Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 376–450

816 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
MCQeasy

A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:

A.Black box
B.White box
C.Grey box
D.Internal test
AnswerA

Black box testing simulates an external attacker with no prior knowledge of the target system's internal structure, network architecture, or source code. The assessor approaches the system as an unprivileged outsider, attempting to discover vulnerabilities through publicly available information and external reconnaissance. This method effectively evaluates an organization's perimeter defenses and its ability to withstand real-world, unknown threats, making it ideal for a third-party assessment where initial knowledge is withheld.

Why this answer

A black box penetration test simulates an external attacker with no prior knowledge of the target environment. The testers are given no credentials, network diagrams, or internal details, forcing them to perform reconnaissance and exploitation from an outsider's perspective. This aligns directly with the scenario where the third party has 'no prior knowledge of the internal network.'

Exam trap

The trap here is confusing the test's knowledge level (black, white, grey) with the test's origin (internal vs. external), leading candidates to incorrectly select 'Internal test' because they associate 'no prior knowledge' with an external perspective, but the question explicitly asks for the type based on knowledge, not location.

How to eliminate wrong answers

Option B is wrong because a white box test provides testers with full knowledge of the internal network, including credentials, source code, and architecture diagrams, which contradicts the 'no prior knowledge' condition. Option C is wrong because a grey box test offers limited knowledge, such as user-level credentials or partial network maps, not zero prior knowledge. Option D is wrong because an internal test is defined by the test's origin (inside the network perimeter), not by the level of knowledge; internal tests can be black, white, or grey box, and the question specifically describes the knowledge level, not the test location.

377
Multi-Selectmedium

A company is conducting a security assessment of its network infrastructure. Which of the following activities are typically performed during a vulnerability assessment? (Select TWO.)

Select 2 answers
A.Identification of missing security patches
B.Attempting to crack password hashes
C.Social engineering attacks against employees
D.Exploiting identified vulnerabilities to gain unauthorized access
E.Automated scanning of open ports and services
AnswersA, E

Vulnerability assessment inventories known weaknesses, and missing security patches are a primary finding because unpatched software exposes documented CVEs. Identifying them satisfies the stem's requirement for a typical vulnerability assessment activity, without exploiting the flaws as a penetration test would.

Why this answer

Option A is correct because a vulnerability assessment catalogs known weaknesses such as missing security patches by comparing installed software versions against vendor advisories and CVE databases. Option E is correct because automated scanners (e.g., Nessus, Qualys, OpenVAS) enumerate open ports and fingerprint running services to identify potential exposures, which is a core assessment activity. Option B does not belong because cracking password hashes is a penetration-testing/attack activity that attempts to exploit credentials rather than merely identify weaknesses.

Option C is incorrect because social engineering targets people and falls under penetration testing or red-team engagements, not technical vulnerability scanning. Option D is incorrect because actively exploiting vulnerabilities to gain unauthorized access defines penetration testing, whereas a vulnerability assessment only identifies and reports them.

Exam trap

The trap here is confusing vulnerability assessment (identification only) with penetration testing (identification plus exploitation), leading candidates to select 'Exploiting identified vulnerabilities to gain unauthorized access' as a correct activity.

378
MCQhard

A company uses differential privacy to release aggregate statistics from a dataset containing sensitive employee information. Which of the following is true regarding differential privacy?

A.It works by adding noise to the data or query results to protect individual privacy
B.It ensures that no individual's data can ever be inferred from the released statistics
C.It requires that data be encrypted before release
D.It is a method of pseudonymization that replaces identifiers with pseudonyms
AnswerA

Differential privacy achieves its robust privacy guarantees by systematically injecting carefully calibrated random noise into either the raw data before aggregation or directly into the query results. This noise obfuscates the contribution of any single individual, making it statistically difficult to determine if a particular individual's data was included in the dataset or query. This method allows for the release of aggregate statistics while mathematically bounding the risk of individual re-identification, balancing utility and privacy.

Why this answer

Differential privacy is a mathematical framework that adds calibrated noise (e.g., Laplace or Gaussian) to either the raw data or the query output so that the presence or absence of any single individual changes the result by only a bounded amount. This provides plausible deniability for each record while still allowing statistically useful aggregate results. Option A correctly captures this core mechanism.

Exam trap

CISSP often tests the misconception that differential privacy offers absolute non-inferability (Option B) — candidates confuse its probabilistic guarantee with the stronger, impossible promise of complete anonymity.

How to eliminate wrong answers

Option B is wrong because differential privacy provides probabilistic, not absolute, guarantees — it bounds the influence of any one record via epsilon, but inference is still possible in some cases (especially with small epsilon or repeated queries). Option C is wrong because encryption protects data in transit/at rest and is orthogonal to differential privacy; noise addition, not encryption, is the defining mechanism. Option D is wrong because pseudonymization simply swaps identifiers for tokens and is reversible with the mapping table — it does not provide the statistical indistinguishability that differential privacy guarantees.

379
MCQmedium

During a penetration test, the tester has obtained initial access and is now trying to move laterally to other systems. Which phase of the penetration testing process does this represent?

A.Reconnaissance
B.Reporting
C.Post-exploitation/lateral movement
D.Exploitation
AnswerC

Post-exploitation begins immediately after initial access is successfully gained on a target system. This crucial phase focuses on maintaining access, escalating privileges within the compromised system, gathering sensitive information, and establishing persistence mechanisms. Lateral movement is a key component, involving techniques to pivot from the initial compromised host to other systems within the network, expanding the tester's foothold and access to additional resources to simulate a real-world breach.

Why this answer

The post-exploitation/lateral movement phase occurs after initial access is gained, where the tester uses compromised systems as pivot points to access other network segments, often leveraging tools like PsExec, WMI, or SMB relay to move across hosts. This phase is distinct from exploitation, which focuses on gaining the initial foothold, and reconnaissance, which occurs before any access is obtained.

Exam trap

The trap here is confusing 'exploitation' (gaining initial access) with 'post-exploitation/lateral movement' (using that access to move to other systems), as candidates often think any active attack step is 'exploitation' without recognizing the sequential phases of a penetration test.

How to eliminate wrong answers

Option A is wrong because reconnaissance is the initial information-gathering phase (e.g., DNS enumeration, port scanning) that occurs before any access is obtained, not after initial access. Option B is wrong because reporting is the final phase where findings are documented and presented to stakeholders, not during active lateral movement. Option D is wrong because exploitation is the phase where vulnerabilities are used to gain initial access (e.g., exploiting an SMB vulnerability), not the subsequent movement to other systems.

380
MCQeasy

Which of the following is the primary purpose of output encoding in web application security?

A.Preventing buffer overflow attacks
B.Preventing cross-site request forgery (CSRF)
C.Preventing cross-site scripting (XSS) attacks
D.Preventing SQL injection attacks
AnswerC

Output encoding is the fundamental defense against cross-site scripting (XSS) attacks, which involve injecting malicious client-side scripts into web pages. By transforming potentially dangerous characters like angle brackets (<, >) and quotes (", ') into their safe entity equivalents (e.g., &lt;, &gt;), output encoding ensures that user-supplied input is always interpreted as inert data. This prevents the browser from executing the injected content as active code, thereby neutralizing the XSS payload before it can affect other users.

Why this answer

Output encoding is the practice of converting special characters (e.g., <, >, &, ") into their corresponding HTML entities (e.g., &lt; &gt; &amp; &quot;) before sending data to the browser. This ensures that any user-supplied data is treated as text, not executable code, thereby neutralizing injected scripts. It is the primary defense against stored, reflected, and DOM-based cross-site scripting (XSS) attacks because it breaks the parser's ability to interpret the data as active content.

Exam trap

The trap here is that candidates confuse output encoding with input validation or sanitization, mistakenly thinking it prevents SQL injection or CSRF, but output encoding only neutralizes XSS by ensuring data is rendered as text in the browser, not as executable code.

How to eliminate wrong answers

Option A is wrong because buffer overflow attacks are prevented by bounds checking, input validation, and safe memory functions (e.g., strncpy instead of strcpy), not by output encoding, which operates on output to browsers, not on memory buffers. Option B is wrong because CSRF is prevented by anti-CSRF tokens (e.g., synchronizer tokens or SameSite cookies), not by output encoding, which does not validate the origin or authenticity of requests. Option D is wrong because SQL injection is prevented by parameterized queries (prepared statements) or stored procedures, not by output encoding, which applies to HTML/JavaScript contexts, not to database query construction.

381
Multi-Selectmedium

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Select 3 answers
A.Forensic Investigator
B.Human Resources Representative
C.Incident Response Manager
D.Chief Financial Officer
E.Communications Lead
AnswersA, C, E

A forensic investigator is crucial for preserving the chain of custody, analyzing digital artifacts, and determining the root cause and scope of an incident. Their specialized skills ensure that evidence is admissible in legal proceedings and that a thorough post-incident analysis can be conducted to prevent future occurrences. This role is typically part of a Tier 2 or Tier 3 response, providing deep technical insight.

Why this answer

The Forensic Investigator (A) is a standard IR team role responsible for collecting, preserving, and analyzing digital evidence using forensically sound methods such as write blockers and chain-of-custody documentation. The Incident Response Manager (C) is standard because this role coordinates the overall response, triages incidents, allocates resources, and serves as the decision-making authority during an incident. The Communications Lead (E) is also standard, handling internal and external messaging, stakeholder updates, and coordination with legal, PR, and regulatory bodies to maintain accurate and timely communications.

Human Resources Representative (B) and Chief Financial Officer (D) are not standard core IR team roles; while HR or finance may be consulted for employee-related or cost-impacting incidents, they are not part of the recognized baseline incident response team structure.

Exam trap

CISSP often tests the distinction between core IR team roles and executive/support stakeholders — the trap is selecting HR or CFO because they sound important, when the exam expects NIST/SANS-standard technical and communications roles.

382
Multi-Selectmedium

A security engineer is hardening a web server before deploying a new application. Which TWO of the following are examples of security misconfiguration vulnerabilities that should be addressed?

Select 2 answers
A.Use of an outdated version of a JavaScript library with known vulnerabilities
B.Default administrator credentials remain unchanged
C.Verbose error messages reveal stack traces to users
D.Lack of CSRF tokens in forms
E.Weak password policy allowing short passwords
AnswersB, C

Leaving default administrator credentials unchanged is a quintessential example of a security misconfiguration. These credentials are often publicly known or easily guessable, providing attackers with a straightforward entry point if not immediately altered post-installation. Proper hardening requires modifying all default passwords and usernames to unique, strong values, ensuring the system's initial setup doesn't become its weakest link.

Why this answer

Option B is correct because leaving default administrator credentials unchanged is a classic security misconfiguration: the system is deployed with vendor-supplied accounts (e.g., admin/admin) that attackers can trivially guess, and hardening requires changing or disabling them. Option C is correct because verbose error messages that expose stack traces, framework versions, or file paths are a misconfiguration of error handling and debug settings (e.g., ASP.NET customErrors=Off or Django DEBUG=True), leaking information useful for further attacks. Option A does not belong because using an outdated JavaScript library with known CVEs is a vulnerable component/software supply chain issue, not a configuration error.

Option D does not belong because missing CSRF tokens is a code-level application flaw (broken access/request forgery protection), not a misconfiguration. Option E does not belong because a weak password policy is an authentication/identity policy weakness rather than a system or server misconfiguration.

Exam trap

The CISSP exam often tests the distinction between 'security misconfiguration' and other vulnerability types (e.g., using outdated libraries is a 'using components with known vulnerabilities' issue, not a misconfiguration), so candidates mistakenly classify all common weaknesses as misconfigurations.

383
Multi-Selecthard

A security team is performing a risk assessment on a legacy application that uses insecure deserialization. Which TWO of the following are recommended approaches to mitigate the risk of insecure deserialization?

Select 2 answers
A.Implementing integrity checks (e.g., digital signatures) on serialized objects
B.Encrypting the serialized data
C.Using allow lists for classes that can be deserialized
D.Using generic exception handling to catch errors
E.Logging all deserialization attempts
AnswersA, C

A digital signature, applied by the sender, creates a cryptographic hash of the serialized object and encrypts it with the sender's private key. Upon deserialization, the receiver can verify this signature using the sender's public key and the sender's public key certificate. This process cryptographically guarantees that the serialized data has not been altered in transit, preventing an attacker from injecting malicious code or modifying object properties before deserialization occurs.

Why this answer

Option A is correct because applying integrity checks such as digital signatures or HMACs to serialized objects lets the receiving application verify that the data was not tampered with before deserialization, preventing attackers from injecting malicious serialized payloads. Option C is correct because an allow list (whitelist) restricts deserialization to only explicitly permitted, trusted classes, blocking the instantiation of dangerous gadget classes that enable remote code execution. Option B is not recommended as a primary mitigation because encryption provides confidentiality but does not prevent an attacker who can supply or replay ciphertext from triggering malicious deserialization, and it does not validate object integrity or class types.

Option D is not appropriate because generic exception handling only masks errors and does not stop malicious objects from being deserialized and executed. Option E is not a mitigation because logging deserialization attempts is a detective control that records activity but does not prevent exploitation.

Exam trap

The trap here is that candidates often confuse encryption with integrity protection, thinking that encrypting serialized data prevents tampering, but encryption alone does not provide authentication or integrity — an attacker can still modify ciphertext (bit-flipping attacks) unless combined with a MAC or digital signature.

384
MCQeasy

A system administrator notices that user accounts are often left active after employees leave the company. Which process should be automated to address this?

A.Single sign-on implementation
B.Password reset policy
C.Multi-factor authentication
D.Automated account provisioning and deprovisioning
AnswerD

Automated account provisioning and deprovisioning directly addresses the comprehensive lifecycle management of user identities across an organization's systems. This integrated process automatically creates accounts for new employees, modifies permissions as roles change, and critically, disables or deletes accounts promptly when an employee departs or no longer requires access. By synchronizing with authoritative sources like HR systems, it ensures that user accounts are always aligned with current employment status, significantly mitigating the security risk of orphaned or unauthorized active accounts.

Why this answer

Automated account provisioning and deprovisioning ensures that when an employee leaves the company, their access rights are automatically revoked in a timely manner. This process directly addresses the issue of orphaned accounts by integrating with HR systems to trigger account disablement or deletion upon termination, reducing the risk of unauthorized access.

Exam trap

The trap here is that candidates confuse authentication mechanisms (SSO, MFA, password policies) with identity lifecycle management, assuming any security control that involves accounts will solve the problem of orphaned accounts.

How to eliminate wrong answers

Option A is wrong because Single Sign-On (SSO) simplifies authentication across multiple systems but does not manage the lifecycle of user accounts or remove them when an employee leaves. Option B is wrong because a password reset policy governs how often passwords must be changed or how they are recovered, but it does not deactivate accounts after termination. Option C is wrong because Multi-Factor Authentication (MFA) adds an extra layer of security to the login process but does not automate the creation or removal of user accounts.

385
MCQmedium

During a forensic investigation, the team needs to preserve evidence from a running server. What is the FIRST step the team should take?

A.Capture a memory dump.
B.Create a disk image.
C.Shut down the server normally.
D.Unplug the network cable.
AnswerA

Capturing a memory dump is the most critical initial step in preserving volatile evidence during a forensic investigation. This action secures data residing in RAM, such as active processes, network connections, open files, and potential malware artifacts that exist only in memory. Failure to capture a memory dump before power loss or system shutdown results in the irreversible loss of this highly volatile and often crucial forensic data, adhering to the principle of the order of volatility.

Why this answer

The first step in a forensic investigation of a running server is to capture a memory dump because volatile data (RAM) contains critical evidence such as running processes, network connections, encryption keys, and malware that would be lost if the system is powered off or altered. Preserving this volatile state before any other action ensures that the most transient evidence is secured, following the order of volatility principle. Capturing memory first prevents irreversible loss of data that cannot be recovered from disk or network captures.

Exam trap

The trap here is that candidates often confuse the urgency of preserving volatile data with the desire to immediately isolate the system from the network, leading them to choose unplugging the network cable first, but the correct forensic priority is to capture the most volatile evidence (memory) before any network or power actions.

How to eliminate wrong answers

Option B is wrong because creating a disk image is a non-volatile data acquisition step that should occur after capturing memory, as disk imaging does not preserve volatile evidence like running processes or encryption keys. Option C is wrong because shutting down the server normally would cause the operating system to cleanly terminate processes, potentially destroying evidence such as temporary files, network connections, and memory-resident malware, and may trigger anti-forensic mechanisms. Option D is wrong because unplugging the network cable, while it may prevent remote tampering, is not the first step; it should be performed after memory capture to avoid disrupting network-based evidence (e.g., active connections, network traffic logs) that could be captured from memory first.

386
MCQmedium

A company uses smart cards for authentication to workstations. A user inserts their smart card but is prompted for a PIN. The user enters the correct PIN but authentication fails. The smart card is not expired. What is the most likely cause?

A.The user's certificate is revoked
B.The PIN is incorrectly stored on the card
C.The smart card driver is outdated
D.The workstation's clock is off by more than 5 minutes
AnswerA

When a user authenticates with a smart card, the workstation verifies the digital certificate stored on the card as part of the Public Key Infrastructure (PKI) process. This verification includes checking the certificate's revocation status against a Certificate Revocation List (CRL) or via Online Certificate Status Protocol (OCSP) with the Certificate Authority (CA). If the certificate has been revoked, even if the user enters the correct PIN, the authentication process will fail because the system no longer trusts the identity bound to that certificate, rendering the credential invalid for access.

Why this answer

When a smart card is used for authentication, the PIN unlocks the private key stored on the card, but the actual authentication typically relies on a certificate chain and the validity of the user's certificate. If the certificate has been revoked (e.g., due to compromise or termination), the Certificate Revocation List (CRL) or Online Certificate Status Protocol (OCSP) check will fail, causing authentication to be denied even though the PIN is correct and the card is not expired.

Exam trap

The trap here is that candidates assume PIN entry failure is the only smart card authentication issue, but the PIN only unlocks the private key; the certificate's revocation status is a separate, often overlooked, layer that can cause authentication to fail after correct PIN entry.

How to eliminate wrong answers

Option B is wrong because the PIN is not stored on the card; the PIN is a user-entered secret used to unlock the card's private key, and if the PIN were incorrectly stored, the card would reject the PIN entry itself, not allow entry and then fail authentication. Option C is wrong because an outdated smart card driver would typically cause the card reader to not be recognized or the card to not be read at all, not allow PIN entry and then fail authentication. Option D is wrong because a workstation clock skew of more than 5 minutes could cause certificate validity period checks to fail, but this would affect the certificate's 'not before' or 'not after' dates, not revocation status; revocation is checked via CRL/OCSP independently of system time.

387
MCQmedium

A multinational corporation maintains site-to-site IPsec VPN tunnels between its headquarters and three regional branch offices. Over the past week, the tunnels have been dropping intermittently, causing disruption to real-time applications. The network team checked logs and found frequent 'Phase 2 rekey failure' messages. The tunnels are configured with IKEv1 and preshared keys. The headquarters uses a Cisco ASA, and the branches use various vendors' firewalls. The team verified that firewall policies allow IPsec traffic, and there is no packet loss on the WAN links. Which action should the team take to resolve the issue most effectively?

A.Increase the MTU on the WAN interfaces to 1500 bytes on all firewalls.
B.Change the encryption algorithm from AES-256 to 3DES on all peers.
C.Migrate all VPN connections from IPsec to SSL VPN using clientless access.
D.Adjust the Dead Peer Detection (DPD) intervals and Phase 2 lifetime settings to be consistent across all sites.
AnswerD

Inconsistent Dead Peer Detection (DPD) intervals can cause one peer to prematurely declare the other dead and tear down the tunnel, disrupting rekey attempts. Similarly, mismatched Phase 2 Security Association (SA) lifetimes will cause peers to attempt rekeying at different times, leading to negotiation failures. Ensuring these critical parameters are synchronized across all sites allows for coordinated rekeying and stable tunnel operation, preventing premature disconnections and rekey failures.

Why this answer

The frequent 'Phase 2 rekey failure' messages indicate a mismatch in IPsec security association (SA) parameters between the Cisco ASA and the branch firewalls. IKEv1 Phase 2 lifetimes and Dead Peer Detection (DPD) intervals must be consistent across all peers; otherwise, one side may attempt to rekey or declare the peer dead while the other expects a different timing, causing intermittent tunnel drops. Adjusting these values to match across all sites resolves the rekey failures without compromising security or requiring a protocol migration.

Exam trap

ISC2 often tests the misconception that rekey failures are caused by encryption algorithm mismatches or MTU issues, but the real cause is almost always inconsistent Phase 2 lifetimes or DPD intervals when using IKEv1 with multiple vendor firewalls.

How to eliminate wrong answers

Option A is wrong because increasing MTU to 1500 bytes is the default for Ethernet and does not address Phase 2 rekey failures; MTU issues typically cause fragmentation or packet loss, not rekey mismatches. Option B is wrong because changing from AES-256 to 3DES weakens encryption and does not fix rekey failures; the problem is timing/parameter consistency, not cipher strength. Option C is wrong because migrating to SSL VPN with clientless access is a completely different architecture that would not resolve IPsec Phase 2 rekey failures and would introduce new complexity; the issue is specific to IKEv1 Phase 2 lifetime mismatches, not the VPN protocol type.

388
MCQhard

A security engineer is configuring SNMPv3 on network devices. The policy requires both authentication and encryption of SNMP messages. Which combination of protocols should be used to meet this requirement?

A.authPriv with MD5 and DES
B.noAuthNoPriv with no security
C.authNoPriv with SHA and no encryption
D.authPriv with SHA and AES
AnswerD

The authPriv security level is the strongest available in SNMPv3, providing both message authentication and data confidentiality. Using SHA (Secure Hash Algorithm) for authentication ensures message integrity and origin authenticity, preventing unauthorized modification or spoofing of management commands or data. Concurrently, AES (Advanced Encryption Standard) encrypts the entire message payload, protecting sensitive network data from eavesdropping and ensuring privacy, making it the recommended configuration for secure network management.

Why this answer

SNMPv3's authPriv security level requires both authentication and encryption. SHA (or SHA-2) provides message authentication via HMAC, and AES provides symmetric encryption for the message payload. This combination satisfies the policy requirement for both confidentiality and integrity.

Exam trap

The trap here is that candidates see 'authPriv' and assume any combination of authentication and encryption protocols will work, but the CISSP exam expects you to recognize that MD5 and DES are deprecated and insecure, making option A a distractor despite the correct security level.

How to eliminate wrong answers

Option A is wrong because MD5 is deprecated due to known collision vulnerabilities and DES is a weak, 56-bit cipher that is no longer considered secure; while authPriv technically provides both authentication and encryption, the specific protocols violate modern security standards. Option B is wrong because noAuthNoPriv provides no security at all—no authentication and no encryption—which directly contradicts the policy requirement. Option C is wrong because authNoPriv provides authentication (e.g., SHA) but no encryption, so the message payload is sent in cleartext, failing the encryption requirement.

389
MCQeasy

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

A.The total downtime the organization can tolerate
B.The time within which IT systems must be restored
C.The maximum amount of data loss acceptable
D.The time required to repair a failed component
AnswerB

This precisely defines the Recovery Time Objective (RTO). The RTO is a critical metric in business continuity and disaster recovery planning, specifying the maximum acceptable duration for a business process or IT service to be unavailable following an incident before significant business impact occurs. It dictates the target timeframe within which IT infrastructure, applications, and data must be brought back online and fully operational to meet business needs. Achieving the RTO requires careful planning, resource allocation, and robust recovery strategies.

Why this answer

RTO defines the maximum time allowed to restore IT services after a disaster, ensuring the MTD is not exceeded.

390
MCQmedium

A development team is designing a new application and wants to ensure that if a failure occurs, the system remains secure by default. Which design principle should they apply?

A.Least privilege
B.Defense in depth
C.Separation of duties
D.Fail-secure
AnswerD

Fail-secure, also known as fail-safe, is a critical design principle ensuring that if a system component or process fails, the system defaults to a state that denies access or prevents operations, thus maintaining security. For instance, a locked door remains locked if power fails, or an authentication system denies all access if its backend database becomes unavailable. This approach prioritizes security over availability during a failure event, directly addressing how an application should behave to protect data and resources.

Why this answer

Fail-secure is the design principle that dictates a system should default to a secure state when it fails — for example, denying access, locking doors, or dropping connections rather than allowing them. It directly addresses the requirement that 'if a failure occurs, the system remains secure by default.' The other principles address access scope, layered controls, and fraud prevention, not failure behavior.

Exam trap

The trap here is confusing fail-secure (secure on failure) with fail-safe/fail-open (available on failure) — CISSP often swaps these terms to test whether you know the security-vs-availability trade-off.

How to eliminate wrong answers

Option A is wrong because least privilege limits what an authenticated subject can do, but says nothing about what happens when the system itself fails. Option B is wrong because defense in depth is about layering multiple controls so no single failure compromises security — it is a strategy, not the specific failure-mode behavior described. Option C is wrong because separation of duties prevents one person from completing a sensitive transaction alone; it does not define system failure behavior.

391
MCQmedium

A company wants to ensure that only authorized software can run on its laptops. They decide to use a hardware component that validates the boot process by measuring each component before it loads. Which technology is being used?

A.Trusted Platform Module (TPM)
B.Trusted Execution Environment (TEE)
C.Security Kernel
D.Hypervisor
AnswerA

The Trusted Platform Module (TPM) is a secure cryptoprocessor designed to secure hardware by integrating cryptographic keys into devices. It performs a "measured boot" process, where each component loaded during startup (firmware, boot loader, operating system kernel) is cryptographically hashed and the measurements are stored in secure PCRs (Platform Configuration Registers). This allows the system to verify the integrity of the boot path and, through remote attestation, prove to a third party that the system booted with an authorized and untampered software configuration.

Why this answer

A Trusted Platform Module (TPM) is a dedicated hardware chip that performs cryptographic measurements of boot components — firmware, bootloader, and OS — storing hashes in Platform Configuration Registers (PCRs). These measurements enable a measured boot and, combined with secure boot, ensure only authorized, unmodified software loads. The question's emphasis on a hardware component validating the boot process by measuring each component maps directly to TPM's role.

Exam trap

CISSP often tests the distinction between TPM (hardware root of trust that measures the boot process) and TEE (runtime isolated execution environment), since both are described as 'hardware security' but serve different phases.

How to eliminate wrong answers

Option B is wrong because a Trusted Execution Environment (TEE) is an isolated execution area within a processor (e.g., ARM TrustZone, Intel SGX) that protects code and data at runtime — it does not measure and validate the boot chain. Option C is wrong because a security kernel is the minimal, verified core of an operating system that enforces the reference monitor; it is software, not a hardware component that measures boot components. Option D is wrong because a hypervisor creates and manages virtual machines; while it can be part of a trusted boot chain, it does not itself perform the hardware-rooted measurement of each boot component.

392
MCQeasy

During a security audit, an organization discovers that several employees are sharing a single generic account to access a critical database. Which principle of security operations is being violated?

A.Accountability
B.Separation of duties
C.Defense in depth
D.Least privilege
AnswerA

Accountability ensures that all actions performed within an information system can be uniquely traced back to the individual or entity responsible for them. When user accounts are shared, the ability to establish a definitive link between a specific action and a particular person is lost, thereby destroying the audit trail and making it impossible to hold individuals responsible for their activities. This directly undermines non-repudiation and the integrity of security logs, which are critical for incident response and compliance.

Why this answer

Accountability requires that each individual user be uniquely identified and their actions traceable. Sharing a generic account breaks this chain because the audit logs cannot attribute specific database operations (e.g., SELECT, UPDATE, DELETE) to a particular employee, making it impossible to hold anyone responsible for misuse or errors.

Exam trap

The trap here is that candidates confuse the lack of individual accountability with the principle of least privilege, assuming that sharing a generic account automatically means excessive permissions, when the real violation is the inability to uniquely identify and trace user actions.

How to eliminate wrong answers

Option B is wrong because separation of duty involves splitting critical tasks among multiple people to prevent fraud (e.g., requiring two different users to authorize and execute a transaction), which is not directly violated by shared accounts. Option C is wrong because defense in depth is a layered security strategy (e.g., firewalls, IDS, encryption) that remains intact even if a single account is shared; the violation here is about identity and audit, not defense layers. Option D is wrong because least privilege restricts users to the minimum permissions needed for their role; while shared accounts may also have excessive privileges, the core violation in this scenario is the inability to attribute actions to individuals, not the level of access rights.

393
MCQmedium

An organization uses a system where access decisions are based on user attributes (e.g., job title, clearance), resource attributes (e.g., classification), and environmental factors (e.g., time of day). This is an example of:

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerB

Attribute-Based Access Control (ABAC) is the correct answer because it defines access policies based on a combination of attributes associated with the subject (user), object (resource), action, and environment. This model allows for highly granular and dynamic access decisions, evaluating conditions like time of day, location, or resource sensitivity in real-time against defined policies.

Why this answer

Attribute-Based Access Control (ABAC) makes access decisions by evaluating attributes of the user (e.g., job title, clearance), the resource (e.g., classification), and the environment (e.g., time of day). This dynamic, policy-based approach is exactly what the question describes. ABAC is more granular than RBAC and allows for complex, context-aware rules.

Exam trap

CISSP often tests the distinction between ABAC and RBAC; candidates may choose RBAC when the scenario mentions multiple attribute types, but RBAC only uses roles, not environmental or resource attributes.

How to eliminate wrong answers

Option A is wrong because RBAC bases access on roles, not on a combination of user, resource, and environmental attributes. Option C is wrong because MAC uses security labels and clearances assigned by a central authority, but does not typically incorporate environmental factors like time of day. Option D is wrong because DAC allows resource owners to set permissions, which is not attribute-based and lacks centralized policy enforcement.

394
MCQhard

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

A.Annual audit report
B.Business Associate Agreement
C.Patient consent
D.Data Protection Impact Assessment
AnswerB

A Business Associate Agreement (BAA) is a legally required contract under HIPAA that must be in place before a Covered Entity (like a hospital) shares Protected Health Information (PHI) with a Business Associate (like a billing company). This agreement outlines the permissible uses and disclosures of PHI by the Business Associate and mandates their compliance with HIPAA's Security and Privacy Rules, ensuring appropriate safeguards are maintained. It establishes the responsibilities and liabilities of both parties regarding PHI protection.

Why this answer

Under HIPAA, any third party that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a Business Associate, and a Business Associate Agreement (BAA) is legally required before PHI can be shared. The billing company qualifies as a business associate, so a BAA must be in place.

Exam trap

CISSP often tests whether candidates confuse HIPAA's BAA requirement with GDPR's consent or DPIA concepts — the trap is picking 'patient consent' when HIPAA's TPO exception removes that need for billing.

How to eliminate wrong answers

Option A is wrong because an annual audit report is not a HIPAA requirement for sharing PHI with a business associate — audits are a separate compliance activity. Option C is wrong because patient consent is generally not required for treatment, payment, and healthcare operations (TPO), which includes billing; HIPAA permits these disclosures without authorization. Option D is wrong because a Data Protection Impact Assessment is a GDPR concept, not a HIPAA requirement.

395
Multi-Selectmedium

A security manager is choosing a risk response for a high-impact, high-likelihood risk. Which TWO responses are most appropriate? (Select TWO)

Select 2 answers
A.Risk mitigation
B.Risk research
C.Risk avoidance
D.Risk acceptance
E.Risk deferral
AnswersA, C

Risk mitigation involves implementing specific security controls and countermeasures to actively reduce the likelihood of a risk occurring or to lessen its potential impact. For a high-impact risk, this means taking proactive steps, such as strengthening defenses, improving processes, or deploying new technologies, to bring the risk level down to an acceptable threshold. It is a primary and responsible strategy when the activity causing the risk cannot be avoided.

Why this answer

Risk mitigation (A) is correct because for a high-impact, high-likelihood risk the organization should implement controls (e.g., firewalls, encryption, MFA, patching) to reduce the probability and/or impact to an acceptable level. Risk avoidance (C) is also correct because eliminating the activity or asset that generates the risk removes the exposure entirely, which is appropriate when the risk is too severe to tolerate. Risk research (B) is not a standard risk response in the mitigation/avoidance/transference/acceptance taxonomy and does not by itself reduce a high/high risk.

Risk acceptance (D) is inappropriate because accepting a high-impact, high-likelihood risk leaves the organization exposed beyond tolerable levels. Risk deferral (E) is not a valid risk response; postponing action does not reduce the risk and is essentially a form of acceptance.

Exam trap

CISSP often tests the risk response taxonomy, tempting candidates to select 'risk acceptance' or 'risk deferral' for high-severity risks when the correct answers are the proactive responses of mitigation and avoidance.

396
MCQeasy

Under the ISC2 Code of Ethics, which canon has the highest priority?

A.Advance the profession
B.Provide diligent service
C.Act honorably
D.Protect society
AnswerD

The canon to "Protect society, the common good, necessary public trust and confidence, and the infrastructure" is unequivocally the first and highest priority within the (ISC)² Code of Ethics. This principle mandates that all cybersecurity professionals prioritize the safety, welfare, and security of the public above all other considerations. It encompasses safeguarding critical infrastructure, protecting sensitive data, and ensuring the reliability of information systems, establishing a clear ethical imperative that supersedes individual, organizational, or professional interests.

Why this answer

The ISC2 Code of Ethics canons are ordered by priority: Protect society, the common good, necessary public trust and confidence, and the infrastructure; Act honorably, honestly, justly, responsibly, and legally; Provide diligent and competent service to principals; and Advance and protect the profession. Therefore, 'Protect society' is the highest priority canon.

Exam trap

The trap is assuming that canons are equal or that 'Act honorably' is the highest because it sounds ethical; candidates must memorize the specific order, with 'Protect society' first.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the lowest priority canon in the ISC2 Code of Ethics. Option B is wrong because 'Provide diligent service' is the third canon, lower than protecting society. Option C is wrong because 'Act honorably' is the second canon, also lower than protecting society.

397
MCQmedium

In a Privileged Access Management (PAM) solution, which feature provides temporary elevation of privileges for specific tasks, reducing the risk of standing privileges?

A.Password vaulting
B.Just-in-time (JIT) access
C.Break-glass account
D.Session recording
AnswerB

Just-in-time (JIT) access is a critical security feature within a PAM solution that grants elevated privileges only when needed and for a strictly limited duration. This approach minimizes the attack surface by eliminating standing privileges, ensuring that users possess administrative rights solely for the specific task and time required. Once the task is completed or the predefined time expires, the privileges are automatically revoked, significantly reducing the window of opportunity for credential misuse or compromise.

Why this answer

Just-in-time (JIT) access in a PAM solution provides temporary, on-demand elevation of privileges for specific tasks, eliminating standing privileges that attackers can exploit. It typically involves approval workflows, time-bound access, and automatic revocation. This reduces the attack surface and limits lateral movement.

Exam trap

CISSP often tests the difference between password vaulting and JIT access; candidates may confuse vaulting (credential storage) with JIT (temporary elevation), but the question specifically asks for temporary elevation.

How to eliminate wrong answers

Option A is wrong because password vaulting stores and manages privileged credentials but does not inherently provide temporary elevation; it can be part of a PAM solution but does not by itself reduce standing privileges. Option C is wrong because a break-glass account is an emergency account used when normal access is unavailable; it is not for routine temporary elevation and often has standing privileges. Option D is wrong because session recording monitors and records privileged sessions for auditing but does not grant or elevate privileges; it is a detective control, not a preventive one.

398
MCQeasy

An attacker sends a flood of SYN packets to a server, consuming its resources and preventing legitimate connections. Which OSI layer is this attack targeting?

A.Layer 4
B.Layer 2
C.Layer 7
D.Layer 3
AnswerA

A SYN flood specifically targets the Transmission Control Protocol (TCP) at the Transport layer (Layer 4) of the OSI model. This attack exploits the TCP three-way handshake by sending numerous SYN (synchronize) requests without completing the final ACK, leaving the server with many half-open connections. This consumes server resources like memory for connection states and CPU cycles, leading to a denial of service for legitimate users attempting to establish new connections.

Why this answer

A SYN flood attack targets the TCP three-way handshake at the transport layer (Layer 4). By sending a high volume of SYN packets without completing the handshake, the attacker exhausts the server's connection queue, preventing legitimate TCP connections from being established. This directly exploits the stateful nature of TCP, which is a Layer 4 protocol.

Exam trap

The trap here is confusing the network layer (Layer 3) with the transport layer (Layer 4), because IP addresses are involved in routing the packets, but the attack specifically targets TCP's connection management at Layer 4.

How to eliminate wrong answers

Option B is wrong because Layer 2 (Data Link) handles MAC addresses and frame switching, not TCP connection state or port exhaustion. Option C is wrong because Layer 7 (Application) involves protocols like HTTP or DNS, whereas SYN floods operate below the application layer at the transport layer. Option D is wrong because Layer 3 (Network) deals with IP routing and packet forwarding, not the TCP handshake mechanics that SYN floods exploit.

399
Multi-Selecteasy

A network administrator is configuring switches to prevent VLAN hopping attacks. Which TWO of the following measures should be implemented?

Select 2 answers
A.Use private VLANs on all trunk ports.
B.Set the native VLAN to an unused VLAN.
C.Enable BPDU guard on all access ports.
D.Disable Dynamic Trunking Protocol (DTP) on trunk ports.
E.Implement port security on all access ports.
AnswersB, D

Setting the native VLAN on trunk ports to an unused VLAN ID is a crucial defense against double-tagging VLAN hopping attacks. In such an attack, a malicious frame with two VLAN tags (an outer tag matching the native VLAN and an inner tag for the target VLAN) is sent. The first switch strips the outer native VLAN tag, then forwards the frame based on the inner, malicious tag. By ensuring the native VLAN is not used by any user traffic, the inner tag, even if revealed, will attempt to reach a non-existent or unpopulated VLAN, effectively dropping the malicious traffic.

Why this answer

Option B is correct because the native VLAN on 802.1Q trunk ports is untagged, so an attacker can craft double-tagged frames that get forwarded onto the native VLAN; changing the native VLAN to an unused, dedicated VLAN removes that attack path. Option D is correct because DTP allows a switch port to negotiate a trunk automatically, so an attacker can send DTP frames to turn an access port into a trunk and gain access to all VLANs; disabling DTP (for example with 'switchport nonegotiate' on trunk ports) prevents this negotiation. Option A is not appropriate because private VLANs are used for Layer 2 isolation within a VLAN, not as a general trunk-port hardening measure against VLAN hopping.

Option C is not correct because BPDU guard protects against rogue switches sending BPDUs on access ports (STP attacks), not VLAN hopping. Option E is not correct because port security limits MAC addresses on access ports and does not stop VLAN hopping via trunk negotiation or double tagging.

Exam trap

ISC2 often tests the distinction between access port security features (like BPDU guard and port security) and trunk-specific controls (like DTP disablement and native VLAN configuration), leading candidates to mistakenly select access port protections for a trunk-based attack.

400
Multi-Selectmedium

Which TWO of the following are characteristics of a Privileged Access Management (PAM) solution? (Choose two.)

Select 2 answers
A.Self-service password reset
B.Session recording
C.Single sign-on for all users
D.Password vaulting
E.OpenID Connect authentication
AnswersB, D

Session recording is a critical characteristic of Privileged Access Management (PAM) systems, capturing video-like records of all activities performed by privileged users during their elevated sessions. This capability provides an immutable audit trail, enabling forensic analysis, compliance reporting, and real-time monitoring of sensitive operations. By documenting every command and action, organizations can ensure accountability and detect unauthorized or suspicious behavior associated with high-risk accounts.

Why this answer

Option B (Session recording) is correct because PAM solutions commonly record and audit privileged sessions (e.g., via SSH/RDP proxies) to provide accountability and forensic evidence for administrative activity. Option D (Password vaulting) is correct because PAM centrally stores, checks out, and rotates privileged credentials (such as root, admin, and service accounts) in an encrypted vault, which is a core PAM capability. Option A (Self-service password reset) is typically an identity management/helpdesk feature for standard users, not a defining PAM characteristic.

Option C (Single sign-on for all users) is an access-management/SSO capability rather than PAM-specific, since PAM focuses on privileged accounts and sessions. Option E (OpenID Connect authentication) is an authentication protocol/federation mechanism, not a characteristic that defines a PAM solution.

Exam trap

CISSP often tests the confusion between PAM and IAM features — candidates may select SSO or self-service reset, which are IAM capabilities, rather than PAM-specific functions like session recording and vaulting.

401
MCQeasy

An organization wants to identify vulnerabilities in their network without attempting to exploit them. Which type of security assessment should they perform?

A.Vulnerability assessment
B.Penetration test
C.Security audit
D.Security review
AnswerA

A vulnerability assessment systematically scans systems, networks, and applications to identify security weaknesses and misconfigurations. It uses automated tools and manual checks to detect known vulnerabilities, providing a prioritized list of potential risks without actively attempting to compromise the system. The goal is to inform remediation efforts by cataloging exposures and potential attack vectors, aligning precisely with the organization's desire to identify vulnerabilities without exploitation.

Why this answer

A vulnerability assessment is the correct choice because it is a systematic review of security weaknesses in a network or system that identifies vulnerabilities without actively exploiting them. This assessment typically uses automated scanning tools (e.g., Nessus, OpenVAS) to compare system configurations against known vulnerability databases (e.g., CVE, NVD) and reports potential issues, but does not attempt to gain unauthorized access or cause disruption.

Exam trap

The trap here is that candidates confuse a vulnerability assessment with a penetration test, assuming both involve exploitation, but the key differentiator is that a vulnerability assessment only identifies vulnerabilities, while a penetration test actively exploits them.

How to eliminate wrong answers

Option B is wrong because a penetration test (pentest) is an authorized simulated attack that actively attempts to exploit identified vulnerabilities to gain access or escalate privileges, which contradicts the requirement to not exploit them. Option C is wrong because a security audit is a formal, compliance-driven evaluation of an organization's adherence to policies, standards, or regulations (e.g., ISO 27001, PCI DSS) and does not focus specifically on identifying technical vulnerabilities in the network. Option D is wrong because a security review is a broad, often high-level examination of security controls, processes, or architecture, and it lacks the targeted, technical scanning and identification of specific vulnerabilities that a vulnerability assessment provides.

402
MCQeasy

Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?

A.MTTR
B.RPO
C.RTO
D.MTD
AnswerB

RPO, or Recovery Point Objective, precisely defines the maximum acceptable amount of data loss, measured in time, that an organization can tolerate following a disruptive event. It dictates the age of files or data that must be recovered from backup storage for normal operations to resume. Establishing the RPO is critical for determining backup frequency and data replication strategies to ensure business continuity.

Why this answer

RPO (Recovery Point Objective) defines the maximum tolerable amount of data loss measured in time. It represents the point in time to which data must be recovered after a disruption, effectively setting the maximum age of the most recent backup that can be restored. For example, an RPO of 4 hours means the organization can tolerate losing up to 4 hours of data, so backups must occur at least every 4 hours.

Exam trap

CISSP often tests the distinction between RPO and RTO, as candidates frequently confuse data loss (RPO) with downtime (RTO).

How to eliminate wrong answers

Option A is wrong because MTTR (Mean Time To Repair) measures the average time required to repair a failed component or system, not data loss tolerance. Option C is wrong because RTO (Recovery Time Objective) defines the maximum acceptable downtime after a disaster, not the amount of data loss. Option D is wrong because MTD (Maximum Tolerable Downtime) is the total time a business process can be unavailable before causing unacceptable consequences, which encompasses both RTO and other recovery activities, but does not directly measure data loss.

403
MCQmedium

A security administrator is configuring SNMPv3 for network device monitoring. The requirement is to provide both authentication and encryption of SNMP traffic. Which combination of options should be used?

A.AuthNoPriv
B.AuthPriv with MD5 and DES
C.AuthPriv with SHA and AES
D.NoAuthNoPriv
AnswerC

The AuthPriv security level, combined with SHA for authentication and AES for privacy, represents the strongest and most recommended configuration for SNMPv3. SHA (Secure Hash Algorithm, typically SHA-256 or higher) provides robust message integrity and origin authentication, effectively preventing tampering and spoofing. Concurrently, AES (Advanced Encryption Standard) offers strong symmetric encryption, ensuring the confidentiality of sensitive network management data. This combination aligns with best practices for securing network communications, mitigating risks from eavesdropping, data modification, and unauthorized access.

Why this answer

SNMPv3 defines three security levels: NoAuthNoPriv, AuthNoPriv, and AuthPriv. The requirement for both authentication and encryption corresponds to the AuthPriv level. The recommended modern cryptographic algorithms for AuthPriv are SHA (for authentication) and AES (for encryption), as specified in RFC 3826 and RFC 3414.

Option C correctly pairs SHA and AES to meet the requirement.

Exam trap

The trap here is that candidates may choose AuthPriv with MD5 and DES (Option B) because it technically provides both authentication and encryption, but they overlook that MD5 and DES are deprecated and insecure, making them unacceptable in a modern security context.

How to eliminate wrong answers

Option A (AuthNoPriv) is wrong because it provides authentication but no encryption, failing the encryption requirement. Option B (AuthPriv with MD5 and DES) is wrong because MD5 and DES are deprecated and considered cryptographically weak; DES uses a 56-bit key and is easily broken, while MD5 is vulnerable to collision attacks. Option D (NoAuthNoPriv) is wrong because it provides neither authentication nor encryption, failing both requirements.

404
Multi-Selecthard

An organization is implementing a Privileged Access Management (PAM) solution. Which THREE of the following are common features of PAM? (Select THREE.)

Select 3 answers
A.Single sign-on
B.Password vaulting
C.Session recording
D.Just-in-time access
E.Role-based access control
AnswersB, C, D

Password vaulting is a fundamental PAM capability that centralizes the secure storage of privileged account credentials, such as administrator passwords and SSH keys, in an encrypted and isolated repository. It enforces strong password policies, automates credential rotation at defined intervals, and manages the secure retrieval and injection of these credentials into target systems, eliminating direct user knowledge of the actual passwords. This significantly reduces the risk of credential theft and misuse.

Why this answer

Password vaulting (B) is a core PAM capability because it stores privileged credentials in an encrypted repository and checks them out to authorized users, removing the need to expose or memorize administrative passwords. Session recording (C) is also a standard PAM feature, as it captures privileged sessions (often via RDP, SSH, or database proxies) for auditing, forensics, and compliance evidence. Just-in-time access (D) is a hallmark of modern PAM because it grants elevated privileges only for a limited time and revokes them automatically, reducing standing administrative rights and the attack surface.

Single sign-on (A) and role-based access control (E) are identity and access management concepts that may integrate with PAM, but they are not defining PAM features in the same way as vaulting, session recording, and just-in-time elevation.

Exam trap

CISSP often tests whether candidates can distinguish PAM-specific features (vaulting, session recording, JIT) from general IAM features (SSO, RBAC) that are commonly present but not unique to PAM.

405
MCQhard

An organization implements a data loss prevention (DLP) solution to monitor data in motion. Which type of data is typically most challenging to detect?

A.Data in images
B.Structured data in CSV files
C.Encrypted traffic
D.Unstructured data in email attachments
AnswerC

Encrypted network traffic poses the most significant challenge for Data Loss Prevention solutions because the content payload is intentionally obscured, preventing direct inspection. To analyze sensitive information within encrypted streams, DLP typically requires a man-in-the-middle (MITM) proxy to decrypt, inspect, and then re-encrypt the traffic, which introduces complexity, performance overhead, and potential privacy concerns, making it difficult to achieve full content visibility without explicit interception.

Why this answer

Encrypted traffic is the most challenging data in motion for DLP to inspect because the payload is obfuscated by encryption protocols such as TLS 1.3 or IPsec. Without decryption (e.g., via a proxy with TLS interception), the DLP sensor cannot read the content to match patterns or keywords, rendering traditional deep packet inspection ineffective.

Exam trap

The trap here is that candidates assume 'data in images' is hardest because it is non-textual, but DLP can use OCR and image analysis, whereas encrypted traffic is fundamentally opaque without decryption keys.

How to eliminate wrong answers

Option A is wrong because data in images can be detected via optical character recognition (OCR) or steganography analysis, though it is harder than plaintext, it is still inspectable. Option B is wrong because structured data in CSV files has predictable delimiters and patterns (e.g., credit card numbers, SSNs) that DLP regex rules can reliably match. Option D is wrong because unstructured data in email attachments, while varied, is still in plaintext or common binary formats (e.g., PDF, DOCX) that DLP can parse and scan for sensitive content.

406
Multi-Selecthard

Which THREE of the following are valid countermeasures against buffer overflow attacks?

Select 3 answers
A.Stack canaries
B.Full disk encryption
C.Address space layout randomization (ASLR)
D.Non-executable stack and heap (NX bit)
E.Input validation using allowlists
AnswersA, C, D

Stack canaries are a security mechanism that places a small, random value, known as a canary, on the stack between the buffer and critical control data, such as the return address. Before a function returns, the program checks if this canary value has been modified. If the canary has been overwritten, it indicates a buffer overflow has occurred, and the program can then terminate safely to prevent malicious code execution.

Why this answer

Stack canaries are correct because they place a known value (canary) between the buffer and control data on the stack. Before a function returns, the canary is checked; if it has been overwritten (indicating a buffer overflow), the program terminates, preventing code execution. This directly detects stack-based buffer overflows before they can hijack the return address.

Exam trap

The trap here is that candidates often confuse general security controls (like input validation or encryption) with specific memory protection mechanisms, leading them to select options that are good practices but not direct countermeasures against buffer overflow attacks.

407
MCQhard

During a security audit of a financial application, the auditor discovers that the application uses a custom encryption algorithm for storing sensitive data. The developer claims it is more efficient than AES. What should the auditor recommend?

A.Conduct additional penetration testing on the encryption implementation
B.Accept the risk if the algorithm is more efficient
C.Perform a cryptoanalysis of the algorithm to validate its strength
D.Migrate to a widely-accepted encryption standard such as AES
AnswerD

Migrating to a widely-accepted encryption standard like AES is the most secure and responsible approach because these algorithms have undergone decades of extensive, global peer review by expert cryptographers. This rigorous scrutiny ensures that known vulnerabilities are identified and addressed, providing a high level of confidence in their mathematical strength and resilience against various attack vectors. Such standards are battle-tested and trusted, offering a robust foundation for protecting sensitive financial data, which is critical for financial applications.

Why this answer

Custom encryption algorithms are highly risky because they have not undergone the extensive peer review and cryptanalysis that standards like AES have. Even if the developer claims better efficiency, the lack of proven security guarantees makes the application vulnerable to attacks. The correct recommendation is to migrate to a widely-accepted standard such as AES, which is FIPS 197 validated and trusted for protecting sensitive financial data.

Exam trap

The trap here is that candidates may think performing cryptanalysis (Option C) is a valid audit recommendation, but in practice, the auditor's role is to enforce the use of proven standards, not to validate unproven custom cryptography.

How to eliminate wrong answers

Option A is wrong because additional penetration testing on a custom encryption implementation cannot uncover fundamental cryptographic weaknesses; penetration testing is not a substitute for formal cryptanalysis or algorithm validation. Option B is wrong because accepting the risk based solely on efficiency claims violates the principle of using proven, standardized cryptography for sensitive data; efficiency does not equate to security. Option C is wrong because performing a cryptanalysis of the custom algorithm is not a practical recommendation for an auditor; it requires expert cryptographers and extensive time, and even then, the algorithm may still have undiscovered flaws, whereas migrating to a proven standard is the immediate and correct security control.

408
MCQeasy

In the context of physical security, which of the following is an example of a preventive control?

A.Security guards monitoring
B.CCTV cameras
C.Intrusion detection system
D.Mantrap door
AnswerD

A mantrap door physically constrains entry, allowing only one person through an interlocking chamber at a time. It stops unauthorised tailgating before access occurs, satisfying the stem's requirement for a preventive control rather than a detective or corrective one.

Why this answer

A mantrap door is a preventive physical security control because it actively prevents unauthorized entry by requiring authentication and verification before allowing passage through a series of interlocking doors. Unlike monitoring or detection systems, a mantrap physically blocks access until the user is validated, thereby stopping a breach before it occurs.

Exam trap

The trap here is confusing preventive controls (which stop an incident) with detective controls (which identify an incident after it occurs), leading candidates to incorrectly select CCTV or IDS as preventive measures.

How to eliminate wrong answers

Option A is wrong because security guards monitoring is a detective and deterrent control, not preventive; they observe and report incidents but do not physically block access. Option B is wrong because CCTV cameras are a detective control that records events for after-the-fact review, they do not prevent an intrusion from happening. Option C is wrong because an intrusion detection system (IDS) is a detective control that alerts on suspicious activity but does not actively block or prevent the intrusion.

409
MCQeasy

Which of the following is an example of a social engineering attack?

A.A brute-force attack on a password
B.SQL injection on a web application
C.A DDoS attack on a server
D.A phishing email requesting credentials
AnswerD

A phishing email requesting credentials is a classic example of social engineering, where an attacker attempts to trick an individual into divulging sensitive information, such as usernames and passwords. These emails often impersonate trusted entities, creating a sense of urgency or fear to manipulate the recipient into clicking a malicious link or entering credentials on a fake website. The success of phishing relies entirely on human psychological manipulation and deception, rather than exploiting technical vulnerabilities directly.

Why this answer

Phishing is a social engineering attack that manipulates human psychology to trick users into revealing credentials or clicking malicious links. It relies on deception and trust rather than technical exploitation, which is the defining characteristic of social engineering.

Exam trap

CISSP often tests whether candidates can distinguish social engineering from technical attacks — the trap is selecting a technically sophisticated attack like SQL injection or brute force because it sounds more 'advanced', missing that social engineering is defined by human manipulation.

How to eliminate wrong answers

Option A is wrong because a brute-force attack is a technical attack that systematically tries password combinations; it does not involve human manipulation. Option B is wrong because SQL injection is a code injection attack that exploits vulnerable input validation in web applications, not human behavior. Option C is wrong because a DDoS attack floods a target with traffic to exhaust resources; it is a network-based availability attack, not social engineering.

410
MCQhard

Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?

A.CVSS base score
B.Exploitability and business impact
C.Number of systems affected
D.Time since discovery
AnswerB

Exploitability and business impact are paramount because they directly align with the fundamental principles of risk management, where risk equals likelihood multiplied by impact. Exploitability assesses the probability of a threat actor successfully leveraging a vulnerability, while business impact quantifies the potential damage or disruption to critical assets and operations. Prioritizing based on these factors ensures that remediation efforts focus on vulnerabilities that pose the greatest actual risk to the organization's mission and assets.

Why this answer

Prioritizing vulnerability remediation should be driven by exploitability (is there a known exploit, is it weaponized, is it reachable) combined with business impact (what asset is affected, what data or process is at risk). This risk-based approach ensures limited remediation resources are directed at the vulnerabilities that pose the greatest actual threat to the organization. CVSS alone does not capture business context.

Exam trap

CISSP often tests the misconception that CVSS base score alone should drive prioritization, when the correct answer requires combining exploitability with business impact.

How to eliminate wrong answers

Option A is wrong because CVSS base score measures intrinsic technical severity but ignores whether the vulnerability is exploitable in your environment, whether compensating controls exist, and what business asset is affected. Option C is wrong because the number of systems affected is a factor but not the most important one; a single critical system with sensitive data may outweigh many low-impact systems. Option D is wrong because time since discovery is a useful tiebreaker but does not reflect exploitability or business impact, and an old vulnerability with no exploit path may be lower priority than a new, actively exploited one.

411
MCQmedium

A security analyst receives an alert that a host in the internal network is sending abnormal amounts of traffic to an external IP. The traffic uses destination port 53. What is the most likely attack?

A.DNS cache poisoning
B.DNS amplification
C.DNS tunneling
D.DNS zone transfer
AnswerC

DNS tunneling is a sophisticated exfiltration technique that encapsulates non-DNS traffic, such as command-and-control communications or stolen data, within legitimate-looking DNS queries and responses. A compromised host encodes data into subdomain names or TXT records of DNS requests, sending them to an attacker-controlled authoritative DNS server. This continuous stream of data-laden DNS queries results in abnormally high volumes of outgoing DNS traffic from the host, precisely matching the alert description.

Why this answer

The alert describes a host sending abnormal traffic to an external IP on destination port 53, which is the default port for DNS. DNS tunneling exploits the DNS protocol to encapsulate non-DNS data (e.g., commands or exfiltrated files) within DNS queries and responses, allowing covert communication through firewalls that typically allow DNS traffic. The abnormal volume of traffic to a single external IP is a classic indicator of a DNS tunnel, as the compromised host continuously sends encoded data to an external command-and-control server.

Exam trap

The trap here is that candidates confuse the use of port 53 with DNS amplification attacks, but amplification requires a victim IP and open resolvers, not a single internal host sending traffic to an external IP.

How to eliminate wrong answers

Option A is wrong because DNS cache poisoning (also known as DNS spoofing) involves injecting forged DNS records into a resolver's cache to redirect traffic, not generating abnormal outbound traffic from a single host. Option B is wrong because DNS amplification is a distributed denial-of-service (DDoS) attack that uses open resolvers to flood a victim with large responses, but the alert describes a single internal host sending traffic outbound, not a reflector sending amplified traffic to a victim. Option D is wrong because a DNS zone transfer is a legitimate mechanism for replicating DNS zone data between authoritative servers, typically using TCP port 53, and is not an attack that causes a single host to send abnormal traffic to an external IP.

412
MCQhard

A financial services firm recently deployed a multi-factor authentication (MFA) solution for remote access to its trading platform. The MFA requires a one-time password (OTP) via a mobile app, in addition to a username and password. Since deployment, remote traders have complained that the authentication process takes too long, especially during market open hours. The help desk reports that many traders are accidentally locking their accounts due to multiple failed OTP attempts. The security team wants to maintain strong security but improve user experience. Which action should the security team take?

A.Reduce MFA to two factors by removing the OTP requirement
B.Remove MFA requirements during peak hours to improve performance
C.Implement risk-based adaptive MFA that prompts only when anomalous activity is detected
D.Extend the OTP validity window to 10 minutes to reduce time pressure
AnswerC

Implementing risk-based adaptive MFA intelligently balances robust security with user convenience by dynamically assessing contextual factors such as location, device, IP address, and behavioral patterns. This system only triggers additional authentication challenges, like an OTP, when an anomaly or elevated risk is detected, such as a login from an unfamiliar location. This approach maintains strong security controls against sophisticated threats while minimizing user friction during routine, low-risk access attempts.

Why this answer

Risk-based adaptive MFA evaluates the context of each authentication request (e.g., location, device, time, behavior) and only triggers an OTP challenge when the risk score exceeds a threshold. This reduces friction for legitimate traders during peak hours while maintaining strong security against anomalous access attempts, directly addressing the complaint of slow authentication without weakening the overall security posture.

Exam trap

The trap here is that candidates may assume extending the OTP validity window (Option D) is a harmless usability fix, but CISSP tests the understanding that longer OTP windows increase the risk of replay attacks and violate the principle of short-lived credentials, whereas adaptive authentication is the correct balance of security and usability.

How to eliminate wrong answers

Option A is wrong because reducing MFA to two factors by removing the OTP requirement would weaken authentication to only username/password, violating the principle of defense-in-depth and exposing the trading platform to credential theft. Option B is wrong because removing MFA during peak hours creates a predictable window of vulnerability that attackers could exploit, directly contradicting the security team's goal to maintain strong security. Option D is wrong because extending the OTP validity window to 10 minutes increases the window of opportunity for replay attacks (e.g., if an OTP is intercepted or leaked) and does not address the root cause of user frustration—the frequency of unnecessary OTP prompts—while also violating NIST SP 800-63B recommendations for short-lived OTPs.

413
MCQhard

You are the security architect for a multinational corporation that handles highly sensitive intellectual property (IP) and personally identifiable information (PII) for clients in multiple jurisdictions, including GDPR and CCPA regions. The company recently experienced a data breach where an attacker exfiltrated 50 GB of data from a file server by exploiting a vulnerability in the backup software. The backup software had been configured with default credentials and was accessible from the internet. The security team has implemented compensating controls, but management wants to prevent such incidents in the future. You have been asked to recommend a long-term strategy to protect sensitive data assets. The budget is limited, and the solution must minimize user friction. Current environment: On-premises Active Directory with Windows file servers, some data in AWS S3, and a mix of laptops and mobile devices. The organization uses Microsoft 365 for email and collaboration. Which of the following is the BEST course of action?

A.Deploy a data classification and labeling solution integrated with endpoint and network DLP to automatically detect and protect sensitive data
B.Implement multi-factor authentication (MFA) for all administrative accounts and backup interfaces
C.Encrypt all data at rest using AES-256 and implement strict key management policies
D.Segment the backup network from the production network and enforce strict firewall rules
AnswerA

This solution directly tackles data protection by identifying sensitive information through classification and applying automated controls via Data Loss Prevention (DLP). Integrating these systems ensures continuous monitoring and enforcement of policies across endpoints, network traffic, and cloud services. This proactive, data-centric approach significantly reduces the risk of unauthorized data exfiltration, regardless of the vector or insider threat, making it the most comprehensive strategy for a multinational corporation.

Why this answer

Data classification and labeling, integrated with endpoint and network DLP, directly addresses the root cause: the inability to distinguish sensitive data from non-sensitive data. By automatically classifying and labeling IP and PII, the organization can enforce policy-based protections (e.g., blocking exfiltration, applying encryption) without relying solely on perimeter controls. This minimizes user friction by automating detection and response, and it scales across on-premises, cloud (AWS S3), and Microsoft 365 environments, aligning with GDPR and CCPA requirements for data protection.

Exam trap

The trap here is that candidates often choose MFA or encryption as a silver bullet, but the CISSP exam emphasizes that data classification is the foundational control for protecting sensitive assets, especially when the threat involves data exfiltration via a compromised application, not just unauthorized access or theft of media.

How to eliminate wrong answers

Option B is wrong because MFA for administrative accounts and backup interfaces is a compensating control that reduces the risk of credential theft, but it does not prevent an attacker who exploits a software vulnerability (as in the breach) from exfiltrating data; the backup software was accessible from the internet with default credentials, but MFA would not have stopped the vulnerability exploitation if the attacker bypassed authentication or used a different vector. Option C is wrong because encrypting all data at rest with AES-256 protects data if storage media is stolen, but it does not prevent exfiltration via a live file server or backup software; the attacker exfiltrated data while the server was online and decrypted, so encryption at rest is irrelevant to the attack vector. Option D is wrong because network segmentation and firewall rules reduce the attack surface but do not address the core issue of sensitive data being accessible and unlabeled; the attacker exploited a vulnerability in backup software, and segmentation alone cannot prevent exfiltration if the attacker already has access to the backup network or if the vulnerability allows lateral movement.

414
Multi-Selectmedium

Which TWO protocols are commonly used for identity federation?

Select 2 answers
A.LDAP
B.OAuth 2.0
C.OpenID Connect
D.RADIUS
E.SAML 2.0
AnswersC, E

OpenID Connect (OIDC) is an identity layer built on top of the OAuth 2.0 framework, specifically designed for federated authentication. It allows clients to verify the identity of the end-user based on the authentication performed by an authorization server and to obtain basic profile information about the end-user in an interoperable REST-like manner. OIDC issues ID Tokens, which are JSON Web Tokens (JWTs) containing verifiable claims about the authenticated user, facilitating single sign-on across multiple services.

Why this answer

OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0 that enables clients to verify the identity of an end-user based on the authentication performed by an authorization server. It provides a standardized way to obtain identity claims via an ID token (JWT) and is widely used for federated identity scenarios, such as single sign-on (SSO) across domains. SAML 2.0 is an XML-based protocol for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP), making it a cornerstone of enterprise identity federation.

Exam trap

The trap here is that candidates often confuse OAuth 2.0 with OpenID Connect, mistakenly selecting OAuth 2.0 as a federation protocol when it is solely an authorization framework, not an identity protocol—OpenID Connect is the correct identity layer built on top of it.

415
MCQeasy

Which type of risk remains after management has implemented controls to mitigate the identified risks?

A.Acceptable risk
B.Control risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is the specific level of risk that persists within an organization or system even after all planned and implemented risk mitigation strategies, controls, and countermeasures have been applied. It represents the remaining exposure that management has either consciously accepted or has been unable to further reduce through cost-effective means. This is the risk an organization must live with, requiring continuous monitoring and potential future reassessment.

Why this answer

Residual risk is the risk that remains after controls have been implemented to mitigate the identified risks. It is the difference between inherent risk (risk before controls) and the effect of the controls. Management must decide whether the residual risk is within the organization's risk appetite or requires further treatment.

Exam trap

CISSP often tests the distinction between inherent, control, and residual risk — the trap is confusing 'acceptable risk' (a management decision) with 'residual risk' (the actual remaining exposure after controls).

How to eliminate wrong answers

Option A is wrong because 'acceptable risk' is a judgment that the residual risk is tolerable, not the term for the remaining risk itself. Option B is wrong because 'control risk' refers to the risk that a control fails to prevent or detect a material error, not the leftover risk after controls. Option D is wrong because 'inherent risk' is the risk level before any controls are applied, which is the opposite of what the question asks.

416
MCQmedium

An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?

A.Reciprocal agreement
B.Warm site
C.Cold site
D.Hot site
AnswerD

A hot site is a fully operational, mirror image of the primary data center, equipped with all necessary hardware, software, and up-to-date data. It maintains real-time or near real-time synchronization with the production environment, allowing for immediate failover and seamless business continuity with minimal disruption. This immediate availability and readiness directly address stringent recovery time objectives (RTOs) that demand near-instantaneous resumption of critical operations following a disaster.

Why this answer

A hot site is fully configured with hardware, software, and real-time data replication, enabling the critical financial application to be operational within minutes to a few hours. With an RTO of 4 hours, a hot site provides the necessary infrastructure and up-to-date data to meet this stringent recovery timeline, as cold and warm sites require significant setup and data restoration time.

Exam trap

The trap here is that candidates often confuse a warm site with a hot site, assuming pre-installed hardware is sufficient, but they overlook the critical need for current data replication to meet a tight RTO like 4 hours.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement relies on another organization's spare capacity, which is not guaranteed to be available or compatible within 4 hours, and typically involves manual setup and data restoration. Option B is wrong because a warm site has pre-installed hardware and software but lacks current data, requiring time to restore from backups, which often exceeds a 4-hour RTO for critical applications. Option C is wrong because a cold site provides only physical space and basic utilities, requiring days or weeks to procure, install, and configure hardware and software, making it impossible to meet a 4-hour RTO.

417
MCQhard

An organization is implementing DNSSEC to protect its DNS infrastructure. Which of the following best describes the primary security benefit of DNSSEC?

A.Authentication of DNS data origin and integrity
B.Prevention of DDoS attacks on DNS servers
C.Anonymization of DNS queries
D.Encryption of DNS queries and responses
AnswerA

DNSSEC primarily establishes cryptographic trust in DNS data by using digital signatures to verify the origin of resource records and ensure their integrity. This process involves a chain of trust from the root zone down to individual domains, where DNSKEY and RRSIG records authenticate that the data originated from the legitimate zone owner and has not been altered during transit. This protection guards against cache poisoning and other forms of DNS data manipulation.

Why this answer

DNSSEC (Domain Name System Security Extensions) provides origin authentication and data integrity verification for DNS responses through digital signatures. It uses public-key cryptography to sign DNS resource record sets (RRSIG records), allowing resolvers to verify that the data has not been modified in transit and originates from the authoritative source. This prevents attacks such as DNS cache poisoning and man-in-the-middle spoofing, but does not provide confidentiality or availability protections.

Exam trap

The trap here is that candidates confuse DNSSEC's authentication and integrity features with encryption or anonymity, mistakenly thinking it secures DNS by hiding data, when in fact it only signs data and leaves it readable.

How to eliminate wrong answers

Option B is wrong because DNSSEC does not prevent DDoS attacks; in fact, it can increase the attack surface by enabling amplification attacks due to larger response sizes (e.g., DNSSEC-signed responses). Option C is wrong because DNSSEC does not anonymize queries; it explicitly adds signatures and keys that can be used to identify the source, and query privacy is addressed by protocols like DNS over TLS (DoT) or DNS over HTTPS (DoH). Option D is wrong because DNSSEC does not encrypt queries or responses; it only signs data for integrity and authentication, leaving the payload in cleartext.

418
MCQhard

During an audit, it is discovered that a database containing personally identifiable information (PII) has been retained for 10 years beyond the regulatory requirement. The data owner has not approved the retention extension. Which data lifecycle principle is primarily being violated?

A.Storage limitation
B.Data minimization
C.Purpose limitation
D.Integrity
AnswerA

Storage limitation mandates that personal data must not be kept for longer than is necessary for the purposes for which it was collected or processed. An audit discovering a database retaining data beyond its defined retention period directly indicates a violation of this principle, necessitating the secure deletion or anonymization of such data. This principle is crucial for minimizing the risk associated with data breaches and ensuring compliance with privacy regulations.

Why this answer

Storage limitation requires that PII be kept only as long as necessary for the stated purpose or as required by regulation, and then securely deleted. Retaining data 10 years beyond the regulatory requirement, without the data owner's approval for an extension, directly violates this principle. The other principles address collection scope, purpose of use, and accuracy/consistency — not retention duration.

Exam trap

CISSP often tests the distinction between storage limitation (how long you keep data) and data minimization (how much you collect) — candidates conflate the two because both sound like 'less data' principles.

How to eliminate wrong answers

Option B is wrong because data minimization concerns collecting only the minimum data necessary for the purpose, not how long data is retained. Option C is wrong because purpose limitation restricts using data only for the purpose it was collected for — it does not govern retention duration. Option D is wrong because integrity refers to ensuring data is accurate, complete, and protected from unauthorized modification, which is unrelated to over-retention.

419
MCQmedium

Under GDPR, a company processes personal data on behalf of a data controller. Which role does the company fulfill?

A.Data custodian
B.Data controller
C.Data processor
D.Data subject
AnswerC

Under GDPR, a data processor is an entity that processes personal data strictly on behalf of, and according to the documented instructions of, a data controller. This relationship is typically formalized through a data processing agreement (DPA), which outlines the scope, nature, and purpose of processing. The processor does not determine the purposes or means of processing independently but acts as a service provider executing tasks delegated by the controller.

Why this answer

Under GDPR Article 4(8), a processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. Since the company is processing data on behalf of the controller, it is the data processor.

Exam trap

CISSP often tests the controller/processor distinction by using the phrase 'on behalf of,' which is the GDPR trigger for processor status — candidates who focus on who 'owns' the data rather than who 'determines the purpose' pick controller incorrectly.

How to eliminate wrong answers

Option A is wrong because 'data custodian' is not a GDPR-defined role; it is a data-governance term (often from ITIL/COBIT) describing someone who implements the controller's instructions technically, and it carries no GDPR legal obligations. Option B is wrong because the data controller determines the purposes and means of processing — here the company is acting on the controller's behalf, not deciding why and how data is processed. Option D is wrong because the data subject is the identifiable individual whose personal data is processed, not the organization doing the processing.

420
MCQmedium

In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?

A.Low
B.Medium
C.High
D.Critical
AnswerC

A risk score of 20, calculated as the product of a high likelihood (e.g., 4 on a 5-point scale) and a very high impact (e.g., 5 on a 5-point scale), correctly places the risk in the "High" category. In a qualitative risk matrix, the "High" range typically encompasses scores from approximately 15 to 25, signifying a significant probability of occurrence combined with substantial potential negative consequences that demand immediate attention and mitigation strategies.

Why this answer

In qualitative risk analysis, the risk score is calculated by multiplying likelihood by impact. Here, likelihood = 4 and impact = 5, so the risk score = 4 × 5 = 20. The risk matrix defines scores of 15–25 as high, so a score of 20 falls into the high category.

Therefore, the risk rating is High.

Exam trap

CISSP often tests the basic calculation of risk score (likelihood × impact) and mapping to the correct qualitative rating, but candidates may mistakenly assume a higher category like 'Critical' exists or miscalculate the multiplication.

How to eliminate wrong answers

Option A is wrong because a score of 20 is not low; low would typically be a score below the medium threshold (e.g., 1–6). Option B is wrong because medium would cover scores between low and high (e.g., 7–14), and 20 exceeds that range. Option D is wrong because 'Critical' is not defined in the given risk matrix; the highest defined category is 'High' for scores 15–25, so assigning 'Critical' introduces an undefined rating.

421
Multi-Selectmedium

Which THREE of the following are control families defined in NIST SP 800-53? (Choose three.)

Select 3 answers
A.Access Control (AC)
B.System and Communications Protection (SC)
C.Data Encryption (DE)
D.Business Continuity (BC)
E.Identification and Authentication (IA)
AnswersA, B, E

Access Control (AC) is a foundational control family within NIST SP 800-53, focusing on limiting information system access to authorized users, processes, or devices. This family establishes the policies and procedures for granting, revoking, and reviewing permissions based on roles and responsibilities. It ensures that only entities with appropriate clearances and need-to-know can interact with sensitive data and system resources.

Why this answer

Access Control (AC) is a control family in NIST SP 800-53 that encompasses policies, procedures, and mechanisms for managing user permissions, authentication, and authorization. It includes controls like AC-2 (Account Management) and AC-3 (Access Enforcement), which are fundamental to enforcing least privilege and separation of duties.

Exam trap

The trap here is that candidates may confuse common security domains (like encryption or business continuity) with the specific control family names used in NIST SP 800-53, leading them to select plausible-sounding but non-existent families like Data Encryption or Business Continuity.

422
Multi-Selecteasy

Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?

Select 2 answers
A.Mean time to remediate critical vulnerabilities
B.Number of servers in the data center
C.Total IT budget
D.Patch compliance percentage
E.Number of employees in the security department
AnswersA, D

Mean time to remediate critical vulnerabilities is a crucial operational security metric, directly indicating the efficiency and effectiveness of an organization's vulnerability management program. It quantifies the average duration from the discovery of a critical vulnerability to its complete resolution, reflecting the organization's ability to mitigate high-risk threats promptly and reduce its attack surface. A lower mean time signifies a more robust and responsive security posture, directly impacting risk reduction.

Why this answer

Option A (Mean time to remediate critical vulnerabilities) is correct because it is a quantifiable security metric that measures how quickly the organization responds to and fixes critical vulnerabilities, directly reflecting the effectiveness of its vulnerability management process and serving as a meaningful KPI for security operations. Option D (Patch compliance percentage) is correct because it measures the proportion of systems that have required patches applied within policy timeframes, providing a measurable indicator of the organization's exposure to known exploits and the health of its patch management program. In contrast, option B (Number of servers in the data center) is an inventory or capacity figure that does not measure security performance or risk reduction.

Option C (Total IT budget) is a financial metric reflecting spending, not security effectiveness. Option E (Number of employees in the security department) is a staffing or headcount measure that indicates resource allocation but does not itself quantify security posture or outcomes.

Exam trap

CISSP often tests the difference between security metrics and general IT or business metrics, so candidates may mistakenly select operational counts like number of servers or budget as KPIs.

423
MCQmedium

During a security assessment, it is found that service accounts have interactive logon rights. What is the BEST remediation?

A.Implement Group Policy to deny interactive logon for service accounts.
B.Ensure service accounts use strong passwords.
C.Use managed service accounts instead.
D.Remove service accounts from the local Administrators group.
AnswerC

Managed Service Accounts (MSAs) and Group Managed Service Accounts (gMSAs) are purpose-built to enhance the security posture of services by design. They inherently lack the capability for interactive logon, effectively preventing their misuse by attackers attempting to gain a desktop session on a server. Furthermore, MSAs automate complex password generation and periodic rotation, significantly reducing administrative overhead and eliminating the risk of stale or weak passwords.

Why this answer

Managed Service Accounts (MSAs) are the best remediation because they are designed specifically for service accounts, automatically manage password changes, and by default have no interactive logon rights. This eliminates the security risk of interactive logon while also addressing password management and reducing administrative overhead. Group Policy changes or manual password policies do not address the underlying architectural issue of using a standard user account for a service.

Exam trap

The trap here is that candidates often choose a Group Policy or password-strength solution because they focus on mitigating the symptom (interactive logon) rather than selecting the architectural fix (MSAs) that eliminates the root cause and aligns with the principle of least privilege and secure design.

How to eliminate wrong answers

Option A is wrong because implementing Group Policy to deny interactive logon for service accounts is a workaround that does not address the root cause; it can be bypassed or misconfigured, and it still leaves the account with other unnecessary privileges and manual password management. Option B is wrong because ensuring strong passwords only mitigates the risk of credential theft but does not prevent interactive logon, which is the primary vulnerability; service accounts should not have interactive logon rights regardless of password strength. Option D is wrong because removing service accounts from the local Administrators group reduces privileges but does not prevent interactive logon; a service account could still log on interactively with lower privileges, which is still a security concern.

424
Multi-Selectmedium

A security analyst is setting up a vulnerability scanning program. Which TWO of the following are best practices for determining scanning frequency?

Select 2 answers
A.Scan once per year to minimize operational impact
B.Scan after significant changes to the infrastructure
C.Align scan frequency with the organization's risk appetite
D.Scan only when vulnerabilities are publicly disclosed
E.Use the same interval for all systems regardless of criticality
AnswersB, C

Significant infrastructure changes, such as deploying new systems, modifying network configurations, or updating major applications, frequently introduce new vulnerabilities or misconfigurations. Scanning immediately after these modifications ensures that any newly exposed attack surfaces or security flaws are identified and remediated before they can be exploited. This proactive approach minimizes the window of exposure created by system evolution and maintains a strong security posture.

Why this answer

Option B is correct because scanning after significant infrastructure changes (new hosts, patched services, reconfigurations, or new deployments) catches newly introduced vulnerabilities and misconfigurations before attackers can exploit them, which is a core tenet of continuous vulnerability management. Option C is correct because scanning frequency should be driven by the organization's risk appetite and tolerance, ensuring that high-value or high-risk assets are scanned more often while lower-risk systems may be scanned less frequently, balancing security coverage against operational cost. Option A is incorrect because an annual scan is far too infrequent to detect and remediate vulnerabilities before exploitation, and it ignores risk-based scheduling.

Option D is incorrect because relying only on public disclosure events is reactive and misses internally discovered or non-public vulnerabilities. Option E is incorrect because a uniform interval ignores asset criticality and exposure, contradicting risk-based vulnerability management.

Exam trap

Candidates often fall into the trap of choosing a static, one-size-fits-all interval (like Option E) or an overly conservative frequency to avoid performance degradation (like Option A). Best practices dictate a dynamic approach combining regular risk-aligned intervals with event-driven scans after major changes.

425
MCQhard

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

A.72 hours
B.24 hours
C.48 hours
D.7 days
AnswerA

Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.

Why this answer

Article 33 of the GDPR requires that a controller notify the competent supervisory authority of a personal data breach likely to result in a risk to the rights and freedoms of natural persons without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This 72-hour window is the regulatory maximum, and failure to meet it must be accompanied by reasons for the delay. The 72-hour clock starts when the controller becomes aware, not when the breach occurred.

Exam trap

The trap is conflating the 72-hour supervisory authority notification deadline with the separate 'without undue delay' obligation for notifying data subjects under Article 34, or with shorter breach-notification timelines from other jurisdictions.

How to eliminate wrong answers

Option B is wrong because 24 hours is not a GDPR notification deadline; it may be confused with other regulatory regimes or internal escalation targets, but the regulation specifies 72 hours. Option C is wrong because 48 hours is a fabricated interval not found in GDPR Article 33. Option D is wrong because 7 days exceeds the regulatory maximum and reflects a misunderstanding that GDPR allows a week-long window, which it does not.

426
Multi-Selectmedium

Which TWO of the following are key objectives of a security assessment? (Select exactly 2.)

Select 2 answers
A.Identify vulnerabilities in systems and applications.
B.Assess the effectiveness of existing security controls.
C.Exploit vulnerabilities to gain unauthorized access.
D.Prioritize threats based on business impact.
E.Implement new security controls to address findings.
AnswersA, B

A primary objective of a security assessment is the systematic discovery of weaknesses or flaws, known as vulnerabilities, within an organization's information systems, applications, and network infrastructure. This proactive identification process helps organizations understand potential attack vectors and exposure points before they can be exploited by malicious actors, forming the essential foundation for subsequent risk mitigation strategies.

Why this answer

A is correct because identifying vulnerabilities is a primary objective of a security assessment, such as a vulnerability scan or penetration test, which systematically discovers weaknesses in systems and applications (e.g., missing patches, misconfigurations, or insecure code). B is correct because assessing the effectiveness of existing security controls (e.g., firewalls, IDS/IPS, access controls) is a core goal, often achieved through control testing or validation to determine if controls are properly implemented and functioning as intended.

Exam trap

The trap here is that candidates often confuse the objectives of a security assessment (identify vulnerabilities and assess controls) with the objectives of a penetration test (exploit vulnerabilities) or risk management (prioritize threats), leading them to select options C or D incorrectly.

427
MCQmedium

An organization is implementing a new backup strategy for its critical servers. The backup must support rapid restoration of individual files and allow for a recovery point objective (RPO) of no more than 15 minutes. Which backup method should be used for daily operations?

A.Full backup every 24 hours
B.Continuous data protection (CDP)
C.Differential backup every 6 hours
D.Incremental backup every 4 hours
AnswerB

Continuous Data Protection (CDP) is the optimal solution because it captures every write operation and data change in real-time, effectively creating a continuous journal of all modifications. This granular, real-time capture allows for restoration to virtually any point in time, often within seconds of a data loss event. Consequently, CDP achieves a near-zero RPO, easily satisfying even the most stringent data loss requirements, such as a 15-minute RPO.

Why this answer

Continuous data protection (CDP) is the only backup method that can guarantee a recovery point objective (RPO) of 15 minutes or less because it captures every write to disk in real time or near-real time, enabling restoration to any point within the protection window. Full, differential, and incremental backups all rely on periodic snapshots, which inherently introduce gaps that exceed a 15-minute RPO unless the interval is shorter than 15 minutes, which is impractical for daily operations.

Exam trap

The trap here is that candidates may confuse the backup method's recovery time objective (RTO) with the recovery point objective (RPO), or assume that frequent incremental backups (e.g., every 4 hours) can achieve a 15-minute RPO, but the RPO is determined by the backup interval, not the method's efficiency.

How to eliminate wrong answers

Option A is wrong because a full backup every 24 hours provides an RPO of up to 24 hours, far exceeding the 15-minute requirement. Option C is wrong because a differential backup every 6 hours still leaves up to 6 hours of potential data loss between backups. Option D is wrong because an incremental backup every 4 hours results in an RPO of up to 4 hours, which does not meet the 15-minute threshold.

428
MCQmedium

A network engineer is troubleshooting a slow VPN connection between two sites. The link is symmetric 100 Mbps, but throughput tests show only 20 Mbps. The VPN uses AES-256 encryption. What is the most likely cause?

A.Packet loss due to link congestion
B.CPU bottleneck on the VPN endpoints
C.MTU mismatch causing fragmentation
D.Incorrect TCP window scaling
AnswerB

VPN encryption and decryption, particularly with strong algorithms like AES-256, are computationally intensive processes that heavily utilize the CPU on the VPN endpoints. If the VPN devices (routers, firewalls, or servers) have insufficient CPU power, they cannot process the encrypted traffic fast enough, regardless of available network bandwidth. This creates a fixed processing ceiling, resulting in a consistently limited throughput, such as the observed 20 Mbps, even if the underlying link could support much higher speeds.

Why this answer

AES-256 encryption is computationally intensive, and the throughput of a VPN is often limited by the cryptographic processing capacity of the endpoint CPUs rather than the link bandwidth. A symmetric 100 Mbps link with only 20 Mbps throughput strongly indicates that the VPN endpoints cannot encrypt/decrypt fast enough, creating a CPU bottleneck.

Exam trap

The trap here is that candidates often assume a slow VPN is always due to network issues like congestion or MTU, but the CISSP exam tests the understanding that encryption overhead, especially with AES-256, can be a CPU-bound bottleneck on the endpoints.

How to eliminate wrong answers

Option A is wrong because packet loss due to link congestion would typically cause TCP throughput to drop, but the link is symmetric 100 Mbps and not reported as saturated; the symptom is a consistent throughput cap, not variable loss. Option C is wrong because MTU mismatch causing fragmentation would result in increased overhead and possibly packet drops, but it would not consistently cap throughput at exactly 20 Mbps; it would cause performance degradation with larger packets, not a fixed rate. Option D is wrong because incorrect TCP window scaling can limit throughput on high-latency links, but the question does not mention high latency, and a fixed 20 Mbps cap on a 100 Mbps link is more characteristic of a CPU processing limit than a window scaling issue.

429
MCQhard

A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?

A.Covert channel
B.Buffer overflow
C.TOCTOU
D.Side-channel attack
AnswerC

TOCTOU, or Time-of-Check to Time-of-Use, is a specific type of race condition vulnerability that occurs when there is a delay between the time a security check is performed on a resource and the time that resource is actually used. An attacker can exploit this window by modifying the resource or its attributes after the check but before the use, thereby bypassing the intended security control. This allows the application to "allow a user" to perform an unauthorized action by manipulating the system state during the vulnerable interval.

Why this answer

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability occurs when a resource's state is verified (check) and then used (use) in separate operations, allowing an attacker to alter the resource between the two steps. The scenario — reading a file before integrity verification completes — is a textbook TOCTOU race condition.

Exam trap

CISSP often tests TOCTOU by describing a race condition in plain language — candidates who don't recognize the check/use timing gap may incorrectly pick side-channel or covert channel based on surface keywords.

How to eliminate wrong answers

Option A is wrong because a covert channel is a communication path that violates a security policy by transferring information illicitly, not a race condition between check and use. Option B is wrong because a buffer overflow involves writing beyond allocated memory bounds, which is unrelated to the timing gap described. Option D is wrong because a side-channel attack extracts information from physical or timing characteristics (e.g., power consumption, cache timing), not from a check/use race window.

430
MCQeasy

A development team is integrating a third-party library for encryption. The security team insists on using only the latest version of the library. What is the primary security benefit of this requirement?

A.Improves performance due to optimized code.
B.Ensures the library has more features than older versions.
C.Reduces the attack surface by patching known vulnerabilities.
D.Guarantees backward compatibility with existing code.
AnswerC

Integrating the latest version of a third-party library is a critical security practice because it incorporates patches for known vulnerabilities discovered in previous iterations. These vulnerabilities, if unaddressed, could serve as exploitable entry points for attackers, allowing for unauthorized access, data breaches, or denial-of-service attacks. By applying these fixes, the overall attack surface of the application is significantly reduced, enhancing its resilience against common threats.

Why this answer

Using the latest version of a third-party encryption library ensures that known vulnerabilities (CVEs) are patched, directly reducing the attack surface. Encryption libraries are frequent targets for exploits, and vendors release updates specifically to address security flaws. This aligns with the principle of secure software development, where outdated dependencies are a primary vector for compromise.

Exam trap

The trap here is that candidates may confuse 'latest version' with 'most features' or 'best performance,' but the CISSP exam emphasizes that the primary security benefit is vulnerability remediation, not feature richness or speed.

How to eliminate wrong answers

Option A is wrong because performance improvements are a secondary benefit, not the primary security rationale; optimized code does not inherently address security vulnerabilities. Option B is wrong because additional features can introduce new attack vectors and increase complexity, which may actually expand the attack surface rather than reduce it. Option D is wrong because backward compatibility is a functional concern, not a security benefit; in fact, newer versions may break compatibility to fix security issues, and guaranteeing backward compatibility could prevent necessary security patches.

431
MCQmedium

A company uses a cloud storage service. Which asset security control is most important to prevent unauthorized access to data?

A.Logging and monitoring
B.Encryption in transit and at rest
C.Periodic access reviews
D.Regular vulnerability scanning
AnswerB

Encryption, applied both when data is actively moving across networks (in transit) and when it is stored on persistent media (at rest), is a foundational preventative control for data confidentiality. By transforming data into an unintelligible format using cryptographic algorithms, it ensures that even if unauthorized access or a data breach occurs, the information remains unreadable and unusable without the correct decryption keys. This directly prevents the compromise of data security by rendering it meaningless to an attacker.

Why this answer

Encryption in transit (e.g., TLS 1.3) and at rest (e.g., AES-256) is the most important asset security control because it renders data unreadable even if the cloud storage service is compromised or an attacker gains access to the underlying infrastructure. Without encryption, all other controls (logging, reviews, scanning) are reactive and cannot prevent a direct breach of the stored data. This aligns with the CISSP principle of defense in depth, where encryption provides a strong preventive layer for data confidentiality.

Exam trap

ISC2 often tests the misconception that logging or access reviews are sufficient to prevent unauthorized access, but the trap here is that only encryption provides a strong preventive control that protects data confidentiality regardless of other failures.

How to eliminate wrong answers

Option A is wrong because logging and monitoring are detective controls that identify unauthorized access after it occurs, not preventive controls that stop it in the first place. Option C is wrong because periodic access reviews are administrative controls that verify existing permissions but do not prevent an attacker from exploiting a misconfiguration or stolen credential between reviews. Option D is wrong because regular vulnerability scanning identifies weaknesses in the system but does not directly protect the data itself; encryption is a compensating control that mitigates the risk of exploitation even if vulnerabilities exist.

432
MCQmedium

A large organization needs to deploy a Public Key Infrastructure (PKI) for thousands of devices and users. A key requirement is the ability to revoke certificates in real time when a device is lost or compromised. Which solution is most appropriate?

A.Deploy multiple hierarchical CAs and distribute CRLs periodically.
B.Rely on certificate expiration only and do not implement revocation.
C.Use a single Certificate Authority (CA) with a large Certificate Revocation List (CRL).
D.Implement Online Certificate Status Protocol (OCSP) responders.
AnswerD

Implementing Online Certificate Status Protocol (OCSP) responders provides a highly efficient and near real-time method for verifying the revocation status of digital certificates. Instead of requiring clients to download and parse potentially large and outdated CRLs, OCSP allows a client to send a specific query for a particular certificate's status to a responder, receiving an immediate 'good,' 'revoked,' or 'unknown' response. This significantly reduces latency and bandwidth usage, ensuring that relying parties can quickly ascertain the current validity of a certificate, which is crucial for dynamic and high-volume transaction environments.

Why this answer

OCSP provides real-time certificate status checking by querying an OCSP responder directly, eliminating the delays inherent in CRL distribution. This meets the requirement for immediate revocation verification when a device is lost or compromised, as the responder can return a 'revoked' status instantly without waiting for a CRL refresh cycle.

Exam trap

The trap here is that candidates confuse periodic CRL distribution (which is batch-oriented and slow) with real-time revocation, or assume a single CA with a large CRL is sufficient, overlooking the scalability and latency issues that make OCSP the correct choice for immediate status checks.

How to eliminate wrong answers

Option A is wrong because distributing CRLs periodically introduces latency (hours or days) between revocation and propagation, failing the real-time requirement. Option B is wrong because relying solely on certificate expiration ignores the need for immediate revocation, leaving compromised certificates valid until their natural expiry. Option C is wrong because a single CA with a large CRL creates a single point of failure and scalability issues, and CRLs are still distributed periodically, not in real time.

433
MCQeasy

Which role is ultimately accountable for the classification of data within an organization?

A.Data steward
B.Data custodian
C.Data processor
D.Data owner
AnswerD

The data owner holds ultimate accountability for the data's protection, value, and proper usage throughout its entire lifecycle. This includes the critical responsibility of determining the data's classification level based on its sensitivity, criticality, and potential business impact if compromised or misused. They are the primary decision-maker regarding how data should be categorized and protected, and they accept the residual risk associated with its handling and security measures.

Why this answer

The data owner is the senior manager or business leader ultimately accountable for the data's classification, protection, and use. They hold the authority and responsibility for deciding how data is categorized (e.g., public, internal, confidential, restricted) based on its sensitivity and business value. Accountability cannot be delegated to custodians or stewards, who execute the owner's decisions.

Exam trap

CISSP often tests the confusion between accountability (data owner) and execution (data steward/custodian) — candidates pick the role that does the work rather than the one that is ultimately answerable.

How to eliminate wrong answers

Option A is wrong because a data steward handles day-to-day data quality and metadata management, implementing the owner's classification decisions rather than being accountable for them. Option B is wrong because a data custodian performs the technical safeguarding (backups, access controls) of data on behalf of the owner, not the classification decision. Option C is wrong because a data processor (e.g., a cloud provider) processes data under the controller's instructions and has no accountability for classification.

434
Multi-Selecthard

An organization is implementing a security information and event management (SIEM) system. Which THREE factors are most critical for the SIEM to provide actionable security insights?

Select 3 answers
A.Real-time alerting capabilities
B.Ability to store raw logs for one year
C.Correlation rules that match attack patterns
D.Low false-positive rate
E.Accurate and normalized log sources
AnswersA, C, E

Real-time alerting lets the SIEM surface correlated events as they occur, satisfying the requirement for actionable insights rather than retrospective reporting. Detection latency drops, so analysts can triage and contain active threats while they are still unfolding, which is the operational value the stem demands from the platform.

Why this answer

Option A (Real-time alerting capabilities) is critical because a SIEM must detect and notify on security events as they occur, enabling rapid incident response before attackers can escalate or exfiltrate data. Option C (Correlation rules that match attack patterns) is essential because correlation engines combine events across multiple sources to identify multi-stage attack sequences (e.g., brute force followed by successful login), which isolated log entries would not reveal. Option E (Accurate and normalized log sources) is fundamental because the SIEM's analytics depend on consistent, correctly parsed data in a common schema; if sources are missing, malformed, or unnormalized, correlation and alerting produce unreliable results.

Option B (storing raw logs for one year) is a retention/compliance consideration rather than a driver of actionable insight, and Option D (low false-positive rate) is a desirable tuning outcome, not a foundational input factor like the three marked correct.

Exam trap

The trap here is that candidates confuse 'low false-positive rate' (a tuning outcome) with a critical implementation factor, when in fact the foundational requirements are accurate normalized logs, correlation rules, and real-time alerting — without these, no alerts (true or false) can be generated at all.

435
Multi-Selecthard

A developer is implementing role-based access control (RBAC). Which THREE components are essential for an RBAC system?

Select 3 answers
A.Permissions
B.Attributes
C.Users
D.Roles
E.Sessions
AnswersA, C, D

In Role-Based Access Control (RBAC), permissions are the atomic units of authorization, specifying precisely what actions can be performed on specific resources (e.g., "read file X", "execute program Y"). They form the fundamental building blocks of access control decisions, defining the granular rights that are then aggregated and assigned to roles, rather than directly to individual users.

Why this answer

Permissions are essential in RBAC because they define the actual access rights (e.g., read, write, execute) that are assigned to roles, not directly to users. Without permissions, roles would have no functional authority, and the RBAC model (as defined in NIST SP 800-53 and ANSI INCITS 359) would be unable to enforce any access control decisions. Permissions are the bridge between roles and resources, making them a core component.

Exam trap

The trap here is that candidates confuse RBAC with ABAC and incorrectly select 'Attributes' as essential, forgetting that RBAC is role-centric, not attribute-centric, and that sessions are an optional administrative feature, not a core component.

436
MCQmedium

An organization is planning a penetration test of its internal network. The test team has been given network diagrams, source code access, and administrative credentials. This type of testing is known as:

A.Black-box testing
B.Red team testing
C.White-box testing
D.Gray-box testing
AnswerC

White-box testing, also known as clear-box or glass-box testing, provides the penetration testers with complete and comprehensive knowledge of the target system's internal architecture, source code, network diagrams, and configurations. This full disclosure allows for a thorough examination of internal logic, potential vulnerabilities in code implementation, and misconfigurations that might be missed by external-only approaches, leading to a very deep and detailed security assessment of the system's inner workings.

Why this answer

White-box testing (also known as clear-box or structural testing) is characterized by the test team having full knowledge of the internal system architecture, including network diagrams, source code, and administrative credentials. This level of access allows testers to perform a thorough analysis of the application logic, configuration weaknesses, and potential backdoors that would be invisible in a black-box approach. The scenario explicitly states the team was given these artifacts, making white-box testing the correct classification.

Exam trap

The trap here is that candidates often confuse 'red team testing' with 'white-box testing' because both involve internal knowledge, but red team testing is defined by its adversarial objectives and operational scope, not by the level of information disclosure, whereas the question's key differentiator is the explicit provision of source code and credentials.

How to eliminate wrong answers

Option A is wrong because black-box testing assumes no prior knowledge of the internal network, source code, or credentials; testers simulate an external attacker with zero information, which contradicts the provided access. Option B is wrong because red team testing is a goal-based, adversarial simulation that often includes social engineering and physical breaches, and while it may use some internal knowledge, it is defined by its objective (e.g., testing detection and response) rather than the level of access given; the question specifically asks about the type of testing based on information provided, not the team's mission. Option D is wrong because gray-box testing involves partial knowledge (e.g., network diagrams but not source code or credentials), whereas the team here received full source code and administrative credentials, which is a hallmark of white-box testing.

437
Multi-Selecteasy

Which TWO of the following are best practices for conducting a penetration test?

Select 2 answers
A.Define scope and rules of engagement
B.Obtain written authorization from the organization
C.Install backdoors for future access
D.Notify law enforcement before testing
E.Use only automated tools
AnswersA, B

Defining a precise scope involves clearly identifying target systems, IP ranges, applications, and the specific types of tests permitted, such as network scanning, web application testing, or social engineering. Establishing rules of engagement outlines communication protocols, timing restrictions, incident handling procedures, and acceptable methods, ensuring the assessment remains controlled, ethical, and within legal boundaries to prevent unintended disruption or overreach.

Why this answer

Option A (Define scope and rules of engagement) is correct because a penetration test must have a clearly documented scope specifying in-scope IP ranges, domains, applications, and testing windows, plus rules of engagement covering allowed techniques, escalation contacts, and handling of sensitive data, so testers avoid unintended impact and legal exposure. Option B (Obtain written authorization from the organization) is correct because explicit, signed permission from an authorized representative of the target organization is the legal and ethical prerequisite for any penetration testing activity; without it, testing can constitute unauthorized access under laws such as the CFAA. Option C is wrong because installing backdoors creates persistent unauthorized access and is not a legitimate testing practice.

Option D is wrong because law enforcement is not normally notified in advance of a penetration test; authorization comes from the asset owner. Option E is wrong because relying only on automated tools misses logic flaws and complex vulnerabilities that require manual testing and human analysis.

Exam trap

Candidates often forget that written authorization (Option B) is the single most important legal protection for a penetration tester. Without explicit, written permission from an authorized representative of the organization, penetration testing can be classified as illegal hacking, regardless of the tester's intent.

438
MCQeasy

According to the ISC2 Code of Ethics, which of the following canons has the highest priority when resolving an ethical dilemma?

A.Act honorably and lawfully
B.Provide diligent and competent service
C.Advance and protect the profession
D.Protect society, the common good, and the public trust
AnswerD

"Protect society, the common good, and the public trust" is unequivocally the highest priority canon in the ISC2 Code of Ethics, serving as the foundational principle for all cybersecurity professionals. This canon mandates that all actions and decisions must prioritize the safety, welfare, and confidence of the public, ensuring that information systems and data are secured to prevent harm to individuals, organizations, and critical infrastructure. This overarching responsibility guides all other ethical considerations, making it the correct answer.

Why this answer

The ISC2 Code of Ethics canons are in order of priority: 1. Protect society, the common good, and the public trust; 2. Act honorably and lawfully; 3.

Provide diligent and competent service; 4. Advance and protect the profession. Therefore, option D is the highest priority canon.

439
MCQmedium

A company has implemented a new web application firewall (WAF) and wants to test its effectiveness. Which of the following testing methods would provide the MOST accurate assessment?

A.Conduct a penetration test that includes attempts to bypass the WAF.
B.Perform a vulnerability scan on the web application with the WAF disabled.
C.Review the WAF logs for any blocked attacks.
D.Run an automated web application scanner against the application with the WAF enabled.
AnswerA

Conducting a penetration test that specifically includes attempts to bypass the WAF is the most effective method because it simulates real-world attacker behavior. Skilled penetration testers employ various evasion techniques, such as encoding, obfuscation, and exploiting WAF logic flaws, to circumvent the WAF's defenses. This approach provides a realistic assessment of the WAF's configuration, rule sets, and overall resilience against sophisticated, targeted attacks, revealing its true protective capabilities.

Why this answer

A penetration test that actively attempts to bypass the WAF provides the most accurate assessment because it simulates a real attacker's behavior, testing the WAF's ability to detect and block evasion techniques such as HTTP parameter pollution, encoding obfuscation, and SQL injection payload splitting. This method validates the WAF's effectiveness under realistic adversarial conditions, revealing gaps that passive or disabled-state testing cannot uncover.

Exam trap

The trap here is that candidates often choose Option D (automated scanner with WAF enabled) thinking it tests the WAF in a live environment, but they overlook that automated scanners typically do not attempt sophisticated bypass techniques and may be blocked, giving a false sense of security.

How to eliminate wrong answers

Option B is wrong because performing a vulnerability scan with the WAF disabled only identifies inherent application flaws without evaluating the WAF's protective capabilities, thus failing to assess the security control's effectiveness. Option C is wrong because reviewing WAF logs for blocked attacks only shows past events and does not test the WAF's ability to handle novel or sophisticated bypass techniques, providing no proactive validation. Option D is wrong because running an automated scanner with the WAF enabled may cause the scanner's traffic to be blocked or modified, leading to incomplete or false results, and does not actively attempt to circumvent the WAF's rules.

440
MCQhard

A cloud storage bucket access policy grants all principals permission to write objects. What is the primary security risk of this policy?

A.It only allows read from a specific IP
B.It allows public read access to all objects
C.It denies all access
D.It allows any IP to write objects
AnswerD

This statement accurately identifies the primary security risk within the provided S3 bucket policy. The second `Statement` block explicitly allows the `s3:PutObject` action, which enables users to upload new objects to the bucket. Crucially, this `Allow` statement lacks any `Condition` to restrict the source IP address, meaning any IP address can successfully perform `PutObject` operations, leading to potential unauthorized data injection or storage abuse.

Why this answer

The primary security risk is that the policy allows any IP to write objects. Public write access can enable unauthorized data modification, upload of malicious content, storage abuse, and potential data breaches. Public read access is also risky, but write access is more dangerous because it permits altering or injecting data.

Exam trap

The trap here is that candidates focus on the obvious public read access and overlook the more dangerous public write permission, which is the primary security risk in this policy.

How to eliminate wrong answers

Option A is wrong because the policy does not restrict read access to a specific IP; it grants `s3:GetObject` to `Principal: *` with no IP condition, making it publicly readable from any IP. Option B is wrong because while the policy does allow public read access, the question asks for the security risk, and the more severe risk is the unrestricted write permission (PutObject) that can lead to data injection or abuse. Option C is wrong because the policy explicitly allows both read and write actions, so it does not deny all access.

441
MCQmedium

An organization is implementing a security program and wants to ensure it meets legal and regulatory requirements. The security manager is reviewing the concept of due care. Which best describes due care in the context of information security?

A.The process of responding to security incidents after they occur
B.The selection of security controls based on cost-benefit analysis
C.Compliance with all applicable laws and regulations
D.The level of prudence expected from a reasonable organization in the same industry
AnswerD

This option accurately defines due care as the standard of reasonable prudence expected from an organization within a specific industry. It signifies the obligation to take appropriate and customary steps to protect information assets and mitigate risks, aligning with what a similarly situated, responsible entity would do under comparable circumstances. This standard is dynamic, evolving with technological advancements and emerging threats, requiring continuous assessment and adaptation of security practices.

Why this answer

Due care is the legal concept that an organization must act with the level of prudence that a reasonable organization in the same industry would exercise to protect sensitive information. It is not merely compliance with laws (option C), but a broader standard of care that includes implementing reasonable security measures, even where specific regulations do not mandate them. In information security, due care is demonstrated through policies, procedures, and controls that a prudent organization would adopt to avoid negligence liability.

Exam trap

The trap here is that candidates confuse 'due care' with 'compliance' (option C), but due care is a broader legal duty of prudence that often exceeds regulatory minimums, and the CISSP exam emphasizes that compliance alone does not guarantee security or legal protection.

How to eliminate wrong answers

Option A is wrong because incident response is a specific operational process, not the overarching legal standard of due care; due care encompasses proactive measures before incidents occur. Option B is wrong because cost-benefit analysis is a method for selecting controls, but due care is the legal standard of reasonableness that may require controls even if they are not the most cost-effective. Option C is wrong because compliance with laws and regulations is a minimum baseline, but due care requires going beyond mere compliance to meet the standard of a reasonable organization in the same industry, which may include voluntary best practices.

442
MCQmedium

A security architect is reviewing a design for an e-commerce application. The architect recommends implementing defense in depth. Which of the following is an example of this principle?

A.Encrypting data at rest only
B.Implementing both a web application firewall (WAF) and input validation
C.Using a single firewall at the network perimeter
D.Requiring strong passwords for all users
AnswerB

This option correctly demonstrates defense in depth by combining two distinct and complementary security controls. A Web Application Firewall (WAF) provides an external, perimeter-like defense, filtering malicious requests before they reach the application server, while input validation acts as an internal, application-level control, ensuring that only safe and properly formatted data is processed. This layered approach significantly reduces the attack surface and effectively mitigates a broader spectrum of web-based threats, such as SQL injection and cross-site scripting, by providing multiple points of enforcement.

Why this answer

Defense in depth layers multiple independent controls so that failure of one does not compromise the system. A WAF filters malicious HTTP traffic at the application layer, while input validation rejects malformed or malicious data at the code layer; together they provide overlapping protections against injection and web attacks. This is a textbook example of layered, complementary controls.

Exam trap

CISSP often tests the misconception that any single strong control (encryption, firewall, passwords) constitutes defense in depth, when the principle requires multiple independent layers.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest only protects stored data and provides no protection against network, application, or insider threats, so it is a single control rather than layered defense. Option C is wrong because a single perimeter firewall is a single point of failure and does not address internal threats, application-layer attacks, or lateral movement. Option D is wrong because strong passwords are one authentication control and do not constitute multiple layers of defense across different attack surfaces.

443
MCQeasy

A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address followed by a successful login. What should the analyst do next?

A.Disable the account immediately
B.Ignore, as failed logins are normal
C.Investigate the successful login
D.Block the IP address
AnswerC

Investigating the successful login is the most appropriate immediate action because it directly addresses the most critical event: potential unauthorized access to a system. This step involves verifying the legitimacy of the successful login with the account owner, analyzing source IP, time, and user agent details, and checking for any subsequent suspicious activity. Understanding whether the successful login was authorized or a breach is paramount for determining the scope of the incident and initiating appropriate containment and eradication strategies.

Why this answer

A successful login immediately following multiple failed attempts from the same IP address is a classic indicator of a brute-force or password-spraying attack that succeeded. The analyst must investigate the successful login to determine if it was legitimate or an account compromise, checking for anomalous behavior, time of access, and any subsequent actions. Ignoring or prematurely blocking the IP could destroy forensic evidence or lock out a legitimate user, while disabling the account without investigation may be premature if the login was authorized.

Exam trap

The trap here is that candidates often jump to a reactive action like blocking the IP or disabling the account, failing to recognize that the immediate priority is to investigate the successful login to confirm compromise and preserve forensic evidence.

How to eliminate wrong answers

Option A is wrong because disabling the account immediately without investigation could lock out a legitimate user who simply mistyped their password multiple times, and it may destroy evidence of the attack vector. Option B is wrong because while failed logins are common, a pattern of multiple failures from a single IP followed by a success is not normal and requires investigation per incident response procedures. Option D is wrong because blocking the IP address without first investigating could prevent the analyst from gathering additional forensic data (e.g., logs from the successful session) and may block a legitimate user if the IP is shared or spoofed.

444
MCQeasy

An organization is implementing a data retention policy. The legal team has determined that certain financial records must be retained for seven years due to regulatory requirements. The IT department is responsible for enforcing the retention and disposal of these records. Which of the following is the most critical factor to consider when implementing the retention policy?

A.Implementing a backup strategy for the retained data
B.Ensuring that data is easily accessible to all employees
C.Ensuring that data is stored in a cost-effective manner
D.Verifying that data is securely deleted after the retention period
AnswerD

The most critical factor is ensuring that data is securely deleted once the retention period expires. Failure to do so can result in legal liabilities, increased storage costs, and potential data breaches. Secure deletion must be verifiable and consistent with the organization's data destruction policies. This ensures compliance with retention schedules and reduces risk.

Why this answer

Secure deletion after the retention period is the most critical factor because it ensures that data is not kept beyond its legal or business requirement, reducing liability and risk. While cost, backups, and accessibility are relevant, they are secondary to the core purpose of a retention policy: to manage data throughout its lifecycle and dispose of it securely when no longer needed.

Exam trap

The trap here is focusing on operational concerns like cost or backups instead of the compliance-driven need for secure disposal.

445
MCQmedium

A vulnerability scanner reports a medium-severity finding on a web server. After investigating, the system administrator claims the finding is a false positive because the service in question is not actually running. Which step should the security analyst take next?

A.Verify the service status using system commands or network scans
B.Remove the finding from the report since the administrator confirmed it
C.Close the finding as accepted risk
D.Escalate the issue to management for risk acceptance
AnswerA

This is the correct initial action. When a vulnerability scanner reports a finding, especially if an administrator disputes it, independent technical verification is crucial to confirm its existence. Using system commands (e.g., `netstat -tuln`, `systemctl status <service>`) or targeted network scans (e.g., `nmap -p <port> <IP>`) directly validates whether the reported service is actually running or listening, thereby confirming if the finding is a true positive or a false positive before proceeding with remediation or risk acceptance.

Why this answer

The security analyst must independently verify the administrator's claim before taking any action. The vulnerability scanner may have detected a service on a different port or the service may be bound to a non-standard interface; using system commands (e.g., `netstat -tulpn` or `ss -tulpn`) or a targeted network scan (e.g., `nmap -sV -p <port> <target>`) provides objective evidence of whether the service is actually listening. Relying solely on the administrator's assertion without verification could lead to a missed true positive, especially if the service is hidden or misconfigured.

Exam trap

The trap here is that candidates may assume the administrator's claim is authoritative and skip verification, but the CISSP exam emphasizes that security analysts must always validate findings through independent technical means before closing or escalating.

How to eliminate wrong answers

Option B is wrong because removing the finding without independent verification violates the principle of evidence-based risk management and could suppress a genuine vulnerability if the administrator is mistaken or the service is transient. Option C is wrong because closing the finding as accepted risk requires a formal risk acceptance process with documented justification and management approval, not a single administrator's claim of a false positive. Option D is wrong because escalating to management for risk acceptance is premature; the analyst must first confirm the service status to determine if the finding is indeed a false positive before any risk acceptance decision is warranted.

446
MCQeasy

An organization wants to ensure that employees can securely access internal applications from home. They deploy a VPN solution. Which VPN type provides the strongest encryption and is most commonly used for remote access?

A.IPsec with IKEv2 and AES-256
B.MPLS Layer 3 VPN
C.L2TP without encryption
D.PPTP
AnswerA

IPsec with IKEv2 and AES-256 is the optimal choice for secure remote access, as IPsec provides robust network layer security through authentication and encryption. IKEv2 (Internet Key Exchange version 2) establishes Security Associations (SAs) and manages cryptographic keys efficiently, offering strong resistance to attacks and supporting modern features like MOBIKE for seamless roaming. AES-256 (Advanced Encryption Standard with a 256-bit key) ensures high-grade confidentiality for data in transit, making this combination a industry standard for protecting sensitive communications.

Why this answer

IPsec with IKEv2 and AES-256 provides the strongest encryption for remote access VPNs. IKEv2 offers improved security features like mobility and multi-homing support, while AES-256 is a symmetric cipher with a 256-bit key that is currently considered unbreakable by brute force. This combination is widely deployed for secure client-to-site connections.

Exam trap

The trap here is that candidates often confuse MPLS Layer 3 VPN (a site-to-site provider-based solution) with remote access VPNs, or they underestimate the weakness of PPTP and unencrypted L2TP, assuming any tunneling protocol provides adequate security.

How to eliminate wrong answers

Option B is wrong because MPLS Layer 3 VPN is a service provider technology used to connect multiple sites over a provider network, not a remote access VPN for individual employees; it does not encrypt user traffic. Option C is wrong because L2TP without encryption provides no confidentiality; it only tunnels traffic and relies on an additional protocol like IPsec for encryption, making it insecure on its own. Option D is wrong because PPTP uses the outdated MPPE encryption with RC4, which has known vulnerabilities and is considered weak and deprecated for secure remote access.

447
MCQeasy

A company is implementing a CI/CD pipeline for a web application. Which security testing method should be integrated into the build stage to catch vulnerabilities early?

A.Only using open-source vulnerability scanners
B.Dynamic Application Security Testing (DAST) in the production stage
C.Manual code review after each sprint
D.Static Application Security Testing (SAST) in the build stage
AnswerD

Integrating Static Application Security Testing (SAST) into the build stage is a fundamental best practice for securing CI/CD pipelines. SAST analyzes source code, bytecode, or binary code for security vulnerabilities without executing the application, allowing developers to identify and remediate flaws early in the development lifecycle. This "shift left" approach provides immediate feedback, reduces the cost of fixing defects, and prevents insecure code from progressing further, aligning perfectly with the speed and automation of CI/CD.

Why this answer

Static Application Security Testing (SAST) analyzes source code without execution, making it suitable for early detection in the build stage of a CI/CD pipeline. Option A is incorrect because open-source vulnerability scanners may not cover custom code and can produce false positives. Option B is incorrect because Dynamic Application Security Testing (DAST) requires a running application and is typically performed in later stages.

Option C is incorrect because manual code review is too slow and resource-intensive for continuous integration, while automated SAST fits the speed of CI/CD.

448
Multi-Selecthard

A risk assessment identifies several threats. Which THREE are considered external threats?

Select 3 answers
A.Insider error
B.Hacktivist
C.Disgruntled employee
D.Natural disaster
E.Competitor
AnswersB, D, E

A hacktivist is an external threat actor who leverages hacking techniques to promote a political or social cause, rather than for direct financial gain. Their motivations are ideological, often targeting organizations whose practices they oppose to disrupt operations, deface websites, or leak sensitive information. This makes them a distinct and significant external threat identified in comprehensive risk assessments.

Why this answer

Option B (Hacktivist) is correct because a hacktivist is an outside actor who attacks systems to advance a political or social agenda, making it an external threat. Option D (Natural disaster) is correct because events such as floods, fires, and earthquakes originate from the environment outside the organization and are classified as external threats. Option E (Competitor) is correct because a rival organization operating outside the company can conduct espionage, sabotage, or other hostile actions, which is an external threat source.

Options A (Insider error) and C (Disgruntled employee) are not external threats because both involve individuals within the organization who already have authorized access, making them internal threats.

Exam trap

Candidates often confuse the source of a threat. While human threats can be both internal and external, any threat originating from an entity with authorized access (like a disgruntled employee or an employee making an error) is classified as an internal threat, whereas competitors, hacktivists, and environmental events are external.

449
MCQhard

A development team is implementing a microservices architecture. Which of the following is the BEST approach to secure inter-service communication?

A.Use JSON Web Tokens (JWT) for each request
B.Use API keys transmitted in HTTP headers
C.Place all services behind a single API gateway
D.Implement mutual TLS (mTLS) between services
AnswerD

Mutual TLS (mTLS) is a robust security protocol that establishes strong, bidirectional authentication and encryption for network communication. It mandates that both the client and the server present and validate cryptographic certificates before any data exchange occurs, ensuring that each microservice verifies the identity of the other. This process guarantees confidentiality, integrity, and authenticity for all inter-service communication, effectively preventing unauthorized access, data tampering, and eavesdropping within the microservices environment.

Why this answer

Mutual TLS (mTLS) is the best approach because it provides both encryption and bidirectional authentication between services, ensuring that only authorized services can communicate. Unlike token-based methods, mTLS verifies the identity of both the client and server using X.509 certificates, which is critical in a zero-trust microservices environment where network boundaries are porous.

Exam trap

ISC2 often tests the misconception that an API gateway secures all inter-service communication, but candidates forget that east-west traffic between microservices bypasses the gateway and requires its own security mechanism like mTLS.

How to eliminate wrong answers

Option A is wrong because JWT per request authenticates the user or service but does not encrypt the communication channel, leaving data vulnerable to interception; it also adds overhead for every request without addressing transport-layer security. Option B is wrong because API keys in HTTP headers are static credentials that can be easily leaked, replayed, or intercepted if the channel is not encrypted, and they provide no mutual authentication. Option C is wrong because placing all services behind a single API gateway creates a central point of failure and a bottleneck, and it does not secure east-west traffic between services—internal calls bypass the gateway entirely.

450
MCQmedium

An organization wants to avoid a particular risk entirely by not engaging in the activity that creates the risk. Which risk response strategy is being used?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerA

Risk avoidance is a strategy where an organization eliminates a particular risk entirely by choosing not to engage in the activity or process that gives rise to it. This approach completely removes the potential for the risk event to occur, rather than merely reducing its likelihood or impact. It is typically employed when the potential consequences of a risk are deemed unacceptable and cannot be effectively managed through other means.

Why this answer

Risk avoidance is the strategy of eliminating the risk by not performing the activity that creates it — for example, deciding not to store credit card data at all to avoid PCI DSS exposure. It is the only strategy that reduces risk to zero for that specific activity, though it may forfeit business benefits. The question's phrasing 'not engaging in the activity' is the textbook definition of avoidance.

Exam trap

The trap here is confusing Avoid with Mitigate — candidates see 'reduce risk' language and pick Mitigate, but the key discriminator is whether the risky activity is eliminated entirely (Avoid) or merely controlled (Mitigate).

How to eliminate wrong answers

Option B (Transfer) is wrong because transfer shifts risk to a third party — via insurance, outsourcing, or contracts — but the activity still occurs and the organization retains residual risk. Option C (Mitigate) is wrong because mitigation reduces the likelihood or impact of the risk through controls, but the activity continues and some residual risk remains. Option D (Accept) is wrong because acceptance means acknowledging the risk and proceeding without additional controls, which is the opposite of eliminating the activity.

Page 5

Page 6 of 11

Page 7

All pages