Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 526–600

816 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
MCQmedium

An LDAP distinguished name (DN) includes the attribute 'CN=John Doe,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

A.Country Name
B.Common Name
C.Certificate Name
D.Container Name
AnswerB

'CN' stands for Common Name, which is a fundamental attribute type used in LDAP Distinguished Names (DNs) to identify the most specific or common name of an entry within its immediate parent container. This attribute is widely employed for various object classes, such as users (e.g., "cn=John Doe"), groups, servers, or other resources, providing a human-readable identifier for the directory object. It forms a crucial part of the Relative Distinguished Name (RDN) for many entries.

Why this answer

In an LDAP distinguished name, CN stands for Common Name, which identifies the object (e.g., a user or group) by its common name attribute. In 'CN=John Doe,OU=Sales,DC=company,DC=com', CN=John Doe is the leaf RDN identifying the user. This is standard LDAP/X.500 naming.

Exam trap

CISSP often tests LDAP attribute abbreviations, so the trap is confusing CN (Common Name) with C (Country Name) or assuming CN relates to certificates rather than the directory attribute.

How to eliminate wrong answers

Option A is wrong because Country Name is represented by the C attribute (e.g., C=US), not CN. Option C is wrong because Certificate Name is not an LDAP attribute; certificates use CN in the subject field but the LDAP attribute itself is Common Name. Option D is wrong because Container Name is not an LDAP attribute; containers in AD are objects but the attribute is not CN in this sense.

527
MCQmedium

Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?

A.External scan
B.Passive scan
C.Authenticated scan
D.Unauthenticated scan
AnswerC

An authenticated scan provides the most comprehensive view because it operates with legitimate user credentials, allowing it to log into target systems and inspect their internal configurations, patch levels, installed software, and user permissions directly. This privileged access enables the scanner to identify vulnerabilities that are only detectable from within the operating system or application, such as missing security updates, insecure registry settings, or weak file permissions, offering a true internal security posture assessment.

Why this answer

An authenticated scan (also called a credentialed scan) provides the scanner with valid credentials to log into target systems, allowing it to read installed software versions, registry keys, configuration files, and patch levels directly. This yields far more accurate and comprehensive vulnerability data than an unauthenticated scan, which can only probe from the outside and often produces false positives or misses local-only vulnerabilities.

Exam trap

The trap is equating 'external' with 'comprehensive' — candidates assume scanning from outside the network covers more, when in fact credentialed internal scanning provides deeper visibility into configurations and patches.

How to eliminate wrong answers

Option A is wrong because an external scan only sees externally exposed services and cannot assess internal configurations or installed patches — it is a scope descriptor, not a depth descriptor. Option B is wrong because a passive scan only observes network traffic without sending probes, so it cannot enumerate vulnerabilities on hosts that are not actively communicating. Option D is wrong because an unauthenticated scan lacks credentials and therefore cannot access detailed configuration information, resulting in more false positives and missed local vulnerabilities.

528
Multi-Selecthard

Under the GDPR, which THREE of the following are rights of data subjects? (Select THREE.)

Select 3 answers
A.Right to erasure (right to be forgotten)
B.Right to ignore processing
C.Right to sell data
D.Right to data portability
E.Right to access
AnswersA, D, E

This fundamental GDPR right allows data subjects to request the deletion or removal of their personal data without undue delay under specific circumstances. These conditions include when the data is no longer necessary for the purpose for which it was collected, when consent is withdrawn, or when the data has been unlawfully processed. However, this right is not absolute and can be overridden by legal obligations or public interest considerations.

Why this answer

The GDPR explicitly grants data subjects the right to erasure (also called the right to be forgotten) under Article 17, allowing individuals to request deletion of personal data when there is no compelling reason for continued processing, so option A is correct. Option D, the right to data portability under Article 20, is correct because it lets data subjects receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller. Option E, the right to access under Article 15, is correct because data subjects may obtain confirmation of whether their personal data is being processed and receive a copy along with related information.

Option B is not a recognized GDPR right, as there is no 'right to ignore processing'; the closest concept is the right to object under Article 21, which is different. Option C is not a GDPR right either, since the regulation does not grant a right to sell data and instead imposes strict conditions on lawful processing and consent.

Exam trap

CISSP often tests fabricated rights like 'right to ignore processing' or 'right to sell data' to see if candidates know the actual enumerated GDPR rights rather than plausible-sounding alternatives.

529
Multi-Selectmedium

During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?

Select 2 answers
A.Storing evidence on a shared network drive
B.Encrypting the evidence file to prevent viewing
C.Labeling evidence with date, time, and collector's name
D.Performing a hash of the evidence immediately
E.Documenting each person who handled the evidence
AnswersC, E

Labeling evidence immediately upon collection with essential details such as the date, time, and the name of the collector is a fundamental step in establishing a robust chain of custody. This initial documentation provides an irrefutable starting point for the evidence's lifecycle, clearly identifying when and by whom it was first secured. Accurate labeling ensures that each piece of evidence can be uniquely identified and tracked throughout the entire forensic process, preventing mix-ups and disputes over its origin.

Why this answer

Option C is correct because labeling evidence with the date, time, and collector's name creates an auditable record of when and by whom the evidence was first obtained, which is a foundational element of chain of custody. Option E is correct because documenting every person who handled the evidence establishes an unbroken, traceable custody trail that shows who had control of the evidence at all times and prevents tampering claims. Options A, B, and D do not belong: storing evidence on a shared network drive (A) compromises integrity and access control rather than preserving custody, encrypting the evidence file to prevent viewing (B) is a confidentiality measure that can hinder forensic examination and is not a chain-of-custody step, and although hashing (D) is essential for proving integrity, it is an evidence-integrity technique rather than a chain-of-custody documentation step.

Exam trap

CISSP often tests the distinction between integrity controls (hashing) and custody controls (labeling and handling logs), causing candidates to select hashing as a chain-of-custody step when it is actually an integrity verification step.

530
Multi-Selecthard

A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?

Select 2 answers
A.Tape backup restoration
B.Cloud DR with continuous data replication
C.Cold site
D.Hot site with real-time replication
E.Warm site
AnswersB, D

Cloud-based Disaster Recovery (DR) leverages the scalability and elasticity of cloud infrastructure to provide a highly agile recovery environment. Continuous data replication ensures that data changes are synchronized almost instantaneously to the cloud DR site, achieving a near-zero Recovery Point Objective (RPO). When a disaster strikes, virtual machines and services can be rapidly provisioned and spun up in the cloud, effectively meeting demanding Recovery Time Objectives (RTOs) with minimal downtime.

Why this answer

Option B (Cloud DR with continuous data replication) is correct because continuous replication keeps the standby environment's data within minutes of the primary, satisfying the 15-minute RPO, while cloud-based failover can typically be initiated well within the 2-hour RTO. Option D (Hot site with real-time replication) is correct because a hot site is fully provisioned and ready to take over immediately, and real-time replication keeps data loss near zero, comfortably meeting both the 2-hour RTO and 15-minute RPO. Option A (Tape backup restoration) is not suitable because restoring from tape is slow and typically yields RTOs measured in days and RPOs in hours or days, far exceeding the targets.

Option C (Cold site) fails because it lacks pre-installed infrastructure and requires lengthy setup, making the 2-hour RTO unachievable. Option E (Warm site) is closer but still requires some configuration and its periodic replication usually cannot guarantee a 15-minute RPO.

Exam trap

The trap is selecting a warm site or tape backup because they are cheaper, but candidates must match the strict RTO/RPO numbers; warm sites often cannot meet 15-minute RPO without continuous replication.

531
MCQeasy

A data classification scheme includes Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

A.Restricted
B.Internal
C.Public
D.Confidential
AnswerA

Restricted data represents the highest level of sensitivity within an organization's classification scheme, indicating that unauthorized disclosure would cause severe, potentially catastrophic, damage to the organization, its operations, or its stakeholders. This classification mandates the most stringent security controls, including robust encryption, strict need-to-know access, multi-factor authentication, and continuous monitoring, to ensure maximum protection against compromise. It typically applies to highly confidential intellectual property, top-secret strategic plans, or critical national security information.

Why this answer

Restricted is the highest classification level in this scheme, indicating data that would cause severe damage to the organization if disclosed. It requires the strongest access controls, encryption (e.g., AES-256 for data at rest, TLS 1.3 for data in transit), and strict need-to-know policies. This aligns with the principle of protecting data based on its sensitivity and the potential impact of unauthorized disclosure.

Exam trap

The trap here is that candidates often confuse 'Confidential' with the highest level because it sounds more restrictive than 'Restricted', but in this scheme 'Restricted' is explicitly the top tier, requiring the most stringent controls.

How to eliminate wrong answers

Option B (Internal) is wrong because Internal data is intended for internal use only but does not require the highest level of protection; its compromise would cause moderate damage, not severe. Option C (Public) is wrong because Public data is intended for unrestricted disclosure and requires the lowest level of protection, often with no access controls. Option D (Confidential) is wrong because Confidential data requires a high level of protection but is still below Restricted; its compromise would cause serious damage, but not the most severe impact.

532
MCQmedium

A security analyst observes a network attack where an attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. This attack occurs at which layer of the OSI model?

A.Layer 3 – Network
B.Layer 1 – Physical
C.Layer 4 – Transport
D.Layer 2 – Data Link
AnswerD

The Data Link layer (Layer 2) is responsible for node-to-node data transfer and error correction from the physical layer, handling frame synchronization, flow control, and error checking. ARP (Address Resolution Protocol) operates at this layer, resolving Layer 3 IP addresses to Layer 2 MAC addresses within a local network segment to enable direct communication. ARP spoofing exploits this protocol by sending forged ARP messages, associating the attacker's MAC address with the IP address of another legitimate host, thereby redirecting traffic at the local network level.

Why this answer

ARP operates at Layer 2 (Data Link) because it maps IP addresses (Layer 3) to MAC addresses (Layer 2) and is encapsulated directly within an Ethernet frame, not an IP packet. The attack described—ARP spoofing—forges ARP replies to poison the target's ARP cache, which is a Layer 2 function. Therefore, the attack occurs at Layer 2 of the OSI model.

Exam trap

The trap here is that candidates see 'IP address' in the question and incorrectly associate it with Layer 3 (Network), forgetting that ARP is a Layer 2 protocol that resolves Layer 3 addresses to Layer 2 addresses.

How to eliminate wrong answers

Option A is wrong because Layer 3 (Network) handles IP routing and packet forwarding, not MAC address resolution; ARP is not an IP protocol and does not use IP headers. Option B is wrong because Layer 1 (Physical) deals with raw bit transmission over media (e.g., voltage, cables), not with logical addressing or frame-level manipulation. Option C is wrong because Layer 4 (Transport) manages end-to-end communication (e.g., TCP/UDP ports, segmentation), and ARP has no concept of ports or transport-layer headers.

533
Multi-Selecteasy

Which TWO of the following are key elements of a disaster recovery plan (DRP)?

Select 2 answers
A.Communication and notification procedures
B.Standard operating procedures for daily tasks
C.Patch management schedules
D.Recovery priorities and order of restoration
E.Business impact analysis (BIA) results
AnswersA, D

Correct. Communication and notification procedures are critical to ensure stakeholders are informed during a disaster.

Why this answer

Option A (Communication and notification procedures) is correct because a DRP must define exactly who is contacted, in what order, through which channels (phone, email, out-of-band), and how stakeholders, staff, and vendors are notified during and after a disruptive event. Option D (Recovery priorities and order of restoration) is correct because a DRP must specify the sequence in which systems, applications, and services are brought back online, typically driven by criticality and dependencies so the most vital functions are restored first. Options B and C are incorrect because standard operating procedures for daily tasks and patch management schedules are routine operational/IT management artifacts, not disaster recovery elements.

Option E is incorrect because the business impact analysis (BIA) is an input that feeds the DRP by identifying critical processes and RTO/RPO targets, but the BIA results themselves are not a key element of the plan.

534
MCQhard

A development team is fixing a stored cross-site scripting (XSS) vulnerability in a web application that displays user comments. The application stores comments in a database and renders them in HTML. Which of the following is the most secure approach to prevent XSS?

A.Use Content Security Policy (CSP) headers to restrict script execution
B.Sanitize input by removing all HTML tags before storing
C.Apply output encoding based on the context (e.g., HTML entity encoding)
D.Store comments in a separate domain to isolate them
AnswerC

Applying output encoding, specifically HTML entity encoding for HTML contexts, is the most effective and robust solution for preventing stored Cross-Site Scripting (XSS). This process transforms malicious characters (like <, >, &, ", ') into their safe, non-executable representations before rendering them in the browser. By ensuring that user-supplied data is treated as data, not executable code, the browser interprets the encoded script as harmless text, thereby neutralizing the XSS payload.

Why this answer

Output encoding (C) is the most secure approach because it neutralizes malicious scripts at the point of rendering, ensuring that user-controlled data is treated as text rather than executable code. For HTML contexts, HTML entity encoding (e.g., `&lt;script&gt;`) prevents the browser from interpreting injected tags, regardless of how the data was stored. This aligns with the defense-in-depth principle and is the primary mitigation for stored XSS as recommended by OWASP.

Exam trap

A common misconception is that input sanitization (removing tags) is the best approach, but the CISSP emphasizes that output encoding is the definitive control because it works regardless of how data enters the system and preserves data integrity for legitimate use.

How to eliminate wrong answers

Option A is wrong because CSP is a defense-in-depth layer that can restrict script execution, but it does not fix the root cause—malicious data remains in the database and could still be exploited if CSP is misconfigured or bypassed (e.g., via JSONP or older browser versions). Option B is wrong because removing all HTML tags before storing destroys legitimate formatting (e.g., bold, lists) and is overly restrictive; a more nuanced sanitization (e.g., whitelist-based) is possible, but output encoding is still needed as a final safeguard. Option D is wrong because storing comments on a separate domain does not prevent XSS—the comments are still rendered in the original application's HTML context, and the same-domain origin policy does not block script execution from injected content.

535
Multi-Selectmedium

Which TWO are examples of administrative controls in an information security program?

Select 2 answers
A.Background checks
B.Encryption algorithms
C.Security awareness training
D.Firewall rules
E.Access control lists (ACLs)
AnswersA, C

Background checks are a critical administrative control, falling under personnel security, designed to mitigate risks associated with hiring untrustworthy individuals. They involve reviewing a candidate's history, including criminal records, employment verification, and educational qualifications, before granting access to sensitive information or systems. This proactive measure establishes a baseline of trust and helps ensure that new hires align with an organization's security posture and ethical standards, thereby preventing potential insider threats.

Why this answer

Administrative controls are the management-oriented, people-and-policy safeguards of a security program, so option A (Background checks) is correct because screening personnel before hire is a procedural/managerial control that reduces insider risk and is mandated by policies rather than enforced by technology. Option C (Security awareness training) is also correct because it is a management-driven program that educates users on policies, phishing, and safe behavior, directly shaping human conduct through process and policy. By contrast, option B (Encryption algorithms), option D (Firewall rules), and option E (Access control lists (ACLs)) are technical (logical) controls — cryptographic mechanisms, packet-filtering rules, and permission lists enforced by systems — not administrative controls.

Exam trap

The trap here is that candidates often confuse administrative controls with technical controls, mistakenly thinking that any security measure that 'controls' access (like ACLs or firewall rules) is administrative, when in fact they are technical controls implemented in systems.

536
Multi-Selecteasy

Which TWO of the following are principles of the data minimization concept under privacy regulations such as GDPR?

Select 2 answers
A.Ensure personal data is accurate and kept up to date
B.Collect only the personal data that is directly relevant and necessary for the specified purpose
C.Store personal data for as long as possible for future analysis
D.Limit the processing of personal data to only what is necessary for the intended purpose
E.Provide individuals with access to their data upon request
AnswersB, D

This option directly reflects a core aspect of data minimization, which dictates that organizations should only collect personal data that is absolutely essential and directly pertinent to achieving a clearly defined, legitimate purpose. By restricting initial data acquisition to the minimum required, it prevents unnecessary accumulation, reduces the potential attack surface, and mitigates privacy risks associated with holding excessive or irrelevant data.

Why this answer

Data minimization under GDPR (Article 5(1)(c)) requires that personal data collected be 'adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.' This principle directly mandates collecting only the data that is directly relevant and necessary for the specified purpose, preventing over-collection and reducing privacy risk.

Exam trap

ISC2 often tests the distinction between the seven GDPR principles (lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability) and the data subject rights (access, rectification, erasure, etc.), so candidates mistakenly select a right like access as a minimization principle.

537
Multi-Selecthard

Which TWO of the following are differences between OAuth 2.0 and OpenID Connect (OIDC)?

Select 2 answers
A.OAuth 2.0 supports device code grant, OIDC does not
B.OAuth 2.0 is for authorization, while OIDC is for authentication
C.OIDC is XML-based, while OAuth 2.0 is JSON-based
D.OIDC uses JSON Web Tokens (JWT) for ID tokens, while OAuth 2.0 does not define a token format
E.OAuth 2.0 requires a client secret, OIDC does not
AnswersB, D

This statement is correct and highlights a fundamental distinction. OAuth 2.0 is an authorization framework, primarily concerned with granting delegated access to protected resources without sharing user credentials. Conversely, OpenID Connect (OIDC) is an authentication protocol built on OAuth 2.0, specifically designed to verify the identity of an end-user and obtain basic profile information, issuing an ID Token for this purpose.

Why this answer

OAuth 2.0 is fundamentally an authorization framework (RFC 6749) that grants delegated access to resources, while OpenID Connect (OIDC) is an authentication layer built on top of OAuth 2.0 (specified in OpenID Connect Core 1.0) that verifies the end-user's identity. OIDC extends OAuth 2.0 by adding an ID token (a JWT) that contains claims about the authenticated user, whereas OAuth 2.0 alone does not provide identity information.

Exam trap

The CISSP exam often tests the misconception that OAuth 2.0 is for authentication and OIDC is for authorization, or that they are interchangeable, when in fact OAuth 2.0 is strictly authorization and OIDC is authentication built on top of it.

538
MCQmedium

A network administrator is deploying a wireless network for a small business and wants to ensure strong security. Which of the following is the best choice for authentication in a WPA3 Personal network?

A.EAP-TLS
B.TKIP
C.Simultaneous Authentication of Equals (SAE)
D.Pre-shared key (PSK)
AnswerC

Simultaneous Authentication of Equals (SAE) is the foundational key exchange mechanism for WPA3-Personal, replacing the less secure Pre-Shared Key (PSK) handshake used in WPA2-Personal. SAE employs a robust password-authenticated key exchange (PAKE) protocol that establishes a strong cryptographic key without directly exposing the shared secret. This design provides crucial protection against offline dictionary attacks and ensures forward secrecy, meaning past session traffic remains confidential even if the shared password is later compromised.

Why this answer

Simultaneous Authentication of Equals (SAE) is the correct choice because WPA3 Personal replaces the vulnerable Pre-Shared Key (PSK) handshake with SAE, which provides a secure key exchange resistant to offline dictionary attacks. SAE uses a Dragonfly handshake based on a zero-knowledge proof, ensuring that even if an attacker captures the handshake, they cannot brute-force the password without being present for each guess.

Exam trap

The trap here is that candidates often confuse WPA2 Personal (PSK) with WPA3 Personal, assuming PSK is still acceptable, but the exam expects you to know that WPA3 Personal mandates SAE as the authentication method, not PSK.

How to eliminate wrong answers

Option A is wrong because EAP-TLS is an enterprise authentication method requiring a RADIUS server and client certificates, which is overkill and not designed for WPA3 Personal (home/small business) mode. Option B is wrong because TKIP is a legacy encryption protocol deprecated by Wi-Fi Alliance since 2012; it is not used in WPA3 and is vulnerable to attacks like MIC key recovery. Option D is wrong because Pre-shared key (PSK) is the WPA2 Personal method that uses a 4-way handshake vulnerable to offline dictionary attacks, whereas WPA3 Personal mandates SAE to eliminate that vulnerability.

539
MCQmedium

Refer to the exhibit. An application running on this server uses HTTPS (port 443). What is the most likely impact of the current firewall rules on the application?

A.Clients will only be able to connect from IP addresses in the 10.0.0.0/8 range.
B.The application will function normally as HTTP is allowed.
C.Clients will be unable to connect to the application because HTTPS is not explicitly allowed.
D.All HTTPS traffic will be logged and then dropped.
AnswerC

This option is correct because the application relies on HTTPS for client connections, which uses TCP port 443. The firewall rules explicitly allow HTTP on port 80 but do not contain any rule to permit traffic on port 443. Consequently, any connection attempts to the application via HTTPS will be intercepted and blocked by the firewall's implicit deny or default drop policy, preventing clients from establishing a connection to the service.

Why this answer

The firewall rules only explicitly permit HTTP (port 80) and deny all other traffic by default. HTTPS uses port 443, which is not listed in the permitted rules, so the firewall will block the connection. Without an explicit allow rule for port 443, the application cannot function over HTTPS.

Exam trap

The trap here is that candidates assume HTTPS is a subset of HTTP or that allowing HTTP implicitly allows HTTPS, but they are separate TCP ports and require distinct firewall rules.

How to eliminate wrong answers

Option A is wrong because the exhibit does not show any source IP restriction; the rules allow HTTP from any source, not just 10.0.0.0/8. Option B is wrong because the application uses HTTPS (port 443), not HTTP (port 80); allowing HTTP does not enable HTTPS traffic. Option D is wrong because the firewall rules do not specify logging for HTTPS traffic; the default implicit deny will silently drop packets without logging unless a log action is explicitly configured.

540
Multi-Selecthard

Which THREE are essential elements of a Transport Layer Security (TLS) handshake? (Choose three.)

Select 3 answers
A.Key generation
B.Cipher suite negotiation
C.Certificate exchange
D.User authentication
E.Session ticket exchange
AnswersA, B, C

Key generation is a fundamental element because it establishes the symmetric encryption keys used to protect the confidentiality and integrity of all subsequent application data exchanged during the secure session. During the TLS/SSL handshake, cryptographic primitives like Diffie-Hellman or RSA are employed to securely derive these shared secret keys. This process ensures that only the communicating parties can encrypt and decrypt the session's traffic, making secure communication possible.

Why this answer

Key generation is essential because during a TLS handshake, the client and server derive session keys using the pre-master secret exchanged via asymmetric encryption (e.g., RSA or Diffie-Hellman). These keys are then used for symmetric encryption of the session, ensuring confidentiality and integrity. Without key generation, no secure communication channel can be established.

Exam trap

The trap here is that candidates often confuse optional features like session resumption (session tickets) or client authentication as mandatory handshake elements, when in fact the three essential components are cipher suite negotiation, certificate exchange, and key generation.

541
MCQeasy

A small business wants to implement multifactor authentication (MFA) for remote access to its internal network. The solution must be cost-effective and easy to deploy. Which combination is most appropriate?

A.Fingerprint scanner and password
B.Password and one-time passcode sent via SMS
C.Smart card and PIN
D.Password and security questions
AnswerB

This option effectively combines 'something you know' (password) with 'something you have' (the mobile phone receiving the OTP), satisfying the criteria for multifactor authentication. SMS-based one-time passcodes are highly accessible and cost-effective, leveraging existing employee mobile devices without requiring additional hardware purchases or complex infrastructure deployment, making it an ideal, low-barrier solution for a small business.

Why this answer

It combines a password (something you know) with a one-time passcode sent via SMS (something you have), satisfying the definition of multifactor authentication. SMS-based OTP is cost-effective and easy to deploy for a small business, as it requires no additional hardware or complex infrastructure, leveraging existing mobile networks.

Exam trap

The trap here is that candidates may incorrectly assume that any two different authentication methods automatically constitute MFA, forgetting that MFA requires factors from at least two distinct categories (knowledge, possession, inherence), and that cost-effectiveness and ease of deployment are key constraints in this scenario.

How to eliminate wrong answers

Option A is wrong because a fingerprint scanner (something you are) and a password (something you know) are two different factors, but fingerprint scanners are typically more expensive and complex to deploy, making them less cost-effective for a small business. Option C is wrong because a smart card (something you have) and a PIN (something you know) are two factors, but smart cards require card readers and provisioning infrastructure, increasing cost and deployment complexity. Option D is wrong because a password and security questions are both 'something you know' factors, which does not constitute multifactor authentication; security questions are a single factor and are often weak due to publicly discoverable answers.

542
MCQeasy

A user calls the help desk because they cannot log in. The help desk technician confirms the user's identity by asking for their employee ID and mother's maiden name. Which of the following is the MOST significant security issue with this practice?

A.The user's mother's maiden name is not stored in the HR system.
B.The technician is using shared secrets that are not effective for strong authentication.
C.The help desk should be using multi-factor authentication.
D.The user's identity is being verified using information that is not unique to the user.
AnswerB

This option correctly identifies the core problem. A mother's maiden name is a classic example of a "shared secret" – information known to both the user and the system, but not truly secret from others. Such data is highly susceptible to social engineering attacks or public record searches, making it an ineffective and weak form of authentication for verifying a user's identity, especially when a user cannot log in and requires a reset or unlock.

Why this answer

The most significant issue is that the help desk is using shared secrets (employee ID and mother's maiden name) for identity verification. These are static, often easily obtainable pieces of information that do not provide strong authentication. They can be compromised through social engineering or data breaches.

While multi-factor authentication (C) is a good practice, the core problem is the reliance on weak shared secrets. Option D is also a concern but less significant than the use of ineffective secrets.

Exam trap

CISSP often tests the difference between authentication factors and the weakness of knowledge-based authentication; candidates might choose MFA as the answer, but the question asks for the issue with the current practice, not the solution.

How to eliminate wrong answers

Option A is wrong because whether the mother's maiden name is stored in HR is irrelevant; the issue is that it's used as a secret, and it may be known to others. Option C is wrong because while MFA is recommended, the question asks for the most significant security issue with the current practice, which is the use of weak shared secrets; MFA is a solution, not the issue itself. Option D is wrong because although mother's maiden name is not unique, the broader problem is that shared secrets are ineffective for strong authentication, making B the most comprehensive answer.

543
MCQeasy

A network administrator is configuring a firewall that examines the source and destination IP addresses, port numbers, and protocol (TCP/UDP) of each packet without considering the state of the connection. Which type of firewall is being deployed?

A.Packet filter firewall
B.Next-generation firewall
C.Stateful inspection firewall
D.Application proxy firewall
AnswerA

A packet filter firewall operates at the network and transport layers (L3/L4) of the OSI model, making decisions solely based on static rules applied to IP addresses, port numbers, and protocols found in packet headers. It is inherently stateless, meaning it does not maintain information about ongoing connections, treating each packet individually without regard for its relationship to previous or subsequent packets. This simplicity allows for high performance but offers limited security context, as it cannot dynamically permit return traffic or detect complex attacks.

Why this answer

A packet filter firewall operates at Layer 3 (Network) and Layer 4 (Transport) of the OSI model, making decisions based solely on static header fields such as source/destination IP addresses, port numbers, and protocol type (TCP/UDP). It does not track connection state or session context, which matches the description of examining each packet independently. This is the defining characteristic of a stateless packet filter, as opposed to stateful or application-layer firewalls.

Exam trap

The trap here is that candidates often confuse 'stateless packet filtering' with 'stateful inspection' because both examine IP/port/protocol, but the key differentiator is the lack of connection state tracking, which the question explicitly states by saying 'without considering the state of the connection.'

How to eliminate wrong answers

Option B is wrong because a next-generation firewall (NGFW) integrates deep packet inspection (DPI), intrusion prevention (IPS), and application-level awareness beyond simple header fields, which is not described in the scenario. Option C is wrong because a stateful inspection firewall maintains a connection state table and tracks the state of active sessions (e.g., TCP handshake sequence numbers), which the question explicitly says is not being considered. Option D is wrong because an application proxy firewall (or application-level gateway) terminates and re-creates connections at Layer 7, inspecting application payloads (e.g., HTTP, FTP commands), far exceeding the simple header-only examination described.

544
MCQeasy

Which of the following is a primary benefit of using an application programming interface (API) gateway in a microservices architecture from a security perspective?

A.It eliminates the need for encryption
B.It replaces the need for a web application firewall
C.It allows direct database access to services
D.It provides a centralized point for authentication and rate limiting
AnswerD

A primary benefit of an API Gateway is its ability to serve as a centralized enforcement point for critical security and operational policies. By handling authentication and authorization at the gateway, individual backend services do not need to implement these mechanisms redundantly, simplifying development and ensuring consistent policy application. Similarly, rate limiting prevents abuse and denial-of-service attacks by controlling the number of requests an API can receive within a given timeframe, all managed efficiently from a single location.

Why this answer

An API gateway acts as a single entry point for all client requests in a microservices architecture. It centralizes cross-cutting security concerns such as authentication (e.g., validating OAuth 2.0 tokens or JWT) and rate limiting (e.g., enforcing requests per second per client), offloading these tasks from individual microservices. This reduces attack surface and ensures consistent enforcement of security policies across the entire system.

Exam trap

The trap here is that candidates may assume an API gateway provides comprehensive security (like a WAF) or replaces encryption, when in fact it is a centralized policy enforcement point for authentication and traffic management, not a substitute for dedicated security controls like encryption or a WAF.

How to eliminate wrong answers

Option A is wrong because an API gateway does not eliminate the need for encryption; in fact, it typically terminates TLS (e.g., HTTPS) and may require encryption between the gateway and backend services (e.g., mTLS). Option B is wrong because an API gateway does not replace a web application firewall (WAF); a WAF provides deep packet inspection for application-layer attacks (e.g., SQL injection, XSS) at Layer 7, which an API gateway is not designed to perform. Option C is wrong because an API gateway does not allow direct database access to services; it routes requests to microservices, which themselves should access databases through controlled interfaces, not directly expose databases to clients.

545
Multi-Selecteasy

Which TWO of the following are valid reasons to implement network segmentation?

Select 2 answers
A.To isolate sensitive data and systems from the rest of the network.
B.To eliminate single points of failure.
C.To contain broadcast traffic and improve performance.
D.To reduce network latency.
E.To simplify routing tables.
AnswersA, C

Network segmentation is a critical security control that logically separates different parts of a network. By creating distinct segments for sensitive data and systems, organizations can significantly limit the exposure of critical assets to unauthorized access or malicious activity. This isolation restricts lateral movement for attackers, ensuring that a compromise in one segment does not automatically grant access to highly protected resources in another.

Why this answer

Network segmentation isolates sensitive data and systems by creating separate broadcast domains or VLANs, restricting unauthorized access and lateral movement. This is a core security principle for protecting critical assets, as it limits the attack surface and enforces access controls between segments.

Exam trap

The trap here is that candidates confuse network segmentation with performance optimization techniques like load balancing or redundancy, leading them to incorrectly select options that address latency or fault tolerance rather than the primary security and broadcast containment benefits.

546
MCQmedium

A penetration tester is engaged to assess a corporate wireless network. After capturing handshakes and attempting offline cracking, the tester obtains valid PSK credentials for the guest SSID. The tester then connects to the guest network but cannot reach any internal servers. Which of the following BEST describes what the tester has demonstrated?

A.The tester has achieved partial network access but is contained by network segmentation controls, which is a valid finding for the engagement.
B.The tester has failed the engagement because no internal systems were compromised during the assessment.
C.The tester should immediately escalate to a full internal penetration test without notifying the client because the guest network is a bridge to the internal environment.
D.The PSK compromise is irrelevant because guest networks are inherently untrusted and require no security controls.
AnswerA

Compromising the guest PSK and being unable to reach internal resources demonstrates that the guest network is segmented from the internal environment. This is a genuine security finding because it shows the control is working as designed while also confirming credential compromise is possible. The tester should document both the successful PSK compromise and the effective segmentation.

Why this answer

Reaching only the guest segment after cracking its PSK shows the segmentation control is functioning and limits lateral movement. The engagement's value is in documenting both the credential weakness and the effective containment. A tester reports what was achieved within scope rather than treating lack of internal compromise as failure or escalating without authorization.

Exam trap

The trap here is assuming that a penetration test is only successful if internal systems are compromised, when containment itself is a reportable finding.

547
Multi-Selectmedium

Which TWO of the following are examples of non-repudiation controls? (Select two)

Select 2 answers
A.Firewall rules
B.Encryption of data at rest
C.Audit logs with timestamps
D.Digital signatures
E.Biometric authentication
AnswersC, D

Audit logs meticulously record system events, user activities, and changes, often including source IP, user ID, and a precise timestamp. When properly secured against tampering, these immutable records serve as irrefutable evidence of who performed what action and when, making it difficult for an individual to deny their involvement in a specific event. This comprehensive logging provides a verifiable trail for accountability.

Why this answer

Audit logs with timestamps (C) are a non-repudiation control because they create a tamper-evident, time-stamped record of who did what and when, so a user cannot later credibly deny having performed an action. Digital signatures (D) provide non-repudiation by cryptographically binding a signer's private key to the message, allowing any party to verify origin and integrity and preventing the signer from denying the signature. Firewall rules (A) are a network access control that filters traffic, not a mechanism for proving an action occurred.

Encryption of data at rest (B) provides confidentiality, not proof of origin or action. Biometric authentication (E) provides strong authentication (something you are) but by itself does not prevent a user from denying an action after authentication.

Exam trap

CISSP often tests the CIA triad vs the supporting principles — candidates confuse authentication (proving identity) or encryption (confidentiality) with non-repudiation, forgetting that non-repudiation specifically requires proof of an action that the actor cannot later deny.

548
MCQeasy

What is the primary purpose of a Web Application Firewall (WAF) in a deployment environment?

A.Encrypting all web traffic
B.Filtering malicious HTTP traffic
C.Managing user authentication
D.Performing vulnerability scanning
AnswerB

Filtering malicious HTTP traffic is the core and primary purpose of a Web Application Firewall (WAF). A WAF inspects incoming HTTP/HTTPS requests and outgoing responses at the application layer (Layer 7) for signatures and behaviors indicative of common web attacks, such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. By analyzing the content, headers, and parameters, the WAF can block or alert on malicious requests before they reach the web application, thereby protecting it from exploitation.

Why this answer

A WAF inspects inbound HTTP/HTTPS requests at Layer 7 and blocks those matching known attack signatures or anomalous patterns, such as SQL injection, cross-site scripting, and malformed requests. It sits in front of a web application (for example, on Azure Application Gateway or Front Door) and enforces rule sets like the OWASP Core Rule Set. Its defining purpose is application-layer traffic filtering, not transport encryption or identity management.

Exam trap

The trap here is confusing the WAF's Layer 7 filtering role with adjacent security functions — encryption (TLS), authentication (IdP), and scanning (vulnerability management) — all of which are handled by different components in a defense-in-depth architecture.

How to eliminate wrong answers

Option A is wrong because encryption of web traffic is provided by TLS termination at the load balancer, gateway, or web server — a WAF may inspect decrypted traffic but does not itself encrypt it. Option C is wrong because user authentication is handled by identity providers, federation protocols (SAML, OIDC), or application code, not by a WAF's filtering rules. Option D is wrong because vulnerability scanning is a separate assessment activity performed by tools like Qualys, Nessus, or Defender for Cloud; a WAF mitigates exploitation attempts at runtime rather than discovering vulnerabilities.

549
MCQmedium

During an incident, a forensic analyst needs to preserve volatile data from a live Windows server. Which command should be used first to collect memory and network connection information?

A.Run ipconfig /all
B.Run tasklist /v
C.Use a forensic tool to capture the contents of RAM
D.Perform a clean shutdown
AnswerC

Using a specialized forensic tool to capture the contents of RAM is the correct action because Random Access Memory (RAM) holds the most volatile and transient data on a system. This includes active processes, network connections, open files, encryption keys, and potentially malicious code that resides only in memory. Such a capture creates a memory dump, which is essential for a thorough forensic analysis, as this critical evidence would be irrevocably lost upon system shutdown or power interruption. This method directly addresses the need to preserve highly ephemeral data.

Why this answer

Volatile data, such as the contents of RAM, is lost when the system is powered off. Capturing RAM first preserves critical evidence like running processes, network connections, and encryption keys. Network connection information can be extracted from the memory dump, so a dedicated forensic tool (e.g., FTK Imager, WinPmem) is the priority before any command-line queries that alter system state.

Exam trap

The trap here is that candidates often choose ipconfig or tasklist because they are familiar Windows commands, but they fail to recognize that these commands do not capture the most volatile data (RAM) and can alter the system state, violating the order of volatility.

How to eliminate wrong answers

Option A is wrong because ipconfig /all only displays static network configuration (IP addresses, DNS servers) and does not capture volatile memory or active network connections; it also modifies the system state minimally but is not the first priority. Option B is wrong because tasklist /v lists running processes but does not capture memory contents or network connections, and it can alter the state of the system by interacting with the process list. Option D is wrong because performing a clean shutdown destroys all volatile data in RAM, including network connections and process information, which is the opposite of preservation.

550
Multi-Selectmedium

A security team is planning to conduct a social engineering test as part of an organization's security assessment. Which THREE of the following should be included in the test plan to ensure ethical and legal compliance?

Select 3 answers
A.Obtain explicit written consent from management
B.Use real personal information of targets
C.Have a stop word or abort mechanism
D.Define clear scope and boundaries
E.Include all employees without exceptions
AnswersA, C, D

Explicit written consent from management establishes documented authorisation before any pretexting or manipulation occurs, satisfying the legal requirement that the organisation's leadership approves the test. Without it, testers could face trespass or fraud claims regardless of intent.

Why this answer

Option A is correct because obtaining explicit written consent from management establishes documented authorization, which is legally required before conducting any social engineering test and protects the testers from liability. Option C is correct because a prearranged stop word or abort mechanism lets targets halt the test immediately if it causes distress or escalates beyond acceptable limits, preserving participant welfare and ethical conduct. Option D is correct because defining clear scope and boundaries specifies which departments, techniques, and timeframes are permitted, preventing unauthorized actions and keeping the assessment within legal and contractual limits.

Options B and E are incorrect: using real personal information of targets violates privacy principles and data protection regulations, and including all employees without exceptions ignores the need for scoping, consent, and exclusion of sensitive roles.

Exam trap

The trap here is that candidates may think 'obtain consent' is optional if the test is internal, or they may confuse 'informed consent' with 'blanket approval' and fail to recognize that explicit written consent from management is mandatory to avoid legal and ethical violations.

551
Drag & Dropmedium

Drag and drop the steps for a disaster recovery (DR) plan activation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for DR plan activation is: declare disaster first to initiate the plan, then notify all stakeholders, perform failover to the alternate site, restore operations from backups or other means, and finally test and resume normal operations. This sequence ensures that activation is acknowledged, resources are aware, critical systems are recovered, and operations can safely return to normal after validation.

552
MCQmedium

What is the primary purpose of a Change Advisory Board (CAB) in change management?

A.To conduct vulnerability assessments
B.To approve and oversee changes to IT systems
C.To implement changes in the IT environment
D.To respond to security incidents
AnswerB

The primary purpose of a Change Advisory Board (CAB) is to evaluate, prioritize, and authorize proposed changes to IT services and infrastructure, ensuring they align with organizational goals and minimize adverse impacts. The CAB meticulously reviews change requests, assessing potential risks, resource requirements, and dependencies before granting approval. Furthermore, it provides oversight throughout the change lifecycle, monitoring implementation progress and reviewing post-implementation reports to confirm successful deployment and address any unforeseen issues.

Why this answer

The CAB is a governance body whose core function is to review, evaluate, and formally approve or reject proposed changes to IT systems before they are implemented. It balances the need for change against risk and business impact, ensuring changes are authorized, prioritized, and scheduled appropriately. This approval/oversight role is distinct from actually performing the change or handling security operations.

Exam trap

CISSP often tests the distinction between governance/oversight roles (CAB approves) and operational roles (implementers execute, SOC responds), so candidates who conflate approval with execution pick option C.

How to eliminate wrong answers

Option A is wrong because vulnerability assessments are performed by security teams using scanning tools (e.g., Nessus, Qualys) and are an input to risk management, not a CAB function. Option C is wrong because implementing changes is the responsibility of the change implementer or technical staff; the CAB approves but does not execute. Option D is wrong because responding to security incidents is the role of the incident response team or SOC, not the CAB, which is a change governance body.

553
MCQmedium

A security engineer is troubleshooting an issue where users are unable to access a web application after being authenticated via OAuth 2.0. The users receive a 403 Forbidden error. The application logs show that the access token is valid but does not contain the required scope. What is the most likely cause?

A.The resource server is configured to expect a different token type.
B.The client application is not using HTTPS to transmit the token.
C.The access token expired before being presented to the resource server.
D.The authorization server did not grant the requested scope due to user consent settings.
AnswerD

If the authorization server, often influenced by user consent or policy, did not include a specific required scope within the issued access token, the resource server will deny the request. Upon receiving the token, the resource server inspects its claims, including the 'scope' claim, and determines that the token does not possess the necessary permissions to perform the requested operation, resulting in a 403 Forbidden response. This indicates the user is authenticated but not authorized for that specific action.

Why this answer

The 403 Forbidden error indicates the resource server received a valid access token but denied access because the token lacks the necessary scope. In OAuth 2.0, the authorization server issues tokens based on the scope granted by the user during consent. If the user did not consent to the required scope (e.g., 'write' instead of 'read'), the token will not include it, causing the resource server to reject the request despite the token being valid.

Exam trap

The trap here is confusing token validity (which is about signature, expiration, and issuer) with token authorization (which is about scope); candidates often assume a valid token guarantees access, but OAuth 2.0 separates authentication from authorization, and scope is the key authorization attribute.

How to eliminate wrong answers

Option A is wrong because the resource server validates the token type (e.g., Bearer) via the token's 'typ' header or introspection endpoint; a mismatch would cause a different error (e.g., 401 Unauthorized), not a scope-related 403. Option B is wrong because HTTPS is a transport-layer security requirement; transmitting the token over HTTP could lead to interception but does not affect the token's scope content, and the error is specifically about missing scope, not token theft. Option C is wrong because an expired token would result in a 401 Unauthorized error (or a token refresh request), not a 403 Forbidden; the logs explicitly state the token is valid, ruling out expiration.

554
Drag & Dropmedium

Drag and drop the steps for implementing a digital signature using asymmetric cryptography in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Digital signatures involve hashing the message, encrypting the hash with the private key, attaching, then verifying with the public key.

555
MCQmedium

A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?

A.Clark-Wilson
B.Biba
C.Brewer-Nash
D.Bell-LaPadula
AnswerC

The Brewer-Nash model, also known as the Chinese Wall policy, is specifically designed to prevent conflicts of interest within organizations. It dynamically restricts a subject's access to information based on their past access history, ensuring that once a subject accesses data related to one company within a conflict-of-interest class, they cannot access data related to any competing company in that same class. This model is crucial in environments like financial services to maintain ethical conduct and prevent insider trading.

Why this answer

Brewer-Nash, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on a user's previous access history. Once a consultant accesses data from one client, the model blocks access to any data belonging to a competing client. This is implemented through dynamically changing access control lists that track what each user has already accessed, ensuring that no user can simultaneously hold data from two competing companies.

Exam trap

CISSP often tests the confusion between Brewer-Nash and Bell-LaPadula, as both are confidentiality models, but candidates must remember that Brewer-Nash is uniquely defined by its conflict-of-interest prevention through dynamic access restrictions based on prior access.

How to eliminate wrong answers

Option A is wrong because Clark-Wilson focuses on data integrity through well-formed transactions and separation of duties, not on preventing conflicts of interest based on access history. Option B is wrong because Biba is an integrity model that prevents unauthorized modification of data by enforcing no read-down and no write-up rules, which does not address conflict-of-interest scenarios. Option D is wrong because Bell-LaPadula is a confidentiality model that enforces no read-up and no write-down based on security labels, but it does not dynamically restrict access based on prior access to competing entities.

556
MCQmedium

During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?

A.Information Disclosure
B.Tampering
C.Elevation of Privilege
D.Spoofing
AnswerB

Tampering specifically refers to the unauthorized modification or alteration of data, whether in transit or at rest, within an application or system. For an online banking application, this could manifest as an attacker changing transaction amounts, recipient details, account balances, or system logs, directly compromising the integrity of financial data and operational processes. This threat directly targets the trustworthiness and accuracy of information, making it a primary concern for financial systems.

Why this answer

STRIDE's Tampering category covers unauthorized modification of data, whether at rest or in transit. Modifying transaction data in transit is the textbook definition of tampering, which violates integrity. The other categories map to different security properties: Information Disclosure to confidentiality, Spoofing to authentication, and Elevation of Privilege to authorization.

Exam trap

CISSP often tests the mapping between STRIDE categories and the CIA/AAA properties they violate; candidates confuse Tampering (integrity) with Spoofing (authentication) or Information Disclosure (confidentiality) when the scenario mentions 'data in transit'.

How to eliminate wrong answers

Option A is wrong because Information Disclosure addresses unauthorized reading/exposure of data (confidentiality breach), not modification. Option C is wrong because Elevation of Privilege describes an attacker gaining higher access rights than authorized, not altering data in transit. Option D is wrong because Spoofing involves impersonating a user, system, or process to gain trust, not modifying the payload itself.

557
MCQmedium

An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?

A.Network firewall
B.Threat intelligence platform
C.SOAR platform
D.Vulnerability scanner
AnswerC

A Security Orchestration, Automation, and Response (SOAR) platform integrates various security tools and systems to automate and orchestrate incident response workflows. It ingests alerts from SIEMs and other sources, applies predefined playbooks to analyze incidents, and automatically executes actions such as blocking IP addresses, isolating endpoints, enriching data, or creating tickets. This capability significantly reduces manual effort, accelerates response times, and standardizes incident handling procedures within a SOC by automating repetitive tasks.

Why this answer

A SOAR (Security Orchestration, Automation, and Response) platform is designed to ingest alerts from SIEM and other sources, apply playbooks, and execute automated response actions such as disabling accounts, blocking IPs, or opening tickets. It is the technology category purpose-built for automating low-severity alert triage and response. SIEM correlates and detects; SOAR orchestrates and acts.

Exam trap

CISSP often tests the boundary between SIEM and SOAR, so the trap is choosing a detection or intelligence tool when the scenario explicitly asks for automated response actions.

How to eliminate wrong answers

Option A is wrong because a network firewall enforces traffic policy at the perimeter; it can block traffic but cannot ingest SIEM alerts, run playbooks, or orchestrate multi-step responses across tools. Option B is wrong because a threat intelligence platform aggregates and enriches indicators of compromise; it informs detection but does not execute response actions. Option D is wrong because a vulnerability scanner identifies weaknesses in systems; it does not respond to runtime alerts or automate SOC workflows.

558
MCQmedium

A security architect is designing a system that must enforce the principle of least privilege for a set of applications. The applications need to access a shared database, but each application should only have the minimum permissions necessary to perform its function. The architect decides to implement a mechanism where each application runs with its own set of credentials and permissions, and these permissions are checked at every access attempt. Which security principle is best demonstrated by this design?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Implicit deny
AnswerA

Least privilege requires that each subject (in this case, each application) be granted only the minimum permissions necessary to perform its function. By giving each application its own credentials and permissions and checking them at every access, the architect ensures that no application has more access than it needs. This directly implements the principle of least privilege, reducing the risk of unauthorized access or damage if an application is compromised.

Why this answer

The design gives each application its own credentials and permissions and checks them at every access, ensuring that each application has only the minimum access required. This is the definition of least privilege. Separation of duties, defense in depth, and implicit deny are related security principles but do not capture the specific requirement of minimizing permissions for each application to only what is necessary for its function.

Exam trap

The trap here is confusing least privilege with implicit deny, because both involve restricting access, but least privilege is about granting minimal necessary permissions, while implicit deny is about denying by default unless explicitly allowed.

559
MCQhard

During a penetration test, the tester successfully performs a VLAN hopping attack by sending packets with a specific tag. Which mitigation technique is most effective at preventing double-tagging VLAN hopping?

A.Use VLAN access control lists (VACLs) only
B.Implement port security with sticky MAC
C.Disable the native VLAN and explicitly tag all VLANs
D.Enable Dynamic Trunking Protocol (DTP) on all ports
AnswerC

The double-tagging attack relies on the switch stripping an outer, attacker-controlled tag when it matches the native VLAN of a trunk port, then forwarding the frame based on the inner, malicious tag. By disabling the native VLAN and explicitly tagging all traffic on trunk links, including the management VLAN, the switch will not strip any untagged frames. This ensures all frames are treated consistently with their explicit VLAN tags, preventing the outer tag from being silently removed and the inner malicious tag from being processed.

Why this answer

Double-tagging VLAN hopping exploits the native VLAN (typically VLAN 1) on a trunk link. By disabling the native VLAN and explicitly tagging all VLANs, including the native VLAN, the switch will not forward untagged frames or frames with a single 802.1Q tag that can be misinterpreted by the next switch, thus preventing the attacker from injecting frames into a different VLAN.

Exam trap

The trap here is that candidates often confuse VLAN hopping with MAC flooding or ARP spoofing, or they assume that VACLs or port security can stop Layer 2 tagging attacks, when in fact the root cause is the untagged native VLAN behavior on trunk ports.

How to eliminate wrong answers

Option A is wrong because VLAN access control lists (VACLs) filter traffic based on Layer 3/4 criteria within a VLAN but do not prevent the underlying frame-tagging manipulation used in double-tagging attacks. Option B is wrong because port security with sticky MAC addresses limits the number of MAC addresses on an access port and prevents MAC flooding, but it has no effect on 802.1Q tag manipulation across trunk links. Option D is wrong because enabling Dynamic Trunking Protocol (DTP) on all ports actually increases the attack surface by allowing an attacker to negotiate a trunk link, which is a prerequisite for launching a VLAN hopping attack; DTP should be disabled on all ports that are not intended to trunk.

560
Multi-Selecteasy

A security analyst is evaluating secure email protocols. Which TWO of the following provide both encryption and digital signing of email messages?

Select 2 answers
A.S/MIME
B.SSL/TLS
C.PGP/GPG
D.SSH
E.IPsec
AnswersA, C

S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for public key encryption and signing of MIME data, commonly used for email. It leverages X.509 certificates issued by a Certificate Authority (CA) to provide confidentiality (encryption), integrity, authentication, and non-repudiation for email messages. S/MIME integrates directly into email clients, allowing users to encrypt the entire email body and attachments, and digitally sign messages to verify sender identity.

Why this answer

S/MIME (Option A) is correct because it uses X.509 digital certificates to provide end-to-end message encryption and digital signing of email content, ensuring confidentiality, integrity, authentication, and non-repudiation. PGP/GPG (Option C) is also correct because it uses public/private key pairs to encrypt and digitally sign email messages, offering the same cryptographic protections for message body and attachments. SSL/TLS (Option B) only encrypts the transport channel between mail clients and servers (e.g., IMAP over TLS, SMTP over TLS) and does not itself digitally sign messages.

SSH (Option D) is a secure remote-access and tunneling protocol unrelated to email message signing or encryption. IPsec (Option E) secures IP packets at the network layer for VPNs and does not provide email-level signing or encryption.

Exam trap

The trap here is confusing transport-layer security (SSL/TLS) with end-to-end message security; candidates often select SSL/TLS because it encrypts email in transit, but it does not provide digital signing or protect the message after delivery.

561
MCQmedium

An organization's risk assessment identified a vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system processes sensitive customer data and is critical for daily operations. The risk is rated as high likelihood and high impact. The organization has a moderate risk appetite. Which risk treatment is most appropriate?

A.Transfer the risk through cyber insurance
B.Avoid the risk by decommissioning the system
C.Accept the risk
D.Mitigate by implementing compensating controls
AnswerD

Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk to an acceptable level. Compensating controls are alternative security measures deployed when primary controls are not feasible or effective, providing an equivalent level of protection. This approach allows the organization to continue critical business operations while addressing the identified vulnerability, making it a practical and responsible strategy when direct remediation is not immediately possible or too disruptive.

Why this answer

Since the system is critical for daily operations and cannot be decommissioned, and the organization has only a moderate risk appetite (meaning it is not willing to simply accept a high/high risk), the appropriate treatment is to reduce the risk by implementing compensating controls such as network segmentation, strict access controls, monitoring, and virtual patching. Compensating controls address the residual risk from the unpatched vulnerability without eliminating the business function. This aligns with the CISSP principle of selecting controls proportionate to risk tolerance and business need.

Exam trap

CISSP often tests the misconception that 'transfer' (insurance) eliminates risk, when in fact it only shifts financial impact and does not address the vulnerability itself.

How to eliminate wrong answers

Option A is wrong because risk transfer via cyber insurance does not reduce the underlying likelihood or impact of the vulnerability — it only shifts financial consequences, and insurers typically will not cover a known, unmitigated high-risk vulnerability. Option B is wrong because decommissioning a system that is critical for daily operations would cause unacceptable business disruption; avoidance is only appropriate when the activity can be discontinued without severe operational harm. Option C is wrong because accepting a high-likelihood, high-impact risk exceeds the organization's stated moderate risk appetite, and acceptance requires formal sign-off at a level consistent with that appetite.

562
MCQmedium

An organization implements Single Sign-On (SSO) using SAML 2.0. A user attempts to access a cloud application (Service Provider) but is not authenticated. The Service Provider redirects the user to the Identity Provider (IdP) for authentication. Which type of SAML flow is this?

A.AuthN-initiated SSO
B.SP-initiated SSO
C.Assertion-initiated SSO
D.IdP-initiated SSO
AnswerB

SP-initiated SSO occurs when a user attempts to access a protected resource directly from a Service Provider (SP). The SP detects the unauthenticated request, generates a SAML authentication request, and redirects the user's browser to the Identity Provider (IdP) along with this request. After the IdP authenticates the user, it creates a SAML assertion and redirects the user's browser back to the SP, allowing the user to access the requested resource without re-authenticating directly to the SP.

Why this answer

In SAML 2.0, SP-initiated SSO occurs when the user first attempts to access a protected resource at the Service Provider (SP). The SP, finding no valid session, generates a SAML AuthnRequest and redirects the user to the Identity Provider (IdP) for authentication. This matches the scenario exactly: the user goes to the cloud application (SP) first, is redirected to the IdP, and then authentication proceeds.

Exam trap

CISSP often tests the distinction between SP-initiated and IdP-initiated SSO by describing the starting point of the user's access attempt; candidates frequently confuse the direction of the initial request and incorrectly choose IdP-initiated when the user actually starts at the application.

How to eliminate wrong answers

Option A is wrong because 'AuthN-initiated SSO' is not a standard SAML flow term; authentication is always initiated by either the SP or the IdP, and the exam expects recognition of the two canonical flows. Option C is wrong because 'Assertion-initiated SSO' is not a recognized SAML flow; assertions are produced by the IdP after authentication, not used to initiate the flow. Option D is wrong because IdP-initiated SSO begins at the IdP (e.g., user clicks an app in the IdP portal), and the IdP sends an unsolicited assertion to the SP without the SP first issuing an AuthnRequest.

563
MCQhard

After a penetration test, the tester provides a report that includes vulnerabilities found, exploitation details, and recommended fixes. Which step of the penetration testing process does this represent?

A.Reporting
B.Post-exploitation
C.Planning and scoping
D.Reconnaissance
AnswerA

Reporting is the formal, final phase of a penetration testing engagement where the tester documents discovered vulnerabilities, methodology, and risk ratings. This deliverable translates technical findings into actionable remediation steps for both executive and technical stakeholders, marking the official conclusion of the active assessment.

Why this answer

The reporting phase is the final step in the penetration testing process, where the tester documents all findings, including vulnerabilities discovered, exploitation details, and recommended remediation steps. This report is delivered to the client to provide a clear understanding of the security posture and actionable fixes. Without this step, the test results would have no value for improving security.

Exam trap

The trap here is that candidates may confuse 'post-exploitation' with the final reporting step, because post-exploitation involves documenting actions taken after access, but the formal report is a separate, distinct phase that synthesizes all findings from the entire test.

How to eliminate wrong answers

Option B (Post-exploitation) is wrong because post-exploitation occurs after gaining access and involves activities like maintaining persistence, escalating privileges, or exfiltrating data, not compiling and delivering the final report. Option C (Planning and scoping) is wrong because this initial phase defines the test's boundaries, rules of engagement, and objectives, not the documentation of results. Option D (Reconnaissance) is wrong because reconnaissance is the information-gathering phase (e.g., using tools like Nmap or Shodan) to identify targets, not the reporting of exploitation outcomes.

564
MCQhard

A company is merging with another and must integrate security policies. What is the first step?

A.Conduct a gap analysis
B.Train all employees
C.Create a new policy
D.Adopt the stricter policy
AnswerA

Conducting a gap analysis is the foundational first step in security integration during a merger. It systematically identifies discrepancies between the merging entities' current security postures, policies, controls, and compliance requirements. This comprehensive assessment provides the critical data needed to understand the combined risk landscape and inform the development of a unified, effective security strategy.

Why this answer

The first step in integrating security policies during a merger is to conduct a gap analysis. This systematically compares the existing policies, controls, and compliance requirements of both organizations against each other and against relevant standards (e.g., ISO 27001, NIST SP 800-53). Without understanding the current state and discrepancies, any subsequent policy creation, training, or adoption of a stricter policy would be uninformed and likely ineffective.

Exam trap

The trap here is that candidates often assume the immediate goal is to enforce the highest security level (Option D), but CISSP emphasizes that effective security management requires a structured, risk-based approach starting with assessment, not unilateral adoption.

How to eliminate wrong answers

Option B is wrong because training all employees is an implementation step that should occur only after the new integrated policy is defined and approved; premature training risks confusion and rework. Option C is wrong because creating a new policy without first understanding the existing policies and gaps could result in a policy that conflicts with legal, regulatory, or operational requirements of either organization. Option D is wrong because simply adopting the stricter policy ignores the need to assess compatibility, enforceability, and business impact; a policy that is stricter but not aligned with the merged entity's risk appetite or operational reality may be impractical or non-compliant.

565
MCQeasy

A financial services company is migrating its customer relationship management (CRM) system to a public cloud provider. The CRM contains personally identifiable information (PII) and financial transaction records. The security architect must design a solution that ensures data confidentiality and integrity both at rest and in transit, while complying with PCI DSS requirements. The cloud provider offers a key management service (KMS) that can generate and store encryption keys, a hardware security module (HSM) in the cloud, and a certificate authority for TLS certificates. The architect needs to select the appropriate encryption methods and access controls. The company's security policy requires encryption keys to be rotated every 90 days and stored separately from the data. The cloud provider's KMS supports automatic key rotation, but the HSM requires manual intervention. The CRM application uses a database that supports transparent data encryption (TDE) with keys stored in the KMS, and the application also requires TLS for all network connections. Which course of action best meets all requirements?

A.Use the cloud provider's KMS to generate and store the database encryption key, disable automatic rotation, and manually rotate it every 90 days. Use a self-signed certificate for TLS to save costs.
B.Use the cloud provider's KMS to generate and store the database encryption key with automatic rotation, and use a certificate from a third-party CA for TLS. Store the KMS key in a separate account and region from the database.
C.Use the cloud HSM to generate and store the database encryption key, manually rotate it every 90 days, and use a certificate from the cloud provider's CA for TLS. Store the HSM key in a different region from the database.
D.Use the cloud provider's KMS to generate and store the database encryption key, enable automatic key rotation, and use a separate KMS-managed key for TLS certificates. Store all keys in the same KMS region as the database.
AnswerB

This option correctly leverages the cloud provider's Key Management Service (KMS) for robust encryption key management, including automatic rotation which satisfies the 90-day policy requirement without manual intervention. Storing the KMS key in a separate account and region from the database enhances security through strong separation of duties and blast radius containment. Furthermore, using a certificate from a trusted third-party Certificate Authority (CA) for TLS ensures strong authentication and encryption for external connections, meeting compliance standards like PCI DSS.

Why this answer

It uses the KMS with automatic key rotation (meeting the 90-day rotation requirement without manual intervention), stores the key in a separate account and region from the database (satisfying the separation requirement), and uses a certificate from a third-party CA for TLS (providing strong trust and compliance with PCI DSS). Option A uses self-signed certificates (not trusted for external connections) and manual rotation (error-prone). Option C uses manual rotation and does not leverage automatic rotation.

Option D stores all keys in the same region as the database, violating the separation requirement, and uses a KMS-managed key for TLS which may not be necessary.

Exam trap

Candidates may think automatic key rotation is not required because manual rotation can meet the 90-day policy, but automatic rotation reduces operational overhead and errors. Also, storing keys in a different region is often overlooked but critical for separation.

566
MCQmedium

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

A.Incident manager
B.Tier 2
C.Tier 1
D.Tier 3
AnswerD

Tier 3 analysts, often comprising threat hunters, malware reverse engineers, and digital forensics experts, possess the most advanced technical skills within a SOC. They are uniquely equipped to conduct deep-dive forensic examinations, including advanced memory forensics, file system analysis, and complex artifact reconstruction, utilizing specialized tools and methodologies. This tier is essential for uncovering sophisticated attack techniques, attributing threats, and developing proactive defenses based on expert-level forensic insights.

Why this answer

Tier 3 performs advanced analysis, which explicitly includes deep packet inspection (DPI) and memory forensics. Confirming DNS tunneling exfiltration requires inspecting DNS query payloads for encoded data and analyzing process memory for injected malware — skills and tooling reserved for Tier 3. Tier 1 and Tier 2 handle triage and investigation but not advanced forensic analysis.

Exam trap

CISSP often tests SOC tier responsibilities — candidates assume Tier 2 handles all investigations, but deep forensics (DPI, memory analysis) is explicitly Tier 3.

How to eliminate wrong answers

Option A is wrong because an incident manager coordinates response, communications, and resources — they do not perform technical forensic analysis like DPI or memory forensics. Option B is wrong because Tier 2 investigates and correlates alerts but does not typically perform deep packet inspection or memory forensics, which are advanced Tier 3 functions. Option C is wrong because Tier 1 only triages and escalates alerts; it lacks the tooling and expertise for DPI and memory forensics.

567
MCQeasy

Which cryptographic algorithm is a symmetric block cipher widely used for encrypting sensitive data, with key sizes of 128, 192, or 256 bits?

A.RSA
B.RC4
C.AES
D.ECC
AnswerC

The Advanced Encryption Standard (AES) is a widely adopted symmetric block cipher, encrypting data in fixed-size blocks of 128 bits using the same secret key for both encryption and decryption. It supports key lengths of 128, 192, or 256 bits, offering robust security against brute-force attacks. As a highly efficient and secure algorithm, AES is the standard for protecting sensitive government and commercial data, making it the correct answer for a symmetric block cipher.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) that operates on 128-bit blocks and supports key sizes of 128, 192, and 256 bits. It replaced DES/3DES for most data-at-rest and data-in-transit encryption. The question's key-size list (128/192/256) is the defining signature of AES.

Exam trap

CISSP often tests the symmetric-vs-asymmetric distinction, so the trap is picking RSA or ECC because they are famous encryption algorithms, ignoring that the question specifies a symmetric block cipher with 128/192/256-bit keys.

How to eliminate wrong answers

Option A is wrong because RSA is an asymmetric algorithm based on integer factorization, using public/private key pairs (commonly 2048/3072/4096 bits), not a symmetric block cipher with 128/192/256-bit keys. Option B is wrong because RC4 is a symmetric stream cipher with variable key sizes (often 40–2048 bits), not a block cipher, and it is deprecated due to biases. Option D is wrong because ECC (Elliptic Curve Cryptography) is asymmetric, using curve-based key pairs (e.g., P-256), not a symmetric block cipher.

568
MCQhard

A company is designing secure boot for IoT devices to ensure only trusted firmware runs. The devices have limited resources. Which mechanism provides the highest assurance of boot integrity?

A.Use a software-based integrity check that runs after boot.
B.Set a BIOS password to prevent unauthorized changes.
C.Use a TPM to measure boot components and compare to stored hashes.
D.Implement full disk encryption (FDE).
AnswerC

A Trusted Platform Module (TPM) provides a hardware root of trust by securely storing cryptographic keys and performing integrity measurements. During the secure boot process, the TPM measures each boot component (firmware, bootloader, kernel) before it executes, extending these measurements into Platform Configuration Registers (PCRs). These PCR values are then compared against known good hashes (golden measurements) stored securely within the TPM or a trusted repository, ensuring that only authorized and untampered software loads.

Why this answer

A Trusted Platform Module (TPM) provides hardware-rooted trust by measuring each boot component (e.g., BIOS, bootloader, OS kernel) and storing the measurements in Platform Configuration Registers (PCRs). These measurements are compared against known-good hashes stored in the TPM, ensuring that any tampering with firmware is detected before execution. This offers the highest assurance for resource-constrained IoT devices as it relies on immutable hardware rather than software-based checks.

Exam trap

The trap here is that candidates often confuse integrity verification (ensuring code hasn't been tampered with) with confidentiality protections (like encryption) or access controls (like passwords), leading them to pick full disk encryption or BIOS passwords instead of the hardware-based attestation provided by a TPM.

How to eliminate wrong answers

Option A is wrong because a software-based integrity check that runs after boot cannot prevent malicious code from already executing; it is a post-boot verification that assumes the system is already compromised, violating the chain of trust. Option B is wrong because a BIOS password only controls access to BIOS settings, not the integrity of the firmware itself; it can be bypassed by resetting CMOS or using default passwords, and does not verify that the firmware has not been modified. Option D is wrong because full disk encryption (FDE) protects data at rest but does not verify the integrity of the boot process or firmware; an attacker could replace the bootloader with a malicious one that still decrypts the disk, leaving the system vulnerable.

569
MCQhard

An organization wants to implement single sign-on across multiple web applications using an XML-based protocol that supports identity provider (IdP) and service provider (SP) initiated flows. Which technology should they choose?

A.OpenID Connect
B.OAuth 2.0
C.SAML 2.0
D.Kerberos
AnswerC

SAML 2.0 (Security Assertion Markup Language) is an XML-based standard specifically designed for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). It is widely adopted for enterprise single sign-on (SSO) scenarios, enabling users to authenticate once with an IdP and gain seamless access to multiple SPs without re-entering credentials. Its robust support for both IdP-initiated and SP-initiated flows makes it a strong choice for cross-domain SSO implementations.

Why this answer

SAML 2.0 is the XML-based federation standard that defines both IdP-initiated and SP-initiated SSO flows using assertions, AuthnRequests, and Response messages. It is the classic choice for browser-based SSO across multiple web applications where the identity provider and service provider exchange XML over HTTP POST or redirect bindings. OpenID Connect and OAuth 2.0 are JSON/REST-based, and Kerberos is a ticket-based network authentication protocol, not a web SSO federation standard.

Exam trap

CISSP often tests the SAML vs OIDC vs OAuth confusion — candidates must remember SAML is XML-based federation with IdP/SP roles, OIDC is JSON/JWT-based authentication, and OAuth 2.0 is authorization only.

How to eliminate wrong answers

Option A is wrong because OpenID Connect uses JSON Web Tokens (JWT) and REST endpoints, not XML, and is a newer OAuth 2.0-based layer rather than the XML protocol described. Option B is wrong because OAuth 2.0 is an authorization framework for delegated access, not an authentication/SSO protocol, and it is JSON-based. Option D is wrong because Kerberos is a symmetric-key ticket protocol used inside a realm (e.g., Active Directory), not an XML federation protocol for cross-domain web SSO.

570
MCQhard

A PAM configuration contains pam_tally2.so with deny=5 and unlock_time=300. What is the effect of this configuration?

A.The account is disabled after 5 successful logins
B.Passwords must be changed every 5 days
C.Users are locked out after 5 failed login attempts, and automatically unlocked after 5 minutes
D.Users are locked out after 5 failed attempts until manually unlocked
AnswerC

The `deny=5` parameter in the `pam_tally2` configuration explicitly instructs the system to lock a user's account after five consecutive unsuccessful authentication attempts, thereby preventing further brute-force efforts. Simultaneously, the `unlock_time=300` parameter ensures that the locked account is automatically re-enabled after 300 seconds, which precisely translates to five minutes, negating the need for any manual administrative intervention.

Why this answer

The PAM configuration shows pam_tally2.so with deny=5 and unlock_time=300. Pam_tally2.so with deny=5 locks the user account after 5 failed authentication attempts, and unlock_time=300 sets the automatic unlock period to 300 seconds (5 minutes). This is a standard PAM (Pluggable Authentication Modules) configuration for account lockout policies, commonly used on Linux systems to mitigate brute-force attacks.

Exam trap

Candidates often confuse pam_tally2.so with password aging or account disablement features, or assume that unlock_time=300 means manual unlock is required, when in fact it specifies automatic unlock after 300 seconds.

How to eliminate wrong answers

Option A is wrong because pam_tally2.so tracks failed logins, not successful logins; disabling after successful logins would be a different mechanism (e.g., account expiration). Option B is wrong because password aging (e.g., 5-day change interval) is configured via pam_unix.so or pam_cracklib.so, not pam_tally2.so. Option D is wrong because unlock_time=300 specifies automatic unlocking after 300 seconds, not manual intervention; manual unlock would require a separate configuration (e.g., pam_tally2.so without unlock_time or with a very high value).

571
MCQmedium

An organization is designing a disaster recovery site. The primary data center is located in a region prone to earthquakes. The recovery site must be far enough away to avoid the same seismic zone but close enough to minimize latency. Which site selection criteria is most important?

A.Access to diverse power grids
B.Geographical diversity to avoid the same seismic zone
C.High-speed network connectivity between sites
D.Availability of skilled personnel near the recovery site
AnswerB

Geographical diversity, specifically avoiding the same seismic zone, is a paramount consideration for a disaster recovery site. This ensures that a single catastrophic event, such as a major earthquake, cannot simultaneously disable both the primary and recovery data centers. Such separation is fundamental to maintaining business continuity and data availability, as it prevents the loss of both operational and recovery capabilities from a single, widespread natural disaster.

Why this answer

Geographical diversity (Option B) is the most important criterion because the primary data center is in an earthquake-prone region, and the recovery site must be located outside the same seismic zone to ensure that a single seismic event does not destroy both sites. This directly addresses the core requirement of disaster recovery: maintaining availability during a regional catastrophe. While latency and connectivity are important, they are secondary to ensuring the recovery site survives the same disaster.

Exam trap

The trap here is that candidates often prioritize network connectivity (Option C) or power diversity (Option A) because they are common in high-availability design, but the question explicitly states the primary risk is a regional earthquake, making geographic diversity the non-negotiable requirement.

How to eliminate wrong answers

Option A is wrong because access to diverse power grids, while beneficial for power redundancy, does not protect against the physical destruction caused by an earthquake; the site could still be in the same seismic zone and be destroyed. Option C is wrong because high-speed network connectivity between sites, though important for data replication and low latency, is irrelevant if both sites are rendered inoperable by the same earthquake. Option D is wrong because availability of skilled personnel near the recovery site is a staffing consideration, not a site selection criterion that mitigates the risk of a single seismic event destroying both locations.

572
MCQmedium

A company wants to test the effectiveness of its security controls without causing disruption. Which type of assessment is most appropriate?

A.Penetration test
B.Security audit
C.Vulnerability scan
D.Red team exercise
AnswerC

A vulnerability scan systematically identifies known security weaknesses and misconfigurations in systems, applications, and networks by passively probing for indicators of potential vulnerabilities. This method is non-intrusive, does not attempt to exploit findings, and therefore minimizes the risk of service disruption, making it an ideal, low-impact approach for regularly assessing the presence of security flaws and the general effectiveness of baseline controls.

Why this answer

A vulnerability scan is the most appropriate assessment because it passively identifies known vulnerabilities (e.g., missing patches, misconfigurations) without exploiting them, ensuring no disruption to production systems. Unlike active exploitation tests, vulnerability scanners use non-intrusive probes (e.g., banner grabbing, version fingerprinting) that do not trigger denial-of-service or system crashes. This aligns with the requirement to test control effectiveness while maintaining operational stability.

Exam trap

ISC2 often tests the distinction between passive identification (vulnerability scan) and active exploitation (penetration test), where candidates mistakenly choose penetration test because they think it provides a more thorough assessment, ignoring the explicit 'without causing disruption' constraint.

How to eliminate wrong answers

Option A is wrong because a penetration test involves active exploitation of vulnerabilities, which can cause service disruptions (e.g., buffer overflows, resource exhaustion) and is not suitable when the primary goal is to avoid disruption. Option B is wrong because a security audit focuses on verifying compliance with policies, standards, or regulations (e.g., ISO 27001) through document review and interviews, not on actively testing technical control effectiveness against real-world threats. Option D is wrong because a red team exercise is a full-scope adversarial simulation that includes social engineering, physical breaches, and aggressive exploitation, often causing significant operational disruption and alerting defenders, contradicting the 'without causing disruption' requirement.

573
MCQeasy

During a code review, a developer notices that an application directly concatenates user input into SQL queries. Which type of vulnerability does this represent?

A.Cross-site scripting (XSS)
B.Cross-site request forgery (CSRF)
C.Buffer overflow
D.SQL injection
AnswerD

SQL injection is a code injection technique that exploits vulnerabilities in an application's database layer, specifically when user-supplied input is directly concatenated into SQL queries without proper sanitization or parameterization. This allows an attacker to modify the intended SQL query structure, enabling unauthorized data access, modification, deletion, or even execution of administrative commands on the database server. It directly targets the database query logic.

Why this answer

Directly concatenating user input into SQL queries allows an attacker to inject arbitrary SQL commands, altering the query's intended behavior. This is the classic definition of SQL injection, which can lead to unauthorized data access, modification, or deletion. The vulnerability arises because the input is treated as executable code rather than data, bypassing parameterized query protections.

Exam trap

The trap here is that candidates may confuse SQL injection with cross-site scripting (XSS) because both involve injection of untrusted data, but XSS targets the browser's DOM, not the database query layer.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) involves injecting client-side scripts into web pages viewed by other users, not into SQL queries. Option B is wrong because cross-site request forgery (CSRF) tricks a user's browser into making unintended requests to a trusted site, exploiting authentication, not directly manipulating database queries. Option C is wrong because buffer overflow occurs when data exceeds a buffer's memory boundary, corrupting adjacent memory, which is unrelated to SQL query construction.

574
MCQeasy

During a penetration test, the tester successfully exploits a vulnerability in a web server and gains initial access. The next step in the penetration testing process is to:

A.Disconnect from the network
B.Report the findings immediately
C.Conduct post-exploitation and lateral movement
D.Perform reconnaissance
AnswerC

After successfully exploiting a vulnerability, the next logical and critical step in a penetration test is to conduct post-exploitation activities and attempt lateral movement. Post-exploitation involves maintaining access, escalating privileges, and gathering information from the compromised system, while lateral movement aims to pivot to other systems within the network. These actions are essential for determining the true impact of the initial compromise, identifying additional vulnerabilities, and mapping the potential blast radius of an attacker, thereby providing a comprehensive security assessment.

Why this answer

After gaining initial access during a penetration test, the standard methodology (e.g., PTES, OWASP) requires conducting post-exploitation and lateral movement to assess the full impact of the compromise. This involves enumerating the compromised host, escalating privileges, and pivoting to other systems using techniques like pass-the-hash or SSH tunneling. Reporting findings immediately or disconnecting would violate the test scope and fail to demonstrate the real risk of the vulnerability.

Exam trap

The trap here is that candidates confuse the linear 'reconnaissance → exploitation → reporting' model with the iterative nature of penetration testing, where post-exploitation and lateral movement are essential steps after initial access to fully assess risk.

How to eliminate wrong answers

Option A is wrong because disconnecting from the network aborts the test prematurely, preventing the tester from identifying the full attack path and potential data exposure, which is the core objective of a penetration test. Option B is wrong because reporting findings immediately after initial access is not part of the penetration testing process; findings are typically documented and reported after the test concludes, not during active exploitation. Option D is wrong because reconnaissance is performed before exploitation, not after gaining initial access; it involves passive and active information gathering (e.g., DNS enumeration, port scanning) to identify targets and vulnerabilities.

575
MCQeasy

A security administrator is reviewing the organization's security policy framework. The administrator needs to identify the document that provides detailed, step-by-step instructions for configuring a new server securely. Which type of document should the administrator reference?

A.Standard
B.Procedure
C.Guideline
D.Policy
AnswerB

A procedure is a detailed, step-by-step document that outlines how to perform a specific task, such as securely configuring a server. It translates standards and policies into actionable steps. This matches the administrator's need for precise instructions, making it the correct choice.

Why this answer

The correct answer is a procedure because it provides detailed, step-by-step instructions for performing a specific task like securely configuring a server. Policies, standards, and guidelines do not offer the operational granularity required for this technical task.

Exam trap

The trap here is confusing a standard with a procedure, assuming that any document specifying security requirements provides step-by-step instructions.

576
Multi-Selectmedium

Which THREE of the following are valid methods for securely disposing of magnetic hard drives?

Select 3 answers
A.Deleting files and emptying recycle bin
B.Physical shredding
C.Overwriting with random data (multiple passes)
D.Degaussing
E.Quick formatting
AnswersB, C, D

Physical shredding is a highly secure method that involves mechanically destroying the storage medium itself, such as hard drive platters or solid-state drive NAND flash chips, into tiny, unrecognizable fragments. This renders the data absolutely unrecoverable by any means, as the physical integrity of the storage device is completely obliterated. It is considered the most definitive method for data destruction across various media types.

Why this answer

Physical shredding (B) is correct because it mechanically destroys the platters into small particles, making any magnetic data recovery physically impossible. Overwriting with random data over multiple passes (C) is correct because it replaces the original magnetic patterns with new data, rendering the previous contents unrecoverable even with laboratory techniques. Degaussing (D) is correct because exposing the drive to a strong magnetic field erases the magnetic alignment on the platters, effectively destroying the data and often rendering the drive unusable.

Deleting files and emptying the recycle bin (A) only removes file system references while the data remains on the platters, and quick formatting (E) merely rewrites the file system metadata without overwriting the actual data, so neither is a secure disposal method.

Exam trap

Candidates often confuse logical deletion or formatting (A, E) with secure sanitization. While deleting and formatting only remove file pointers, overwriting, degaussing, and physical destruction actually sanitize the media by removing or destroying the underlying data.

577
MCQhard

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

A.RTO = 15 minutes, RPO = 4 hours
B.RTO = 4 hours, RPO = 4 hours
C.RTO = 4 hours, RPO = 15 minutes
D.RTO = 15 minutes, RPO = 15 minutes
AnswerC

This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.

Why this answer

RTO (Recovery Time Objective) defines the maximum acceptable downtime — how long until systems are restored — so 4 hours matches the requirement to recover critical systems within 4 hours. RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time, so 15 minutes matches the requirement to lose no more than 15 minutes of data. Option C is the only pairing that maps each objective to its correct definition.

Exam trap

CISSP often tests the classic RTO/RPO swap — candidates who memorize the acronyms but not their definitions reverse them, picking RTO for data loss and RPO for downtime, which is exactly what Option A represents.

How to eliminate wrong answers

Option A is wrong because it swaps the definitions — it assigns RTO to the data-loss requirement (15 minutes) and RPO to the downtime requirement (4 hours), which inverts the meaning of both metrics. Option B is wrong because it sets RPO to 4 hours, which would permit up to 4 hours of data loss, violating the 15-minute data-loss limit; it also overstates RTO relative to the data requirement while ignoring the tighter RPO. Option D is wrong because it sets RTO to 15 minutes, which is stricter than the stated 4-hour recovery requirement and would drive unnecessary cost and complexity; while its RPO is correct, the RTO misassignment makes the combination incorrect.

578
MCQhard

In a microservices architecture with a service mesh, what is the most effective approach to secure inter-service communication?

A.Segment services into separate VLANs without encryption
B.Use TLS only for all communication
C.Implement mutual TLS (mTLS) and identity-based access policies
D.Rely on API keys in the request headers
AnswerC

Implementing mutual TLS (mTLS) and identity-based access policies is the most robust approach for securing microservices in a service mesh. mTLS ensures strong, bidirectional cryptographic authentication between services, verifying both the client's and server's identities using certificates for every connection. Coupled with identity-based access policies, this enables fine-grained authorization decisions based on verified service identities, enforcing the principle of least privilege and establishing a zero-trust environment within the mesh.

Why this answer

In a service mesh, mutual TLS (mTLS) provides both encryption and identity verification for every inter-service call, ensuring that only authenticated services with the correct identity can communicate. Identity-based access policies (e.g., using SPIFFE IDs) then enforce fine-grained authorization, which is essential in dynamic microservices environments where IP addresses are ephemeral. This combination directly addresses the core security requirements of confidentiality, integrity, and authentication in zero-trust architectures.

Exam trap

The trap here is that candidates often choose 'TLS only' (Option B) thinking encryption alone is sufficient, but the CISSP exam emphasizes that in a zero-trust microservices environment, mutual authentication and identity-based authorization are critical to prevent impersonation and lateral movement.

How to eliminate wrong answers

Option A is wrong because segmenting services into separate VLANs without encryption fails to protect data in transit; VLANs provide network segmentation but no encryption, leaving traffic vulnerable to sniffing or man-in-the-middle attacks within the same physical network. Option B is wrong because using TLS only for all communication provides encryption but does not authenticate the identity of the calling service; without mutual authentication, a compromised or rogue service can impersonate a legitimate one. Option D is wrong because relying on API keys in request headers is a weak form of authentication that can be easily intercepted, replayed, or leaked, and it does not provide encryption or identity-based authorization at the transport layer.

579
MCQhard

An organization deploys a hypervisor to host multiple virtual machines. To mitigate the risk of VM escape attacks, which of the following is the most effective security measure?

A.Disabling all unnecessary hypervisor services and applying security patches
B.Using Type 2 hypervisor only
C.Using VLANs to isolate VM traffic
D.Enabling VM snapshots for quick recovery
AnswerA

Disabling unnecessary hypervisor services significantly reduces the attack surface by removing potential entry points and unneeded code that could harbor vulnerabilities. Concurrently, applying security patches promptly addresses known flaws and exploits, preventing attackers from leveraging publicly disclosed weaknesses in the hypervisor software. This proactive combination of hardening and continuous vulnerability management is critical for maintaining the integrity and security of the virtualization layer, directly mitigating risks like VM escape.

Why this answer

Disabling unnecessary hypervisor services reduces the attack surface available to a guest attempting VM escape, and applying hypervisor security patches closes known vulnerabilities (e.g., VENOM, CVE-2015-3456) that allow guest-to-host breakout. Since the hypervisor is the isolation boundary between VMs and the host, hardening and patching it directly addresses the escape vector. This is the most effective preventive control because it targets the root cause rather than the symptoms.

Exam trap

CISSP often tests the distinction between preventive controls that address the root cause (hypervisor hardening/patching) and compensating or detective controls (VLANs, snapshots) that candidates mistakenly select as 'most effective' for VM escape.

How to eliminate wrong answers

Option B is wrong because Type 2 hypervisors (hosted, e.g., VirtualBox, VMware Workstation) run atop a general-purpose OS and typically have a larger attack surface than Type 1 bare-metal hypervisors, so mandating Type 2 does not mitigate escape risk. Option C is wrong because VLANs only segment Layer 2 network traffic between VMs; they do nothing to prevent a guest from exploiting the hypervisor to break isolation and reach the host. Option D is wrong because snapshots are a recovery/rollback mechanism, not a preventive control — they help after a compromise but do not stop a VM escape from occurring.

580
MCQhard

A company develops a web application using microservices architecture deployed on Kubernetes. The security team identifies that the application is vulnerable to injection attacks because user input is concatenated into SQL queries. The development team wants to implement a fix quickly. They propose using parameterized queries, but the database access layer currently uses stored procedures. The team considers modifying the stored procedures to accept parameters and using prepared statements in the code. However, the operations team is concerned about performance impact. Which of the following is the BEST course of action?

A.Use parameterized queries immediately without modifying stored procedures.
B.Implement both parameterized queries and modify stored procedures to use parameters, and then monitor performance.
C.Modify stored procedures to use dynamic SQL with input validation.
D.Use input validation only, as stored procedures inherently prevent injection.
AnswerB

Implementing parameterized queries at the application layer combined with modifying existing stored procedures to properly utilize parameters creates a robust, defense-in-depth strategy against SQL injection. This approach eliminates injection vulnerabilities at both the application and database levels. Monitoring performance post-implementation is crucial to identify any potential bottlenecks introduced by the changes before a full production rollout, ensuring system stability and efficiency.

Why this answer

The best course is to implement both parameterized queries in the application and modify stored procedures to accept parameters, then monitor performance. This defense-in-depth approach ensures that all database access paths are protected against SQL injection, while the monitoring step addresses the operations team's performance concerns with empirical data rather than speculation.

Exam trap

CISSP often tests the misconception that stored procedures inherently prevent SQL injection, or that input validation alone is sufficient — candidates may choose a partial fix instead of a comprehensive one.

How to eliminate wrong answers

Option A is wrong because using parameterized queries only in the application layer leaves stored procedures that may still concatenate input, leaving a gap. Option C is wrong because dynamic SQL with input validation is still vulnerable to injection if validation is incomplete, and dynamic SQL is riskier than parameterized queries. Option D is wrong because stored procedures do not inherently prevent injection — if they use dynamic SQL with concatenated input, they are vulnerable; input validation alone is insufficient.

581
Multi-Selectmedium

A security analyst is evaluating access control models for a healthcare organization that needs to enforce both confidentiality and integrity. Which TWO models should be considered? Select two.

Select 2 answers
A.Take-Grant
B.Bell-LaPadula
C.Biba
D.Clark-Wilson
E.Brewer-Nash
AnswersB, C

The Bell-LaPadula model is a state-machine model primarily designed to enforce confidentiality, particularly in military and government systems. It operates on the principles of 'no read up' (Simple Security Property) and 'no write down' (*-property), ensuring that subjects can only access information at or below their security clearance level and cannot write information to a lower security level. This prevents unauthorized disclosure of classified information by strictly controlling information flow.

Why this answer

Bell-LaPadula (B) is correct because it is the classic mandatory access control model designed to enforce confidentiality through the no-read-up and no-write-down rules, which fits the healthcare requirement to protect sensitive patient data from unauthorized disclosure. Biba (C) is correct because it is the complementary integrity model that enforces no-read-down and no-write-up, preventing untrusted or lower-integrity data from corrupting higher-integrity records, which addresses the stated need to enforce integrity. Together these two models directly map to the scenario's dual requirement for confidentiality and integrity.

Take-Grant (A) is not the best fit because it focuses on modeling how rights can be transferred or granted in a graph-based access control system rather than enforcing confidentiality or integrity policies. Clark-Wilson (D) is an integrity model based on well-formed transactions and separation of duties, but it does not enforce confidentiality, so it does not satisfy both requirements. Brewer-Nash (E) is the Chinese Wall model, which addresses conflict-of-interest access control rather than the general confidentiality and integrity enforcement described here.

Exam trap

CISSP often tests the pairing of confidentiality and integrity models, tricking candidates into selecting Clark-Wilson (integrity only) or Brewer-Nash (conflict of interest) when the question explicitly requires both confidentiality and integrity.

582
MCQmedium

A security analyst is tasked with identifying vulnerabilities in a network without exploiting them. Which type of assessment is most appropriate?

A.Vulnerability assessment
B.Security audit
C.Penetration test
D.Security review
AnswerA

A vulnerability assessment systematically identifies security weaknesses and misconfigurations within systems, applications, or networks. It typically employs automated scanning tools and manual analysis to detect known vulnerabilities, providing a prioritized list of potential risks without attempting to exploit them. This process aims to give an organization a comprehensive overview of its security posture and areas requiring remediation.

Why this answer

A vulnerability assessment is designed to identify and enumerate vulnerabilities in a system or network without exploiting them. It typically uses automated scanners and manual techniques to produce a report of potential weaknesses. This matches the requirement of identifying vulnerabilities without exploitation.

Exam trap

The trap is conflating vulnerability assessment with penetration testing; candidates often pick penetration test because it sounds more thorough, but the key differentiator is that pen tests exploit vulnerabilities, while assessments do not.

How to eliminate wrong answers

Option B is wrong because a security audit is a broader evaluation of compliance with policies, standards, and procedures, not specifically focused on identifying technical vulnerabilities. Option C is wrong because a penetration test actively exploits vulnerabilities to demonstrate impact, which violates the 'without exploiting them' constraint. Option D is wrong because a security review is a general term for examining security controls and may not include technical vulnerability identification.

583
MCQmedium

An organization uses a data loss prevention (DLP) system to monitor outbound emails. Which data classification type would the DLP most likely use to detect sensitive information leaving the network?

A.Context-based classification
B.Content-based classification
C.User-based classification
D.Role-based classification
AnswerB

Content-based classification is a fundamental capability of Data Loss Prevention (DLP) systems, directly examining the actual data payload to identify sensitive information. This method employs techniques like keyword matching, regular expressions (e.g., for credit card numbers or Social Security numbers), exact data matching (EDM) against known sensitive datasets, and machine learning to detect patterns and specific data types. By analyzing the content itself, DLP can accurately classify data as sensitive and enforce policies to prevent its unauthorized exfiltration or misuse.

Why this answer

Content-based classification inspects the actual data within outbound emails—such as credit card numbers, social security numbers, or other regex-defined patterns—to detect sensitive information. DLP systems rely on content analysis (e.g., regular expressions, exact data matching, or fingerprinting) to identify and block policy violations, making this the correct classification type for detecting sensitive data leaving the network.

Exam trap

ISC2 often tests the distinction between context-based and content-based classification, where candidates mistakenly choose context-based because they confuse 'monitoring outbound emails' with analyzing sender/recipient metadata rather than the actual data content.

How to eliminate wrong answers

Option A is wrong because context-based classification examines metadata like sender, recipient, or time of transmission, not the actual data payload, so it cannot detect sensitive content within the email body or attachments. Option C is wrong because user-based classification assigns sensitivity based on the user's identity or group membership, but it does not inspect the content of the email itself, making it insufficient for DLP detection of specific data patterns. Option D is wrong because role-based classification uses job roles to determine data access rights, but it does not analyze the content of outbound messages, so it cannot identify sensitive information in transit.

584
MCQmedium

A network engineer is configuring 802.1X authentication for wired network access. The authentication server supports EAP-TLS. What must be deployed to clients to support this authentication method?

A.Client certificate
B.Server certificate
C.RADIUS server
D.Shared secret
AnswerA

EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) is a robust, certificate-based EAP method designed for strong mutual authentication. For a client to successfully authenticate using EAP-TLS, it must possess and present its own digital certificate to the authentication server (e.g., RADIUS server). This client certificate serves as proof of identity, allowing the server to verify the client's legitimacy and establish a secure, trusted communication channel before granting network access. Without a valid client certificate, EAP-TLS authentication cannot proceed.

Why this answer

EAP-TLS requires mutual authentication using digital certificates on both the client and the server. The client must present a certificate to prove its identity to the authentication server, which is validated against a trusted root CA. Without a client certificate, EAP-TLS cannot establish the TLS tunnel, as it relies on certificate-based client authentication per RFC 5216.

Exam trap

ISC2 often tests the distinction between what is deployed to clients versus the infrastructure; candidates mistakenly choose 'server certificate' because they know TLS requires certificates, but forget that EAP-TLS mandates client certificates for mutual authentication.

How to eliminate wrong answers

Option B is wrong because a server certificate is already required by the authentication server (RADIUS) for EAP-TLS, but the question asks what must be deployed to clients, not the server. Option C is wrong because a RADIUS server is the authentication server itself, not something deployed to clients; clients communicate with the RADIUS server via the authenticator (switch). Option D is wrong because a shared secret is used between the authenticator (switch) and the RADIUS server for secure communication, not between the client and the authentication server in EAP-TLS.

585
MCQmedium

A financial institution must retain customer transaction records for 7 years. After that, what is the most appropriate action?

A.Degauss and physically destroy
B.Securely delete using overwriting
C.Transfer to a third-party storage vendor
D.Archive to tape for additional redundancy
AnswerB

Secure deletion through overwriting involves writing new data, such as zeros, ones, or random patterns, multiple times over the original data's physical location on the storage medium. This process renders the original data irretrievable, even with advanced forensic techniques, effectively meeting data disposal requirements for most regulatory and security standards. It is a cost-effective and widely applicable method for ensuring data confidentiality on reusable storage devices without destroying the media itself.

Why this answer

After the 7-year retention period, the most appropriate action is to securely delete the records using overwriting. This ensures that the data is irrecoverable while maintaining compliance with data disposal policies. Overwriting with multiple passes (e.g., using the Gutmann method or DoD 5220.22-M standard) prevents data remanence, which is critical for financial records.

Exam trap

The trap here is that candidates often confuse 'secure deletion' with 'physical destruction' or 'archiving,' failing to recognize that after the retention period, the primary goal is to eliminate the data securely, not to preserve or transfer it.

How to eliminate wrong answers

Option A is wrong because degaussing and physical destruction are excessive for digital records that only need secure deletion; degaussing destroys the magnetic media entirely, which is unnecessary and may not be feasible for all storage types (e.g., SSDs). Option C is wrong because transferring to a third-party storage vendor does not address the requirement to dispose of the data after retention; it merely shifts custody, which could lead to compliance violations. Option D is wrong because archiving to tape for additional redundancy retains the data beyond the required period, violating the retention policy and increasing legal and security risks.

586
Matchingmedium

Match each OSI layer to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Frames and MAC addressing

Routing and logical addressing

End-to-end reliability and segmentation

User interface and application services

Why these pairings

The correct matches are: Transport with reliable data transfer, Network with routing and logical addressing, Data Link with frame transmission between nodes, and Physical with bit transmission. Common confusions involve swapping Transport and Network functions.

587
MCQmedium

A hospital is implementing an access control system for its electronic health record (EHR) application. The system must ensure that only authorized healthcare providers can access patient records based on their role (doctor, nurse, administrator), department (cardiology, oncology, etc.), and patient consent status. The hospital also needs to support break-the-glass access for emergencies. The current solution uses static role-based access control (RBAC) but fails to enforce department-level restrictions and consent checks. What is the most appropriate access control model to address these requirements?

A.Enhance the existing RBAC model with more granular roles for each department
B.Use mandatory access control (MAC) with security labels per patient record
C.Implement an attribute-based access control (ABAC) system
D.Apply discretionary access control (DAC) allowing providers to set access permissions
AnswerC

Implementing an Attribute-Based Access Control (ABAC) system is the most suitable solution because it evaluates access requests based on a combination of attributes related to the user (e.g., role, department), the resource (e.g., patient data sensitivity, consent status), and the environment (e.g., time of day, emergency flag). This dynamic policy evaluation capability allows ABAC to precisely enforce complex rules, such as patient-specific consent requirements and "break-the-glass" emergency access, providing unparalleled flexibility and granularity.

Why this answer

Attribute-based access control (ABAC) is the correct choice because it can dynamically evaluate multiple attributes—such as user role, department, patient consent status, and emergency context—to grant or deny access. Unlike static RBAC, ABAC supports fine-grained, context-aware policies that can enforce department-level restrictions and consent checks, and it can incorporate break-the-glass rules by evaluating an emergency attribute or time-based condition.

Exam trap

The trap here is that candidates often assume RBAC can be extended with more roles to cover all requirements, but they miss that RBAC cannot dynamically evaluate multi-attribute conditions like consent status or emergency context without becoming unmanageable, whereas ABAC is designed for exactly such fine-grained, attribute-driven policies.

How to eliminate wrong answers

Option A is wrong because simply adding more granular roles to RBAC would still result in a static, role-based model that cannot evaluate dynamic attributes like patient consent status or emergency context; it would require an explosion of roles (e.g., 'Cardiology-Nurse-ConsentYes') that is impractical and does not support break-the-glass. Option B is wrong because MAC uses fixed security labels (e.g., classification levels) assigned by a central authority and cannot dynamically enforce consent status or department-specific rules based on user attributes; it is designed for confidentiality hierarchies, not fine-grained, multi-attribute policies. Option D is wrong because DAC allows data owners (e.g., individual providers) to set permissions, which violates the hospital's need for centralized, policy-driven enforcement of department and consent restrictions and would introduce security inconsistencies and potential unauthorized sharing.

588
MCQhard

A security assessment reveals that a web application uses client-side input validation exclusively. What is the most likely security risk?

A.Attacker can inject malicious scripts that execute on the client side.
B.An attacker can submit malicious data directly to the server without client-side constraints.
C.The application will have poor user experience due to slow responses.
D.The client-side code can be obfuscated but not decrypted.
AnswerB

Client-side validation, implemented in the user's browser, can be easily bypassed by an attacker using various methods, such as disabling JavaScript, manipulating browser developer tools, or intercepting and modifying requests with proxy tools like Burp Suite. Without robust server-side validation, the application's backend will process any data received, including malicious inputs, directly from the attacker, leading to potential vulnerabilities like SQL injection, command injection, or data corruption, as the server trusts the unverified input.

Why this answer

Client-side validation (e.g., JavaScript in the browser) can be bypassed by intercepting and modifying HTTP requests using tools like Burp Suite or cURL. Since the server does not re-validate the input, an attacker can submit crafted payloads (e.g., SQL injection, command injection) directly to the server, leading to data breaches or code execution. This violates the principle of defense in depth, where validation must occur on the server side regardless of client-side checks.

Exam trap

The trap here is that candidates confuse client-side validation with a security control, when in fact it is only a usability feature that provides no real security against a determined attacker.

How to eliminate wrong answers

Option A is wrong because client-side validation does not inherently prevent or enable XSS; XSS is a separate vulnerability caused by improper output encoding, not by the location of input validation. Option C is wrong because client-side validation typically improves user experience by providing instant feedback, not causing slow responses. Option D is wrong because client-side code can be obfuscated to hinder readability, but it can always be decrypted or reversed by the client (e.g., via browser developer tools), making obfuscation a weak security control.

589
MCQhard

A software vulnerability allows an attacker to overwrite a return address on the stack to execute arbitrary code. What mitigation technique randomizes the memory layout to prevent the attacker from predicting target addresses?

A.ASLR (Address Space Layout Randomization)
B.Stack canary
C.Data Execution Prevention (DEP)
D.NX bit (No-Execute)
AnswerA

ASLR (Address Space Layout Randomization) actively randomizes the base memory addresses of key program components like the executable, libraries, stack, and heap each time a program loads. This randomization makes it significantly more challenging for an attacker to reliably predict the exact memory locations of critical data or functions they intend to overwrite or jump to. By introducing unpredictability into the memory layout, ASLR directly hinders exploits that rely on fixed or predictable memory addresses.

Why this answer

ASLR (Address Space Layout Randomization) randomizes the base addresses of the stack, heap, and libraries each time a program runs, making it infeasible for an attacker to predict the exact address to overwrite a return pointer with. This directly defeats the return-to-libc and ROP techniques that depend on knowing target addresses. It is the canonical mitigation for memory-layout predictability.

Exam trap

CISSP often tests the confusion between ASLR (randomizes addresses) and DEP/NX (prevents execution of data), so candidates must map the question's keyword 'randomizes memory layout' specifically to ASLR.

How to eliminate wrong answers

Option B is wrong because a stack canary places a sentinel value before the return address to detect overflow at runtime — it detects corruption but does not randomize memory layout. Option C is wrong because DEP marks memory pages as non-executable to prevent code execution from data regions, which is a different control (execution prevention, not address randomization). Option D is wrong because the NX bit is the hardware implementation of DEP; it prevents execution of data pages but does not randomize addresses.

590
MCQeasy

Which protocol is specifically designed for authorization and not authentication, often using grant types like authorization code and client credentials?

A.SAML 2.0
B.OpenID Connect
C.Kerberos
D.OAuth 2.0
AnswerD

OAuth 2.0 is an authorization framework specifically designed to enable a third-party application to obtain limited access to an HTTP service on behalf of a resource owner. It orchestrates an approval interaction where the user grants specific permissions to the application without ever sharing their credentials with it. This protocol's core purpose is the secure delegation of authority for accessing protected resources, making it an authorization framework rather than an authentication protocol for the end-user.

Why this answer

OAuth 2.0 is an authorization framework, not an authentication protocol, and it defines grant types such as authorization code, client credentials, implicit, and resource owner password credentials. It issues access tokens that grant scoped permissions to resources, deliberately leaving user identity verification to other layers. This is why OAuth 2.0 is the correct answer for a protocol designed specifically for authorization.

Exam trap

CISSP often tests the OAuth-versus-OIDC confusion, and the trap is selecting OpenID Connect because candidates conflate 'authorization' with 'authentication' and forget that OIDC is the authentication layer built on OAuth.

How to eliminate wrong answers

Option A (SAML 2.0) is wrong because SAML is primarily an authentication and single sign-on protocol that asserts user identity via XML assertions, not a delegated authorization framework with grant types. Option B (OpenID Connect) is wrong because OIDC is an authentication layer built on top of OAuth 2.0 that adds an ID token to verify user identity, so it is not 'authorization only.' Option C (Kerberos) is wrong because Kerberos is a ticket-based authentication protocol for network services, not an authorization framework with grant types like authorization code or client credentials.

591
MCQmedium

A security engineer is designing an API that handles sensitive customer data. The engineer wants to ensure that only authorized clients can access the API, and that requests are not tampered with in transit. Which approach best addresses both requirements?

A.Enforcing TLS for all communications
B.Requiring a digital signature using HMAC on each request
C.Implementing OAuth 2.0 with Bearer tokens over HTTPS
D.Using API keys transmitted in the request header
AnswerC

Implementing OAuth 2.0 with Bearer tokens over HTTPS provides a robust solution for delegated authorization, allowing a third-party application to access protected resources on behalf of a user without exposing the user's credentials. OAuth 2.0 defines the authorization flow, while Bearer tokens serve as the credentials presented by the client to access resources. HTTPS is essential to protect the confidentiality and integrity of these tokens and the sensitive data exchanged, preventing interception and ensuring secure communication.

Why this answer

OAuth 2.0 with Bearer tokens over HTTPS combines a token-based authorization framework with TLS encryption. HTTPS (TLS) ensures confidentiality and integrity of data in transit, preventing tampering, while OAuth 2.0 provides a standardized mechanism for issuing and validating access tokens, ensuring only authorized clients with valid tokens can access the API. This dual approach directly addresses both authorization and integrity requirements.

Exam trap

The trap here is that candidates often assume TLS alone is sufficient for API security, overlooking that TLS provides transport-layer security but does not enforce application-layer authorization, which is a separate requirement.

How to eliminate wrong answers

Option A is wrong because enforcing TLS for all communications only protects data in transit (confidentiality and integrity) but does not provide any mechanism for authenticating or authorizing individual clients; any client with network access could still call the API. Option B is wrong because requiring a digital signature using HMAC on each request provides integrity and authenticity of the request payload but does not inherently enforce client authorization; HMAC alone does not manage token issuance, revocation, or scoped permissions. Option D is wrong because using API keys transmitted in the request header provides a simple form of client identification but lacks robust authorization scoping, and if transmitted over plain HTTP (or even HTTPS without proper token management), they are vulnerable to interception and replay; API keys are not designed for fine-grained authorization or delegation.

592
MCQmedium

In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?

A.Domain Controller
B.Ticket Granting Server (TGS)
C.Key Distribution Center (KDC)
D.Authentication Server (AS)
AnswerD

The Authentication Server (AS) is the precise Kerberos component responsible for the initial authentication of a user or service principal. Upon successful authentication, typically involving a shared secret (like a password hash), the AS issues a Ticket Granting Ticket (TGT) to the client. This TGT is then used by the client to request service tickets from the Ticket Granting Server (TGS) without needing to re-authenticate with the AS, streamlining subsequent access.

Why this answer

In Kerberos, the Authentication Server (AS) is the component that verifies the user's credentials (typically by decrypting a timestamp with the user's long-term key) and issues the Ticket Granting Ticket (TGT). The AS is part of the Key Distribution Center (KDC), but it is specifically the AS that performs authentication and returns the TGT. This makes Authentication Server the correct answer.

Exam trap

CISSP often tests the confusion between the KDC (the overall service) and the AS (the specific component that issues the TGT), causing candidates to pick KDC or TGS instead of Authentication Server.

How to eliminate wrong answers

Option A is wrong because Domain Controller is the Windows server role that hosts the KDC, but it is not the specific Kerberos component that issues the TGT. Option B is wrong because the Ticket Granting Server (TGS) issues service tickets after the client presents a valid TGT; it does not issue the TGT itself. Option C is wrong because the Key Distribution Center (KDC) is the overarching service that includes both the AS and TGS; while the KDC hosts the AS, the question asks for the specific component that issues the TGT, which is the AS.

593
MCQeasy

In LDAP, what does the Distinguished Name (DN) uniquely identify?

A.An entry in the directory
B.The root of the directory
C.The schema of the directory
D.A group within the directory
AnswerA

The Distinguished Name (DN) serves as the unique identifier for every individual entry within an LDAP directory. It specifies the exact, unambiguous path from the root of the Directory Information Tree (DIT) down to that specific entry, composed of a sequence of Relative Distinguished Names (RDNs). This hierarchical naming ensures that no two entries can share the same DN, guaranteeing absolute uniqueness across the entire directory and enabling precise referencing for all operations.

Why this answer

In LDAP, the Distinguished Name (DN) is a globally unique identifier for a single entry in the directory, composed of a sequence of Relative Distinguished Names (RDNs) that describe the entry's path from the leaf to the root. For example, cn=John Doe,ou=Users,dc=example,dc=com uniquely identifies one entry. The DN is used in bind operations, search base specifications, and modify operations to target a specific entry.

Exam trap

CISSP often tests whether candidates understand LDAP naming hierarchy — the trap is confusing the DN (a specific entry) with the base DN (the root suffix) or with the schema that governs the directory.

How to eliminate wrong answers

Option B is wrong because the root of the directory is identified by the base DN (e.g., dc=example,dc=com), which is a suffix of an entry's DN, not the DN itself. Option C is wrong because the schema defines the object classes and attribute types allowed in the directory, not the identity of an entry. Option D is wrong because a group is just one type of entry; a DN can identify a user, group, printer, or any other object, so 'a group' is too narrow and not the definition of a DN.

594
MCQhard

An organization's backup strategy includes daily full backups and hourly incremental backups. The system suffers a ransomware attack that encrypts all data. Which backup set is essential to restore the most recent clean state?

A.The last full backup plus all incremental backups after that
B.The last full backup plus the last incremental backup
C.The last full backup only
D.The last incremental backup only
AnswerA

When employing a daily full backup strategy combined with incremental backups, a complete restoration to the most recent state requires the last full backup as the foundational baseline. Subsequently, all incremental backups taken after that full backup must be applied sequentially. Each incremental backup captures only the changes since the *previous* backup, ensuring that every modification up to the point of failure is included for a comprehensive and accurate recovery.

Why this answer

To restore the most recent clean state after a ransomware attack, you need the last full backup as the base and all subsequent incremental backups to apply every change made up to the moment before the attack. Incremental backups capture only data changed since the last backup (full or incremental), so skipping any breaks the chain and results in data loss. Option A correctly includes the full backup and every incremental backup after it, ensuring a complete restoration to the latest point before encryption.

Exam trap

The trap here is that candidates confuse incremental backups with differential backups, mistakenly thinking only the last incremental is needed, when in fact incremental backups require the entire chain from the last full backup to restore completely.

How to eliminate wrong answers

Option B is wrong because it omits all intermediate incremental backups between the last full and the last incremental, which would leave the restored data missing changes from those skipped intervals, resulting in an incomplete state. Option C is wrong because a full backup alone restores only the data as of its creation time, losing all changes made by subsequent hourly increments, which is far from the most recent clean state. Option D is wrong because an incremental backup contains only changes since the last backup and cannot be restored without its base full backup and all prior increments in the chain; applying it alone would fail due to missing parent data.

595
MCQhard

During a vulnerability assessment, a security analyst discovers that a web application uses a library known to be vulnerable to Log4Shell (CVE-2021-44228). Which type of vulnerability does this represent?

A.Server-side request forgery (SSRF)
B.Vulnerable components
C.Insecure deserialization
D.Security misconfiguration
AnswerB

Vulnerable components refer to weaknesses found within third-party libraries, frameworks, or modules that are integrated into an application. The Log4Shell vulnerability (CVE-2021-44228) is a quintessential example, where a critical remote code execution flaw existed within the widely used Apache Log4j logging library itself. Discovering a flaw in a logging library directly aligns with identifying a vulnerable component, as the application's security posture is compromised by a defect in one of its constituent parts.

Why this answer

Log4Shell (CVE-2021-44228) is a remote code execution flaw in the Apache Log4j 2 library's JNDI lookup feature. Because the vulnerability resides in a third-party dependency that the application includes, it is classified under OWASP Top 10 A06:2021 — Vulnerable and Outdated Components. The application code itself may be fine; the risk comes from the library version it ships with.

Exam trap

CISSP often tests the confusion between 'the app has a bug' and 'the app uses a buggy library' — candidates pick SSRF or deserialization because Log4Shell's exploit path resembles those, missing that the vulnerability classification is about the component, not the attack technique.

How to eliminate wrong answers

Option A is wrong because SSRF involves the server being tricked into making requests to unintended destinations — while Log4Shell's JNDI lookup can be leveraged for SSRF-like behavior, the root vulnerability class is the vulnerable component, not SSRF. Option C is wrong because insecure deserialization refers to untrusted data being deserialized into objects (e.g., Java ObjectInputStream, Python pickle) — Log4Shell exploits a JNDI lookup, not a deserialization sink. Option D is wrong because security misconfiguration refers to improperly configured servers, frameworks, or cloud services (default credentials, verbose errors, open buckets), not a flaw in a library's code.

596
MCQmedium

Which type of firewall can inspect the contents of application-layer traffic, such as HTTP requests, and block malicious payloads?

A.Packet filter firewall
B.Circuit-level gateway
C.Application proxy firewall
D.Stateful inspection firewall
AnswerC

An application proxy firewall, also known as a Layer 7 firewall, acts as a full intermediary for specific application protocols. It terminates both the client's and the server's connections, completely parsing and re-establishing them. This deep inspection allows it to fully understand, filter, and even modify application-layer commands and data, providing granular control and robust security against application-specific attacks.

Why this answer

An application proxy firewall (also known as an application-level gateway) operates at Layer 7 of the OSI model and can fully inspect the content of application-layer protocols such as HTTP, FTP, and SMTP. By terminating the client connection and establishing a separate connection to the server, it can parse and validate the payload—for example, examining HTTP request bodies for SQL injection strings or malicious scripts—and block them before they reach the internal server. This deep inspection capability distinguishes it from lower-layer firewalls that only examine headers or connection states.

Exam trap

The trap here is that candidates often confuse a stateful inspection firewall (which tracks connection state) with an application proxy firewall, mistakenly believing that stateful inspection includes deep payload analysis, when in fact stateful inspection only monitors packet headers and connection state at Layers 3 and 4.

How to eliminate wrong answers

Option A is wrong because a packet filter firewall operates at Layer 3 (and sometimes Layer 4), inspecting only source/destination IP addresses, ports, and protocol types; it cannot examine the application-layer payload of an HTTP request. Option B is wrong because a circuit-level gateway operates at Layer 5 (session layer) and validates TCP handshakes and session establishment (e.g., SOCKS proxy), but it does not inspect the contents of application-layer traffic. Option D is wrong because a stateful inspection firewall tracks the state of network connections (e.g., TCP sequence numbers) at Layers 3 and 4, but it does not perform deep packet inspection of application-layer payloads like HTTP bodies.

597
MCQhard

An organization uses a siem to collect logs from multiple sources. The security team notices that some events are missing during peak traffic hours. Analysis shows that the log sources are sending data via UDP. What is the most likely cause?

A.Clock skew between sources and SIEM
B.Insufficient SIEM storage capacity
C.UDP packet loss
D.Network bandwidth saturation
AnswerC

UDP (User Datagram Protocol) is a connectionless protocol that offers no guarantees of delivery, ordering, or duplicate protection. When log events are transmitted via UDP, packets can be dropped by network devices or the receiving SIEM without any notification to the sender, and there are no built-in mechanisms for retransmission. This inherent unreliability makes UDP packet loss a direct and common cause for missing log events within a SIEM system, as the sender is unaware of the loss.

Why this answer

UDP is a connectionless, best-effort transport protocol that does not guarantee delivery. During peak traffic hours, network congestion can cause UDP datagrams to be dropped without any retransmission mechanism, leading to missing events in the SIEM. This is the most direct and likely cause given the scenario.

Exam trap

The trap here is that candidates may incorrectly attribute missing events to storage or bandwidth issues, but the question specifically highlights UDP as the transport, which directly implies packet loss due to the protocol's lack of reliability.

How to eliminate wrong answers

Option A is wrong because clock skew would cause timestamp misalignment, not event loss; NTP synchronization is the standard remedy. Option B is wrong because insufficient SIEM storage would cause older data to be rotated out or ingestion to stop, not selective loss during peak hours. Option D is wrong because network bandwidth saturation could cause packet loss, but the specific mention of UDP points to the protocol's lack of reliability as the root cause; bandwidth saturation alone would affect TCP and UDP equally, but TCP would retransmit lost segments.

598
Multi-Selectmedium

A security architect is designing a network segmentation strategy for a financial institution. Which TWO techniques are best suited for implementing micro-segmentation in a data center environment? (Select two.)

Select 2 answers
A.VLANs (Virtual Local Area Networks)
B.Software-Defined Networking (SDN)
C.Hypervisor-based firewalls
D.Physical network firewalls
E.DMZ (screened subnet)
AnswersB, C

Software-Defined Networking (SDN) provides dynamic, centralized control over network infrastructure, enabling highly granular security policies. By decoupling the control plane from the data plane, SDN controllers can define and enforce per-application or per-workload segmentation policies, often leveraging virtual switches to isolate East-West traffic. This allows for flexible, identity-based security that adapts to changing application requirements.

Why this answer

Software-Defined Networking (SDN) is correct because it centralizes control-plane policy and lets the architect program granular, workload-level segmentation rules (e.g., via OpenFlow or APIs) that can be applied dynamically across the data center fabric, which is essential for micro-segmentation. Hypervisor-based firewalls are correct because they enforce Layer 2–4 (and often Layer 7) policy directly at the virtual NIC of each VM, enabling per-workload isolation and east-west traffic control without relying on physical topology. VLANs are not the best fit because they provide coarse Layer 2 broadcast-domain separation (limited to ~4094 IDs) rather than fine-grained per-workload policy.

Physical network firewalls are too coarse and chokepoint-oriented for micro-segmentation, as they cannot practically enforce policy between every workload pair. A DMZ (screened subnet) is a perimeter segmentation pattern for exposing services to untrusted networks, not an east-west micro-segmentation technique inside the data center.

Exam trap

Candidates often confuse traditional network segmentation (such as VLANs or physical firewalls) with micro-segmentation. While VLANs segment networks at Layer 2, they lack the granularity, scalability, and dynamic policy enforcement required for workload-level (micro) isolation in a cloud or virtualized data center.

599
MCQeasy

Which of the following is an example of an Insecure Direct Object Reference (IDOR) vulnerability?

A.An attacker intercepts session cookies to impersonate a user
B.An attacker uses a SQL injection to retrieve data from the database
C.An attacker submits a cross-site request forgery (CSRF) token to perform actions
D.An attacker changes the user ID parameter in a URL to view another user's profile
AnswerD

This is a classic example of an Insecure Direct Object Reference (IDOR). The application directly exposes a reference to an internal implementation object, such as a user ID in a URL parameter, without adequately verifying the user's authorization to access that specific object. By simply modifying the user ID parameter, the attacker can bypass access controls and retrieve or manipulate data belonging to other users, demonstrating a critical authorization flaw.

Why this answer

IDOR occurs when an application exposes an internal object reference, such as a user ID in a URL, and fails to verify that the requester is authorized to access that object. Changing the user ID parameter to view another user's profile is the textbook example of this broken access control flaw.

Exam trap

CISSP often tests the distinction between access control flaws and injection or session attacks, so the trap is picking SQL injection or session hijacking when the scenario describes manipulating an object reference.

How to eliminate wrong answers

Option A is wrong because intercepting session cookies is session hijacking, not IDOR. Option B is wrong because SQL injection exploits unsanitized input to manipulate database queries, which is a different vulnerability class. Option C is wrong because submitting a CSRF token describes a cross-site request forgery scenario, not direct object reference manipulation.

600
MCQmedium

A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?

A.Bell-LaPadula model
B.Biba model
C.Brewer-Nash model
D.Clark-Wilson model
AnswerA

The Bell-LaPadula model is a state machine model primarily designed to enforce strict confidentiality in multi-level security environments, making it ideal for military systems handling classified information. It operates on two core rules: the "simple security property" (no read up), preventing subjects from reading data at a higher classification level, and the "*-property" (no write down), preventing subjects from writing data to a lower classification level. These rules ensure that information flows only upwards, effectively protecting classified data from unauthorized disclosure.

Why this answer

The Bell-LaPadula model is a mandatory access control (MAC) model built around data confidentiality, using security labels and clearances so that subjects cannot read data above their clearance (no read up) and cannot write data below their level (no write down). This exactly matches the military classification scenario where Top Secret, Secret, Confidential, and Unclassified labels are mandatory and users are cleared to a specific level.

Exam trap

CISSP often tests the classic confidentiality-versus-integrity confusion, so the trap is choosing Biba when the scenario describes classification labels and clearance-based reading restrictions.

How to eliminate wrong answers

Option B is wrong because the Biba model enforces integrity, not confidentiality, using no read down and no write up rules. Option C is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in commercial environments, not military classification enforcement. Option D is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not on clearance-based confidentiality labels.

Page 7

Page 8 of 11

Page 9

All pages