Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 151–225

816 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQeasy

Which of the following best describes the primary purpose of an incident response plan?

A.To replace the need for a disaster recovery plan
B.To assign blame after an incident occurs
C.To document all security controls in place
D.To provide a structured approach for managing and resolving security incidents
AnswerD

An Incident Response (IR) plan establishes a systematic and predefined set of procedures, roles, and communication protocols for an organization to effectively handle security breaches. This structured approach ensures that incidents are detected promptly, analyzed thoroughly, contained efficiently, eradicated completely, and that systems are recovered swiftly. Its primary purpose is to minimize impact, restore normal operations, and learn from each event to enhance overall security posture.

Why this answer

An incident response plan provides a structured approach to manage and resolve security incidents, minimizing impact.

152
MCQeasy

An organization is implementing a bring-your-own-device (BYOD) policy. Which security control should be enforced to ensure that only compliant devices can access corporate resources?

A.Using a VPN concentrator
B.Requiring strong passwords
C.Implementing network access control (NAC)
D.Enabling full disk encryption
AnswerC

Implementing Network Access Control (NAC) is the most effective solution for managing BYOD security by dynamically assessing the security posture of devices attempting to connect to the network. NAC verifies device compliance with organizational policies, checking for up-to-date antivirus, patch levels, and configuration settings before granting or restricting network access. This allows for granular control and automated remediation, ensuring only healthy and compliant devices can access corporate resources.

Why this answer

Network access control (NAC) is the correct control because it evaluates device posture (e.g., OS patch level, antivirus status, disk encryption) against a compliance policy before granting network access. NAC can quarantine non-compliant devices to a remediation VLAN or deny access entirely, ensuring only trusted endpoints reach corporate resources. This is distinct from generic encryption or authentication controls, as NAC enforces a dynamic, policy-based admission decision at the network layer.

Exam trap

The trap here is that candidates often confuse authentication controls (like strong passwords or VPN) with device compliance enforcement, but NAC is the only option that actively checks and enforces a security posture before granting network access.

How to eliminate wrong answers

Option A is wrong because a VPN concentrator only provides encrypted tunneling for remote access and does not evaluate device compliance or posture before allowing connectivity. Option B is wrong because requiring strong passwords addresses authentication but does not verify that the device itself meets security baselines (e.g., patching, encryption, or jailbreak status). Option D is wrong because full disk encryption protects data at rest on the device but does not control network access or enforce compliance checks at the point of connection.

153
MCQmedium

A company wants to securely transfer files between systems over SSH. Which protocol should they use to leverage the existing SSH infrastructure and provide both authentication and encryption?

A.FTPS
B.SFTP
C.TFTP
D.SCP
AnswerB

SFTP (SSH File Transfer Protocol) is the correct choice because it runs as a subsystem over a single SSH connection, leveraging SSH's robust authentication and encryption capabilities. This provides strong security for both data in transit and control commands, operating efficiently over a single port (typically 22) which simplifies firewall management. SFTP also offers a rich set of features, including directory listings, file deletion, and resume capabilities, making it a comprehensive solution for secure file management.

Why this answer

SFTP (SSH File Transfer Protocol) is the correct choice because it operates over the SSH protocol (typically port 22), leveraging its existing authentication and encryption mechanisms. Unlike FTPS, which adds SSL/TLS to FTP, SFTP is designed as a secure file transfer subsystem of SSH, providing both confidentiality and integrity without requiring additional infrastructure.

Exam trap

The trap here is confusing SFTP with FTPS or SCP, as many candidates assume 'SSH' implies SCP is the only option, but SFTP is the modern, feature-rich protocol that fully leverages SSH infrastructure for secure file transfers.

How to eliminate wrong answers

Option A (FTPS) is wrong because it uses FTP over SSL/TLS, which requires separate certificates and typically operates on port 990, not leveraging the existing SSH infrastructure. Option C (TFTP) is wrong because it is a trivial, unauthenticated, and unencrypted protocol (UDP port 69) used for simple file transfers, with no security features. Option D (SCP) is wrong because while it uses SSH for authentication and encryption, it is a legacy protocol that lacks the advanced features of SFTP (e.g., directory listing, resume, and file deletion) and is being deprecated in favor of SFTP.

154
MCQeasy

Which component of a trusted computing base (TCB) implements the reference monitor concept by enforcing access control decisions for all subjects and objects in the system?

A.Trusted platform module
B.Trusted computing base
C.Reference monitor
D.Security kernel
AnswerD

The security kernel is the concrete implementation of the abstract reference monitor concept within a Trusted Computing Base (TCB). It is the core of the operating system that enforces the system's access control policies, mediating all subject-object interactions to ensure security. This critical component is responsible for isolating processes, managing memory, and controlling access to resources, making it the actual mechanism that implements the TCB's security functions.

Why this answer

The security kernel is the hardware, firmware, and software component of the TCB that implements the reference monitor concept by mediating all access requests between subjects and objects. It enforces the access control policy and is the only portion of the TCB that must be tamper-proof and always invoked. While the reference monitor is the abstract concept, the security kernel is its concrete implementation within the TCB.

Exam trap

The trap is conflating the abstract reference monitor concept with its concrete implementation (security kernel), or confusing the broader TCB with the specific enforcement component.

How to eliminate wrong answers

Option A is wrong because the Trusted Platform Module (TPM) is a hardware chip for secure key storage and platform integrity measurement, not the access-control enforcement mechanism. Option B is wrong because the TCB is the broader set of components (hardware, firmware, software) that enforce security policy; it contains the security kernel but is not itself the reference monitor implementation. Option C is wrong because the reference monitor is the abstract model or concept (always invoked, tamper-proof, verifiable) rather than the concrete component that implements it.

155
MCQmedium

A security manager is calculating the annual loss expectancy (ALE) for a server valued at $50,000. The exposure factor (EF) is 40%, and the annual rate of occurrence (ARO) is 0.5. What is the ALE?

A.$10,000
B.$100,000
C.$25,000
D.$20,000
AnswerA

This option correctly calculates the Annual Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Subsequently, multiplying this SLE by the ARO (0.5) yields the correct ALE of $10,000, representing the expected financial loss from this specific risk over a year.

Why this answer

ALE is calculated as SLE × ARO, where SLE = Asset Value × Exposure Factor. Here, SLE = $50,000 × 0.40 = $20,000, and ALE = $20,000 × 0.5 = $10,000. This quantifies the expected yearly monetary loss from the risk, which is the standard CISSP quantitative risk analysis formula.

Exam trap

CISSP often tests the distinction between SLE and ALE — candidates frequently stop at SLE ($20,000) and forget to multiply by the ARO, or they confuse ARO with EF in the formula.

How to eliminate wrong answers

Option B is wrong because $100,000 would result from multiplying the asset value by 2 (an ARO of 2 with 100% EF), which misapplies the formula and ignores the 40% exposure factor. Option C is wrong because $25,000 equals half the asset value, which would only be correct if EF were 100% and ARO were 0.5, ignoring the stated 40% exposure factor. Option D is wrong because $20,000 is the Single Loss Expectancy (SLE), not the ALE — it omits the multiplication by the ARO of 0.5.

156
MCQmedium

A government agency requires a security model that prevents users from reading documents at a higher classification level and from writing to documents at a lower classification level. Which model enforces these constraints?

A.Bell-LaPadula
B.Brewer-Nash
C.Clark-Wilson
D.Biba
AnswerA

The Bell-LaPadula security model is specifically designed to enforce confidentiality, primarily within military and government hierarchical classification systems. It prevents unauthorized disclosure of information by implementing two core rules: the Simple Security Property (no read up) and the *-Property (no write down). This ensures that subjects can only access information at or below their security clearance level and cannot write information to a lower clearance level, thus maintaining strict confidentiality.

Why this answer

Bell-LaPadula is the mandatory access control model focused on confidentiality. Its two core rules are 'no read up' (a subject cannot read data at a higher classification) and 'no write down' (a subject cannot write to a lower classification), which exactly match the government agency's stated constraints. The simple security property and the *-property (star property) enforce these respectively.

Exam trap

CISSP often tests the read/write direction of Bell-LaPadula versus Biba, so the trap is mixing up 'no read up/no write down' (confidentiality) with 'no read down/no write up' (integrity).

How to eliminate wrong answers

Option B is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by classification hierarchy. Option C is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not confidentiality classification levels. Option D is wrong because Biba is the integrity model and enforces the reverse rules — 'no read down' and 'no write up' — which would allow reading higher-classification data, the opposite of what is required.

157
MCQmedium

A security analyst reviews the following logs from a Linux server: May 10 03:12:15 server sshd[1234]: Failed password for root from 203.0.113.7 port 51234 ssh2 May 10 03:12:17 server sshd[1234]: Failed password for admin from 203.0.113.7 port 51235 ssh2 May 10 03:12:19 server sshd[1234]: Failed password for user from 203.0.113.7 port 51236 ssh2 May 10 03:12:21 server sshd[1234]: Failed password for root from 203.0.113.7 port 51237 ssh2 What is the most likely cause of these events?

A.The root account is disabled
B.The firewall is blocking port 22
C.A brute-force attack is in progress
D.The SSH service is not running
AnswerC

The log entries clearly show numerous consecutive "Failed password" attempts for the highly privileged "root" user, all originating from the same source IP address within a short period. This repetitive pattern of incorrect password submissions for a specific account from a single source is a definitive indicator of an automated brute-force attack. The attacker is systematically trying various password combinations to gain unauthorized access to the system, targeting a critical administrative account.

Why this answer

The logs show repeated SSH authentication failures from the same source IP address with different usernames, including root, admin, and user. This pattern of multiple failed login attempts in rapid succession is characteristic of a brute-force attack against the SSH service. The fact that attempts continue across different usernames indicates an automated tool is systematically trying credentials, not a single misconfiguration or network issue.

Exam trap

ISC2 often tests the distinction between a service being unreachable (firewall blocking or service down) versus a service being reachable but under attack, where logs show authentication failures rather than connection failures.

How to eliminate wrong answers

Option A is wrong because the logs show failed attempts for root, admin, and user accounts, and a disabled root account would only affect root logins, not the other usernames; also, a disabled root account would not generate repeated authentication failure logs. Option B is wrong because if the firewall were blocking port 22, the SSH service would not receive any connection attempts at all, and the logs would not show authentication failures (they would show connection refused or timeout errors). Option D is wrong because if the SSH service were not running, the server would not respond to SSH connection attempts, and the logs would not contain authentication failure entries; the service must be running to process and log these attempts.

158
MCQhard

A developer is implementing cryptographic storage for sensitive user data. Which of the following is a cryptographic best practice?

A.Using a static initialization vector (IV) for all encryption operations
B.Encrypting data with a hardcoded key in source code
C.Hashing passwords with MD5 for performance
D.Using AES-256 in Galois/Counter Mode (GCM) for authenticated encryption
AnswerD

Using AES-256 in Galois/Counter Mode (GCM) for authenticated encryption represents a strong and recommended cryptographic best practice. AES-256 provides robust confidentiality with its 256-bit key, making brute-force attacks computationally infeasible. GCM, as an Authenticated Encryption with Associated Data (AEAD) mode, simultaneously ensures data integrity and authenticity by generating an authentication tag, which verifies that the ciphertext has not been tampered with and originated from a legitimate source. This combination offers comprehensive protection against both eavesdropping and active manipulation.

Why this answer

Industry-standard algorithms like AES-256 and SHA-256 are recommended, while MD5 and SHA-1 are deprecated due to weaknesses. Authenticated encryption (e.g., GCM) provides both confidentiality and integrity.

159
MCQmedium

An organization is implementing a new access control system. The security team wants to ensure that users cannot deny having performed an action. Which security principle is being addressed?

A.Availability
B.Integrity
C.Confidentiality
D.Non-repudiation
AnswerD

Non-repudiation provides irrefutable proof that a specific action or event has occurred and that a particular entity was responsible for it, preventing them from later denying their involvement. This is typically achieved through robust audit trails, digital signatures, and secure logging mechanisms that cryptographically link an action to a user. Therefore, it directly addresses the requirement to prevent users from disclaiming responsibility for their actions within an access control system.

Why this answer

Non-repudiation is the security principle that ensures a party to a communication or transaction cannot later deny having performed that action. It is typically achieved through digital signatures, audit logs, and cryptographic proof of origin and delivery. The question directly describes the inability to deny an action, which is the textbook definition of non-repudiation.

Exam trap

CISSP often tests the distinction between integrity and non-repudiation, as both involve protecting data from unauthorized changes; candidates may incorrectly choose integrity when the scenario emphasizes denying an action.

How to eliminate wrong answers

Option A is wrong because availability ensures systems and data are accessible to authorized users when needed, not that actions can be proven. Option B is wrong because integrity ensures data has not been altered or tampered with, but does not prevent a user from denying they performed an action. Option C is wrong because confidentiality ensures data is only disclosed to authorized parties, which is unrelated to proving an action occurred.

160
Matchingmedium

Match each security model to its primary characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

No read up, no write down

No read down, no write up

Well-formed transactions and separation of duties

Prevents conflict of interest among clients

Rules for granting and taking permissions

Why these pairings

The correct matches are: Bell-LaPadula (confidentiality, no read up/no write down), Biba (integrity, no read down/no write up), Clark-Wilson (integrity, well-formed transactions and separation of duties), and Brewer-Nash (confidentiality, conflict of interest). Common confusions involve swapping the rules between Bell-LaPadula and Biba.

161
MCQeasy

An organization is conducting a security assessment of a new web application. Which testing technique would best identify cross-site scripting (XSS) vulnerabilities?

A.Manual code review
B.Static application security testing (SAST)
C.Interactive application security testing (IAST)
D.Dynamic application security testing (DAST)
AnswerD

Dynamic Application Security Testing (DAST) actively tests the running application from an external perspective, simulating real-world attacks against the deployed environment. By interacting with the application's exposed interfaces (like a browser or API client), DAST can effectively identify runtime vulnerabilities such as XSS, SQL injection, and broken authentication by observing the application's responses to malicious inputs. This black-box approach accurately reflects an attacker's view and confirms actual exploitability, making it highly effective for web application security assessments.

Why this answer

Dynamic Application Security Testing (DAST) is a black-box testing methodology that inspects a running application from the outside in. Because the assessment is conducted without access to the source code (black-box), DAST is the primary method used to find vulnerabilities like XSS and SQL injection by actively injecting payloads into input fields and analyzing the application's runtime responses.

Exam trap

Candidates often confuse SAST and DAST. Remember that SAST requires access to the source code (white-box) and is performed early in the SDLC, whereas DAST is performed on a running application (black-box) without requiring source code access.

How to eliminate wrong answers

Option A is wrong because manual code review relies on human inspection of source code, which is time-consuming, error-prone, and may miss subtle XSS vectors that only appear during runtime (e.g., DOM-based XSS or context-dependent encoding issues). Option B is wrong because SAST analyzes source code without executing it, so it cannot detect XSS vulnerabilities that depend on runtime data flow, such as those involving dynamic JavaScript execution or third-party libraries. Option C is wrong because IAST combines static and dynamic analysis but requires instrumentation of the running application; while it can detect XSS, it is not the best technique for a standalone assessment because it introduces overhead and may not be available for all environments, whereas DAST is a direct, non-invasive black-box test.

162
MCQmedium

During a business impact analysis (BIA), a department manager states that a critical process cannot be interrupted for more than 2 hours. However, the current backup system requires 8 hours to restore. What is the most appropriate risk management action?

A.Mitigate the risk by implementing faster backup and restoration procedures.
B.Avoid the risk by discontinuing the process.
C.Accept the risk and document the decision.
D.Transfer the risk to a third-party service provider.
AnswerA

The Business Impact Analysis (BIA) identified that the current 8-hour recovery time for a critical system far exceeds the required 2-hour Recovery Time Objective (RTO). Implementing faster backup technologies, such as incremental backups with rapid restore capabilities, or enhancing restoration procedures, directly addresses this gap. This strategy reduces the impact of an outage by bringing the actual recovery time within acceptable business parameters, thereby mitigating the identified risk.

Why this answer

The BIA identifies a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 8 hours, creating a gap. Mitigating the risk by implementing faster backup and restoration procedures directly reduces the RTO to meet the MTD, aligning recovery capability with business requirements. This is the most appropriate action because it addresses the root cause—insufficient recovery speed—without unnecessarily discarding or transferring the process.

Exam trap

The trap here is that candidates may choose 'accept the risk' (Option C) thinking it is a valid risk management strategy, but the BIA has already defined an unacceptable downtime threshold, making acceptance inappropriate without a formal risk treatment plan that justifies the gap.

How to eliminate wrong answers

Option B is wrong because discontinuing the process (risk avoidance) is an extreme measure that would likely cause significant business disruption or loss of revenue, and it is not warranted when a feasible technical solution exists to close the RTO gap. Option C is wrong because accepting the risk without action would leave the organization exposed to a known, unacceptable downtime exceeding the MTD, which violates basic risk management principles unless the cost of mitigation exceeds the potential loss. Option D is wrong because transferring the risk to a third-party service provider does not inherently solve the RTO mismatch; the provider would still need to meet the 2-hour RTO, and the organization retains residual liability for the process's criticality.

163
Multi-Selecthard

A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)

Select 3 answers
A.Reciprocal agreement
B.Cloud DR with replication
C.Synchronous replication to a secondary site
D.Hot site
E.Cold site
AnswersB, C, D

Cloud Disaster Recovery (DR) with replication leverages public or private cloud infrastructure to host backup systems and data. This approach enables rapid recovery with low RTO and RPO by continuously replicating data and virtual machine images to the cloud, allowing for quick spin-up of services in a disaster. Its scalability and pay-as-you-go model also offer cost-effectiveness compared to maintaining a dedicated secondary site.

Why this answer

Option B (Cloud DR with replication) is correct because continuously replicating workloads and data to a cloud region keeps a near-current copy of the environment, allowing rapid failover for a low RTO and minimal data loss for a low RPO. Option C (Synchronous replication to a secondary site) is correct because synchronous replication only acknowledges writes once they are committed at both sites, giving an RPO of essentially zero, and the mirrored secondary site can be activated quickly for a low RTO. Option D (Hot site) is correct because a hot site is a fully operational duplicate facility with current data and ready-to-run systems, enabling failover in minutes or hours (low RTO) with little to no data loss (low RPO).

Option A (Reciprocal agreement) does not belong because it relies on another organization's idle capacity that may not be available or current during a disaster, yielding high RTO and RPO. Option E (Cold site) does not belong because it provides only basic space and power with no pre-installed systems or data, requiring lengthy setup and restoration, which produces the highest RTO and RPO.

Exam trap

CISSP often tests the trade-off between cost and recovery objectives, tempting candidates to select reciprocal agreements or cold sites as 'good enough' when the question explicitly demands minimal RTO and RPO.

164
Multi-Selecthard

Which THREE of the following are common indicators of a privilege escalation attack? (Choose three.)

Select 3 answers
A.Creation of new user accounts with administrative privileges
B.Higher-than-normal network traffic
C.System performance degradation
D.Modification of system files or registry keys
E.Unusual processes running under elevated privileges
AnswersA, D, E

Once an attacker successfully gains elevated privileges, creating new user accounts with administrative rights is a common tactic to establish a persistent backdoor. This allows them to maintain access to the compromised system even if the original exploit vector is patched or the initial compromised user account is disabled. It provides a reliable, independent method for future access, making detection and remediation more challenging for defenders.

Why this answer

Option A is correct because attackers who achieve privilege escalation often create new local or domain accounts and add them to administrative groups (e.g., Administrators, Domain Admins, or sudoers) to establish persistent, high-privilege access. Option D is correct because privilege escalation commonly involves tampering with system files or registry keys—such as modifying HKLM\SYSTEM or service binaries—to weaken security controls, disable protections like UAC, or enable persistence. Option E is correct because processes running under SYSTEM, root, or other elevated contexts that are unexpected (e.g., cmd.exe spawned by a service, or unusual binaries with high integrity levels) are a classic sign that an attacker has escalated privileges.

Option B is not specific to privilege escalation, since higher-than-normal network traffic more often indicates data exfiltration, scanning, or DoS activity rather than elevation itself. Option C is likewise a generic symptom that can result from malware, resource exhaustion, or many other causes, so it is not a reliable indicator of privilege escalation specifically.

Exam trap

ISC2 often tests the distinction between general attack symptoms (like network traffic spikes or performance drops) and specific indicators that directly evidence the privilege escalation technique itself, leading candidates to over-select broad, non-specific options.

165
MCQmedium

During a security review of a web application, testers discover that the application discloses detailed error messages to users, including stack traces. Which secure coding best practice is being violated?

A.Input validation
B.Error handling
C.Secure logging
D.Output encoding
AnswerB

Proper error handling is the direct solution to preventing sensitive information disclosure through error messages. It mandates that applications gracefully intercept all exceptions and internal failures, subsequently presenting only generic, non-informative messages to end-users. Crucially, detailed diagnostic information, such as stack traces or database errors, must be securely logged on the server-side for administrators to troubleshoot, ensuring that no sensitive system details are inadvertently exposed to potential attackers or unauthorized individuals.

Why this answer

Detailed error messages with stack traces expose sensitive implementation details, which is a failure of proper error handling. Secure error handling requires generic user-facing messages while logging details internally. This prevents attackers from learning about the system's internals.

Exam trap

CISSP often tests the misconception that secure logging alone prevents information disclosure, when the core issue is the error handling mechanism that returns sensitive data to the user.

How to eliminate wrong answers

Option A is wrong because input validation focuses on rejecting malicious input, not on how errors are presented. Option C is wrong because secure logging is about protecting log data and ensuring it does not contain sensitive information, but the issue here is disclosure to users. Option D is wrong because output encoding prevents injection attacks like XSS, not information leakage via error messages.

166
MCQmedium

A security team is planning a social engineering test for their organization. Which of the following scenarios would BEST assess the effectiveness of security awareness training?

A.Sending a phishing email that mimics a common internal communication.
B.Calling employees and pretending to be IT support to obtain passwords.
C.Attempting to tailgate into a secure facility.
D.Searching through trash bins for sensitive documents.
AnswerA

Sending a phishing email that mimics a common internal communication directly tests the effectiveness of an organization's security awareness training regarding email-borne threats. This method assesses employees' ability to identify suspicious emails, recognize social engineering indicators, and follow established protocols for reporting potential phishing attempts. It provides measurable data on human vulnerability to the most prevalent form of digital social engineering.

Why this answer

Sending a phishing email that mimics a common internal communication directly tests whether employees can recognize and report a realistic social engineering attempt, which is the primary goal of security awareness training. This scenario evaluates the human firewall by simulating the most prevalent attack vector—email-based phishing—and measures the effectiveness of training in reducing click-through rates and increasing reporting behavior.

Exam trap

The trap here is that candidates may choose tailgating or vishing because they seem more dramatic or directly test human behavior, but the CISSP exam emphasizes that phishing emails are the most common and effective social engineering vector, and thus the best assessment of security awareness training in a typical enterprise environment.

How to eliminate wrong answers

Option B is wrong because calling employees and pretending to be IT support to obtain passwords tests vishing (voice phishing), which is a valid social engineering vector but less common than email phishing and not the best measure of general security awareness training effectiveness, as training often focuses more on email-based threats. Option C is wrong because tailgating tests physical security controls and employee vigilance at access points, which is a separate domain (physical security) and not the primary focus of most security awareness training programs. Option D is wrong because searching through trash bins for sensitive documents tests dumpster diving, which assesses physical disposal policies and shredding compliance, not the behavioral response to social engineering that awareness training aims to improve.

167
MCQmedium

A security architect is designing access controls for a healthcare application where permissions are based on the user's role, the sensitivity of the data, and the context of the access (e.g., time of day). Which access control model best fits this requirement?

A.Role-Based Access Control (RBAC)
B.Mandatory Access Control (MAC)
C.Attribute-Based Access Control (ABAC)
D.Discretionary Access Control (DAC)
AnswerC

Attribute-Based Access Control (ABAC) is a highly flexible and dynamic authorization model that grants or denies access requests by evaluating a comprehensive set of attributes associated with the user, the resource, the environment, and the requested action. This approach allows for fine-grained access decisions that can incorporate real-time contextual information, such as the user's location, device posture, time of access, and the specific data sensitivity. By leveraging a policy engine to process these diverse attributes against defined rules, ABAC effectively supports complex, adaptive access control requirements.

Why this answer

Attribute-Based Access Control (ABAC) is the correct model because it evaluates access decisions based on multiple attributes: the user's role, the data sensitivity (object attributes), and environmental context such as time of day. Unlike simpler models, ABAC can combine subject, resource, and environment attributes using policy rules (e.g., XACML or ALFA) to enforce fine-grained, context-aware permissions, which is essential for healthcare applications with dynamic compliance requirements like HIPAA.

Exam trap

The trap here is that candidates see 'role' in the requirement and immediately choose RBAC, overlooking that the question explicitly includes data sensitivity and context (time of day), which are attributes that only ABAC can combine into a single policy decision.

How to eliminate wrong answers

Option A is wrong because Role-Based Access Control (RBAC) only considers the user's role and does not natively incorporate data sensitivity or environmental context like time of day; it would require additional custom logic or a hybrid model. Option B is wrong because Mandatory Access Control (MAC) enforces access based on fixed security labels (e.g., classification levels) and system-wide policies, not on dynamic attributes like time or user role; it is too rigid for context-aware healthcare scenarios. Option D is wrong because Discretionary Access Control (DAC) allows resource owners to set permissions at their discretion, which cannot enforce organization-wide policies based on data sensitivity or contextual factors like time of day, leading to inconsistent and insecure access.

168
MCQeasy

Which term describes the process of modifying data so that it cannot be attributed to a specific individual without additional information that is kept separately?

A.Anonymisation
B.Differential privacy
C.Pseudonymisation
D.Encryption
AnswerC

Pseudonymisation is a data management and de-identification technique where directly identifying fields within a data record are replaced with artificial identifiers, or pseudonyms. While the direct identifiers are removed, a separate 'key' or mapping table is maintained, allowing for the re-identification of the original data subject if necessary, typically under strict controls and for specific purposes. This process reduces the linkability of a dataset to an individual without completely destroying the possibility of re-identification, making it a reversible de-identification method.

Why this answer

Pseudonymisation replaces identifying information with a pseudonym, and the mapping between the pseudonym and the original identity is kept separately, so re-identification is possible only with access to that additional information. This matches the definition exactly.

Exam trap

CISSP often tests the distinction between pseudonymisation (reversible with additional info) and anonymisation (irreversible), causing candidates to choose anonymisation when the scenario mentions separately kept additional information.

How to eliminate wrong answers

Option A is wrong because anonymisation irreversibly removes identifying information so that re-identification is not possible, even with additional data; the question specifies that additional information kept separately can re-attribute the data, which is pseudonymisation. Option B is wrong because differential privacy adds statistical noise to query results to protect individual privacy, not a process of replacing identifiers with pseudonyms. Option D is wrong because encryption transforms data into ciphertext to protect confidentiality, but it does not replace identifiers with pseudonyms; the data remains attributable if the key is available, and the definition does not match.

169
MCQeasy

An organization requires that all data stored in a cloud object storage service be encrypted at rest using customer-managed keys. Which encryption option should be implemented?

A.Server-side encryption with cloud service provider-managed keys
B.Transport Layer Security (TLS)
C.Server-side encryption with customer-provided keys
D.Client-side encryption
AnswerC

This option allows the customer to provide and manage their own encryption keys for server-side encryption, fulfilling the requirement for customer-managed keys.

Why this answer

Server-Side Encryption with Customer-Provided Keys allows the organization to encrypt objects at rest in cloud object storage using keys that are managed and supplied by the customer, not the cloud provider. This meets the requirement for customer-managed keys because the encryption key is provided in each API request and is never stored by the service, giving the customer full control over key lifecycle and access.

Exam trap

The trap here is that candidates confuse 'customer-managed keys' with 'client-side encryption,' but the question specifies encryption at rest within the cloud service, which requires a server-side encryption option where the customer provides the key, not encryption performed before upload.

How to eliminate wrong answers

Option A is wrong because SSE-S3 uses Amazon-managed keys, not customer-managed keys, so the customer does not control the encryption keys. Option B is wrong because TLS encrypts data in transit between the client and server, not data at rest in storage. Option D is wrong because client-side encryption encrypts data before it is sent to the cloud, but the question specifically requires encryption at rest using customer-managed keys within the cloud service, and client-side encryption does not leverage the server-side encryption feature of the object storage service.

170
MCQmedium

An organization wants to enable single sign-on (SSO) across multiple web applications using an XML-based protocol that supports browser redirect flows. Which technology is most appropriate?

A.Kerberos
B.OAuth 2.0
C.OpenID Connect (OIDC)
D.SAML 2.0
AnswerD

SAML 2.0 (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. It is specifically designed to facilitate browser-based single sign-on (SSO) for web applications across different security domains, allowing users to authenticate once and gain access to multiple services without re-entering credentials. Its robust support for federated identity management makes it a cornerstone for enterprise SSO solutions.

Why this answer

SAML 2.0 is an XML-based federation standard designed specifically for browser-based SSO via HTTP Redirect and POST bindings, where the IdP issues a signed XML assertion to the SP. It is the canonical choice when the requirement explicitly says 'XML-based protocol' and 'browser redirect flows.'

Exam trap

CISSP often tests SAML vs OIDC by emphasizing 'XML-based' — candidates who default to OIDC because it's 'modern' miss that the question explicitly requires XML.

How to eliminate wrong answers

Option A is wrong because Kerberos is a ticket-based authentication protocol for domain environments (typically Windows/AD) and is not XML-based nor designed for cross-domain web SSO via browser redirects. Option B is wrong because OAuth 2.0 is an authorization framework (JSON/REST, not XML) and does not itself authenticate users or provide SSO identity assertions. Option C is wrong because OpenID Connect is built on OAuth 2.0 and uses JSON/JWT tokens, not XML, so it fails the 'XML-based' requirement even though it does support browser redirect flows.

171
MCQeasy

An organization wants to implement single sign-on (SSO) for multiple cloud applications. Which of the following is the most secure and scalable approach?

A.Implement SAML-based federation
B.Use OAuth for authentication
C.Use the same password for all applications
D.Implement LDAP directory
AnswerA

SAML (Security Assertion Markup Language) is an XML-based open standard specifically designed for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It enables Single Sign-On (SSO) by allowing a user to authenticate once with an IdP and then access multiple SPs without re-authenticating, using cryptographically signed assertions. This federation model ensures secure, scalable, and interoperable identity management across disparate systems, making it the industry standard for enterprise SSO.

Why this answer

SAML-based federation is the most secure and scalable approach for SSO across multiple cloud applications because it uses a trusted identity provider (IdP) to authenticate users and issue signed assertions, eliminating password sharing and enabling centralized access control. It is an industry standard (OASIS) designed specifically for cross-domain SSO, supporting strong authentication and fine-grained attribute sharing. This makes it both secure (no credential proliferation) and scalable (new apps can be added by trusting the IdP).

Exam trap

CISSP often tests the confusion between authentication and authorization protocols, leading candidates to select OAuth for SSO when it is actually an authorization framework, not an authentication mechanism.

How to eliminate wrong answers

Option B is wrong because OAuth is an authorization framework, not an authentication protocol; it grants access tokens for resources but does not verify user identity, so it cannot provide SSO authentication by itself. Option C is wrong because using the same password for all applications is a critical security anti-pattern that increases the blast radius of a single credential compromise and fails to provide true SSO or scalability. Option D is wrong because LDAP is a directory protocol designed for on-premises environments; it does not natively support federated SSO across cloud applications and requires additional components like synchronization or gateways, reducing scalability and security.

172
MCQeasy

Which authentication factor type is a smart card?

A.Somewhere you are
B.Type 2 (something you have)
C.Type 3 (something you are)
D.Type 1 (something you know)
AnswerB

A smart card is a quintessential example of a "something you have" authentication factor because it is a tangible, physical item that the user must possess and present for authentication. This factor relies on the physical control of an object, such as a cryptographic token, USB key, or in this case, a smart card. The card securely stores cryptographic keys or digital certificates, which are accessed only when the card is physically inserted into a compatible reader, thereby proving possession.

Why this answer

A smart card is a Type 2 authentication factor because it falls under the 'something you have' category. The card itself is a physical device that stores a digital certificate or cryptographic key, which the user must possess to authenticate. Unlike knowledge-based or biometric factors, possession of the smart card is the core authentication mechanism, often combined with a PIN (Type 1) for two-factor authentication.

Exam trap

The trap here is that candidates confuse 'something you have' (Type 2) with 'something you are' (Type 3) because smart cards are often used with biometric readers, but the card itself is a possession factor, not a biometric.

How to eliminate wrong answers

Option A is wrong because 'Somewhere you are' is not a standard authentication factor type in the CISSP framework; it is a location-based attribute, not a factor category. Option C is wrong because Type 3 (something you are) refers to biometric characteristics such as fingerprints or iris scans, not a physical token like a smart card. Option D is wrong because Type 1 (something you know) includes passwords, PINs, or passphrases, whereas a smart card is a tangible object, not knowledge.

173
MCQhard

A multinational corporation is designing a data retention schedule. Which factor is most critical when determining retention periods for personal data subject to the GDPR?

A.The length of the third-party data processing agreement
B.The purpose for which the data was collected
C.The cost of storage media
D.The duration of any pending legal holds
AnswerB

This is the fundamental driver for data retention, directly aligning with privacy principles such as "storage limitation" found in regulations like GDPR and CCPA. Data should only be retained for as long as it is necessary to fulfill the specific, explicit, and legitimate purposes for which it was originally collected, or for subsequent compatible purposes, unless a legal or regulatory obligation explicitly dictates a longer period. This principle minimizes data exposure and associated risks.

Why this answer

Under the GDPR, Article 5(1)(e) establishes the 'storage limitation' principle, which mandates that personal data must be kept no longer than necessary for the purposes for which it was collected. Therefore, the purpose of collection is the primary driver for determining the retention period, as it defines the lawful basis and necessity for processing. Without a defined purpose, any retention period would be arbitrary and non-compliant with the regulation.

Exam trap

ISC2 often tests the misconception that legal holds or contractual agreements override the primary GDPR requirement, but the trap here is that candidates confuse operational constraints (cost, contracts) with the regulatory mandate that purpose must dictate retention.

How to eliminate wrong answers

Option A is wrong because the length of a third-party data processing agreement is a contractual term that may align with retention needs, but it is not the most critical factor; GDPR requires the data controller to determine retention based on purpose, not the duration of a vendor contract. Option C is wrong because the cost of storage media is an operational or financial consideration, not a legal or compliance driver; GDPR explicitly prohibits retaining data solely because storage is cheap or convenient. Option D is wrong because while legal holds can extend retention periods to comply with litigation or investigation requirements, they are an exception to the standard retention schedule, not the primary factor for setting the initial retention period; the purpose of collection remains the foundational criterion.

174
MCQeasy

A large enterprise uses Active Directory for authentication. Several users report intermittent authentication failures when accessing internal web applications. The help desk confirms that the failures occur at random times and affect both new and existing users. The security team discovers that the system clocks on domain controllers are within acceptable limits, but some client workstations show time drift of up to 10 minutes. The Kerberos protocol is used for authentication. What is the most likely cause of the authentication failures, and what action should be taken?

A.Implement password complexity policies to reduce authentication errors
B.Enable NTLM fallback authentication for the web applications
C.Synchronize all client workstation clocks using a centralized NTP server
D.Configure Kerberos ticket lifetimes to 24 hours to reduce sensitivity to time skew
AnswerC

Kerberos relies heavily on precise time synchronization between the client, the authenticating server, and the Key Distribution Center (KDC) to prevent replay attacks and ensure ticket validity. By synchronizing all client workstation clocks with a centralized Network Time Protocol (NTP) server, the enterprise ensures that all systems operate within the acceptable time skew tolerance (typically 5 minutes) required by Kerberos. This direct approach eliminates the root cause of authentication failures related to clock differences, allowing Kerberos to function securely and efficiently.

Why this answer

Kerberos authentication relies on synchronized clocks between clients and domain controllers, with a default maximum time skew tolerance of 5 minutes (RFC 4120). A client clock drift of up to 10 minutes exceeds this tolerance, causing intermittent authentication failures because Kerberos ticket requests are rejected as invalid or replay attacks. Synchronizing all client workstations to a centralized NTP server resolves the time skew and restores Kerberos authentication reliability.

Exam trap

The trap here is that candidates may think increasing Kerberos ticket lifetimes or enabling NTLM fallback will solve the issue, but they overlook the strict time synchronization requirement that is fundamental to Kerberos protocol security.

How to eliminate wrong answers

Option A is wrong because password complexity policies do not address time synchronization issues; they reduce the risk of password guessing but have no effect on Kerberos time skew errors. Option B is wrong because enabling NTLM fallback would degrade security by using a weaker, challenge-response protocol that is vulnerable to pass-the-hash attacks, and it does not fix the root cause of clock drift. Option D is wrong because increasing Kerberos ticket lifetimes does not change the maximum allowable time skew (default 5 minutes); tickets still require synchronized clocks for initial authentication, and a 10-minute drift will still cause failures regardless of ticket lifetime.

175
MCQeasy

An organization has implemented a password policy requiring a minimum of 8 characters, including uppercase, lowercase, numbers, and special characters. Despite annual security awareness training, a recent audit revealed that 60% of employees are using passwords that can be cracked within hours. The organization is also experiencing a high number of account compromises due to credential stuffing attacks. The security team is considering various controls to reduce the risk. Which of the following would be the MOST effective in addressing the identified issues?

A.Increase the minimum password length to 15 characters
B.Conduct quarterly password cracking attempts and notify users with weak passwords
C.Implement multifactor authentication for all user accounts
D.Require password changes every 30 days
AnswerC

Implementing multifactor authentication (MFA) significantly enhances security by requiring users to provide two or more distinct verification factors (e.g., something they know, something they have, something they are). This creates a robust defense-in-depth mechanism, as even if an attacker compromises a user's password through credential stuffing or other means, they would still lack the second factor needed to gain unauthorized access, effectively mitigating the risk of password-only breaches.

Why this answer

Multifactor authentication (MFA) adds an additional layer of security that significantly reduces the risk of credential compromise, even if passwords are weak. Increasing password length may help but is still vulnerable to cracking if users choose predictable patterns. Password cracking tests are reactive and may not prevent attacks.

Frequent password changes often lead to weaker passwords.

176
MCQeasy

Which of the following is a key principle of privileged access management (PAM)?

A.Use shared accounts for simplicity
B.Monitor and audit privileged account usage
C.Grant all users administrative rights for efficiency
D.Disable logging for performance
AnswerB

Monitoring and auditing privileged account usage is a cornerstone of effective privileged access management (PAM). This continuous oversight enables the prompt detection of unauthorized activities, policy violations, or suspicious behavior that could indicate a compromise. Regular audits provide irrefutable evidence for accountability, support compliance requirements, and are critical for post-incident forensic analysis, thereby significantly reducing operational risk.

Why this answer

Privileged Access Management (PAM) is centered on the principle of least privilege and the need to control, monitor, and audit the use of privileged accounts (e.g., root, domain admin). Option B is correct because continuous monitoring and auditing of privileged account usage is a foundational PAM requirement, enabling detection of misuse, lateral movement, and privilege escalation. Without auditing, organizations cannot enforce accountability or respond to security incidents involving high-risk accounts.

Exam trap

The trap here is that candidates may confuse PAM with general identity management and choose 'shared accounts for simplicity' (Option A), failing to recognize that PAM specifically enforces individual accountability and credential rotation, not shared access.

How to eliminate wrong answers

Option A is wrong because shared accounts violate non-repudiation and accountability, making it impossible to attribute actions to a specific individual, which is a core PAM goal. Option C is wrong because granting all users administrative rights directly contradicts the principle of least privilege and dramatically increases the attack surface for privilege escalation and ransomware. Option D is wrong because disabling logging for performance eliminates the audit trail required for forensic analysis and compliance, and PAM systems rely on detailed logging (e.g., session recording, keystroke logging) to detect anomalies.

177
Multi-Selectmedium

Which TWO of the following are valid types of data classification labels commonly used in commercial organizations?

Select 2 answers
A.Top Secret
B.Confidential
C.Unclassified
D.Public
E.For Official Use Only
AnswersB, D

"Confidential" is a widely recognized and valid data classification type, commonly applied to sensitive business information whose unauthorized disclosure could cause significant harm or financial loss to an organization. This classification level typically requires strict access controls, encryption, and other protective measures to ensure its integrity and privacy, making it a cornerstone of commercial data protection policies.

Why this answer

Confidential is a valid data classification label in commercial organizations, typically used to protect sensitive business information that could cause harm if disclosed. It is part of common classification schemes such as Public, Internal, Confidential, and Restricted, aligning with ISO/IEC 27001 guidelines for information asset management.

Exam trap

In the ISC2 CISSP exam, it's important to distinguish between government classification levels (Top Secret, Secret, Confidential, Unclassified) and commercial classification labels (Public, Internal, Confidential, Restricted). Candidates often mistakenly apply government terms like Top Secret or Unclassified to commercial scenarios, but these are not typically used in commercial organizations.

178
MCQmedium

OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?

A.Client credential management
B.Authorization delegation
C.Token introspection
D.User authentication
AnswerD

OpenID Connect (OIDC) primarily extends OAuth 2.0 by adding a standardized layer for user authentication. While OAuth 2.0 focuses solely on authorization, allowing a client to obtain delegated access to protected resources, OIDC introduces the concept of an ID Token. This ID Token, a JSON Web Token (JWT), provides verifiable claims about the authenticated user, enabling the client application to confirm the user's identity and retrieve basic profile information.

Why this answer

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0 that primarily adds user authentication. While OAuth 2.0 provides authorization delegation (access tokens for resources), OIDC introduces an ID token (a JSON Web Token, JWT) that contains claims about the authenticated user, enabling the client to verify the user's identity. This is defined in the OIDC specification (OpenID Foundation) and is the key differentiator from plain OAuth 2.0.

Exam trap

The trap here is that candidates often confuse OAuth 2.0's authorization delegation (access tokens for resources) with OIDC's authentication (ID tokens for user identity), leading them to incorrectly select 'Authorization delegation' as the primary addition.

How to eliminate wrong answers

Option A is wrong because client credential management is a feature of OAuth 2.0 itself (e.g., client_id, client_secret, client credentials grant type), not something OIDC adds. Option B is wrong because authorization delegation is the core purpose of OAuth 2.0, not an extension provided by OIDC; OIDC adds authentication on top of that delegation. Option C is wrong because token introspection is an OAuth 2.0 extension (RFC 7662) for validating token status, not a feature introduced by OIDC; OIDC uses the UserInfo endpoint for identity claims.

179
MCQhard

A multinational bank must enforce least privilege across 4,000 roles that change frequently as employees move between trading, compliance, and IT functions. Auditors found that access reviews are performed manually and that role definitions drift from actual job duties. The identity team proposes a role mining and management program. Which approach best aligns with identity and access management governance objectives while reducing role explosion?

A.Create a unique role for every employee based on their current entitlements and assign it during onboarding.
B.Eliminate all roles and assign entitlements directly to each user through workflow-based access requests.
C.Perform bottom-up role mining to derive candidate roles from existing entitlement data, then normalize and approve them through a role governance board.
D.Adopt a top-down role engineering approach that defines roles solely from the organizational chart and job descriptions.
AnswerC

Bottom-up role mining analyzes actual entitlement assignments to identify common access patterns and proposes candidate roles, which are then refined and approved by business owners. This reduces role sprawl, aligns roles with real job functions, and creates a governed, reviewable role catalog, directly addressing the drift and manual review problems.

Why this answer

Bottom-up role mining derives roles from observed entitlement patterns, which exposes drift between documented and actual access and produces a smaller, business-relevant role set. Normalizing and approving candidates through a governance board keeps roles controlled and auditable, reducing role explosion while supporting least privilege and repeatable access reviews across the bank's diverse functions.

Exam trap

The trap here is treating role mining as purely technical and skipping governance approval, or assuming that eliminating roles removes the need for access reviews.

180
MCQeasy

A user reports that they cannot access a file share after being moved to a different department. The file share is secured with NTFS permissions and share permissions. The user is a member of the 'Marketing' group, but the file share is only accessible by 'Sales' group. What is the most likely reason?

A.The share permissions deny access to Marketing
B.The user is not a member of the Sales group
C.The user's account is disabled
D.The NTFS permissions deny access
AnswerB

This is the correct answer because access to file shares is governed by both share and NTFS permissions, with the most restrictive applying. If the file share's security configuration explicitly grants access only to members of the 'Sales' group, and the user in question belongs to the 'Marketing' group, they will be denied access. The user's lack of membership in the required 'Sales' group directly prevents them from satisfying the access control criteria.

Why this answer

The user is unable to access the file share because the share is explicitly configured to allow access only to the 'Sales' group. Since the user has been moved to a different department and is now a member of 'Marketing' rather than 'Sales', they lack the necessary group membership. Even if share permissions were permissive, NTFS permissions would still need to grant access; however, the core issue is that the user is not in the required group.

This is the most direct and likely reason for the access failure.

Exam trap

The trap here is that candidates often focus on the interplay between share and NTFS permissions (the 'most restrictive' rule) and overlook the simpler, more direct cause: the user simply does not belong to the required group, which is the foundational prerequisite for any access to be granted.

How to eliminate wrong answers

Option A is wrong because share permissions that deny access to 'Marketing' would be an explicit deny, but the scenario states the share is only accessible by 'Sales', implying an allow list, not a deny entry; a deny would override allows but is not the most likely reason given the user's group change. Option C is wrong because a disabled account would prevent all access to any resource, not just this specific file share, and the user is only reporting an issue with this one share. Option D is wrong because NTFS permissions denying access would be a secondary factor; the primary issue is that the user is not a member of the 'Sales' group, and without that membership, NTFS permissions cannot grant access regardless of their configuration.

181
MCQhard

A company is implementing a secure multi-tenant cloud environment. The primary security requirement is that tenants cannot access each other's data even if the hypervisor is compromised. Which architecture best meets this requirement?

A.Encrypt each tenant's data with a single master key stored in the hypervisor.
B.Use a Trusted Execution Environment (TEE) such as Intel SGX to isolate tenant processes and memory.
C.Implement Mandatory Access Control (MAC) on the hypervisor.
D.Use VLANs to isolate tenant traffic at the network layer.
AnswerB

A Trusted Execution Environment (TEE), such as Intel SGX, provides robust hardware-enforced isolation for tenant processes and memory regions. It creates secure "enclaves" where code and data are protected from unauthorized access, even by privileged software like the hypervisor or host operating system. This ensures that a compromise of the underlying cloud infrastructure or hypervisor does not allow an attacker to inspect or tamper with sensitive tenant data or execution within the enclave, providing a strong security boundary crucial for multi-tenant environments.

Why this answer

A Trusted Execution Environment (TEE) like Intel SGX creates hardware-enforced enclaves that isolate tenant processes and memory at the CPU level. Even if the hypervisor is compromised, the enclave's memory is encrypted and inaccessible to the host OS or hypervisor, ensuring tenant data remains confidential. This directly meets the requirement that tenants cannot access each other's data despite a hypervisor breach.

Exam trap

The trap here is that candidates often choose MAC or VLANs because they associate them with isolation, but they fail to recognize that these controls operate at the OS or network layer and do not protect against a compromised hypervisor that has direct memory access.

How to eliminate wrong answers

Option A is wrong because storing a single master key in the hypervisor creates a single point of failure; if the hypervisor is compromised, the attacker can access the master key and decrypt all tenants' data, violating the isolation requirement. Option C is wrong because Mandatory Access Control (MAC) on the hypervisor enforces policy-based access controls but does not protect tenant data if the hypervisor itself is compromised—MAC cannot prevent the hypervisor from reading memory it manages. Option D is wrong because VLANs isolate network traffic at Layer 2, but they do not protect data at rest or in memory; a compromised hypervisor can still access tenant data directly from memory or storage, bypassing network segmentation.

182
MCQeasy

A company uses VLANs to separate traffic between the IT, HR, and Finance departments. A user in the HR VLAN reports that she cannot access a file server located in the IT VLAN. The file server's default gateway is correctly set to the IT VLAN interface. All workstations have correct IP addresses and subnet masks. What is the most likely cause of this issue?

A.Spanning Tree Protocol (STP) is blocking the link between the HR and IT switches.
B.The HR workstation has an incorrect subnet mask.
C.The HR VLAN switch port is incorrectly configured with the wrong VLAN ID.
D.No routing is configured between the HR and IT VLANs.
AnswerD

VLANs are designed to segment a network into distinct Layer 2 broadcast domains, meaning devices in separate VLANs reside on different logical networks. For communication to occur between these isolated VLANs, such as between HR and IT, traffic must be explicitly routed at Layer 3. Without a dedicated router or a Layer 3 switch configured with appropriate routing interfaces (like Switched Virtual Interfaces or SVIs) and routing protocols, packets attempting to traverse VLAN boundaries will be dropped, preventing inter-VLAN connectivity.

Why this answer

VLANs create separate broadcast domains, so traffic between different VLANs must be routed. Since the HR workstation is in a different VLAN than the file server, and no routing is configured between the HR and IT VLANs, the HR workstation cannot reach the file server even though the server's default gateway is correctly set. This is the most likely cause because all other network settings (IP addresses, subnet masks, switch port configurations) are described as correct.

Exam trap

The trap here is that candidates often assume VLANs inherently block all cross-VLAN traffic, but the real issue is the absence of a Layer 3 routing mechanism; VLANs only separate broadcast domains, not routed traffic.

How to eliminate wrong answers

Option A is wrong because Spanning Tree Protocol (STP) blocks redundant links to prevent loops, not to isolate VLAN traffic; STP operates at Layer 2 and does not block links between different VLANs unless a loop exists. Option B is wrong because the question states that all workstations have correct IP addresses and subnet masks, so an incorrect subnet mask is not the issue. Option C is wrong because the question explicitly states that the HR workstation has correct IP settings, and a switch port with the wrong VLAN ID would prevent the workstation from communicating even within its own VLAN, not just across VLANs; the user can access other HR resources, so the port configuration is likely correct.

183
MCQhard

A security architect is designing a network for a high-security data center. The requirement is to ensure that even if an attacker compromises one server, they cannot easily move laterally to other servers in the same data center. Which network design principle should be applied?

A.Principle of least privilege
B.Defense in depth
C.Single point of failure elimination
D.Microsegmentation (e.g., using virtual firewalls on each hypervisor)
AnswerD

Microsegmentation is a network security technique that logically divides a data center or cloud network into distinct, isolated segments down to the individual workload level. By applying granular security policies, often via virtual firewalls or host-based agents, it creates a "zero-trust" environment between applications and servers, significantly limiting an attacker's ability to move laterally across the network even after compromising an initial system.

Why this answer

Microsegmentation (D) is the correct network design principle because it enforces granular, per-workload firewall rules—often implemented via virtual firewalls on each hypervisor or using VXLAN/ACL policies—that restrict east-west traffic between servers. Even if an attacker compromises one server, microsegmentation prevents lateral movement by allowing only explicitly permitted inter-server communication, effectively isolating the breach to the compromised host.

Exam trap

The trap here is that candidates confuse the broad strategy of defense in depth (B) with the specific technical mechanism of microsegmentation, but the question explicitly asks for a network design principle that prevents lateral movement, which is exactly what microsegmentation enforces at the data center network layer.

How to eliminate wrong answers

Option A is wrong because the principle of least privilege governs user and process access rights (e.g., file permissions, RBAC), not network-level isolation between servers; it does not inherently restrict east-west traffic at the network layer. Option B is wrong because defense in depth is a broad security strategy that layers multiple controls (e.g., firewalls, IDS, encryption), but it is not a specific network design principle that directly prevents lateral movement within a data center segment. Option C is wrong because eliminating single points of failure focuses on redundancy and high availability (e.g., dual power supplies, redundant links), not on restricting lateral traffic between servers after a compromise.

184
MCQmedium

During a security assessment, a penetration tester discovers that a web application exposes internal IP addresses in error messages. Which vulnerability category does this represent?

A.Broken access control
B.Sensitive data exposure
C.Security misconfiguration
D.Insecure deserialization
AnswerC

Security misconfiguration is the correct classification because verbose error messages, which reveal internal IP addresses and potentially other system details like software versions or stack traces, are a direct result of improper system hardening. Production environments should be configured to suppress such detailed output, presenting only generic error messages to end-users. This prevents attackers from gathering valuable reconnaissance information that could facilitate further targeted attacks.

Why this answer

Exposing internal IP addresses in error messages is a classic example of a security misconfiguration (C). The web application is likely configured to output detailed error messages (e.g., stack traces or debug information) that include internal network details, which should be suppressed in production environments. This violates the principle of least information disclosure and is categorized under security misconfiguration because it stems from improper default or runtime settings.

Exam trap

The trap here is that candidates confuse the disclosure of internal IP addresses with 'sensitive data exposure' (B), but CISSP categorizes this under security misconfiguration because the root cause is a failure to properly configure error handling, not the inherent sensitivity of the data itself.

How to eliminate wrong answers

Option A is wrong because broken access control refers to failures in enforcing user permissions (e.g., accessing unauthorized resources via path traversal or privilege escalation), not the inadvertent disclosure of internal network information in error outputs. Option B is wrong because sensitive data exposure typically involves the exposure of protected data such as passwords, credit card numbers, or PII, whereas internal IP addresses are not classified as sensitive data under most regulatory frameworks (e.g., GDPR, PCI DSS) unless they reveal system architecture that could aid an attacker. Option D is wrong because insecure deserialization involves the manipulation of serialized objects to execute arbitrary code or bypass authentication, which is unrelated to the verbosity of error messages.

185
Matchingmedium

Match each business continuity term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Maximum acceptable downtime after a disaster

Maximum acceptable data loss measured in time

Average time between system failures

Average time to repair a failed system

Service level agreement defining performance metrics

Why these pairings

Correct matches: RTO defines the acceptable downtime; RPO defines acceptable data loss; MTD is the total tolerable downtime; BIA is the analysis process identifying critical functions. Common confusions involve swapping time-based metrics (RTO/RPO/MTD) or misapplying process terms (BIA).

186
MCQmedium

An organization is implementing a defense-in-depth strategy for its web application. Which of the following is an example of a compensating control?

A.A firewall blocking port 80
B.Regular vulnerability scanning
C.A web application firewall (WAF) blocking SQL injection
D.Two-factor authentication for administrative access
AnswerC

A Web Application Firewall (WAF) blocking SQL injection is an excellent example of a compensating control. It provides an external layer of protection by inspecting HTTP/S traffic and filtering malicious input, thereby mitigating common web application vulnerabilities like SQL injection, even if the underlying application code has deficiencies in input validation or secure coding practices. This external control compensates for internal application weaknesses.

Why this answer

A compensating control is an alternative security measure implemented when a primary control cannot be applied due to technical or business constraints. In this context, a Web Application Firewall (WAF) blocking SQL injection serves as a compensating control when, for example, source code fixes for input validation are not immediately feasible. The WAF inspects HTTP/HTTPS traffic at the application layer (Layer 7) and uses signature-based or behavioral analysis to detect and block malicious SQL patterns, thereby mitigating the vulnerability without modifying the application code.

Exam trap

The trap here is that candidates often confuse compensating controls with preventive or detective controls, mistakenly selecting a direct security measure like a firewall or two-factor authentication as compensating, when in fact a compensating control is specifically an alternative measure used because the primary control cannot be implemented.

How to eliminate wrong answers

Option A is wrong because a firewall blocking port 80 is a preventive control that restricts network traffic, not a compensating control; it directly enforces a security policy by denying HTTP traffic. Option B is wrong because regular vulnerability scanning is a detective control that identifies weaknesses but does not actively mitigate or compensate for a specific control deficiency. Option D is wrong because two-factor authentication for administrative access is a preventive control that strengthens authentication, not a compensating control that substitutes for an existing control that cannot be implemented.

187
MCQeasy

An organization is developing a business continuity plan (BCP). The IT department has identified a critical application that must be restored within 4 hours of a disruption. Which metric defines the maximum acceptable time that the application can be unavailable?

A.Recovery Time Objective (RTO)
B.Recovery Point Objective (RPO)
C.Mean Time to Repair (MTTR)
D.Mean Time Between Failures (MTBF)
E.Service Level Agreement (SLA)
AnswerA

Recovery Time Objective (RTO) is a crucial metric in business continuity planning, representing the maximum tolerable period of time following a disaster or disruption during which a business process or system can be unavailable before unacceptable consequences occur. It dictates how quickly systems and applications must be restored to an operational state to meet defined business requirements. Establishing a precise RTO guides the selection of appropriate recovery strategies and technologies, ensuring alignment with organizational resilience goals.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable downtime for a critical application after a disruption. In this scenario, the IT department has specified that the application must be restored within 4 hours, which directly aligns with the RTO metric. RTO is a key BCP parameter that drives resource allocation and recovery strategy design.

Exam trap

The trap here is confusing RTO with RPO: candidates often pick RPO because they think 'recovery' refers to time, but RPO is about data loss tolerance, not downtime duration.

How to eliminate wrong answers

Option B (Recovery Point Objective) is wrong because RPO defines the maximum acceptable data loss measured in time (e.g., how far back in time data may be lost), not the allowable downtime duration. Option C (Mean Time to Repair) is wrong because MTTR is a reliability metric that measures the average time to repair a failed component, not a predefined target for acceptable downtime. Option D (Mean Time Between Failures) is wrong because MTBF measures the average operational time between failures, used for availability calculations, not for defining recovery time limits.

Option E (Service Level Agreement) is wrong because an SLA is a contractual commitment that may include RTOs, but the RTO itself is the specific metric defining maximum acceptable unavailability.

188
Multi-Selecthard

An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?

Select 3 answers
A.Reviewing logs only after a security incident
B.Log retention policies that comply with legal and regulatory requirements
C.Storing logs in plaintext without access controls
D.Regularly scheduled review of logs for anomalies
E.Centralized log management for aggregation and correlation
AnswersB, D, E

Establishing log retention policies that strictly comply with all applicable legal and regulatory requirements is fundamental for maintaining an organization's security posture and legal standing. These policies ensure that critical audit trails are preserved for forensic investigations, e-discovery, and regulatory audits, demonstrating due diligence and accountability. Proper retention periods prevent premature deletion of evidence while also managing storage costs and data privacy obligations.

Why this answer

Option B is correct because log retention policies must satisfy legal, regulatory, and contractual requirements (e.g., GDPR, HIPAA, PCI DSS, SOX), ensuring logs are kept for the mandated period and disposed of securely afterward. Option D is correct because effective log review requires regularly scheduled reviews, not just reactive ones, so that anomalies, trends, and indicators of compromise can be detected proactively before they escalate. Option E is correct because centralized log management (e.g., via a SIEM or syslog server) aggregates logs from disparate sources, enabling correlation across systems and time synchronization for accurate event reconstruction.

Option A is not appropriate because reviewing logs only after an incident is reactive and misses ongoing threats, while option C is wrong because storing logs in plaintext without access controls exposes sensitive data and violates integrity and confidentiality requirements.

Exam trap

The trap here is that candidates may think reviewing logs only after an incident is sufficient, but the CISSP emphasizes proactive, continuous monitoring as a key security control, not just reactive forensics.

189
Multi-Selecthard

An organization is developing a privacy program. Which THREE of the following are core principles of privacy by design? (Select 3)

Select 3 answers
A.Open data sharing
B.Data minimization
C.Purpose limitation
D.Maximum data retention
E.Storage limitation
AnswersB, C, E

This core privacy principle dictates that organizations must limit the collection of personal data to what is strictly relevant and necessary to accomplish the specified, legitimate processing purposes. By reducing the volume of personally identifiable information (PII) ingested, organizations significantly lower their overall risk profile and potential breach impact.

Why this answer

Data minimization (B) is a core privacy-by-design principle because it requires collecting only the personal data that is adequate, relevant, and necessary for the specified purpose, reducing exposure and risk. Purpose limitation (C) is correct because personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a way incompatible with those purposes. Storage limitation (E) is correct because data should be kept only as long as necessary for the stated purpose, after which it must be deleted or anonymized.

Open data sharing (A) is not a privacy-by-design principle, as unrestricted sharing conflicts with confidentiality and purpose controls, and maximum data retention (D) is the opposite of storage limitation and increases privacy risk.

Exam trap

CISSP often tests the distinction between privacy principles and general data handling concepts; candidates may pick 'open data sharing' or 'maximum data retention' because they sound like data management best practices, but they contradict privacy by design.

190
MCQmedium

A security administrator is configuring a stateful firewall to allow HTTP traffic from the internet to a web server. The firewall uses a default-deny policy. What is the correct rule placement?

A.Place the allow rule after the deny all rule
B.Use a stateless firewall instead
C.Use an implicit deny rule
D.Place the allow rule before the deny all rule
AnswerD

With default-deny, the firewall evaluates rules top-down and stops at the first match. The allow rule for HTTP must precede the deny-all rule, otherwise the deny rule matches first and blocks the permitted web traffic.

Why this answer

In a stateful firewall with a default-deny policy, rules are processed in sequential order from top to bottom. Placing the allow rule before the deny all rule ensures that HTTP traffic (TCP port 80) is explicitly permitted before the catch-all deny rule drops all unmatched packets. If the deny all rule were placed first, all traffic would be dropped, including the intended HTTP traffic, making the allow rule unreachable.

Exam trap

ISC2 often tests the misconception that a default-deny policy automatically allows traffic if a permit rule exists anywhere in the ACL, but in reality, rule order determines which rule is applied first, and a deny all placed before the permit will block all traffic.

How to eliminate wrong answers

Option A is wrong because placing the allow rule after the deny all rule would cause the deny all rule to match and drop all traffic first, rendering the allow rule ineffective and blocking legitimate HTTP traffic. Option B is wrong because a stateless firewall would not track connection state, making it unsuitable for allowing return traffic from the web server without explicit rules for ephemeral ports, whereas a stateful firewall automatically permits return traffic for established connections. Option C is wrong because an implicit deny rule is already the default behavior at the end of the rule set; the question asks for explicit rule placement, and relying solely on implicit deny does not solve the ordering requirement to allow HTTP traffic.

191
MCQeasy

A company has implemented data classification labels such as 'Public', 'Internal', 'Confidential', and 'Restricted'. Which control is most appropriate for protecting 'Confidential' data?

A.Data masking for all users
B.Encryption at rest and in transit
C.Removing all access controls to streamline sharing
D.Public posting on the company website
AnswerB

Encryption at rest and in transit is a foundational security control directly supporting data classification by ensuring confidentiality throughout the data lifecycle. Encryption at rest protects data stored on various media from unauthorized access, even if the storage device is compromised. Encryption in transit safeguards data as it traverses networks, preventing eavesdropping or interception, thereby maintaining the integrity and confidentiality of classified information during transmission between systems or users.

Why this answer

Encryption at rest and in transit is the most appropriate control for protecting 'Confidential' data because it renders the data unreadable to unauthorized parties both when stored on disk (e.g., AES-256) and when transmitted over networks (e.g., TLS 1.3). This directly enforces confidentiality by ensuring that even if an attacker gains access to the storage medium or intercepts network traffic, the data remains protected. Data classification labels like 'Confidential' require strong cryptographic controls to meet the principle of least privilege and compliance mandates such as GDPR or HIPAA.

Exam trap

The trap here is that candidates often pick data masking (Option A) thinking it protects confidentiality, but masking is a de-identification technique for specific use cases like testing, not a primary control for protecting classified data in production.

How to eliminate wrong answers

Option A is wrong because data masking for all users would prevent even authorized users from seeing the actual data, breaking business functionality; masking is typically applied only to non-production environments or specific roles, not universally. Option C is wrong because removing all access controls to streamline sharing would completely undermine confidentiality, exposing 'Confidential' data to anyone and violating the fundamental security principle of least privilege. Option D is wrong because public posting on the company website would make the data accessible to everyone, directly contradicting the need to protect 'Confidential' data and likely violating regulatory requirements.

192
MCQhard

An organization implements a data loss prevention (DLP) solution. Which action is most effective for protecting data at rest on endpoint devices?

A.Encryption of files
B.User awareness training
C.USB port blocking
D.Network DLP monitoring
AnswerA

Encryption of files directly protects data at rest by rendering it unreadable to unauthorized individuals, even if it is successfully exfiltrated from the organization's control. This method ensures that sensitive information remains confidential, providing a critical layer of defense against data breaches where DLP might fail to prevent the initial data movement. It is a foundational technical control for data protection on endpoints.

Why this answer

Encryption of files directly protects data at rest on endpoint devices by rendering the data unreadable without the appropriate decryption key. This ensures that even if an endpoint is lost, stolen, or accessed by an unauthorized user, the data remains confidential. DLP solutions often integrate with file-level encryption (e.g., BitLocker, FileVault, or EFS) to enforce policy-based encryption on sensitive files at rest.

Exam trap

ISC2 often tests the distinction between data states (at rest, in motion, in use) and the specific controls that apply to each; the trap here is that candidates confuse network DLP (data in motion) with endpoint DLP (data at rest), or they select a general security control like user training instead of the direct technical control for data at rest.

How to eliminate wrong answers

Option B is wrong because user awareness training is a preventive administrative control that reduces human error but does not provide a technical mechanism to protect data at rest on endpoints; it addresses behavior, not the data itself. Option C is wrong because USB port blocking is a physical security control that prevents data exfiltration via removable media but does not protect data already stored on the endpoint's hard drive; it addresses data in motion, not data at rest. Option D is wrong because network DLP monitoring inspects data in transit across the network, not data stored locally on endpoint devices; it is effective for data in motion but cannot enforce protection for data at rest on the endpoint.

193
MCQeasy

An organization wants to test its security controls by simulating an attack where the tester has no prior knowledge of the internal network. This is known as a:

A.Grey box test
B.White box test
C.Red team exercise
D.Black box test
AnswerD

A black box test simulates an external attacker with absolutely no prior knowledge of the target system's internal architecture, network topology, or source code. Testers approach the system purely from an outsider's perspective, relying on public information, reconnaissance, and common attack methodologies to discover vulnerabilities. This method directly assesses how well an organization's external defenses would withstand an attack from an unknown, unprivileged adversary.

Why this answer

A black box test (D) is correct because the tester has no prior knowledge of the internal network, simulating an external attacker with zero inside information. This approach evaluates the security controls from an unprivileged, external perspective, relying solely on publicly available information and active reconnaissance. It is the purest form of adversarial simulation for testing perimeter defenses and detection capabilities.

Exam trap

The trap here is confusing the testing methodology (black/grey/white box) with the team structure (red team exercise), leading candidates to select 'Red team exercise' because it sounds like an attack simulation, but the question explicitly defines the knowledge level, not the team composition.

How to eliminate wrong answers

Option A is wrong because a grey box test involves partial knowledge of the internal network, such as network diagrams or credentials, which contradicts the 'no prior knowledge' requirement. Option B is wrong because a white box test provides full knowledge of the internal network, including source code, architecture, and credentials, which is the opposite of the described scenario. Option C is wrong because a red team exercise is a broader, goal-oriented adversarial simulation that may use black, grey, or white box methodologies; the question specifically asks for the type of test based on knowledge level, not the team structure.

194
MCQeasy

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

A.$10,000
B.$100,000
C.$50,000
D.$20,000
AnswerA

This value represents the Annualized Loss Expectancy (ALE), which is derived by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $50,000 and an ARO of 0.2 (meaning a 20% chance of the event occurring annually), the correct ALE calculation is $50,000 * 0.2, resulting in $10,000. This figure quantifies the expected financial loss from a specific risk over a one-year period.

Why this answer

The annualized loss expectancy (ALE) is calculated as single loss expectancy (SLE) multiplied by annualized rate of occurrence (ARO). SLE is asset value ($100,000) times exposure factor (0.5), yielding $50,000. Multiplying by ARO (0.2) gives ALE = $50,000 * 0.2 = $10,000.

Thus, $10,000 is the correct answer.

Exam trap

CISSP often tests the mistake of confusing SLE with ALE or forgetting to multiply by ARO; candidates may incorrectly use asset value directly or omit the exposure factor.

How to eliminate wrong answers

Option B ($100,000) is wrong because it represents the full asset value, not the expected annual loss. Option C ($50,000) is wrong because it is the SLE, not adjusted for ARO. Option D ($20,000) is wrong because it incorrectly multiplies asset value by ARO without applying the exposure factor.

195
MCQmedium

A security architect is designing a zero-trust network. Which principle is fundamental to a zero-trust architecture (ZTA) such as BeyondCorp?

A.Never trust, always verify
B.Trust but verify
C.Trust internal users implicitly
D.Trust network location as a primary factor
AnswerA

Never trust, always verify requires every request to be authenticated and authorised based on identity, device posture and context, regardless of network location. This eliminates implicit trust from network position, the foundational principle underlying BeyondCorp's zero-trust architecture.

Why this answer

In a zero-trust architecture (ZTA) like Google's BeyondCorp, the foundational principle is 'never trust, always verify.' This means no entity—user, device, or network—is trusted by default, regardless of its location (inside or outside the corporate perimeter). Every access request must be authenticated, authorized, and continuously validated before granting access to resources, eliminating implicit trust based on network location.

Exam trap

The trap here is that candidates may confuse 'trust but verify' (a common security mantra) with zero-trust, but the key distinction is that zero-trust removes all implicit trust, including for internal users and devices.

How to eliminate wrong answers

Option B is wrong because 'trust but verify' still assumes an initial level of trust, which contradicts zero-trust's requirement of no implicit trust; it is a legacy perimeter-based model. Option C is wrong because trusting internal users implicitly is the opposite of zero-trust, which treats all users as potential threats until verified. Option D is wrong because zero-trust explicitly rejects network location as a primary factor for trust; instead, it relies on identity, device health, and context for access decisions.

196
MCQmedium

A security analyst discovers an attack where an attacker sets up a rogue wireless access point with a legitimate SSID to trick users into connecting. Once connected, the attacker captures credentials. This type of attack is known as:

A.Deauthentication attack
B.Rogue AP attack
C.Evil twin attack
D.Karma attack
AnswerC

An evil twin attack specifically involves an attacker setting up a malicious access point that mimics the SSID (Service Set Identifier) and often the MAC address of a legitimate, trusted wireless network. The objective is to trick unsuspecting users into connecting to the fraudulent AP, believing it to be the authentic network. Once connected, the attacker can intercept traffic, capture login credentials through fake portals, or launch further attacks, making it a highly effective method for credential harvesting.

Why this answer

This is an evil twin attack because the attacker creates a rogue access point that broadcasts the same SSID as a legitimate network, tricking users into connecting to it. Once connected, the attacker can capture credentials or other sensitive data by acting as a man-in-the-middle. The key differentiator is the impersonation of a legitimate SSID to deceive users, not just the presence of an unauthorized AP.

Exam trap

The trap here is that candidates confuse 'rogue AP' (any unauthorized AP) with 'evil twin' (a specific type of rogue AP that impersonates a legitimate SSID), leading them to choose option B instead of C.

How to eliminate wrong answers

Option A is wrong because a deauthentication attack involves sending deauth frames (typically from a tool like aireplay-ng) to disconnect clients from a legitimate AP, often as a precursor to an evil twin attack, but it is not the attack itself. Option B is wrong because a rogue AP attack is a broader category that includes any unauthorized AP on the network, but it does not specifically require the AP to impersonate a legitimate SSID to trick users; a rogue AP might simply be a misconfigured or malicious device connected to the wired network. Option D is wrong because a Karma attack exploits the probe request behavior of wireless clients that automatically connect to any network with a previously saved SSID, but it does not involve setting up an AP with a legitimate SSID to trick users; instead, it responds to any probe request with a matching SSID.

197
MCQeasy

Which of the following is an example of a security policy?

A.Step 1: Log in, Step 2: Enter code, Step 3: Access system
B.It is recommended to change passwords every 90 days
C.All employees must use multi-factor authentication
D.Use passwords of at least 12 characters with mixed case and numbers
AnswerC

A security policy is a high-level, mandatory statement issued by management that defines the organization's overall security objectives and requirements. This statement clearly dictates a non-negotiable requirement for all employees, establishing a foundational security control to protect organizational assets. It addresses *what* is required for security, without specifying the technical implementation details.

Why this answer

A security policy is a high-level statement of management intent that mandates required behavior. 'All employees must use multi-factor authentication' is a directive, organization-wide requirement, which is the defining characteristic of a policy.

Exam trap

The trap is confusing a standard with a policy — candidates pick D because it sounds security-related, but specific password rules are a standard, while a policy is a mandatory high-level directive.

How to eliminate wrong answers

Option A is wrong because it describes a procedure — a step-by-step operational instruction for performing a task. Option B is wrong because 'It is recommended' indicates a guideline or best practice, not a mandatory policy; policies use mandatory language like 'must' or 'shall'. Option D is wrong because it specifies a technical standard (password length and complexity), which is a standard or baseline, not a policy statement.

198
MCQmedium

A security architect is designing a system for a government agency that requires strict confidentiality controls. Data must be classified at multiple levels (e.g., Top Secret, Secret, Confidential). Users at a lower classification should not be able to read data at a higher classification, and users at a higher classification should not be able to write data to a lower classification. Which security model enforces these rules?

A.Biba model
B.Clark-Wilson model
C.Brewer-Nash model
D.Bell-LaPadula model
AnswerD

The Bell-LaPadula model is a state machine model designed specifically to enforce confidentiality in systems handling classified information, such as those used by governments. It prevents unauthorized disclosure by implementing two core rules: the Simple Security Property ("no read up") and the *-Property ("no write down"). These rules ensure that subjects can only access information at or below their security clearance level and cannot write information to a lower security level, thus preventing information flow to less secure domains.

Why this answer

The Bell-LaPadula model is specifically designed for confidentiality and enforces two core rules: the Simple Security Property (no read up — a subject at a lower classification cannot read data at a higher classification) and the *-Property (no write down — a subject at a higher classification cannot write to a lower classification). These exactly match the government agency's requirements.

Exam trap

CISSP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates mix up the direction of the rules or pick Biba because both are 'multi-level' models.

How to eliminate wrong answers

Option A is wrong because the Biba model is the integrity-focused counterpart to Bell-LaPadula — it enforces no read down and no write up to protect data integrity, not confidentiality. Option B is wrong because the Clark-Wilson model focuses on integrity through well-formed transactions and separation of duties, using access triplets (subject, program, object), and does not address multi-level confidentiality classifications. Option C is wrong because the Brewer-Nash model (Chinese Wall) prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by static classification levels.

199
Multi-Selecthard

Which THREE are key components of a business continuity plan (BCP)?

Select 3 answers
A.Vendor risk assessments
B.Backup strategies
C.Recovery time objectives (RTOs)
D.System hardening standards
E.Emergency response procedures
AnswersB, C, E

Backup strategies are fundamental components of a Business Continuity Plan, detailing the systematic process of creating and storing copies of critical data and systems. These strategies specify backup frequency, storage locations (on-site, off-site, cloud), retention policies, and the methods for restoring data, ensuring the availability and integrity of information required for business operations post-disruption.

Why this answer

Backup strategies (B) are a core BCP component because they define how data and systems are preserved and restored so critical operations can resume after disruption. Recovery time objectives (C) are essential because they set the maximum acceptable downtime for each business function, driving recovery priorities and resource allocation. Emergency response procedures (E) belong in a BCP because they specify the immediate actions, roles, and communications needed to protect people and stabilize operations during an incident.

Vendor risk assessments (A) are more closely tied to third-party risk management, and system hardening standards (D) are technical security controls, so neither is one of the three key BCP components in this scenario.

Exam trap

ISC2 often tests the distinction between BCP components (recovery-focused) and security controls (prevention-focused), so candidates mistakenly select vendor assessments or hardening standards because they sound like 'planning' activities.

200
MCQeasy

A security engineer notices that the IKE phase 1 lifetime is set to 3600 seconds. What is a potential security implication?

A.Longer lifetimes reduce rekeying overhead
B.Shorter lifetimes increase performance
C.Short lifetimes may cause frequent reauthentication and potential disruption
D.The lifetime should be at least 86400 seconds
AnswerC

Short IKE Phase 1 lifetimes necessitate frequent reauthentication, which significantly increases the operational overhead and the potential for service disruption. Each rekeying attempt presents an opportunity for failure due to network issues, misconfigurations, or resource exhaustion on either endpoint. Such frequent re-establishment of the secure channel can lead to intermittent connectivity problems or complete outages if the reauthentication process repeatedly fails, impacting availability and user experience.

Why this answer

IKE phase 1 establishes a secure authenticated channel for subsequent IKE phase 2 negotiations. A lifetime of 3600 seconds (1 hour) is relatively short, causing frequent reauthentication. This can lead to service disruption if the rekeying process fails or if the VPN peers experience transient network issues, potentially dropping active tunnels and impacting production traffic.

Exam trap

ISC2 often tests the trade-off between security and availability: candidates may incorrectly assume shorter lifetimes are always more secure without considering the operational risk of frequent reauthentication causing tunnel drops.

How to eliminate wrong answers

Option A is wrong because longer lifetimes reduce rekeying overhead, but the question asks for a security implication of the given short lifetime, not a benefit of longer lifetimes. Option B is wrong because shorter lifetimes do not increase performance; they increase computational overhead and latency due to more frequent Diffie-Hellman exchanges and authentication. Option D is wrong because there is no mandatory minimum of 86400 seconds (24 hours); RFC 7296 recommends a default of 3600 seconds for IKEv1 phase 1, and shorter lifetimes can actually improve security by limiting exposure of the session key, though they risk disruption.

201
MCQmedium

Under GDPR, which of the following is a valid lawful basis for processing personal data?

A.Corporate policy
B.Profit motive
C.Marketing preference
D.Vital interests
AnswerD

Vital interests is a lawful basis under GDPR Article 6(1)(d) that permits the processing of personal data when it is necessary to protect the life of the data subject or another natural person. This basis is typically invoked in emergency situations where obtaining consent is impossible or impractical, such as medical emergencies, humanitarian crises, or public health threats. It represents a very high threshold and is generally reserved for situations involving a serious threat to life or physical integrity, making it a basis of last resort rather than routine processing.

Why this answer

GDPR Article 6(1) lists six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests. 'Vital interests' is one of these — it covers processing necessary to protect someone's life.

Exam trap

CISSP often tests whether candidates can distinguish the six GDPR lawful bases from business justifications, and the trap is picking 'legitimate interests'-sounding answers like 'profit motive' or 'corporate policy' that are not enumerated in Article 6.

How to eliminate wrong answers

Option A is wrong because 'corporate policy' is not a GDPR lawful basis — an internal policy cannot override the need for a legal ground under Article 6. Option B is wrong because 'profit motive' is not a lawful basis; commercial gain falls under 'legitimate interests' only if balanced against data subject rights, and even then it is not the same as a profit motive per se. Option C is wrong because 'marketing preference' is not a lawful basis — marketing typically relies on consent or legitimate interests, and a preference alone does not satisfy Article 6.

202
MCQeasy

A medium-sized financial services company has a flat network topology with no segmentation between the corporate LAN and the server farm. The security team recently deployed a host-based intrusion detection system (HIDS) on all critical servers. Over the past week, the HIDS has generated multiple high-severity alerts indicating outbound connections from a database server to an external IP address in a foreign country, occurring every hour and lasting only a few seconds. The database server contains sensitive customer data. The company's incident response plan (IRP) has not been updated in two years, and the CISO wants to ensure a response that minimizes business disruption while protecting data. The IT team is small, and the security analyst on duty suspects a data exfiltration attempt but is unsure. What should the analyst do FIRST?

A.Disconnect the database server from the network at the switch port and preserve the system state for forensic analysis
B.Run a full antivirus scan on the database server and update the HIDS signatures
C.Review the firewall logs to identify all external IPs the server has contacted
D.Immediately notify the company's legal department and public relations team
AnswerA

Disconnecting the database server at the switch port immediately halts any ongoing data exfiltration or malicious activity, achieving critical containment. Preserving the system state, through memory capture or disk imaging, ensures that volatile evidence and forensic artifacts are maintained for subsequent detailed analysis without alteration by continued network access or system changes. This action prioritizes stopping the active breach and securing evidence for a thorough investigation.

Why this answer

The immediate priority is to contain the suspected data exfiltration by isolating the database server from the network, which stops the outbound connections and preserves volatile evidence for forensic analysis. Disconnecting at the switch port (e.g., via `shutdown` interface command) is a rapid, reversible action that minimizes business disruption compared to pulling the power cable, and it aligns with the incident response phase of containment before eradication or recovery. The HIDS alerts indicate a persistent, short-lived outbound connection pattern, which strongly suggests a beaconing or data-stealing malware that must be contained first to prevent further data loss.

Exam trap

The trap here is that candidates may choose Option C (review firewall logs) because they think gathering evidence first is the correct incident response step, but the CISSP emphasizes containment as the immediate priority when there is an active, ongoing threat of data exfiltration.

How to eliminate wrong answers

Option B is wrong because running a full antivirus scan and updating HIDS signatures is a detection and remediation step that should occur after containment; it does not stop the ongoing outbound connections and may alert the attacker if the malware detects the scan. Option C is wrong because reviewing firewall logs to identify external IPs is a forensic analysis step that should be performed after containment; delaying containment to gather logs allows the potential exfiltration to continue. Option D is wrong because immediately notifying legal and PR teams is premature without first confirming the incident and containing the threat; such notification is part of the post-containment communication phase and could cause unnecessary business disruption or panic.

203
MCQmedium

A company is designing a recovery site for its critical database. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which of the following replication strategies is BEST suited?

A.Asynchronous replication to a warm site
B.Full backups every 24 hours to a cold site
C.Weekly snapshots to a warm site
D.Synchronous replication to a hot site
AnswerD

Synchronous replication ensures that data is written to both the primary and recovery sites simultaneously, guaranteeing zero data loss (RPO of near zero) in the event of a primary site failure. Coupled with a hot site, which is fully equipped with active hardware, network, and data, this configuration allows for immediate failover with minimal downtime, effectively meeting stringent Recovery Time Objectives (RTOs) for critical systems.

Why this answer

Synchronous replication writes data to both the primary and the hot site simultaneously, ensuring zero data loss upon failover. With an RPO of 15 minutes, synchronous replication can meet this requirement because it commits transactions at both sites before acknowledging completion. A hot site is fully configured and ready to take over within the RTO of 2 hours, making this combination the best fit.

Exam trap

The trap here is that candidates often choose asynchronous replication (Option A) thinking it is sufficient for a 15-minute RPO, but they overlook that asynchronous replication can have variable lag that may exceed the RPO, especially under high write loads or network congestion.

How to eliminate wrong answers

Option A is wrong because asynchronous replication introduces a replication lag that can exceed the 15-minute RPO, as data is sent in batches and may not be fully current at the recovery site. Option B is wrong because full backups every 24 hours to a cold site cannot meet the 15-minute RPO (potential data loss of up to 24 hours) and the cold site would require significant time to restore, likely exceeding the 2-hour RTO. Option C is wrong because weekly snapshots provide a recovery point that is up to 7 days old, far exceeding the 15-minute RPO, and a warm site may require additional configuration time that could jeopardize the 2-hour RTO.

204
Multi-Selectmedium

Which TWO of the following are examples of types of security assessments?

Select 2 answers
A.Vulnerability scan
B.Firewall rule review
C.Password policy enforcement
D.Antivirus update
E.Penetration test
AnswersA, E

A vulnerability scan is an automated process that identifies known weaknesses or misconfigurations in systems, networks, or applications. It typically uses specialized software to detect potential security flaws without actively exploiting them, providing a report of identified vulnerabilities that could be exploited by attackers. This proactive assessment helps organizations understand their exposure to risks and prioritize remediation efforts.

Why this answer

A vulnerability scan (A) is a recognized type of security assessment because it systematically probes hosts, services, and applications for known weaknesses using signature/CVE-based checks, producing a report of findings. A penetration test (E) is also a security assessment type, as it goes beyond scanning by actively exploiting vulnerabilities under a defined scope and rules of engagement to demonstrate real-world impact. The other options are operational or administrative controls rather than assessment types: a firewall rule review (B) is a configuration audit of one control, password policy enforcement (C) is a preventive administrative control, and antivirus update (D) is routine maintenance of a protective tool.

Exam trap

Candidates often confuse security assessments (active evaluation of security posture, such as vulnerability scans and penetration tests) with security controls or operational tasks (such as installing firewalls, enforcing policies, or updating antivirus definitions), which are management or maintenance activities.

205
MCQeasy

A security professional is tasked with testing the effectiveness of security controls in a production environment without causing disruption. Which type of assessment should be performed?

A.Penetration test
B.Red team exercise
C.Vulnerability scan
D.Social engineering test
AnswerC

A vulnerability scan is an automated, non-intrusive assessment that identifies known security weaknesses, misconfigurations, and missing patches in systems and applications. It passively checks for indicators of vulnerabilities without attempting to exploit them, making it a safe and efficient method for regularly assessing technical controls in production environments without causing disruption.

Why this answer

A vulnerability scan is the correct choice because it is a non-intrusive, automated assessment that identifies known vulnerabilities (e.g., missing patches, misconfigurations) by comparing system states against a database of CVEs and configuration benchmarks (e.g., CIS benchmarks). It does not exploit vulnerabilities or generate attack traffic, making it safe for production environments. In contrast, penetration tests and red team exercises involve active exploitation and simulated attacks that risk service disruption.

Exam trap

The trap here is that candidates often confuse a vulnerability scan with a penetration test, assuming both involve active exploitation, but the key distinction is that a vulnerability scan is passive and non-destructive, while a penetration test is active and potentially disruptive.

How to eliminate wrong answers

Option A is wrong because a penetration test involves active exploitation of vulnerabilities to gain unauthorized access, which can cause system crashes, data corruption, or service interruptions in a production environment. Option B is wrong because a red team exercise is a full-scope, adversarial simulation that includes social engineering, physical breaches, and active exploitation, all of which carry a high risk of disrupting operations. Option D is wrong because a social engineering test targets human behavior (e.g., phishing emails, pretexting calls) and does not directly assess the effectiveness of technical security controls such as firewalls, IDS/IPS, or patch management.

206
MCQhard

An organization is implementing privacy by design in a new application that collects user location data. Which practice best aligns with the data minimization principle?

A.Encrypting location data both at rest and in transit
B.Anonymizing location data after collection
C.Obtaining explicit consent from users before collection
D.Collecting location data only when the app is actively in use
AnswerD

This approach directly embodies the 'data minimization' principle of Privacy by Design by ensuring that location data is only acquired when it is essential for the application's active functionality. By limiting collection to periods of active use, the organization significantly reduces the overall volume of sensitive personal data held, thereby mitigating potential privacy risks and demonstrating a proactive commitment to user privacy.

Why this answer

Data minimization means collecting only the data that is necessary for the specified purpose. Collecting location data only when the app is actively in use limits collection to the minimum needed for the app's functionality, directly aligning with the principle.

Exam trap

CISSP often tests the distinction between data minimization (collect less) and other privacy controls like encryption, consent, or anonymization, which do not reduce collection scope.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest and in transit is a security control that protects confidentiality but does not reduce the amount of data collected; it addresses protection, not minimization. Option B is wrong because anonymizing data after collection still involves collecting the full data set first; minimization requires limiting collection at the source, not transforming it afterward. Option C is wrong because obtaining explicit consent is a transparency and legal basis requirement, not a minimization practice; consent does not reduce the volume or scope of data collected.

207
MCQeasy

Which of the following is the primary purpose of a security assessment?

A.To identify and evaluate security risks
B.To fix all vulnerabilities
C.To achieve compliance with regulations
D.To punish non-compliant employees
AnswerA

A security assessment systematically examines an organization's information systems, processes, and infrastructure to pinpoint vulnerabilities and potential threats. Its primary goal is to analyze the likelihood of these threats exploiting identified weaknesses and the potential impact, thereby quantifying the associated risks to organizational assets. This comprehensive evaluation informs strategic decision-making for effective risk treatment and resource allocation.

Why this answer

A security assessment's primary purpose is to systematically identify and evaluate security risks by analyzing assets, threats, vulnerabilities, and existing controls. This aligns with the NIST SP 800-115 framework, which defines assessment as the process of determining how effectively an entity is meeting specific security objectives, not as a remediation or enforcement activity.

Exam trap

The trap here is that candidates confuse the assessment phase with the remediation phase, assuming the primary goal is to fix vulnerabilities, when in fact the assessment stops at identification and evaluation.

How to eliminate wrong answers

Option B is wrong because fixing all vulnerabilities is the goal of remediation or vulnerability management, not the assessment itself; assessment only identifies and evaluates, leaving remediation to subsequent processes. Option C is wrong because achieving compliance is a possible outcome or driver, but the primary purpose is risk identification and evaluation, not merely meeting regulatory checklists. Option D is wrong because punishing non-compliant employees is a disciplinary action unrelated to the technical evaluation of security posture; assessments focus on systems and processes, not personnel discipline.

208
MCQhard

A network engineer is configuring an IPsec VPN in tunnel mode. Which IPsec protocol provides both authentication and encryption of the entire IP packet?

A.ESP (Encapsulating Security Payload)
B.IKE (Internet Key Exchange)
C.ISAKMP
D.AH (Authentication Header)
AnswerA

ESP encapsulates the original IP packet and applies both confidentiality and integrity, encrypting the payload and authenticating it. AH only authenticates and cannot encrypt, so ESP is the protocol satisfying the requirement for authentication plus encryption of the entire packet.

Why this answer

ESP (Encapsulating Security Payload) in tunnel mode provides both authentication and encryption for the entire original IP packet, including the original header and payload. It encapsulates the packet with a new IP header and ESP trailer, ensuring confidentiality via encryption and integrity via authentication. This makes it the correct choice for a VPN requiring both security services.

Exam trap

A common pitfall is thinking AH (Authentication Header) provides encryption because it offers authentication, but AH only ensures integrity and origin authentication—it does not encrypt. For both authentication and encryption, ESP must be used.

How to eliminate wrong answers

Option B (IKE) is wrong because IKE is a key exchange protocol used to establish security associations (SAs) for IPsec, not a protocol that directly provides authentication and encryption of IP packets. Option C (ISAKMP) is wrong because ISAKMP defines the framework for key exchange and SA negotiation, but it does not itself encrypt or authenticate packets; it relies on protocols like IKE for actual keying material. Option D (AH) is wrong because AH provides authentication and integrity but no encryption, so it cannot encrypt the entire IP packet as required by the question.

209
MCQeasy

Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?

A.Legal counsel
B.Incident manager
C.Forensic investigator
D.Communications lead
AnswerD

The Communications Lead is the designated individual primarily responsible for developing and executing the incident communication strategy. This critical role involves crafting accurate, timely, and consistent messages for all internal and external stakeholders, including employees, customers, partners, regulators, and the media. They manage public relations, coordinate press releases, and ensure that all official statements align with the incident response objectives and organizational values.

Why this answer

The communications lead is the incident response team role specifically tasked with managing all external and internal communications, including press releases, media inquiries, and regulator notifications. This role ensures a single, consistent message and prevents unauthorized disclosures. Legal counsel, the incident manager, and forensic investigators have different primary responsibilities that do not center on external communications.

Exam trap

The trap is conflating 'legal counsel' with 'communications lead' — candidates may assume lawyers handle regulator communication, but the communications lead owns the messaging while legal counsel provides legal guidance.

How to eliminate wrong answers

Option A (Legal counsel) is wrong because legal counsel advises on legal obligations, privilege, and regulatory interpretation but does not own the communication channel with media or regulators. Option B (Incident manager) is wrong because the incident manager coordinates the overall response effort and resource allocation, not the drafting and delivery of external communications. Option C (Forensic investigator) is wrong because the forensic investigator collects, preserves, and analyzes evidence; communicating with the media or regulators is outside that scope.

210
MCQmedium

An organization is implementing network segmentation. They need to place publicly accessible servers (e.g., web and email) in a separate network that is isolated from the internal LAN but still allows controlled access from the internet. Which architecture should they use?

A.DMZ
B.Micro-segmentation
C.VPN
D.VLAN
AnswerA

A Demilitarized Zone (DMZ) is a perimeter network designed to host public-facing services, such as web servers or email servers, that need to be accessible from the internet while protecting the internal private network. It acts as a buffer zone, typically secured by two firewalls, allowing controlled inbound and outbound traffic to specific services without exposing the internal LAN directly to external threats. This architecture provides a critical layer of security by isolating public assets from the internal network.

Why this answer

A DMZ (demilitarized zone) is a network segment that sits between the internet and the internal LAN, hosting publicly accessible servers like web and email. It uses firewall rules to allow inbound traffic from the internet to the DMZ servers while blocking direct access to the internal network, and typically permits only specific outbound responses or updates from the DMZ to the internal LAN. This architecture provides the isolation and controlled access required by the scenario.

Exam trap

The trap here is that candidates confuse VLANs with DMZs, assuming that a VLAN alone provides security isolation from the internet, when in fact VLANs only segment Layer 2 traffic and require additional firewall rules to control access—unlike a DMZ which is specifically designed for public-facing servers with explicit security policies.

How to eliminate wrong answers

Option B (Micro-segmentation) is wrong because it focuses on granular east-west traffic control within a data center or internal network using software-defined policies, not on isolating public-facing servers from the internet and internal LAN. Option C (VPN) is wrong because it creates an encrypted tunnel for remote users to access an internal network, not for hosting publicly accessible servers with controlled internet access. Option D (VLAN) is wrong because it segments traffic at Layer 2 within a broadcast domain but does not inherently provide security isolation or firewall-based access control from the internet; a VLAN alone cannot enforce the required inbound/outbound filtering.

211
MCQmedium

A security analyst is reviewing a web application and notices that it includes a feature that allows users to view their own profile by providing a user ID in the URL (e.g., /profile?userid=123). The application does not verify that the logged-in user owns that profile. Which vulnerability is present?

A.Security misconfiguration
B.Cross-site scripting (XSS)
C.Insecure direct object reference (IDOR)
D.Cross-site request forgery (CSRF)
AnswerC

Insecure direct object reference (IDOR) occurs when a web application exposes a direct reference to an internal implementation object, such as a file, directory, or database key, and fails to verify that the user is authorized to access that object. Attackers can manipulate these references, often found in URL parameters or form fields, to access or modify data belonging to other users or system files. The scenario directly aligns with an IDOR vulnerability, as it involves bypassing authorization by directly referencing an object.

Why this answer

The application exposes an internal object reference (the userid parameter) and fails to perform an authorization check that the logged-in user owns that object. This is the textbook definition of an Insecure Direct Object Reference (IDOR), classified under OWASP as Broken Access Control (A01:2021). Because the URL directly maps to a backend record without an ownership check, an attacker can simply increment the userid value to view other users' profiles.

Exam trap

CISSP often tests the distinction between IDOR (missing object-level authorization) and CSRF (forged request using victim's session) — candidates confuse the two because both involve manipulating requests, but only IDOR exposes a direct object reference without an ownership check.

How to eliminate wrong answers

Option A is wrong because security misconfiguration refers to insecure defaults, verbose errors, or unnecessary features enabled (e.g., default credentials, directory listing), not a missing authorization check on an object reference. Option B is wrong because XSS involves injecting malicious client-side script that executes in another user's browser, whereas here the flaw is server-side access control, not script injection. Option D is wrong because CSRF tricks an authenticated user's browser into sending an unwanted request using their existing session; in this scenario the attacker is directly manipulating an object identifier, not forging a request via a victim's session.

212
MCQmedium

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

A.High risk
B.Medium risk
C.Low risk
D.De minimis risk
AnswerA

In a qualitative risk assessment, "High risk" is assigned when both the likelihood of a threat event occurring and the potential impact of that event on organizational assets or operations are rated as high or critical. This combination signifies a significant exposure that demands immediate attention and substantial resource allocation for mitigation, as the potential for severe damage is both probable and substantial.

Why this answer

In a qualitative risk matrix, likelihood and impact ratings are combined to produce an overall risk level. A 'High' likelihood paired with a 'Critical' impact sits at the top of the matrix and is classified as High risk, warranting immediate treatment. Lower combinations (e.g., High likelihood + Low impact) would map to Medium or Low.

Exam trap

CISSP often tests the risk matrix combination logic; candidates overthink and pick Medium assuming 'averaging' of High and Critical, when the matrix maps the highest likelihood-impact pair to High risk.

How to eliminate wrong answers

Option B is wrong because Medium risk results from moderate combinations such as High likelihood with Low/Medium impact or Medium likelihood with Medium impact — not High + Critical. Option C is wrong because Low risk corresponds to low likelihood and/or low impact combinations. Option D is wrong because 'de minimis' risk refers to a negligible level below Low, which cannot result from the highest likelihood and highest impact ratings.

213
MCQeasy

An organization wants to implement a password policy that balances security and usability. Which of the following is the BEST practice according to current NIST guidelines?

A.Compare new passwords against a list of known compromised passwords
B.Set maximum password length to 8 characters
C.Require password changes every 30 days
D.Enforce a minimum of one uppercase, one lowercase, one digit, and one special character
AnswerA

Comparing new passwords against a list of known compromised passwords, often referred to as a "blacklist" or "denylist," is a highly effective modern security practice. This method prevents users from selecting passwords that have already been exposed in data breaches, significantly mitigating the risk of credential stuffing attacks where attackers try known username/password combinations across multiple services. By proactively blocking weak or compromised credentials, organizations enhance their overall security posture without imposing burdensome complexity rules on users. This approach directly addresses the widespread problem of password reuse.

Why this answer

NIST SP 800-63B explicitly recommends checking passwords against a list of known compromised passwords (e.g., from previous breaches) rather than enforcing arbitrary complexity rules. This approach directly mitigates credential stuffing and dictionary attacks by rejecting passwords that have already been exposed, while avoiding user frustration from frequent changes or complex composition requirements.

Exam trap

The trap here is that many candidates cling to outdated complexity rules (Option D) or frequent rotation (Option C) because they were once considered security best practices, but NIST now prioritizes breach-checking and longer, memorable passwords over arbitrary composition and expiry.

How to eliminate wrong answers

Option B is wrong because setting a maximum password length to 8 characters contradicts NIST guidance, which recommends a minimum of 8 characters but encourages longer passwords (up to 64 characters or more) to resist brute-force attacks. Option C is wrong because mandatory password changes every 30 days are discouraged by NIST SP 800-63B; frequent changes often lead to weaker passwords and are only recommended when there is evidence of compromise. Option D is wrong because enforcing complex composition rules (uppercase, lowercase, digit, special character) is no longer considered a best practice by NIST; such rules often result in predictable patterns (e.g., 'Password1!') and do not effectively defend against modern attacks like credential stuffing.

214
MCQmedium

A remote user at 203.0.113.5 cannot access the internal web server at 10.0.0.10 over HTTPS. What is the most likely cause of the denial?

A.The ACL is missing a permit rule for the user's IP
B.The ACL is applied in the wrong direction
C.The firewall is not performing stateful inspection
D.The web server is not listening on port 443
AnswerA

Access Control Lists (ACLs) process rules sequentially, and if no explicit permit rule matches, traffic is implicitly denied by the ACL's default "deny all" at the end. Since the existing permit rule only specifies 203.0.113.2, traffic originating from 203.0.113.5 will not match this specific rule. Consequently, the packet from 203.0.113.5 proceeds to the implicit deny, preventing access to the internal web server.

Why this answer

The user at 203.0.113.5 is attempting to reach the internal web server over HTTPS (TCP/443). If a firewall with an ACL is implemented to control this traffic, the most direct cause of a silent denial for a specific user is the absence of an explicit permit rule for that user's source IP. Because ACLs process rules sequentially and end with an implicit deny, any traffic not explicitly permitted will be dropped.

Exam trap

Candidates often overthink firewall issues and select complex answers like directionality (Option B) or stateful inspection failures (Option C), when the most common and likely administrative oversight is simply forgetting to add a permit rule for the specific host or subnet in the ACL.

How to eliminate wrong answers

Option B is wrong because applying an ACL in the wrong direction (e.g., inbound vs. outbound) would cause traffic to be filtered incorrectly, but the question states the user cannot access the server at all, which is more consistent with a missing permit rule than a directional misapplication that might still allow some traffic. Option C is wrong because stateful inspection is a feature that tracks connection state; even without stateful inspection, a stateless ACL with a proper permit rule would allow the HTTPS traffic. Option D is wrong because if the web server were not listening on port 443, the user would receive a connection refused (RST) or timeout, not a denial caused by an ACL; the question implies a silent drop, which is characteristic of ACL filtering.

215
MCQmedium

An organization requires a commercial integrity model where users cannot modify data in higher integrity levels and cannot read data from lower integrity levels. Which model should they implement?

A.Bell-LaPadula
B.Clark-Wilson
C.Biba
D.Take-Grant
AnswerC

The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity by enforcing a strict hierarchical integrity policy. Its primary rules are 'no write up' (Simple Integrity Property) and 'no read down' (*-Integrity Property), which prevent subjects from writing to objects of higher integrity or reading from objects of lower integrity. This model ensures that high-integrity data is not contaminated by low-integrity data, making it ideal for scenarios requiring strong data trustworthiness.

Why this answer

The Biba integrity model is the classic commercial integrity model that enforces 'no write up, no read down' — users cannot modify data at a higher integrity level and cannot read data at a lower integrity level. This exactly matches the scenario described, making Biba the correct choice.

Exam trap

CISSP often tests the mirror-image confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up), so candidates who memorize only one direction pick the wrong model.

How to eliminate wrong answers

Option A is wrong because Bell-LaPadula is a confidentiality model with the inverse rules ('no read up, no write down'), which protects secrecy rather than integrity. Option B is wrong because Clark-Wilson is an integrity model based on well-formed transactions and separation of duties, not on hierarchical integrity levels with read/write restrictions. Option D is wrong because Take-Grant is a model of access-right propagation and delegation, not an integrity enforcement model.

216
MCQmedium

A security analyst discovers that a business unit is storing sensitive data on a file share without classification labels. What is the first step to remediate?

A.Move the data to a secure server
B.Immediately delete the data
C.Notify the data owner to classify the data
D.Encrypt the file share
AnswerC

Notifying the data owner is the most appropriate first step because the data owner is ultimately accountable for the data's protection, including its classification. Classification dictates the appropriate security controls (e.g., encryption, access controls, retention policies) required to protect the data's confidentiality, integrity, and availability. Without proper classification, any security measures implemented would be based on assumptions rather than defined organizational policy and risk appetite, potentially leading to misallocated resources or inadequate protection.

Why this answer

The first step in remediating unclassified sensitive data is to notify the data owner, who is responsible for assigning classification labels based on organizational policy. Without classification, subsequent security controls (e.g., encryption, access controls) cannot be correctly applied because the data's sensitivity level is unknown. This aligns with the CISSP principle that data classification must precede protection mechanisms.

Exam trap

The trap here is that candidates often jump to technical controls (encryption, moving data) instead of recognizing that classification is a prerequisite governance step, as emphasized in the CISSP Asset Security domain.

How to eliminate wrong answers

Option A is wrong because moving data to a secure server without first classifying it may misapply controls (e.g., over- or under-protection) and does not address the root cause of missing labels. Option B is wrong because immediately deleting data violates data retention policies and could destroy business-essential information without authorization. Option D is wrong because encrypting the file share without classification may apply inappropriate cryptographic strength or key management, and encryption does not resolve the missing classification labels required for proper data governance.

217
MCQhard

A security manager is evaluating risk treatment options for a high-impact, low-probability risk. Which approach is most appropriate?

A.Transfer
B.Accept
C.Avoid
D.Mitigate
AnswerA

Risk transfer involves shifting the financial burden of a potential loss to a third party, typically through insurance policies or contractual agreements with vendors. While the organization retains ultimate accountability for the risk, the financial impact of a catastrophic yet rare event is absorbed by the insurer or service provider. This strategy is particularly effective for high-impact, low-probability risks where the cost of complete mitigation is prohibitive, but the potential loss is too great to accept.

Why this answer

Transfer is the most appropriate approach for a high-impact, low-probability risk because it shifts the financial burden of a rare but severe event to a third party, such as through cyber insurance or outsourcing. This aligns with the risk management principle that low-probability, high-impact risks are often uneconomical to mitigate fully, making transfer a cost-effective strategy. For example, purchasing a cyber liability policy with specific coverage for data breaches ensures the organization does not bear the full recovery cost.

Exam trap

The trap here is that candidates often choose 'Mitigate' because they assume all high-impact risks require active reduction, failing to recognize that transfer is a distinct and often more cost-effective strategy for low-probability events.

How to eliminate wrong answers

Option B (Accept) is wrong because accepting a high-impact risk without active treatment is imprudent; acceptance is reserved for low-impact risks where the cost of treatment exceeds the potential loss. Option C (Avoid) is wrong because avoidance would require eliminating the activity causing the risk, which may not be feasible or strategic for a low-probability event that could still yield significant business benefits. Option D (Mitigate) is wrong because mitigation involves implementing controls to reduce likelihood or impact, but for a low-probability, high-impact risk, the cost of mitigation often outweighs the benefit, making transfer more efficient.

218
MCQhard

An organization is decommissioning a data center. Which of the following is the most secure method for sanitizing hard drives that will be reused?

A.Physical destruction
B.Deleting all files
C.Overwriting with random data multiple times
D.Quick format
AnswerC

Overwriting the entire storage medium with random data multiple times is a highly effective and recognized method for data sanitization. This process ensures that residual magnetic or electrical traces of previous data are thoroughly obscured, making data recovery practically impossible even with advanced forensic techniques, thereby preparing the media for secure reuse.

Why this answer

Overwriting with random data multiple times (option C) is the most secure method for sanitizing hard drives that will be reused because it ensures that the original data is irrecoverable through any known forensic technique. Unlike physical destruction, which renders the drive unusable, or file deletion and quick format, which only remove file system pointers and leave data intact, multiple-pass overwriting (e.g., using the DoD 5220.22-M standard) writes patterns over every sector, including remapped sectors, making the original data unrecoverable even with advanced magnetic force microscopy.

Exam trap

The trap here is that candidates often choose 'Physical destruction' because it seems most secure, but they overlook the explicit requirement that the drives will be reused, making destruction invalid.

How to eliminate wrong answers

Option A is wrong because physical destruction (e.g., shredding or degaussing) permanently damages the drive, preventing reuse, which contradicts the requirement that the drives will be reused. Option B is wrong because deleting all files only removes directory entries and marks clusters as available; the actual data remains on the platters and can be easily recovered with file recovery tools. Option D is wrong because a quick format only rewrites the file system metadata (e.g., boot sector and FAT) and does not touch the data areas, leaving all user data intact and recoverable.

219
MCQeasy

A healthcare organization must decommission a server containing protected health information (PHI). Which data sanitization method ensures the data is irrecoverable while complying with regulatory requirements?

A.Reformat the hard drive with a quick format
B.Degauss the hard drive
C.Physically shred the hard drive
D.Overwrite the hard drive with a single pass of zeros
AnswerC

Physically shredding the hard drive is an extremely effective method for data destruction, as it mechanically breaks the platters into tiny, unrecoverable fragments. While this method undeniably destroys all data and meets stringent regulatory requirements for PHI disposal, it is an irreversible process that prevents any potential reuse of the drive or its components. Compared to degaussing, which can also destroy data effectively, shredding represents a more absolute and typically more costly form of destruction.

Why this answer

Physical destruction, such as shredding, is the most secure method of data sanitization (the 'Destroy' level in NIST SP 800-88). It physically breaks the media into tiny pieces, ensuring that data is completely irrecoverable. This is the most compliant method under regulations like HIPAA for decommissioning assets containing PHI.

Degaussing (Option B) is only effective for magnetic media (HDDs) and is completely ineffective on Solid-State Drives (SSDs), which are common in modern servers. Overwriting (Option D) and formatting (Option A) do not meet the strict destruction standards required for decommissioning high-sensitivity PHI assets.

Exam trap

Candidates often choose degaussing as the default 'strong' destruction method, but CISSP tests the understanding that degaussing only works on magnetic media. For modern servers that likely contain SSDs, physical destruction (shredding) is the only method that guarantees complete sanitization across all media types.

How to eliminate wrong answers

Option A is wrong because a quick format only clears the file system index (e.g., MFT or FAT), leaving the actual PHI data intact on the disk and easily recoverable with tools like TestDisk or Recuva. Option C is wrong because physically shredding the hard drive, while destructive, is not a data sanitization method per NIST SP 800-88 Rev. 1 (which classifies it as 'destroy' for disposal, not 'clear' or 'purge') and may not be practical for verifying complete data destruction in a regulatory audit. Option D is wrong because a single pass of zeros (overwrite) is considered 'clear' by NIST SP 800-88, which is insufficient for PHI under HIPAA; it leaves residual magnetic signatures that can be recovered using magnetic force microscopy (MFM) or other advanced techniques, and is only acceptable for non-sensitive data.

220
MCQmedium

A financial institution is implementing a data classification policy. Which role is responsible for assigning initial classification labels to data assets?

A.Data custodian
B.Data processor
C.Data owner
D.Data steward
AnswerC

The data owner holds ultimate accountability for the data's value, sensitivity, and the impact its compromise could have on the organization. They are responsible for defining the data classification levels and assigning the appropriate classification to specific datasets based on business criticality, regulatory requirements, and potential risk. This decision dictates the security controls and protection measures required throughout the data lifecycle.

Why this answer

The data owner is the senior manager or business stakeholder who has ultimate accountability for a data asset and is responsible for determining its classification level based on business impact and sensitivity. In the CISSP framework, the data owner defines the classification labels (e.g., Public, Internal, Confidential, Restricted) at the time of creation or acquisition, ensuring the asset is tagged according to the organization's data classification policy. This role does not handle the technical implementation but sets the initial classification, which then drives downstream controls like encryption and access control lists (ACLs).

Exam trap

ISC2 often tests the distinction between data owner and data custodian, trapping candidates who confuse the 'owner' as the person who physically handles the data (custodian) rather than the person who has accountability for classification and risk acceptance.

How to eliminate wrong answers

Option A is wrong because the data custodian is responsible for implementing and maintaining technical controls (e.g., encryption, backups, access enforcement) based on the classification assigned by the data owner, not for assigning the initial classification label. Option B is wrong because the data processor is a third-party entity that processes data on behalf of the data controller under a contract, typically in cloud or outsourcing scenarios, and has no authority to assign classification labels—that remains with the data owner. Option D is wrong because the data steward focuses on data quality, metadata management, and compliance with data governance rules, but does not have the authority to assign initial classification labels; that decision is reserved for the data owner who bears the risk.

221
MCQmedium

In an OAuth 2.0 authorization code flow with PKCE, what is the primary purpose of the code verifier and code challenge?

A.To encrypt the authorization code
B.To authenticate the end user
C.To ensure the client that requested the code is the same one redeeming it
D.To generate the ID token
AnswerC

This statement accurately describes the core purpose of PKCE. By requiring the client to generate a `code_verifier` and send a transformed `code_challenge` at the beginning of the flow, then present the original `code_verifier` when redeeming the authorization code, PKCE ensures that only the client that initiated the request can successfully exchange the code for tokens. This mechanism effectively prevents authorization code interception attacks, where a malicious application might steal the code and impersonate the legitimate client.

Why this answer

In OAuth 2.0 authorization code flow with PKCE, the code verifier and code challenge are used to prove that the client redeeming the authorization code is the same client that initiated the authorization request. The client generates a random code verifier, hashes it to create the code challenge, sends the challenge with the authorization request, and later sends the verifier with the token request — the authorization server verifies they match. This prevents authorization code interception attacks, especially for public clients.

Exam trap

The trap is assuming PKCE encrypts the authorization code or authenticates the user; candidates who don't understand that PKCE binds the code to the requesting client pick options about encryption or user authentication.

How to eliminate wrong answers

Option A is wrong because PKCE does not encrypt the authorization code; the code is still transmitted as-is, and PKCE adds a proof-of-possession check, not encryption. Option B is wrong because PKCE does not authenticate the end user — user authentication is handled by the authorization server (e.g., via login credentials or federation), and PKCE is about client verification. Option D is wrong because the ID token is generated by the OpenID Connect provider as part of authentication, not by PKCE; PKCE does not generate or influence the ID token.

222
MCQeasy

An internet-facing Apache web server is running version 2.4.49 and is vulnerable to CVE-2021-41773 path traversal. What is the most urgent remediation?

A.Disable directory listing
B.Upgrade to Apache 2.4.51 or later
C.Recompile Apache with security flags
D.Apply a WAF rule to block path traversal attempts
AnswerB

Upgrading to Apache HTTP Server version 2.4.50 or later is the most direct and effective remediation for known path traversal vulnerabilities, specifically CVE-2021-41773 and CVE-2021-42013. These patched versions contain specific code fixes that correctly normalize paths and prevent directory traversal sequences from being misinterpreted by the server's core logic. This approach permanently resolves the vulnerability at its source by eliminating the underlying software flaw.

Why this answer

CVE-2021-41773 was patched in Apache 2.4.50, but CVE-2021-42013 demonstrated an incomplete fix affecting 2.4.50. The complete remediation is to upgrade to Apache 2.4.51 or later, which closes the path traversal and RCE vector. Disabling directory listing, recompiling with security flags, or adding a WAF rule are compensating controls, not the most urgent remediation.

Exam trap

ISC2 exams focus on the most complete and effective remediation. A WAF rule or configuration change may reduce exposure but does not fix the underlying vulnerable code; the most urgent action is upgrading to a fully patched version such as Apache 2.4.51 or later.

How to eliminate wrong answers

Option A is wrong because disabling directory listing addresses information disclosure but does not fix the underlying path traversal or RCE vulnerability in Apache 2.4.49; it is a secondary hardening step. Option C is wrong because recompiling Apache with security flags does not patch the specific CVE-2021-41773 flaw in the shipped binary; the vulnerability is in the source code logic of `mod_cgi` and `util_path.c`, which requires a version upgrade. Option D is wrong because applying a WAF rule to block path traversal attempts is a compensating control, not a remediation; it can be bypassed with encoding variations and does not eliminate the root cause in the Apache server itself.

223
MCQmedium

An organization is developing a business continuity plan (BCP) for its critical IT systems. Which of the following is the FIRST step in the BCP process?

A.Identify recovery strategies for critical systems.
B.Conduct a business impact analysis (BIA) to prioritize critical business functions.
C.Develop a testing schedule for the BCP.
D.Perform a risk assessment to identify potential threats.
AnswerB

Conducting a Business Impact Analysis (BIA) is the foundational and initial step in developing a robust Business Continuity Plan (BCP). The BIA systematically identifies and prioritizes an organization's critical business functions and processes, quantifying the potential financial and operational impacts of their disruption. This analysis establishes crucial metrics like Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), which are indispensable for guiding all subsequent BCP activities, including strategy selection and resource allocation.

Why this answer

The first step in the BCP process is to conduct a Business Impact Analysis (BIA) to identify and prioritize critical business functions and their dependencies. Without the BIA, you cannot determine which systems require recovery strategies or what recovery time objectives (RTOs) and recovery point objectives (RPOs) are needed. The BIA provides the quantitative and qualitative basis for all subsequent BCP decisions.

Exam trap

The trap here is that candidates often confuse the risk assessment (which identifies threats) with the BIA (which identifies business impact), but the BCP process explicitly begins with the BIA to prioritize business functions before addressing threats or recovery strategies.

How to eliminate wrong answers

Option A is wrong because identifying recovery strategies comes after the BIA has established which systems are critical and their specific recovery requirements. Option C is wrong because developing a testing schedule is a later phase, performed after the BCP has been written and approved. Option D is wrong because performing a risk assessment is a separate, earlier process that feeds into the overall risk management framework, but the BCP specifically starts with the BIA to understand business impact, not just threats.

224
MCQeasy

Which component of the AAA framework is responsible for determining what resources a user can access and what actions they can perform?

A.Auditing
B.Authentication
C.Accounting
D.Authorization
AnswerD

Authorization is the critical component of the AAA framework responsible for determining what actions an authenticated user or system is permitted to perform on a resource. After identity verification, authorization mechanisms consult policies and access control lists (ACLs) to decide "what you are allowed to do," granting or denying specific privileges based on the user's role, group membership, or other attributes. This directly addresses the question of defining permissions.

Why this answer

Authorization is the AAA component that determines what resources a user can access and what actions they can perform after identity has been verified. It evaluates access policies, group memberships, and permissions to grant or deny specific operations. Authentication proves identity, accounting tracks activity, and auditing reviews logs — none of these define access rights.

Exam trap

CISSP often tests the distinction between authentication (identity verification) and authorization (access rights), causing candidates to confuse 'who you are' with 'what you can do'.

How to eliminate wrong answers

Option A is wrong because auditing is the retrospective review of logs and events to verify compliance and detect anomalies, not the real-time granting of access rights. Option B is wrong because authentication only verifies the identity of a user (e.g., via password, token, or biometrics) and does not determine what that user is permitted to do. Option C is wrong because accounting (also called auditing in some frameworks) tracks resource consumption and session activity for billing or forensic purposes, not access decisions.

225
MCQhard

A multinational company must comply with the EU General Data Protection Regulation (GDPR) for processing personal data of EU citizens. The company's data protection officer (DPO) has been appointed but reports to the Chief Marketing Officer (CMO). Which compliance issue is most critical?

A.The DPO should not hold any other role within the organization
B.The DPO must be a lawyer certified in data protection
C.The DPO must be located in the EU
D.The DPO must report directly to the board of directors or CEO
AnswerD

GDPR Article 38(3) explicitly mandates that the Data Protection Officer (DPO) must directly report to the highest management level of the controller or processor. This direct reporting line, typically to the board of directors or CEO, is fundamental to ensuring the DPO's independence and authority within the organization. It enables the DPO to perform their duties without undue influence and ensures their recommendations on data protection are given due consideration by strategic decision-makers.

Why this answer

Under the GDPR, the Data Protection Officer (DPO) must report directly to the highest level of management, typically the board of directors or CEO, to ensure independence and authority. Reporting to the Chief Marketing Officer (CMO) creates a conflict of interest because the CMO oversees marketing activities that often involve extensive personal data processing, compromising the DPO's ability to provide unbiased oversight. This structural subordination is the most critical compliance issue as it directly undermines the DPO's statutory role under Article 38(3) of the GDPR.

Exam trap

The trap here is that candidates often focus on the DPO's qualifications or location (options B and C) because those are commonly discussed in GDPR training, but the most critical issue is the DPO's independence and reporting line, which directly impacts their ability to enforce compliance without conflict of interest.

How to eliminate wrong answers

Option A is wrong because the GDPR does not prohibit the DPO from holding other roles; it only requires that those roles do not create a conflict of interest (Article 38(6)). Option B is wrong because the GDPR does not mandate that the DPO be a lawyer or hold any specific certification; it requires expertise in data protection law and practices (Article 37(5)). Option C is wrong because the GDPR does not require the DPO to be physically located in the EU; the DPO can be outside the EU as long as they are accessible and can effectively perform their duties (Article 37(2) and EDPB guidelines).

Page 2

Page 3 of 11

Page 4

All pages