Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 226–300

816 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQhard

A medium-sized financial services company recently deployed a new identity governance and administration (IGA) solution to manage user access across on-premises Active Directory and cloud-based SaaS applications. The IGA system uses a role-based access control (RBAC) model with hundreds of roles defined. The company has a policy that all access certifications must be completed quarterly. During the first quarterly certification, the access reviewers complain that they are overwhelmed by the number of entitlements they need to review, and many certifications are not completed on time. The security team also notices that some users have accumulated excessive privileges because role assignments were not properly reviewed. The company wants to streamline the certification process without sacrificing security. Which of the following is the BEST course of action?

A.Increase the certification frequency to monthly and assign more reviewers
B.Eliminate role-based access and assign permissions directly to users
C.Implement a risk-based certification approach that focuses on high-risk access and uses automated certification for low-risk access
D.Automate all certifications by using scripts that approve access if no violations are detected
AnswerC

Implementing a risk-based certification approach is the most effective strategy for managing extensive entitlement reviews by intelligently prioritizing human effort. High-risk access, such as privileged accounts or access to sensitive data, receives thorough manual scrutiny, ensuring critical security controls are meticulously maintained. Conversely, low-risk, routine access can be efficiently certified through automated processes, significantly reducing reviewer fatigue and operational costs while still meeting compliance requirements for regular access reviews and maintaining overall security.

Why this answer

A risk-based certification approach prioritizes high-risk entitlements for manual review while automating the certification of low-risk access, reducing reviewer fatigue and ensuring critical privileges are scrutinized. This aligns with the principle of 'defense in depth' and addresses the core issue of overwhelming certification volume without compromising security, as low-risk access can be certified based on predefined policies and automated workflows.

Exam trap

The trap here is that candidates may choose option D (automate all certifications) because it seems efficient, but they overlook the critical requirement for human oversight in high-risk access decisions, which is a core principle of identity governance and audit compliance.

How to eliminate wrong answers

Option A is wrong because increasing certification frequency to monthly would exacerbate reviewer overload and likely lead to even more incomplete certifications, as it increases the volume of reviews without addressing the root cause of excessive entitlements. Option B is wrong because eliminating role-based access and assigning permissions directly to users would abandon the RBAC model entirely, leading to a chaotic, unmanageable permission structure that violates the principle of least privilege and increases security risk. Option D is wrong because automating all certifications with scripts that approve access if no violations are detected removes human oversight entirely, which could allow inappropriate access to persist if violations are not detected by the scripts, undermining the certification process's purpose of ensuring proper access governance.

227
MCQeasy

A security analyst is tasked with identifying vulnerabilities in a web application that is still in development. The application code is not yet stable, and frequent changes are expected. Which testing approach would be most appropriate to identify vulnerabilities without hindering the development process?

A.Fuzz testing
B.Manual penetration testing
C.Static application security testing (SAST)
D.Dynamic application security testing (DAST)
AnswerC

Static Application Security Testing (SAST) analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program. This method allows for early detection of flaws during the development lifecycle, often integrated directly into the Continuous Integration/Continuous Delivery (CI/CD) pipeline. SAST tools can identify a wide range of vulnerabilities, including SQL injection, cross-site scripting, and buffer overflows, by examining code patterns and ensuring adherence to secure coding standards before deployment.

Why this answer

Static Application Security Testing (SAST) is the most appropriate approach because it analyzes source code, byte code, or binary code without executing the application, making it ideal for early-stage development where code is unstable and frequently changing. SAST can be integrated into the development pipeline (e.g., as a pre-commit hook or CI/CD step) to identify vulnerabilities like SQL injection, XSS, or buffer overflows without requiring a running application or hindering the iterative development process.

Exam trap

The trap here is that candidates often choose DAST (Option D) because they associate 'dynamic' with 'real-world testing,' but they overlook the critical constraint that the application is unstable and in development, making SAST the only viable option that does not require a running application.

How to eliminate wrong answers

Option A is wrong because fuzz testing is a dynamic testing technique that requires a running, stable application to inject malformed or unexpected inputs, which is not feasible when the code is unstable and frequently changing. Option B is wrong because manual penetration testing is a time-intensive, point-in-time assessment that relies on a functional, deployed application and would significantly hinder the development process due to the need for a stable environment and repeated retesting after each code change. Option D is wrong because Dynamic Application Security Testing (DAST) requires a fully running application to scan for vulnerabilities from the outside (e.g., via HTTP requests), and it cannot be effectively performed on an unstable, in-development application that may not even compile or run correctly.

228
Multi-Selectmedium

When implementing a federated identity management system, which TWO components are essential for establishing trust between Identity Provider and Service Provider? (Select two.)

Select 2 answers
A.Metadata exchange
B.User directory synchronization
C.Single logout
D.Shared secret
E.Public key certificates
AnswersA, E

Metadata exchange is crucial for establishing trust in a federated identity management system because it provides a standardized way for identity providers (IdPs) and service providers (SPs) to share configuration information. This metadata, typically an XML document, includes essential details such as entity IDs, endpoint URLs for various services (e.g., SSO, SLO), and critically, the public key certificates used for signing and encryption. This exchange allows entities to automatically configure their trust relationships, validate digital signatures on assertions, and encrypt communications, forming the foundational basis for secure authentication.

Why this answer

Metadata exchange (A) is essential because the IdP and SP must exchange XML metadata documents describing their entity IDs, endpoints (SSO, SLO), supported bindings, and signing/encryption certificates before any assertion can be trusted. Public key certificates (E) are essential because the SP validates the IdP's digital signature on SAML assertions (or the IdP validates tokens) using the IdP's public key, establishing cryptographic trust; the private key never leaves the IdP. Together, metadata exchange distributes the certificates and endpoint configuration that make signature verification and secure message routing possible.

User directory synchronization (B) is not required — federated identity relies on just-in-time provisioning or attribute statements rather than replicating directories. Single logout (C) is a session-management convenience, not a trust-establishment requirement. Shared secret (D) applies to symmetric schemes like WS-Security or OAuth client secrets, but SAML federation trust is built on asymmetric keys and metadata, not a shared secret.

Exam trap

The trap here is that candidates confuse operational components like user synchronization or session management with the foundational trust-establishing mechanisms, forgetting that federated trust relies on cryptographic verification through metadata and certificates, not shared secrets or directory replication.

229
Multi-Selectmedium

A company is planning to conduct a penetration test. Which THREE of the following should be included in the rules of engagement?

Select 3 answers
A.The tester's personal contact information
B.Emergency stop criteria
C.Definition of the scope (systems to be tested)
D.Written authorization from management
E.Specific vulnerabilities to be exploited
AnswersB, C, D

Emergency stop criteria are crucial elements within the Rules of Engagement, defining specific conditions under which the penetration test must be immediately halted. These criteria typically include scenarios such as causing a critical system outage, corrupting production data, triggering an organization-wide incident response, or exceeding predefined resource utilization thresholds. Establishing these clear boundaries ensures that the testing activities do not inflict unacceptable damage or operational disruption to the target environment.

Why this answer

Emergency stop criteria define the conditions under which the penetration test must be immediately halted, such as causing a production system outage or detecting unauthorized data access. This is a critical component of the rules of engagement (RoE) to ensure the test does not cause unacceptable business impact, aligning with the principle of minimizing risk during security assessments.

Exam trap

The trap here is that candidates often confuse the rules of engagement with the test plan or methodology, mistakenly including operational details like specific vulnerabilities or personal contact information, when the RoE is strictly about boundaries, authorization, and safety constraints.

230
MCQmedium

A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?

A.Biometric authentication
B.Step-up authentication
C.Single-factor authentication
D.Multi-factor authentication
AnswerD

Multi-factor authentication (MFA) is the correct choice because it precisely describes an authentication system that requires a user to present two or more independent authentication factors from different categories to verify their identity. By combining distinct types, such as 'something you know' (e.g., a password) and 'something you have' (e.g., a token or smart card), MFA significantly enhances security. This approach ensures that even if one factor is compromised, unauthorized access is prevented due to the requirement for a second, different factor.

Why this answer

Multi-factor authentication (MFA) requires two or more different categories of authentication factors: something you know (password), something you have (hardware token), and something you are (biometric). Here, the password is a knowledge factor and the one-time code from a hardware token is a possession factor, satisfying the definition of MFA. Because the factors come from distinct categories, this is not single-factor or step-up authentication.

Exam trap

CISSP often tests the distinction between authentication factors and the misconception that any two authentication steps constitute MFA, when they must be from different categories.

How to eliminate wrong answers

Option A is wrong because biometric authentication relies on something you are (e.g., fingerprint, retina), and no biometric factor is mentioned in the scenario. Option B is wrong because step-up authentication refers to increasing the authentication assurance level when accessing more sensitive resources, not the initial login method described. Option C is wrong because single-factor authentication would require only one factor (e.g., just a password), but the scenario uses two distinct factors.

231
MCQmedium

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

A.Warm site
B.Cold site
C.Hot site
D.Reciprocal agreement
AnswerC

A hot site is a fully operational, mirrored facility that replicates the primary production environment with identical hardware, software, and up-to-date data, often synchronized in real-time. This comprehensive setup allows for immediate failover in the event of a disaster, ensuring minimal data loss and near-zero downtime. A hot site achieves the lowest Recovery Time Objective (RTO) and Recovery Point Objective (RPO), making it the optimal choice for critical applications requiring continuous availability and rapid business continuity.

Why this answer

A hot site is a fully operational duplicate of the primary environment with real-time or near-real-time data replication, so it can take over almost immediately. This yields the shortest RTO (minutes) and RPO (near zero) of the options listed, at the highest cost.

Exam trap

The trap is assuming a reciprocal agreement is fast because it is a formal arrangement — candidates pick D, but reciprocal agreements offer poor RTO/RPO because capacity and readiness are not guaranteed.

How to eliminate wrong answers

Option A is wrong because a warm site has hardware and some data but requires configuration and restoration before it can operate, giving an RTO of hours to days and a higher RPO. Option B is wrong because a cold site is just space and power with no pre-installed equipment, resulting in the longest RTO (days to weeks) and RPO. Option D is wrong because a reciprocal agreement is a mutual arrangement with another organization to use their facilities in an emergency; it is unreliable, hard to test, and typically offers poor RTO/RPO because capacity and compatibility are not guaranteed.

232
MCQhard

You are the chief information security officer (CISO) of a large healthcare organization that handles protected health information (PHI). The organization has recently been acquired by a larger conglomerate, and the new parent company mandates that all subsidiaries adopt a single, unified risk management framework based on NIST SP 800-39. Your current framework is ISO 27005-based and has been effective for years. During the transition, you discover that the parent company's framework requires quantitative risk analysis for all critical assets, while your team has been primarily using qualitative analysis due to lack of accurate financial data. Moreover, the parent company expects all risk assessments to be completed within 30 days, a timeframe your team considers unrealistic given the number of assets. Several key stakeholders are concerned about the additional resource burden and potential disruption to operations. You need to propose a course of action that balances compliance with the parent company's mandate while maintaining operational effectiveness and minimizing risk to patient data.

A.Conduct a gap analysis between ISO 27005 and NIST SP 800-39, then develop a phased transition plan with a longer timeline, presenting it to the parent company's board for approval.
B.Continue using ISO 27005 and argue that it is equally valid, citing the principle of risk management flexibility and the disruption that a transition would cause.
C.Hire external consultants to perform the quantitative assessments, allowing the internal team to focus on existing operations, and accept the cost as a business necessity.
D.Immediately adopt the NIST framework and begin quantitative assessments, using industry-standard cost estimates to expedite the process within 30 days.
AnswerA

A gap analysis between ISO 27005 and NIST SP 800-39 is a critical first step to identify specific differences in risk management methodologies, control sets, and reporting requirements. Developing a phased transition plan allows for systematic integration, training, and resource allocation, minimizing operational disruption while ensuring thorough adoption. Presenting this strategic roadmap to the parent company's board secures essential executive buy-in, funding, and alignment with overall corporate governance and risk appetite.

Why this answer

The best course of action is to conduct a gap analysis between the current ISO 27005 framework and the mandated NIST SP 800-39, then propose a phased transition plan with a realistic timeline. This balances compliance with the parent company's mandate while addressing the team's concerns about the 30-day timeframe and resource burden. Presenting it to the board for approval ensures executive buy-in and allows for negotiation of the timeline.

Exam trap

CISSP often tests the balance between compliance and operational reality — candidates may choose the most compliant option (immediate adoption) without considering feasibility, or the most operational option (continue ISO) without considering the mandate.

How to eliminate wrong answers

Option B is wrong because refusing to adopt the parent company's mandate is not a viable option — it ignores the acquisition reality and the parent company's authority. Option C is wrong because hiring external consultants to perform quantitative assessments may help with resources but does not address the unrealistic 30-day timeline or the need for a structured transition; it also does not ensure knowledge transfer. Option D is wrong because immediately adopting the framework and using industry-standard cost estimates within 30 days is unrealistic and risks inaccurate risk assessments, which could lead to poor decisions and potential patient data risk.

233
MCQeasy

In a public key infrastructure (PKI), which component is responsible for issuing and revoking digital certificates?

A.Registration Authority (RA)
B.Certificate Authority (CA)
C.Certificate Revocation List (CRL)
D.Validation Authority (VA)
AnswerB

The Certificate Authority signs and publishes certificates, binding a public key to an identity, and maintains the CRL or OCSP responder for revocation. No other PKI component holds both issuing and revoking authority, satisfying the stem's dual requirement.

Why this answer

The Certificate Authority (CA) is the trusted entity in a PKI that issues digital certificates by signing them with its private key, and it also revokes certificates by publishing Certificate Revocation Lists (CRLs) or using the Online Certificate Status Protocol (OCSP). The CA is the authoritative source for certificate lifecycle management, including issuance, renewal, and revocation.

Exam trap

The trap here is confusing the Registration Authority (RA) with the Certificate Authority (CA), as the RA performs identity verification but candidates often mistakenly think it also issues certificates.

How to eliminate wrong answers

Option A is wrong because the Registration Authority (RA) is only responsible for verifying the identity of certificate requestors and forwarding requests to the CA; it does not issue or revoke certificates itself. Option C is wrong because the Certificate Revocation List (CRL) is a data structure published by the CA that lists revoked certificates, not an entity that performs issuance or revocation actions. Option D is wrong because the Validation Authority (VA) is an optional component that validates certificate status (e.g., via OCSP responder) but does not issue or revoke certificates.

234
MCQeasy

A company must comply with a regulation requiring a formal, independent assessment of its security controls against a standard. Which type of assessment is MOST appropriate?

A.Penetration test
B.Security audit
C.Security review
D.Vulnerability assessment
AnswerB

A security audit is a formal, independent, and systematic examination of an organization's security controls, processes, and policies against a specific set of criteria, such as regulatory requirements or industry standards. It involves evidence collection, analysis, and reporting to determine the extent of compliance and the effectiveness of controls. This structured, evidence-based approach, conducted by independent parties, is precisely what a regulation requiring a formal comparison of controls to a standard demands.

Why this answer

A security audit is the most appropriate assessment because it is a formal, independent evaluation of an organization's security controls against a predefined standard (e.g., ISO 27001, NIST SP 800-53). Unlike other assessments, an audit is conducted by an independent third party or internal audit function, providing objective evidence of compliance with regulatory requirements.

Exam trap

The trap here is that candidates confuse a security audit with a penetration test or vulnerability assessment, mistakenly thinking that technical exploitation is required for compliance, when the regulation specifically demands an independent evaluation against a standard, not a technical attack simulation.

How to eliminate wrong answers

Option A is wrong because a penetration test is an authorized simulated attack to exploit vulnerabilities, not a formal assessment of controls against a standard; it focuses on identifying exploitable weaknesses rather than compliance. Option C is wrong because a security review is typically an informal, internal evaluation (e.g., peer review or design review) that lacks the independence and formal structure required for regulatory compliance. Option D is wrong because a vulnerability assessment is an automated or manual scan to identify and list vulnerabilities (e.g., missing patches, misconfigurations), but it does not evaluate controls against a specific standard or provide an independent compliance opinion.

235
MCQmedium

A security team is reviewing a web application that allows users to search for products. The application uses a SQL database and constructs queries by concatenating user input directly into the SQL statement. Which of the following is the most effective mitigation against SQL injection attacks?

A.Using parameterized queries with prepared statements
B.Escaping all user input before concatenation
C.Input validation using a blacklist of known malicious patterns
D.Implementing a Web Application Firewall (WAF)
AnswerA

Parameterized queries with prepared statements are the most effective defense against SQL injection because they fundamentally separate the SQL code structure from user-provided data. The database engine treats all input as literal values, not executable commands, preventing malicious input from altering the query's intent. This architectural separation ensures that special characters in user input are never interpreted as SQL syntax, thereby eliminating the injection vector at its root.

Why this answer

Parameterized queries with prepared statements separate SQL logic from user input by sending the query structure to the database first, then binding input values as data parameters. This prevents the database from interpreting user input as executable SQL code, even if the input contains malicious characters. It is the only defense that completely eliminates the injection vector at the database interaction layer.

Exam trap

The trap here is that candidates often choose input validation or escaping because they seem proactive, but the CISSP exam emphasizes that parameterized queries are the only definitive defense against SQL injection at the code level, as they enforce separation of code and data by design.

How to eliminate wrong answers

Option B is wrong because escaping user input is error-prone and context-dependent; an attacker can bypass escaping if the escape function is not perfectly aligned with the database's character set or query context (e.g., using alternate encodings or second-order injection). Option C is wrong because blacklist-based input validation can be circumvented by obfuscation techniques (e.g., using hex, Unicode, or case variations) and fails to block novel or unknown attack patterns. Option D is wrong because a WAF operates at the network or application layer and can only detect known attack signatures; it cannot prevent injection if the underlying code still concatenates input, and it can be bypassed by encoding or timing attacks.

236
MCQmedium

An organization is required to declassify a document that was previously classified as 'Secret' under government guidelines. What process must be followed before the document can be released to the public?

A.The data owner must reclassify it as 'Unclassified' without further action
B.The document can be released immediately after the classification period expires
C.A declassification review by authorized personnel must be conducted
D.The document should be shredded and a new version created without classified markings
AnswerC

This option is correct because declassification is a formal, systematic process that mandates a thorough review by personnel specifically authorized for this task. This review ensures that the information no longer meets the criteria for classification and that its release will not compromise national security, privacy, or other protected interests. It's a critical safeguard against inadvertent disclosure of still-sensitive data and ensures compliance with declassification policies.

Why this answer

Declassification under government guidelines (e.g., EO 13526 in the US, or equivalent national frameworks) requires a formal declassification review by authorized personnel before any classified material can be released. The review verifies whether the information still warrants protection, whether exemptions apply, and whether any portions must remain redacted. Only after this review and approval can the document be downgraded or released to the public.

Exam trap

CISSP often tests the misconception that classification automatically expires into public release or that a data owner can unilaterally declassify — the exam expects you to know that a formal declassification review by authorized personnel is mandatory.

How to eliminate wrong answers

Option A is wrong because a data owner cannot unilaterally reclassify a Secret document as Unclassified — declassification requires review by designated declassification authorities under the governing classification policy, not just an owner's decision. Option B is wrong because classification periods (e.g., 10, 25 years) trigger a review, not automatic release; documents may be reclassified or have exemptions extended. Option D is wrong because shredding and recreating a document does not declassify the underlying information — the same content remains classified regardless of the physical artifact, and this would constitute an unauthorized destruction of classified material.

237
MCQhard

An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?

A.Archive
B.Use
C.Create/Collect
D.Share
AnswerA

Archiving is the process of moving data that is no longer actively used but must be retained for compliance, legal, or historical purposes to a separate, often less expensive, long-term storage system. This phase directly implements data retention policies by ensuring data is stored securely and immutably for its mandated lifecycle, distinct from active operational storage.

Why this answer

The Archive phase of the data lifecycle is where data retention policies are enforced, because this is the stage where data is moved to long-term storage and governed by retention schedules, legal holds, and disposition rules. Retention policies define how long data must be kept and when it must be securely destroyed, and these controls are applied at the archive stage. Without proper archival governance, data may be retained indefinitely or destroyed prematurely, violating regulatory requirements.

Exam trap

CISSP often tests the misconception that retention policies are enforced at data creation or use, when in fact they are enforced during the Archive phase where lifecycle governance and disposition controls reside.

How to eliminate wrong answers

Option B (Use) is wrong because the Use phase concerns active access, processing, and application of data — retention duration is not determined here. Option C (Create/Collect) is wrong because this is the point of data origination, where classification and labeling begin, but retention periods are not yet enforced. Option D (Share) is wrong because sharing governs data transfer and disclosure to third parties, not how long data is retained or when it is destroyed.

238
MCQhard

During an internal audit, an organization discovers that a critical application has not been patched for six months. The application is business-critical and cannot be taken offline during business hours. Which of the following is the best course of action?

A.Implement compensating controls and schedule patching at the next available maintenance window
B.Accept the risk and continue operations
C.Apply the patch immediately during off-hours even if it risks downtime
D.Disconnect the application until it is patched
AnswerA

Compensating controls (such as segmentation, monitoring or virtual patching) reduce exposure while the application stays online, and scheduling the patch for the next maintenance window satisfies the constraint that it cannot be taken offline during business hours.

Why this answer

Compensating controls (e.g., network segmentation, WAF rules, or host-based IPS) reduce the immediate risk while the critical application remains online. Scheduling patching for the next maintenance window aligns with change management and ensures the patch is tested and applied without disrupting business operations. This balances security needs with operational continuity, a core principle of risk management.

Exam trap

The trap here is that candidates may choose immediate patching (Option C) thinking it is the most secure action, but the CISSP exam emphasizes balancing security with business continuity and following proper change management procedures.

How to eliminate wrong answers

Option B is wrong because accepting risk without any mitigating action ignores the known vulnerability exposure for six months, which violates due care and could lead to exploitation. Option C is wrong because applying the patch immediately during off-hours without prior testing or change approval could introduce instability or downtime, which is unacceptable for a business-critical application. Option D is wrong because disconnecting the application halts business operations entirely, which is disproportionate when less disruptive compensating controls can be implemented first.

239
MCQmedium

A company is conducting a risk assessment and needs to prioritize risks based on both likelihood and impact. The risk management team decides to use a quantitative approach. Which of the following is a key advantage of using quantitative risk analysis over qualitative risk analysis?

A.It provides monetary values for risks, facilitating cost-benefit analysis.
B.It relies on expert opinions and does not require historical data.
C.It is easier to communicate to non-technical stakeholders.
D.It requires less data and is faster to perform.
AnswerA

Quantitative risk analysis directly translates potential risks into financial terms, such as Annualized Loss Expectancy (ALE), by calculating the monetary impact of a single loss event (SLE) and its annual frequency (ARO). This financial quantification is crucial because it allows organizations to perform a rigorous cost-benefit analysis, comparing the projected monetary losses from a risk against the investment required for mitigation controls. Consequently, it facilitates informed decision-making, ensuring that security expenditures are justified and prioritized based on their financial return on investment.

Why this answer

Quantitative risk analysis assigns monetary values to assets, threats, and vulnerabilities, enabling precise cost-benefit calculations for risk mitigation options. This allows organizations to compare the cost of controls directly against the expected loss, a key advantage over qualitative methods that rely on subjective rankings.

Exam trap

The trap here is that candidates often confuse the ease of communication (qualitative) with the numerical rigor (quantitative), or mistakenly think quantitative analysis is faster because it uses numbers, when in fact it demands more data and time.

How to eliminate wrong answers

Option B is wrong because quantitative analysis relies on numerical data and historical loss records, not expert opinions; qualitative analysis is the approach that depends on expert judgment. Option C is wrong because quantitative results (e.g., ALE, SLE) are often harder for non-technical stakeholders to grasp than the simple high/medium/low ratings of qualitative analysis. Option D is wrong because quantitative analysis requires extensive data collection and computation, making it slower and more resource-intensive than qualitative analysis.

240
MCQhard

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

A.Avoid
B.Mitigate
C.Transfer
D.Accept
AnswerD

Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.

Why this answer

Risk acceptance is the appropriate response when the cost of mitigating a risk exceeds the potential loss and the risk falls within the organization's risk tolerance. For a high-likelihood, low-impact risk where mitigation is not cost-effective, accepting the risk (with documented awareness and monitoring) is the rational business decision.

Exam trap

CISSP often tests whether candidates reflexively choose 'mitigate' as the 'safest' answer, ignoring the cost-benefit analysis that makes acceptance the correct business-aligned choice.

How to eliminate wrong answers

Option A is wrong because avoidance requires eliminating the activity or asset that creates the risk, which is disproportionate for a low-impact risk and would disrupt business operations. Option B is wrong because mitigation is explicitly ruled out by the scenario — the cost of mitigation exceeds the potential loss, so spending more than the risk is worth is not justified. Option C is wrong because transfer (e.g., insurance, outsourcing) is typically used for low-likelihood, high-impact risks where the financial exposure is significant enough to warrant paying a third party to absorb it.

241
MCQmedium

An organization is implementing a BCP. After completing the BIA, which of the following is the next logical step in the planning process?

A.Develop recovery strategies
B.Test the plan
C.Conduct a risk assessment
D.Train personnel
AnswerA

Developing recovery strategies is the direct and logical next step after completing a Business Impact Analysis (BIA). The BIA identifies critical business functions, their Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs), essentially defining *what* needs to be recovered and *how quickly*. Based on these findings, the organization then determines the *how* by selecting and designing appropriate recovery strategies, such as hot sites, warm sites, or reciprocal agreements, to meet those defined objectives.

Why this answer

After the BIA identifies critical processes and recovery requirements, the next step is to develop strategies to meet those requirements, such as selecting recovery sites and technologies.

242
MCQmedium

An organization is developing a security governance framework to align with business objectives. Which group should have ultimate authority and responsibility for the cybersecurity program?

A.IT steering committee
B.Board of directors
C.Chief Information Security Officer (CISO)
D.Chief Executive Officer (CEO)
AnswerB

The Board of Directors holds the ultimate fiduciary responsibility for the organization's overall governance, risk management, and compliance, including cybersecurity. They are legally accountable to shareholders and stakeholders for ensuring that adequate controls and strategies are in place to protect assets and manage enterprise risks effectively. Establishing the security governance framework is a strategic imperative that falls squarely within their purview, setting the tone at the top and delegating authority appropriately.

Why this answer

The board of directors holds ultimate fiduciary duty for the organization, including oversight of risk management and cybersecurity. They approve the security governance framework and ensure it aligns with business objectives, as they are legally accountable for the entire enterprise. The CISO and CEO implement the program, but the board retains final authority.

Exam trap

CISSP often tests the distinction between operational responsibility (CISO, CEO) and ultimate governance authority (board of directors), tricking candidates into selecting the CISO as the answer because they are the most visible security leader.

How to eliminate wrong answers

Option A is wrong because the IT steering committee is an operational or tactical group that coordinates IT projects and priorities, not a governing body with ultimate fiduciary responsibility for cybersecurity risk. Option C is wrong because the CISO is the senior executive who designs and manages the cybersecurity program, but they report to the board or CEO and do not hold ultimate authority over the entire organization's risk posture. Option D is wrong because while the CEO is the top executive and accountable to the board, the board of directors has the ultimate legal and fiduciary authority to approve and oversee the cybersecurity governance framework.

243
MCQhard

During a security assessment, a penetration tester successfully performs an ARP spoofing attack, redirecting traffic through their machine. This attack exploits which protocol vulnerability?

A.Stateless nature of ARP with no authentication
B.Lack of encryption in ARP packets
C.Weakness in the IP address resolution algorithm
D.Use of broadcast frames for all requests
AnswerA

ARP's stateless design means it does not maintain session information or prior trust relationships between IP and MAC addresses. Consequently, it lacks any built-in authentication mechanism to verify the sender's legitimacy for ARP replies. This fundamental absence of authentication allows any host on the local network to send forged ARP replies, which are then accepted and cached by other devices without verification, leading directly to vulnerabilities like ARP spoofing.

Why this answer

ARP spoofing succeeds because ARP is a stateless protocol that does not authenticate or verify the legitimacy of ARP replies. Any host on a local network can send an unsolicited ARP reply (gratuitous ARP) to associate any IP address with any MAC address, allowing an attacker to redirect traffic without any validation mechanism.

Exam trap

CISSP candidates often confuse the stateless nature of ARP (no authentication) with the use of broadcast frames. While ARP uses broadcasts for requests, the vulnerability is that any host can send unsolicited replies (gratuitous ARP) without validation, not the broadcast mechanism itself.

How to eliminate wrong answers

Option B is wrong because ARP packets are not encrypted by design, but the lack of encryption is not the fundamental vulnerability exploited in spoofing; the core issue is the absence of authentication, not confidentiality. Option C is wrong because the IP address resolution algorithm itself is not weak; the vulnerability lies in the protocol's trust model, not in the algorithm used to map IP to MAC addresses. Option D is wrong because while ARP requests use broadcast frames, the attack exploits the acceptance of unsolicited replies, not the broadcast nature of requests; broadcast is a normal operational characteristic, not the security flaw.

244
MCQeasy

A company has a headquarters and three branch offices connected via MPLS VPN. Recently, they deployed a new VoIP system across all sites. Users report intermittent call drops and poor voice quality during peak business hours. The network team suspects packet loss and jitter are the cause. The IT manager wants to verify the issue without affecting production traffic. Which of the following is the best course of action?

A.Deploy a full packet capture on all branch routers.
B.Use IP SLA to generate test traffic and measure jitter and packet loss.
C.Conduct a network assessment by duplicating traffic to a monitoring tool.
D.Increase the MPLS bandwidth immediately.
AnswerB

IP Service Level Agreements (SLA) actively generate synthetic traffic, mimicking real application flows like VoIP or video, to measure specific performance metrics. This non-intrusive method allows for precise measurement of jitter, latency, and packet loss without impacting live production traffic. By simulating actual application behavior, IP SLA provides a clear baseline and ongoing insight into network quality, making it ideal for proactive performance assessment and identifying subtle degradations.

Why this answer

IP SLA (Internet Protocol Service Level Agreement) is a Cisco IOS feature that generates synthetic test traffic to measure network performance metrics — including jitter, latency, packet loss, and round-trip time — without impacting production traffic. It is the standard tool for proactively verifying VoIP quality issues on MPLS networks. This directly addresses the suspected packet loss and jitter without disrupting users.

Exam trap

CISSP often tests the difference between active monitoring (IP SLA, synthetic probes) and passive monitoring (packet capture, SPAN) — candidates pick packet capture because it sounds thorough, but it is disruptive and does not generate controlled test conditions for jitter and loss measurement.

How to eliminate wrong answers

Option A is wrong because a full packet capture on all branch routers is highly resource-intensive, generates massive data volumes, and can impact router CPU and production traffic — it is not a non-disruptive verification method. Option C is wrong because duplicating traffic to a monitoring tool (SPAN/RSPAN) still requires capturing production traffic and does not generate controlled test conditions to isolate jitter and loss. Option D is wrong because increasing MPLS bandwidth immediately is a costly, premature action that does not verify the root cause and may not fix jitter or loss if the issue is QoS configuration or congestion elsewhere.

245
MCQmedium

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

A.Work Recovery Time (WRT)
B.Maximum Tolerable Period of Disruption (MTPD)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerB

The Maximum Tolerable Period of Disruption (MTPD) represents the absolute longest time a business process or function can be inoperative before the organization experiences unacceptable consequences, such as significant financial loss, regulatory penalties, or irreparable reputational damage. It is a critical business-driven metric established during the BIA, defining the ultimate threshold for downtime that the business can endure without suffering severe harm. All recovery objectives, including RTO, must be set to ensure MTPD is not exceeded.

Why this answer

The Maximum Tolerable Period of Disruption (MTPD) is the metric that defines the longest time a business process can be unavailable before its disruption causes unacceptable harm to the organization. It is determined during the BIA and sets the upper bound from which RTO and RPO are derived. MTPD is sometimes called Maximum Allowable Downtime (MAD).

Exam trap

CISSP often tests the subtle distinction between MTPD (business tolerance limit) and RTO (technical recovery target), causing candidates to pick RTO because it sounds like the time to recover rather than the maximum tolerable outage.

How to eliminate wrong answers

Option A is wrong because Work Recovery Time (WRT) is the time needed after systems are restored to verify data integrity and resume normal business processing, not the maximum tolerable outage. Option C is wrong because Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time (how far back the last good backup must be), not the tolerable downtime. Option D is wrong because Recovery Time Objective (RTO) is the target time to restore a process after disruption, which must be less than or equal to MTPD, not the maximum tolerable period itself.

246
MCQmedium

A company is implementing a risk management program. They have identified a critical server with an asset value of $50,000. The exposure factor due to a potential threat is 40%, and the annual rate of occurrence is 2. What is the Annualized Loss Expectancy (ALE)?

A.$50,000
B.$40,000
C.$20,000
D.$100,000
AnswerB

This option correctly calculates the Annualized Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Multiplying this SLE by the ARO of 2 yields an ALE of $40,000, representing the expected financial loss from this specific risk over a year.

Why this answer

ALE = SLE × ARO, where SLE = Asset Value × Exposure Factor. Here SLE = $50,000 × 0.40 = $20,000, and ARO = 2, so ALE = $20,000 × 2 = $40,000. This quantifies the expected annual monetary loss from the threat, which is used to justify security controls whose cost is less than the ALE.

Exam trap

CISSP often tests whether candidates correctly separate SLE from ALE — the trap is stopping at SLE ($20,000) or multiplying AV by ARO without applying the exposure factor.

How to eliminate wrong answers

Option A is wrong because $50,000 is the raw asset value (AV), not adjusted for exposure factor or annualized occurrence. Option C is wrong because $20,000 is the Single Loss Expectancy (SLE = AV × EF), which represents loss per incident, not per year. Option D is wrong because $100,000 would result from multiplying AV by ARO without applying the exposure factor (50,000 × 2), ignoring that only 40% of the asset is exposed per incident.

247
MCQhard

A multinational corporation operates a private MPLS VPN network connecting 50 branch offices to a central data center. The network uses BGP as the routing protocol within the VPN, with each branch announcing its internal prefixes to the data center routers. Over the past week, several branch offices have reported intermittent connectivity issues, with traffic being routed to incorrect destinations before recovering. Network logs show that during these incidents, the data center router receives unexpected BGP updates from one of the branch routers, advertising prefixes that belong to other branches. BGP sessions remain established without flaps. The security team is concerned that this could be a route leak or intentional hijack. The network engineer has verified that all BGP sessions are authenticated with MD5 and that RPKI validation is not currently deployed. Which course of action should the engineer take first to mitigate the issue?

A.Configure inbound BGP prefix filtering on the data center routers.
B.Implement BGP Flowspec to rate-limit traffic to the affected prefixes.
C.Deploy RPKI validation across all routers.
D.Increase the BGP hold timer on data center routers.
AnswerA

Configuring inbound BGP prefix filtering on data center routers is a direct and immediate control mechanism to prevent route leaks. By explicitly defining which prefixes are acceptable to receive from branch routers, the data center routers can block any unauthorized or unexpected prefixes from being propagated further into the core network or other VPN segments. This ensures that only legitimate routes are learned and advertised, effectively containing the leak at its ingress point.

Why this answer

The intermittent connectivity issues are caused by a branch router advertising prefixes that belong to other branches, which is a classic route leak or hijack scenario. Configuring inbound BGP prefix filtering on the data center routers is the immediate and most effective mitigation because it allows the engineer to explicitly define which prefixes are accepted from each BGP neighbor, preventing unauthorized or incorrect routes from being installed in the routing table. This approach does not require additional infrastructure or protocol changes and directly addresses the root cause of the traffic misdirection.

Exam trap

The trap here is that candidates may assume RPKI is the best first step because it is a modern security mechanism, but the question explicitly states it is not deployed and asks for the first action to mitigate the issue, making immediate inbound filtering the correct answer over a longer-term deployment.

How to eliminate wrong answers

Option B is wrong because BGP Flowspec is designed to filter or rate-limit traffic based on flow specifications (e.g., source/destination IP, port) after routes are already installed, but it does not prevent the initial injection of invalid BGP routes; it is a reactive traffic engineering tool, not a proactive route validation mechanism. Option C is wrong because deploying RPKI validation is a longer-term, infrastructure-dependent solution that requires setting up RPKI caches, configuring routers to validate route origin, and potentially updating ROAs; it is not the first course of action when an immediate fix is needed, and it does not address the specific issue of a branch advertising other branches' prefixes (which could still pass RPKI if the AS origin is valid). Option D is wrong because increasing the BGP hold timer only affects how long a router waits for keepalive messages before declaring a peer down; it does not prevent the acceptance of invalid routes and would actually delay detection of session issues, making the problem worse.

248
MCQmedium

A software company uses a third-party library that has a known critical vulnerability. The library is used extensively and rewriting the code would take months. What is the BEST immediate action to reduce risk?

A.Remove the library from the codebase immediately
B.Disable the vulnerable feature in the library
C.Increase logging and monitoring to detect exploitation attempts
D.Implement a Web Application Firewall (WAF) rule to block exploitation
AnswerD

Implementing a Web Application Firewall (WAF) rule provides an effective 'virtual patching' solution by inspecting incoming traffic and blocking malicious requests targeting the known vulnerability before they reach the application. A WAF can be configured rapidly to identify and filter specific attack patterns, offering immediate protection without requiring modifications to the application's source code or the vulnerable library itself. This external layer of defense is a strong interim measure until a permanent fix can be deployed.

Why this answer

Implementing a Web Application Firewall (WAF) rule to block exploitation provides an immediate, compensating control that mitigates the known vulnerability without requiring code changes. This is the best immediate action because it buys time for a permanent fix while reducing risk, aligning with the principle of defense in depth. The WAF can inspect HTTP/HTTPS traffic for attack patterns (e.g., SQL injection, path traversal) specific to the vulnerable library and block malicious requests at the application layer.

Exam trap

The trap here is that candidates often choose 'Remove the library immediately' (Option A) because it seems like the most direct fix, but they fail to consider the business continuity impact and the need for a risk-based, phased approach to remediation.

How to eliminate wrong answers

Option A is wrong because removing the library immediately would break the application, causing a denial of service and potentially greater business impact than the vulnerability itself. Option B is wrong because disabling the vulnerable feature may not be feasible if the feature is integral to the library's core functionality, and it could still leave other attack surfaces exposed (e.g., memory corruption bugs). Option C is wrong because increasing logging and monitoring only detects exploitation attempts after they occur, not preventing them; it does not reduce the risk of a successful attack in real time.

249
MCQmedium

Which of the following is the correct order of priority for the ISC2 Code of Ethics Canons?

A.Advance the profession, protect society, act honorably, provide diligent service
B.Protect society, act honorably, provide diligent service, advance the profession
C.Provide diligent service, protect society, act honorably, advance the profession
D.Act honorably, provide diligent service, protect society, advance the profession
AnswerB

This sequence accurately represents the correct hierarchical order of the (ISC)² Code of Ethics Canons. "Protect Society, the Commonwealth, and the Infrastructure" is the foundational and highest-priority canon, followed by "Act honorably, honestly, justly, responsibly, and legally," then "Provide diligent and competent service to principals and the profession," and finally, "Advance and protect the profession."

Why this answer

The ISC2 Code of Ethics Canons are ordered by priority: Protect society, the common good, necessary public trust and confidence, and the infrastructure; Act honorably, honestly, justly, responsibly, and legally; Provide diligent and competent service to principals; and Advance and protect the profession. Option B correctly lists this order.

Exam trap

CISSP often tests the exact order of the Code of Ethics Canons, and candidates frequently misremember 'Advance the profession' as a high priority when it is actually last.

How to eliminate wrong answers

Option A is wrong because it places 'Advance the profession' first, but the profession is the lowest priority in the canon order. Option C is wrong because it places 'Provide diligent service' first, but service to principals ranks third, after society and honorable conduct. Option D is wrong because it places 'Act honorably' first, but protection of society is the highest priority and must come before honorable conduct.

250
MCQhard

A security architect is reviewing a system that uses a microkernel operating system. The architect is concerned about potential side-channel attacks between processes. Which mitigation is most effective at the architecture level?

A.Randomize the address space layout (ASLR)
B.Implement stack canaries in all user-space applications
C.Reduce the number of system calls and IPC mechanisms
D.Use cache partitioning or cache coloring to isolate process caches
AnswerD

Using cache partitioning or cache coloring directly addresses cache-based side-channel attacks by logically or physically isolating cache lines used by different processes or security domains. Cache partitioning assigns dedicated cache regions to specific processes, while cache coloring maps virtual pages to distinct physical cache sets, preventing one process from influencing or observing the cache state of another. This isolation mitigates timing-based information leakage, where an attacker infers sensitive data by observing variations in memory access times caused by cache hits or misses induced by a victim's operations.

Why this answer

D is correct because cache partitioning or cache coloring directly addresses the root cause of side-channel attacks in a microkernel environment: shared CPU caches. By isolating each process's cache footprint, an attacker cannot infer sensitive data (e.g., cryptographic keys) through timing variations or cache occupancy measurements, which is a fundamental architectural mitigation.

Exam trap

The trap here is that candidates often confuse software-based mitigations (ASLR, stack canaries) with hardware-level side-channel defenses, or mistakenly think reducing IPC eliminates all covert channels when the real threat is shared microarchitectural state.

How to eliminate wrong answers

Option A is wrong because ASLR randomizes memory addresses to hinder code-reuse attacks (e.g., ROP), but it does not prevent cache-based side channels that exploit timing differences in shared hardware resources. Option B is wrong because stack canaries detect buffer overflows in user-space applications, which is a software vulnerability mitigation unrelated to side-channel attacks between processes. Option C is wrong because reducing system calls and IPC mechanisms may shrink the attack surface for kernel exploits but does not eliminate the hardware-level cache contention that enables side-channel leakage.

251
MCQhard

A company uses a qualitative risk analysis matrix where likelihood ranges from 1 to 5 and impact ranges from 1 to 5. A risk with a likelihood of 4 and an impact of 5 would fall into which risk level if the matrix defines high risk as scores above 15, medium as 10-15, and low as below 10?

A.Medium
B.Critical
C.High
D.Low
AnswerC

According to the company's qualitative risk analysis matrix, a risk score of 20 exceeds the established threshold of 15, which delineates the boundary for 'High' risk. This indicates that any risk with a numerical assessment equal to or greater than 15 is categorized into the 'High' severity level. Consequently, a score of 20 directly and correctly maps to a 'High' risk classification within this framework.

Why this answer

The risk score is calculated as likelihood × impact = 4 × 5 = 20. The matrix defines high risk as scores above 15, and 20 exceeds 15, so the risk falls into the High category. This is a straightforward application of the qualitative risk scoring formula used in the scenario.

Exam trap

CISSP often tests whether candidates read the threshold definitions carefully — the trap is assuming a score of 20 is 'Critical' when the matrix only defines High, Medium, and Low.

How to eliminate wrong answers

Option A is wrong because Medium is defined as scores between 10 and 15, and 20 is above that range. Option B is wrong because 'Critical' is not one of the risk levels defined in this matrix — the matrix only defines High, Medium, and Low, so introducing a fourth level is a misreading of the scenario. Option D is wrong because Low is defined as scores below 10, and 20 is far above that threshold.

252
MCQmedium

Which physical security design principle emphasizes that the physical environment should be designed to discourage criminal activity by using natural surveillance, access control, and territorial reinforcement?

A.TEMPEST
B.Fail-safe
C.Layered defense
D.CPTED
AnswerD

Crime Prevention Through Environmental Design (CPTED) is a multidisciplinary approach that uses urban and architectural design to reduce the incidence and fear of crime, and improve the quality of life. It emphasizes manipulating the built environment to create a sense of ownership, increase natural surveillance, and define clear territorial boundaries. CPTED principles, such as natural access control, natural surveillance, and territorial reinforcement, directly focus on how physical design can proactively deter undesirable behavior and enhance security.

Why this answer

CPTED (Crime Prevention Through Environmental Design) is the discipline that uses natural surveillance (sightlines that make intruders visible), natural access control (directing flow through defined entry points), and territorial reinforcement (fences, signage, landscaping that signal private space) to deter criminal activity. It is a design philosophy applied to the physical environment itself, not a technology or a layered-defense strategy.

Exam trap

CISSP often tests acronym recognition by pairing CPTED with other physical security terms like TEMPEST and layered defense, so candidates who don't recall that CPTED specifically maps to natural surveillance/access control/territorial reinforcement may choose the more familiar 'layered defense' answer.

How to eliminate wrong answers

Option A is wrong because TEMPEST is a U.S. government standard (NSTISSAM TEMPEST/1-92) addressing electromagnetic emanations from equipment that could be intercepted — it concerns signal leakage, not environmental design against crime. Option B is wrong because 'fail-safe' describes a system defaulting to a safe state on failure (e.g., doors unlocking on power loss), which is a resilience principle, not a crime-deterrence design methodology. Option C is wrong because layered defense (defense in depth) refers to stacking multiple overlapping controls — fences, guards, locks, sensors — so that no single failure compromises security; it is a strategy, not the specific CPTED design principle described.

253
MCQhard

During a risk assessment, a company identifies that its primary data center is located in a flood-prone area. The estimated annual loss expectancy (ALE) for a flood event is $500,000. Installing flood barriers costs $200,000 and reduces the ALE to $50,000. What is the net benefit of implementing the flood barriers?

A.$300,000
B.$250,000
C.$450,000
D.$200,000
AnswerB

Flood barriers reduce the ALE from $500,000 to $50,000, giving an annual mitigation benefit of $450,000. Subtracting the $200,000 control cost yields a net benefit of $250,000, satisfying the stem's requirement to quantify the value of the safeguard.

Why this answer

The net benefit is calculated as the reduction in ALE minus the cost of the control. The original ALE is $500,000, and after implementing flood barriers the ALE drops to $50,000, a reduction of $450,000. Subtracting the $200,000 cost of the barriers yields a net benefit of $250,000.

This aligns with the CISSP risk management formula: Net Benefit = (ALE_old - ALE_new) - Cost_of_control.

Exam trap

The trap here is that candidates often forget to subtract the cost of the control from the reduction in ALE, leading them to select the $450,000 reduction as the net benefit instead of the correct $250,000.

How to eliminate wrong answers

Option A is wrong because $300,000 mistakenly subtracts the cost of the barriers from the original ALE ($500,000 - $200,000) without accounting for the residual ALE of $50,000. Option C is wrong because $450,000 represents only the reduction in ALE ($500,000 - $50,000) but ignores the $200,000 cost of implementing the flood barriers. Option D is wrong because $200,000 is simply the cost of the flood barriers and does not reflect any calculation of net benefit from risk reduction.

254
MCQeasy

An organization is developing an information security policy. Which of the following should be included?

A.Incident response playbooks
B.Detailed technical controls
C.Roles and responsibilities
D.Vendor contracts
AnswerC

Policy must assign accountability, so specifying roles and responsibilities ensures each control has a named owner. This satisfies the stem's requirement for content defining who does what, distinguishing it from procedural or technical detail that belongs in supporting standards.

Why this answer

An information security policy is a high-level document that establishes management direction and sets the strategic framework for security. Roles and responsibilities must be included to define who is accountable and responsible for security tasks, ensuring clear ownership and governance. This aligns with ISO/IEC 27001 and the NIST SP 800-53 framework, which mandate that policies specify organizational roles.

Exam trap

ISC2 often tests the distinction between policy (high-level strategic) and procedure/standard (low-level tactical), so the trap here is confusing incident response playbooks or technical controls as policy elements when they belong in subordinate documents.

How to eliminate wrong answers

Option A is wrong because incident response playbooks are detailed procedural documents that belong at the operational or tactical level, not within the high-level policy. Option B is wrong because detailed technical controls (e.g., specific firewall rules or encryption algorithms) are defined in standards, baselines, or procedures, not in the policy itself. Option D is wrong because vendor contracts are legal agreements managed by procurement and legal teams, not a component of the information security policy.

255
MCQhard

During a Kerberos authentication process, the client receives a Ticket Granting Ticket (TGT) from the Authentication Server (AS). Later, the client presents the TGT to the Ticket Granting Server (TGS) to request a service ticket. Which of the following best describes the purpose of the TGT?

A.It verifies the client's IP address to prevent replay attacks.
B.It allows the client to request additional service tickets without re-authentication.
C.It encrypts the session key between the client and the target service.
D.It authenticates the user to the target service directly.
AnswerB

The Ticket Granting Ticket (TGT) is a crucial component that facilitates single sign-on within a Kerberos realm. Once a client successfully authenticates to the Authentication Service (AS) and receives a TGT, this ticket serves as proof of their identity to the Ticket Granting Service (TGS). This allows the client to subsequently request service tickets for various network services without needing to re-enter their password or re-authenticate to the KDC for each new service.

Why this answer

The TGT is correct because it is issued once by the Authentication Server after the client proves its identity (typically via password-derived pre-authentication), and it is then presented to the TGS to obtain service tickets for specific resources — enabling single sign-on without re-entering credentials. The TGT is encrypted with the krbtgt account's secret key, so only the KDC can decrypt and validate it, and it carries the client's identity and a session key for securing subsequent TGS exchanges. This design is what makes Kerberos efficient: authenticate once, then request many service tickets.

Exam trap

CISSP often tests whether candidates conflate the TGT with the service ticket, so the trap is choosing an answer that describes service-ticket behavior (direct authentication to a resource) as the TGT's purpose.

How to eliminate wrong answers

Option A is wrong because Kerberos does not rely on IP address verification for replay protection; it uses timestamps and nonces within authenticators, and IP binding is not a core Kerberos mechanism (though some implementations add it as a hardening measure). Option C is wrong because the session key between client and target service is generated by the TGS and delivered inside the service ticket, not by the TGT itself — the TGT's session key only protects client-to-KDC communication. Option D is wrong because the TGT does not authenticate the user to the target service directly; the client must first exchange the TGT for a service ticket, and it is that service ticket (encrypted with the service's long-term key) that authenticates the user to the resource.

256
MCQhard

A user reports that a VPN client cannot connect to the corporate gateway. The client log shows the following excerpt: "TLS Error: server certificate verification failed: unable to get local issuer certificate." What does this indicate?

A.The VPN server certificate is expired
B.The server is using a self-signed certificate
C.The client certificate is missing
D.The client does not trust the CA that issued the server certificate
AnswerD

This is the correct answer because the client receives the server's certificate but cannot validate its authenticity. The client attempts to trace the certificate's issuer back to a trusted root Certificate Authority (CA) in its local trust store. If the issuing CA's certificate, or any intermediate CA in the chain, is not found or recognized as trusted by the client, the validation process fails, preventing the secure connection from being established due to an untrusted certificate chain.

Why this answer

The log message 'unable to get local issuer certificate' indicates that the client cannot locate or trust the CA certificate that issued the VPN server certificate. This is a trust chain issue, not an expired server certificate, a self-signed certificate, or a missing client certificate.

Exam trap

The trap here is that candidates confuse 'certificate expired' with 'untrusted CA' — both cause failures, but the log message and the underlying PKI process are different, and ISC2 often tests the distinction between trust chain errors and expiration errors.

How to eliminate wrong answers

Option A is wrong because an expired certificate would produce a different error, such as 'certificate has expired' or 'validity period mismatch', not a trust chain failure. Option B is wrong because a self-signed certificate would still cause a trust error, but the specific log message points to a missing CA in the client's trust store, not the server's certificate type. Option C is wrong because a missing client certificate would result in a 'no certificate sent' or 'bad certificate' error during client authentication, not a server certificate validation failure.

257
MCQmedium

During an internal security assessment, a tester uses a tool to attempt to crack password hashes extracted from a domain controller. Which phase of the penetration testing process does this represent?

A.Reconnaissance
B.Reporting
C.Post-exploitation
D.Exploitation
AnswerC

Post-exploitation refers to the actions performed after initial access to a system has been successfully gained. This phase aims to escalate privileges, maintain persistence, pivot to other systems, and gather sensitive information, such as user credentials. Password cracking, often performed on collected hash files (e.g., from SAM database, /etc/shadow, or network traffic), is a common post-exploitation activity used to obtain plaintext passwords for further lateral movement or deeper system compromise.

Why this answer

C is correct because cracking password hashes extracted from a domain controller occurs after the tester has already gained access to the system. This activity is part of the post-exploitation phase, where the tester escalates privileges, extracts credentials, and moves laterally. In this context, the tester is using a tool like John the Ripper or Hashcat to crack NTLM hashes, which is a classic post-exploitation step to obtain plaintext passwords for further access.

Exam trap

The trap here is that candidates often confuse post-exploitation with exploitation, mistakenly thinking that cracking hashes is part of the initial exploitation phase, when in fact exploitation is the act of gaining access, and post-exploitation includes all activities performed after that access is achieved.

How to eliminate wrong answers

Option A is wrong because reconnaissance is the initial phase of gathering information about the target without direct interaction, such as scanning open ports or enumerating services, not cracking already extracted hashes. Option B is wrong because reporting is the final phase where findings are documented and presented to stakeholders, not during active technical testing. Option D is wrong because exploitation is the phase where vulnerabilities are actively used to gain initial access or execute code on a target; cracking hashes after access is obtained is a post-exploitation activity, not the initial exploitation event.

258
MCQeasy

Which of the following is a secure coding practice to prevent SQL injection attacks?

A.Escaping all user input
B.Using parameterized queries
C.Using stored procedures exclusively
D.Validating input length
AnswerB

Parameterized queries, also known as prepared statements, are a highly effective secure coding practice for preventing SQL injection. They work by defining the SQL query structure with placeholders for data, which are then passed separately to the database engine. This strict separation ensures that user-supplied input is always treated as data values, never as executable SQL code, thus neutralizing any embedded malicious commands.

Why this answer

Parameterized queries (also known as prepared statements) separate SQL code from data by using placeholders (e.g., '?' in ODBC/JDBC or ':param' in Oracle) that are bound to user-supplied values at execution time. This ensures that input is always treated as data, never as executable SQL syntax, effectively neutralizing SQL injection regardless of the input content.

Exam trap

The trap here is that candidates often confuse 'stored procedures' with being inherently secure, but the CISSP exam tests that stored procedures can still be vulnerable if they use dynamic SQL with concatenated input, whereas parameterized queries (or prepared statements) are the definitive defense.

How to eliminate wrong answers

Option A is wrong because escaping all user input is error-prone and context-dependent; different database systems require different escape characters (e.g., backslash in MySQL vs. doubling single quotes in SQL Server), and incomplete or incorrect escaping can still allow injection. Option C is wrong because stored procedures alone do not prevent SQL injection if they contain dynamic SQL built with string concatenation (e.g., EXECUTE IMMEDIATE in Oracle or sp_executesql with concatenated parameters in SQL Server). Option D is wrong because validating input length only restricts the size of the input, not its content; an attacker can still inject malicious SQL within a valid length limit (e.g., a 10-character string like '1 OR 1=1').

259
Multi-Selectmedium

Which TWO are security benefits of using a federated identity model?

Select 2 answers
A.Simplified user management across organizations
B.Stronger authentication due to shared trust
C.Elimination of password policies
D.Reduced risk of credential theft
E.Single point of failure for authentication
AnswersA, D

Federated identity centralizes user authentication at an Identity Provider (IdP), eliminating the need for each Service Provider (SP) to create and manage separate user accounts. This significantly reduces administrative overhead for account provisioning, de-provisioning, and password resets across multiple applications or organizations. Users benefit from a single sign-on experience, while administrators gain a consolidated view and control over user access, streamlining the entire identity lifecycle management process.

Why this answer

Option A (Simplified user management across organizations) is correct because federation lets each organization manage its own users in its own identity provider (IdP) while relying parties trust assertions via standards like SAML 2.0 or OpenID Connect, eliminating the need to duplicate accounts and provisioning across partner domains. Option D (Reduced risk of credential theft) is correct because users authenticate only to their home IdP and services receive tokens/assertions rather than reusable passwords, so credentials are not stored or transmitted to every relying party, shrinking the attack surface for credential harvesting. Option B is not marked correct because federation shifts trust to the IdP and does not inherently strengthen authentication strength; that requires MFA, certificate-based auth, or similar controls.

Option C is wrong because password policies still apply at the IdP and are not eliminated by federation. Option E is wrong because federation is not inherently a single point of failure; well-designed deployments use multiple IdPs, failover, and fallback authentication to avoid that.

Exam trap

Candidates often confuse the benefits of federation. While federation centralizes authentication (which can create a single point of failure), its primary security benefit is that credentials are never shared with or stored by external service providers, thereby reducing the risk of credential theft.

260
MCQeasy

A security architect is evaluating security models for a multilevel secure system. Which model enforces the * property (no write down) and is typically used for confidentiality?

A.Clark-Wilson
B.Brewer-Nash
C.Bell-LaPadula
D.Biba
AnswerC

Bell-LaPadula is a mandatory access control (MAC) model specifically designed to enforce confidentiality, primarily used in military and government systems. It prevents unauthorized disclosure of information by enforcing two key rules: the Simple Security Property ('no read down'), which states a subject cannot read an object with a higher security level, and the *-property ('no write up'), which states a subject cannot write to an object with a lower security level. This model is correct as it directly addresses confidentiality requirements.

Why this answer

The Bell-LaPadula model enforces the * (star) property, which prohibits subjects from writing to objects at a lower classification level (no write down). This property, combined with the simple security property (no read up), ensures that information cannot flow from higher to lower security levels, making it the standard model for enforcing confidentiality in multilevel secure systems.

Exam trap

ISC2 often tests the confusion between Bell-LaPadula (confidentiality, no write down) and Biba (integrity, no write up), leading candidates to mistakenly select Biba when the question specifies confidentiality.

How to eliminate wrong answers

Option A is wrong because the Clark-Wilson model focuses on integrity through well-formed transactions and separation of duty, not on confidentiality or the * property. Option B is wrong because the Brewer-Nash (Chinese Wall) model addresses conflict of interest by preventing access to competing datasets, not multilevel confidentiality with no write down. Option D is wrong because the Biba model enforces integrity via no write up and no read down, which is the inverse of Bell-LaPadula's confidentiality properties.

261
MCQhard

A security analyst is reviewing logs from multiple systems and needs to ensure that logs are tamper-proof and available for incident investigation. Which of the following is the BEST approach?

A.Use a cloud storage bucket with public read access
B.Store logs locally on each system with restricted permissions
C.Encrypt logs at the source and send via email to the security team
D.Centralize logs to a syslog server with cryptographic hashing and append-only access
AnswerD

Centralizing logs to a dedicated syslog server significantly enhances security by providing a single, hardened repository for all audit data, making it easier to monitor and analyze. Cryptographic hashing ensures the integrity of each log entry, detecting any unauthorized modifications or tampering attempts after creation. Combined with append-only access, which prevents deletion or alteration of historical records, this approach provides a robust, forensically sound audit trail critical for incident response and compliance.

Why this answer

Option D is correct because it combines three essential log-security controls: centralization (so logs survive compromise of individual hosts), cryptographic hashing (which provides integrity verification and detects tampering), and append-only access (which prevents attackers or insiders from deleting or altering existing records). Centralizing to a syslog server also supports availability for incident investigation, since logs are not lost if a source system is wiped. Together, these controls directly satisfy the requirement for tamper-proof, investigation-ready logs.

Exam trap

CISSP often tests the misconception that encryption alone equals tamper-proofing, when integrity (hashing/signing) and append-only controls are what actually detect and prevent log modification.

How to eliminate wrong answers

Option A is wrong because a publicly readable cloud bucket exposes sensitive log data to anyone on the internet and provides no integrity protection, so logs could be read, copied, or replaced without detection. Option B is wrong because local storage with restricted permissions still leaves logs vulnerable to a compromised host, privileged insiders, ransomware, or disk failure, and it prevents correlation across systems during an investigation. Option C is wrong because email is not a reliable or secure log transport: it lacks integrity guarantees, can be intercepted or altered in transit, has mailbox size limits, and provides no centralized, tamper-evident repository for forensic review.

262
MCQhard

An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?

A.Orphaned account
B.Privilege escalation
C.Social engineering
D.Insider threat
AnswerA

An orphaned account is an active user account that no longer has an associated legitimate user, typically because the employee has left the organization but their account was not properly deprovisioned or disabled. This oversight creates a significant security vulnerability, as the account could be exploited by an attacker or the former employee themselves to gain unauthorized access to systems and data. The discovery of a former employee's active account directly indicates a failure in the organization's identity and access management offboarding process.

Why this answer

The scenario describes an account that should have been deprovisioned when the employee left but remained active — that is precisely an orphaned account. The fact that it was used to access sensitive data highlights the risk orphaned accounts create, but the root condition being tested is the orphaned account itself. Orphaned accounts are a well-known access control weakness in identity lifecycle management.

Exam trap

The trap is choosing 'insider threat' because a former employee accessed data; the exam distinguishes the underlying access control defect (orphaned account) from the resulting threat category.

How to eliminate wrong answers

Option B is wrong because privilege escalation involves an actor gaining elevated rights, whereas here the issue is an unmanaged account retaining its existing access. Option C is wrong because social engineering involves manipulating people into divulging information or access, which is not described. Option D is wrong because insider threat implies a current insider misusing access; a former employee's leftover account is more precisely classified as an orphaned account, even though it can enable insider-style abuse.

263
MCQhard

A company is outsourcing its customer support operations to a third-party vendor. The vendor will have access to sensitive customer data. Which of the following should be the primary security requirement in the contract with the vendor?

A.The vendor must perform annual penetration testing.
B.The vendor must conduct background checks on all employees.
C.The vendor must provide a list of all subcontractors.
D.The vendor must comply with the company's security policies and standards.
AnswerD

This is the most comprehensive and fundamental requirement for any outsourced operation, ensuring the vendor adopts the same baseline security posture, controls, and risk management philosophy as the client. By mandating compliance with the company's established security policies and standards, the contract holistically covers all aspects of data protection, access control, incident response, and regulatory adherence. This approach directly aligns the vendor's security practices with the client's expectations and risk tolerance, providing a robust framework for protecting sensitive information.

Why this answer

The primary security requirement in any outsourcing contract is that the vendor must comply with the company's security policies and standards. This ensures the vendor adheres to the same security controls, procedures, and risk management practices that the company has established to protect its data. Without this overarching requirement, other specific measures like penetration testing or background checks may not align with the company's overall security posture.

It also provides a contractual basis for auditing and enforcing compliance.

Exam trap

CISSP often tests the misconception that specific tactical measures (like penetration testing or background checks) are sufficient as primary security requirements, when the overarching requirement should be contractual compliance with the organization's security policies and standards.

How to eliminate wrong answers

Option A is wrong because annual penetration testing, while valuable, is a point-in-time assessment and not a comprehensive security requirement; it does not ensure ongoing compliance with security policies. Option B is wrong because background checks, though important, are only one aspect of personnel security and do not cover the full spectrum of security controls needed to protect data. Option C is wrong because providing a list of subcontractors is a transparency measure but does not by itself ensure that those subcontractors will implement adequate security controls.

264
Matchingmedium

Match each PKI component to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Issues and revokes certificates

Verifies identity before certificate issuance

List of revoked certificates

Binds a public key to an identity

Why these pairings

In PKI, the CA issues and signs certificates, the RA verifies identities, the repository stores certificates for retrieval, and the CRL tracks revoked certificates. Common confusions involve mixing the roles of CA and RA or CA and repository.

265
MCQhard

A large financial institution is migrating its core banking system to a private cloud. The architecture must protect against data leakage between different business units sharing the same physical infrastructure. The system uses a hypervisor and virtual machines. Each business unit has its own security classification. The security requirement is that no VM belonging to a lower classification should be able to read data from a higher classification VM, even if the hypervisor is compromised. The architect proposes using mandatory access control at the hypervisor level. However, the IT team notes that a hypervisor compromise could bypass MAC. Additionally, they need to ensure that data at rest is encrypted and keys are stored securely. Which of the following would BEST meet the requirement?

A.Implement network segmentation with VLANs and IPsec encryption between VMs.
B.Deploy a data loss prevention (DLP) system to monitor data transfers between VMs.
C.Use a public key infrastructure (PKI) to issue certificates for each VM and enforce mutual TLS for all inter-VM communication.
D.Use a hardware security module (HSM) to manage keys and implement full memory encryption using AES-256 with integrity protection, and use a trusted execution environment (TEE) for each VM, ensuring that even the hypervisor cannot access VM memory.
AnswerD

This option provides comprehensive protection against a compromised hypervisor by leveraging hardware-level security. A Trusted Execution Environment (TEE), such as Intel SGX or AMD SEV, creates a hardware-enforced isolated execution space for each VM, encrypting its memory and CPU state such that even the hypervisor cannot access it in plaintext. Full memory encryption with AES-256 and integrity protection further secures data in use, while a Hardware Security Module (HSM) securely manages the cryptographic keys, ensuring their protection from the compromised hypervisor.

Why this answer

It addresses the core requirement: preventing data leakage even if the hypervisor is compromised. By using a hardware security module (HSM) for key management, full memory encryption with AES-256 and integrity protection, and a trusted execution environment (TEE) for each VM, the solution ensures that VM memory is encrypted and isolated at the hardware level. The hypervisor, even if compromised, cannot access the decrypted memory of a VM, thus enforcing the security classification separation regardless of hypervisor integrity.

Exam trap

The trap here is that candidates often focus on network-level controls (like encryption or segmentation) and overlook the requirement that protection must hold even when the hypervisor is compromised, which demands hardware-enforced memory isolation rather than software-only solutions.

How to eliminate wrong answers

Option A is wrong because network segmentation with VLANs and IPsec only protects data in transit between VMs, not data at rest in memory, and a compromised hypervisor could still read VM memory directly, bypassing network controls. Option B is wrong because a data loss prevention (DLP) system is a detective control that monitors data transfers but does not prevent a compromised hypervisor from reading VM memory; it cannot enforce access control at the hardware or memory level. Option C is wrong because mutual TLS with PKI certificates only secures inter-VM communication over the network, but does not protect VM memory from a compromised hypervisor that can read memory directly, bypassing network encryption.

266
Multi-Selecteasy

Which TWO are examples of 'something you know' authentication factors?

Select 2 answers
A.PIN
B.Security question answer
C.Retina scan
D.Fingerprint
E.Smart card
AnswersA, B

A Personal Identification Number (PIN) is a classic example of "something you know" authentication. It is a secret numerical code that a user memorizes and provides to verify their identity. The system validates the entered PIN against a stored value, confirming the user's knowledge of this specific piece of information. This knowledge-based factor relies entirely on the user's memory and the confidentiality of the secret.

Why this answer

A PIN is a classic 'something you know' factor because it is a memorized numeric secret the user provides to authenticate, making option A correct. A security question answer is likewise knowledge-based: the user recalls a fact or personal detail previously registered, so option B is correct. The remaining options are not knowledge factors: a retina scan (C) and a fingerprint (D) are 'something you are' biometric factors, and a smart card (E) is a 'something you have' possession factor.

Exam trap

ISC2 often tests the distinction between authentication factor categories, and the trap here is confusing a smart card (possession) or biometric (inherence) with a knowledge factor because they may involve a PIN or password entry step, but the factor type is defined by the primary source of the secret.

267
MCQeasy

What is the primary purpose of a configuration management database (CMDB) in asset management?

A.Monitor network traffic for anomalies
B.Store and manage data classification labels
C.Track software licenses and compliance
D.Provide a repository of configuration items and their relationships
AnswerD

The fundamental purpose of a Configuration Management Database (CMDB) is to serve as a centralized repository for all relevant information about Configuration Items (CIs) within an IT environment. CIs encompass any component, service, or other asset that needs to be managed to deliver an IT service, such as servers, applications, networks, and documentation. Crucially, the CMDB also meticulously maps the interdependencies and relationships between these CIs, providing a holistic view that is vital for impact analysis, incident resolution, and change management processes.

Why this answer

The primary purpose of a configuration management database (CMDB) is to provide a repository of configuration items (CIs) and their relationships, enabling IT service management processes like change management, incident management, and asset management. It tracks the components of an IT environment and how they interconnect.

Exam trap

CISSP often tests the confusion between a CMDB and other asset management tools, leading candidates to choose software license tracking or network monitoring as the primary purpose.

How to eliminate wrong answers

Option A is wrong because monitoring network traffic for anomalies is a function of network monitoring tools, not a CMDB. Option B is wrong because storing data classification labels is typically done in a data catalog or classification system, not a CMDB. Option C is wrong because tracking software licenses and compliance is a function of software asset management (SAM) tools, which may integrate with a CMDB but is not its primary purpose.

268
MCQhard

A security engineer is reviewing the architecture of a system that uses the Bell-LaPadula model. The system has subjects with security clearances and objects with classifications. To prevent covert timing channels, which additional control should be implemented?

A.Enforce strict data labeling
B.Implement audit logging
C.Disable concurrent access to shared resources
D.Use encryption for data at rest
AnswerC

Disabling or severely limiting concurrent access to shared system resources is a highly effective mitigation strategy against covert timing channels. These channels fundamentally rely on two or more processes interacting with a shared resource, where one process modulates the resource's state and another observes the resulting timing variations to infer information. By eliminating or restricting concurrency, the opportunity for one process to influence the timing observable by another through a shared medium is significantly reduced, thereby closing a primary avenue for such covert communication.

Why this answer

Covert timing channels exploit the ability of a subject to modulate the timing of its access to a shared resource, thereby leaking information to another subject at a different security level. The Bell-LaPadula model enforces mandatory access control (MAC) but does not inherently prevent these channels. Disabling concurrent access to shared resources (option C) eliminates the ability to use timing variations as a signaling mechanism, directly addressing the covert channel at the resource scheduling level.

Exam trap

The trap here is that candidates confuse covert timing channels with covert storage channels (which involve writing data to a shared attribute) and incorrectly choose audit logging or encryption as a catch-all solution, rather than recognizing that timing channels require controlling the concurrency of resource access.

How to eliminate wrong answers

Option A is wrong because strict data labeling is a fundamental requirement of the Bell-LaPadula model itself (it enforces the *-property and simple security property) and does not address the temporal modulation of resource access that defines a timing channel. Option B is wrong because audit logging records events after they occur and cannot prevent the real-time signaling that a covert timing channel exploits; it is a detective, not a preventive, control. Option D is wrong because encryption for data at rest protects the confidentiality of stored data but has no effect on the timing of access to shared resources, which is the mechanism of a covert timing channel.

269
MCQmedium

An organization is transitioning from waterfall to agile development. How should security be integrated into the new process to align with the SDLC?

A.Perform a single security review at the end of the release cycle
B.Conduct security testing only during the integration phase
C.Skip threat modeling and rely solely on automated scanning
D.Include security requirements in user stories and conduct threat modeling each iteration
AnswerD

Embedding security requirements in user stories and threat modelling each iteration makes security continuous rather than a late gate, satisfying the stem's agile alignment constraint. It replaces waterfall's upfront sign-off with per-sprint security work, so controls evolve alongside rapidly changing code.

Why this answer

In agile development, security must be integrated continuously throughout each iteration, not deferred to the end. Option D is correct because it embeds security into the user story definition (including acceptance criteria for security requirements) and mandates threat modeling each iteration, which aligns with the iterative, incremental nature of agile and ensures security is addressed early and often, reducing risk and rework.

Exam trap

The trap here is that candidates mistakenly think security can be 'bolted on' at the end or only during specific phases, failing to recognize that agile demands security be woven into every iteration through practices like threat modeling and security user stories.

How to eliminate wrong answers

Option A is wrong because performing a single security review at the end of the release cycle is a waterfall practice that violates agile principles; it introduces security too late, making fixes costly and delaying releases. Option B is wrong because conducting security testing only during the integration phase ignores the need for continuous security validation throughout development, including unit testing and static analysis in earlier phases, and misses the opportunity to catch vulnerabilities early. Option C is wrong because skipping threat modeling and relying solely on automated scanning leaves the system vulnerable to business logic flaws, design-level threats, and context-dependent attacks that automated tools cannot detect; threat modeling is essential for identifying and mitigating these risks proactively.

270
MCQhard

An organization discovers that an employee has been using a personal cloud storage account to share confidential files. After revoking access, what is the NEXT best step to prevent recurrence?

A.Block access to all cloud storage sites
B.Deploy a data loss prevention (DLP) solution
C.Discipline the employee
D.Retrain all employees on data handling policy
AnswerB

Deploying a Data Loss Prevention (DLP) solution is the most effective and proactive technical control for preventing unauthorized data exfiltration. DLP systems identify sensitive data based on content, context, and metadata, then monitor and block its transfer across various egress points, including email, cloud services, removable media, and network protocols. This provides continuous, policy-driven protection against both accidental and malicious data loss, ensuring compliance and safeguarding critical information assets.

Why this answer

Deploying a Data Loss Prevention (DLP) solution is the next best step because it provides automated, policy-based monitoring and control of data in motion, at rest, and in use. DLP can inspect content for sensitive patterns (e.g., credit card numbers, proprietary file headers) and block unauthorized transfers to personal cloud storage, addressing the root cause of the incident rather than relying on manual enforcement.

Exam trap

The trap here is that candidates often choose retraining (D) because it seems like a proactive people-focused control, but the CISSP emphasizes that technical controls (like DLP) are necessary to enforce policy and prevent recurrence, especially after a security incident involving data exfiltration.

How to eliminate wrong answers

Option A is wrong because blocking all cloud storage sites is an overly restrictive, reactive measure that can hinder legitimate business operations and is easily bypassed by employees using encrypted tunnels or alternative services. Option C is wrong because disciplining the employee addresses the individual but does not implement a technical control to prevent recurrence across the organization. Option D is wrong because retraining alone is insufficient; without technical enforcement, employees may still inadvertently or deliberately violate policy, and training does not detect or block future violations in real time.

271
MCQeasy

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

A.Authentication, Authorization, Accounting
B.Authorization, Authentication, Accounting
C.Authentication, Accounting, Authorization
D.Accounting, Authentication, Authorization
AnswerA

This sequence correctly represents the foundational AAA framework. Authentication verifies the user's identity, establishing 'who you are.' Subsequently, Authorization determines the specific resources or actions the authenticated user is permitted to access, defining 'what you can do.' Finally, Accounting meticulously logs all user activities and resource consumption, providing a record of 'what you did' for auditing and accountability.

Why this answer

The AAA framework defines a sequential process: Authentication verifies the identity of a subject (e.g., via password, token, or biometrics), Authorization determines what resources that authenticated subject may access, and Accounting logs the subject's activities for auditing and billing. This order is logical because you cannot authorize an unauthenticated user, and accounting requires both identity and access decisions to be meaningful. Thus, Authentication → Authorization → Accounting is correct.

Exam trap

CISSP often tests the logical sequence of AAA, and candidates may confuse the order by thinking accounting comes before authorization because logs are generated during authentication, but the correct order is Authentication, Authorization, Accounting.

How to eliminate wrong answers

Option B is wrong because it places Authorization before Authentication, which is impossible since access rights cannot be granted without first verifying identity. Option C is wrong because it places Accounting before Authorization, but accounting records what an authenticated user actually did, which depends on what they were authorized to do. Option D is wrong because it places Accounting first, which is illogical as there is nothing to account for until a user has been authenticated and authorized.

272
Multi-Selectmedium

Your organization is forming an incident response team (IRT). According to NIST SP 800-61, which TWO roles are considered core to the incident response team?

Select 2 answers
A.Public Relations
B.Technical Lead
C.Manager
D.Legal Counsel
E.Human Resources
AnswersB, C

The Technical Lead is an absolutely core role within an Incident Response Team, providing critical hands-on expertise and strategic direction for technical incident handling. This individual drives forensic analysis, identifies the root cause of the incident, develops containment strategies, and oversees eradication and recovery efforts. Their deep technical knowledge is essential for effectively understanding and mitigating the impact of security breaches.

Why this answer

NIST SP 800-61 Rev. 2 identifies the Team Manager and the Technical Lead as core roles within an incident response team. The Manager oversees the response process, allocates resources, and coordinates communication, while the Technical Lead drives the technical analysis, containment, and eradication efforts. These two roles are essential for both strategic direction and hands-on technical execution during an incident.

Exam trap

The trap here is that candidates often confuse 'supporting roles' (like PR, Legal, HR) with 'core roles,' but NIST SP 800-61 strictly limits core IRT to Manager and Technical Lead to ensure rapid, focused technical response without bureaucratic delays.

273
MCQeasy

Which IPsec protocol provides both authentication and encryption of the packet payload, but does not encrypt the IP header?

A.AH in transport mode
B.ESP in transport mode
C.AH in tunnel mode
D.ESP in tunnel mode
AnswerB

Encapsulating Security Payload (ESP) in transport mode encrypts the IP payload to ensure confidentiality while also providing integrity and authentication for the payload and ESP headers. This mode is highly efficient for direct host-to-host communication because it secures the upper-layer data without the overhead of a new IP header.

Why this answer

ESP in transport mode encrypts the payload and provides authentication (via an optional ICV), but it does not encrypt the IP header. This matches the question's requirement of payload authentication and encryption without header encryption. In contrast, AH authenticates the entire packet (including the IP header) but provides no encryption.

Exam trap

The trap here is that candidates often confuse 'encryption of the payload' with 'encryption of the entire packet,' leading them to choose ESP in tunnel mode, which encrypts the inner IP header, or AH, which provides no encryption at all.

How to eliminate wrong answers

Option A is wrong because AH in transport mode provides authentication of the payload and parts of the IP header, but it does not offer any encryption of the payload. Option C is wrong because AH in tunnel mode authenticates the entire inner IP packet and parts of the outer header, but still lacks encryption. Option D is wrong because ESP in tunnel mode encrypts the entire inner IP packet (including the inner header), which goes beyond the question's requirement of not encrypting the IP header (the outer header remains unencrypted, but the inner header is encrypted, making it incorrect for the specific condition stated).

274
MCQmedium

A financial application uses a third-party library for PDF generation. A security review finds that the library is no longer maintained and has known vulnerabilities. What is the BEST course of action?

A.Restrict network access to the PDF server.
B.Encrypt all PDF files after generation.
C.Implement a web application firewall to block attacks targeting the library.
D.Replace the library with a maintained alternative.
AnswerD

Replacing the vulnerable third-party library with a well-maintained and secure alternative directly addresses the root cause of the security flaw. This action permanently removes the insecure code from the application's codebase, thereby eliminating the specific vulnerability that could be exploited. This proactive remediation strategy is the most effective way to ensure the long-term security and integrity of the financial application against this particular threat.

Why this answer

Replacing the unmaintained library with a maintained alternative is the best action because it eliminates the root cause: known vulnerabilities in code you cannot patch. A maintained library receives security updates, so the risk is removed rather than mitigated. Compensating controls like network restrictions or WAFs do not fix the underlying vulnerable code.

Exam trap

The trap is choosing a compensating control (WAF, network restriction) because it seems quicker — but CISSP always prefers eliminating the root cause when feasible.

How to eliminate wrong answers

Option A is wrong because restricting network access does not remediate the library's vulnerabilities and may not be feasible if the PDF server needs external connectivity. Option B is wrong because encrypting output PDFs protects data at rest but does nothing to prevent exploitation of the vulnerable library during generation. Option C is wrong because a WAF may not detect or block attacks targeting a server-side library, and it is a compensating control, not a fix.

275
MCQeasy

Which document provides detailed step-by-step instructions for performing a specific security task?

A.Policy
B.Procedure
C.Standard
D.Guideline
AnswerB

A procedure is a mandatory, detailed set of step-by-step instructions that describes *how* to perform a specific task or process consistently and securely. It outlines the exact actions to be taken, the order in which they should occur, and often specifies roles, responsibilities, and tools required. Procedures ensure uniformity, repeatability, and compliance with established policies and standards, directly addressing the need for explicit operational guidance for security functions.

Why this answer

A procedure is the most granular level of security documentation, providing explicit, sequential steps required to accomplish a specific task. It answers 'how' to implement a policy or standard, ensuring consistency and repeatability. Unlike policies (which are high-level management directives) or standards (which specify mandatory requirements), procedures are operational and action-oriented.

Exam trap

CISSP often tests the distinction between policies, standards, procedures, and guidelines, and candidates frequently confuse standards (which specify what must be done) with procedures (which specify how to do it).

How to eliminate wrong answers

Option A is wrong because a policy is a high-level statement of management intent that outlines goals and responsibilities, not detailed steps. Option C is wrong because a standard defines specific mandatory requirements, such as technical configurations or rules, but does not provide step-by-step instructions. Option D is wrong because a guideline offers non-mandatory recommendations and best practices, lacking the prescriptive detail of a procedure.

276
MCQeasy

A small business wants to ensure compliance with GDPR for its customer data. What is the initial action required to comply with GDPR?

A.Obtain consent from all data subjects
B.Implement pseudonymization techniques
C.Conduct a Data Protection Impact Assessment (DPIA)
D.Map data flows and identify personal data
AnswerD

Mapping data flows and identifying personal data is the crucial foundational step for any GDPR compliance program. This process involves creating a comprehensive inventory of all personal data an organization collects, processes, stores, and shares, including its origin, destination, purpose, and legal basis. This initial understanding of the data landscape is essential for assessing risks, implementing appropriate safeguards, and demonstrating accountability under GDPR.

Why this answer

The initial action for GDPR compliance is to map data flows and identify what personal data the organization collects, where it resides, how it flows, and who has access. Without this data inventory and mapping, an organization cannot determine lawful basis, apply appropriate controls, or conduct a DPIA. Data mapping is the foundational step that informs all subsequent compliance activities.

Exam trap

CISSP often tests whether candidates jump to consent or DPIA as the first GDPR step, when the correct foundational action is data mapping and inventory to understand what personal data exists and how it flows.

How to eliminate wrong answers

Option A is wrong because obtaining consent from all data subjects is not always the lawful basis (GDPR allows contract, legal obligation, vital interests, public task, and legitimate interests), and consent cannot be obtained before knowing what data is processed. Option B is wrong because pseudonymization is a technical safeguard applied after understanding data flows, not the initial compliance step. Option C is wrong because a DPIA is required only for high-risk processing and comes after identifying and assessing the data processing activities.

277
Multi-Selectmedium

A security architect is designing a system that must ensure integrity of commercial transactions. Which of the following models are specifically focused on integrity? (Choose TWO)

Select 2 answers
A.Take-Grant
B.Brewer-Nash
C.Biba
D.Clark-Wilson
E.Bell-LaPadula
AnswersC, D

Biba is a formal state-machine model designed specifically to protect data integrity by preventing unauthorized modification. It operates on the principle of "no write up, no read down" to ensure that information from lower-integrity levels cannot contaminate higher-integrity levels. This makes it the ideal choice for a system where preventing data corruption and maintaining trustworthiness is the primary objective.

Why this answer

Biba (C) is an integrity model that enforces the no-read-down and no-write-up rules to prevent data at a lower integrity level from contaminating higher-integrity data, directly protecting transaction integrity. Clark-Wilson (D) is also an integrity model, using well-formed transactions and separation of duties to ensure that commercial data remains consistent and can only be modified through authorized transformation procedures. Take-Grant (A) is a model for analyzing access rights and information flow, not specifically an integrity model.

Brewer-Nash (B) is the Chinese Wall model, which addresses conflict-of-interest and confidentiality, not integrity. Bell-LaPadula (E) is a confidentiality model based on no-read-up and no-write-down, so it does not focus on integrity.

Exam trap

CISSP often tests the confusion between confidentiality and integrity models; candidates may incorrectly select Bell-LaPadula (confidentiality) or Brewer-Nash (conflict of interest) when asked about integrity.

278
MCQmedium

A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?

A.DoS
B.Insider threat
C.Social engineering
D.Unauthorized access
AnswerD

Unauthorized access refers to gaining entry to a system, network, or data without the necessary permissions or authorization. The SIEM logs indicating a pattern, such as numerous failed login attempts followed by a successful one, directly points to a successful breach where an entity gained entry without legitimate credentials, fulfilling the definition of unauthorized access.

Why this answer

The sequence of multiple failed login attempts followed by a successful login from the same external IP address indicates a brute-force or password-spraying attack that succeeded. This constitutes unauthorized access because the attacker gained entry to an account without legitimate authorization, violating the confidentiality and integrity of the finance user's account.

Exam trap

The trap here is that candidates may confuse 'insider threat' with any unauthorized access, but the external IP address clearly indicates the attacker is not an insider, making unauthorized access the correct category.

How to eliminate wrong answers

Option A is wrong because a DoS (Denial of Service) attack aims to disrupt service availability by overwhelming resources, not to gain authenticated access through repeated login attempts. Option B is wrong because an insider threat involves a trusted user misusing their legitimate access, whereas this scenario shows an external IP address performing the login attempts, not an internal user. Option C is wrong because social engineering relies on manipulating human psychology (e.g., phishing calls or emails) to trick users into revealing credentials, not on automated brute-force attempts against a login interface.

279
MCQmedium

An organization is implementing a Public Key Infrastructure (PKI) to support secure email and web communications. The PKI includes a root CA, intermediate CAs, and end-entity certificates. Which of the following best describes the role of the root CA in this hierarchy?

A.It performs key escrow for all users
B.It issues certificates directly to end users
C.It validates certificate revocation lists (CRLs)
D.It is self-signed and forms the trust anchor
AnswerD

The root CA's certificate is uniquely self-signed, meaning its public key is used to verify a signature created by its own private key, making it inherently self-authenticating. This self-signed certificate is then manually or automatically distributed and pre-installed as a trusted root in operating systems and applications. It serves as the ultimate trust anchor, the foundational point from which all other certificates in the PKI hierarchy derive their trustworthiness and validity.

Why this answer

The root CA is the top of the PKI hierarchy and is self-signed, meaning its certificate is signed by its own private key. It serves as the ultimate trust anchor: all trust in the chain derives from it, and its public key is distributed out-of-band to relying parties. In a well-designed hierarchy, the root CA issues certificates only to intermediate CAs, not directly to end entities, to protect its private key.

Exam trap

CISSP often tests the misconception that the root CA issues end-entity certificates directly; candidates who overlook the security best practice of offline root and intermediate CA delegation will choose the 'issues directly to end users' option.

How to eliminate wrong answers

Option A is wrong because key escrow is a separate key recovery function (often handled by a dedicated escrow system or CA feature) and is not the defining role of the root CA. Option B is wrong because best practice is for the root CA to issue only to intermediate CAs, keeping the root offline; issuing directly to end users increases risk and is not the root's primary role. Option C is wrong because CRL validation is performed by relying parties or validation services, not by the root CA itself; the CA may publish CRLs, but validating them is a client-side or OCSP responder function.

280
MCQeasy

Which phase of the data lifecycle includes the act of securely deleting data that is no longer needed, in accordance with retention policies?

A.Store
B.Share
C.Archive
D.Destroy
AnswerD

The Destroy phase is the critical final stage of the data lifecycle, specifically encompassing the secure and irreversible removal of data from all storage media. This involves employing methods like degaussing, cryptographic erasure, or physical destruction (e.g., shredding, pulverizing) to ensure data cannot be reconstructed or recovered. This phase directly addresses the act of secure deletion, preventing unauthorized access after data's useful life has ended.

Why this answer

The Destroy phase of the data lifecycle is explicitly the stage where data is securely deleted once it is no longer needed and retention policies permit disposal. It covers techniques like cryptographic erasure, degaussing, shredding, and secure overwrite, ensuring data cannot be recovered. This is the terminal phase before the lifecycle restarts.

Exam trap

CISSP often tests confusion between Archive (long-term retention for future access) and Destroy (irreversible secure disposal), so candidates pick Archive thinking retention equals eventual deletion.

How to eliminate wrong answers

Option A is wrong because Store covers the retention and protection of data at rest, not its disposal. Option B is wrong because Share covers controlled distribution of data to authorized parties, not deletion. Option C is wrong because Archive is a long-term retention stage for data kept for compliance or historical purposes — it precedes, not replaces, destruction.

281
MCQmedium

A company uses a SIEM to correlate logs from multiple sources. Which log source is most critical for detecting privilege escalation attacks?

A.Authentication logs
B.DNS logs
C.Firewall logs
D.Web server logs
AnswerA

Authentication logs are paramount for detecting security incidents like privilege escalation because they meticulously record all login attempts, account lockouts, password changes, and user role modifications across operating systems, applications, and directory services. A Security Information and Event Management (SIEM) system correlates these granular events to identify suspicious patterns, such as multiple failed login attempts followed by a successful one from an unusual location, or unauthorized privilege assignments, which are direct indicators of a potential account compromise or escalation.

Why this answer

Authentication logs are most critical for detecting privilege escalation attacks because they record user identity changes, such as the use of 'su' or 'sudo' commands, and account modifications like group membership changes. A SIEM can correlate these events with other logs to identify anomalous privilege transitions, such as a standard user suddenly acquiring administrative rights, which is a hallmark of privilege escalation.

Exam trap

The trap here is that candidates often choose firewall logs or DNS logs because they associate them with detecting attacks in general, but the question specifically targets privilege escalation, which requires logs that capture user identity and privilege changes, not network-level events.

How to eliminate wrong answers

Option B (DNS logs) is wrong because DNS logs primarily track domain name resolution queries and are useful for detecting command-and-control (C2) traffic or data exfiltration, not direct privilege escalation events. Option C (Firewall logs) is wrong because firewall logs record network traffic allowed or blocked based on IP addresses and ports, which can indicate lateral movement but do not capture the user-level account changes or privilege transitions that define privilege escalation. Option D (Web server logs) is wrong because web server logs record HTTP requests and responses, which are valuable for detecting web application attacks like SQL injection or cross-site scripting, but they do not directly log operating system-level privilege changes or authentication events.

282
MCQhard

A financial institution stores customer PII, including Social Security numbers (SSNs). Under privacy regulations, SSNs are considered sensitive PII. Which of the following techniques would best reduce the risk of re-identification while preserving the utility of the data for statistical analysis?

A.Anonymization by removing all direct identifiers
B.Encrypting the entire dataset at rest
C.Differential privacy by adding calibrated noise to the dataset
D.Pseudonymization by replacing names with random identifiers
AnswerC

Differential privacy offers a strong, mathematically provable guarantee of privacy by introducing carefully calibrated noise into the dataset or query results. This noise ensures that the presence or absence of any single individual's data point does not significantly alter the output, making it extremely difficult for an adversary to infer specific individual attributes, even with substantial auxiliary information. It allows for aggregate statistical analysis while rigorously protecting individual privacy against sophisticated re-identification attempts.

Why this answer

Differential privacy adds mathematically calibrated noise to query results or dataset statistics so that the presence or absence of any single individual cannot be inferred, while aggregate statistical properties remain accurate. This directly addresses re-identification risk — even with auxiliary data, an attacker cannot confidently determine whether a specific person is in the dataset. It preserves utility for statistical analysis because the noise is bounded and unbiased across large populations.

Exam trap

CISSP often tests the distinction between de-identification/pseudonymization (reversible or re-identifiable) and true anonymization techniques like differential privacy — the trap is picking 'remove identifiers' or 'pseudonymize' as sufficient when quasi-identifier attacks still enable re-identification.

How to eliminate wrong answers

Option A is wrong because removing direct identifiers (names, SSNs) is only de-identification, not anonymization — quasi-identifiers like ZIP code, birth date, and gender can be combined with external datasets to re-identify individuals (the classic Sweeney 1997 Massachusetts voter case). Option B is wrong because encryption at rest protects data from unauthorized access but does nothing to prevent re-identification once the data is decrypted for analysis — it is a confidentiality control, not a privacy-preserving technique. Option D is wrong because pseudonymization replaces identifiers with tokens but the mapping table still exists, and quasi-identifiers remain, so re-identification is still possible; GDPR explicitly treats pseudonymized data as still personal data.

283
MCQeasy

Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?

A.RPO
B.MTD
C.MTTR
D.RTO
AnswerA

The Recovery Point Objective (RPO) specifies the maximum acceptable amount of data that an organization can afford to lose following a disruption. This metric is typically expressed as a time interval, such as 'data loss not exceeding the last four hours' or 'no more than one day's worth of transactions.' It directly influences the frequency of data backups, snapshots, or replication strategies required to meet this business continuity target.

Why this answer

Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time — for example, an RPO of 4 hours means the organization can tolerate losing up to 4 hours of data. It directly drives backup frequency and replication strategy. RTO, by contrast, defines how long recovery can take, not how much data can be lost.

Exam trap

CISSP often tests the confusion between RPO (data loss tolerance) and RTO (downtime tolerance) — candidates frequently swap these definitions under exam pressure.

How to eliminate wrong answers

Option B is wrong because Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable before unacceptable impact occurs; it is a broader business metric that encompasses both RTO and RPO considerations. Option C is wrong because Mean Time To Repair (MTTR) measures the average time to restore a failed component, which is an operational reliability metric, not a data-loss tolerance. Option D is wrong because Recovery Time Objective (RTO) defines the maximum acceptable duration of downtime before service must be restored, not the amount of data that can be lost.

284
Multi-Selecthard

A security administrator is evaluating secure file transfer protocols. Which THREE of the following protocols provide encryption for data in transit? (Select THREE.)

Select 3 answers
A.FTP
B.SFTP
C.TFTP
D.SCP
E.FTPS
AnswersB, D, E

Secure File Transfer Protocol (SFTP) is a network protocol that provides file access, file transfer, and file management functionalities over any reliable data stream. Crucially, SFTP runs as a subsystem of the Secure Shell (SSH) protocol, leveraging SSH's robust encryption capabilities to secure both the authentication credentials and the data being transferred. This ensures confidentiality and integrity, making SFTP a highly secure choice for transferring sensitive files across untrusted networks.

Why this answer

SFTP (B) is correct because it runs over SSH (typically TCP port 22) and encrypts all data and commands in transit. SCP (D) is correct because it also operates over SSH, providing encrypted file transfer using the SSH transport layer. FTPS (E) is correct because it wraps FTP in TLS/SSL, encrypting the control and data channels.

FTP (A) is not marked correct because it transmits credentials and data in cleartext, and TFTP (C) is not marked correct because it uses UDP with no encryption or authentication.

Exam trap

Candidates often confuse SFTP (SSH-based) and FTPS (SSL/TLS-based), or mistakenly believe that TFTP (Trivial FTP) has security features. On the CISSP exam, remember that FTP and TFTP send credentials and data in cleartext, while SFTP, SCP, and FTPS provide encryption in transit.

285
MCQhard

Your organization is a medium-sized e-commerce company with a hybrid infrastructure: on-premises datacenter and AWS cloud. The security team recently conducted an internal vulnerability scan of the on-premises network and discovered multiple critical vulnerabilities in a legacy ERP system that cannot be patched because the vendor no longer supports it. The ERP system is essential for order processing and cannot be decommissioned. The team also ran a penetration test against the cloud environment and found that an attacker with network access could leverage misconfigured security groups to move laterally between instances. The company has a risk appetite that allows for limited risk acceptance with compensating controls. As the senior security analyst, what is the BEST course of action?

A.Immediately isolate the legacy ERP system from the network and implement a manual workaround for order processing.
B.Decommission the legacy ERP system and migrate to a modern alternative, accepting a temporary disruption in operations.
C.Accept the risk for both findings and document them in the risk register without additional controls.
D.Apply virtual patching via an intrusion prevention system (IPS) for the ERP vulnerabilities and implement stricter security group rules in the cloud to restrict lateral movement.
AnswerD

Virtual patching through IPS blocks exploitation of the unpatchable ERP flaws without vendor support, while tightened security group rules break the lateral-movement path found in AWS. Both are compensating controls, matching the stated risk appetite for limited acceptance with controls.

Why this answer

The best course of action is to apply compensating controls: virtual patching via IPS for the legacy ERP vulnerabilities and stricter security group rules to restrict lateral movement in the cloud. This aligns with the company's risk appetite for limited risk acceptance with compensating controls, and addresses both findings without disrupting essential operations. Isolating or decommissioning the ERP would disrupt order processing, and accepting risk without controls is not acceptable.

Exam trap

CISSP often tests risk management concepts, and candidates may choose extreme options like isolation or decommissioning without considering business impact, or incorrectly accept risk without controls.

How to eliminate wrong answers

Option A is wrong because isolating the ERP system would disrupt essential order processing. Option B is wrong because decommissioning would cause a major disruption and is not feasible. Option C is wrong because accepting risk without additional controls violates the risk appetite that requires compensating controls.

286
Multi-Selectmedium

Which TWO of the following are characteristics of a SOC 2 Type II report?

Select 2 answers
A.Covers the design and operating effectiveness of controls over a period of time
B.Is a public summary report available to anyone
C.Includes trust service criteria such as security, availability, and confidentiality
D.Focuses only on financial reporting controls
E.Evaluates controls at a single point in time
AnswersA, C

A SOC 2 Type II report provides an opinion on the suitability of the design of controls and their operating effectiveness throughout a specified reporting period, typically 6-12 months. This extended observation period offers a higher level of assurance regarding the consistent application and performance of a service organization's system and controls. It demonstrates sustained adherence to the Trust Service Criteria, which is crucial for user entities relying on these services.

Why this answer

Option A is correct because a SOC 2 Type II report specifically tests both the design and the operating effectiveness of controls throughout a defined review period (typically 3–12 months), unlike a Type I report which only assesses design at a point in time. Option C is correct because SOC 2 engagements are structured around the AICPA Trust Services Criteria, which include security (required) plus availability, processing integrity, confidentiality, and privacy as optional categories. Option B is incorrect because SOC 2 reports are restricted-use reports distributed under NDA to management, customers, and auditors—not public documents (that role belongs to SOC 3).

Option D is incorrect because financial reporting controls are the focus of SOC 1 (SSAE 18/ISAE 3402), not SOC 2. Option E is incorrect because point-in-time evaluation describes a SOC 2 Type I report, whereas Type II covers a period.

Exam trap

CISSP often tests the distinction between SOC 2 Type I and Type II, and between SOC 2 and SOC 3 reports, causing candidates to confuse point-in-time vs. period coverage or public vs. restricted distribution.

287
MCQhard

During a penetration test, the tester gains initial access to a server and then attempts to pivot to other systems. Which phase of the penetration testing process does this represent?

A.Post-exploitation/lateral movement
B.Reconnaissance
C.Exploitation
D.Reporting
AnswerA

After gaining initial access, the penetration tester enters the post-exploitation phase. This involves actions like privilege escalation on the compromised system, establishing persistence to maintain access, and then pivoting to other systems within the network. Lateral movement aims to expand the tester's control and reach additional valuable assets beyond the initial foothold, demonstrating the potential impact of a breach.

Why this answer

After gaining initial access, the penetration tester attempts to pivot to other systems, which is part of post-exploitation and specifically lateral movement. This phase involves expanding access, escalating privileges, and moving laterally within the network to compromise additional targets.

Exam trap

CISSP often tests the phases of penetration testing, and candidates may confuse exploitation with post-exploitation; the key is that lateral movement occurs after initial access, so it is post-exploitation.

How to eliminate wrong answers

Option B is wrong because reconnaissance is the initial phase of gathering information about the target before any exploitation, not after gaining access. Option C is wrong because exploitation is the phase where the tester actually gains initial access by exploiting a vulnerability, which has already occurred. Option D is wrong because reporting is the final phase where findings are documented and presented, not the phase involving lateral movement.

288
MCQeasy

A security auditor is reviewing the results of a recently completed internal vulnerability scan. The scan report shows several hosts with the same vulnerability. Which of the following actions should the auditor take FIRST?

A.Manually verify the vulnerability on a sample of affected hosts.
B.Immediately apply patches to all affected hosts.
C.Remove the hosts from the network until the vulnerability is resolved.
D.Re-run the scan with a different scanner.
AnswerA

An auditor's primary role includes validating findings to ensure accuracy and reduce the risk of acting on erroneous information. Manually verifying a sample of affected hosts directly confirms the vulnerability's existence and helps differentiate between actual threats and potential false positives from automated scans. This targeted approach ensures that subsequent remediation efforts are focused on legitimate security concerns, preventing unnecessary resource expenditure and potential system disruption.

Why this answer

The auditor must first manually verify the vulnerability on a sample of affected hosts because automated vulnerability scans can produce false positives due to factors like incomplete banner grabbing, outdated plugin signatures, or network-level interference. Confirming the finding ensures that subsequent remediation efforts are based on accurate, validated data, preventing wasted resources on non-existent issues.

Exam trap

The trap here is that candidates may assume automated scan results are always accurate and jump to remediation (Option B) or isolation (Option C), failing to recognize that the first step in the assessment process is to validate findings to avoid acting on false positives.

How to eliminate wrong answers

Option B is wrong because immediately applying patches without verification risks introducing instability or breaking functionality if the vulnerability is a false positive, and it bypasses the change management process required in a secure environment. Option C is wrong because removing hosts from the network is an overly drastic and disruptive response that should only be considered after the vulnerability is confirmed and the risk is assessed as critical, not as a first step. Option D is wrong because re-running the scan with a different scanner does not address the need for manual validation; it merely repeats an automated process that may still produce false positives due to inherent scanner limitations.

289
MCQmedium

A company implements a centralized authentication system using RADIUS for network devices. The security team notices that after a user's password is changed in Active Directory, the user can still authenticate to network devices using the old password for up to 30 minutes. What is the most likely cause?

A.Kerberos ticket lifetime
B.Network devices caching authentication responses
C.Active Directory replication delay
D.RADIUS server caching credentials
AnswerC

Active Directory replication delay occurs when a password change made on one domain controller has not yet synchronized to all other domain controllers. If the RADIUS server queries a domain controller that has not received the updated password, authentication would fail. While replication delays can cause authentication problems, a 30-minute delay for a password change to propagate across an Active Directory forest is typically excessive for a well-configured environment, making it a less probable primary cause than device-level caching.

Why this answer

When a password is changed in Active Directory, the change is processed by a specific Domain Controller (DC) and urgently replicated to the PDC Emulator. However, if the RADIUS server queries a different DC (such as one in a different AD site), that DC will not know about the password change until normal replication occurs. Inter-site replication typically occurs on a schedule (often 15 to 30 minutes).

During this replication window, the DC queried by the RADIUS server still holds the old password hash as valid, allowing the user to successfully authenticate with their old password.

Exam trap

A common trap is assuming that password changes are instantly updated globally across all Domain Controllers. In large environments with multiple AD sites, replication latency (which defaults to 15 or 30 minutes for inter-site replication) means old credentials remain valid on non-replicated DCs for a short period.

How to eliminate wrong answers

Option A is wrong because Kerberos ticket lifetime controls how long a TGT or service ticket is valid, but RADIUS authentication does not use Kerberos tickets; RADIUS relies on PAP, CHAP, or EAP methods and does not involve Kerberos ticket caching. Option C is wrong because Active Directory replication delay would affect password changes across domain controllers, but the RADIUS server typically queries a single domain controller and would immediately see the new password; the delay is on the network device side, not AD replication. Option D is wrong because the RADIUS server does not cache credentials; it forwards authentication requests to the directory service (e.g., Active Directory) in real time and does not store old passwords locally.

290
MCQeasy

A security architect is selecting an access control model for a system that must prevent users from reading objects at a higher classification level. Which model enforces this property?

A.Bell-LaPadula
B.Clark-Wilson
C.Biba
D.Brewer-Nash
AnswerA

The Bell-LaPadula model is a state machine model primarily concerned with confidentiality, designed to prevent unauthorized disclosure of information. It enforces the "simple security property" (no read-up) and the "*-property" (no write-down), ensuring that subjects at a given security level cannot read objects at a higher level or write to objects at a lower level. This strict hierarchical control is ideal for environments where preventing unauthorized disclosure of classified information is paramount, such as military or government systems requiring multi-level security.

Why this answer

The Bell-LaPadula model enforces mandatory access control (MAC) with the *-property (no write-down) and the simple security property (no read-up). The question specifically asks to prevent reading objects at a higher classification level, which is exactly the 'no read-up' rule of Bell-LaPadula. This model is designed for confidentiality-focused systems, such as military or government classified environments.

Exam trap

The trap here is that candidates often confuse the Biba model (integrity, no read-down) with Bell-LaPadula (confidentiality, no read-up), so they incorrectly select Biba when the question explicitly asks about preventing reading at a higher classification level.

How to eliminate wrong answers

Option B (Clark-Wilson) is wrong because it focuses on integrity and enforces separation of duties and well-formed transactions, not on preventing read-up based on classification levels. Option C (Biba) is wrong because it is an integrity model that prevents subjects from writing to higher integrity levels (no write-up) and reading from lower integrity levels (no read-down), which is the opposite of the confidentiality requirement in the question. Option D (Brewer-Nash) is wrong because it is designed to prevent conflicts of interest (Chinese Wall model) by dynamically controlling access based on previously accessed datasets, not by enforcing static classification levels.

291
MCQeasy

An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?

A.Communication plan
B.Recovery procedures
C.Legal notification requirements
D.Incident categories
AnswerD

Incident categories establish predefined classifications and criteria that help an organization determine whether a particular event constitutes a security incident requiring formal response. These categories, such as "malware infection," "unauthorized access," "denial of service," or "data exfiltration," provide clear definitions and often include specific indicators or thresholds. By categorizing events, organizations can standardize incident identification, prioritize response efforts, and ensure consistent handling based on the nature and potential impact of the security breach.

Why this answer

Incident categories define the classification scheme that specifies what types of events constitute an incident and how they are grouped (e.g., malware, DoS, unauthorized access). This component establishes the conditions and thresholds that trigger incident declaration, making it the correct answer for 'defining the specific conditions that constitute an incident.' Categories also drive escalation paths and response procedures.

Exam trap

CISSP often tests whether candidates can distinguish the components of an incident response plan — the trap is confusing the definition of an incident (categories) with the actions taken after an incident (communication, recovery, legal notification).

How to eliminate wrong answers

Option A is wrong because the communication plan defines who to notify, when, and through what channels — it does not define what constitutes an incident. Option B is wrong because recovery procedures describe how to restore systems after an incident, not the criteria for declaring one. Option C is wrong because legal notification requirements specify regulatory and contractual obligations for reporting incidents, not the conditions that define an incident.

292
MCQeasy

Which type of data is considered sensitive PII and requires enhanced protection?

A.Name and email address
B.Job title
C.Phone number
D.Social Security number
AnswerD

A Social Security number (SSN) is unequivocally considered sensitive PII due to its direct linkage to an individual's financial, medical, and governmental records. Its compromise presents an extremely high risk of identity theft, financial fraud, and other severe personal harm. Consequently, SSNs require the most stringent security controls and regulatory protections to safeguard individuals from significant adverse impacts.

Why this answer

A Social Security number is a government-issued unique identifier that, if exposed, enables identity theft and fraud, so it is classified as sensitive PII requiring enhanced protection under regulations like GLBA, HIPAA, and state privacy laws. Names, email addresses, and phone numbers are PII but generally lower sensitivity, while job titles are typically not considered sensitive PII at all. The SSN is the classic example of high-sensitivity personal data.

Exam trap

The trap is treating all PII as equally sensitive; the exam expects you to recognize that government identifiers like SSNs are categorically sensitive and demand enhanced protection beyond ordinary PII.

How to eliminate wrong answers

Option A is wrong because a name and email address, while PII, are commonly shared and do not by themselves enable identity theft the way an SSN does. Option B is wrong because a job title is generally not considered PII, let alone sensitive PII. Option C is wrong because a phone number is PII but is lower sensitivity than a government identifier like an SSN.

293
MCQmedium

A hospital chain collects and stores electronic health records (EHR) for millions of patients. The EHR system is hosted in a private cloud and accessed by doctors, nurses, and administrative staff from various locations. Recently, an internal audit found that several employees shared their login credentials with colleagues to expedite workflows. The hospital must comply with HIPAA and state privacy laws. The security officer wants to implement a solution that minimizes the risk of unauthorized access due to shared credentials while still allowing efficient access for patient care. Which of the following is the BEST approach?

A.Implement single sign-on (SSO) integrated with role-based access control (RBAC) and enforce audit logging of all access
B.Enforce a policy requiring password changes every 30 days and complexity requirements
C.Replace passwords with biometric authentication (fingerprint and iris scans) for all users
D.Disable remote access to the EHR system and require all access to occur only from within the hospital's LAN
AnswerA

Single Sign-On (SSO) centralizes authentication, significantly reducing password fatigue and the associated risk of users resorting to insecure practices like writing down or sharing credentials. Integrated Role-Based Access Control (RBAC) ensures that users are granted only the minimum necessary privileges to perform their job functions, directly enforcing the principle of least privilege and preventing unauthorized access to sensitive EHR data. Furthermore, comprehensive audit logging creates an immutable record of all system access and data interactions, establishing clear accountability and providing a strong deterrent against credential sharing or misuse, as all actions are traceable.

Why this answer

SSO integrated with RBAC reduces the attack surface of shared credentials by centralizing authentication and enforcing least-privilege access based on job roles. Audit logging provides non-repudiation and traceability, which deters credential sharing and satisfies HIPAA's requirement to track access to ePHI. This combination directly addresses the root cause (shared credentials) while maintaining workflow efficiency through seamless authentication.

Exam trap

The trap here is that candidates often choose biometric authentication (C) thinking it eliminates credential sharing, but they overlook that biometrics can be bypassed or shared (e.g., a user holding a fingerprint scanner for a colleague) and introduce significant privacy and revocation challenges under HIPAA.

How to eliminate wrong answers

Option B is wrong because frequent password changes and complexity requirements do not prevent credential sharing; they often increase user frustration, leading to even more sharing or insecure storage. Option C is wrong because biometric authentication introduces privacy and usability concerns (e.g., false rejection rates, inability to revoke compromised biometrics) and does not inherently prevent users from sharing a single enrolled device or bypassing the system. Option D is wrong because disabling remote access severely impacts patient care and operational efficiency, and it does not address the core issue of credential sharing among authorized users within the LAN.

294
MCQmedium

A financial services company needs to provide remote employees with access to internal applications. The security policy mandates that the solution must support granular access control based on user identity, integrate with the existing RADIUS server, and encrypt all traffic. The IT team is evaluating remote access technologies. Which of the following best meets these requirements?

A.SSL/TLS VPN with client certificates and local user database
B.Layer 2 Tunneling Protocol (L2TP) over IPsec with pre-shared key authentication
C.IPsec VPN in tunnel mode with IKEv2 and RADIUS authentication
D.Remote Desktop Protocol (RDP) gateway with Network Level Authentication
AnswerC

IPsec VPN in tunnel mode with IKEv2 provides strong encryption and can authenticate users via RADIUS (using EAP). Granular access control can be enforced through security policies tied to user identity after authentication. This directly meets the requirements for encryption, RADIUS integration, and per-user access control.

Why this answer

The requirement for granular access control based on user identity, RADIUS integration, and encryption points to an IPsec VPN in tunnel mode with IKEv2. IKEv2 supports EAP authentication, allowing RADIUS to authenticate users. Tunnel mode encrypts the entire packet, and security policies can be applied per user or group.

Other options lack RADIUS integration or do not provide the necessary access control.

Exam trap

The trap here is assuming that any VPN with encryption meets the requirements, while overlooking the need for RADIUS integration and user-specific access control.

295
MCQeasy

A company wants to ensure that its security policy is effectively enforced across all departments. Currently, the policy is published on the intranet and included in the employee handbook. However, the security team notices that many employees are not following the policy, leading to security incidents. Which of the following would be the most effective way to improve policy enforcement?

A.Include the policy in the employee handbook
B.Require annual signed acknowledgment of the policy
C.Conduct random audits and penalize non-compliance
D.Publish the policy on the intranet only
AnswerB

Requiring annual signed acknowledgment of the security policy is a highly effective method to ensure policy effectiveness. This active engagement process mandates that employees formally confirm they have read, understood, and agree to abide by the policy, creating a clear audit trail and establishing individual accountability. It significantly strengthens the organization's legal standing in cases of non-compliance, demonstrating due diligence in communication.

Why this answer

Requiring annual signed acknowledgment ensures that employees are aware of and agree to comply with the policy. This creates a record of acceptance and can be used in disciplinary actions. Publishing on intranet or handbook alone does not guarantee reading or acceptance.

Random audits with penalties may enforce compliance but without awareness, employees may not know what is expected.

296
MCQmedium

A security architect is designing a cryptographic system for a high-security environment where data must be encrypted both at rest and in transit, with granular access control. The system must be efficient for large volumes of data. Which approach is most appropriate?

A.Use symmetric encryption (e.g., AES-256) for all data and share keys out-of-band.
B.Use only asymmetric encryption (e.g., RSA) for all data.
C.Use asymmetric encryption for key exchange and symmetric encryption for data (hybrid cryptosystem).
D.Use hash functions (e.g., SHA-256) to ensure confidentiality.
AnswerC

A hybrid cryptosystem is the industry standard because it leverages the strengths of both symmetric and asymmetric encryption while mitigating their individual weaknesses. Asymmetric encryption, such as RSA or ECC, is used to securely exchange a temporary symmetric 'session key,' which is then used by symmetric algorithms like AES-256 for efficient bulk data encryption. This approach ensures secure key establishment without the performance overhead of asymmetric encryption for the actual data transfer, providing both confidentiality and efficiency.

Why this answer

A hybrid cryptosystem combines the efficiency of symmetric encryption (e.g., AES-256) for bulk data encryption with the secure key distribution of asymmetric encryption (e.g., RSA or ECDH). This approach ensures strong confidentiality for large volumes of data at rest and in transit, while enabling granular access control through per-user or per-session key management.

Exam trap

The trap here is that candidates may choose symmetric encryption alone (Option A) because it is fast, overlooking the critical need for secure key distribution and granular access control that only a hybrid system provides.

How to eliminate wrong answers

Option A is wrong because sharing symmetric keys out-of-band is impractical and insecure for large-scale, high-security environments; it lacks scalability and does not support granular access control without a secure key distribution mechanism. Option B is wrong because asymmetric encryption alone is computationally expensive and impractically slow for encrypting large volumes of data, making it unsuitable for bulk encryption. Option D is wrong because hash functions (e.g., SHA-256) are one-way and provide data integrity, not confidentiality; they cannot encrypt data or protect it from disclosure.

297
MCQmedium

A network analyst suspects a host on the internal network is sending abnormal amounts of traffic. Which tool should be used to capture and analyze the packets?

A.Wireshark
B.Nmap
C.Netstat
D.Traceroute
AnswerA

Wireshark is a powerful network protocol analyzer that captures and interactively displays the contents of network packets in real-time or from saved capture files. When suspecting a host, Wireshark allows an analyst to perform deep packet inspection, revealing the exact protocols, source/destination IPs, port numbers, and even the payload data, which is critical for identifying anomalous traffic patterns, malware communication, or unauthorized data transfers originating from or destined for that specific host.

Why this answer

Wireshark is the correct tool because it is a packet analyzer that captures live network traffic and provides deep inspection of individual packets, including headers and payloads. This allows the analyst to examine the abnormal traffic patterns, identify source/destination IPs, protocols, and payload content to diagnose the issue.

Exam trap

The trap here is that candidates often confuse Nmap's ability to send and receive packets for scanning with actual packet capture and analysis, but Nmap does not provide the deep packet inspection or continuous capture that Wireshark offers.

How to eliminate wrong answers

Option B (Nmap) is wrong because Nmap is a network scanning tool used for host discovery, port scanning, and service enumeration, not for capturing and analyzing live packet traffic. Option C (Netstat) is wrong because Netstat displays active network connections, routing tables, and interface statistics, but it does not capture or analyze packet contents. Option D (Traceroute) is wrong because Traceroute is a diagnostic tool that maps the path packets take to a destination by manipulating TTL values, not for capturing or analyzing packet payloads.

298
Multi-Selecteasy

Which three are network-layer security controls in a defense-in-depth strategy? (Choose THREE.)

Select 3 answers
A.Antivirus
B.Access control lists (ACLs)
C.Data encryption at rest
D.Firewall
E.Intrusion Detection System (IDS)
AnswersB, D, E

Access Control Lists (ACLs) are a fundamental network layer security control, typically configured on routers and firewalls, to filter incoming and outgoing network traffic. They operate by examining packet headers, specifically source and destination IP addresses (Network Layer, Layer 3) and often source and destination port numbers (Transport Layer, Layer 4). This granular control allows administrators to permit or deny traffic flows based on predefined rules, directly impacting network connectivity and resource access.

Why this answer

Access control lists (ACLs) (B) are correct because they are enforced on routers and layer-3 switches to filter packets by source/destination IP address, protocol, and port, directly controlling traffic at the network layer. Firewall (D) is correct because firewalls operate at layers 3 and 4 (and beyond), inspecting and permitting or denying packets based on IP addresses, ports, and connection state, which is a core network-layer defense-in-depth control. Intrusion Detection System (IDS) (E) is correct because network-based IDS sensors monitor layer-3 traffic for malicious patterns and anomalies, providing detection at the network layer.

Antivirus (A) is not a network-layer control; it is a host-based endpoint control that scans files and processes at the application/host level. Data encryption at rest (C) is not a network-layer control; it protects stored data on disks or databases at the data/presentation layer rather than filtering network traffic.

Exam trap

Candidates often confuse network-level controls with host-level or data-level controls. While antivirus and encryption at rest are critical security measures, they protect endpoints and stored data respectively, rather than securing the network transit layer.

299
Multi-Selecteasy

Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?

Select 2 answers
A.Can detect vulnerabilities that require valid credentials to be seen
B.Reduces network traffic
C.Eliminates false positives entirely
D.Provides more accurate patch-level information
E.Does not require network access
AnswersA, D

Authenticated scans operate with valid credentials, allowing them to access the internal configuration, file systems, and running processes of a target system. This deep access enables the detection of vulnerabilities that are only visible post-authentication, such as misconfigurations in internal services, insecure file permissions, or unpatched software versions that an unauthenticated scan might miss entirely.

Why this answer

Option A is correct because authenticated scanning logs into the target host with valid credentials, allowing the scanner to inspect local files, registry keys, installed packages, and configuration settings that are invisible to an unauthenticated scan, thereby detecting vulnerabilities that require credentials to be seen. Option D is correct because credentialed access lets the scanner read exact software versions, patch levels, and update history directly from the host, yielding more accurate patch-level information than remote banner grabbing or version inference. Option B is not correct because authenticated scans typically generate more traffic, not less, since they perform deeper enumeration and local checks.

Option C is not correct because no scanning method eliminates false positives entirely; authentication reduces but does not remove them. Option E is not correct because authenticated scans still require network access to reach and log into the target host.

Exam trap

CISSP often tests the misconception that authenticated scanning is 'quieter' or 'faster' — in reality it is deeper and heavier, and the exam expects you to recognize that its primary benefits are visibility and accuracy, not traffic reduction.

300
Multi-Selecteasy

Which TWO of the following are characteristics of a VPN that uses TLS?

Select 2 answers
A.Provides confidentiality
B.Requires a digital certificate on the server
C.Provides integrity
D.Operates at the network layer
E.Typically uses UDP port 500
AnswersA, C

A core characteristic of a VPN, particularly those utilizing protocols like TLS (Transport Layer Security) or IPsec, is the establishment of a secure, encrypted tunnel. This encryption process, often employing strong cryptographic algorithms such as AES (Advanced Encryption Standard), transforms the data into an unreadable format. This ensures that even if the data is intercepted during transit across an untrusted network, its content remains confidential and inaccessible to unauthorized parties.

Why this answer

TLS-based VPNs, such as OpenVPN in TLS mode, provide confidentiality through encryption of the tunneled traffic using symmetric ciphers (e.g., AES) negotiated during the TLS handshake. They also provide integrity via message authentication codes (e.g., HMAC) applied to each record, ensuring data has not been altered in transit. These are fundamental security services of the TLS protocol itself.

Exam trap

The trap here is that candidates confuse TLS VPNs with IPsec VPNs, incorrectly associating UDP port 500 or network layer operation with TLS, or assuming a digital certificate is mandatory for all TLS VPN deployments.

Page 3

Page 4 of 11

Page 5

All pages