CISSP Security and Risk Management Practice Question
Which TWO of the following are examples of non-repudiation controls? (Select two)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit logs with timestamps
Non-repudiation ensures that a party cannot deny an action. Digital signatures and audit logs with timestamps provide evidence of actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules
Why it's wrong here
Firewall rules define permissible network traffic flow based on predefined criteria (e.g., IP addresses, ports, protocols). While crucial for access control and network security, they do not inherently provide proof that a specific user performed an action or prevent a user from denying an action they took within the allowed parameters. Their function is to enforce boundaries, not to attribute actions to individuals irrevocably.
- ✗
Encryption of data at rest
Why it's wrong here
Encryption of data at rest primarily protects the confidentiality of information by rendering it unreadable to unauthorized parties when stored on a device. While it safeguards data from disclosure, it does not inherently link an action (like accessing or modifying data) to a specific individual in a way that prevents them from later denying that action. Its core purpose is data secrecy, not accountability for actions.
- ✓
Audit logs with timestamps
Why this is correct
Audit logs meticulously record system events, user activities, and changes, often including source IP, user ID, and a precise timestamp. When properly secured against tampering, these immutable records serve as irrefutable evidence of who performed what action and when, making it difficult for an individual to deny their involvement in a specific event. This comprehensive logging provides a verifiable trail for accountability.
- ✓
Digital signatures
Why this is correct
Digital signatures cryptographically bind an individual's identity to a document or transaction, ensuring both the authenticity of the sender and the integrity of the data. By using a private key to sign, the sender cannot later deny having sent the message, and any alteration to the signed data invalidates the signature, thus providing strong non-repudiation for both origin and content.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication verifies a user's identity based on unique physical or behavioral characteristics (e.g., fingerprint, retina scan) to grant access to a system or resource. While it strongly confirms 'who you are' at the point of access, it does not inherently create an undeniable, cryptographically linked record of subsequent actions performed by that authenticated user that prevents them from later denying those actions. Its primary role is identity verification for access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.