Courseiva

Certified Information Systems Security Professional CISSP (CISSP) — Questions 601–675

816 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
MCQmedium

Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?

A.To determine the maximum acceptable outage for each process
B.To test the disaster recovery plan
C.To assign roles and responsibilities during a disaster
D.To select a hot site vendor
AnswerA

The primary goal of a Business Impact Analysis (BIA) is to systematically identify and quantify the potential impacts of business disruptions and, crucially, to determine the Maximum Acceptable Outage (MAO), also known as Maximum Tolerable Downtime (MTD), for each critical business process. This analysis establishes the absolute longest period a business function can be unavailable before suffering unacceptable consequences, thereby setting critical recovery time objectives (RTOs) that guide subsequent disaster recovery planning and resource allocation.

Why this answer

The primary goal of a Business Impact Analysis (BIA) is to identify the critical business processes and determine the maximum acceptable outage (MAO) or maximum tolerable downtime (MTD) for each. This involves assessing the financial, operational, and legal impacts of disruptions over time. The BIA provides the data needed to set recovery time objectives (RTOs) and recovery point objectives (RPOs), which drive the overall business continuity strategy.

Thus, determining the maximum acceptable outage is the core purpose of a BIA.

Exam trap

CISSP often tests the confusion between the BIA and other BCP phases, such as plan testing or role assignment, so candidates must remember that the BIA is strictly about identifying critical processes and their impact over time, not about implementing or testing recovery strategies.

How to eliminate wrong answers

Option B is wrong because testing the disaster recovery plan is part of the testing and maintenance phase, not the BIA; the BIA informs the plan but does not test it. Option C is wrong because assigning roles and responsibilities is a component of the business continuity plan development, not the BIA itself; the BIA identifies what needs to be recovered, not who does it. Option D is wrong because selecting a hot site vendor is a recovery strategy decision that comes after the BIA has determined the requirements; the BIA does not involve vendor selection.

602
MCQmedium

An organization wants to implement a security mechanism that ensures all accesses are mediated and cannot be bypassed, is tamperproof, and is small enough to be verified. This describes which concept?

A.Trusted Computing Base (TCB)
B.Reference Monitor
C.Trusted Platform Module (TPM)
D.Security Kernel
AnswerB

The reference monitor is an abstract, conceptual security mechanism that mediates all access attempts by subjects to objects, ensuring strict compliance with the system's defined security policy. For it to be truly effective and secure, it must possess three fundamental properties: it must be tamperproof, always invoked for every access request, and verifiable, allowing its correctness to be mathematically proven. This abstract model serves as the foundational principle for designing secure access control enforcement.

Why this answer

A reference monitor is the abstract security concept that enforces access control by mediating every access request between subjects and objects, is tamperproof, and is small enough to be verified. These three properties — complete mediation, tamperproofness, and verifiability — are the defining characteristics of a reference monitor as described in the Orange Book (TCSEC). It is the conceptual model that a security kernel implements in hardware and software.

Exam trap

CISSP often tests the confusion between the reference monitor (abstract concept), security kernel (implementation), and TCB (the entire trusted base), so candidates pick the broader or narrower term instead of the one matching the three defining properties.

How to eliminate wrong answers

Option A is wrong because the Trusted Computing Base (TCB) is the totality of protection mechanisms within a system (hardware, firmware, software) that enforce the security policy — it is broader than the reference monitor and includes the reference monitor as a component. Option C is wrong because a Trusted Platform Module (TPM) is a hardware chip that stores cryptographic keys and supports secure boot and attestation; it is a specific implementation technology, not the abstract mediation concept. Option D is wrong because a security kernel is the actual hardware/software implementation of the reference monitor concept — the reference monitor is the abstract model, while the security kernel is its concrete realization.

603
MCQeasy

Which principle ensures that a user is granted only the permissions necessary to perform their job functions?

A.Need-to-know
B.Least privilege
C.Separation of duties
D.Zero standing privileges
AnswerB

The principle of least privilege mandates that users, programs, or processes are granted only the absolute minimum set of permissions or access rights required to perform their legitimate tasks and nothing more. This fundamental security practice minimizes the attack surface by reducing the potential damage from accidental errors, insider threats, or successful external attacks, as compromised accounts have severely limited capabilities. It directly ensures a user is granted only the necessary permissions.

Why this answer

Least privilege is the principle that users should be granted only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting potential damage from accidental or malicious actions. The question explicitly describes granting only necessary permissions, which is the definition of least privilege. This principle is a core tenet of access control and is widely tested in security certifications.

Exam trap

CISSP often tests the confusion between least privilege and need-to-know; candidates may select need-to-know when the scenario emphasizes job function permissions rather than specific data access.

How to eliminate wrong answers

Option A is wrong because need-to-know is a subset of least privilege that focuses on data access based on specific information requirements, not on overall permissions for job functions. Option C is wrong because separation of duties divides critical tasks among multiple people to prevent fraud, rather than limiting permissions to job needs. Option D is wrong because zero standing privileges is a just-in-time access model where users have no persistent permissions, which is a specific implementation of least privilege but not the general principle described.

604
MCQmedium

A healthcare organization uses a custom application to manage patient records. The application uses a database with encrypted columns for sensitive data. The security team discovers that an insider has been copying encrypted data to an external drive. While the data is encrypted, the encryption key is stored in a configuration file accessible to the application. Which additional control would best mitigate this risk?

A.Enable audit logging on the application.
B.Implement role-based access control on the configuration file.
C.Use transparent data encryption (TDE) at the database level.
D.Store the encryption key in a hardware security module (HSM) with access policies.
AnswerD

Storing the encryption key in a Hardware Security Module (HSM) with access policies provides robust protection. An HSM is a tamper-resistant physical device specifically designed to securely generate, store, and manage cryptographic keys, ensuring keys never leave the module in plaintext. Access policies within the HSM enforce strict authentication and authorization, allowing only approved applications or services to perform cryptographic operations *inside* the HSM, thereby preventing direct key exposure and unauthorized copying or extraction.

Why this answer

Storing the encryption key in an HSM with strict access policies removes the key from the application-accessible configuration file, so even an insider with file access cannot retrieve the key. HSMs provide tamper-resistant hardware key storage, enforce cryptographic access controls, and can require dual control or M-of-N authentication, directly mitigating the risk of key exfiltration alongside encrypted data.

Exam trap

CISSP often tests the difference between encryption at rest (TDE) and key management (HSM) — candidates pick TDE thinking it protects against insiders, but if the key is accessible, encryption is defeated.

How to eliminate wrong answers

Option A is wrong because audit logging only records access — it provides detective, not preventive, control and does nothing to stop the insider from copying both the encrypted data and the accessible key. Option B is wrong because RBAC on the configuration file still leaves the key readable by the application (and thus by anyone who compromises the application's identity), and a privileged insider may already have access; it reduces but does not eliminate the exposure. Option C is wrong because TDE encrypts data at rest at the database level but still relies on keys managed by the database or OS — if those keys are accessible, TDE does not prevent an insider from decrypting copied data, and it does not address the configuration-file key exposure.

605
MCQmedium

A security analyst notices that an attacker is sending forged ARP messages onto a local area network, linking the attacker's MAC address with the IP address of the default gateway. This allows the attacker to intercept traffic destined for the gateway. Which OSI layer is directly targeted by this attack?

A.Layer 4 – Transport
B.Layer 3 – Network
C.Layer 1 – Physical
D.Layer 2 – Data Link
AnswerD

The Data Link layer, Layer 2, is responsible for node-to-node data transfer, handling error correction from the physical layer and defining the format of data on the network segment. ARP (Address Resolution Protocol) is a foundational Layer 2 protocol, specifically designed to resolve logical IP addresses to physical MAC addresses within a local area network. ARP spoofing directly exploits the stateless and trusting nature of this layer's address resolution mechanism, allowing attackers to inject forged MAC-to-IP mappings into device ARP caches.

Why this answer

ARP spoofing (or ARP poisoning) operates at Layer 2 (Data Link) because ARP messages are encapsulated directly within Ethernet frames and rely on MAC addresses, not IP routing. By forging ARP replies, the attacker corrupts the IP-to-MAC mapping in the victim's ARP cache, causing frames destined for the default gateway to be sent to the attacker's MAC address instead. This attack exploits the lack of authentication in the ARP protocol (RFC 826) and directly targets the Data Link layer's addressing and frame delivery mechanism.

Exam trap

The trap here is that candidates often confuse ARP's role in resolving IP addresses (Layer 3) with the layer at which the attack actually occurs, mistakenly choosing Layer 3 instead of recognizing that ARP operates at Layer 2 and exploits the Data Link layer's addressing scheme.

How to eliminate wrong answers

Option A is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and port-based services (TCP/UDP), not MAC-to-IP address resolution or frame forwarding. Option B is wrong because Layer 3 (Network) deals with logical addressing and routing (e.g., IP, ICMP), but ARP itself is a Layer 2 protocol that maps IP addresses to MAC addresses and does not involve routing tables or IP header manipulation. Option C is wrong because Layer 1 (Physical) concerns the electrical, mechanical, and procedural interface to the transmission medium (e.g., cables, signals, hubs), not the addressing or frame-level manipulation used in ARP spoofing.

606
MCQeasy

Which of the following is the primary purpose of a configuration management database (CMDB) in asset management?

A.Store information about hardware and software components and their relationships
B.Track software licenses and compliance
C.Perform vulnerability scanning
D.Monitor network performance
AnswerA

A Configuration Management Database (CMDB) is fundamentally designed to serve as a centralized repository for detailed information about all Configuration Items (CIs) within an IT environment. This includes hardware assets, software applications, network devices, services, and documentation. Its primary purpose is to meticulously record the attributes of these components and, critically, map out their interdependencies and relationships, providing a comprehensive understanding of the IT infrastructure's structure and connections. This data is essential for effective IT service management processes.

Why this answer

A CMDB's primary purpose is to store information about configuration items (CIs) — hardware, software, and other assets — and the relationships between them. This relationship mapping supports impact analysis, incident management, and change management by showing how components depend on each other.

Exam trap

CISSP often tests the distinction between a CMDB and an asset inventory — candidates pick license tracking or scanning because they confuse asset management functions with the CMDB's relational purpose.

How to eliminate wrong answers

Option B is wrong because tracking software licenses and compliance is a function of license management or SAM tools, which may feed into a CMDB but are not its primary purpose. Option C is wrong because vulnerability scanning is performed by dedicated scanners (e.g., Nessus, Qualys), not by a CMDB. Option D is wrong because network performance monitoring is handled by monitoring tools (e.g., Nagios, SolarWinds), not by a CMDB.

607
MCQmedium

A security engineer is designing a cryptographic solution to ensure data integrity and non-repudiation. Which combination should be used?

A.HMAC with a shared key
B.Asymmetric encryption with digital signature
C.Digital signature with hashing
D.Symmetric encryption with HMAC
AnswerC

This combination is the standard and correct approach for achieving both integrity and non-repudiation. First, the message is hashed to create a fixed-size digest, ensuring any alteration will change the hash. Then, this hash is encrypted with the sender's private key, creating the digital signature. This process guarantees integrity because the recipient can re-hash the message and compare it to the decrypted signature, and non-repudiation because only the sender's unique private key could have generated a valid signature.

Why this answer

Digital signature with hashing is the correct combination because hashing ensures data integrity by producing a fixed-size digest, and the digital signature encrypts that hash with the sender's private key, providing non-repudiation by proving the sender's identity and preventing denial of message origin. This satisfies both requirements without relying on a shared secret.

Exam trap

The trap here is that candidates often confuse 'asymmetric encryption' with 'digital signature,' thinking encryption alone provides non-repudiation, but encryption only provides confidentiality, while a digital signature specifically uses the private key for signing (not encryption) to achieve non-repudiation.

How to eliminate wrong answers

Option A is wrong because HMAC with a shared key provides integrity and authentication via a symmetric key, but it does not offer non-repudiation since the shared key could be held by either party, allowing denial of origin. Option B is wrong because asymmetric encryption alone (e.g., RSA encryption) does not inherently provide integrity or non-repudiation; it must be combined with a digital signature, which uses the private key to sign, not encrypt. Option D is wrong because symmetric encryption with HMAC ensures confidentiality and integrity, but non-repudiation is absent because the symmetric key is shared, making it impossible to prove which party created the HMAC.

608
MCQhard

During a security audit, a vulnerability scanner reports a buffer overflow vulnerability in a legacy application. The application runs on a system with Data Execution Prevention (DEP/NX) enabled and Address Space Layout Randomization (ASLR) active. Which of the following is the most likely impact of these mitigations on a typical stack-based buffer overflow exploit?

A.They only protect heap-based overflows, not stack-based
B.They completely prevent any exploitation of buffer overflows
C.They make it harder to execute arbitrary code via injected shellcode
D.They have no effect on buffer overflow exploits
AnswerC

This statement is correct because Data Execution Prevention (DEP) directly prevents the execution of code from non-executable memory regions, such as the stack and heap, where injected shellcode typically resides. Concurrently, Address Space Layout Randomization (ASLR) randomizes the memory addresses of key program components, making it extremely challenging for an attacker to reliably predict the exact location of their injected shellcode or necessary return addresses. Together, these mechanisms significantly increase the difficulty and complexity of exploiting buffer overflows with injected shellcode.

Why this answer

DEP/NX marks memory pages as non-executable, so injected shellcode on the stack cannot be executed directly. ASLR randomizes the memory layout, making it difficult for an attacker to reliably jump to existing code (like a ROP gadget or system function). Together they significantly raise the bar for a typical stack-based buffer overflow exploit, though they do not make exploitation impossible.

Exam trap

CISSP often tests whether candidates understand that mitigations like DEP and ASLR raise the difficulty but do not eliminate exploitation — the trap is selecting 'completely prevent.'

How to eliminate wrong answers

Option A is wrong because DEP and ASLR apply to both stack and heap memory — they are not limited to heap-based overflows. Option B is wrong because these mitigations can be bypassed (e.g., return-oriented programming to defeat DEP, memory leaks or brute force to defeat ASLR), so they do not completely prevent exploitation. Option D is wrong because DEP and ASLR demonstrably affect exploitability — they force attackers to use more sophisticated techniques, so they are not without effect.

609
MCQmedium

A vulnerability scanner reports a vulnerability with a CVSS score of 9.8. What does this score indicate?

A.High severity
B.Medium severity
C.Low severity
D.Critical severity
AnswerD

A CVSS score of 9.8 unequivocally falls within the Critical severity range, defined as scores from 9.0 to 10.0. This classification signifies vulnerabilities that are extremely severe, often easily exploitable, and can lead to complete loss of confidentiality, integrity, or availability without requiring user interaction or elevated privileges. Such a high score demands immediate attention and remediation due to the profound potential for widespread damage and business disruption.

Why this answer

A CVSS score of 9.8 falls within the range of 9.0–10.0, which is classified as 'Critical' severity according to the CVSS v3.1 specification. This score typically indicates a vulnerability that can be exploited remotely without authentication and with low attack complexity, often leading to complete compromise of confidentiality, integrity, and availability.

Exam trap

The trap here is that candidates may confuse the CVSS v3.1 severity rating scale with the older v2 scale, where scores of 7.0–10.0 were all labeled 'High', but in v3.1, 9.0–10.0 is explicitly 'Critical'.

How to eliminate wrong answers

Option A is wrong because 'High severity' corresponds to CVSS scores of 7.0–8.9, not 9.8. Option B is wrong because 'Medium severity' corresponds to scores of 4.0–6.9, which is far below 9.8. Option C is wrong because 'Low severity' corresponds to scores of 0.1–3.9, and a score of 9.8 is at the top of the scale, not low.

610
MCQmedium

A security architect is designing a zero trust network. Which principle is fundamental to a zero trust architecture?

A.Trust but verify
B.Rely on perimeter defenses
C.Never trust, always verify
D.Trust internal traffic implicitly
AnswerC

"Never trust, always verify" is the foundational tenet of Zero Trust, asserting that no user, device, or application should be implicitly trusted, regardless of its location or previous authentication status. Every access request must be authenticated, authorized, and continuously validated based on context, such as user identity, device posture, and requested resource. This principle enforces a strict "assume breach" mentality, requiring granular access controls and continuous monitoring to minimize the attack surface and contain potential threats effectively.

Why this answer

Zero trust architecture (ZTA) fundamentally rejects implicit trust based on network location. The principle 'never trust, always verify' mandates continuous authentication and authorization for every access request, regardless of whether it originates from inside or outside the network perimeter. This is enforced through micro-segmentation, least-privilege access, and per-session verification, often using technologies like identity-aware proxies and software-defined perimeters (SDP).

Exam trap

The trap here is that candidates may confuse 'trust but verify' (Option A) with zero trust, but zero trust explicitly removes the initial trust assumption, making 'never trust, always verify' the correct principle.

How to eliminate wrong answers

Option A is wrong because 'trust but verify' is the traditional perimeter-based model that assumes trust once a user or device is inside the network, which is the opposite of zero trust's assumption of breach. Option B is wrong because relying on perimeter defenses is a castle-and-moat approach that fails once an attacker breaches the boundary; zero trust eliminates the concept of a trusted internal network. Option D is wrong because trusting internal traffic implicitly is the exact vulnerability zero trust aims to remove; internal traffic must be subject to the same verification as external traffic.

611
MCQeasy

Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?

A.CVSS
B.NVD
C.CVE
D.OWASP
AnswerA

CVSS provides a standardised, vendor-neutral framework that scores vulnerabilities from 0.0 to 10.0 across base, temporal and environmental metrics, satisfying the stem's requirement for a commonly used severity assessment system. Its base metric group alone captures exploitability and impact, enabling consistent prioritisation across disparate platforms and tooling.

Why this answer

The Common Vulnerability Scoring System (CVSS) is the industry-standard framework for assigning a numerical severity score (0–10) to a vulnerability based on metrics like attack vector, complexity, privileges required, and impact. It is maintained by the Forum of Incident Response and Security Teams (FIRST) and is widely adopted by organizations for prioritization in vulnerability management. CVSS provides a consistent, quantitative measure that allows security teams to compare and triage vulnerabilities across different systems and vendors.

Exam trap

The CISSP exam often tests the distinction between a vulnerability database (NVD), a naming standard (CVE), and a scoring system (CVSS), so the trap here is confusing the repository or identifier with the actual scoring methodology.

How to eliminate wrong answers

Option B (NVD) is wrong because the National Vulnerability Database (NVD) is a repository of vulnerability data that uses CVSS scores, but it is not itself a scoring system; it is a database that references CVSS. Option C (CVE) is wrong because the Common Vulnerabilities and Exposures (CVE) system is a dictionary of unique identifiers for publicly known vulnerabilities, not a scoring or severity assessment system. Option D (OWASP) is wrong because the Open Web Application Security Project (OWASP) provides guidelines, tools, and frameworks for web application security (e.g., the OWASP Top 10), but it does not define a standardized vulnerability scoring system like CVSS.

612
Multi-Selecthard

A network administrator is reviewing the security of the company's VPN solution. They discover that the current VPN uses PPTP. Which TWO of the following are significant security weaknesses associated with PPTP?

Select 2 answers
A.It uses MS-CHAPv2 authentication which is susceptible to brute-force attacks
B.It relies on IKE for key exchange
C.It uses MPPE encryption which is considered weak
D.It supports strong authentication with digital certificates
E.It provides perfect forward secrecy
AnswersA, C

MS-CHAPv2 authentication is critically flawed because it uses a challenge-response mechanism that is highly susceptible to offline dictionary and brute-force attacks. The server's challenge and the client's response, which incorporates a derivative of the user's NTLM password hash, can be captured and then subjected to rapid cracking attempts. This vulnerability allows attackers to recover the user's password hash, subsequently enabling impersonation or decryption of past communications.

Why this answer

PPTP uses Microsoft Point-to-Point Encryption (MPPE), which relies on the RC4 stream cipher. RC4 has known weaknesses, including statistical biases and the ability to recover plaintext after encrypting a large volume of traffic, making it considered weak for modern security requirements. Additionally, PPTP's default authentication protocol is MS-CHAPv2, which is vulnerable to offline brute-force attacks because its challenge-response mechanism uses a weak DES-based hash that can be cracked with tools like Asleap or ChapCrack.

Exam trap

The trap here is that candidates may confuse PPTP's use of MPPE with stronger encryption protocols like IPsec, or mistakenly think that MS-CHAPv2 is secure because it uses a challenge-response mechanism, overlooking its fundamental reliance on weak DES encryption and the NT hash.

613
MCQeasy

A small company with 50 employees operates a flat network where all workstations, servers, and printers are on a single subnet without segmentation. The company recently suffered a ransomware outbreak that spread rapidly from an infected workstation to the file server and multiple other machines, causing significant downtime. The IT manager wants to redesign the network to contain future outbreaks and limit lateral movement. The budget is limited, and the environment uses a mixture of managed and unmanaged switches. Which course of action would BEST mitigate the risk of lateral spread while minimizing cost and complexity?

A.Implement VLANs with ACLs to separate departments and restrict traffic between them.
B.Enable full-disk encryption on all endpoints and servers.
C.Upgrade all endpoint antivirus to the latest version and enable real-time scanning.
D.Deploy a network-based intrusion detection system (IDS) to alert on suspicious traffic.
AnswerA

Implementing VLANs logically segments the flat network into distinct broadcast domains, effectively separating departments. Access Control Lists (ACLs) are then applied to inter-VLAN routing interfaces, such as on a Layer 3 switch or firewall, to strictly control and restrict traffic flow between these segments. This prevents unauthorized lateral movement of threats, ensuring that a compromise in one department cannot easily spread to others, thereby containing potential outbreaks.

Why this answer

Implementing VLANs with ACLs segments the flat network into separate broadcast domains, preventing lateral movement by restricting traffic between departments at Layer 2. This directly contains ransomware propagation without requiring new hardware, as VLANs can be configured on existing managed switches, making it cost-effective. ACLs further enforce least-privilege access between VLANs, blocking unauthorized inter-VLAN communication.

Exam trap

The trap here is that candidates often choose endpoint-focused solutions (like antivirus or encryption) because they seem directly related to malware, but the question specifically targets lateral movement containment, which requires network segmentation, not just endpoint protection.

How to eliminate wrong answers

Option B is wrong because full-disk encryption protects data at rest but does not prevent lateral movement or contain ransomware spread across the network. Option C is wrong because upgrading antivirus only improves endpoint detection but does not segment the network, so ransomware can still propagate laterally via SMB or other protocols. Option D is wrong because a network-based IDS only alerts on suspicious traffic after it occurs, lacking proactive containment to stop lateral movement in real time.

614
MCQhard

A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?

A.Golden ticket attack
B.Pass-the-ticket attack
C.Silver ticket attack
D.Kerberos brute force attack
AnswerA

Forging a TGT with the KRBTGT account hash lets an attacker mint arbitrary Kerberos tickets, including domain admin privileges, without authenticating. This is the defining mechanism of a golden ticket, which grants persistent, forged access to the entire domain.

Why this answer

A Golden Ticket attack occurs when an attacker compromises the KRBTGT account's password hash and uses it to forge a legitimate-looking Kerberos Ticket Granting Ticket (TGT). Because the KRBTGT account signs all TGTs in the domain, a forged TGT is trusted by every Kerberos-enabled service, granting the attacker persistent domain-wide access — often as domain admin — without needing to authenticate normally.

Exam trap

CISSP often tests the distinction between Golden Ticket (KRBTGT hash, forges TGT, domain-wide) and Silver Ticket (service account hash, forges TGS, single service), so candidates who confuse the two ticket types pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because Pass-the-ticket involves stealing and reusing a valid existing Kerberos ticket (TGT or service ticket) from memory, not forging a new one with the KRBTGT hash. Option C is wrong because a Silver ticket attack forges a service ticket (TGS) using the target service account's hash, granting access only to that specific service, not domain-wide admin. Option D is wrong because Kerberos brute force is an online password-guessing attack against the KDC, not a ticket-forging technique.

615
MCQeasy

Which security model focuses on preventing unauthorized access by enforcing a 'no read up, no write down' rule?

A.Clark-Wilson
B.Bell-LaPadula
C.Biba
D.Brewer-Nash
AnswerB

The Bell-LaPadula security model is a foundational confidentiality model specifically designed to prevent unauthorized disclosure of information. It employs a mandatory access control mechanism based on security levels, enforcing two primary rules: the Simple Security Property ("no read up") and the *-Property ("no write down"). This ensures subjects can only access objects at or below their security clearance and cannot write information to a lower security level, effectively protecting classified data.

Why this answer

The Bell-LaPadula model is a formal state machine model for enforcing access control in government and military systems. Its core rule, 'no read up' (simple security property) and 'no write down' (star property), prevents subjects from reading objects at a higher classification level and from writing to objects at a lower classification level, thereby preventing unauthorized disclosure of sensitive information.

Exam trap

The trap here is that candidates often confuse the Biba model's 'no read down, no write up' integrity rules with Bell-LaPadula's confidentiality rules, leading them to select Biba when the question specifically describes 'no read up, no write down'.

How to eliminate wrong answers

Option A is wrong because the Clark-Wilson model focuses on integrity through well-formed transactions and separation of duty, not on confidentiality or the 'no read up, no write down' rule. Option C is wrong because the Biba model enforces integrity with 'no read down, no write up' rules, which is the inverse of Bell-LaPadula's confidentiality rules. Option D is wrong because the Brewer-Nash (Chinese Wall) model prevents conflicts of interest by dynamically controlling access based on previously accessed datasets, not by enforcing a static 'no read up, no write down' policy.

616
MCQeasy

An organization is migrating from a waterfall to an Agile development methodology. Which of the following is a key security advantage of Agile?

A.Security testing is performed only at the end of the project
B.Security issues can be addressed incrementally throughout development
C.Security requirements are finalized upfront
D.Security documentation is minimized to reduce overhead
AnswerB

Agile's iterative nature, characterized by short development cycles or sprints, inherently allows for security issues to be addressed incrementally. As security findings emerge from continuous testing, threat modeling, or code reviews within a sprint, they can be prioritized and remediated promptly in subsequent iterations. This continuous feedback loop ensures that security debt is minimized and risks are mitigated proactively throughout the entire development process.

Why this answer

In Agile development, security testing and remediation are integrated into each iteration (sprint), allowing teams to identify and fix vulnerabilities incrementally rather than waiting until the end. This continuous feedback loop reduces the risk of late-stage security surprises and aligns with the principle of 'shifting left' on security.

Exam trap

The trap here is conflating 'Agile' with 'no documentation' or 'no upfront planning,' when in reality Agile requires disciplined, just-in-time security activities and maintains necessary documentation for compliance and risk management.

How to eliminate wrong answers

Option A is wrong because performing security testing only at the end of the project is a characteristic of the waterfall model, not Agile, and it increases the cost and effort to remediate issues found late. Option C is wrong because Agile embraces changing requirements; security requirements are refined iteratively through backlog grooming and user stories, not finalized upfront. Option D is wrong because while Agile may reduce unnecessary documentation, security documentation (e.g., threat models, security acceptance criteria) is still essential and should not be minimized to the point of compromising auditability or compliance.

617
MCQhard

A multinational corporation is developing a new cloud-based collaboration platform that handles sensitive intellectual property. The platform must ensure end-to-end encryption (E2EE) so that even the cloud provider cannot access the data. Users communicate via chat and file sharing. The architect proposes using a hybrid encryption scheme where each user has a public/private key pair, and for each message, a random symmetric key is used to encrypt the message, which is then encrypted with the recipient's public key. However, there is a requirement for the company to be able to lawfully intercept communications in case of a court order. This conflicts with E2EE. Which design can satisfy both confidentiality and lawful interception?

A.Implement key escrow where the company holds a copy of all users' private keys.
B.Implement a transparent encryption proxy on the user's device that logs all keys and sends them to the company.
C.Use client-side encryption where the encryption key is derived from user password and stored with a backup that can be recovered by the company using a master key.
D.Implement a split-key design where the encryption keys are generated and held by the users, but a separate escrow agent splits the key into two parts: one held by the user and one held by the company. Alternatively, use a 'drop box' approach where communications are recorded in an encrypted format and the company can decrypt only after a court order by using a secondary key that is released upon authorization.
AnswerD

A split-key design maintains End-to-End Encryption (E2EE) by ensuring users retain a critical part of their encryption key, preventing unilateral decryption by the company. Lawful access requires cooperation to reconstruct the key from parts held by the user and an authorized escrow agent. Alternatively, a 'drop box' approach stores encrypted communications, only allowing company decryption via a secondary key released exclusively upon a valid court order, thus preserving E2EE for routine use while enabling legally mandated access.

Why this answer

It uses a split-key or drop-box design that preserves end-to-end encryption for regular communications while enabling lawful interception under strict authorization. In this scheme, the user holds one part of the key and the company holds another, or communications are recorded encrypted and a secondary key is released only after a court order, ensuring that neither the cloud provider nor the company can decrypt data without proper legal process. This satisfies both the E2EE requirement and the lawful interception mandate without compromising the core security principle of least privilege.

Exam trap

The trap here is that candidates often assume key escrow (Option A) is the only way to achieve lawful interception, failing to recognize that escrow breaks E2EE and that split-key or drop-box designs can satisfy both requirements without compromising the confidentiality of all communications.

How to eliminate wrong answers

Option A is wrong because key escrow where the company holds a copy of all users' private keys completely breaks end-to-end encryption, as the company (and potentially the cloud provider) can decrypt any past or future communication at any time, violating the confidentiality requirement. Option B is wrong because a transparent encryption proxy on the user's device that logs all keys and sends them to the company effectively creates a backdoor that bypasses E2EE, allowing the company to access all communications without user consent or court order, and it introduces a single point of compromise. Option C is wrong because deriving encryption keys from user passwords and storing a backup recoverable by a master key means the company can decrypt all data without a court order, and password-derived keys are often weak and vulnerable to offline brute-force attacks, undermining both confidentiality and the lawful interception control.

618
MCQmedium

A company uses WPA2-Enterprise with EAP-TLS for wireless access. An employee reports that a new laptop cannot connect to the wireless network, while older laptops work fine. The employee has installed the correct client certificate. What is the most likely cause?

A.The wireless network uses WPA2-PSK instead of WPA2-Enterprise.
B.The RADIUS server's certificate is not trusted by the new laptop.
C.The client certificate is not correctly associated with the user account.
D.The laptop does not support MSCHAPv2.
AnswerB

EAP-TLS requires the client to validate the RADIUS server's certificate during the TLS handshake. The new laptop likely lacks the issuing CA in its Trusted Root store, so validation fails and authentication aborts, whereas older laptops already trust that CA.

Why this answer

In WPA2-Enterprise with EAP-TLS, mutual authentication requires the client to validate the RADIUS server's certificate. If the new laptop does not trust the RADIUS server's certificate (e.g., its CA root certificate is missing or expired), the EAP-TLS handshake will fail, preventing connection. Older laptops likely have the necessary root CA installed, while the new laptop does not.

Exam trap

The trap here is that candidates may confuse EAP-TLS with EAP-PEAP or EAP-TTLS, which use MSCHAPv2 for inner authentication, and incorrectly assume the issue is MSCHAPv2 support, when in fact EAP-TLS relies solely on certificate trust.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the network uses WPA2-Enterprise with EAP-TLS, not WPA2-PSK; a PSK mismatch would affect all clients, not just the new laptop. Option C is wrong because the employee has installed the correct client certificate, and EAP-TLS authenticates the client based on the certificate itself, not a user account association; the RADIUS server validates the client certificate against its trust store, not a user account. Option D is wrong because EAP-TLS does not use MSCHAPv2; it uses TLS-based certificate authentication, so MSCHAPv2 support is irrelevant.

619
MCQhard

A multinational corporation deploys a single sign-on (SSO) solution using SAML 2.0 across all subsidiaries. Recently, users in one subsidiary report being unable to access an internal application. The identity provider (IdP) logs show successful authentication, but the service provider (SP) logs indicate assertion validation failures. Which of the following is the MOST likely cause?

A.The system clocks on the IdP and SP are significantly out of sync
B.The SP is configured to require a specific SAML attribute not present in the assertion
C.The IdP server for the subsidiary is temporarily unreachable
D.The SAML certificate used by the SP has expired
AnswerA

SAML assertions include `NotBefore` and `NotOnOrAfter` conditions, specifying the validity period. If the IdP and SP clocks are significantly out of sync, the SP might receive an assertion that, according to its own clock, is either not yet valid or already expired. This clock skew leads to a validation failure, often manifesting as a `InvalidTime` error, preventing successful authentication.

Why this answer

SAML 2.0 relies on timestamps (NotBefore and NotOnOrAfter) within the assertion for validity. If the system clocks on the identity provider (IdP) and service provider (SP) are significantly out of sync, the SP will reject the assertion as expired or not yet valid, even though the IdP logs show successful authentication. This is the most common cause of assertion validation failures in cross-domain SSO deployments.

Exam trap

The trap here is that candidates confuse assertion validation failures (which involve timestamps, signatures, or conditions) with authentication failures (which involve credentials or IdP reachability), leading them to incorrectly select options like IdP unreachability or certificate expiration.

How to eliminate wrong answers

Option B is wrong because a missing required SAML attribute would cause an authorization failure or attribute mismatch error, not an assertion validation failure; the SP would still validate the assertion's signature and timestamps first. Option C is wrong because if the IdP server were unreachable, the user would not be able to authenticate at all, and the IdP logs would not show successful authentication. Option D is wrong because an expired SAML certificate would cause a signature validation failure, not a generic assertion validation failure; the SP would log a certificate-related error, not a timestamp or validity period issue.

620
MCQmedium

An organization is migrating from WPA2 to WPA3 for its wireless network. Which improvement does WPA3 provide over WPA2?

A.Use of TKIP for backward compatibility
B.Mandatory use of WPS for easy setup
C.Simultaneous Authentication of Equals (SAE) providing forward secrecy
D.Support for 802.1X only, no personal mode
AnswerC

Simultaneous Authentication of Equals (SAE), also known as Dragonfly Key Exchange, is the foundational key exchange protocol for WPA3-Personal mode. SAE significantly enhances security by providing robust protection against offline dictionary attacks, even if a weak passphrase is used, through its password-authenticated key exchange (PAKE) mechanism. Crucially, SAE also delivers forward secrecy, meaning that if the network's long-term secret key is ever compromised, past session traffic remains encrypted and secure because unique session keys are not derivable from the master key alone.

Why this answer

WPA3 replaces WPA2's Pre-Shared Key (PSK) handshake with Simultaneous Authentication of Equals (SAE), defined in IEEE 802.11-2016 and RFC 7664. SAE uses a Dragonfly key exchange based on discrete logarithm cryptography, which provides forward secrecy: even if an attacker captures the handshake and later obtains the pre-shared key, they cannot decrypt past session traffic. This eliminates the vulnerability to offline dictionary attacks that plagued WPA2-PSK.

Exam trap

The trap here is that candidates confuse WPA3's mandatory use of SAE with the older WPA2-PSK handshake, and mistakenly think WPA3 still supports TKIP or WPS, or that it only works in Enterprise mode, when in fact SAE is the core personal mode enhancement.

How to eliminate wrong answers

Option A is wrong because TKIP (Temporal Key Integrity Protocol) is deprecated and not used in WPA3; WPA3 mandates CCMP (AES) and removes TKIP for security reasons. Option B is wrong because WPS (Wi-Fi Protected Setup) is not mandatory in WPA3; in fact, WPS is often disabled due to its known PIN brute-force vulnerability, and WPA3 does not require it. Option D is wrong because WPA3 supports both Personal mode (SAE) and Enterprise mode (with 802.1X and EAP), not only 802.1X; the personal mode is a key improvement over WPA2.

621
MCQeasy

A DevOps team implements a CI/CD pipeline that runs security scans automatically. The pipeline fails often due to false positives, causing delays. Which approach balances security and efficiency?

A.Tune scan rules to reduce false positives while retaining critical checks.
B.Turn off all security scans.
C.Manually review every false positive.
D.Only run scans on code that is deployed to production.
AnswerA

Tuning scan rules involves refining the configurations of security tools, such as Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST), to align with the application's specific context and risk profile. This process aims to minimize the number of non-actionable false positives, which can overwhelm development teams and lead to alert fatigue, while ensuring that genuine, critical vulnerabilities are still accurately identified and flagged. By customizing rule sets, teams can maintain a high signal-to-noise ratio, making security findings more relevant and actionable within the rapid CI/CD cycle.

Why this answer

Tuning scan rules reduces false positives by adjusting thresholds or disabling low-severity checks while preserving critical security controls (e.g., SAST rules for OWASP Top 10). This maintains automated security validation in the CI/CD pipeline without blocking development velocity, aligning with the principle of 'secure enough' rather than 'perfect security'.

Exam trap

ISC2 often tests the misconception that 'security must never be compromised,' leading candidates to choose manual review (C) or full scans (D), but the CISSP emphasizes risk-based decisions where tuning is the pragmatic balance between security and efficiency.

How to eliminate wrong answers

Option B is wrong because disabling all security scans eliminates detection of vulnerabilities, violating the 'secure development' requirement in the Software Development Security domain. Option C is wrong because manually reviewing every false positive is unscalable and defeats the purpose of automation, causing unacceptable delays in a CI/CD pipeline. Option D is wrong because running scans only on production code misses vulnerabilities introduced earlier in the development lifecycle, violating the 'shift left' security principle and allowing defects to reach production.

622
MCQeasy

An organization's security team wants to validate that its incident response plan works as documented before a real breach occurs. The team needs to exercise communication paths, decision-making, and coordination among technical staff, legal, and public relations without touching production systems. Which of the following is the MOST appropriate exercise type?

A.A vulnerability scan of the production environment to identify weaknesses the plan should address
B.A penetration test conducted by an external firm to simulate a real attacker
C.A full-scale simulation that disables production systems to test real recovery capabilities
D.A tabletop exercise where participants discuss their roles and responses to a simulated scenario
AnswerD

A tabletop exercise gathers stakeholders in a discussion-based setting to walk through a simulated incident, exercising communication, decision-making, and coordination without affecting production. It directly matches the goal of validating the plan and involving legal and public relations personnel in a low-risk environment.

Why this answer

A tabletop exercise is discussion-based and designed to validate plans, roles, and coordination among diverse stakeholders without impacting production. It exercises communication and decision-making with legal and public relations participants, matching the stated goal. Full-scale simulations, vulnerability scans, and penetration tests address different objectives and either disrupt production or fail to exercise the plan.

Exam trap

The trap here is selecting the highest-fidelity exercise such as a full-scale simulation when the objective is low-risk validation of plans and coordination.

623
MCQhard

A security analyst is evaluating the impact of upgrading web servers from TLS 1.2 to TLS 1.3. Which advantage does TLS 1.3 offer in terms of handshake efficiency?

A.It supports the same cipher suites as TLS 1.2
B.Fewer round trips during handshake
C.More round trips during handshake
D.It eliminates the need for asymmetric encryption
AnswerB

TLS 1.3 drastically improves performance by reducing the handshake process to just one Round Trip Time (1-RTT) for initial connections, compared to the two RTTs typically required by TLS 1.2. This efficiency is achieved because the client can proactively send its key share in its initial "Client Hello" message. The server can then immediately respond with its key share and the encrypted handshake messages, allowing application data transmission to begin sooner.

Why this answer

TLS 1.3 reduces the handshake from two round trips (2-RTT) in TLS 1.2 to one round trip (1-RTT) for a full handshake, and offers 0-RTT for resumed sessions. This is achieved by combining the ClientHello and ServerHello with key exchange parameters, eliminating the separate round trip for the ServerHello and Certificate exchange. The result is lower latency and faster connection establishment, which is critical for performance-sensitive applications.

Exam trap

The trap here is that candidates may confuse 'fewer round trips' with 'eliminating asymmetric encryption,' but TLS 1.3 still relies on asymmetric key exchange (e.g., ECDHE) for forward secrecy, just in a more streamlined handshake.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 does not support the same cipher suites as TLS 1.2; it removes weak or obsolete ciphers (e.g., CBC-mode ciphers, RC4, 3DES) and mandates only AEAD ciphers like AES-GCM and ChaCha20-Poly1305. Option C is wrong because TLS 1.3 actually reduces the number of round trips compared to TLS 1.2, not increases them. Option D is wrong because TLS 1.3 still requires asymmetric encryption for the initial key exchange (e.g., ECDHE or DHE) to establish a shared secret; it does not eliminate asymmetric cryptography entirely.

624
MCQmedium

During a security assessment, a penetration tester sends TCP SYN packets to various ports on a target server. Based on the responses, the tester determines which ports are open. This technique is commonly used at which OSI layer?

A.Layer 7 – Application
B.Layer 3 – Network
C.Layer 4 – Transport
D.Layer 2 – Data Link
AnswerC

TCP SYN scanning operates at Layer 4, the Transport layer, because it manipulates TCP flags and port numbers to infer open, closed or filtered states. Ports and TCP handshake behaviour are Transport-layer constructs, so interpreting SYN responses belongs to this layer.

Why this answer

The TCP SYN scan operates at Layer 4 (Transport) of the OSI model because it manipulates TCP segment headers, specifically the SYN flag, to probe port states. The tester sends SYN packets and interprets the response (SYN-ACK for open, RST for closed) to infer port availability, which is a transport-layer function defined by RFC 793.

Exam trap

The trap is that candidates may mistakenly associate the scanning technique with the application layer (Layer 7) because many protocols (HTTP, FTP) run on top of TCP, but the SYN scan itself operates at the transport layer (Layer 4) by manipulating TCP segment headers.

How to eliminate wrong answers

Option A is wrong because Layer 7 (Application) deals with application-specific protocols like HTTP or FTP, not raw TCP segment manipulation; SYN scanning does not involve application-layer payloads. Option B is wrong because Layer 3 (Network) handles IP addressing and routing, not the TCP flags or port numbers used in SYN scanning; the scan relies on transport-layer port numbers, not IP addresses. Option D is wrong because Layer 2 (Data Link) manages framing and MAC addresses on a local network segment; SYN scanning operates above this layer and does not interact with Ethernet frames or switches.

625
MCQhard

A company is deploying a new application that processes personally identifiable information (PII) in a hybrid cloud environment. The security architect needs to ensure that encryption keys are never exposed to the cloud provider. Which solution should be recommended?

A.Envelope encryption with a key management service
B.Server-side encryption with cloud provider managed keys
C.Client-side encryption with keys stored on-premises
D.Server-side encryption with customer-provided keys
AnswerC

Client-side encryption with keys stored on-premises ensures that data is encrypted by the customer's application before it is ever transmitted to or stored in the cloud. The encryption keys are generated, stored, and managed exclusively within the customer's secure on-premises environment, never being exposed to the cloud provider. This architecture provides the strongest assurance of data confidentiality and integrity, as the cloud provider only ever receives encrypted data and possesses no means to decrypt it, thereby maintaining complete customer control over sensitive information.

Why this answer

Client-side encryption ensures that encryption keys are generated and managed on-premises, never transmitted to the cloud provider. This directly meets the requirement that keys are never exposed to the cloud provider, as all cryptographic operations occur before data leaves the customer's controlled environment.

Exam trap

The trap here is confusing 'customer-provided keys' (SSE-C) with 'client-side encryption' — SSE-C still sends the key to the cloud provider for each operation, while client-side encryption keeps the key entirely on-premises.

How to eliminate wrong answers

Option A is wrong because envelope encryption with a key management service still involves the cloud provider's KMS handling the key encryption key (KEK), which could be exposed to the provider. Option B is wrong because server-side encryption with cloud provider managed keys gives the provider full control over the keys, violating the requirement. Option D is wrong because server-side encryption with customer-provided keys (SSE-C) still transmits the key to the cloud provider for each encryption/decryption operation, exposing it to the provider's infrastructure.

626
MCQhard

A security engineer is evaluating a system that uses a Trusted Platform Module (TPM) for secure boot. The TPM measures the boot components and stores the measurements in Platform Configuration Registers (PCRs). Which of the following is a primary security goal achieved by this process?

A.Ensures the boot process has not been tampered with
B.Provides full disk encryption
C.Prevents all malware from executing
D.Authenticates the user during boot
AnswerA

A Trusted Platform Module (TPM) actively measures critical boot components, including firmware, bootloaders, and operating system kernels, before they execute. These measurements are stored in Platform Configuration Registers (PCRs) and compared against known good values. If any component's measurement deviates, it indicates unauthorized modification or tampering, preventing the system from booting or alerting the user to a compromised state.

Why this answer

Measured boot ensures that each boot component's hash is extended into PCRs. The TPM can attest these measurements to a remote verifier, proving the boot integrity.

627
MCQhard

An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?

A.Session recording
B.Password vaulting
C.Break-glass accounts
D.Just-in-time access
AnswerD

Just-in-time (JIT) access is a core principle of modern Privileged Access Management that grants elevated privileges to users only when they are needed, for the specific task at hand, and for a strictly limited duration. This approach significantly reduces the attack surface by minimizing the time privileged accounts exist with standing access. Once the task is completed or the time limit expires, the elevated privileges are automatically revoked, aligning perfectly with the goal of managing privilege duration.

Why this answer

Just-in-time (JIT) access grants elevated privileges only for a limited time when a user requests and is approved for them, which directly reduces standing privileges. This matches the requirement to provide temporary elevated access only when needed.

Exam trap

CISSP often tests the difference between monitoring controls and access-granting controls, so the trap is selecting session recording or password vaulting when the question asks for temporary elevation.

How to eliminate wrong answers

Option A is wrong because session recording is a monitoring and audit control, not an access-granting mechanism. Option B is wrong because password vaulting stores and checks out credentials but does not by itself enforce time-bound elevation. Option C is wrong because break-glass accounts are emergency fallback accounts with standing high privileges, which increases rather than reduces standing privilege risk.

628
MCQeasy

A security manager is tasked with classifying data based on its sensitivity. Which of the following is the PRIMARY reason for data classification?

A.To ensure appropriate protection measures are applied to data based on its value and sensitivity.
B.To satisfy regulatory requirements for data retention.
C.To facilitate data sharing across departments without restrictions.
D.To simplify the process of granting access to users.
AnswerA

Data classification is the foundational process for assigning a level of sensitivity or criticality to information assets. This categorization directly dictates the specific security controls, such as encryption, access restrictions, and auditing requirements, that must be implemented to safeguard the data throughout its lifecycle. Without proper classification, organizations risk over-protecting low-value data or, more critically, under-protecting highly sensitive information, leading to inefficient resource allocation and increased risk exposure.

Why this answer

Data classification is the foundational process of assigning a sensitivity label (e.g., Public, Internal, Confidential, Restricted) to information assets. The primary reason is to ensure that appropriate security controls—such as encryption, access control lists (ACLs), and data loss prevention (DLP) policies—are applied proportionally to the data's value and sensitivity, aligning with the principle of defense in depth and risk management.

Exam trap

The trap here is that candidates often confuse the primary purpose of classification (protection) with secondary outcomes like compliance or access management, leading them to select options B or D instead of the correct risk-based reasoning in A.

How to eliminate wrong answers

Option B is wrong because satisfying regulatory requirements for data retention is a separate process governed by legal and compliance policies (e.g., GDPR, HIPAA), not the primary driver for classification; classification informs retention but retention is a downstream action. Option C is wrong because unrestricted data sharing across departments would violate the principle of least privilege and confidentiality; classification actually restricts sharing based on sensitivity levels. Option D is wrong because simplifying access granting is a secondary benefit of classification (via role-based access control), but the primary reason is to apply appropriate protection measures, not to simplify administration.

629
MCQmedium

A security team is implementing a zero trust architecture. Which component is essential to enforce access decisions based on user identity, device posture, and context before granting access to resources?

A.Virtual private network (VPN)
B.Network Access Control (NAC)
C.Next-generation firewall (NGFW)
D.Software-defined perimeter (SDP)
AnswerD

A Software-Defined Perimeter (SDP), often referred to as Zero Trust Network Access (ZTNA), dynamically creates a secure, individualized network segment between a user/device and the specific application or resource they are authorized to access. It authenticates and authorizes every user and device before granting access to any resource, effectively making resources invisible to unauthorized entities and embodying the core tenets of zero trust by enforcing least privilege access.

Why this answer

A software-defined perimeter (SDP) is the essential component for enforcing access decisions based on user identity, device posture, and context in a zero trust architecture. SDP creates a dynamic, encrypted micro-perimeter around each resource, requiring authentication and authorization before any connection is established, effectively hiding the resource from unauthorized users. This aligns with the zero trust principle of 'never trust, always verify' by evaluating identity, device health, and contextual factors (e.g., location, time) before granting access.

Exam trap

The trap here is that candidates often confuse Network Access Control (NAC) with zero trust because both involve device posture checks, but NAC is a pre-admission network-level control, whereas SDP provides per-session, application-level access control that is fundamental to zero trust architecture.

How to eliminate wrong answers

Option A is wrong because a VPN provides encrypted tunnels for remote access but typically grants broad network-level access after authentication, lacking granular, per-request context-based authorization and device posture checks required for zero trust. Option B is wrong because Network Access Control (NAC) focuses on pre-admission authentication and endpoint compliance at the network edge (e.g., 802.1X), but does not enforce per-session, application-level access decisions based on continuous context after initial admission. Option C is wrong because a next-generation firewall (NGFW) performs deep packet inspection and application-level filtering, but it operates at the network perimeter and does not inherently integrate identity- and device-posture-based access control for each resource request in a zero trust model.

630
MCQhard

A network administrator is configuring DNSSEC to protect against DNS spoofing. Which record type is used to provide cryptographic verification of DNS data origins?

A.RRSIG
B.DS
C.DNSKEY
D.NSEC
AnswerA

The RRSIG (Resource Record Signature) record contains the cryptographic digital signature for a specific DNS resource record set (RRset). This signature is generated using a private key associated with the zone and allows DNS resolvers to cryptographically verify the authenticity and integrity of the corresponding RRset. By checking the RRSIG, resolvers can confirm that the data originated from the authoritative server and has not been tampered with in transit, thus directly protecting against modification.

Why this answer

RRSIG (Resource Record Signature) is the DNSSEC record type that contains the cryptographic signature for a DNS record set. It provides data origin authentication and integrity verification by allowing resolvers to validate that the DNS data came from the authoritative source and was not modified in transit.

Exam trap

The trap here is that candidates confuse the role of DNSKEY (the key) with RRSIG (the signature), mistakenly thinking the public key itself provides verification, when in fact the signature record (RRSIG) is what cryptographically binds the data to the zone.

How to eliminate wrong answers

Option B (DS) is wrong because DS (Delegation Signer) records are used to create a chain of trust between DNS zones, not to directly sign or verify individual DNS data origins. Option C (DNSKEY) is wrong because DNSKEY records hold the public signing key used to verify RRSIG signatures, but they do not themselves provide cryptographic verification of data origins. Option D (NSEC) is wrong because NSEC (Next Secure) records are used for authenticated denial of existence, proving that a DNS name does not exist, and have no role in verifying data origin signatures.

631
MCQmedium

Which of the following is a key difference between a policy and a guideline in information security governance?

A.Policies are created by IT, while guidelines are created by executives
B.Policies are technical, while guidelines are managerial
C.Policies are mandatory, while guidelines are recommended
D.Policies are static, while guidelines are updated frequently
AnswerC

This is the correct distinction. Policies are formal, high-level statements that mandate specific actions or behaviors, establishing compulsory rules that all relevant parties must adhere to, with non-compliance typically incurring disciplinary or legal consequences. In contrast, guidelines provide recommended best practices, suggestions, or advisory information designed to assist individuals in making informed decisions or performing tasks, but they are not strictly enforced. This fundamental difference in obligation and enforceability is key to their purpose within an organization's governance framework.

Why this answer

Policies are formal, high-level statements that mandate specific behaviors or requirements across the organization; compliance is compulsory. Guidelines, in contrast, are non-mandatory recommendations or best practices that offer advice on how to achieve policy objectives. This distinction is fundamental to information security governance because it clarifies which documents carry enforcement weight and which are merely advisory.

Exam trap

CISSP often tests the misconception that policies are technical and guidelines are managerial, or that policies are created by IT rather than executives, leading candidates to overlook the mandatory versus recommended distinction.

How to eliminate wrong answers

Option A is wrong because policies are typically approved by executive management or the board, not IT, while guidelines may be developed by IT or security teams but are not necessarily created by executives. Option B is wrong because policies are not inherently technical—they are management directives that can cover any aspect of security—and guidelines are not exclusively managerial; they can be technical or procedural. Option D is wrong because both policies and guidelines can be updated as needed; policies are not necessarily static, and guidelines are not uniquely dynamic.

632
MCQmedium

A company uses SSH for remote administration. To enhance security, they want to implement public-key authentication. Which statement about SSH public-key authentication is true?

A.The private key must be kept secret by the user
B.The public key is used to decrypt the session
C.Public-key authentication does not require a passphrase
D.The private key is stored on the server
AnswerA

The private key is the core secret in asymmetric cryptography for SSH authentication. Its secrecy is paramount because it uniquely identifies the user and authorizes access to the remote server. If this key is compromised or shared, an attacker can impersonate the legitimate user, bypassing all other security controls. Therefore, users must diligently protect their private keys from unauthorized access and disclosure.

Why this answer

In SSH public-key authentication, the private key is the secret half of the asymmetric key pair and must be kept confidential by the user. The server stores only the public key, and authentication is proven by the client signing a challenge with the private key, which the server verifies using the stored public key. This ensures that even if the server is compromised, the private key remains safe on the client side.

Exam trap

The trap here is that candidates often confuse the roles of public and private keys, mistakenly thinking the public key is used for decryption or that the private key is stored on the server, when in fact the private key is kept secret by the user and used only for signing.

How to eliminate wrong answers

Option B is wrong because the public key is used to verify a signature from the client, not to decrypt the session; session encryption is established via a symmetric key negotiated during the key exchange (e.g., Diffie-Hellman). Option C is wrong because while a passphrase is not strictly required, it is strongly recommended to protect the private key at rest; without a passphrase, the private key file is stored in plaintext and can be used by anyone who gains access to it. Option D is wrong because the private key is never stored on the server; only the public key is placed in the user's authorized_keys file on the server.

633
MCQhard

A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?

A.The module uses a software-based cryptographic algorithm implementation that runs in the host OS's user space.
B.The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.
C.The module performs key generation using a random number generator that is seeded from the host OS's entropy pool.
D.The module uses a FIPS-approved algorithm such as AES-256 for encryption.
AnswerB

An HSM within the cryptographic boundary stores and processes keys internally, isolating them from the host OS. Even if the host OS is compromised, the attacker cannot directly access the keys because they never leave the HSM's protected environment. Cryptographic operations are performed inside the HSM, and only results are returned. This hardware isolation is critical to protecting keys against unauthorized disclosure when the host OS is compromised.

Why this answer

The most critical aspect is the hardware security module (HSM) within the cryptographic boundary, which stores and processes keys internally. This ensures that keys are never exposed to the host OS, so even if the OS is compromised, the keys remain protected. A software implementation, strong algorithms, or entropy seeding do not provide the same level of isolation and are insufficient when the host OS is untrusted.

Exam trap

The trap here is focusing on the strength of the cryptographic algorithm or the randomness of key generation, when the real issue is where the keys are stored and processed relative to the compromised host OS.

634
Multi-Selectmedium

A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)

Select 2 answers
A.Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).
B.Accepting the risk of a minor vulnerability because the cost of fixing it exceeds the potential loss.
C.Implementing a firewall to block unauthorized access to the network.
D.Deciding not to deploy a new application because it introduces unacceptable vulnerabilities.
E.Purchasing cyber insurance to cover potential financial losses from a data breach.
AnswersA, E

Outsourcing transfers the operational risk to the third-party provider, who is contractually obligated to meet performance and security requirements. The organization retains some residual risk, but the primary responsibility shifts, which is a form of risk transfer. Thus, this action is correct.

Why this answer

The correct answers are purchasing cyber insurance and outsourcing a critical function with an SLA. Both actions shift the financial or operational impact of a risk to another party. Insurance transfers financial risk, while outsourcing transfers operational risk through contractual agreements, making them valid examples of risk transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation, assuming that any action that reduces risk (like a firewall) is transfer, when transfer specifically involves shifting the risk to a third party.

635
Multi-Selectmedium

Which TWO of the following are essential components of a disaster recovery plan? (Choose two.)

Select 2 answers
A.Recovery Point Objective (RPO)
B.Business continuity plan
C.Recovery Time Objective (RTO)
D.Service Level Agreement (SLA)
E.Cold site configuration
AnswersA, C

The Recovery Point Objective (RPO) is a critical metric in disaster recovery planning, defining the maximum tolerable period in which data might be lost from an IT service due to a major incident. It quantifies the acceptable amount of data loss, typically measured in time (e.g., 1 hour, 24 hours), and directly influences backup frequency and data replication strategies. A well-defined RPO ensures that data recovery efforts align with business tolerance for data loss.

Why this answer

Option A, Recovery Point Objective (RPO), is correct because it defines the maximum acceptable amount of data loss measured in time, which directly determines backup frequency and replication strategy within a disaster recovery plan. Option C, Recovery Time Objective (RTO), is correct because it specifies the maximum tolerable downtime for restoring systems and services after a disruption, driving the recovery architecture and resource prioritization. Together, RPO and RTO are the two foundational metrics that every DR plan must define to set recovery expectations and design appropriate solutions.

Option B, a business continuity plan, is broader and encompasses the DR plan rather than being a component of it. Option D, a Service Level Agreement, is a contractual document defining service expectations and is not itself a DR component. Option E, a cold site configuration, is only one possible recovery site strategy and is not essential to every DR plan.

Exam trap

CISSP often tests the difference between RPO/RTO and broader concepts like BCP and SLA, so candidates might select BCP or SLA as components of the DR plan when they are actually separate.

636
MCQhard

A security engineer is evaluating VPN protocols for a remote access solution. The requirements are: strong encryption with perfect forward secrecy, support for mutual authentication, and no reliance on pre-shared keys that could be brute-forced. Which protocol best meets these requirements?

A.L2TP/IPsec with pre-shared keys
B.PPTP with MS-CHAPv2
C.WireGuard
D.IPsec with IKEv2 using pre-shared keys
AnswerC

WireGuard uses Curve25519 for key exchange, providing perfect forward secrecy without pre-shared keys, and supports mutual authentication via public-key cryptography. Its Noise protocol framework underpins these guarantees, satisfying the stem's three constraints: strong encryption, PFS, and no brute-forceable PSKs.

Why this answer

WireGuard is the correct choice because it uses modern cryptographic primitives (Curve25519, ChaCha20, Poly1305, BLAKE2s) that inherently provide perfect forward secrecy via ephemeral Diffie-Hellman key exchanges, supports mutual authentication through public-key-based handshakes, and eliminates pre-shared keys as the sole authentication factor—though an optional PSK can be added for post-quantum resistance, it is not required and does not weaken security if omitted.

Exam trap

A common misconception is that IPsec with IKEv2 is always secure regardless of authentication method, but the trap here is that pre-shared keys (even with IKEv2) violate the 'no reliance on pre-shared keys' requirement and can be brute-forced if weak, whereas WireGuard's public-key-based mutual authentication avoids this vulnerability entirely.

How to eliminate wrong answers

Option A is wrong because L2TP/IPsec with pre-shared keys relies on a static PSK that can be brute-forced if weak, and does not inherently enforce perfect forward secrecy unless IKEv2 with ephemeral Diffie-Hellman is explicitly configured, which is not guaranteed by the option. Option B is wrong because PPTP with MS-CHAPv2 uses the RC4 cipher and MS-CHAPv2 authentication, both of which are cryptographically broken and lack perfect forward secrecy; additionally, PPTP does not support mutual authentication in a strong sense and relies on passwords that can be brute-forced. Option D is wrong because IPsec with IKEv2 using pre-shared keys still depends on a static PSK that can be brute-forced, and while IKEv2 can support perfect forward secrecy, the use of a PSK as the primary authentication method contradicts the requirement of no reliance on pre-shared keys.

637
MCQeasy

A security analyst is conducting a review of aggregated logs from firewalls, IDS, and servers to detect anomalous behavior. This activity is best described as:

A.Security log analysis
B.Risk assessment
C.Vulnerability scanning
D.Penetration testing
AnswerA

Security log analysis is the systematic examination of aggregated log data from various sources to identify security incidents, anomalies, and policy violations. This process involves reviewing event records, often correlated and normalized, to detect patterns indicative of malicious activity, system failures, or unauthorized access attempts. By analyzing these operational records, a security analyst can gain critical insights into the security posture and operational health of the environment, directly addressing the task of reviewing aggregated logs.

Why this answer

Security log analysis involves the systematic review of logs from firewalls, IDS, and servers to identify patterns, anomalies, or indicators of compromise. This activity directly matches the scenario of detecting anomalous behavior through aggregated log review, which is a core practice in security monitoring and incident detection.

Exam trap

The trap here is confusing security log analysis (a passive, detective control) with vulnerability scanning or penetration testing (active, preventive controls), leading candidates to choose a more 'technical-sounding' option like vulnerability scanning.

How to eliminate wrong answers

Option B is wrong because risk assessment is a broader process of identifying, evaluating, and prioritizing risks, not the specific act of reviewing aggregated logs for anomalies. Option C is wrong because vulnerability scanning uses automated tools to probe systems for known weaknesses (e.g., missing patches, misconfigurations), not to analyze historical log data for anomalous behavior. Option D is wrong because penetration testing is an active, simulated attack to exploit vulnerabilities, not a passive review of log data.

638
MCQeasy

Which of the following is a primary purpose of conducting a tabletop exercise for incident response?

A.Measure the effectiveness of backup restoration.
B.Validate communication and decision-making processes.
C.Test technical capabilities of security tools.
D.Identify unpatched vulnerabilities in systems.
AnswerB

A primary purpose of tabletop exercises is to validate communication and decision-making processes by simulating a crisis scenario in a low-stress, discussion-based environment. Participants articulate their responses, escalation paths, and coordination efforts, allowing facilitators to observe how teams interpret policies, make critical choices, and communicate information under simulated pressure. This helps identify gaps in established procedures, roles, and inter-departmental coordination without impacting live systems.

Why this answer

A tabletop exercise is a discussion-based session where participants walk through a simulated incident scenario to evaluate the effectiveness of communication channels, decision-making hierarchies, and coordination among stakeholders. It does not involve live systems or technical testing, so its primary purpose is to validate the procedural and human elements of the incident response plan, such as who notifies whom and how escalation decisions are made.

Exam trap

The trap here is that candidates confuse a tabletop exercise with a technical drill or live-fire exercise, mistakenly thinking it tests tool capabilities or system-level actions, when in fact it strictly evaluates human processes and communication workflows.

How to eliminate wrong answers

Option A is wrong because measuring backup restoration effectiveness requires a hands-on technical test (e.g., a recovery drill or restore validation), not a discussion-based tabletop exercise. Option C is wrong because testing technical capabilities of security tools (e.g., SIEM rule tuning or firewall ACLs) demands live execution or simulation in a lab environment, not a walkthrough. Option D is wrong because identifying unpatched vulnerabilities is the domain of vulnerability scanning (e.g., using Nessus or OpenVAS) or penetration testing, not a tabletop exercise which focuses on process and communication.

639
MCQeasy

Which of the following is a lightweight directory access protocol used for accessing and maintaining distributed directory information?

A.OAuth
B.LDAP
C.Kerberos
D.SAML
AnswerB

LDAP (Lightweight Directory Access Protocol) is an open, vendor-neutral, industry-standard application protocol for accessing and maintaining distributed directory information services over an Internet Protocol (IP) network. It provides a standardized method for clients to query and update information in a directory, such as user accounts, groups, and network resources. Its "lightweight" designation refers to its streamlined design compared to its predecessor, X.500 DAP, making it efficient for common directory operations.

Why this answer

LDAP (Lightweight Directory Access Protocol) is specifically designed for accessing and maintaining distributed directory information services over an IP network. It operates on a client-server model, allowing queries and modifications to directory entries organized in a hierarchical structure (DIT). LDAP is an open standard and is widely used for authentication and authorization in enterprise environments, such as Microsoft Active Directory and OpenLDAP.

Exam trap

CISSP often tests the confusion between authentication protocols (like Kerberos) and directory access protocols (like LDAP), causing candidates to select Kerberos when asked about directory services.

How to eliminate wrong answers

Option A is wrong because OAuth is an authorization framework for granting third-party applications limited access to user resources without sharing credentials, not a directory access protocol. Option C is wrong because Kerberos is a network authentication protocol that uses tickets to allow nodes to prove their identity securely, but it does not provide directory access or maintenance. Option D is wrong because SAML is an XML-based framework for exchanging authentication and authorization data between parties, typically for single sign-on, not for accessing directory information.

640
Multi-Selecthard

Which THREE of the following are essential components of a software supply chain security program? (Select exactly three.)

Select 3 answers
A.Using signed and verified software artifacts
B.Maintaining a software bill of materials (SBOM) for all dependencies
C.Running penetration tests on the production environment
D.Conducting static analysis on all in-house code
E.Performing security assessments on third-party vendors
AnswersA, B, E

Signed and verified artefacts let consumers confirm software originated from a trusted publisher and was not tampered with in transit. This cryptographic provenance check directly satisfies the stem's requirement for an essential component of software supply chain security.

Why this answer

Option A is correct because using signed and verified software artifacts ensures integrity and authenticity through cryptographic signatures (e.g., GPG, Sigstore), preventing tampering or substitution of components within the supply chain. Option B is correct because maintaining a software bill of materials (SBOM) for all dependencies provides the inventory and transparency needed to identify and respond to vulnerabilities such as Log4Shell across transitive dependencies. Option E is correct because performing security assessments on third-party vendors addresses the risk introduced by external suppliers, a core element of supply chain risk management.

Option C is not essential to a supply chain security program because penetration testing the production environment tests deployed infrastructure and applications rather than the provenance, integrity, or composition of software components. Option D is not essential because static analysis on in-house code improves code quality and finds coding flaws but does not address the third-party dependencies, artifact integrity, or vendor risks that define supply chain security.

Exam trap

ISC2 often tests the distinction between general security practices (like penetration testing or static analysis) and the specific, unique controls required for software supply chain security, such as artifact signing and vendor assessments.

641
MCQeasy

Which of the following is the PRIMARY purpose of the confidentiality principle in the CIA triad?

A.Preventing unauthorized access to information
B.Ensuring data is accurate and complete
C.Ensuring that users are who they claim to be
D.Guaranteeing that systems are available when needed
AnswerA

Confidentiality's primary purpose is to safeguard sensitive information from unauthorized disclosure or access. This involves implementing controls such as encryption, robust access control mechanisms, and the principle of least privilege to ensure that only authorized individuals or systems can view or obtain specific data. Its core objective is to maintain the secrecy and privacy of information, preventing its exposure to those without a legitimate need-to-know.

Why this answer

Confidentiality in the CIA triad ensures information is disclosed only to authorized parties, so its primary purpose is preventing unauthorized access to data. This is achieved through encryption, access controls, and classification. The other options describe integrity, authentication, and availability respectively.

Exam trap

The trap is conflating confidentiality with authentication or integrity; candidates pick 'users are who they claim to be' because authentication feels security-related, but confidentiality is specifically about preventing unauthorized disclosure.

How to eliminate wrong answers

Option B is wrong because ensuring data is accurate and complete describes integrity, not confidentiality. Option C is wrong because verifying that users are who they claim to be describes authentication, which supports but is distinct from confidentiality. Option D is wrong because guaranteeing systems are available when needed describes availability, the third leg of the CIA triad.

642
Multi-Selecteasy

An organization plans to allow employees to access third-party SaaS applications using their corporate credentials. Which THREE are necessary components for implementing SAML-based identity federation?

Select 3 answers
A.Service Provider (SP)
B.Bcrypt password hashing
C.Identity Provider (IdP)
D.RADIUS server
E.XML digital signatures
AnswersA, C, E

The Service Provider (SP) is the entity that hosts the application or resource the user wishes to access. In a SAML exchange, the SP receives and validates the SAML assertion issued by the Identity Provider. Upon successful validation, the SP uses the information within the assertion to establish a local session for the user and grant access to the requested service without requiring a separate login. This role is crucial for enabling single sign-on.

Why this answer

SAML-based identity federation requires a Service Provider (SP), which is the third-party SaaS application that receives and validates SAML assertions to grant access, so option A is correct. It also requires an Identity Provider (IdP), the corporate system that authenticates employees and issues signed SAML assertions containing identity and attribute claims, making option C correct. XML digital signatures are essential because SAML assertions and responses must be cryptographically signed (typically with XML Signature, using the IdP's private key and validated with its public certificate) to ensure integrity and authenticity, so option E is correct.

Bcrypt password hashing (B) is a local credential-storage technique and is not a SAML federation component, since the IdP handles authentication and the SP does not need to hash the user's corporate password. A RADIUS server (D) provides network access authentication via the RADIUS protocol and is unrelated to SAML web-based identity federation.

Exam trap

The trap here is that candidates confuse authentication protocols (like RADIUS or password hashing) with federation components, forgetting that SAML is an XML-based assertion framework that requires an IdP, SP, and digital signatures, not network-level or storage mechanisms.

643
MCQmedium

A multinational corporation has experienced several security incidents where terminated employees retained access to internal systems for weeks after their departure. The HR department manually terminates accounts by sending notifications to IT, but the process is often delayed or missed. The company uses an identity management system (IDM) that supports automated provisioning and deprovisioning. The security team is tasked with reducing the risk of unauthorized access by former employees. Which of the following is the most effective course of action?

A.Integrate the HR system with the identity management system for automated deprovisioning
B.Require terminated employees to change their passwords upon exit
C.Increase frequency of access reviews and audits to identify stale accounts
D.Implement a user self-service portal for managers to disable accounts
AnswerA

Integrating the HR system with the identity management system establishes an authoritative source for employee status changes, enabling automated deprovisioning. This critical integration ensures that when an employee's status changes to terminated in HR, their accounts and access rights are immediately disabled across all connected systems. This proactive, system-driven approach minimizes the window of opportunity for unauthorized access post-termination, significantly reducing insider threat risks and enhancing compliance.

Why this answer

Integrating the HR system with the identity management (IDM) system enables automated deprovisioning, ensuring that when an employee is terminated in HR records, the IDM immediately triggers account disablement across all connected systems. This eliminates the manual delay and human error inherent in the current notification-based process, directly addressing the root cause of the risk.

Exam trap

The trap here is that candidates often choose 'increase access reviews' (Option C) because it sounds like a thorough security measure, but they fail to recognize that it is a detective control that does not prevent the immediate risk of unauthorized access by former employees.

How to eliminate wrong answers

Option B is wrong because requiring terminated employees to change their passwords upon exit is impractical and insecure; former employees cannot be relied upon to perform this action, and it does not prevent access if they refuse or forget. Option C is wrong because increasing the frequency of access reviews and audits only identifies stale accounts after the fact, not preventing access in the critical window between termination and review; it is a detective control, not a preventive one. Option D is wrong because a user self-service portal for managers to disable accounts still relies on manual action by managers, which can be delayed, forgotten, or misused, and does not provide the automated, policy-driven deprovisioning that an integrated HR-IDM system offers.

644
Multi-Selectmedium

Which TWO of the following are essential components of a data classification policy? (Select two.)

Select 2 answers
A.Data retention periods for each classification level
B.Roles and responsibilities for data classification
C.Definition of classification levels (e.g., public, confidential, secret)
D.Methods for secure data destruction
E.Encryption standards for each classification level
AnswersB, C

A robust data classification policy must explicitly delineate the roles and responsibilities for its implementation and ongoing management. This includes identifying data owners, data custodians, and users, clarifying who is accountable for initial classification, review, and reclassification, ensuring consistent application and adherence to the policy across the organization. Without clear ownership, the policy cannot be effectively enforced.

Why this answer

Roles and responsibilities are essential because a data classification policy must clearly define who is accountable for classifying data, who can assign classification levels, and who is responsible for maintaining the labels. Without this, classification efforts become inconsistent and unenforceable, leading to security gaps. The CISSP emphasizes that governance requires clear assignment of ownership and decision-making authority for data assets.

Exam trap

ISC2 often tests the distinction between a data classification policy (which defines levels and roles) and supporting policies (retention, encryption, destruction) that operationalize the classification but are not core components of the classification policy itself.

645
MCQeasy

Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

A.BCP deals with natural disasters, DRP deals with cyberattacks
B.BCP is for IT systems, DRP is for business processes
C.BCP is a subset of DRP
D.BCP ensures business functions continue, DRP restores IT operations
AnswerD

This statement accurately distinguishes between the primary objectives of Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP). BCP is the strategic, holistic program designed to ensure that an organization's essential business functions can continue operating at an acceptable level during and immediately after a disruptive event. DRP, on the other hand, is the tactical plan focused specifically on the systematic recovery and restoration of the organization's critical information technology systems, applications, and data to an operational state.

Why this answer

D is correct because the Business Continuity Plan (BCP) focuses on maintaining critical business functions during and after a disruption, ensuring minimal impact on operations, while the Disaster Recovery Plan (DRP) is a subset of BCP that specifically addresses the restoration of IT infrastructure, systems, and data after a disaster. The BCP encompasses broader organizational resilience, including manual workarounds and alternate sites, whereas the DRP targets technical recovery procedures such as system rebuilds, data restoration from backups, and failover to redundant systems.

Exam trap

The trap here is that candidates often confuse the scope of BCP and DRP, mistakenly thinking BCP is only for business processes and DRP only for IT, when in fact BCP is the overarching plan that includes DRP as a component for IT recovery.

How to eliminate wrong answers

Option A is wrong because BCP and DRP are not distinguished by the type of disaster; both plans address a wide range of incidents including natural disasters, cyberattacks, and human errors. Option B is wrong because it reverses the roles: BCP covers business processes and continuity strategies, while DRP is specifically for IT systems and technical recovery. Option C is wrong because it incorrectly states that BCP is a subset of DRP; in reality, the DRP is a subset of the BCP, as the BCP includes the DRP along with other continuity elements like crisis communication and alternate site activation.

646
MCQmedium

A financial application requires two employees to authorize a wire transfer. Which principle does this implement?

A.Least privilege
B.Separation of duties
C.Need-to-know
D.Zero standing privileges
AnswerB

Separation of duties (SoD) is an administrative control designed to prevent fraud, error, and abuse by distributing critical functions and responsibilities among multiple individuals. This ensures that no single person has complete control over an entire sensitive process, requiring collusion to compromise it. The scenario, demanding two employees to authorize a financial transaction, is a direct and classic implementation of SoD, as it mandates shared responsibility for a high-risk action.

Why this answer

Separation of duties (SoD) is the principle that requires two or more individuals to complete a sensitive transaction, such as a wire transfer, to prevent fraud or error. By mandating two employees to authorize the transfer, the application ensures no single person has unchecked control over the entire process, enforcing a dual-control mechanism. This directly implements the SoD principle, which is a core access control concept in identity and access management.

Exam trap

The trap here is that candidates confuse separation of duties with least privilege, thinking that limiting permissions alone achieves the same goal, but least privilege does not prevent a single user from performing all steps of a critical process.

How to eliminate wrong answers

Option A is wrong because least privilege grants users only the minimum permissions needed to perform their job, but it does not require multiple people to authorize a single action; that is a separate control. Option C is wrong because need-to-know restricts access to information based on necessity for a specific task, not the collaborative authorization of a transaction. Option D is wrong because zero standing privileges (ZSP) removes persistent access rights and grants them just-in-time, but it does not inherently enforce dual authorization for a single operation.

647
Matchingmedium

Match each access control type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Owner controls access permissions

System-enforced based on labels

Access based on job roles

Access based on rules and policies

Why these pairings

The four main access control models are DAC (owner-based), MAC (label-based), RBAC (role-based), and ABAC (attribute-based). Common confusions include swapping DAC with MAC and RBAC with ABAC.

648
MCQmedium

A company recently suffered a data breach where an attacker was able to intercept network traffic and read sensitive data. Which network security control should be implemented to prevent this type of attack?

A.Encryption at the network layer (e.g., IPsec)
B.Network segmentation
C.Intrusion prevention system (IPS)
D.Strong password policies
AnswerA

IPsec operates at Layer 3 of the OSI model, encrypting entire IP packets, including the payload and often parts of the header. This ensures that even if an attacker successfully intercepts network traffic, the data remains unintelligible without the correct cryptographic keys. It directly addresses the risk of data exposure from sniffing by rendering the intercepted information useless and confidential.

Why this answer

IPsec operates at the network layer (Layer 3) and provides encryption of the entire IP packet, including the payload, ensuring that even if an attacker intercepts the traffic, the data remains unreadable. This directly addresses the scenario where an attacker reads sensitive data from intercepted network traffic, as IPsec can be configured in transport mode for end-to-end encryption or tunnel mode for VPNs.

Exam trap

ISC2 often tests the misconception that network segmentation (Option B) prevents data interception, but segmentation only limits lateral movement, not the ability to read traffic within the same segment.

How to eliminate wrong answers

Option B is wrong because network segmentation (e.g., VLANs, subnets) limits the scope of traffic an attacker can reach but does not encrypt data; an attacker who intercepts traffic within a segment can still read it in plaintext. Option C is wrong because an intrusion prevention system (IPS) detects and blocks malicious patterns in traffic but does not encrypt data; it cannot prevent an attacker from reading already intercepted plaintext traffic. Option D is wrong because strong password policies control authentication and access but do not protect data in transit; an attacker who intercepts network traffic can bypass password controls entirely.

649
Multi-Selecthard

A company needs to protect data at rest in a cloud storage system. Which THREE encryption methods are appropriate for this purpose?

Select 3 answers
A.Stream cipher without authentication (e.g., RC4)
B.Client-side encryption with key management
C.MD5 hashing
D.AES-256 in GCM mode
E.Envelope encryption
AnswersB, D, E

Client-side encryption is a highly effective method for protecting data at rest in the cloud because it ensures that data is encrypted on the client's system *before* it is transmitted to or stored by the cloud provider. This approach guarantees that the cloud provider only ever receives encrypted data and has no access to the plaintext or the encryption keys. Robust key management, encompassing secure generation, storage, rotation, and revocation of these client-controlled keys, is absolutely essential to maintain the overall security posture and prevent unauthorized data access.

Why this answer

Client-side encryption with key management (B) is correct because encrypting data before it leaves the client and managing keys via a KMS or HSM ensures data at rest in the cloud storage is protected and keys are controlled separately from the data. AES-256 in GCM mode (D) is correct because AES-256 provides strong symmetric encryption for data at rest while GCM supplies authenticated encryption (confidentiality plus integrity/authenticity), making it suitable for stored objects. Envelope encryption (E) is correct because it encrypts data with a data encryption key (DEK) and then encrypts that DEK with a master key (KEK) held in a KMS/HSM, which is the standard approach for protecting data at rest at scale in cloud storage.

MD5 hashing (C) is not an encryption method—it is a broken cryptographic hash used for integrity checks, not confidentiality—and a stream cipher without authentication such as RC4 (A) is inappropriate because RC4 is deprecated/insecure and lacks authentication, so it does not properly protect data at rest.

Exam trap

Candidates often confuse hashing with encryption, or fail to recognize that stream ciphers without authentication (like RC4) are highly vulnerable to bit-flipping attacks and are completely inappropriate for securing data at rest.

650
MCQhard

An organization wants to ensure that its web application is secure by analyzing the source code for vulnerabilities without executing the code. Which type of testing is most appropriate?

A.Interactive Application Security Testing (IAST)
B.Dynamic Application Security Testing (DAST)
C.Runtime Application Self-Protection (RASP)
D.Static Application Security Testing (SAST)
AnswerD

Static Application Security Testing (SAST) directly analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program. It identifies potential flaws such as buffer overflows, SQL injection vulnerabilities, and insecure coding practices by examining the code structure and data flow paths. This 'shift-left' approach allows developers to find and fix security defects early in the software development lifecycle, before deployment.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, making it the only option that matches the requirement of reviewing code for vulnerabilities in a non-running state. SAST tools perform data-flow and control-flow analysis to detect issues like SQL injection, buffer overflows, and hardcoded secrets directly in the codebase. Because it operates pre-execution, it can be integrated early in the SDLC (shift-left) and pinpoint the exact file and line of a flaw.

Exam trap

CISSP often tests the distinction between static (non-running code) and dynamic (running application) testing, and candidates frequently confuse IAST with SAST because both can involve code analysis, but IAST requires execution.

How to eliminate wrong answers

Option A is wrong because IAST instruments a running application (often via an agent) and analyzes traffic and execution flow during runtime, so it requires code execution. Option B is wrong because DAST tests a running application from the outside by sending malicious requests and observing responses, which is black-box and does not examine source code. Option C is wrong because RASP is a runtime protection mechanism embedded in the application that detects and blocks attacks as they occur, not a source-code analysis technique.

651
MCQhard

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

A.A physical room where payment cards are stored
B.Any system that connects to the internet
C.Systems that store, process, or transmit cardholder data
D.A network segment that contains only point-of-sale devices
AnswerC

This statement precisely defines the Cardholder Data Environment (CDE) according to PCI DSS. It includes all system components, applications, and network devices that directly store, process, or transmit cardholder data, as well as any system that could impact the security of the CDE. This comprehensive definition ensures that all relevant assets handling sensitive payment information are brought under the stringent security controls mandated by the standard.

Why this answer

The cardholder data environment (CDE) is defined by PCI DSS as the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, plus any systems that connect to or could impact the security of that environment. Option C captures the core definition accurately. This scope determines which systems must comply with PCI DSS requirements.

Exam trap

CISSP often tests the misconception that the CDE is a physical location or only POS devices, when it is actually a logical scope defined by systems that store, process, transmit, or can impact cardholder data security.

How to eliminate wrong answers

Option A is wrong because the CDE is not limited to a physical room; it is a logical and physical scope encompassing all systems and networks that handle cardholder data, wherever they reside. Option B is wrong because connecting to the internet does not make a system part of the CDE; only systems that store, process, transmit, or can impact the security of cardholder data are in scope. Option D is wrong because the CDE is not restricted to a network segment containing only point-of-sale devices; it includes any system that handles cardholder data, such as servers, databases, and applications.

652
MCQmedium

An organization wants to verify that its security policies are being followed by employees. Which testing method is most appropriate?

A.Compliance audit
B.Vulnerability scan
C.Risk assessment
D.Penetration test
AnswerA

A compliance audit systematically evaluates an organization's adherence to established security policies, standards, regulations, and best practices. It involves reviewing documentation, interviewing personnel, and examining controls to determine if they are implemented and operating effectively as prescribed by the policy. This process directly verifies whether the organization's actions align with its stated security commitments.

Why this answer

A compliance audit is the most appropriate method to verify that security policies are being followed because it systematically compares actual practices, configurations, and controls against documented policy requirements. Unlike technical scans that identify vulnerabilities, a compliance audit focuses on adherence to rules, standards, and procedures, often using checklists derived from frameworks like ISO 27001 or NIST SP 800-53.

Exam trap

The trap here is that candidates confuse 'compliance audit' with 'vulnerability scan' because both involve checking systems, but the audit is specifically about policy adherence by people and processes, not technical flaws.

How to eliminate wrong answers

Option B (Vulnerability scan) is wrong because it identifies technical weaknesses in systems (e.g., missing patches, open ports) but does not assess whether employees are following security policies such as password handling or data classification procedures. Option C (Risk assessment) is wrong because it evaluates the likelihood and impact of threats to assets, not the degree of policy compliance by personnel. Option D (Penetration test) is wrong because it simulates attacks to exploit vulnerabilities and gain unauthorized access, focusing on technical defenses rather than verifying employee adherence to policies.

653
MCQeasy

A company experiences a data breach. Which step should be taken first according to best practices?

A.Inform affected parties
B.Contain the breach
C.Notify law enforcement
D.Assess the damage
AnswerB

Containment is the immediate and most critical first step in incident response following identification. Its primary objective is to stop the incident from spreading further, limit the damage, and prevent additional data loss or system compromise. This involves isolating affected systems, disabling compromised accounts, and implementing temporary fixes to stabilize the environment.

Why this answer

According to incident response best practices (NIST SP 800-61), the first priority after confirming a breach is to contain it. This prevents further data exfiltration, limits lateral movement by an attacker, and preserves forensic evidence. Containment actions may include isolating affected systems, blocking malicious IPs at the firewall, or revoking compromised credentials.

Exam trap

The trap here is that candidates confuse the urgency of notification (A) or assessment (D) with the immediate need to stop the attack, forgetting that containment is the foundational step that enables all subsequent actions.

How to eliminate wrong answers

Option A is wrong because informing affected parties prematurely can alert the attacker, destroy evidence, and violate legal hold requirements; notification should occur after containment and forensic analysis. Option C is wrong because notifying law enforcement is a secondary step that typically occurs after containment and initial assessment, and may not be required in all jurisdictions. Option D is wrong because assessing the damage before containment allows the breach to continue spreading, increasing data loss and making recovery more difficult.

654
MCQhard

A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?

A.ASLR
B.SafeSEH
C.Stack canaries
D.DEP/NX bit
AnswerA

ASLR (Address Space Layout Randomization) is a memory protection technique that randomly arranges the positions of key data areas, such as the base of the executable, the stack, heap, and libraries, within a process's virtual address space. This randomization makes it significantly more difficult for an attacker to predict target addresses for return-oriented programming (ROP) attacks or to reliably locate malicious code or useful gadgets. By introducing unpredictability, ASLR effectively mitigates the success rate of many memory corruption exploits that rely on known memory layouts.

Why this answer

ASLR (Address Space Layout Randomization) randomizes the memory locations of key areas such as the stack, heap, and libraries on each execution, making it difficult for an attacker to predict where shellcode or a return address resides. This directly counters buffer overflow exploitation that relies on fixed addresses. It is the mitigation specifically described as randomizing memory addresses.

Exam trap

CISSP often tests confusion among memory-corruption mitigations — ASLR randomizes addresses, DEP/NX blocks execution, canaries detect overwrites, and SafeSEH protects exception handlers.

How to eliminate wrong answers

Option B is wrong because SafeSEH is a Windows compiler/linker mitigation that validates exception handler pointers on the stack to prevent SEH overwrite attacks — it does not randomize memory addresses. Option C is wrong because stack canaries place a known guard value before the return address and detect corruption on function return; they detect overflows but do not randomize addresses. Option D is wrong because DEP/NX marks memory pages as non-executable to prevent code execution from data regions like the stack — it blocks execution but does not randomize addresses.

655
MCQhard

During a risk assessment, a critical asset has a vulnerability with a CVSS score of 9.0. Which risk treatment strategy is most appropriate if the cost to mitigate exceeds the asset's value?

A.Transfer
B.Acceptance
C.Avoidance
D.Mitigation
AnswerB

Accepting a significant vulnerability on a critical asset without implementing any treatment is generally an irresponsible risk management decision. This approach implies that the potential impact of a breach or compromise on the critical asset is deemed tolerable, which is rarely the case for assets vital to business continuity or regulatory compliance. Such a strategy is typically reserved for low-impact, low-probability risks, not for critical infrastructure.

Why this answer

In risk management, a fundamental rule is that the cost of a safeguard (mitigation) should never exceed the value of the asset being protected. If mitigating a vulnerability costs more than the asset is worth, the organization should choose to accept the risk (Risk Acceptance). Spending more to protect an asset than the asset itself is worth is financially illogical.

Exam trap

Candidates often assume that a high-severity vulnerability (such as CVSS 9.0) must always be mitigated or transferred. However, CISSP questions test your business acumen: if the cost of the countermeasure exceeds the asset's value, the correct business decision is to accept the risk.

How to eliminate wrong answers

Option B (Acceptance) is wrong because acceptance is only appropriate when the residual risk is within the organization's risk appetite and the cost of mitigation is not justified; however, a CVSS 9.0 vulnerability represents a high-severity risk that, if exploited, could cause disproportionate damage, making passive acceptance imprudent without explicit senior management approval and a formal risk acceptance process. Option C (Avoidance) is wrong because avoidance means eliminating the risk by discontinuing the activity or decommissioning the asset, which is often too drastic and may not be feasible if the asset is critical to business operations; the question does not indicate that the asset can be removed. Option D (Mitigation) is wrong because mitigation involves reducing the vulnerability's likelihood or impact through controls, but the prompt explicitly states that the cost to mitigate exceeds the asset's value, making mitigation economically unjustifiable and a poor use of resources.

656
Matchingmedium

Match each threat type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Fraudulent emails to obtain sensitive info

Targeted phishing at specific individuals

Phishing targeting senior executives

Voice phishing over phone

Phishing via SMS

Why these pairings

The correct matches are: Phishing with mass email (A), Spear Phishing with targeted attacks (C), and Whaling with executive targets (D). Option B is incorrect because it describes spear phishing, not phishing. Option E is also incorrect as it misassigns whaling as mass email.

657
MCQmedium

During the requirements gathering phase of a secure SDLC, the team uses a threat modeling approach that focuses on identifying threats such as spoofing, tampering, and denial of service. Which threat modeling methodology is being employed?

A.PASTA
B.Trike
C.STRIDE
D.OCTAVE
AnswerC

STRIDE is a mnemonic developed by Microsoft that provides a systematic framework for categorizing and identifying common types of threats against software and systems. Each letter represents a specific threat category: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. This framework is exceptionally useful during the requirements gathering phase of the SDLC to proactively identify potential vulnerabilities and design security controls that directly mitigate these well-defined threat types.

Why this answer

STRIDE is a threat modeling methodology developed by Microsoft that categorizes threats into six types: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. The question explicitly mentions spoofing, tampering, and denial of service, which are three of the STRIDE categories. Therefore, STRIDE is the correct answer.

Exam trap

CISSP often tests the confusion between threat modeling methodologies like STRIDE, PASTA, Trike, and OCTAVE, where candidates may pick a methodology based on familiarity rather than matching the specific threat categories mentioned in the question.

How to eliminate wrong answers

Option A is wrong because PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric, seven-step threat modeling methodology that focuses on aligning business objectives with technical requirements, not on categorizing threats by type like spoofing or tampering. Option B is wrong because Trike is a threat modeling framework that uses a risk-based approach with a focus on satisfying security requirements and is not organized around the specific threat categories mentioned. Option D is wrong because OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a risk assessment methodology that focuses on organizational risk, not on categorizing threats into spoofing, tampering, etc.

658
Multi-Selectmedium

A security auditor is reviewing an organization's governance framework. Which TWO of the following are commonly used frameworks for IT governance and security management?

Select 2 answers
A.ISO/IEC 27001
B.PMBOK
C.TOGAF
D.COBIT 2019
E.Six Sigma
AnswersA, D

ISO/IEC 27001 is a globally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides security auditors with a structured, risk-based framework to evaluate an organization's overall security governance, risk management, and control objectives.

Why this answer

ISO/IEC 27001 (A) is correct because it is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), directly addressing security management and governance controls. COBIT 2019 (D) is correct because it is ISACA's governance framework specifically designed for enterprise IT governance and management, providing control objectives and processes that align IT with business goals. PMBOK (B) is a project management body of knowledge focused on managing projects, not on IT governance or security management.

TOGAF (C) is an enterprise architecture framework for designing and structuring IT architecture, not a governance or security management framework. Six Sigma (E) is a process improvement and quality management methodology aimed at reducing defects, not an IT governance or security framework.

Exam trap

CISSP often tests whether candidates can distinguish governance/security frameworks (ISO 27001, COBIT, NIST) from adjacent disciplines like project management (PMBOK), enterprise architecture (TOGAF), and process improvement (Six Sigma).

659
MCQhard

An organization is designing a multicast network for live video streaming. They need to ensure that only authorized receivers can access the multicast group. Which technique should be implemented?

A.IGMP filtering
B.Multicast VLAN registration
C.Static IGMP entries
D.IGMP snooping with port security
AnswerA

IGMP filtering operates at Layer 3, typically on a router or Layer 3 switch, to control which multicast groups hosts are permitted to join. By inspecting IGMP Join/Leave messages, it can enforce access policies based on source IP, destination multicast group address, or even specific user credentials, effectively acting as an access control mechanism for multicast streams. This directly addresses the need to restrict access to live video streams by preventing unauthorized subscriptions.

Why this answer

IGMP filtering allows the network to control which hosts are permitted to join a multicast group by filtering IGMP membership reports at the access layer. This ensures that only authorized receivers can become members of the multicast group, providing access control for live video streaming. It is the most direct technique for enforcing authorization at the receiver level.

Exam trap

The trap here is that candidates confuse IGMP snooping (which optimizes multicast traffic delivery) with IGMP filtering (which enforces access control), leading them to pick IGMP snooping with port security as a security measure when it only controls traffic flooding, not authorization.

How to eliminate wrong answers

Option B is wrong because Multicast VLAN Registration (MVR) is designed to efficiently deliver multicast traffic across VLANs, not to enforce receiver authorization. Option C is wrong because static IGMP entries manually assign a host to a multicast group without any dynamic authorization check, which does not scale or enforce per-receiver access control. Option D is wrong because IGMP snooping with port security only monitors and restricts traffic based on MAC addresses or port-level security, not IGMP group membership authorization; it does not prevent an unauthorized host from sending a valid IGMP join.

660
Multi-Selecteasy

Which TWO features are true of IPsec tunnel mode compared to transport mode? (Select two.)

Select 2 answers
A.It provides better performance than transport mode
B.A new IP header is added to the packet
C.The entire original IP packet is encapsulated and encrypted
D.It is used for end-to-end communication between hosts
E.Only the payload of the packet is encrypted
AnswersB, C

In IPSec tunnel mode, the fundamental mechanism involves taking the complete original IP packet, which includes both its header and its payload, and encapsulating it. A distinct and entirely new outer IP header is then prepended to this encapsulated data. This new header contains the IP addresses of the IPSec endpoints (e.g., security gateways), allowing the packet to be routed across intermediate networks while the original packet's addressing information remains hidden and protected within the tunnel.

Why this answer

In IPsec tunnel mode, the entire original IP packet (including the original IP header) is encapsulated within a new IP packet. A new outer IP header is added, and the entire inner packet is encrypted and optionally authenticated. This is why option B is correct: a new IP header is added to the packet.

Exam trap

A common misconception is that tunnel mode is faster because it 'tunnels' traffic, but the added encapsulation and encryption overhead actually makes it slower than transport mode. The trap is confusing the purpose (hiding internal addresses) with performance characteristics.

661
MCQmedium

A business is evaluating risk treatment options for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk treatment strategy is most appropriate?

A.Risk transfer by purchasing insurance
B.Risk acceptance with documented decision
C.Risk mitigation by implementing additional controls
D.Risk avoidance by discontinuing the activity
AnswerB

Risk acceptance is the appropriate strategy when the cost of implementing other risk treatment options, such as mitigation or transfer, exceeds the potential impact of the risk itself. For a high-likelihood, low-impact risk, the financial outlay for controls or insurance might be greater than the actual loss incurred if the risk materializes. A formal, documented decision ensures that management acknowledges the risk, understands its implications, and accepts the potential consequences, providing accountability and a basis for future review.

Why this answer

When the cost of mitigation exceeds the potential loss, risk acceptance is the most cost-effective strategy. The business formally acknowledges the risk and documents the decision to accept it, often because the residual risk is within the organization's risk appetite. This aligns with the principle that not all risks must be mitigated or transferred if the economic justification is absent.

Exam trap

The trap here is that candidates often assume insurance (transfer) is always the best option for any risk, but the CISSP exam emphasizes cost-benefit analysis, making acceptance the correct choice when mitigation costs exceed the potential loss.

How to eliminate wrong answers

Option A is wrong because risk transfer via insurance typically involves paying a premium that may exceed the potential loss, and insurance is more suitable for low-likelihood, high-impact risks, not high-likelihood, low-impact ones. Option C is wrong because risk mitigation by implementing additional controls would cost more than the potential loss, violating the cost-benefit analysis that underpins risk treatment decisions. Option D is wrong because risk avoidance by discontinuing the activity would eliminate the risk but also forfeit any business benefit, which is disproportionate for a low-impact risk that can be accepted at lower cost.

662
MCQhard

During a penetration test, the tester gains access to a server and finds sensitive customer data. What should the tester do next?

A.Exfiltrate the data to demonstrate the risk
B.Delete the data to prevent exposure
C.Continue testing to find more vulnerabilities
D.Report the finding immediately and secure the data
AnswerD

Immediately reporting the finding and coordinating to secure the data is the paramount ethical and professional responsibility of a penetration tester upon discovering sensitive data access. This action adheres to responsible disclosure principles, enabling the client's incident response team to swiftly contain the breach, conduct forensics, and remediate the vulnerability before further damage occurs. Securing the data, often in collaboration with the client, might involve isolating the compromised system or revoking the unauthorized access path, ensuring the integrity and confidentiality of the information.

Why this answer

The tester's primary responsibility is to protect sensitive data and minimize risk. Upon discovering PII or other regulated data, the tester must immediately report the finding to the client and secure the data (e.g., by isolating the server or encrypting the data in place) to prevent unauthorized access or exposure. This aligns with the ethical hacking code of conduct and the CISSP principle of 'do no harm'.

Exam trap

The trap here is that candidates confuse the goal of demonstrating risk (which is valid in a controlled lab) with the ethical obligation to protect live data; the CISSP exam emphasizes that a tester must never exfiltrate or alter production data, even to prove a point.

How to eliminate wrong answers

Option A is wrong because exfiltrating data, even to demonstrate risk, violates confidentiality and legal agreements (e.g., GDPR, HIPAA) and could cause real harm; penetration testers must never copy or remove sensitive data without explicit written authorization. Option B is wrong because deleting data destroys evidence and could disrupt business operations or violate chain-of-custody requirements; the tester should not alter production data. Option C is wrong because continuing to test without first securing the exposed data increases the risk of further compromise and violates the responsible disclosure process; the tester must halt and report the finding immediately.

663
MCQhard

A company is deploying a hypervisor to run multiple virtual servers. To minimize the risk of VM escape attacks, which type of hypervisor should they choose and what hardening measure is most effective?

A.Type 1 hypervisor with minimal services and regular patching
B.Type 2 hypervisor with regular patching
C.Type 2 hypervisor with host-based firewall
D.Type 1 hypervisor with no additional hardening
AnswerA

A Type 1 hypervisor, also known as a bare-metal hypervisor, runs directly on the host hardware, significantly reducing the attack surface by eliminating the need for an underlying general-purpose operating system. Implementing minimal services further restricts potential entry points for attackers. Regular patching is critical to address known vulnerabilities, including hypervisor escape flaws, ensuring the integrity and isolation of virtual machines.

Why this answer

A Type 1 (bare-metal) hypervisor runs directly on the hardware with a much smaller attack surface than a Type 2 hypervisor, which sits atop a general-purpose host OS full of exploitable services. Minimizing installed services and applying regular patches further shrinks the attack surface and closes known VM-escape vulnerabilities. Together, these are the most effective mitigations for VM escape risk.

Exam trap

CISSP often tests the assumption that 'patching alone' or 'a firewall' mitigates VM escape — candidates miss that the hypervisor type and attack-surface reduction are the primary controls.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor depends on a full host OS, dramatically expanding the attack surface — patching alone cannot compensate for the extra exploitable layers. Option C is wrong because a host-based firewall controls network traffic but does nothing to prevent a guest-to-host escape via a hypervisor vulnerability; it addresses the wrong threat vector. Option D is wrong because a Type 1 hypervisor with no hardening still exposes unnecessary services and unpatched vulnerabilities — the hypervisor type alone is insufficient without hardening.

664
MCQmedium

Which of the following is a key objective of a business impact analysis (BIA)?

A.Implement security controls
B.Identify vulnerabilities in the network
C.Test the disaster recovery plan
D.Determine the maximum tolerable downtime for critical processes
AnswerD

The BIA quantifies how long each critical process can be unavailable before unacceptable impact, producing the maximum tolerable downtime that shapes recovery time objectives and continuity strategies. This directly satisfies the objective of prioritising recovery efforts by business impact.

Why this answer

A BIA is a foundational step in business continuity planning (BCP) that identifies critical business functions and quantifies the impact of their disruption over time. Its primary output is the maximum tolerable downtime (MTD), also called maximum allowable outage, along with recovery time objectives (RTO) and recovery point objectives (RPO) for each critical process. Determining MTD lets the organization prioritize recovery efforts and justify continuity investments.

Exam trap

CISSP often tests the confusion between BIA outputs (MTD, RTO, RPO) and downstream activities like control implementation or DR testing, so candidates must remember BIA is an analysis, not an action.

How to eliminate wrong answers

Option A is wrong because implementing security controls is a risk-mitigation activity that follows risk assessment and BIA, not the objective of the BIA itself. Option B is wrong because identifying network vulnerabilities is the purpose of vulnerability assessment or scanning, not BIA. Option C is wrong because testing the disaster recovery plan occurs after the BIA and BCP are developed, as part of validation and maintenance.

665
MCQeasy

Which security control is most effective for preventing unauthorized access to a data center?

A.Biometric authentication
B.Mantrap
C.Access logs
D.Video surveillance
AnswerB

A mantrap is a highly effective physical security control designed to prevent unauthorized physical access by creating a controlled entry point with two interlocking doors. This system ensures that one door must be securely closed and locked before the other can open, physically preventing tailgating or piggybacking. It enforces a one-person-at-a-time policy, verifying authorization before allowing passage into a secure area, thereby directly impeding unauthorized entry.

Why this answer

A mantrap is a physical security control consisting of two interlocking doors with a small vestibule between them, allowing only one person through at a time and preventing tailgating. It is the most effective control for preventing unauthorized physical access to a data center because it enforces one-person-at-a-time entry and can integrate with authentication and detection.

Exam trap

CISSP often tests the distinction between preventive physical controls (mantrap, bollards, locks) and detective controls (logs, CCTV), tempting candidates to pick biometrics or surveillance when the question asks for the most effective prevention of unauthorized access.

How to eliminate wrong answers

Option A is wrong because biometric authentication verifies identity but does not prevent tailgating — an authorized person can hold the door for an unauthorized one. Option C is wrong because access logs are detective controls that record who entered, not preventive controls that stop unauthorized access. Option D is wrong because video surveillance is a detective and deterrent control; it records activity but does not physically prevent entry.

666
MCQmedium

A security analyst notices that the SIEM is generating an overwhelming number of low-priority alerts from a single application server. The server is critical to operations. What is the BEST approach to reduce noise without compromising security?

A.Increase the severity threshold for that server's alerts.
B.Disable all alerts from that server.
C.Create a suppression rule for known benign patterns.
D.Exclude the server from SIEM monitoring.
AnswerC

Implementing a suppression rule specifically targets and filters out alerts generated by known, legitimate, and non-malicious system behaviors or application activities that are frequently observed. This method intelligently reduces alert fatigue by eliminating noise without compromising visibility into actual threats, as it allows all other, potentially malicious, activity to continue generating alerts. It optimizes SIEM effectiveness by focusing analyst attention on truly anomalous or suspicious events, improving incident response efficiency.

Why this answer

Suppression rules allow the SIEM to filter out known benign patterns (e.g., routine service checks or scheduled scans) while still capturing genuine threats. This reduces alert fatigue without disabling monitoring for the critical server, preserving visibility into anomalous or malicious activity.

Exam trap

The trap here is that candidates confuse 'reducing noise' with 'reducing monitoring,' leading them to choose threshold increases or outright exclusion, when the correct approach is to surgically filter known benign events while maintaining full detection coverage.

How to eliminate wrong answers

Option A is wrong because increasing the severity threshold would cause the SIEM to ignore all low-severity alerts, potentially missing early indicators of compromise (e.g., reconnaissance or privilege escalation attempts) that often start as low-priority events. Option B is wrong because disabling all alerts from a critical server creates a complete blind spot, violating the principle of defense in depth and allowing attacks to go undetected. Option D is wrong because excluding the server from SIEM monitoring removes all visibility into its security posture, which is unacceptable for a critical asset and contradicts the core purpose of a SIEM.

667
MCQhard

An organization is implementing privacy by design for a new application that processes PII. Which practice BEST aligns with the data minimization principle?

A.Collecting only the PII required for the stated function.
B.Anonymizing data after collection.
C.Obtaining explicit consent from users.
D.Collecting all possible PII in case it is needed later.
AnswerA

This action directly embodies the Privacy by Design principle of data minimization, which mandates that organizations collect only the absolute minimum amount of personal identifiable information (PII) necessary to achieve a specified, legitimate purpose. By limiting data collection at the outset, the organization proactively reduces the attack surface and potential impact of a data breach, aligning with PBD's foundational, preventative approach rather than reactive measures.

Why this answer

Data minimization means collecting only the personal data that is necessary for the specified purpose. Collecting only the PII required for the stated function directly implements this principle by limiting the scope of data collection at the source, reducing privacy risk and compliance burden.

Exam trap

CISSP often tests the confusion between data minimization (collect less) and anonymization or consent (post-collection controls), tempting candidates to pick anonymization as the best minimization practice.

How to eliminate wrong answers

Option B is wrong because anonymizing data after collection does not minimize collection; it is a post-hoc risk reduction technique, and the data was still collected and processed. Option C is wrong because obtaining explicit consent addresses lawfulness and transparency, not minimization; consent does not justify collecting more data than needed. Option D is wrong because collecting all possible PII 'just in case' is the opposite of data minimization and violates privacy by design principles.

668
MCQmedium

A company is designing a network segmentation strategy to isolate a public-facing web server from the internal corporate network. Which of the following is the most appropriate architecture?

A.Micro-segmentation using SDN
B.VLAN with no firewall
C.Direct connection to internet without segmentation
D.DMZ (screened subnet)
AnswerD

A Demilitarized Zone (DMZ), also known as a screened subnet, is a dedicated network segment specifically designed to host public-facing services that require external accessibility, such as web servers, email servers, or DNS servers. It acts as a buffer zone, typically situated between two firewalls, isolating these public services from the more sensitive internal network. This architecture ensures that even if a server within the DMZ is compromised, attackers still face another security layer before gaining access to internal resources, significantly enhancing overall network security.

Why this answer

A DMZ (screened subnet) is the most appropriate architecture because it places the public-facing web server in a separate, isolated network segment that sits between the internal corporate network and the untrusted internet. Traffic from the internet is allowed only to the DMZ (typically via stateful firewall rules permitting HTTP/HTTPS on TCP ports 80/443), and traffic from the DMZ to the internal network is strictly controlled or proxied, preventing direct lateral movement. This aligns with the principle of defense in depth and is a standard CISSP-recommended design for securing publicly accessible services.

Exam trap

The trap here is that candidates often confuse VLANs with security boundaries, assuming a VLAN alone provides sufficient isolation, when in fact VLANs lack access control and are vulnerable to Layer 2 attacks, making a DMZ with firewalls the correct answer for network segmentation of public-facing services.

How to eliminate wrong answers

Option A is wrong because micro-segmentation using SDN is an advanced, granular isolation technique typically used within data centers or east-west traffic control, but it is not the standard or most appropriate architecture for isolating a single public-facing web server from the internal network; a DMZ is simpler, more established, and directly addresses the requirement. Option B is wrong because a VLAN without a firewall provides only Layer 2 separation and no access control or traffic filtering, leaving the web server and internal network vulnerable to attacks that bypass VLAN segmentation (e.g., VLAN hopping via DTP or double-tagging). Option C is wrong because a direct connection to the internet without segmentation exposes the web server and the entire internal network to unrestricted inbound and outbound traffic, violating the fundamental security principle of least privilege and offering no isolation.

669
Multi-Selecthard

An organization is implementing OpenID Connect (OIDC) for authentication. Which THREE of the following are components of OIDC? (Choose three.)

Select 3 answers
A.Authorization code flow
B.Kerberos ticket granting ticket
C.UserInfo endpoint
D.SAML assertion
E.ID token
AnswersA, C, E

The Authorization Code flow is the most secure and widely recommended OAuth 2.0 flow for confidential clients, such as web applications, within OpenID Connect. It involves the client redirecting the user's browser to the authorization server, receiving a temporary authorization code, and then exchanging this code directly with the authorization server's token endpoint for ID and access tokens. This method prevents sensitive tokens from being exposed in the user's browser or URL, enhancing security significantly.

Why this answer

OIDC defines the Authorization Code Flow (option A) as one of its core authentication flows, where the client exchanges an authorization code at the token endpoint for an ID token and access token, making it a standard OIDC component. The UserInfo endpoint (option C) is a defined OIDC endpoint that returns claims about the authenticated end-user when presented with a valid access token, so it is part of the OIDC specification. The ID token (option E) is the central OIDC artifact—a signed JWT containing authentication claims such as iss, sub, aud, exp, and iat—that proves the user's identity to the client.

Kerberos ticket granting tickets (option B) belong to the Kerberos protocol, not OIDC, and SAML assertions (option D) are part of the SAML 2.0 standard, which is a separate federation protocol from OIDC.

Exam trap

CISSP often tests the confusion between OIDC and other authentication protocols like SAML and Kerberos, leading candidates to select SAML assertion or Kerberos TGT as OIDC components.

670
MCQmedium

A government agency requires a security model that prevents users from reading documents classified above their clearance level and from writing classified information to lower-level systems. Which model enforces these constraints?

A.Bell-LaPadula
B.Biba
C.Brewer-Nash
D.Clark-Wilson
AnswerA

The Bell-LaPadula security model is specifically designed to enforce confidentiality in multi-level security systems, making it ideal for government agencies dealing with classified information. It operates on two core rules: the Simple Security Property (no read up) and the *-Property (no write down). These rules prevent subjects from accessing information at a higher security level than their own and from writing information to a lower security level, thereby ensuring that classified data remains protected from unauthorized disclosure.

Why this answer

Bell-LaPadula is the mandatory access control model focused on confidentiality, enforcing 'no read up' (simple security property) and 'no write down' (star property). These two rules exactly match the requirement: users cannot read above their clearance and cannot write classified data to lower levels. Biba, Brewer-Nash, and Clark-Wilson address integrity or conflict-of-interest, not confidentiality.

Exam trap

CISSP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates who memorize only one direction pick the wrong model.

How to eliminate wrong answers

Option B (Biba) is wrong because Biba enforces integrity with 'no read down' and 'no write up' — the inverse of Bell-LaPadula — protecting data integrity, not confidentiality. Option C (Brewer-Nash) is wrong because it is the Chinese Wall model, which prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by clearance levels. Option D (Clark-Wilson) is wrong because it enforces integrity through well-formed transactions and separation of duties, using access triplets (subject, program, object), and does not address classification-based confidentiality.

671
MCQmedium

A security analyst runs a vulnerability scan and sees the output shown in the exhibit. The analyst wants to remediate the most critical issue first. Which action should the analyst take to address the SQL injection vulnerability?

A.Deploy a web application firewall (WAF) with SQL injection signatures.
B.Rewrite the database query to use parameterized statements.
C.Implement strict input validation on the 'id' parameter.
D.Encode all output from the 'id' parameter using HTML entity encoding.
AnswerB

Rewriting the database query to use parameterized statements is the definitive solution for preventing SQL injection. This technique ensures that user-supplied input is treated purely as data values, not as executable SQL code. The query structure is pre-compiled by the database, and then the user input is bound to placeholders, preventing an attacker from altering the query's logic or introducing new commands, thereby maintaining the strict separation of code and data.

Why this answer

Parameterized statements (prepared statements) separate SQL code from data, ensuring that user input is treated as data rather than executable code. This prevents SQL injection because the database engine parses the query structure before binding parameters. Rewriting the query to use parameterized statements is the most effective and fundamental remediation for SQL injection.

Exam trap

The trap here is that candidates may choose a WAF or input validation because they sound like security best practices, but the question asks for the action to address the SQL injection vulnerability itself, which requires fixing the code with parameterized statements.

How to eliminate wrong answers

Option A is wrong because a WAF with SQL injection signatures is a compensating control that can be bypassed and does not fix the underlying vulnerability. Option C is wrong because input validation alone is insufficient; attackers can often bypass validation filters, and it does not address the root cause. Option D is wrong because HTML entity encoding is for output encoding to prevent XSS, not for preventing SQL injection.

672
MCQmedium

An employee leaves the company, and their user account is not disabled. This creates a security risk known as:

A.Orphaned account
B.Insider threat
C.Privilege creep
D.Separation of duties violation
AnswerA

When an employee departs an organization and their associated user account remains active in the identity provider or directory services without an assigned owner, it is classified as an orphaned account. These accounts pose significant security risks as they lack accountability and are prime targets for unauthorized access or exploitation.

Why this answer

An orphaned account is a user account that remains active in the identity management system after the employee has left the organization. This creates a security risk because the account can be exploited by attackers or former employees to gain unauthorized access to systems, data, or network resources, bypassing access controls that rely on account deactivation.

Exam trap

The trap here is that candidates may confuse 'orphaned account' with 'insider threat' because both involve a former employee, but the question specifically asks for the name of the security risk created by the account itself, not the general threat category.

How to eliminate wrong answers

Option B is wrong because an insider threat is a broader category of risk posed by individuals within the organization (current or former) who misuse their access, but the specific risk of an account not being disabled after departure is defined as an orphaned account. Option C is wrong because privilege creep refers to the gradual accumulation of excessive permissions over time for a user who remains employed, not to an account left active after termination. Option D is wrong because a separation of duties violation occurs when a single user is allowed to perform conflicting tasks (e.g., both creating and approving a purchase order), which is unrelated to the failure to disable a departed user's account.

673
MCQhard

A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?

A.Risk acceptance
B.Risk avoidance
C.Risk enhancement
D.Risk transfer
E.Risk mitigation
AnswerE

Risk mitigation involves implementing controls or countermeasures to reduce the likelihood or impact of a risk event to an acceptable level. Upgrading to stronger encryption algorithms, increasing key lengths, or improving cryptographic protocols directly reduces the probability of a successful attack against encrypted data. This action directly lessens the organization's exposure to a data breach, aligning precisely with the definition and objective of risk mitigation.

Why this answer

The risk manager is applying risk mitigation by implementing the encryption upgrade to reduce the likelihood or impact of a data breach. This directly addresses the identified risk by deploying a stronger cryptographic control, such as moving from AES-128 to AES-256 or replacing deprecated TLS 1.0/1.1 with TLS 1.3, thereby lowering the residual risk to an acceptable level.

Exam trap

The trap here is confusing risk mitigation with risk avoidance, as candidates may think avoiding outdated encryption means avoiding the risk entirely, but risk avoidance requires ceasing the risky activity, not upgrading the control.

How to eliminate wrong answers

Option A is wrong because risk acceptance would involve acknowledging the risk and taking no action to reduce it, which contradicts the decision to spend $50,000 on an upgrade. Option B is wrong because risk avoidance would mean eliminating the activity that creates the risk (e.g., ceasing all data transmission), not upgrading encryption. Option C is wrong because risk enhancement is not a standard risk treatment option; it would involve deliberately increasing risk, which is the opposite of the manager's action.

Option D is wrong because risk transfer would involve shifting the financial burden of a breach to a third party (e.g., purchasing cyber insurance), not investing in internal controls.

674
MCQeasy

An organization is implementing a new governance framework to align IT with business goals. Which framework is specifically designed for IT service management?

A.ISO/IEC 27001
B.COBIT 2019
C.ITIL
D.NIST Cybersecurity Framework
AnswerC

ITIL (Information Technology Infrastructure Library) is the most appropriate choice as it provides a detailed, practical framework of best practices for IT service management (ITSM). It encompasses the entire service lifecycle, from strategy and design to transition, operation, and continual service improvement, ensuring that IT services are aligned with business needs and deliver value. ITIL's focus on service delivery, customer experience, and value co-creation makes it ideal for governing IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) is the framework specifically designed for IT service management (ITSM), providing best practices for service strategy, design, transition, operation, and continual improvement. It focuses on aligning IT services with business needs through processes like incident, problem, change, and service-level management. COBIT is a governance framework, ISO/IEC 27001 is an information security management standard, and NIST CSF is a cybersecurity framework — none are ITSM-specific.

Exam trap

CISSP often tests the confusion between governance frameworks (COBIT) and service management frameworks (ITIL), since both address 'aligning IT with business goals' — the key discriminator is whether the question emphasizes service delivery/operations versus oversight/control.

How to eliminate wrong answers

Option A is wrong because ISO/IEC 27001 specifies requirements for an information security management system (ISMS), not IT service delivery processes. Option B is wrong because COBIT 2019 is an IT governance and management framework focused on control objectives and enterprise IT oversight, not day-to-day service management. Option D is wrong because the NIST Cybersecurity Framework provides voluntary guidance for managing cybersecurity risk (Identify, Protect, Detect, Respond, Recover), not IT service management.

675
Multi-Selecthard

Which THREE of the following are valid types of penetration testing based on the level of knowledge provided to the tester?

Select 3 answers
A.Blue box
B.White box
C.Grey box
D.Black box
E.Red box
AnswersB, C, D

White-box penetration testing, also known as clear-box testing, provides the assessor with complete access to system documentation, source code, network diagrams, and IP addressing schemes. This comprehensive visibility allows for a highly thorough security assessment, simulating an insider threat or a scenario where an attacker has obtained deep administrative access.

Why this answer

The three valid penetration-testing types classified by the tester's level of knowledge are White box (B), Grey box (C), and Black box (D). White box testing gives the tester full knowledge of the target, including source code, architecture, and credentials, making it the highest-knowledge category. Grey box testing provides partial knowledge, such as limited documentation or user-level credentials, simulating an insider with some access.

Black box testing provides no prior knowledge of the target, simulating an external attacker who must perform reconnaissance. Blue box (A) and Red box (E) are not standard knowledge-based penetration-testing classifications; 'blue team' and 'red team' refer to defensive and offensive roles, not levels of tester knowledge.

Exam trap

CISSP often tests the three knowledge-based pen test types (white, grey, black) while seeding color-based distractors like 'blue box' and 'red box' that refer to team roles, not testing methodologies — candidates who conflate team colors with test types select the wrong options.

Page 8

Page 9 of 11

Page 10

All pages