Courseiva

CCNA Security Operations Questions

54 questions · Security Operations · All types, answers revealed

1
MCQmedium

A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:

A.Securing physical facilities
B.Restoring IT systems and infrastructure
C.Maintaining critical business processes during a disruption
D.Replacing hardware and software
AnswerC

Maintaining critical business processes during a disruption is the defining characteristic and primary objective of a Business Continuity Plan (BCP). A BCP outlines the strategies, procedures, and resources necessary to ensure that an organization's essential functions continue to operate, even when faced with significant outages or disasters. This involves identifying critical processes, determining acceptable downtime, and establishing alternative methods to sustain operations until full recovery is achieved.

Why this answer

A Business Continuity Plan (BCP) is broader in scope and focuses on maintaining critical business processes — people, facilities, suppliers, and operations — during and after a disruption. The Disaster Recovery Plan (DRP) is a subset focused specifically on restoring IT systems and infrastructure. Thus, maintaining critical business processes is the BCP's primary focus.

Exam trap

CISSP often tests the BCP vs. DRP distinction; candidates incorrectly select 'restoring IT systems' as the BCP focus when that is the DRP's defining scope.

How to eliminate wrong answers

Option A is wrong because securing physical facilities is a component of physical security and part of continuity planning, but not the defining focus that distinguishes BCP from DRP. Option B is wrong because restoring IT systems and infrastructure is precisely the DRP's focus, not the BCP's primary scope. Option D is wrong because replacing hardware and software is a tactical DRP recovery activity, not the strategic business-process focus of the BCP.

2
Multi-Selecthard

A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?

Select 3 answers
A.Vulnerability scanning
B.Automated patch deployment
C.Reporting and dashboarding
D.Real-time correlation and alerting
E.Log aggregation and normalization
AnswersC, D, E

SIEM systems are fundamentally designed to provide comprehensive reporting and intuitive dashboarding capabilities, which are critical for security analysts to visualize aggregated security data. These features allow for the creation of custom reports on compliance, incident trends, and threat landscapes, alongside real-time dashboards that display key performance indicators and security posture at a glance. This facilitates proactive monitoring, historical analysis, and effective communication of security status to stakeholders.

Why this answer

Option C (Reporting and dashboarding) is correct because a SIEM must present security data through dashboards and scheduled or ad hoc reports, giving analysts and compliance teams visibility into trends, incidents, and KPIs derived from correlated events. Option D (Real-time correlation and alerting) is correct because the core value of a SIEM is correlating events from multiple sources against rules, signatures, or behavioral logic and generating timely alerts when suspicious patterns match. Option E (Log aggregation and normalization) is correct because a SIEM must collect logs from disparate devices and applications and normalize them into a common schema (for example, parsing syslog, Windows Event Log, and CEF into consistent fields) so correlation and search can work across sources.

Option A (Vulnerability scanning) is not correct because vulnerability assessment is typically performed by dedicated scanners such as Nessus or Qualys, even though their findings may be forwarded to a SIEM. Option B (Automated patch deployment) is not correct because patch management is handled by configuration management or endpoint management tools like WSUS, SCCM, or Intune, not by the SIEM itself.

Exam trap

The trap here is confusing SIEM's passive analysis and reporting role with active remediation tools (vulnerability scanners and patch managers), leading candidates to select options that describe functions SIEMs do not perform themselves.

3
MCQmedium

An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?

A.MTD
B.MTTR
C.RPO
D.RTO
AnswerC

Recovery Point Objective (RPO) precisely defines the maximum acceptable amount of data loss, measured as a period of time. It specifies the point in time to which data must be recovered, meaning any data created or modified after that point will be lost. For instance, an RPO of 15 minutes indicates that the organization can tolerate losing up to 15 minutes of data. This metric directly addresses the question's concern about ensuring an acceptable level of data loss for critical databases.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — i.e., how far back a restore point can be. A requirement to restore to a point within the last 15 minutes is precisely an RPO of 15 minutes, dictating backup/replication frequency. RTO, by contrast, defines how quickly service must be restored, not how much data can be lost.

Exam trap

CISSP often tests the RPO vs. RTO distinction by phrasing the question around 'point in time' or 'data loss' — candidates who read 'restore within 15 minutes' as a speed requirement pick RTO instead of RPO.

How to eliminate wrong answers

Option A is wrong because MTD (Maximum Tolerable Downtime) is the total time a business process can be unavailable before unacceptable impact — it encompasses both RTO and other recovery activities, not the data-loss window. Option B is wrong because MTTR (Mean Time To Repair) is the average time to repair a failed component, an operational metric, not a data-loss tolerance. Option D is wrong because RTO (Recovery Time Objective) is the target duration to restore service after disruption, not the acceptable data loss measured in time.

4
MCQmedium

A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?

A.Network DLP
B.Cloud DLP
C.Endpoint DLP
D.Classification-based controls
AnswerA

Network DLP solutions are strategically deployed at network egress points, such as internet gateways or email servers, to inspect all outbound network traffic in real-time. This technology analyzes data streams for sensitive information based on predefined policies, identifying and preventing unauthorized transmission of confidential data via protocols like HTTP, HTTPS, FTP, and SMTP. Its primary function is to stop data leakage as it attempts to leave the organizational boundary.

Why this answer

Network DLP is designed to monitor and control data in transit across network boundaries, including email and web traffic. It inspects packets leaving the corporate network to detect and block sensitive data exfiltration. Therefore, it is best suited for monitoring and blocking sensitive data leaving via email or web traffic.

Exam trap

Candidates often confuse network DLP with endpoint DLP; the key is that network DLP focuses on data in motion across the network perimeter, while endpoint DLP focuses on data at rest or in use on devices.

How to eliminate wrong answers

Option B is wrong because Cloud DLP focuses on data stored in or moving to cloud services (e.g., SaaS, IaaS), not on general network egress. Option C is wrong because Endpoint DLP monitors data at rest and in use on endpoints (e.g., USB, local email clients), but it does not comprehensively cover network egress channels like web traffic. Option D is wrong because classification-based controls are a method of labeling data, not a DLP deployment type; they can complement DLP but do not themselves monitor network traffic.

5
MCQhard

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

A.Unauthorized access
B.Denial of Service (DoS)
C.Malware infection
D.Data breach
AnswerD

A data breach is precisely defined as the unauthorized access, disclosure, or exfiltration of sensitive, protected, or confidential information. The SIEM alert indicating unauthorized data transfer out of the network directly describes the core characteristic of a data breach, where data has left the secure perimeter without proper authorization. This makes it the most accurate classification for an incident involving data exfiltration.

Why this answer

Large outbound data transfers from a sensitive database server to an external IP during non-business hours strongly indicate exfiltration, which is the hallmark of a data breach. The volume, sensitivity of the source, and off-hours timing all point to unauthorized data movement rather than other incident types.

Exam trap

CISSP often tests whether candidates can distinguish the underlying cause (malware, unauthorized access) from the resulting incident classification (data breach) based on the evidence presented.

How to eliminate wrong answers

Option A is wrong because unauthorized access alone doesn't explain the large outbound data volume; access may have occurred, but the defining symptom here is exfiltration. Option B is wrong because a DoS would manifest as service unavailability or traffic flooding inbound, not outbound data from a database. Option C is wrong because while malware could cause exfiltration, the question asks for the most likely incident type given the evidence, which is a data breach.

6
Multi-Selectmedium

A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)

Select 2 answers
A.Wireshark
B.Volatility
C.Autopsy
D.EnCase
E.FTK
AnswersB, E

Volatility is an advanced, open-source framework specifically engineered for volatile memory (RAM) extraction and analysis. It allows forensic analysts to reconstruct active network connections, extract running processes, inspect loaded DLLs, and recover cached credentials directly from a memory dump, making it the premier choice for memory forensics.

Why this answer

Volatility is a dedicated memory forensics framework; FTK can also capture and analyze memory, though it's more general. EnCase is disk forensics, Wireshark network, Autopsy disk.

7
MCQmedium

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

A.Verification
B.Reporting
C.Remediation
D.Risk acceptance
AnswerC

Following the identification and prioritization of vulnerabilities based on their potential impact and likelihood, the immediate and most critical next phase in the vulnerability management lifecycle is remediation. This involves applying patches, reconfiguring systems, implementing compensating controls, or otherwise eliminating or reducing the risk posed by the identified weaknesses. Prioritization dictates what to fix first, and remediation is how those fixes are applied.

Why this answer

The vulnerability management lifecycle is typically: identify → prioritize (assess/rank) → remediate → verify → report, with risk acceptance as an alternative outcome to remediation. After vulnerabilities are identified and prioritized, the next action is to remediate (patch, mitigate, or compensate), because prioritization exists to drive remediation decisions. Verification and reporting come after remediation to confirm the fix and communicate status.

Exam trap

CISSP often tests the ordering of the vulnerability management lifecycle, tempting candidates to pick 'verification' or 'reporting' because those feel like quality steps, when the lifecycle's next action after prioritization is remediation.

How to eliminate wrong answers

Option A is wrong because verification happens after remediation to confirm the fix was applied and effective — it is not the step immediately following prioritization. Option B is wrong because reporting is a communication activity that occurs throughout and especially after remediation, not the direct next step. Option D is wrong because risk acceptance is an exception path taken when remediation is not feasible or cost-justified; it is a decision made during remediation planning, not the default next step after prioritization.

8
MCQhard

An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?

A.Cloud DR with continuous replication
B.Hot site with real-time replication
C.Cold site with daily backups
D.Warm site with hourly backups
AnswerA

This option is correct because continuous replication ensures near-zero data loss, effectively meeting the stringent 30-minute Recovery Point Objective (RPO). Leveraging cloud-based Disaster Recovery (DR) allows for rapid provisioning of resources and pre-configured environments, which can be activated to meet the 4-hour Recovery Time Objective (RTO). Furthermore, cloud DR typically offers a more cost-effective solution compared to maintaining a dedicated physical hot site, making it an optimal choice that satisfies all technical and financial requirements.

Why this answer

Cloud DR with continuous replication meets the RPO of 30 minutes because data is replicated in near real-time, resulting in minimal data loss. It can also meet the RTO of 4 hours if automated failover and resource provisioning are configured. This approach is more cost-effective than a hot site because it avoids maintaining idle infrastructure and only incurs costs during actual disaster recovery operations.

Hot site with real-time replication (option B) also meets the requirements but is more expensive. Cold site with daily backups (option C) fails both RTO and RPO. Warm site with hourly backups (option D) fails RPO because it can result in up to 1 hour of data loss, exceeding the 30-minute limit.

9
MCQmedium

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

A.Classification-based controls
B.Cloud DLP
C.Network DLP
D.Endpoint DLP
AnswerC

Monitoring email attachments in transit for sensitive data inspects network traffic flows, which is network DLP. Endpoint DLP would inspect data on devices, and storage DLP would scan data at rest rather than email in transit.

Why this answer

Network DLP monitors data in motion by inspecting network traffic, such as email attachments, as they traverse the network perimeter. This is the correct type because the scenario explicitly describes monitoring email attachments, which are transmitted over the network, and Network DLP is designed to inspect SMTP, HTTP, FTP, and other protocols for sensitive content at the network layer.

Exam trap

The trap here is that candidates confuse 'monitoring email attachments' with endpoint-based controls, but the key distinction is that Network DLP inspects data in motion across the network, whereas Endpoint DLP focuses on local device actions like saving to USB or printing.

How to eliminate wrong answers

Option A is wrong because classification-based controls are not a type of DLP; they are a data governance mechanism that labels data based on sensitivity, but they do not actively monitor or block data in transit. Option B is wrong because Cloud DLP is a service provided by cloud providers (e.g., AWS Macie, Google Cloud DLP) that inspects data stored in cloud repositories, not email attachments traversing an on-premises or hybrid network. Option D is wrong because Endpoint DLP monitors data at rest or in use on endpoints (e.g., USB copy, clipboard operations), not data in motion over the network like email attachments.

10
MCQeasy

Which of the following best describes the primary purpose of an incident response plan?

A.To replace the need for a disaster recovery plan
B.To assign blame after an incident occurs
C.To document all security controls in place
D.To provide a structured approach for managing and resolving security incidents
AnswerD

An Incident Response (IR) plan establishes a systematic and predefined set of procedures, roles, and communication protocols for an organization to effectively handle security breaches. This structured approach ensures that incidents are detected promptly, analyzed thoroughly, contained efficiently, eradicated completely, and that systems are recovered swiftly. Its primary purpose is to minimize impact, restore normal operations, and learn from each event to enhance overall security posture.

Why this answer

An incident response plan provides a structured approach to manage and resolve security incidents, minimizing impact.

11
Multi-Selecthard

A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)

Select 3 answers
A.Reciprocal agreement
B.Cloud DR with replication
C.Synchronous replication to a secondary site
D.Hot site
E.Cold site
AnswersB, C, D

Cloud Disaster Recovery (DR) with replication leverages public or private cloud infrastructure to host backup systems and data. This approach enables rapid recovery with low RTO and RPO by continuously replicating data and virtual machine images to the cloud, allowing for quick spin-up of services in a disaster. Its scalability and pay-as-you-go model also offer cost-effectiveness compared to maintaining a dedicated secondary site.

Why this answer

Option B (Cloud DR with replication) is correct because continuously replicating workloads and data to a cloud region keeps a near-current copy of the environment, allowing rapid failover for a low RTO and minimal data loss for a low RPO. Option C (Synchronous replication to a secondary site) is correct because synchronous replication only acknowledges writes once they are committed at both sites, giving an RPO of essentially zero, and the mirrored secondary site can be activated quickly for a low RTO. Option D (Hot site) is correct because a hot site is a fully operational duplicate facility with current data and ready-to-run systems, enabling failover in minutes or hours (low RTO) with little to no data loss (low RPO).

Option A (Reciprocal agreement) does not belong because it relies on another organization's idle capacity that may not be available or current during a disaster, yielding high RTO and RPO. Option E (Cold site) does not belong because it provides only basic space and power with no pre-installed systems or data, requiring lengthy setup and restoration, which produces the highest RTO and RPO.

Exam trap

CISSP often tests the trade-off between cost and recovery objectives, tempting candidates to select reciprocal agreements or cold sites as 'good enough' when the question explicitly demands minimal RTO and RPO.

12
MCQeasy

Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?

A.Legal counsel
B.Incident manager
C.Forensic investigator
D.Communications lead
AnswerD

The Communications Lead is the designated individual primarily responsible for developing and executing the incident communication strategy. This critical role involves crafting accurate, timely, and consistent messages for all internal and external stakeholders, including employees, customers, partners, regulators, and the media. They manage public relations, coordinate press releases, and ensure that all official statements align with the incident response objectives and organizational values.

Why this answer

The communications lead is the incident response team role specifically tasked with managing all external and internal communications, including press releases, media inquiries, and regulator notifications. This role ensures a single, consistent message and prevents unauthorized disclosures. Legal counsel, the incident manager, and forensic investigators have different primary responsibilities that do not center on external communications.

Exam trap

The trap is conflating 'legal counsel' with 'communications lead' — candidates may assume lawyers handle regulator communication, but the communications lead owns the messaging while legal counsel provides legal guidance.

How to eliminate wrong answers

Option A (Legal counsel) is wrong because legal counsel advises on legal obligations, privilege, and regulatory interpretation but does not own the communication channel with media or regulators. Option B (Incident manager) is wrong because the incident manager coordinates the overall response effort and resource allocation, not the drafting and delivery of external communications. Option C (Forensic investigator) is wrong because the forensic investigator collects, preserves, and analyzes evidence; communicating with the media or regulators is outside that scope.

13
MCQmedium

A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?

A.DoS
B.Insider threat
C.Social engineering
D.Unauthorized access
AnswerD

Unauthorized access refers to gaining entry to a system, network, or data without the necessary permissions or authorization. The SIEM logs indicating a pattern, such as numerous failed login attempts followed by a successful one, directly points to a successful breach where an entity gained entry without legitimate credentials, fulfilling the definition of unauthorized access.

Why this answer

The sequence of multiple failed login attempts followed by a successful login from the same external IP address indicates a brute-force or password-spraying attack that succeeded. This constitutes unauthorized access because the attacker gained entry to an account without legitimate authorization, violating the confidentiality and integrity of the finance user's account.

Exam trap

The trap here is that candidates may confuse 'insider threat' with any unauthorized access, but the external IP address clearly indicates the attacker is not an insider, making unauthorized access the correct category.

How to eliminate wrong answers

Option A is wrong because a DoS (Denial of Service) attack aims to disrupt service availability by overwhelming resources, not to gain authenticated access through repeated login attempts. Option B is wrong because an insider threat involves a trusted user misusing their legitimate access, whereas this scenario shows an external IP address performing the login attempts, not an internal user. Option C is wrong because social engineering relies on manipulating human psychology (e.g., phishing calls or emails) to trick users into revealing credentials, not on automated brute-force attempts against a login interface.

14
MCQeasy

Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?

A.RPO
B.MTD
C.MTTR
D.RTO
AnswerA

The Recovery Point Objective (RPO) specifies the maximum acceptable amount of data that an organization can afford to lose following a disruption. This metric is typically expressed as a time interval, such as 'data loss not exceeding the last four hours' or 'no more than one day's worth of transactions.' It directly influences the frequency of data backups, snapshots, or replication strategies required to meet this business continuity target.

Why this answer

Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time — for example, an RPO of 4 hours means the organization can tolerate losing up to 4 hours of data. It directly drives backup frequency and replication strategy. RTO, by contrast, defines how long recovery can take, not how much data can be lost.

Exam trap

CISSP often tests the confusion between RPO (data loss tolerance) and RTO (downtime tolerance) — candidates frequently swap these definitions under exam pressure.

How to eliminate wrong answers

Option B is wrong because Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable before unacceptable impact occurs; it is a broader business metric that encompasses both RTO and RPO considerations. Option C is wrong because Mean Time To Repair (MTTR) measures the average time to restore a failed component, which is an operational reliability metric, not a data-loss tolerance. Option D is wrong because Recovery Time Objective (RTO) defines the maximum acceptable duration of downtime before service must be restored, not the amount of data that can be lost.

15
MCQeasy

An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?

A.Communication plan
B.Recovery procedures
C.Legal notification requirements
D.Incident categories
AnswerD

Incident categories establish predefined classifications and criteria that help an organization determine whether a particular event constitutes a security incident requiring formal response. These categories, such as "malware infection," "unauthorized access," "denial of service," or "data exfiltration," provide clear definitions and often include specific indicators or thresholds. By categorizing events, organizations can standardize incident identification, prioritize response efforts, and ensure consistent handling based on the nature and potential impact of the security breach.

Why this answer

Incident categories define the classification scheme that specifies what types of events constitute an incident and how they are grouped (e.g., malware, DoS, unauthorized access). This component establishes the conditions and thresholds that trigger incident declaration, making it the correct answer for 'defining the specific conditions that constitute an incident.' Categories also drive escalation paths and response procedures.

Exam trap

CISSP often tests whether candidates can distinguish the components of an incident response plan — the trap is confusing the definition of an incident (categories) with the actions taken after an incident (communication, recovery, legal notification).

How to eliminate wrong answers

Option A is wrong because the communication plan defines who to notify, when, and through what channels — it does not define what constitutes an incident. Option B is wrong because recovery procedures describe how to restore systems after an incident, not the criteria for declaring one. Option C is wrong because legal notification requirements specify regulatory and contractual obligations for reporting incidents, not the conditions that define an incident.

16
MCQmedium

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

A.Project management office
B.Incident response team
C.Change Advisory Board (CAB)
D.Security operations center
AnswerC

The Change Advisory Board (CAB) is a crucial component of a robust change management process, specifically tasked with reviewing, assessing, prioritizing, and authorizing proposed changes to an organization's IT services and infrastructure. Comprising diverse stakeholders, the CAB ensures that all potential impacts, risks, and resource requirements are thoroughly evaluated, including security implications, before a change is approved for implementation. This structured review minimizes adverse effects and maintains system stability.

Why this answer

The Change Advisory Board (CAB) is the formal group within ITIL-based change management responsible for reviewing, assessing, and approving major or high-risk changes. Major changes typically require a CAB meeting to evaluate impact, resource requirements, and rollback plans before authorization. This ensures changes do not introduce security vulnerabilities or disrupt critical operations.

Exam trap

The CISSP exam often tests the distinction between operational roles (SOC, Incident Response) and governance/approval bodies (CAB), leading candidates to confuse real-time monitoring functions with change authorization responsibilities.

How to eliminate wrong answers

Option A is wrong because the Project Management Office (PMO) oversees project portfolios and ensures alignment with business goals, but it does not have the authority or technical mandate to approve operational changes to production systems. Option B is wrong because the Incident Response Team handles active security incidents and post-incident remediation, not the proactive review and approval of planned changes. Option D is wrong because the Security Operations Center (SOC) monitors real-time security events and alerts, but it is not chartered to approve changes; its role is to detect and respond to anomalies that may result from changes, not to authorize them.

17
Multi-Selecteasy

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

Select 3 answers
A.Application DLP
B.Network DLP
C.Cloud DLP
D.Endpoint DLP
E.Physical DLP
AnswersB, C, D

Network DLP systems are strategically positioned at key network egress points, such as internet gateways or between network segments, to inspect all data traversing the network perimeter. This deployment type actively monitors data "in motion" by analyzing network traffic, including email, web protocols, and file transfers, for sensitive content that violates predefined organizational policies. Its primary function is to prevent unauthorized data exfiltration before it leaves the controlled network environment.

Why this answer

Network DLP (B) is correct because it monitors and inspects data in transit at network egress points such as email gateways, web proxies, and firewalls, typically using deep packet inspection to detect sensitive data leaving the perimeter. Cloud DLP (C) is correct because it applies policy enforcement to data stored in or moving through SaaS, IaaS, and PaaS environments via APIs and CASB integrations, covering cloud storage, email, and collaboration apps. Endpoint DLP (D) is correct because it runs agents on workstations and servers to control data at rest and in use, monitoring file operations, USB/removable media, clipboard, printing, and screen capture.

Application DLP and Physical DLP are not standard DLP control categories: application-level enforcement is generally a function within endpoint or network DLP, and physical controls (locked cabinets, badge access, media destruction) belong to physical security rather than DLP technology classifications.

Exam trap

CISSP often tests whether candidates confuse DLP control categories with unrelated security controls — the trap is selecting plausible-sounding but non-standard options like 'Application DLP' or 'Physical DLP' instead of the three canonical types (network, endpoint, cloud).

18
Multi-Selectmedium

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

Select 2 answers
A.Performing threat hunting
B.Monitoring SIEM alerts and performing initial triage
C.Escalating incidents to Tier 2 when necessary
D.Conducting in-depth forensic analysis
E.Developing new detection rules for the SIEM
AnswersB, C

Tier 1 SOC analysts are primarily responsible for the continuous monitoring of security information and event management (SIEM) systems. Their core duty involves reviewing incoming alerts, correlating events, and performing an initial assessment to determine if an alert represents a legitimate security incident. This initial triage ensures that potential threats are identified promptly and categorized for appropriate next steps.

Why this answer

Option B is correct because Tier 1 analysts are the first line of defense in a SOC, continuously monitoring SIEM alerts and performing initial triage to determine whether an alert is a true positive, false positive, or benign event. Option C is correct because a core Tier 1 responsibility is escalating validated or suspicious incidents to Tier 2 for deeper investigation when the alert exceeds their scope or requires advanced analysis. Threat hunting (A) is typically performed by Tier 2 or Tier 3 analysts who proactively search for hidden threats rather than react to alerts.

In-depth forensic analysis (D) is a Tier 3 or dedicated incident response function requiring specialized tools and expertise. Developing new detection rules for the SIEM (E) is usually the responsibility of Tier 2/Tier 3 analysts or detection engineers, not Tier 1.

Exam trap

CISSP often tests the boundaries between SOC tiers, so candidates assign advanced tasks like threat hunting or detection engineering to Tier 1 when those belong to Tier 2 or Tier 3.

19
MCQmedium

A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?

A.Vulnerability scanner
B.SOAR
C.Endpoint detection and response (EDR)
D.Network-based IDS
AnswerB

Security Orchestration, Automation, and Response (SOAR) platforms are specifically designed to integrate with SIEM systems to automate and orchestrate incident response workflows. SOAR tools ingest alerts, enrich them with contextual data, and execute predefined playbooks, enabling a SOC team to rapidly respond to threats by automating tasks such as blocking malicious IPs, isolating compromised endpoints, or gathering additional forensic evidence, thereby significantly reducing manual effort and improving response times.

Why this answer

SOAR (Security Orchestration, Automation, and Response) is the technology designed to integrate with SIEM systems to automate incident response workflows, orchestrate actions across security tools, and execute playbooks for common threats. It directly addresses the requirement for security orchestration and automation.

Exam trap

CISSP often tests the distinction between detection tools (SIEM, IDS, EDR) and response orchestration tools (SOAR), so candidates must recognize that automation and orchestration are the defining characteristics of SOAR.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner identifies weaknesses but does not orchestrate responses or automate remediation workflows. Option C is wrong because EDR focuses on endpoint detection and response, providing telemetry and containment on endpoints, but it does not provide cross-tool orchestration and automation. Option D is wrong because a network-based IDS detects malicious traffic but lacks the orchestration and automated response capabilities required for SOAR.

20
MCQmedium

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

A.To provide oversight and approval for significant changes
B.To implement changes as requested by management
C.To review security incidents after they occur
D.To approve all changes to the production environment
AnswerA

The Change Advisory Board (CAB) primarily serves as a governance body responsible for evaluating and authorizing significant changes to IT services and infrastructure. This oversight ensures that all high-impact or high-risk modifications are thoroughly assessed for potential security implications, operational disruptions, and resource requirements before implementation. Their approval process is crucial for maintaining system stability, security posture, and compliance.

Why this answer

The Change Advisory Board (CAB) exists to review, assess, and approve significant changes before they are deployed, providing governance and risk oversight across the IT environment. Its primary purpose is oversight and approval, not hands-on implementation or incident review. This aligns with ITIL change enablement practices, where the CAB advises the change authority on risk and impact.

Exam trap

CISSP often tests the scope of CAB authority — candidates pick 'approve all changes' because it sounds comprehensive, but the CAB only reviews significant/high-risk changes; standard changes are pre-authorized and bypass the CAB.

How to eliminate wrong answers

Option B is wrong because implementing changes is the responsibility of the change implementer or technical team, not the CAB; the CAB is a governance body, not an execution team. Option C is wrong because reviewing security incidents after they occur is the role of incident response and post-incident review processes, not the CAB, whose focus is pre-deployment change risk. Option D is wrong because the CAB does not approve all changes — standard/low-risk changes are typically pre-authorized and handled through the change model without CAB review, and the CAB only reviews significant or high-risk changes.

21
MCQmedium

An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?

A.Escalation paths
B.Communication plan
C.Recovery procedures
D.Incident categories
AnswerA

Escalation paths are a critical component of an incident response plan, explicitly detailing the predefined triggers and the hierarchical notification process for significant incidents. They specify which individuals or departments, such as senior management, legal counsel, or public relations, must be informed at various stages of an incident based on its severity, impact, or regulatory implications. This ensures that appropriate leadership and specialized expertise are engaged promptly to manage the broader organizational consequences.

Why this answer

Escalation paths define the criteria, thresholds, and chain of command for moving an incident to higher authority, including when senior management and legal counsel must be engaged. They specify who is notified, under what conditions, and in what timeframe, which is exactly the component that governs escalation to executives and legal. This makes escalation paths the primary owner of that decision logic within the IR plan.

Exam trap

The trap here is confusing the communication plan (how you communicate) with escalation paths (when and to whom you escalate), causing candidates to pick the communication plan for a question about escalation criteria.

How to eliminate wrong answers

Option B is wrong because the communication plan defines how information is shared (internal/external messaging, stakeholders, media), not the criteria for when to escalate to management or legal. Option C is wrong because recovery procedures describe how to restore systems and services after an incident, not who gets notified or when escalation is triggered. Option D is wrong because incident categories classify incidents by type or severity for triage and prioritization; while severity can inform escalation, the categories themselves do not define the escalation criteria or the management/legal notification triggers.

22
Multi-Selectmedium

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Select 3 answers
A.Forensic Investigator
B.Human Resources Representative
C.Incident Response Manager
D.Chief Financial Officer
E.Communications Lead
AnswersA, C, E

A forensic investigator is crucial for preserving the chain of custody, analyzing digital artifacts, and determining the root cause and scope of an incident. Their specialized skills ensure that evidence is admissible in legal proceedings and that a thorough post-incident analysis can be conducted to prevent future occurrences. This role is typically part of a Tier 2 or Tier 3 response, providing deep technical insight.

Why this answer

The Forensic Investigator (A) is a standard IR team role responsible for collecting, preserving, and analyzing digital evidence using forensically sound methods such as write blockers and chain-of-custody documentation. The Incident Response Manager (C) is standard because this role coordinates the overall response, triages incidents, allocates resources, and serves as the decision-making authority during an incident. The Communications Lead (E) is also standard, handling internal and external messaging, stakeholder updates, and coordination with legal, PR, and regulatory bodies to maintain accurate and timely communications.

Human Resources Representative (B) and Chief Financial Officer (D) are not standard core IR team roles; while HR or finance may be consulted for employee-related or cost-impacting incidents, they are not part of the recognized baseline incident response team structure.

Exam trap

CISSP often tests the distinction between core IR team roles and executive/support stakeholders — the trap is selecting HR or CFO because they sound important, when the exam expects NIST/SANS-standard technical and communications roles.

23
MCQeasy

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

A.The total downtime the organization can tolerate
B.The time within which IT systems must be restored
C.The maximum amount of data loss acceptable
D.The time required to repair a failed component
AnswerB

This precisely defines the Recovery Time Objective (RTO). The RTO is a critical metric in business continuity and disaster recovery planning, specifying the maximum acceptable duration for a business process or IT service to be unavailable following an incident before significant business impact occurs. It dictates the target timeframe within which IT infrastructure, applications, and data must be brought back online and fully operational to meet business needs. Achieving the RTO requires careful planning, resource allocation, and robust recovery strategies.

Why this answer

RTO defines the maximum time allowed to restore IT services after a disaster, ensuring the MTD is not exceeded.

24
MCQeasy

Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?

A.MTTR
B.RPO
C.RTO
D.MTD
AnswerB

RPO, or Recovery Point Objective, precisely defines the maximum acceptable amount of data loss, measured in time, that an organization can tolerate following a disruptive event. It dictates the age of files or data that must be recovered from backup storage for normal operations to resume. Establishing the RPO is critical for determining backup frequency and data replication strategies to ensure business continuity.

Why this answer

RPO (Recovery Point Objective) defines the maximum tolerable amount of data loss measured in time. It represents the point in time to which data must be recovered after a disruption, effectively setting the maximum age of the most recent backup that can be restored. For example, an RPO of 4 hours means the organization can tolerate losing up to 4 hours of data, so backups must occur at least every 4 hours.

Exam trap

CISSP often tests the distinction between RPO and RTO, as candidates frequently confuse data loss (RPO) with downtime (RTO).

How to eliminate wrong answers

Option A is wrong because MTTR (Mean Time To Repair) measures the average time required to repair a failed component or system, not data loss tolerance. Option C is wrong because RTO (Recovery Time Objective) defines the maximum acceptable downtime after a disaster, not the amount of data loss. Option D is wrong because MTD (Maximum Tolerable Downtime) is the total time a business process can be unavailable before causing unacceptable consequences, which encompasses both RTO and other recovery activities, but does not directly measure data loss.

25
MCQeasy

Which of the following is an example of a social engineering attack?

A.A brute-force attack on a password
B.SQL injection on a web application
C.A DDoS attack on a server
D.A phishing email requesting credentials
AnswerD

A phishing email requesting credentials is a classic example of social engineering, where an attacker attempts to trick an individual into divulging sensitive information, such as usernames and passwords. These emails often impersonate trusted entities, creating a sense of urgency or fear to manipulate the recipient into clicking a malicious link or entering credentials on a fake website. The success of phishing relies entirely on human psychological manipulation and deception, rather than exploiting technical vulnerabilities directly.

Why this answer

Phishing is a social engineering attack that manipulates human psychology to trick users into revealing credentials or clicking malicious links. It relies on deception and trust rather than technical exploitation, which is the defining characteristic of social engineering.

Exam trap

CISSP often tests whether candidates can distinguish social engineering from technical attacks — the trap is selecting a technically sophisticated attack like SQL injection or brute force because it sounds more 'advanced', missing that social engineering is defined by human manipulation.

How to eliminate wrong answers

Option A is wrong because a brute-force attack is a technical attack that systematically tries password combinations; it does not involve human manipulation. Option B is wrong because SQL injection is a code injection attack that exploits vulnerable input validation in web applications, not human behavior. Option C is wrong because a DDoS attack floods a target with traffic to exhaust resources; it is a network-based availability attack, not social engineering.

26
MCQhard

Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?

A.CVSS base score
B.Exploitability and business impact
C.Number of systems affected
D.Time since discovery
AnswerB

Exploitability and business impact are paramount because they directly align with the fundamental principles of risk management, where risk equals likelihood multiplied by impact. Exploitability assesses the probability of a threat actor successfully leveraging a vulnerability, while business impact quantifies the potential damage or disruption to critical assets and operations. Prioritizing based on these factors ensures that remediation efforts focus on vulnerabilities that pose the greatest actual risk to the organization's mission and assets.

Why this answer

Prioritizing vulnerability remediation should be driven by exploitability (is there a known exploit, is it weaponized, is it reachable) combined with business impact (what asset is affected, what data or process is at risk). This risk-based approach ensures limited remediation resources are directed at the vulnerabilities that pose the greatest actual threat to the organization. CVSS alone does not capture business context.

Exam trap

CISSP often tests the misconception that CVSS base score alone should drive prioritization, when the correct answer requires combining exploitability with business impact.

How to eliminate wrong answers

Option A is wrong because CVSS base score measures intrinsic technical severity but ignores whether the vulnerability is exploitable in your environment, whether compensating controls exist, and what business asset is affected. Option C is wrong because the number of systems affected is a factor but not the most important one; a single critical system with sensitive data may outweigh many low-impact systems. Option D is wrong because time since discovery is a useful tiebreaker but does not reflect exploitability or business impact, and an old vulnerability with no exploit path may be lower priority than a new, actively exploited one.

27
MCQmedium

An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?

A.Reciprocal agreement
B.Warm site
C.Cold site
D.Hot site
AnswerD

A hot site is a fully operational, mirror image of the primary data center, equipped with all necessary hardware, software, and up-to-date data. It maintains real-time or near real-time synchronization with the production environment, allowing for immediate failover and seamless business continuity with minimal disruption. This immediate availability and readiness directly address stringent recovery time objectives (RTOs) that demand near-instantaneous resumption of critical operations following a disaster.

Why this answer

A hot site is fully configured with hardware, software, and real-time data replication, enabling the critical financial application to be operational within minutes to a few hours. With an RTO of 4 hours, a hot site provides the necessary infrastructure and up-to-date data to meet this stringent recovery timeline, as cold and warm sites require significant setup and data restoration time.

Exam trap

The trap here is that candidates often confuse a warm site with a hot site, assuming pre-installed hardware is sufficient, but they overlook the critical need for current data replication to meet a tight RTO like 4 hours.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement relies on another organization's spare capacity, which is not guaranteed to be available or compatible within 4 hours, and typically involves manual setup and data restoration. Option B is wrong because a warm site has pre-installed hardware and software but lacks current data, requiring time to restore from backups, which often exceeds a 4-hour RTO for critical applications. Option C is wrong because a cold site provides only physical space and basic utilities, requiring days or weeks to procure, install, and configure hardware and software, making it impossible to meet a 4-hour RTO.

28
MCQeasy

What type of DLP system monitors data in motion across the network?

A.Network DLP
B.Storage DLP
C.Endpoint DLP
D.Cloud DLP
AnswerA

Network DLP systems specifically monitor "data in motion" by inspecting network traffic as it traverses the organization's boundaries or internal segments. These solutions typically employ deep packet inspection (DPI) to analyze data streams for sensitive content, patterns, or metadata, preventing unauthorized transmission over protocols like HTTP, FTP, or email. They are often deployed at network egress points or internal chokepoints to enforce data security policies.

Why this answer

Network DLP (A) is designed to monitor data in motion across the network, inspecting traffic for sensitive information being transmitted. It sits at network egress points and analyzes protocols like HTTP, SMTP, and FTP to prevent data exfiltration. This directly matches the requirement to monitor data in motion.

Exam trap

The trap is confusing the three states of data (motion, rest, use) and selecting endpoint or storage DLP; the key is recognizing that 'in motion across the network' specifically points to Network DLP.

How to eliminate wrong answers

Option B is wrong because Storage DLP monitors data at rest in storage repositories (e.g., file servers, databases), not data moving across the network. Option C is wrong because Endpoint DLP monitors data on endpoint devices (e.g., laptops, desktops) and controls actions like copy/paste or USB transfers, but it does not focus on network traffic. Option D is wrong because Cloud DLP typically refers to scanning data at rest in cloud storage or SaaS applications, not data in motion across the network.

29
MCQhard

During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?

A.CPU registers → cache → RAM → swap → disk
B.Disk → RAM → CPU registers → cache → swap
C.RAM → CPU registers → swap → disk → remote logging
D.Swap → RAM → cache → CPU registers → disk
AnswerA

This sequence accurately represents the decreasing order of volatility for digital evidence, which is crucial for forensic collection. CPU registers are the most volatile, holding data only during active processing and being lost immediately upon power loss or context switch. Cache memory is slightly less volatile but still transient, followed by RAM, which requires continuous power to retain data. Swap space, residing on disk, is less volatile than RAM but more dynamic than persistent disk storage, making disk the least volatile and most persistent data source.

Why this answer

The order of volatility (RFC 3227) dictates that the most ephemeral data must be captured first because it disappears fastest. CPU registers and cache lose their contents within nanoseconds to milliseconds, RAM persists only while powered, swap holds paged memory on disk, and the disk itself is the most persistent. Therefore CPU registers → cache → RAM → swap → disk is the correct forensic collection sequence.

Exam trap

CISSP often tests the order of volatility by presenting plausible-looking sequences that swap adjacent layers (e.g., RAM before cache, or swap before RAM), so candidates who memorize only 'memory before disk' without the full hierarchy pick the wrong ordering.

How to eliminate wrong answers

Option B is wrong because it reverses the order of volatility, starting with the most persistent medium (disk) and ending with the most ephemeral (CPU registers), which would guarantee loss of critical evidence. Option C is wrong because it places RAM before CPU registers and cache, and it inserts 'remote logging' as a final step even though remote logs are network-persistent and not part of the local volatility hierarchy. Option D is wrong because it starts with swap (a disk-based structure) before RAM and CPU registers, inverting the fundamental principle that memory-resident data must be captured before disk-resident data.

30
MCQmedium

During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?

A.To speed up the investigation process
B.To document who accessed the evidence and when
C.To encrypt the evidence at rest
D.To store evidence in a fireproof safe
AnswerB

Documenting who accessed the evidence and when is the fundamental purpose of maintaining a chain of custody during a forensic investigation. This process creates an unbroken, verifiable audit trail that identifies every individual who has handled or had control over a piece of evidence, along with the precise dates and times of these interactions. This meticulous record is essential for demonstrating that the evidence has not been tampered with, substituted, or compromised, thereby ensuring its integrity and legal admissibility in court.

Why this answer

The chain of custody is a documented record of who handled evidence, when, where, and for what purpose, from collection through presentation in court. Its primary purpose is to preserve the integrity and admissibility of evidence by showing an unbroken sequence of custody (B). Without it, opposing counsel can challenge that evidence was tampered with or contaminated.

Exam trap

CISSP often tests whether candidates confuse chain of custody (documenting handling) with other evidence controls like encryption or physical storage, or mistakenly believe CoC's purpose is investigative speed.

How to eliminate wrong answers

Option A is wrong because chain of custody does not speed up investigations — it is a control mechanism that can add procedural steps. Option C is wrong because encryption at rest is a separate data-protection control; chain of custody documents handling, not cryptographic protection. Option D is wrong because storing evidence in a fireproof safe is one physical safeguard, but it is not the purpose of the chain of custody, which is about documenting the custody trail.

31
MCQeasy

Which digital forensics tool is specifically designed for memory forensics?

A.Volatility
B.Wireshark
C.EnCase
D.FTK
AnswerA

Volatility is an open-source framework specifically designed for memory forensics, enabling investigators to extract and analyze digital artifacts from volatile memory (RAM) dumps. It allows for the examination of running processes, open network connections, loaded kernel modules, and user activity, which are crucial for incident response, malware analysis, and understanding the runtime state of a compromised system. Its capabilities are centered on analyzing live system memory rather than persistent storage.

Why this answer

Volatility is the leading open-source memory forensics framework, designed to analyze RAM dumps (e.g., from LiME, WinPmem, or hibernation files) to extract running processes, network connections, injected code, and encryption keys. It parses memory structures using profiles or symbol tables to reconstruct system state. This makes it the tool specifically built for memory forensics.

Exam trap

CISSP often tests tool-to-purpose mapping, and candidates confuse disk forensics suites (EnCase, FTK) with memory forensics (Volatility) or network forensics (Wireshark).

How to eliminate wrong answers

Option B is wrong because Wireshark is a network protocol analyzer that captures and inspects packet traffic, not memory contents. Option C is wrong because EnCase is a disk forensics suite for imaging and analyzing storage media, not RAM. Option D is wrong because FTK (Forensic Toolkit) is also a disk and file-system forensics platform, not a memory analysis tool.

32
MCQeasy

A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?

A.Isolate the workstation from the network while preserving its state for investigation.
B.Power off the workstation immediately to stop the malware from spreading.
C.Run a full antivirus scan and delete any detected files before escalating.
D.Notify the affected nurse and ask them to stop using the workstation until further notice.
AnswerA

Containment is the priority once an active compromise is confirmed, because the host is beaconing to attacker infrastructure and could enable lateral movement. Network isolation stops command-and-control and spread while keeping memory and disk intact, so the subsequent investigation can determine how the malware arrived and what data was touched.

Why this answer

With an active beacon to attacker infrastructure, the immediate priority in the incident response lifecycle is containment. Isolating the workstation at the network layer halts command-and-control and limits lateral movement while preserving volatile and non-volatile evidence. Powering off, deleting files, or relying on user cooperation all either destroy evidence or leave the compromised host communicating with the adversary.

Exam trap

The trap here is equating containment with shutting the machine down, when powering off destroys volatile memory evidence and can break disk encryption, making later forensics far harder.

33
Multi-Selectmedium

During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?

Select 2 answers
A.Storing evidence on a shared network drive
B.Encrypting the evidence file to prevent viewing
C.Labeling evidence with date, time, and collector's name
D.Performing a hash of the evidence immediately
E.Documenting each person who handled the evidence
AnswersC, E

Labeling evidence immediately upon collection with essential details such as the date, time, and the name of the collector is a fundamental step in establishing a robust chain of custody. This initial documentation provides an irrefutable starting point for the evidence's lifecycle, clearly identifying when and by whom it was first secured. Accurate labeling ensures that each piece of evidence can be uniquely identified and tracked throughout the entire forensic process, preventing mix-ups and disputes over its origin.

Why this answer

Option C is correct because labeling evidence with the date, time, and collector's name creates an auditable record of when and by whom the evidence was first obtained, which is a foundational element of chain of custody. Option E is correct because documenting every person who handled the evidence establishes an unbroken, traceable custody trail that shows who had control of the evidence at all times and prevents tampering claims. Options A, B, and D do not belong: storing evidence on a shared network drive (A) compromises integrity and access control rather than preserving custody, encrypting the evidence file to prevent viewing (B) is a confidentiality measure that can hinder forensic examination and is not a chain-of-custody step, and although hashing (D) is essential for proving integrity, it is an evidence-integrity technique rather than a chain-of-custody documentation step.

Exam trap

CISSP often tests the distinction between integrity controls (hashing) and custody controls (labeling and handling logs), causing candidates to select hashing as a chain-of-custody step when it is actually an integrity verification step.

34
Multi-Selecthard

A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?

Select 2 answers
A.Tape backup restoration
B.Cloud DR with continuous data replication
C.Cold site
D.Hot site with real-time replication
E.Warm site
AnswersB, D

Cloud-based Disaster Recovery (DR) leverages the scalability and elasticity of cloud infrastructure to provide a highly agile recovery environment. Continuous data replication ensures that data changes are synchronized almost instantaneously to the cloud DR site, achieving a near-zero Recovery Point Objective (RPO). When a disaster strikes, virtual machines and services can be rapidly provisioned and spun up in the cloud, effectively meeting demanding Recovery Time Objectives (RTOs) with minimal downtime.

Why this answer

Option B (Cloud DR with continuous data replication) is correct because continuous replication keeps the standby environment's data within minutes of the primary, satisfying the 15-minute RPO, while cloud-based failover can typically be initiated well within the 2-hour RTO. Option D (Hot site with real-time replication) is correct because a hot site is fully provisioned and ready to take over immediately, and real-time replication keeps data loss near zero, comfortably meeting both the 2-hour RTO and 15-minute RPO. Option A (Tape backup restoration) is not suitable because restoring from tape is slow and typically yields RTOs measured in days and RPOs in hours or days, far exceeding the targets.

Option C (Cold site) fails because it lacks pre-installed infrastructure and requires lengthy setup, making the 2-hour RTO unachievable. Option E (Warm site) is closer but still requires some configuration and its periodic replication usually cannot guarantee a 15-minute RPO.

Exam trap

The trap is selecting a warm site or tape backup because they are cheaper, but candidates must match the strict RTO/RPO numbers; warm sites often cannot meet 15-minute RPO without continuous replication.

35
MCQmedium

What is the primary purpose of a Change Advisory Board (CAB) in change management?

A.To conduct vulnerability assessments
B.To approve and oversee changes to IT systems
C.To implement changes in the IT environment
D.To respond to security incidents
AnswerB

The primary purpose of a Change Advisory Board (CAB) is to evaluate, prioritize, and authorize proposed changes to IT services and infrastructure, ensuring they align with organizational goals and minimize adverse impacts. The CAB meticulously reviews change requests, assessing potential risks, resource requirements, and dependencies before granting approval. Furthermore, it provides oversight throughout the change lifecycle, monitoring implementation progress and reviewing post-implementation reports to confirm successful deployment and address any unforeseen issues.

Why this answer

The CAB is a governance body whose core function is to review, evaluate, and formally approve or reject proposed changes to IT systems before they are implemented. It balances the need for change against risk and business impact, ensuring changes are authorized, prioritized, and scheduled appropriately. This approval/oversight role is distinct from actually performing the change or handling security operations.

Exam trap

CISSP often tests the distinction between governance/oversight roles (CAB approves) and operational roles (implementers execute, SOC responds), so candidates who conflate approval with execution pick option C.

How to eliminate wrong answers

Option A is wrong because vulnerability assessments are performed by security teams using scanning tools (e.g., Nessus, Qualys) and are an input to risk management, not a CAB function. Option C is wrong because implementing changes is the responsibility of the change implementer or technical staff; the CAB approves but does not execute. Option D is wrong because responding to security incidents is the role of the incident response team or SOC, not the CAB, which is a change governance body.

36
MCQmedium

An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?

A.Network firewall
B.Threat intelligence platform
C.SOAR platform
D.Vulnerability scanner
AnswerC

A Security Orchestration, Automation, and Response (SOAR) platform integrates various security tools and systems to automate and orchestrate incident response workflows. It ingests alerts from SIEMs and other sources, applies predefined playbooks to analyze incidents, and automatically executes actions such as blocking IP addresses, isolating endpoints, enriching data, or creating tickets. This capability significantly reduces manual effort, accelerates response times, and standardizes incident handling procedures within a SOC by automating repetitive tasks.

Why this answer

A SOAR (Security Orchestration, Automation, and Response) platform is designed to ingest alerts from SIEM and other sources, apply playbooks, and execute automated response actions such as disabling accounts, blocking IPs, or opening tickets. It is the technology category purpose-built for automating low-severity alert triage and response. SIEM correlates and detects; SOAR orchestrates and acts.

Exam trap

CISSP often tests the boundary between SIEM and SOAR, so the trap is choosing a detection or intelligence tool when the scenario explicitly asks for automated response actions.

How to eliminate wrong answers

Option A is wrong because a network firewall enforces traffic policy at the perimeter; it can block traffic but cannot ingest SIEM alerts, run playbooks, or orchestrate multi-step responses across tools. Option B is wrong because a threat intelligence platform aggregates and enriches indicators of compromise; it informs detection but does not execute response actions. Option D is wrong because a vulnerability scanner identifies weaknesses in systems; it does not respond to runtime alerts or automate SOC workflows.

37
MCQmedium

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

A.Incident manager
B.Tier 2
C.Tier 1
D.Tier 3
AnswerD

Tier 3 analysts, often comprising threat hunters, malware reverse engineers, and digital forensics experts, possess the most advanced technical skills within a SOC. They are uniquely equipped to conduct deep-dive forensic examinations, including advanced memory forensics, file system analysis, and complex artifact reconstruction, utilizing specialized tools and methodologies. This tier is essential for uncovering sophisticated attack techniques, attributing threats, and developing proactive defenses based on expert-level forensic insights.

Why this answer

Tier 3 performs advanced analysis, which explicitly includes deep packet inspection (DPI) and memory forensics. Confirming DNS tunneling exfiltration requires inspecting DNS query payloads for encoded data and analyzing process memory for injected malware — skills and tooling reserved for Tier 3. Tier 1 and Tier 2 handle triage and investigation but not advanced forensic analysis.

Exam trap

CISSP often tests SOC tier responsibilities — candidates assume Tier 2 handles all investigations, but deep forensics (DPI, memory analysis) is explicitly Tier 3.

How to eliminate wrong answers

Option A is wrong because an incident manager coordinates response, communications, and resources — they do not perform technical forensic analysis like DPI or memory forensics. Option B is wrong because Tier 2 investigates and correlates alerts but does not typically perform deep packet inspection or memory forensics, which are advanced Tier 3 functions. Option C is wrong because Tier 1 only triages and escalates alerts; it lacks the tooling and expertise for DPI and memory forensics.

38
MCQeasy

Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

A.BCP deals with natural disasters, DRP deals with cyberattacks
B.BCP is for IT systems, DRP is for business processes
C.BCP is a subset of DRP
D.BCP ensures business functions continue, DRP restores IT operations
AnswerD

This statement accurately distinguishes between the primary objectives of Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP). BCP is the strategic, holistic program designed to ensure that an organization's essential business functions can continue operating at an acceptable level during and immediately after a disruptive event. DRP, on the other hand, is the tactical plan focused specifically on the systematic recovery and restoration of the organization's critical information technology systems, applications, and data to an operational state.

Why this answer

D is correct because the Business Continuity Plan (BCP) focuses on maintaining critical business functions during and after a disruption, ensuring minimal impact on operations, while the Disaster Recovery Plan (DRP) is a subset of BCP that specifically addresses the restoration of IT infrastructure, systems, and data after a disaster. The BCP encompasses broader organizational resilience, including manual workarounds and alternate sites, whereas the DRP targets technical recovery procedures such as system rebuilds, data restoration from backups, and failover to redundant systems.

Exam trap

The trap here is that candidates often confuse the scope of BCP and DRP, mistakenly thinking BCP is only for business processes and DRP only for IT, when in fact BCP is the overarching plan that includes DRP as a component for IT recovery.

How to eliminate wrong answers

Option A is wrong because BCP and DRP are not distinguished by the type of disaster; both plans address a wide range of incidents including natural disasters, cyberattacks, and human errors. Option B is wrong because it reverses the roles: BCP covers business processes and continuity strategies, while DRP is specifically for IT systems and technical recovery. Option C is wrong because it incorrectly states that BCP is a subset of DRP; in reality, the DRP is a subset of the BCP, as the BCP includes the DRP along with other continuity elements like crisis communication and alternate site activation.

39
MCQhard

An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?

A.Forensic investigator
B.Communications lead
C.Incident manager
D.Security analyst
AnswerA

The forensic investigator is specifically tasked with the meticulous collection, preservation, and analysis of digital evidence from compromised systems. This role ensures that all evidence is handled according to strict chain-of-custody protocols and forensic best practices, making it admissible in legal proceedings and crucial for understanding the full scope and impact of an incident.

Why this answer

The forensic investigator is specifically trained to identify, collect, preserve, and document digital evidence using forensically sound methods that maintain chain of custody and evidentiary integrity. This role ensures evidence is admissible in legal or disciplinary proceedings. Other incident response roles focus on coordination, communication, or analysis rather than legal evidence handling.

Exam trap

CISSP often tests role differentiation within incident response, so candidates who assume the incident manager or security analyst handles all technical tasks pick C or D instead of the specialized forensic investigator.

How to eliminate wrong answers

Option B is wrong because the communications lead manages internal and external messaging and stakeholder communication during an incident, not evidence collection. Option C is wrong because the incident manager coordinates the overall response effort, assigns tasks, and escalates, but does not personally handle forensic evidence preservation. Option D is wrong because a security analyst monitors and triages alerts and may support investigations, but evidence collection for legal proceedings requires forensic specialization and chain-of-custody discipline.

40
MCQmedium

A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?

A.Hot site
B.Cold site
C.Reciprocal agreement
D.Warm site
AnswerA

A hot site is a fully equipped, mirrored facility with identical hardware, software, and network connectivity to the primary data center. It maintains real-time or near real-time data synchronization, enabling immediate failover and operational resumption within minutes to a few hours. This capability is essential for critical systems requiring a very low Recovery Time Objective (RTO), such as the 4-hour RTO implied for critical company systems, making it the most suitable choice.

Why this answer

A hot site is fully configured with hardware, software, network connectivity, and real-time data replication, enabling recovery within minutes to hours and minimal data loss. This matches the requirement of restoring critical applications within 4 hours with minimal data loss, as hot sites maintain near-synchronous or synchronous replication (e.g., using synchronous replication over Fibre Channel or iSCSI with RPOs in seconds).

Exam trap

The trap here is that candidates confuse 'warm site' with 'hot site' because both have pre-installed hardware, but warm sites lack real-time data replication and automated failover, making them unsuitable for RTOs under 4 hours with minimal data loss.

How to eliminate wrong answers

Option B is wrong because a cold site provides only physical infrastructure (power, cooling, space) with no pre-installed hardware or data, requiring days or weeks to restore, far exceeding the 4-hour RTO. Option C is wrong because a reciprocal agreement relies on another organization's spare capacity, which is not guaranteed, lacks dedicated hardware, and typically has no real-time data replication, leading to RTOs of days and significant data loss. Option D is wrong because a warm site has partially configured hardware and software but lacks real-time data replication, often using periodic backups (e.g., daily tape or disk snapshots), resulting in RTOs of 12-24 hours and RPOs of hours to a day, failing the 4-hour RTO and minimal data loss requirement.

41
Multi-Selectmedium

An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)

Select 3 answers
A.Cloud DR
B.Hot site
C.Cold site
D.Warm site
E.Reciprocal agreement
AnswersB, C, D

A hot site is a fully operational, geographically separate duplicate of the primary data center, equipped with all necessary hardware, software, and up-to-date data. It is designed to allow critical business operations to resume almost instantaneously, minimizing both Recovery Time Objective (RTO) and Recovery Point Objective (RPO) to near zero. This high level of readiness makes it the most expensive but also the most resilient DR site option.

Why this answer

The three recognized recovery site types are the hot site (B), cold site (C), and warm site (D), which differ by readiness and cost: a hot site is a fully equipped, mirrored facility with near-zero RTO, a warm site has hardware and connectivity but requires data restoration and configuration (moderate RTO), and a cold site provides only basic space and power with no pre-installed systems (longest RTO). These three form the standard tiered continuum of alternate processing sites in disaster recovery planning. Cloud DR (A) is a recovery strategy or deployment approach rather than a site type in the classic tiered model, and a reciprocal agreement (E) is a mutual aid arrangement between organizations to share resources, not a dedicated recovery site type.

Exam trap

CISSP often tests the classic three recovery site types, and candidates may be tempted to include 'cloud DR' or 'reciprocal agreement' as site types; the trap is confusing recovery strategies with site classifications.

42
MCQhard

A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?

A.RAM contents
B.CPU registers
C.Hard disk contents
D.Network connections
AnswerB

CPU registers represent the absolute most volatile data on a live system, holding the processor's current operational state, including instructions, memory addresses, and data actively being processed. Any interruption of power or even a context switch can instantly alter or erase this information. Capturing CPU registers first is paramount because they provide the most immediate and granular insight into what the system was doing at the precise moment of forensic interest, making them the highest priority in the order of volatility.

Why this answer

The order of volatility ranks evidence by how quickly it disappears, and CPU registers/cache are the most volatile — they change with every instruction cycle and are lost the instant power is cut or the process is preempted. Capturing CPU registers first preserves the most perishable evidence before it is overwritten. RAM, disk, and network connections are progressively less volatile by comparison.

Exam trap

The trap here is assuming RAM is always the most volatile — candidates forget that CPU registers and cache sit above RAM in the RFC 3227 order of volatility and must be captured first.

How to eliminate wrong answers

Option A is wrong because RAM contents, while highly volatile, are less volatile than CPU registers and cache — RAM persists as long as power is maintained, whereas registers change every clock cycle. Option C is wrong because hard disk contents are the least volatile of the listed items and should be captured last, after all memory and network state. Option D is wrong because network connections (and their associated state) are more volatile than disk but less volatile than RAM and registers; they should be captured after registers and RAM but before disk.

43
MCQhard

An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?

A.Integrating patch deployment with change management
B.Applying patches as soon as they are released
C.Scanning for vulnerabilities weekly
D.Using automated patch tools
AnswerA

Integrating patch deployment with change management ensures that all updates undergo a formal process of planning, testing, scheduling, and approval before implementation. This structured approach minimizes the risk of introducing new vulnerabilities, system instability, or service disruptions by verifying compatibility and functionality in a controlled environment. It also provides a clear audit trail and rollback plan, which are critical for maintaining system integrity and operational continuity.

Why this answer

Integrating patch deployment with change management ensures patches are assessed, approved, scheduled, and rolled back if needed, which is the most critical step to avoid disrupting critical business operations. Change management provides the governance and risk review that prevents untested patches from breaking production.

Exam trap

CISSP often tests the tension between speed and stability, so the trap is choosing immediate patching or automation when the question emphasizes avoiding disruption to critical operations.

How to eliminate wrong answers

Option B is wrong because applying patches immediately without testing or approval can introduce regressions and outages. Option C is wrong because weekly vulnerability scanning identifies gaps but does not control how patches are deployed. Option D is wrong because automated patch tools improve efficiency but do not by themselves prevent business disruption without change control.

44
MCQeasy

Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

A.BCP ensures continuity of business operations; DRP restores IT infrastructure
B.BCP only addresses natural disasters; DRP addresses all disasters
C.BCP is tested annually; DRP is tested monthly
D.BCP focuses on IT restoration; DRP focuses on business processes
AnswerA

The Business Continuity Plan (BCP) is a strategic, high-level plan focused on ensuring the continued operation of critical business functions and processes during and after a disruptive event. Its primary objective is to maintain essential organizational activities, people, and facilities. In contrast, the Disaster Recovery Plan (DRP) is a tactical subset of the BCP, specifically detailing the procedures for restoring an organization's technology infrastructure, including systems, applications, and data, to an operational state.

Why this answer

The key difference is that a Business Continuity Plan (BCP) ensures the continuity of critical business operations during and after a disruption, while a Disaster Recovery Plan (DRP) focuses specifically on restoring IT infrastructure and systems. BCP is broader, encompassing processes, people, and facilities, whereas DRP is a subset of BCP that deals with technical recovery.

Exam trap

CISSP often tests the confusion between BCP and DRP, where candidates might think BCP is IT-focused and DRP is business-focused, but it's the opposite; also, testing frequency is not a defining characteristic.

How to eliminate wrong answers

Option B is wrong because BCP addresses all types of disruptions, not just natural disasters; DRP also addresses all disasters, so the distinction is incorrect. Option C is wrong because testing frequency is not a defining difference; both plans are tested based on organizational requirements, not fixed schedules. Option D is wrong because it reverses the roles: BCP focuses on business processes, while DRP focuses on IT restoration.

45
MCQmedium

During a digital forensics investigation, which of the following data sources has the highest order of volatility?

A.CPU registers
B.Remote logging server
C.Network packets in transit
D.Hard disk drive
AnswerA

CPU registers represent the absolute highest level of data volatility in a system. These tiny, high-speed storage locations are integral to the CPU's operation, holding data and instructions actively being processed. Their contents are transient, changing with every clock cycle and being completely lost the moment power is interrupted or the operating system performs a context switch, making them critical to capture first in a forensic investigation.

Why this answer

CPU registers have the highest order of volatility because they hold the most transient data — values change with every instruction cycle and are lost when power is removed or the process is context-switched. In digital forensics, the order of volatility (RFC 3227) dictates that you collect the most volatile data first, starting with CPU registers and cache, then memory, then network state, then disk.

Exam trap

The trap is confusing 'network packets in transit' as highly volatile — they are volatile, but CPU registers are at the very top of the RFC 3227 order, and candidates often overlook registers in favor of more familiar network data.

How to eliminate wrong answers

Option B is wrong because a remote logging server stores data persistently on disk and is one of the least volatile sources — it may even survive the incident. Option C is wrong because network packets in transit are more volatile than disk but less volatile than CPU registers; they can be captured with tools like tcpdump but are not the highest order. Option D is wrong because a hard disk drive is non-volatile storage — data persists after power-off, making it the least volatile of the listed sources.

46
MCQeasy

Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?

A.Media analysis
B.Log analysis
C.Network forensics
D.Memory forensics
AnswerC

Network forensics is the specialized discipline of digital forensics that focuses on monitoring, capturing, storing, and analyzing network traffic to detect intrusions, identify malicious activity, and reconstruct communication events. It involves the examination of network packets, communication protocols, and flow data to understand the origin, nature, and impact of security incidents. This type of forensics directly addresses the capturing and analysis of data in transit across a network, making it the correct answer for examining network traffic.

Why this answer

Network forensics involves capturing, recording, and analyzing network traffic to investigate security incidents, identify intrusions, and gather evidence. It focuses on data in transit, such as packet captures, flow records, and network logs. This distinguishes it from host-based forensics.

Exam trap

CISSP often tests the distinction between network forensics and other types like memory or media forensics; candidates may confuse log analysis with network forensics because logs can be network-related, but the question specifies capturing and analyzing network traffic.

How to eliminate wrong answers

Option A is wrong because media analysis (or disk forensics) involves examining storage media like hard drives for artifacts, not network traffic. Option B is wrong because log analysis examines logs from various sources, which may include network devices, but it is not specifically about capturing and analyzing network traffic; it is a broader category. Option D is wrong because memory forensics analyzes volatile memory (RAM) for artifacts like running processes and encryption keys, not network traffic.

47
Multi-Selectmedium

An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?

Select 3 answers
A.Roles and responsibilities
B.Vendor product list
C.Employee performance reviews
D.Communication plan
E.Recovery procedures
AnswersA, D, E

Establishing clearly defined roles and responsibilities is a foundational requirement of an incident response plan. It ensures that the incident response team members, such as the incident commander, technical leads, and legal liaisons, understand their specific duties, preventing chaos and ensuring coordinated execution during a high-pressure security event.

Why this answer

Option A (Roles and responsibilities) is correct because an incident response plan must define who does what during an incident, assigning clear ownership of tasks such as detection, triage, containment, eradication, and recovery so that actions are not duplicated or missed. Option D (Communication plan) is correct because it specifies internal and external notification paths, escalation thresholds, contact trees, and stakeholder/customer/regulator messaging, which is essential for coordinated response and meeting breach-notification obligations. Option E (Recovery procedures) is correct because the plan must document the steps to restore affected systems and services to normal operation, including validation, prioritization, and return-to-production criteria.

Option B (Vendor product list) is not a required component; while asset and vendor inventories can support response, a mere product list is not part of the core plan structure. Option C (Employee performance reviews) is unrelated to incident response and belongs to HR performance management, not the IR plan.

Exam trap

CISSP often tests the confusion between core incident response plan components and ancillary documents like asset inventories or HR records, so candidates must recognize the three essential elements.

48
MCQhard

A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?

A.Hot site
B.Warm site
C.Cold site
D.Reciprocal agreement
AnswerA

A hot site represents a fully operational, mirror image of the primary production environment, complete with all necessary hardware, software, and up-to-date data. This configuration allows for near-instantaneous failover and activation, typically within 1-2 hours, minimizing both downtime (RTO) and data loss (RPO). Its readiness ensures business continuity for critical systems requiring the lowest possible recovery times.

Why this answer

A hot site is a fully equipped, mirrored facility with hardware, software, data replication, and network connectivity already in place, allowing operations to resume within minutes to a couple of hours. Because everything is pre-provisioned and continuously synchronized, it is the only DR site type that reliably meets a 2-hour RTO. Warm and cold sites require additional setup time that exceeds this window.

Exam trap

The trap here is confusing RTO with RPO — candidates who see '2 hours' may pick warm site thinking of backup frequency, but the question specifies operational recovery time, which demands a hot site.

How to eliminate wrong answers

Option B is wrong because a warm site has hardware and connectivity but requires restoring data and reconfiguring systems, typically taking 12-72 hours — too slow for a 2-hour RTO. Option C is wrong because a cold site is essentially empty space with power and cooling, requiring days to weeks to become operational. Option D is wrong because a reciprocal agreement relies on another organization's facility, which offers no guaranteed availability, no pre-staged equipment, and no defined RTO — it is the least reliable option.

49
Multi-Selecthard

A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?

Select 2 answers
A.Hot site
B.Reciprocal agreement
C.Warm site
D.Cloud DR with pre-configured instances
E.Cold site
AnswersA, D

A hot site is a fully equipped, mirrored data center with real-time or near real-time data replication from the primary site. It includes all necessary hardware, software, and network connectivity, allowing for immediate failover and minimal downtime. This strategy ensures the lowest possible Recovery Time Objective (RTO) by being continuously operational and ready for activation, making it ideal for mission-critical systems.

Why this answer

A hot site (A) is correct because it is a fully operational duplicate of the primary data center with hardware, software, and near-real-time replicated data already in place, so failover can occur in minutes or even seconds, yielding the shortest RTO. Cloud DR with pre-configured instances (D) is also correct because pre-provisioned, ready-to-launch compute instances and replicated data in the cloud allow rapid failover, typically within minutes, matching the low RTO requirement. By contrast, a reciprocal agreement (B) depends on another organization's spare capacity that may not be available or compatible during a widespread disaster, and a warm site (C) requires some configuration and data restoration before going live, while a cold site (E) provides only basic facilities with no pre-installed systems or data, resulting in the longest RTO of all options.

Exam trap

Candidates often overlook cloud-based disaster recovery options, but modern CISSP exams recognize Cloud DR (especially with pre-configured, warm, or hot standby instances) as a highly efficient, low-RTO alternative to traditional physical hot sites.

50
Multi-Selectmedium

A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?

Select 2 answers
A.Wireshark
B.EnCase
C.Volatility
D.Rekall
E.FTK Imager
AnswersC, D

Volatility is an industry-leading, open-source memory forensics framework specifically engineered to extract digital artifacts from volatile memory (RAM) samples. It allows security analysts to inspect the runtime state of a compromised system, identifying active processes, network connections, loaded kernel modules, and even extracting cached files, cryptographic keys, or injected code. Its extensive plugin architecture makes it indispensable for incident response, malware analysis, and advanced threat hunting by providing deep visibility into system memory.

Why this answer

Volatility (C) is the de facto open-source framework for memory forensics, designed to parse raw memory images and extract artifacts such as processes, network connections, and injected code via plugins. Rekall (D) is another memory forensics framework, originally forked from Volatility, that analyzes RAM dumps for malware and rootkit indicators. Both operate directly on memory captures, which is exactly what the analyst needs.

Wireshark (A) is a network protocol analyzer that inspects packet captures, not RAM dumps. EnCase (B) and FTK Imager (E) are disk imaging and file-system forensic tools, not memory analysis frameworks.

Exam trap

The trap here is that candidates confuse network forensics tools (Wireshark) or disk imaging tools (EnCase, FTK Imager) with memory-specific analysis tools, forgetting that RAM analysis requires specialized frameworks like Volatility or Rekall.

51
MCQeasy

What is the PRIMARY purpose of a chain of custody in digital forensics?

A.To document the tools used during investigation
B.To identify the perpetrator of a cybercrime
C.To speed up the forensic analysis process
D.To maintain evidence integrity and admissibility in court
AnswerD

The primary purpose of a chain of custody in digital forensics is to establish an unbroken, documented chronological record of the possession, handling, transfer, and analysis of digital evidence. This meticulous record demonstrates that the evidence has not been altered, substituted, or tampered with from the moment of its collection until its presentation in court, thereby preserving its integrity. By proving the evidence's authenticity and reliability, the chain of custody is absolutely critical for ensuring its legal admissibility and weight in any judicial proceeding.

Why this answer

A chain of custody is a chronological record documenting who collected, handled, transferred, and analyzed evidence, along with when and why each action occurred. Its primary purpose is to preserve evidence integrity and prove in court that the evidence was not tampered with, making it admissible under rules such as the Federal Rules of Evidence (FRE 901). Without an unbroken chain, opposing counsel can challenge authenticity and the evidence may be excluded.

Exam trap

CISSP often tests the distinction between the investigative goal (identifying the attacker) and the evidentiary requirement (proving integrity), so candidates who focus on 'catching the criminal' pick option B instead of the admissibility-focused answer.

How to eliminate wrong answers

Option A is wrong because documenting tools used is part of forensic reporting and methodology, not the purpose of chain of custody — tools documentation does not establish who had control of the evidence. Option B is wrong because identifying the perpetrator is the overall investigative goal, not the function of chain of custody; the chain proves evidence integrity, not guilt. Option C is wrong because chain of custody adds administrative overhead and does not speed up analysis — it can actually slow the process by requiring signatures and logs at each transfer.

52
MCQmedium

A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?

A.Enable SELinux in enforcing mode on each server and audit the resulting AVC denials daily.
B.Deploy a host-based intrusion detection agent that alerts the SOC whenever a failed logon threshold is exceeded.
C.Increase the local /var/log/secure rotation interval and set the file permissions to 600 on each server.
D.Configure rsyslog to forward authpriv facility messages to a remote log server that stores them on WORM media.
AnswerD

The authpriv facility carries authentication and authorization messages on Linux, so forwarding it to a hardened remote collector preserves the events. Writing to write-once media plus remote shipping makes the record tamper-evident and supports the one-year retention the auditor demands, because local compromise cannot silently rewrite already-archived entries.

Why this answer

Authentication events on Linux flow through the authpriv facility, so shipping those messages to a separate collector addresses both integrity and retention. Storing them on write-once media means a compromised server cannot alter history, and centralizing them satisfies the one-year retention demand. Local-only controls, SELinux auditing, and alerting tools each miss either the completeness or the tamper-evidence requirement.

Exam trap

The trap here is assuming that stronger local file permissions or SELinux enforcement make logs tamper-evident, when only off-host, append-only storage actually prevents a compromised server from rewriting its own history.

53
MCQmedium

A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?

A.Update the SIEM correlation rule to ignore similar alerts
B.Escalate the incident to Tier 2 analyst for further investigation
C.Disconnect the workstation from the network immediately
D.Perform a deep forensic analysis of the workstation
AnswerB

Escalating the incident to a Tier 2 analyst for further investigation is the correct and standard procedure for a Tier 1 SOC analyst who has identified a potential malware infection. Tier 1 analysts are primarily responsible for initial alert triage, basic investigation, and confirming the legitimacy of an alert. If the incident requires more advanced analysis, specialized tools, or decision-making beyond their scope, proper escalation ensures the incident is handled by personnel with the appropriate expertise and authority, following established incident response playbooks.

Why this answer

Tier 1 analysts typically triage alerts and escalate if they cannot resolve them.

54
Multi-Selectmedium

A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?

Select 2 answers
A.Change request
B.Denial of Service (DoS)
C.Patch management failure
D.Insider threat
E.Business continuity exercise
AnswersB, D

Denial of Service (DoS) is a critical incident category because it directly impacts the availability of systems and services, often rendering them inaccessible to legitimate users. This type of attack involves overwhelming a target with traffic or requests, consuming resources, and preventing normal operation. Such an event requires immediate incident response to restore service and mitigate ongoing impact.

Why this answer

Option B, Denial of Service (DoS), is a valid incident category because standard IR frameworks such as NIST SP 800-61 and SANS categorize attacks that degrade or block availability of systems and networks (e.g., volumetric floods, SYN floods, application-layer exhaustion) as a distinct incident type requiring specific detection and containment playbooks. Option D, Insider threat, is also a valid category because incidents involving authorized users—whether malicious, negligent, or compromised—such as data exfiltration, privilege abuse, or credential misuse are treated as a separate class due to their unique investigative and legal handling needs. The remaining options are not incident categories: A, Change request, is an ITIL change-management artifact, not an incident type; C, Patch management failure, is a vulnerability or configuration management issue that may contribute to an incident but is not itself a standard IR category; and E, Business continuity exercise, is a planned testing activity, not a security incident.

Exam trap

CISSP often tests whether candidates can distinguish actual incident categories from routine IT processes or preparedness activities, so they mistakenly select change requests or BC exercises as incident types.

Ready to test yourself?

Try a timed practice session using only Security Operations questions.