Courseiva

(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) (ISC) — Questions 151219

219 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
MCQeasy

During an incident, which document is used by the SOC to record evidence, timestamps, and actions taken to ensure admissibility in a legal proceeding?

A.Chain of Custody
B.Runbook
C.Lessons Learned Report
D.Risk Register
AnswerA

This document ensures the integrity and legal admissibility of evidence.

Why this answer

The Chain of Custody document tracks the handling of evidence from discovery through to investigation.

152
MCQeasy

An organization wants to improve its security posture by adopting a continuous monitoring approach. Which approach is most effective for an ISSMP to champion?

A.Implementing integrated security telemetry and automated analysis.
B.Relying on manual logs review on a monthly basis.
C.Implementing a firewall with default deny rules.
D.Conducting annual penetration tests.
AnswerA

This approach enables real-time visibility and faster response to emerging threats, which is central to continuous monitoring.

Why this answer

Continuous monitoring requires integrated data collection, automated analysis, and real-time reporting to provide actionable insights, which is the definition of a robust monitoring strategy.

153
Multi-Selecthard

When building an Enterprise Risk Management (ERM) program, which THREE factors must be considered to ensure integration with the organization?

Select 3 answers
A.Integration with existing business processes
B.Replacing all existing staff with security experts
C.Purchasing the most expensive security tool available
D.Alignment with business strategic objectives
E.Organizational culture and risk appetite
AnswersA, D, E

Seamless operation is key to adoption.

Why this answer

ERM is successful when it aligns with the culture, business goals, and organizational structure.

154
MCQeasy

An ISSMP is overseeing the integration of security into a new DevOps pipeline using Jenkins. Which stage of the SDLC should the ISSMP enforce the execution of SAST tools to ensure security requirements are met early?

A.Decommissioning phase
B.Post-deployment monitoring
C.Requirements gathering phase
D.Development/Build phase
AnswerD

SAST is most effective when integrated into the build/development phase to provide immediate feedback.

Why this answer

Security integration requires SAST (Static Application Security Testing) to be performed during the development phase, specifically as part of the commit or build process.

155
MCQmedium

When using Palo Alto Networks Cortex XSOAR, which component is responsible for orchestrating the execution of scripts across multiple third-party integrations?

A.Classifier
B.Integration Instance
C.Playbook
D.Indicator Field
AnswerC

Playbooks are the workflows that define the automated steps and cross-tool actions.

Why this answer

The XSOAR 'Playbook' engine manages the logic flow and script execution across various integrated products.

156
Multi-Selectmedium

Which TWO methods are commonly used to identify new risks in an enterprise environment?

Select 2 answers
A.Threat intelligence feeds
B.The annual holiday party schedule
C.Automated server patching
D.Purchasing more hardware
E.Periodic security risk assessments
AnswersA, E

Provides external context for new threats.

Why this answer

Risk identification is often driven by systematic reviews (audits/assessments) and data-driven analysis (threat intelligence).

157
Multi-Selectmedium

Which TWO of the following are common challenges in quantitative risk analysis?

Select 2 answers
A.It is not allowed by regulatory standards
B.The models are too simple to understand
C.High complexity and resource intensity of modeling
D.Quantitative data is always free
E.Difficulty in obtaining accurate, high-quality data
AnswersC, E

Requires specialized skills and significant time.

Why this answer

Quantitative risk analysis suffers from lack of reliable data and the complexity of modeling.

158
Multi-Selecthard

Which THREE of the following are key indicators of a mature security governance program?

Select 3 answers
A.The board receives regular, meaningful updates on security posture
B.Security metrics are tied to clear business KPIs
C.Security risks are integrated into the enterprise risk management (ERM) process
D.The security team works in total isolation from the rest of the company
E.The CISO reports to the Help Desk manager
AnswersA, B, C

Active oversight by the board is a hallmark of maturity.

Why this answer

Mature programs are characterized by metrics-driven processes, integration with enterprise functions, and active, informed oversight by the board.

159
MCQhard

You are utilizing a quantitative risk analysis. What is the 'SLE' in the context of an ARO-based calculation?

A.Single Loss Expectancy
B.Security Loss Estimate
C.System Level Exposure
D.Serious Loss Evaluation
AnswerA

Correct definition.

Why this answer

The Single Loss Expectancy (SLE) is the monetary value of a single loss event.

160
MCQhard

An organization must comply with CCPA/CPRA requirements regarding 'Right to Delete'. In a hybrid environment utilizing Google Cloud Platform, which mechanism is best suited for implementing automated lifecycle policies to satisfy deletion requests across Cloud Storage buckets?

A.Cloud IAM condition policies
B.VPC Service Controls
C.Data Loss Prevention (DLP) API scan-only mode
D.Cloud Storage Lifecycle Management rules
AnswerD

Lifecycle rules are designed to automate object deletion to meet compliance retention/deletion needs.

Why this answer

Lifecycle management policies in Cloud Storage are the standard way to automate data deletion based on specific conditions to meet privacy regulations.

161
Multi-Selectmedium

Which TWO of the following are core components of a business-aligned security strategy?

Select 2 answers
A.A requirement for all employees to have PhDs
B.Prioritization of security investments based on business impact
C.A complete list of every software vulnerability in the firm
D.A mandate that all security tools must be from one vendor
E.Identification of business-critical assets and processes
AnswersB, E

This ensures the most significant risks are addressed first.

Why this answer

Alignment requires understanding the business's current state and risk profile, and ensuring that security projects are prioritized to support the most important business functions.

162
MCQhard

A CISO is managing a security budget with high pressure for cost optimization. Which strategy provides the best balance between security and cost efficiency?

A.Delaying all security projects by 12 months
B.Reducing headcount in security operations
C.Implementing risk-based resource allocation
D.Switching to only open-source security tools
AnswerC

This ensures investments are directed where they provide the most protection.

Why this answer

Risk-based resource allocation allows the security team to prioritize investments on the highest-impact threats, ensuring maximum ROI on security spending.

163
Multi-Selecthard

An ISSMP is developing a cross-functional incident response team. Which THREE roles or functions are absolutely critical to include to ensure comprehensive handling of a major security breach?

Select 3 answers
A.Legal Counsel (General Counsel or Privacy Officer).
B.External janitorial staff for physical security.
C.Executive leadership representative (C-Suite).
D.Public Relations / Corporate Communications.
E.Internal cafeteria staff for onsite catering.
AnswersA, C, D

Legal is essential for handling regulatory notifications, liability, and evidence handling.

Why this answer

A major incident requires more than just technical response; it requires legal oversight, communication strategies, and executive decision-making capabilities.

164
MCQhard

To ensure security requirements are integrated into the System Development Life Cycle (SDLC), what is the most effective approach for the security team?

A.Embedding security champions within development teams
B.Requiring developers to attend annual security seminars
C.Automating the code deployment process
D.Mandating a security review before production release
AnswerA

This allows for continuous security advocacy and integration.

Why this answer

Embed security champions within development teams to act as liaisons, ensuring security is considered throughout the development process rather than treated as a final check.

165
MCQmedium

Which organizational structure is most effective for a CISO to influence security behavior across geographically dispersed and independent business units?

A.Centralized Command and Control
B.Outsourced Security Operations
C.Matrix Management
D.Decentralized/Siloed Management
AnswerC

Provides the balance of authority and influence needed in large, complex organizations.

Why this answer

A matrix management structure allows the CISO to exert influence through both functional and operational lines, ensuring security standards are consistent while respecting business unit autonomy.

166
Multi-Selectmedium

Which TWO actions are part of the 'Risk Monitoring' process?

Select 2 answers
A.Tracking Key Risk Indicators (KRIs)
B.Hiring new administrative assistants
C.Reviewing effectiveness of existing controls
D.Developing new software from scratch
E.Changing the company name
AnswersA, C

KRIs provide continuous visibility into risk trends.

Why this answer

Monitoring ensures that risks remain within appetite and that mitigation strategies are actually working.

167
MCQeasy

In an incident response plan, which metric is most useful for measuring the 'dwell time' of a threat actor?

A.Mean Time to Acknowledge (MTTA)
B.Mean Time to Recovery (MTTR)
C.Mean Time to Detect (MTTD)
D.Mean Time to Contain (MTTC)
AnswerC

MTTD directly relates to how long a threat remains active before it is discovered.

Why this answer

Dwell time is the period between the initial compromise and the time the organization detects the breach.

168
MCQmedium

During the maintenance phase, a production database needs a schema change. The ISSMP requires that this change be tested in a staging environment that mirrors production. Which process best demonstrates compliance with the 'Separation of Duties' principle?

A.The ISSMP personally reviewing every SQL script.
B.Allowing the automated CI/CD tool to deploy without human review.
C.Having the DBA perform the deployment in staging and production.
D.Requiring a separate release team to deploy changes approved by a Change Advisory Board (CAB).
AnswerD

This ensures that development, approval, and deployment are performed by different entities.

Why this answer

Separation of duties requires that the person who develops the change (DBA) is different from the person who approves the change (Change Manager) and the person who performs the production deployment (Release Engineer).

169
Multi-Selecthard

Which THREE factors must be considered during the 'Compliance Program Management' phase when evaluating whether to adopt a new cloud-based tool?

Select 3 answers
A.The tool's marketing budget
B.The availability of audit logs for compliance verification
C.The data residency capabilities of the tool
D.The tool's alignment with existing security and privacy policies
E.The number of social media followers of the vendor
AnswersB, C, D

If you cannot audit it, you cannot prove compliance.

Why this answer

Adopting new tools requires balancing risk, regulatory adherence, and technical capability.

170
MCQmedium

You are managing third-party risk. Which tool or method is most appropriate for a continuous assessment of a cloud service provider (CSP)?

A.Review of the CSP's website
B.Real-time CSPM monitoring
C.One-time penetration test
D.Annual SOC 2 Type II review
AnswerB

CSPM tools offer the continuous visibility required for modern cloud risk management.

Why this answer

Cloud security posture management (CSPM) provides continuous monitoring against compliance and risk frameworks.

171
MCQeasy

Which phase of the NIST Incident Response Life Cycle involves activities like system sanitization and validation of system integrity?

A.Post-Incident Activity
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Preparation
AnswerB

This phase includes cleaning systems and returning them to production.

Why this answer

Recovery includes restoring systems to normal operation and confirming they are secure.

172
Multi-Selecthard

Which THREE criteria are essential for establishing a successful 'Risk Committee'?

Select 3 answers
A.Limiting membership to only IT security staff
B.Conducting meetings at midnight for secrecy
C.Representation from multiple business units
D.Explicit mandate and authority from the board
E.Regular cadence of meetings and reporting
AnswersC, D, E

Diverse viewpoints are essential for enterprise risk.

Why this answer

A successful committee needs diverse perspectives, executive support, and a defined mandate.

173
Multi-Selectmedium

Which THREE components should be included in an application security requirements document?

Select 3 answers
A.The marketing tagline for the product
B.Authentication requirements (e.g., MFA)
C.Encryption standards (e.g., TLS 1.3)
D.Authorization/Access control definitions
E.The number of features to include
AnswersB, C, D

MFA is a standard security requirement for most applications.

Why this answer

Requirements must include authentication, authorization, and data encryption standards to ensure the application is secure by design.

174
Multi-Selecthard

Which THREE factors are required to calculate the 'Risk' of a vulnerability for reporting purposes?

Select 3 answers
A.Asset Criticality
B.Vulnerability Severity
C.Number of employees in the SOC
D.The cost of the security appliance
E.Threat Intelligence (Exploitability)
AnswersA, B, E

Impact depends on how critical the asset is to the business.

Why this answer

Risk is typically calculated as Likelihood x Impact, where Likelihood is influenced by Threat and Vulnerability, and Impact is determined by Asset Criticality.

175
MCQeasy

Which phase of the SDLC is most appropriate for conducting a formal Threat Modeling exercise?

A.Design phase
B.Release phase
C.Operations and Maintenance
D.Initiation phase
AnswerA

The design phase is the optimal time to identify threats against the architecture.

Why this answer

Threat modeling is most effective during the design phase because it allows architects to identify and mitigate design-level security flaws before implementation begins.

176
MCQmedium

An organization is migrating to a hybrid cloud environment and is updating its security architecture. Which of the following is the MOST effective way to ensure consistent security policy enforcement across both on-premises and cloud environments?

A.Managing separate security policies for on-premises and cloud environments.
B.Prioritizing the security of on-premises assets over cloud assets.
C.Allowing individual departments to define their own security policies.
D.Implementing a unified security policy framework across all environments.
AnswerD

A unified policy framework provides a consistent set of rules and controls, which simplifies management and auditing while reducing the risk of configuration errors.

Why this answer

Implementing a unified security policy framework ensures that security requirements are standardized and consistently applied regardless of the underlying infrastructure. This approach reduces complexity and human error in policy management.

177
MCQeasy

What is the primary objective of a Business Impact Analysis (BIA)?

A.To calculate the cost of a data breach
B.To identify all system vulnerabilities
C.To determine the impact of disruptions on business operations
D.To configure firewalls for recovery
AnswerC

The BIA focuses on availability and process continuity.

Why this answer

The BIA identifies critical business processes and the impact of their disruption, which informs the BCP/DR plan.

178
Multi-Selectmedium

Which THREE items are typically verified in a Security Gate check before a production deployment?

Select 3 answers
A.Formal change request approval is documented
B.The marketing campaign has been approved
C.Critical security vulnerabilities are remediated
D.Static/Dynamic analysis tests have passed
E.The developer has finished their vacation
AnswersA, C, D

Governance requires proof of approval before production changes.

Why this answer

Production gates check for vulnerability remediation, passing functional/security tests, and the presence of required documentation (like the change request).

179
MCQeasy

Which document establishes the high-level security objectives and the roles/responsibilities of senior management within an organization?

A.Standard Operating Procedure (SOP)
B.Security Charter
C.Acceptable Use Policy (AUP)
D.Incident Response Plan
AnswerB

This defines the purpose and authority of the security function.

Why this answer

The Security Charter or Security Governance Framework outlines the scope, mandate, and leadership roles required to oversee the security program.

180
MCQeasy

During a cross-functional security planning session, the IT operations team argues that security controls are negatively impacting system performance. As an ISSMP, what is the most appropriate management approach to resolve this conflict?

A.Perform a joint business impact analysis to determine the optimal balance of security and performance
B.Enforce the security controls regardless of performance impacts
C.Escalate the issue to the CIO for a final decision without further analysis
D.Reduce security controls until performance targets are met
AnswerA

A BIA allows all stakeholders to quantify the risk and make a consensus-based decision.

Why this answer

Effective security management involves balancing security needs with business operational requirements through a collaborative risk-based approach, ensuring security is integrated rather than imposed.

181
MCQmedium

A project manager wants to bypass a security vulnerability finding because 'the patch will break the application'. What is the correct ISSMP response?

A.Rewrite the application code personally.
B.Ignore the finding as it is non-critical.
C.Force the patch regardless of impact.
D.Document a formal Risk Acceptance with the business owner.
AnswerD

When a security control cannot be implemented, the risk must be formally accepted by the accountable business owner.

Why this answer

The ISSMP must initiate a formal Risk Acceptance process, requiring the business owner to acknowledge the residual risk and documenting it in the risk register.

182
MCQhard

An organization is adopting a Zero Trust Architecture (ZTA). Which management principle is critical for the long-term success of this transition?

A.Continuous monitoring and verification
B.Centralized static access lists
C.Automated patch management only
D.Strict perimeter-based defense
AnswerA

ZTA relies on the assumption that no user or device is inherently trusted.

Why this answer

Continuous monitoring and verification are the fundamental principles of ZTA; without them, the architecture cannot adapt to changing threat landscapes.

183
Multi-Selectmedium

When presenting a security budget request to the Board of Directors, which THREE of the following elements should be included to ensure the request is compelling and understood?

Select 3 answers
A.A summary of the latest cybersecurity job market trends.
B.A comprehensive analysis of the return on investment (ROI) or risk-reduction value.
C.Alignment of the investment with specific business risk reduction goals.
D.A clear articulation of the potential business impact of failing to act.
E.Detailed list of every firewall rule and server configuration.
AnswersB, C, D

Demonstrating the value of the spend is essential for executive approval.

Why this answer

Board members prioritize risk-based arguments over technical jargon. They need to understand the impact on business outcomes, the current risk level, and the return on investment (or cost of inaction).

184
Multi-Selecthard

Which THREE of the following are critical for successfully managing cross-functional security initiatives?

Select 3 answers
A.Demonstrating clear alignment with business benefits
B.Early and active involvement of key stakeholders
C.Focusing solely on the technical specifications
D.Excluding IT management from the planning phase
E.Establishing shared accountability for security outcomes
AnswersA, B, E

Business leaders are more likely to support initiatives that help them reach their goals.

Why this answer

Success in cross-functional work requires stakeholder involvement, clear communication of the business value, and shared ownership of the outcomes.

185
Multi-Selectmedium

Which TWO items must be documented in a Change Control Log after a successful production change?

Select 2 answers
A.The developer's personal home address
B.The timestamp of the change
C.The final status of the change (e.g., successful, failed)
D.The names of all employees who saw the change code
E.The total budget of the organization
AnswersB, C

Audit trails require precise timestamps for all changes.

Why this answer

A change log must include the final outcome (status) and the timestamp to ensure traceability and audit accuracy.

186
Multi-Selecthard

Which THREE of the following are common indicators that a security program is failing to align with business objectives?

Select 3 answers
A.Increase in unauthorized technology use (Shadow IT)
B.Employees consistently bypassing security controls
C.Security budget is lower than the IT budget
D.The security team is located in the basement
E.Lack of visibility or support from senior leadership
AnswersA, B, E

This shows that business units are solving problems without IT/security approval.

Why this answer

Lack of executive support, high levels of friction, and shadow IT are all strong indicators of a disconnect between security strategy and business goals.

187
MCQmedium

In VMware Carbon Black Cloud, which feature should be enabled to block unauthorized scripts while allowing signed binaries from trusted software vendors?

A.Watchlists
B.Policy Bypass
C.Advanced Threat Prevention (ATP)
D.Live Query
AnswerC

ATP policies provide granular control over process execution based on trust.

Why this answer

The 'Advanced Threat Prevention' policies allow for specific exclusion and blocking rules based on file reputation and signing certificates.

188
MCQhard

An ISSMP is evaluating a Cloud Access Security Broker (CASB) implementation. Which management goal is most effectively addressed by this tool?

A.Automating the patching of local workstations
B.Managing user access to local databases
C.Enforcing security policies for cloud application usage
D.Securing the physical data center
AnswerC

CASB is specifically designed to bridge the visibility gap in cloud environments.

Why this answer

A CASB provides visibility and control over cloud usage, enabling the enforcement of corporate security policies on data stored or accessed in cloud applications.

189
MCQmedium

An enterprise is moving to a 'Zero Trust' architecture. How does this impact the risk assessment process?

A.It makes the risk assessment easier
B.It eliminates the need for risk assessment
C.It requires assessing risk at the resource and identity level
D.It only impacts physical security
AnswerC

Zero Trust assumes breach; therefore, risk must be assessed per transaction and per asset.

Why this answer

Zero Trust shifts the focus from network perimeters to identity and device health, requiring a more granular, asset-centric risk assessment.

190
MCQmedium

In Tenable.io, when prioritizing vulnerability remediation, which metric provides the best insight into the likelihood of a vulnerability being exploited in the wild?

A.Plugin Family
B.Asset Criticality Rating
C.CVSS Base Score
D.Vulnerability Priority Rating (VPR)
AnswerD

VPR uses real-time threat intelligence to measure the urgency of remediation.

Why this answer

The Vulnerability Priority Rating (VPR) incorporates threat intelligence and exploit code availability, making it more accurate for risk-based prioritization than CVSS alone.

191
Multi-Selecthard

When designing a Disaster Recovery Program, which THREE of the following represent common 'single points of failure' that must be addressed?

Select 3 answers
A.Key-person dependency for initiating the disaster declaration.
B.Dependence on a single, non-redundant telecommunications provider for data replication.
C.Reliance on a single physical location for primary and backup storage.
D.Use of standardized enterprise resource planning software.
E.The use of automated server patching tools.
AnswersA, B, C

If only one person can declare a disaster, the process fails if that person is incapacitated.

Why this answer

Resilience requires removing dependencies on single, irreplaceable entities (people, physical locations, or specific gateway devices).

192
MCQeasy

When drafting an organizational 'Acceptable Use Policy' (AUP), which element is most critical to ensure legal enforceability in a professional environment?

A.Inclusion of the entire ISO 27001 standard
B.A list of blocked websites
C.Detailed technical specifications of the firewall
D.Mandatory user acknowledgment signature
AnswerD

The signature provides the evidence needed to hold users accountable.

Why this answer

A signed acknowledgement of the AUP is necessary to establish legal evidence that the user was aware of the policy expectations.

193
MCQmedium

In a decentralized organization, which approach to BCP management ensures both local agility and global alignment?

A.Leaving BCP entirely to the discretion of local department managers.
B.A strictly centralized command-and-control model.
C.Outsourcing the entire BCP function to a single managed service provider.
D.A federated model with a centralized governance framework.
AnswerD

This provides the balance of local flexibility and enterprise-wide compliance.

Why this answer

A federated model allows individual business units to customize plans to their specific needs while adhering to a common global framework/policy.

194
MCQmedium

Which of the following is the most important factor to consider when evaluating the effectiveness of a security training and awareness program?

A.Measurable improvements in employee behavior and incident reporting.
B.The total budget allocated to security awareness programs.
C.The frequency and quality of security awareness training sessions.
D.The number of employees who completed the training modules.
AnswerA

The primary goal of security awareness is to reduce human risk, which is best measured by behavioral changes.

Why this answer

Behavioral changes, such as reduced click rates on phishing simulations and increased reporting of suspicious activities, are the best indicators of a successful security awareness program.

195
MCQeasy

Which document describes the specific steps an analyst should take when a 'Phishing' alert is triggered in the SIEM?

A.System Architecture Diagram
B.Service Level Agreement
C.Playbook
D.Incident Response Plan
AnswerC

Playbooks provide the operational, step-by-step instructions for specific incident types.

Why this answer

A Playbook or Runbook provides step-by-step guidance for specific, repeatable incident types.

196
Multi-Selectmedium

During a BIA review, you need to identify critical assets and their recovery requirements. Which TWO of the following inputs are essential for this classification process?

Select 2 answers
A.Current data center power consumption logs.
B.Interviews with business process owners.
C.Technical dependency mapping of applications to infrastructure.
D.The organization's current IT procurement strategy.
E.Employee performance review records.
AnswersB, C

Business owners identify which processes are critical to business survival.

Why this answer

The BIA requires both understanding of the process importance and the technical dependencies (what systems are actually used).

197
MCQhard

When implementing FIM (File Integrity Monitoring) in Tripwire Enterprise, what is the specific purpose of a 'Promotion' action?

A.To revert a file to its previous version
B.To deploy the file to all servers
C.To archive the file for legal hold
D.To update the baseline with the current file state
AnswerD

Promotion is the mechanism to officially acknowledge a change as authorized and update the baseline.

Why this answer

Promotion updates the 'Known Good' baseline with the state of the monitored file from a current scan.

198
MCQeasy

When managing a compliance program, what is the first step in the 'Continuous Compliance' lifecycle?

A.Defining the compliance scope and regulatory requirements
B.Performing a penetration test
C.Auditing existing logs
D.Deploying security controls
AnswerA

Defining the scope is the prerequisite for all subsequent steps.

Why this answer

Identification of regulatory requirements (scope) is the foundation of any compliance program.

199
Multi-Selectmedium

Which TWO of the following are effective communication strategies for a CISO interacting with senior executives?

Select 2 answers
A.Focusing on the business impact of security risks
B.Providing hour-long technical deep dives on every vulnerability
C.Presenting data in a clear, actionable format
D.Using complex, obscure security acronyms
E.Writing 50-page reports for every meeting
AnswersA, C

This connects security to the executive's world.

Why this answer

Executives need concise, business-focused information that allows them to make informed decisions about risk and resource allocation.

200
MCQmedium

Which metric provides the best insight into the effectiveness of the security program within the SDLC?

A.Number of servers decommissioned.
B.Number of lines of code written.
C.Mean Time to Remediation (MTTR).
D.Number of developers hired.
AnswerC

MTTR measures how quickly security issues are resolved, which is a key indicator of effective security lifecycle management.

Why this answer

The 'Vulnerability Density' (vulnerabilities per KLOC) or 'Mean Time to Remediation' (MTTR) are the most effective metrics for demonstrating SDLC security health.

201
MCQhard

When analyzing network traffic in Wireshark for potential exfiltration, what specific filter allows you to isolate TCP traffic where the payload size exceeds 10MB?

A.tcp.len > 10000000
B.frame.size > 10000000
C.ip.len > 10000000
D.tcp.payload.size > 10000000
AnswerA

The 'tcp.len' field represents the length of the TCP payload, and the filter evaluates this against the 10MB threshold.

Why this answer

While Wireshark does not have a single simple filter for payload size without complex length calculations, the correct syntax involves identifying TCP segments that contain payload.

202
MCQhard

An ISSMP is managing a merger where two organizations use different identity providers. Which strategy best mitigates identity-related risk during the integration phase?

A.Granting domain administrative rights to both IT teams
B.Implementing a federated identity solution
C.Migrating all users to a new identity provider immediately
D.Creating duplicate user accounts for all employees
AnswerB

Federation provides a secure, scalable way to manage cross-organizational identities.

Why this answer

Establishing a federated identity model allows for centralized management and consistent access control policies across both entities without forcing an immediate migration.

203
Multi-Selectmedium

Which TWO of the following are effective ways to improve 'Crisis Management Leadership' effectiveness during an incident?

Select 2 answers
A.Ensuring a dedicated communications officer manages stakeholder messaging.
B.Removing all documentation to force teams to think creatively.
C.Ignoring external media requests to focus only on technical repair.
D.Establishing a clear chain of command for incident authority.
E.Requiring all employees to attend weekly disaster drills.
AnswersA, D

Having a single point of truth for communication prevents misinformation.

Why this answer

Leadership requires clear delegation and effective, structured communication to prevent panic and ensure well-informed decisions.

204
MCQmedium

To comply with the 'Right to Explanation' under certain AI regulations, which feature in Google Vertex AI is used to provide transparency into model decision-making?

A.Vertex AI Explainable AI (XAI)
B.Vertex AI Model Monitoring
C.Vertex AI Feature Store
D.Vertex AI Pipelines
AnswerA

XAI allows for feature attribution, providing the 'right to explanation'.

Why this answer

Vertex AI Explainable AI provides insights into how models make predictions, satisfying transparency requirements.

205
MCQeasy

Which document is the primary source for defining the 'Risk Appetite' of an enterprise?

A.Risk Appetite Statement
B.Security Policy
C.Business Impact Analysis
D.Incident Response Plan
AnswerA

This defines the amount of risk an organization is willing to accept.

Why this answer

The Risk Appetite Statement is the foundational document authorized by the board/senior management.

206
Multi-Selecthard

Which THREE of the following are considered 'Risk Assessment' methodologies?

Select 3 answers
A.NIST SP 800-30
B.FAIR (Factor Analysis of Information Risk)
C.HTML 5.0
D.TCP/IP protocol
E.ISO 27005
AnswersA, B, E

The NIST guide for conducting risk assessments.

Why this answer

Common risk assessment methodologies include NIST RMF, FAIR, and ISO 27005.

207
MCQeasy

Which of the following is a key component of a successful security awareness training program?

A.Focusing only on threats to external users
B.Regular, engaging, and relevant content
C.Using outdated training videos to save costs
D.Mandating attendance once every five years
AnswerB

This ensures the message is understood and remembered.

Why this answer

Regular, relevant, and engaging content is necessary to keep security top-of-mind for employees and to ensure long-term retention of good security practices.

208
MCQmedium

During a BCP planning session, the executive team is debating the 'Maximum Tolerable Downtime' (MTD) for a legacy internal application. What is the correct way to define this metric?

A.The maximum acceptable age of data in the event of a system crash.
B.The time taken to fail over to the secondary site during a disaster.
C.The time required to restore the application from the latest tape backup.
D.The total duration of time that an organization can tolerate a business process being unavailable.
AnswerD

MTD represents the upper limit of downtime tolerance before irreversible business impact occurs.

Why this answer

MTD is the total time a process can be down before the organization suffers catastrophic/irreversible harm.

209
MCQeasy

Which SOC metric is most appropriate to present to executive leadership to demonstrate the business value of security investments?

A.Reduction in Mean Time to Remediate (MTTR)
B.Total number of firewall rules
C.Disk space usage of the SIEM
D.Number of dropped packets per day
AnswerA

MTTR demonstrates operational efficiency and reduced risk exposure time.

Why this answer

Executive leadership cares about the reduction in risk and the financial impact of incidents, not technical metrics like 'events per second'.

210
Multi-Selectmedium

Which TWO metrics are essential for evaluating the performance of a SOC team in identifying and containing threats?

Select 2 answers
A.Mean Time to Detect (MTTD)
B.Total server downtime during updates
C.Mean Time to Contain (MTTC)
D.Number of coffee breaks taken
E.Total number of users on the network
AnswersA, C

Measures how fast the SOC identifies a potential breach.

Why this answer

MTTD and MTTC are standard industry metrics used to measure SOC efficiency.

211
MCQmedium

You are reviewing the organization's Incident Response Plan (IRP). According to the NIST SP 800-61 framework, which phase requires the highest level of coordination between legal, human resources, and IT departments?

A.Detection and Analysis
B.Post-Incident Activity
C.Preparation
D.Containment, Eradication, and Recovery
AnswerD

This phase necessitates the most complex multi-departmental decision-making during an active event.

Why this answer

The 'Containment, Eradication, and Recovery' phase requires intense cross-functional coordination, especially when legal and HR involvement is needed for evidence preservation or employee-related policy enforcement.

212
Multi-Selecthard

As an ISSMP developing a security governance program, which THREE of the following activities are essential to ensure the program remains effective and compliant?

Select 3 answers
A.Directly managing all firewall configurations manually
B.Establishing a formal security steering committee
C.Assigning clear roles and responsibilities for security tasks
D.Reviewing security policy compliance through regular audits
E.Increasing the number of help desk tickets handled daily
AnswersB, C, D

Provides the governance structure and oversight required.

Why this answer

Governance requires continuous monitoring, clear policy oversight, and defined accountability structures, which are achieved through these three activities.

213
Multi-Selectmedium

Which TWO of the following are valid responses to a high-risk finding?

Select 2 answers
A.Ask the auditor to leave
B.Delete all enterprise data
C.Purchase insurance (Transference)
D.Implement compensating controls (Mitigation)
E.Ignore the finding until the next budget cycle
AnswersC, D

A standard way to transfer financial impact.

Why this answer

Risk treatment options are generally to mitigate, transfer, avoid, or accept.

214
MCQeasy

Which document is considered the primary 'source of truth' for defining the SOC's roles, responsibilities, and communication paths during a major security incident?

A.Vulnerability Assessment Report
B.Standard Operating Procedure (SOP)
C.Incident Response Plan (IRP)
D.Asset Inventory
AnswerC

The IRP outlines the management, roles, and escalation procedures for incidents.

Why this answer

The Incident Response Plan (IRP) defines the strategy and governance for responding to incidents.

215
MCQeasy

What is the primary purpose of an Incident Response (IR) plan?

A.To identify all vulnerabilities in the network
B.To punish employees who cause incidents
C.To replace the need for security policies
D.To provide a structured approach to incident handling
AnswerD

Standardization ensures efficiency and reduces panic during incidents.

Why this answer

An IR plan provides a structured, predefined approach to handling security incidents to minimize impact and ensure business continuity.

216
MCQmedium

An ISSMP is overseeing a BCP program and notes that the current Business Impact Analysis (BIA) is heavily focused on RTO but lacks a critical dependency mapping for cross-functional business processes. Which specific action should the ISSMP prioritize to address the systemic risk of cascading failure during a disaster?

A.Implement a redundant secondary site for all identified Tier 1 applications.
B.Update the BIA to include qualitative impact assessments for all business units.
C.Initiate a value chain analysis using the SCOR model to identify inter-process dependencies.
D.Mandate an immediate increase in the frequency of full-scale BCP simulation exercises.
AnswerC

The Supply Chain Operations Reference (SCOR) model is effective for mapping internal process dependencies.

Why this answer

BIA must move beyond simple RTO/RPO metrics to identify upstream and downstream process dependencies to ensure that recovery orchestration remains viable.

217
MCQhard

An organization is moving from a reactive security posture to a proactive threat-informed defense. As the ISSMP, you are implementing the MITRE ATT&CK framework. Which executive-level metric best demonstrates the maturity of the security program to the Board of Directors regarding this transition?

A.Time to remediate critical security incidents
B.Percentage of MITRE ATT&CK techniques covered by existing controls
C.Number of phishing emails blocked by the email gateway
D.Total number of vulnerabilities patched per month
AnswerB

This metric directly ties the security program's capabilities to real-world adversary behaviors.

Why this answer

Mapping security coverage to MITRE ATT&CK techniques provides a quantifiable measure of defensive maturity that boards can understand, representing the shift from reactive compliance to proactive threat management.

218
MCQhard

Following a ransomware attack, the organization must decide whether to invoke the DRP or remain in a degraded state while security teams perform forensics. What is the ISSMP's primary responsibility in this decision-making process?

A.Choosing the restore point from the offsite immutable backup.
B.Ensuring the decision is documented to align with the organization's risk appetite.
C.Performing the initial forensic image of the infected servers.
D.Directing the IT team to disconnect the network immediately.
AnswerB

The ISSMP acts as an advisor to ensure the chosen path reflects the established risk appetite.

Why this answer

The ISSMP must facilitate the risk-based decision between recovery speed (DRP) and evidence preservation (Forensics).

219
MCQhard

A Microsoft Entra ID (Azure AD) user account is suspected of compromise. What is the most effective way to invalidate all active session tokens immediately?

A.Revoke sessions
B.Disable the user account
C.Remove assigned licenses
D.Reset the password
AnswerA

This action explicitly forces the revocation of all currently active refresh tokens.

Why this answer

The 'Revoke sessions' action in the Entra ID user blade forces the user to re-authenticate and clears all current refresh tokens.

Page 2

Page 3 of 3

All pages