Courseiva
Security and Risk ManagementmediumMultiple SelectObjective-mapped

CISSP Security and Risk Management Practice Question

Which TWO of the following are examples of non-repudiation controls? (Select two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Audit logs with timestamps

Non-repudiation ensures that a party cannot deny an action. Digital signatures and audit logs with timestamps provide evidence of actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Firewall rules

    Why it's wrong here

    Firewall rules define permissible network traffic flow based on predefined criteria (e.g., IP addresses, ports, protocols). While crucial for access control and network security, they do not inherently provide proof that a specific user performed an action or prevent a user from denying an action they took within the allowed parameters. Their function is to enforce boundaries, not to attribute actions to individuals irrevocably.

  • Encryption of data at rest

    Why it's wrong here

    Encryption of data at rest primarily protects the confidentiality of information by rendering it unreadable to unauthorized parties when stored on a device. While it safeguards data from disclosure, it does not inherently link an action (like accessing or modifying data) to a specific individual in a way that prevents them from later denying that action. Its core purpose is data secrecy, not accountability for actions.

  • Audit logs with timestamps

    Why this is correct

    Audit logs meticulously record system events, user activities, and changes, often including source IP, user ID, and a precise timestamp. When properly secured against tampering, these immutable records serve as irrefutable evidence of who performed what action and when, making it difficult for an individual to deny their involvement in a specific event. This comprehensive logging provides a verifiable trail for accountability.

  • Digital signatures

    Why this is correct

    Digital signatures cryptographically bind an individual's identity to a document or transaction, ensuring both the authenticity of the sender and the integrity of the data. By using a private key to sign, the sender cannot later deny having sent the message, and any alteration to the signed data invalidates the signature, thus providing strong non-repudiation for both origin and content.

  • Biometric authentication

    Why it's wrong here

    Biometric authentication verifies a user's identity based on unique physical or behavioral characteristics (e.g., fingerprint, retina scan) to grant access to a system or resource. While it strongly confirms 'who you are' at the point of access, it does not inherently create an undeniable, cryptographically linked record of subsequent actions performed by that authenticated user that prevents them from later denying those actions. Its primary role is identity verification for access.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.