Courseiva

CCNA Security Architecture and Engineering Questions

59 questions · Security Architecture and Engineering · All types, answers revealed

1
MCQmedium

A security architect is deploying a public key infrastructure (PKI) and wants to ensure that certificate revocation status is verified efficiently without relying on a centralized CRL distribution point. Which technique should be used?

A.Certificate Transparency Logs
B.OCSP Stapling
C.Certificate Pinning
D.Self-Signed Certificates
AnswerB

OCSP Stapling is an efficient method for web servers to provide clients with the revocation status of their own SSL/TLS certificates during the TLS handshake. The server periodically queries the Certificate Authority's (CA) Online Certificate Status Protocol (OCSP) responder for its certificate's status, caches the signed response, and "staples" it to the certificate sent to the client. This significantly improves privacy and performance by eliminating the need for each client to directly query the OCSP responder, reducing latency and server load.

Why this answer

OCSP Stapling allows the server to obtain a signed, time-stamped OCSP response from the CA and present it to clients during the TLS handshake, so clients do not need to contact the OCSP responder directly. This eliminates the latency and privacy concerns of real-time OCSP lookups and avoids reliance on a centralized CRL distribution point. It is the standard technique for efficient, decentralized revocation checking.

Exam trap

CISSP often tests the difference between OCSP Stapling (server-provided, cached revocation proof) and plain OCSP (client-to-responder lookup) — candidates pick Certificate Transparency or pinning because they sound security-related, but only stapling provides efficient decentralized revocation verification.

How to eliminate wrong answers

Option A is wrong because Certificate Transparency Logs are append-only public logs used to detect mis-issued certificates; they do not provide revocation status and are not a substitute for CRL or OCSP. Option C is wrong because certificate pinning hardcodes a specific certificate or public key in the client, which prevents use of fraudulent certs but does not verify revocation status and can break on legitimate cert rotation. Option D is wrong because self-signed certificates are not issued by a trusted CA, so they bypass the PKI trust model entirely and provide no revocation mechanism — they are unsuitable for public PKI deployments.

2
MCQeasy

A company is implementing an access control system where permissions are granted based on attributes such as user role, department, time of day, and device trust score. This approach allows for fine-grained policies that can adapt to context. Which access control model is being used?

A.MAC (Mandatory Access Control)
B.ABAC (Attribute-Based Access Control)
C.DAC (Discretionary Access Control)
D.RBAC (Role-Based Access Control)
AnswerB

Attribute-Based Access Control (ABAC) is the correct choice because it dynamically evaluates a comprehensive set of attributes associated with the subject (user), object (resource), and environment (e.g., time of day, location, device security posture) to make real-time access decisions. This model offers fine-grained control and exceptional flexibility, allowing policies to be expressed as logical rules that combine various contextual factors beyond just roles or labels.

Why this answer

ABAC grants or denies access based on attributes of the subject (role, department), the resource, the action, and the environment (time of day, device trust score). The scenario explicitly lists multiple contextual attributes combined into fine-grained, adaptive policies, which is the defining characteristic of ABAC. RBAC only uses roles, MAC uses labels/clearances, and DAC uses owner discretion.

Exam trap

CISSP often tests the ABAC vs RBAC boundary, tempting candidates to pick RBAC because roles are mentioned — but the presence of environmental attributes like time and device trust is the giveaway for ABAC.

How to eliminate wrong answers

Option A is wrong because MAC uses mandatory labels (e.g., Bell-LaPadula, Biba) assigned by a central authority, not dynamic contextual attributes like time or device trust. Option C is wrong because DAC lets resource owners set permissions at their discretion, which does not match policy-driven attribute evaluation. Option D is wrong because RBAC bases decisions on roles alone; while roles can be one attribute in ABAC, the scenario's inclusion of time of day and device trust score goes beyond RBAC's scope.

3
Multi-Selectmedium

A security architect is evaluating access control models for a healthcare system where users have specific roles (e.g., doctor, nurse, admin) and permissions are assigned based on those roles. However, the architect also wants to incorporate attributes such as time of day, patient consent status, and device type. Which TWO models should be combined to meet these requirements?

Select 2 answers
A.Clark-Wilson
B.MAC
C.ABAC
D.RBAC
E.DAC
AnswersC, D

Attribute-Based Access Control (ABAC) is a dynamic access control model that evaluates a set of attributes associated with the subject (user), object (resource), action (operation), and environment (context) to make real-time access decisions. This highly flexible approach allows for fine-grained control, enabling policies like "a manager in department X can approve expenses up to $500 during business hours." ABAC provides unparalleled granularity and adaptability, making it suitable for complex, evolving access requirements.

Why this answer

Option D (RBAC) is correct because the scenario explicitly states that users have specific roles such as doctor, nurse, and admin, and permissions are assigned based on those roles — this is the defining characteristic of Role-Based Access Control, where access rights are grouped into roles and users are assigned to roles. Option C (ABAC) is correct because the architect additionally wants to enforce dynamic, fine-grained conditions such as time of day, patient consent status, and device type, which are attributes evaluated at request time — exactly what Attribute-Based Access Control provides through policies combining subject, resource, action, and environmental attributes. Combining RBAC and ABAC (often called a hybrid or role-and-attribute model) lets roles provide coarse-grained baseline permissions while attributes refine decisions for context-sensitive healthcare access.

Option A (Clark-Wilson) is not selected because it is an integrity model focused on well-formed transactions and separation of duties, not on role- or attribute-driven access decisions. Option B (MAC) is not selected because it relies on mandatory labels and clearances rather than the role and contextual attribute inputs described. Option E (DAC) is not selected because it grants resource owners discretionary control via ACLs, which does not satisfy the role-based and attribute-based requirements stated.

Exam trap

CISSP often tests the misconception that ABAC replaces RBAC — the trap is choosing only ABAC when the scenario explicitly requires role-based permissions plus contextual attributes, which mandates combining both.

4
Multi-Selectmedium

A security engineer is hardening a web application against race condition vulnerabilities. Which TWO techniques are effective mitigations?

Select 2 answers
A.Enabling ASLR
B.Input validation
C.Implementing file locking
D.Using prepared statements
E.Use of atomic transactions
AnswersC, E

Implementing file locking is an effective mechanism to prevent race conditions when multiple processes or threads attempt to access and modify the same file concurrently. A file lock ensures that only one process can hold the lock and access the critical section of code involving file operations at any given time. This serialization of access prevents inconsistent states or data corruption that could occur if operations like reading, modifying, and writing were interleaved unpredictably by competing processes, thereby maintaining data integrity.

Why this answer

Implementing file locking (C) is correct because race conditions arise when concurrent processes access shared resources such as files without synchronization; advisory or mandatory locks (e.g., flock, fcntl) serialize access so one process completes its read-modify-write before another proceeds. Use of atomic transactions (E) is correct because database or filesystem transactions with ACID properties (BEGIN/COMMIT, row-level locking, SELECT ... FOR UPDATE) ensure that check-then-act sequences execute indivisibly, preventing time-of-check-to-time-of-use (TOCTOU) interleavings.

Enabling ASLR (A) only randomizes memory layout to hinder exploitation of memory-corruption bugs, not to prevent logical race conditions. Input validation (B) filters malformed or malicious data but does not coordinate concurrent access to shared state. Using prepared statements (D) parameterizes SQL to stop injection attacks, which is unrelated to synchronizing concurrent operations.

Exam trap

CISSP often tests the misconception that input validation or prepared statements mitigate race conditions — candidates must recognize that only synchronization mechanisms (locks, atomic transactions) address concurrency, while those other controls address injection or memory exploitation.

5
MCQmedium

A security analyst is investigating a potential covert timing channel in a system. Which of the following characteristics best describes this type of channel?

A.It requires high bandwidth to be effective
B.It modulates the time between events to encode information
C.It uses storage locations not normally accessible to the sender and receiver
D.It uses encryption to hide the content of the communication
AnswerB

A covert timing channel encodes information by precisely modulating the temporal relationship between observable events within a shared system. This involves a sender manipulating the timing of an action, like delaying a process or altering packet transmission intervals, which a receiver then observes and decodes based on the temporal variations. For example, a short delay might represent a '0' bit, while a longer delay signifies a '1' bit, transmitting data without using explicit storage or direct communication channels.

Why this answer

A covert timing channel encodes information by varying the timing of observable events—such as packet inter-arrival times, CPU scheduling delays, or response latencies—rather than by writing to a shared storage location. The receiver measures these timing variations to reconstruct the hidden message. This is the defining characteristic that distinguishes timing channels from storage channels.

Exam trap

The trap here is confusing covert timing channels with covert storage channels; CISSP candidates frequently pick the storage-channel description because both involve hidden communication, but only timing channels modulate event timing.

How to eliminate wrong answers

Option A is wrong because covert timing channels are typically low-bandwidth by nature; high bandwidth would make them easier to detect and is not a requirement. Option C is wrong because it describes a covert storage channel, which uses shared storage locations (like unused header bits or file attributes) rather than timing. Option D is wrong because encryption conceals content, not the existence of the channel, and is unrelated to the definition of a covert timing channel.

6
MCQmedium

A security analyst is investigating a potential data leak via covert channels. Which of the following is an example of a timing covert channel?

A.Modifying unused fields in network packets
B.Encoding data in the TCP sequence number
C.Writing data to a shared disk file
D.Varying the spacing between keystrokes
AnswerD

Varying the spacing between keystrokes is a classic example of a timing covert channel. The secret information is not stored in any persistent state or modified data field, but rather conveyed through the temporal relationship between events. By subtly altering the inter-event delay, such as the time between keystrokes, the sender encodes data that the receiver can decode by observing these timing variations.

Why this answer

A timing covert channel conveys information by modulating the timing of events rather than the content of messages. Varying the spacing between keystrokes encodes bits through inter-keystroke delays, which an observer can decode — this is a classic timing channel. The other options describe storage covert channels.

Exam trap

CISSP often tests whether candidates can distinguish storage covert channels (data hidden in fields/files) from timing covert channels (data encoded in event timing), since both are covert but use different mechanisms.

How to eliminate wrong answers

Option A is wrong because modifying unused fields in network packets is a storage covert channel — data is hidden in packet header fields, not in timing. Option B is wrong because encoding data in the TCP sequence number is also a storage channel, hiding information in a protocol field. Option C is wrong because writing data to a shared disk file is a storage covert channel using a shared resource, not timing.

7
MCQmedium

An organization is evaluating a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in a file access routine. The routine checks if a user has permission to open a file, then later opens the file. Which of the following best describes the potential exploitation?

A.An attacker exploits a weak cryptographic algorithm
B.An attacker modifies the file after the permission check but before the open operation
C.An attacker performs a buffer overflow to gain elevated privileges
D.An attacker intercepts the network traffic to steal credentials
AnswerB

This scenario precisely describes a Time of Check to Time of Use (TOCTOU) vulnerability, where a system first checks a resource's state, such as file permissions, and then later uses that resource, like opening the file. An attacker exploits the brief interval between these two operations to maliciously alter the file, for instance, by replacing a legitimate file with a symlink to a sensitive system file. This allows the attacker to bypass the initial security check and gain unauthorized access or control over the system's subsequent actions.

Why this answer

TOCTOU is a race condition where the state checked (permission) can change between the check and the use (open). An attacker swaps or modifies the file — often via a symlink — after the permission check passes but before the open executes, causing the program to operate on a different resource than the one authorized.

Exam trap

CISSP often tests whether candidates can distinguish TOCTOU (a race condition) from other vulnerability classes like buffer overflow or crypto weakness — the key is the timing gap between check and use.

How to eliminate wrong answers

Option A is wrong because weak cryptography is a separate class of vulnerability (e.g., MD5 collisions) unrelated to the timing gap between check and use. Option C is wrong because buffer overflow is a memory-safety flaw, not a race condition — it doesn't rely on a check/use window. Option D is wrong because network interception (MITM/sniffing) is a confidentiality attack on traffic, not a local file-access race condition.

8
MCQmedium

A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?

A.RC4
B.RSA
C.AES
D.3DES
AnswerC

AES (Advanced Encryption Standard) is a symmetric block cipher, widely recognized and adopted as the global standard for secure data encryption. It operates by encrypting data in fixed-size blocks (128 bits) using key sizes of 128, 192, or 256 bits, offering robust security against all known practical attacks when properly implemented. Its excellent balance of strong cryptographic properties, high performance, and efficiency makes it the optimal choice for encrypting bulk data in contemporary systems.

Why this answer

AES (Advanced Encryption Standard) is a NIST-approved symmetric block cipher defined in FIPS 197, supporting key sizes of 128, 192, and 256 bits. It is the standard choice for encrypting data at rest and satisfies all stated requirements.

Exam trap

CISSP often tests the block-vs-stream and symmetric-vs-asymmetric distinction — candidates see 'strong security' and pick RSA or 3DES, missing that the question specifies a NIST-approved block cipher with 128/192/256-bit keys, which uniquely identifies AES.

How to eliminate wrong answers

Option A is wrong because RC4 is a stream cipher, not a block cipher, and it is deprecated due to serious biases in its keystream (RFC 7465 prohibits it in TLS). Option B is wrong because RSA is an asymmetric algorithm used for key exchange and digital signatures, not for bulk data-at-rest encryption, and its key sizes (e.g., 2048, 3072) do not match the 128/192/256-bit requirement. Option D is wrong because 3DES is a block cipher but uses 112 or 168 effective bits, is deprecated by NIST (disallowed after 2023), and does not offer the 128/192/256-bit key sizes required.

9
MCQeasy

A security architect is designing a physical security perimeter for a data center. Which of the following is an example of Crime Prevention Through Environmental Design (CPTED) principle?

A.Using high fences with barbed wire around the facility
B.Designing the landscape to provide clear sightlines from the guard post
C.Deploying motion sensors and CCTV cameras
D.Installing biometric locks on all server room doors
AnswerB

Designing the landscape to provide clear sightlines from a guard post directly implements the CPTED principle of natural surveillance. By eliminating potential hiding spots and ensuring unobstructed views, this design choice increases the perceived risk for potential offenders, as they believe their actions are more likely to be observed. This proactive environmental design deters criminal activity by making illicit behavior more difficult to conceal, thereby enhancing overall security through visibility.

Why this answer

CPTED focuses on designing the physical environment to reduce crime and fear of crime by influencing human behavior. Clear sightlines from a guard post are a classic CPTED principle—natural surveillance—which allows guards to observe the area without obstruction, deterring potential intruders. This is a design-based approach, not just adding security hardware.

Exam trap

CISSP often tests the distinction between CPTED principles (design-based, passive) and physical security controls (active, hardware-based), so candidates must recognize that clear sightlines are a design feature, not a device.

How to eliminate wrong answers

Option A is wrong because high fences with barbed wire are a physical security control (target hardening), not a CPTED principle; CPTED emphasizes natural surveillance, territorial reinforcement, and access control through design. Option C is wrong because motion sensors and CCTV are electronic surveillance systems, which are active security technologies, not environmental design principles. Option D is wrong because biometric locks are access control mechanisms (target hardening), not CPTED; CPTED would instead use natural access control like landscaping or pathways to guide people.

10
MCQeasy

Which access control model allows the data owner to determine who can access their resources, typically using Access Control Lists (ACLs)?

A.Discretionary Access Control (DAC)
B.Role-Based Access Control (RBAC)
C.Mandatory Access Control (MAC)
D.Attribute-Based Access Control (ABAC)
AnswerA

DAC lets the resource owner set permissions themselves, typically through ACLs listing permitted subjects and rights. Authority is discretionary and delegated to the owner, unlike mandatory or role-based models where central policy dictates access regardless of ownership.

Why this answer

Discretionary Access Control (DAC) is defined by the property that the owner of a resource decides who can access it and with what permissions, typically by configuring Access Control Lists (ACLs) on the object. This owner-controlled discretion is the defining characteristic that separates DAC from MAC, RBAC, and ABAC. In DAC systems like Windows NTFS or Unix file permissions, the resource owner can grant or revoke access at will.

Exam trap

CISSP often tests the confusion between DAC and RBAC — candidates see 'owner determines access' and think of role owners, but the key discriminator is that DAC grants discretion to the resource owner, not to a role administrator.

How to eliminate wrong answers

Option B is wrong because RBAC assigns permissions based on organizational roles rather than individual owner discretion — access is determined by the user's role, not by the resource owner's choice. Option C is wrong because MAC uses system-enforced labels (e.g., Bell-LaPadula, Biba) where the operating system, not the data owner, controls access based on security clearances and object classifications. Option D is wrong because ABAC evaluates a combination of attributes (user, resource, environment, action) via policies, which is more granular and policy-driven than owner-discretionary ACLs.

11
MCQeasy

Which component of a trusted computing base (TCB) implements the reference monitor concept by enforcing access control decisions for all subjects and objects in the system?

A.Trusted platform module
B.Trusted computing base
C.Reference monitor
D.Security kernel
AnswerD

The security kernel is the concrete implementation of the abstract reference monitor concept within a Trusted Computing Base (TCB). It is the core of the operating system that enforces the system's access control policies, mediating all subject-object interactions to ensure security. This critical component is responsible for isolating processes, managing memory, and controlling access to resources, making it the actual mechanism that implements the TCB's security functions.

Why this answer

The security kernel is the hardware, firmware, and software component of the TCB that implements the reference monitor concept by mediating all access requests between subjects and objects. It enforces the access control policy and is the only portion of the TCB that must be tamper-proof and always invoked. While the reference monitor is the abstract concept, the security kernel is its concrete implementation within the TCB.

Exam trap

The trap is conflating the abstract reference monitor concept with its concrete implementation (security kernel), or confusing the broader TCB with the specific enforcement component.

How to eliminate wrong answers

Option A is wrong because the Trusted Platform Module (TPM) is a hardware chip for secure key storage and platform integrity measurement, not the access-control enforcement mechanism. Option B is wrong because the TCB is the broader set of components (hardware, firmware, software) that enforce security policy; it contains the security kernel but is not itself the reference monitor implementation. Option C is wrong because the reference monitor is the abstract model or concept (always invoked, tamper-proof, verifiable) rather than the concrete component that implements it.

12
MCQmedium

A government agency requires a security model that prevents users from reading documents at a higher classification level and from writing to documents at a lower classification level. Which model enforces these constraints?

A.Bell-LaPadula
B.Brewer-Nash
C.Clark-Wilson
D.Biba
AnswerA

The Bell-LaPadula security model is specifically designed to enforce confidentiality, primarily within military and government hierarchical classification systems. It prevents unauthorized disclosure of information by implementing two core rules: the Simple Security Property (no read up) and the *-Property (no write down). This ensures that subjects can only access information at or below their security clearance level and cannot write information to a lower clearance level, thus maintaining strict confidentiality.

Why this answer

Bell-LaPadula is the mandatory access control model focused on confidentiality. Its two core rules are 'no read up' (a subject cannot read data at a higher classification) and 'no write down' (a subject cannot write to a lower classification), which exactly match the government agency's stated constraints. The simple security property and the *-property (star property) enforce these respectively.

Exam trap

CISSP often tests the read/write direction of Bell-LaPadula versus Biba, so the trap is mixing up 'no read up/no write down' (confidentiality) with 'no read down/no write up' (integrity).

How to eliminate wrong answers

Option B is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by classification hierarchy. Option C is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not confidentiality classification levels. Option D is wrong because Biba is the integrity model and enforces the reverse rules — 'no read down' and 'no write up' — which would allow reading higher-classification data, the opposite of what is required.

13
MCQmedium

A security architect is designing a system for a government agency that requires strict confidentiality controls. Data must be classified at multiple levels (e.g., Top Secret, Secret, Confidential). Users at a lower classification should not be able to read data at a higher classification, and users at a higher classification should not be able to write data to a lower classification. Which security model enforces these rules?

A.Biba model
B.Clark-Wilson model
C.Brewer-Nash model
D.Bell-LaPadula model
AnswerD

The Bell-LaPadula model is a state machine model designed specifically to enforce confidentiality in systems handling classified information, such as those used by governments. It prevents unauthorized disclosure by implementing two core rules: the Simple Security Property ("no read up") and the *-Property ("no write down"). These rules ensure that subjects can only access information at or below their security clearance level and cannot write information to a lower security level, thus preventing information flow to less secure domains.

Why this answer

The Bell-LaPadula model is specifically designed for confidentiality and enforces two core rules: the Simple Security Property (no read up — a subject at a lower classification cannot read data at a higher classification) and the *-Property (no write down — a subject at a higher classification cannot write to a lower classification). These exactly match the government agency's requirements.

Exam trap

CISSP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates mix up the direction of the rules or pick Biba because both are 'multi-level' models.

How to eliminate wrong answers

Option A is wrong because the Biba model is the integrity-focused counterpart to Bell-LaPadula — it enforces no read down and no write up to protect data integrity, not confidentiality. Option B is wrong because the Clark-Wilson model focuses on integrity through well-formed transactions and separation of duties, using access triplets (subject, program, object), and does not address multi-level confidentiality classifications. Option C is wrong because the Brewer-Nash model (Chinese Wall) prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by static classification levels.

14
MCQmedium

An organization requires a commercial integrity model where users cannot modify data in higher integrity levels and cannot read data from lower integrity levels. Which model should they implement?

A.Bell-LaPadula
B.Clark-Wilson
C.Biba
D.Take-Grant
AnswerC

The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity by enforcing a strict hierarchical integrity policy. Its primary rules are 'no write up' (Simple Integrity Property) and 'no read down' (*-Integrity Property), which prevent subjects from writing to objects of higher integrity or reading from objects of lower integrity. This model ensures that high-integrity data is not contaminated by low-integrity data, making it ideal for scenarios requiring strong data trustworthiness.

Why this answer

The Biba integrity model is the classic commercial integrity model that enforces 'no write up, no read down' — users cannot modify data at a higher integrity level and cannot read data at a lower integrity level. This exactly matches the scenario described, making Biba the correct choice.

Exam trap

CISSP often tests the mirror-image confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up), so candidates who memorize only one direction pick the wrong model.

How to eliminate wrong answers

Option A is wrong because Bell-LaPadula is a confidentiality model with the inverse rules ('no read up, no write down'), which protects secrecy rather than integrity. Option B is wrong because Clark-Wilson is an integrity model based on well-formed transactions and separation of duties, not on hierarchical integrity levels with read/write restrictions. Option D is wrong because Take-Grant is a model of access-right propagation and delegation, not an integrity enforcement model.

15
MCQmedium

Which physical security design principle emphasizes that the physical environment should be designed to discourage criminal activity by using natural surveillance, access control, and territorial reinforcement?

A.TEMPEST
B.Fail-safe
C.Layered defense
D.CPTED
AnswerD

Crime Prevention Through Environmental Design (CPTED) is a multidisciplinary approach that uses urban and architectural design to reduce the incidence and fear of crime, and improve the quality of life. It emphasizes manipulating the built environment to create a sense of ownership, increase natural surveillance, and define clear territorial boundaries. CPTED principles, such as natural access control, natural surveillance, and territorial reinforcement, directly focus on how physical design can proactively deter undesirable behavior and enhance security.

Why this answer

CPTED (Crime Prevention Through Environmental Design) is the discipline that uses natural surveillance (sightlines that make intruders visible), natural access control (directing flow through defined entry points), and territorial reinforcement (fences, signage, landscaping that signal private space) to deter criminal activity. It is a design philosophy applied to the physical environment itself, not a technology or a layered-defense strategy.

Exam trap

CISSP often tests acronym recognition by pairing CPTED with other physical security terms like TEMPEST and layered defense, so candidates who don't recall that CPTED specifically maps to natural surveillance/access control/territorial reinforcement may choose the more familiar 'layered defense' answer.

How to eliminate wrong answers

Option A is wrong because TEMPEST is a U.S. government standard (NSTISSAM TEMPEST/1-92) addressing electromagnetic emanations from equipment that could be intercepted — it concerns signal leakage, not environmental design against crime. Option B is wrong because 'fail-safe' describes a system defaulting to a safe state on failure (e.g., doors unlocking on power loss), which is a resilience principle, not a crime-deterrence design methodology. Option C is wrong because layered defense (defense in depth) refers to stacking multiple overlapping controls — fences, guards, locks, sensors — so that no single failure compromises security; it is a strategy, not the specific CPTED design principle described.

16
Multi-Selectmedium

A security architect is designing a system that must ensure integrity of commercial transactions. Which of the following models are specifically focused on integrity? (Choose TWO)

Select 2 answers
A.Take-Grant
B.Brewer-Nash
C.Biba
D.Clark-Wilson
E.Bell-LaPadula
AnswersC, D

Biba is a formal state-machine model designed specifically to protect data integrity by preventing unauthorized modification. It operates on the principle of "no write up, no read down" to ensure that information from lower-integrity levels cannot contaminate higher-integrity levels. This makes it the ideal choice for a system where preventing data corruption and maintaining trustworthiness is the primary objective.

Why this answer

Biba (C) is an integrity model that enforces the no-read-down and no-write-up rules to prevent data at a lower integrity level from contaminating higher-integrity data, directly protecting transaction integrity. Clark-Wilson (D) is also an integrity model, using well-formed transactions and separation of duties to ensure that commercial data remains consistent and can only be modified through authorized transformation procedures. Take-Grant (A) is a model for analyzing access rights and information flow, not specifically an integrity model.

Brewer-Nash (B) is the Chinese Wall model, which addresses conflict-of-interest and confidentiality, not integrity. Bell-LaPadula (E) is a confidentiality model based on no-read-up and no-write-down, so it does not focus on integrity.

Exam trap

CISSP often tests the confusion between confidentiality and integrity models; candidates may incorrectly select Bell-LaPadula (confidentiality) or Brewer-Nash (conflict of interest) when asked about integrity.

17
MCQmedium

An organization is implementing a Public Key Infrastructure (PKI) to support secure email and web communications. The PKI includes a root CA, intermediate CAs, and end-entity certificates. Which of the following best describes the role of the root CA in this hierarchy?

A.It performs key escrow for all users
B.It issues certificates directly to end users
C.It validates certificate revocation lists (CRLs)
D.It is self-signed and forms the trust anchor
AnswerD

The root CA's certificate is uniquely self-signed, meaning its public key is used to verify a signature created by its own private key, making it inherently self-authenticating. This self-signed certificate is then manually or automatically distributed and pre-installed as a trusted root in operating systems and applications. It serves as the ultimate trust anchor, the foundational point from which all other certificates in the PKI hierarchy derive their trustworthiness and validity.

Why this answer

The root CA is the top of the PKI hierarchy and is self-signed, meaning its certificate is signed by its own private key. It serves as the ultimate trust anchor: all trust in the chain derives from it, and its public key is distributed out-of-band to relying parties. In a well-designed hierarchy, the root CA issues certificates only to intermediate CAs, not directly to end entities, to protect its private key.

Exam trap

CISSP often tests the misconception that the root CA issues end-entity certificates directly; candidates who overlook the security best practice of offline root and intermediate CA delegation will choose the 'issues directly to end users' option.

How to eliminate wrong answers

Option A is wrong because key escrow is a separate key recovery function (often handled by a dedicated escrow system or CA feature) and is not the defining role of the root CA. Option B is wrong because best practice is for the root CA to issue only to intermediate CAs, keeping the root offline; issuing directly to end users increases risk and is not the root's primary role. Option C is wrong because CRL validation is performed by relying parties or validation services, not by the root CA itself; the CA may publish CRLs, but validating them is a client-side or OCSP responder function.

18
MCQhard

A financial institution must ensure that transactions are well-formed and enforce separation of duties to prevent fraud. Which security model best addresses these requirements?

A.Biba
B.Clark-Wilson
C.Brewer-Nash
D.Bell-LaPadula
AnswerB

The Clark-Wilson integrity model is specifically designed for commercial environments requiring strong data integrity, well-formed transactions, and accountability. It enforces integrity through constrained data items (CDIs) that can only be modified by certified transformation procedures (TPs), which are executed by authorized users under strict separation of duties. This model directly addresses the need for controlled, validated operations and accountability in financial systems, ensuring transactions are processed correctly and preventing fraud.

Why this answer

The Clark-Wilson model is specifically designed for commercial integrity and enforces well-formed transactions and separation of duties through its access control triple (subject, program, object). It ensures that data can only be modified through certified transformation procedures, which directly addresses the requirement for well-formed transactions and fraud prevention via separation of duties. This makes it the correct model for financial transaction integrity.

Exam trap

CISSP often tests the confusion between integrity models (Biba, Clark-Wilson) and confidentiality models (Bell-LaPadula), and between Clark-Wilson's commercial integrity focus and Biba's hierarchical integrity levels.

How to eliminate wrong answers

Option A is wrong because the Biba model addresses integrity via hierarchical levels (no read down, no write up) but does not enforce well-formed transactions or separation of duties. Option C is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in consulting scenarios, not transaction integrity or separation of duties. Option D is wrong because Bell-LaPadula is a confidentiality model (no read up, no write down) and does not address integrity or separation of duties.

19
MCQeasy

Which access control model allows the owner of a resource to grant or deny access to other users?

A.Mandatory Access Control (MAC)
B.Discretionary Access Control (DAC)
C.Attribute-Based Access Control (ABAC)
D.Role-Based Access Control (RBAC)
AnswerB

Discretionary Access Control (DAC) is the correct model because it empowers the resource owner to define and modify access permissions for the resources they own. Under DAC, the owner can grant or revoke specific access rights (e.g., read, write, execute) to other users or groups, typically through mechanisms like Access Control Lists (ACLs) or permission bits. This model provides flexibility by allowing individual users to manage access to their own data and files, making it prevalent in many common operating systems.

Why this answer

Discretionary Access Control (DAC) is defined by the property that the owner of a resource (its creator or designated owner) has discretion to grant or revoke access to other subjects, typically via ACLs or permission bits. This owner-controlled delegation is the defining characteristic that separates DAC from MAC, RBAC, and ABAC.

Exam trap

CISSP often tests the owner-discretion distinction, so candidates who see 'owner' and jump to RBAC (because roles are assigned by owners) or ABAC (because attributes can be owner-defined) miss that DAC is specifically the model where the resource owner directly controls access.

How to eliminate wrong answers

Option A is wrong because in Mandatory Access Control (MAC), access decisions are made by the system based on security labels (e.g., Bell-LaPadula, Biba) and a central policy — owners cannot override or delegate access at their discretion. Option C is wrong because Attribute-Based Access Control (ABAC) evaluates policies against attributes of subjects, objects, and environment (e.g., department, time, location), not owner discretion. Option D is wrong because Role-Based Access Control (RBAC) grants access based on the roles assigned to a user, with permissions managed centrally by administrators rather than by resource owners.

20
Multi-Selecthard

A security architect is designing a trusted recovery capability for a high-assurance system that must continue operating during a failure without violating its security policy. The system must be able to recover from a failure while maintaining the security of the data it processes, and must not enter an insecure state during recovery. Which two recovery strategies best satisfy the requirement to maintain security during failure and recovery? (Choose two.)

Select 2 answers
A.Fail-secure operation, where the system denies access to resources and defaults to a secure state when a failure is detected.
B.Fail-open operation, where the system allows all access to maintain availability during a failure.
C.Cold restart, where the system reboots and reloads all software from scratch after a failure.
D.Fail-soft operation, where the system continues to provide degraded but secure functionality while the failed component is isolated.
E.Manual intervention, where an administrator restores the system from backups after a failure.
AnswersA, D

Fail-secure operation ensures that when a failure occurs, the system defaults to a state that denies access and protects data, rather than allowing unsafe access. This maintains the security policy during recovery by refusing to grant access until the system is restored. It prevents an insecure state, which is exactly what the requirement demands, and is a core principle in trusted recovery design for high-assurance systems.

Why this answer

Fail-soft and fail-secure operations are the two recovery strategies that maintain security during failure. Fail-soft keeps the system running in a degraded but secure mode, isolating the failed component, while fail-secure defaults to denying access and protecting data. Both prevent the system from entering an insecure state, which is essential for trusted recovery in high-assurance systems.

Fail-open, cold restart, and manual intervention either compromise security or fail to guarantee continuous protection during recovery.

Exam trap

The trap here is assuming that any recovery method that restores availability is acceptable, when the requirement is specifically to maintain security during failure and recovery, which fail-soft and fail-secure achieve but fail-open does not.

21
MCQmedium

A security architect is implementing a system that must prevent conflicts of interest for a consulting firm serving competing clients. Which security model is best suited for this requirement?

A.Take-Grant
B.Brewer-Nash
C.Clark-Wilson
D.Graham-Denning
AnswerB

The Brewer-Nash model, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on prior access history. It ensures that a subject who has accessed information from one company within a "conflict of interest class" cannot subsequently access information from a competing company within the same class. This dynamic access control mechanism effectively enforces ethical walls, making it the ideal choice for scenarios requiring the prevention of information leakage between competing entities.

Why this answer

The Brewer-Nash model (also called the Chinese Wall model) is specifically designed to prevent conflicts of interest by dynamically restricting access based on what a subject has already accessed. Once a consultant accesses data from one competing client, they are blocked from accessing data about that client's competitors. This dynamic, history-based access control is exactly what the scenario requires.

Exam trap

CISSP often tests the confusion between Brewer-Nash (conflict of interest) and Clark-Wilson (integrity) — candidates pick Clark-Wilson because both sound 'commercial' and integrity-focused, missing the conflict-of-interest keyword.

How to eliminate wrong answers

Option A is wrong because Take-Grant is a model for describing how rights can be transferred or delegated between subjects and objects — it addresses permission propagation, not conflict-of-interest separation. Option C is wrong because Clark-Wilson focuses on data integrity through well-formed transactions and separation of duties, not on preventing conflicts of interest across competing clients. Option D is wrong because Graham-Denning defines eight primitive operations for secure subject/object creation and rights transfer — it is a foundational access-control model, not a conflict-of-interest model.

22
MCQeasy

Which physical security concept uses natural surveillance, territorial reinforcement, and access control to deter crime in built environments?

A.TEMPEST
B.Faraday cage
C.Defense in depth
D.CPTED
AnswerD

Crime Prevention Through Environmental Design (CPTED) is a multidisciplinary approach that strategically uses the physical environment to reduce crime and the fear of crime. It achieves this by manipulating the built environment to enhance natural surveillance, control access, define territoriality, and maintain spaces, thereby increasing the perceived risk for offenders and reducing opportunities for crime. Natural surveillance, a core CPTED principle, involves designing spaces where legitimate users can naturally observe their surroundings, making criminal acts more difficult or noticeable.

Why this answer

CPTED (Crime Prevention Through Environmental Design) is the discipline that applies natural surveillance, territorial reinforcement, and access control to the built environment to reduce crime and fear of crime. These three principles, along with maintenance and activity support, form the core CPTED framework used by security architects and urban planners. The question's three named elements map directly to CPTED's foundational principles.

Exam trap

CISSP often tests acronym recognition by pairing CPTED with other physical/EMSEC terms like TEMPEST and Faraday cage, so candidates who don't know that CPTED stands for Crime Prevention Through Environmental Design may pick a technical countermeasure instead.

How to eliminate wrong answers

Option A is wrong because TEMPEST is a U.S. government standard (and NSA certification program) for limiting electromagnetic emanations from equipment to prevent signal interception, not a crime-deterrence design philosophy. Option B is wrong because a Faraday cage is a physical enclosure of conductive mesh that blocks electromagnetic fields and RF signals — a technical countermeasure, not a design methodology for surveillance and territoriality. Option C is wrong because defense in depth is a layered-security strategy (perimeter, network, host, application, data controls) and does not specifically describe natural surveillance, territorial reinforcement, or access control in built environments.

23
Multi-Selecthard

A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?

Select 2 answers
A.TOCTOU
B.Emanations
C.Covert timing channel
D.Side-channel
E.Covert storage channel
AnswersC, E

A covert timing channel transmits information by modulating the temporal characteristics of system events or resource access, such as the precise timing of CPU cycles, network packet delays, or disk I/O operations. A sender encodes data by introducing subtle, detectable delays or variations in these timings, which a receiver then observes and decodes. This method exploits shared system resources or observable event sequences to establish a hidden communication path, bypassing explicit security policies.

Why this answer

Option C, a covert timing channel, is correct because it leaks information by modulating the timing of events (e.g., CPU scheduling, packet delays, or response latencies) so that a high-security process signals bits to a low-security process without sharing a direct data object. Option E, a covert storage channel, is correct because it leaks information by writing to and reading from a shared storage resource (e.g., file locks, disk sectors, or memory locations) whose presence or value is observable across security levels. Option A, TOCTOU, is a race-condition vulnerability class, not a covert channel type, so it does not belong.

Option B, emanations, refers to unintentional electromagnetic or acoustic leakage, which is a side-channel phenomenon rather than the intentional signaling mechanism of a covert channel. Option D, side-channel, is a broader category of information leakage (e.g., power, cache, or timing analysis) and is not one of the two standard covert channel types asked for here.

Exam trap

CISSP often tests the precise two-category taxonomy of covert channels — candidates pick 'side-channel' or 'emanations' because they sound like leakage, but the exam expects the classic storage/timing pair.

24
MCQmedium

A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?

A.Bell-LaPadula
B.Graham-Denning
C.Clark-Wilson
D.Biba
AnswerD

The Biba integrity model is specifically designed to prevent data corruption and maintain data integrity. It operates on two core principles: the Simple Integrity Axiom (no read down) and the * (Star) Integrity Axiom (no write up). These rules ensure that subjects cannot read data of lower integrity (to prevent being corrupted) and cannot write to data of higher integrity (to prevent corrupting it), making it ideal for applications requiring strict integrity controls.

Why this answer

The Biba integrity model is defined by the 'no write up' and 'no read down' rules, which prevent subjects at a lower integrity level from writing to higher levels and prevent subjects at a higher level from reading lower-level (potentially tainted) data. This directly matches the scenario's requirement to prevent unauthorized modifications by preserving integrity across levels. Biba is the integrity counterpart to Bell-LaPadula, which focuses on confidentiality.

Exam trap

CISSP often tests the confusion between Bell-LaPadula and Biba by swapping the direction of the no-read/no-write rules; candidates who memorize 'no read up, no write down' without associating it to confidentiality will pick Bell-LaPadula for an integrity scenario.

How to eliminate wrong answers

Option A is wrong because Bell-LaPadula enforces confidentiality with 'no read up' and 'no write down' rules, the inverse of the stated controls. Option B is wrong because Graham-Denning is a formal access control model defining eight primitive operations for secure subject/object creation and deletion, not an integrity-level model. Option C is wrong because Clark-Wilson enforces integrity through well-formed transactions and separation of duties, not through hierarchical integrity labels with no-write-up/no-read-down rules.

25
MCQeasy

Which cryptographic algorithm is an example of a symmetric stream cipher?

A.RC4
B.AES
C.3DES
D.RSA
AnswerA

RC4 is indeed a symmetric stream cipher, meaning it encrypts data one byte or bit at a time, generating a pseudorandom keystream that is then XORed with the plaintext to produce ciphertext. This approach makes it highly efficient for real-time communication and variable-length data streams, as it does not require padding to fixed block sizes. While widely used in protocols like WEP and SSL/TLS in the past, RC4 is now largely deprecated due to identified vulnerabilities when used improperly, particularly related to weak keys and non-random keystream generation.

Why this answer

RC4 is a symmetric stream cipher that generates a pseudorandom keystream and XORs it with plaintext one byte at a time. It was widely used in WEP, WPA (TKIP), and SSL/TLS before being deprecated due to keystream biases. Stream ciphers encrypt data bit-by-bit or byte-by-byte, unlike block ciphers which process fixed-size blocks.

Exam trap

CISSP often tests the stream-vs-block cipher distinction, and candidates mistakenly classify AES as a stream cipher because it can operate in stream-like modes such as CTR or GCM.

How to eliminate wrong answers

Option B is wrong because AES is a symmetric block cipher operating on 128-bit blocks (with 128/192/256-bit keys), not a stream cipher — though it can be used in stream-like modes such as CTR or GCM. Option C is wrong because 3DES is a symmetric block cipher that applies DES three times to 64-bit blocks, not a stream cipher. Option D is wrong because RSA is an asymmetric (public-key) algorithm based on integer factorization, not a symmetric cipher at all.

26
MCQeasy

Which of the following is a primary function of a Trusted Platform Module (TPM)?

A.Encrypting network traffic
B.Providing antivirus protection
C.Enforcing access control policies
D.Storing cryptographic keys securely
AnswerD

Storing cryptographic keys securely is a core and primary function of a Trusted Platform Module (TPM). The TPM provides a tamper-resistant environment, often isolated from the main CPU, where sensitive cryptographic keys can be generated, stored, and used without being exposed to software vulnerabilities or physical attacks on the host system. This secure storage protects keys from unauthorized access and ensures their integrity, which is crucial for secure boot, disk encryption, and digital signing operations.

Why this answer

A Trusted Platform Module (TPM) is a hardware chip that securely stores cryptographic keys, certificates, and measurements used for platform integrity and encryption. Its primary function is secure key storage and cryptographic operations, such as protecting BitLocker keys and enabling measured boot. Option D correctly identifies this core capability.

Exam trap

CISSP often tests the misconception that a TPM encrypts network traffic or enforces access control, when its primary role is secure cryptographic key storage and platform integrity measurement.

How to eliminate wrong answers

Option A is wrong because encrypting network traffic is the role of protocols like TLS/IPsec, not the TPM; the TPM may store keys used by those protocols but does not encrypt traffic itself. Option B is wrong because antivirus protection is a software function, unrelated to the TPM's cryptographic and integrity roles. Option C is wrong because enforcing access control policies is handled by operating systems, IAM systems, and policy engines; the TPM supports secure boot and attestation but does not enforce access control policies.

27
MCQmedium

A company wants to ensure that only authorized software can run on its laptops. They decide to use a hardware component that validates the boot process by measuring each component before it loads. Which technology is being used?

A.Trusted Platform Module (TPM)
B.Trusted Execution Environment (TEE)
C.Security Kernel
D.Hypervisor
AnswerA

The Trusted Platform Module (TPM) is a secure cryptoprocessor designed to secure hardware by integrating cryptographic keys into devices. It performs a "measured boot" process, where each component loaded during startup (firmware, boot loader, operating system kernel) is cryptographically hashed and the measurements are stored in secure PCRs (Platform Configuration Registers). This allows the system to verify the integrity of the boot path and, through remote attestation, prove to a third party that the system booted with an authorized and untampered software configuration.

Why this answer

A Trusted Platform Module (TPM) is a dedicated hardware chip that performs cryptographic measurements of boot components — firmware, bootloader, and OS — storing hashes in Platform Configuration Registers (PCRs). These measurements enable a measured boot and, combined with secure boot, ensure only authorized, unmodified software loads. The question's emphasis on a hardware component validating the boot process by measuring each component maps directly to TPM's role.

Exam trap

CISSP often tests the distinction between TPM (hardware root of trust that measures the boot process) and TEE (runtime isolated execution environment), since both are described as 'hardware security' but serve different phases.

How to eliminate wrong answers

Option B is wrong because a Trusted Execution Environment (TEE) is an isolated execution area within a processor (e.g., ARM TrustZone, Intel SGX) that protects code and data at runtime — it does not measure and validate the boot chain. Option C is wrong because a security kernel is the minimal, verified core of an operating system that enforces the reference monitor; it is software, not a hardware component that measures boot components. Option D is wrong because a hypervisor creates and manages virtual machines; while it can be part of a trusted boot chain, it does not itself perform the hardware-rooted measurement of each boot component.

28
MCQmedium

An organization uses a system where access decisions are based on user attributes (e.g., job title, clearance), resource attributes (e.g., classification), and environmental factors (e.g., time of day). This is an example of:

A.Role-Based Access Control (RBAC)
B.Attribute-Based Access Control (ABAC)
C.Mandatory Access Control (MAC)
D.Discretionary Access Control (DAC)
AnswerB

Attribute-Based Access Control (ABAC) is the correct answer because it defines access policies based on a combination of attributes associated with the subject (user), object (resource), action, and environment. This model allows for highly granular and dynamic access decisions, evaluating conditions like time of day, location, or resource sensitivity in real-time against defined policies.

Why this answer

Attribute-Based Access Control (ABAC) makes access decisions by evaluating attributes of the user (e.g., job title, clearance), the resource (e.g., classification), and the environment (e.g., time of day). This dynamic, policy-based approach is exactly what the question describes. ABAC is more granular than RBAC and allows for complex, context-aware rules.

Exam trap

CISSP often tests the distinction between ABAC and RBAC; candidates may choose RBAC when the scenario mentions multiple attribute types, but RBAC only uses roles, not environmental or resource attributes.

How to eliminate wrong answers

Option A is wrong because RBAC bases access on roles, not on a combination of user, resource, and environmental attributes. Option C is wrong because MAC uses security labels and clearances assigned by a central authority, but does not typically incorporate environmental factors like time of day. Option D is wrong because DAC allows resource owners to set permissions, which is not attribute-based and lacks centralized policy enforcement.

29
MCQhard

A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?

A.Covert channel
B.Buffer overflow
C.TOCTOU
D.Side-channel attack
AnswerC

TOCTOU, or Time-of-Check to Time-of-Use, is a specific type of race condition vulnerability that occurs when there is a delay between the time a security check is performed on a resource and the time that resource is actually used. An attacker can exploit this window by modifying the resource or its attributes after the check but before the use, thereby bypassing the intended security control. This allows the application to "allow a user" to perform an unauthorized action by manipulating the system state during the vulnerable interval.

Why this answer

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability occurs when a resource's state is verified (check) and then used (use) in separate operations, allowing an attacker to alter the resource between the two steps. The scenario — reading a file before integrity verification completes — is a textbook TOCTOU race condition.

Exam trap

CISSP often tests TOCTOU by describing a race condition in plain language — candidates who don't recognize the check/use timing gap may incorrectly pick side-channel or covert channel based on surface keywords.

How to eliminate wrong answers

Option A is wrong because a covert channel is a communication path that violates a security policy by transferring information illicitly, not a race condition between check and use. Option B is wrong because a buffer overflow involves writing beyond allocated memory bounds, which is unrelated to the timing gap described. Option D is wrong because a side-channel attack extracts information from physical or timing characteristics (e.g., power consumption, cache timing), not from a check/use race window.

30
MCQmedium

An organization implements a security model where users can only read objects at or below their security clearance, and can only write to objects at or above their clearance. This model primarily ensures:

A.Integrity
B.Confidentiality
C.Accountability
D.Availability
AnswerB

The Bell-LaPadula model is specifically designed to enforce confidentiality in multi-level security environments. It achieves this through two primary rules: the simple security property, which prevents subjects from reading objects at a higher classification level ('no read up'), and the *-property (star property), which prevents subjects from writing to objects at a lower classification level ('no write down'). These rules collectively ensure that sensitive information cannot flow downwards to less secure classifications, thereby preserving its secrecy.

Why this answer

The described model is the Bell-LaPadula model: 'no read up' (subjects can only read at or below their clearance) and 'no write down' (subjects can only write at or above their clearance). Both rules exist to prevent sensitive information from leaking to lower classification levels, so the model primarily ensures confidentiality.

Exam trap

The trap is mixing up Bell-LaPadula (confidentiality, no read up/no write down) with Biba (integrity, no read down/no write up) — the direction of the rules is the giveaway.

How to eliminate wrong answers

Option A is wrong because integrity is the focus of the Biba model, which uses 'no read down' and 'no write up' — the inverse of Bell-LaPadula. Option C is wrong because accountability concerns auditing and non-repudiation, not access direction rules. Option D is wrong because availability concerns uptime and access to resources, which is unrelated to the read/write clearance rules described.

31
MCQhard

A security team is investigating a vulnerability where an attacker can intercept and modify data as it moves between processes within a CPU's secure enclave. Which technology is designed to protect against such attacks by creating a trusted execution environment?

A.Trusted Platform Module (TPM)
B.Intel Software Guard Extensions (SGX)
C.Measured Boot
D.Secure Boot
AnswerB

Intel Software Guard Extensions (SGX) is a set of CPU instructions that allows developers to protect specific code and data from disclosure or modification. It achieves this by creating "enclaves," which are isolated, hardware-protected memory regions within an application's address space. Even if the operating system, hypervisor, or other privileged software is compromised, the code and data inside an SGX enclave remain protected, making it suitable for mitigating vulnerabilities that target runtime execution integrity and confidentiality.

Why this answer

Intel SGX creates a trusted execution environment (enclave) inside the CPU that isolates code and data from the rest of the system, including the OS and hypervisor, protecting against interception and modification of data in use. It encrypts enclave memory and enforces access controls at the hardware level, which directly addresses intra-CPU tampering between processes. This is why SGX is the correct answer for protecting data within a secure enclave.

Exam trap

CISSP often tests the distinction between hardware security for data at rest (TPM), boot integrity (Secure Boot/Measured Boot), and runtime isolation (SGX), causing candidates to pick TPM for questions about protecting data in use.

How to eliminate wrong answers

Option A is wrong because a TPM is a separate hardware chip used for cryptographic key storage, platform integrity measurement, and attestation — it does not create an isolated execution environment for running code. Option C is wrong because Measured Boot records hashes of boot components into TPM PCRs to detect tampering during startup; it is a boot-integrity mechanism, not a runtime enclave. Option D is wrong because Secure Boot verifies the signatures of bootloaders and firmware to prevent unauthorized code from loading at boot, but it does not protect data in use inside the CPU after the system is running.

32
Multi-Selecteasy

Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)

Select 2 answers
A.It is only available in cloud environments
B.It runs as a separate virtual machine
C.It requires a TPM chip
D.It provides hardware-enforced isolation from the main OS
E.It protects code and data from unauthorized access even by the OS
AnswersD, E

A fundamental characteristic of a Trusted Execution Environment (TEE) is its ability to provide robust hardware-enforced isolation from the main operating system. This isolation ensures that code and data running within the TEE are protected from unauthorized access or tampering by the rich OS, hypervisor, or any other software running in the less privileged 'normal world.' This hardware-level separation is critical for maintaining the integrity and confidentiality of sensitive computations.

Why this answer

Option D is correct because a TEE, such as Intel SGX enclaves or ARM TrustZone secure world, relies on CPU hardware mechanisms to create an isolated execution context that is separated from the rich operating system, so the main OS cannot access the enclave's memory. Option E is correct because the whole purpose of a TEE is to keep code and data confidential and integrity-protected even against a compromised or malicious host OS, hypervisor, or other privileged software, using hardware-based memory encryption and access control. Option A is incorrect because TEEs are available on client devices, mobile phones, and embedded systems, not only in cloud environments.

Option B is incorrect because a TEE is not a separate virtual machine; it is a hardware-isolated execution environment within a processor, distinct from VM-based isolation. Option C is incorrect because a TEE does not require a discrete TPM chip; it uses CPU-level features, and a TPM is a separate component for key storage and attestation, not a prerequisite for a TEE.

Exam trap

CISSP often tests the misconception that a TEE requires a TPM or is a cloud-only construct, when in fact the defining traits are hardware isolation from the OS and protection even against the OS itself.

33
Multi-Selecthard

A security engineer is hardening a system against buffer overflow attacks. Which of the following are effective mitigations? (Choose THREE)

Select 3 answers
A.Address Space Layout Randomization (ASLR)
B.Data Execution Prevention (DEP/NX)
C.Using unpatched software
D.Stack canaries
E.Disabling ASLR
AnswersA, B, D

Address Space Layout Randomization (ASLR) is an effective defense that randomizes the memory locations of program components, such as the stack, heap, and libraries. By making these addresses unpredictable, ASLR prevents attackers from reliably targeting specific memory addresses with malicious payloads during a buffer overflow attack. This significantly increases the difficulty of executing successful shellcode or return-oriented programming (ROP) exploits.

Why this answer

ASLR (A) is correct because it randomizes the memory locations of key process areas such as the stack, heap, and libraries, making it much harder for an attacker to reliably redirect execution to injected shellcode. DEP/NX (B) is correct because it marks memory pages (e.g., the stack and heap) as non-executable, so injected code cannot run even if a buffer overflow succeeds in writing to those regions. Stack canaries (D) are correct because a canary value placed between local buffers and the saved return address is checked before a function returns, detecting and aborting the overwrite that a classic stack-based buffer overflow would perform.

Option C (using unpatched software) is wrong because unpatched software retains known vulnerabilities, including buffer overflows, increasing rather than mitigating risk. Option E (disabling ASLR) is wrong because removing ASLR eliminates a key randomization defense and makes exploitation of memory-corruption bugs easier.

Exam trap

CISSP often tests whether candidates recognize that disabling ASLR or using unpatched software are vulnerabilities, not mitigations, and may confuse stack canaries with other protections.

34
MCQhard

A cloud service provider uses a Type 1 hypervisor to host multiple virtual machines (VMs) for different customers. Which of the following is a primary security concern specific to this architecture?

A.Virtual machine escape from one guest to the hypervisor or other guests
B.Inability to patch the hypervisor without downtime
C.Performance degradation due to resource sharing
D.Lack of support for legacy operating systems
AnswerA

Virtual machine escape is a critical security vulnerability where an attacker breaks out of the confines of a guest operating system to gain unauthorized access to the hypervisor or other virtual machines. This breach compromises the fundamental isolation provided by the hypervisor, potentially allowing an attacker to control the host system or access sensitive data across multiple tenants. It represents a severe failure of the hypervisor's security mechanisms, making it a top concern for cloud providers.

Why this answer

A Type 1 hypervisor runs directly on the host hardware, and a VM escape vulnerability allows an attacker in a guest VM to break out and access the hypervisor or other guests, compromising the entire host. This is a primary security concern because it breaks the isolation boundary that multi-tenancy relies on.

Exam trap

CISSP often tests the difference between security and operational concerns; candidates may pick performance or patching issues, but the question asks for a primary security concern specific to Type 1 hypervisor architecture.

How to eliminate wrong answers

Option B is wrong because hypervisors can often be patched with minimal downtime using live migration or rolling updates, and this is an operational concern, not a primary security concern specific to Type 1. Option C is wrong because performance degradation is a performance issue, not a security concern. Option D is wrong because lack of support for legacy OS is a compatibility issue, not a security concern.

35
Multi-Selectmedium

A company is implementing a PKI to support secure web browsing. Which of the following are commonly used to enhance the security of certificate validation? (Choose TWO)

Select 2 answers
A.OCSP stapling
B.Certificate revocation lists (CRLs)
C.Certificate pinning
D.Self-signed root certificates
E.Wildcard certificates
AnswersA, C

OCSP stapling significantly improves the efficiency and privacy of certificate revocation checks. Instead of each client directly querying the Certificate Authority's (CA) OCSP responder, the web server periodically fetches a signed OCSP response from the CA and "staples" it to its own certificate during the TLS handshake. This reduces the load on CA infrastructure, minimizes client-side latency, and enhances user privacy by preventing the CA from logging individual client queries.

Why this answer

OCSP stapling (A) is correct because it enhances certificate validation security by having the web server fetch a time-stamped, signed OCSP response from the CA and present it during the TLS handshake, allowing the client to verify revocation status without contacting the CA directly, which improves privacy and reduces latency. Certificate pinning (C) is correct because it associates a host with a specific expected certificate or public key, so the client rejects any certificate that does not match the pinned value, mitigating attacks involving fraudulently issued but otherwise valid certificates. CRLs (B) are a revocation mechanism, but they are a baseline validation input rather than an enhancement, and they can be large and stale.

Self-signed root certificates (D) are not an enhancement to validation; unless explicitly trusted, they fail validation and can weaken trust if improperly installed. Wildcard certificates (E) only cover multiple subdomains under one name and do not improve the security of certificate validation.

Exam trap

CISSP often tests whether candidates confuse revocation mechanisms (CRLs) with validation enhancements (OCSP stapling, pinning), or assume wildcard/self-signed certs improve security.

36
MCQmedium

A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?

A.Clark-Wilson
B.Biba
C.Brewer-Nash
D.Bell-LaPadula
AnswerC

The Brewer-Nash model, also known as the Chinese Wall policy, is specifically designed to prevent conflicts of interest within organizations. It dynamically restricts a subject's access to information based on their past access history, ensuring that once a subject accesses data related to one company within a conflict-of-interest class, they cannot access data related to any competing company in that same class. This model is crucial in environments like financial services to maintain ethical conduct and prevent insider trading.

Why this answer

Brewer-Nash, also known as the Chinese Wall model, is specifically designed to prevent conflicts of interest by dynamically restricting access based on a user's previous access history. Once a consultant accesses data from one client, the model blocks access to any data belonging to a competing client. This is implemented through dynamically changing access control lists that track what each user has already accessed, ensuring that no user can simultaneously hold data from two competing companies.

Exam trap

CISSP often tests the confusion between Brewer-Nash and Bell-LaPadula, as both are confidentiality models, but candidates must remember that Brewer-Nash is uniquely defined by its conflict-of-interest prevention through dynamic access restrictions based on prior access.

How to eliminate wrong answers

Option A is wrong because Clark-Wilson focuses on data integrity through well-formed transactions and separation of duties, not on preventing conflicts of interest based on access history. Option B is wrong because Biba is an integrity model that prevents unauthorized modification of data by enforcing no read-down and no write-up rules, which does not address conflict-of-interest scenarios. Option D is wrong because Bell-LaPadula is a confidentiality model that enforces no read-up and no write-down based on security labels, but it does not dynamically restrict access based on prior access to competing entities.

37
MCQmedium

A security architect is designing a system that must enforce the principle of least privilege for a set of applications. The applications need to access a shared database, but each application should only have the minimum permissions necessary to perform its function. The architect decides to implement a mechanism where each application runs with its own set of credentials and permissions, and these permissions are checked at every access attempt. Which security principle is best demonstrated by this design?

A.Least privilege
B.Separation of duties
C.Defense in depth
D.Implicit deny
AnswerA

Least privilege requires that each subject (in this case, each application) be granted only the minimum permissions necessary to perform its function. By giving each application its own credentials and permissions and checking them at every access, the architect ensures that no application has more access than it needs. This directly implements the principle of least privilege, reducing the risk of unauthorized access or damage if an application is compromised.

Why this answer

The design gives each application its own credentials and permissions and checks them at every access, ensuring that each application has only the minimum access required. This is the definition of least privilege. Separation of duties, defense in depth, and implicit deny are related security principles but do not capture the specific requirement of minimizing permissions for each application to only what is necessary for its function.

Exam trap

The trap here is confusing least privilege with implicit deny, because both involve restricting access, but least privilege is about granting minimal necessary permissions, while implicit deny is about denying by default unless explicitly allowed.

38
MCQeasy

Which cryptographic algorithm is a symmetric block cipher widely used for encrypting sensitive data, with key sizes of 128, 192, or 256 bits?

A.RSA
B.RC4
C.AES
D.ECC
AnswerC

The Advanced Encryption Standard (AES) is a widely adopted symmetric block cipher, encrypting data in fixed-size blocks of 128 bits using the same secret key for both encryption and decryption. It supports key lengths of 128, 192, or 256 bits, offering robust security against brute-force attacks. As a highly efficient and secure algorithm, AES is the standard for protecting sensitive government and commercial data, making it the correct answer for a symmetric block cipher.

Why this answer

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) that operates on 128-bit blocks and supports key sizes of 128, 192, and 256 bits. It replaced DES/3DES for most data-at-rest and data-in-transit encryption. The question's key-size list (128/192/256) is the defining signature of AES.

Exam trap

CISSP often tests the symmetric-vs-asymmetric distinction, so the trap is picking RSA or ECC because they are famous encryption algorithms, ignoring that the question specifies a symmetric block cipher with 128/192/256-bit keys.

How to eliminate wrong answers

Option A is wrong because RSA is an asymmetric algorithm based on integer factorization, using public/private key pairs (commonly 2048/3072/4096 bits), not a symmetric block cipher with 128/192/256-bit keys. Option B is wrong because RC4 is a symmetric stream cipher with variable key sizes (often 40–2048 bits), not a block cipher, and it is deprecated due to biases. Option D is wrong because ECC (Elliptic Curve Cryptography) is asymmetric, using curve-based key pairs (e.g., P-256), not a symmetric block cipher.

39
MCQhard

An organization deploys a hypervisor to host multiple virtual machines. To mitigate the risk of VM escape attacks, which of the following is the most effective security measure?

A.Disabling all unnecessary hypervisor services and applying security patches
B.Using Type 2 hypervisor only
C.Using VLANs to isolate VM traffic
D.Enabling VM snapshots for quick recovery
AnswerA

Disabling unnecessary hypervisor services significantly reduces the attack surface by removing potential entry points and unneeded code that could harbor vulnerabilities. Concurrently, applying security patches promptly addresses known flaws and exploits, preventing attackers from leveraging publicly disclosed weaknesses in the hypervisor software. This proactive combination of hardening and continuous vulnerability management is critical for maintaining the integrity and security of the virtualization layer, directly mitigating risks like VM escape.

Why this answer

Disabling unnecessary hypervisor services reduces the attack surface available to a guest attempting VM escape, and applying hypervisor security patches closes known vulnerabilities (e.g., VENOM, CVE-2015-3456) that allow guest-to-host breakout. Since the hypervisor is the isolation boundary between VMs and the host, hardening and patching it directly addresses the escape vector. This is the most effective preventive control because it targets the root cause rather than the symptoms.

Exam trap

CISSP often tests the distinction between preventive controls that address the root cause (hypervisor hardening/patching) and compensating or detective controls (VLANs, snapshots) that candidates mistakenly select as 'most effective' for VM escape.

How to eliminate wrong answers

Option B is wrong because Type 2 hypervisors (hosted, e.g., VirtualBox, VMware Workstation) run atop a general-purpose OS and typically have a larger attack surface than Type 1 bare-metal hypervisors, so mandating Type 2 does not mitigate escape risk. Option C is wrong because VLANs only segment Layer 2 network traffic between VMs; they do nothing to prevent a guest from exploiting the hypervisor to break isolation and reach the host. Option D is wrong because snapshots are a recovery/rollback mechanism, not a preventive control — they help after a compromise but do not stop a VM escape from occurring.

40
Multi-Selectmedium

A security analyst is evaluating access control models for a healthcare organization that needs to enforce both confidentiality and integrity. Which TWO models should be considered? Select two.

Select 2 answers
A.Take-Grant
B.Bell-LaPadula
C.Biba
D.Clark-Wilson
E.Brewer-Nash
AnswersB, C

The Bell-LaPadula model is a state-machine model primarily designed to enforce confidentiality, particularly in military and government systems. It operates on the principles of 'no read up' (Simple Security Property) and 'no write down' (*-property), ensuring that subjects can only access information at or below their security clearance level and cannot write information to a lower security level. This prevents unauthorized disclosure of classified information by strictly controlling information flow.

Why this answer

Bell-LaPadula (B) is correct because it is the classic mandatory access control model designed to enforce confidentiality through the no-read-up and no-write-down rules, which fits the healthcare requirement to protect sensitive patient data from unauthorized disclosure. Biba (C) is correct because it is the complementary integrity model that enforces no-read-down and no-write-up, preventing untrusted or lower-integrity data from corrupting higher-integrity records, which addresses the stated need to enforce integrity. Together these two models directly map to the scenario's dual requirement for confidentiality and integrity.

Take-Grant (A) is not the best fit because it focuses on modeling how rights can be transferred or granted in a graph-based access control system rather than enforcing confidentiality or integrity policies. Clark-Wilson (D) is an integrity model based on well-formed transactions and separation of duties, but it does not enforce confidentiality, so it does not satisfy both requirements. Brewer-Nash (E) is the Chinese Wall model, which addresses conflict-of-interest access control rather than the general confidentiality and integrity enforcement described here.

Exam trap

CISSP often tests the pairing of confidentiality and integrity models, tricking candidates into selecting Clark-Wilson (integrity only) or Brewer-Nash (conflict of interest) when the question explicitly requires both confidentiality and integrity.

41
MCQhard

A software vulnerability allows an attacker to overwrite a return address on the stack to execute arbitrary code. What mitigation technique randomizes the memory layout to prevent the attacker from predicting target addresses?

A.ASLR (Address Space Layout Randomization)
B.Stack canary
C.Data Execution Prevention (DEP)
D.NX bit (No-Execute)
AnswerA

ASLR (Address Space Layout Randomization) actively randomizes the base memory addresses of key program components like the executable, libraries, stack, and heap each time a program loads. This randomization makes it significantly more challenging for an attacker to reliably predict the exact memory locations of critical data or functions they intend to overwrite or jump to. By introducing unpredictability into the memory layout, ASLR directly hinders exploits that rely on fixed or predictable memory addresses.

Why this answer

ASLR (Address Space Layout Randomization) randomizes the base addresses of the stack, heap, and libraries each time a program runs, making it infeasible for an attacker to predict the exact address to overwrite a return pointer with. This directly defeats the return-to-libc and ROP techniques that depend on knowing target addresses. It is the canonical mitigation for memory-layout predictability.

Exam trap

CISSP often tests the confusion between ASLR (randomizes addresses) and DEP/NX (prevents execution of data), so candidates must map the question's keyword 'randomizes memory layout' specifically to ASLR.

How to eliminate wrong answers

Option B is wrong because a stack canary places a sentinel value before the return address to detect overflow at runtime — it detects corruption but does not randomize memory layout. Option C is wrong because DEP marks memory pages as non-executable to prevent code execution from data regions, which is a different control (execution prevention, not address randomization). Option D is wrong because the NX bit is the hardware implementation of DEP; it prevents execution of data pages but does not randomize addresses.

42
MCQmedium

A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?

A.Bell-LaPadula model
B.Biba model
C.Brewer-Nash model
D.Clark-Wilson model
AnswerA

The Bell-LaPadula model is a state machine model primarily designed to enforce strict confidentiality in multi-level security environments, making it ideal for military systems handling classified information. It operates on two core rules: the "simple security property" (no read up), preventing subjects from reading data at a higher classification level, and the "*-property" (no write down), preventing subjects from writing data to a lower classification level. These rules ensure that information flows only upwards, effectively protecting classified data from unauthorized disclosure.

Why this answer

The Bell-LaPadula model is a mandatory access control (MAC) model built around data confidentiality, using security labels and clearances so that subjects cannot read data above their clearance (no read up) and cannot write data below their level (no write down). This exactly matches the military classification scenario where Top Secret, Secret, Confidential, and Unclassified labels are mandatory and users are cleared to a specific level.

Exam trap

CISSP often tests the classic confidentiality-versus-integrity confusion, so the trap is choosing Biba when the scenario describes classification labels and clearance-based reading restrictions.

How to eliminate wrong answers

Option B is wrong because the Biba model enforces integrity, not confidentiality, using no read down and no write up rules. Option C is wrong because Brewer-Nash (the Chinese Wall model) prevents conflicts of interest in commercial environments, not military classification enforcement. Option D is wrong because Clark-Wilson focuses on integrity through well-formed transactions and separation of duties, not on clearance-based confidentiality labels.

43
MCQmedium

An organization wants to implement a security mechanism that ensures all accesses are mediated and cannot be bypassed, is tamperproof, and is small enough to be verified. This describes which concept?

A.Trusted Computing Base (TCB)
B.Reference Monitor
C.Trusted Platform Module (TPM)
D.Security Kernel
AnswerB

The reference monitor is an abstract, conceptual security mechanism that mediates all access attempts by subjects to objects, ensuring strict compliance with the system's defined security policy. For it to be truly effective and secure, it must possess three fundamental properties: it must be tamperproof, always invoked for every access request, and verifiable, allowing its correctness to be mathematically proven. This abstract model serves as the foundational principle for designing secure access control enforcement.

Why this answer

A reference monitor is the abstract security concept that enforces access control by mediating every access request between subjects and objects, is tamperproof, and is small enough to be verified. These three properties — complete mediation, tamperproofness, and verifiability — are the defining characteristics of a reference monitor as described in the Orange Book (TCSEC). It is the conceptual model that a security kernel implements in hardware and software.

Exam trap

CISSP often tests the confusion between the reference monitor (abstract concept), security kernel (implementation), and TCB (the entire trusted base), so candidates pick the broader or narrower term instead of the one matching the three defining properties.

How to eliminate wrong answers

Option A is wrong because the Trusted Computing Base (TCB) is the totality of protection mechanisms within a system (hardware, firmware, software) that enforce the security policy — it is broader than the reference monitor and includes the reference monitor as a component. Option C is wrong because a Trusted Platform Module (TPM) is a hardware chip that stores cryptographic keys and supports secure boot and attestation; it is a specific implementation technology, not the abstract mediation concept. Option D is wrong because a security kernel is the actual hardware/software implementation of the reference monitor concept — the reference monitor is the abstract model, while the security kernel is its concrete realization.

44
MCQhard

During a security audit, a vulnerability scanner reports a buffer overflow vulnerability in a legacy application. The application runs on a system with Data Execution Prevention (DEP/NX) enabled and Address Space Layout Randomization (ASLR) active. Which of the following is the most likely impact of these mitigations on a typical stack-based buffer overflow exploit?

A.They only protect heap-based overflows, not stack-based
B.They completely prevent any exploitation of buffer overflows
C.They make it harder to execute arbitrary code via injected shellcode
D.They have no effect on buffer overflow exploits
AnswerC

This statement is correct because Data Execution Prevention (DEP) directly prevents the execution of code from non-executable memory regions, such as the stack and heap, where injected shellcode typically resides. Concurrently, Address Space Layout Randomization (ASLR) randomizes the memory addresses of key program components, making it extremely challenging for an attacker to reliably predict the exact location of their injected shellcode or necessary return addresses. Together, these mechanisms significantly increase the difficulty and complexity of exploiting buffer overflows with injected shellcode.

Why this answer

DEP/NX marks memory pages as non-executable, so injected shellcode on the stack cannot be executed directly. ASLR randomizes the memory layout, making it difficult for an attacker to reliably jump to existing code (like a ROP gadget or system function). Together they significantly raise the bar for a typical stack-based buffer overflow exploit, though they do not make exploitation impossible.

Exam trap

CISSP often tests whether candidates understand that mitigations like DEP and ASLR raise the difficulty but do not eliminate exploitation — the trap is selecting 'completely prevent.'

How to eliminate wrong answers

Option A is wrong because DEP and ASLR apply to both stack and heap memory — they are not limited to heap-based overflows. Option B is wrong because these mitigations can be bypassed (e.g., return-oriented programming to defeat DEP, memory leaks or brute force to defeat ASLR), so they do not completely prevent exploitation. Option D is wrong because DEP and ASLR demonstrably affect exploitability — they force attackers to use more sophisticated techniques, so they are not without effect.

45
MCQhard

A security engineer is evaluating a system that uses a Trusted Platform Module (TPM) for secure boot. The TPM measures the boot components and stores the measurements in Platform Configuration Registers (PCRs). Which of the following is a primary security goal achieved by this process?

A.Ensures the boot process has not been tampered with
B.Provides full disk encryption
C.Prevents all malware from executing
D.Authenticates the user during boot
AnswerA

A Trusted Platform Module (TPM) actively measures critical boot components, including firmware, bootloaders, and operating system kernels, before they execute. These measurements are stored in Platform Configuration Registers (PCRs) and compared against known good values. If any component's measurement deviates, it indicates unauthorized modification or tampering, preventing the system from booting or alerting the user to a compromised state.

Why this answer

Measured boot ensures that each boot component's hash is extended into PCRs. The TPM can attest these measurements to a remote verifier, proving the boot integrity.

46
MCQhard

A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?

A.The module uses a software-based cryptographic algorithm implementation that runs in the host OS's user space.
B.The module's cryptographic boundary includes a hardware security module (HSM) that performs key storage and cryptographic operations internally.
C.The module performs key generation using a random number generator that is seeded from the host OS's entropy pool.
D.The module uses a FIPS-approved algorithm such as AES-256 for encryption.
AnswerB

An HSM within the cryptographic boundary stores and processes keys internally, isolating them from the host OS. Even if the host OS is compromised, the attacker cannot directly access the keys because they never leave the HSM's protected environment. Cryptographic operations are performed inside the HSM, and only results are returned. This hardware isolation is critical to protecting keys against unauthorized disclosure when the host OS is compromised.

Why this answer

The most critical aspect is the hardware security module (HSM) within the cryptographic boundary, which stores and processes keys internally. This ensures that keys are never exposed to the host OS, so even if the OS is compromised, the keys remain protected. A software implementation, strong algorithms, or entropy seeding do not provide the same level of isolation and are insufficient when the host OS is untrusted.

Exam trap

The trap here is focusing on the strength of the cryptographic algorithm or the randomness of key generation, when the real issue is where the keys are stored and processed relative to the compromised host OS.

47
MCQhard

A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?

A.ASLR
B.SafeSEH
C.Stack canaries
D.DEP/NX bit
AnswerA

ASLR (Address Space Layout Randomization) is a memory protection technique that randomly arranges the positions of key data areas, such as the base of the executable, the stack, heap, and libraries, within a process's virtual address space. This randomization makes it significantly more difficult for an attacker to predict target addresses for return-oriented programming (ROP) attacks or to reliably locate malicious code or useful gadgets. By introducing unpredictability, ASLR effectively mitigates the success rate of many memory corruption exploits that rely on known memory layouts.

Why this answer

ASLR (Address Space Layout Randomization) randomizes the memory locations of key areas such as the stack, heap, and libraries on each execution, making it difficult for an attacker to predict where shellcode or a return address resides. This directly counters buffer overflow exploitation that relies on fixed addresses. It is the mitigation specifically described as randomizing memory addresses.

Exam trap

CISSP often tests confusion among memory-corruption mitigations — ASLR randomizes addresses, DEP/NX blocks execution, canaries detect overwrites, and SafeSEH protects exception handlers.

How to eliminate wrong answers

Option B is wrong because SafeSEH is a Windows compiler/linker mitigation that validates exception handler pointers on the stack to prevent SEH overwrite attacks — it does not randomize memory addresses. Option C is wrong because stack canaries place a known guard value before the return address and detect corruption on function return; they detect overflows but do not randomize addresses. Option D is wrong because DEP/NX marks memory pages as non-executable to prevent code execution from data regions like the stack — it blocks execution but does not randomize addresses.

48
MCQhard

A company is deploying a hypervisor to run multiple virtual servers. To minimize the risk of VM escape attacks, which type of hypervisor should they choose and what hardening measure is most effective?

A.Type 1 hypervisor with minimal services and regular patching
B.Type 2 hypervisor with regular patching
C.Type 2 hypervisor with host-based firewall
D.Type 1 hypervisor with no additional hardening
AnswerA

A Type 1 hypervisor, also known as a bare-metal hypervisor, runs directly on the host hardware, significantly reducing the attack surface by eliminating the need for an underlying general-purpose operating system. Implementing minimal services further restricts potential entry points for attackers. Regular patching is critical to address known vulnerabilities, including hypervisor escape flaws, ensuring the integrity and isolation of virtual machines.

Why this answer

A Type 1 (bare-metal) hypervisor runs directly on the hardware with a much smaller attack surface than a Type 2 hypervisor, which sits atop a general-purpose host OS full of exploitable services. Minimizing installed services and applying regular patches further shrinks the attack surface and closes known VM-escape vulnerabilities. Together, these are the most effective mitigations for VM escape risk.

Exam trap

CISSP often tests the assumption that 'patching alone' or 'a firewall' mitigates VM escape — candidates miss that the hypervisor type and attack-surface reduction are the primary controls.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor depends on a full host OS, dramatically expanding the attack surface — patching alone cannot compensate for the extra exploitable layers. Option C is wrong because a host-based firewall controls network traffic but does nothing to prevent a guest-to-host escape via a hypervisor vulnerability; it addresses the wrong threat vector. Option D is wrong because a Type 1 hypervisor with no hardening still exposes unnecessary services and unpatched vulnerabilities — the hypervisor type alone is insufficient without hardening.

49
MCQmedium

A government agency requires a security model that prevents users from reading documents classified above their clearance level and from writing classified information to lower-level systems. Which model enforces these constraints?

A.Bell-LaPadula
B.Biba
C.Brewer-Nash
D.Clark-Wilson
AnswerA

The Bell-LaPadula security model is specifically designed to enforce confidentiality in multi-level security systems, making it ideal for government agencies dealing with classified information. It operates on two core rules: the Simple Security Property (no read up) and the *-Property (no write down). These rules prevent subjects from accessing information at a higher security level than their own and from writing information to a lower security level, thereby ensuring that classified data remains protected from unauthorized disclosure.

Why this answer

Bell-LaPadula is the mandatory access control model focused on confidentiality, enforcing 'no read up' (simple security property) and 'no write down' (star property). These two rules exactly match the requirement: users cannot read above their clearance and cannot write classified data to lower levels. Biba, Brewer-Nash, and Clark-Wilson address integrity or conflict-of-interest, not confidentiality.

Exam trap

CISSP often tests the confusion between Bell-LaPadula (confidentiality: no read up, no write down) and Biba (integrity: no read down, no write up) — candidates who memorize only one direction pick the wrong model.

How to eliminate wrong answers

Option B (Biba) is wrong because Biba enforces integrity with 'no read down' and 'no write up' — the inverse of Bell-LaPadula — protecting data integrity, not confidentiality. Option C (Brewer-Nash) is wrong because it is the Chinese Wall model, which prevents conflicts of interest by dynamically restricting access based on what a subject has already accessed, not by clearance levels. Option D (Clark-Wilson) is wrong because it enforces integrity through well-formed transactions and separation of duties, using access triplets (subject, program, object), and does not address classification-based confidentiality.

50
MCQeasy

Which type of covert channel uses the timing of events or operations to transmit information?

A.Emanations channel
B.Side channel
C.Timing channel
D.Storage channel
AnswerC

A timing channel is a specific type of covert channel that modulates information by altering the temporal characteristics of system events or operations. This involves varying the time taken for a process to complete, the delay between two events, or the order of operations, to encode and transmit data between processes that are not supposed to communicate directly. The receiver deciphers the secret message by observing these temporal variations.

Why this answer

A timing channel is a covert channel that conveys information by modulating the timing of events or operations — for example, varying the delay between packets or CPU bursts so a receiver can decode bits from the timing pattern. It is a type of side channel where the shared resource is time itself.

Exam trap

CISSP often tests the distinction between storage and timing covert channels — candidates pick 'side channel' because it sounds broader, but the question asks for the specific type defined by timing.

How to eliminate wrong answers

Option A is wrong because an emanations channel refers to unintentional electromagnetic or acoustic radiation that leaks information, not deliberate timing modulation. Option B is wrong because 'side channel' is the broader category that includes timing, power, cache, and electromagnetic channels — it is not the specific type defined by timing of events. Option D is wrong because a storage channel uses a shared storage location (e.g., a file, memory location, or disk sector) to pass information, not timing.

51
Multi-Selectmedium

A security engineer is hardening a system against side-channel attacks that exploit variations in execution time or power consumption. Which TWO mitigations are specifically designed to counter such attacks? Select two.

Select 2 answers
A.Data Execution Prevention (DEP)
B.Address Space Layout Randomization (ASLR)
C.Input validation
D.Constant-time algorithms
E.Noise injection in power consumption
AnswersD, E

Constant-time algorithms are specifically designed to execute in a predictable amount of time, regardless of the secret data being processed or the input values. By eliminating data-dependent branches, memory access patterns, or loop iterations, these algorithms prevent timing variations that could otherwise be observed by an attacker to infer sensitive information, such as cryptographic keys. This approach directly counters timing side-channel attacks by removing the observable timing differences.

Why this answer

Constant-time programming ensures operations take the same time regardless of inputs, and noise injection obscures power consumption patterns.

52
MCQhard

In a PKI hierarchy, a relying party needs to verify a certificate's validity. To reduce latency and improve privacy, which mechanism allows the relying party to obtain the revocation status without contacting the CA directly for each verification?

A.Certificate Transparency (CT) logs
B.Certificate pinning
C.Certificate Revocation List (CRL)
D.OCSP stapling
AnswerD

OCSP stapling, formally known as the TLS Certificate Status Request extension, allows the web server itself to query the Certificate Authority's (CA) Online Certificate Status Protocol (OCSP) responder for the revocation status of its own certificate. The server then caches this signed OCSP response and "staples" it to the TLS handshake, sending it directly to the client. This method significantly improves performance by eliminating the need for each client to contact the OCSP responder directly and enhances privacy by preventing the OCSP responder from tracking client requests.

Why this answer

OCSP stapling allows the certificate holder (web server) to periodically query the CA's OCSP responder and cache a signed, time-stamped OCSP response, which it then 'staples' to the TLS handshake. The relying party receives the revocation status directly from the server during the handshake, eliminating a separate round-trip to the CA and hiding the client's browsing activity from the CA. This reduces latency and improves privacy compared to traditional OCSP or CRL retrieval.

Exam trap

CISSP often tests the confusion between OCSP stapling (server-provided, privacy-preserving, low-latency) and traditional OCSP/CRL (client-initiated, privacy-leaking, higher-latency), so candidates who only remember 'OCSP' without the 'stapling' qualifier pick the wrong mechanism.

How to eliminate wrong answers

Option A is wrong because Certificate Transparency logs are append-only public logs of issued certificates used to detect mis-issuance, not a revocation-status mechanism. Option B is wrong because certificate pinning hardcodes a specific certificate or public key to prevent MITM attacks; it does not provide revocation status. Option C is wrong because a CRL is a CA-published list of revoked certificates that the relying party must download and parse, which increases latency and leaks the client's certificate-checking behavior to the CA.

53
MCQeasy

A security architect is designing a physical security system for a data center. Which of the following is an example of a layered physical control at the perimeter?

A.Biometric access to server room
B.Locked server cabinets
C.CCTV in the lobby
D.Fencing around the property
AnswerD

Fencing around the property is a primary perimeter physical security control, establishing the outermost boundary of the secured area. Its purpose is to deter unauthorized entry, define the property line, and delay intruders before they can reach the building itself. This initial barrier provides the first line of defense against external threats, making it a foundational perimeter measure.

Why this answer

Fencing around the property is a perimeter-layer physical control that provides a first line of defense by deterring and delaying intruders before they reach the building. In a layered defense-in-depth model, perimeter controls (fencing, bollards, lighting, gates) sit at the outermost ring, ahead of building entry controls and interior controls. This makes fencing the only option that operates at the perimeter layer.

Exam trap

CISSP often tests whether candidates can distinguish perimeter-layer controls from interior or asset-layer controls, since all four options are legitimate physical controls but only one sits at the outermost boundary.

How to eliminate wrong answers

Option A is wrong because biometric access to a server room is an interior access control at the asset/room layer, not the perimeter. Option B is wrong because locked server cabinets are an innermost asset-level control protecting individual hardware, not the perimeter. Option C is wrong because CCTV in the lobby is a detective control inside the building envelope, not a perimeter barrier.

54
Multi-Selectmedium

A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)

Select 3 answers
A.Perimeter fence
B.Server rack locks
C.Mantrap at the entrance to the secure area
D.Single-factor authentication for all doors
E.Unsecured windows on ground floor
AnswersA, B, C

A perimeter fence serves as a foundational deterrent and delay mechanism, establishing the outermost boundary of a secured area. It acts as a primary physical control, designed to discourage unauthorized entry and provide early detection of intrusion attempts by forcing an attacker to spend time breaching it. This initial barrier is crucial for defining the property line and channeling legitimate access through controlled entry points.

Why this answer

The question asks for layered physical security controls, meaning multiple defensive measures at different depths. Option A, a perimeter fence, is correct because it establishes the outermost physical boundary and deters or delays unauthorized access before an intruder reaches the building. Option B, server rack locks, is correct because it provides an inner layer of protection directly at the asset, restricting access to the servers even after someone has entered the facility.

Option C, a mantrap at the entrance to the secure area, is correct because it is a physical access control vestibule that allows only one person through at a time and prevents tailgating, adding a controlled transition layer between zones. Option D, single-factor authentication for all doors, is not a layered physical control; single-factor authentication is weak and does not add defense in depth, and authentication is more of an access control mechanism than a physical barrier. Option E, unsecured windows on the ground floor, is not a control at all but a vulnerability, since unlocked or unprotected windows provide an easy bypass of other physical defenses.

Exam trap

CISSP often tests the distinction between actual layered controls and single points of failure or vulnerabilities, so candidates must recognize that unsecured windows and single-factor auth are weaknesses, not layers.

55
MCQeasy

Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?

A.MAC
B.RBAC
C.ABAC
D.DAC
AnswerD

Discretionary Access Control (DAC) is an access control model where the owner of a resource (or an authorized administrator) has the discretion to grant or revoke access permissions to other users. This is typically implemented using Access Control Lists (ACLs) or capabilities, allowing owners to specify who can perform specific actions (read, write, execute) on their owned objects. DAC is highly flexible and widely used in commercial operating systems because it empowers data owners to manage access to their own data.

Why this answer

Discretionary Access Control (DAC) lets the owner of a resource decide who can access it and with what permissions, typically implemented through Access Control Lists (ACLs) on files and objects. Because the data owner grants or revokes access at their discretion, DAC matches the scenario exactly.

Exam trap

CISSP often tests whether candidates can distinguish DAC (owner-controlled, ACL-based) from MAC (system-enforced labels) and RBAC (role-based), since all three are access control models but only DAC centers on owner discretion.

How to eliminate wrong answers

Option A is wrong because Mandatory Access Control (MAC) uses system-enforced labels and clearances (e.g., SELinux, Trusted Solaris) where owners cannot override policy — access is determined by the system, not the data owner. Option B is wrong because Role-Based Access Control (RBAC) grants permissions based on organizational roles rather than per-object owner discretion, and it does not rely on ACLs as its defining mechanism. Option C is wrong because Attribute-Based Access Control (ABAC) evaluates policies combining user, resource, action, and environment attributes — it is more dynamic and policy-driven than owner-controlled ACLs.

56
MCQmedium

A software developer is concerned about buffer overflow vulnerabilities. Which combination of mitigations makes it most difficult for an attacker to exploit a stack-based buffer overflow?

A.Using a privileged account to run the application
B.Disabling stack protection
C.Stack canaries and NOP sleds
D.Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR)
AnswerD

Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are fundamental and effective mitigations against buffer overflow vulnerabilities. DEP marks memory regions, such as the stack and heap, as non-executable, preventing an attacker from executing injected shellcode directly from these areas. ASLR randomizes the memory locations of key program components, making it significantly more difficult for an attacker to predict the exact addresses needed to launch successful return-oriented programming (ROP) attacks or jump to injected code.

Why this answer

DEP marks memory pages as non-executable, so even if an attacker successfully overwrites the return address and injects shellcode onto the stack, the CPU will refuse to execute it. ASLR randomizes the base addresses of the stack, heap, and libraries, forcing the attacker to guess memory locations, which dramatically reduces the reliability of return-to-libc or ROP-style exploits. Together they block both code injection and reliable redirection, making exploitation far harder than either mitigation alone.

Exam trap

CISSP often tests the misconception that any single mitigation (like stack canaries) fully prevents buffer overflow exploitation, when in reality layered defenses such as DEP plus ASLR are needed to defeat both code injection and address guessing.

How to eliminate wrong answers

Option A is wrong because running the application with a privileged account actually amplifies the impact of a successful buffer overflow, granting the attacker elevated rights rather than mitigating the vulnerability. Option B is wrong because disabling stack protection removes compiler-level defenses such as stack canaries and safe exception handlers, directly increasing exploitability. Option C is wrong because while stack canaries detect return-address overwrites, NOP sleds are an attacker technique used to increase exploit reliability, not a defensive mitigation.

57
MCQmedium

A security architect is evaluating hypervisor security for a multi-tenant cloud environment. Which type of hypervisor is considered more secure because it runs directly on the hardware without a host operating system, reducing the attack surface?

A.Virtual machine monitor
B.Containers
C.Type 1 hypervisor
D.Type 2 hypervisor
AnswerC

A Type 1 hypervisor, also known as a bare-metal hypervisor, runs directly on the host hardware without an intervening operating system. This architecture provides a significantly reduced attack surface because it has a minimal codebase and fewer dependencies than a hypervisor running on a host OS. Its direct control over hardware resources and strong isolation capabilities make it the most secure choice for critical infrastructure and sensitive workloads.

Why this answer

A Type 1 hypervisor (also called a bare-metal hypervisor) runs directly on the host's physical hardware, with no intervening host operating system. Because there is no general-purpose OS layer to exploit, the attack surface is significantly smaller than a Type 2 hypervisor, which depends on a full host OS. This architectural reduction in exploitable code is why Type 1 hypervisors are preferred in multi-tenant cloud environments.

Exam trap

CISSP often tests the distinction between Type 1 and Type 2 hypervisors by rewarding the 'bare-metal equals more secure' heuristic, while distractors like 'virtual machine monitor' tempt candidates who confuse the generic term with a specific architecture.

How to eliminate wrong answers

Option A is wrong because 'virtual machine monitor' is simply the generic technical term for a hypervisor, not a specific type that distinguishes security posture. Option B is wrong because containers share the host kernel and are an OS-level virtualization technology, not a hypervisor type, so they do not match the question's framing. Option D is wrong because a Type 2 hypervisor runs on top of a host operating system, which adds an entire OS layer to the attack surface and makes it less secure for multi-tenant use.

58
Multi-Selectmedium

A security architect is designing a system to protect against side-channel attacks that exploit electromagnetic emanations. Which TWO controls are most effective?

Select 2 answers
A.Data encryption at rest
B.TEMPEST shielding
C.Intrusion detection system
D.Time-based access controls
E.Faraday cage
AnswersB, E

TEMPEST shielding involves applying specialized materials, filters, and design principles directly to electronic equipment to suppress compromising electromagnetic emanations. This standard prevents adversaries from intercepting and reconstructing sensitive data processed by the system through transient electromagnetic pulse emanations.

Why this answer

TEMPEST shielding (B) is correct because TEMPEST is the standard for reducing compromising emanations, including electromagnetic radiation from monitors, cables, and processors, that can leak data to nearby receivers; shielding enclosures and filtered power/communications lines directly mitigate this side-channel. A Faraday cage (E) is also correct because it blocks external electromagnetic fields and contains internal emissions, preventing EM leakage from being intercepted, which is the core defense against emanation-based side-channel attacks. Data encryption at rest (A) protects stored data but does not stop electromagnetic emissions from a running system.

An intrusion detection system (C) monitors network or host activity for malicious behavior and does not address physical EM leakage. Time-based access controls (D) restrict when users may access resources and are irrelevant to electromagnetic side-channel exploitation.

Exam trap

CISSP often tests the confusion between logical and physical controls for side-channel attacks, leading candidates to choose encryption or IDS instead of recognizing that electromagnetic emanation protection requires physical shielding like TEMPEST or Faraday cages.

59
Multi-Selectmedium

An organization is implementing a defense-in-depth strategy for a data center. Which THREE of the following are examples of physical security controls that align with layered defense?

Select 3 answers
A.Antivirus software
B.Intrusion detection system on the network
C.Card reader at building entrance
D.Server cage locks
E.Perimeter fencing
AnswersC, D, E

A card reader at a building entrance is a definitive physical access control mechanism, serving as a critical layer in a defense-in-depth strategy. It enforces authentication and authorization requirements before granting physical entry to a facility, directly restricting human movement and protecting all assets within from unauthorized personnel.

Why this answer

Option C (card reader at building entrance) is correct because it is a physical access control that authenticates individuals before they can enter the facility, forming an outer layer of defense. Option D (server cage locks) is correct because locking cages around server racks physically restrict access to the most sensitive hardware, adding an inner layer of protection even after someone has entered the building. Option E (perimeter fencing) is correct because fencing establishes the outermost physical boundary of the data center, deterring and delaying unauthorized entry.

Options A (antivirus software) and B (network intrusion detection system) are logical/technical controls, not physical security controls, so they do not belong in this layered physical defense scenario.

Exam trap

CISSP often tests control classification — candidates see 'intrusion detection' and 'antivirus' as security controls and incorrectly include them as physical controls, forgetting that physical controls must restrict or monitor physical access to facilities and assets.

Ready to test yourself?

Try a timed practice session using only Security Architecture and Engineering questions.