Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 451–525

816 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
Multi-Selectmedium

Which THREE of the following are components of a Privileged Access Management (PAM) solution?

Select 3 answers
A.User self-service password reset
B.Single sign-on for web applications
C.Session recording
D.Just-in-time access
E.Password vaulting
AnswersC, D, E

Session recording is a critical component of Privileged Access Management (PAM) that captures and archives all activities performed during a privileged session. This includes keystrokes, mouse movements, and screen content, providing an immutable audit trail. Such recordings are invaluable for forensic analysis, compliance auditing, and identifying unauthorized or suspicious actions by privileged users, enhancing accountability and security posture.

Why this answer

Session recording (C) is a core PAM component because it captures and audits privileged sessions (e.g., SSH, RDP) for accountability and forensic review. Just-in-time access (D) is a PAM capability that grants elevated privileges only when needed and for a limited time, reducing standing access. Password vaulting (E) is central to PAM, as it securely stores, rotates, and checks out privileged credentials.

User self-service password reset (A) and single sign-on for web applications (B) are identity and access management (IAM) features, not PAM-specific components.

Exam trap

The trap is that SSO and self-service password reset sound like 'access management' and get lumped in with PAM — remember PAM is specifically about privileged accounts, vaulting, JIT elevation, and session auditing.

452
MCQhard

In a virtualized environment, which security control is most effective for isolating VMs from each other?

A.Host-based firewall on each VM
B.Physical separation
C.Virtual LAN (VLAN) segmentation
D.Hypervisor-level network policies
AnswerD

Hypervisor-level network policies are enforced directly by the hypervisor, which sits above all virtual machines and has ultimate control over their network interactions. This allows for granular control over traffic flow, micro-segmentation, and robust isolation between VMs, even those on the same virtual network. Because these policies are enforced at a layer inaccessible to guest operating systems, they provide the most effective and resilient security control against compromised VMs or lateral movement within the virtualized environment.

Why this answer

Hypervisor-level network policies, such as virtual switches with port groups and VLAN tagging, enforce isolation directly at the hypervisor layer, ensuring that VM traffic is segmented without relying on guest OS configurations. This control is independent of the VM's own firewall settings and can prevent lateral movement even if a VM is compromised, because the hypervisor mediates all network I/O.

Exam trap

The trap here is that candidates often confuse VLAN segmentation (Option C) as the primary isolation mechanism, but in a virtualized environment, VLANs are configured at the hypervisor level as part of virtual switch policies, making 'Hypervisor-level network policies' the more precise and encompassing answer.

How to eliminate wrong answers

Option A is wrong because a host-based firewall on each VM relies on the guest OS, which can be bypassed if the VM is compromised or if the firewall is misconfigured; it does not provide isolation at the hypervisor level. Option B is wrong because physical separation defeats the purpose of virtualization and is not a practical control within a virtualized environment; it refers to separate physical hosts, not VM-to-VM isolation. Option C is wrong because VLAN segmentation operates at Layer 2 of the network and can be effective, but it is configured on physical switches and does not inherently control traffic between VMs on the same hypervisor unless combined with hypervisor-level policies; it is an external control that can be bypassed if the hypervisor's virtual switch is not properly configured.

453
Multi-Selectmedium

A security analyst is reviewing the findings from a vulnerability scan of a web application. Which TWO actions are most appropriate to prioritize remediation?

Select 2 answers
A.The asset's value to the organization
B.The number of times the scan was run
C.Whether a known exploit exists
D.The date the vulnerability was discovered
E.The CVSS score of the vulnerability
AnswersC, E

Correct. Whether a known exploit exists is a key factor because vulnerabilities with existing exploits are more likely to be targeted, increasing urgency.

Why this answer

Option C is correct because the existence of a known, weaponized exploit (e.g., one listed in CISA's KEV catalog or available in Metasploit) dramatically raises the likelihood of active compromise, so it should drive remediation priority. Option E is correct because the CVSS score provides a standardized, quantitative measure of a vulnerability's severity (base, temporal, and environmental metrics), making it a primary input for ranking remediation efforts. Options A, B, and D are not the best answers here: asset value is a contextual factor that can influence prioritization but is not itself a vulnerability attribute used to rank scan findings, the number of times a scan was run is irrelevant to the severity of a finding, and the discovery date does not indicate exploitability or impact, though age may matter for SLA tracking.

Exam trap

The trap here is that candidates may think only one of these factors is sufficient. However, CISSP emphasizes that remediation priority should consider both exploitability (known exploit existence) and severity (CVSS score) together. A high CVSS vulnerability without an exploit may be less urgent than one with a known exploit, but both are important inputs.

454
MCQmedium

A security team is reviewing firewall logs and sees many dropped packets from an external IP. What type of attack is most likely?

A.Man-in-the-middle
B.Port scanning
C.SQL injection
D.Phishing
AnswerB

Port scanning involves an attacker systematically probing a target system's ports to discover which services are listening or open. When a scanner attempts to connect to numerous closed or filtered ports, the firewall will log these connection attempts as dropped packets, as it denies access or the target service does not respond. A high volume of such drops across various ports is a strong indicator of an adversary performing reconnaissance.

Why this answer

Port scanning is the most likely attack because it involves an external IP sending packets to multiple ports on a target system to identify open services. Firewalls log these as dropped packets when they block unsolicited inbound traffic to closed or filtered ports, which is a common signature of reconnaissance activity.

Exam trap

The trap here is that candidates may confuse port scanning with a denial-of-service (DoS) attack, but port scanning is reconnaissance, not resource exhaustion, and the key clue is the pattern of dropped packets to multiple ports from a single IP.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack requires the attacker to intercept and potentially modify communications between two parties, which would not typically manifest as dropped packets from a single external IP; instead, it involves ARP spoofing, DNS poisoning, or session hijacking. Option C is wrong because SQL injection targets web application input fields to manipulate database queries, not network-layer packet filtering, and would not appear as dropped packets in firewall logs. Option D is wrong because phishing is a social engineering attack that uses deceptive emails or websites to steal credentials, not a network-level activity that generates dropped packets from an external IP.

455
Multi-Selecthard

A security manager is designing a continuous monitoring program to satisfy ongoing authorization requirements. The program must detect unauthorized configuration changes to production servers, verify that security patches are applied within policy timeframes, and provide evidence for auditors. Which TWO of the following controls BEST support these objectives? (Choose two.)

Select 2 answers
A.A vulnerability scanner scheduled to run quarterly against all production servers with results emailed to the security team
B.Security information and event management (SIEM) correlation of change logs, patch deployment records, and FIM alerts with retention aligned to the audit period
C.A configuration management database (CMDB) updated manually by administrators when changes are made
D.Annual penetration testing of the production environment performed by an external firm
E.File integrity monitoring (FIM) that baselines critical system files and alerts on unauthorized modifications
AnswersB, E

A SIEM aggregates and correlates FIM alerts, patch deployment records, and change management logs, providing the centralized detection and evidence repository continuous monitoring requires. Retention aligned to the audit period ensures auditors can review historical events, and correlation surfaces changes that lack an approved change record.

Why this answer

Continuous monitoring requires automated, recurrent detection of change and patch state plus a durable evidence repository. File integrity monitoring detects unauthorized modifications against a baseline, while a SIEM correlates change, patch, and integrity data and retains it for audit review. Manual records and periodic scanning or testing cannot deliver the required continuous detection or evidence.

Exam trap

The trap here is equating periodic assessments such as quarterly scans or annual penetration tests with continuous monitoring.

456
MCQhard

A financial institution is required to retain customer transaction records for seven years under regulatory mandates. The institution is facing a lawsuit and must preserve all relevant data. What legal concept applies?

A.E-discovery
B.Data retention policy
C.Chain of custody
D.Legal hold
AnswerD

A legal hold, also known as a litigation hold or preservation order, is a formal directive issued by an organization to suspend the normal disposition or alteration of records and information that may be relevant to a pending or reasonably anticipated legal action, investigation, or audit. This critical process ensures that all potentially discoverable data, including electronically stored information (ESI), is preserved, overriding any routine data retention policies that might otherwise lead to its deletion. It directly addresses the requirement to retain customer transaction data in anticipation of legal needs.

Why this answer

When a lawsuit is reasonably anticipated or has been filed, the duty to preserve relevant evidence arises. A legal hold (also known as a litigation hold) is the formal process that suspends normal data retention and destruction policies to ensure that all potentially relevant electronically stored information (ESI) is preserved. This overrides the standard seven-year retention schedule because the legal obligation to preserve supersedes the regulatory retention mandate.

Exam trap

The trap here is that candidates confuse the operational concept of a data retention policy (Option B) with the legal obligation of a legal hold, failing to recognize that a lawsuit triggers a superseding duty to preserve that overrides any scheduled destruction.

How to eliminate wrong answers

Option A is wrong because e-discovery is the broader process of identifying, collecting, and producing ESI in litigation, not the specific legal directive to preserve data. Option B is wrong because a data retention policy is a pre-existing schedule for how long data is kept for operational or regulatory reasons; it does not create a legal duty to preserve data in anticipation of litigation. Option C is wrong because chain of custody is a procedural documentation method used to track the handling of evidence from collection to presentation, not the legal concept that triggers preservation obligations.

457
MCQeasy

A company wants to implement multi-factor authentication (MFA) for remote access. Which combination of factors represents something you have and something you are?

A.Password and PIN
B.Hardware token and mobile phone
C.Smart card and fingerprint
D.Password and SMS code
AnswerC

A smart card is a physical token the user possesses, satisfying something you have. A fingerprint is a biometric trait inherent to the user, satisfying something you are. Together they combine possession and inherence factors for MFA.

Why this answer

A smart card is a physical device that you possess (something you have), and a fingerprint is a biometric characteristic unique to you (something you are). This combination satisfies the multi-factor authentication requirement by using two distinct factors from different categories, which is more secure than using two factors from the same category.

Exam trap

The trap here is that candidates often confuse 'something you have' with 'something you know' or fail to recognize that two factors from the same category (e.g., two knowledge factors) do not constitute true multi-factor authentication.

How to eliminate wrong answers

Option A is wrong because both a password and a PIN are knowledge-based factors (something you know), so they do not provide multi-factor authentication; they are two instances of the same factor type. Option B is wrong because both a hardware token and a mobile phone are possession-based factors (something you have), which again fails to combine two different factor categories. Option D is wrong because a password is something you know and an SMS code is typically considered something you have (possession of the phone), but SMS codes are vulnerable to interception and SIM-swapping attacks, and more importantly, the question asks for 'something you have and something you are'—an SMS code is not a biometric or inherent characteristic.

458
MCQeasy

An organization's security policy requires that all data at rest must be encrypted. Which security principle is primarily being addressed?

A.Integrity
B.Confidentiality
C.Availability
D.Non-repudiation
AnswerB

Encryption directly addresses confidentiality by transforming plaintext data into an unreadable ciphertext using a cryptographic algorithm and a secret key. This process ensures that even if unauthorized individuals gain access to the encrypted data, they cannot decipher its content without the correct decryption key. Consequently, encryption effectively prevents unauthorized disclosure of sensitive information, making it the primary control for upholding the confidentiality of data both at rest and in transit.

Why this answer

Encryption of data at rest protects data from unauthorized disclosure by rendering it unreadable without the decryption key. This directly addresses the confidentiality principle of the CIA triad, ensuring only authorized parties can access the data. Integrity concerns unauthorized modification, availability concerns uptime, and non-repudiation concerns proving an action occurred.

Exam trap

CISSP often tests whether candidates correctly map controls to CIA triad principles; the trap is confusing encryption (confidentiality) with integrity or non-repudiation, especially when AEAD modes provide both.

How to eliminate wrong answers

Option A is wrong because integrity ensures data is not altered improperly; encryption alone does not guarantee integrity (though AEAD modes provide both). Option C is wrong because availability ensures data and systems are accessible when needed, which encryption does not address. Option D is wrong because non-repudiation provides proof of origin or action, typically via digital signatures, not encryption at rest.

459
MCQmedium

An organization implements a security model where users can only read objects at or below their security clearance, and can only write to objects at or above their clearance. This model primarily ensures:

A.Integrity
B.Confidentiality
C.Accountability
D.Availability
AnswerB

The Bell-LaPadula model is specifically designed to enforce confidentiality in multi-level security environments. It achieves this through two primary rules: the simple security property, which prevents subjects from reading objects at a higher classification level ('no read up'), and the *-property (star property), which prevents subjects from writing to objects at a lower classification level ('no write down'). These rules collectively ensure that sensitive information cannot flow downwards to less secure classifications, thereby preserving its secrecy.

Why this answer

The described model is the Bell-LaPadula model: 'no read up' (subjects can only read at or below their clearance) and 'no write down' (subjects can only write at or above their clearance). Both rules exist to prevent sensitive information from leaking to lower classification levels, so the model primarily ensures confidentiality.

Exam trap

The trap is mixing up Bell-LaPadula (confidentiality, no read up/no write down) with Biba (integrity, no read down/no write up) — the direction of the rules is the giveaway.

How to eliminate wrong answers

Option A is wrong because integrity is the focus of the Biba model, which uses 'no read down' and 'no write up' — the inverse of Bell-LaPadula. Option C is wrong because accountability concerns auditing and non-repudiation, not access direction rules. Option D is wrong because availability concerns uptime and access to resources, which is unrelated to the read/write clearance rules described.

460
MCQhard

An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?

A.Low likelihood, low impact
B.Medium likelihood, medium impact
C.High likelihood, high impact
D.Control risk is not a defined term
AnswerB

After implementing security controls, the inherent risk (high likelihood, potentially high impact) is expected to be reduced to a more acceptable level. "Medium likelihood, medium impact" represents a plausible and common outcome of effective risk mitigation strategies, where controls successfully diminish the probability of the event occurring and/or lessen its potential consequences. This remaining risk, after controls are applied, is precisely what is defined as residual risk, indicating a successful but not absolute reduction from the initial state.

Why this answer

Residual risk is the risk that remains after controls have been implemented. In this scenario, the original risk was high likelihood and high impact; after controls, it is reassessed as medium likelihood and medium impact. Therefore, the residual risk is medium likelihood and medium impact.

Exam trap

CISSP often tests the definition of residual risk, and candidates may mistakenly select the original risk or assume controls eliminate all risk; the key is that residual risk is what remains after controls.

How to eliminate wrong answers

Option A is wrong because low likelihood and low impact would represent a further reduction beyond what was achieved; the reassessment explicitly states medium likelihood and medium impact. Option C is wrong because high likelihood and high impact is the original inherent risk before controls, not the residual risk. Option D is wrong because 'control risk' is not a defined term in this context; the question asks for residual risk, which is a standard risk management concept.

461
MCQhard

Refer to the exhibit. A legal hold exception preserves FinancialRecords FIN-001 and FIN-002. What is the correct action for FinancialRecords that are not under legal hold?

A.They should be audited and then preserved indefinitely
B.They should be archived after 2555 days
C.They should be deleted after 2555 days
D.They should be deleted after 365 days
AnswerC

Deleting financial records after 2555 days would directly violate most regulatory compliance mandates, which typically require these records to be retained and accessible for auditability over extended periods. The specified action for financial data is archiving, which preserves the data in a secure, immutable state for its required lifecycle, rather than permanent destruction. Deletion would render the organization non-compliant and unable to produce necessary documentation if requested by auditors or legal entities.

Why this answer

In CISSP and general data lifecycle management, a retention policy defines the maximum period for which data should be kept. Once the retention period (e.g., 2555 days / 7 years) expires, the standard and legally compliant action is to securely destroy/delete the data to limit liability and adhere to data minimization principles (unless a legal hold is active). Archiving is a method of retention, not an action taken after the retention period expires.

Therefore, Option C (deleted after 2555 days) is typically the correct compliance action, not Option B.

Exam trap

Candidates often confuse retention with indefinite archiving. A retention policy dictates the maximum lifespan of data; once that lifespan is reached, the data must be destroyed/deleted to mitigate legal and security risks, unless a legal hold exception applies.

How to eliminate wrong answers

Option A is wrong because auditing and preserving indefinitely violates the principle of data lifecycle management, which requires defined retention periods; indefinite preservation is not a standard action for records not under legal hold. Option C is wrong because deletion after 2555 days would destroy records that may still be needed for compliance or operational purposes; archiving is the appropriate action to retain them beyond active use. Option D is wrong because 365 days is too short for FinancialRecords, which typically require longer retention (e.g., 7 years for tax or audit purposes), and the policy specifies 2555 days.

462
MCQmedium

Based on the vulnerability scan exhibit, which vulnerability should be remediated first?

A.All vulnerabilities equally because they have the same host
B.SSH weak MAC algorithms
C.SMTP open relay
D.OpenSSL Heartbleed vulnerability
AnswerD

The OpenSSL Heartbleed vulnerability (CVE-2014-0160) is a critical memory disclosure flaw that allowed attackers to read up to 64KB of memory from affected servers, potentially exposing private keys, user credentials, and other sensitive data without leaving a trace. Its high severity stems from its widespread impact on internet services, ease of exploitation, and the direct compromise of confidentiality, making it a top priority for immediate remediation.

Why this answer

The OpenSSL Heartbleed vulnerability (CVE-2014-0160) allows an attacker to read up to 64 KB of memory from a vulnerable server, potentially exposing private keys, session tokens, and passwords. This is a critical information disclosure flaw that requires immediate remediation because it compromises the confidentiality of all encrypted communications. In contrast, the other vulnerabilities are less severe: SSH weak MAC algorithms reduce cryptographic strength but do not directly leak data, and SMTP open relay is a misconfiguration that enables spam but not direct data theft.

Exam trap

The trap here is that candidates may prioritize SMTP open relay or SSH weak MAC algorithms because they sound like common misconfigurations, but the CISSP exam emphasizes that vulnerabilities with direct, remote exploitation for data disclosure (like Heartbleed) must be remediated first under the principle of risk prioritization.

How to eliminate wrong answers

Option A is wrong because not all vulnerabilities have the same severity or exploitability; prioritization must be based on risk, not just host commonality. Option B is wrong because SSH weak MAC algorithms (e.g., HMAC-MD5) weaken integrity but are not remotely exploitable for direct data disclosure like Heartbleed; they are a lower-priority hardening issue. Option C is wrong because SMTP open relay allows unauthorized email forwarding (spam) but does not expose sensitive server memory or credentials; it is a configuration flaw with lower impact on confidentiality.

463
Multi-Selectmedium

Which THREE of the following are characteristics of a federated identity management system?

Select 3 answers
A.It relies on standard protocols such as SAML or OpenID Connect
B.It operates with a single identity provider for all organizations
C.It requires all participating organizations to use the same user directory
D.It enables identity information to be shared across different security domains
E.It provides single sign-on (SSO) across multiple organizations
AnswersA, D, E

Federated identity management fundamentally depends on established, open standards to facilitate secure and interoperable communication between distinct identity providers and service providers. Protocols like Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) define the formats for exchanging authentication and authorization assertions, ensuring that diverse systems can understand and trust each other's identity information. This standardization is critical for enabling seamless cross-domain access and single sign-on without requiring proprietary integrations.

Why this answer

Federated identity management systems rely on standard protocols like SAML (Security Assertion Markup Language) or OpenID Connect to exchange authentication and authorization data between identity providers (IdPs) and service providers (SPs). These protocols enable trust relationships across different security domains without requiring shared directories or a single IdP.

Exam trap

The trap here is that candidates confuse federation with centralized SSO, assuming a single IdP or shared directory is required, when in fact federation decouples identity providers and directories across organizational boundaries.

464
MCQeasy

Which of the following is an example of a Type 2 authentication factor?

A.Smart card
B.PIN
C.Password
D.Fingerprint
AnswerA

A smart card represents 'something you have' (Type 2) because it is a physical token that must be possessed by the user to grant access. These cards typically contain an embedded microchip capable of performing cryptographic operations, such as storing digital certificates or generating one-time passwords. Its security relies on the physical control of the device, making it a robust authentication factor, often combined with a PIN for multi-factor authentication.

Why this answer

A smart card is a Type 2 authentication factor because it falls under the category of 'something you have.' Type 2 factors are possession-based, meaning the user must physically possess the token to authenticate. Smart cards store cryptographic keys or certificates and require a card reader to present the credential, making them a classic example of a possession factor.

Exam trap

The trap here is that candidates often confuse a smart card with a PIN or password because both are used together in practice, but the question specifically asks for the factor type of the smart card itself, not the combined authentication method.

How to eliminate wrong answers

Option B is wrong because a PIN (Personal Identification Number) is a Type 1 factor ('something you know'), not a Type 2 factor; it relies on knowledge rather than possession. Option C is wrong because a password is also a Type 1 factor, based on secret knowledge, not on a physical object. Option D is wrong because a fingerprint is a Type 3 factor ('something you are'), using biometric characteristics, not a possession-based factor.

465
Multi-Selecthard

Which TWO of the following are essential characteristics of an effective information classification scheme?

Select 2 answers
A.Should have at least seven classification levels to capture granularity
B.Must be accompanied by mandatory training for all users
C.Should have clear labels that map to specific handling procedures
D.Should be based on the encryption algorithm used to protect the data
E.Must be applied consistently across the entire organization
AnswersC, E

An essential characteristic of an effective data classification scheme is that its labels (e.g., "Confidential," "Internal Use Only") must directly correspond to specific, actionable handling procedures. These procedures dictate how data at each classification level should be stored, transmitted, accessed, and disposed of. Without this clear mapping, labels become meaningless, as users would lack the necessary guidance to protect information appropriately, rendering the entire classification effort ineffective.

Why this answer

Option C is correct because an effective classification scheme must use clear, well-defined labels (e.g., Public, Internal, Confidential, Restricted) that directly map to specific handling procedures such as storage, transmission, and disposal requirements, ensuring users know exactly how to treat each data type. Option E is correct because the scheme must be applied consistently across the entire organization so that the same label means the same thing in every department, avoiding confusion, gaps, and inconsistent protection that could lead to data exposure. Option A is incorrect because the number of classification levels is not fixed at seven; schemes typically use three to five levels, and the right number depends on the organization's needs rather than a minimum count.

Option B is incorrect because while training is important for implementation, it is a supporting control rather than an essential characteristic of the classification scheme itself. Option D is incorrect because classification should be based on the data's sensitivity, value, and business impact, not on the encryption algorithm used to protect it, which is a separate technical control.

Exam trap

The trap here is that candidates confuse 'essential characteristics of the scheme' with 'supporting activities' (like training) or 'implementation details' (like encryption algorithms), leading them to select options that are good practices but not defining properties of the classification scheme itself.

466
Multi-Selecteasy

Which TWO of the following are key indicators that a security awareness training program is effective? (Choose two.)

Select 2 answers
A.More instances of employees bypassing security controls to improve productivity.
B.An increase in help desk calls for password resets.
C.An increase in employees reporting suspicious emails to the security team.
D.Fewer security policies are being issued.
E.A reduction in the number of successful phishing attacks.
AnswersC, E

Reporting suspicious emails shows that employees are applying their training.

Why this answer

A measurable increase in employees reporting suspicious emails directly indicates that the training has improved their ability to recognize phishing indicators (e.g., mismatched URLs, spoofed sender domains, urgent language) and has instilled the desired reporting behavior. This is a leading indicator of security awareness effectiveness, as it demonstrates proactive threat identification before a compromise occurs.

Exam trap

The trap here is that candidates may confuse activity metrics (e.g., more help desk calls) with effectiveness metrics, or mistakenly think that fewer policies indicate simpler, more effective training, when in fact the CISSP emphasizes behavioral outcomes like reporting and reduced incident success rates.

467
MCQmedium

A company is deploying a new web application and needs to ensure that only HTTPS traffic is allowed. What is the MOST effective way to enforce this at the network perimeter?

A.Allow TCP port 443 only and block port 80.
B.Configure the firewall to allow TCP port 80 and 443.
C.Use a proxy server to decrypt all traffic.
D.Block TCP port 443.
AnswerA

This configuration directly enforces the use of HTTPS by making TCP port 443 (HTTPS) accessible while explicitly denying TCP port 80 (HTTP). It ensures all web traffic to the application is encrypted, meeting security requirements for data confidentiality and integrity. Any attempt to connect via unencrypted HTTP would be blocked at the network perimeter, preventing insecure access and upholding the 'HTTPS-only' mandate.

Why this answer

Blocking TCP port 80 and allowing only TCP port 443 at the network perimeter ensures that only HTTPS traffic can enter or leave the network. This is the most effective method because it directly enforces the protocol restriction at the firewall, preventing any HTTP traffic from bypassing encryption. Allowing both ports would permit unencrypted HTTP, while using a proxy or blocking port 443 would either add unnecessary complexity or deny legitimate HTTPS traffic.

Exam trap

The trap here is that candidates may think allowing both ports 80 and 443 is acceptable for flexibility, but the question explicitly requires only HTTPS, so blocking port 80 is essential to enforce encryption at the perimeter.

How to eliminate wrong answers

Option B is wrong because allowing both TCP port 80 and 443 permits unencrypted HTTP traffic, which violates the requirement to allow only HTTPS. Option C is wrong because using a proxy server to decrypt all traffic does not enforce the restriction at the network perimeter; it adds overhead and may introduce privacy or compliance issues, and it does not block port 80 by itself. Option D is wrong because blocking TCP port 443 would deny all HTTPS traffic, which is the opposite of the requirement to allow only HTTPS.

468
MCQeasy

An organization uses a version control system for all software development. Which practice best ensures that code changes are reviewed for security issues before merging into the main branch?

A.Requiring all pull requests to be approved by at least one peer reviewer.
B.Configuring the CI pipeline to run static analysis tools only on the main branch.
C.Enforcing that all commits pass automated unit tests before merging.
D.Using pre-commit hooks to scan for secrets in code before commit.
AnswerA

Requiring peer review for all pull requests is a critical security control because human reviewers can identify complex logical flaws, design vulnerabilities, and business logic errors that automated static analysis tools often miss. This manual inspection allows for a deeper understanding of the code's intent and potential misuse, ensuring adherence to secure coding standards and architectural principles before changes are integrated into the main codebase. It provides an essential layer of defense against subtle security defects.

Why this answer

Requiring pull request approval by at least one peer reviewer ensures that code changes are manually inspected for security flaws before merging into the main branch. This practice leverages human expertise to catch logic errors, insecure patterns, and design weaknesses that automated tools might miss, aligning with the principle of defense in depth in the software development lifecycle.

Exam trap

The trap here is that candidates often confuse automated security testing (like SAST in CI) with the human review process, assuming that automated checks alone are sufficient for security, whereas the CISSP emphasizes the necessity of peer review for catching complex security flaws that tools cannot reliably detect.

How to eliminate wrong answers

Option B is wrong because running static analysis tools only on the main branch fails to catch security issues before they are merged, allowing vulnerable code to enter the main branch undetected. Option C is wrong because automated unit tests primarily verify functional correctness, not security vulnerabilities, and they do not involve human review of security-specific concerns. Option D is wrong because pre-commit hooks for secret scanning only prevent accidental exposure of credentials at commit time, but do not provide a comprehensive security review of the code logic or architecture.

469
MCQhard

A security team is investigating a vulnerability where an attacker can intercept and modify data as it moves between processes within a CPU's secure enclave. Which technology is designed to protect against such attacks by creating a trusted execution environment?

A.Trusted Platform Module (TPM)
B.Intel Software Guard Extensions (SGX)
C.Measured Boot
D.Secure Boot
AnswerB

Intel Software Guard Extensions (SGX) is a set of CPU instructions that allows developers to protect specific code and data from disclosure or modification. It achieves this by creating "enclaves," which are isolated, hardware-protected memory regions within an application's address space. Even if the operating system, hypervisor, or other privileged software is compromised, the code and data inside an SGX enclave remain protected, making it suitable for mitigating vulnerabilities that target runtime execution integrity and confidentiality.

Why this answer

Intel SGX creates a trusted execution environment (enclave) inside the CPU that isolates code and data from the rest of the system, including the OS and hypervisor, protecting against interception and modification of data in use. It encrypts enclave memory and enforces access controls at the hardware level, which directly addresses intra-CPU tampering between processes. This is why SGX is the correct answer for protecting data within a secure enclave.

Exam trap

CISSP often tests the distinction between hardware security for data at rest (TPM), boot integrity (Secure Boot/Measured Boot), and runtime isolation (SGX), causing candidates to pick TPM for questions about protecting data in use.

How to eliminate wrong answers

Option A is wrong because a TPM is a separate hardware chip used for cryptographic key storage, platform integrity measurement, and attestation — it does not create an isolated execution environment for running code. Option C is wrong because Measured Boot records hashes of boot components into TPM PCRs to detect tampering during startup; it is a boot-integrity mechanism, not a runtime enclave. Option D is wrong because Secure Boot verifies the signatures of bootloaders and firmware to prevent unauthorized code from loading at boot, but it does not protect data in use inside the CPU after the system is running.

470
MCQmedium

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

A.ISO/IEC 27001
B.NIST Cybersecurity Framework
C.COBIT 2019
D.ITIL
AnswerD

ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing best practices for IT service management (ITSM). It specifically guides organizations through the entire service lifecycle, encompassing Service Strategy, Design, Transition, Operation, and Continual Service Improvement, making it ideal for managing the full journey of IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) is the framework specifically focused on IT service management, providing guidance on aligning IT services with business needs through a service lifecycle (strategy, design, transition, operation, continual service improvement). Its service lifecycle model is the defining characteristic referenced in the question.

Exam trap

CISSP often tests the COBIT-versus-ITIL distinction — candidates pick COBIT because it sounds like a governance framework, but the 'service lifecycle' and 'aligning IT services with business needs' wording points specifically to ITIL.

How to eliminate wrong answers

Option A (ISO/IEC 27001) is wrong because it is an information security management standard specifying requirements for an ISMS, not an IT service alignment or service lifecycle framework. Option B (NIST Cybersecurity Framework) is wrong because it addresses cybersecurity risk management through the Identify/Protect/Detect/Respond/Recover functions, not IT service delivery alignment. Option C (COBIT 2019) is wrong because it is an IT governance and management framework focused on control objectives and enterprise governance of IT, not a service lifecycle model.

471
MCQeasy

Which wireless security protocol replaces the pre-shared key (PSK) authentication with Simultaneous Authentication of Equals (SAE) to provide stronger security and forward secrecy?

A.WPA3
B.WEP
C.WPA2 with TKIP
D.WPA2 with CCMP
AnswerA

WPA3 significantly enhances wireless security by replacing the vulnerable Pre-Shared Key (PSK) 4-way handshake with the Simultaneous Authentication of Equals (SAE) protocol, also known as Dragonfly. SAE is a password-authenticated key agreement (PAKE) protocol that establishes a secure session key without ever transmitting the password directly. This robust cryptographic exchange provides stronger protection against offline dictionary attacks and ensures forward secrecy, making it the correct answer for replacing the PSK mechanism.

Why this answer

WPA3 replaces the Pre-Shared Key (PSK) authentication used in WPA2 with Simultaneous Authentication of Equals (SAE), defined in IEEE 802.11-2016 and specified in RFC 7664. SAE provides forward secrecy by using a Diffie-Hellman key exchange that ensures even if the long-term password is compromised, past session keys remain secure. This eliminates vulnerabilities to offline dictionary attacks that plague WPA2-PSK.

Exam trap

Candidates often confuse encryption strength with authentication improvements. While WPA2 with CCMP uses AES encryption, this question focuses on authentication (PSK vs SAE), not encryption. The key difference is that SAE provides forward secrecy and resistance to offline dictionary attacks, which are unique to WPA3.

How to eliminate wrong answers

Option B (WEP) is wrong because it uses the RC4 stream cipher with a static key and no authentication mechanism like SAE, making it completely insecure and deprecated. Option C (WPA2 with TKIP) is wrong because TKIP is a legacy encryption protocol that still relies on PSK authentication and does not implement SAE or forward secrecy; it was designed as a temporary fix for WEP. Option D (WPA2 with CCMP) is wrong because while CCMP uses AES-based encryption, WPA2 still uses PSK or 802.1X for authentication, not SAE, and lacks forward secrecy.

472
MCQeasy

A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?

A.Dynamic Application Security Testing (DAST)
B.Interactive Application Security Testing (IAST)
C.Static Application Security Testing (SAST)
D.Software Composition Analysis (SCA)
AnswerA

DAST tests a running application from the outside, simulating attacks similar to those a real attacker would use. It can identify vulnerabilities such as injection, authentication flaws, and misconfigurations that only appear at runtime. This directly meets the requirement to test for security vulnerabilities by simulating real-world attacks against the deployed application.

Why this answer

Dynamic Application Security Testing (DAST) is designed to simulate real-world attacks by testing a running application from the outside. It identifies vulnerabilities that manifest at runtime, such as input validation errors and authentication flaws. Unlike SAST or SCA, DAST actively probes the application as an attacker would, making it the appropriate choice for this requirement.

Exam trap

The trap here is confusing DAST with other testing methods like SAST or IAST, which do not simulate external attacks against a running application.

473
MCQeasy

Which of the following is the primary purpose of a security audit?

A.To identify vulnerabilities in the network
B.To compare security controls against a defined standard
C.To perform an informal evaluation of security posture
D.To exploit vulnerabilities and demonstrate impact
AnswerB

The core function of a security audit is to systematically evaluate an organization's security posture by comparing its implemented security controls, policies, and procedures against a predetermined set of criteria. These criteria typically include industry best practices, regulatory requirements (e.g., GDPR, HIPAA), internal policies, or recognized security frameworks (e.g., ISO 27001, NIST CSF). This comparison determines the degree of compliance and identifies any deviations or gaps that need remediation.

Why this answer

A security audit's primary purpose is to systematically evaluate an organization's security controls against a predefined standard, such as ISO 27001, NIST SP 800-53, or PCI DSS. This comparison verifies compliance and identifies gaps, not merely vulnerabilities. Unlike a vulnerability assessment or penetration test, an audit focuses on adherence to criteria, not exploitation or informal review.

Exam trap

The trap here is confusing a security audit with a vulnerability assessment or penetration test, leading candidates to pick 'identify vulnerabilities' or 'exploit vulnerabilities' instead of recognizing the audit's formal, standards-based comparison purpose.

How to eliminate wrong answers

Option A is wrong because identifying vulnerabilities is the goal of a vulnerability assessment, not a security audit; an audit compares controls to a standard, not just finds weaknesses. Option C is wrong because a security audit is a formal, structured evaluation with defined criteria, not an informal assessment of posture. Option D is wrong because exploiting vulnerabilities to demonstrate impact is the objective of a penetration test, which is distinct from an audit's compliance-focused comparison.

474
MCQhard

A data warehouse contains anonymized customer transaction data used for analytics. The anonymization process removed direct identifiers and applied k-anonymity with k=10. An attacker obtains the dataset and attempts to re-identify individuals using auxiliary information. Which of the following best describes the residual privacy risk?

A.No risk because anonymization eliminates all PII
B.High risk because k=10 is too small to provide meaningful privacy
C.Low risk because k=10 ensures a group of at least 10 individuals
D.Moderate risk because k-anonymity does not protect against attribute disclosure if the group is homogeneous
AnswerD

This option correctly identifies a fundamental limitation of k-anonymity, known as the homogeneity attack. If all individuals within an equivalence class (a group of k records sharing identical quasi-identifiers) also share the same value for a sensitive attribute, then that attribute is effectively disclosed for everyone in the group. Despite the anonymity of individual identity, the sensitive information becomes known, leading to attribute disclosure and a moderate level of risk.

Why this answer

k-anonymity means each record is indistinguishable from at least k-1 other records, but attacks like homogeneity or background knowledge can still lead to re-identification, especially if auxiliary data is available.

475
MCQeasy

What type of DLP system monitors data in motion across the network?

A.Network DLP
B.Storage DLP
C.Endpoint DLP
D.Cloud DLP
AnswerA

Network DLP systems specifically monitor "data in motion" by inspecting network traffic as it traverses the organization's boundaries or internal segments. These solutions typically employ deep packet inspection (DPI) to analyze data streams for sensitive content, patterns, or metadata, preventing unauthorized transmission over protocols like HTTP, FTP, or email. They are often deployed at network egress points or internal chokepoints to enforce data security policies.

Why this answer

Network DLP (A) is designed to monitor data in motion across the network, inspecting traffic for sensitive information being transmitted. It sits at network egress points and analyzes protocols like HTTP, SMTP, and FTP to prevent data exfiltration. This directly matches the requirement to monitor data in motion.

Exam trap

The trap is confusing the three states of data (motion, rest, use) and selecting endpoint or storage DLP; the key is recognizing that 'in motion across the network' specifically points to Network DLP.

How to eliminate wrong answers

Option B is wrong because Storage DLP monitors data at rest in storage repositories (e.g., file servers, databases), not data moving across the network. Option C is wrong because Endpoint DLP monitors data on endpoint devices (e.g., laptops, desktops) and controls actions like copy/paste or USB transfers, but it does not focus on network traffic. Option D is wrong because Cloud DLP typically refers to scanning data at rest in cloud storage or SaaS applications, not data in motion across the network.

476
MCQhard

During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?

A.CPU registers → cache → RAM → swap → disk
B.Disk → RAM → CPU registers → cache → swap
C.RAM → CPU registers → swap → disk → remote logging
D.Swap → RAM → cache → CPU registers → disk
AnswerA

This sequence accurately represents the decreasing order of volatility for digital evidence, which is crucial for forensic collection. CPU registers are the most volatile, holding data only during active processing and being lost immediately upon power loss or context switch. Cache memory is slightly less volatile but still transient, followed by RAM, which requires continuous power to retain data. Swap space, residing on disk, is less volatile than RAM but more dynamic than persistent disk storage, making disk the least volatile and most persistent data source.

Why this answer

The order of volatility (RFC 3227) dictates that the most ephemeral data must be captured first because it disappears fastest. CPU registers and cache lose their contents within nanoseconds to milliseconds, RAM persists only while powered, swap holds paged memory on disk, and the disk itself is the most persistent. Therefore CPU registers → cache → RAM → swap → disk is the correct forensic collection sequence.

Exam trap

CISSP often tests the order of volatility by presenting plausible-looking sequences that swap adjacent layers (e.g., RAM before cache, or swap before RAM), so candidates who memorize only 'memory before disk' without the full hierarchy pick the wrong ordering.

How to eliminate wrong answers

Option B is wrong because it reverses the order of volatility, starting with the most persistent medium (disk) and ending with the most ephemeral (CPU registers), which would guarantee loss of critical evidence. Option C is wrong because it places RAM before CPU registers and cache, and it inserts 'remote logging' as a final step even though remote logs are network-persistent and not part of the local volatility hierarchy. Option D is wrong because it starts with swap (a disk-based structure) before RAM and CPU registers, inverting the fundamental principle that memory-resident data must be captured before disk-resident data.

477
MCQmedium

Which of the following is a key requirement under the GDPR regarding personal data breaches?

A.Notify the supervisory authority within 72 hours
B.Conduct a privacy impact assessment within 30 days
C.Report the breach to law enforcement immediately
D.Notify affected individuals within 24 hours
AnswerA

GDPR Article 33 mandates that in the event of a personal data breach, the data controller must notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This notification is required unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification must include details such as the nature of the breach, categories of data subjects and records concerned, and the likely consequences.

Why this answer

Under GDPR Article 33, a controller must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is the core regulatory deadline tested here. Notification to individuals (Article 34) is only required when the breach poses a high risk, and it has no fixed 24-hour deadline.

Exam trap

CISSP often tests the confusion between the 72-hour supervisory-authority deadline and the separate, risk-based individual-notification obligation, tempting candidates to pick a fabricated 24-hour figure.

How to eliminate wrong answers

Option B is wrong because a Data Protection Impact Assessment (DPIA) is required under Article 35 before processing that is likely to result in high risk — it is not a breach-response action and has no 30-day breach trigger. Option C is wrong because GDPR does not mandate immediate law-enforcement reporting; that may be a separate legal or sectoral obligation, not a GDPR breach requirement. Option D is wrong because the 24-hour individual-notification deadline does not exist in GDPR; individual notification is risk-based and 'without undue delay,' not a fixed 24-hour clock.

478
MCQmedium

A development team is implementing a web application that allows users to search for products. To prevent SQL injection attacks, which secure coding practice should be applied?

A.Input validation using a blacklist of SQL keywords
B.Parameterized queries with prepared statements
C.Output encoding of user input
D.Using stored procedures exclusively
AnswerB

Parameterized queries with prepared statements are the most effective defense against SQL injection vulnerabilities. By separating the SQL code from user-supplied data, the database engine can distinguish between the query structure and the values to be inserted, updated, or retrieved. This mechanism ensures that user input is always treated as literal data, preventing it from being interpreted as executable SQL commands.

Why this answer

Parameterized queries with prepared statements (Option B) are the definitive defense against SQL injection because they separate SQL logic from user-supplied data. The database engine compiles the query structure first, then binds input values as parameters, ensuring that malicious input cannot alter the intended SQL command. This approach is language-agnostic and works across all modern database interfaces (e.g., JDBC, PDO, ADO.NET).

Exam trap

The trap here is that candidates often confuse stored procedures as a silver bullet for SQL injection, failing to realize that the security lies in how parameters are bound, not in the procedure container itself.

How to eliminate wrong answers

Option A is wrong because blacklisting SQL keywords is inherently incomplete and easily bypassed; attackers can use encoding, comments, or alternative syntax (e.g., CHAR(), CONCAT()) to evade the filter. Option C is wrong because output encoding (e.g., HTML entity encoding) is designed to prevent cross-site scripting (XSS), not SQL injection, which occurs at the database layer before output is rendered. Option D is wrong because stored procedures alone do not prevent SQL injection if dynamic SQL is constructed within the procedure; the protection comes only when parameters are used inside the stored procedure, not from the procedure itself.

479
Multi-Selecteasy

Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)

Select 2 answers
A.It is only available in cloud environments
B.It runs as a separate virtual machine
C.It requires a TPM chip
D.It provides hardware-enforced isolation from the main OS
E.It protects code and data from unauthorized access even by the OS
AnswersD, E

A fundamental characteristic of a Trusted Execution Environment (TEE) is its ability to provide robust hardware-enforced isolation from the main operating system. This isolation ensures that code and data running within the TEE are protected from unauthorized access or tampering by the rich OS, hypervisor, or any other software running in the less privileged 'normal world.' This hardware-level separation is critical for maintaining the integrity and confidentiality of sensitive computations.

Why this answer

Option D is correct because a TEE, such as Intel SGX enclaves or ARM TrustZone secure world, relies on CPU hardware mechanisms to create an isolated execution context that is separated from the rich operating system, so the main OS cannot access the enclave's memory. Option E is correct because the whole purpose of a TEE is to keep code and data confidential and integrity-protected even against a compromised or malicious host OS, hypervisor, or other privileged software, using hardware-based memory encryption and access control. Option A is incorrect because TEEs are available on client devices, mobile phones, and embedded systems, not only in cloud environments.

Option B is incorrect because a TEE is not a separate virtual machine; it is a hardware-isolated execution environment within a processor, distinct from VM-based isolation. Option C is incorrect because a TEE does not require a discrete TPM chip; it uses CPU-level features, and a TPM is a separate component for key storage and attestation, not a prerequisite for a TEE.

Exam trap

CISSP often tests the misconception that a TEE requires a TPM or is a cloud-only construct, when in fact the defining traits are hardware isolation from the OS and protection even against the OS itself.

480
MCQmedium

A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?

A.Three
B.Four
C.One
D.Two
AnswerD

This option is correct because the authentication system leverages two distinct types of factors to verify a user's identity. The password serves as the 'something you know' factor, requiring the user to recall a secret piece of information. The SMS One-Time Password (OTP), delivered to a registered mobile device, functions as the 'something you have' factor, relying on the user's possession of that specific device. This combination of two different factor categories precisely defines two-factor authentication (2FA).

Why this answer

Password is Type 1 (something you know), SMS OTP is Type 2 (something you have, as the phone is possessed). Only two factor types are used.

481
MCQhard

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Attribute-Based Access Control (ABAC)
AnswerA

DAC binds permissions to resource owners, who grant or revoke access at their discretion. This directly satisfies the stem's requirement that the owner determines both who may access the resource and which permissions they hold, unlike mandatory or role-based models where policy is centrally imposed.

Why this answer

Discretionary Access Control (DAC) allows the resource owner to control access at their discretion.

482
MCQmedium

An organization is required to retain audit logs for seven years due to regulatory compliance. The logs are currently stored on a file server that is approaching capacity. What is the BEST way to manage log storage?

A.Reduce the logging level to generate less data.
B.Delete logs older than one year.
C.Increase the frequency of log rotation.
D.Compress logs and move them to low-cost archival storage.
AnswerD

Compressing logs significantly reduces their storage footprint, making them more economical to retain over extended periods. Moving these compressed logs to low-cost archival storage, such as tape libraries, object storage, or cloud cold storage tiers, directly addresses the challenge of managing large volumes of data while meeting the seven-year retention requirement. This strategy ensures data integrity and availability for compliance and forensic needs without incurring prohibitive costs on primary storage systems.

Why this answer

It balances the seven-year retention requirement with storage constraints by compressing logs (reducing size) and moving them to low-cost archival storage (e.g., cold storage or tape). This preserves data integrity and accessibility for compliance audits while freeing up space on the primary file server.

Exam trap

The trap here is that candidates may confuse operational efficiency (log rotation) with long-term retention, failing to recognize that compliance mandates absolute retention periods that cannot be circumvented by deletion or reduced logging.

How to eliminate wrong answers

Option A is wrong because reducing the logging level would omit critical security events, violating the principle of complete audit trails and potentially failing compliance requirements. Option B is wrong because deleting logs older than one year directly violates the seven-year retention mandate, exposing the organization to regulatory penalties. Option C is wrong because increasing log rotation frequency merely creates more files without addressing the underlying capacity issue; it does not reduce total data volume or extend retention capabilities.

483
MCQhard

During a security assessment, a consultant discovers that a legacy VPN solution uses MS-CHAPv2 for authentication and does not support IKE. The protocol is known to be vulnerable to dictionary attacks. Which VPN protocol is most likely being used?

A.PPTP
B.IPsec with IKEv2
C.SSL/TLS VPN
D.L2TP/IPsec
AnswerA

PPTP (Point-to-Point Tunneling Protocol) is a legacy VPN protocol that relies heavily on MS-CHAPv2 for authentication. MS-CHAPv2 has well-documented cryptographic weaknesses, including susceptibility to offline dictionary attacks and specific attacks that can extract the NT password hash, compromising user credentials. Furthermore, PPTP lacks a robust key exchange mechanism like IKE, making its session key negotiation vulnerable and failing to provide forward secrecy, which is a critical security requirement for modern VPNs.

Why this answer

MS-CHAPv2 is a Microsoft proprietary authentication protocol used by PPTP (Point-to-Point Tunneling Protocol). PPTP does not support IKE (Internet Key Exchange) and relies on MS-CHAPv2, which is vulnerable to dictionary attacks due to its weak hashing and lack of mutual authentication. The combination of MS-CHAPv2 authentication and the absence of IKE support directly points to PPTP as the VPN protocol in use.

Exam trap

The trap here is that candidates may confuse L2TP/IPsec with PPTP because both can use MS-CHAPv2, but L2TP/IPsec requires IKE and typically uses IPsec for encryption, whereas PPTP does not support IKE and relies solely on MS-CHAPv2 for authentication.

How to eliminate wrong answers

Option B is wrong because IPsec with IKEv2 uses IKE (Internet Key Exchange) for key management and authentication, and it does not use MS-CHAPv2; it typically relies on certificates, pre-shared keys, or EAP. Option C is wrong because SSL/TLS VPNs use TLS for encryption and authentication, not MS-CHAPv2, and they do not involve IKE. Option D is wrong because L2TP/IPsec uses IKE for key exchange and typically authenticates via IPsec mechanisms (e.g., certificates or PSK), not MS-CHAPv2; L2TP itself is a tunneling protocol that requires IPsec for encryption, and MS-CHAPv2 is not a standard authentication method for L2TP/IPsec.

484
MCQhard

During a security audit, it is discovered that a company's data classification labels are inconsistently applied across different departments. Which of the following is the BEST long-term solution to ensure consistent data classification?

A.Conduct annual retraining on data classification policies
B.Implement automated data classification tools that apply labels based on content and context
C.Adopt a single classification level for all data to eliminate confusion
D.Assign a data owner in each department to manually review and classify data
AnswerB

Automated data classification tools leverage machine learning, regular expressions, and predefined policies to scan, identify, and label data based on its content (e.g., PII, PCI data) and context (e.g., location, creator, access patterns). This significantly reduces human error and subjectivity, ensuring consistent, scalable, and real-time application of classification labels across vast and dynamic data repositories. Such tools enforce organizational policies uniformly, enhancing compliance and security posture effectively.

Why this answer

Automated data classification tools use content inspection (e.g., regex patterns, keyword matching) and contextual analysis (e.g., file location, creator, metadata) to consistently apply labels across the enterprise. This eliminates human error and variability between departments, ensuring uniform enforcement of the classification policy without relying on manual interpretation or periodic training.

Exam trap

The trap here is that candidates often choose annual retraining (A) as a 'best practice' for policy adherence, but the question specifically asks for the 'BEST long-term solution' to ensure consistency, which requires automation to remove human subjectivity.

How to eliminate wrong answers

Option A is wrong because annual retraining is a temporary, human-dependent solution that does not prevent inconsistent application between training cycles; it fails to address the root cause of manual variability. Option C is wrong because adopting a single classification level for all data violates the principle of least privilege and the need for granular access controls, effectively negating the purpose of data classification. Option D is wrong because assigning a data owner in each department to manually review and classify data perpetuates the inconsistency problem, as different owners will apply subjective judgment, leading to the same cross-departmental variability.

485
MCQeasy

A company has multiple offices connected via a WAN. They want to ensure that all traffic between offices is encrypted and authenticated. Which technology is most appropriate?

A.MPLS
B.DMVPN
C.SSL VPN
D.IPsec VPN
AnswerD

IPsec (Internet Protocol Security) is a suite of protocols that provides cryptographic security services at the IP layer, ensuring confidentiality, integrity, and authenticity of data packets. It is the industry standard for establishing secure, encrypted tunnels between networks, making it ideal for connecting multiple office locations over an untrusted WAN. IPsec VPNs utilize protocols like Authentication Header (AH) and Encapsulating Security Payload (ESP) to secure all traffic flowing between the connected sites, providing robust site-to-site connectivity.

Why this answer

IPsec VPN is the most appropriate technology because it operates at the network layer (Layer 3) and provides both encryption and authentication for all IP traffic between sites over an untrusted WAN. It uses protocols such as ESP (Encapsulating Security Payload) for confidentiality and AH (Authentication Header) or ESP for integrity and authentication, ensuring that all inter-office traffic is protected in transit.

Exam trap

ISC2 often tests the distinction between VPN technologies by presenting DMVPN as a tempting answer because it is a Cisco-specific solution for dynamic site-to-site VPNs, but the trap is that DMVPN is a framework that relies on IPsec for encryption and authentication, not a replacement for it.

How to eliminate wrong answers

Option A (MPLS) is wrong because MPLS is a label-switching technology that improves performance and traffic engineering but does not inherently provide encryption or authentication; it relies on underlying security mechanisms like IPsec for confidentiality. Option B (DMVPN) is wrong because DMVPN is a dynamic VPN architecture that simplifies hub-and-spoke or spoke-to-spoke VPN deployments, but it still requires IPsec for encryption and authentication; it is not a standalone encryption technology. Option C (SSL VPN) is wrong because SSL VPN typically operates at the application or transport layer and is designed for remote user access to specific applications or networks, not for site-to-site encryption of all traffic between offices; it lacks the network-layer transparency and scalability for full site-to-site connectivity.

486
MCQmedium

A security analyst is reviewing logs from a web application firewall (WAF) and notices multiple requests containing the payload "1=1--" in the query string. The analyst suspects a SQL injection attack. Which of the following is the BEST immediate action to validate the suspicion?

A.Use a manual SQL injection tool like sqlmap to test the application.
B.Implement prepared statements in the application code.
C.Run a vulnerability scan with a SQL injection detection module.
D.Check the application logs for database error messages.
AnswerD

Reviewing application logs for database error messages is the most immediate, passive, and non-intrusive method to validate a suspected SQL injection. Successful SQL injection attempts, especially those designed to extract information or manipulate queries, often result in distinct database errors (e.g., syntax errors, unhandled exceptions, or specific database-level warnings) that are logged by the application or database server. These errors provide direct, forensic evidence of an attempted or successful injection, allowing the analyst to confirm the vulnerability without active probing or risk to the system.

Why this answer

Checking the application logs for database error messages is the best immediate action because SQL injection attempts often trigger verbose database errors (e.g., MySQL syntax errors, ODBC error codes) that confirm the injection point. This passive validation requires no additional tools and directly correlates the WAF alert with backend behavior, avoiding the risk of actively exploiting a live system.

Exam trap

The trap here is that candidates often choose an active testing tool (Option A) or a remediation step (Option B) instead of recognizing that passive log review is the safest and most immediate validation method in a security assessment context.

How to eliminate wrong answers

Option A is wrong because using a manual SQL injection tool like sqlmap on a production system without prior validation could cause data corruption, denial of service, or legal/authorization violations, and is not an immediate passive validation step. Option B is wrong because implementing prepared statements is a long-term remediation measure, not a validation technique; it does not help confirm whether the observed payload actually succeeded. Option C is wrong because running a vulnerability scan with a SQL injection detection module is an active assessment that may introduce additional load or false positives, and is less immediate than checking existing logs for direct evidence of exploitation.

487
MCQhard

A development team is implementing cryptographic functions for a new application. They need to store passwords securely. Which of the following is the most appropriate approach?

A.Use a key derivation function (e.g., bcrypt) with a per-user salt
B.Encrypt passwords using AES-256 with a static key
C.Store passwords in plaintext but in a protected database
D.Hash passwords with SHA-256 without salt
AnswerA

Using a key derivation function (KDF) like bcrypt with a per-user salt is the most secure method for storing passwords. Bcrypt is specifically designed to be computationally intensive and slow, making brute-force attacks economically infeasible by requiring significant processing power for each guess. The unique, randomly generated per-user salt ensures that even identical passwords produce different hashes, effectively neutralizing precomputed rainbow table attacks and dictionary attacks across multiple user accounts.

Why this answer

Passwords must be stored using a slow, salted, adaptive key derivation function such as bcrypt, scrypt, Argon2, or PBKDF2. A per-user salt prevents rainbow-table and precomputation attacks, and the deliberately slow work factor makes brute-force and GPU-accelerated cracking impractical. bcrypt with a per-user salt is the canonical correct answer for secure password storage.

Exam trap

CISSP often tests the confusion between hashing and encryption for passwords — candidates pick AES encryption thinking it is 'stronger,' missing that reversibility is the fatal flaw, and they underestimate how fast unsalted SHA-256 can be brute-forced.

How to eliminate wrong answers

Option B is wrong because encrypting passwords with AES-256 using a static key is reversible — anyone who obtains the key can decrypt all passwords, and a static key shared across the application is a single point of catastrophic failure. Option C is wrong because storing passwords in plaintext, even in a 'protected' database, means a single database breach exposes every credential directly; this violates every password-storage standard (NIST SP 800-63B, OWASP ASVS). Option D is wrong because SHA-256 without salt is a fast general-purpose hash vulnerable to rainbow tables and GPU brute-force (billions of hashes per second), and identical passwords produce identical hashes, enabling credential-stuffing correlation.

488
Multi-Selectmedium

An access control policy grants Read and Write permissions on a specific target object and includes a network source condition restricting access to a trusted IP range. Which TWO statements about this policy are true?

Select 2 answers
A.The policy grants full administrative access to the target object.
B.The policy implicitly denies access to subjects outside the specified IP range.
C.The policy allows all actions on the target object.
D.The policy applies to all resources in the organization.
E.The policy allows read and write operations on the target object.
AnswersB, E

The Condition element specifies that the Allow effect is only active when the source IP address of the request is within the 10.0.0.0/8 range. For any request originating from an IP address outside this specified range, the condition evaluates to false, causing the Allow statement to not apply. In AWS IAM, if no explicit Allow statement applies and no explicit Deny statement exists, the default behavior is an implicit deny, effectively blocking access.

Why this answer

Option B is correct because an access control policy that includes a network source condition restricting access to a trusted IP range will not match requests originating from outside that range, so those subjects are implicitly denied access under the default-deny model of access control. Option E is correct because the policy explicitly grants Read and Write permissions on the specific target object, meaning read and write operations on that object are allowed for subjects that also satisfy the network source condition. Option A is incorrect because Read and Write permissions do not constitute full administrative access, which would require broader privileges such as ownership, permission management, or delete rights.

Option C is incorrect because the policy only grants Read and Write, not all possible actions on the object. Option D is incorrect because the policy targets a specific object rather than all resources in the organization.

Exam trap

Do not assume a policy grants more than it explicitly states; explicit permissions and conditions define the authorized scope.

489
MCQmedium

A security analyst is conducting a vulnerability scan of a web application. The scan identifies several vulnerabilities, but the analyst wants to minimize false positives. Which type of vulnerability scan would be most appropriate?

A.External scan
B.Passive scan
C.Authenticated scan
D.Unauthenticated scan
AnswerC

An authenticated scan is performed with valid user credentials, allowing the scanner to interact with the application as a legitimate, logged-in user. This approach provides a comprehensive view of vulnerabilities, including those in protected areas, authorization flaws, and business logic issues that are only accessible post-authentication. By simulating a real user, it significantly reduces false positives and offers a more accurate security posture assessment of the application's internal workings.

Why this answer

An authenticated scan uses valid credentials to log into the target system, allowing the scanner to access deeper configuration details and patch levels. This reduces false positives by distinguishing between vulnerabilities that are actually present and those that appear due to incomplete visibility, such as missing patches that are actually applied but not visible to an unauthenticated scanner.

Exam trap

The trap here is that candidates often assume an unauthenticated scan is more thorough because it tests from an attacker's perspective, but they miss that authenticated scans provide the internal visibility needed to eliminate false positives by verifying actual patch levels and configurations.

How to eliminate wrong answers

Option A is wrong because an external scan is performed from outside the network boundary and typically lacks internal context, leading to a higher rate of false positives due to incomplete visibility of internal services and configurations. Option B is wrong because a passive scan only monitors network traffic without actively probing systems, so it cannot verify the presence of vulnerabilities and often generates false positives from observed but unconfirmed behaviors. Option D is wrong because an unauthenticated scan does not use credentials, so it cannot access restricted areas of the application or system, resulting in many false positives from assumptions about missing patches or misconfigurations that may not actually exist.

490
MCQhard

During a SOC 2 audit, the auditor evaluates controls over a period of time to assess their operating effectiveness. Which type of SOC report is being performed?

A.SOC 2 Type II
B.SOC 1 Type I
C.SOC 3
D.SOC 2 Type I
AnswerA

A SOC 2 Type II report provides a comprehensive evaluation of a service organization's controls related to the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy). Crucially, it assesses both the suitability of the design of these controls and their operating effectiveness over a defined period, typically 6-12 months. This report offers user entities a high level of assurance that controls were consistently applied and functioned as intended throughout the audit period.

Why this answer

A SOC 2 Type II report evaluates the operating effectiveness of controls over a period of time (typically 3–12 months), which is exactly what the auditor is doing here. Type II includes testing of control activities across the audit period, unlike Type I which only assesses design at a point in time.

Exam trap

CISSP often tests the distinction between Type I (point-in-time design) and Type II (operating effectiveness over time), and candidates confuse SOC 1/2/3 scope with report type.

How to eliminate wrong answers

Option B is wrong because SOC 1 Type I focuses on financial reporting controls and only at a point in time, not over a period. Option C is wrong because SOC 3 is a general-use report that provides only a seal/opinion without detailed control descriptions or period testing. Option D is wrong because SOC 2 Type I assesses control design at a single point in time, not operating effectiveness over a period.

491
MCQhard

To enforce separation of duties in a CI/CD pipeline, what architectural principle should be implemented?

A.Allow all developers to deploy their own code to production
B.Use a single approval gate without role distinction
C.Grant a single DevOps team full access to both source code and deployment
D.Require different permissions for committing code vs. deploying to production
AnswerD

Requiring distinct permissions for committing code into a repository versus deploying that code to a production environment is a fundamental application of separation of duties. This ensures that individuals responsible for developing and modifying code are not the same ones authorized to release it, thereby introducing an independent control point. It mitigates risks associated with insider threats and accidental errors by distributing critical responsibilities.

Why this answer

Separation of duties in a CI/CD pipeline requires distinct permissions for code commits and production deployments. This ensures that no single individual can introduce and deploy malicious code without oversight, aligning with the principle of least privilege and auditability. By enforcing role-based access control (RBAC) with separate pipelines for build and release, organizations mitigate the risk of unauthorized changes reaching production.

Exam trap

The trap here is that candidates often confuse 'DevOps' with 'no separation of duties,' assuming a single team should have full access to both code and deployment, when in fact the CISSP requires distinct roles even in agile pipelines to maintain accountability and audit trails.

How to eliminate wrong answers

Option A is wrong because allowing all developers to deploy their own code to production violates separation of duties, removing any independent review or approval gate and increasing the risk of unauthorized or flawed code reaching production. Option B is wrong because a single approval gate without role distinction fails to enforce different responsibilities between developers and operators, allowing the same person who commits code to approve its deployment, which undermines the control. Option C is wrong because granting a single DevOps team full access to both source code and deployment eliminates the separation between development and operations roles, creating a conflict of interest and bypassing the principle of least privilege.

492
MCQmedium

A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?

A.Using data loss prevention (DLP) software
B.Implementing a data classification policy and training employees on labeling and handling procedures
C.Encrypting all data at rest
D.Restricting access to the data through role-based access control
AnswerB

Implementing a robust data classification policy clearly defines what "internal use" data means, outlines specific labeling conventions, and details the mandatory handling procedures for such information. Coupled with comprehensive employee training, this approach directly communicates the organization's expectations and legal obligations to all personnel. This ensures employees understand their responsibilities and the implications of mishandling sensitive data, fostering a culture of compliance.

Why this answer

A data classification policy defines the categories (e.g., Public, Internal Use Only, Confidential) and the required handling procedures for each, and employee training ensures that everyone who creates or handles data knows how to label and protect it. This is the most effective way to communicate handling requirements because it establishes both the rule and the human behavior needed to follow it. Technical controls alone cannot fully prevent inadvertent disclosure by authorized users.

Exam trap

CISSP often tests the difference between administrative controls (policy, training) and technical controls (DLP, encryption, RBAC)—candidates may pick a technical control when the question asks how to communicate requirements to people.

How to eliminate wrong answers

Option A is wrong because DLP software is a technical enforcement tool that detects and blocks policy violations, but it does not communicate handling requirements to employees; it assumes the policy already exists and is known. Option C is wrong because encrypting all data at rest protects against physical theft or unauthorized storage access but does not address inadvertent disclosure by authorized users who can decrypt and share data. Option D is wrong because RBAC restricts access based on roles but does not tell employees how to handle data once they have access, nor does it prevent them from sharing it inappropriately.

493
Multi-Selecteasy

Which TWO of the following are examples of risk response strategies?

Select 2 answers
A.Risk acceptance
B.Risk analysis
C.Risk identification
D.Risk avoidance
E.Risk communication
AnswersA, D

Risk acceptance is a deliberate decision by an organization to acknowledge and bear the potential consequences of a specific risk, often when the cost or effort of implementing other response strategies outweighs the potential impact. This strategy is typically documented, and the organization may establish a contingency plan or simply monitor the risk without further action.

Why this answer

Risk acceptance (A) is a valid risk response strategy because the organization consciously decides to acknowledge a risk and take no proactive action to mitigate it, often documenting the decision and setting aside contingency reserves. Risk avoidance (D) is also a valid risk response strategy because it involves eliminating the risk entirely by changing plans, such as discontinuing a risky activity, technology, or process. These two belong to the standard risk response categories (avoid, transfer, mitigate, accept), so they directly answer the question.

In contrast, risk analysis (B) and risk identification (C) are earlier risk management process steps used to discover and evaluate risks, not strategies for responding to them, and risk communication (E) is an ongoing activity for sharing risk information among stakeholders rather than a response strategy itself.

Exam trap

CISSP often tests the boundary between risk assessment activities (identification, analysis, evaluation) and risk response strategies — the trap is selecting 'risk analysis' or 'risk identification' because they sound like risk management actions when they are inputs to, not outputs of, the response decision.

494
MCQhard

A security architect is reviewing a software design that uses a third-party library for XML parsing. The library is known to be vulnerable to XML External Entity (XXE) attacks. The architect recommends replacing the library. What is the primary risk of XXE attacks that the architect wants to avoid?

A.Disclosure of sensitive files from the server
B.Remote code execution by injecting malicious XML
C.Denial of service (DoS) from entity expansion
D.Cross-site scripting (XSS) delivered via XML response
AnswerA

This is the correct answer. XML External Entity (XXE) vulnerabilities allow an attacker to define or reference external entities within XML documents, which are then processed by the XML parser. By leveraging the `file://` protocol, an attacker can instruct the server to read arbitrary local files, such as `/etc/passwd`, application configuration files, or other sensitive system files, and include their content within the XML parser's response or error messages, leading to unauthorized data disclosure.

Why this answer

XXE attacks exploit XML parsers that process external entities, allowing an attacker to read sensitive files from the server (e.g., /etc/passwd) by referencing them in the entity definition. The primary risk is unauthorized data disclosure, as the parser may include the file content in the response or error message. This directly violates confidentiality, a core security objective.

Exam trap

The CISSP exam often tests the distinction between the primary risk (data disclosure) and secondary risks (DoS, SSRF, or RCE), so candidates mistakenly choose denial of service (Option C) because they recall the 'billion laughs' attack, but the question explicitly asks for the primary risk of XXE.

How to eliminate wrong answers

Option B is wrong because remote code execution via XML is not a direct consequence of XXE; while XXE can sometimes lead to SSRF or file inclusion, it does not inherently execute arbitrary code. Option C is wrong because denial of service from entity expansion (e.g., billion laughs attack) is a separate threat known as XML Bomb or Billion Laughs Attack, not the primary risk of XXE. Option D is wrong because cross-site scripting (XSS) is a client-side injection attack delivered via HTML/JavaScript, not a direct result of server-side XXE processing.

495
MCQeasy

A company's help desk receives many requests from users who have forgotten their passwords. Which solution is MOST effective in reducing these requests while maintaining security?

A.Implement a self-service password reset (SSPR) with identity verification.
B.Increase the password expiration period to 180 days.
C.Use single sign-on for all applications.
D.Reduce the password complexity requirements.
AnswerA

Implement a self-service password reset (SSPR) with identity verification. — SSPR empowers users to reset forgotten passwords independently by leveraging pre-registered identity verification methods, such as multi-factor authentication (MFA) or security questions. This significantly reduces the volume of password reset requests directed to the help desk, freeing up their resources for more complex issues. The integrated identity verification ensures that only the legitimate user can perform the reset, maintaining security while improving operational efficiency.

Why this answer

Self-service password reset (SSPR) with identity verification directly addresses the root cause of help desk calls—forgotten passwords—by allowing users to reset their own passwords after proving their identity via pre-registered methods (e.g., SMS, security questions, or biometrics). This reduces operational overhead while maintaining security through multi-factor verification and policy enforcement, unlike options that weaken security or fail to address the frequency of resets.

Exam trap

The trap here is that candidates often choose SSO (Option C) thinking it eliminates all password-related issues, but they overlook that SSO still requires a primary password and does not address forgotten-password requests for that single credential.

How to eliminate wrong answers

Option B is wrong because increasing the password expiration period to 180 days reduces the frequency of forced changes but does nothing to help users who forget their current password; it may even increase the risk of forgotten passwords due to longer intervals between use. Option C is wrong because single sign-on (SSO) reduces the number of passwords a user must remember but does not eliminate the need for the primary password; if that password is forgotten, the help desk still receives requests, and SSO introduces a single point of failure. Option D is wrong because reducing password complexity requirements weakens security by making passwords easier to guess or brute-force, violating the principle of defense in depth and increasing the risk of unauthorized access.

496
MCQmedium

During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?

A.To speed up the investigation process
B.To document who accessed the evidence and when
C.To encrypt the evidence at rest
D.To store evidence in a fireproof safe
AnswerB

Documenting who accessed the evidence and when is the fundamental purpose of maintaining a chain of custody during a forensic investigation. This process creates an unbroken, verifiable audit trail that identifies every individual who has handled or had control over a piece of evidence, along with the precise dates and times of these interactions. This meticulous record is essential for demonstrating that the evidence has not been tampered with, substituted, or compromised, thereby ensuring its integrity and legal admissibility in court.

Why this answer

The chain of custody is a documented record of who handled evidence, when, where, and for what purpose, from collection through presentation in court. Its primary purpose is to preserve the integrity and admissibility of evidence by showing an unbroken sequence of custody (B). Without it, opposing counsel can challenge that evidence was tampered with or contaminated.

Exam trap

CISSP often tests whether candidates confuse chain of custody (documenting handling) with other evidence controls like encryption or physical storage, or mistakenly believe CoC's purpose is investigative speed.

How to eliminate wrong answers

Option A is wrong because chain of custody does not speed up investigations — it is a control mechanism that can add procedural steps. Option C is wrong because encryption at rest is a separate data-protection control; chain of custody documents handling, not cryptographic protection. Option D is wrong because storing evidence in a fireproof safe is one physical safeguard, but it is not the purpose of the chain of custody, which is about documenting the custody trail.

497
Multi-Selectmedium

A security architect is reviewing a web application's design and identifies several potential vulnerabilities. Which TWO of the following are effective mitigations for cross-site scripting (XSS) attacks?

Select 2 answers
A.Enabling Content Security Policy (CSP)
B.Using CSRF tokens
C.Disabling client-side scripts entirely
D.Implementing parameterized queries
E.Using output encoding
AnswersA, E

Content Security Policy (CSP) is a crucial security mechanism that allows web administrators to define trusted sources for content, such as scripts, stylesheets, and images, that a user agent is permitted to load for a given page. By restricting script execution to only approved origins, CSP significantly mitigates Cross-Site Scripting (XSS) attacks, preventing browsers from executing malicious scripts injected from untrusted sources, even if an injection vulnerability exists. This policy acts as a powerful, browser-enforced second layer of defense.

Why this answer

Option A, enabling Content Security Policy (CSP), is correct because CSP is a browser-enforced response header (e.g., Content-Security-Policy: default-src 'self') that restricts which scripts may execute, blocking inline scripts and untrusted external sources, which directly mitigates XSS. Option E, using output encoding, is correct because encoding untrusted data for the correct context (HTML entity, JavaScript, URL, or CSS encoding) ensures injected markup is rendered as inert text rather than executable script, which is the primary defense against XSS. Option B, using CSRF tokens, does not belong because anti-CSRF tokens defend against cross-site request forgery, a different attack that abuses a victim's authenticated session, not script injection.

Option C, disabling client-side scripts entirely, does not belong because it is an impractical, functionality-breaking measure rather than a targeted XSS mitigation and is not a standard remediation. Option D, implementing parameterized queries, does not belong because prepared statements with bound parameters mitigate SQL injection, not XSS.

Exam trap

CISSP often mixes injection attack mitigations, so candidates who see 'parameterized queries' reflexively associate it with all injection flaws and incorrectly apply it to XSS instead of SQL injection.

498
Multi-Selecthard

Which THREE of the following are common methods used in security assessment and testing? (Select exactly 3.)

Select 3 answers
A.Risk analysis
B.Penetration testing
C.Security auditing
D.Forensic analysis
E.Vulnerability scanning
AnswersB, C, E

Penetration testing is a highly effective and common method for proactively assessing an organization's security posture by simulating real-world attacks. Ethical hackers attempt to exploit identified vulnerabilities in systems, applications, and networks to determine the extent to which an attacker could compromise assets. This hands-on approach provides valuable insights into the effectiveness of existing security controls and the potential impact of a successful breach.

Why this answer

Penetration testing is a common method in security assessment and testing that simulates real-world attacks to identify exploitable vulnerabilities. Unlike vulnerability scanning, which only identifies potential weaknesses, penetration testing actively exploits them to validate security controls and measure the impact of a breach.

Exam trap

The trap here is that candidates confuse risk analysis (a management activity) with security testing, or mistake forensic analysis (a reactive process) for a proactive assessment method, leading them to select options outside the three correct ones (penetration testing, security auditing, vulnerability scanning).

499
MCQeasy

A company's security policy requires that all removable media be encrypted. An employee plugs in a USB drive and is prompted to format it before use. After formatting, the drive is not encrypted. What is the most likely reason?

A.The employee did not enable encryption (e.g., BitLocker To Go) after formatting
B.The USB drive hardware does not support encryption
C.The operating system does not support encryption of removable media
D.The employee used the wrong file system (FAT32 vs NTFS)
AnswerA

Formatting a removable drive prepares it for data storage by creating a file system, but this process does not automatically encrypt the data written to it. Encryption, such as using Windows' BitLocker To Go, is a distinct security measure that must be explicitly enabled by the user after formatting. This separate step involves generating and managing cryptographic keys to protect the data at rest, ensuring confidentiality even if the physical device is compromised.

Why this answer

BitLocker To Go, the native encryption feature for removable drives in Windows, is not automatically enabled when a USB drive is formatted. The employee must explicitly enable encryption (e.g., via BitLocker To Go in Control Panel or by right-clicking the drive and selecting 'Turn on BitLocker') after formatting. Without this step, the drive remains unencrypted, violating the security policy.

Exam trap

The trap here is that candidates assume formatting a drive automatically applies encryption (e.g., thinking BitLocker is enabled by default), when in fact encryption must be explicitly activated after formatting.

How to eliminate wrong answers

Option B is wrong because modern USB drives, even basic ones, support encryption at the software level (e.g., BitLocker To Go) regardless of hardware encryption capabilities; the policy requires encryption, which can be achieved via software. Option C is wrong because Windows (the most common OS for such scenarios) fully supports encryption of removable media via BitLocker To Go, which is available in Pro, Enterprise, and Education editions. Option D is wrong because the file system (FAT32 vs NTFS) does not determine encryption; BitLocker To Go works with both, though NTFS is recommended for full feature support, and the lack of encryption is due to the employee not enabling it, not the file system choice.

500
Multi-Selectmedium

Which THREE of the following are valid methods to reduce the risk of data exfiltration via removable media in a high-security environment?

Select 3 answers
A.Disable USB ports via group policy and physically lock cases
B.Require annual security awareness training on data handling
C.Use full disk encryption on all endpoints
D.Deploy endpoint DLP agents that block copy operations to removable media based on content
E.Implement data classification and labeling policies to raise awareness
AnswersA, D, E

Disabling USB ports via Group Policy establishes a robust logical control, preventing unauthorized mounting of removable storage devices across an organization's endpoints. Concurrently, physically locking computer cases adds a crucial physical security layer, thwarting attempts to bypass software controls or access internal ports for data transfer. This dual-layered approach effectively eliminates the primary vector for data exfiltration using portable media, making it a highly enforceable preventative measure.

Why this answer

Option A is correct because disabling USB mass-storage via Group Policy (e.g., the 'All Removable Storage classes: Deny all access' setting under Computer Configuration\Administrative Templates\System\Removable Storage Access) blocks the technical channel for copying data, and physically locking cases prevents an attacker or insider from bypassing the control by attaching drives to internal ports. Option D is correct because endpoint DLP agents inspect file content and context (e.g., regex/EDM fingerprints for PII, PCI, or classified markings) and enforce block or audit rules specifically on write/copy operations to removable media, which directly mitigates exfiltration even when ports remain enabled for legitimate use. Option E is correct because data classification and labeling (e.g., Public/Internal/Confidential/Secret tags) establishes handling rules that DLP and access controls can enforce, and it raises user awareness so staff recognize which data must never leave on removable media.

Option B is not among the marked answers because annual training alone is a weak, periodic awareness measure that does not technically prevent or block exfiltration. Option C is not among the marked answers because full disk encryption protects data at rest on a lost or stolen endpoint; it does not stop an authorized user from copying plaintext files onto a removable drive.

Exam trap

The trap here is that candidates often confuse full disk encryption (a data-at-rest protection) with a data exfiltration prevention control, failing to recognize that encryption does not block the copy operation itself.

501
MCQeasy

Which digital forensics tool is specifically designed for memory forensics?

A.Volatility
B.Wireshark
C.EnCase
D.FTK
AnswerA

Volatility is an open-source framework specifically designed for memory forensics, enabling investigators to extract and analyze digital artifacts from volatile memory (RAM) dumps. It allows for the examination of running processes, open network connections, loaded kernel modules, and user activity, which are crucial for incident response, malware analysis, and understanding the runtime state of a compromised system. Its capabilities are centered on analyzing live system memory rather than persistent storage.

Why this answer

Volatility is the leading open-source memory forensics framework, designed to analyze RAM dumps (e.g., from LiME, WinPmem, or hibernation files) to extract running processes, network connections, injected code, and encryption keys. It parses memory structures using profiles or symbol tables to reconstruct system state. This makes it the tool specifically built for memory forensics.

Exam trap

CISSP often tests tool-to-purpose mapping, and candidates confuse disk forensics suites (EnCase, FTK) with memory forensics (Volatility) or network forensics (Wireshark).

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer that captures and inspects packet traffic, not memory contents. Option C is wrong because EnCase is a disk forensics suite for imaging and analyzing storage media, not RAM. Option D is wrong because FTK (Forensic Toolkit) is also a disk and file-system forensics platform, not a memory analysis tool.

502
Multi-Selectmedium

Which TWO of the following are effective methods for detecting unauthorized access to a network? (Choose two.)

Select 2 answers
A.Vulnerability scanner
B.Antivirus software
C.Security information and event management (SIEM)
D.Firewall rule review
E.Intrusion detection system (IDS)
AnswersC, E

A Security Information and Event Management (SIEM) system aggregates and correlates security event data from various sources, including network devices, servers, applications, and intrusion detection systems. By analyzing these logs in real-time for anomalous patterns, policy violations, and known attack signatures, SIEM can effectively detect sophisticated unauthorized access attempts and ongoing breaches that might otherwise go unnoticed.

Why this answer

A SIEM aggregates and correlates logs from multiple sources (e.g., firewalls, servers, IDS) in real time, enabling detection of anomalous patterns indicative of unauthorized access. It provides centralized visibility and alerting that can identify a breach even when individual logs appear benign.

Exam trap

The trap here is that candidates confuse vulnerability scanning (proactive) with intrusion detection (reactive), or assume antivirus covers network-level threats, when in fact neither provides real-time monitoring of network access attempts.

503
Drag & Dropmedium

Drag and drop the steps for conducting a risk assessment in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threat/vulnerability identification, likelihood/impact determination, risk calculation, and treatment recommendations.

504
Multi-Selecteasy

Which THREE of the following are recognized roles in asset security?

Select 3 answers
A.Data custodian
B.Data owner
C.Data processor
D.Data subject
E.Data auditor
AnswersA, B, C

The data custodian is responsible for the operational implementation and maintenance of security controls and safeguards for information assets. This includes tasks such as data backup, system patching, access control enforcement, and ensuring data integrity and availability according to the policies established by the data owner. They act as the 'hands-on' technical and administrative staff who manage the data on a day-to-day basis.

Why this answer

The data custodian (A) is responsible for implementing and maintaining security controls according to the data owner's directives, such as applying encryption, managing backups, and enforcing access controls. This role is recognized in asset security because it bridges policy and operational execution, ensuring the CIA triad is maintained on the stored or processed data.

Exam trap

The trap here is that candidates confuse the data subject (a GDPR-defined individual) with a security role, or mistakenly think the data auditor is a primary asset security role, when the CISSP framework explicitly lists only data owner, data custodian, and data processor as the recognized roles in asset security.

505
Multi-Selecthard

A security engineer is hardening a system against buffer overflow attacks. Which of the following are effective mitigations? (Choose THREE)

Select 3 answers
A.Address Space Layout Randomization (ASLR)
B.Data Execution Prevention (DEP/NX)
C.Using unpatched software
D.Stack canaries
E.Disabling ASLR
AnswersA, B, D

Address Space Layout Randomization (ASLR) is an effective defense that randomizes the memory locations of program components, such as the stack, heap, and libraries. By making these addresses unpredictable, ASLR prevents attackers from reliably targeting specific memory addresses with malicious payloads during a buffer overflow attack. This significantly increases the difficulty of executing successful shellcode or return-oriented programming (ROP) exploits.

Why this answer

ASLR (A) is correct because it randomizes the memory locations of key process areas such as the stack, heap, and libraries, making it much harder for an attacker to reliably redirect execution to injected shellcode. DEP/NX (B) is correct because it marks memory pages (e.g., the stack and heap) as non-executable, so injected code cannot run even if a buffer overflow succeeds in writing to those regions. Stack canaries (D) are correct because a canary value placed between local buffers and the saved return address is checked before a function returns, detecting and aborting the overwrite that a classic stack-based buffer overflow would perform.

Option C (using unpatched software) is wrong because unpatched software retains known vulnerabilities, including buffer overflows, increasing rather than mitigating risk. Option E (disabling ASLR) is wrong because removing ASLR eliminates a key randomization defense and makes exploitation of memory-corruption bugs easier.

Exam trap

CISSP often tests whether candidates recognize that disabling ASLR or using unpatched software are vulnerabilities, not mitigations, and may confuse stack canaries with other protections.

506
MCQmedium

In Kerberos authentication, what is the purpose of the Ticket Granting Ticket (TGT)?

A.To prove the user's identity to the Ticket Granting Service (TGS)
B.To store the user's password hash
C.To encrypt all communication between client and server
D.To authenticate the user to the resource server directly
AnswerA

The Ticket Granting Ticket (TGT) serves as a crucial credential, issued by the Authentication Server (AS), that the client presents to the Ticket Granting Service (TGS). It contains the user's identity and a session key, encrypted with the TGS's secret key, proving the user has been successfully authenticated by the AS. This allows the TGS to trust the client's request for service tickets without requiring re-authentication to the AS for each new service.

Why this answer

The TGT is issued by the Authentication Service (AS) after initial authentication and is used to prove the user's identity to the Ticket Granting Service (TGS) when requesting service tickets. It is encrypted with the TGS's secret key and contains the user's identity and session key.

Exam trap

CISSP often tests the confusion between TGT and service ticket; candidates may think the TGT directly authenticates to a resource server, but it's only used to obtain service tickets from the TGS.

How to eliminate wrong answers

Option B is wrong because the TGT does not store the user's password hash; it contains a session key and identity information. Option C is wrong because the TGT is not used to encrypt all communication; it is a ticket used for authentication, while session keys encrypt specific communications. Option D is wrong because the TGT is not used to authenticate directly to a resource server; the user must first obtain a service ticket from the TGS using the TGT.

507
MCQmedium

An organization is required to retain security logs for a minimum of one year to meet compliance regulations. Which practice is most directly related to this requirement?

A.Log review frequency
B.Log format standardization
C.Centralized log management
D.Log retention requirements
AnswerD

Log retention requirements explicitly define the mandatory duration for which security logs must be stored and maintained by an organization. These requirements are typically driven by legal obligations (e.g., GDPR, HIPAA), industry regulations (e.g., PCI DSS), compliance frameworks, or internal corporate policies for forensic investigations, auditing, and historical analysis. They directly address the "how long" aspect of log management, ensuring data availability for specified periods.

Why this answer

The requirement to retain security logs for a minimum of one year is directly about the duration logs must be stored. Option D, 'Log retention requirements,' is the practice that defines this storage duration, ensuring compliance with regulations such as PCI DSS or SOX. This is a policy-driven specification of how long logs are kept, not how they are reviewed, formatted, or collected.

Exam trap

The trap here is that candidates often confuse 'log retention requirements' with 'centralized log management,' thinking that centralization inherently includes retention, but retention is a separate policy that must be explicitly defined and configured regardless of where logs are stored.

How to eliminate wrong answers

Option A is wrong because log review frequency concerns how often logs are analyzed (e.g., daily or weekly), not how long they are stored; it addresses operational monitoring, not retention duration. Option B is wrong because log format standardization (e.g., syslog RFC 5424 or W3C Extended Log Format) ensures consistency for parsing and analysis, but does not dictate the retention period. Option C is wrong because centralized log management (e.g., using a SIEM like Splunk or ELK stack) aggregates logs from multiple sources for correlation and storage, but the retention period is a separate policy that defines how long logs are kept in that central repository.

508
MCQmedium

A software development company uses a continuous integration/continuous deployment (CI/CD) pipeline that automatically builds and deploys code to production after passing automated tests. The code repository contains proprietary algorithms and customer data. A recent incident was traced to an attacker who injected malicious code into a library that was pulled from a public package repository during the build process. The company wants to prevent similar supply chain attacks without significantly slowing development. Which of the following is the BEST course of action?

A.Require all developers to perform manual code review of every third-party library before inclusion
B.Perform static application security testing (SAST) on the entire codebase including libraries
C.Increase the frequency of vulnerability scanning on the production environment and delay deployment of any library that has a deprecation notice
D.Implement a private repository that mirrors approved open-source libraries and enforces signature verification and hash checks before allowing use
AnswerD

Implementing a private repository that mirrors approved open-source libraries establishes a controlled and trusted software supply chain, preventing direct reliance on potentially compromised public sources. Enforcing signature verification confirms the authenticity of the package's origin, while hash checks guarantee the integrity of the content, ensuring no unauthorized modifications or malicious injections have occurred. This proactive approach effectively blocks compromised or malicious packages from entering the development environment.

Why this answer

Implementing a private repository that mirrors only approved, vetted open-source libraries with enforced signature verification and hash checks directly addresses supply chain attacks by ensuring that only trusted, integrity-verified code enters the build pipeline. This approach prevents malicious code from public repositories from being pulled automatically, without requiring manual review of every library (which would slow development) or relying on post-build scanning that cannot prevent the initial injection. It aligns with the principle of secure software supply chain management by establishing a trusted source of components.

Exam trap

ISC2 often tests the distinction between reactive security controls (like SAST or vulnerability scanning) and proactive supply chain controls (like private repositories with integrity verification), and the trap here is that candidates may choose SAST (option B) because it sounds technical and comprehensive, but it fails to prevent the initial injection of malicious code during the build process.

How to eliminate wrong answers

Option A is wrong because requiring manual code review of every third-party library is impractical and would significantly slow development, defeating the goal of not slowing the pipeline; it also does not scale for large numbers of dependencies and is error-prone. Option B is wrong because performing SAST on the entire codebase including libraries would detect vulnerabilities in the code but cannot prevent the initial injection of malicious code during the build process, as SAST analyzes source code after it is already in the repository, not during the pull from a public package repository. Option C is wrong because increasing vulnerability scanning frequency on the production environment and delaying deployment of libraries with deprecation notices does not prevent the initial injection of malicious code into the build; it only identifies issues after deployment and introduces delays that conflict with the goal of not slowing development.

509
Multi-Selecteasy

During a security assessment, an organization wants to ensure that its web application is resistant to common attacks. Which THREE testing types should be included?

Select 3 answers
A.Input validation testing
B.Network segmentation testing
C.Load testing
D.Authentication testing
E.Session management testing
AnswersA, D, E

This testing method rigorously examines how an application processes and sanitizes all user-supplied data, both client-side and server-side. Its primary goal is to identify vulnerabilities where malicious input, such as SQL injection payloads, Cross-Site Scripting (XSS) scripts, or command injection strings, could be accepted and executed by the application or underlying systems. Effective input validation is fundamental to preventing a wide array of application-layer attacks that exploit trust in user input.

Why this answer

Input validation testing (A) is correct because it verifies that the application properly sanitizes and validates user-supplied data, directly defending against injection attacks such as SQL injection, XSS, and command injection, which are among the most common web application attacks. Authentication testing (D) is correct because it assesses the login mechanisms, credential handling, password policies, and resistance to brute-force or credential-stuffing attacks, ensuring only legitimate users gain access. Session management testing (E) is correct because it examines how session tokens are generated, transmitted, and invalidated, protecting against session hijacking, fixation, and replay attacks that are common in web applications.

Network segmentation testing (B) is not included because it focuses on infrastructure-level isolation between network zones rather than the web application's own attack surface. Load testing (C) is not included because it measures performance and scalability under traffic, not resistance to security attacks.

Exam trap

ISC2 often tests the distinction between application-layer security testing and network-layer or performance testing. Candidates often mistakenly choose load testing (C) because they confuse 'resistance to attacks' with 'resistance to high traffic' (e.g., DDoS), or network segmentation testing (B) because it is a security concept, but neither directly assesses application-layer vulnerabilities like input validation, authentication, and session management do.

510
MCQhard

A cloud service provider uses a Type 1 hypervisor to host multiple virtual machines (VMs) for different customers. Which of the following is a primary security concern specific to this architecture?

A.Virtual machine escape from one guest to the hypervisor or other guests
B.Inability to patch the hypervisor without downtime
C.Performance degradation due to resource sharing
D.Lack of support for legacy operating systems
AnswerA

Virtual machine escape is a critical security vulnerability where an attacker breaks out of the confines of a guest operating system to gain unauthorized access to the hypervisor or other virtual machines. This breach compromises the fundamental isolation provided by the hypervisor, potentially allowing an attacker to control the host system or access sensitive data across multiple tenants. It represents a severe failure of the hypervisor's security mechanisms, making it a top concern for cloud providers.

Why this answer

A Type 1 hypervisor runs directly on the host hardware, and a VM escape vulnerability allows an attacker in a guest VM to break out and access the hypervisor or other guests, compromising the entire host. This is a primary security concern because it breaks the isolation boundary that multi-tenancy relies on.

Exam trap

CISSP often tests the difference between security and operational concerns; candidates may pick performance or patching issues, but the question asks for a primary security concern specific to Type 1 hypervisor architecture.

How to eliminate wrong answers

Option B is wrong because hypervisors can often be patched with minimal downtime using live migration or rolling updates, and this is an operational concern, not a primary security concern specific to Type 1. Option C is wrong because performance degradation is a performance issue, not a security concern. Option D is wrong because lack of support for legacy OS is a compatibility issue, not a security concern.

511
Multi-Selecthard

A multinational corporation is implementing a data classification program. The information security manager must ensure that data is handled appropriately based on its classification level. The company operates in multiple jurisdictions, including the European Union and the United States. Which two of the following are key considerations when developing the data classification policy? (Choose two.)

Select 2 answers
A.Delegating classification decisions solely to the IT department
B.Defining clear criteria for each classification level based on data sensitivity and business impact
C.Aligning classification levels with legal and regulatory requirements in each jurisdiction
D.Ensuring that all data is classified as 'Confidential' by default to maximize protection
E.Implementing a single global classification scheme without considering local variations
AnswersB, C

Clear criteria ensure consistent application of classification levels across the organization. Without defined criteria, employees may classify data inconsistently, leading to either overprotection or underprotection. Criteria should consider factors such as confidentiality, integrity, availability, legal requirements, and business impact. This is essential for a successful data classification program.

Why this answer

Aligning classification with legal requirements and defining clear criteria are essential for a multinational data classification policy. Legal alignment ensures compliance across jurisdictions, while clear criteria promote consistent application. Other options are flawed: overclassification is inefficient, delegating solely to IT ignores business ownership, and a rigid global scheme fails to address local legal nuances.

Exam trap

The trap here is assuming that a one-size-fits-all classification scheme works globally, or that IT alone should classify data.

512
MCQeasy

An information security manager is implementing an asset classification policy. Which of the following is the primary purpose of classifying information assets?

A.To track the physical location of all assets
B.To apply appropriate security controls based on asset sensitivity
C.To determine the monetary value of each asset
D.To identify the legal owner of each asset
AnswerB

The primary objective of asset classification is to assign a sensitivity level to information assets, such as 'Confidential' or 'Public,' based on the potential impact of their compromise. This classification directly dictates the specific security controls—like encryption, access restrictions, or data handling procedures—that must be applied to protect the asset effectively. By aligning controls with sensitivity, organizations ensure resources are allocated efficiently to safeguard their most critical information.

Why this answer

The primary purpose of classifying information assets is to assign a level of sensitivity (e.g., confidential, internal, public) so that appropriate security controls—such as encryption, access control lists, and data loss prevention rules—can be applied proportionally. This ensures that resources are focused on protecting the most critical data, aligning with the principle of cost-effective risk management.

Exam trap

The trap here is that candidates confuse the purpose of classification with asset inventory or valuation, but the CISSP emphasizes that classification is fundamentally about applying the right security controls based on sensitivity, not about tracking, pricing, or ownership.

How to eliminate wrong answers

Option A is wrong because tracking physical location is a function of asset inventory and management, not classification; classification focuses on the data's sensitivity, not its physical whereabouts. Option C is wrong because while classification may inform valuation, its primary purpose is not to determine monetary value—that is a separate financial or risk assessment activity. Option D is wrong because identifying the legal owner is a matter of asset ownership and accountability, which is related but secondary; classification is about the data's sensitivity level, not who owns it.

513
Multi-Selectmedium

A company is implementing a PKI to support secure web browsing. Which of the following are commonly used to enhance the security of certificate validation? (Choose TWO)

Select 2 answers
A.OCSP stapling
B.Certificate revocation lists (CRLs)
C.Certificate pinning
D.Self-signed root certificates
E.Wildcard certificates
AnswersA, C

OCSP stapling significantly improves the efficiency and privacy of certificate revocation checks. Instead of each client directly querying the Certificate Authority's (CA) OCSP responder, the web server periodically fetches a signed OCSP response from the CA and "staples" it to its own certificate during the TLS handshake. This reduces the load on CA infrastructure, minimizes client-side latency, and enhances user privacy by preventing the CA from logging individual client queries.

Why this answer

OCSP stapling (A) is correct because it enhances certificate validation security by having the web server fetch a time-stamped, signed OCSP response from the CA and present it during the TLS handshake, allowing the client to verify revocation status without contacting the CA directly, which improves privacy and reduces latency. Certificate pinning (C) is correct because it associates a host with a specific expected certificate or public key, so the client rejects any certificate that does not match the pinned value, mitigating attacks involving fraudulently issued but otherwise valid certificates. CRLs (B) are a revocation mechanism, but they are a baseline validation input rather than an enhancement, and they can be large and stale.

Self-signed root certificates (D) are not an enhancement to validation; unless explicitly trusted, they fail validation and can weaken trust if improperly installed. Wildcard certificates (E) only cover multiple subdomains under one name and do not improve the security of certificate validation.

Exam trap

CISSP often tests whether candidates confuse revocation mechanisms (CRLs) with validation enhancements (OCSP stapling, pinning), or assume wildcard/self-signed certs improve security.

514
MCQmedium

A healthcare organization is moving patient records to a cloud storage service. Which of the following is the MOST important requirement to ensure data security and compliance with HIPAA?

A.Multi-factor authentication for all cloud access
B.Encryption of data in transit using TLS 1.2
C.A signed Business Associate Agreement (BAA) with the cloud provider
D.Encryption of data at rest using AES-256
AnswerC

Under HIPAA, a cloud provider storing or processing Protected Health Information (PHI) is considered a Business Associate. Before any PHI can be legally shared or stored with such a provider, a signed Business Associate Agreement (BAA) is a mandatory contractual requirement. This agreement legally obligates the cloud provider to comply with HIPAA's Security and Privacy Rules, safeguarding PHI and outlining their responsibilities, permitted uses, disclosures, and breach notification procedures.

Why this answer

Under HIPAA, a covered entity must have a signed Business Associate Agreement (BAA) with any cloud service provider that creates, receives, maintains, or transmits protected health information (PHI). Without a BAA, the provider is not contractually bound to safeguard PHI, making the organization non-compliant regardless of technical controls. While encryption and MFA are important security measures, they cannot substitute for the legal and regulatory requirement of a BAA.

Exam trap

The trap here is that candidates often focus on technical security controls like encryption or MFA, overlooking the foundational legal and regulatory requirement of a signed Business Associate Agreement, which is the non-negotiable first step for HIPAA compliance with a cloud provider.

How to eliminate wrong answers

Option A is wrong because multi-factor authentication (MFA) is a strong access control but does not address the contractual and legal obligations required by HIPAA for business associates; it is a security best practice, not a compliance requirement. Option B is wrong because encryption of data in transit using TLS 1.2 protects data during transmission but does not ensure the cloud provider is legally bound to protect PHI as a business associate; HIPAA mandates a BAA regardless of transport encryption. Option D is wrong because encryption of data at rest using AES-256 protects stored data but, like the other technical controls, does not satisfy the HIPAA requirement for a signed BAA with the cloud provider.

515
MCQmedium

A company uses Role-Based Access Control (RBAC) for its ERP system. A user in the 'Accounts Payable' role needs to temporarily approve purchase orders up to $10,000 while the 'Purchasing Manager' is on leave. What is the BEST way to grant this access?

A.Share the Purchasing Manager's account credentials with the user
B.Temporarily assign the 'Purchasing Approver' role to the user with an expiration date
C.Modify the 'Accounts Payable' role to include purchase order approval permissions
D.Create a new role with the exact permissions needed and assign it to the user
AnswerB

This is the most appropriate solution as it adheres to the principle of least privilege and just-in-time (JIT) access. By temporarily assigning an existing, appropriate role with an explicit expiration date, the user gains only the necessary permissions for the required duration, automatically revoking access once the task is complete. This minimizes the window of potential misuse and maintains strong access control governance.

Why this answer

It follows the principle of least privilege by temporarily assigning the 'Purchasing Approver' role to the user with an expiration date, ensuring that the elevated permissions are automatically revoked after the leave period. This approach maintains RBAC integrity without permanently altering role definitions or sharing credentials.

Exam trap

The trap here is that candidates often choose Option D (creating a new role) because they think it follows least privilege, but they overlook that RBAC best practice is to reuse existing roles with temporary assignments rather than proliferating roles, which violates role-mining principles and adds administrative overhead.

How to eliminate wrong answers

Option A is wrong because sharing the Purchasing Manager's account credentials violates the principle of non-repudiation and accountability, as actions cannot be attributed to the correct user, and it bypasses RBAC entirely. Option C is wrong because modifying the 'Accounts Payable' role to include purchase order approval permissions would permanently grant those rights to all users in that role, violating least privilege and potentially creating a segregation of duties conflict. Option D is wrong because creating a new role with exact permissions is unnecessarily complex and violates RBAC role-mining best practices; it is better to reuse an existing role (Purchasing Approver) with a temporary assignment than to proliferate roles.

516
MCQhard

A network engineer is configuring a firewall to allow HTTP traffic from the internet to a web server (10.0.0.10). The firewall has three interfaces: outside (ISP), DMZ (10.0.0.0/24), and inside (192.168.1.0/24). The web server is in the DMZ. Which rule is correct?

A.Rule: Source interface Inside, Source any, Destination 10.0.0.10, Port 80, Action allow
B.Rule: Source interface Outside, Source any, Destination 10.0.0.10, Port 80, Action allow
C.Rule: Source interface Outside, Source 192.168.1.0/24, Destination 10.0.0.10, Port 80, Action allow
D.Rule: Source interface DMZ, Source any, Destination 10.0.0.10, Port 80, Action allow
AnswerB

This rule correctly permits inbound HTTP traffic from the internet to the specified web server. The 'Outside' interface is the proper entry point for external traffic, and 'Source any' allows requests from any public IP address. Directing traffic to destination 10.0.0.10 on Port 80 precisely targets the web server for standard HTTP communication, fulfilling the requirement.

Why this answer

HTTP traffic from the internet arrives on the outside interface, and the firewall rule must match the source interface (Outside), allow any source IP, and specify the destination IP (10.0.0.10) and port 80. This permits inbound web traffic to the DMZ web server while maintaining security boundaries.

Exam trap

ISC2 often tests the concept that firewall rules must specify the correct source interface (ingress zone) rather than just the source IP, leading candidates to mistakenly choose rules that match the destination but not the traffic's entry point.

How to eliminate wrong answers

Option A is wrong because the source interface is Inside (192.168.1.0/24), which would allow traffic from the internal network, not from the internet. Option C is wrong because the source is restricted to 192.168.1.0/24, which is the internal subnet, not the internet; this would block legitimate external HTTP requests. Option D is wrong because the source interface is DMZ, which would only allow traffic originating from within the DMZ itself, not from the internet.

517
Multi-Selecthard

Which TWO of the following are best practices for securing containerized applications? (Select exactly 2.)

Select 2 answers
A.Mounting the host filesystem to persist logs
B.Running the container process as a non-root user
C.Cleaning the certificate store to prevent MITM
D.Exposing port 22 for SSH debugging in production
E.Using minimal base images such as Alpine or scratch
AnswersB, E

Running the container process as a non-root user enforces least privilege, so a container escape or compromised application cannot gain root on the host. This directly satisfies the stem's container-hardening constraint by removing unnecessary privileged capabilities from the workload.

Why this answer

Option B is correct because running the container process as a non-root user (e.g., via the USER directive in a Dockerfile or runAsNonRoot in Kubernetes) enforces least privilege, so a container escape or compromised process cannot gain root-level access to the host or other resources. Option E is correct because minimal base images such as Alpine or scratch drastically reduce the attack surface by eliminating unnecessary packages, shells, and libraries that could contain exploitable vulnerabilities. Option A is wrong because mounting the host filesystem into a container breaks isolation and can expose sensitive host data to compromise.

Option C is wrong because 'cleaning the certificate store' is not a recognized container security practice and would actually break TLS trust, not prevent MITM. Option D is wrong because exposing port 22 for SSH debugging in production increases the attack surface and is discouraged in favor of exec-based debugging or ephemeral containers.

Exam trap

The trap here is that candidates often confuse 'persisting logs' (Option A) as a security measure, but in container security, mounting the host filesystem is a major isolation violation, not a best practice.

518
Multi-Selecthard

A company is implementing PCI DSS compliance. Which THREE requirements are part of the PCI DSS? (Select THREE)

Select 3 answers
A.Use only approved encryption algorithms for stored data
B.Implement multi-factor authentication for all employees
C.Encrypt transmission of cardholder data across open, public networks
D.Restrict physical access to cardholder data
E.Install and maintain a firewall configuration to protect cardholder data
AnswersC, D, E

This option directly corresponds to PCI DSS Requirement 4: 'Encrypt transmission of cardholder data across open, public networks.' This foundational requirement mandates the use of strong cryptography and security protocols, such as TLS 1.2 or higher, to protect cardholder data during transit over untrusted networks, preventing interception and unauthorized disclosure. It is one of the 12 high-level requirements.

Why this answer

Option C is correct because PCI DSS Requirement 4 mandates protecting cardholder data with strong cryptography during transmission over open, public networks such as the internet. Option D is correct because PCI DSS Requirement 9 requires restricting physical access to cardholder data and systems that store, process, or transmit it. Option E is correct because PCI DSS Requirement 1 requires installing and maintaining firewall and router configurations to protect cardholder data, including controlling traffic between trusted and untrusted networks.

Option A is not a standalone PCI DSS requirement as phrased, since the standard addresses encryption of stored data under Requirement 3 but does not simply state 'use only approved encryption algorithms' as a requirement. Option B is not a PCI DSS requirement for all employees; MFA is required for remote access and certain non-console administrative access, not universally for every employee.

Exam trap

CISSP often tests the misconception that PCI DSS requires MFA for all employees or a specific approved-algorithm list, when in fact MFA is scoped to CDE access and encryption requirements are intent-based rather than a fixed algorithm catalog.

519
MCQmedium

A security engineer reviews the cloud storage bucket policy in the exhibit. What is the most significant security issue with this configuration?

A.The resource identifier does not specify a version ID
B.The policy does not enforce encryption in transit
C.The bucket allows public read access to all objects
D.The policy lacks an explicit deny statement
AnswerC

The policy grants read access to anyone, exposing sensitive data.

Why this answer

The cloud storage bucket policy in the exhibit grants "Effect": "Allow" with "Principal": "*" and an action that permits reading or retrieving objects from the bucket. This configuration effectively makes all objects in the bucket publicly readable over the internet, which is a severe data exposure risk. Option C correctly identifies this as the most significant security issue because it violates the principle of least privilege and can lead to unauthorized access to sensitive data.

Exam trap

The trap here is that candidates may focus on missing technical details like version IDs or encryption conditions, but the most critical security flaw is the explicit public read access granted to all objects, which directly leads to data exposure.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies apply to all versions of objects unless a specific version ID is required; omitting a version ID does not inherently create a security vulnerability. Option B is wrong because S3 bucket policies do not enforce encryption in transit (HTTPS); that is controlled by the bucket's policy condition using "aws:SecureTransport" or by enabling S3 Block Public Access settings, and the absence of such a condition is not the most significant issue here. Option D is wrong because an explicit deny statement is not required for security; the default implicit deny (deny by default) applies to any action not explicitly allowed, and the problem is the overly permissive allow statement, not the lack of an explicit deny.

520
MCQhard

A company collects PII from European customers for order processing. Under GDPR, they engage a third-party logistics provider to handle shipping. Which role does the logistics provider typically assume in this scenario?

A.Data controller
B.Data custodian
C.Data processor
D.Data subject
AnswerC

The logistics provider processes PII solely on the controller's documented instructions for shipping, satisfying GDPR's Article 28 processor definition. It determines neither purposes nor means of processing, unlike a controller or joint controller. This distinction hinges on decision-making authority over processing, not data volume or technical access.

Why this answer

Under GDPR, the logistics provider processes personal data on behalf of the company and therefore assumes the role of data processor. The company that determines the purposes and means of processing is the data controller, and the processor acts only on the controller's documented instructions. This controller-processor relationship must be governed by a written data processing agreement.

Exam trap

CISSP often tests the confusion between controller and processor, and the invented-sounding 'data custodian' role, which is not a GDPR legal designation.

How to eliminate wrong answers

Option A is wrong because the data controller is the entity that determines why and how personal data is processed — here that is the company collecting PII, not the shipping vendor. Option B is wrong because 'data custodian' is not a GDPR-defined role; it is a term from other frameworks (like ITIL or internal data governance) referring to day-to-day data safekeeping, and it carries no GDPR legal meaning. Option D is wrong because the data subject is the individual whose personal data is being processed — the European customer — not the logistics provider.

521
Multi-Selectmedium

A security team is reviewing network segmentation strategies. Which TWO of the following are benefits of using VLANs? (Select TWO.)

Select 2 answers
A.They provide encryption of network traffic
B.They allow logical grouping of devices regardless of physical location
C.They can reduce broadcast traffic
D.They eliminate the need for firewalls
E.They provide inherent protection against ARP spoofing
AnswersB, C

VLANs provide the crucial capability to logically segment a network into distinct broadcast domains, irrespective of the physical location of the connected devices. This means that devices belonging to the same logical group or department can be physically distributed across different switches or geographical areas, yet still reside on their dedicated VLAN, simplifying network management and policy enforcement.

Why this answer

VLANs operate at Layer 2 (Data Link Layer) and allow network administrators to segment devices into distinct broadcast domains based on logical criteria such as department or function, regardless of their physical location on the network. This logical grouping reduces the scope of broadcast traffic because broadcasts are confined to the VLAN, not the entire physical network. By containing broadcasts, VLANs improve network performance and security by limiting unnecessary traffic and isolating potential threats.

Exam trap

The trap here is that candidates often confuse VLANs with security mechanisms like encryption or firewalls, mistakenly believing VLANs provide confidentiality or replace perimeter defenses, when in fact VLANs only offer logical segmentation at Layer 2.

522
MCQmedium

An organization has implemented a new SIEM system. What is the most critical factor for its effectiveness?

A.The cost of the solution
B.The speed of data ingestion
C.The ability to correlate events
D.The number of log sources integrated
AnswerC

The fundamental value proposition of a SIEM system lies in its capacity to aggregate disparate security event data from numerous sources and identify meaningful relationships between them. Event correlation allows the SIEM to detect complex attack patterns, anomalous behaviors, and potential security incidents that would be invisible when examining individual log entries in isolation. This capability transforms raw data into actionable intelligence, enabling proactive threat detection and efficient incident response by linking seemingly unrelated events into a coherent narrative.

Why this answer

The most critical factor for a SIEM's effectiveness is its ability to correlate events across diverse log sources to detect complex attack patterns, such as a lateral movement chain or a multi-stage exploit. Without correlation, a SIEM is merely a log aggregator, unable to distinguish a true security incident from isolated benign events. Correlation engines apply rule-based or statistical analysis (e.g., using Sigma rules or machine learning) to identify relationships between seemingly unrelated log entries, which is the core value proposition of a SIEM.

Exam trap

The trap here is that candidates often mistake 'speed of data ingestion' or 'number of log sources' as the primary success factor, confusing operational metrics with the analytical core of a SIEM, which is correlation.

How to eliminate wrong answers

Option A is wrong because the cost of the solution does not directly impact the SIEM's analytical capability; a high-cost SIEM can still be ineffective if its correlation logic is weak or misconfigured. Option B is wrong because while data ingestion speed is important for real-time monitoring, it is not the most critical factor; a SIEM that ingests data quickly but lacks correlation logic will still fail to detect sophisticated attacks. Option D is wrong because the number of log sources integrated is secondary to the quality of correlation; integrating many sources without proper normalization and correlation rules leads to noise and alert fatigue, not improved detection.

523
MCQeasy

A data owner has classified a dataset as 'Confidential' in a commercial organization. Which of the following best describes the primary responsibility of the data owner for this dataset?

A.Determining the data's classification and ensuring it is labeled appropriately
B.Ensuring the data is accurate and complete
C.Implementing technical controls to protect the data
D.Performing daily backups of the data
AnswerA

The data owner holds ultimate accountability for the data, making them responsible for determining its classification level, such as "confidential," based on its business value, sensitivity, and regulatory compliance requirements. This classification dictates the necessary security controls and handling procedures. Furthermore, the data owner ensures that the data is appropriately labeled to communicate its sensitivity to all users and systems, thereby guiding its protection throughout its lifecycle.

Why this answer

The data owner is accountable for data classification and assigning protection requirements, while the custodian implements controls.

524
MCQhard

A security analyst notes that a recent penetration test successfully exploited a vulnerability in a legacy application that cannot be patched. The analyst recommends implementing network segmentation to limit the application's exposure. This recommendation is an example of:

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerA

Network segmentation is a classic example of risk mitigation, as it directly reduces the potential impact and likelihood of a successful attack spreading across an entire network. By isolating critical systems or sensitive data into separate segments, a breach in one area is contained, preventing lateral movement and significantly diminishing the overall damage. This proactive control implements safeguards to lower the risk exposure to an acceptable level.

Why this answer

Implementing network segmentation to limit exposure of an unpatched legacy application is a classic example of risk mitigation. By isolating the application on a separate network segment (e.g., using VLANs or firewall rules), the analyst reduces the likelihood or impact of a successful exploit, even though the underlying vulnerability remains unpatched. This directly aligns with the CISSP definition of risk mitigation: applying controls to reduce risk to an acceptable level.

Exam trap

The trap here is confusing risk mitigation with risk avoidance — candidates often think that any action taken to address a vulnerability is avoidance, but avoidance requires eliminating the risk entirely (e.g., removing the application), whereas mitigation reduces but does not eliminate the risk.

How to eliminate wrong answers

Option B (Risk acceptance) is wrong because risk acceptance involves formally acknowledging the risk and deciding not to take any action, whereas the analyst is actively implementing a control (segmentation). Option C (Risk avoidance) is wrong because risk avoidance would mean discontinuing the application or removing it entirely to eliminate the risk, not isolating it. Option D (Risk transfer) is wrong because risk transfer shifts the financial burden of a loss to a third party (e.g., via insurance or outsourcing), not implementing a technical control like segmentation.

525
MCQeasy

A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?

A.Isolate the workstation from the network while preserving its state for investigation.
B.Power off the workstation immediately to stop the malware from spreading.
C.Run a full antivirus scan and delete any detected files before escalating.
D.Notify the affected nurse and ask them to stop using the workstation until further notice.
AnswerA

Containment is the priority once an active compromise is confirmed, because the host is beaconing to attacker infrastructure and could enable lateral movement. Network isolation stops command-and-control and spread while keeping memory and disk intact, so the subsequent investigation can determine how the malware arrived and what data was touched.

Why this answer

With an active beacon to attacker infrastructure, the immediate priority in the incident response lifecycle is containment. Isolating the workstation at the network layer halts command-and-control and limits lateral movement while preserving volatile and non-volatile evidence. Powering off, deleting files, or relying on user cooperation all either destroy evidence or leave the compromised host communicating with the adversary.

Exam trap

The trap here is equating containment with shutting the machine down, when powering off destroys volatile memory evidence and can break disk encryption, making later forensics far harder.

Page 6

Page 7 of 11

Page 8

All pages