Courseiva

(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) (ISC) — Questions 175

219 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQeasy

Which component in the MITRE ATT&CK framework should be mapped to an SOC alerting rule to ensure the alert covers a specific adversary objective?

A.Technique
B.Tactic
C.Platform
D.Group
AnswerA

Techniques represent the specific methods an adversary uses to achieve their goal.

Why this answer

The 'Technique' ID is the core component that describes the 'how' of an adversary's action.

2
MCQmedium

When evaluating a third-party SaaS provider, which activity is most critical for assessing the vendor's security commitment?

A.Checking the vendor's marketing materials
B.Reviewing independent audit reports like SOC 2 Type II
C.Asking for the vendor's internal password policy
D.Verifying the vendor's office location
AnswerB

This is the industry standard for validating third-party security posture.

Why this answer

Reviewing independent audit reports (such as SOC 2 Type II) provides verified evidence of the vendor's controls, which is more reliable than self-assessments.

3
MCQmedium

Which of the following is the most important factor in the success of a security governance program?

A.The complexity of the security technology
B.Executive leadership support and commitment
C.The number of security staff members
D.The frequency of internal audits
AnswerB

Governance requires the mandate that only executive leadership can provide.

Why this answer

Executive leadership support is the foundation upon which the security program is built; without it, policies lack authority and resources remain scarce.

4
MCQmedium

Your organization uses a 'Warm Site' for its disaster recovery strategy. During a recent audit, you find that the site lacks the necessary bandwidth to support peak production traffic. What is the most appropriate management response?

A.Cancel the warm site contract and build a cold site.
B.Require all employees to work from home during a disaster to save bandwidth.
C.Accept the risk formally via the Risk Register without further mitigation.
D.Update the DRP to include a 'throttling' policy for non-critical services during failover.
AnswerD

Managing capacity through service degradation is a legitimate risk mitigation strategy when infrastructure is limited.

Why this answer

A warm site must be periodically validated against current production loads to ensure the SLA can be met.

5
MCQeasy

A security manager is evaluating organizational security culture. Which indicator provides the most reliable evidence of a 'security-first' culture?

A.Volume of self-reported security near-misses
B.Budget allocated to security
C.Percentage of employees who completed training
D.Number of security policies written
AnswerA

This indicates an empowered and vigilant workforce.

Why this answer

The reporting of near-misses by employees shows that staff are actively engaged in security awareness and feel safe identifying potential threats, which is a key trait of a mature security culture.

6
MCQmedium

You are auditing a third-party disaster recovery service provider. Which metric provides the most accurate evidence that the provider can meet your organization's required recovery point for a database cluster?

A.Mean Time to Recovery (MTTR) reports from previous tests.
B.Service Level Agreement (SLA) uptime percentages.
C.Replication Lag monitoring logs showing synchronization latency.
D.Annual penetration test results.
AnswerC

Replication lag directly indicates the age of the data at the secondary site, which is the definition of RPO.

Why this answer

RPO is defined by data loss tolerance, which is best measured by the age of the last successful backup or replication point.

7
MCQhard

An ISSMP needs to ensure compliance with global data privacy regulations in a multinational environment. Which governance strategy provides the most consistent approach?

A.Excluding high-risk regions from business operations
B.Maintaining separate policies for every country
C.Adopting the strictest regulatory standard as the global baseline
D.Relying on legal counsel to interpret local laws for every access request
AnswerC

This creates a unified, compliant, and manageable framework.

Why this answer

Implementing a global privacy framework that defaults to the strictest common denominator ensures compliance across all jurisdictions, simplifying operational management.

8
MCQeasy

In Splunk Enterprise Security, which dashboard should the SOC manager review to evaluate the effectiveness of the current correlation searches and the volume of notable events?

A.Threat Intelligence Dashboard
B.Asset Center
C.Content Management Dashboard
D.Incident Review Dashboard
AnswerC

This dashboard displays the health and performance metrics of correlation searches.

Why this answer

The Content Management dashboard provides insights into the performance, trigger volume, and status of correlation searches.

9
MCQmedium

A CISO is aligning the organizational information security strategy with the NIST Cybersecurity Framework (CSF) 2.0. Which specific function should the CISO prioritize to ensure that the organizational security culture promotes the identification of risks before they impact business operations?

A.Identify
B.Govern
C.Protect
D.Recover
AnswerB

The Govern function provides the oversight necessary to inform the organization's cybersecurity strategy and culture.

Why this answer

The 'Govern' function in NIST CSF 2.0 is specifically designed to establish the organizational context, risk management strategy, and cybersecurity supply chain risk management, which are foundational for aligning security culture with business objectives.

10
MCQeasy

A Chief Information Security Officer (CISO) is establishing an ethics program. Which framework provides the most comprehensive international standard for establishing an Information Security Management System (ISMS) encompassing compliance and ethical conduct?

A.COBIT 2019
B.ITIL 4
C.ISO/IEC 27001
D.NIST SP 800-53
AnswerC

ISO/IEC 27001 is the standard for building and certifying an ISMS.

Why this answer

ISO/IEC 27001 is the global standard for ISMS, which inherently includes compliance and governance management.

11
MCQhard

During a merger, you identify two different risk assessment methodologies. What is the best strategy for the ISSMP?

A.Develop a unified risk assessment framework for the combined entity
B.Ignore the methodologies and rely on external audits
C.Force the smaller entity to adopt the larger one's tool
D.Keep both and report separately
AnswerA

A unified framework ensures consistency and comparable risk data.

Why this answer

Harmonizing methodologies allows for a unified risk view across the enterprise, which is essential for consistent governance.

12
Multi-Selectmedium

Which THREE factors should an ISSMP consider when selecting security controls for a new system?

Select 3 answers
A.The vendor's marketing materials
B.The organization's threat landscape
C.Operational impact and performance
D.Regulatory and compliance requirements
E.The number of employees in the company
AnswersB, C, D

Controls must be relevant to the threats the organization faces.

Why this answer

Selecting controls involves balancing business requirements, regulatory compliance, and the actual threat landscape to ensure a proportionate risk response.

13
MCQeasy

In the context of the SDLC, what is the primary purpose of a 'Software Bill of Materials' (SBOM)?

A.To outline the project timeline.
B.To identify and manage open-source component risks.
C.To track the financial cost of software licenses.
D.To document the application architecture.
AnswerB

SBOMs are the standard for tracking dependencies for supply chain risk management.

Why this answer

An SBOM provides a comprehensive list of all components, libraries, and modules used in an application, which is crucial for managing supply chain security risks (e.g., identifying vulnerable dependencies).

14
Multi-Selectmedium

Which TWO of the following are essential components of an effective security governance framework?

Select 2 answers
A.The latest artificial intelligence tools
B.Clearly defined roles, responsibilities, and accountability
C.Documented security policies and standards
D.A dedicated office space for the security team
E.A large annual security budget
AnswersB, C

This ensures that people are assigned to execute and uphold the policies.

Why this answer

A comprehensive framework needs defined policies (what) and a structure of accountability (who) to ensure execution.

15
MCQhard

An ISSMP is leading a strategic security planning initiative using the balanced scorecard approach. Which perspective should be used to track metrics related to the workforce's proficiency and security awareness training success?

A.Financial
B.Customer
C.Internal Business Processes
D.Learning and Growth
AnswerD

This perspective specifically tracks training, skills, and organizational culture.

Why this answer

In the balanced scorecard framework, the 'Learning and Growth' perspective focuses on the human capital, infrastructure, and culture necessary to achieve the organization's security goals.

16
MCQeasy

Which of the following is a 'Key Risk Indicator' (KRI) for an organization's email security program?

A.Phishing simulation failure rate
B.Total number of employees
C.Cost of the email license
D.Number of emails received
AnswerA

An increasing failure rate indicates rising risk of compromise.

Why this answer

A KRI provides an early signal of increasing risk exposure. Phishing click-through rates measure effectiveness and exposure.

17
Multi-Selectmedium

Which TWO of the following are primary components of an effective strategic security planning process as defined by (ISC)2 best practices for an ISSMP?

Select 2 answers
A.Alignment of security objectives with organizational business goals
B.Creating a daily incident report for the Board
C.Manual review of every individual firewall rule change
D.Purchasing the most expensive security software available
E.Conducting a gap analysis between current security maturity and target state
AnswersA, E

Fundamental for ensuring security supports rather than hinders business outcomes.

Why this answer

Strategic planning requires aligning security goals with business objectives and conducting a formal gap analysis to determine the current state versus the future state.

18
MCQmedium

An organization is expanding into a new region. What is the most important first step for the ISSMP?

A.Updating the corporate security policy
B.Deploying security monitoring tools
C.Conducting a regulatory and legal gap analysis
D.Hiring a local security manager
AnswerC

This provides the foundation for all subsequent security and compliance activities.

Why this answer

Conducting a regulatory and legal gap analysis ensures that the organization understands the compliance requirements of the new jurisdiction before initiating operations.

19
MCQmedium

A CISO is aligning security objectives with the enterprise's Balanced Scorecard. Which perspective should the CISO focus on to demonstrate the value of security investments in achieving organizational mission readiness?

A.Customer Perspective
B.Learning and Growth Perspective
C.Internal Process Perspective
D.Financial Perspective
AnswerC

This aligns security controls with the key internal operations needed to achieve mission objectives.

Why this answer

The Internal Process perspective of the Balanced Scorecard focuses on the processes at which the organization must excel to satisfy shareholders and customers, which directly links security program maturity to organizational mission readiness.

20
Multi-Selectmedium

Which THREE pieces of information should be included in an 'Incident Notification' for executive stakeholders?

Select 3 answers
A.The raw packet captures of the attack
B.Next steps for mitigation and remediation
C.Current containment status
D.The specific login credentials used
E.High-level summary of the business impact
AnswersB, C, E

Executives need to know how the incident is being resolved.

Why this answer

Executives need the business impact, the current status, and the next planned actions.

21
MCQeasy

Which document defines the security requirements that must be met for a third-party vendor to integrate with the company's internal systems?

A.Memorandum of Understanding (MOU)
B.Interconnection Security Agreement (ISA)
C.Service Level Agreement
D.Acceptable Use Policy
AnswerB

The ISA is the technical document governing the secure connection between systems.

Why this answer

The Interconnection Security Agreement (ISA) specifically outlines the security requirements and responsibilities for connecting two systems.

22
MCQeasy

Which principle of 'Ethics in Security Leadership' dictates that a manager should prioritize the safety and privacy of the user over organizational convenience?

A.Transparency
B.Duty of care / Stewardship
C.Principle of least privilege
D.Separation of duties
AnswerB

Stewardship requires putting the protection of the resource and user rights first.

Why this answer

The principle of stewardship and duty of care requires leaders to act in the best interest of the data subject.

23
Multi-Selectmedium

Which TWO of the following are effective ways to promote a strong security culture?

Select 2 answers
A.Hiring more security staff
B.Establishing a 'blame-free' reporting environment for incidents
C.Mandating that all employees use a password manager
D.Publicly rewarding security-conscious behavior
E.Sending daily phishing emails to everyone
AnswersB, D

This encourages transparency and learning over secrecy.

Why this answer

Culture is driven by leadership example and the empowerment of employees to take ownership of security as a shared responsibility.

24
MCQhard

A security analyst is troubleshooting a failed connection to an internal application that is protected by Zscaler Private Access (ZPA). Which tool should the analyst use to verify if the policy is blocking the request?

A.Cloud Connector Log
B.App Connector Dashboard
C.Policy Simulation Tool
D.ZPA Diagnostics
AnswerD

ZPA Diagnostics allows viewing the logs of connection attempts and the associated policy decisions.

Why this answer

The Zscaler 'Diagnostics' or 'Insights' portal provides detailed logs on why a specific user-to-app connection was denied or allowed.

25
Multi-Selecteasy

Which TWO data sources are most critical for detecting lateral movement within a corporate network?

Select 2 answers
A.Authentication logs (e.g., Kerberos/LDAP)
B.External DNS query logs
C.Internal firewall traffic logs
D.Public web server logs
E.VPN gateway logs
AnswersA, C

Authentication logs show the 'who' and 'where' of credential usage on other hosts.

Why this answer

Lateral movement is characterized by network traffic between internal hosts and authentication logs indicating access attempts.

26
Multi-Selecthard

Which THREE of the following strategies should be included in a 'Disaster Recovery Program Oversight' function to ensure long-term viability?

Select 3 answers
A.Annual validation of the BIA to ensure it reflects current business priorities.
B.Mandating the use of specific hardware vendors for all offices.
C.Standardization of server naming conventions across all data centers.
D.Conducting regular, risk-based testing of the recovery plans.
E.Periodic review and updating of the DRP based on infrastructure changes.
AnswersA, D, E

Business priorities shift; the BIA must be validated to keep DR efforts focused.

Why this answer

Oversight involves continuous validation through testing, alignment with changing business goals, and periodic audits of the documentation.

27
Multi-Selectmedium

Which TWO of the following are key responsibilities of the CISO regarding corporate risk management?

Select 2 answers
A.Aligning security controls with the enterprise risk appetite
B.Determining the organization's risk appetite
C.Hiring external penetration testers
D.Personally fixing every firewall misconfiguration
E.Reporting on residual risk to the board
AnswersA, E

Ensuring controls match the risk appetite is a primary CISO duty.

Why this answer

The CISO is responsible for translating technical risks into business impact and for ensuring that the organization's risk appetite is reflected in security controls.

28
MCQhard

In an environment governed by SOX (Sarbanes-Oxley), which feature of AWS IAM must be utilized to maintain strict 'Segregation of Duties' for account administrative tasks?

A.AWS IAM Roles with Service Control Policies (SCPs)
B.AWS CloudTrail insights
C.IAM User Access Keys
D.AWS Directory Service
AnswerA

SCPs provide the guardrails necessary to prevent administrative overlap.

Why this answer

IAM Policies with explicit denies or restricted permission sets (like Service Control Policies) enforce segregation of duties in AWS.

29
MCQmedium

A security manager is conducting a third-party risk assessment using the NIST Cybersecurity Framework. Which tool in the AWS Artifact portal is most appropriate for obtaining the necessary SOC 2 Type II reports to fulfill compliance auditing requirements?

A.AWS Trusted Advisor
B.AWS Config rules
C.AWS Security Hub
D.AWS Artifact Reports
AnswerD

AWS Artifact is the designated portal for obtaining compliance reports.

Why this answer

AWS Artifact provides on-demand access to AWS compliance reports, including SOC 2 Type II, for auditing purposes.

30
MCQhard

When integrating risk management with the SDLC, which activity represents the most effective 'Shift-Left' approach to mitigate design-level risk?

A.Static Application Security Testing (SAST)
B.Threat Modeling
C.Dynamic Application Security Testing (DAST)
D.Penetration Testing
AnswerB

Threat modeling is the gold standard for identifying design risks early.

Why this answer

Threat modeling during the design phase identifies architectural risks before code is written.

31
Multi-Selectmedium

Which THREE types of data should be ingested by a SIEM to improve its threat detection capabilities?

Select 3 answers
A.Authentication/Identity logs
B.Firewall/Network traffic logs
C.Building HVAC monitoring logs
D.Endpoint Detection and Response (EDR) events
E.Office breakroom temperature logs
AnswersA, B, D

Identity logs allow detection of credential misuse.

Why this answer

A robust SIEM needs endpoint logs, network logs, and identity/access logs to correlate threats.

32
MCQhard

Your organization has decided to use a 'Cloud Disaster Recovery' service. The vendor provides a 'Pilot Light' strategy. What does this mean for your organization's recovery capability?

A.A complete replica of the production environment is running 24/7.
B.Core services are running, and the remaining infrastructure can be scaled up on demand.
C.The environment only exists as data snapshots in cold storage.
D.The environment is hosted on-premises and fails over to a secondary data center.
AnswerB

This is the definition of a pilot light approach, balancing cost and speed.

Why this answer

A pilot light maintains critical core components (e.g., database) in a running state, while application tiers are spun up on-demand during a disaster.

33
MCQeasy

An ISSMP is conducting a security awareness program. What is the primary metric for measuring the success of this program?

A.The cost per employee for training
B.Number of training slides created
C.Percentage of employees who attended sessions
D.Change in behavior evidenced by incident reduction or simulation data
AnswerD

This directly reflects the effectiveness of the training.

Why this answer

A reduction in actual security incidents or improved response to simulated phishing tests are direct indicators of improved security behavior, which is the program's goal.

34
MCQmedium

When executive leadership discusses 'Acceptable Risk', they are referring to:

A.Inherent risk before controls
B.Zero risk tolerance
C.The total budget for security
D.Residual risk within the risk appetite
AnswerD

This is the definition of acceptable risk.

Why this answer

Acceptable risk is the remaining risk after controls are applied that remains within the organizational risk tolerance.

35
MCQeasy

When designing the Crisis Communication Plan, why is it essential to establish pre-approved communication templates?

A.To allow marketing teams to create brand-focused content.
B.To bypass legal review during the crisis.
C.To ensure consistent and rapid messaging during high-stress situations.
D.To fulfill regulatory requirements for daily status reports.
AnswerC

Pre-approved templates minimize time spent drafting messages and reduce the likelihood of inconsistent communication.

Why this answer

During a crisis, speed and accuracy are critical. Templates reduce cognitive load and prevent errors in messaging.

36
MCQhard

Your organization is performing a supply chain risk assessment. Which factor is most critical when evaluating a critical software vendor?

A.The vendor's secure software development lifecycle (SSDLC) practices
B.The physical location of their headquarters
C.The number of employees at the vendor
D.The vendor's marketing budget
AnswerA

Assessing how they build software is the highest priority for supply chain security.

Why this answer

Vendor financial stability and their own security development lifecycle (SDL) are paramount for long-term supply chain risk.

37
Multi-Selecthard

Which THREE of the following should be included in an annual strategic security plan?

Select 3 answers
A.Current state assessment of security maturity
B.Resource and budget requirements
C.A detailed list of every firewall rule
D.A list of all employee salaries
E.Proposed security projects and initiatives
AnswersA, B, E

You must understand where you are to plan where to go.

Why this answer

A strategic plan must look at current maturity, future initiatives (projects), and the resources required to achieve those goals.

38
MCQmedium

A project team is using Jira for issue tracking and wants to implement a formal change control board (CCB) approval workflow. Which feature should the ISSMP configure to ensure changes cannot be merged without approval?

A.Workflow Validators
B.Automation for Jira
C.Issue Security Levels
D.Post-functions
AnswerA

Validators ensure that specific conditions, such as the presence of an approval comment or a specific flag, are met before a workflow transition occurs.

Why this answer

Using Jira's 'Workflow Validator' or 'Conditions' on the transition to the 'Ready for Production' status enforces that approvals (e.g., from an authorized manager) are logged before code can be merged.

39
MCQmedium

A company is migrating legacy applications to AWS. The ISSMP mandates that changes to the production environment must follow a strict change control process. Which AWS native tool provides the necessary auditing and change management history for infrastructure changes?

A.AWS CloudTrail
B.AWS Shield
C.AWS Config
D.AWS Trusted Advisor
AnswerA

CloudTrail logs every action taken in the AWS account, providing the audit log required for change management.

Why this answer

AWS CloudTrail provides the audit trail of API calls and infrastructure changes, which is the cornerstone of change control auditing.

40
MCQhard

A company is subject to HIPAA. When configuring Microsoft 365, which feature is critical to ensure that PHI (Protected Health Information) is not accidentally shared via email while meeting 'Minimum Necessary' disclosure standards?

A.Exchange Online Protection (EOP) malware filtering
B.Microsoft Defender for Endpoint
C.Microsoft Purview DLP policies
D.Retention labels in the Compliance Center
AnswerC

Purview DLP identifies and restricts the sharing of PHI content.

Why this answer

Data Loss Prevention (DLP) policies in Microsoft 365 can be configured to detect PHI patterns and block or encrypt emails accordingly.

41
MCQhard

An organization uses a microservices architecture. How can the ISSMP ensure that inter-service communication is encrypted and that services are authenticated to one another?

A.Hardcoding API keys into environment variables.
B.Installing an antivirus agent on every container.
C.Using a standard VPN between all services.
D.Using a Service Mesh (e.g., Istio) to enforce mTLS.
AnswerD

A service mesh handles mTLS and identity at the infrastructure layer, independent of the application code.

Why this answer

Implementing a Service Mesh (e.g., Istio) provides mutual TLS (mTLS) for encrypted communication and cryptographic identity verification between services.

42
MCQmedium

A Chief Risk Officer is utilizing the FAIR framework to quantify cyber risk. Which input is required to calculate the Loss Event Frequency?

A.Primary Loss Magnitude and Secondary Loss Magnitude
B.Inherent Risk and Residual Risk
C.Control Strength and Asset Valuation
D.Threat Event Frequency and Vulnerability
AnswerD

Correct, these are the two components of Loss Event Frequency.

Why this answer

FAIR defines Loss Event Frequency as a function of Threat Event Frequency and Vulnerability. Threat Capability and Threat Event Frequency are primary drivers.

43
MCQmedium

An organization uses Microsoft Sentinel. To ensure that an automated incident response playbook only triggers when a high-severity alert originates from a specific production subnet, where should the condition be defined?

A.In the Azure Policy definitions
B.In the Sentinel Data Connector configuration
C.Inside the KQL query of the analytic rule
D.In the Automation Rule trigger condition
AnswerD

Automation rules allow filtering by alert severity and entity values before triggering the playbook.

Why this answer

The logic app trigger conditions or the Sentinel Automation Rule 'If' conditions allow filtering based on alert properties like severity and entity fields.

44
Multi-Selectmedium

Which TWO actions should a security manager take to ensure an organization remains compliant with the Sarbanes-Oxley (SOX) Act regarding IT controls?

Select 2 answers
A.Conduct quarterly physical server room inspections
B.Encrypt all data at rest using AES-256
C.Maintain comprehensive audit logs for all financial system changes
D.Ensure all employees receive annual ethics training
E.Implement strict access control and separation of duties for financial applications
AnswersC, E

Audit logs are mandatory to provide accountability for financial transactions.

Why this answer

SOX focuses on financial reporting integrity, specifically requiring access controls and audit trails.

45
MCQmedium

When performing a risk assessment on a new SaaS implementation, which document is most useful for understanding the vendor's risk profile?

A.The vendor's sales brochure
B.A SOC 2 Type II report
C.The vendor's stock ticker symbol
D.The vendor's customer list
AnswerB

Provides verified information on control effectiveness.

Why this answer

A SOC 2 Type II report provides an independent auditor's assessment of the vendor's security controls over time.

46
MCQmedium

An organization wants to monitor its compliance with CIS Benchmarks automatically. Which tool is best suited to provide an automated 'Compliance Score' against these benchmarks in a multi-cloud environment?

A.Azure Resource Graph
B.Microsoft Purview Data Map
C.Microsoft Defender for Cloud
D.Azure Network Watcher
AnswerC

Defender for Cloud offers built-in regulatory compliance dashboards and CIS benchmark tracking.

Why this answer

Microsoft Defender for Cloud provides automated assessments against industry standards, including CIS Benchmarks.

47
Multi-Selecthard

Which THREE configurations are necessary to satisfy the 'Technical Safeguards' requirement under HIPAA for data at rest?

Select 3 answers
A.Physical fencing around the data center
B.Encryption of all storage volumes containing ePHI
C.Unique user identification for all system access
D.Automatic logoff of inactive sessions
E.Annual financial budget reporting
AnswersB, C, D

Encryption is the primary technical safeguard for data at rest.

Why this answer

HIPAA requires encryption and access control to protect ePHI at rest.

48
MCQmedium

An ISSMP is reviewing an organizational risk register. Which field is essential for effective risk prioritization?

A.Name of the auditor
B.Asset owner's email address
C.Inherent risk rating
D.Last modified date
AnswerC

The rating allows for comparative prioritization of threats.

Why this answer

Risk Rating (often Impact x Likelihood) is necessary to rank risks for treatment.

49
MCQmedium

You are implementing a disaster recovery strategy for a database that uses synchronous replication. What is the most significant trade-off you must accept by enforcing this configuration?

A.Increased latency for write operations.
B.Higher risk of data corruption.
C.Increased probability of backup failure.
D.Limited scalability of the database cluster.
AnswerA

Synchronous replication mandates that the primary site waits for confirmation from the secondary, increasing write latency.

Why this answer

Synchronous replication guarantees zero data loss (RPO=0) but introduces latency overhead on write operations because the commit must wait for the acknowledgment from the secondary site.

50
Multi-Selecthard

When conducting a risk assessment on an IoT ecosystem, which THREE factors are specifically critical?

Select 3 answers
A.The manufacturer's stock price history
B.Device patch management capabilities
C.Physical security of the device endpoints
D.Network isolation and segmentation
E.The aesthetic design of the device
AnswersB, C, D

Many IoT devices are unpatchable.

Why this answer

IoT devices often have poor security (patching challenges), high network exposure, and physical access vulnerabilities.

51
MCQmedium

When evaluating the effectiveness of a risk mitigation strategy, which stakeholder is most critical to involve in the sign-off process?

A.The IT helpdesk manager
B.The external auditor
C.The Business Process Owner
D.The HR department
AnswerC

They own the risk and must accept the residual level.

Why this answer

The Business Process Owner is the ultimate owner of the risk and must accept the residual risk.

52
Multi-Selectmedium

Which TWO of the following are primary risks associated with an 'asynchronous' data replication strategy?

Select 2 answers
A.Excessive consumption of bandwidth during peak hours.
B.Total system failure due to incompatible storage protocols.
C.The RPO will always be greater than zero.
D.Potential for data divergence (data loss) in the event of a failover.
E.Increased network latency on the primary application.
AnswersC, D

Because there is a lag, some data loss is inevitable if the primary site fails suddenly.

Why this answer

Asynchronous replication introduces a lag, meaning if the primary fails, the latest data might not have reached the secondary, risking data loss.

53
MCQeasy

What is the primary objective of a 'Security Gate' in an SDLC?

A.To ensure security activities were completed before moving to the next phase.
B.To automate the removal of legacy hardware.
C.To stop all software development until the budget is approved.
D.To provide a location for developers to submit their resignation.
AnswerA

Security gates act as validation points to prevent security defects from moving downstream.

Why this answer

Security gates are checkpoints placed at the end of SDLC phases to verify that security requirements have been satisfied before proceeding to the next stage.

54
MCQeasy

When reporting risk to the Board of Directors, which metric is most effective for demonstrating the value of an investment in a new EDR solution?

A.Time taken to deploy the agent
B.Reduction in annualized loss expectancy (ALE)
C.Version number of the security software
D.Number of detected malware incidents
AnswerB

ALE reduction directly correlates to financial risk management.

Why this answer

Risk reduction is best demonstrated by showing the shift in risk posture (heat map movement) or cost-avoidance metrics.

55
MCQhard

A company is integrating a Third-Party API into their application. What must the ISSMP ensure is included in the risk assessment process?

A.Asking the vendor to sign a standard NDA.
B.Verifying the vendor's stock price.
C.Reviewing the vendor's SOC2 Type II report.
D.Checking if the vendor has a nice website.
AnswerC

Reviewing independent audit reports is a standard method for assessing third-party security posture.

Why this answer

The ISSMP must perform a 'Third-Party Risk Assessment' (TPRA) that evaluates the vendor's security controls, such as their SOC2 Type II report or ISO 27001 certification, to ensure the integration does not violate company security standards.

56
Multi-Selecthard

Which THREE items must be included in a 'Data Processing Agreement' (DPA) between a cloud provider and a controller under GDPR?

Select 3 answers
A.Commitment that the processor only processes data on documented instructions
B.Obligations of the processor to assist the controller in responding to DSARs
C.Marketing agreements for joint promotions
D.The price list for cloud services
E.Obligation for the processor to notify the controller of data breaches
AnswersA, B, E

This ensures the processor does not exceed its authority.

Why this answer

GDPR Article 28 lists mandatory items for DPAs, including security obligations and rights of the data subject.

57
MCQeasy

Which of the following best describes the 'Risk Management Framework' (RMF) process step of 'Assess'?

A.Authorize the system
B.Define the boundary
C.Determine the effectiveness of controls
D.Select controls
AnswerC

Assessment evaluates the implementation and effectiveness of selected controls.

Why this answer

In NIST SP 800-37, 'Assess' involves evaluating the controls to determine if they are implemented correctly and effective.

58
MCQhard

A company uses Microsoft Entra ID. To comply with the 'Zero Trust' requirement for 'Explicit Verification', which conditional access grant control must be enabled for all administrative access?

A.Require Password Change
B.Require Multi-Factor Authentication
C.Enable Identity Protection alerts
D.Disable legacy authentication
AnswerB

MFA is the mandatory control for explicit identity verification.

Why this answer

Requiring MFA and device compliance is the core component of explicit verification in Zero Trust.

59
MCQhard

The board of directors requests a quantitative risk assessment for a new cloud-based initiative. Which metric provides the best representation of potential financial exposure to the organization for a single, significant security event?

A.Single Loss Expectancy (SLE)
B.Residual Risk
C.Annualized Loss Expectancy (ALE)
D.Annualized Rate of Occurrence (ARO)
AnswerA

SLE is the direct product of the asset value and the exposure factor.

Why this answer

Single Loss Expectancy (SLE) is the monetary loss expected from a single security incident, making it the most direct metric for board-level financial exposure discussions.

60
MCQmedium

A risk assessment reveals that a legacy system stores PII without encryption. The business cannot replace it. What is the most appropriate risk management action?

A.Avoid the risk
B.Implement compensating controls
C.Transfer the risk
D.Accept the risk
AnswerB

Implementing network segmentation or egress filtering mitigates the risk when encryption is impossible.

Why this answer

Mitigating the risk (compensating controls) is the standard professional approach when avoidance is not feasible.

61
Multi-Selecthard

Which THREE of the following are important considerations for an ISSMP when outsourcing security functions?

Select 3 answers
A.Retaining the ultimate accountability for security
B.Requiring the vendor to use only your internal tools
C.Defining clear Service Level Agreements (SLAs)
D.Verifying the provider's security compliance and capability
E.Choosing the vendor with the lowest price
AnswersA, C, D

The organization cannot outsource its legal and regulatory responsibility.

Why this answer

Outsourcing requires careful legal review, performance monitoring (SLAs), and ensuring that the provider is properly integrated into the organization's overall risk management.

62
MCQmedium

An organization is conducting a risk assessment and identifies a critical vulnerability in a legacy system that cannot be patched. Which of the following is the most appropriate risk management strategy to address this vulnerability?

A.Transfer the risk to a third-party vendor without further assessment.
B.Decommission the system immediately regardless of business impact.
C.Implement compensatory controls to reduce the risk.
D.Accept the risk without implementing any additional controls.
AnswerC

Compensatory controls are designed to mitigate risk when the primary control (patching) cannot be implemented.

Why this answer

When patching is not possible, implementing compensatory controls (such as network segmentation or enhanced monitoring) is the standard approach to reduce the residual risk to an acceptable level.

63
Multi-Selectmedium

When designing a security program, which TWO of the following factors should be considered to ensure the program can successfully scale with organizational growth?

Select 2 answers
A.Limiting the organization to only one type of operating system.
B.Designing security controls that are modular and can be easily integrated.
C.Requiring all security configurations to be manually audited daily.
D.Automating security controls and workflows to reduce manual overhead.
E.Maintaining all security data in a single, local spreadsheet.
AnswersB, D

Modular design allows for easier integration into new environments as the organization grows.

Why this answer

Scalability depends on automating processes where possible and ensuring the security architecture is modular and flexible to adapt to new business units or technologies.

64
MCQmedium

During a software audit, it is found that developers have administrative access to the production database to troubleshoot errors. What change should the ISSMP implement?

A.Remove all access and require developers to submit tickets for DBAs to perform changes.
B.Create a shared 'admin' account for all developers.
C.Implement Just-In-Time (JIT) privileged access for troubleshooting.
D.Only allow access during business hours.
AnswerC

JIT access provides temporary, audited credentials, minimizing standing privileges.

Why this answer

The ISSMP should implement a 'break-glass' access policy where developers can request temporary, audited access via a tool like HashiCorp Boundary or AWS IAM Identity Center, rather than having persistent standing access.

65
Multi-Selectmedium

Which TWO aspects of the NIST Cybersecurity Framework (CSF) are most relevant when establishing a 'Compliance Program Management' function?

Select 2 answers
A.Recover (RC) function
B.Identify (ID) function
C.Detect (DE) function
D.Govern (GV) function
E.Protect (PR) function
AnswersB, D

The 'Identify' function helps define the scope and regulatory requirements.

Why this answer

The CSF provides structure; 'Govern' and 'Identify' are the pillars for compliance management.

66
Multi-Selecteasy

Which THREE of the following represent the primary responsibilities of executive leadership in fostering a strong organizational security culture?

Select 3 answers
A.Holding business units accountable for security outcomes
B.Writing technical documentation for network architecture
C.Installing software patches on all end-user workstations
D.Approving and supporting the security strategy and resource allocation
E.Modeling secure behavior and prioritizing security in decision-making
AnswersA, D, E

Ensures security is a shared responsibility across the organization.

Why this answer

Executive leadership is responsible for setting the tone, providing resources, and ensuring accountability, which directly shapes the security culture of the organization.

67
MCQeasy

Which document serves as the primary governing authority to define the triggers, escalation paths, and communication roles during a declared crisis event?

A.Business Impact Analysis (BIA)
B.Crisis Management Plan (CMP)
C.Standard Operating Procedure (SOP)
D.Disaster Recovery Plan (DRP)
AnswerB

The CMP specifically addresses leadership, communication, and decision-making during crisis events.

Why this answer

The Crisis Management Plan provides the governance for decision-making during a crisis, whereas the DRP focuses on technical restoration.

68
MCQhard

During a disaster recovery simulation for a hybrid cloud environment, you discover that the automated orchestration tool fails to restore dependencies in the correct order because the cloud provider's metadata tags were purged. What is the most effective administrative control to prevent this during a real event?

A.Enforce mandatory tagging policies using AWS Service Control Policies (SCPs) or Azure Policy.
B.Increase the RTO buffer time in the Service Level Agreement (SLA).
C.Switch from automated restoration to manual snapshot-based restores.
D.Implement a manual verification step in the Disaster Recovery Plan (DRP) documentation.
AnswerA

Policy-based enforcement ensures metadata persistence required for automated recovery orchestration.

Why this answer

Maintaining configuration drift control and metadata persistence through Infrastructure as Code (IaC) is essential for automated recovery.

69
MCQhard

In a Kubernetes cluster, which policy must be configured to ensure that containers are compliant with the CIS Kubernetes Benchmark regarding 'Privileged Containers'?

A.Cluster Autoscaler settings
B.Namespace resource quotas
C.Pod Security Admission policies
D.Kube-proxy configuration
AnswerC

These enforce security standards including the prohibition of privileged containers.

Why this answer

Pod Security Admissions (formerly Pod Security Policies) can explicitly forbid privileged containers to maintain security benchmarks.

70
MCQmedium

When managing a FortiGate firewall, which feature allows the SOC to dynamically update network objects based on external threat feeds?

A.DHCP Server
B.External Connectors
C.Traffic Shaper
D.Virtual Domains (VDOMs)
AnswerB

External Connectors integrate with threat feeds to update dynamic address objects.

Why this answer

FortiGate 'External Connectors' allow the ingestion of dynamic threat intelligence lists.

71
MCQhard

Your organization adopts the NIST CSF 2.0. Which specific function should be assessed to identify gaps in your enterprise risk management program's Governance component?

A.Govern
B.Protect
C.Respond
D.Recover
E.Identify
AnswerA

The Govern function addresses organizational context and risk management strategy.

Why this answer

The 'Govern' function was elevated in CSF 2.0 to encompass enterprise risk management, strategy, and policy.

72
Multi-Selectmedium

Which TWO factors should be used to weigh the 'Impact' in a risk assessment?

Select 2 answers
A.The number of hours the system has been running
B.The font size used in internal memos
C.The replacement cost of the asset
D.The age of the server hardware
E.The criticality of the data or service to business operations
AnswersC, E

A direct financial component of impact.

Why this answer

Impact is generally measured by the potential loss to the business, focusing on availability, confidentiality, and integrity.

73
Multi-Selecthard

Which THREE actions are necessary when preparing to decommission a cloud-based Virtual Machine (VM)?

Select 3 answers
A.Taking a final full-disk backup to a public S3 bucket
B.Deleting associated snapshots and backups
C.Updating the local hardware inventory
D.Terminating the compute instance
E.Removing identity and access management (IAM) permissions
AnswersB, D, E

Snapshots can contain sensitive data that persists after the VM is deleted.

Why this answer

Decommissioning in the cloud involves ensuring data is wiped, access rights are removed, and the resources are actually terminated to prevent billing and security exposure.

74
MCQmedium

When managing cross-functional security projects, which stakeholder communication strategy is most effective for securing project resources?

A.Focusing strictly on threat lists and vulnerability counts
B.Aligning security project outcomes with business goals
C.Escalating all requests to the CEO
D.Using technical jargon to emphasize the severity of risks
AnswerB

Demonstrating value in business terms is the most effective way to secure resources.

Why this answer

Linking security initiatives to business outcomes, such as reduced downtime or faster time-to-market, ensures that non-technical stakeholders understand the necessity of resource allocation.

75
MCQmedium

When classifying business processes for BCP, what is the 'Recovery Time Objective' (RTO) most effectively used for?

A.Identifying the critical staff needed for recovery.
B.Determining the technology and infrastructure requirements for restoration.
C.Assessing the data loss tolerance.
D.Calculating the financial impact of the event.
AnswerB

RTO drives the technical design (e.g., hot vs. cold site) to meet the business window.

Why this answer

RTO informs the investment and technology choices for the recovery strategy to ensure service restoration occurs within the business-defined window.

Page 1 of 3

Page 2

All pages