Courseiva

CISSP · domain

troubleshooting

Practise Certified Information Systems Security Professional CISSP troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

816 questions217 easy357 medium242 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (816)

Click any question to see the full explanation, or start a practice session above.

1

A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:

Medium
2

During an incident response, the team identifies that the attacker gained access through a compromised service account with domain admin privileges. Which of the following steps should be taken FIRST to contain the incident?

Hard
3

A financial institution is required to comply with SOX. Which of the following is a key focus area for IT under SOX?

Medium
4

An organization wants to ensure that only devices that meet security policies can connect to the network. Which technology should be deployed?

Easy
5

During a penetration test, an ethical hacker sets up a rogue access point with the same SSID as the corporate network and broadcasts a stronger signal. Users inadvertently connect to the rogue AP, allowing the hacker to capture credentials. What is this attack called?

Hard
6

A security team is selecting tools for code review. Which THREE of the following are characteristics of Static Application Security Testing (SAST) tools?

Hard
7

A SOC analyst receives an alert for a high number of outbound connections to a known malicious IP. Which action should be taken first?

Medium
8

A security architect is deploying a public key infrastructure (PKI) and wants to ensure that certificate revocation status is verified efficiently without relying on a centralized CRL distribution point. Which technique should be used?

Medium
9

An organization uses full disk encryption on all laptops containing sensitive data. A laptop is to be decommissioned, and the data must be sanitized. The laptop's SSD cannot be overwritten reliably due to wear-leveling. Which method is most appropriate?

Hard
10

Which of the following is a secure protocol for transferring files that uses SSH for authentication and encryption?

Easy
11

An organization is developing a new application that collects and processes European customers' personal data. To comply with the privacy by design principles under GDPR, which THREE measures should be implemented? (Select THREE.)

Medium
12

A financial institution is implementing a data loss prevention (DLP) solution to protect customer financial information. The DLP system must detect and block the transmission of credit card numbers via email. Which of the following is the BEST approach to ensure accurate detection while minimizing false positives?

Medium
13

A company's software asset management team discovers an unauthorized copy of a licensed application installed on several employee workstations. What is the primary risk associated with this finding?

Medium
14

A multinational corporation is evaluating risk treatment options for a identified high-impact, low-probability risk. The risk is below the organization's risk appetite threshold. Which is the most appropriate action?

Medium
15

An organization wants to secure email communications by providing encryption and digital signatures. They require a solution that uses a web of trust model rather than a hierarchical PKI. Which protocol should they implement?

Medium
16

A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?

Hard
17

Match each cryptographic algorithm to its type.

Medium
18

During a security incident, the incident response team identifies that an attacker exfiltrated data via a compromised service account. Which of the following is the BEST immediate step to contain the incident?

Medium
19

Which type of testing analyzes source code for security vulnerabilities without executing the program?

Medium
20

A company is deploying a wireless network for guests. The security requirement is to provide internet access only, with no access to the internal corporate network. Which technology should be used?

Easy
21

A company wants to ensure that data is properly classified before storage. Which control should be implemented?

Easy
22

An organization is implementing IPsec VPN tunnels between multiple branch offices and the main office. The security team notices that the VPN tunnels are established successfully but no traffic passes through. Which of the following is the most likely cause?

Medium
23

A multinational corporation must comply with GDPR and CCPA. Which data protection strategy should they prioritize?

Medium
24

A security engineer is configuring a firewall that makes decisions based on source/destination IP addresses and port numbers without tracking the state of connections. Which type of firewall is this?

Easy
25

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

Medium
26

A developer is implementing OAuth 2.0 for a mobile app (public client) that needs to access a user's data from a third-party API. To mitigate the authorization code interception attack, which OAuth 2.0 extension should be used?

Hard
27

Which component of the CIA triad ensures that information is not disclosed to unauthorized individuals, entities, or processes?

Easy
28

A company is implementing an access control system where permissions are granted based on attributes such as user role, department, time of day, and device trust score. This approach allows for fine-grained policies that can adapt to context. Which access control model is being used?

Easy
29

A security engineer is evaluating a new third-party software component for use in a critical application. Which document is most important to review to understand the component's supply chain security?

Hard
30

Which type of SOC report provides a public summary of an organization's controls over security, availability, and confidentiality?

Easy
31

A data custodian is responsible for implementing controls to protect data. Which TWO of the following are typical responsibilities of a data custodian? (Select 2)

Medium
32

Which THREE of the following are common key performance indicators (KPIs) used in security assessment and testing?

Hard
33

Which TWO of the following are common techniques used in dynamic application security testing (DAST)?

Easy
34

An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?

Medium
35

An organization requires a security assessment that evaluates controls against a specific standard and results in a formal report. The organization is not required to exploit vulnerabilities. Which type of assessment is this?

Medium
36

During a vulnerability scan, a security analyst discovers that a web server is running an outdated version of Apache with known remote code execution vulnerabilities. The server is in production and cannot be patched immediately due to dependency conflicts. What is the best compensating control to reduce risk while a permanent fix is developed?

Medium
37

Which TWO principles are essential for implementing least privilege in identity and access management?

Easy
38

Which THREE of the following are common security design principles? (Select THREE.)

Medium
39

A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?

Hard
40

A security architect is evaluating access control models for a healthcare system where users have specific roles (e.g., doctor, nurse, admin) and permissions are assigned based on those roles. However, the architect also wants to incorporate attributes such as time of day, patient consent status, and device type. Which TWO models should be combined to meet these requirements?

Medium
41

Refer to the exhibit. A security analyst receives this alert. What is the most likely explanation for the successful login after the account was disabled?

Hard
42

During a web application security test, a tester attempts to inject JavaScript into a search field and observes that the script executes when the page is loaded. This indicates a vulnerability to:

Medium
43

Which vulnerability scoring system provides a standardized severity rating for vulnerabilities based on exploitability and impact metrics?

Medium
44

A healthcare organization recently experienced a data breach. The incident response team traced the breach to a compromised third-party vendor that had remote access to the organization's network. The vendor's credentials were stolen via a phishing attack. The organization's security policy requires that all third-party remote access be monitored and logged. During the investigation, it was discovered that the vendor's session traffic was not logged because the logging system was misconfigured. The security team needs to prevent similar incidents in the future. Which of the following is the MOST effective remediation?

Medium
45

A security analyst discovers that an employee shared confidential customer data with an unauthorized third party. The analyst reports this to the CISO, who decides to terminate the employee. Which ethical principle from the (ISC)² Code of Ethics is most directly violated by the employee?

Hard
46

Which access control model assigns permissions based on a user's job function?

Easy
47

A security analyst is reviewing log data from various sources. Which of the following are essential for effective security logging in accordance with best practices? (Select THREE.)

Hard
48

A security engineer is hardening a web application against race condition vulnerabilities. Which TWO techniques are effective mitigations?

Medium
49

A development team is using a third-party library that is known to have a critical vulnerability. The team decides to continue using the library because it is widely used and the vulnerability has not been exploited. Which security risk is the team ignoring?

Hard
50

An organization is implementing DNSSEC to protect against DNS spoofing attacks. Which of the following best describes the primary security function provided by DNSSEC?

Medium
51

A password policy requires passwords to be at least 12 characters, with uppercase, lowercase, digits, and special characters. Which of the following is an example of a password that meets the policy?

Easy
52

A security assessor is conducting a penetration test and needs to identify live hosts on a network without causing disruption. Which of the following techniques should the assessor use FIRST?

Easy
53

Which TWO of the following are principles of the zero trust security model? (Select TWO.)

Easy
54

A security policy requires that a user cannot have both the ability to create purchase orders and approve invoices. This is an example of:

Medium
55

A financial services company uses a custom web application for online banking. The application is developed in-house using Java and deployed on Apache Tomcat servers. Recently, the security team discovered that the application is vulnerable to a critical remote code execution (RCE) vulnerability due to insecure deserialization of untrusted data. The vulnerability exists in a module that processes session objects. The development team has been assigned to fix this issue. They propose the following options: A. Implement a custom deserialization filter using ObjectInputFilter to whitelist only expected classes. B. Replace Java serialization with JSON serialization using a library like Jackson, and configure it to disallow polymorphic deserialization by default. C. Encrypt all serialized objects using AES-256 before sending them to the client. D. Use a Web Application Firewall (WAF) to block requests containing known deserialization payloads. The application must maintain high availability and minimal latency. Which option provides the MOST effective and sustainable remediation?

Hard
56

A healthcare organization must decommission an old server containing patient health information (PHI) stored on solid-state drives (SSDs). Standard overwriting techniques are ineffective for SSDs due to wear-leveling and bad block mapping. Which sanitization method is most appropriate for these drives?

Medium
57

In a zero trust architecture, which component is responsible for continuously verifying the trustworthiness of a device before granting access to resources?

Medium
58

Which THREE of the following are examples of asymmetric cryptographic algorithms? (Select THREE.)

Hard
59

An organization is implementing a security awareness program. Which topic should be emphasized most?

Medium
60

Which phase of the data lifecycle involves the removal of data from active storage and placement into long-term storage for potential future use?

Easy
61

A global manufacturing company with headquarters in Europe and factories in Asia and North America has recently experienced a data breach. The breach involved the theft of intellectual property (IP) containing product designs stored on a file server located in the Asian factory. The investigation revealed that the attacker gained access using a compromised administrator account from a contractor's laptop that was connected to the corporate VPN. The company has implemented network segmentation, but the file server resides in the same VLAN as other factory equipment. The company uses Active Directory for identity management, and all employees and contractors use the same domain. The company is now reviewing its data governance policies to prevent future incidents. The security team must recommend a set of controls that address the root cause while maintaining operational efficiency. Which of the following is the BEST course of action?

Hard
62

Which TWO of the following are examples of administrative controls? (Select exactly 2)

Easy
63

A company is implementing a continuous monitoring program for its cloud infrastructure. Which of the following metrics would be MOST useful for detecting unauthorized changes to production systems?

Hard
64

An organization implements a data masking policy for production databases. Which of the following best describes the primary goal?

Hard
65

In asset security, which of the following is a primary responsibility of a data owner?

Easy
66

A government contractor handles data classified as 'Secret'. According to government data classification levels, which of the following is the correct order from most restrictive to least restrictive?

Medium
67

A vulnerability scan report shows that a web server has a critical vulnerability with a CVSS score of 9.8. However, the server is behind a WAF that blocks the attack vector, and the vulnerability is in a deprecated feature that cannot be removed until the next major release. What should the security manager do first?

Medium
68

An organization uses OAuth 2.0 for delegated access to APIs. A developer creates a public client application that runs on mobile devices. Which OAuth 2.0 grant type is MOST appropriate for this scenario?

Medium
69

A government contractor handles classified information up to the Secret level. The company's data classification policy recently changed, requiring that all documents marked as 'Confidential' be reclassified as 'Secret' after review. Who is ultimately accountable for ensuring that reclassification is performed correctly?

Medium
70

Which of the following is a key element of the rules of engagement for a penetration test?

Easy
71

You are a security analyst at a financial institution. The company has a hybrid infrastructure with on-premises servers and AWS cloud. The on-premises network uses a SIEM that aggregates logs from all sources. Recently, the SIEM has been generating a high volume of alerts for failed SSH login attempts from an internal IP (10.10.50.100) to multiple Linux servers. The IP belongs to a jump box used by system administrators. Upon investigation, you find that the jump box is running a hardened OS, and only authorized admins can access it via SSH key authentication. However, the failed login attempts show usernames like 'root', 'admin', 'test', which are not valid accounts on the target servers. The attempts occur every 5 seconds around the clock. There are no successful logins from that IP. The jump box has the latest patches and antivirus. What should you do FIRST?

Medium
72

During a business impact analysis (BIA), which metric represents the maximum amount of time a business process can be disrupted before causing significant harm to the organization?

Medium
73

During a risk communication session, the security team needs to present risk analysis results to executive management. Which approach is most effective for this audience?

Easy
74

A security analyst is performing an access review. Which THREE of the following are best practices for user access recertification? (Choose three.)

Hard
75

A financial services firm stores customer account data on a storage area network (SAN). The data is replicated to a secondary site for disaster recovery. The security team must ensure that when data is no longer needed, it is securely destroyed in accordance with the data retention policy. The primary site uses SSD-based storage, while the secondary site uses traditional HDDs. Which data destruction method is most appropriate for the SSD-based primary site?

Medium
76

A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?

Hard
77

Which TWO of the following are examples of Type 3 authentication factors? (Choose two.)

Easy
78

A multinational corporation with a hybrid cloud infrastructure has recently experienced a series of security incidents involving unauthorized access to sensitive customer data. The incidents were traced to compromised credentials of privileged users. The company has implemented multi-factor authentication (MFA) for all privileged accounts, but the attacks persisted. A security assessment team is brought in to evaluate the environment. During the assessment, they discover that some privileged accounts do not require MFA when accessing systems via API calls, and that session tokens for these APIs have a long expiration time of 24 hours. Additionally, the team finds that the logging and monitoring system does not capture API calls from privileged accounts, making it difficult to detect anomalous behavior. The company wants to remediate these issues effectively. Which of the following is the BEST course of action to address the root cause of the incidents?

Medium
79

A healthcare organization covered by HIPAA wants to share protected health information (PHI) with a third-party billing service. What must be in place to comply with HIPAA?

Hard
80

A security engineer is troubleshooting a site-to-site IPsec VPN between two firewalls. The tunnel status shows Phase 1 is up but Phase 2 is not. Which of the following is the most likely cause?

Hard
81

A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?

Medium
82

A red team exercise is planned to simulate a sophisticated adversary. The blue team is aware of the exercise but not the exact methods. The red team is given a budget to acquire attack tools. What is the primary advantage of this approach over a traditional penetration test?

Hard
83

Which document is mandatory, high-level, and sets the direction for security within an organization?

Easy
84

A security analyst is investigating a potential covert timing channel in a system. Which of the following characteristics best describes this type of channel?

Medium
85

A development team is adopting a secure SDLC. Which phase should include threat modeling to identify potential security vulnerabilities early?

Easy
86

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

Hard
87

Which TWO of the following are principles of the Bell-LaPadula security model?

Medium
88

A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)

Medium
89

A security analyst is investigating a potential data leak via covert channels. Which of the following is an example of a timing covert channel?

Medium
90

During a code review, a developer encounters the following code snippet in a Java web application used to authenticate users: String query = "SELECT * FROM users WHERE username = '" + request.getParameter("user") + "' AND password = '" + request.getParameter("pass") + "'"; Which of the following is the MOST effective remediation?

Hard
91

During a penetration test, a tester discovers that the target web application responds to HTTP requests with a "200 OK" status for both valid and invalid session tokens on a particular API endpoint. The application uses JSON Web Tokens (JWT) for authentication. Which of the following vulnerabilities is MOST likely present?

Hard
92

A company's vulnerability management program requires that all critical vulnerabilities be remediated within 30 days. A critical vulnerability is discovered in a legacy system that cannot be patched because the vendor no longer supports it. Which of the following is the best compensating control?

Hard
93

An organization is evaluating a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in a file access routine. The routine checks if a user has permission to open a file, then later opens the file. Which of the following best describes the potential exploitation?

Medium
94

A network administrator is configuring SNMPv3 for monitoring network devices. The organization requires both authentication and encryption of SNMP traffic. Which combination of protocols should be used to meet this requirement?

Hard
95

A security analyst is reviewing the error handling of an application. The application currently displays detailed stack traces to users when an exception occurs. Which of the following is the best practice for error handling in production?

Medium
96

Which of the following is a key requirement for an effective backup strategy to ensure data can be recovered after a ransomware attack?

Easy
97

Match each security policy to its purpose.

Medium
98

A security analyst is reviewing access controls for a financial application. Which TWO of the following are considered best practices for preventing fraud? (Select TWO.)

Medium
99

A company is deploying a containerized application using Kubernetes. Which practice BEST ensures the security of the container images?

Medium
100

A business continuity coordinator is planning a test of the disaster recovery plan. Which type of test involves a walk-through of the plan with key stakeholders without actually invoking the technical recovery?

Easy
101

A company's compliance officer wants to ensure that the organization's security controls meet regulatory requirements for data protection. The officer requests a review of the controls against the regulation's specific clauses. Which type of assessment is most appropriate?

Hard
102

During the requirements gathering phase of a software development project, which threat modeling methodology is most commonly used to identify threats such as spoofing, tampering, and elevation of privilege?

Easy
103

Which two methods provide strong encryption and authentication for wireless networks? (Choose TWO.)

Medium
104

In SAML 2.0, which component is responsible for authenticating the user and generating an assertion?

Medium
105

A company wants to ensure its internal web application is free from security flaws during development. Which testing approach analyzes source code without executing the program?

Hard
106

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

Medium
107

In a quantitative risk analysis, if the single loss expectancy (SLE) is $15,000 and the annual rate of occurrence (ARO) is 0.5, what is the annualized loss expectancy (ALE)?

Hard
108

Which TWO of the following are secure coding practices to prevent buffer overflow vulnerabilities?

Easy
109

A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?

Medium
110

A company wants to secure its wireless network. Which approach provides the strongest authentication and encryption?

Easy
111

Refer to the exhibit. A network administrator configures a new WLAN. Clients can associate but cannot obtain an IP address via DHCP. What is the most likely cause?

Hard
112

A security analyst runs a vulnerability scan against a web application and receives a report listing several critical vulnerabilities. However, the development team argues that many of these findings are false positives. Which of the following is the BEST next step for the analyst?

Medium
113

Which of the following is a key component of the rules of engagement for a penetration test?

Easy
114

Which TWO of the following are OAuth 2.0 grant types? (Choose two.)

Medium
115

Which THREE of the following are essential components of an effective incident response plan according to NIST SP 800-61?

Hard
116

Which TWO of the following are lawful bases for processing personal data under the GDPR? (Select two)

Medium
117

An organization is implementing network segmentation to enhance security. They create a DMZ to host public-facing servers and want to ensure that if a server is compromised, the attacker cannot pivot to the internal network. Which firewall placement best achieves this?

Medium
118

A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?

Medium
119

A financial institution is conducting a vulnerability assessment of its internal network. The assessor runs a comprehensive scan and discovers that several Windows servers have missing security patches. The organization has a patch management policy that requires all critical patches to be applied within 30 days. The scan results show that some patches have been pending for 45 days. The assessor also finds that the servers are isolated in a separate VLAN with strict firewall rules limiting inbound traffic to only necessary ports. The business owner argues that because the servers are isolated, the risk is low and the patches can be delayed. As the security assessor, what should be the BEST course of action?

Easy
120

A security architect is designing a physical security perimeter for a data center. Which of the following is an example of Crime Prevention Through Environmental Design (CPTED) principle?

Easy
121

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

Medium
122

Which TWO of the following are examples of detective controls?

Medium
123

An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?

Hard
124

A company's disaster recovery plan includes an agreement with another company to provide backup computing facilities in case of a disaster. The agreement allows the second company to use the facilities for its own operations if needed. This arrangement is best described as:

Hard
125

A security architect is considering secure design principles. Which two principles are essential for a defense-in-depth strategy? (Select TWO.)

Easy
126

Which of the following is the primary purpose of a hardware security module (HSM)?

Easy
127

Which THREE are core principles of secure system design?

Easy
128

An organization uses a configuration management database (CMDB). Which of the following is the PRIMARY purpose of a CMDB?

Medium
129

A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:

Medium
130

Which of the following is the correct order of the ISC2 Code of Ethics canons from highest to lowest priority?

Easy
131

Drag and drop the steps for implementing mandatory access control (MAC) in a secure system in the correct order.

Medium
132

A security engineer is recommending a VPN protocol for remote access. The requirements are: strong encryption, perfect forward secrecy, use of elliptic curve cryptography, and minimal overhead. Which VPN protocol best meets these requirements?

Medium
133

Which access control model bases decisions on attributes of the user, resource, and environment, and can use Boolean logic to define policies?

Hard
134

A security engineer is evaluating a web application for common vulnerabilities. The application uses a Content Management System (CMS) that is outdated and has known vulnerabilities. Additionally, the application displays detailed error messages and uses default administrative credentials. Which TWO of the following OWASP Top 10 categories are most relevant to these issues?

Medium
135

Which access control model allows the data owner to determine who can access their resources, typically using Access Control Lists (ACLs)?

Easy
136

Under GDPR, which TWO of the following are valid lawful bases for processing personal data?

Hard
137

A development team is implementing a new feature that processes sensitive user data. Which of the following is the most secure approach to prevent data leakage during processing?

Easy
138

A large e-commerce company operates a multi-tier application in a public cloud. The environment includes a web tier, application tier, and database tier. The security team recently deployed a host-based intrusion detection system (HIDS) on all servers. During a routine review, the HIDS alerts show repeated failed login attempts from a single external IP address to several web servers, but no successful logins from that IP. The team also notices that the database servers have been sending outbound traffic to an unknown IP address on port 443, which is unusual because the database servers typically communicate only with the application servers on port 3306 (MySQL). The application team confirms no changes were made recently. The CISO wants an immediate investigation. What should the security team do first?

Hard
139

In a software-defined network (SDN) architecture, the control plane is separated from the data plane. A network administrator is troubleshooting packet forwarding delays. Which plane is directly responsible for forwarding packets?

Hard
140

During a business impact analysis (BIA), the team identifies that the customer service application must be restored within 4 hours of a disruption. What is the term for this metric?

Easy
141

Which TWO principles are fundamental to a defense-in-depth security architecture?

Medium
142

A multinational corporation must ensure that data leaving the organization's network is classified and labeled appropriately. Which of the following is the MOST effective method to enforce consistent labeling across all data types?

Easy
143

Which TWO of the following are valid reasons for conducting a business impact analysis (BIA)?

Easy
144

An organization is deploying a VPN solution for remote employees. The security team requires a modern protocol with perfect forward secrecy, uses elliptic curve cryptography, and is known for its efficient, minimal codebase. Which VPN protocol should they choose?

Hard
145

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

Medium
146

Under the ISC2 Code of Ethics, which canon takes precedence over all others?

Medium
147

A cloud security architect is designing a system that must comply with the principle of data sovereignty. Which three controls should be implemented? (Select THREE.)

Hard
148

A company wants to secure email communications for its employees. They need to ensure message confidentiality and integrity, and also verify the sender's identity. Which protocol uses a hierarchical public key infrastructure (PKI) for email encryption and signing?

Medium
149

A security administrator needs to ensure that data stored on a server is unrecoverable after decommissioning. The server uses SSDs. Which sanitization method is MOST appropriate?

Medium
150

A security architect is designing an authentication system. To prevent session fixation attacks, which secure design principle should be implemented?

Hard
151

Which of the following best describes the primary purpose of an incident response plan?

Easy
152

An organization is implementing a bring-your-own-device (BYOD) policy. Which security control should be enforced to ensure that only compliant devices can access corporate resources?

Easy
153

A company wants to securely transfer files between systems over SSH. Which protocol should they use to leverage the existing SSH infrastructure and provide both authentication and encryption?

Medium
154

Which component of a trusted computing base (TCB) implements the reference monitor concept by enforcing access control decisions for all subjects and objects in the system?

Easy
155

A security manager is calculating the annual loss expectancy (ALE) for a server valued at $50,000. The exposure factor (EF) is 40%, and the annual rate of occurrence (ARO) is 0.5. What is the ALE?

Medium
156

A government agency requires a security model that prevents users from reading documents at a higher classification level and from writing to documents at a lower classification level. Which model enforces these constraints?

Medium
157

A security analyst reviews the following logs from a Linux server: May 10 03:12:15 server sshd[1234]: Failed password for root from 203.0.113.7 port 51234 ssh2 May 10 03:12:17 server sshd[1234]: Failed password for admin from 203.0.113.7 port 51235 ssh2 May 10 03:12:19 server sshd[1234]: Failed password for user from 203.0.113.7 port 51236 ssh2 May 10 03:12:21 server sshd[1234]: Failed password for root from 203.0.113.7 port 51237 ssh2 What is the most likely cause of these events?

Medium
158

A developer is implementing cryptographic storage for sensitive user data. Which of the following is a cryptographic best practice?

Hard
159

An organization is implementing a new access control system. The security team wants to ensure that users cannot deny having performed an action. Which security principle is being addressed?

Medium
160

Match each security model to its primary characteristic.

Medium
161

An organization is conducting a security assessment of a new web application. Which testing technique would best identify cross-site scripting (XSS) vulnerabilities?

Easy
162

During a business impact analysis (BIA), a department manager states that a critical process cannot be interrupted for more than 2 hours. However, the current backup system requires 8 hours to restore. What is the most appropriate risk management action?

Medium
163

A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)

Hard
164

Which THREE of the following are common indicators of a privilege escalation attack? (Choose three.)

Hard
165

During a security review of a web application, testers discover that the application discloses detailed error messages to users, including stack traces. Which secure coding best practice is being violated?

Medium
166

A security team is planning a social engineering test for their organization. Which of the following scenarios would BEST assess the effectiveness of security awareness training?

Medium
167

A security architect is designing access controls for a healthcare application where permissions are based on the user's role, the sensitivity of the data, and the context of the access (e.g., time of day). Which access control model best fits this requirement?

Medium
168

Which term describes the process of modifying data so that it cannot be attributed to a specific individual without additional information that is kept separately?

Easy
169

An organization requires that all data stored in a cloud object storage service be encrypted at rest using customer-managed keys. Which encryption option should be implemented?

Easy
170

An organization wants to enable single sign-on (SSO) across multiple web applications using an XML-based protocol that supports browser redirect flows. Which technology is most appropriate?

Medium
171

An organization wants to implement single sign-on (SSO) for multiple cloud applications. Which of the following is the most secure and scalable approach?

Easy
172

Which authentication factor type is a smart card?

Easy
173

A multinational corporation is designing a data retention schedule. Which factor is most critical when determining retention periods for personal data subject to the GDPR?

Hard
174

A large enterprise uses Active Directory for authentication. Several users report intermittent authentication failures when accessing internal web applications. The help desk confirms that the failures occur at random times and affect both new and existing users. The security team discovers that the system clocks on domain controllers are within acceptable limits, but some client workstations show time drift of up to 10 minutes. The Kerberos protocol is used for authentication. What is the most likely cause of the authentication failures, and what action should be taken?

Easy
175

An organization has implemented a password policy requiring a minimum of 8 characters, including uppercase, lowercase, numbers, and special characters. Despite annual security awareness training, a recent audit revealed that 60% of employees are using passwords that can be cracked within hours. The organization is also experiencing a high number of account compromises due to credential stuffing attacks. The security team is considering various controls to reduce the risk. Which of the following would be the MOST effective in addressing the identified issues?

Easy
176

Which of the following is a key principle of privileged access management (PAM)?

Easy
177

Which TWO of the following are valid types of data classification labels commonly used in commercial organizations?

Medium
178

OpenID Connect (OIDC) extends OAuth 2.0 primarily by adding which capability?

Medium
179

A multinational bank must enforce least privilege across 4,000 roles that change frequently as employees move between trading, compliance, and IT functions. Auditors found that access reviews are performed manually and that role definitions drift from actual job duties. The identity team proposes a role mining and management program. Which approach best aligns with identity and access management governance objectives while reducing role explosion?

Hard
180

A user reports that they cannot access a file share after being moved to a different department. The file share is secured with NTFS permissions and share permissions. The user is a member of the 'Marketing' group, but the file share is only accessible by 'Sales' group. What is the most likely reason?

Easy
181

A company is implementing a secure multi-tenant cloud environment. The primary security requirement is that tenants cannot access each other's data even if the hypervisor is compromised. Which architecture best meets this requirement?

Hard
182

A company uses VLANs to separate traffic between the IT, HR, and Finance departments. A user in the HR VLAN reports that she cannot access a file server located in the IT VLAN. The file server's default gateway is correctly set to the IT VLAN interface. All workstations have correct IP addresses and subnet masks. What is the most likely cause of this issue?

Easy
183

A security architect is designing a network for a high-security data center. The requirement is to ensure that even if an attacker compromises one server, they cannot easily move laterally to other servers in the same data center. Which network design principle should be applied?

Hard
184

During a security assessment, a penetration tester discovers that a web application exposes internal IP addresses in error messages. Which vulnerability category does this represent?

Medium
185

Match each business continuity term to its definition.

Medium
186

An organization is implementing a defense-in-depth strategy for its web application. Which of the following is an example of a compensating control?

Medium
187

An organization is developing a business continuity plan (BCP). The IT department has identified a critical application that must be restored within 4 hours of a disruption. Which metric defines the maximum acceptable time that the application can be unavailable?

Easy
188

An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?

Hard
189

An organization is developing a privacy program. Which THREE of the following are core principles of privacy by design? (Select 3)

Hard
190

A security administrator is configuring a stateful firewall to allow HTTP traffic from the internet to a web server. The firewall uses a default-deny policy. What is the correct rule placement?

Medium
191

A company has implemented data classification labels such as 'Public', 'Internal', 'Confidential', and 'Restricted'. Which control is most appropriate for protecting 'Confidential' data?

Easy
192

An organization implements a data loss prevention (DLP) solution. Which action is most effective for protecting data at rest on endpoint devices?

Hard
193

An organization wants to test its security controls by simulating an attack where the tester has no prior knowledge of the internal network. This is known as a:

Easy
194

A security analyst is evaluating the risk of a data breach. The asset value of the database is $100,000, and the exposure factor is 0.5. If the annual rate of occurrence is 0.2, what is the annualized loss expectancy (ALE)?

Easy
195

A security architect is designing a zero-trust network. Which principle is fundamental to a zero-trust architecture (ZTA) such as BeyondCorp?

Medium
196

A security analyst discovers an attack where an attacker sets up a rogue wireless access point with a legitimate SSID to trick users into connecting. Once connected, the attacker captures credentials. This type of attack is known as:

Medium
197

Which of the following is an example of a security policy?

Easy
198

A security architect is designing a system for a government agency that requires strict confidentiality controls. Data must be classified at multiple levels (e.g., Top Secret, Secret, Confidential). Users at a lower classification should not be able to read data at a higher classification, and users at a higher classification should not be able to write data to a lower classification. Which security model enforces these rules?

Medium
199

Which THREE are key components of a business continuity plan (BCP)?

Hard
200

A security engineer notices that the IKE phase 1 lifetime is set to 3600 seconds. What is a potential security implication?

Easy
201

Under GDPR, which of the following is a valid lawful basis for processing personal data?

Medium
202

A medium-sized financial services company has a flat network topology with no segmentation between the corporate LAN and the server farm. The security team recently deployed a host-based intrusion detection system (HIDS) on all critical servers. Over the past week, the HIDS has generated multiple high-severity alerts indicating outbound connections from a database server to an external IP address in a foreign country, occurring every hour and lasting only a few seconds. The database server contains sensitive customer data. The company's incident response plan (IRP) has not been updated in two years, and the CISO wants to ensure a response that minimizes business disruption while protecting data. The IT team is small, and the security analyst on duty suspects a data exfiltration attempt but is unsure. What should the analyst do FIRST?

Easy
203

A company is designing a recovery site for its critical database. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which of the following replication strategies is BEST suited?

Medium
204

Which TWO of the following are examples of types of security assessments?

Medium
205

A security professional is tasked with testing the effectiveness of security controls in a production environment without causing disruption. Which type of assessment should be performed?

Easy
206

An organization is implementing privacy by design in a new application that collects user location data. Which practice best aligns with the data minimization principle?

Hard
207

Which of the following is the primary purpose of a security assessment?

Easy
208

A network engineer is configuring an IPsec VPN in tunnel mode. Which IPsec protocol provides both authentication and encryption of the entire IP packet?

Hard
209

Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?

Easy
210

An organization is implementing network segmentation. They need to place publicly accessible servers (e.g., web and email) in a separate network that is isolated from the internal LAN but still allows controlled access from the internet. Which architecture should they use?

Medium
211

A security analyst is reviewing a web application and notices that it includes a feature that allows users to view their own profile by providing a user ID in the URL (e.g., /profile?userid=123). The application does not verify that the logged-in user owns that profile. Which vulnerability is present?

Medium
212

In a qualitative risk assessment, a risk with a likelihood rating of 'High' and an impact rating of 'Critical' would typically fall into which category?

Medium
213

An organization wants to implement a password policy that balances security and usability. Which of the following is the BEST practice according to current NIST guidelines?

Easy
214

A remote user at 203.0.113.5 cannot access the internal web server at 10.0.0.10 over HTTPS. What is the most likely cause of the denial?

Medium
215

An organization requires a commercial integrity model where users cannot modify data in higher integrity levels and cannot read data from lower integrity levels. Which model should they implement?

Medium
216

A security analyst discovers that a business unit is storing sensitive data on a file share without classification labels. What is the first step to remediate?

Medium
217

A security manager is evaluating risk treatment options for a high-impact, low-probability risk. Which approach is most appropriate?

Hard
218

An organization is decommissioning a data center. Which of the following is the most secure method for sanitizing hard drives that will be reused?

Hard
219

A healthcare organization must decommission a server containing protected health information (PHI). Which data sanitization method ensures the data is irrecoverable while complying with regulatory requirements?

Easy
220

A financial institution is implementing a data classification policy. Which role is responsible for assigning initial classification labels to data assets?

Medium
221

In an OAuth 2.0 authorization code flow with PKCE, what is the primary purpose of the code verifier and code challenge?

Medium
222

An internet-facing Apache web server is running version 2.4.49 and is vulnerable to CVE-2021-41773 path traversal. What is the most urgent remediation?

Easy
223

An organization is developing a business continuity plan (BCP) for its critical IT systems. Which of the following is the FIRST step in the BCP process?

Medium
224

Which component of the AAA framework is responsible for determining what resources a user can access and what actions they can perform?

Easy
225

A multinational company must comply with the EU General Data Protection Regulation (GDPR) for processing personal data of EU citizens. The company's data protection officer (DPO) has been appointed but reports to the Chief Marketing Officer (CMO). Which compliance issue is most critical?

Hard
226

A medium-sized financial services company recently deployed a new identity governance and administration (IGA) solution to manage user access across on-premises Active Directory and cloud-based SaaS applications. The IGA system uses a role-based access control (RBAC) model with hundreds of roles defined. The company has a policy that all access certifications must be completed quarterly. During the first quarterly certification, the access reviewers complain that they are overwhelmed by the number of entitlements they need to review, and many certifications are not completed on time. The security team also notices that some users have accumulated excessive privileges because role assignments were not properly reviewed. The company wants to streamline the certification process without sacrificing security. Which of the following is the BEST course of action?

Hard
227

A security analyst is tasked with identifying vulnerabilities in a web application that is still in development. The application code is not yet stable, and frequent changes are expected. Which testing approach would be most appropriate to identify vulnerabilities without hindering the development process?

Easy
228

When implementing a federated identity management system, which TWO components are essential for establishing trust between Identity Provider and Service Provider? (Select two.)

Medium
229

A company is planning to conduct a penetration test. Which THREE of the following should be included in the rules of engagement?

Medium
230

A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?

Medium
231

A company is migrating its critical application to a cloud provider. Which disaster recovery strategy provides the shortest recovery time objective (RTO) and recovery point objective (RPO)?

Medium
232

You are the chief information security officer (CISO) of a large healthcare organization that handles protected health information (PHI). The organization has recently been acquired by a larger conglomerate, and the new parent company mandates that all subsidiaries adopt a single, unified risk management framework based on NIST SP 800-39. Your current framework is ISO 27005-based and has been effective for years. During the transition, you discover that the parent company's framework requires quantitative risk analysis for all critical assets, while your team has been primarily using qualitative analysis due to lack of accurate financial data. Moreover, the parent company expects all risk assessments to be completed within 30 days, a timeframe your team considers unrealistic given the number of assets. Several key stakeholders are concerned about the additional resource burden and potential disruption to operations. You need to propose a course of action that balances compliance with the parent company's mandate while maintaining operational effectiveness and minimizing risk to patient data.

Hard
233

In a public key infrastructure (PKI), which component is responsible for issuing and revoking digital certificates?

Easy
234

A company must comply with a regulation requiring a formal, independent assessment of its security controls against a standard. Which type of assessment is MOST appropriate?

Easy
235

A security team is reviewing a web application that allows users to search for products. The application uses a SQL database and constructs queries by concatenating user input directly into the SQL statement. Which of the following is the most effective mitigation against SQL injection attacks?

Medium
236

An organization is required to declassify a document that was previously classified as 'Secret' under government guidelines. What process must be followed before the document can be released to the public?

Medium
237

An organization wants to ensure that data is protected throughout its lifecycle. Which step in the data lifecycle is most critical for enforcing data retention policies?

Hard
238

During an internal audit, an organization discovers that a critical application has not been patched for six months. The application is business-critical and cannot be taken offline during business hours. Which of the following is the best course of action?

Hard
239

A company is conducting a risk assessment and needs to prioritize risks based on both likelihood and impact. The risk management team decides to use a quantitative approach. Which of the following is a key advantage of using quantitative risk analysis over qualitative risk analysis?

Medium
240

A security manager is evaluating risk responses for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk response strategy is most appropriate?

Hard
241

An organization is implementing a BCP. After completing the BIA, which of the following is the next logical step in the planning process?

Medium
242

An organization is developing a security governance framework to align with business objectives. Which group should have ultimate authority and responsibility for the cybersecurity program?

Medium
243

During a security assessment, a penetration tester successfully performs an ARP spoofing attack, redirecting traffic through their machine. This attack exploits which protocol vulnerability?

Hard
244

A company has a headquarters and three branch offices connected via MPLS VPN. Recently, they deployed a new VoIP system across all sites. Users report intermittent call drops and poor voice quality during peak business hours. The network team suspects packet loss and jitter are the cause. The IT manager wants to verify the issue without affecting production traffic. Which of the following is the best course of action?

Easy
245

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

Medium
246

A company is implementing a risk management program. They have identified a critical server with an asset value of $50,000. The exposure factor due to a potential threat is 40%, and the annual rate of occurrence is 2. What is the Annualized Loss Expectancy (ALE)?

Medium
247

A multinational corporation operates a private MPLS VPN network connecting 50 branch offices to a central data center. The network uses BGP as the routing protocol within the VPN, with each branch announcing its internal prefixes to the data center routers. Over the past week, several branch offices have reported intermittent connectivity issues, with traffic being routed to incorrect destinations before recovering. Network logs show that during these incidents, the data center router receives unexpected BGP updates from one of the branch routers, advertising prefixes that belong to other branches. BGP sessions remain established without flaps. The security team is concerned that this could be a route leak or intentional hijack. The network engineer has verified that all BGP sessions are authenticated with MD5 and that RPKI validation is not currently deployed. Which course of action should the engineer take first to mitigate the issue?

Hard
248

A software company uses a third-party library that has a known critical vulnerability. The library is used extensively and rewriting the code would take months. What is the BEST immediate action to reduce risk?

Medium
249

Which of the following is the correct order of priority for the ISC2 Code of Ethics Canons?

Medium
250

A security architect is reviewing a system that uses a microkernel operating system. The architect is concerned about potential side-channel attacks between processes. Which mitigation is most effective at the architecture level?

Hard
251

A company uses a qualitative risk analysis matrix where likelihood ranges from 1 to 5 and impact ranges from 1 to 5. A risk with a likelihood of 4 and an impact of 5 would fall into which risk level if the matrix defines high risk as scores above 15, medium as 10-15, and low as below 10?

Hard
252

Which physical security design principle emphasizes that the physical environment should be designed to discourage criminal activity by using natural surveillance, access control, and territorial reinforcement?

Medium
253

During a risk assessment, a company identifies that its primary data center is located in a flood-prone area. The estimated annual loss expectancy (ALE) for a flood event is $500,000. Installing flood barriers costs $200,000 and reduces the ALE to $50,000. What is the net benefit of implementing the flood barriers?

Hard
254

An organization is developing an information security policy. Which of the following should be included?

Easy
255

During a Kerberos authentication process, the client receives a Ticket Granting Ticket (TGT) from the Authentication Server (AS). Later, the client presents the TGT to the Ticket Granting Server (TGS) to request a service ticket. Which of the following best describes the purpose of the TGT?

Hard
256

A user reports that a VPN client cannot connect to the corporate gateway. The client log shows the following excerpt: "TLS Error: server certificate verification failed: unable to get local issuer certificate." What does this indicate?

Hard
257

During an internal security assessment, a tester uses a tool to attempt to crack password hashes extracted from a domain controller. Which phase of the penetration testing process does this represent?

Medium
258

Which of the following is a secure coding practice to prevent SQL injection attacks?

Easy
259

Which TWO are security benefits of using a federated identity model?

Medium
260

A security architect is evaluating security models for a multilevel secure system. Which model enforces the * property (no write down) and is typically used for confidentiality?

Easy
261

A security analyst is reviewing logs from multiple systems and needs to ensure that logs are tamper-proof and available for incident investigation. Which of the following is the BEST approach?

Hard
262

An organization discovers that a former employee's account is still active and has been used to access sensitive data. This is an example of which type of risk?

Hard
263

A company is outsourcing its customer support operations to a third-party vendor. The vendor will have access to sensitive customer data. Which of the following should be the primary security requirement in the contract with the vendor?

Hard
264

Match each PKI component to its function.

Medium
265

A large financial institution is migrating its core banking system to a private cloud. The architecture must protect against data leakage between different business units sharing the same physical infrastructure. The system uses a hypervisor and virtual machines. Each business unit has its own security classification. The security requirement is that no VM belonging to a lower classification should be able to read data from a higher classification VM, even if the hypervisor is compromised. The architect proposes using mandatory access control at the hypervisor level. However, the IT team notes that a hypervisor compromise could bypass MAC. Additionally, they need to ensure that data at rest is encrypted and keys are stored securely. Which of the following would BEST meet the requirement?

Hard
266

Which TWO are examples of 'something you know' authentication factors?

Easy
267

What is the primary purpose of a configuration management database (CMDB) in asset management?

Easy
268

A security engineer is reviewing the architecture of a system that uses the Bell-LaPadula model. The system has subjects with security clearances and objects with classifications. To prevent covert timing channels, which additional control should be implemented?

Hard
269

An organization is transitioning from waterfall to agile development. How should security be integrated into the new process to align with the SDLC?

Medium
270

An organization discovers that an employee has been using a personal cloud storage account to share confidential files. After revoking access, what is the NEXT best step to prevent recurrence?

Hard
271

An organization is implementing a new access control system. Which of the following represents the correct order of the AAA framework components?

Easy
272

Your organization is forming an incident response team (IRT). According to NIST SP 800-61, which TWO roles are considered core to the incident response team?

Medium
273

Which IPsec protocol provides both authentication and encryption of the packet payload, but does not encrypt the IP header?

Easy
274

A financial application uses a third-party library for PDF generation. A security review finds that the library is no longer maintained and has known vulnerabilities. What is the BEST course of action?

Medium
275

Which document provides detailed step-by-step instructions for performing a specific security task?

Easy
276

A small business wants to ensure compliance with GDPR for its customer data. What is the initial action required to comply with GDPR?

Easy
277

A security architect is designing a system that must ensure integrity of commercial transactions. Which of the following models are specifically focused on integrity? (Choose TWO)

Medium
278

A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?

Medium
279

An organization is implementing a Public Key Infrastructure (PKI) to support secure email and web communications. The PKI includes a root CA, intermediate CAs, and end-entity certificates. Which of the following best describes the role of the root CA in this hierarchy?

Medium
280

Which phase of the data lifecycle includes the act of securely deleting data that is no longer needed, in accordance with retention policies?

Easy
281

A company uses a SIEM to correlate logs from multiple sources. Which log source is most critical for detecting privilege escalation attacks?

Medium
282

A financial institution stores customer PII, including Social Security numbers (SSNs). Under privacy regulations, SSNs are considered sensitive PII. Which of the following techniques would best reduce the risk of re-identification while preserving the utility of the data for statistical analysis?

Hard
283

Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?

Easy
284

A security administrator is evaluating secure file transfer protocols. Which THREE of the following protocols provide encryption for data in transit? (Select THREE.)

Hard
285

Your organization is a medium-sized e-commerce company with a hybrid infrastructure: on-premises datacenter and AWS cloud. The security team recently conducted an internal vulnerability scan of the on-premises network and discovered multiple critical vulnerabilities in a legacy ERP system that cannot be patched because the vendor no longer supports it. The ERP system is essential for order processing and cannot be decommissioned. The team also ran a penetration test against the cloud environment and found that an attacker with network access could leverage misconfigured security groups to move laterally between instances. The company has a risk appetite that allows for limited risk acceptance with compensating controls. As the senior security analyst, what is the BEST course of action?

Hard
286

Which TWO of the following are characteristics of a SOC 2 Type II report?

Medium
287

During a penetration test, the tester gains initial access to a server and then attempts to pivot to other systems. Which phase of the penetration testing process does this represent?

Hard
288

A security auditor is reviewing the results of a recently completed internal vulnerability scan. The scan report shows several hosts with the same vulnerability. Which of the following actions should the auditor take FIRST?

Easy
289

A company implements a centralized authentication system using RADIUS for network devices. The security team notices that after a user's password is changed in Active Directory, the user can still authenticate to network devices using the old password for up to 30 minutes. What is the most likely cause?

Medium
290

A security architect is selecting an access control model for a system that must prevent users from reading objects at a higher classification level. Which model enforces this property?

Easy
291

An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?

Easy
292

Which type of data is considered sensitive PII and requires enhanced protection?

Easy
293

A hospital chain collects and stores electronic health records (EHR) for millions of patients. The EHR system is hosted in a private cloud and accessed by doctors, nurses, and administrative staff from various locations. Recently, an internal audit found that several employees shared their login credentials with colleagues to expedite workflows. The hospital must comply with HIPAA and state privacy laws. The security officer wants to implement a solution that minimizes the risk of unauthorized access due to shared credentials while still allowing efficient access for patient care. Which of the following is the BEST approach?

Medium
294

A financial services company needs to provide remote employees with access to internal applications. The security policy mandates that the solution must support granular access control based on user identity, integrate with the existing RADIUS server, and encrypt all traffic. The IT team is evaluating remote access technologies. Which of the following best meets these requirements?

Medium
295

A company wants to ensure that its security policy is effectively enforced across all departments. Currently, the policy is published on the intranet and included in the employee handbook. However, the security team notices that many employees are not following the policy, leading to security incidents. Which of the following would be the most effective way to improve policy enforcement?

Easy
296

A security architect is designing a cryptographic system for a high-security environment where data must be encrypted both at rest and in transit, with granular access control. The system must be efficient for large volumes of data. Which approach is most appropriate?

Medium
297

A network analyst suspects a host on the internal network is sending abnormal amounts of traffic. Which tool should be used to capture and analyze the packets?

Medium
298

Which three are network-layer security controls in a defense-in-depth strategy? (Choose THREE.)

Easy
299

Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?

Easy
300

Which TWO of the following are characteristics of a VPN that uses TLS?

Easy
301

An organization uses a role-based access control (RBAC) model. After an audit, it was discovered that users have accumulated excessive permissions due to role proliferation. The security architect proposes migrating to an attribute-based access control (ABAC) model. Which challenge is MOST likely to be encountered during this migration?

Hard
302

A company is developing a mobile payment application. To comply with PCI DSS, what should be implemented to protect cardholder data during transmission?

Medium
303

A company is implementing TLS 1.3 to secure web communications. Which of the following features is unique to TLS 1.3 compared to earlier versions?

Medium
304

A company is designing an access control system for a highly sensitive database. They want to ensure that only authorized users can access data, and that access is automatically revoked when the user's context changes (e.g., job role change). Which model BEST meets these requirements?

Hard
305

Which TWO of the following are essential elements of a secure software development lifecycle (SSDLC)? (Select exactly 2.)

Medium
306

Under HIPAA, what is the primary purpose of a Business Associate Agreement (BAA)?

Hard
307

An organization is reviewing its media sanitization procedures. Which TWO methods are considered acceptable for sanitizing solid-state drives (SSDs) according to NIST SP 800-88 guidelines?

Hard
308

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

Medium
309

Which TWO of the following are fundamental phases of a secure software development lifecycle (SSDLC) where security should be integrated? (Select exactly two.)

Easy
310

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

Easy
311

Which THREE are components of a privileged access management (PAM) solution?

Hard
312

A financial institution must ensure that transactions are well-formed and enforce separation of duties to prevent fraud. Which security model best addresses these requirements?

Hard
313

Which access control model allows the owner of a resource to grant or deny access to other users?

Easy
314

An incident responder is analyzing a network compromise that involved ICMP attacks. Which THREE types of ICMP attacks could have been used to disrupt network operations? (Select three.)

Medium
315

A security architect is reviewing the access control model for a microservices architecture. Which approach minimizes the risk of privilege escalation from a compromised service?

Hard
316

A security architect is designing a trusted recovery capability for a high-assurance system that must continue operating during a failure without violating its security policy. The system must be able to recover from a failure while maintaining the security of the data it processes, and must not enter an insecure state during recovery. Which two recovery strategies best satisfy the requirement to maintain security during failure and recovery? (Choose two.)

Hard
317

A security architect is implementing a system that must prevent conflicts of interest for a consulting firm serving competing clients. Which security model is best suited for this requirement?

Medium
318

A financial services company has a hybrid cloud environment with on-premises servers and a public cloud provider. The security team recently discovered that an attacker exfiltrated sensitive customer data from a cloud storage bucket. The investigation reveals that the bucket was configured with a bucket policy that allowed anonymous read access. The security architect must redesign the architecture to prevent such incidents. The company uses AWS for cloud services. The architect proposes the following: (1) Enable AWS CloudTrail and Amazon GuardDuty for monitoring. (2) Implement AWS Identity and Access Management (IAM) roles for applications instead of long-term access keys. (3) Use AWS Key Management Service (KMS) to encrypt data at rest. (4) Configure a VPC with a NAT gateway and private subnets for all compute resources. (5) Implement S3 bucket policies that deny all access unless explicitly allowed by a specific IAM role. During a review, the chief information security officer (CISO) points out that one of these measures does not directly address the root cause of the incident. Which measure is least effective in preventing unauthorized access to S3 buckets?

Hard
319

An organization is adopting DevOps. Which of the following is a primary security concern when integrating security into CI/CD pipelines?

Hard
320

A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?

Easy
321

Which THREE of the following are valid considerations when implementing data loss prevention (DLP) controls to protect sensitive data? (Select three.)

Hard
322

A small business wants to implement a security policy that balances protection with usability. Which of the following is the MOST important factor when developing the policy?

Easy
323

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

Medium
324

A multinational corporation is expanding its operations into a new country with strict data protection laws. The company needs to ensure compliance while maintaining operational efficiency. Which of the following is the BEST approach to manage this risk?

Medium
325

Which TWO of the following are valid data de-identification techniques?

Hard
326

Which physical security concept uses natural surveillance, territorial reinforcement, and access control to deter crime in built environments?

Easy
327

Which THREE of the following are commonly used metrics for measuring the effectiveness of a vulnerability management program?

Hard
328

A network administrator notices that users in the accounting department can access the internet but are unable to access the internal payroll server (10.10.10.50). The firewall rule allows traffic from the accounting subnet (10.10.20.0/24) to the payroll server. What is the most likely issue?

Easy
329

A government agency requires a new secure document management system that enforces mandatory access control with the properties that users cannot read documents at a higher classification and cannot write documents to a lower classification (to prevent data leaking). The system must also support different categories (compartments) within the same classification level, and a user with access to one compartment should not be able to access another compartment unless explicitly allowed. The architect is considering the Bell-LaPadula model. However, the Bell-LaPadula model's *-property (no write-down) addresses the write issue, but there is also a need to handle compartment isolation. Which additional model or mechanism should be incorporated to ensure compartment isolation?

Medium
330

Which TWO of the following are mandatory secure coding practices to prevent injection attacks? (Select exactly two.)

Medium
331

A company is evaluating a third-party software library for use in their application. Which document provides a detailed inventory of the library's components and dependencies to help assess supply chain risk?

Hard
332

A security manager is selecting controls to protect sensitive data. Which TWO are examples of administrative controls?

Medium
333

A company is decommissioning a data center and needs to dispose of hard drives that contained highly confidential financial data. Which of the following methods provides the HIGHEST assurance that data cannot be recovered?

Hard
334

An organization needs to ensure that its employees understand their responsibilities regarding information security. Which of the following is the MOST effective way to achieve this?

Medium
335

A security administrator is reviewing potential risks associated with orphaned accounts. Which TWO of the following are risks of orphaned accounts?

Medium
336

Which of the following is a key feature of TLS 1.3 that enhances security compared to earlier versions?

Easy
337

After a recent security audit, a network administrator discovers that an attacker has been intercepting traffic by associating with a legitimate access point's MAC address and broadcasting a stronger signal. Which type of attack has occurred?

Medium
338

An organization is planning a penetration test of its internal network. Which TWO of the following are essential elements to include in the test scope and rules of engagement?

Easy
339

Which type of security testing involves analyzing source code for vulnerabilities without executing the code?

Easy
340

During a penetration test, a security analyst discovers that a web application allows an attacker to bypass authorization and view another user's private messages by simply changing a numeric ID in the URL. Which vulnerability is being exploited?

Hard
341

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

Easy
342

A company is designing a database that will contain personally identifiable information (PII). To reduce privacy risk, they decide to add controlled noise to query results. This technique is known as:

Hard
343

A security administrator is configuring role-based access control (RBAC) for a cloud storage system. Which of the following is the best practice for assigning permissions?

Medium
344

A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?

Medium
345

A healthcare organization uses a federated identity provider (IdP) to authenticate clinicians into a third-party electronic health record (EHR) application acting as a SAML 2.0 Service Provider (SP). The security team wants to reduce the risk that a stolen IdP session cookie could be replayed against the EHR. Which SAML 2.0 control should the team implement to bind the assertion to the authenticated browser session and limit replay?

Medium
346

A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?

Hard
347

An organization is implementing a bring-your-own-device (BYOD) policy. The security architect must ensure that corporate data on the device is protected from unauthorized access if the device is lost or stolen, while minimizing impact on user privacy. Which solution is most appropriate?

Medium
348

Which of the following is an example of a Type 1 authentication factor?

Easy
349

A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?

Medium
350

A large financial institution is finalizing its annual risk treatment plan based on a recent enterprise risk assessment. The risk appetite statement approved by the board specifies that the organization will accept only low residual risks for financial loss, but is willing to accept moderate risks for reputational damage if cost-benefit justifies. The risk register includes the following findings: 1) A critical SQL injection vulnerability in the online banking portal with high likelihood and critical impact; current controls include a web application firewall (WAF) that is not fully tuned. 2) Use of outdated TLS 1.0 encryption on internal communications between data centers; likelihood is medium, impact is low. 3) Lack of background checks for third-party vendors with access to sensitive data; likelihood is low, impact is moderate. 4) A single point of failure in the primary data center's power supply; likelihood is low, impact is critical. 5) An incident response plan that has not been tested in two years; likelihood is medium, impact is moderate. The CISO must prioritize actions for the upcoming quarter. What is the most appropriate first step?

Easy
351

An attacker who has compromised the Kerberos Key Distribution Center (KDC) could forge a Ticket Granting Ticket (TGT) to impersonate any user. This type of attack is known as:

Hard
352

A company is implementing a digital signature system to ensure non-repudiation. The security architect must select a hash function that meets the required security properties. Which THREE of the following are necessary properties for the hash function?

Medium
353

A small business owner stores customer payment card information (PCI) in a legacy database that is not compliant with PCI DSS. The business is migrating to a new cloud-based point-of-sale (POS) system that uses tokenization. The owner wants to ensure that the legacy data is handled securely during the transition. Which of the following is the BEST approach?

Easy
354

Which cryptographic algorithm is an example of a symmetric stream cipher?

Easy
355

A security team is evaluating a new endpoint detection and response (EDR) solution. Which of the following capabilities is MOST important for detecting fileless malware?

Hard
356

Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?

Hard
357

An organization uses a custom application that stores user passwords using salted SHA-256 hashes. During a security audit, the auditor recommends migrating to a more secure password storage mechanism. Which of the following is the best recommendation?

Hard
358

Which TWO are essential components of a security policy framework?

Easy
359

A government agency's data retention policy requires that classified documents be destroyed after 10 years. Which method ensures both the information and the media are completely destroyed in a way that is verifiable and auditable?

Hard
360

A multinational corporation is establishing a security governance framework. The board of directors wants to ensure that information security strategy aligns with business objectives. Which role is primarily responsible for integrating security into the organization's strategic decision-making?

Hard
361

A company is implementing a secure software development lifecycle (SSDLC). Which of the following is a key activity during the design phase?

Medium
362

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

Medium
363

Which of the following describes the concept of 'least privilege' in the context of access control?

Medium
364

In OAuth 2.0, which grant type is recommended for a native mobile application that cannot securely store a client secret, and uses PKCE?

Hard
365

A company is migrating from WPA2 to WPA3 to improve wireless security. Which THREE of the following are features of WPA3 compared to WPA2?

Medium
366

A financial institution mandates that all administrative access to network devices must go through a privileged access management (PAM) solution. The PAM solution manages and rotates credentials automatically and logs all sessions. Recently, an auditor discovered that a router's configuration was changed outside of the approved change window. PAM logs show no session during that time. The router supports both local and RADIUS authentication. Which of the following is the MOST likely explanation for the unauthorized change?

Hard
367

A network architect is designing a network to comply with PCI DSS requirements that cardholder data must be encrypted during transmission over open networks. Which protocol should be used for encrypting traffic between a point-of-sale (POS) terminal and the payment gateway?

Hard
368

Which of the following is a primary function of a Trusted Platform Module (TPM)?

Easy
369

Drag and drop the steps for a secure password change procedure in the correct order.

Medium
370

A security analyst discovers that a service account in Active Directory has not had its password changed in 5 years and has domain admin privileges. The account is used by a legacy application that does not support modern authentication protocols. Which of the following is the MOST secure approach to manage this account?

Hard
371

A system administrator is configuring an LDAP directory for user authentication. The policy requires that account lockout occurs after a specified number of failed attempts. Which attribute should be configured?

Easy
372

An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?

Medium
373

A company uses BGP to exchange routes with its ISP. To prevent prefix hijacking, which mechanism should be implemented?

Hard
374

A network security analyst receives an alert from the intrusion detection system (IDS) indicating a high volume of TCP SYN packets to a single external IP address from a compromised internal host. This is characteristic of which type of attack?

Easy
375

A company requires employees to authenticate using a smart card and PIN to access the corporate network. This is an example of which type of authentication?

Easy
376

A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:

Easy
377

A company is conducting a security assessment of its network infrastructure. Which of the following activities are typically performed during a vulnerability assessment? (Select TWO.)

Medium
378

A company uses differential privacy to release aggregate statistics from a dataset containing sensitive employee information. Which of the following is true regarding differential privacy?

Hard
379

During a penetration test, the tester has obtained initial access and is now trying to move laterally to other systems. Which phase of the penetration testing process does this represent?

Medium
380

Which of the following is the primary purpose of output encoding in web application security?

Easy
381

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Medium
382

A security engineer is hardening a web server before deploying a new application. Which TWO of the following are examples of security misconfiguration vulnerabilities that should be addressed?

Medium
383

A security team is performing a risk assessment on a legacy application that uses insecure deserialization. Which TWO of the following are recommended approaches to mitigate the risk of insecure deserialization?

Hard
384

A system administrator notices that user accounts are often left active after employees leave the company. Which process should be automated to address this?

Easy
385

During a forensic investigation, the team needs to preserve evidence from a running server. What is the FIRST step the team should take?

Medium
386

A company uses smart cards for authentication to workstations. A user inserts their smart card but is prompted for a PIN. The user enters the correct PIN but authentication fails. The smart card is not expired. What is the most likely cause?

Medium
387

A multinational corporation maintains site-to-site IPsec VPN tunnels between its headquarters and three regional branch offices. Over the past week, the tunnels have been dropping intermittently, causing disruption to real-time applications. The network team checked logs and found frequent 'Phase 2 rekey failure' messages. The tunnels are configured with IKEv1 and preshared keys. The headquarters uses a Cisco ASA, and the branches use various vendors' firewalls. The team verified that firewall policies allow IPsec traffic, and there is no packet loss on the WAN links. Which action should the team take to resolve the issue most effectively?

Medium
388

A security engineer is configuring SNMPv3 on network devices. The policy requires both authentication and encryption of SNMP messages. Which combination of protocols should be used to meet this requirement?

Hard
389

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

Easy
390

A development team is designing a new application and wants to ensure that if a failure occurs, the system remains secure by default. Which design principle should they apply?

Medium
391

A company wants to ensure that only authorized software can run on its laptops. They decide to use a hardware component that validates the boot process by measuring each component before it loads. Which technology is being used?

Medium
392

During a security audit, an organization discovers that several employees are sharing a single generic account to access a critical database. Which principle of security operations is being violated?

Easy
393

An organization uses a system where access decisions are based on user attributes (e.g., job title, clearance), resource attributes (e.g., classification), and environmental factors (e.g., time of day). This is an example of:

Medium
394

A hospital is subject to HIPAA. Which of the following is required when sharing protected health information (PHI) with a third-party billing company?

Hard
395

A security manager is choosing a risk response for a high-impact, high-likelihood risk. Which TWO responses are most appropriate? (Select TWO)

Medium
396

Under the ISC2 Code of Ethics, which canon has the highest priority?

Easy
397

In a Privileged Access Management (PAM) solution, which feature provides temporary elevation of privileges for specific tasks, reducing the risk of standing privileges?

Medium
398

An attacker sends a flood of SYN packets to a server, consuming its resources and preventing legitimate connections. Which OSI layer is this attack targeting?

Easy
399

A network administrator is configuring switches to prevent VLAN hopping attacks. Which TWO of the following measures should be implemented?

Easy
400

Which TWO of the following are characteristics of a Privileged Access Management (PAM) solution? (Choose two.)

Medium
401

An organization wants to identify vulnerabilities in their network without attempting to exploit them. Which type of security assessment should they perform?

Easy
402

Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?

Easy
403

A security administrator is configuring SNMPv3 for network device monitoring. The requirement is to provide both authentication and encryption of SNMP traffic. Which combination of options should be used?

Medium
404

An organization is implementing a Privileged Access Management (PAM) solution. Which THREE of the following are common features of PAM? (Select THREE.)

Hard
405

An organization implements a data loss prevention (DLP) solution to monitor data in motion. Which type of data is typically most challenging to detect?

Hard
406

Which THREE of the following are valid countermeasures against buffer overflow attacks?

Hard
407

During a security audit of a financial application, the auditor discovers that the application uses a custom encryption algorithm for storing sensitive data. The developer claims it is more efficient than AES. What should the auditor recommend?

Hard
408

In the context of physical security, which of the following is an example of a preventive control?

Easy
409

Which of the following is an example of a social engineering attack?

Easy
410

Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?

Hard
411

A security analyst receives an alert that a host in the internal network is sending abnormal amounts of traffic to an external IP. The traffic uses destination port 53. What is the most likely attack?

Medium
412

A financial services firm recently deployed a multi-factor authentication (MFA) solution for remote access to its trading platform. The MFA requires a one-time password (OTP) via a mobile app, in addition to a username and password. Since deployment, remote traders have complained that the authentication process takes too long, especially during market open hours. The help desk reports that many traders are accidentally locking their accounts due to multiple failed OTP attempts. The security team wants to maintain strong security but improve user experience. Which action should the security team take?

Hard
413

You are the security architect for a multinational corporation that handles highly sensitive intellectual property (IP) and personally identifiable information (PII) for clients in multiple jurisdictions, including GDPR and CCPA regions. The company recently experienced a data breach where an attacker exfiltrated 50 GB of data from a file server by exploiting a vulnerability in the backup software. The backup software had been configured with default credentials and was accessible from the internet. The security team has implemented compensating controls, but management wants to prevent such incidents in the future. You have been asked to recommend a long-term strategy to protect sensitive data assets. The budget is limited, and the solution must minimize user friction. Current environment: On-premises Active Directory with Windows file servers, some data in AWS S3, and a mix of laptops and mobile devices. The organization uses Microsoft 365 for email and collaboration. Which of the following is the BEST course of action?

Hard
414

Which TWO protocols are commonly used for identity federation?

Medium
415

Which type of risk remains after management has implemented controls to mitigate the identified risks?

Easy
416

An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?

Medium
417

An organization is implementing DNSSEC to protect its DNS infrastructure. Which of the following best describes the primary security benefit of DNSSEC?

Hard
418

During an audit, it is discovered that a database containing personally identifiable information (PII) has been retained for 10 years beyond the regulatory requirement. The data owner has not approved the retention extension. Which data lifecycle principle is primarily being violated?

Hard
419

Under GDPR, a company processes personal data on behalf of a data controller. Which role does the company fulfill?

Medium
420

In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?

Medium
421

Which THREE of the following are control families defined in NIST SP 800-53? (Choose three.)

Medium
422

Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?

Easy
423

During a security assessment, it is found that service accounts have interactive logon rights. What is the BEST remediation?

Medium
424

A security analyst is setting up a vulnerability scanning program. Which TWO of the following are best practices for determining scanning frequency?

Medium
425

Under the GDPR, a data controller experiences a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. What is the maximum time frame within which the controller must notify the supervisory authority?

Hard
426

Which TWO of the following are key objectives of a security assessment? (Select exactly 2.)

Medium
427

An organization is implementing a new backup strategy for its critical servers. The backup must support rapid restoration of individual files and allow for a recovery point objective (RPO) of no more than 15 minutes. Which backup method should be used for daily operations?

Medium
428

A network engineer is troubleshooting a slow VPN connection between two sites. The link is symmetric 100 Mbps, but throughput tests show only 20 Mbps. The VPN uses AES-256 encryption. What is the most likely cause?

Medium
429

A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?

Hard
430

A development team is integrating a third-party library for encryption. The security team insists on using only the latest version of the library. What is the primary security benefit of this requirement?

Easy
431

A company uses a cloud storage service. Which asset security control is most important to prevent unauthorized access to data?

Medium
432

A large organization needs to deploy a Public Key Infrastructure (PKI) for thousands of devices and users. A key requirement is the ability to revoke certificates in real time when a device is lost or compromised. Which solution is most appropriate?

Medium
433

Which role is ultimately accountable for the classification of data within an organization?

Easy
434

An organization is implementing a security information and event management (SIEM) system. Which THREE factors are most critical for the SIEM to provide actionable security insights?

Hard
435

A developer is implementing role-based access control (RBAC). Which THREE components are essential for an RBAC system?

Hard
436

An organization is planning a penetration test of its internal network. The test team has been given network diagrams, source code access, and administrative credentials. This type of testing is known as:

Medium
437

Which TWO of the following are best practices for conducting a penetration test?

Easy
438

According to the ISC2 Code of Ethics, which of the following canons has the highest priority when resolving an ethical dilemma?

Easy
439

A company has implemented a new web application firewall (WAF) and wants to test its effectiveness. Which of the following testing methods would provide the MOST accurate assessment?

Medium
440

A cloud storage bucket access policy grants all principals permission to write objects. What is the primary security risk of this policy?

Hard
441

An organization is implementing a security program and wants to ensure it meets legal and regulatory requirements. The security manager is reviewing the concept of due care. Which best describes due care in the context of information security?

Medium
442

A security architect is reviewing a design for an e-commerce application. The architect recommends implementing defense in depth. Which of the following is an example of this principle?

Medium
443

A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address followed by a successful login. What should the analyst do next?

Easy
444

An organization is implementing a data retention policy. The legal team has determined that certain financial records must be retained for seven years due to regulatory requirements. The IT department is responsible for enforcing the retention and disposal of these records. Which of the following is the most critical factor to consider when implementing the retention policy?

Easy
445

A vulnerability scanner reports a medium-severity finding on a web server. After investigating, the system administrator claims the finding is a false positive because the service in question is not actually running. Which step should the security analyst take next?

Medium
446

An organization wants to ensure that employees can securely access internal applications from home. They deploy a VPN solution. Which VPN type provides the strongest encryption and is most commonly used for remote access?

Easy
447

A company is implementing a CI/CD pipeline for a web application. Which security testing method should be integrated into the build stage to catch vulnerabilities early?

Easy
448

A risk assessment identifies several threats. Which THREE are considered external threats?

Hard
449

A development team is implementing a microservices architecture. Which of the following is the BEST approach to secure inter-service communication?

Hard
450

An organization wants to avoid a particular risk entirely by not engaging in the activity that creates the risk. Which risk response strategy is being used?

Medium
451

Which THREE of the following are components of a Privileged Access Management (PAM) solution?

Medium
452

In a virtualized environment, which security control is most effective for isolating VMs from each other?

Hard
453

A security analyst is reviewing the findings from a vulnerability scan of a web application. Which TWO actions are most appropriate to prioritize remediation?

Medium
454

A security team is reviewing firewall logs and sees many dropped packets from an external IP. What type of attack is most likely?

Medium
455

A security manager is designing a continuous monitoring program to satisfy ongoing authorization requirements. The program must detect unauthorized configuration changes to production servers, verify that security patches are applied within policy timeframes, and provide evidence for auditors. Which TWO of the following controls BEST support these objectives? (Choose two.)

Hard
456

A financial institution is required to retain customer transaction records for seven years under regulatory mandates. The institution is facing a lawsuit and must preserve all relevant data. What legal concept applies?

Hard
457

A company wants to implement multi-factor authentication (MFA) for remote access. Which combination of factors represents something you have and something you are?

Easy
458

An organization's security policy requires that all data at rest must be encrypted. Which security principle is primarily being addressed?

Easy
459

An organization implements a security model where users can only read objects at or below their security clearance, and can only write to objects at or above their clearance. This model primarily ensures:

Medium
460

An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?

Hard
461

Refer to the exhibit. A legal hold exception preserves FinancialRecords FIN-001 and FIN-002. What is the correct action for FinancialRecords that are not under legal hold?

Hard
462

Based on the vulnerability scan exhibit, which vulnerability should be remediated first?

Medium
463

Which THREE of the following are characteristics of a federated identity management system?

Medium
464

Which of the following is an example of a Type 2 authentication factor?

Easy
465

Which TWO of the following are essential characteristics of an effective information classification scheme?

Hard
466

Which TWO of the following are key indicators that a security awareness training program is effective? (Choose two.)

Easy
467

A company is deploying a new web application and needs to ensure that only HTTPS traffic is allowed. What is the MOST effective way to enforce this at the network perimeter?

Medium
468

An organization uses a version control system for all software development. Which practice best ensures that code changes are reviewed for security issues before merging into the main branch?

Easy
469

A security team is investigating a vulnerability where an attacker can intercept and modify data as it moves between processes within a CPU's secure enclave. Which technology is designed to protect against such attacks by creating a trusted execution environment?

Hard
470

Which governance framework provides guidance specifically for aligning IT services with business needs and includes a service lifecycle?

Medium
471

Which wireless security protocol replaces the pre-shared key (PSK) authentication with Simultaneous Authentication of Equals (SAE) to provide stronger security and forward secrecy?

Easy
472

A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?

Easy
473

Which of the following is the primary purpose of a security audit?

Easy
474

A data warehouse contains anonymized customer transaction data used for analytics. The anonymization process removed direct identifiers and applied k-anonymity with k=10. An attacker obtains the dataset and attempts to re-identify individuals using auxiliary information. Which of the following best describes the residual privacy risk?

Hard
475

What type of DLP system monitors data in motion across the network?

Easy
476

During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?

Hard
477

Which of the following is a key requirement under the GDPR regarding personal data breaches?

Medium
478

A development team is implementing a web application that allows users to search for products. To prevent SQL injection attacks, which secure coding practice should be applied?

Medium
479

Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)

Easy
480

A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?

Medium
481

Which access control model allows the owner of a resource to determine who can access it and what permissions they have?

Hard
482

An organization is required to retain audit logs for seven years due to regulatory compliance. The logs are currently stored on a file server that is approaching capacity. What is the BEST way to manage log storage?

Medium
483

During a security assessment, a consultant discovers that a legacy VPN solution uses MS-CHAPv2 for authentication and does not support IKE. The protocol is known to be vulnerable to dictionary attacks. Which VPN protocol is most likely being used?

Hard
484

During a security audit, it is discovered that a company's data classification labels are inconsistently applied across different departments. Which of the following is the BEST long-term solution to ensure consistent data classification?

Hard
485

A company has multiple offices connected via a WAN. They want to ensure that all traffic between offices is encrypted and authenticated. Which technology is most appropriate?

Easy
486

A security analyst is reviewing logs from a web application firewall (WAF) and notices multiple requests containing the payload "1=1--" in the query string. The analyst suspects a SQL injection attack. Which of the following is the BEST immediate action to validate the suspicion?

Medium
487

A development team is implementing cryptographic functions for a new application. They need to store passwords securely. Which of the following is the most appropriate approach?

Hard
488

An access control policy grants Read and Write permissions on a specific target object and includes a network source condition restricting access to a trusted IP range. Which TWO statements about this policy are true?

Medium
489

A security analyst is conducting a vulnerability scan of a web application. The scan identifies several vulnerabilities, but the analyst wants to minimize false positives. Which type of vulnerability scan would be most appropriate?

Medium
490

During a SOC 2 audit, the auditor evaluates controls over a period of time to assess their operating effectiveness. Which type of SOC report is being performed?

Hard
491

To enforce separation of duties in a CI/CD pipeline, what architectural principle should be implemented?

Hard
492

A company wants to ensure that data labeled 'Internal Use Only' is not inadvertently disclosed to unauthorized parties. What is the most effective way to communicate handling requirements to employees?

Medium
493

Which TWO of the following are examples of risk response strategies?

Easy
494

A security architect is reviewing a software design that uses a third-party library for XML parsing. The library is known to be vulnerable to XML External Entity (XXE) attacks. The architect recommends replacing the library. What is the primary risk of XXE attacks that the architect wants to avoid?

Hard
495

A company's help desk receives many requests from users who have forgotten their passwords. Which solution is MOST effective in reducing these requests while maintaining security?

Easy
496

During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?

Medium
497

A security architect is reviewing a web application's design and identifies several potential vulnerabilities. Which TWO of the following are effective mitigations for cross-site scripting (XSS) attacks?

Medium
498

Which THREE of the following are common methods used in security assessment and testing? (Select exactly 3.)

Hard
499

A company's security policy requires that all removable media be encrypted. An employee plugs in a USB drive and is prompted to format it before use. After formatting, the drive is not encrypted. What is the most likely reason?

Easy
500

Which THREE of the following are valid methods to reduce the risk of data exfiltration via removable media in a high-security environment?

Medium
501

Which digital forensics tool is specifically designed for memory forensics?

Easy
502

Which TWO of the following are effective methods for detecting unauthorized access to a network? (Choose two.)

Medium
503

Drag and drop the steps for conducting a risk assessment in the correct order.

Medium
504

Which THREE of the following are recognized roles in asset security?

Easy
505

A security engineer is hardening a system against buffer overflow attacks. Which of the following are effective mitigations? (Choose THREE)

Hard
506

In Kerberos authentication, what is the purpose of the Ticket Granting Ticket (TGT)?

Medium
507

An organization is required to retain security logs for a minimum of one year to meet compliance regulations. Which practice is most directly related to this requirement?

Medium
508

A software development company uses a continuous integration/continuous deployment (CI/CD) pipeline that automatically builds and deploys code to production after passing automated tests. The code repository contains proprietary algorithms and customer data. A recent incident was traced to an attacker who injected malicious code into a library that was pulled from a public package repository during the build process. The company wants to prevent similar supply chain attacks without significantly slowing development. Which of the following is the BEST course of action?

Medium
509

During a security assessment, an organization wants to ensure that its web application is resistant to common attacks. Which THREE testing types should be included?

Easy
510

A cloud service provider uses a Type 1 hypervisor to host multiple virtual machines (VMs) for different customers. Which of the following is a primary security concern specific to this architecture?

Hard
511

A multinational corporation is implementing a data classification program. The information security manager must ensure that data is handled appropriately based on its classification level. The company operates in multiple jurisdictions, including the European Union and the United States. Which two of the following are key considerations when developing the data classification policy? (Choose two.)

Hard
512

An information security manager is implementing an asset classification policy. Which of the following is the primary purpose of classifying information assets?

Easy
513

A company is implementing a PKI to support secure web browsing. Which of the following are commonly used to enhance the security of certificate validation? (Choose TWO)

Medium
514

A healthcare organization is moving patient records to a cloud storage service. Which of the following is the MOST important requirement to ensure data security and compliance with HIPAA?

Medium
515

A company uses Role-Based Access Control (RBAC) for its ERP system. A user in the 'Accounts Payable' role needs to temporarily approve purchase orders up to $10,000 while the 'Purchasing Manager' is on leave. What is the BEST way to grant this access?

Medium
516

A network engineer is configuring a firewall to allow HTTP traffic from the internet to a web server (10.0.0.10). The firewall has three interfaces: outside (ISP), DMZ (10.0.0.0/24), and inside (192.168.1.0/24). The web server is in the DMZ. Which rule is correct?

Hard
517

Which TWO of the following are best practices for securing containerized applications? (Select exactly 2.)

Hard
518

A company is implementing PCI DSS compliance. Which THREE requirements are part of the PCI DSS? (Select THREE)

Hard
519

A security engineer reviews the cloud storage bucket policy in the exhibit. What is the most significant security issue with this configuration?

Medium
520

A company collects PII from European customers for order processing. Under GDPR, they engage a third-party logistics provider to handle shipping. Which role does the logistics provider typically assume in this scenario?

Hard
521

A security team is reviewing network segmentation strategies. Which TWO of the following are benefits of using VLANs? (Select TWO.)

Medium
522

An organization has implemented a new SIEM system. What is the most critical factor for its effectiveness?

Medium
523

A data owner has classified a dataset as 'Confidential' in a commercial organization. Which of the following best describes the primary responsibility of the data owner for this dataset?

Easy
524

A security analyst notes that a recent penetration test successfully exploited a vulnerability in a legacy application that cannot be patched. The analyst recommends implementing network segmentation to limit the application's exposure. This recommendation is an example of:

Hard
525

A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?

Easy
526

An LDAP distinguished name (DN) includes the attribute 'CN=John Doe,OU=Sales,DC=company,DC=com'. What does 'CN' stand for?

Medium
527

Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?

Medium
528

Under the GDPR, which THREE of the following are rights of data subjects? (Select THREE.)

Hard
529

During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?

Medium
530

A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?

Hard
531

A data classification scheme includes Public, Internal, Confidential, and Restricted. Which classification requires the highest level of protection?

Easy
532

A security analyst observes a network attack where an attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. This attack occurs at which layer of the OSI model?

Medium
533

Which TWO of the following are key elements of a disaster recovery plan (DRP)?

Easy
534

A development team is fixing a stored cross-site scripting (XSS) vulnerability in a web application that displays user comments. The application stores comments in a database and renders them in HTML. Which of the following is the most secure approach to prevent XSS?

Hard
535

Which TWO are examples of administrative controls in an information security program?

Medium
536

Which TWO of the following are principles of the data minimization concept under privacy regulations such as GDPR?

Easy
537

Which TWO of the following are differences between OAuth 2.0 and OpenID Connect (OIDC)?

Hard
538

A network administrator is deploying a wireless network for a small business and wants to ensure strong security. Which of the following is the best choice for authentication in a WPA3 Personal network?

Medium
539

Refer to the exhibit. An application running on this server uses HTTPS (port 443). What is the most likely impact of the current firewall rules on the application?

Medium
540

Which THREE are essential elements of a Transport Layer Security (TLS) handshake? (Choose three.)

Hard
541

A small business wants to implement multifactor authentication (MFA) for remote access to its internal network. The solution must be cost-effective and easy to deploy. Which combination is most appropriate?

Easy
542

A user calls the help desk because they cannot log in. The help desk technician confirms the user's identity by asking for their employee ID and mother's maiden name. Which of the following is the MOST significant security issue with this practice?

Easy
543

A network administrator is configuring a firewall that examines the source and destination IP addresses, port numbers, and protocol (TCP/UDP) of each packet without considering the state of the connection. Which type of firewall is being deployed?

Easy
544

Which of the following is a primary benefit of using an application programming interface (API) gateway in a microservices architecture from a security perspective?

Easy
545

Which TWO of the following are valid reasons to implement network segmentation?

Easy
546

A penetration tester is engaged to assess a corporate wireless network. After capturing handshakes and attempting offline cracking, the tester obtains valid PSK credentials for the guest SSID. The tester then connects to the guest network but cannot reach any internal servers. Which of the following BEST describes what the tester has demonstrated?

Medium
547

Which TWO of the following are examples of non-repudiation controls? (Select two)

Medium
548

What is the primary purpose of a Web Application Firewall (WAF) in a deployment environment?

Easy
549

During an incident, a forensic analyst needs to preserve volatile data from a live Windows server. Which command should be used first to collect memory and network connection information?

Medium
550

A security team is planning to conduct a social engineering test as part of an organization's security assessment. Which THREE of the following should be included in the test plan to ensure ethical and legal compliance?

Medium
551

Drag and drop the steps for a disaster recovery (DR) plan activation in the correct order.

Medium
552

What is the primary purpose of a Change Advisory Board (CAB) in change management?

Medium
553

A security engineer is troubleshooting an issue where users are unable to access a web application after being authenticated via OAuth 2.0. The users receive a 403 Forbidden error. The application logs show that the access token is valid but does not contain the required scope. What is the most likely cause?

Medium
554

Drag and drop the steps for implementing a digital signature using asymmetric cryptography in the correct order.

Medium
555

A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?

Medium
556

During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?

Medium
557

An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?

Medium
558

A security architect is designing a system that must enforce the principle of least privilege for a set of applications. The applications need to access a shared database, but each application should only have the minimum permissions necessary to perform its function. The architect decides to implement a mechanism where each application runs with its own set of credentials and permissions, and these permissions are checked at every access attempt. Which security principle is best demonstrated by this design?

Medium
559

During a penetration test, the tester successfully performs a VLAN hopping attack by sending packets with a specific tag. Which mitigation technique is most effective at preventing double-tagging VLAN hopping?

Hard
560

A security analyst is evaluating secure email protocols. Which TWO of the following provide both encryption and digital signing of email messages?

Easy
561

An organization's risk assessment identified a vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system processes sensitive customer data and is critical for daily operations. The risk is rated as high likelihood and high impact. The organization has a moderate risk appetite. Which risk treatment is most appropriate?

Medium
562

An organization implements Single Sign-On (SSO) using SAML 2.0. A user attempts to access a cloud application (Service Provider) but is not authenticated. The Service Provider redirects the user to the Identity Provider (IdP) for authentication. Which type of SAML flow is this?

Medium
563

After a penetration test, the tester provides a report that includes vulnerabilities found, exploitation details, and recommended fixes. Which step of the penetration testing process does this represent?

Hard
564

A company is merging with another and must integrate security policies. What is the first step?

Hard
565

A financial services company is migrating its customer relationship management (CRM) system to a public cloud provider. The CRM contains personally identifiable information (PII) and financial transaction records. The security architect must design a solution that ensures data confidentiality and integrity both at rest and in transit, while complying with PCI DSS requirements. The cloud provider offers a key management service (KMS) that can generate and store encryption keys, a hardware security module (HSM) in the cloud, and a certificate authority for TLS certificates. The architect needs to select the appropriate encryption methods and access controls. The company's security policy requires encryption keys to be rotated every 90 days and stored separately from the data. The cloud provider's KMS supports automatic key rotation, but the HSM requires manual intervention. The CRM application uses a database that supports transparent data encryption (TDE) with keys stored in the KMS, and the application also requires TLS for all network connections. Which course of action best meets all requirements?

Easy
566

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

Medium
567

Which cryptographic algorithm is a symmetric block cipher widely used for encrypting sensitive data, with key sizes of 128, 192, or 256 bits?

Easy
568

A company is designing secure boot for IoT devices to ensure only trusted firmware runs. The devices have limited resources. Which mechanism provides the highest assurance of boot integrity?

Hard
569

An organization wants to implement single sign-on across multiple web applications using an XML-based protocol that supports identity provider (IdP) and service provider (SP) initiated flows. Which technology should they choose?

Hard
570

A PAM configuration contains pam_tally2.so with deny=5 and unlock_time=300. What is the effect of this configuration?

Hard
571

An organization is designing a disaster recovery site. The primary data center is located in a region prone to earthquakes. The recovery site must be far enough away to avoid the same seismic zone but close enough to minimize latency. Which site selection criteria is most important?

Medium
572

A company wants to test the effectiveness of its security controls without causing disruption. Which type of assessment is most appropriate?

Medium
573

During a code review, a developer notices that an application directly concatenates user input into SQL queries. Which type of vulnerability does this represent?

Easy
574

During a penetration test, the tester successfully exploits a vulnerability in a web server and gains initial access. The next step in the penetration testing process is to:

Easy
575

A security administrator is reviewing the organization's security policy framework. The administrator needs to identify the document that provides detailed, step-by-step instructions for configuring a new server securely. Which type of document should the administrator reference?

Easy
576

Which THREE of the following are valid methods for securely disposing of magnetic hard drives?

Medium
577

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

Hard
578

In a microservices architecture with a service mesh, what is the most effective approach to secure inter-service communication?

Hard
579

An organization deploys a hypervisor to host multiple virtual machines. To mitigate the risk of VM escape attacks, which of the following is the most effective security measure?

Hard
580

A company develops a web application using microservices architecture deployed on Kubernetes. The security team identifies that the application is vulnerable to injection attacks because user input is concatenated into SQL queries. The development team wants to implement a fix quickly. They propose using parameterized queries, but the database access layer currently uses stored procedures. The team considers modifying the stored procedures to accept parameters and using prepared statements in the code. However, the operations team is concerned about performance impact. Which of the following is the BEST course of action?

Hard
581

A security analyst is evaluating access control models for a healthcare organization that needs to enforce both confidentiality and integrity. Which TWO models should be considered? Select two.

Medium
582

A security analyst is tasked with identifying vulnerabilities in a network without exploiting them. Which type of assessment is most appropriate?

Medium
583

An organization uses a data loss prevention (DLP) system to monitor outbound emails. Which data classification type would the DLP most likely use to detect sensitive information leaving the network?

Medium
584

A network engineer is configuring 802.1X authentication for wired network access. The authentication server supports EAP-TLS. What must be deployed to clients to support this authentication method?

Medium
585

A financial institution must retain customer transaction records for 7 years. After that, what is the most appropriate action?

Medium
586

Match each OSI layer to its function.

Medium
587

A hospital is implementing an access control system for its electronic health record (EHR) application. The system must ensure that only authorized healthcare providers can access patient records based on their role (doctor, nurse, administrator), department (cardiology, oncology, etc.), and patient consent status. The hospital also needs to support break-the-glass access for emergencies. The current solution uses static role-based access control (RBAC) but fails to enforce department-level restrictions and consent checks. What is the most appropriate access control model to address these requirements?

Medium
588

A security assessment reveals that a web application uses client-side input validation exclusively. What is the most likely security risk?

Hard
589

A software vulnerability allows an attacker to overwrite a return address on the stack to execute arbitrary code. What mitigation technique randomizes the memory layout to prevent the attacker from predicting target addresses?

Hard
590

Which protocol is specifically designed for authorization and not authentication, often using grant types like authorization code and client credentials?

Easy
591

A security engineer is designing an API that handles sensitive customer data. The engineer wants to ensure that only authorized clients can access the API, and that requests are not tampered with in transit. Which approach best addresses both requirements?

Medium
592

In Kerberos authentication, which component issues a Ticket Granting Ticket (TGT) after verifying the user's credentials?

Medium
593

In LDAP, what does the Distinguished Name (DN) uniquely identify?

Easy
594

An organization's backup strategy includes daily full backups and hourly incremental backups. The system suffers a ransomware attack that encrypts all data. Which backup set is essential to restore the most recent clean state?

Hard
595

During a vulnerability assessment, a security analyst discovers that a web application uses a library known to be vulnerable to Log4Shell (CVE-2021-44228). Which type of vulnerability does this represent?

Hard
596

Which type of firewall can inspect the contents of application-layer traffic, such as HTTP requests, and block malicious payloads?

Medium
597

An organization uses a siem to collect logs from multiple sources. The security team notices that some events are missing during peak traffic hours. Analysis shows that the log sources are sending data via UDP. What is the most likely cause?

Hard
598

A security architect is designing a network segmentation strategy for a financial institution. Which TWO techniques are best suited for implementing micro-segmentation in a data center environment? (Select two.)

Medium
599

Which of the following is an example of an Insecure Direct Object Reference (IDOR) vulnerability?

Easy
600

A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?

Medium
601

Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?

Medium
602

An organization wants to implement a security mechanism that ensures all accesses are mediated and cannot be bypassed, is tamperproof, and is small enough to be verified. This describes which concept?

Medium
603

Which principle ensures that a user is granted only the permissions necessary to perform their job functions?

Easy
604

A healthcare organization uses a custom application to manage patient records. The application uses a database with encrypted columns for sensitive data. The security team discovers that an insider has been copying encrypted data to an external drive. While the data is encrypted, the encryption key is stored in a configuration file accessible to the application. Which additional control would best mitigate this risk?

Medium
605

A security analyst notices that an attacker is sending forged ARP messages onto a local area network, linking the attacker's MAC address with the IP address of the default gateway. This allows the attacker to intercept traffic destined for the gateway. Which OSI layer is directly targeted by this attack?

Medium
606

Which of the following is the primary purpose of a configuration management database (CMDB) in asset management?

Easy
607

A security engineer is designing a cryptographic solution to ensure data integrity and non-repudiation. Which combination should be used?

Medium
608

During a security audit, a vulnerability scanner reports a buffer overflow vulnerability in a legacy application. The application runs on a system with Data Execution Prevention (DEP/NX) enabled and Address Space Layout Randomization (ASLR) active. Which of the following is the most likely impact of these mitigations on a typical stack-based buffer overflow exploit?

Hard
609

A vulnerability scanner reports a vulnerability with a CVSS score of 9.8. What does this score indicate?

Medium
610

A security architect is designing a zero trust network. Which principle is fundamental to a zero trust architecture?

Medium
611

Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?

Easy
612

A network administrator is reviewing the security of the company's VPN solution. They discover that the current VPN uses PPTP. Which TWO of the following are significant security weaknesses associated with PPTP?

Hard
613

A small company with 50 employees operates a flat network where all workstations, servers, and printers are on a single subnet without segmentation. The company recently suffered a ransomware outbreak that spread rapidly from an infected workstation to the file server and multiple other machines, causing significant downtime. The IT manager wants to redesign the network to contain future outbreaks and limit lateral movement. The budget is limited, and the environment uses a mixture of managed and unmanaged switches. Which course of action would BEST mitigate the risk of lateral spread while minimizing cost and complexity?

Easy
614

A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?

Hard
615

Which security model focuses on preventing unauthorized access by enforcing a 'no read up, no write down' rule?

Easy
616

An organization is migrating from a waterfall to an Agile development methodology. Which of the following is a key security advantage of Agile?

Easy
617

A multinational corporation is developing a new cloud-based collaboration platform that handles sensitive intellectual property. The platform must ensure end-to-end encryption (E2EE) so that even the cloud provider cannot access the data. Users communicate via chat and file sharing. The architect proposes using a hybrid encryption scheme where each user has a public/private key pair, and for each message, a random symmetric key is used to encrypt the message, which is then encrypted with the recipient's public key. However, there is a requirement for the company to be able to lawfully intercept communications in case of a court order. This conflicts with E2EE. Which design can satisfy both confidentiality and lawful interception?

Hard
618

A company uses WPA2-Enterprise with EAP-TLS for wireless access. An employee reports that a new laptop cannot connect to the wireless network, while older laptops work fine. The employee has installed the correct client certificate. What is the most likely cause?

Medium
619

A multinational corporation deploys a single sign-on (SSO) solution using SAML 2.0 across all subsidiaries. Recently, users in one subsidiary report being unable to access an internal application. The identity provider (IdP) logs show successful authentication, but the service provider (SP) logs indicate assertion validation failures. Which of the following is the MOST likely cause?

Hard
620

An organization is migrating from WPA2 to WPA3 for its wireless network. Which improvement does WPA3 provide over WPA2?

Medium
621

A DevOps team implements a CI/CD pipeline that runs security scans automatically. The pipeline fails often due to false positives, causing delays. Which approach balances security and efficiency?

Easy
622

An organization's security team wants to validate that its incident response plan works as documented before a real breach occurs. The team needs to exercise communication paths, decision-making, and coordination among technical staff, legal, and public relations without touching production systems. Which of the following is the MOST appropriate exercise type?

Easy
623

A security analyst is evaluating the impact of upgrading web servers from TLS 1.2 to TLS 1.3. Which advantage does TLS 1.3 offer in terms of handshake efficiency?

Hard
624

During a security assessment, a penetration tester sends TCP SYN packets to various ports on a target server. Based on the responses, the tester determines which ports are open. This technique is commonly used at which OSI layer?

Medium
625

A company is deploying a new application that processes personally identifiable information (PII) in a hybrid cloud environment. The security architect needs to ensure that encryption keys are never exposed to the cloud provider. Which solution should be recommended?

Hard
626

A security engineer is evaluating a system that uses a Trusted Platform Module (TPM) for secure boot. The TPM measures the boot components and stores the measurements in Platform Configuration Registers (PCRs). Which of the following is a primary security goal achieved by this process?

Hard
627

An organization implements Privileged Access Management (PAM) and wants to reduce the risk of standing privileges. Which approach grants temporary elevated access only when needed?

Hard
628

A security manager is tasked with classifying data based on its sensitivity. Which of the following is the PRIMARY reason for data classification?

Easy
629

A security team is implementing a zero trust architecture. Which component is essential to enforce access decisions based on user identity, device posture, and context before granting access to resources?

Medium
630

A network administrator is configuring DNSSEC to protect against DNS spoofing. Which record type is used to provide cryptographic verification of DNS data origins?

Hard
631

Which of the following is a key difference between a policy and a guideline in information security governance?

Medium
632

A company uses SSH for remote administration. To enhance security, they want to implement public-key authentication. Which statement about SSH public-key authentication is true?

Medium
633

A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?

Hard
634

A security manager is conducting a risk assessment and needs to categorize the following risk responses: risk avoidance, risk transfer, risk mitigation, and risk acceptance. Which TWO of the following actions are examples of risk transfer? (Choose two.)

Medium
635

Which TWO of the following are essential components of a disaster recovery plan? (Choose two.)

Medium
636

A security engineer is evaluating VPN protocols for a remote access solution. The requirements are: strong encryption with perfect forward secrecy, support for mutual authentication, and no reliance on pre-shared keys that could be brute-forced. Which protocol best meets these requirements?

Hard
637

A security analyst is conducting a review of aggregated logs from firewalls, IDS, and servers to detect anomalous behavior. This activity is best described as:

Easy
638

Which of the following is a primary purpose of conducting a tabletop exercise for incident response?

Easy
639

Which of the following is a lightweight directory access protocol used for accessing and maintaining distributed directory information?

Easy
640

Which THREE of the following are essential components of a software supply chain security program? (Select exactly three.)

Hard
641

Which of the following is the PRIMARY purpose of the confidentiality principle in the CIA triad?

Easy
642

An organization plans to allow employees to access third-party SaaS applications using their corporate credentials. Which THREE are necessary components for implementing SAML-based identity federation?

Easy
643

A multinational corporation has experienced several security incidents where terminated employees retained access to internal systems for weeks after their departure. The HR department manually terminates accounts by sending notifications to IT, but the process is often delayed or missed. The company uses an identity management system (IDM) that supports automated provisioning and deprovisioning. The security team is tasked with reducing the risk of unauthorized access by former employees. Which of the following is the most effective course of action?

Medium
644

Which TWO of the following are essential components of a data classification policy? (Select two.)

Medium
645

Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
646

A financial application requires two employees to authorize a wire transfer. Which principle does this implement?

Medium
647

Match each access control type to its description.

Medium
648

A company recently suffered a data breach where an attacker was able to intercept network traffic and read sensitive data. Which network security control should be implemented to prevent this type of attack?

Medium
649

A company needs to protect data at rest in a cloud storage system. Which THREE encryption methods are appropriate for this purpose?

Hard
650

An organization wants to ensure that its web application is secure by analyzing the source code for vulnerabilities without executing the code. Which type of testing is most appropriate?

Hard
651

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

Hard
652

An organization wants to verify that its security policies are being followed by employees. Which testing method is most appropriate?

Medium
653

A company experiences a data breach. Which step should be taken first according to best practices?

Easy
654

A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?

Hard
655

During a risk assessment, a critical asset has a vulnerability with a CVSS score of 9.0. Which risk treatment strategy is most appropriate if the cost to mitigate exceeds the asset's value?

Hard
656

Match each threat type to its description.

Medium
657

During the requirements gathering phase of a secure SDLC, the team uses a threat modeling approach that focuses on identifying threats such as spoofing, tampering, and denial of service. Which threat modeling methodology is being employed?

Medium
658

A security auditor is reviewing an organization's governance framework. Which TWO of the following are commonly used frameworks for IT governance and security management?

Medium
659

An organization is designing a multicast network for live video streaming. They need to ensure that only authorized receivers can access the multicast group. Which technique should be implemented?

Hard
660

Which TWO features are true of IPsec tunnel mode compared to transport mode? (Select two.)

Easy
661

A business is evaluating risk treatment options for a high-likelihood, low-impact risk. The cost of mitigation exceeds the potential loss. Which risk treatment strategy is most appropriate?

Medium
662

During a penetration test, the tester gains access to a server and finds sensitive customer data. What should the tester do next?

Hard
663

A company is deploying a hypervisor to run multiple virtual servers. To minimize the risk of VM escape attacks, which type of hypervisor should they choose and what hardening measure is most effective?

Hard
664

Which of the following is a key objective of a business impact analysis (BIA)?

Medium
665

Which security control is most effective for preventing unauthorized access to a data center?

Easy
666

A security analyst notices that the SIEM is generating an overwhelming number of low-priority alerts from a single application server. The server is critical to operations. What is the BEST approach to reduce noise without compromising security?

Medium
667

An organization is implementing privacy by design for a new application that processes PII. Which practice BEST aligns with the data minimization principle?

Hard
668

A company is designing a network segmentation strategy to isolate a public-facing web server from the internal corporate network. Which of the following is the most appropriate architecture?

Medium
669

An organization is implementing OpenID Connect (OIDC) for authentication. Which THREE of the following are components of OIDC? (Choose three.)

Hard
670

A government agency requires a security model that prevents users from reading documents classified above their clearance level and from writing classified information to lower-level systems. Which model enforces these constraints?

Medium
671

A security analyst runs a vulnerability scan and sees the output shown in the exhibit. The analyst wants to remediate the most critical issue first. Which action should the analyst take to address the SQL injection vulnerability?

Medium
672

An employee leaves the company, and their user account is not disabled. This creates a security risk known as:

Medium
673

A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?

Hard
674

An organization is implementing a new governance framework to align IT with business goals. Which framework is specifically designed for IT service management?

Easy
675

Which THREE of the following are valid types of penetration testing based on the level of knowledge provided to the tester?

Hard
676

Refer to the exhibit. A user named Alice has encrypted files using EFS. What is a potential risk associated with the current configuration?

Medium
677

An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?

Hard
678

Your organization, a multinational e-commerce company, has suffered a ransomware attack that encrypted critical database servers and file shares. The ransom note demands payment in cryptocurrency within 48 hours or the data will be permanently destroyed. The company has a backup strategy that includes daily full backups and hourly incremental backups, stored both on-site and off-site. However, during the incident response, you discover that the most recent on-site backups are also encrypted because the backup server was connected to the network and affected by the same ransomware. Off-site backups are on tape and were last rotated out 72 hours ago. The CEO is pressuring to pay the ransom to restore operations quickly. Which option should the incident response team prioritize to minimize data loss and reputational damage?

Hard
679

A development team heavily uses third-party libraries. What is the most effective way to manage vulnerabilities in these libraries?

Easy
680

An organization's security team is drafting a document that defines the organization's intent to protect information assets and assigns responsibilities to the information security manager. The document must align with ISO/IEC 27001 requirements and be approved by executive management. Which type of document is being created?

Medium
681

A security team is reviewing application security and needs to analyze source code without executing the application. Which technique should they use?

Medium
682

During a security audit, it is discovered that the database server is also accepting connections from the web server. Which of the following is the most likely misconfiguration?

Hard
683

Under the Sarbanes-Oxley Act (SOX), which of the following is an example of an IT general control that supports financial reporting?

Hard
684

A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?

Medium
685

An organization is implementing federated identity to allow partners to access its web application. The solution must support single logout and attribute exchange. Which protocol is most appropriate?

Hard
686

A security architect is designing a system that must enforce the principle of least privilege at the operating system level. Which mechanism should be implemented to grant processes only the minimal permissions required for their tasks?

Medium
687

An organization is planning an external audit for SOC 2 Type II compliance. Which TWO of the following are true about this type of audit?

Medium
688

Which type of covert channel uses the timing of events or operations to transmit information?

Easy
689

An organization's data retention policy specifies that customer records must be retained for five years after the end of the business relationship. After that period, what should be done with the data according to best practices?

Medium
690

A security tester needs to test a new application for vulnerabilities but is concerned about contaminating the production database with test data. What is the best practice for conducting such tests?

Easy
691

A security architect is designing a system that must continue to function even when a component fails. The architect implements multiple layers of security controls so that if one fails, others still provide protection. Which principle is being applied?

Easy
692

Which OAuth 2.0 grant type is recommended for a public client (e.g., single-page application) that cannot securely store a client secret?

Medium
693

A financial institution is required to perform regular penetration tests on its online banking platform. The testing must be as realistic as possible while minimizing risk to production data. Which of the following approaches BEST meets these requirements?

Hard
694

An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)

Medium
695

During an audit, it is discovered that several users have inherited permissions through nested group memberships that violate least privilege. What is the best approach to correct this?

Hard
696

A security team is analyzing logs from multiple sources and notices anomalous outbound traffic to a known command-and-control server. What is the most likely conclusion?

Medium
697

During a code review, a developer identifies that the application uses a custom encryption algorithm for storing sensitive data. Which THREE of the following are secure cryptographic practices that should be recommended instead?

Medium
698

A security architect is designing a secure enclave for processing highly sensitive data. The architecture must ensure that even if the operating system is compromised, the enclave's memory contents remain confidential and integrity-protected. Which technology should be used?

Hard
699

A security analyst is evaluating the risk of a data breach in a healthcare organization. The asset value of the patient database is $500,000, and the exposure factor is 0.2. The annual rate of occurrence is estimated at 0.1. What is the annualized loss expectancy (ALE)?

Medium
700

A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?

Hard
701

An organization develops a SaaS platform that integrates with multiple third-party services via APIs. The platform handles authentication tokens and user data. A security review reveals that the platform uses hardcoded API keys in the source code. What is the most secure way to manage these secrets in a cloud-native environment?

Hard
702

An organization is implementing identity management and wants to ensure that when an employee leaves, all access is promptly revoked. Which process is most directly responsible for removing accounts and access rights for a leaver?

Hard
703

A company decides to purchase cyber insurance to cover potential losses from data breaches. Which risk response strategy does this represent?

Medium
704

Which TWO of the following are essential components of a quantitative risk analysis formula? (Choose two.)

Hard
705

An organization is implementing role-based access control (RBAC). Which two components are fundamental to the RBAC model? (Select TWO.)

Medium
706

An organization needs to ensure that backup tapes containing sensitive data are protected during transportation between sites. What is the most effective control?

Easy
707

Which VPN technology operates at Layer 2 of the OSI model and is often used in combination with IPsec to provide encryption?

Easy
708

A security manager is planning a penetration test and needs to ensure proper rules of engagement are established. Which TWO of the following are essential components of the rules of engagement?

Medium
709

Which of the following is a primary advantage of using a hardware security module (HSM) over software-based key storage?

Medium
710

Which THREE of the following are key practices in the OWASP ASVS (Application Security Verification Standard) for secure software? (Select exactly three.)

Medium
711

A financial institution is implementing a data retention policy to comply with regulatory requirements. The policy must ensure that transaction records are retained for 7 years and then securely destroyed. Which of the following is the BEST approach to implement this policy?

Medium
712

During a penetration testing engagement, which TWO of the following are essential components of the rules of engagement document?

Medium
713

You are the lead security analyst at a mid-sized financial services firm. At 2:15 PM, the SIEM alerts on multiple failed login attempts from an external IP address against the VPN gateway. The attempts stopped at 2:20 PM, but at 2:30 PM, a user reports that their account was used to send a phishing email to internal employees. You confirm that the user's account has been compromised. The CEO asks for an immediate update. What should be your FIRST action according to the incident response framework your company follows (based on NIST SP 800-61)?

Easy
714

An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?

Hard
715

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with which of the following?

Hard
716

Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
717

A security engineer is hardening a system against side-channel attacks that exploit variations in execution time or power consumption. Which TWO mitigations are specifically designed to counter such attacks? Select two.

Medium
718

A security architect is designing controls for a cloud-based file storage service that stores personally identifiable information (PII). Which control best ensures that data remains encrypted at rest without involving the cloud provider's key management?

Medium
719

In IPsec, which protocol provides both authentication and encryption for the packet payload, but does not encrypt the IP header?

Easy
720

A company needs to provide secure remote access to employees using company-issued laptops. The solution must support both web applications and legacy client-server apps without installing client software on the laptops. Which VPN technology is best?

Easy
721

During a digital forensics investigation, which of the following data sources has the highest order of volatility?

Medium
722

A security analyst detects repeated failed login attempts from a single external IP address targeting a user account. What is the best IMMEDIATE action?

Easy
723

An organization is adopting a microservices architecture. Which security control is most effective for ensuring that inter-service communication is authenticated and authorized?

Hard
724

Which THREE of the following are key components of a disaster recovery plan for a hot site? (Select three)

Hard
725

An organization's data retention policy requires that financial records be kept for seven years. After that period, the records must be destroyed in a manner that prevents reconstruction. Which of the following is the best sanitization method for paper records containing sensitive financial data?

Easy
726

A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?

Hard
727

Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?

Easy
728

A security analyst is reviewing the authentication mechanism of a web application. Which TWO of the following are examples of broken authentication vulnerabilities?

Easy
729

Which type of firewall is capable of inspecting application-layer data, performing SSL decryption, and integrating intrusion prevention capabilities?

Easy
730

A security analyst is reviewing a web application that handles financial transactions. Which TWO of the following are effective controls against Cross-Site Request Forgery (CSRF)?

Medium
731

A penetration tester is planning an engagement. Which of the following rules of engagement should be defined before testing begins? (Select TWO.)

Easy
732

An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?

Medium
733

A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?

Hard
734

Refer to the exhibit. A SAML response is received by the service provider. Which security issue is present?

Hard
735

A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?

Hard
736

A large hospital uses a wireless LAN (WLAN) for mobile medical devices and staff tablets. Recently, nurses reported intermittent connectivity drops and high retransmission rates specifically in the east wing near the elevator banks. The WLAN is based on 802.11ac in the 5 GHz band. The hospital's IT team has already checked for channel overlap, and the APs are configured to use non-overlapping channels with automatic channel selection. Signal strength in the area is adequate (-65 dBm). However, the retransmission rate spikes during peak hours. Which approach should the network team take FIRST to diagnose and resolve the issue?

Hard
737

During a security audit, it is discovered that a network firewall is allowing traffic based on source IP address only, without inspecting application-layer data. Which type of firewall is this?

Hard
738

A software development team is adopting secure coding practices. They decide to implement input validation for all user-supplied data. Which approach is recommended as the most effective for preventing injection attacks?

Easy
739

During a penetration test, the tester successfully gains access to a server and then attempts to move laterally to other systems. This phase is known as:

Hard
740

A large healthcare organization is subject to both HIPAA and GDPR. They are creating a data retention policy for electronic protected health information (ePHI) concerning European patients. HIPAA requires retention for 6 years from creation or last effective date, while GDPR requires that personal data not be kept longer than necessary for the purpose, with a general guideline of retaining for the duration of the relationship plus a reasonable period. The organization wants to minimize storage costs while ensuring compliance. Which approach should they take?

Hard
741

In a PKI hierarchy, a relying party needs to verify a certificate's validity. To reduce latency and improve privacy, which mechanism allows the relying party to obtain the revocation status without contacting the CA directly for each verification?

Hard
742

A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?

Medium
743

Under the GDPR, what is the maximum time frame for notifying the supervisory authority of a personal data breach?

Medium
744

A company deploys DNSSEC to protect its DNS infrastructure. Which cryptographic operation does DNSSEC primarily use to ensure the authenticity and integrity of DNS data?

Hard
745

A security manager is conducting a risk assessment for a new cloud application. The manager needs to estimate the potential financial loss from a data breach. Which approach should be used?

Medium
746

A company wants to implement 802.1X authentication on their wired network. Which components are required?

Medium
747

A company is considering outsourcing its customer support operations to a third-party vendor. Which of the following should be the PRIMARY risk management activity before finalizing the contract?

Hard
748

An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?

Medium
749

A company is preparing for an external audit to comply with PCI DSS. Which type of auditor is typically required to perform this assessment?

Medium
750

A security team is evaluating the results of a penetration test. The test revealed that a low-privileged user could escalate privileges to domain administrator. This is a critical finding. Which of the following should be the immediate next step?

Hard
751

A security team is performing a quantitative risk analysis for a server valued at $100,000. The exposure factor is 0.4 and the annual rate of occurrence is 2. What is the annualized loss expectancy (ALE)?

Medium
752

A company is deploying a VPN solution for remote employees using SSL/TLS VPN. Which TWO security considerations are important when implementing this type of VPN? (Select two.)

Hard
753

A SOC analyst receives an alert for a suspicious outbound connection from a server in the DMZ to an external IP on port 443. The server is a web application server that should only communicate internally. The analyst checks the process and finds it is 'svchost.exe' running from a non-standard path. What is the most appropriate immediate action?

Hard
754

In the context of identity management, which TWO of the following are risks associated with orphaned accounts? (Choose two.)

Medium
755

A health records system requires that doctors can write new records but cannot modify existing ones, and integrity is maintained through separation of duties. Which security model best fits this requirement?

Easy
756

Which type of firewall operates at Layer 7 and can inspect application payloads, such as blocking specific SQL commands or HTTP methods?

Easy
757

A security engineer is troubleshooting an authentication failure for a Windows domain user. The user receives 'Access denied' when trying to access a file server. The Kerberos ticket-granting ticket was successfully obtained. What is the most likely issue?

Hard
758

What is the PRIMARY purpose of a chain of custody in digital forensics?

Easy
759

An organization is required to report a personal data breach to the supervisory authority within 72 hours. Which regulation imposes this requirement?

Medium
760

A web application exposes an API that allows users to fetch data from internal network resources based on a URL parameter. An attacker discovers they can use this API to access internal servers that are not meant to be public. Which vulnerability is being exploited?

Medium
761

A company's data classification policy labels information as 'Internal Use Only' and 'Confidential.' An employee emails a 'Confidential' document to an external partner without authorization. Which type of data security objective has been violated?

Easy
762

A company uses Docker containers for microservices. What is the most important security measure for container images?

Medium
763

An auditor finds that a system uses the same service account for multiple applications. Which risk does this pose?

Easy
764

A developer is tasked with securely storing user passwords in a database. Which of the following is the most secure approach?

Medium
765

A security architect is designing a physical security system for a data center. Which of the following is an example of a layered physical control at the perimeter?

Easy
766

A security analyst notices repeated failed login attempts from an internal IP address on the domain controller. After enabling account lockout, the lockouts continue but the source IP changes. What is the best next step?

Medium
767

Which THREE of the following are valid risk response strategies?

Medium
768

You are the security architect for a global financial firm. The organization has recently deployed a new cloud-based application that requires low-latency connections between data centers in New York, London, and Tokyo. The existing WAN uses MPLS L3 VPNs with IPsec encryption. However, the application team reports excessive latency and packet loss during peak hours. The network team confirms that the MPLS links are underutilized, but the IPsec tunnels show high CPU usage on the edge routers. Additionally, the security policy mandates that all inter-data center traffic must be encrypted and authenticated. The firm has a budget for hardware upgrades but wants to minimize operational changes. Which of the following is the BEST course of action?

Hard
769

A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)

Medium
770

An organization wants to provide just-in-time administrative access to servers, with session recording and password vaulting. Which solution is best suited?

Hard
771

Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?

Easy
772

A security analyst is configuring a firewall to allow HTTP traffic (TCP port 80) from the internet to a web server in the DMZ. The firewall should also allow return traffic from the server back to the internet. Which type of firewall is best suited to handle this traffic while maintaining security?

Easy
773

A DevOps team is implementing a DevSecOps pipeline. Which of the following should be introduced first in the pipeline to catch security issues early and reduce remediation cost?

Medium
774

A database administrator (DBA) is responsible for implementing access controls and backup procedures for a customer database containing PII. The DBA reports to the data owner regarding security measures. Which role best describes the DBA's responsibilities?

Medium
775

Which of the following is a process that ensures users periodically confirm they still need access to systems and data?

Easy
776

An organization is preparing for an ISO 27001 certification audit. The audit will be performed by an external body. This type of audit is classified as:

Medium
777

A company is implementing a hot site as a disaster recovery option. Which of the following best describes a hot site?

Medium
778

A software developer is concerned about buffer overflow vulnerabilities. Which combination of mitigations makes it most difficult for an attacker to exploit a stack-based buffer overflow?

Medium
779

A security architect is evaluating hypervisor security for a multi-tenant cloud environment. Which type of hypervisor is considered more secure because it runs directly on the hardware without a host operating system, reducing the attack surface?

Medium
780

A security architect is designing a system to protect against side-channel attacks that exploit electromagnetic emanations. Which TWO controls are most effective?

Medium
781

A security analyst detects an attack where the attacker sends forged ARP messages to associate the attacker's MAC address with the IP address of the default gateway. Which OSI layer is primarily targeted by this attack?

Medium
782

A financial institution is migrating its customer data to a cloud environment. The cloud provider offers encryption at rest and in transit using AES-256 and TLS 1.2+. The compliance team requires that the organization maintain full control of encryption keys to meet regulatory obligations such as PCI DSS and local banking laws. The data is highly sensitive and includes personally identifiable information (PII). Which solution should the security architect recommend?

Medium
783

Which three BGP security mechanisms help protect against route hijacking? (Choose THREE.)

Hard
784

During a code review, a developer identifies a SQL injection vulnerability. What is the most effective fix?

Easy
785

Refer to the exhibit. A security analyst reviews this event log entry. What does this event indicate? Event Log Entry: Log Name: Security Source: Microsoft-Windows-Security-Auditing Event ID: 4625 Task Category: Logon Level: Information Keywords: Audit Failure User: N/A Computer: SRV01 Description: An account failed to log on. Subject: Security ID: SYSTEM Account Name: SRV01$ Account Domain: CORP Logon ID: 0x3E7 Logon Type: 3 Account For Which Logon Failed: Security ID: S-1-5-21-... Account Name: jdoe Account Domain: CORP Failure Information: Failure Reason: Account locked out. Status: 0xC0000234 Sub Status: 0x0

Hard
786

In LDAP, which attribute uniquely identifies an entry within the directory information tree?

Medium
787

An organization is implementing a new access control system. They want to ensure that users are who they claim to be, that actions can be traced to individuals, and that access rights are managed appropriately. Which framework encompasses all three of these goals?

Medium
788

A developer uses a tool that analyzes source code for potential security flaws without executing the program. This is an example of:

Medium
789

An organization is selecting security metrics to report to the board. Which THREE metrics would best demonstrate the effectiveness of the vulnerability management program?

Medium
790

Which of the following is the primary purpose of the CIA triad in information security?

Easy
791

A security engineer is troubleshooting a network where internal users can access internet websites but cannot reach the company's external VPN server (IP 203.0.113.50, UDP port 500). The firewall rule for VPN traffic is correctly configured. What is the most likely cause?

Medium
792

A global technology firm has implemented a continuous integration/continuous deployment (CI/CD) pipeline for its flagship software product. The security testing team is tasked with integrating security testing into the pipeline. The team has decided to use a static application security testing (SAST) tool and a software composition analysis (SCA) tool. They are currently running both tools every night against the entire codebase, but the developers complain that the reports are too long and often contain false positives. The team wants to improve the efficiency without sacrificing security coverage. Which of the following is the BEST strategy?

Hard
793

During a security audit of a web application, the following issues are found: (1) Session tokens are included in URLs, (2) The application does not invalidate session tokens after logout, and (3) Session tokens are predictable. Which THREE of the following controls are most appropriate to address these issues?

Medium
794

A healthcare organization implements a policy requiring all employees to use biometric fingerprint scanners to access patient records. Which of the following is the MOST significant risk associated with this authentication method?

Medium
795

Under the GDPR, which role is responsible for determining the purposes and means of processing personal data?

Medium
796

A company's security team discovers that an employee inadvertently shared sensitive customer data via a public cloud storage link. The incident response team contains the breach and notifies affected customers. Which of the following risk management strategies would BEST prevent recurrence?

Hard
797

A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?

Medium
798

An organization wants to protect sensitive data stored on laptops. Which of the following is the MOST effective control to prevent data loss if a laptop is stolen?

Easy
799

A financial services firm is deploying a customer-facing mobile banking app and wants to delegate limited access to account balances and transaction history to third-party budgeting apps without sharing the customer's banking credentials. The security architect must select controls that implement this delegation securely. (Choose two.)

Medium
800

Which THREE of the following are examples of data at rest?

Medium
801

A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?

Medium
802

During a security assessment, a penetration tester successfully performed a VLAN hopping attack from a host in VLAN 10 to a host in VLAN 20. The switches are configured with IEEE 802.1Q trunking. Which misconfiguration likely allowed this attack?

Hard
803

A financial institution requires that no single employee can approve a transaction and also reconcile the account. This is an example of which security principle?

Medium
804

A network architect is designing a secure connection between two data centers across an untrusted WAN. The requirement is to encrypt all traffic and authenticate both endpoints. Which protocol should be used?

Hard
805

A DevSecOps team wants to integrate security into the CI/CD pipeline without slowing down development. Which approach best achieves this?

Hard
806

An organization is conducting a Business Impact Analysis (BIA) as part of its business continuity planning. Which THREE of the following are essential components of a BIA? (Choose three.)

Medium
807

A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?

Medium
808

An organization is implementing a defense-in-depth strategy for a data center. Which THREE of the following are examples of physical security controls that align with layered defense?

Medium
809

A security team is planning to integrate security testing into the software development lifecycle. They want to identify vulnerabilities early and often. Which TWO of the following testing methods should be implemented during the development phase (before deployment) to catch code-level vulnerabilities?

Hard
810

Match each security assessment type to its description.

Medium
811

An organization's security policy requires that privileged accounts have their passwords changed every 30 days and be monitored. Which solution effectively manages these requirements?

Medium
812

A security analyst is reviewing access rights and discovers an active account belonging to a former employee who left six months ago. This is an example of:

Medium
813

A security team is conducting a penetration test on a web application. They identify that the application is vulnerable to reflected cross-site scripting (XSS). Which of the following is the most effective mitigation?

Medium
814

An organization wants to test its web application for vulnerabilities by running the application and probing it with malicious inputs. Which tool is BEST suited for this purpose?

Medium
815

A company's security team uses a tool that instruments the application at runtime to monitor and block attacks. This is an example of:

Hard
816

A security architect is defining security requirements for a new software development project that will use an Agile methodology. The organization wants to ensure that security is integrated throughout the development lifecycle. Which TWO of the following practices BEST support this goal? (Choose two.)

Hard

Frequently asked questions

What does the troubleshooting domain cover on the CISSP exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 816 troubleshooting questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.