Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 301–375

816 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
MCQhard

An organization uses a role-based access control (RBAC) model. After an audit, it was discovered that users have accumulated excessive permissions due to role proliferation. The security architect proposes migrating to an attribute-based access control (ABAC) model. Which challenge is MOST likely to be encountered during this migration?

A.Difficulty in assigning roles to users.
B.Reduced performance due to policy evaluation overhead.
C.Lack of support for ABAC in legacy applications.
D.Increased complexity in defining and managing attributes.
AnswerD

ABAC's power derives from its ability to make fine-grained access decisions based on a multitude of attributes related to the user, resource, action, and environment. This necessitates a robust and consistent attribute taxonomy, requiring significant upfront effort to define, standardize, collect, and maintain these attributes across various identity stores and systems. The sheer volume, dynamic nature, and precision required for attributes, coupled with their lifecycle management, represent the most substantial initial and ongoing complexity in an ABAC implementation.

Why this answer

Migrating from RBAC to ABAC requires defining a comprehensive set of attributes (subject, resource, environment) and the policies that combine them, which is inherently more complex than managing static role assignments. Role proliferation in RBAC often results from an attempt to mimic attribute-based decisions, but ABAC shifts the complexity from role engineering to attribute governance and policy logic, making attribute definition and management the primary challenge.

Exam trap

The trap here is that candidates confuse the operational challenge of performance (Option B) with the architectural challenge of attribute management, but CISSP emphasizes that the most significant hurdle in ABAC adoption is the complexity of defining and governing attributes, not the runtime evaluation speed.

How to eliminate wrong answers

Option A is wrong because RBAC already involves assigning roles to users, and migrating to ABAC eliminates the need for role assignment entirely, replacing it with attribute-based policy evaluation; difficulty in assigning roles is a pre-existing RBAC problem, not a new challenge of migration. Option B is wrong while ABAC can introduce performance overhead due to real-time policy evaluation, this is typically mitigated by policy caching and optimized engines, and it is not the most likely challenge compared to the fundamental complexity of attribute management. Option C is wrong because lack of support for ABAC in legacy applications is a potential integration issue, but it is not the most likely challenge; many legacy systems can be adapted via a policy enforcement point (PEP) or attribute proxy, whereas the core difficulty lies in defining and maintaining the attribute schema and policies themselves.

302
MCQmedium

A company is developing a mobile payment application. To comply with PCI DSS, what should be implemented to protect cardholder data during transmission?

A.Apply base64 encoding.
B.Use RC4 encryption.
C.Implement TLS 1.2 or higher with strong ciphers.
D.Use SSL 3.0.
AnswerC

TLS 1.2 or higher with strong ciphers encrypts cardholder data in transit between the mobile app and backend, preventing interception. PCI DSS requires strong cryptography for transmission over open, public networks, which older protocols and weak ciphers fail to provide.

Why this answer

TLS 1.2 or higher with strong ciphers is the correct choice because PCI DSS Requirement 4 mandates that cardholder data must be encrypted using strong cryptography (e.g., TLS 1.2/1.3) during transmission over open, public networks. TLS provides mutual authentication, data integrity, and confidentiality through a handshake that negotiates a session key, protecting against eavesdropping and tampering.

Exam trap

The trap here is that candidates confuse encoding (base64) with encryption, or assume that any SSL/TLS version is acceptable, but PCI DSS specifically requires TLS 1.2 or higher and prohibits deprecated protocols like SSL 3.0 and weak ciphers like RC4.

How to eliminate wrong answers

Option A is wrong because base64 encoding is not encryption; it is a reversible encoding scheme that provides no confidentiality, so cardholder data would be transmitted in plaintext and easily decoded. Option B is wrong because RC4 is a stream cipher that is deprecated and considered weak due to known biases in its keystream, making it unsuitable for PCI DSS compliance. Option D is wrong because SSL 3.0 is an obsolete protocol with multiple critical vulnerabilities (e.g., POODLE attack) and is explicitly prohibited by PCI DSS as of June 2018.

303
MCQmedium

A company is implementing TLS 1.3 to secure web communications. Which of the following features is unique to TLS 1.3 compared to earlier versions?

A.Mandatory forward secrecy using ephemeral Diffie-Hellman
B.Support for RSA key exchange
C.Only server-side authentication
D.Use of RC4 for encryption
AnswerA

TLS 1.3 mandates ephemeral Diffie-Hellman key exchange for all cipher suites, so every session achieves forward secrecy. Earlier versions permitted static RSA key transport, where compromise of the server's private key would expose previously recorded sessions.

Why this answer

TLS 1.3 (RFC 8446) mandates forward secrecy by requiring ephemeral Diffie-Hellman (DHE or ECDHE) key exchange for all handshakes. This ensures that session keys are never derived from long-term static keys, so compromising the server's private key does not compromise past session keys. Earlier TLS versions allowed static RSA key exchange, which lacks forward secrecy.

Exam trap

The trap here is that candidates may confuse 'mandatory forward secrecy' with optional forward secrecy in earlier TLS versions, or mistakenly think RSA key exchange is still supported in TLS 1.3.

How to eliminate wrong answers

Option B is wrong because TLS 1.3 removed support for RSA key exchange entirely; RSA key transport does not provide forward secrecy and is vulnerable to decryption if the private key is compromised. Option C is wrong because TLS 1.3 supports mutual authentication (client and server certificates) via CertificateRequest and CertificateVerify messages, not only server-side authentication. Option D is wrong because RC4 is a deprecated stream cipher that was removed from TLS 1.2 and is not supported in TLS 1.3; TLS 1.3 uses AEAD ciphers like AES-GCM and ChaCha20-Poly1305.

304
MCQhard

A company is designing an access control system for a highly sensitive database. They want to ensure that only authorized users can access data, and that access is automatically revoked when the user's context changes (e.g., job role change). Which model BEST meets these requirements?

A.Attribute-based access control (ABAC) with dynamic policy evaluation.
B.Discretionary access control (DAC) with access control lists.
C.Role-based access control (RBAC) with periodic reviews.
D.Mandatory access control (MAC) with security labels.
AnswerA

Attribute-based access control (ABAC) is the most suitable model for highly dynamic environments because it evaluates access requests against policies that consider multiple attributes of the subject (user), object (resource), action, and environment in real-time. This dynamic policy evaluation allows access decisions to adapt instantly to changing conditions, such as a user's current location, time of day, or the sensitivity of the data being accessed, providing fine-grained and context-aware authorization.

Why this answer

ABAC with dynamic policy evaluation is the best fit because it uses attributes (user, resource, environment) to make real-time access decisions. This allows access to be automatically revoked when context changes, such as a job role update, without manual intervention or periodic reviews.

Exam trap

The trap here is that candidates often choose RBAC (Option C) because it is role-based and seems to handle role changes, but they miss that RBAC typically requires manual or periodic updates to revoke access, whereas ABAC provides automatic, real-time revocation based on dynamic attribute changes.

How to eliminate wrong answers

Option B (DAC) is wrong because it relies on resource owners to grant permissions via ACLs, which lacks automatic revocation based on context changes and introduces security risks from user-controlled access. Option C (RBAC) is wrong because while it uses roles, it typically requires periodic reviews or manual updates to revoke access when a role changes, not automatic dynamic revocation. Option D (MAC) is wrong because it enforces access based on fixed security labels (e.g., classification levels) and does not adapt to dynamic context changes like job role updates; it is designed for static, hierarchical security policies.

305
Multi-Selectmedium

Which TWO of the following are essential elements of a secure software development lifecycle (SSDLC)? (Select exactly 2.)

Select 2 answers
A.Security testing during the verification phase
B.Threat modeling during the design phase
C.Code obfuscation after compilation
D.Penetration testing after deployment
E.User acceptance testing before release
AnswersA, B

Security testing during the verification phase is an essential element because it systematically evaluates the software's adherence to defined security requirements and identifies vulnerabilities before deployment. This phase encompasses various testing methodologies, such as static application security testing (SAST), dynamic application security testing (DAST), and vulnerability scanning, ensuring that implemented security controls function as intended. It validates that the application can withstand anticipated attacks and protects sensitive data effectively. This proactive validation is critical for minimizing post-release security incidents.

Why this answer

Option A is correct because security testing during the verification phase is an essential SSDLC element: it validates that security requirements and controls are actually implemented in the code, typically via SAST, DAST, and security-focused test cases, so defects are found before release rather than in production. Option B is correct because threat modeling during the design phase is a core SSDLC practice: it identifies assets, trust boundaries, data flows, and potential threats (e.g., using STRIDE) early, when architectural changes are cheapest and most effective. Option C is not essential to an SSDLC because code obfuscation after compilation is only a defense-in-depth technique to hinder reverse engineering, not a lifecycle security activity, and it does not address vulnerabilities.

Option D is not essential to an SSDLC because penetration testing after deployment is a late, point-in-time assessment; while valuable, it is not a foundational lifecycle element and cannot replace earlier design and verification controls. Option E is not essential to an SSDLC because user acceptance testing before release focuses on functional fitness for business use, not on identifying or mitigating security weaknesses.

Exam trap

CISSP often tests the distinction between proactive, lifecycle-integrated security activities (threat modeling, security testing in verification) and reactive or optional security measures (penetration testing, obfuscation), tricking candidates into selecting any security-sounding option rather than the ones that are essential SSDLC elements.

306
MCQhard

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

A.To transfer ownership of PHI to the business associate
B.To authorize the use of PHI for marketing purposes
C.To require the business associate to comply with HIPAA Privacy and Security Rules
D.To allow the business associate to disclose PHI to any third party
AnswerC

The primary purpose of a Business Associate Agreement (BAA) is to contractually obligate the business associate to comply with the applicable provisions of the HIPAA Privacy and Security Rules. This legally binding agreement ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect Protected Health Information (PHI), reports breaches, and limits PHI use and disclosure to only what is necessary for the services provided, thereby extending the chain of trust.

Why this answer

A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and a business associate that ensures the business associate will appropriately safeguard Protected Health Information (PHI). It mandates compliance with the HIPAA Privacy and Security Rules and specifies permitted uses and disclosures of PHI. The BAA does not transfer ownership or grant unrestricted rights to PHI.

Exam trap

CISSP often tests the misconception that a BAA grants ownership or broad rights to PHI, when in fact it imposes strict compliance obligations and limits on the business associate.

How to eliminate wrong answers

Option A is wrong because a BAA does not transfer ownership of PHI; ownership remains with the covered entity or the individual, and the business associate is only a custodian. Option B is wrong because a BAA does not authorize marketing use of PHI; marketing requires specific patient authorization under HIPAA, and a BAA cannot override that. Option D is wrong because a BAA restricts disclosures to those permitted by the agreement or required by law; it does not allow unrestricted disclosure to any third party.

307
Multi-Selecthard

An organization is reviewing its media sanitization procedures. Which TWO methods are considered acceptable for sanitizing solid-state drives (SSDs) according to NIST SP 800-88 guidelines?

Select 2 answers
A.Degaussing
B.Cryptographic erase
C.Physical destruction (shredding or pulverizing)
D.Overwriting with a random pattern
E.Data wiping software
AnswersB, C

Cryptographic erasure (CE) sanitizes media by permanently deleting or overwriting the decryption keys associated with self-encrypting drives (SEDs). Without the key, the ciphertext remaining on the storage chips becomes mathematically infeasible to decrypt. This process is highly efficient and completed in seconds, making it ideal for both solid-state and magnetic media.

Why this answer

According to NIST SP 800-88, cryptographic erase (Option B) is an acceptable sanitization method for SSDs because it destroys the media encryption key (MEK) used by the drive's built-in self-encrypting drive (SED) controller, rendering all data on the NAND flash unreadable without ever needing to overwrite every cell. Physical destruction (Option C) via shredding or pulverizing is also acceptable because it reduces the flash memory chips to particles small enough that data recovery is infeasible, which NIST lists as a valid media disposal technique. Degaussing (Option A) does not belong because SSDs use flash memory rather than magnetic media, so a magnetic field has no effect on the stored charge.

Overwriting with a random pattern (Option D) is not reliable for SSDs due to wear leveling, over-provisioning, and remapped blocks that can retain residual data outside the logical address space. Data wiping software (Option E) is likewise not an approved SSD sanitization method in NIST SP 800-88 because it cannot guarantee that every flash cell, including spare and remapped blocks, is overwritten.

Exam trap

CISSP often tests the misconception that overwriting or degaussing works on SSDs, when in fact only cryptographic erase or physical destruction are reliable per NIST SP 800-88.

308
MCQmedium

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

A.Project management office
B.Incident response team
C.Change Advisory Board (CAB)
D.Security operations center
AnswerC

The Change Advisory Board (CAB) is a crucial component of a robust change management process, specifically tasked with reviewing, assessing, prioritizing, and authorizing proposed changes to an organization's IT services and infrastructure. Comprising diverse stakeholders, the CAB ensures that all potential impacts, risks, and resource requirements are thoroughly evaluated, including security implications, before a change is approved for implementation. This structured review minimizes adverse effects and maintains system stability.

Why this answer

The Change Advisory Board (CAB) is the formal group within ITIL-based change management responsible for reviewing, assessing, and approving major or high-risk changes. Major changes typically require a CAB meeting to evaluate impact, resource requirements, and rollback plans before authorization. This ensures changes do not introduce security vulnerabilities or disrupt critical operations.

Exam trap

The CISSP exam often tests the distinction between operational roles (SOC, Incident Response) and governance/approval bodies (CAB), leading candidates to confuse real-time monitoring functions with change authorization responsibilities.

How to eliminate wrong answers

Option A is wrong because the Project Management Office (PMO) oversees project portfolios and ensures alignment with business goals, but it does not have the authority or technical mandate to approve operational changes to production systems. Option B is wrong because the Incident Response Team handles active security incidents and post-incident remediation, not the proactive review and approval of planned changes. Option D is wrong because the Security Operations Center (SOC) monitors real-time security events and alerts, but it is not chartered to approve changes; its role is to detect and respond to anomalies that may result from changes, not to authorize them.

309
Multi-Selecteasy

Which TWO of the following are fundamental phases of a secure software development lifecycle (SSDLC) where security should be integrated? (Select exactly two.)

Select 2 answers
A.Testing and validation
B.Software retirement
C.User acceptance testing
D.Production operations
E.Requirements gathering
AnswersA, E

Security testing should occur before release.

Why this answer

Requirements gathering (E) is a fundamental SSDLC phase where security must be integrated, since security requirements, compliance obligations, and risk analysis (e.g., misuse/abuse cases, data classification) are defined before design and coding begin. Testing and validation (A) is also a fundamental SSDLC phase where security is integrated through activities such as static/dynamic application security testing (SAST/DAST), penetration testing, and vulnerability validation to confirm controls work as intended. Software retirement (B) is a lifecycle consideration but not one of the core SSDLC phases emphasized for security integration in this context.

User acceptance testing (C) is a type of testing, not a distinct fundamental SSDLC phase, and it focuses on business fitness rather than security-specific validation. Production operations (D) is an operational/maintenance concern outside the core development lifecycle phases where security is primarily built in.

Exam trap

The CISSP exam often tests the misconception that user acceptance testing (UAT) is a security phase, but UAT is strictly for functional acceptance by business stakeholders, not for security validation.

310
Multi-Selecteasy

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

Select 3 answers
A.Application DLP
B.Network DLP
C.Cloud DLP
D.Endpoint DLP
E.Physical DLP
AnswersB, C, D

Network DLP systems are strategically positioned at key network egress points, such as internet gateways or between network segments, to inspect all data traversing the network perimeter. This deployment type actively monitors data "in motion" by analyzing network traffic, including email, web protocols, and file transfers, for sensitive content that violates predefined organizational policies. Its primary function is to prevent unauthorized data exfiltration before it leaves the controlled network environment.

Why this answer

Network DLP (B) is correct because it monitors and inspects data in transit at network egress points such as email gateways, web proxies, and firewalls, typically using deep packet inspection to detect sensitive data leaving the perimeter. Cloud DLP (C) is correct because it applies policy enforcement to data stored in or moving through SaaS, IaaS, and PaaS environments via APIs and CASB integrations, covering cloud storage, email, and collaboration apps. Endpoint DLP (D) is correct because it runs agents on workstations and servers to control data at rest and in use, monitoring file operations, USB/removable media, clipboard, printing, and screen capture.

Application DLP and Physical DLP are not standard DLP control categories: application-level enforcement is generally a function within endpoint or network DLP, and physical controls (locked cabinets, badge access, media destruction) belong to physical security rather than DLP technology classifications.

Exam trap

CISSP often tests whether candidates confuse DLP control categories with unrelated security controls — the trap is selecting plausible-sounding but non-standard options like 'Application DLP' or 'Physical DLP' instead of the three canonical types (network, endpoint, cloud).

311
Multi-Selecthard

Which THREE are components of a privileged access management (PAM) solution?

Select 3 answers
A.Credential vaulting
B.Password complexity rules
C.Multi-factor authentication for all users
D.Just-in-time privilege elevation
E.Session recording and monitoring
AnswersA, D, E

Credential vaulting is a fundamental component of PAM, securely centralizing and managing the lifecycle of privileged credentials, such as administrator passwords, SSH keys, and API keys. It eliminates hardcoded credentials, enforces automated rotation, and controls access to these sensitive assets, thereby significantly reducing the risk of credential theft and misuse by preventing direct user knowledge of the actual passwords.

Why this answer

Credential vaulting (A) is a core PAM component because it stores privileged account credentials in an encrypted repository, allowing checkout, rotation, and brokering so administrators never need to know the underlying passwords. Just-in-time privilege elevation (D) is correct because PAM solutions grant elevated rights only for the specific task and time window needed, then automatically revoke them, reducing standing privileged access. Session recording and monitoring (E) is also correct because PAM platforms proxy and record privileged sessions (e.g., SSH, RDP) to provide audit trails, keystroke logging, and real-time threat detection.

Password complexity rules (B) are a general identity/password-policy control, not a defining PAM component, and multi-factor authentication for all users (C) is broader than PAM—MFA may integrate with PAM, but applying it to every user is an enterprise-wide authentication requirement rather than a PAM component itself.

Exam trap

The trap here is that candidates confuse general security best practices (like password complexity or MFA for all users) with the specific architectural components that define a PAM solution, leading them to select options that are not core PAM elements.

312
MCQhard

A financial institution must ensure that transactions are well-formed and enforce separation of duties to prevent fraud. Which security model best addresses these requirements?

A.Biba
B.Clark-Wilson
C.Brewer-Nash
D.Bell-LaPadula
AnswerB

The Clark-Wilson integrity model is specifically designed for commercial environments requiring strong data integrity, well-formed transactions, and accountability. It enforces integrity through constrained data items (CDIs) that can only be modified by certified transformation procedures (TPs), which are executed by authorized users under strict separation of duties. This model directly addresses the need for controlled, validated operations and accountability in financial systems, ensuring transactions are processed correctly and preventing fraud.

Why this answer

The Clark-Wilson model is specifically designed for commercial integrity and enforces well-formed transactions and separation of duties through its access control triple (subject, program, object). It ensures that data can only be modified through certified transformation procedures, which directly addresses the requirement for well-formed transactions and fraud prevention via separation of duties. This makes it the correct model for financial transaction integrity.

Exam trap

CISSP often tests the confusion between integrity models (Biba, Clark-Wilson) and confidentiality models (Bell-LaPadula), and between Clark-Wilson's commercial integrity focus and Biba's hierarchical integrity levels.

How to eliminate wrong answers

Option A is wrong because the Biba model addresses integrity via hierarchical levels (no read down, no write up) but does not enforce well-formed transactions or separation of duties. Option C is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in consulting scenarios, not transaction integrity or separation of duties. Option D is wrong because Bell-LaPadula is a confidentiality model (no read up, no write down) and does not address integrity or separation of duties.

313
MCQeasy

Which access control model allows the owner of a resource to grant or deny access to other users?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Role-Based Access Control (RBAC)
AnswerB

Discretionary Access Control (DAC) is the correct model because it empowers the resource owner to define and modify access permissions for the resources they own. Under DAC, the owner can grant or revoke specific access rights (e.g., read, write, execute) to other users or groups, typically through mechanisms like Access Control Lists (ACLs) or permission bits. This model provides flexibility by allowing individual users to manage access to their own data and files, making it prevalent in many common operating systems.

Why this answer

Discretionary Access Control (DAC) is defined by the property that the owner of a resource (its creator or designated owner) has discretion to grant or revoke access to other subjects, typically via ACLs or permission bits. This owner-controlled delegation is the defining characteristic that separates DAC from MAC, RBAC, and ABAC.

Exam trap

CISSP often tests the owner-discretion distinction, so candidates who see 'owner' and jump to RBAC (because roles are assigned by owners) or ABAC (because attributes can be owner-defined) miss that DAC is specifically the model where the resource owner directly controls access.

How to eliminate wrong answers

Option A is wrong because in Mandatory Access Control (MAC), access decisions are made by the system based on security labels (e.g., Bell-LaPadula, Biba) and a central policy — owners cannot override or delegate access at their discretion. Option C is wrong because Attribute-Based Access Control (ABAC) evaluates policies against attributes of subjects, objects, and environment (e.g., department, time, location), not owner discretion. Option D is wrong because Role-Based Access Control (RBAC) grants access based on the roles assigned to a user, with permissions managed centrally by administrators rather than by resource owners.

314
Multi-Selectmedium

An incident responder is analyzing a network compromise that involved ICMP attacks. Which THREE types of ICMP attacks could have been used to disrupt network operations? (Select three.)

Select 3 answers
A.Smurf attack
B.ICMP redirect attack
C.ARP poisoning
D.SYN flood
E.Ping of Death
AnswersA, B, E

A Smurf attack is a distributed denial-of-service (DDoS) technique that leverages ICMP echo requests and IP broadcast addresses. An attacker sends a large number of ICMP echo requests to a network's broadcast address, spoofing the source IP to be the victim's address. All hosts on that network then reply to the spoofed source, flooding the victim with an overwhelming volume of ICMP echo replies, effectively causing a denial of service.

Why this answer

The Smurf attack (A) is correct because it spoofs the victim's source IP and sends ICMP echo requests to a network's broadcast address, causing every host to reply to the victim and amplifying traffic to disrupt operations. The ICMP redirect attack (B) is correct because forged ICMP Type 5 redirect messages can alter a host's routing table, sending traffic through an attacker-controlled path and disrupting or intercepting network communications. The Ping of Death (E) is correct because it sends malformed or oversized ICMP echo request packets (historically exceeding the 65,535-byte IP packet limit) that can crash or destabilize vulnerable systems.

ARP poisoning (C) is not an ICMP attack; it manipulates ARP cache entries at Layer 2. SYN flood (D) is a TCP-based attack abusing the three-way handshake, not ICMP.

Exam trap

The trap here is that candidates confuse ARP poisoning and SYN flood with ICMP attacks because they are common network attacks, but they operate at different layers (Layer 2 and Layer 4, respectively) and do not use ICMP as the attack vector.

315
MCQhard

A security architect is reviewing the access control model for a microservices architecture. Which approach minimizes the risk of privilege escalation from a compromised service?

A.Use attribute-based access control (ABAC) with service-specific policies.
B.Implement role-based access control (RBAC) with global roles.
C.Use API keys for all service-to-service communication.
D.Deploy a single sign-on solution.
AnswerA

Attribute-Based Access Control (ABAC) is the most suitable model for complex, dynamic authorization requirements in modern service architectures. It evaluates access requests based on a combination of attributes associated with the subject (e.g., calling service identity), object (e.g., target resource), action (e.g., read, write), and environment (e.g., time of day, network location). By implementing service-specific policies, ABAC enables highly granular, context-aware authorization decisions, effectively limiting privilege escalation by ensuring services only access what is precisely needed under specific conditions.

Why this answer

ABAC with service-specific policies minimizes privilege escalation because it enforces fine-grained, context-aware permissions (e.g., user attributes, resource type, action) per microservice. If a service is compromised, its policies are scoped only to that service’s required operations, preventing lateral movement or elevation to other services. This aligns with the principle of least privilege and defense in depth in a distributed architecture.

Exam trap

The trap here is that candidates confuse authentication (API keys, SSO) with authorization (ABAC, RBAC), assuming that verifying identity alone prevents privilege escalation, when in fact fine-grained authorization policies are required to limit what a compromised service can do.

How to eliminate wrong answers

Option B is wrong because RBAC with global roles assigns broad, static permissions across all services, so a compromised service inherits excessive privileges that can be exploited for escalation. Option C is wrong because API keys authenticate services but do not enforce authorization policies; a compromised key grants full access to the target service without granular control. Option D is wrong because SSO authenticates users across services but does not restrict what a compromised service can do; it centralizes identity but not authorization, leaving privilege escalation risks unaddressed.

316
Multi-Selecthard

A security architect is designing a trusted recovery capability for a high-assurance system that must continue operating during a failure without violating its security policy. The system must be able to recover from a failure while maintaining the security of the data it processes, and must not enter an insecure state during recovery. Which two recovery strategies best satisfy the requirement to maintain security during failure and recovery? (Choose two.)

Select 2 answers
A.Fail-secure operation, where the system denies access to resources and defaults to a secure state when a failure is detected.
B.Fail-open operation, where the system allows all access to maintain availability during a failure.
C.Cold restart, where the system reboots and reloads all software from scratch after a failure.
D.Fail-soft operation, where the system continues to provide degraded but secure functionality while the failed component is isolated.
E.Manual intervention, where an administrator restores the system from backups after a failure.
AnswersA, D

Fail-secure operation ensures that when a failure occurs, the system defaults to a state that denies access and protects data, rather than allowing unsafe access. This maintains the security policy during recovery by refusing to grant access until the system is restored. It prevents an insecure state, which is exactly what the requirement demands, and is a core principle in trusted recovery design for high-assurance systems.

Why this answer

Fail-soft and fail-secure operations are the two recovery strategies that maintain security during failure. Fail-soft keeps the system running in a degraded but secure mode, isolating the failed component, while fail-secure defaults to denying access and protecting data. Both prevent the system from entering an insecure state, which is essential for trusted recovery in high-assurance systems.

Fail-open, cold restart, and manual intervention either compromise security or fail to guarantee continuous protection during recovery.

Exam trap

The trap here is assuming that any recovery method that restores availability is acceptable, when the requirement is specifically to maintain security during failure and recovery, which fail-soft and fail-secure achieve but fail-open does not.

317
MCQmedium

A security architect is implementing a system that must prevent conflicts of interest for a consulting firm serving competing clients. Which security model is best suited for this requirement?

A.Take-Grant
B.Brewer-Nash
C.Clark-Wilson
D.Graham-Denning
AnswerB

The Brewer-Nash model, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on prior access history. It ensures that a subject who has accessed information from one company within a "conflict of interest class" cannot subsequently access information from a competing company within the same class. This dynamic access control mechanism effectively enforces ethical walls, making it the ideal choice for scenarios requiring the prevention of information leakage between competing entities.

Why this answer

The Brewer-Nash model (also called the Chinese Wall model) is specifically designed to prevent conflicts of interest by dynamically restricting access based on what a subject has already accessed. Once a consultant accesses data from one competing client, they are blocked from accessing data about that client's competitors. This dynamic, history-based access control is exactly what the scenario requires.

Exam trap

CISSP often tests the confusion between Brewer-Nash (conflict of interest) and Clark-Wilson (integrity) — candidates pick Clark-Wilson because both sound 'commercial' and integrity-focused, missing the conflict-of-interest keyword.

How to eliminate wrong answers

Option A is wrong because Take-Grant is a model for describing how rights can be transferred or delegated between subjects and objects — it addresses permission propagation, not conflict-of-interest separation. Option C is wrong because Clark-Wilson focuses on data integrity through well-formed transactions and separation of duties, not on preventing conflicts of interest across competing clients. Option D is wrong because Graham-Denning defines eight primitive operations for secure subject/object creation and rights transfer — it is a foundational access-control model, not a conflict-of-interest model.

318
MCQhard

A financial services company has a hybrid cloud environment with on-premises servers and a public cloud provider. The security team recently discovered that an attacker exfiltrated sensitive customer data from a cloud storage bucket. The investigation reveals that the bucket was configured with a bucket policy that allowed anonymous read access. The security architect must redesign the architecture to prevent such incidents. The company uses AWS for cloud services. The architect proposes the following: (1) Enable AWS CloudTrail and Amazon GuardDuty for monitoring. (2) Implement AWS Identity and Access Management (IAM) roles for applications instead of long-term access keys. (3) Use AWS Key Management Service (KMS) to encrypt data at rest. (4) Configure a VPC with a NAT gateway and private subnets for all compute resources. (5) Implement S3 bucket policies that deny all access unless explicitly allowed by a specific IAM role. During a review, the chief information security officer (CISO) points out that one of these measures does not directly address the root cause of the incident. Which measure is least effective in preventing unauthorized access to S3 buckets?

A.Use AWS KMS to encrypt data at rest
B.Configure a VPC with private subnets and a NAT gateway
C.Enable AWS CloudTrail and Amazon GuardDuty for monitoring
D.Implement IAM roles for applications instead of long-term access keys
AnswerC

Enabling AWS CloudTrail and Amazon GuardDuty is a critical detective control for identifying security misconfigurations and unauthorized activity. CloudTrail logs all API calls, including changes to S3 bucket policies that could expose data, providing an audit trail. GuardDuty continuously monitors for malicious activity and unusual S3 access patterns, such as anonymous access or data exfiltration attempts, alerting security teams to potential breaches for rapid response.

Why this answer

(enabling AWS CloudTrail and Amazon GuardDuty) is a detective control, not a preventive one. The root cause of the incident was a misconfigured bucket policy that allowed anonymous read access. Monitoring tools can detect unauthorized access after it occurs but cannot prevent it.

The other options directly address the root cause by enforcing least privilege, encrypting data, or restricting network access.

Exam trap

The trap here is confusing detective controls (monitoring) with preventive controls (access policies, encryption, network segmentation), leading candidates to think that enabling logging and threat detection directly prevents the root cause of a misconfigured bucket policy.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest with AWS KMS does not prevent unauthorized access; it only protects data confidentiality if access is gained, but the root cause is a permissive bucket policy that allows anonymous read access. Option B is wrong because configuring a VPC with private subnets and a NAT gateway does not affect S3 bucket policies; S3 is a global service and bucket policies are evaluated independently of network architecture. Option D is wrong because implementing IAM roles instead of long-term access keys addresses credential management but does not prevent anonymous access granted by a bucket policy; the incident occurred because the bucket policy allowed anonymous read, not because of compromised keys.

319
MCQhard

An organization is adopting DevOps. Which of the following is a primary security concern when integrating security into CI/CD pipelines?

A.Credential management for automated tools.
B.Increased number of releases.
C.Automated testing slows down deployment.
D.Resistance from development teams.
AnswerA

In a DevOps environment, automated tools frequently require access to various systems, repositories, and environments. If these credentials are hardcoded, stored insecurely in source control, or managed without robust secrets management solutions, they become a critical attack vector. A compromise of such credentials could grant an attacker extensive unauthorized access across the entire software delivery pipeline, from development to production, leading to data breaches or system manipulation. This makes secure credential management a paramount security challenge.

Why this answer

Credential management for automated tools is a primary security concern because CI/CD pipelines require automated access to repositories, artifact registries, and deployment environments. Hardcoding secrets or using weak storage (e.g., plaintext in scripts) exposes credentials to compromise via pipeline logs, version control history, or insider threats. Proper management using vaults (e.g., HashiCorp Vault) or secret injection (e.g., Kubernetes Secrets) is critical to prevent unauthorized access.

Exam trap

The trap here is that candidates may focus on operational or cultural issues (like resistance or speed) instead of the fundamental technical risk of credential exposure in automated, unattended processes.

How to eliminate wrong answers

Option B is wrong because an increased number of releases is a DevOps benefit, not a security concern; it can actually improve security by enabling faster patching. Option C is wrong because automated testing, while potentially slower, is a security enabler (e.g., SAST/DAST) that catches vulnerabilities early, not a primary concern. Option D is wrong because resistance from development teams is a cultural or process issue, not a technical security concern specific to CI/CD pipeline integration.

320
MCQeasy

A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?

A.Security review
B.Vulnerability assessment
C.Security audit
D.Penetration test
AnswerB

A vulnerability assessment systematically scans systems, applications, and networks for known security weaknesses, configuration errors, and missing patches. It utilizes automated tools and manual analysis to identify potential flaws without attempting to exploit them. The primary goal is to provide a prioritized list of vulnerabilities that could be exploited, enabling organizations to proactively address risks before they are leveraged by attackers.

Why this answer

A vulnerability assessment is a systematic review of security weaknesses in a system or application, but it does not involve actively exploiting those weaknesses. The question specifies that the analyst is asked to identify vulnerabilities without attempting to exploit them, which directly matches the definition of a vulnerability assessment. This type of assessment typically uses automated scanners (e.g., Nessus, OpenVAS) and manual checks to enumerate potential vulnerabilities, such as missing patches or misconfigurations, without moving to the exploitation phase.

Exam trap

The trap here is that candidates often confuse vulnerability assessment with penetration testing, assuming that any active testing must include exploitation, but the CISSP exam emphasizes the distinction that vulnerability assessment stops at identification, while penetration testing includes exploitation.

How to eliminate wrong answers

Option A is wrong because a security review is a broad, often high-level evaluation of security policies, procedures, and controls, not a focused technical scan for specific vulnerabilities in a web application. Option C is wrong because a security audit is a formal, compliance-driven examination against a defined standard (e.g., ISO 27001, PCI DSS), which may include vulnerability identification but is not limited to it and often involves verifying controls rather than just scanning for weaknesses. Option D is wrong because a penetration test actively exploits vulnerabilities to determine the extent of compromise, which contradicts the question's condition of not attempting to exploit them.

321
Multi-Selecthard

Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)

Select 3 answers
A.Integration with all third-party applications
B.User training to reduce false positives and increase acceptance
C.Monitoring of data in use, in motion, and at rest
D.Data classification schemes to identify sensitive data
E.Blocking all data transfers to external devices
AnswersB, C, D

Effective user training is a critical consideration for successful Data Loss Prevention (DLP) implementation. Educating users on what constitutes sensitive data, acceptable data handling practices, and the purpose of DLP policies helps significantly reduce the occurrence of false positives. This understanding also fosters user acceptance and compliance, minimizing frustration and workarounds when legitimate business activities are temporarily flagged, ultimately improving the overall effectiveness and adoption of the DLP solution.

Why this answer

User training is a critical component of a successful DLP implementation. Without proper training, users may inadvertently trigger false positives by mishandling data or may attempt to bypass controls they perceive as overly restrictive. Training helps users understand classification labels and proper data handling procedures, reducing the operational burden on security teams and increasing overall acceptance of DLP policies.

Exam trap

The trap here is that candidates often assume DLP must be all-encompassing (e.g., blocking all transfers or integrating with every app), but the CISSP emphasizes risk-based, balanced controls that include user awareness and layered monitoring.

322
MCQeasy

A small business wants to implement a security policy that balances protection with usability. Which of the following is the MOST important factor when developing the policy?

A.Adopting a template from a similar organization to save time.
B.Aligning the policy with business objectives and risk appetite.
C.Ensuring the policy is enforceable with technical controls.
D.Basing the policy solely on regulatory compliance requirements.
AnswerB

This is the most crucial initial step because a security policy must fundamentally support the organization's mission and strategic goals. By aligning with business objectives, the policy ensures security measures facilitate, rather than hinder, operations. Incorporating the organization's risk appetite ensures that security investments and controls are proportionate to the acceptable level of residual risk, optimizing resource allocation and providing relevant protection.

Why this answer

A security policy must be aligned with the organization's business objectives and risk appetite to ensure it supports operations without imposing unnecessary restrictions. For a small business, this balance is critical—overly strict controls can hinder productivity, while weak controls increase risk. The policy should reflect the specific threats and tolerances of the business, not generic templates or compliance-only checklists.

Exam trap

The trap here is that candidates often confuse 'enforceability' (Option C) with policy effectiveness, but the CISSP emphasizes that policy must first be business-aligned; technical enforcement is a later step in the governance hierarchy.

How to eliminate wrong answers

Option A is wrong because adopting a template from a similar organization ignores the unique risk profile, business processes, and regulatory environment of the small business, leading to misaligned controls and potential gaps. Option C is wrong because enforceability with technical controls is a secondary consideration—the policy must first define what is acceptable; technical controls are implementation details that can be adjusted later. Option D is wrong because basing the policy solely on regulatory compliance requirements creates a minimum-security baseline that may not address the business's actual risk exposure or operational needs, leaving it vulnerable to non-compliance-related threats.

323
Multi-Selectmedium

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

Select 2 answers
A.Performing threat hunting
B.Monitoring SIEM alerts and performing initial triage
C.Escalating incidents to Tier 2 when necessary
D.Conducting in-depth forensic analysis
E.Developing new detection rules for the SIEM
AnswersB, C

Tier 1 SOC analysts are primarily responsible for the continuous monitoring of security information and event management (SIEM) systems. Their core duty involves reviewing incoming alerts, correlating events, and performing an initial assessment to determine if an alert represents a legitimate security incident. This initial triage ensures that potential threats are identified promptly and categorized for appropriate next steps.

Why this answer

Option B is correct because Tier 1 analysts are the first line of defense in a SOC, continuously monitoring SIEM alerts and performing initial triage to determine whether an alert is a true positive, false positive, or benign event. Option C is correct because a core Tier 1 responsibility is escalating validated or suspicious incidents to Tier 2 for deeper investigation when the alert exceeds their scope or requires advanced analysis. Threat hunting (A) is typically performed by Tier 2 or Tier 3 analysts who proactively search for hidden threats rather than react to alerts.

In-depth forensic analysis (D) is a Tier 3 or dedicated incident response function requiring specialized tools and expertise. Developing new detection rules for the SIEM (E) is usually the responsibility of Tier 2/Tier 3 analysts or detection engineers, not Tier 1.

Exam trap

CISSP often tests the boundaries between SOC tiers, so candidates assign advanced tasks like threat hunting or detection engineering to Tier 1 when those belong to Tier 2 or Tier 3.

324
MCQmedium

A multinational corporation is expanding its operations into a new country with strict data protection laws. The company needs to ensure compliance while maintaining operational efficiency. Which of the following is the BEST approach to manage this risk?

A.Accept the risk of non-compliance as a cost of doing business and set aside a contingency fund for fines.
B.Assign legal counsel to review local laws and implement a one-time compliance checklist.
C.Create a uniform global privacy policy that satisfies all jurisdictions with minimal adjustments.
D.Adopt a privacy-by-design framework and conduct a Data Protection Impact Assessment (DPIA) before launching operations.
AnswerD

Adopting a privacy-by-design framework ensures that privacy and data protection are proactively embedded into the design and architecture of systems and business practices from the outset, rather than being an afterthought. Conducting a Data Protection Impact Assessment (DPIA) before launching operations is crucial for identifying, assessing, and mitigating privacy risks associated with new data processing activities. This proactive approach is essential for achieving and demonstrating compliance with stringent global privacy regulations.

Why this answer

A privacy-by-design framework ensures data protection is embedded into systems and processes from the outset, while a Data Protection Impact Assessment (DPIA) systematically identifies and mitigates privacy risks specific to the new jurisdiction. This proactive, risk-based approach aligns with regulatory requirements like the GDPR and demonstrates due diligence, reducing the likelihood of non-compliance and operational disruption.

Exam trap

The trap here is that candidates often choose Option B (one-time compliance checklist) because it seems practical and legally focused, but they overlook that privacy compliance is an ongoing process requiring continuous risk assessment and adaptation, not a single review event.

How to eliminate wrong answers

Option A is wrong because accepting non-compliance risk as a cost of doing business ignores legal obligations and can lead to severe penalties, reputational damage, and operational bans, which is not a viable risk management strategy under strict data protection laws. Option B is wrong because a one-time compliance checklist is static and fails to address ongoing regulatory changes, data lifecycle management, and the need for continuous monitoring and adaptation required by modern privacy frameworks. Option C is wrong because a uniform global privacy policy cannot satisfy all jurisdictions due to conflicting requirements (e.g., GDPR’s strict consent vs. other laws’ legitimate interest provisions), and minimal adjustments often result in gaps that violate local laws.

325
Multi-Selecthard

Which TWO of the following are valid data de-identification techniques?

Select 2 answers
A.Encryption
B.Access control
C.Data masking
D.Backup
E.Tokenization
AnswersC, E

Data masking is a de-identification technique that replaces sensitive, identifiable information with structurally similar but inauthentic data. This process creates a functional but fictitious version of the original data, suitable for purposes like testing, training, or development, without exposing actual personal identifiers. The original data cannot be reconstructed from the masked version, effectively breaking the link to the individual while maintaining data utility.

Why this answer

Data masking (C) is a valid de-identification technique because it replaces sensitive values with fictitious but structurally similar data (for example, showing only the last four digits of a credit card), so the original information cannot be reconstructed from the masked output. Tokenization (E) is also valid because it substitutes a sensitive value with a non-sensitive surrogate token that maps back to the original only through a securely stored token vault, removing the sensitive data from the exposed system. Encryption (A) is not de-identification here because it is a reversible confidentiality control that preserves the original data and can be decrypted with the key.

Access control (B) restricts who may view data but does not alter or remove the identifying content itself. Backup (D) is a data availability and recovery measure, not a technique for de-identifying data.

Exam trap

Candidates often confuse encryption with de-identification. While encryption protects data confidentiality, it is a cryptographic control that is easily reversed with a key and does not structurally de-identify the dataset for general use. De-identification techniques like masking and tokenization are specifically designed to remove or replace direct and indirect identifiers so that the data can be used or processed with reduced privacy risk.

326
MCQeasy

Which physical security concept uses natural surveillance, territorial reinforcement, and access control to deter crime in built environments?

A.TEMPEST
B.Faraday cage
C.Defense in depth
D.CPTED
AnswerD

Crime Prevention Through Environmental Design (CPTED) is a multidisciplinary approach that strategically uses the physical environment to reduce crime and the fear of crime. It achieves this by manipulating the built environment to enhance natural surveillance, control access, define territoriality, and maintain spaces, thereby increasing the perceived risk for offenders and reducing opportunities for crime. Natural surveillance, a core CPTED principle, involves designing spaces where legitimate users can naturally observe their surroundings, making criminal acts more difficult or noticeable.

Why this answer

CPTED (Crime Prevention Through Environmental Design) is the discipline that applies natural surveillance, territorial reinforcement, and access control to the built environment to reduce crime and fear of crime. These three principles, along with maintenance and activity support, form the core CPTED framework used by security architects and urban planners. The question's three named elements map directly to CPTED's foundational principles.

Exam trap

CISSP often tests acronym recognition by pairing CPTED with other physical/EMSEC terms like TEMPEST and Faraday cage, so candidates who don't know that CPTED stands for Crime Prevention Through Environmental Design may pick a technical countermeasure instead.

How to eliminate wrong answers

Option A is wrong because TEMPEST is a U.S. government standard (and NSA certification program) for limiting electromagnetic emanations from equipment to prevent signal interception, not a crime-deterrence design philosophy. Option B is wrong because a Faraday cage is a physical enclosure of conductive mesh that blocks electromagnetic fields and RF signals — a technical countermeasure, not a design methodology for surveillance and territoriality. Option C is wrong because defense in depth is a layered-security strategy (perimeter, network, host, application, data controls) and does not specifically describe natural surveillance, territorial reinforcement, or access control in built environments.

327
Multi-Selecthard

Which THREE of the following are commonly used metrics for measuring the effectiveness of a vulnerability management program?

Select 3 answers
A.Patch coverage percentage
B.Mean time to detect (MTTD)
C.Mean time to remediate (MTTR)
D.Number of vulnerabilities per scan
E.Number of security incidents
AnswersA, C, D

Patch coverage percentage quantifies the proportion of an organization's assets (e.g., servers, applications, network devices) that have successfully received and applied necessary security patches. This metric directly measures the completeness and effectiveness of the patching process, indicating how well the vulnerability management program is protecting the environment from known exploits. A high percentage signifies a robust defense against common, remediable vulnerabilities.

Why this answer

Patch coverage percentage (A) is a core effectiveness metric because it quantifies the proportion of assets that have received required patches, directly reflecting how well the program closes known vulnerabilities. Mean time to remediate (C) measures the average elapsed time from vulnerability discovery to fix, showing how quickly the program reduces exposure window. Number of vulnerabilities per scan (D) tracks the volume of findings over successive scans, indicating whether the program is reducing the overall vulnerability backlog.

Mean time to detect (B) is a detection/incident-response metric rather than a vulnerability management effectiveness measure, and number of security incidents (E) reflects overall security posture or incident response outcomes, not the performance of the vulnerability management process itself.

Exam trap

The trap here is that candidates confuse Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) as both being relevant to vulnerability management, but MTTD is specific to incident response, not to the proactive patching and remediation cycle measured by MTTR and patch coverage.

328
MCQeasy

A network administrator notices that users in the accounting department can access the internet but are unable to access the internal payroll server (10.10.10.50). The firewall rule allows traffic from the accounting subnet (10.10.20.0/24) to the payroll server. What is the most likely issue?

A.DNS is not resolving the payroll server's IP address.
B.The payroll server's default gateway does not have a route back to 10.10.20.0/24.
C.The firewall rule is applied to the outbound interface only.
D.The accounting subnet is blocked by an implicit deny rule.
AnswerB

For successful two-way communication between devices residing on different subnets, both the source and destination networks must possess valid routes to each other. If the payroll server's default gateway lacks a specific route back to the accounting subnet (10.10.20.0/24), the server's response packets will be dropped, misrouted, or sent to an incorrect destination. This absence of a proper return path prevents the accounting users from receiving data, leading to a perceived connectivity failure.

Why this answer

The most likely issue is that the payroll server's default gateway does not have a route back to the accounting subnet (10.10.20.0/24). Even if the firewall permits outbound traffic from the accounting subnet to the payroll server, the return traffic from the server must be routed back through the firewall or a router that knows how to reach 10.10.20.0/24. Without a return route, the server's response packets are dropped, causing a one-way communication failure.

Exam trap

The trap here is that candidates often focus on firewall rule direction (inbound vs. outbound) or DNS, overlooking the fundamental requirement for symmetric routing and the fact that the server's default gateway must know how to reach the source subnet.

How to eliminate wrong answers

Option A is wrong because DNS resolution is irrelevant when the user is accessing the payroll server by its IP address (10.10.10.50), not a hostname. Option C is wrong because firewall rules are typically applied to inbound and outbound interfaces; if the rule is applied only to the outbound interface, it would still allow traffic leaving the accounting subnet, but the real issue is the lack of a return route, not the firewall rule placement. Option D is wrong because an implicit deny rule would block all traffic not explicitly permitted, but the question states the firewall rule allows traffic from the accounting subnet to the payroll server, so the implicit deny is not the cause of the specific failure.

329
MCQmedium

A government agency requires a new secure document management system that enforces mandatory access control with the properties that users cannot read documents at a higher classification and cannot write documents to a lower classification (to prevent data leaking). The system must also support different categories (compartments) within the same classification level, and a user with access to one compartment should not be able to access another compartment unless explicitly allowed. The architect is considering the Bell-LaPadula model. However, the Bell-LaPadula model's *-property (no write-down) addresses the write issue, but there is also a need to handle compartment isolation. Which additional model or mechanism should be incorporated to ensure compartment isolation?

A.Apply the Brewer-Nash (Chinese Wall) model which enforces conflict of interest by preventing access to multiple compartments that conflict.
B.Implement Biba's integrity model which prevents write-up, thus complementing Bell-LaPadula.
C.Use a lattice-based access control (LBAC) that extends Bell-LaPadula by defining a security lattice that includes compartments and categories, ensuring that a subject's clearance must dominate the object's classification, including compartments.
D.Use role-based access control (RBAC) to define compartments.
AnswerC

Lattice-based access control (LBAC) is a powerful mandatory access control (MAC) model that extends Bell-LaPadula by incorporating multiple, non-hierarchical compartments (e.g., 'Nuclear,' 'Space,' 'Cyber') alongside hierarchical classification levels. It defines a security lattice where a subject's clearance must 'dominate' an object's classification, meaning the subject must possess all required classification levels and *all* specified compartments to gain access, precisely addressing the need for fine-grained compartment isolation.

Why this answer

Lattice-based access control (LBAC) extends the Bell-LaPadula model by defining a security lattice that includes both hierarchical classifications (e.g., Top Secret, Secret) and non-hierarchical categories (compartments). In this lattice, a subject's clearance must dominate an object's classification across both dimensions, ensuring that a user with access to one compartment cannot access another unless their clearance includes that specific category. This directly enforces the required compartment isolation while maintaining the *-property (no write-down) for data leakage prevention.

Exam trap

The trap here is that candidates may confuse the Brewer-Nash model's dynamic separation of duties with the static, lattice-based compartment isolation required by MAC, or incorrectly assume that Biba's integrity model can somehow enforce confidentiality-based compartment boundaries.

How to eliminate wrong answers

Option A is wrong because the Brewer-Nash (Chinese Wall) model is designed to prevent conflict of interest in commercial environments by dynamically restricting access to competing datasets, not to enforce static compartment isolation within a single classification level as required by the government agency. Option B is wrong because Biba's integrity model focuses on preventing unauthorized modification (no write-up, no read-down) to protect data integrity, which does not address compartment isolation or complement Bell-LaPadula's confidentiality goals in this context. Option D is wrong because role-based access control (RBAC) assigns permissions based on job functions, not on a formal lattice of classifications and categories, and it lacks the mandatory, system-enforced dominance checks needed for compartment isolation in a mandatory access control (MAC) system.

330
Multi-Selectmedium

Which TWO of the following are mandatory secure coding practices to prevent injection attacks? (Select exactly two.)

Select 2 answers
A.Encode output to the browser
B.Encrypt sensitive input data
C.Use custom error messages that detail the failure
D.Use parameterized queries or prepared statements
E.Validate and sanitize all user input
AnswersD, E

Parameterised queries bind user input as data rather than executable SQL, so the database engine never interprets it as code. This directly satisfies the stem's constraint of preventing injection attacks, since structural query logic stays fixed while values are passed separately, defeating classic SQL injection.

Why this answer

Option D is correct because parameterized queries or prepared statements ensure that user-supplied data is treated strictly as data, not executable code, which structurally prevents SQL injection and similar injection flaws by separating the query logic from the input values. Option E is correct because validating and sanitizing all user input enforces allow-list or expected-format checks and strips or neutralizes dangerous characters, reducing the attack surface for injection vectors such as SQL, command, and LDAP injection. Option A is not mandatory for preventing injection itself; output encoding primarily mitigates cross-site scripting (XSS) by rendering data inert in the browser context, which is a different vulnerability class.

Option B is incorrect because encrypting sensitive input data protects confidentiality in transit or at rest but does nothing to stop malicious payloads from being interpreted as code by an interpreter. Option C is incorrect because detailed custom error messages can leak schema, stack traces, or query structure to attackers, aiding injection exploitation rather than preventing it; generic error handling is the safer practice.

Exam trap

The trap here is that candidates often confuse output encoding (which prevents XSS) with input validation/sanitization (which prevents injection), but the CISSP expects you to recognize that parameterized queries are the definitive defense against SQL injection, while input validation is a broader, mandatory practice for all injection types.

331
MCQhard

A company is evaluating a third-party software library for use in their application. Which document provides a detailed inventory of the library's components and dependencies to help assess supply chain risk?

A.Service Level Agreement (SLA)
B.Data processing agreement
C.Vulnerability disclosure report
D.Software Bill of Materials (SBOM)
AnswerD

A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of all software components, including open-source and commercial elements, and their dependencies used in a product. It provides critical transparency into the software supply chain, enabling organizations to proactively identify and track known vulnerabilities, licensing obligations, and potential risks associated with third-party libraries, which is essential for comprehensive risk assessment.

Why this answer

A Software Bill of Materials (SBOM) is a machine-readable inventory of all components, libraries, and dependencies in a software artifact, including versions and suppliers. It is the primary document for assessing supply chain risk because it reveals transitive dependencies that may contain known vulnerabilities.

Exam trap

CISSP often tests whether candidates confuse SBOM with vulnerability reports or SLAs — the trap is picking 'vulnerability disclosure report' because it sounds security-related, when the question asks specifically for a component and dependency inventory.

How to eliminate wrong answers

Option A is wrong because an SLA defines service performance and availability commitments between provider and customer, not component inventory. Option B is wrong because a data processing agreement governs how personal data is handled under privacy law (e.g., GDPR Article 28), not software composition. Option C is wrong because a vulnerability disclosure report describes known vulnerabilities and disclosure timelines, but it does not enumerate the full component inventory needed for supply chain analysis.

332
Multi-Selectmedium

A security manager is selecting controls to protect sensitive data. Which TWO are examples of administrative controls?

Select 2 answers
A.Security awareness training
B.Firewalls
C.Access control lists
D.Background checks
E.Encryption
AnswersA, D

Security awareness training is an essential administrative control that educates employees about security policies, best practices, and common threats like phishing or social engineering. Its primary goal is to foster a security-conscious culture and empower personnel to identify and report suspicious activities, thereby reducing human-factor vulnerabilities. This control operates through policy, education, and human behavior modification, making it a foundational administrative measure.

Why this answer

Security awareness training (A) is an administrative control because it is a management-directed program that educates personnel on policies and procedures to reduce human error and social-engineering risk, rather than a technical mechanism. Background checks (D) are also administrative controls because they are personnel-security processes—pre-employment screening, verification of identity and history—implemented through policy and HR procedures to mitigate insider threats. Firewalls (B), access control lists (C), and encryption (E) are technical (logical) controls: firewalls filter network traffic, ACLs enforce permissions on resources, and encryption protects data confidentiality through cryptographic algorithms, so none of them are administrative in nature.

Exam trap

Candidates often confuse administrative controls with technical or physical controls. Remember that administrative controls deal with people, policies, procedures, and management (such as training, background checks, and hiring practices), whereas technical controls use hardware or software (like firewalls and encryption).

333
MCQhard

A company is decommissioning a data center and needs to dispose of hard drives that contained highly confidential financial data. Which of the following methods provides the HIGHEST assurance that data cannot be recovered?

A.Overwriting the drives with multiple passes of random data
B.Shredding the drives into small pieces
C.Degaussing the drives
D.Overwriting the drives with a single pass of zeros
AnswerB

Shredding is a physical destruction method that renders the storage media completely unusable and makes data recovery physically impossible. By breaking the platters or flash memory chips into tiny fragments, the integrity of the data storage surfaces is irrevocably destroyed. This method provides the highest level of assurance for data sanitization, making it the most appropriate choice for highly confidential information.

Why this answer

Shredding the drives into small pieces physically destroys the platters, making data recovery impossible regardless of the storage technology (e.g., HDD vs. SSD). This method provides the highest assurance because it eliminates any possibility of reading residual magnetic or solid-state data, even with advanced forensic tools like electron microscopy.

Exam trap

The trap here is that candidates often choose degaussing or multi-pass overwriting because they are familiar with these methods, but they fail to recognize that physical destruction is the only method that guarantees data irretrievability across all drive types, especially SSDs.

How to eliminate wrong answers

Option A is wrong because overwriting with multiple passes (e.g., Gutmann method) is effective for magnetic media but provides no assurance for SSDs or modern HDDs with high-density platters, and it is time-consuming; more importantly, it does not physically destroy the drive, so residual data could theoretically be recovered with specialized equipment. Option C is wrong because degaussing uses a strong magnetic field to erase data on HDDs, but it is ineffective on SSDs (which store data in NAND flash cells) and may leave the drive non-functional without guaranteeing complete erasure of all sectors. Option D is wrong because a single pass of zeros is sufficient for many modern HDDs (per NIST SP 800-88), but it does not address SSDs or provide the same level of assurance as physical destruction, and it leaves the drive intact for potential recovery attempts.

334
MCQmedium

An organization needs to ensure that its employees understand their responsibilities regarding information security. Which of the following is the MOST effective way to achieve this?

A.Distribute a security policy document and require a signature.
B.Conduct a one-time annual security briefing.
C.Display security posters in common areas.
D.Implement a security awareness program with regular training and assessments.
AnswerD

An effective security awareness program incorporates regular, ongoing training sessions to reinforce critical concepts, adapt to evolving threats, and address new vulnerabilities. Crucially, it includes assessments (e.g., quizzes, simulated phishing exercises) to objectively measure employee comprehension and identify knowledge gaps. This continuous cycle of education, reinforcement, and evaluation ensures employees not only receive information but also understand, retain, and consistently apply security best practices, thereby measurably improving the organization's human firewall.

Why this answer

A security awareness program with regular training and assessments is the most effective way to ensure employees understand their responsibilities because it establishes a continuous learning cycle. Unlike one-time events, it reinforces secure behaviors through repetition, real-world scenarios, and measurable assessments, aligning with the NIST SP 800-50 framework for building a security-conscious culture.

Exam trap

The trap here is that candidates often mistake a one-time annual briefing (Option B) as sufficient due to its common use in compliance checklists, but the CISSP emphasizes continuous, behavior-changing programs over periodic, passive activities.

How to eliminate wrong answers

Option A is wrong because simply distributing a policy document and requiring a signature does not guarantee comprehension or retention; it relies on passive acknowledgment and lacks verification of understanding, which is a common failure point in compliance-driven approaches. Option B is wrong because a one-time annual briefing is insufficient to address evolving threats and employee turnover; it provides only a snapshot of knowledge without ongoing reinforcement, leading to decay of awareness over time. Option C is wrong because security posters in common areas are passive communication tools that lack interactivity and assessment; they may raise superficial awareness but fail to change behavior or ensure employees grasp their specific responsibilities.

335
Multi-Selectmedium

A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?

Select 2 answers
A.Compliance with password policies is weakened
B.Performance degradation of authentication servers
C.Increased logging overhead
D.Attackers can use orphaned accounts to gain unauthorized access
E.Former employees can still access systems
AnswersD, E

Attackers actively seek out orphaned accounts because they often represent overlooked security gaps. These accounts may retain elevated privileges, possess weak or default passwords that were never updated, or simply go unnoticed in routine security audits, making them prime targets for credential stuffing, brute-force attacks, or lateral movement once initial network access is achieved. Exploiting such accounts provides a persistent backdoor for unauthorized access and privilege escalation.

Why this answer

Option D is correct because orphaned accounts remain valid credentials that are no longer tied to an active owner, so an attacker who compromises or guesses those credentials can authenticate and move laterally without triggering account-owner scrutiny. Option E is correct because orphaned accounts often belong to former employees, contractors, or vendors whose access was never revoked, allowing those individuals to retain system access after their relationship with the organization ends. These two risks are the core security concerns of orphaned accounts: unauthorized access by external attackers and lingering access by terminated insiders.

Option A is not the primary risk here because password-policy compliance is a control weakness rather than a direct orphaned-account risk, and orphaned accounts may still technically meet password complexity or rotation rules. Option B is incorrect because authentication-server performance is a capacity/scalability issue, not a consequence of accounts lacking an owner. Option C is incorrect because increased logging overhead is an operational side effect, not a distinct risk of orphaned accounts.

Exam trap

CISSP often tests the distinction between direct security risks (unauthorized access, insider threat) and indirect operational issues (performance, logging), so candidates may incorrectly select operational impacts as risks of orphaned accounts.

336
MCQeasy

Which of the following is a key feature of TLS 1.3 that enhances security compared to earlier versions?

A.Support for RC4 encryption
B.Support for DES and 3DES
C.Mandatory forward secrecy
D.Use of static RSA key exchange
AnswerC

Mandatory forward secrecy is a cornerstone security feature enforced by TLS 1.3, significantly enhancing protection against future compromise. This is achieved by requiring the use of ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) key exchange mechanisms. Consequently, even if a server's long-term private key is compromised at a later date, an attacker cannot decrypt previously recorded session traffic because the session keys were unique and discarded after use, ensuring past communications remain confidential.

Why this answer

TLS 1.3 mandates forward secrecy by requiring ephemeral Diffie-Hellman (DHE or ECDHE) key exchange for all sessions, eliminating static RSA and static DH key exchanges. This ensures that even if the server's long-term private key is compromised, past session keys cannot be derived, protecting historical traffic. Earlier TLS versions allowed static key exchanges, making them vulnerable to retrospective decryption.

Exam trap

The trap here is that candidates often confuse 'forward secrecy' with 'encryption strength' or 'cipher support,' and may incorrectly think that simply using a strong cipher like AES provides forward secrecy, when in fact it is the key exchange mechanism (ephemeral vs. static) that determines whether past sessions remain secure after key compromise.

How to eliminate wrong answers

Option A is wrong because RC4 is a stream cipher with known biases (e.g., in the first output bytes) and has been deprecated in all TLS versions since 1.1; TLS 1.3 completely removes RC4 and all other non-AEAD ciphers. Option B is wrong because DES and 3DES are block ciphers with small block sizes (64-bit) and are vulnerable to Sweet32 birthday attacks; TLS 1.3 eliminates them entirely, requiring AEAD ciphers like AES-GCM or ChaCha20-Poly1305. Option D is wrong because static RSA key exchange does not provide forward secrecy—if the server's RSA private key is compromised, all past session keys can be decrypted; TLS 1.3 removes static RSA entirely.

337
MCQmedium

After a recent security audit, a network administrator discovers that an attacker has been intercepting traffic by associating with a legitimate access point's MAC address and broadcasting a stronger signal. Which type of attack has occurred?

A.Rogue access point
B.Karma attack
C.Evil twin attack
D.ARP spoofing
AnswerC

An evil twin attack involves an attacker setting up a malicious access point that precisely mimics a legitimate Wi-Fi network, typically by using the same Service Set Identifier (SSID) and often the same MAC address. The attacker then broadcasts this imposter network with a stronger signal than the legitimate one, luring unsuspecting users to connect to it instead. Once connected, the attacker can intercept all network traffic, harvest credentials, or inject malware, making it a highly effective man-in-the-middle attack.

Why this answer

Evil twin attack. This attack involves an attacker setting up a rogue access point that mimics a legitimate access point by spoofing its MAC address (BSSID) and broadcasting a stronger signal, causing clients to associate with the attacker's device instead of the legitimate AP. The key distinction is the active impersonation of a specific legitimate AP, not just the presence of an unauthorized AP.

Exam trap

The trap here is that candidates often confuse 'rogue access point' (any unauthorized AP) with 'evil twin' (a specific impersonation of a legitimate AP), but the key differentiator is the active spoofing of the legitimate AP's MAC address and signal strength to intercept traffic, not just the presence of an unauthorized device.

How to eliminate wrong answers

Option A is wrong because a rogue access point is any unauthorized AP connected to the network, but it does not necessarily spoof a legitimate AP's MAC address or broadcast a stronger signal to intercept traffic; it is simply an unapproved device on the network. Option B is wrong because a Karma attack exploits probe requests from clients by responding with a fake AP that matches any SSID the client has previously connected to, but it does not involve spoofing a specific legitimate AP's MAC address or broadcasting a stronger signal from that same AP. Option D is wrong because ARP spoofing is a Layer 2 attack that manipulates ARP tables to redirect traffic on a local network, not an attack that uses a fake access point or wireless signal strength to intercept traffic.

338
Multi-Selecteasy

An organization is planning a penetration test of its internal network. Which TWO of the following are essential elements to include in the test scope and rules of engagement?

Select 2 answers
A.List of specific exploitation tools to be used.
B.Time windows when testing is permitted (e.g., after business hours).
C.Schedule for automated vulnerability scanning of all external systems.
D.List of IP addresses and systems authorized for testing.
E.Detailed plan for exploiting client-side vulnerabilities.
AnswersB, D

Defining specific time windows during which penetration testing is permitted is a critical component of the Rules of Engagement (RoE). This ensures that testing activities, which can sometimes be disruptive or resource-intensive, occur during periods of low operational impact, such as after business hours or on weekends. Establishing these boundaries helps prevent service interruptions to critical business functions and minimizes potential negative effects on user experience or system availability.

Why this answer

The rules of engagement (ROE) and scope define the boundaries of the penetration test. Essential elements include authorized time windows (option B) to minimize business disruption and ensure testing occurs during agreed-upon periods, and a list of authorized IP addresses and systems (option D) to clearly define the target scope and avoid legal issues. Option A (list of specific tools) is not necessarily required in the scope; tools can be agreed upon but are not essential.

Option C (vulnerability scanning schedule) is a separate activity and not part of penetration test scope. Option E (detailed client-side exploitation plan) is too specific and not a required element of the overall scope.

339
MCQeasy

Which type of security testing involves analyzing source code for vulnerabilities without executing the code?

A.SAST
B.Penetration testing
C.IAST
D.DAST
AnswerA

SAST (Static Application Security Testing) is a white-box testing methodology that directly analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the program. It identifies potential flaws such as SQL injection, cross-site scripting (XSS), buffer overflows, and insecure direct object references by examining code patterns and data flows. This static analysis occurs early in the Software Development Life Cycle (SDLC), allowing developers to fix issues before deployment.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. It operates by scanning the codebase for patterns known to be insecure (e.g., SQL injection via string concatenation) using techniques like data flow analysis, taint tracking, and pattern matching, all performed at rest.

Exam trap

The trap here is that candidates confuse SAST with DAST because both are 'security testing' acronyms, but the key differentiator is that SAST analyzes code without execution (static), while DAST requires a running application (dynamic).

How to eliminate wrong answers

Option B is wrong because penetration testing is a dynamic, manual or automated process that tests a running application or system by simulating attacks, not by analyzing static source code. Option C is wrong because IAST (Interactive Application Security Testing) combines static and dynamic analysis by instrumenting the application and monitoring its behavior during runtime execution, not by analyzing code without execution. Option D is wrong because DAST (Dynamic Application Security Testing) tests an application while it is running, typically by sending malicious payloads and observing responses, which requires execution and does not involve source code analysis.

340
MCQhard

During a penetration test, a security analyst discovers that a web application allows an attacker to bypass authorization and view another user's private messages by simply changing a numeric ID in the URL. Which vulnerability is being exploited?

A.Broken authentication
B.Insecure direct object reference (IDOR)
C.Server-side request forgery (SSRF)
D.Security misconfiguration
AnswerB

Insecure direct object reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, database key, or directory, and fails to implement sufficient authorization checks. An attacker can manipulate these references, often found in URL parameters or request bodies, to access or modify resources belonging to other users or system components without explicit permission. This directly aligns with a penetration test discovery where an analyst accesses unauthorized objects by altering an identifier.

Why this answer

B is correct because the vulnerability allows an attacker to access another user's private messages by simply changing a numeric ID in the URL, which is a classic example of Insecure Direct Object Reference (IDOR). This occurs when the application exposes a direct reference to an internal object (e.g., a database key) without proper access control checks, enabling unauthorized access to resources belonging to other users.

Exam trap

The trap here is that candidates confuse IDOR with broken authentication because both involve unauthorized access, but IDOR specifically targets direct object references without proper access controls, whereas broken authentication focuses on flaws in the authentication process itself.

How to eliminate wrong answers

Option A is wrong because broken authentication refers to flaws in session management, credential handling, or login mechanisms (e.g., weak password policies, session fixation), not the direct manipulation of object references in URLs. Option C is wrong because Server-Side Request Forgery (SSRF) involves an attacker inducing the server to make requests to internal or external resources, not directly accessing another user's data via a modified URL parameter. Option D is wrong because security misconfiguration covers issues like default credentials, unnecessary services, or verbose error messages, but does not specifically describe the lack of authorization checks on object references.

341
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

A.Identify critical business functions and dependencies
B.Develop and test the continuity plan
C.Determine recovery time objectives (RTO) and recovery point objectives (RPO)
D.Create the business continuity plan document
AnswerA

A BIA determines which business functions are essential and how their loss affects the organisation, plus their dependencies and recovery priorities. That identification of critical functions and dependencies is the foundation for subsequent continuity and recovery strategies.

Why this answer

The primary purpose of a business impact analysis (BIA) is to identify critical business functions and their dependencies on resources such as personnel, systems, data, and third-party services. This identification drives all subsequent continuity planning by quantifying the impact of disruptions and establishing the basis for recovery strategies. Without a BIA, recovery objectives and plans would be based on assumptions rather than empirical data about operational priorities.

Exam trap

The trap here is that candidates confuse the BIA's primary purpose with its outputs (RTO/RPO), but the BIA is fundamentally about identifying what is critical and why, not setting the numerical targets themselves.

How to eliminate wrong answers

Option B is wrong because developing and testing the continuity plan occurs after the BIA, using its outputs to design and validate recovery procedures; the BIA itself does not involve plan creation or testing. Option C is wrong because while RTO and RPO are derived from BIA findings, they are not the primary purpose—the BIA first identifies critical functions and dependencies, and then those metrics are calculated as part of the recovery strategy phase. Option D is wrong because creating the business continuity plan document is a separate step that synthesizes BIA results, recovery strategies, and procedures into a formal document; the BIA is an analytical input, not the document itself.

342
MCQhard

A company is designing a database that will contain personally identifiable information (PII). To reduce privacy risk, they decide to add controlled noise to query results. This technique is known as:

A.Data masking
B.Tokenization
C.Differential privacy
D.Anonymization
AnswerC

Differential privacy is a rigorous mathematical framework that quantifies and limits the privacy risk to individuals when their data is part of a dataset used for statistical queries. It achieves this by strategically injecting calibrated noise into query results or the data itself, ensuring that the presence or absence of any single individual's data in the dataset does not significantly alter the output of an analysis. This allows for aggregate insights while providing strong, provable guarantees against re-identification, even by an attacker with auxiliary information.

Why this answer

Differential privacy is a technique that adds controlled noise to query results to protect individual privacy while allowing aggregate analysis. It ensures that the inclusion or exclusion of a single individual's data does not significantly affect the output, thereby reducing privacy risk. This matches the scenario of adding noise to query results for PII.

Exam trap

CISSP often tests the confusion between differential privacy and anonymization or masking; candidates may think any privacy technique involving data alteration is differential privacy, but only differential privacy adds noise to query results with a formal privacy guarantee.

How to eliminate wrong answers

Option A (Data masking) is wrong because it involves obfuscating specific data fields, often for testing or non-production use, but does not add noise to query results. Option B (Tokenization) is wrong because it replaces sensitive data with non-sensitive tokens, preserving format but not adding noise. Option D (Anonymization) is wrong because it irreversibly removes personally identifiable information, but does not typically involve adding noise to query outputs.

343
MCQmedium

A security administrator is configuring role-based access control (RBAC) for a cloud storage system. Which of the following is the best practice for assigning permissions?

A.Use access control lists on each object
B.Implement mandatory access control
C.Create roles based on job functions and assign users to roles
D.Assign permissions directly to users for flexibility
AnswerC

Creating roles based on job functions and then assigning users to these predefined roles is the fundamental principle of Role-Based Access Control (RBAC). This method centralizes permission management by associating specific permissions with a role, ensuring that users automatically inherit the appropriate access rights for their position. It significantly simplifies administration, enhances security by enforcing least privilege, and provides a scalable, consistent access policy across the organization.

Why this answer

Role-based access control (RBAC) is the recommended approach for managing permissions in cloud storage systems because it aligns with the principle of least privilege and simplifies administration. By creating roles based on job functions and assigning users to those roles, permissions are granted consistently and can be easily audited or modified without touching individual user accounts. This reduces the risk of excessive permissions and makes compliance with policies like separation of duties more manageable.

Exam trap

A common misconception in CISSP is that ACLs are the best way to secure cloud storage because they seem granular, but the trap is that ACLs are a legacy DAC mechanism that does not scale and violates the RBAC model's centralized management principle.

How to eliminate wrong answers

Option A is wrong because using access control lists (ACLs) on each object is a discretionary access control (DAC) method that becomes unmanageable at scale in cloud storage, leading to permission sprawl and increased risk of misconfiguration. Option B is wrong because mandatory access control (MAC) relies on system-enforced labels and clearances, which is overly rigid for a cloud storage system where users need flexible, role-based access rather than government-style classification. Option D is wrong because assigning permissions directly to users violates the core RBAC principle of role-based assignment, creating administrative overhead and making it difficult to enforce consistent access policies across the organization.

344
MCQmedium

A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?

A.Vulnerability scanner
B.SOAR
C.Endpoint detection and response (EDR)
D.Network-based IDS
AnswerB

Security Orchestration, Automation, and Response (SOAR) platforms are specifically designed to integrate with SIEM systems to automate and orchestrate incident response workflows. SOAR tools ingest alerts, enrich them with contextual data, and execute predefined playbooks, enabling a SOC team to rapidly respond to threats by automating tasks such as blocking malicious IPs, isolating compromised endpoints, or gathering additional forensic evidence, thereby significantly reducing manual effort and improving response times.

Why this answer

SOAR (Security Orchestration, Automation, and Response) is the technology designed to integrate with SIEM systems to automate incident response workflows, orchestrate actions across security tools, and execute playbooks for common threats. It directly addresses the requirement for security orchestration and automation.

Exam trap

CISSP often tests the distinction between detection tools (SIEM, IDS, EDR) and response orchestration tools (SOAR), so candidates must recognize that automation and orchestration are the defining characteristics of SOAR.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner identifies weaknesses but does not orchestrate responses or automate remediation workflows. Option C is wrong because EDR focuses on endpoint detection and response, providing telemetry and containment on endpoints, but it does not provide cross-tool orchestration and automation. Option D is wrong because a network-based IDS detects malicious traffic but lacks the orchestration and automated response capabilities required for SOAR.

345
MCQmedium

A healthcare organization uses a federated identity provider (IdP) to authenticate clinicians into a third-party electronic health record (EHR) application acting as a SAML 2.0 Service Provider (SP). The security team wants to reduce the risk that a stolen IdP session cookie could be replayed against the EHR. Which SAML 2.0 control should the team implement to bind the assertion to the authenticated browser session and limit replay?

A.Enable SAML 2.0 Single Logout (SLO) between the IdP and the EHR Service Provider.
B.Require the IdP to include a Holder-of-Key (HoK) subject confirmation in the assertion and have the SP verify possession of the corresponding key.
C.Configure the IdP to issue short-lived assertions and require the SP to validate the NotOnOrAfter condition against its own clock.
D.Use SAML 2.0 Enhanced Client or Proxy (ECP) profile so the EHR can request authentication directly from the IdP.
AnswerB

Holder-of-Key subject confirmation binds the assertion to a key the requester must prove possession of, so a stolen session cookie alone cannot satisfy the SP. This directly addresses replay of a captured assertion or cookie, which is exactly the risk the security team wants to reduce for clinician access to the EHR.

Why this answer

Binding a SAML assertion to a key the requester must prove possession of prevents an attacker who only has a stolen cookie from being accepted by the Service Provider, because the attacker cannot demonstrate possession of the associated private key. Short-lived assertions, Single Logout, and the ECP profile change timing or transport but leave the assertion bearer-based and replayable within its validity window.

Exam trap

The trap here is assuming that shortening assertion lifetime or enabling Single Logout prevents cookie replay, when neither binds the assertion to the requester's session.

346
Multi-Selecthard

A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?

Select 2 answers
A.TOCTOU
B.Emanations
C.Covert timing channel
D.Side-channel
E.Covert storage channel
AnswersC, E

A covert timing channel transmits information by modulating the temporal characteristics of system events or resource access, such as the precise timing of CPU cycles, network packet delays, or disk I/O operations. A sender encodes data by introducing subtle, detectable delays or variations in these timings, which a receiver then observes and decodes. This method exploits shared system resources or observable event sequences to establish a hidden communication path, bypassing explicit security policies.

Why this answer

Option C, a covert timing channel, is correct because it leaks information by modulating the timing of events (e.g., CPU scheduling, packet delays, or response latencies) so that a high-security process signals bits to a low-security process without sharing a direct data object. Option E, a covert storage channel, is correct because it leaks information by writing to and reading from a shared storage resource (e.g., file locks, disk sectors, or memory locations) whose presence or value is observable across security levels. Option A, TOCTOU, is a race-condition vulnerability class, not a covert channel type, so it does not belong.

Option B, emanations, refers to unintentional electromagnetic or acoustic leakage, which is a side-channel phenomenon rather than the intentional signaling mechanism of a covert channel. Option D, side-channel, is a broader category of information leakage (e.g., power, cache, or timing analysis) and is not one of the two standard covert channel types asked for here.

Exam trap

CISSP often tests the precise two-category taxonomy of covert channels — candidates pick 'side-channel' or 'emanations' because they sound like leakage, but the exam expects the classic storage/timing pair.

347
MCQmedium

An organization is implementing a bring-your-own-device (BYOD) policy. The security architect must ensure that corporate data on the device is protected from unauthorized access if the device is lost or stolen, while minimizing impact on user privacy. Which solution is most appropriate?

A.Use mobile device management (MDM) to create a secure container for corporate apps and data
B.Require employees to use company-issued devices only
C.Disable camera and microphone on the device
D.Full device encryption with remote wipe capability
AnswerA

Mobile Device Management (MDM) is the most appropriate solution for securing corporate data on personal devices in a BYOD program. By creating a secure container, MDM logically isolates corporate applications and data from the user's personal information. This isolation allows the organization to enforce specific security policies, manage corporate applications, and perform a selective wipe of only the corporate container if the device is lost, stolen, or an employee departs, without affecting personal data.

Why this answer

A secure container (often implemented via MDM with app wrapping or per-app VPN) creates an encrypted, isolated partition on the device for corporate apps and data. This ensures that if the device is lost or stolen, the corporate data remains encrypted and inaccessible without the container's authentication, while personal apps and data outside the container remain untouched, thus minimizing privacy impact.

Exam trap

The trap here is that candidates often choose full device encryption with remote wipe (Option D) because it sounds strong, but they overlook the privacy impact of wiping personal data, which the question explicitly states must be minimized.

How to eliminate wrong answers

Option B is wrong because requiring company-issued devices only eliminates BYOD entirely, failing to meet the policy's goal of allowing personal devices while protecting corporate data. Option C is wrong because disabling camera and microphone does not protect corporate data from unauthorized access on a lost or stolen device; it addresses data exfiltration via sensors, not storage security. Option D is wrong because full device encryption with remote wipe protects all data but wipes personal data too, violating the requirement to minimize impact on user privacy; it also lacks granularity for selective corporate data protection.

348
MCQeasy

Which of the following is an example of a Type 1 authentication factor?

A.OTP token
B.Fingerprint
C.Password
D.Smart card
AnswerC

A password serves as a classic example of a Type 1 authentication factor, representing "something you know." This form of authentication relies on a secret piece of information, such as a string of characters, that only the legitimate user is supposed to possess and recall. Users must cognitively remember and accurately input this credential to prove their identity, making it a foundational element in most access control systems. Its security is directly dependent on its complexity and the user's ability to keep it confidential.

Why this answer

A Type 1 authentication factor is something you know, such as a password, PIN, or passphrase. The password is knowledge held in the user's memory, making it the classic example of a Type 1 factor. The other options represent possession (something you have) or inherence (something you are).

Exam trap

CISSP often tests the distinction between authentication factor types, and candidates frequently misclassify smart cards or OTP tokens as Type 1 because they involve user interaction, forgetting that possession is the defining characteristic.

How to eliminate wrong answers

Option A is wrong because an OTP token is a possession factor (Type 2) — the user has a physical or virtual device that generates one-time codes. Option B is wrong because a fingerprint is a biometric inherence factor (Type 3) — it is a physical characteristic of the user. Option D is wrong because a smart card is a possession factor (Type 2) — the user must have the physical card, even if it also stores a certificate.

349
MCQmedium

A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?

A.Bell-LaPadula
B.Graham-Denning
C.Clark-Wilson
D.Biba
AnswerD

The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity. It operates on two core principles: the Simple Integrity Axiom (no read down) and the * (Star) Integrity Axiom (no write up). These rules ensure that subjects cannot read data of lower integrity (to prevent being corrupted) and cannot write to data of higher integrity (to prevent corrupting it), making it ideal for applications requiring strict integrity controls.

Why this answer

The Biba integrity model is defined by the 'no write up' and 'no read down' rules, which prevent subjects at a lower integrity level from writing to higher levels and prevent subjects at a higher level from reading lower-level (potentially tainted) data. This directly matches the scenario's requirement to prevent unauthorized modifications by preserving integrity across levels. Biba is the integrity counterpart to Bell-LaPadula, which focuses on confidentiality.

Exam trap

CISSP often tests the confusion between Bell-LaPadula and Biba by swapping the direction of the no-read/no-write rules; candidates who memorize 'no read up, no write down' without associating it to confidentiality will pick Bell-LaPadula for an integrity scenario.

How to eliminate wrong answers

Option A is wrong because Bell-LaPadula enforces confidentiality with 'no read up' and 'no write down' rules, the inverse of the stated controls. Option B is wrong because Graham-Denning is a formal access control model defining eight primitive operations for secure subject/object creation and deletion, not an integrity-level model. Option C is wrong because Clark-Wilson enforces integrity through well-formed transactions and separation of duties, not through hierarchical integrity labels with no-write-up/no-read-down rules.

350
MCQeasy

A large financial institution is finalizing its annual risk treatment plan based on a recent enterprise risk assessment. The risk appetite statement approved by the board specifies that the organization will accept only low residual risks for financial loss, but is willing to accept moderate risks for reputational damage if cost-benefit justifies. The risk register includes the following findings: 1) A critical SQL injection vulnerability in the online banking portal with high likelihood and critical impact; current controls include a web application firewall (WAF) that is not fully tuned. 2) Use of outdated TLS 1.0 encryption on internal communications between data centers; likelihood is medium, impact is low. 3) Lack of background checks for third-party vendors with access to sensitive data; likelihood is low, impact is moderate. 4) A single point of failure in the primary data center's power supply; likelihood is low, impact is critical. 5) An incident response plan that has not been tested in two years; likelihood is medium, impact is moderate. The CISO must prioritize actions for the upcoming quarter. What is the most appropriate first step?

A.Transfer the single point of failure risk by purchasing business interruption insurance.
B.Immediately remediate the SQL injection vulnerability by tuning the WAF and applying vendor patches.
C.Outsource incident response to a managed security service provider (MSSP) to compensate for the untested plan.
D.Accept the risk of outdated TLS 1.0 encryption because impact is low.
AnswerB

Immediately remediating the SQL injection vulnerability by tuning the Web Application Firewall (WAF) and applying vendor patches is the most appropriate action because SQL injection represents a critical threat with potentially severe impact and high likelihood. This direct technical mitigation strategy actively reduces the attack surface and closes known security gaps, preventing unauthorized data access or manipulation. This proactive approach aligns with best practices for addressing the highest-priority risks first, directly improving the organization's security posture.

Why this answer

The SQL injection vulnerability in the online banking portal represents the highest-priority risk because it combines high likelihood with critical impact on a customer-facing financial system, directly violating the board's stated risk appetite of accepting only low residual risk for financial loss. Tuning the WAF and applying vendor patches directly reduces the likelihood and impact of exploitation, addressing the risk at its source. Under CISSP risk management principles, treatment priority is driven by risk exposure (likelihood × impact) relative to the organization's risk appetite, and this finding clearly exceeds the acceptable threshold.

Exam trap

CISSP often tests the misconception that any low-impact risk can be accepted outright, or that insurance is a universal fix — candidates must instead rank by likelihood × impact against the stated risk appetite and pick the highest-exposure item for immediate remediation.

How to eliminate wrong answers

Option A is wrong because transferring the single point of failure via insurance does not reduce the critical impact of a data center outage and insurance only addresses financial recovery, not the availability risk itself; moreover, its low likelihood makes it a lower priority than the high-likelihood SQL injection. Option C is wrong because outsourcing incident response does not remediate the untested plan's underlying gap and the IR plan risk is only medium/medium, well below the SQL injection's critical exposure. Option D is wrong because although TLS 1.0 has low impact, accepting risk without documented justification and without considering the medium likelihood is premature when a higher-priority critical risk exists; risk acceptance must be a deliberate, authorized decision, not a default.

351
MCQhard

An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:

A.Golden ticket attack
B.Silver ticket attack
C.Pass-the-ticket attack
D.Kerberos poisoning attack
AnswerA

A golden ticket attack leverages a compromised Kerberos Key Distribution Center (KDC) account's NTLM hash (specifically, the krbtgt account) to forge a valid Ticket Granting Ticket (TGT). This forged TGT grants the attacker unlimited, domain-wide administrative access to all resources within the Active Directory environment. The attacker can impersonate any user, including non-existent ones, and request service tickets for any service without further authentication from the legitimate KDC.

Why this answer

A Golden Ticket attack involves compromising the Kerberos Key Distribution Center (KDC), specifically the KRBTGT account's password hash. With this hash, an attacker can forge a legitimate Ticket Granting Ticket (TGT) that grants access to any service or resource in the domain, effectively impersonating any user. This is possible because the KRBTGT account is used to sign all TGTs, and its compromise allows the attacker to mint arbitrary TGTs.

The attack is called 'Golden' because it grants unlimited access, akin to having a master key to the domain.

Exam trap

CISSP often tests the distinction between Golden Ticket and Silver Ticket attacks, where candidates may confuse the scope of compromise (KDC vs. service account) and the type of ticket forged (TGT vs. TGS).

How to eliminate wrong answers

Option B is wrong because a Silver ticket attack forges a Service Ticket (TGS) using the compromised service account's password hash, not the KDC's KRBTGT hash, and it only grants access to that specific service, not domain-wide impersonation. Option C is wrong because Pass-the-ticket involves stealing a valid existing Kerberos ticket (TGT or TGS) from memory and reusing it, not forging a new one from scratch. Option D is wrong because 'Kerberos poisoning' is not a standard term; it may refer to attacks like Kerberoasting or AS-REP roasting, which involve requesting and cracking tickets, not forging TGTs via KDC compromise.

352
Multi-Selectmedium

A company is implementing a digital signature system to ensure non-repudiation. The security architect must select a hash function that meets the required security properties. Which THREE of the following are necessary properties for the hash function?

Select 3 answers
A.Preimage resistance
B.Reversibility
C.Collision resistance
D.Second preimage resistance
E.Determinism
AnswersA, C, D

Preimage resistance is a fundamental security property for digital signatures, ensuring that given a hash value, it is computationally infeasible to find any input message that produces that specific hash. This prevents an attacker from forging a signature by simply generating a new document that hashes to a known, legitimately signed hash, thereby upholding the non-repudiation principle.

Why this answer

Option A (Preimage resistance) is correct because a secure hash function must make it computationally infeasible to reverse the process and find any input that produces a given hash output, which is essential for non-repudiation since an attacker cannot forge a message matching a known digest. Option C (Collision resistance) is correct because it must be infeasible to find any two distinct inputs that produce the same hash value, preventing an attacker from substituting a fraudulent message for a legitimately signed one. Option D (Second preimage resistance) is correct because given a specific input and its hash, it must be infeasible to find a different input with the same hash, which protects the integrity of the original signed message.

Option B (Reversibility) is incorrect because hash functions are by design one-way and must not be reversible; reversibility would destroy their security. Option E (Determinism) is incorrect because while determinism is a functional characteristic of hash functions (same input always yields the same output), it is not one of the three cryptographic security properties required for non-repudiation in this context.

Exam trap

CISSP often tests whether candidates confuse functional properties (determinism) with security properties (preimage, second preimage, collision resistance), causing them to select determinism as a required security property.

353
MCQeasy

A small business owner stores customer payment card information (PCI) in a legacy database that is not compliant with PCI DSS. The business is migrating to a new cloud-based point-of-sale (POS) system that uses tokenization. The owner wants to ensure that the legacy data is handled securely during the transition. Which of the following is the BEST approach?

A.Migrate the legacy data into the new POS system and have the tokenization service replace it
B.Encrypt the legacy database using AES-256 and store the encryption key on a separate server
C.Archive the legacy database to a tape backup and store it in a secure offsite vault
D.Tokenize the payment data in the legacy database, then securely purge the original cardholder data and verify the purge
AnswerD

This is the most effective strategy for reducing PCI DSS scope and inherent risk. Tokenization replaces actual sensitive payment card information with non-sensitive, algorithmically generated tokens, which are then stored. Crucially, the subsequent secure purging and verification of the original cardholder data completely eliminates the sensitive information from the organization's systems, significantly reducing the attack surface and compliance burden.

Why this answer

Tokenization replaces sensitive cardholder data with a non-sensitive token, rendering the original data useless for attackers. After tokenizing the legacy database, securely purging the original cardholder data (e.g., using NIST SP 800-88 compliant methods like overwriting or degaussing) and verifying the purge ensures compliance with PCI DSS requirement 3.1 (minimize stored cardholder data) and eliminates the risk of data breach from the legacy system.

Exam trap

The trap here is that candidates often choose encryption (Option B) as a 'secure' catch-all, but PCI DSS requires minimizing stored cardholder data, not just protecting it—tokenization with purging is the only option that eliminates the data entirely, which is the core principle of asset security and data minimization.

How to eliminate wrong answers

Option A is wrong because migrating raw PCI data into the new POS system before tokenization would expose the data in transit and at rest, violating PCI DSS requirement 4 (encrypt transmission) and 3.4 (render stored data unreadable); tokenization should occur before or during migration, not after. Option B is wrong because encrypting the legacy database with AES-256 but storing the encryption key on a separate server still leaves the encrypted data vulnerable to key compromise and does not meet PCI DSS requirement 3.1 to minimize stored cardholder data—encryption is a compensating control, not a replacement for purging. Option C is wrong because archiving the legacy database to tape backup preserves the cardholder data indefinitely, violating PCI DSS requirement 3.1 and 3.2 (retention policy); even if stored offsite, the data remains a liability and must be purged after business need ends.

354
MCQeasy

Which cryptographic algorithm is an example of a symmetric stream cipher?

A.RC4
B.AES
C.3DES
D.RSA
AnswerA

RC4 is indeed a symmetric stream cipher, meaning it encrypts data one byte or bit at a time, generating a pseudorandom keystream that is then XORed with the plaintext to produce ciphertext. This approach makes it highly efficient for real-time communication and variable-length data streams, as it does not require padding to fixed block sizes. While widely used in protocols like WEP and SSL/TLS in the past, RC4 is now largely deprecated due to identified vulnerabilities when used improperly, particularly related to weak keys and non-random keystream generation.

Why this answer

RC4 is a symmetric stream cipher that generates a pseudorandom keystream and XORs it with plaintext one byte at a time. It was widely used in WEP, WPA (TKIP), and SSL/TLS before being deprecated due to keystream biases. Stream ciphers encrypt data bit-by-bit or byte-by-byte, unlike block ciphers which process fixed-size blocks.

Exam trap

CISSP often tests the stream-vs-block cipher distinction, and candidates mistakenly classify AES as a stream cipher because it can operate in stream-like modes such as CTR or GCM.

How to eliminate wrong answers

Option B is wrong because AES is a symmetric block cipher operating on 128-bit blocks (with 128/192/256-bit keys), not a stream cipher — though it can be used in stream-like modes such as CTR or GCM. Option C is wrong because 3DES is a symmetric block cipher that applies DES three times to 64-bit blocks, not a stream cipher. Option D is wrong because RSA is an asymmetric (public-key) algorithm based on integer factorization, not a symmetric cipher at all.

355
MCQhard

A security team is evaluating a new endpoint detection and response (EDR) solution. Which of the following capabilities is MOST important for detecting fileless malware?

A.Static malware analysis.
B.Signature-based detection.
C.Behavioral analysis and process monitoring.
D.Network traffic inspection.
AnswerC

Behavioral analysis and process monitoring are highly effective against fileless malware because they observe the actual actions and interactions of processes in real-time on the endpoint. This includes detecting anomalous process creation, suspicious command-line arguments (e.g., PowerShell executing encoded commands), unauthorized memory access (e.g., process injection), and unusual system calls, regardless of whether a file was ever written to disk.

Why this answer

Behavioral analysis and process monitoring is the most important capability for detecting fileless malware because fileless attacks execute in memory using legitimate system tools (e.g., PowerShell, WMI, .NET) and leave no files on disk for static or signature-based tools to detect. EDR solutions with behavioral analytics monitor process execution chains, API calls, and anomalous activity patterns to identify malicious behavior regardless of file artifacts.

Exam trap

CISSP often tests the distinction between prevention/detection layers — candidates select network traffic inspection because they associate 'detection' with network monitoring, missing that fileless malware requires host-level behavioral visibility.

How to eliminate wrong answers

Option A is wrong because static malware analysis examines file contents at rest — fileless malware has no persistent file on disk, so there is nothing to analyze statically. Option B is wrong because signature-based detection relies on known file hashes or byte patterns; fileless malware uses legitimate binaries and scripts that do not match malware signatures. Option D is wrong because network traffic inspection can detect some command-and-control communication but cannot identify the in-memory execution techniques, process injection, or script-based payloads that define fileless malware — it addresses a different layer of the attack.

356
MCQhard

Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?

A.SOC 2 Type II
B.SOC 3
C.SOC 1 Type II
D.SOC 2 Type I
AnswerB

A SOC 3 report is specifically designed for general public use, offering a high-level summary of a service organization's internal controls related to the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Unlike SOC 2 reports, it omits the detailed description of controls and test results, making it suitable for marketing purposes or posting on a website without revealing sensitive operational details. Its primary purpose is public assurance.

Why this answer

SOC 3 reports are designed for public distribution and provide a high-level summary of an organization's controls related to security, availability, confidentiality, integrity, and privacy (the Trust Services Criteria). Unlike SOC 2 reports, SOC 3 reports do not include detailed testing results, control descriptions, or the auditor's opinion on control effectiveness, making them suitable for marketing or public disclosure.

Exam trap

The trap here is that candidates confuse SOC 2 Type II (which includes detailed testing results) with SOC 3, or assume that SOC 2 Type I (point-in-time) is a public summary, when in fact SOC 3 is the only report designed for public distribution without detailed testing results.

How to eliminate wrong answers

Option A is wrong because SOC 2 Type II reports include detailed testing results over a period of time, including the auditor's opinion on the effectiveness of controls, which contradicts the question's requirement for a public summary without detailed testing results. Option C is wrong because SOC 1 Type II reports focus on controls relevant to financial reporting (under SSAE 18) and are restricted to user entities and their auditors, not public summaries, and they include detailed testing results. Option D is wrong because SOC 2 Type I reports, while covering the same Trust Services Criteria, describe controls at a single point in time and include detailed control descriptions and auditor opinions, not a public summary without testing results.

357
MCQhard

An organization uses a custom application that stores user passwords using salted SHA-256 hashes. During a security audit, the auditor recommends migrating to a more secure password storage mechanism. Which of the following is the best recommendation?

A.Use plaintext with database encryption
B.Use AES-256 encryption for passwords
C.Use bcrypt with a cost factor of 12
D.Use MD5 with a salt
E.Use PBKDF2 with 10,000 iterations
AnswerC

Bcrypt is an excellent choice for password storage because it is a deliberately slow, adaptive hashing algorithm designed to resist brute-force and rainbow table attacks. Its "cost factor" (or work factor) parameter, set at 12 in this case, controls the computational difficulty, making it expensive for attackers to test many passwords per second. This inherent slowness, combined with built-in salting, significantly enhances the security of stored passwords against modern cracking techniques, including those utilizing GPUs.

Why this answer

bcrypt is a deliberately slow, adaptive password hashing function that includes a built-in salt and a configurable cost factor. A cost factor of 12 makes each hash computation computationally expensive, effectively thwarting brute-force and GPU-based attacks. Unlike SHA-256, which is designed for speed and can be cracked rapidly with modern hardware, bcrypt's design inherently resists parallelization and ASIC/GPU acceleration.

Exam trap

The trap here is that candidates often confuse 'encryption' (reversible) with 'hashing' (one-way) and mistakenly choose AES-256 or database encryption, failing to recognize that password storage must use a slow, salted, one-way hashing algorithm specifically designed for credential protection.

How to eliminate wrong answers

Option A is wrong because storing passwords in plaintext, even with database encryption, exposes them to any attacker who gains access to the decryption key or the running application, violating the fundamental principle of never storing passwords in recoverable form. Option B is wrong because AES-256 encryption is reversible; if the encryption key is compromised, all passwords are instantly exposed, and encryption does not protect against insider threats or application-level breaches. Option D is wrong because MD5 is cryptographically broken and vulnerable to collision attacks, and even with a salt, it is far too fast to compute, allowing attackers to crack hashes at billions per second.

Option E is wrong because while PBKDF2 is a reasonable key derivation function, 10,000 iterations is considered a weak and outdated iteration count; modern recommendations (e.g., NIST SP 800-63B) suggest at least 310,000 iterations for SHA-256, and PBKDF2 is less resistant to GPU/ASIC attacks than bcrypt or Argon2.

358
Multi-Selecteasy

Which TWO are essential components of a security policy framework?

Select 2 answers
A.Specific encryption key lengths
B.Incident response flowcharts
C.Network topology diagrams
D.Roles and responsibilities
E.Statement of scope
AnswersD, E

Defining roles and responsibilities is an essential component of a security policy framework because it assigns accountability and clarifies who is responsible for specific security tasks and decisions. This ensures that all personnel understand their obligations regarding information security, from data ownership and system administration to compliance monitoring. Without clearly delineated roles, policies lack enforceability and the organization cannot effectively manage its security posture, leading to potential gaps and failures in implementation.

Why this answer

Roles and responsibilities (D) are essential because they define who is accountable for implementing, maintaining, and enforcing the security policy. Without clear assignment of duties, policy execution becomes unenforceable and audit trails lack ownership, violating the separation of duties principle central to the Security and Risk Management domain.

Exam trap

The trap here is that candidates confuse operational documents (flowcharts, diagrams, key lengths) with the foundational governance components of a policy framework, which must always include scope and accountability to be enforceable.

359
MCQhard

A government agency's data retention policy requires that classified documents be destroyed after 10 years. Which method ensures both the information and the media are completely destroyed in a way that is verifiable and auditable?

A.Incineration in a certified facility
B.Overwriting the data seven times
C.Degaussing the storage media
D.Deleting all files and emptying the recycle bin
AnswerA

Incineration in a certified facility provides the most absolute method of data destruction by physically reducing the storage media to ash. This process renders all data completely unrecoverable, satisfying the highest security requirements for sensitive government information. The certification ensures compliance with environmental regulations and provides an essential audit trail through destruction certificates, verifying the complete and irreversible elimination of the data-bearing asset.

Why this answer

Incineration in a certified facility is the only option that completely destroys both the information and the physical media, leaving no residue that could be reconstructed. For classified government documents, the destruction must be verifiable and auditable, which a certified incineration facility provides through documented chain-of-custody and destruction certificates. This method ensures the media is physically reduced to ash, eliminating any possibility of data recovery, unlike logical or magnetic techniques.

Exam trap

The trap here is that candidates often confuse 'sanitization' with 'destruction' — they may choose degaussing or overwriting because those methods effectively erase data, but the question explicitly requires complete destruction of both information and media, which only physical destruction methods like incineration achieve.

How to eliminate wrong answers

Option B is wrong because overwriting data seven times (e.g., using the Gutmann method) only addresses logical data on functional media; it does not destroy the physical media itself, and for classified documents, the media must be physically destroyed to prevent reconstruction from residual magnetic patterns or platter remnants. Option C is wrong because degaussing destroys the magnetic field on storage media, rendering data unreadable, but it does not destroy the media itself; degaussed drives can still be physically intact and potentially leak information through physical inspection or advanced forensic techniques, and it is not verifiable for all media types (e.g., SSDs). Option D is wrong because deleting files and emptying the recycle bin only removes file system pointers, leaving the actual data intact on the media until overwritten; this is completely insufficient for classified destruction and provides no verifiable or auditable proof of destruction.

360
MCQhard

A multinational corporation is establishing a security governance framework. The board of directors wants to ensure that information security strategy aligns with business objectives. Which role is primarily responsible for integrating security into the organization's strategic decision-making?

A.IT security team
B.Internal audit team
C.Senior management
D.Data owner
AnswerC

Senior management is ultimately responsible for establishing and overseeing the organization's security governance framework. They possess the necessary authority to define the strategic direction for security, articulate the enterprise's risk appetite, and ensure that security objectives are fully integrated with and support overall business goals. This leadership ensures adequate resources are allocated and accountability is clearly defined across the organization.

Why this answer

Senior management (C) is primarily responsible for integrating security into strategic decision-making because they hold the authority to allocate resources, define risk appetite, and ensure that security initiatives directly support business objectives. In a governance framework, only senior management can bridge the gap between operational security and enterprise strategy, as they are accountable for the organization's overall risk posture and compliance mandates.

Exam trap

The trap here is that candidates often confuse operational responsibility (IT security team) with strategic accountability (senior management), leading them to select the IT security team because they are the ones executing security tasks, but the CISSP emphasizes that governance and strategic alignment are board-level duties.

How to eliminate wrong answers

Option A is wrong because the IT security team is responsible for implementing and operationalizing security controls, not for setting strategic direction or aligning security with business goals. Option B is wrong because the internal audit team provides independent assurance and evaluates control effectiveness, but they do not own or drive strategic integration of security. Option D is wrong because the data owner is accountable for classifying and protecting specific data assets, not for enterprise-wide strategic alignment of security with business objectives.

361
MCQmedium

A company is implementing a secure software development lifecycle (SSDLC). Which of the following is a key activity during the design phase?

A.Static code analysis
B.Code signing
C.Threat modeling
D.Penetration testing
AnswerC

Threat modeling is a structured approach used early in the Software Development Life Cycle (SDLC), specifically during the design phase, to identify potential threats, vulnerabilities, and attack vectors. It involves analyzing the system's architecture, data flows, and trust boundaries to proactively understand where security controls are needed. By identifying and mitigating risks before coding begins, it significantly reduces the cost and effort of fixing security flaws later.

Why this answer

Threat modeling is a key activity during the design phase of the SSDLC because it proactively identifies potential security threats, vulnerabilities, and attack vectors before any code is written. By analyzing the system's architecture, data flows, and trust boundaries (e.g., using STRIDE or PASTA methodologies), teams can design security controls directly into the system, reducing the cost and impact of fixes later. This aligns with the NIST SP 800-64 and Microsoft SDL frameworks, which mandate threat modeling as a core design-phase activity.

Exam trap

The trap here is that candidates confuse 'design phase' with 'implementation phase' activities, mistakenly selecting static code analysis (A) because it is a common security review, but it requires code to exist, whereas threat modeling is the only design-phase option that addresses architecture before code is written.

How to eliminate wrong answers

Option A is wrong because static code analysis is a source code review technique performed during the implementation phase, not the design phase, as it requires code to be written to scan for syntax errors and security flaws. Option B is wrong because code signing is a deployment-phase activity that uses digital signatures (e.g., Authenticode) to verify the integrity and origin of compiled binaries, not a design-phase task. Option D is wrong because penetration testing is a validation activity performed during the testing or operations phase, where live systems are attacked to find vulnerabilities, not during design.

362
MCQmedium

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

A.To provide oversight and approval for significant changes
B.To implement changes as requested by management
C.To review security incidents after they occur
D.To approve all changes to the production environment
AnswerA

The Change Advisory Board (CAB) primarily serves as a governance body responsible for evaluating and authorizing significant changes to IT services and infrastructure. This oversight ensures that all high-impact or high-risk modifications are thoroughly assessed for potential security implications, operational disruptions, and resource requirements before implementation. Their approval process is crucial for maintaining system stability, security posture, and compliance.

Why this answer

The Change Advisory Board (CAB) exists to review, assess, and approve significant changes before they are deployed, providing governance and risk oversight across the IT environment. Its primary purpose is oversight and approval, not hands-on implementation or incident review. This aligns with ITIL change enablement practices, where the CAB advises the change authority on risk and impact.

Exam trap

CISSP often tests the scope of CAB authority — candidates pick 'approve all changes' because it sounds comprehensive, but the CAB only reviews significant/high-risk changes; standard changes are pre-authorized and bypass the CAB.

How to eliminate wrong answers

Option B is wrong because implementing changes is the responsibility of the change implementer or technical team, not the CAB; the CAB is a governance body, not an execution team. Option C is wrong because reviewing security incidents after they occur is the role of incident response and post-incident review processes, not the CAB, whose focus is pre-deployment change risk. Option D is wrong because the CAB does not approve all changes — standard/low-risk changes are typically pre-authorized and handled through the change model without CAB review, and the CAB only reviews significant or high-risk changes.

363
MCQmedium

Which of the following describes the concept of 'least privilege' in the context of access control?

A.Users are granted only the permissions necessary to perform their job functions
B.Access is granted on a need-to-know basis but with maximum permissions
C.Access is based on roles and seniority
D.Users have access to all resources unless explicitly denied
AnswerA

The principle of least privilege dictates that users, processes, and applications should be granted only the absolute minimum set of permissions required to perform their legitimate functions. This minimizes the potential damage from accidental errors, insider threats, or external attacks, as a compromised entity will have limited capabilities within the system. It's a foundational security concept that reduces the overall attack surface and limits the blast radius of any security incident.

Why this answer

Least privilege is a fundamental access control principle that mandates users be granted only the permissions necessary to perform their specific job functions. This minimizes the attack surface by reducing unnecessary access to sensitive resources, limiting potential damage from accidental or malicious actions. In practice, this is enforced through mechanisms like discretionary access control (DAC) or role-based access control (RBAC) with granular permission sets, ensuring no user has more rights than required.

Exam trap

The trap here is that candidates often confuse 'least privilege' with 'need-to-know' (which focuses on data confidentiality rather than permission granularity) or assume that role-based access inherently enforces least privilege, ignoring that roles can be overly broad.

How to eliminate wrong answers

Option B is wrong because it contradicts least privilege by granting 'maximum permissions' on a need-to-know basis, which would over-provision access and increase risk. Option C is wrong because it conflates least privilege with role-based access control (RBAC) and seniority, which may assign excessive permissions based on role hierarchy rather than actual job necessity. Option D is wrong because it describes a default-allow or 'open' access model, which is the opposite of least privilege; least privilege requires explicit permission grants, not implicit access to all resources.

364
MCQhard

In OAuth 2.0, which grant type is recommended for a native mobile application that cannot securely store a client secret, and uses PKCE?

A.Client Credentials grant
B.Implicit grant
C.Device Code grant
D.Authorization Code grant with PKCE
AnswerD

The Authorization Code grant with Proof Key for Code Exchange (PKCE) is the recommended and most secure flow for public clients like native mobile applications. PKCE mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and send its hash (`code_challenge`) during the initial authorization request. The same `code_verifier` must then be presented when exchanging the authorization code for an access token, ensuring only the legitimate client that initiated the request can complete the exchange, even if the code is intercepted.

Why this answer

The Authorization Code grant with PKCE (Proof Key for Code Exchange, RFC 7636) is the OAuth 2.0 best practice for public clients like native mobile apps that cannot keep a client secret. PKCE replaces the static client secret with a dynamically generated code_verifier/code_challenge pair, preventing authorization code interception attacks.

Exam trap

CISSP often tests the misconception that the Implicit grant is still acceptable for mobile/SPA clients — candidates must know it is deprecated in favor of Authorization Code + PKCE.

How to eliminate wrong answers

Option A is wrong because the Client Credentials grant is for machine-to-machine (confidential) clients with no user context and requires a client secret — inappropriate for a mobile app acting on behalf of a user. Option B is wrong because the Implicit grant returns tokens directly in the URL fragment, is deprecated in OAuth 2.1, and is vulnerable to token leakage; it does not use PKCE. Option C is wrong because the Device Code grant is designed for input-constrained devices (smart TVs, CLI) where the user authorizes on a separate device, not for a native mobile app that has a browser.

365
Multi-Selectmedium

A company is migrating from WPA2 to WPA3 to improve wireless security. Which THREE of the following are features of WPA3 compared to WPA2?

Select 3 answers
A.Backward compatibility with WPA2 clients without security reduction
B.Protected Management Frames (PMF)
C.Use of SAE instead of PSK for key exchange
D.Forward secrecy
E.Mandatory use of TKIP for encryption
AnswersB, C, D

Protected Management Frames (PMF) is a correct answer because it is a mandatory feature in WPA3, significantly enhancing the robustness of wireless networks. PMF cryptographically protects critical Wi-Fi management frames, such as deauthentication and disassociation messages, from spoofing and tampering. This prevents denial-of-service attacks where an attacker could easily disconnect legitimate users from the network in WPA2.

Why this answer

Option B is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protect management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks that were possible under WPA2. Option C is correct because WPA3 replaces the WPA2 Pre-Shared Key (PSK) four-way handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that resists offline dictionary attacks. Option D is correct because SAE provides forward secrecy, meaning a compromised session key or password cannot be used to decrypt previously captured traffic, a property WPA2-PSK lacks.

Option A is not correct as stated because WPA3's backward-compatible WPA3-Personal transition mode allows WPA2 clients to connect only by operating in a mixed mode that can be downgraded, so it does not preserve full WPA3 security without reduction. Option E is not correct because WPA3 does not mandate TKIP; TKIP is a deprecated WPA cipher, and WPA3 requires CCMP-128 (and optionally GCMP-256) with AES.

Exam trap

A common misconception is that WPA3 transition mode (mixed mode) allows backward compatibility without any security trade-offs. In reality, transition mode is vulnerable to downgrade attacks where an attacker can force a WPA3-capable client to connect using WPA2, thereby reducing the overall security of the network.

366
MCQhard

A financial institution mandates that all administrative access to network devices must go through a privileged access management (PAM) solution. The PAM solution manages and rotates credentials automatically and logs all sessions. Recently, an auditor discovered that a router's configuration was changed outside of the approved change window. PAM logs show no session during that time. The router supports both local and RADIUS authentication. Which of the following is the MOST likely explanation for the unauthorized change?

A.A local account on the router was used that is not managed by the PAM solution.
B.The PAM solution's database was corrupted and failed to log the session.
C.The router's RADIUS configuration pointed to a different, unmonitored authentication server.
D.The network administrator used a shared service account not unique to the PAM system.
AnswerA

This is the most direct and common vulnerability that allows administrative actions to bypass centralized logging. If a router maintains local user accounts or an 'enable secret' password that is not integrated with or managed by the PAM solution, any access performed using these credentials will entirely circumvent the PAM system's session recording, auditing, and logging capabilities. This creates a critical blind spot, enabling unmonitored configuration changes and directly violating the financial institution's mandate for comprehensive administrative access logging.

Why this answer

The PAM solution logs all sessions, but the logs show no session during the time of the unauthorized change. Since the router supports both local and RADIUS authentication, the most likely explanation is that a local account (e.g., a console or enable password) was used directly on the router, bypassing the PAM-managed RADIUS authentication entirely. Local accounts are not managed or rotated by the PAM solution, so no session would be recorded.

Exam trap

The trap here is that candidates assume all administrative access must go through PAM, but they overlook that local accounts on the device itself are not managed by PAM and can be used to make changes without any PAM session log.

How to eliminate wrong answers

Option B is wrong because database corruption would likely cause a failure to log multiple sessions or produce error logs, not a single missing session with all other logs intact. Option C is wrong because if the RADIUS configuration pointed to a different, unmonitored server, that server would still authenticate the session, and the PAM solution would not log it, but the router's RADIUS configuration is typically managed by the PAM solution or network team; however, the question states the PAM solution manages credentials and logs sessions, so a different RADIUS server would still generate a session log on that server, not a complete absence of logs. Option D is wrong because a shared service account not unique to the PAM system would still be authenticated via RADIUS (if configured) and would appear in the PAM logs as a session, even if the account is shared; the absence of any session log indicates no RADIUS authentication occurred.

367
MCQhard

A network architect is designing a network to comply with PCI DSS requirements that cardholder data must be encrypted during transmission over open networks. Which protocol should be used for encrypting traffic between a point-of-sale (POS) terminal and the payment gateway?

A.TLS 1.0
B.TLS 1.2
C.SSH
D.SSL 3.0
AnswerB

TLS 1.2 is currently considered a strong cryptographic protocol, supporting robust algorithms like AES-GCM and SHA-256 for encryption and hashing, respectively. It effectively mitigates vulnerabilities present in older versions, making it compliant with PCI DSS Requirement 4.1 for securing cardholder data in transit. Its widespread adoption ensures interoperability and strong security for payment transactions.

Why this answer

TLS 1.2 is the correct choice because it is a widely accepted, secure protocol for encrypting data in transit, and it meets PCI DSS requirements for strong cryptography. PCI DSS explicitly prohibits the use of SSL and early TLS versions (1.0) due to known vulnerabilities, and TLS 1.2 provides robust cipher suites and forward secrecy.

Exam trap

The trap here is that candidates may confuse TLS 1.0 with TLS 1.2, assuming all TLS versions are equally secure, but PCI DSS explicitly requires TLS 1.2 or higher, and TLS 1.0 is considered weak and non-compliant.

How to eliminate wrong answers

Option A is wrong because TLS 1.0 is deprecated by PCI DSS as of June 30, 2018, due to vulnerabilities such as BEAST and POODLE, and does not meet the requirement for strong encryption. Option C is wrong because SSH is primarily used for secure remote administration and file transfer, not for encrypting POS-to-gateway traffic, and it operates at a different layer (application) than the transport-layer encryption needed for payment protocols. Option D is wrong because SSL 3.0 is completely broken and prohibited by PCI DSS since June 30, 2015, due to the POODLE attack and lack of secure cipher suites.

368
MCQeasy

Which of the following is a primary function of a Trusted Platform Module (TPM)?

A.Encrypting network traffic
B.Providing antivirus protection
C.Enforcing access control policies
D.Storing cryptographic keys securely
AnswerD

Storing cryptographic keys securely is a core and primary function of a Trusted Platform Module (TPM). The TPM provides a tamper-resistant environment, often isolated from the main CPU, where sensitive cryptographic keys can be generated, stored, and used without being exposed to software vulnerabilities or physical attacks on the host system. This secure storage protects keys from unauthorized access and ensures their integrity, which is crucial for secure boot, disk encryption, and digital signing operations.

Why this answer

A Trusted Platform Module (TPM) is a hardware chip that securely stores cryptographic keys, certificates, and measurements used for platform integrity and encryption. Its primary function is secure key storage and cryptographic operations, such as protecting BitLocker keys and enabling measured boot. Option D correctly identifies this core capability.

Exam trap

CISSP often tests the misconception that a TPM encrypts network traffic or enforces access control, when its primary role is secure cryptographic key storage and platform integrity measurement.

How to eliminate wrong answers

Option A is wrong because encrypting network traffic is the role of protocols like TLS/IPsec, not the TPM; the TPM may store keys used by those protocols but does not encrypt traffic itself. Option B is wrong because antivirus protection is a software function, unrelated to the TPM's cryptographic and integrity roles. Option C is wrong because enforcing access control policies is handled by operating systems, IAM systems, and policy engines; the TPM supports secure boot and attestation but does not enforce access control policies.

369
Drag & Dropmedium

Drag and drop the steps for a secure password change procedure in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Password change: verify identity, enter new password, enforce history, hash storage, log.

370
MCQhard

A security analyst discovers that a service account in Active Directory has not had its password changed in 5 years and has domain admin privileges. The account is used by a legacy application that does not support modern authentication protocols. Which of the following is the MOST secure approach to manage this account?

A.Convert the account to a group Managed Service Account (gMSA)
B.Set a very long, complex password and store it in a password manager
C.Decommission the legacy application and migrate to a modern alternative that supports secure authentication
D.Disable the account and create a new service account with limited privileges
AnswerC

Decommissioning the legacy application and migrating to a modern alternative is the most comprehensive and effective long-term solution. This approach eliminates the underlying security risk entirely by removing the need for a problematic service account that relies on insecure authentication methods. Modern applications typically support robust authentication mechanisms like OAuth 2.0, OpenID Connect, or integrated Windows authentication, which significantly enhance security posture and reduce the attack surface associated with static credentials. This strategy proactively addresses the root cause of the vulnerability.

Why this answer

The most secure long-term approach is to eliminate the risky legacy dependency entirely by decommissioning the application and migrating to a modern alternative that supports secure authentication such as Kerberos, OAuth, or certificate-based auth. This removes the need for a standing domain-admin service account with a five-year-old password, which is a severe lateral-movement and credential-theft risk. Until the application is retired, no compensating control fully neutralizes the exposure of a privileged, stale credential.

Exam trap

The trap here is choosing a 'compensating control' (long password, gMSA, disable-and-recreate) that sounds secure but does not actually work for a legacy app that cannot support modern authentication — CISSP expects you to pick the option that removes the risk rather than patches around it.

How to eliminate wrong answers

Option A is wrong because a gMSA requires the application to support Windows authentication/Kerberos and managed password retrieval; a legacy app that does not support modern authentication protocols typically cannot consume a gMSA, so it is not a viable fix. Option B is wrong because a long complex password stored in a password manager still leaves a privileged static credential that can be phished, dumped from memory, or reused, and it does not address the legacy protocol weakness. Option D is wrong because disabling the account breaks the legacy application, and creating a new limited-privilege account may not satisfy the application's requirements — it is a partial mitigation that does not remove the underlying risk.

371
MCQeasy

A system administrator is configuring an LDAP directory for user authentication. The policy requires that account lockout occurs after a specified number of failed attempts. Which attribute should be configured?

A.failedLoginAttempts
B.lockoutThreshold
C.lockoutDuration
D.passwordLockoutTime
AnswerB

The `lockoutThreshold` attribute is the precise configuration setting that defines the maximum number of consecutive failed authentication attempts permitted for a user account before the system automatically locks it. This attribute establishes the critical security policy that prevents brute-force attacks by specifying *how many* failures will trigger the account lockout mechanism, directly addressing the system administrator's goal.

Why this answer

The `lockoutThreshold` attribute in an LDAP directory specifies the maximum number of consecutive failed authentication attempts allowed before the account is locked. This directly satisfies the policy requirement to lock the account after a specified number of failed attempts, making it the correct attribute to configure.

Exam trap

The trap here is that candidates confuse the attribute that sets the failure limit (`lockoutThreshold`) with the attribute that tracks current failures (`failedLoginAttempts`) or the attribute that sets the lockout duration (`lockoutDuration`), leading them to pick a wrong option that describes a related but distinct function.

How to eliminate wrong answers

Option A is wrong because `failedLoginAttempts` is typically an operational attribute that tracks the current count of failed attempts, not a configuration parameter that sets the threshold for lockout. Option C is wrong because `lockoutDuration` defines how long the account remains locked after the threshold is exceeded, not the number of failed attempts that trigger the lockout. Option D is wrong because `passwordLockoutTime` is not a standard LDAP attribute; it may be confused with a timestamp of when the lockout occurred, but it does not set the failure count limit.

372
MCQmedium

An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?

A.Escalation paths
B.Communication plan
C.Recovery procedures
D.Incident categories
AnswerA

Escalation paths are a critical component of an incident response plan, explicitly detailing the predefined triggers and the hierarchical notification process for significant incidents. They specify which individuals or departments, such as senior management, legal counsel, or public relations, must be informed at various stages of an incident based on its severity, impact, or regulatory implications. This ensures that appropriate leadership and specialized expertise are engaged promptly to manage the broader organizational consequences.

Why this answer

Escalation paths define the criteria, thresholds, and chain of command for moving an incident to higher authority, including when senior management and legal counsel must be engaged. They specify who is notified, under what conditions, and in what timeframe, which is exactly the component that governs escalation to executives and legal. This makes escalation paths the primary owner of that decision logic within the IR plan.

Exam trap

The trap here is confusing the communication plan (how you communicate) with escalation paths (when and to whom you escalate), causing candidates to pick the communication plan for a question about escalation criteria.

How to eliminate wrong answers

Option B is wrong because the communication plan defines how information is shared (internal/external messaging, stakeholders, media), not the criteria for when to escalate to management or legal. Option C is wrong because recovery procedures describe how to restore systems and services after an incident, not who gets notified or when escalation is triggered. Option D is wrong because incident categories classify incidents by type or severity for triage and prioritization; while severity can inform escalation, the categories themselves do not define the escalation criteria or the management/legal notification triggers.

373
MCQhard

A company uses BGP to exchange routes with its ISP. To prevent prefix hijacking, which mechanism should be implemented?

A.BGP MD5 authentication
B.BGP community values
C.RPKI
D.AS-path filtering
AnswerC

Resource Public Key Infrastructure (RPKI) provides a robust cryptographic framework for validating the origin of IP prefixes, directly addressing route hijacking. It enables legitimate IP address holders to create cryptographically signed Route Origin Authorizations (ROAs), which explicitly state which Autonomous System (AS) is authorized to originate specific IP prefixes. Routers can then use these ROAs to verify the authenticity of BGP announcements, filtering out routes where the advertised origin AS does not match the authorized AS, thereby effectively mitigating route hijacking.

Why this answer

RPKI (Resource Public Key Infrastructure) is the correct mechanism because it cryptographically validates the origin AS of a BGP route announcement, preventing prefix hijacking by ensuring that only the legitimate owner of an IP prefix can announce it. Unlike other options, RPKI provides a trust anchor based on the IP address allocation hierarchy, making it the only solution that directly addresses the root cause of hijacking—unauthorized origin AS claims.

Exam trap

ISC2 often tests BGP MD5 authentication as a security measure, but the trap here is confusing session-level authentication (MD5) with route-level validation (RPKI), leading candidates to choose A because they think 'authentication' covers route integrity, when it only protects the BGP session itself.

How to eliminate wrong answers

Option A is wrong because BGP MD5 authentication (RFC 2385) only secures the TCP session between BGP peers, preventing spoofed TCP resets or session hijacking, but does not validate the legitimacy of the route content itself, so it cannot stop a malicious AS from announcing a prefix it does not own. Option B is wrong because BGP community values are tags used for route policy and traffic engineering (e.g., prepending, local preference), but they are not authenticated or cryptographically bound to the origin AS, so they can be easily manipulated or ignored by an attacker. Option D is wrong because AS-path filtering relies on manually configured prefix lists or AS-path access lists to block routes based on AS-path patterns, which is static, error-prone, and cannot detect hijacks where the attacker uses a legitimate AS-path (e.g., via a compromised AS or by prepending a valid AS number).

374
MCQeasy

A network security analyst receives an alert from the intrusion detection system (IDS) indicating a high volume of TCP SYN packets to a single external IP address from a compromised internal host. This is characteristic of which type of attack?

A.SYN flood
B.Man-in-the-middle
C.ARP spoofing
D.DNS amplification
AnswerA

A SYN flood is a classic Denial-of-Service (DoS) attack that exploits the TCP three-way handshake. Attackers send a high volume of TCP SYN packets to a target server, but intentionally never complete the handshake by sending the final ACK. This leaves the server with numerous half-open connections, rapidly exhausting its connection table and memory resources, thereby preventing legitimate users from establishing new connections and causing a service outage.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending a high volume of SYN packets to a target, exhausting its connection table and preventing legitimate connections. The IDS alert specifically describes a compromised internal host generating many SYN packets to a single external IP, which matches the classic behavior of a SYN flood where the attacker spoofs the source IP or uses a bot to saturate the target's resources.

Exam trap

The trap here is that candidates confuse a SYN flood (which uses TCP SYN packets to exhaust resources) with a DNS amplification attack (which uses UDP and reflection), but the question's mention of 'TCP SYN packets' directly points to the SYN flood, not a volumetric reflection attack.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack involves intercepting and potentially altering communications between two parties, not generating a high volume of SYN packets to a single external IP. Option C is wrong because ARP spoofing operates at Layer 2 by associating an attacker's MAC address with a legitimate IP address on a local network, not by sending TCP SYN packets to an external IP. Option D is wrong because a DNS amplification attack uses small DNS queries with spoofed source IPs to generate large responses directed at a victim, relying on UDP and DNS servers, not TCP SYN packets from a compromised host.

375
MCQeasy

A company requires employees to authenticate using a smart card and PIN to access the corporate network. This is an example of which type of authentication?

A.Single-factor authentication
B.Biometric authentication
C.Two-factor authentication
D.Single sign-on
AnswerC

Two-factor authentication (2FA) requires a user to provide two different types of credentials from distinct categories to verify their identity. The scenario explicitly states the use of a smart card, which represents "something you have," and a PIN, which represents "something you know." Since these are two separate and independent authentication factors, this method precisely matches the definition and implementation of two-factor authentication, making it the correct answer.

Why this answer

This scenario requires two distinct authentication factors: something you have (the smart card) and something you know (the PIN). Smart cards store a private key or certificate that must be unlocked by the PIN, and both factors must be presented simultaneously to authenticate. This meets the NIST SP 800-63 definition of multi-factor authentication, specifically two-factor authentication.

Exam trap

The trap here is that candidates may mistakenly think a smart card alone is a single factor, forgetting that the PIN is a separate knowledge factor, or they may confuse two-factor authentication with SSO because both can involve a single login event.

How to eliminate wrong answers

Option A is wrong because single-factor authentication uses only one factor (e.g., just a password or just a smart card), but here both a smart card and a PIN are required. Option B is wrong because biometric authentication relies on physical characteristics like fingerprints or iris patterns, not a smart card and PIN. Option D is wrong because single sign-on (SSO) allows a user to authenticate once and access multiple systems without re-entering credentials, but it does not define the number of factors used in that initial authentication.

Page 4

Page 5 of 11

Page 6

All pages