing channels with covert storage channels; CISSP candidates frequently pick the storage-channel description because both involve hidden communication, but only timing channels modulate event timing.

How to eliminate wrong answers

Option A is wrong because covert timing channels are typically low-bandwidth by nature; high bandwidth would make them easier to detect and is not a requirement. Option C is wrong because it describes a covert storage channel, which uses shared storage locations (like unused header bits or file attributes) rather than timing. Option D is wrong because encryption conceals content, not the existence of the channel, and is unrelated to the definition of a covert timing channel.

85
MCQeasy

A development team is adopting a secure SDLC. Which phase should include threat modeling to identify potential security vulnerabilities early?

A.Implementation
B.Design
C.Testing
D.Requirements gathering
AnswerB

The design phase is the optimal stage for threat modeling because detailed architectural diagrams, data flow diagrams, and component interactions are established. This allows security professionals to systematically analyze the system's structure, identify trust boundaries, and pinpoint potential attack vectors using methodologies like STRIDE or PASTA. Addressing security concerns here ensures controls are built-in from the ground up, preventing vulnerabilities before any code is written, which is far more efficient and cost-effective.

Why this answer

Threat modeling is a structured activity that identifies potential threats, vulnerabilities, and attack vectors against a system. It is most effective during the Design phase because architectural decisions, data flow diagrams, trust boundaries, and component interactions are being defined, allowing security controls to be built in rather than bolted on later. Performing threat modeling here aligns with the 'shift left' principle of secure SDLC, reducing cost and effort compared to retrofitting security after implementation.

Exam trap

The trap here is that candidates confuse 'Requirements gathering' (where high-level security goals are set) with 'Design' (where concrete architectural decisions enable actionable threat modeling), leading them to pick D instead of B.

How to eliminate wrong answers

Option A is wrong because Implementation focuses on writing code; threat modeling at this stage is too late to influence architecture and would require costly rework to fix design-level flaws. Option C is wrong because Testing occurs after code is built; while security testing can validate threats, it cannot prevent design flaws from being embedded. Option D is wrong because Requirements gathering captures functional and security objectives but lacks the detailed system architecture and data flow context needed for effective threat modeling (e.g., STRIDE or PASTA analysis).

86
MCQhard

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

A.Unauthorized access
B.Denial of Service (DoS)
C.Malware infection
D.Data breach
AnswerD

A data breach is precisely defined as the unauthorized access, disclosure, or exfiltration of sensitive, protected, or confidential information. The SIEM alert indicating unauthorized data transfer out of the network directly describes the core characteristic of a data breach, where data has left the secure perimeter without proper authorization. This makes it the most accurate classification for an incident involving data exfiltration.

Why this answer

Large outbound data transfers from a sensitive database server to an external IP during non-business hours strongly indicate exfiltration, which is the hallmark of a data breach. The volume, sensitivity of the source, and off-hours timing all point to unauthorized data movement rather than other incident types.

Exam trap

CISSP often tests whether candidates can distinguish the underlying cause (malware, unauthorized access) from the resulting incident classification (data breach) based on the evidence presented.

How to eliminate wrong answers

Option A is wrong because unauthorized access alone doesn't explain the large outbound data volume; access may have occurred, but the defining symptom here is exfiltration. Option B is wrong because a DoS would manifest as service unavailability or traffic flooding inbound, not outbound data from a database. Option C is wrong because while malware could cause exfiltration, the question asks for the most likely incident type given the evidence, which is a data breach.

87
Multi-Selectmedium

Which TWO of the following are principles of the Bell-LaPadula security model?

Select 2 answers
A.Separation of duty
B.No write up
C.No read down
D.No read up
E.No write down
AnswersD, E

The 'no read up' rule is formally known as the Simple Security Property within the Bell-LaPadula model. This principle states that a subject at a given security clearance level cannot read information from an object classified at a higher security level. Its purpose is to enforce confidentiality by preventing unauthorized disclosure of classified information to subjects with insufficient clearance, ensuring that users only access data they are authorized to view.

Why this answer

The Bell-LaPadula model enforces mandatory access control (MAC) to protect confidentiality. Option D (No read up) is correct because a subject cannot read an object at a higher classification level, preventing unauthorized access to sensitive information. Option E (No write down) is correct because a subject cannot write to an object at a lower classification level, preventing the downgrading of classified data.

Exam trap

The trap here is that candidates confuse 'no write up' (which Bell-LaPadula allows) with 'no write down' (which it prohibits), or they misapply the Biba model's integrity rules (no read down, no write up) to Bell-LaPadula's confidentiality rules.

88
Multi-Selectmedium

A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)

Select 2 answers
A.Wireshark
B.Volatility
C.Autopsy
D.EnCase
E.FTK
AnswersB, E

Volatility is an advanced, open-source framework specifically engineered for volatile memory (RAM) extraction and analysis. It allows forensic analysts to reconstruct active network connections, extract running processes, inspect loaded DLLs, and recover cached credentials directly from a memory dump, making it the premier choice for memory forensics.

Why this answer

Volatility is a dedicated memory forensics framework; FTK can also capture and analyze memory, though it's more general. EnCase is disk forensics, Wireshark network, Autopsy disk.

89
MCQmedium

A security analyst is investigating a potential data leak via covert channels. Which of the following is an example of a timing covert channel?

A.Modifying unused fields in network packets
B.Encoding data in the TCP sequence number
C.Writing data to a shared disk file
D.Varying the spacing between keystrokes
AnswerD

Varying the spacing between keystrokes is a classic example of a timing covert channel. The secret information is not stored in any persistent state or modified data field, but rather conveyed through the temporal relationship between events. By subtly altering the inter-event delay, such as the time between keystrokes, the sender encodes data that the receiver can decode by observing these timing variations.

Why this answer

A timing covert channel conveys information by modulating the timing of events rather than the content of messages. Varying the spacing between keystrokes encodes bits through inter-keystroke delays, which an observer can decode — this is a classic timing channel. The other options describe storage covert channels.

Exam trap

CISSP often tests whether candidates can distinguish storage covert channels (data hidden in fields/files) from timing covert channels (data encoded in event timing), since both are covert but use different mechanisms.

How to eliminate wrong answers

Option A is wrong because modifying unused fields in network packets is a storage covert channel — data is hidden in packet header fields, not in timing. Option B is wrong because encoding data in the TCP sequence number is also a storage channel, hiding information in a protocol field. Option C is wrong because writing data to a shared disk file is a storage covert channel using a shared resource, not timing.

90
MCQhard

During a code review, a developer encounters the following code snippet in a Java web application used to authenticate users: String query = "SELECT * FROM users WHERE username = '" + request.getParameter("user") + "' AND password = '" + request.getParameter("pass") + "'"; Which of the following is the MOST effective remediation?

A.Use regular expressions to validate the username and password inputs
B.Encode the input using HTML entity encoding before inclusion in the query
C.Escape single quotes in the input parameters
D.Replace the concatenated query with a prepared statement and bind parameters
AnswerD

String concatenation lets attacker-supplied input alter query structure, enabling SQL injection and authentication bypass. A prepared statement with bound parameters sends the query template separately from data, so input is treated strictly as a value and cannot change the SQL grammar.

Why this answer

Prepared statements with parameterized queries separate SQL logic from user input, preventing SQL injection entirely. In Java, using PreparedStatement with bind variables (e.g., `ps.setString(1, user)`) ensures the database treats input as data, not executable code, which is the only reliable defense against SQL injection attacks.

Exam trap

The trap here is that candidates often choose input validation (Option A) or escaping (Option C) because they seem like reasonable security measures, but the CISSP exam emphasizes that parameterized queries/prepared statements are the definitive, defense-in-depth solution for SQL injection, not ad-hoc sanitization.

How to eliminate wrong answers

Option A is wrong because regular expressions alone cannot prevent SQL injection; an attacker can craft input that passes validation but still contains malicious SQL syntax (e.g., using alternate encodings or bypassing regex logic). Option B is wrong because HTML entity encoding is designed to prevent XSS, not SQL injection; it does not neutralize SQL metacharacters like single quotes or dashes in a database context. Option C is wrong because escaping single quotes is insufficient; attackers can exploit other SQL injection vectors such as backslash escapes, second-order injection, or using `UNION` statements without quotes, and escaping is error-prone across different database drivers.

91
MCQhard

During a penetration test, a tester discovers that the target web application responds to HTTP requests with a "200 OK" status for both valid and invalid session tokens on a particular API endpoint. The application uses JSON Web Tokens (JWT) for authentication. Which of the following vulnerabilities is MOST likely present?

A.Weak JWT signing algorithm
B.Session fixation
C.Missing authentication
D.Insecure direct object reference
AnswerC

Missing authentication implies that the application allows access to protected resources without requiring any form of user identity verification whatsoever. In this scenario, the application does perform an authentication step, evidenced by its acceptance of valid tokens and returning a 200 status. The problem isn't a complete absence of authentication, but rather a critical flaw in the validation process of the authentication tokens, allowing invalid ones to bypass security checks.

Why this answer

If an API endpoint returns a '200 OK' status regardless of whether the session token is valid or invalid, it indicates that the endpoint does not actually enforce authentication. Therefore, 'Missing authentication' is the most likely vulnerability. If the issue were a weak JWT signing algorithm, the server would still reject tokens that do not conform to its expected validation rules (such as completely malformed or random invalid tokens).

Accepting any invalid token means authentication is entirely bypassed or missing on this endpoint.

Exam trap

ISC2 exams often include scenarios with complex technologies like JWT to distract candidates. The trap is focusing too much on the JWT aspect and choosing a complex cryptographic flaw (like weak signing algorithms) when the actual behavior—accepting completely invalid tokens—demonstrates a simple lack of authentication enforcement (Missing authentication).

How to eliminate wrong answers

Option B is wrong because session fixation involves an attacker setting a user's session ID before login, but here the issue is with JWT token validation, not session ID fixation. Option C is wrong because missing authentication would mean the endpoint requires no token at all, but the application does check for a token (it returns 200 OK for both valid and invalid tokens, implying token presence is checked but signature is not). Option D is wrong because insecure direct object reference (IDOR) is about exposing internal object references without authorization checks, which is unrelated to JWT signature validation.

92
MCQhard

A company's vulnerability management program requires that all critical vulnerabilities be remediated within 30 days. A critical vulnerability is discovered in a legacy system that cannot be patched because the vendor no longer supports it. Which of the following is the best compensating control?

A.Deploy a host-based intrusion detection system (HIDS)
B.Increase logging and monitoring
C.Segment the system from the rest of the network
D.Encrypt all data at rest on the system
AnswerC

Segmenting the system from the rest of the network is a highly effective preventive and mitigating control for managing a known vulnerability. By isolating the system into a separate network zone, access to the vulnerable service or system is severely restricted, drastically reducing its attack surface. This containment strategy limits the number of potential attackers who can reach the system and prevents an exploit from easily propagating to other network resources, thereby minimizing the overall risk.

Why this answer

Segmenting the legacy system from the rest of the network is the best compensating control because it limits the blast radius if the unpatched vulnerability is exploited. By isolating the system, lateral movement to other critical assets is prevented, reducing overall risk. This is a classic network segmentation control that directly addresses the inability to patch.

Exam trap

CISSP often tests the distinction between preventive controls (segmentation) and detective controls (HIDS, logging), causing candidates to choose detection over prevention when asked for the 'best' compensating control.

How to eliminate wrong answers

Option A (Deploy a host-based intrusion detection system) is wrong because a HIDS only detects and alerts on malicious activity; it does not prevent exploitation or contain the impact, making it a detective rather than a preventive compensating control. Option B (Increase logging and monitoring) is wrong because logging and monitoring are detective controls that improve visibility but do not reduce the likelihood or impact of exploitation. Option D (Encrypt all data at rest on the system) is wrong because encryption at rest protects data if the storage media is stolen, but does not prevent a remote attacker from exploiting the vulnerability and accessing decrypted data in memory or via the application.

93
MCQmedium

An organization is evaluating a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in a file access routine. The routine checks if a user has permission to open a file, then later opens the file. Which of the following best describes the potential exploitation?

A.An attacker exploits a weak cryptographic algorithm
B.An attacker modifies the file after the permission check but before the open operation
C.An attacker performs a buffer overflow to gain elevated privileges
D.An attacker intercepts the network traffic to steal credentials
AnswerB

This scenario precisely describes a Time of Check to Time of Use (TOCTOU) vulnerability, where a system first checks a resource's state, such as file permissions, and then later uses that resource, like opening the file. An attacker exploits the brief interval between these two operations to maliciously alter the file, for instance, by replacing a legitimate file with a symlink to a sensitive system file. This allows the attacker to bypass the initial security check and gain unauthorized access or control over the system's subsequent actions.

Why this answer

TOCTOU is a race condition where the state checked (permission) can change between the check and the use (open). An attacker swaps or modifies the file — often via a symlink — after the permission check passes but before the open executes, causing the program to operate on a different resource than the one authorized.

Exam trap

CISSP often tests whether candidates can distinguish TOCTOU (a race condition) from other vulnerability classes like buffer overflow or crypto weakness — the key is the timing gap between check and use.

How to eliminate wrong answers

Option A is wrong because weak cryptography is a separate class of vulnerability (e.g., MD5 collisions) unrelated to the timing gap between check and use. Option C is wrong because buffer overflow is a memory-safety flaw, not a race condition — it doesn't rely on a check/use window. Option D is wrong because network interception (MITM/sniffing) is a confidentiality attack on traffic, not a local file-access race condition.

94
MCQhard

A network administrator is configuring SNMPv3 for monitoring network devices. The organization requires both authentication and encryption of SNMP traffic. Which combination of protocols should be used to meet this requirement?

A.MD5 for authentication, no privacy
B.SHA for authentication, no privacy
C.SHA for authentication, AES for privacy
D.MD5 for authentication, DES for privacy
AnswerC

This option is correct because it combines the strongest available security algorithms within SNMPv3's User-based Security Model (USM). SHA (Secure Hash Algorithm) provides robust message integrity and authentication, ensuring that messages have not been tampered with and originate from a legitimate source. AES (Advanced Encryption Standard) delivers strong confidentiality, encrypting the entire SNMP message to protect sensitive monitoring data from eavesdropping and unauthorized disclosure, aligning with current best practices for secure network management.

Why this answer

SNMPv3 supports both authentication and encryption via separate User-based Security Model (USM) parameters. To meet the requirement for both, you must select an authentication protocol (e.g., SHA) and a privacy (encryption) protocol (e.g., AES). Option C correctly pairs SHA for authentication with AES for privacy, providing integrity verification and confidentiality of SNMP messages.

Exam trap

The trap here is that candidates may think DES is acceptable because it provides encryption, but CISSP emphasizes that DES is cryptographically weak and not considered secure for modern use, making AES the correct privacy choice.

How to eliminate wrong answers

Option A is wrong because MD5 for authentication with no privacy provides only integrity verification, not encryption, so SNMP traffic remains in plaintext. Option B is wrong because SHA for authentication with no privacy also lacks encryption, failing the confidentiality requirement. Option D is wrong because while MD5 for authentication with DES for privacy provides both, DES is a deprecated, weak encryption algorithm (56-bit key) that does not meet modern security standards; AES is the recommended choice.

95
MCQmedium

A security analyst is reviewing the error handling of an application. The application currently displays detailed stack traces to users when an exception occurs. Which of the following is the best practice for error handling in production?

A.Display generic error messages to users and log detailed errors for admins
B.Display detailed errors to users for troubleshooting
C.Disable all error reporting to eliminate information leakage
D.Encrypt error messages before displaying to users
AnswerA

Displaying generic error messages like 'An unexpected error occurred' to users is a critical security practice that prevents the inadvertent disclosure of sensitive system information, such as database schemas, server configurations, or internal file paths. Concurrently, logging detailed error messages, including stack traces and specific error codes, for administrators is essential for effective debugging, incident response, and proactive identification of application vulnerabilities. This balanced approach ensures operational efficiency and maintainability without compromising the application's security posture by exposing internal workings to potential attackers.

Why this answer

Displaying generic error messages to users prevents attackers from learning internal details such as stack traces, file paths, database schema, or library versions that could be used to craft further attacks. Logging the detailed error information for administrators preserves the ability to troubleshoot and monitor without exposing sensitive data to end users. This separation of user-facing and admin-facing error detail is a fundamental secure coding practice.

Exam trap

CISSP often tests the confusion between 'no error reporting' and 'secure error reporting'—candidates may think disabling all errors is safest, but the correct answer preserves logging for admins while hiding details from users.

How to eliminate wrong answers

Option B is wrong because displaying detailed errors to users directly leaks implementation details (stack traces, SQL fragments, internal IPs) that enable reconnaissance and exploitation, which is the exact vulnerability being remediated. Option C is wrong because disabling all error reporting eliminates the audit and troubleshooting capability entirely, violating availability and monitoring requirements; errors should be logged, not suppressed. Option D is wrong because encrypting error messages before display is impractical and does not solve the problem—users would still receive ciphertext they cannot interpret, and the underlying information leakage risk remains if the key is compromised or the message is decrypted.

96
MCQeasy

Which of the following is a key requirement for an effective backup strategy to ensure data can be recovered after a ransomware attack?

A.Incremental backups are performed monthly.
B.Backups use the same credentials as the production environment.
C.Backups are stored on the same network as production.
D.Backups are encrypted and stored offline or air-gapped.
AnswerD

Encrypting backups protects data confidentiality both in transit and at rest, preventing unauthorized access even if the storage media is compromised. Storing these encrypted backups offline or in an air-gapped manner physically isolates them from the production network, making them impervious to network-borne threats like ransomware, malware, or insider attacks that target online data. This strategy ensures data immutability and provides a secure, last-resort recovery point.

Why this answer

For ransomware resilience, backups must be isolated from the production environment so that malware cannot encrypt or delete them along with production data. Encrypting backups and storing them offline or air-gapped ensures that even if attackers compromise the network and credentials, the backup copies remain intact and recoverable. This directly addresses the ransomware threat model where attackers target connected backups first.

Exam trap

The trap is assuming that any backup is sufficient for ransomware recovery; the exam expects you to recognize that isolation (offline/air-gapped) and encryption, not just frequency or location, are what make backups ransomware-resistant.

How to eliminate wrong answers

Option A is wrong because monthly incremental backups leave up to a month of data at risk and provide a poor recovery point objective, and frequency alone does not protect against ransomware. Option B is wrong because reusing production credentials means a compromised account can also destroy or encrypt the backups, defeating their purpose. Option C is wrong because storing backups on the same network as production allows lateral movement and ransomware to reach and encrypt the backups.

97
Matchingmedium

Match each security policy to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines allowed use of organizational assets

Categorizes data based on sensitivity

Procedures for handling security incidents

Rules for password creation and management

Why these pairings

Security policies provide organizational guidance. The Acceptable Use Policy details proper use of IT resources; the Information Security Policy sets the overall security vision; the Data Classification Policy categorizes data by sensitivity.

98
Multi-Selectmedium

A security analyst is reviewing access controls for a financial application. Which TWO of the following are considered best practices for preventing fraud? (Select TWO.)

Select 2 answers
A.Password complexity
B.Single sign-on
C.Least privilege
D.Two-person control
E.Separation of duties
AnswersD, E

Two-person control, also known as the "two-man rule" or dual control, is a procedural security mechanism requiring the simultaneous involvement and agreement of two authorized individuals to perform a critical or sensitive action. This control prevents a single person from initiating or completing a high-risk transaction or operation, significantly mitigating the risk of fraud, error, or malicious intent by ensuring mutual oversight and accountability. It directly addresses the need for multiple people to complete a sensitive action.

Why this answer

Two-person control (D) is a best practice for preventing fraud because it requires two authorized individuals to perform a critical action, such as approving a high-value transaction or accessing a sensitive system. This ensures collusion is needed to commit fraud, as no single person can complete the action alone. In a financial application, this might involve dual approval for wire transfers over a threshold, directly mitigating insider threats.

Exam trap

The trap here is that candidates often confuse 'least privilege' (a preventive control for limiting access) with 'separation of duties' (a detective/preventive control for fraud), or they incorrectly think 'password complexity' or 'single sign-on' directly prevent fraud when they only address authentication security.

99
MCQmedium

A company is deploying a containerized application using Kubernetes. Which practice BEST ensures the security of the container images?

A.Scan images for vulnerabilities and use minimal base images
B.Restrict containers from running as root
C.Use the latest version of the base image without scanning
D.Enable container escape protection
AnswerA

Scanning container images for vulnerabilities identifies known CVEs and misconfigurations within the software components before deployment. Concurrently, using minimal base images significantly reduces the attack surface by excluding unnecessary libraries, packages, and executables. This dual approach proactively minimizes the number of potential vulnerabilities and limits the scope for exploitation, directly enhancing the security posture of the containerized application.

Why this answer

Scanning container images for known vulnerabilities (e.g., using Trivy, Clair, or Snyk) and using minimal base images (e.g., Alpine or distroless) directly reduces the attack surface and eliminates unnecessary packages that may contain exploitable flaws. This practice is foundational to secure software supply chain management and aligns with the principle of least functionality in containerized environments.

Exam trap

The trap here is that candidates often confuse runtime security controls (like root restrictions or escape protection) with image-level security, mistakenly thinking they ensure the image itself is free of vulnerabilities, when in fact they only mitigate exploitation after deployment.

How to eliminate wrong answers

Option B is wrong because restricting containers from running as root is a runtime security control (e.g., using `securityContext.runAsNonRoot: true`), not a practice that ensures the security of the container images themselves; it addresses privilege escalation at runtime, not image composition. Option C is wrong because using the latest version of a base image without scanning introduces unknown vulnerabilities and violates the secure development lifecycle; latest tags can be stale or contain unpatched CVEs, and scanning is essential to verify integrity. Option D is wrong because container escape protection (e.g., using seccomp, AppArmor, or gVisor) is a runtime isolation mechanism that prevents a compromised container from breaking out to the host, but it does not address vulnerabilities embedded within the image layers.

100
MCQeasy

A business continuity coordinator is planning a test of the disaster recovery plan. Which type of test involves a walk-through of the plan with key stakeholders without actually invoking the technical recovery?

A.Tabletop exercise
B.Full interruption test
C.Checklist review
D.Parallel test
AnswerA

A tabletop exercise is a collaborative, discussion-based session where key stakeholders verbally walk through a simulated disaster scenario. Participants discuss their roles, responsibilities, decision-making processes, and interdependencies without activating any technical systems. This low-cost, low-risk method effectively identifies gaps in plans, validates communication protocols, and enhances team understanding of the business continuity strategy before more complex tests.

Why this answer

A tabletop exercise is a discussion-based session where key stakeholders walk through the disaster recovery plan step-by-step without invoking any technical recovery procedures. This validates roles, responsibilities, and decision-making processes in a low-risk environment, ensuring the plan's logic is sound before any actual failover or system restoration is attempted.

Exam trap

The trap here is that candidates often confuse a tabletop exercise with a checklist review, but a tabletop is an interactive discussion with stakeholders, not a passive document check.

How to eliminate wrong answers

Option B (Full interruption test) is wrong because it involves actually shutting down production systems and invoking technical recovery, which is the opposite of a non-technical walk-through. Option C (Checklist review) is wrong because it is a simple verification that documentation is complete and up-to-date, not a collaborative walk-through with stakeholders. Option D (Parallel test) is wrong because it involves running recovery systems in parallel with production to validate technical functionality, which requires actual technical invocation.

101
MCQhard

A company's compliance officer wants to ensure that the organization's security controls meet regulatory requirements for data protection. The officer requests a review of the controls against the regulation's specific clauses. Which type of assessment is most appropriate?

A.Risk assessment
B.Vulnerability assessment
C.Penetration test
D.Compliance audit
AnswerD

A compliance audit maps implemented controls directly against each regulatory clause, producing evidence of conformity or gaps. This clause-by-clause verification is precisely what the compliance officer requests, distinguishing it from a risk assessment or penetration test, which evaluate exposure rather than regulatory alignment.

Why this answer

A compliance audit is the correct assessment type because it systematically evaluates security controls against specific regulatory clauses (e.g., GDPR Article 32, HIPAA Security Rule §164.312). Unlike risk or vulnerability assessments, a compliance audit maps controls directly to legal requirements to verify adherence, often using checklists and evidence collection.

Exam trap

The trap here is confusing a compliance audit with a risk assessment, as both involve reviewing controls, but only the audit measures adherence to specific regulatory clauses rather than prioritizing risks.

How to eliminate wrong answers

Option A is wrong because a risk assessment identifies and prioritizes threats and vulnerabilities based on likelihood and impact, but does not map controls to specific regulatory clauses. Option B is wrong because a vulnerability assessment scans for technical weaknesses (e.g., missing patches, misconfigurations) without evaluating compliance with legal or regulatory text. Option C is wrong because a penetration test simulates attacks to exploit vulnerabilities, focusing on security posture rather than verifying control alignment with regulation clauses.

102
MCQeasy

During the requirements gathering phase of a software development project, which threat modeling methodology is most commonly used to identify threats such as spoofing, tampering, and elevation of privilege?

A.CVSS
B.STRIDE
C.OCTAVE
D.PASTA
AnswerB

STRIDE is a widely recognized threat modeling methodology developed by Microsoft, specifically designed to identify and categorize potential threats to a system during its design phase. Its acronym represents six distinct threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. These categories directly map to fundamental security properties like Authenticity, Integrity, Non-Repudiation, Confidentiality, Availability, and Authorization, making it highly effective for systematic threat identification in software.

Why this answer

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. During the requirements gathering phase, STRIDE is commonly used to systematically identify and classify potential security threats against each system component, making it the correct choice for identifying threats like spoofing, tampering, and elevation of privilege.

Exam trap

The trap here is that candidates often confuse CVSS (a scoring system) or OCTAVE (a risk assessment framework) with threat modeling methodologies, but the question specifically asks for the methodology most commonly used to identify threat types like spoofing and tampering, which is STRIDE.

How to eliminate wrong answers

Option A (CVSS) is wrong because CVSS (Common Vulnerability Scoring System) is a framework for scoring the severity of known vulnerabilities, not a threat modeling methodology used during requirements gathering to identify threats like spoofing or tampering. Option C (OCTAVE) is wrong because OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk assessment framework focused on organizational risk and strategic planning, not a lightweight threat modeling technique for identifying specific threat types during software development requirements. Option D (PASTA) is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling methodology that aligns business objectives with technical requirements, but it is not the most commonly used methodology for simply identifying threats like spoofing, tampering, and elevation of privilege during the requirements phase; STRIDE is more straightforward and widely adopted for that purpose.

103
Multi-Selectmedium

Which two methods provide strong encryption and authentication for wireless networks? (Choose TWO.)

Select 2 answers
A.WEP
B.WPA2-PSK
C.WPA2-Enterprise
D.MAC filtering
E.WPA3
AnswersC, E

WPA2-Enterprise provides robust encryption and authentication by integrating the 802.1X framework with an external authentication server, typically RADIUS. This architecture supports strong, centralized user or device authentication using methods like EAP-TLS with certificates, EAP-PEAP, or EAP-TTLS, dynamically generating unique encryption keys for each client session. This ensures strong, individualized security, accountability, and protection against unauthorized access.

Why this answer

WPA2-Enterprise (C) is correct because it uses IEEE 802.1X authentication with a RADIUS server, providing mutual authentication and per-session dynamic encryption keys via the 4-way handshake using AES-CCMP. WPA3 (E) is correct because it introduces Simultaneous Authentication of Equals (SAE) to replace the pre-shared key (PSK) handshake, offering forward secrecy and stronger encryption with GCMP-256, and also supports 802.1X for enterprise deployments.

Exam trap

The trap here is that candidates often confuse WPA2-PSK with WPA2-Enterprise, assuming both provide strong authentication, but the exam tests the distinction that PSK lacks per-user authentication and is vulnerable to dictionary attacks, while Enterprise uses RADIUS for robust identity verification.

104
MCQmedium

In SAML 2.0, which component is responsible for authenticating the user and generating an assertion?

A.Identity Provider (IdP)
B.Service Provider (SP)
C.Certificate Authority (CA)
D.Relying Party (RP)
AnswerA

The Identity Provider (IdP) is the authoritative entity responsible for authenticating the user's identity within a SAML 2.0 federation. It verifies user credentials against its own identity store (e.g., an LDAP directory or database) and, upon successful authentication, generates a digitally signed SAML assertion containing the user's authentication status and relevant attributes. This assertion is then securely transmitted to the Service Provider, confirming the user's identity without sharing their actual credentials.

Why this answer

In SAML 2.0, the Identity Provider (IdP) is the entity that authenticates the user and issues the SAML assertion containing authentication and attribute statements. The Service Provider (SP) consumes that assertion to grant access. The IdP is the authoritative source of identity, so it is the component that generates the assertion.

Exam trap

CISSP often tests SAML role terminology, so the trap is confusing the Service Provider/Relying Party (consumer) with the Identity Provider (issuer), or selecting Certificate Authority because it sounds like the component that 'validates' assertions.

How to eliminate wrong answers

Option B is wrong because the Service Provider is the relying application that requests authentication and consumes the assertion; it does not authenticate the user or generate the assertion. Option C is wrong because a Certificate Authority issues X.509 certificates used to sign and validate SAML assertions, but it plays no role in authenticating users or generating assertions. Option D is wrong because Relying Party is essentially a synonym for Service Provider in federation terminology (and the term used in OIDC), so it is the consumer, not the issuer, of the assertion.

105
MCQhard

A company wants to ensure its internal web application is free from security flaws during development. Which testing approach analyzes source code without executing the program?

A.IAST
B.RASP
C.DAST
D.SAST
AnswerD

SAST (Static Application Security Testing) directly examines the application's source code, bytecode, or binary code without executing it, identifying potential security vulnerabilities like SQL injection or cross-site scripting. This "white-box" approach is ideal for finding flaws early in the development lifecycle, before the application is even compiled or deployed, making it highly effective for proactive security.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, which is exactly what the question describes. It is integrated into the IDE or CI/CD pipeline to catch flaws like SQL injection, XSS, and hardcoded secrets early in the SDLC, shifting security left.

Exam trap

CISSP often tests the SAST vs DAST vs IAST vs RASP taxonomy — candidates pick DAST because it sounds like 'testing the app,' forgetting that SAST is the only one that analyzes source code without executing it.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) instruments a running application and analyzes behavior during execution, typically via an agent — it requires a running app and often a DAST-style scan or test suite. Option B is wrong because RASP (Runtime Application Self-Protection) is a runtime protection mechanism embedded in the app that detects and blocks attacks in production; it is not a source-code analysis technique. Option C is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside (black-box) by sending malicious inputs and observing responses — it does not read source code.

106
MCQmedium

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

A.Verification
B.Reporting
C.Remediation
D.Risk acceptance
AnswerC

Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.

Why this answer

The vulnerability management lifecycle is typically: identify → prioritize (assess/rank) → remediate → verify → report, with risk acceptance as an alternative outcome to remediation. After vulnerabilities are identified and prioritized, the next action is to remediate (patch, mitigate, or compensate), because prioritization exists to drive remediation decisions. Verification and reporting come after remediation to confirm the fix and communicate status.

Exam trap

CISSP often tests the ordering of the vulnerability management lifecycle, tempting candidates to pick 'verification' or 'reporting' because those feel like quality steps, when the lifecycle's next action after prioritization is remediation.

How to eliminate wrong answers

Option A is wrong because verification happens after remediation to confirm the fix was applied and effective — it is not the step immediately following prioritization. Option B is wrong because reporting is a communication activity that occurs throughout and especially after remediation, not the direct next step. Option D is wrong because risk acceptance is an exception path taken when remediation is not feasible or cost-justified; it is a decision made during remediation planning, not the default next step after prioritization.

107
MCQhard

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

A.$7,500
B.$30,000
C.$15,000
D.$75,000
AnswerA

This value correctly represents the Annualized Loss Expectancy (ALE), which is a key metric in quantitative risk analysis. It is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Assuming an SLE of $15,000 and an ARO of 0.5 (meaning the event is expected to occur once every two years), the ALE is $15,000 * 0.5 = $7,500. This figure quantifies the expected financial loss from a specific risk over a one-year period, informing cost-benefit analyses for security controls.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as SLE × ARO. With an SLE of $15,000 and an ARO of 0.5, the ALE is $15,000 × 0.5 = $7,500. This represents the expected yearly financial loss from a given risk, factoring in both the impact per incident and how often it is expected to occur.

Exam trap

CISSP often tests the confusion between SLE, ARO, and ALE, and candidates may mistakenly multiply by the reciprocal of ARO or forget to multiply at all, leading to selecting the SLE or an inflated value.

How to eliminate wrong answers

Option B is wrong because $30,000 results from multiplying SLE by 2 (the reciprocal of ARO), which would be appropriate if the ARO were 2.0, not 0.5. Option C is wrong because $15,000 is simply the SLE, ignoring the ARO entirely; it would only be the ALE if the ARO were 1.0. Option D is wrong because $75,000 is five times the SLE, which would require an ARO of 5.0, not 0.5.

108
Multi-Selecteasy

Which TWO of the following are secure coding practices to prevent buffer overflow vulnerabilities?

Select 2 answers
A.Code obfuscation.
B.Input validation.
C.Dynamic memory allocation without bounds.
D.Use of unsafe functions like strcpy.
E.Use of compilers with stack protection.
AnswersB, E

Input validation is a fundamental secure coding practice that involves rigorously checking user-supplied data against predefined criteria before processing it. For buffer overflows, this means verifying the length, type, and format of all inputs to ensure they do not exceed the allocated buffer size. By rejecting or truncating oversized inputs, input validation directly prevents data from spilling beyond its intended memory boundaries, thereby eliminating a common vector for buffer overflow attacks.

Why this answer

Input validation (B) is a core secure coding practice because it ensures that data entering a program is checked for type, length, format, and range before being processed, so oversized or malformed input cannot be written past the boundaries of a fixed-size buffer. Use of compilers with stack protection (E) is also correct because mechanisms such as stack canaries (e.g., -fstack-protector in GCC/Clang) detect and abort execution when a return address or saved frame pointer has been overwritten, mitigating classic stack-based buffer overflows. The other options do not belong: code obfuscation (A) only makes code harder to read and provides no memory-safety benefit, dynamic memory allocation without bounds (C) actually increases overflow risk by failing to limit how much data is written, and unsafe functions like strcpy (D) perform no length checking and are a well-known cause of buffer overflows.

Exam trap

Candidates often confuse compiler-level mitigations like stack protection with network-level controls, or mistakenly believe that dynamic memory allocation (C) inherently prevents overflows, when in fact unbounded dynamic allocation is a primary source of heap-based buffer overflows.

109
MCQmedium

A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?

A.Storage capacity
B.Incident response needs
C.Regulatory requirements
D.Log volume
AnswerC

Regulatory requirements are the primary driver for log retention policies because various compliance frameworks, such as HIPAA, PCI DSS, GDPR, and SOX, explicitly mandate specific types of logs and their minimum retention periods. These mandates ensure accountability, provide an audit trail, and support legal defensibility, with non-compliance leading to severe penalties, fines, and reputational damage. Organizations must align their log retention strategies directly with these external obligations.

Why this answer

Regulatory compliance frameworks (e.g., PCI DSS, HIPAA, SOX, GDPR) explicitly mandate minimum log retention periods (e.g., PCI DSS Requirement 10.7 requires at least one year of logs, with three months immediately accessible). Storage capacity, incident response needs, and log volume are operational considerations that may influence implementation but do not override the legal or contractual obligation to retain logs for a specified duration. The primary factor is the regulatory requirement itself, as failure to comply can result in fines, legal liability, or loss of certification.

Exam trap

The trap here is that candidates often confuse operational factors (storage capacity, log volume) with the primary driver (regulatory requirements), mistakenly thinking that if storage is limited, the retention period can be shortened—but compliance mandates are non-negotiable and must be met regardless of infrastructure constraints.

How to eliminate wrong answers

Option A is wrong because storage capacity is a resource constraint that may force log rotation or archiving, but it does not define the retention period; organizations must provision sufficient storage to meet regulatory mandates. Option B is wrong because incident response needs may require retaining logs beyond the standard period for forensic analysis, but they do not set the baseline retention period; the baseline is driven by compliance, not by the timing of incidents. Option D is wrong because log volume affects how logs are stored and rotated (e.g., log rotation policies based on size), but the retention duration is a time-based requirement set by regulations, not a function of how many logs are generated.

110
MCQeasy

A company wants to secure its wireless network. Which approach provides the strongest authentication and encryption?

A.WEP
B.Disabling SSID broadcast
C.WPA2-Enterprise with RADIUS
D.WPA2-PSK with a strong passphrase
AnswerC

WPA2-Enterprise with RADIUS authenticates each user individually via 802.1X against a central server, rather than relying on a shared pre-shared key. This satisfies the demand for the strongest authentication and encryption, since unique per-user credentials and dynamic keying prevent the key-sharing weaknesses of WPA2-Personal.

Why this answer

WPA2-Enterprise with RADIUS provides the strongest authentication and encryption for wireless networks because it uses 802.1X/EAP for per-user authentication against a central RADIUS server, and AES-CCMP for encryption. This eliminates the shared passphrase vulnerability of PSK modes and supports dynamic, unique encryption keys per session, making it resistant to offline dictionary attacks and key reuse.

Exam trap

The trap here is that candidates often choose WPA2-PSK with a strong passphrase (Option D) because they think a long, complex passphrase is sufficient, but they overlook that PSK still lacks per-user authentication and is vulnerable to offline brute-force attacks once the 4-way handshake is captured.

How to eliminate wrong answers

Option A is wrong because WEP uses the flawed RC4 stream cipher with a static 40- or 104-bit key and weak IVs, making it trivially crackable in minutes with tools like aircrack-ng. Option B is wrong because disabling SSID broadcast is a security-by-obscurity measure that does not provide authentication or encryption; the SSID is still leaked in probe requests and management frames, and an attacker can easily discover it. Option D is wrong because WPA2-PSK relies on a single pre-shared key (PMK) derived from the passphrase, which is vulnerable to offline dictionary attacks if the passphrase is weak, and all users share the same key, preventing individual accountability and revocation.

111
MCQhard

Refer to the exhibit. A network administrator configures a new WLAN. Clients can associate but cannot obtain an IP address via DHCP. What is the most likely cause?

A.The WLAN uses TKIP instead of AES, which is less secure but functional.
B.The WLAN uses WPA2 with PSK, but the passphrase is too short.
C.The broadcast forwarding (or DHCP relay) is not properly configured to forward DHCP requests to the DHCP server.
D.The WLAN interface and the virtual interface are on the same subnet, causing an IP conflict.
AnswerC

Without a DHCP relay or server, DHCP broadcasts are not forwarded across the bridge to a DHCP server. The controller needs a DHCP server or a relay configuration.

Why this answer

The scenario describes clients can associate but cannot obtain IP addresses via DHCP. This indicates DHCP broadcast requests from clients are not being forwarded to a DHCP server. The most likely cause is that broadcast forwarding or DHCP relay is not properly configured on the WLAN or intermediary network device.

Without broadcast forwarding or DHCP relay, DHCP discover messages from wireless clients are dropped or not delivered, preventing lease assignment. Other factors such as encryption type or passphrase length would affect association, not DHCP.

112
MCQmedium

A security analyst runs a vulnerability scan against a web application and receives a report listing several critical vulnerabilities. However, the development team argues that many of these findings are false positives. Which of the following is the BEST next step for the analyst?

A.Re-scan the application with the same settings to confirm the results.
B.Manually verify a sample of the findings to confirm true vs. false positives.
C.Escalate all critical findings to management immediately.
D.Retune the vulnerability scanner to reduce false positives and re-scan.
AnswerB

Manual verification of a representative sample establishes the scanner's true-positive rate without exhaustively retesting every finding. That evidence lets the analyst either defend the report or tune scanner rules, resolving the disagreement objectively before remediation effort is committed.

Why this answer

Manual verification is the definitive method to distinguish true positives from false positives in vulnerability scanning. Automated scanners can produce false positives due to factors like incomplete service fingerprinting or reliance on banner grabbing, which may not reflect actual exploitability. The analyst must validate a representative sample of findings against the actual application behavior and configuration before taking further action.

Exam trap

The trap here is that candidates often choose Option D (retune the scanner) because they assume tuning reduces false positives, but the CISSP emphasizes that validation through manual testing must precede any scanner configuration changes to avoid missing real vulnerabilities.

How to eliminate wrong answers

Option A is wrong because re-scanning with the same settings will produce identical results, as the scanner will repeat the same checks and generate the same false positives without addressing the root cause. Option C is wrong because escalating all critical findings without verification wastes management's time and resources on potentially non-existent threats, undermining the credibility of the security team. Option D is wrong because retuning the scanner without first understanding which findings are false positives may inadvertently suppress true vulnerabilities or fail to eliminate the specific false positives reported.

113
MCQeasy

Which of the following is a key component of the rules of engagement for a penetration test?

A.Exploitation techniques to use
B.Emergency stop criteria
C.CVSS score of vulnerabilities
D.Number of vulnerabilities found
AnswerB

Emergency stop criteria are a critical component of the Rules of Engagement (RoE) because they explicitly define the conditions under which an engagement must be immediately halted to prevent unintended harm, legal issues, or excessive risk. These criteria ensure that testing can be safely terminated if unexpected system instability, unauthorized access to sensitive data, or other critical incidents occur, thereby protecting the target environment and the testing team. Establishing these clear boundaries is fundamental to responsible and controlled security assessments.

Why this answer

Emergency stop criteria are a core element of the rules of engagement (RoE) for a penetration test because they define the conditions under which testing must immediately halt — for example, if production availability is threatened or a critical system is destabilized. RoE documents scope, timing, authorized techniques, communication channels, and stop conditions agreed upon by the client and tester.

Exam trap

CISSP often tests the confusion between RoE (pre-engagement boundaries and stop conditions) and post-engagement outputs (CVSS scores, vulnerability counts), so candidates who pick a metric or technique miss the definition of RoE.

How to eliminate wrong answers

Option A is wrong because specific exploitation techniques are typically described in the testing methodology or scope, not as a defining component of the RoE — and RoE focuses on boundaries and constraints rather than a menu of exploits. Option C is wrong because CVSS scores are assigned to discovered vulnerabilities during or after testing; they are an output, not an RoE input. Option D is wrong because the number of vulnerabilities found is a result metric, not a component of the rules of engagement.

114
Multi-Selectmedium

Which TWO of the following are OAuth 2.0 grant types? (Choose two.)

Select 2 answers
A.SAML assertion
B.Client credentials
C.LDAP bind
D.Kerberos ticket
E.Authorization code
AnswersB, E

The Client Credentials grant type is specifically designed for machine-to-machine authentication, where a confidential client (e.g., a service, daemon, or another API) needs to access protected resources on behalf of itself, rather than a specific end-user. In this flow, the client authenticates directly with the authorization server using its own client ID and client secret, receiving an access token that grants it access to resources it is authorized for. This grant is ideal for server-to-server interactions or automated processes where no user interaction is present or required.

Why this answer

Option B (Client credentials) is correct because the client credentials grant is one of the standard OAuth 2.0 grant types defined in RFC 6749, used for machine-to-machine authentication where the client requests an access token using its own credentials without a resource owner. Option E (Authorization code) is correct because the authorization code grant is the core OAuth 2.0 flow defined in RFC 6749, where the client exchanges an authorization code obtained via the authorization endpoint for an access token at the token endpoint. The other options do not belong: SAML assertion (A) is an XML-based authentication/authorization standard used in SAML bearer assertions, not an OAuth 2.0 grant type; LDAP bind (C) is an authentication operation in the LDAP protocol, not an OAuth grant; and Kerberos ticket (D) is a ticket-based authentication mechanism in the Kerberos protocol, unrelated to OAuth 2.0 grant types.

Exam trap

CISSP often tests whether candidates can distinguish OAuth 2.0 grant types from other authentication protocols like SAML, LDAP, and Kerberos, so they pick protocol names that sound like grants but are not part of OAuth 2.0.

115
Multi-Selecthard

Which THREE of the following are essential components of an effective incident response plan according to NIST SP 800-61?

Select 3 answers
A.Preparation
B.Notification
C.Detection and Analysis
D.Vulnerability scanning
E.Containment, Eradication, and Recovery
AnswersA, C, E

Preparation is the foundational phase of an incident response plan, establishing the necessary policies, procedures, and resources before an incident occurs. This includes developing communication plans, training personnel, acquiring essential tools, and conducting regular drills to ensure the organization is ready to respond effectively. Proper preparation significantly reduces the impact and duration of security incidents by building a robust framework for action.

Why this answer

NIST SP 800-61 defines the incident response lifecycle as having four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Preparation is the foundational phase that establishes the incident response capability, including creating policies, forming a team, and acquiring necessary tools before any incident occurs.

Exam trap

The trap here is that candidates often confuse Notification as a formal phase because it appears in many incident response frameworks (e.g., SANS PICERL), but NIST SP 800-61 does not list it as a core phase; instead, it is a task within other phases.

116
Multi-Selectmedium

Which TWO of the following are lawful bases for processing personal data under the GDPR? (Select two)

Select 2 answers
A.Data subject's employment status
B.Data subject's nationality
C.Consent of the data subject
D.Legitimate interests of the controller
E.Profit maximization
AnswersC, D

Consent is a fundamental lawful basis where the data subject explicitly and unambiguously agrees to the processing of their personal data for a specific purpose. For consent to be valid, it must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, often requiring a clear affirmative action. This places control directly with the individual.

Why this answer

Option C (Consent of the data subject) is correct because Article 6(1)(a) of the GDPR expressly lists the data subject's consent as a lawful basis for processing personal data, provided it is freely given, specific, informed, and unambiguous. Option D (Legitimate interests of the controller) is correct because Article 6(1)(f) recognizes the legitimate interests pursued by the controller or a third party as a lawful basis, subject to a balancing test against the data subject's rights and freedoms. Options A (employment status) and B (nationality) are not lawful bases; they are merely categories of personal data, and nationality can even constitute special category data under Article 9.

Option E (profit maximization) is not a lawful basis; it is a business objective that must still be grounded in one of the Article 6(1) legal grounds, such as legitimate interests, to be lawful.

Exam trap

The trap is assuming any business rationale (like profit) or personal attribute (like nationality) can be a lawful basis; GDPR requires one of six specific bases, and candidates often overlook that legitimate interests must be balanced and documented.

117
MCQmedium

An organization is implementing network segmentation to enhance security. They create a DMZ to host public-facing servers and want to ensure that if a server is compromised, the attacker cannot pivot to the internal network. Which firewall placement best achieves this?

A.Place the DMZ on the internal network side with a strong host-based firewall on each server
B.Place a single firewall between the internet and the DMZ, and allow traffic from DMZ to internal network
C.Use a stateful firewall that only allows return traffic from internal to DMZ
D.Implement a screened subnet with two firewalls: one between internet and DMZ, and one between DMZ and internal network
AnswerD

Implementing a screened subnet architecture with two firewalls is the industry-standard and most robust method for DMZ deployment. The first firewall isolates the DMZ from the internet, while the second firewall strictly controls traffic between the DMZ and the internal network. This design provides defense-in-depth, ensuring that even if a DMZ server is compromised, the attacker still faces a second, dedicated firewall before gaining access to sensitive internal resources, significantly limiting the blast radius of a breach.

Why this answer

A screened subnet architecture uses two firewalls to create a DMZ that is logically isolated from both the internet and the internal network. The first firewall (internet-facing) controls inbound traffic to the DMZ, while the second firewall (internal-facing) strictly controls outbound traffic from the DMZ to the internal network, typically allowing only specific return traffic. This prevents an attacker who compromises a DMZ server from directly initiating connections to internal hosts, as the internal firewall would block such traffic unless explicitly permitted.

Exam trap

The trap here is that candidates often assume a single firewall with a DMZ interface (three-legged firewall) provides sufficient isolation, but without a second firewall or strict egress filtering, the DMZ can still be used as a pivot point to the internal network.

How to eliminate wrong answers

Option A is wrong because placing the DMZ on the internal network side with only host-based firewalls does not provide network-level isolation; if a server is compromised, the attacker can still pivot to other internal hosts by bypassing or disabling the host firewall. Option B is wrong because a single firewall between the internet and the DMZ, while allowing traffic from the DMZ to the internal network, creates a flat trust model where a compromised DMZ server can directly initiate connections to internal hosts, violating the principle of least privilege. Option C is wrong because a stateful firewall that only allows return traffic from internal to DMZ does not prevent an attacker from using the DMZ server to initiate new outbound connections to the internal network; stateful inspection tracks connection state but does not enforce application-layer or direction-based restrictions on new sessions.

118
MCQmedium

A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?

A.RC4
B.RSA
C.AES
D.3DES
AnswerC

AES (Advanced Encryption Standard) is a symmetric block cipher, widely recognized and adopted as the global standard for secure data encryption. It operates by encrypting data in fixed-size blocks (128 bits) using key sizes of 128, 192, or 256 bits, offering robust security against all known practical attacks when properly implemented. Its excellent balance of strong cryptographic properties, high performance, and efficiency makes it the optimal choice for encrypting bulk data in contemporary systems.

Why this answer

AES (Advanced Encryption Standard) is a NIST-approved symmetric block cipher defined in FIPS 197, supporting key sizes of 128, 192, and 256 bits. It is the standard choice for encrypting data at rest and satisfies all stated requirements.

Exam trap

CISSP often tests the block-vs-stream and symmetric-vs-asymmetric distinction — candidates see 'strong security' and pick RSA or 3DES, missing that the question specifies a NIST-approved block cipher with 128/192/256-bit keys, which uniquely identifies AES.

How to eliminate wrong answers

Option A is wrong because RC4 is a stream cipher, not a block cipher, and it is deprecated due to serious biases in its keystream (RFC 7465 prohibits it in TLS). Option B is wrong because RSA is an asymmetric algorithm used for key exchange and digital signatures, not for bulk data-at-rest encryption, and its key sizes (e.g., 2048, 3072) do not match the 128/192/256-bit requirement. Option D is wrong because 3DES is a block cipher but uses 112 or 168 effective bits, is deprecated by NIST (disallowed after 2023), and does not offer the 128/192/256-bit key sizes required.

119
MCQeasy

A financial institution is conducting a vulnerability assessment of its internal network. The assessor runs a comprehensive scan and discovers that several Windows servers have missing security patches. The organization has a patch management policy that requires all critical patches to be applied within 30 days. The scan results show that some patches have been pending for 45 days. The assessor also finds that the servers are isolated in a separate VLAN with strict firewall rules limiting inbound traffic to only necessary ports. The business owner argues that because the servers are isolated, the risk is low and the patches can be delayed. As the security assessor, what should be the BEST course of action?

A.Recommend additional compensating controls such as intrusion prevention.
B.Accept the risk and close the finding.
C.Escalate the finding to the risk management team for formal risk acceptance.
D.Immediately apply the patches without further approval.
AnswerC

Escalating the finding to the risk management team for formal risk acceptance is the correct procedure when a significant vulnerability is identified and immediate remediation is not feasible or desired. This process ensures that the decision to operate with a known risk is thoroughly documented, reviewed by appropriate organizational stakeholders, and approved by management with the authority to accept that level of risk. Formal acceptance establishes clear accountability and ensures the organization's risk posture is transparently understood and managed.

Why this answer

The organization's patch management policy has been violated (patches overdue by 45 days vs. 30-day requirement), and the business owner's informal risk acceptance is insufficient. Formal risk acceptance requires documented approval from the risk management team, ensuring accountability and alignment with the organization's risk appetite. The VLAN isolation and firewall rules are compensating controls, but they do not negate the need for proper risk treatment per policy.

Exam trap

The trap here is that candidates confuse compensating controls (Option A) with a complete solution, forgetting that policy violations require formal risk acceptance rather than just technical workarounds.

How to eliminate wrong answers

Option A is wrong because recommending additional compensating controls (e.g., intrusion prevention) does not address the existing policy violation; it only adds defense-in-depth without resolving the overdue patches or obtaining formal acceptance. Option B is wrong because accepting the risk without formal documentation bypasses the risk management process and violates the patch management policy, which requires explicit risk acceptance from authorized stakeholders. Option D is wrong because immediately applying patches without further approval could disrupt operations, violate change management procedures, and ignore the business owner's input; patches should be applied through a controlled change process.

120
MCQeasy

A security architect is designing a physical security perimeter for a data center. Which of the following is an example of Crime Prevention Through Environmental Design (CPTED) principle?

A.Using high fences with barbed wire around the facility
B.Designing the landscape to provide clear sightlines from the guard post
C.Deploying motion sensors and CCTV cameras
D.Installing biometric locks on all server room doors
AnswerB

Designing the landscape to provide clear sightlines from a guard post directly implements the CPTED principle of natural surveillance. By eliminating potential hiding spots and ensuring unobstructed views, this design choice increases the perceived risk for potential offenders, as they believe their actions are more likely to be observed. This proactive environmental design deters criminal activity by making illicit behavior more difficult to conceal, thereby enhancing overall security through visibility.

Why this answer

CPTED focuses on designing the physical environment to reduce crime and fear of crime by influencing human behavior. Clear sightlines from a guard post are a classic CPTED principle—natural surveillance—which allows guards to observe the area without obstruction, deterring potential intruders. This is a design-based approach, not just adding security hardware.

Exam trap

CISSP often tests the distinction between CPTED principles (design-based, passive) and physical security controls (active, hardware-based), so candidates must recognize that clear sightlines are a design feature, not a device.

How to eliminate wrong answers

Option A is wrong because high fences with barbed wire are a physical security control (target hardening), not a CPTED principle; CPTED emphasizes natural surveillance, territorial reinforcement, and access control through design. Option C is wrong because motion sensors and CCTV are electronic surveillance systems, which are active security technologies, not environmental design principles. Option D is wrong because biometric locks are access control mechanisms (target hardening), not CPTED; CPTED would instead use natural access control like landscaping or pathways to guide people.

121
Multi-Selectmedium

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

Select 3 answers
A.Critical business processes
B.Maximum tolerable downtime (MTD)
C.Preferred vendor contracts
D.Recovery point objective (RPO)
E.Employee performance metrics
AnswersA, B, D

The primary objective of a Business Impact Analysis (BIA) is to identify and prioritize the organization's critical business processes. By distinguishing core operations from non-essential ones, the BIA allows planners to allocate recovery resources effectively and establish realistic recovery timelines. Without this inventory, the BCP cannot target the most vital survival functions of the enterprise.

Why this answer

A BIA identifies critical business processes (A) because it must determine which functions are essential to the organization's survival and prioritize them for recovery. It also establishes the maximum tolerable downtime (B), the longest time a process can be unavailable before causing unacceptable harm, which drives recovery strategies. The recovery point objective (D) is likewise derived during the BIA, defining the maximum acceptable data loss measured in time and setting backup frequency requirements.

Preferred vendor contracts (C) are procurement/legal artifacts addressed during recovery planning or supply-chain review, not core BIA outputs. Employee performance metrics (E) belong to HR performance management and are unrelated to continuity impact analysis.

Exam trap

CISSP often tests the confusion between BIA outputs and other planning artifacts, such as vendor contracts or HR metrics, which are not part of the BIA scope.

122
Multi-Selectmedium

Which TWO of the following are examples of detective controls?

Select 2 answers
A.Access control list
B.CCTV surveillance
C.Firewall
D.Security awareness training
E.Intrusion detection system (IDS)
AnswersB, E

Closed-circuit television (CCTV) surveillance systems are designed to continuously monitor and record activities within a specified physical area. While their visible presence can act as a deterrent, their primary security function is detective, as they capture visual evidence of events such as unauthorized entry, theft, or vandalism as they unfold or after they have occurred. This recorded footage is invaluable for post-incident analysis, identification of perpetrators, and understanding the timeline of a security breach.

Why this answer

B (CCTV surveillance) is a detective control because it records and monitors activity after or during an event to identify and investigate security incidents, rather than stopping them. E (Intrusion detection system (IDS)) is also detective because it monitors network or host traffic and generates alerts on suspicious or malicious activity, detecting intrusions that have occurred or are occurring. A (Access control list) is a preventive control, as it enforces which subjects may access resources and blocks unauthorized access.

C (Firewall) is preventive, filtering and blocking traffic according to rules before it reaches protected systems. D (Security awareness training) is a preventive/administrative control that reduces the likelihood of user errors and policy violations.

Exam trap

The trap here is confusing preventive controls (like ACLs and firewalls) with detective controls, as candidates often misclassify any technology that 'monitors' as detective, but ACLs and firewalls are inherently preventive because they block or allow access in real-time, not after the fact.

123
MCQhard

An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?

A.Cloud DR with continuous replication
B.Hot site with real-time replication
C.Cold site with daily backups
D.Warm site with hourly backups
AnswerA

This option is correct because continuous replication ensures near-zero data loss, effectively meeting the stringent 30-minute Recovery Point Objective (RPO). Leveraging cloud-based Disaster Recovery (DR) allows for rapid provisioning of resources and pre-configured environments, which can be activated to meet the 4-hour Recovery Time Objective (RTO). Furthermore, cloud DR typically offers a more cost-effective solution compared to maintaining a dedicated physical hot site, making it an optimal choice that satisfies all technical and financial requirements.

Why this answer

Cloud DR with continuous replication meets the RPO of 30 minutes because data is replicated in near real-time, resulting in minimal data loss. It can also meet the RTO of 4 hours if automated failover and resource provisioning are configured. This approach is more cost-effective than a hot site because it avoids maintaining idle infrastructure and only incurs costs during actual disaster recovery operations.

Hot site with real-time replication (option B) also meets the requirements but is more expensive. Cold site with daily backups (option C) fails both RTO and RPO. Warm site with hourly backups (option D) fails RPO because it can result in up to 1 hour of data loss, exceeding the 30-minute limit.

124
MCQhard

A company's disaster recovery plan includes an agreement with another company to provide backup computing facilities in case of a disaster. The agreement allows the second company to use the facilities for its own operations if needed. This arrangement is best described as:

A.Hot site
B.Warm site
C.Cold site
D.Reciprocal agreement
AnswerD

A reciprocal agreement is a mutual arrangement between two organizations, often competitors or peers, to provide each other with backup facilities, equipment, or resources in the event of a disaster. This type of agreement directly addresses the concept of 'an agreement with' another entity to ensure business continuity, leveraging shared risk and resources rather than dedicated, pre-built recovery sites.

Why this answer

A reciprocal agreement is a mutual arrangement where two organizations agree to provide backup computing facilities to each other in the event of a disaster. Because the second company can also use the facilities for its own operations, the arrangement is explicitly reciprocal rather than a one-way commercial contract. Hot, warm, and cold sites are unilateral facility types owned or leased by the primary organization, not mutual sharing agreements.

Exam trap

The trap is the phrase 'the second company can use the facilities for its own operations' — candidates may focus on the facility type (hot/warm/cold) and miss that mutuality is the defining characteristic of a reciprocal agreement.

How to eliminate wrong answers

Option A (Hot site) is wrong because a hot site is a fully equipped, immediately available alternate facility — typically owned or leased by the primary organization, not shared reciprocally with another company. Option B (Warm site) is wrong because a warm site is a partially equipped facility with some hardware and connectivity, again unilateral rather than a mutual agreement. Option C (Cold site) is wrong because a cold site provides only basic infrastructure (power, cooling, space) with no pre-installed systems, and it is not defined by a reciprocal sharing arrangement.

125
Multi-Selecteasy

A security architect is considering secure design principles. Which two principles are essential for a defense-in-depth strategy? (Select TWO.)

Select 2 answers
A.Single point of failure
B.Layered security
C.Open design
D.Fail safe
E.Least privilege
AnswersB, E

Layered security, also known as defense-in-depth, is a fundamental secure design principle that involves deploying multiple, independent security controls throughout a system. This approach ensures that if one security control fails or is bypassed, other controls are still in place to detect and prevent unauthorized access or actions. It significantly increases the attacker's effort and time required to compromise a system, making it a cornerstone of robust cybersecurity architectures.

Why this answer

Layered security (defense in depth) is essential because it implements multiple, overlapping security controls so that if one layer fails, another layer continues to provide protection. This principle ensures that no single vulnerability can compromise the entire system, which is the core of a defense-in-depth strategy. Least privilege is equally essential because it restricts users and processes to only the minimum permissions necessary, limiting the blast radius of any breach and preventing lateral movement across layers.

Exam trap

The trap here is that candidates often confuse 'fail safe' or 'open design' as core to defense in depth, but the exam specifically tests that defense in depth is defined by layered security and least privilege, not by fail-safe mechanisms or design transparency.

126
MCQeasy

Which of the following is the primary purpose of a hardware security module (HSM)?

A.Filtering malicious traffic
B.Generating and storing cryptographic keys securely
C.Encrypting hard drives at rest
D.Accelerating network traffic
AnswerB

The primary purpose of a Hardware Security Module (HSM) is to provide a highly secure, tamper-resistant environment for the entire lifecycle of cryptographic keys, including generation, storage, and usage. HSMs are engineered with robust physical and logical security mechanisms to protect keys from unauthorized access, extraction, and manipulation, often meeting stringent security standards like FIPS 140-2. This secure key management is critical for maintaining the integrity and confidentiality of cryptographic operations across various applications and systems.

Why this answer

A hardware security module (HSM) is a dedicated, tamper-resistant hardware appliance designed to securely generate, store, and manage cryptographic keys throughout their lifecycle. Its primary purpose is to protect the root of trust for encryption operations, ensuring that private keys never leave the secure boundary of the module. This is critical for high-assurance environments such as certificate authorities (CAs) and payment processing systems.

Exam trap

The trap here is that candidates confuse an HSM with a general-purpose encryption tool or a network security appliance, mistakenly thinking it performs bulk encryption or traffic filtering, when its core role is secure key generation and storage.

How to eliminate wrong answers

Option A is wrong because filtering malicious traffic is the function of a firewall or intrusion prevention system (IPS), not an HSM. Option C is wrong because encrypting hard drives at rest is typically performed by full-disk encryption (FDE) software or self-encrypting drives (SEDs), not by an HSM; an HSM may store the encryption keys but does not perform the bulk encryption of the drive. Option D is wrong because accelerating network traffic is the role of a load balancer or a dedicated network accelerator; an HSM focuses on cryptographic operations and key management, not on improving network throughput.

127
Multi-Selecteasy

Which THREE are core principles of secure system design?

Select 3 answers
A.Complexity increases security
B.Security through obscurity
C.Least privilege
D.Fail securely
E.Defense in depth
AnswersC, D, E

The principle of least privilege dictates that every subject (e.g., user, process, or program) should be granted only the minimum set of permissions and access rights necessary to perform its legitimate function and no more. This minimizes the potential damage an attacker can inflict if a system component or account is compromised, restricting lateral movement and limiting data exfiltration. It is a fundamental control for reducing the blast radius of security incidents.

Why this answer

Least privilege (C) is a core secure design principle because each user, process, or service should be granted only the minimum access rights and permissions required to perform its function, limiting the blast radius of a compromise. Fail securely (D) is correct because systems should default to a safe, denying state when errors, exceptions, or failures occur, so that a failure does not inadvertently expose data or bypass controls. Defense in depth (E) is correct because relying on multiple, layered, and independent security controls ensures that if one control fails, others still protect the asset.

Complexity (A) is not a security principle; unnecessary complexity actually increases the attack surface and the likelihood of misconfiguration and vulnerabilities. Security through obscurity (B) is not a core principle because hiding design details or secrets does not provide real protection once the obscurity is bypassed or discovered, and it should never replace proper security controls.

Exam trap

ISC2 often tests the distinction between 'security through obscurity' as a valid supplementary measure versus a core principle, and candidates mistakenly select it because they confuse obfuscation with a foundational design tenet.

128
MCQmedium

An organization uses a configuration management database (CMDB). Which of the following is the PRIMARY purpose of a CMDB?

A.Manage user passwords
B.Monitor network performance
C.Record asset relationships and configurations
D.Track software licenses
AnswerC

The primary purpose of a Configuration Management Database (CMDB) is to serve as a centralized repository for information about all Configuration Items (CIs) within an IT environment. This includes not only detailed attributes of each asset, such as hardware specifications, software versions, and network addresses, but critically, also the intricate relationships and dependencies between these CIs. By mapping these connections, a CMDB enables organizations to understand the impact of changes and facilitate effective incident and problem management.

Why this answer

A CMDB's core function is to serve as a repository that records configuration items (CIs) and, critically, the relationships between them — such as which server hosts which application, which application depends on which database, and how changes propagate. This relationship mapping is what enables impact analysis, change management, and incident root-cause analysis. Simply storing asset attributes without relationships would be an asset inventory, not a CMDB.

Exam trap

CISSP often tests the distinction between a CMDB (which emphasizes CI relationships and configuration state) and a simple asset inventory or license tracker, so candidates who focus only on 'recording assets' rather than 'recording relationships' may pick the license-tracking distractor.

How to eliminate wrong answers

Option A is wrong because managing user passwords is the function of an identity and access management (IAM) system or directory service (e.g., Active Directory, LDAP), not a CMDB. Option B is wrong because network performance monitoring is performed by tools such as SNMP-based NMS platforms, NetFlow analyzers, or APM solutions — a CMDB records configuration state, not real-time telemetry. Option D is wrong because tracking software licenses is a software asset management (SAM) function; while license data may be stored as attributes of CIs in a CMDB, license tracking is not the PRIMARY purpose of the CMDB itself.

129
MCQmedium

A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:

A.Security baseline
B.Key Goal Indicator (KGI)
C.Key Performance Indicator (KPI)
D.Key Risk Indicator (KRI)
AnswerC

A Key Performance Indicator (KPI) is a quantifiable metric used to evaluate the success of a particular activity, process, or project against predefined objectives. Mean time to remediate (MTTR) is an excellent example of a KPI because it directly measures the efficiency and effectiveness of the incident response and vulnerability management processes. Tracking MTTR allows security managers to assess operational performance, identify bottlenecks, and drive continuous improvement in their remediation efforts.

Why this answer

Mean time to remediate (MTTR) for critical vulnerabilities measures how efficiently the security team is performing remediation, making it a Key Performance Indicator (KPI). KPIs track the performance of processes and activities against operational targets.

Exam trap

CISSP often tests the distinction between KPI (process performance), KGI (goal achievement), and KRI (risk exposure) — candidates frequently confuse KPI with KRI because both involve metrics.

How to eliminate wrong answers

Option A is wrong because a security baseline is a documented minimum set of controls or configurations, not a performance measurement. Option B is wrong because a Key Goal Indicator (KGI) measures whether high-level business goals have been achieved (e.g., 'reduce breach risk by 30%'), not the speed of an operational process. Option D is wrong because a Key Risk Indicator (KRI) is a forward-looking metric that signals increasing risk exposure (e.g., number of unpatched critical systems), whereas MTTR measures past remediation performance.

130
MCQeasy

Which of the following is the correct order of the ISC2 Code of Ethics canons from highest to lowest priority?

A.Protect society, act honorably, provide diligent service, advance the profession
B.Act honorably, protect society, provide diligent service, advance the profession
C.Advance the profession, protect society, act honorably, provide diligent service
D.Provide diligent service, advance the profession, protect society, act honorably
AnswerA

This sequence precisely matches the four canons of the (ISC)² Code of Ethics, which are hierarchically ordered to guide cybersecurity professionals. The primary responsibility is to protect society, followed by acting honorably, providing diligent service to principals, and finally advancing the profession. This specific order reflects the increasing scope of responsibility, from global impact to individual professional growth, making it the correct representation of the ethical framework.

Why this answer

The ISC2 Code of Ethics canons are ordered by priority: (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure; (2) Act honorably, honestly, justly, responsibly, and legally; (3) Provide diligent and competent service to principals; (4) Advance and protect the profession. Option A lists them in this exact order, making it correct. This hierarchy is critical because when canons conflict, the higher one must take precedence.

Exam trap

CISSP often tests the exact ordering of the Code of Ethics canons, and candidates frequently misremember 'Act honorably' as the top priority because it sounds noble; the trap is forgetting that 'Protect society' is explicitly first.

How to eliminate wrong answers

Option B is wrong because it places 'Act honorably' above 'Protect society,' reversing the top two canons; society and public trust always outrank personal honor. Option C is wrong because it puts 'Advance the profession' first, which is actually the lowest priority canon, and demotes 'Protect society' to second. Option D is wrong because it places 'Provide diligent service' first, but service to principals ranks third, below both society and honorable conduct.

131
Drag & Dropmedium

Drag and drop the steps for implementing mandatory access control (MAC) in a secure system in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

MAC implementation: define labels, assign clearances, assign classifications, configure monitor, test.

132
MCQmedium

A security engineer is recommending a VPN protocol for remote access. The requirements are: strong encryption, perfect forward secrecy, use of elliptic curve cryptography, and minimal overhead. Which VPN protocol best meets these requirements?

A.L2TP/IPsec
B.IPsec with ESP in tunnel mode
C.WireGuard
D.SSL/TLS VPN
AnswerC

WireGuard is the superior choice due to its modern cryptographic design, which inherently incorporates elliptic curve cryptography (ECC) for efficient key exchange and strong Perfect Forward Secrecy (PFS) through its Noise protocol framework. Its extremely lightweight codebase, consisting of only a few thousand lines, significantly reduces the attack surface and contributes to its high performance and minimal overhead, making it ideal for various platforms and resource-constrained environments.

Why this answer

WireGuard is the correct choice because it uses modern elliptic curve cryptography (Curve25519) for key exchange, provides perfect forward secrecy by default through ephemeral session keys, and has minimal overhead due to its streamlined codebase (roughly 4,000 lines of code) and lack of stateful configuration. It operates over UDP with a simple cryptographic design that meets all specified requirements without the complexity of IPsec or SSL/TLS.

Exam trap

Candidates often default to IPsec (options A or B) as the 'standard' VPN protocol, overlooking that WireGuard is a modern, lightweight alternative that natively integrates elliptic curve cryptography and PFS with minimal overhead, which IPsec does not guarantee without additional configuration.

How to eliminate wrong answers

Option A is wrong because L2TP/IPsec relies on IPsec for encryption, which typically uses Diffie-Hellman with finite field groups (e.g., MODP) rather than elliptic curve cryptography by default, and introduces significant overhead from the dual encapsulation (L2TP over IPsec). Option B is wrong because IPsec with ESP in tunnel mode, while supporting strong encryption and PFS, does not natively mandate elliptic curve cryptography and has higher overhead due to complex IKEv2 handshakes and multiple protocol layers. Option D is wrong because SSL/TLS VPNs (e.g., OpenVPN) can use elliptic curve cryptography and PFS, but they typically have higher overhead from the TLS handshake and certificate management, and are not as lightweight as WireGuard.

133
MCQhard

Which access control model bases decisions on attributes of the user, resource, and environment, and can use Boolean logic to define policies?

A.Role-Based Access Control (RBAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Mandatory Access Control (MAC)
AnswerC

Attribute-Based Access Control (ABAC) makes access decisions by evaluating a comprehensive set of attributes associated with the subject (e.g., user's department, clearance level), the object (e.g., resource sensitivity, file type), the action being requested (e.g., read, write), and the environmental context (e.g., time of day, network location). This highly dynamic and granular model uses policies that define rules based on these combined attributes, enabling context-aware authorization beyond static roles or identities.

Why this answer

ABAC (Attribute-Based Access Control) evaluates attributes of the subject (user), object (resource), and environment (context such as time, location, or threat level) to make access decisions. It supports Boolean logic (AND, OR, NOT) to combine these attributes into fine-grained policies, enabling dynamic and context-aware authorization. This contrasts with RBAC, which relies on roles, and MAC/DAC, which use labels or ownership, respectively.

Exam trap

CISSP often tests the confusion between RBAC and ABAC, where candidates mistakenly select RBAC because they overlook the requirement for environmental attributes and Boolean logic, which are defining features of ABAC.

How to eliminate wrong answers

Option A is wrong because RBAC bases decisions on roles assigned to users, not on a combination of user, resource, and environmental attributes, and it does not inherently use Boolean logic for policy definition. Option B is wrong because DAC bases decisions on the discretion of the resource owner (e.g., via ACLs), not on attributes of user, resource, and environment. Option D is wrong because MAC bases decisions on security labels (e.g., clearance and classification) and is non-discretionary, lacking the dynamic attribute-based and Boolean logic capabilities of ABAC.

134
Multi-Selectmedium

A security engineer is evaluating a web application for common vulnerabilities. The application uses a Content Management System (CMS) that is outdated and has known vulnerabilities. Additionally, the application displays detailed error messages and uses default administrative credentials. Which TWO of the following OWASP Top 10 categories are most relevant to these issues?

Select 2 answers
A.Vulnerable and Outdated Components
B.Security Misconfiguration
C.Injection
D.Cryptographic Failures
E.Broken Access Control
AnswersA, B

Vulnerable and Outdated Components refers to the risk posed by using software components, such as libraries, frameworks, and other modules, that have known security flaws or are no longer supported. Exploiting these vulnerabilities, often documented as Common Vulnerabilities and Exposures (CVEs), can grant attackers unauthorized access, data breaches, or system control. Regularly updating and patching all third-party components is crucial to mitigate this significant attack vector.

Why this answer

A is correct because the outdated CMS with known vulnerabilities directly corresponds to OWASP A06:2021 – Vulnerable and Outdated Components. This category covers using software versions with unpatched security flaws, which attackers can exploit via public exploit databases or automated scanners. B is correct because displaying detailed error messages and using default administrative credentials are classic examples of Security Misconfiguration (OWASP A05:2021).

This occurs when security settings are not properly defined, implemented, or maintained, allowing attackers to gain information or unauthorized access.

Exam trap

Candidates may incorrectly associate default credentials with Broken Access Control, but these are a security misconfiguration. The outdated CMS is clearly Vulnerable and Outdated Components.

135
MCQeasy

Which access control model allows the data owner to determine who can access their resources, typically using Access Control Lists (ACLs)?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Attribute-Based Access Control (ABAC)
AnswerA

DAC lets the resource owner set permissions themselves, typically through ACLs listing permitted subjects and rights. Authority is discretionary and delegated to the owner, unlike mandatory or role-based models where central policy dictates access regardless of ownership.

Why this answer

Discretionary Access Control (DAC) is defined by the property that the owner of a resource decides who can access it and with what permissions, typically by configuring Access Control Lists (ACLs) on the object. This owner-controlled discretion is the defining characteristic that separates DAC from MAC, RBAC, and ABAC. In DAC systems like Windows NTFS or Unix file permissions, the resource owner can grant or revoke access at will.

Exam trap

CISSP often tests the confusion between DAC and RBAC — candidates see 'owner determines access' and think of role owners, but the key discriminator is that DAC grants discretion to the resource owner, not to a role administrator.

How to eliminate wrong answers

Option B is wrong because RBAC assigns permissions based on organizational roles rather than individual owner discretion — access is determined by the user's role, not by the resource owner's choice. Option C is wrong because MAC uses system-enforced labels (e.g., Bell-LaPadula, Biba) where the operating system, not the data owner, controls access based on security clearances and object classifications. Option D is wrong because ABAC evaluates a combination of attributes (user, resource, environment, action) via policies, which is more granular and policy-driven than owner-discretionary ACLs.

136
Multi-Selecthard

Under GDPR, which TWO of the following are valid lawful bases for processing personal data?

Select 2 answers
A.Data subject's employment
B.Data processor's request
C.Consent
D.Legitimate interest
E.Data controller's profit
AnswersC, D

Consent is a valid lawful basis under GDPR Article 6(1)(a) when the data subject has given their explicit agreement to the processing of their personal data for one or more specific purposes. For consent to be valid, it must be freely given, specific, informed, and unambiguous, signified by a clear affirmative action. Furthermore, the data subject must be able to withdraw their consent as easily as they gave it, and the controller must be able to demonstrate that consent was obtained.

Why this answer

Under GDPR Article 6(1), the six lawful bases for processing personal data include consent (option C), where the data subject has given clear, specific, informed, and unambiguous agreement, and legitimate interest (option D), where processing is necessary for the legitimate interests pursued by the controller or a third party unless overridden by the data subject's rights and interests. These are both explicitly enumerated lawful bases, making C and D correct. Option A (data subject's employment) is not a lawful basis under Article 6; employment status is not one of the six grounds, though employment context may affect consent validity or other bases.

Option B (data processor's request) is invalid because a processor acts only on the controller's documented instructions and cannot itself create a lawful basis for processing. Option E (data controller's profit) is not a recognized lawful basis; profit alone does not satisfy any Article 6 condition, though it might be considered under legitimate interest only if the balancing test is met.

Exam trap

The trap is selecting plausible-sounding but non-existent bases like 'employment' or 'profit' — candidates must recall the exact six Article 6 bases rather than reasoning from business context.

137
MCQeasy

A development team is implementing a new feature that processes sensitive user data. Which of the following is the most secure approach to prevent data leakage during processing?

A.Use a separate virtual machine for each request.
B.Use memory encryption for all user data.
C.Store all data in a temporary file and delete it after processing.
D.Log all data access for auditing.
AnswerB

Implementing memory encryption ensures that sensitive user data remains unintelligible even if an attacker gains unauthorized access to the system's RAM, for instance, through memory scraping malware, cold boot attacks, or direct memory access (DMA) exploits. This proactive measure protects data in its most vulnerable state—during active processing—by encrypting memory pages or regions, thereby preventing the compromise of sensitive information residing in volatile memory.

Why this answer

Memory encryption protects sensitive user data while it resides in RAM, preventing unauthorized access through memory dumps, cold boot attacks, or other memory-scraping techniques. This is the most secure approach because it safeguards data during the entire processing lifecycle, unlike other options that leave data exposed in memory or rely on post-processing cleanup.

Exam trap

The trap here is that candidates often choose logging (Option D) because auditing is a common security control, but they overlook that logging does not prevent data leakage during active processing, which is the core requirement of the question.

How to eliminate wrong answers

Option A is wrong because using a separate virtual machine for each request introduces significant overhead and complexity, and does not inherently prevent data leakage from memory within the VM (e.g., via side-channel attacks or VM escape). Option C is wrong because storing data in a temporary file and deleting it after processing leaves the data vulnerable to recovery from disk (e.g., via file system journaling or forensic tools) and does not protect data while it is in memory. Option D is wrong because logging all data access for auditing only provides detective controls, not preventive controls, and the logs themselves could become a source of data leakage if not properly secured.

138
MCQhard

A large e-commerce company operates a multi-tier application in a public cloud. The environment includes a web tier, application tier, and database tier. The security team recently deployed a host-based intrusion detection system (HIDS) on all servers. During a routine review, the HIDS alerts show repeated failed login attempts from a single external IP address to several web servers, but no successful logins from that IP. The team also notices that the database servers have been sending outbound traffic to an unknown IP address on port 443, which is unusual because the database servers typically communicate only with the application servers on port 3306 (MySQL). The application team confirms no changes were made recently. The CISO wants an immediate investigation. What should the security team do first?

A.Immediately restart all database servers to stop any malicious processes.
B.Isolate the database servers from the network and perform forensic analysis on system logs and memory dumps.
C.Add a firewall rule to deny outbound traffic from the database tier to the unknown IP.
D.Block the external IP that is attempting to log in to the web servers and continue monitoring.
AnswerB

Outbound port 443 traffic from database servers that should only speak MySQL on 3306 signals likely exfiltration or compromise. Isolating preserves volatile evidence such as memory-resident malware while containing the threat, satisfying the CISO's demand for immediate investigation before the attacker exfiltrates further data.

Why this answer

The outbound port 443 traffic from database servers to an unknown IP is a strong indicator of active compromise (e.g., C2 beaconing or data exfiltration), so the first priority is containment via network isolation to stop further damage while preserving volatile evidence. Forensic analysis of logs and memory dumps must follow immediately to determine scope, persistence, and lateral movement before any remediation.

Exam trap

CISSP often tests the containment-before-eradication principle — the trap is choosing 'restart' or 'block the IP' because they feel decisive, when the correct first action is to isolate and preserve evidence.

How to eliminate wrong answers

Option A is wrong because restarting database servers destroys volatile evidence (memory-resident malware, active connections) and may trigger destructive payloads or alert the attacker, without confirming or containing the compromise. Option C is wrong because a firewall rule only blocks one destination and leaves the compromised host active — the attacker can pivot to another C2 endpoint, and evidence is lost. Option D is wrong because blocking the external IP targeting the web servers addresses a failed-login nuisance, not the confirmed database compromise, and ignores the actual incident.

139
MCQhard

In a software-defined network (SDN) architecture, the control plane is separated from the data plane. A network administrator is troubleshooting packet forwarding delays. Which plane is directly responsible for forwarding packets?

A.Data plane
B.Application plane
C.Control plane
D.Management plane
AnswerA

In an SDN architecture, the data plane, also known as the forwarding plane, is directly responsible for the physical movement of network traffic. It comprises the network devices (e.g., switches, routers) that execute the forwarding rules, or "flow tables," pushed down by the control plane. Its primary function is high-speed packet forwarding, encapsulation, and decapsulation, strictly adhering to the instructions received to direct packets to their next hop.

Why this answer

In SDN, the data plane (also called the forwarding plane) is directly responsible for forwarding packets based on flow table entries installed by the controller. It handles per-packet operations like looking up destination addresses, applying actions (e.g., output to port, drop, modify header), and forwarding at line rate. Packet forwarding delays are typically caused by data plane issues such as flow table misses, hardware forwarding pipeline congestion, or inefficient TCAM lookups.

Exam trap

ISC2 often tests the misconception that the control plane is responsible for forwarding because it makes routing decisions, but in SDN the control plane only programs the data plane, which actually performs the forwarding.

How to eliminate wrong answers

Option B (Application plane) is wrong because it hosts network applications (e.g., load balancers, firewalls) that communicate with the controller via northbound APIs, but it does not directly forward packets. Option C (Control plane) is wrong because it makes forwarding decisions and populates flow tables (e.g., via OpenFlow or NETCONF), but the actual packet forwarding is executed by the data plane. Option D (Management plane) is wrong because it handles administrative tasks like configuration, monitoring, and fault management (e.g., SNMP, CLI), not real-time packet forwarding.

140
MCQeasy

During a business impact analysis (BIA), the team identifies that the customer service application must be restored within 4 hours of a disruption. What is the term for this metric?

A.Maximum Tolerable Downtime (MTD)
B.Recovery Point Objective (RPO)
C.Service Level Agreement (SLA)
D.Recovery Time Objective (RTO)
AnswerD

The Recovery Time Objective (RTO) is the maximum acceptable duration of time within which a business process or system must be restored after a disruption to avoid unacceptable consequences. During a Business Impact Analysis (BIA), the team identifies the RTO for critical functions by assessing the financial, operational, and reputational impacts of downtime over time. This objective serves as a key target for disaster recovery and business continuity planning, guiding the selection of appropriate recovery strategies.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time that a business process or application can be unavailable after a disruption. In this scenario, the 4-hour restoration requirement for the customer service application directly matches the RTO metric, which drives the design of recovery strategies and resource allocation.

Exam trap

The trap here is confusing RTO with MTD, as candidates often think MTD is the same as the recovery time target, but MTD is the total tolerable outage including business impact, while RTO is the specific IT recovery goal set to meet that MTD.

How to eliminate wrong answers

Option A is wrong because Maximum Tolerable Downtime (MTD) represents the total duration a business process can be non-functional before causing irreparable harm, which is typically longer than the RTO and includes the time to recover plus any additional buffer. Option B is wrong because Recovery Point Objective (RPO) measures the maximum acceptable data loss in terms of time (e.g., minutes or hours of lost transactions), not the time to restore service. Option C is wrong because a Service Level Agreement (SLA) is a contractual commitment between a provider and customer that may include RTOs, but it is not the metric itself; the question asks for the term describing the restoration time requirement.

141
Multi-Selectmedium

Which TWO principles are fundamental to a defense-in-depth security architecture?

Select 2 answers
A.Diversity of defense
B.Centralized logging
C.Single point of failure
D.Layered security controls
E.Minimal user training
AnswersA, D

Diversity of defense is a fundamental principle requiring the deployment of different types of security controls, technologies, and vendors across various layers. This strategic heterogeneity ensures that a single vulnerability or attack method targeting one specific control type cannot bypass all defenses simultaneously. By avoiding reliance on a uniform set of protections, the overall resilience against sophisticated threats is significantly enhanced, making it harder for attackers to find a common weakness.

Why this answer

Diversity of defense (A) is fundamental because using different vendors, technologies, or mechanisms across layers prevents a single exploit or vulnerability from compromising the entire architecture, so an attacker who defeats one control faces dissimilar controls elsewhere. Layered security controls (D) are equally fundamental because defense-in-depth deliberately stacks multiple independent controls (network, host, application, data) so that if one layer fails, others still protect the asset. Centralized logging (B) is a valuable detective and monitoring practice, but it is a supporting capability rather than a defining principle of defense-in-depth.

A single point of failure (C) directly contradicts defense-in-depth, which seeks to eliminate such dependencies. Minimal user training (E) is not a principle of defense-in-depth; user awareness and training are actually important complementary controls that strengthen the human layer.

Exam trap

CISSP often tests the confusion between defense-in-depth principles (layering, diversity) and supporting operational capabilities like centralized logging, tricking candidates into selecting a monitoring tool as a foundational principle.

142
MCQeasy

A multinational corporation must ensure that data leaving the organization's network is classified and labeled appropriately. Which of the following is the MOST effective method to enforce consistent labeling across all data types?

A.Implement automated data classification tools that scan for sensitive content and apply labels
B.Appoint data stewards in each department to manually review and label data
C.Require all employees to complete annual training on data classification
D.Encrypt all data in transit and at rest to prevent unauthorized access
AnswerA

Automated data classification tools are essential for a multinational corporation because they consistently identify and label sensitive content across diverse systems and jurisdictions. These tools leverage predefined rules, machine learning, and regular expressions to scan vast datasets, ensuring uniform application of data handling policies. This consistency is critical for maintaining regulatory compliance and enforcing appropriate security controls, regardless of where the data resides or travels.

Why this answer

Automated data classification tools (e.g., Microsoft Purview, Symantec DLP) use content inspection, pattern matching, and machine learning to scan data at rest, in use, and in transit. They apply consistent labels based on predefined policies (e.g., regex for PII, fingerprinting for IP), ensuring uniform labeling across all data types without relying on human consistency or manual effort.

Exam trap

The trap here is that candidates often confuse encryption (which protects data) with classification (which labels data), or they overestimate the effectiveness of training and manual processes for consistent enforcement at scale.

How to eliminate wrong answers

Option B is wrong because manual review by data stewards is error-prone, inconsistent across departments, and cannot scale to the volume of data in a multinational corporation, leading to labeling gaps and misclassification. Option C is wrong because annual training alone does not enforce labeling; employees may forget, ignore, or apply labels inconsistently, and training cannot ensure real-time compliance for every data item. Option D is wrong because encryption protects confidentiality but does not classify or label data; encrypted data can still be unlabeled or mislabeled, failing to meet the requirement for consistent labeling.

143
Multi-Selecteasy

Which TWO of the following are valid reasons for conducting a business impact analysis (BIA)?

Select 2 answers
A.To identify vulnerabilities in the network infrastructure
B.To perform a full security audit of the organization
C.To create a list of all hardware and software assets
D.To identify critical business processes and their dependencies
E.To determine the maximum acceptable outage time for each process
AnswersD, E

A fundamental objective of a Business Impact Analysis (BIA) is to systematically identify and prioritize the organization's critical business processes. This involves determining which operations are essential for the organization's survival and mission fulfillment. Furthermore, the BIA meticulously maps out the internal and external dependencies—such as IT systems, personnel, facilities, and third-party services—that these critical processes rely upon to function effectively.

Why this answer

A Business Impact Analysis (BIA) is specifically designed to identify critical business processes and their dependencies on resources such as personnel, systems, and data. This identification is foundational for prioritizing recovery strategies in business continuity planning, as it directly links operational needs to technical infrastructure.

Exam trap

The trap here is that candidates confuse the BIA with technical assessments like vulnerability scans or asset inventories, but the BIA is exclusively a business-oriented analysis of process criticality and outage tolerance, not a technical audit or inventory exercise.

144
MCQhard

An organization is deploying a VPN solution for remote employees. The security team requires a modern protocol with perfect forward secrecy, uses elliptic curve cryptography, and is known for its efficient, minimal codebase. Which VPN protocol should they choose?

A.WireGuard
B.L2TP/IPsec
C.PPTP
D.IPsec with IKEv2
AnswerA

WireGuard is a modern, high-performance VPN protocol distinguished by its extremely small codebase, which significantly reduces the attack surface and simplifies auditing. It leverages state-of-the-art cryptographic primitives, including ChaCha20 for symmetric encryption, Poly1305 for authentication, and Curve25519 for Elliptic Curve Cryptography (ECC) and Perfect Forward Secrecy (PFS) key exchange. This combination ensures robust security, exceptional speed, and efficient resource utilization, making it ideal for remote employees seeking a fast and secure connection.

Why this answer

WireGuard is the correct choice because it is a modern VPN protocol that uses elliptic curve cryptography (Curve25519) for key exchange, provides perfect forward secrecy by default through its ephemeral session keys, and is designed with a minimal, auditable codebase (around 4,000 lines) for efficiency and security. These features directly match the organization's requirements for a modern protocol with PFS, ECC, and a lean implementation.

Exam trap

In the CISSP exam, candidates may incorrectly choose IPsec with IKEv2 because it supports PFS and ECC, but fail to recognize that only WireGuard is designed with a minimal, auditable codebase, which is explicitly required in the question.

How to eliminate wrong answers

Option B (L2TP/IPsec) is wrong because it relies on IPsec for encryption, which often uses Diffie-Hellman with finite-field groups rather than elliptic curve cryptography by default, and its codebase is not minimal or efficient due to the layered architecture and multiple components. Option C (PPTP) is wrong because it uses outdated RC4 encryption and MS-CHAPv2 authentication, lacks perfect forward secrecy, and is considered insecure due to known vulnerabilities (e.g., MS-CHAPv2 cracking). Option D (IPsec with IKEv2) is wrong because while it can support ECC and PFS, it is not known for a minimal codebase; its implementation is complex with many configuration options and a larger attack surface compared to WireGuard.

145
MCQmedium

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

A.Classification-based controls
B.Cloud DLP
C.Network DLP
D.Endpoint DLP
AnswerC

Monitoring email attachments in transit for sensitive data inspects network traffic flows, which is network DLP. Endpoint DLP would inspect data on devices, and storage DLP would scan data at rest rather than email in transit.

Why this answer

Network DLP monitors data in motion by inspecting network traffic, such as email attachments, as they traverse the network perimeter. This is the correct type because the scenario explicitly describes monitoring email attachments, which are transmitted over the network, and Network DLP is designed to inspect SMTP, HTTP, FTP, and other protocols for sensitive content at the network layer.

Exam trap

The trap here is that candidates confuse 'monitoring email attachments' with endpoint-based controls, but the key distinction is that Network DLP inspects data in motion across the network, whereas Endpoint DLP focuses on local device actions like saving to USB or printing.

How to eliminate wrong answers

Option A is wrong because classification-based controls are not a type of DLP; they are a data governance mechanism that labels data based on sensitivity, but they do not actively monitor or block data in transit. Option B is wrong because Cloud DLP is a service provided by cloud providers (e.g., AWS Macie, Google Cloud DLP) that inspects data stored in cloud repositories, not email attachments traversing an on-premises or hybrid network. Option D is wrong because Endpoint DLP monitors data at rest or in use on endpoints (e.g., USB copy, clipboard operations), not data in motion over the network like email attachments.

146
MCQmedium

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

A.Provide diligent and competent service to principals
B.Act honorably, honestly, justly, responsibly, and legally
C.Protect society, the common good, and the infrastructure
D.Advance and protect the profession
AnswerC

This is the correct answer because it represents the first and highest priority canon in the (ISC)² Code of Ethics. It mandates that certified professionals prioritize the safety, welfare, and security of the public, critical systems, and shared resources above all other considerations. This overarching responsibility ensures that individual or organizational interests never compromise the broader societal well-being or the integrity of essential information technology infrastructure.

Why this answer

The ISC2 Code of Ethics canons are ordered by precedence, and the first canon—'Protect society, the common good, and the infrastructure'—takes priority over all others. This means that when ethical obligations conflict, a CISSP must prioritize the safety and well-being of society and critical infrastructure above duties to clients, employers, or the profession. The remaining canons are subordinate and must be interpreted in light of this primary obligation.

Exam trap

CISSP often tests the specific order of the ISC2 Code of Ethics canons, and candidates frequently misremember which canon is first or assume all canons are equal in weight.

How to eliminate wrong answers

Option A is wrong because 'Provide diligent and competent service to principals' is the third canon, which applies after the first two and does not take precedence. Option B is wrong because 'Act honorably, honestly, justly, responsibly, and legally' is the second canon, subordinate to the first. Option D is wrong because 'Advance and protect the profession' is the fourth and final canon, which is important but has the lowest precedence among the four.

147
Multi-Selecthard

A cloud security architect is designing a system that must comply with the principle of data sovereignty. Which three controls should be implemented? (Select THREE.)

Select 3 answers
A.Encrypt data at rest using customer-managed keys
B.Enforce contractual clauses with cloud provider regarding data location
C.Implement data classification policies
D.Store data only in approved geographic regions
E.Use a virtual private network (VPN) for all transfers
AnswersB, C, D

Enforcing explicit contractual clauses with the cloud provider regarding data location is a fundamental and legally binding method to ensure data sovereignty. These agreements legally obligate the provider to store and process data exclusively within specified geographic regions or countries, preventing unauthorized data transfers across borders. This provides a formal framework for accountability and compliance with jurisdictional requirements.

Why this answer

Data sovereignty requires that data remains subject to the laws and regulations of the jurisdiction where it is stored, so option B is correct because contractual clauses with the cloud provider legally bind the provider to keep data within specified locations and comply with local regulations. Option C is correct because data classification policies identify which data is subject to sovereignty requirements, enabling proper handling, access control, and residency enforcement based on sensitivity and regulatory scope. Option D is correct because storing data only in approved geographic regions directly enforces residency, ensuring data does not leave the legal jurisdiction whose laws must govern it.

Option A is not correct because customer-managed encryption keys address confidentiality and key control, not the physical or legal location of data, and encryption alone does not satisfy sovereignty. Option E is not correct because a VPN protects data in transit from interception but does not control or guarantee where data is stored or which laws apply to it.

Exam trap

Candidates often confuse data sovereignty (which is about legal jurisdiction and physical/geographic location) with general data security controls like encryption or VPNs. While security controls protect data, sovereignty is specifically governed by geography and legal boundaries.

148
MCQmedium

A company wants to secure email communications for its employees. They need to ensure message confidentiality and integrity, and also verify the sender's identity. Which protocol uses a hierarchical public key infrastructure (PKI) for email encryption and signing?

A.S/MIME
B.PGP
C.TLS
D.SSH
AnswerA

S/MIME (Secure/Multipurpose Internet Mail Extensions) is a widely adopted standard for public key encryption and digital signing of MIME data, primarily used for email. It leverages a hierarchical Public Key Infrastructure (PKI) where X.509 certificates, issued by trusted Certificate Authorities (CAs), bind public keys to user identities. This enables end-to-end encryption for confidentiality, digital signatures for integrity and non-repudiation, and sender authentication, making it the most suitable choice for securing corporate email communications.

Why this answer

S/MIME (Secure/Multipurpose Internet Mail Extensions) is the correct answer because it is specifically designed to provide email encryption and digital signing using a hierarchical public key infrastructure (PKI) based on X.509 certificates. This allows the company to ensure message confidentiality (via encryption), integrity (via hashing and signing), and sender authentication (via certificate validation against a trusted root CA).

Exam trap

The trap here is confusing PGP's Web of Trust with S/MIME's hierarchical PKI, as both can encrypt and sign emails, but only S/MIME relies on a formal CA hierarchy as described in the question.

How to eliminate wrong answers

Option B (PGP) is wrong because it uses a decentralized 'Web of Trust' model rather than a hierarchical PKI, relying on user-signed keys instead of a formal certificate authority hierarchy. Option C (TLS) is wrong because it secures the transport layer (e.g., SMTP, HTTP) between servers or clients, not the email message itself end-to-end, and does not inherently provide sender authentication for individual emails. Option D (SSH) is wrong because it is a protocol for secure remote shell access and file transfer, not for email encryption or signing.

149
MCQmedium

A security administrator needs to ensure that data stored on a server is unrecoverable after decommissioning. The server uses SSDs. Which sanitization method is MOST appropriate?

A.Quick format
B.Standard overwriting with multiple passes
C.Physical destruction (shredding)
D.Degaussing
AnswerC

Physical destruction, such as shredding, is the most secure and definitive method for sanitizing solid-state drives. This process involves mechanically breaking the SSD's components, including the NAND flash memory chips where data is stored, into tiny, unrecoverable fragments. By rendering the storage media physically unreadable and non-functional, shredding ensures that data cannot be reconstructed or accessed by any means, providing absolute data destruction.

Why this answer

SSDs cannot be reliably overwritten due to wear leveling; physical destruction or cryptographic erasure is recommended.

150
MCQhard

A security architect is designing an authentication system. To prevent session fixation attacks, which secure design principle should be implemented?

A.Using HTTPS for all communications
B.Setting session timeout to 30 minutes
C.Implementing multi-factor authentication
D.Regenerating session IDs after successful login
AnswerD

Regenerating the session ID immediately after a user successfully authenticates is the most effective direct countermeasure against session fixation. This action ensures that any session ID an attacker might have previously forced upon the victim's browser becomes invalid and unusable. By issuing a completely new, cryptographically random session ID for the authenticated session, the application effectively severs the link between the attacker's known ID and the legitimate user's secure session, preventing unauthorized access.

Why this answer

Session fixation attacks occur when an attacker forces a user to use a known session ID. Regenerating the session ID after successful login (e.g., via `session_regenerate_id()` in PHP or `HttpServletRequest.changeSessionId()` in Java) ensures that the pre-authentication session ID is discarded and a new, unpredictable one is issued, breaking the attacker's control.

Exam trap

The trap here is that candidates confuse session fixation with session hijacking or general secure transmission, leading them to choose HTTPS or MFA, which are important but do not directly counter the fixation mechanism.

How to eliminate wrong answers

Option A is wrong because HTTPS encrypts data in transit but does not prevent an attacker from fixing a session ID before login; it protects against eavesdropping, not session fixation. Option B is wrong because setting a session timeout limits the window of opportunity for an attacker to use a fixed session, but it does not invalidate the fixed session ID after authentication; the attacker can still reuse it within the timeout period. Option C is wrong because multi-factor authentication strengthens identity verification but does not address the core issue of an attacker controlling the session ID; the fixed session ID remains valid even with MFA.

Page 1

Page 2 of 11

Page 3

All pages