Courseiva

CCNA Security and Risk Management Questions

69 questions · Security and Risk Management · All types, answers revealed

1
MCQmedium

A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?

A.IT general controls for financial systems
B.Encryption of data at rest
C.Breach notification procedures
D.Privacy of customer data
AnswerA

The Sarbanes-Oxley Act (SOX) mandates that public companies establish and maintain internal controls over financial reporting. IT General Controls (ITGC) are foundational to this, ensuring the integrity, reliability, and security of the information systems that process financial data. These controls, encompassing areas like access management, change management, and operations, directly support the accuracy of financial statements, which is a core requirement of SOX Sections 302 and 404. Without robust ITGC, the reliability of financial data cannot be assured.

Why this answer

SOX Section 404 requires management to assess and auditors to attest to the effectiveness of internal controls over financial reporting (ICFR). IT general controls (ITGCs) — change management, access control, IT operations, and SDLC controls — are the primary mechanism by which IT supports that assertion for financial systems. Encryption, breach notification, and privacy are important but are not the defining IT compliance focus of SOX.

Exam trap

CISSP often tests the distinction between financial-reporting integrity regulations (SOX) and privacy/security regulations (GDPR, HIPAA, GLBA), so candidates who see 'encryption' or 'breach notification' and assume they are SOX requirements pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because encryption of data at rest is a security control that may support SOX compliance but is not the key IT focus area SOX mandates; SOX does not prescribe specific cryptographic controls. Option C is wrong because breach notification procedures are driven by state breach laws, HIPAA, and GDPR-style regulations, not SOX, which addresses financial reporting integrity. Option D is wrong because privacy of customer data is the domain of privacy regulations (GDPR, CCPA, GLBA privacy provisions), whereas SOX targets the accuracy and reliability of financial disclosures.

2
MCQmedium

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

A.Restrict physical access to cardholder data
B.Encrypt transmission of cardholder data over open networks
C.Install and maintain a firewall configuration
D.Protect stored cardholder data
AnswerD

Protecting stored cardholder data is precisely what PCI DSS Requirement 3 mandates, making this the correct answer. This requirement specifically addresses data at rest, compelling organizations to render cardholder data unreadable through methods such as strong encryption, truncation, masking, or tokenization when it is stored on systems, databases, or other media, thereby minimizing its value if a breach occurs.

Why this answer

PCI DSS Requirement 3 is 'Protect stored cardholder data,' which specifically addresses data at rest through encryption, truncation, masking, and hashing. This requirement mandates protections for cardholder data wherever it is stored, including databases, files, and backups.

Exam trap

CISSP often tests the confusion between data-at-rest and data-in-transit requirements, and candidates may incorrectly associate physical access or firewalls with protecting stored data.

How to eliminate wrong answers

Option A is wrong because restricting physical access to cardholder data is part of Requirement 9 (Restrict physical access to cardholder data), which covers physical security, not data-at-rest encryption. Option B is wrong because encrypting transmission of cardholder data over open networks is Requirement 4 (Encrypt transmission of cardholder data across open, public networks), which addresses data in transit. Option C is wrong because installing and maintaining a firewall configuration is Requirement 1, which focuses on network security controls, not storage protection.

3
MCQeasy

Which component of the CIA triad ensures that information is not disclosed to unauthorized individuals, entities, or processes?

A.Non-repudiation
B.Integrity
C.Availability
D.Confidentiality
AnswerD

Confidentiality is the core principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. It involves protecting sensitive data from being viewed or accessed by those without the proper clearance or need-to-know. Encryption, access controls, and proper data handling policies are primary mechanisms used to uphold confidentiality, directly addressing the prevention of unauthorized disclosure.

Why this answer

Confidentiality is the core security objective that ensures information is not disclosed to unauthorized individuals, entities, or processes. It is achieved through mechanisms such as encryption, access control lists, and data classification. The CIA triad defines confidentiality as the opposite of disclosure, directly matching the question's wording.

Thus, option D is correct.

Exam trap

CISSP often tests the distinction between confidentiality and integrity by using similar phrasing like 'unauthorized disclosure' versus 'unauthorized modification', so candidates must map the exact wording to the correct CIA component.

How to eliminate wrong answers

Option A is wrong because non-repudiation ensures that a party cannot deny having performed an action, typically via digital signatures or audit logs, and does not address unauthorized disclosure. Option B is wrong because integrity ensures data is not modified or destroyed in an unauthorized manner, focusing on accuracy and completeness rather than secrecy. Option C is wrong because availability ensures timely and reliable access to information by authorized users, not the prevention of disclosure to unauthorized ones.

4
MCQmedium

During a business impact analysis (BIA), which metric represents the maximum amount of time a business process can be disrupted before causing significant harm to the organization?

A.Work Recovery Time (WRT)
B.Recovery Point Objective (RPO)
C.Maximum Tolerable Period of Disruption (MTPD)
D.Recovery Time Objective (RTO)
AnswerC

The Maximum Tolerable Period of Disruption (MTPD), also known as Maximum Tolerable Downtime (MTD), is the absolute longest period a business process or function can be inoperative before experiencing unacceptable consequences. This critical metric, determined during a Business Impact Analysis (BIA), establishes the ultimate deadline for recovery, guiding the prioritization of resources and recovery strategies to prevent severe organizational harm.

Why this answer

The Maximum Tolerable Period of Disruption (MTPD) is the metric defined during a BIA that captures the absolute upper bound of time a business process can be unavailable before the organization suffers unacceptable or significant harm. It is derived from business-side impact analysis (financial, regulatory, reputational) rather than technical recovery capabilities, and it serves as the ceiling from which RTO is derived. Because MTPD represents the business's tolerance limit, it is the correct answer for the maximum disruption time before significant harm.

Exam trap

CISSP often tests the confusion between business-driven MTPD and technology-driven RTO, tricking candidates into selecting RTO because it sounds like the 'maximum time' a system can be down.

How to eliminate wrong answers

Option A is wrong because Work Recovery Time (WRT) is the time needed after systems are restored to verify data integrity, catch up on backlogged transactions, and resume normal business processing — it is a component of the overall recovery window, not the maximum tolerable disruption. Option B is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (how far back a restore point can be), not the duration of process disruption. Option D is wrong because Recovery Time Objective (RTO) is the target time set for restoring a process or system after disruption — it is a technical/operational goal that must be less than MTPD, not the maximum tolerable disruption itself.

5
MCQhard

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

A.A memorandum of understanding (MOU)
B.A data processing agreement under GDPR
C.A consent form from each patient
D.A business associate agreement (BAA)
AnswerD

A Business Associate Agreement (BAA) is a legally mandated contract under HIPAA that must be established between a covered entity and its business associates before Protected Health Information (PHI) is shared. This agreement obligates the business associate to implement specific administrative, physical, and technical safeguards to protect PHI, adhering to the HIPAA Security and Privacy Rules. The BAA ensures accountability and extends the covered entity's compliance responsibilities to third parties handling PHI on its behalf, making it the correct and essential mechanism for such sharing.

Why this answer

Under HIPAA, a covered entity sharing PHI with a third-party vendor that performs a function involving PHI must have a Business Associate Agreement (BAA) in place. The BAA contractually obligates the business associate to safeguard PHI and comply with HIPAA Privacy and Security Rules. This is a legal requirement, not optional.

Exam trap

CISSP often tests whether candidates confuse HIPAA's BAA with GDPR's DPA or generic MOUs; the trap is picking a plausible-sounding agreement that does not carry HIPAA's specific legal obligations.

How to eliminate wrong answers

Option A is wrong because an MOU is a general non-binding or loosely binding agreement that does not satisfy HIPAA's specific contractual requirements for business associates. Option B is wrong because GDPR's Data Processing Agreement applies to EU personal data and does not fulfill HIPAA obligations for PHI in the US. Option C is wrong because individual patient consent does not replace the BAA requirement; HIPAA permits certain disclosures for treatment, payment, and operations without consent, but the BAA is still mandatory for business associates.

6
MCQeasy

Which document is mandatory, high-level, and sets the direction for security within an organization?

A.Policy
B.Standard
C.Procedure
D.Baseline
AnswerA

A policy is a mandatory, high-level statement approved by management, articulating the organization's strategic intent and overarching requirements for information security. It establishes the fundamental rules and direction for protecting assets, often driven by legal, regulatory, or business imperatives, without specifying technical details. Policies are foundational, setting the broad scope and purpose of security efforts across the enterprise.

Why this answer

A security policy is a mandatory, high-level document that defines an organization's security objectives, principles, and management intent. It sets direction and assigns responsibility without prescribing specific technical implementations. Standards, procedures, and baselines all derive from and must comply with the policy, making policy the authoritative top-level document.

Exam trap

CISSP often tests the distinction between mandatory vs. advisory and high-level vs. detailed, since policy, standard, procedure, and baseline are all part of the same hierarchy but differ in authority, specificity, and audience.

How to eliminate wrong answers

Option B is wrong because a standard is a mandatory, more detailed document that specifies uniform technical or operational requirements to support the policy — it is lower-level and more prescriptive. Option C is wrong because a procedure is a step-by-step operational instruction for performing a task, which is tactical rather than directional. Option D is wrong because a baseline is a minimum set of security configurations for a specific system or category, derived from standards, and is technical rather than high-level.

7
MCQhard

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

A.$7,500
B.$30,000
C.$15,000
D.$75,000
AnswerA

This value correctly represents the Annualized Loss Expectancy (ALE), which is a key metric in quantitative risk analysis. It is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Assuming an SLE of $15,000 and an ARO of 0.5 (meaning the event is expected to occur once every two years), the ALE is $15,000 * 0.5 = $7,500. This figure quantifies the expected financial loss from a specific risk over a one-year period, informing cost-benefit analyses for security controls.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as SLE × ARO. With an SLE of $15,000 and an ARO of 0.5, the ALE is $15,000 × 0.5 = $7,500. This represents the expected yearly financial loss from a given risk, factoring in both the impact per incident and how often it is expected to occur.

Exam trap

CISSP often tests the confusion between SLE, ARO, and ALE, and candidates may mistakenly multiply by the reciprocal of ARO or forget to multiply at all, leading to selecting the SLE or an inflated value.

How to eliminate wrong answers

Option B is wrong because $30,000 results from multiplying SLE by 2 (the reciprocal of ARO), which would be appropriate if the ARO were 2.0, not 0.5. Option C is wrong because $15,000 is simply the SLE, ignoring the ARO entirely; it would only be the ALE if the ARO were 1.0. Option D is wrong because $75,000 is five times the SLE, which would require an ARO of 5.0, not 0.5.

8
Multi-Selectmedium

Which TWO of the following are lawful bases for processing personal data under the GDPR? (Select two)

Select 2 answers
A.Data subject's employment status
B.Data subject's nationality
C.Consent of the data subject
D.Legitimate interests of the controller
E.Profit maximization
AnswersC, D

Consent is a fundamental lawful basis where the data subject explicitly and unambiguously agrees to the processing of their personal data for a specific purpose. For consent to be valid, it must be freely given, specific, informed, and an unambiguous indication of the data subject's wishes, often requiring a clear affirmative action. This places control directly with the individual.

Why this answer

Option C (Consent of the data subject) is correct because Article 6(1)(a) of the GDPR expressly lists the data subject's consent as a lawful basis for processing personal data, provided it is freely given, specific, informed, and unambiguous. Option D (Legitimate interests of the controller) is correct because Article 6(1)(f) recognizes the legitimate interests pursued by the controller or a third party as a lawful basis, subject to a balancing test against the data subject's rights and freedoms. Options A (employment status) and B (nationality) are not lawful bases; they are merely categories of personal data, and nationality can even constitute special category data under Article 9.

Option E (profit maximization) is not a lawful basis; it is a business objective that must still be grounded in one of the Article 6(1) legal grounds, such as legitimate interests, to be lawful.

Exam trap

The trap is assuming any business rationale (like profit) or personal attribute (like nationality) can be a lawful basis; GDPR requires one of six specific bases, and candidates often overlook that legitimate interests must be balanced and documented.

9
Multi-Selectmedium

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

Select 3 answers
A.Critical business processes
B.Maximum tolerable downtime (MTD)
C.Preferred vendor contracts
D.Recovery point objective (RPO)
E.Employee performance metrics
AnswersA, B, D

The primary objective of a Business Impact Analysis (BIA) is to identify and prioritize the organization's critical business processes. By distinguishing core operations from non-essential ones, the BIA allows planners to allocate recovery resources effectively and establish realistic recovery timelines. Without this inventory, the BCP cannot target the most vital survival functions of the enterprise.

Why this answer

A BIA identifies critical business processes (A) because it must determine which functions are essential to the organization's survival and prioritize them for recovery. It also establishes the maximum tolerable downtime (B), the longest time a process can be unavailable before causing unacceptable harm, which drives recovery strategies. The recovery point objective (D) is likewise derived during the BIA, defining the maximum acceptable data loss measured in time and setting backup frequency requirements.

Preferred vendor contracts (C) are procurement/legal artifacts addressed during recovery planning or supply-chain review, not core BIA outputs. Employee performance metrics (E) belong to HR performance management and are unrelated to continuity impact analysis.

Exam trap

CISSP often tests the confusion between BIA outputs and other planning artifacts, such as vendor contracts or HR metrics, which are not part of the BIA scope.

10
MCQhard

A company's disaster recovery plan includes an agreement with another company to provide backup computing facilities in case of a disaster. The agreement allows the second company to use the facilities for its own operations if needed. This arrangement is best described as:

A.Hot site
B.Warm site
C.Cold site
D.Reciprocal agreement
AnswerD

A reciprocal agreement is a mutual arrangement between two organizations, often competitors or peers, to provide each other with backup facilities, equipment, or resources in the event of a disaster. This type of agreement directly addresses the concept of 'an agreement with' another entity to ensure business continuity, leveraging shared risk and resources rather than dedicated, pre-built recovery sites.

Why this answer

A reciprocal agreement is a mutual arrangement where two organizations agree to provide backup computing facilities to each other in the event of a disaster. Because the second company can also use the facilities for its own operations, the arrangement is explicitly reciprocal rather than a one-way commercial contract. Hot, warm, and cold sites are unilateral facility types owned or leased by the primary organization, not mutual sharing agreements.

Exam trap

The trap is the phrase 'the second company can use the facilities for its own operations' — candidates may focus on the facility type (hot/warm/cold) and miss that mutuality is the defining characteristic of a reciprocal agreement.

How to eliminate wrong answers

Option A (Hot site) is wrong because a hot site is a fully equipped, immediately available alternate facility — typically owned or leased by the primary organization, not shared reciprocally with another company. Option B (Warm site) is wrong because a warm site is a partially equipped facility with some hardware and connectivity, again unilateral rather than a mutual agreement. Option C (Cold site) is wrong because a cold site provides only basic infrastructure (power, cooling, space) with no pre-installed systems, and it is not defined by a reciprocal sharing arrangement.

11
MCQeasy

Which of the following is the correct order of the ISC2 Code of Ethics canons from highest to lowest priority?

A.Protect society, act honorably, provide diligent service, advance the profession
B.Act honorably, protect society, provide diligent service, advance the profession
C.Advance the profession, protect society, act honorably, provide diligent service
D.Provide diligent service, advance the profession, protect society, act honorably
AnswerA

This sequence precisely matches the four canons of the (ISC)² Code of Ethics, which are hierarchically ordered to guide cybersecurity professionals. The primary responsibility is to protect society, followed by acting honorably, providing diligent service to principals, and finally advancing the profession. This specific order reflects the increasing scope of responsibility, from global impact to individual professional growth, making it the correct representation of the ethical framework.

Why this answer

The ISC2 Code of Ethics canons are ordered by priority: (1) Protect society, the common good, necessary public trust and confidence, and the infrastructure; (2) Act honorably, honestly, justly, responsibly, and legally; (3) Provide diligent and competent service to principals; (4) Advance and protect the profession. Option A lists them in this exact order, making it correct. This hierarchy is critical because when canons conflict, the higher one must take precedence.

Exam trap

CISSP often tests the exact ordering of the Code of Ethics canons, and candidates frequently misremember 'Act honorably' as the top priority because it sounds noble; the trap is forgetting that 'Protect society' is explicitly first.

How to eliminate wrong answers

Option B is wrong because it places 'Act honorably' above 'Protect society,' reversing the top two canons; society and public trust always outrank personal honor. Option C is wrong because it puts 'Advance the profession' first, which is actually the lowest priority canon, and demotes 'Protect society' to second. Option D is wrong because it places 'Provide diligent service' first, but service to principals ranks third, below both society and honorable conduct.

12
Multi-Selecthard

Under GDPR, which TWO of the following are valid lawful bases for processing personal data?

Select 2 answers
A.Data subject's employment
B.Data processor's request
C.Consent
D.Legitimate interest
E.Data controller's profit
AnswersC, D

Consent is a valid lawful basis under GDPR Article 6(1)(a) when the data subject has given their explicit agreement to the processing of their personal data for one or more specific purposes. For consent to be valid, it must be freely given, specific, informed, and unambiguous, signified by a clear affirmative action. Furthermore, the data subject must be able to withdraw their consent as easily as they gave it, and the controller must be able to demonstrate that consent was obtained.

Why this answer

Under GDPR Article 6(1), the six lawful bases for processing personal data include consent (option C), where the data subject has given clear, specific, informed, and unambiguous agreement, and legitimate interest (option D), where processing is necessary for the legitimate interests pursued by the controller or a third party unless overridden by the data subject's rights and interests. These are both explicitly enumerated lawful bases, making C and D correct. Option A (data subject's employment) is not a lawful basis under Article 6; employment status is not one of the six grounds, though employment context may affect consent validity or other bases.

Option B (data processor's request) is invalid because a processor acts only on the controller's documented instructions and cannot itself create a lawful basis for processing. Option E (data controller's profit) is not a recognized lawful basis; profit alone does not satisfy any Article 6 condition, though it might be considered under legitimate interest only if the balancing test is met.

Exam trap

The trap is selecting plausible-sounding but non-existent bases like 'employment' or 'profit' — candidates must recall the exact six Article 6 bases rather than reasoning from business context.

13
MCQmedium

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

A.Provide diligent and competent service to principals
B.Act honorably, honestly, justly, responsibly, and legally
C.Protect society, the common good, and the infrastructure
D.Advance and protect the profession
AnswerC

This is the correct answer because it represents the first and highest priority canon in the (ISC)² Code of Ethics. It mandates that certified professionals prioritize the safety, welfare, and security of the public, critical systems, and shared resources above all other considerations. This overarching responsibility ensures that individual or organizational interests never compromise the broader societal well-being or the integrity of essential information technology infrastructure.

Why this answer

The ISC2 Code of Ethics canons are ordered by precedence, and the first canon—'Protect society, the common good, and the infrastructure'—takes priority over all others. This means that when ethical obligations conflict, a CISSP must prioritize the safety and well-being of society and critical infrastructure above duties to clients, employers, or the profession. The remaining canons are subordinate and must be interpreted in light of this primary obligation.

Exam trap

CISSP often tests the specific order of the ISC2 Code of Ethics canons, and candidates frequently misremember which canon is first or assume all canons are equal in weight.

How to eliminate wrong answers

Option A is wrong because 'Provide diligent and competent service to principals' is the third canon, which applies after the first two and does not take precedence. Option B is wrong because 'Act honorably, honestly, justly, responsibly, and legally' is the second canon, subordinate to the first. Option D is wrong because 'Advance and protect the profession' is the fourth and final canon, which is important but has the lowest precedence among the four.

14
MCQmedium

A security manager is calculating the annual loss expectancy (ALE) for a server valued at $50,000. The exposure factor (EF) is 40%, and the annual rate of occurrence (ARO) is 0.5. What is the ALE?

A.$10,000
B.$100,000
C.$25,000
D.$20,000
AnswerA

This option correctly calculates the Annual Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Subsequently, multiplying this SLE by the ARO (0.5) yields the correct ALE of $10,000, representing the expected financial loss from this specific risk over a year.

Why this answer

ALE is calculated as SLE × ARO, where SLE = Asset Value × Exposure Factor. Here, SLE = $50,000 × 0.40 = $20,000, and ALE = $20,000 × 0.5 = $10,000. This quantifies the expected yearly monetary loss from the risk, which is the standard CISSP quantitative risk analysis formula.

Exam trap

CISSP often tests the distinction between SLE and ALE — candidates frequently stop at SLE ($20,000) and forget to multiply by the ARO, or they confuse ARO with EF in the formula.

How to eliminate wrong answers

Option B is wrong because $100,000 would result from multiplying the asset value by 2 (an ARO of 2 with 100% EF), which misapplies the formula and ignores the 40% exposure factor. Option C is wrong because $25,000 equals half the asset value, which would only be correct if EF were 100% and ARO were 0.5, ignoring the stated 40% exposure factor. Option D is wrong because $20,000 is the Single Loss Expectancy (SLE), not the ALE — it omits the multiplication by the ARO of 0.5.

15
MCQmedium

An organization is implementing a new access control system. The security team wants to ensure that users cannot deny having performed an action. Which security principle is being addressed?

A.Availability
B.Integrity
C.Confidentiality
D.Non-repudiation
AnswerD

Non-repudiation provides irrefutable proof that a specific action or event has occurred and that a particular entity was responsible for it, preventing them from later denying their involvement. This is typically achieved through robust audit trails, digital signatures, and secure logging mechanisms that cryptographically link an action to a user. Therefore, it directly addresses the requirement to prevent users from disclaiming responsibility for their actions within an access control system.

Why this answer

Non-repudiation is the security principle that ensures a party to a communication or transaction cannot later deny having performed that action. It is typically achieved through digital signatures, audit logs, and cryptographic proof of origin and delivery. The question directly describes the inability to deny an action, which is the textbook definition of non-repudiation.

Exam trap

CISSP often tests the distinction between integrity and non-repudiation, as both involve protecting data from unauthorized changes; candidates may incorrectly choose integrity when the scenario emphasizes denying an action.

How to eliminate wrong answers

Option A is wrong because availability ensures systems and data are accessible to authorized users when needed, not that actions can be proven. Option B is wrong because integrity ensures data has not been altered or tampered with, but does not prevent a user from denying they performed an action. Option C is wrong because confidentiality ensures data is only disclosed to authorized parties, which is unrelated to proving an action occurred.

16
MCQeasy

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

A.$10,000
B.$100,000
C.$50,000
D.$20,000
AnswerA

This value represents the Annualized Loss Expectancy (ALE), which is derived by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). Given an SLE of $50,000 and an ARO of 0.2 (meaning a 20% chance of the event occurring annually), the correct ALE calculation is $50,000 * 0.2, resulting in $10,000. This figure quantifies the expected financial loss from a specific risk over a one-year period.

Why this answer

The annualized loss expectancy (ALE) is calculated as single loss expectancy (SLE) multiplied by annualized rate of occurrence (ARO). SLE is asset value ($100,000) times exposure factor (0.5), yielding $50,000. Multiplying by ARO (0.2) gives ALE = $50,000 * 0.2 = $10,000.

Thus, $10,000 is the correct answer.

Exam trap

CISSP often tests the mistake of confusing SLE with ALE or forgetting to multiply by ARO; candidates may incorrectly use asset value directly or omit the exposure factor.

How to eliminate wrong answers

Option B ($100,000) is wrong because it represents the full asset value, not the expected annual loss. Option C ($50,000) is wrong because it is the SLE, not adjusted for ARO. Option D ($20,000) is wrong because it incorrectly multiplies asset value by ARO without applying the exposure factor.

17
MCQeasy

Which of the following is an example of a security policy?

A.Step 1: Log in, Step 2: Enter code, Step 3: Access system
B.It is recommended to change passwords every 90 days
C.All employees must use multi-factor authentication
D.Use passwords of at least 12 characters with mixed case and numbers
AnswerC

A security policy is a high-level, mandatory statement issued by management that defines the organization's overall security objectives and requirements. This statement clearly dictates a non-negotiable requirement for all employees, establishing a foundational security control to protect organizational assets. It addresses *what* is required for security, without specifying the technical implementation details.

Why this answer

A security policy is a high-level statement of management intent that mandates required behavior. 'All employees must use multi-factor authentication' is a directive, organization-wide requirement, which is the defining characteristic of a policy.

Exam trap

The trap is confusing a standard with a policy — candidates pick D because it sounds security-related, but specific password rules are a standard, while a policy is a mandatory high-level directive.

How to eliminate wrong answers

Option A is wrong because it describes a procedure — a step-by-step operational instruction for performing a task. Option B is wrong because 'It is recommended' indicates a guideline or best practice, not a mandatory policy; policies use mandatory language like 'must' or 'shall'. Option D is wrong because it specifies a technical standard (password length and complexity), which is a standard or baseline, not a policy statement.

18
MCQmedium

Under GDPR, which of the following is a valid lawful basis for processing personal data?

A.Corporate policy
B.Profit motive
C.Marketing preference
D.Vital interests
AnswerD

Vital interests is a lawful basis under GDPR Article 6(1)(d) that permits the processing of personal data when it is necessary to protect the life of the data subject or another natural person. This basis is typically invoked in emergency situations where obtaining consent is impossible or impractical, such as medical emergencies, humanitarian crises, or public health threats. It represents a very high threshold and is generally reserved for situations involving a serious threat to life or physical integrity, making it a basis of last resort rather than routine processing.

Why this answer

GDPR Article 6(1) lists six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests. 'Vital interests' is one of these — it covers processing necessary to protect someone's life.

Exam trap

CISSP often tests whether candidates can distinguish the six GDPR lawful bases from business justifications, and the trap is picking 'legitimate interests'-sounding answers like 'profit motive' or 'corporate policy' that are not enumerated in Article 6.

How to eliminate wrong answers

Option A is wrong because 'corporate policy' is not a GDPR lawful basis — an internal policy cannot override the need for a legal ground under Article 6. Option B is wrong because 'profit motive' is not a lawful basis; commercial gain falls under 'legitimate interests' only if balanced against data subject rights, and even then it is not the same as a profit motive per se. Option C is wrong because 'marketing preference' is not a lawful basis — marketing typically relies on consent or legitimate interests, and a preference alone does not satisfy Article 6.

19
MCQmedium

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

A.High risk
B.Medium risk
C.Low risk
D.De minimis risk
AnswerA

In a qualitative risk assessment, "High risk" is assigned when both the likelihood of a threat event occurring and the potential impact of that event on organizational assets or operations are rated as high or critical. This combination signifies a significant exposure that demands immediate attention and substantial resource allocation for mitigation, as the potential for severe damage is both probable and substantial.

Why this answer

In a qualitative risk matrix, likelihood and impact ratings are combined to produce an overall risk level. A 'High' likelihood paired with a 'Critical' impact sits at the top of the matrix and is classified as High risk, warranting immediate treatment. Lower combinations (e.g., High likelihood + Low impact) would map to Medium or Low.

Exam trap

CISSP often tests the risk matrix combination logic; candidates overthink and pick Medium assuming 'averaging' of High and Critical, when the matrix maps the highest likelihood-impact pair to High risk.

How to eliminate wrong answers

Option B is wrong because Medium risk results from moderate combinations such as High likelihood with Low/Medium impact or Medium likelihood with Medium impact — not High + Critical. Option C is wrong because Low risk corresponds to low likelihood and/or low impact combinations. Option D is wrong because 'de minimis' risk refers to a negligible level below Low, which cannot result from the highest likelihood and highest impact ratings.

20
MCQeasy

Which component of the AAA framework is responsible for determining what resources a user can access and what actions they can perform?

A.Auditing
B.Authentication
C.Accounting
D.Authorization
AnswerD

Authorization is the critical component of the AAA framework responsible for determining what actions an authenticated user or system is permitted to perform on a resource. After identity verification, authorization mechanisms consult policies and access control lists (ACLs) to decide "what you are allowed to do," granting or denying specific privileges based on the user's role, group membership, or other attributes. This directly addresses the question of defining permissions.

Why this answer

Authorization is the AAA component that determines what resources a user can access and what actions they can perform after identity has been verified. It evaluates access policies, group memberships, and permissions to grant or deny specific operations. Authentication proves identity, accounting tracks activity, and auditing reviews logs — none of these define access rights.

Exam trap

CISSP often tests the distinction between authentication (identity verification) and authorization (access rights), causing candidates to confuse 'who you are' with 'what you can do'.

How to eliminate wrong answers

Option A is wrong because auditing is the retrospective review of logs and events to verify compliance and detect anomalies, not the real-time granting of access rights. Option B is wrong because authentication only verifies the identity of a user (e.g., via password, token, or biometrics) and does not determine what that user is permitted to do. Option C is wrong because accounting (also called auditing in some frameworks) tracks resource consumption and session activity for billing or forensic purposes, not access decisions.

21
MCQmedium

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

A.Warm site
B.Cold site
C.Hot site
D.Reciprocal agreement
AnswerC

A hot site is a fully operational, mirrored facility that replicates the primary production environment with identical hardware, software, and up-to-date data, often synchronized in real-time. This comprehensive setup allows for immediate failover in the event of a disaster, ensuring minimal data loss and near-zero downtime. A hot site achieves the lowest Recovery Time Objective (RTO) and Recovery Point Objective (RPO), making it the optimal choice for critical applications requiring continuous availability and rapid business continuity.

Why this answer

A hot site is a fully operational duplicate of the primary environment with real-time or near-real-time data replication, so it can take over almost immediately. This yields the shortest RTO (minutes) and RPO (near zero) of the options listed, at the highest cost.

Exam trap

The trap is assuming a reciprocal agreement is fast because it is a formal arrangement — candidates pick D, but reciprocal agreements offer poor RTO/RPO because capacity and readiness are not guaranteed.

How to eliminate wrong answers

Option A is wrong because a warm site has hardware and some data but requires configuration and restoration before it can operate, giving an RTO of hours to days and a higher RPO. Option B is wrong because a cold site is just space and power with no pre-installed equipment, resulting in the longest RTO (days to weeks) and RPO. Option D is wrong because a reciprocal agreement is a mutual arrangement with another organization to use their facilities in an emergency; it is unreliable, hard to test, and typically offers poor RTO/RPO because capacity and compatibility are not guaranteed.

22
MCQhard

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

A.Avoid
B.Mitigate
C.Transfer
D.Accept
AnswerD

Accepting the risk means consciously deciding to take no action to reduce the likelihood or impact of a risk, and instead bearing the potential consequences if the risk materializes. This strategy is economically sound and appropriate when the cost of implementing any other risk response, such as mitigation or transfer, is greater than the potential financial loss that would be incurred if the risk event occurs. For high-likelihood, low-impact risks where response costs exceed potential losses, acceptance is the most pragmatic and cost-effective approach.

Why this answer

Risk acceptance is the appropriate response when the cost of mitigating a risk exceeds the potential loss and the risk falls within the organization's risk tolerance. For a high-likelihood, low-impact risk where mitigation is not cost-effective, accepting the risk (with documented awareness and monitoring) is the rational business decision.

Exam trap

CISSP often tests whether candidates reflexively choose 'mitigate' as the 'safest' answer, ignoring the cost-benefit analysis that makes acceptance the correct business-aligned choice.

How to eliminate wrong answers

Option A is wrong because avoidance requires eliminating the activity or asset that creates the risk, which is disproportionate for a low-impact risk and would disrupt business operations. Option B is wrong because mitigation is explicitly ruled out by the scenario — the cost of mitigation exceeds the potential loss, so spending more than the risk is worth is not justified. Option C is wrong because transfer (e.g., insurance, outsourcing) is typically used for low-likelihood, high-impact risks where the financial exposure is significant enough to warrant paying a third party to absorb it.

23
MCQmedium

An organization is implementing a BCP. After completing the BIA, which of the following is the next logical step in the planning process?

A.Develop recovery strategies
B.Test the plan
C.Conduct a risk assessment
D.Train personnel
AnswerA

Developing recovery strategies is the direct and logical next step after completing a Business Impact Analysis (BIA). The BIA identifies critical business functions, their Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs), essentially defining *what* needs to be recovered and *how quickly*. Based on these findings, the organization then determines the *how* by selecting and designing appropriate recovery strategies, such as hot sites, warm sites, or reciprocal agreements, to meet those defined objectives.

Why this answer

After the BIA identifies critical processes and recovery requirements, the next step is to develop strategies to meet those requirements, such as selecting recovery sites and technologies.

24
MCQmedium

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

A.Work Recovery Time (WRT)
B.Maximum Tolerable Period of Disruption (MTPD)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerB

The Maximum Tolerable Period of Disruption (MTPD) represents the absolute longest time a business process or function can be inoperative before the organization experiences unacceptable consequences, such as significant financial loss, regulatory penalties, or irreparable reputational damage. It is a critical business-driven metric established during the BIA, defining the ultimate threshold for downtime that the business can endure without suffering severe harm. All recovery objectives, including RTO, must be set to ensure MTPD is not exceeded.

Why this answer

The Maximum Tolerable Period of Disruption (MTPD) is the metric that defines the longest time a business process can be unavailable before its disruption causes unacceptable harm to the organization. It is determined during the BIA and sets the upper bound from which RTO and RPO are derived. MTPD is sometimes called Maximum Allowable Downtime (MAD).

Exam trap

CISSP often tests the subtle distinction between MTPD (business tolerance limit) and RTO (technical recovery target), causing candidates to pick RTO because it sounds like the time to recover rather than the maximum tolerable outage.

How to eliminate wrong answers

Option A is wrong because Work Recovery Time (WRT) is the time needed after systems are restored to verify data integrity and resume normal business processing, not the maximum tolerable outage. Option C is wrong because Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time (how far back the last good backup must be), not the tolerable downtime. Option D is wrong because Recovery Time Objective (RTO) is the target time to restore a process after disruption, which must be less than or equal to MTPD, not the maximum tolerable period itself.

25
MCQmedium

A company is implementing a risk management program. They have identified a critical server with an asset value of $50,000. The exposure factor due to a potential threat is 40%, and the annual rate of occurrence is 2. What is the Annualized Loss Expectancy (ALE)?

A.$50,000
B.$40,000
C.$20,000
D.$100,000
AnswerB

This option correctly calculates the Annualized Loss Expectancy (ALE) by first determining the Single Loss Expectancy (SLE) and then multiplying it by the Annualized Rate of Occurrence (ARO). The SLE is derived from the Asset Value ($50,000) multiplied by the Exposure Factor (0.4), resulting in $20,000. Multiplying this SLE by the ARO of 2 yields an ALE of $40,000, representing the expected financial loss from this specific risk over a year.

Why this answer

ALE = SLE × ARO, where SLE = Asset Value × Exposure Factor. Here SLE = $50,000 × 0.40 = $20,000, and ARO = 2, so ALE = $20,000 × 2 = $40,000. This quantifies the expected annual monetary loss from the threat, which is used to justify security controls whose cost is less than the ALE.

Exam trap

CISSP often tests whether candidates correctly separate SLE from ALE — the trap is stopping at SLE ($20,000) or multiplying AV by ARO without applying the exposure factor.

How to eliminate wrong answers

Option A is wrong because $50,000 is the raw asset value (AV), not adjusted for exposure factor or annualized occurrence. Option C is wrong because $20,000 is the Single Loss Expectancy (SLE = AV × EF), which represents loss per incident, not per year. Option D is wrong because $100,000 would result from multiplying AV by ARO without applying the exposure factor (50,000 × 2), ignoring that only 40% of the asset is exposed per incident.

26
MCQmedium

Which of the following is the correct order of priority for the ISC2 Code of Ethics Canons?

A.Advance the profession, protect society, act honorably, provide diligent service
B.Protect society, act honorably, provide diligent service, advance the profession
C.Provide diligent service, protect society, act honorably, advance the profession
D.Act honorably, provide diligent service, protect society, advance the profession
AnswerB

This sequence accurately represents the correct hierarchical order of the (ISC)² Code of Ethics Canons. "Protect Society, the Commonwealth, and the Infrastructure" is the foundational and highest-priority canon, followed by "Act honorably, honestly, justly, responsibly, and legally," then "Provide diligent and competent service to principals and the profession," and finally, "Advance and protect the profession."

Why this answer

The ISC2 Code of Ethics Canons are ordered by priority: Protect society, the common good, necessary public trust and confidence, and the infrastructure; Act honorably, honestly, justly, responsibly, and legally; Provide diligent and competent service to principals; and Advance and protect the profession. Option B correctly lists this order.

Exam trap

CISSP often tests the exact order of the Code of Ethics Canons, and candidates frequently misremember 'Advance the profession' as a high priority when it is actually last.

How to eliminate wrong answers

Option A is wrong because it places 'Advance the profession' first, but the profession is the lowest priority in the canon order. Option C is wrong because it places 'Provide diligent service' first, but service to principals ranks third, after society and honorable conduct. Option D is wrong because it places 'Act honorably' first, but protection of society is the highest priority and must come before honorable conduct.

27
MCQhard

A company uses a qualitative risk analysis matrix where likelihood ranges from 1 to 5 and impact ranges from 1 to 5. A risk with a likelihood of 4 and an impact of 5 would fall into which risk level if the matrix defines high risk as scores above 15, medium as 10-15, and low as below 10?

A.Medium
B.Critical
C.High
D.Low
AnswerC

According to the company's qualitative risk analysis matrix, a risk score of 20 exceeds the established threshold of 15, which delineates the boundary for 'High' risk. This indicates that any risk with a numerical assessment equal to or greater than 15 is categorized into the 'High' severity level. Consequently, a score of 20 directly and correctly maps to a 'High' risk classification within this framework.

Why this answer

The risk score is calculated as likelihood × impact = 4 × 5 = 20. The matrix defines high risk as scores above 15, and 20 exceeds 15, so the risk falls into the High category. This is a straightforward application of the qualitative risk scoring formula used in the scenario.

Exam trap

CISSP often tests whether candidates read the threshold definitions carefully — the trap is assuming a score of 20 is 'Critical' when the matrix only defines High, Medium, and Low.

How to eliminate wrong answers

Option A is wrong because Medium is defined as scores between 10 and 15, and 20 is above that range. Option B is wrong because 'Critical' is not one of the risk levels defined in this matrix — the matrix only defines High, Medium, and Low, so introducing a fourth level is a misreading of the scenario. Option D is wrong because Low is defined as scores below 10, and 20 is far above that threshold.

28
MCQeasy

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

A.Authentication, Authorization, Accounting
B.Authorization, Authentication, Accounting
C.Authentication, Accounting, Authorization
D.Accounting, Authentication, Authorization
AnswerA

This sequence correctly represents the foundational AAA framework. Authentication verifies the user's identity, establishing 'who you are.' Subsequently, Authorization determines the specific resources or actions the authenticated user is permitted to access, defining 'what you can do.' Finally, Accounting meticulously logs all user activities and resource consumption, providing a record of 'what you did' for auditing and accountability.

Why this answer

The AAA framework defines a sequential process: Authentication verifies the identity of a subject (e.g., via password, token, or biometrics), Authorization determines what resources that authenticated subject may access, and Accounting logs the subject's activities for auditing and billing. This order is logical because you cannot authorize an unauthenticated user, and accounting requires both identity and access decisions to be meaningful. Thus, Authentication → Authorization → Accounting is correct.

Exam trap

CISSP often tests the logical sequence of AAA, and candidates may confuse the order by thinking accounting comes before authorization because logs are generated during authentication, but the correct order is Authentication, Authorization, Accounting.

How to eliminate wrong answers

Option B is wrong because it places Authorization before Authentication, which is impossible since access rights cannot be granted without first verifying identity. Option C is wrong because it places Accounting before Authorization, but accounting records what an authenticated user actually did, which depends on what they were authorized to do. Option D is wrong because it places Accounting first, which is illogical as there is nothing to account for until a user has been authenticated and authorized.

29
MCQeasy

Which document provides detailed step-by-step instructions for performing a specific security task?

A.Policy
B.Procedure
C.Standard
D.Guideline
AnswerB

A procedure is a mandatory, detailed set of step-by-step instructions that describes *how* to perform a specific task or process consistently and securely. It outlines the exact actions to be taken, the order in which they should occur, and often specifies roles, responsibilities, and tools required. Procedures ensure uniformity, repeatability, and compliance with established policies and standards, directly addressing the need for explicit operational guidance for security functions.

Why this answer

A procedure is the most granular level of security documentation, providing explicit, sequential steps required to accomplish a specific task. It answers 'how' to implement a policy or standard, ensuring consistency and repeatability. Unlike policies (which are high-level management directives) or standards (which specify mandatory requirements), procedures are operational and action-oriented.

Exam trap

CISSP often tests the distinction between policies, standards, procedures, and guidelines, and candidates frequently confuse standards (which specify what must be done) with procedures (which specify how to do it).

How to eliminate wrong answers

Option A is wrong because a policy is a high-level statement of management intent that outlines goals and responsibilities, not detailed steps. Option C is wrong because a standard defines specific mandatory requirements, such as technical configurations or rules, but does not provide step-by-step instructions. Option D is wrong because a guideline offers non-mandatory recommendations and best practices, lacking the prescriptive detail of a procedure.

30
MCQhard

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

A.To transfer ownership of PHI to the business associate
B.To authorize the use of PHI for marketing purposes
C.To require the business associate to comply with HIPAA Privacy and Security Rules
D.To allow the business associate to disclose PHI to any third party
AnswerC

The primary purpose of a Business Associate Agreement (BAA) is to contractually obligate the business associate to comply with the applicable provisions of the HIPAA Privacy and Security Rules. This legally binding agreement ensures that the business associate implements appropriate administrative, physical, and technical safeguards to protect Protected Health Information (PHI), reports breaches, and limits PHI use and disclosure to only what is necessary for the services provided, thereby extending the chain of trust.

Why this answer

A Business Associate Agreement (BAA) is a contract required by HIPAA between a covered entity and a business associate that ensures the business associate will appropriately safeguard Protected Health Information (PHI). It mandates compliance with the HIPAA Privacy and Security Rules and specifies permitted uses and disclosures of PHI. The BAA does not transfer ownership or grant unrestricted rights to PHI.

Exam trap

CISSP often tests the misconception that a BAA grants ownership or broad rights to PHI, when in fact it imposes strict compliance obligations and limits on the business associate.

How to eliminate wrong answers

Option A is wrong because a BAA does not transfer ownership of PHI; ownership remains with the covered entity or the individual, and the business associate is only a custodian. Option B is wrong because a BAA does not authorize marketing use of PHI; marketing requires specific patient authorization under HIPAA, and a BAA cannot override that. Option D is wrong because a BAA restricts disclosures to those permitted by the agreement or required by law; it does not allow unrestricted disclosure to any third party.

31
MCQhard

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

A.Annual audit report
B.Business Associate Agreement
C.Patient consent
D.Data Protection Impact Assessment
AnswerB

A Business Associate Agreement (BAA) is a legally required contract under HIPAA that must be in place before a Covered Entity (like a hospital) shares Protected Health Information (PHI) with a Business Associate (like a billing company). This agreement outlines the permissible uses and disclosures of PHI by the Business Associate and mandates their compliance with HIPAA's Security and Privacy Rules, ensuring appropriate safeguards are maintained. It establishes the responsibilities and liabilities of both parties regarding PHI protection.

Why this answer

Under HIPAA, any third party that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a Business Associate, and a Business Associate Agreement (BAA) is legally required before PHI can be shared. The billing company qualifies as a business associate, so a BAA must be in place.

Exam trap

CISSP often tests whether candidates confuse HIPAA's BAA requirement with GDPR's consent or DPIA concepts — the trap is picking 'patient consent' when HIPAA's TPO exception removes that need for billing.

How to eliminate wrong answers

Option A is wrong because an annual audit report is not a HIPAA requirement for sharing PHI with a business associate — audits are a separate compliance activity. Option C is wrong because patient consent is generally not required for treatment, payment, and healthcare operations (TPO), which includes billing; HIPAA permits these disclosures without authorization. Option D is wrong because a Data Protection Impact Assessment is a GDPR concept, not a HIPAA requirement.

32
Multi-Selectmedium

A security manager is choosing a risk response for a high-impact, high-likelihood risk. Which TWO responses are most appropriate? (Select TWO)

Select 2 answers
A.Risk mitigation
B.Risk research
C.Risk avoidance
D.Risk acceptance
E.Risk deferral
AnswersA, C

Risk mitigation involves implementing specific security controls and countermeasures to actively reduce the likelihood of a risk occurring or to lessen its potential impact. For a high-impact risk, this means taking proactive steps, such as strengthening defenses, improving processes, or deploying new technologies, to bring the risk level down to an acceptable threshold. It is a primary and responsible strategy when the activity causing the risk cannot be avoided.

Why this answer

Risk mitigation (A) is correct because for a high-impact, high-likelihood risk the organization should implement controls (e.g., firewalls, encryption, MFA, patching) to reduce the probability and/or impact to an acceptable level. Risk avoidance (C) is also correct because eliminating the activity or asset that generates the risk removes the exposure entirely, which is appropriate when the risk is too severe to tolerate. Risk research (B) is not a standard risk response in the mitigation/avoidance/transference/acceptance taxonomy and does not by itself reduce a high/high risk.

Risk acceptance (D) is inappropriate because accepting a high-impact, high-likelihood risk leaves the organization exposed beyond tolerable levels. Risk deferral (E) is not a valid risk response; postponing action does not reduce the risk and is essentially a form of acceptance.

Exam trap

CISSP often tests the risk response taxonomy, tempting candidates to select 'risk acceptance' or 'risk deferral' for high-severity risks when the correct answers are the proactive responses of mitigation and avoidance.

33
MCQeasy

Under the ISC2 Code of Ethics, which canon has the highest priority?

A.Advance the profession
B.Provide diligent service
C.Act honorably
D.Protect society
AnswerD

The canon to "Protect society, the common good, necessary public trust and confidence, and the infrastructure" is unequivocally the first and highest priority within the (ISC)² Code of Ethics. This principle mandates that all cybersecurity professionals prioritize the safety, welfare, and security of the public above all other considerations. It encompasses safeguarding critical infrastructure, protecting sensitive data, and ensuring the reliability of information systems, establishing a clear ethical imperative that supersedes individual, organizational, or professional interests.

Why this answer

The ISC2 Code of Ethics canons are ordered by priority: Protect society, the common good, necessary public trust and confidence, and the infrastructure; Act honorably, honestly, justly, responsibly, and legally; Provide diligent and competent service to principals; and Advance and protect the profession. Therefore, 'Protect society' is the highest priority canon.

Exam trap

The trap is assuming that canons are equal or that 'Act honorably' is the highest because it sounds ethical; candidates must memorize the specific order, with 'Protect society' first.

How to eliminate wrong answers

Option A is wrong because 'Advance the profession' is the lowest priority canon in the ISC2 Code of Ethics. Option B is wrong because 'Provide diligent service' is the third canon, lower than protecting society. Option C is wrong because 'Act honorably' is the second canon, also lower than protecting society.

34
MCQeasy

Which type of risk remains after management has implemented controls to mitigate the identified risks?

A.Acceptable risk
B.Control risk
C.Residual risk
D.Inherent risk
AnswerC

Residual risk is the specific level of risk that persists within an organization or system even after all planned and implemented risk mitigation strategies, controls, and countermeasures have been applied. It represents the remaining exposure that management has either consciously accepted or has been unable to further reduce through cost-effective means. This is the risk an organization must live with, requiring continuous monitoring and potential future reassessment.

Why this answer

Residual risk is the risk that remains after controls have been implemented to mitigate the identified risks. It is the difference between inherent risk (risk before controls) and the effect of the controls. Management must decide whether the residual risk is within the organization's risk appetite or requires further treatment.

Exam trap

CISSP often tests the distinction between inherent, control, and residual risk — the trap is confusing 'acceptable risk' (a management decision) with 'residual risk' (the actual remaining exposure after controls).

How to eliminate wrong answers

Option A is wrong because 'acceptable risk' is a judgment that the residual risk is tolerable, not the term for the remaining risk itself. Option B is wrong because 'control risk' refers to the risk that a control fails to prevent or detect a material error, not the leftover risk after controls. Option D is wrong because 'inherent risk' is the risk level before any controls are applied, which is the opposite of what the question asks.

35
MCQmedium

In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?

A.Low
B.Medium
C.High
D.Critical
AnswerC

A risk score of 20, calculated as the product of a high likelihood (e.g., 4 on a 5-point scale) and a very high impact (e.g., 5 on a 5-point scale), correctly places the risk in the "High" category. In a qualitative risk matrix, the "High" range typically encompasses scores from approximately 15 to 25, signifying a significant probability of occurrence combined with substantial potential negative consequences that demand immediate attention and mitigation strategies.

Why this answer

In qualitative risk analysis, the risk score is calculated by multiplying likelihood by impact. Here, likelihood = 4 and impact = 5, so the risk score = 4 × 5 = 20. The risk matrix defines scores of 15–25 as high, so a score of 20 falls into the high category.

Therefore, the risk rating is High.

Exam trap

CISSP often tests the basic calculation of risk score (likelihood × impact) and mapping to the correct qualitative rating, but candidates may mistakenly assume a higher category like 'Critical' exists or miscalculate the multiplication.

How to eliminate wrong answers

Option A is wrong because a score of 20 is not low; low would typically be a score below the medium threshold (e.g., 1–6). Option B is wrong because medium would cover scores between low and high (e.g., 7–14), and 20 exceeds that range. Option D is wrong because 'Critical' is not defined in the given risk matrix; the highest defined category is 'High' for scores 15–25, so assigning 'Critical' introduces an undefined rating.

36
MCQhard

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

A.72 hours
B.24 hours
C.48 hours
D.7 days
AnswerA

Under GDPR Article 33(1), a data controller must notify the competent supervisory authority of a personal data breach "without undue delay" and, where feasible, not later than 72 hours after becoming aware of it. This strict timeframe is critical for enabling authorities to assess the breach's impact and advise on necessary mitigation steps promptly. Failure to adhere to this 72-hour deadline without proper justification can lead to significant penalties under the regulation.

Why this answer

Article 33 of the GDPR requires that a controller notify the competent supervisory authority of a personal data breach likely to result in a risk to the rights and freedoms of natural persons without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This 72-hour window is the regulatory maximum, and failure to meet it must be accompanied by reasons for the delay. The 72-hour clock starts when the controller becomes aware, not when the breach occurred.

Exam trap

The trap is conflating the 72-hour supervisory authority notification deadline with the separate 'without undue delay' obligation for notifying data subjects under Article 34, or with shorter breach-notification timelines from other jurisdictions.

How to eliminate wrong answers

Option B is wrong because 24 hours is not a GDPR notification deadline; it may be confused with other regulatory regimes or internal escalation targets, but the regulation specifies 72 hours. Option C is wrong because 48 hours is a fabricated interval not found in GDPR Article 33. Option D is wrong because 7 days exceeds the regulatory maximum and reflects a misunderstanding that GDPR allows a week-long window, which it does not.

37
MCQeasy

According to the ISC2 Code of Ethics, which of the following canons has the highest priority when resolving an ethical dilemma?

A.Act honorably and lawfully
B.Provide diligent and competent service
C.Advance and protect the profession
D.Protect society, the common good, and the public trust
AnswerD

"Protect society, the common good, and the public trust" is unequivocally the highest priority canon in the ISC2 Code of Ethics, serving as the foundational principle for all cybersecurity professionals. This canon mandates that all actions and decisions must prioritize the safety, welfare, and confidence of the public, ensuring that information systems and data are secured to prevent harm to individuals, organizations, and critical infrastructure. This overarching responsibility guides all other ethical considerations, making it the correct answer.

Why this answer

The ISC2 Code of Ethics canons are in order of priority: 1. Protect society, the common good, and the public trust; 2. Act honorably and lawfully; 3.

Provide diligent and competent service; 4. Advance and protect the profession. Therefore, option D is the highest priority canon.

38
MCQmedium

An organization wants to avoid a particular risk entirely by not engaging in the activity that creates the risk. Which risk response strategy is being used?

A.Avoid
B.Transfer
C.Mitigate
D.Accept
AnswerA

Risk avoidance is a strategy where an organization eliminates a particular risk entirely by choosing not to engage in the activity or process that gives rise to it. This approach completely removes the potential for the risk event to occur, rather than merely reducing its likelihood or impact. It is typically employed when the potential consequences of a risk are deemed unacceptable and cannot be effectively managed through other means.

Why this answer

Risk avoidance is the strategy of eliminating the risk by not performing the activity that creates it — for example, deciding not to store credit card data at all to avoid PCI DSS exposure. It is the only strategy that reduces risk to zero for that specific activity, though it may forfeit business benefits. The question's phrasing 'not engaging in the activity' is the textbook definition of avoidance.

Exam trap

The trap here is confusing Avoid with Mitigate — candidates see 'reduce risk' language and pick Mitigate, but the key discriminator is whether the risky activity is eliminated entirely (Avoid) or merely controlled (Mitigate).

How to eliminate wrong answers

Option B (Transfer) is wrong because transfer shifts risk to a third party — via insurance, outsourcing, or contracts — but the activity still occurs and the organization retains residual risk. Option C (Mitigate) is wrong because mitigation reduces the likelihood or impact of the risk through controls, but the activity continues and some residual risk remains. Option D (Accept) is wrong because acceptance means acknowledging the risk and proceeding without additional controls, which is the opposite of eliminating the activity.

39
MCQeasy

An organization's security policy requires that all data at rest must be encrypted. Which security principle is primarily being addressed?

A.Integrity
B.Confidentiality
C.Availability
D.Non-repudiation
AnswerB

Encryption directly addresses confidentiality by transforming plaintext data into an unreadable ciphertext using a cryptographic algorithm and a secret key. This process ensures that even if unauthorized individuals gain access to the encrypted data, they cannot decipher its content without the correct decryption key. Consequently, encryption effectively prevents unauthorized disclosure of sensitive information, making it the primary control for upholding the confidentiality of data both at rest and in transit.

Why this answer

Encryption of data at rest protects data from unauthorized disclosure by rendering it unreadable without the decryption key. This directly addresses the confidentiality principle of the CIA triad, ensuring only authorized parties can access the data. Integrity concerns unauthorized modification, availability concerns uptime, and non-repudiation concerns proving an action occurred.

Exam trap

CISSP often tests whether candidates correctly map controls to CIA triad principles; the trap is confusing encryption (confidentiality) with integrity or non-repudiation, especially when AEAD modes provide both.

How to eliminate wrong answers

Option A is wrong because integrity ensures data is not altered improperly; encryption alone does not guarantee integrity (though AEAD modes provide both). Option C is wrong because availability ensures data and systems are accessible when needed, which encryption does not address. Option D is wrong because non-repudiation provides proof of origin or action, typically via digital signatures, not encryption at rest.

40
MCQhard

An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?

A.Low likelihood, low impact
B.Medium likelihood, medium impact
C.High likelihood, high impact
D.Control risk is not a defined term
AnswerB

After implementing security controls, the inherent risk (high likelihood, potentially high impact) is expected to be reduced to a more acceptable level. "Medium likelihood, medium impact" represents a plausible and common outcome of effective risk mitigation strategies, where controls successfully diminish the probability of the event occurring and/or lessen its potential consequences. This remaining risk, after controls are applied, is precisely what is defined as residual risk, indicating a successful but not absolute reduction from the initial state.

Why this answer

Residual risk is the risk that remains after controls have been implemented. In this scenario, the original risk was high likelihood and high impact; after controls, it is reassessed as medium likelihood and medium impact. Therefore, the residual risk is medium likelihood and medium impact.

Exam trap

CISSP often tests the definition of residual risk, and candidates may mistakenly select the original risk or assume controls eliminate all risk; the key is that residual risk is what remains after controls.

How to eliminate wrong answers

Option A is wrong because low likelihood and low impact would represent a further reduction beyond what was achieved; the reassessment explicitly states medium likelihood and medium impact. Option C is wrong because high likelihood and high impact is the original inherent risk before controls, not the residual risk. Option D is wrong because 'control risk' is not a defined term in this context; the question asks for residual risk, which is a standard risk management concept.

41
MCQmedium

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

A.ISO/IEC 27001
B.NIST Cybersecurity Framework
C.COBIT 2019
D.ITIL
AnswerD

ITIL (Information Technology Infrastructure Library) is a widely adopted framework providing best practices for IT service management (ITSM). It specifically guides organizations through the entire service lifecycle, encompassing Service Strategy, Design, Transition, Operation, and Continual Service Improvement, making it ideal for managing the full journey of IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) is the framework specifically focused on IT service management, providing guidance on aligning IT services with business needs through a service lifecycle (strategy, design, transition, operation, continual service improvement). Its service lifecycle model is the defining characteristic referenced in the question.

Exam trap

CISSP often tests the COBIT-versus-ITIL distinction — candidates pick COBIT because it sounds like a governance framework, but the 'service lifecycle' and 'aligning IT services with business needs' wording points specifically to ITIL.

How to eliminate wrong answers

Option A (ISO/IEC 27001) is wrong because it is an information security management standard specifying requirements for an ISMS, not an IT service alignment or service lifecycle framework. Option B (NIST Cybersecurity Framework) is wrong because it addresses cybersecurity risk management through the Identify/Protect/Detect/Respond/Recover functions, not IT service delivery alignment. Option C (COBIT 2019) is wrong because it is an IT governance and management framework focused on control objectives and enterprise governance of IT, not a service lifecycle model.

42
MCQmedium

Which of the following is a key requirement under the GDPR regarding personal data breaches?

A.Notify the supervisory authority within 72 hours
B.Conduct a privacy impact assessment within 30 days
C.Report the breach to law enforcement immediately
D.Notify affected individuals within 24 hours
AnswerA

GDPR Article 33 mandates that in the event of a personal data breach, the data controller must notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This notification is required unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification must include details such as the nature of the breach, categories of data subjects and records concerned, and the likely consequences.

Why this answer

Under GDPR Article 33, a controller must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is the core regulatory deadline tested here. Notification to individuals (Article 34) is only required when the breach poses a high risk, and it has no fixed 24-hour deadline.

Exam trap

CISSP often tests the confusion between the 72-hour supervisory-authority deadline and the separate, risk-based individual-notification obligation, tempting candidates to pick a fabricated 24-hour figure.

How to eliminate wrong answers

Option B is wrong because a Data Protection Impact Assessment (DPIA) is required under Article 35 before processing that is likely to result in high risk — it is not a breach-response action and has no 30-day breach trigger. Option C is wrong because GDPR does not mandate immediate law-enforcement reporting; that may be a separate legal or sectoral obligation, not a GDPR breach requirement. Option D is wrong because the 24-hour individual-notification deadline does not exist in GDPR; individual notification is risk-based and 'without undue delay,' not a fixed 24-hour clock.

43
Multi-Selecteasy

Which TWO of the following are examples of risk response strategies?

Select 2 answers
A.Risk acceptance
B.Risk analysis
C.Risk identification
D.Risk avoidance
E.Risk communication
AnswersA, D

Risk acceptance is a deliberate decision by an organization to acknowledge and bear the potential consequences of a specific risk, often when the cost or effort of implementing other response strategies outweighs the potential impact. This strategy is typically documented, and the organization may establish a contingency plan or simply monitor the risk without further action.

Why this answer

Risk acceptance (A) is a valid risk response strategy because the organization consciously decides to acknowledge a risk and take no proactive action to mitigate it, often documenting the decision and setting aside contingency reserves. Risk avoidance (D) is also a valid risk response strategy because it involves eliminating the risk entirely by changing plans, such as discontinuing a risky activity, technology, or process. These two belong to the standard risk response categories (avoid, transfer, mitigate, accept), so they directly answer the question.

In contrast, risk analysis (B) and risk identification (C) are earlier risk management process steps used to discover and evaluate risks, not strategies for responding to them, and risk communication (E) is an ongoing activity for sharing risk information among stakeholders rather than a response strategy itself.

Exam trap

CISSP often tests the boundary between risk assessment activities (identification, analysis, evaluation) and risk response strategies — the trap is selecting 'risk analysis' or 'risk identification' because they sound like risk management actions when they are inputs to, not outputs of, the response decision.

44
Multi-Selecthard

A company is implementing PCI DSS compliance. Which THREE requirements are part of the PCI DSS? (Select THREE)

Select 3 answers
A.Use only approved encryption algorithms for stored data
B.Implement multi-factor authentication for all employees
C.Encrypt transmission of cardholder data across open, public networks
D.Restrict physical access to cardholder data
E.Install and maintain a firewall configuration to protect cardholder data
AnswersC, D, E

This option directly corresponds to PCI DSS Requirement 4: 'Encrypt transmission of cardholder data across open, public networks.' This foundational requirement mandates the use of strong cryptography and security protocols, such as TLS 1.2 or higher, to protect cardholder data during transit over untrusted networks, preventing interception and unauthorized disclosure. It is one of the 12 high-level requirements.

Why this answer

Option C is correct because PCI DSS Requirement 4 mandates protecting cardholder data with strong cryptography during transmission over open, public networks such as the internet. Option D is correct because PCI DSS Requirement 9 requires restricting physical access to cardholder data and systems that store, process, or transmit it. Option E is correct because PCI DSS Requirement 1 requires installing and maintaining firewall and router configurations to protect cardholder data, including controlling traffic between trusted and untrusted networks.

Option A is not a standalone PCI DSS requirement as phrased, since the standard addresses encryption of stored data under Requirement 3 but does not simply state 'use only approved encryption algorithms' as a requirement. Option B is not a PCI DSS requirement for all employees; MFA is required for remote access and certain non-console administrative access, not universally for every employee.

Exam trap

CISSP often tests the misconception that PCI DSS requires MFA for all employees or a specific approved-algorithm list, when in fact MFA is scoped to CDE access and encryption requirements are intent-based rather than a fixed algorithm catalog.

45
Multi-Selecthard

Under the GDPR, which THREE of the following are rights of data subjects? (Select THREE.)

Select 3 answers
A.Right to erasure (right to be forgotten)
B.Right to ignore processing
C.Right to sell data
D.Right to data portability
E.Right to access
AnswersA, D, E

This fundamental GDPR right allows data subjects to request the deletion or removal of their personal data without undue delay under specific circumstances. These conditions include when the data is no longer necessary for the purpose for which it was collected, when consent is withdrawn, or when the data has been unlawfully processed. However, this right is not absolute and can be overridden by legal obligations or public interest considerations.

Why this answer

The GDPR explicitly grants data subjects the right to erasure (also called the right to be forgotten) under Article 17, allowing individuals to request deletion of personal data when there is no compelling reason for continued processing, so option A is correct. Option D, the right to data portability under Article 20, is correct because it lets data subjects receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller. Option E, the right to access under Article 15, is correct because data subjects may obtain confirmation of whether their personal data is being processed and receive a copy along with related information.

Option B is not a recognized GDPR right, as there is no 'right to ignore processing'; the closest concept is the right to object under Article 21, which is different. Option C is not a GDPR right either, since the regulation does not grant a right to sell data and instead imposes strict conditions on lawful processing and consent.

Exam trap

CISSP often tests fabricated rights like 'right to ignore processing' or 'right to sell data' to see if candidates know the actual enumerated GDPR rights rather than plausible-sounding alternatives.

46
Multi-Selectmedium

Which TWO of the following are examples of non-repudiation controls? (Select two)

Select 2 answers
A.Firewall rules
B.Encryption of data at rest
C.Audit logs with timestamps
D.Digital signatures
E.Biometric authentication
AnswersC, D

Audit logs meticulously record system events, user activities, and changes, often including source IP, user ID, and a precise timestamp. When properly secured against tampering, these immutable records serve as irrefutable evidence of who performed what action and when, making it difficult for an individual to deny their involvement in a specific event. This comprehensive logging provides a verifiable trail for accountability.

Why this answer

Audit logs with timestamps (C) are a non-repudiation control because they create a tamper-evident, time-stamped record of who did what and when, so a user cannot later credibly deny having performed an action. Digital signatures (D) provide non-repudiation by cryptographically binding a signer's private key to the message, allowing any party to verify origin and integrity and preventing the signer from denying the signature. Firewall rules (A) are a network access control that filters traffic, not a mechanism for proving an action occurred.

Encryption of data at rest (B) provides confidentiality, not proof of origin or action. Biometric authentication (E) provides strong authentication (something you are) but by itself does not prevent a user from denying an action after authentication.

Exam trap

CISSP often tests the CIA triad vs the supporting principles — candidates confuse authentication (proving identity) or encryption (confidentiality) with non-repudiation, forgetting that non-repudiation specifically requires proof of an action that the actor cannot later deny.

47
MCQeasy

A security administrator is reviewing the organization's security policy framework. The administrator needs to identify the document that provides detailed, step-by-step instructions for configuring a new server securely. Which type of document should the administrator reference?

A.Standard
B.Procedure
C.Guideline
D.Policy
AnswerB

A procedure is a detailed, step-by-step document that outlines how to perform a specific task, such as securely configuring a server. It translates standards and policies into actionable steps. This matches the administrator's need for precise instructions, making it the correct choice.

Why this answer

The correct answer is a procedure because it provides detailed, step-by-step instructions for performing a specific task like securely configuring a server. Policies, standards, and guidelines do not offer the operational granularity required for this technical task.

Exam trap

The trap here is confusing a standard with a procedure, assuming that any document specifying security requirements provides step-by-step instructions.

48
MCQhard

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

A.RTO = 15 minutes, RPO = 4 hours
B.RTO = 4 hours, RPO = 4 hours
C.RTO = 4 hours, RPO = 15 minutes
D.RTO = 15 minutes, RPO = 15 minutes
AnswerC

This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.

Why this answer

RTO (Recovery Time Objective) defines the maximum acceptable downtime — how long until systems are restored — so 4 hours matches the requirement to recover critical systems within 4 hours. RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time, so 15 minutes matches the requirement to lose no more than 15 minutes of data. Option C is the only pairing that maps each objective to its correct definition.

Exam trap

CISSP often tests the classic RTO/RPO swap — candidates who memorize the acronyms but not their definitions reverse them, picking RTO for data loss and RPO for downtime, which is exactly what Option A represents.

How to eliminate wrong answers

Option A is wrong because it swaps the definitions — it assigns RTO to the data-loss requirement (15 minutes) and RPO to the downtime requirement (4 hours), which inverts the meaning of both metrics. Option B is wrong because it sets RPO to 4 hours, which would permit up to 4 hours of data loss, violating the 15-minute data-loss limit; it also overstates RTO relative to the data requirement while ignoring the tighter RPO. Option D is wrong because it sets RTO to 15 minutes, which is stricter than the stated 4-hour recovery requirement and would drive unnecessary cost and complexity; while its RPO is correct, the RTO misassignment makes the combination incorrect.

49
MCQmedium

Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?

A.To determine the maximum acceptable outage for each process
B.To test the disaster recovery plan
C.To assign roles and responsibilities during a disaster
D.To select a hot site vendor
AnswerA

The primary goal of a Business Impact Analysis (BIA) is to systematically identify and quantify the potential impacts of business disruptions and, crucially, to determine the Maximum Acceptable Outage (MAO), also known as Maximum Tolerable Downtime (MTD), for each critical business process. This analysis establishes the absolute longest period a business function can be unavailable before suffering unacceptable consequences, thereby setting critical recovery time objectives (RTOs) that guide subsequent disaster recovery planning and resource allocation.

Why this answer

The primary goal of a Business Impact Analysis (BIA) is to identify the critical business processes and determine the maximum acceptable outage (MAO) or maximum tolerable downtime (MTD) for each. This involves assessing the financial, operational, and legal impacts of disruptions over time. The BIA provides the data needed to set recovery time objectives (RTOs) and recovery point objectives (RPOs), which drive the overall business continuity strategy.

Thus, determining the maximum acceptable outage is the core purpose of a BIA.

Exam trap

CISSP often tests the confusion between the BIA and other BCP phases, such as plan testing or role assignment, so candidates must remember that the BIA is strictly about identifying critical processes and their impact over time, not about implementing or testing recovery strategies.

How to eliminate wrong answers

Option B is wrong because testing the disaster recovery plan is part of the testing and maintenance phase, not the BIA; the BIA informs the plan but does not test it. Option C is wrong because assigning roles and responsibilities is a component of the business continuity plan development, not the BIA itself; the BIA identifies what needs to be recovered, not who does it. Option D is wrong because selecting a hot site vendor is a recovery strategy decision that comes after the BIA has determined the requirements; the BIA does not involve vendor selection.

50
MCQmedium

Which of the following is a key difference between a policy and a guideline in information security governance?

A.Policies are created by IT, while guidelines are created by executives
B.Policies are technical, while guidelines are managerial
C.Policies are mandatory, while guidelines are recommended
D.Policies are static, while guidelines are updated frequently
AnswerC

This is the correct distinction. Policies are formal, high-level statements that mandate specific actions or behaviors, establishing compulsory rules that all relevant parties must adhere to, with non-compliance typically incurring disciplinary or legal consequences. In contrast, guidelines provide recommended best practices, suggestions, or advisory information designed to assist individuals in making informed decisions or performing tasks, but they are not strictly enforced. This fundamental difference in obligation and enforceability is key to their purpose within an organization's governance framework.

Why this answer

Policies are formal, high-level statements that mandate specific behaviors or requirements across the organization; compliance is compulsory. Guidelines, in contrast, are non-mandatory recommendations or best practices that offer advice on how to achieve policy objectives. This distinction is fundamental to information security governance because it clarifies which documents carry enforcement weight and which are merely advisory.

Exam trap

CISSP often tests the misconception that policies are technical and guidelines are managerial, or that policies are created by IT rather than executives, leading candidates to overlook the mandatory versus recommended distinction.

How to eliminate wrong answers

Option A is wrong because policies are typically approved by executive management or the board, not IT, while guidelines may be developed by IT or security teams but are not necessarily created by executives. Option B is wrong because policies are not inherently technical—they are management directives that can cover any aspect of security—and guidelines are not exclusively managerial; they can be technical or procedural. Option D is wrong because both policies and guidelines can be updated as needed; policies are not necessarily static, and guidelines are not uniquely dynamic.

51
Multi-Selectmedium

A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)

Select 2 answers
A.Outsourcing a critical business function to a third-party provider with a service-level agreement (SLA).
B.Accepting the risk of a minor vulnerability because the cost of fixing it exceeds the potential loss.
C.Implementing a firewall to block unauthorized access to the network.
D.Deciding not to deploy a new application because it introduces unacceptable vulnerabilities.
E.Purchasing cyber insurance to cover potential financial losses from a data breach.
AnswersA, E

Outsourcing transfers the operational risk to the third-party provider, who is contractually obligated to meet performance and security requirements. The organization retains some residual risk, but the primary responsibility shifts, which is a form of risk transfer. Thus, this action is correct.

Why this answer

The correct answers are purchasing cyber insurance and outsourcing a critical function with an SLA. Both actions shift the financial or operational impact of a risk to another party. Insurance transfers financial risk, while outsourcing transfers operational risk through contractual agreements, making them valid examples of risk transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation, assuming that any action that reduces risk (like a firewall) is transfer, when transfer specifically involves shifting the risk to a third party.

52
MCQeasy

Which of the following is the PRIMARY purpose of the confidentiality principle in the CIA triad?

A.Preventing unauthorized access to information
B.Ensuring data is accurate and complete
C.Ensuring that users are who they claim to be
D.Guaranteeing that systems are available when needed
AnswerA

Confidentiality's primary purpose is to safeguard sensitive information from unauthorized disclosure or access. This involves implementing controls such as encryption, robust access control mechanisms, and the principle of least privilege to ensure that only authorized individuals or systems can view or obtain specific data. Its core objective is to maintain the secrecy and privacy of information, preventing its exposure to those without a legitimate need-to-know.

Why this answer

Confidentiality in the CIA triad ensures information is disclosed only to authorized parties, so its primary purpose is preventing unauthorized access to data. This is achieved through encryption, access controls, and classification. The other options describe integrity, authentication, and availability respectively.

Exam trap

The trap is conflating confidentiality with authentication or integrity; candidates pick 'users are who they claim to be' because authentication feels security-related, but confidentiality is specifically about preventing unauthorized disclosure.

How to eliminate wrong answers

Option B is wrong because ensuring data is accurate and complete describes integrity, not confidentiality. Option C is wrong because verifying that users are who they claim to be describes authentication, which supports but is distinct from confidentiality. Option D is wrong because guaranteeing systems are available when needed describes availability, the third leg of the CIA triad.

53
MCQhard

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

A.A physical room where payment cards are stored
B.Any system that connects to the internet
C.Systems that store, process, or transmit cardholder data
D.A network segment that contains only point-of-sale devices
AnswerC

This statement precisely defines the Cardholder Data Environment (CDE) according to PCI DSS. It includes all system components, applications, and network devices that directly store, process, or transmit cardholder data, as well as any system that could impact the security of the CDE. This comprehensive definition ensures that all relevant assets handling sensitive payment information are brought under the stringent security controls mandated by the standard.

Why this answer

The cardholder data environment (CDE) is defined by PCI DSS as the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, plus any systems that connect to or could impact the security of that environment. Option C captures the core definition accurately. This scope determines which systems must comply with PCI DSS requirements.

Exam trap

CISSP often tests the misconception that the CDE is a physical location or only POS devices, when it is actually a logical scope defined by systems that store, process, transmit, or can impact cardholder data security.

How to eliminate wrong answers

Option A is wrong because the CDE is not limited to a physical room; it is a logical and physical scope encompassing all systems and networks that handle cardholder data, wherever they reside. Option B is wrong because connecting to the internet does not make a system part of the CDE; only systems that store, process, transmit, or can impact the security of cardholder data are in scope. Option D is wrong because the CDE is not restricted to a network segment containing only point-of-sale devices; it includes any system that handles cardholder data, such as servers, databases, and applications.

54
Multi-Selectmedium

A security auditor is reviewing an organization's governance framework. Which TWO of the following are commonly used frameworks for IT governance and security management?

Select 2 answers
A.ISO/IEC 27001
B.PMBOK
C.TOGAF
D.COBIT 2019
E.Six Sigma
AnswersA, D

ISO/IEC 27001 is a globally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It provides security auditors with a structured, risk-based framework to evaluate an organization's overall security governance, risk management, and control objectives.

Why this answer

ISO/IEC 27001 (A) is correct because it is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), directly addressing security management and governance controls. COBIT 2019 (D) is correct because it is ISACA's governance framework specifically designed for enterprise IT governance and management, providing control objectives and processes that align IT with business goals. PMBOK (B) is a project management body of knowledge focused on managing projects, not on IT governance or security management.

TOGAF (C) is an enterprise architecture framework for designing and structuring IT architecture, not a governance or security management framework. Six Sigma (E) is a process improvement and quality management methodology aimed at reducing defects, not an IT governance or security framework.

Exam trap

CISSP often tests whether candidates can distinguish governance/security frameworks (ISO 27001, COBIT, NIST) from adjacent disciplines like project management (PMBOK), enterprise architecture (TOGAF), and process improvement (Six Sigma).

55
MCQmedium

Which of the following is a key objective of a business impact analysis (BIA)?

A.Implement security controls
B.Identify vulnerabilities in the network
C.Test the disaster recovery plan
D.Determine the maximum tolerable downtime for critical processes
AnswerD

The BIA quantifies how long each critical process can be unavailable before unacceptable impact, producing the maximum tolerable downtime that shapes recovery time objectives and continuity strategies. This directly satisfies the objective of prioritising recovery efforts by business impact.

Why this answer

A BIA is a foundational step in business continuity planning (BCP) that identifies critical business functions and quantifies the impact of their disruption over time. Its primary output is the maximum tolerable downtime (MTD), also called maximum allowable outage, along with recovery time objectives (RTO) and recovery point objectives (RPO) for each critical process. Determining MTD lets the organization prioritize recovery efforts and justify continuity investments.

Exam trap

CISSP often tests the confusion between BIA outputs (MTD, RTO, RPO) and downstream activities like control implementation or DR testing, so candidates must remember BIA is an analysis, not an action.

How to eliminate wrong answers

Option A is wrong because implementing security controls is a risk-mitigation activity that follows risk assessment and BIA, not the objective of the BIA itself. Option B is wrong because identifying network vulnerabilities is the purpose of vulnerability assessment or scanning, not BIA. Option C is wrong because testing the disaster recovery plan occurs after the BIA and BCP are developed, as part of validation and maintenance.

56
MCQeasy

An organization is implementing a new governance framework to align IT with business goals. Which framework is specifically designed for IT service management?

A.ISO/IEC 27001
B.COBIT 2019
C.ITIL
D.NIST Cybersecurity Framework
AnswerC

ITIL (Information Technology Infrastructure Library) is the most appropriate choice as it provides a detailed, practical framework of best practices for IT service management (ITSM). It encompasses the entire service lifecycle, from strategy and design to transition, operation, and continual service improvement, ensuring that IT services are aligned with business needs and deliver value. ITIL's focus on service delivery, customer experience, and value co-creation makes it ideal for governing IT services.

Why this answer

ITIL (Information Technology Infrastructure Library) is the framework specifically designed for IT service management (ITSM), providing best practices for service strategy, design, transition, operation, and continual improvement. It focuses on aligning IT services with business needs through processes like incident, problem, change, and service-level management. COBIT is a governance framework, ISO/IEC 27001 is an information security management standard, and NIST CSF is a cybersecurity framework — none are ITSM-specific.

Exam trap

CISSP often tests the confusion between governance frameworks (COBIT) and service management frameworks (ITIL), since both address 'aligning IT with business goals' — the key discriminator is whether the question emphasizes service delivery/operations versus oversight/control.

How to eliminate wrong answers

Option A is wrong because ISO/IEC 27001 specifies requirements for an information security management system (ISMS), not IT service delivery processes. Option B is wrong because COBIT 2019 is an IT governance and management framework focused on control objectives and enterprise IT oversight, not day-to-day service management. Option D is wrong because the NIST Cybersecurity Framework provides voluntary guidance for managing cybersecurity risk (Identify, Protect, Detect, Respond, Recover), not IT service management.

57
MCQmedium

An organization's security team is drafting a document that defines the organization's intent to protect information assets and assigns responsibilities to the information security manager. The document must align with ISO/IEC 27001 requirements and be approved by executive management. Which type of document is being created?

A.Information security policy
B.Information security guideline
C.Information security procedure
D.Information security standard
AnswerA

An information security policy is a high-level document that expresses management's intent to protect information assets, assigns roles and responsibilities, and aligns with frameworks like ISO/IEC 27001. It requires executive approval and sets the foundation for all other security documents. This scenario matches that definition exactly, making it the correct choice.

Why this answer

The correct answer is the information security policy because it is the only document type that expresses management's intent, assigns security responsibilities, and requires executive approval to align with ISO/IEC 27001. Standards, procedures, and guidelines are more detailed or advisory and do not fulfill this strategic role.

Exam trap

The trap here is confusing a policy with a standard or procedure, assuming that any security document approved by management qualifies as a policy.

58
MCQhard

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

A.Change management process for the financial system
B.Data encryption for customer PII
C.Firewall rule to block unauthorized traffic
D.Automated calculation of interest on loans
AnswerA

Under SOX, the integrity and reliability of financial reporting systems are paramount. A robust change management process for financial systems is a critical IT General Control (ITGC) because it ensures that all modifications to these systems are authorized, tested, and documented, preventing unauthorized changes that could compromise financial data accuracy. This control directly supports the reliability of financial statements by maintaining the stability and correctness of the applications processing financial transactions.

Why this answer

Under SOX, IT general controls (ITGCs) are the foundational controls that ensure the reliability, integrity, and security of the IT environment supporting financial reporting. A change management process for the financial system is a classic ITGC because it ensures that modifications to applications affecting financial data are authorized, tested, approved, and documented — directly protecting the accuracy and completeness of financial statements. SOX Section 404 requires management to assess and auditors to attest to the effectiveness of these internal controls over financial reporting (ICFR), and ITGCs like change management are a core part of that assessment.

Exam trap

CISSP often tests the distinction between IT general controls (which govern the IT environment and support financial reporting under SOX) and application/business controls (which operate within a specific application) — candidates frequently pick the automated business calculation (Option D) because it sounds financial, missing that it is an application control, not an ITGC.

How to eliminate wrong answers

Option B is wrong because data encryption for customer PII is a data protection/privacy control (relevant to GDPR, CCPA, or PCI DSS) rather than an ITGC specifically supporting the integrity of financial reporting — encryption of PII does not directly ensure financial data accuracy or authorization. Option C is wrong because a firewall rule blocking unauthorized traffic is a network perimeter security control; while it contributes to overall security, it is not a financial-reporting ITGC and does not address the authorization, completeness, or accuracy of financial transactions. Option D is wrong because automated calculation of interest on loans is an application (business) control — an automated process embedded in the application logic — not an IT general control, which governs the IT environment across applications.

59
MCQmedium

A security analyst is evaluating the risk of a data breach in a healthcare organization. The asset value of the patient database is $500,000, and the exposure factor is 0.2. The annual rate of occurrence is estimated at 0.1. What is the annualized loss expectancy (ALE)?

A.$10,000
B.$5,000
C.$50,000
D.$100,000
AnswerA

This option correctly calculates the Annualized Loss Expectancy (ALE) using the formula ALE = SLE × ARO. With an Asset Value (AV) of $500,000 and an Exposure Factor (EF) of 0.20, the Single Loss Expectancy (SLE) is $100,000. Multiplying this SLE by the Annualized Rate of Occurrence (ARO) of 0.10 yields the correct annualized risk value of $10,000.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE = Asset Value × Exposure Factor = $500,000 × 0.2 = $100,000. ALE = SLE × ARO = $100,000 × 0.1 = $10,000.

Therefore, the ALE is $10,000.

Exam trap

CISSP often tests whether candidates can correctly sequence the formulas — the trap is stopping at SLE ($100,000) or misapplying ARO, so candidates must remember ALE = AV × EF × ARO.

How to eliminate wrong answers

Option B is wrong because $5,000 results from incorrectly multiplying asset value by ARO and exposure factor in the wrong order or using a different formula (e.g., $500,000 × 0.1 × 0.1). Option C is wrong because $50,000 is the asset value multiplied by ARO ($500,000 × 0.1), omitting the exposure factor. Option D is wrong because $100,000 is the SLE (asset value × exposure factor) but not annualized — it ignores the ARO of 0.1.

60
MCQmedium

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

A.Transfer
B.Accept
C.Avoid
D.Mitigate
AnswerA

Purchasing cyber insurance is a classic example of risk transfer. This strategy involves shifting the financial responsibility for potential losses, such as those arising from data breaches, ransomware attacks, or business interruption, to a third party—the insurance provider. While the underlying operational risk itself still exists, the financial impact on the company is significantly reduced, as the insurer assumes the cost of recovery, legal fees, and other covered damages. This allows the organization to mitigate the severe financial consequences of a cyber incident without eliminating the threat entirely.

Why this answer

Purchasing cyber insurance shifts the financial impact of a breach to a third party (the insurer), which is the definition of risk transfer. The organization still owns the risk event but transfers the financial consequence. Accept, Avoid, and Mitigate describe retaining, eliminating, or reducing risk, respectively.

Exam trap

CISSP often tests whether candidates equate insurance with mitigation — insurance transfers financial impact, it does not reduce the likelihood or technical impact of the risk.

How to eliminate wrong answers

Option B (Accept) is wrong because acceptance means acknowledging the risk and bearing the loss without action — no third party absorbs the impact. Option C (Avoid) is wrong because avoidance means eliminating the activity that creates the risk entirely (e.g., not storing the data), which insurance does not do. Option D (Mitigate) is wrong because mitigation reduces the likelihood or impact via controls (e.g., encryption, MFA), whereas insurance does not reduce the probability or technical impact — it only compensates financially.

61
MCQhard

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

A.A cloud service provider hosting ePHI
B.A janitorial service that cleans the office
C.A government regulator conducting an audit
D.A patient requesting their medical records
AnswerA

A cloud service provider that hosts electronic Protected Health Information (ePHI) on behalf of a covered entity is unequivocally a Business Associate under HIPAA. By storing or processing ePHI, the CSP creates, receives, maintains, or transmits this data, making them directly subject to HIPAA's Security Rule and certain aspects of the Privacy Rule. A Business Associate Agreement (BAA) is mandatory to define their responsibilities and ensure appropriate safeguards are in place for the ePHI.

Why this answer

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with a cloud service provider that hosts electronic protected health information (ePHI). This is because the cloud provider is a business associate, as it creates, receives, maintains, or transmits ePHI on behalf of the covered entity. The BAA ensures the business associate safeguards the ePHI and complies with HIPAA.

Exam trap

CISSP often tests the definition of a business associate, and candidates may incorrectly include entities that do not handle PHI, such as janitorial services or patients themselves.

How to eliminate wrong answers

Option B is wrong because a janitorial service that cleans the office does not typically access ePHI, so it is not a business associate. Option C is wrong because a government regulator conducting an audit is not a business associate; they are an oversight entity. Option D is wrong because a patient requesting their medical records is the subject of the records, not a business associate; they have rights to access but are not performing functions on behalf of the covered entity.

62
Multi-Selecthard

Which THREE of the following are key components of a disaster recovery plan for a hot site? (Select three)

Select 3 answers
A.Pre-installed servers and workstations
B.Empty space with power and cooling only
C.Real-time data replication from primary site
D.Network connectivity with bandwidth to support operations
E.Long lead time to activate (e.g., weeks)
AnswersA, C, D

A hot site's defining characteristic is its immediate operational readiness. This means all necessary computing hardware, including servers, storage, and end-user workstations, must be pre-installed, configured, and often pre-loaded with essential operating systems and applications. This readiness minimizes recovery time objectives (RTO) by eliminating the need for hardware procurement and setup during a crisis, allowing for rapid business resumption.

Why this answer

A hot site is a fully equipped alternate facility that is ready to operate almost immediately, so pre-installed servers and workstations (A) are essential components because they eliminate procurement and build time during failover. Real-time data replication from the primary site (C) is also required so the hot site holds current, usable data with minimal RPO, typically achieved through synchronous or asynchronous replication. Network connectivity with sufficient bandwidth to support operations (D) is likewise critical, since the hot site must carry production traffic and connect users, systems, and replicated data without performance degradation.

Option B describes a cold site, which provides only space, power, and cooling with no pre-installed equipment, and option E describes a cold or warm site characteristic, since a hot site is designed for rapid activation, often within minutes or hours, not weeks.

Exam trap

CISSP often tests the distinction between hot, warm, and cold sites, and candidates may confuse the characteristics of a hot site with those of a warm or cold site, especially regarding activation time and data replication.

63
MCQmedium

Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

Article 33(1) of the GDPR requires data controllers to notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This timeframe applies specifically when the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, ensuring prompt action to mitigate potential harm and facilitate regulatory oversight.

Why this answer

Article 33 of the GDPR requires that, in the case of a personal data breach, the controller notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. This 72-hour window is the maximum time frame specified by the regulation. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.

Exam trap

The trap is mixing up the 72-hour supervisory authority notification with the 'without undue delay' data subject notification, or recalling a different regulation's timeline (e.g., 24 or 48 hours) and selecting it under pressure.

How to eliminate wrong answers

Option B is wrong because 7 days is not a GDPR notification deadline — it is a common misconception, possibly confused with other regulatory timelines. Option C is wrong because 24 hours is shorter than the GDPR requirement and is sometimes mistakenly cited from other breach-notification regimes or internal policies. Option D is wrong because 48 hours is not a GDPR deadline; the regulation explicitly sets 72 hours as the outer limit.

64
MCQmedium

A security team is performing a quantitative risk analysis for a server valued at $100,000. The exposure factor is 0.4 and the annual rate of occurrence is 2. What is the annualized loss expectancy (ALE)?

A.$40,000
B.$200,000
C.$160,000
D.$80,000
AnswerD

This is the correct Annualized Loss Expectancy (ALE), derived from accurately applying the quantitative risk analysis formula. First, the Single Loss Expectancy (SLE) is calculated as the Asset Value ($100,000) multiplied by the Exposure Factor (0.4), yielding $40,000. This SLE is then correctly multiplied by the Annualized Rate of Occurrence (2) to determine the total expected financial loss over a year, which is $80,000.

Why this answer

The ALE is calculated as SLE × ARO, where SLE = Asset Value × Exposure Factor. Here, SLE = $100,000 × 0.4 = $40,000, and ARO = 2, so ALE = $40,000 × 2 = $80,000. This represents the expected annual monetary loss from the risk event.

Exam trap

CISSP often tests the distinction between SLE and ALE, and candidates frequently stop at SLE ($40,000) or forget to apply the exposure factor when computing ALE.

How to eliminate wrong answers

Option A is wrong because $40,000 is the Single Loss Expectancy (SLE), not the annualized figure — it omits the ARO multiplier. Option B is wrong because $200,000 incorrectly multiplies the full asset value by the ARO without applying the exposure factor. Option C is wrong because $160,000 results from multiplying the asset value by 0.4 and then by 4 (or some other misapplied factor), not the correct ARO of 2.

65
MCQmedium

An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?

A.GDPR
B.PCI DSS
C.SOX
D.HIPAA
AnswerA

The General Data Protection Regulation (GDPR) explicitly mandates that organizations report personal data breaches to the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. This strict timeline applies unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. It also requires notification to affected data subjects if the breach poses a high risk.

Why this answer

The GDPR (General Data Protection Regulation) Article 33 mandates that controllers notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms. This 72-hour window is a signature GDPR requirement. No other listed regulation imposes this specific timeline for personal data breaches.

Exam trap

CISSP often tests the confusion between GDPR's 72-hour supervisory authority notification and HIPAA's 60-day HHS notification, or PCI DSS's contractual breach reporting — candidates must anchor on the exact 72-hour figure.

How to eliminate wrong answers

Option B is wrong because PCI DSS governs payment card data security and does not mandate a 72-hour breach notification to a supervisory authority; it has its own incident response requirements. Option C is wrong because SOX (Sarbanes-Oxley) focuses on financial reporting controls and does not address personal data breach notification timelines. Option D is wrong because HIPAA requires breach notification to HHS without unreasonable delay and no later than 60 days, not 72 hours, and applies to protected health information in the US.

66
Multi-Selectmedium

Which THREE of the following are valid risk response strategies?

Select 3 answers
A.Transfer
B.Eliminate
C.Avoid
D.Mitigate
E.Ignore
AnswersA, C, D

Risk transfer is a strategic approach where the financial liability or responsibility for a specific risk is contractually shifted to a third party. This does not eliminate the underlying risk event itself, but rather reallocates the potential financial impact or operational burden. Common methods include purchasing insurance policies, outsourcing functions to vendors who assume associated risks, or incorporating indemnification clauses into service level agreements, thereby protecting the organization from direct financial loss.

Why this answer

Common risk responses include Avoid, Transfer, Mitigate, and Accept.

67
MCQmedium

A company is implementing a hot site as a disaster recovery option. Which of the following best describes a hot site?

A.A facility with basic infrastructure but no equipment
B.A reciprocal agreement with another company to share space
C.A facility with some equipment but not fully operational
D.A facility that is fully configured and ready to operate within hours
AnswerD

A hot site is a fully operational and configured disaster recovery facility, mirroring the primary site with all necessary hardware, software, and up-to-date data. It is designed for immediate activation, allowing critical business operations to resume within hours or even minutes, minimizing downtime and data loss. This level of readiness is crucial for systems with very low recovery time objectives (RTOs).

Why this answer

A hot site is a fully configured disaster recovery facility that is ready to operate within hours (or immediately). It contains all necessary hardware, software, data, and network connectivity, often with near-real-time replication, allowing the organization to resume operations quickly after a disaster.

Exam trap

CISSP often tests the differences between hot, warm, and cold sites, so candidates must remember hot site = fully configured and ready within hours, not just basic infrastructure or reciprocal agreements.

How to eliminate wrong answers

Option A is wrong because a facility with basic infrastructure but no equipment describes a cold site. Option B is wrong because a reciprocal agreement is a mutual arrangement to share space, not a dedicated hot site. Option C is wrong because a facility with some equipment but not fully operational describes a warm site, which requires some setup before use.

68
MCQmedium

An organization is implementing a new access control system. They want to ensure that users are who they claim to be, that actions can be traced to individuals, and that access rights are managed appropriately. Which framework encompasses all three of these goals?

A.COBIT 2019
B.AAA framework
C.CIA triad
D.ISO/IEC 27001
AnswerB

The AAA (Authentication, Authorization, and Accounting) framework is the fundamental model for implementing access control systems, directly addressing the core requirements for managing user access. Authentication verifies a user's identity, ensuring only legitimate entities can attempt access to resources. Authorization then determines what specific actions the authenticated user is permitted to perform, based on defined policies and privileges. Finally, Accounting tracks user activities and resource consumption, providing an essential audit trail for accountability, billing, and compliance purposes.

Why this answer

The AAA framework directly addresses the three stated goals: Authentication verifies that users are who they claim to be, Authorization determines what resources they can access and manages their rights, and Accounting (or Auditing) ensures that actions can be traced back to individuals through logging and auditing. This triad of functions is the foundational model for access control in information security, making it the exact match for the question's requirements.

Exam trap

CISSP often tests the confusion between overarching security frameworks (like COBIT or ISO 27001) and the specific AAA framework that directly implements identity verification, access control, and accountability.

How to eliminate wrong answers

Option A is wrong because COBIT 2019 is a governance and management framework for enterprise IT, focusing on aligning IT with business objectives, not specifically on authentication, authorization, and accountability mechanisms. Option C is wrong because the CIA triad (Confidentiality, Integrity, Availability) describes core security objectives for data and systems, but does not encompass identity verification, access rights management, or traceability of actions. Option D is wrong because ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS); it provides a systematic approach to managing sensitive information but does not itself define the AAA functions.

69
MCQeasy

Which of the following is the primary purpose of the CIA triad in information security?

A.To establish a framework for risk management
B.To ensure compliance with regulatory requirements
C.To balance security controls with usability
D.To define the core objectives of information security
AnswerD

The CIA triad fundamentally defines the three paramount objectives that information security strives to achieve: Confidentiality, Integrity, and Availability. This foundational model provides a universal language and framework for understanding, categorizing, and prioritizing security goals across all aspects of information systems and data protection.

Why this answer

The CIA triad—Confidentiality, Integrity, and Availability—provides a foundational model for developing security policies and ensuring that data is protected from unauthorized access, tampering, and downtime.

Ready to test yourself?

Try a timed practice session using only Security and Risk Management questions.