View Full ISC CISSP Exam Dumps and Practice Test Dumps.
Question 21
Which security concept ensures that an organization can identify the individual or entity responsible for a specific action?
- Accountability
- Availability
- Confidentiality
- Privacy
Correct Answer: 1
Explanation
Accountability ensures that actions can be traced to the individual, process, or system responsible for performing them. It is commonly supported by identification, authentication, authorization, and auditing mechanisms. For example, unique user accounts combined with detailed audit logs can help determine which administrator changed a critical configuration. Accountability is important for investigations, compliance, and deterrence because users are less likely to misuse systems when their actions can be associated with their identities. Shared accounts can weaken accountability because they make it difficult to determine which individual performed a specific action.
Question 22
A security manager needs to determine the potential financial impact of a threat that could occur once every two years. Which calculation is most appropriate?
- Exposure factor
- Annualized loss expectancy
- Single loss expectancy
- Annualized rate of occurrence
Correct Answer: 2
Explanation
Annualized Loss Expectancy, or ALE, estimates the expected yearly financial loss associated with a specific risk. It is calculated by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence. If a loss is expected to occur once every two years, the annualized rate of occurrence would be 0.5. ALE helps management compare potential losses against the cost of implementing security controls. Single Loss Expectancy represents the estimated loss from one occurrence, while exposure factor represents the percentage of an asset lost from a single incident.
Question 23
Which document establishes the formal agreement between a service provider and a customer regarding expected service performance and availability?
- Memorandum of understanding
- Business impact analysis
- Service-level agreement
- Acceptable use policy
Correct Answer: 3
Explanation
A Service-Level Agreement, or SLA, formally defines expected service performance between a provider and customer. It may specify availability targets, response times, support requirements, maintenance windows, escalation procedures, and remedies for failing to meet agreed service levels. SLAs are particularly important when organizations depend on external cloud, hosting, telecommunications, or managed security providers. A Memorandum of Understanding generally describes an intended relationship without necessarily establishing detailed service metrics. A Business Impact Analysis identifies business consequences of disruptions, while an Acceptable Use Policy defines appropriate use of organizational resources.
Question 24
Which type of control is primarily designed to identify that a security incident has already occurred or is currently occurring?
- Preventive
- Deterrent
- Corrective
- Detective
Correct Answer: 4
Explanation
Detective controls are designed to identify security events, incidents, or policy violations that have occurred or are occurring. Examples include intrusion detection systems, security monitoring platforms, audit logs, security cameras, and certain alerting mechanisms. Their purpose is not necessarily to stop an event before it happens but to provide visibility so that appropriate action can follow. Preventive controls attempt to stop unwanted events, deterrent controls discourage unwanted behavior, and corrective controls help restore systems or conditions after an incident. Organizations commonly combine all these control categories.
Question 25
An organization needs to securely erase confidential data from storage media before the media is disposed of. Which process is most appropriate?
- Sanitization
- Classification
- Aggregation
- Tokenization
Correct Answer: 1
Explanation
Media sanitization is the process of removing sensitive information from storage media so that unauthorized individuals cannot reasonably recover it. Depending on the media type and organizational requirements, sanitization can involve clearing, purging, cryptographic erasure, or physical destruction. The appropriate method depends on factors such as sensitivity, media characteristics, reuse requirements, and applicable regulations. Classification determines how information should be protected, while tokenization replaces sensitive values with tokens. Proper sanitization is especially important when devices are retired, returned to vendors, transferred, or repurposed.
Question 26
Which access control model is most appropriate when permissions are assigned according to a user’s organizational job function?
- Discretionary access control
- Role-based access control
- Mandatory access control
- Rule-based access control
Correct Answer: 2
Explanation
Role-Based Access Control, or RBAC, assigns permissions according to organizational roles rather than individually granting every permission to every user. For example, employees assigned the accounting role may receive access to financial applications, while members of the human resources role receive access to personnel systems. RBAC simplifies administration and supports consistent authorization because permissions can be managed through defined roles. When a user’s job changes, administrators can modify the user’s role instead of manually adjusting numerous individual permissions. This approach can also support least privilege when roles are properly designed.
Question 27
Which type of authentication factor is represented by a fingerprint?
- Something you know
- Something you have
- Somewhere you are
- Something you are
Correct Answer: 4
Explanation
A fingerprint is an example of the “something you are” authentication factor because it is a biometric characteristic of an individual. Other biometric factors include facial characteristics, iris patterns, voice characteristics, and certain behavioral characteristics. “Something you know” includes passwords and PINs, while “something you have” includes smart cards, hardware tokens, and mobile devices. Location-based authentication can sometimes be described as “somewhere you are.” Authentication becomes multifactor when it combines evidence from different factor categories rather than using multiple methods from the same category.
Question 28
Which security architecture principle requires an access check to be performed every time a subject attempts to access an object?
- Complete mediation
- Least privilege
- Open design
- Separation of duties
Correct Answer: 1
Explanation
Complete mediation requires every access request to be checked against the applicable authorization rules rather than relying indefinitely on a previous access decision. This principle helps prevent unauthorized access when permissions, identities, or security conditions change. For example, a system should not assume that because a user previously accessed a resource, the user should automatically retain access later. Implementing complete mediation must be balanced with performance considerations because repeated authorization checks can introduce overhead. Caching decisions may be used carefully when the security architecture ensures that authorization remains reliable.
Question 29
During a business impact analysis, what does the Recovery Time Objective primarily define?
- Maximum acceptable data loss
- Maximum tolerable downtime before recovery
- Total cost of a disaster
- Required backup frequency
Correct Answer: 2
Explanation
Recovery Time Objective, or RTO, defines the targeted maximum amount of time that a business process, application, or service can remain unavailable following a disruption before it must be restored. RTO helps organizations select appropriate recovery strategies and technologies. A system requiring a very short RTO may need highly available infrastructure or rapid failover capabilities. Recovery Point Objective, or RPO, addresses the maximum acceptable amount of data loss measured in time. Therefore, RTO focuses primarily on recovery time, while RPO focuses on recoverable data currency.
Question 30
A company determines that a critical application can tolerate losing no more than five minutes of transactional data after a disaster. Which metric describes this requirement?
- Recovery Time Objective
- Maximum Tolerable Downtime
- Recovery Point Objective
- Mean Time To Repair
Correct Answer: 3
Explanation
Recovery Point Objective, or RPO, identifies the maximum acceptable amount of data loss measured in time. If an organization can tolerate losing no more than five minutes of transactions, its RPO for that application is five minutes. This requirement influences backup frequency, replication methods, and recovery architecture. A shorter RPO generally requires more frequent replication or backup activity. RTO is different because it measures how quickly a service must be restored. RPO therefore addresses data recovery currency, while RTO addresses service recovery time after a disruption.
Question 31
Which type of business continuity exercise involves participants discussing how they would respond to a simulated scenario without actually disrupting production systems?
- Full interruption test
- Tabletop exercise
- Parallel test
- Functional test
Correct Answer: 2
Explanation
A tabletop exercise is a discussion-based business continuity or incident response exercise in which participants walk through a simulated scenario and explain how they would respond. It can test plans, responsibilities, communication procedures, escalation paths, and decision-making without creating the risks associated with an actual interruption. Tabletop exercises are relatively low-impact and can be performed before more disruptive testing. A full interruption test intentionally moves operations into a recovery environment, while parallel and functional exercises provide different levels of operational testing.
Question 32
Which disaster recovery site typically contains the equipment and infrastructure needed to restore operations quickly but may require current data to be restored before production resumes?
- Cold site
- Mobile site
- Hot site
- Warm site
Correct Answer: 4
Explanation
A warm site provides a partially prepared recovery environment with infrastructure and equipment available for restoring business operations. It generally requires more preparation and configuration than a hot site but can usually be activated faster than a cold site. A hot site is typically maintained in a highly ready state and may contain operational systems and current data, allowing rapid recovery. A cold site generally provides basic facilities and requires significant equipment installation and configuration. Organizations select among these options according to recovery requirements, cost, and acceptable downtime.
Question 33
Which security testing approach provides testers with no internal knowledge of the target environment before testing begins?
- White-box testing
- Gray-box testing
- Black-box testing
- Source-code review
Correct Answer: 3
Explanation
Black-box testing is performed with little or no prior knowledge of the internal design, architecture, source code, or implementation details of the target. It attempts to simulate an external attacker who must discover information during the assessment. White-box testing provides extensive internal knowledge, which can allow deeper examination of the environment. Gray-box testing provides partial information and represents an intermediate approach. Black-box testing can provide valuable insight into externally discoverable weaknesses, while other testing methods may identify vulnerabilities that require internal knowledge to uncover.
Question 34
Which security principle states that a system should remain secure even if its internal design is publicly known?
- Open design
- Least common mechanism
- Fail-safe defaults
- Work factor
Correct Answer: 1
Explanation
The open design principle states that the security of a system should not depend on keeping its design or implementation secret. Instead, protection should rely on strong, well-designed security mechanisms and secret values such as cryptographic keys. This principle is important because security architectures may eventually become publicly known through documentation, reverse engineering, or disclosure. Open design encourages systems to remain secure even when attackers understand how they work. It contrasts with security through obscurity, which relies primarily on hiding implementation details rather than using robust security controls.
Question 35
An organization wants its security program to address confidentiality, integrity, and availability as its primary information security objectives. Which model represents these objectives?
- AAA model
- CIA triad
- OSI model
- Clark-Wilson model
Correct Answer: 2
Explanation
The CIA triad represents confidentiality, integrity, and availability, which are fundamental objectives of information security. Confidentiality protects information from unauthorized disclosure. Integrity protects information against unauthorized or improper modification. Availability ensures that authorized users can access systems and information when required. Security controls are often evaluated according to how they support one or more of these objectives. The CIA triad provides a foundational framework for security planning, risk assessment, architecture, and control selection across applications, networks, systems, and organizational processes.
Question 36
Which privacy principle requires organizations to collect only the personal information necessary for a defined purpose?
- Data minimization
- Purpose limitation
- Transparency
- Accountability
Correct Answer: 1
Explanation
Data minimization means collecting and retaining only the personal information necessary to accomplish a legitimate and defined purpose. Limiting the amount of personal information an organization holds can reduce privacy risks, storage requirements, exposure during a breach, and unnecessary processing. Organizations should identify what information is genuinely required rather than collecting excessive data simply because it might become useful later. Purpose limitation is related but focuses on using collected information consistently with specified purposes. Data minimization therefore emphasizes reducing unnecessary collection and retention of personal information.
Question 37
Which type of evidence is most directly concerned with demonstrating that a digital message or document was created or approved by a particular person?
- Hash value
- Digital signature
- Symmetric encryption
- Steganography
Correct Answer: 2
Explanation
A digital signature uses asymmetric cryptography to provide evidence that a message or document was signed using the private key associated with the signer. When properly implemented, it can provide integrity and support authentication of the signer, while also contributing to nonrepudiation depending on the legal and technical context. A hash value can detect changes but does not independently identify who created the data. Symmetric encryption primarily protects confidentiality, while steganography hides information within another medium. Digital signatures are therefore especially useful for verifying signed digital content.
Question 38
An organization wants to reduce the likelihood that two administrators will collude to misuse privileged access. Which control is most directly applicable?
- Job rotation
- Separation of duties
- Mandatory vacation
- Least functionality
Correct Answer: 2
Explanation
Separation of duties divides sensitive responsibilities among different individuals to reduce the risk that one person can independently complete an unauthorized process. Although it cannot eliminate collusion between multiple individuals, it raises the number of people required to perform certain activities and creates additional opportunities for detection. For example, one administrator may request a privileged change while another reviews and approves it. Job rotation can expose irregularities by moving personnel between roles, and mandatory vacation can sometimes reveal fraudulent activity. Separation of duties directly addresses concentrated authority and control over sensitive processes.
Question 39
Which metric measures the average amount of time required to repair or restore a failed system?
- Mean Time Between Failures
- Recovery Point Objective
- Mean Time To Repair
- Maximum Tolerable Downtime
Correct Answer: 3
Explanation
Mean Time To Repair, or MTTR, measures the average time required to repair a failed component or restore a system to an operational state. Organizations use MTTR to evaluate maintenance and recovery efficiency. A lower MTTR generally indicates that failures can be resolved more quickly, which can contribute to improved availability. Mean Time Between Failures measures the average operating time between failures. RPO measures acceptable data loss, while Maximum Tolerable Downtime represents the longest period a business process can remain unavailable before unacceptable consequences occur.
Question 40
Which principle recommends that access should be denied by default unless a subject is explicitly authorized to perform the requested action?
- Fail-safe defaults
- Open design
- Complete mediation
- Economy of mechanism
Correct Answer: 1
Explanation
Fail-safe defaults means that when a security decision is uncertain or no explicit permission exists, access should be denied rather than automatically allowed. This approach reduces the risk that configuration errors, unexpected conditions, or missing authorization rules will unintentionally grant access. For example, a newly created account should not automatically receive access to sensitive resources unless appropriate permissions are explicitly assigned. Complete mediation requires access checks for each access request, while open design concerns security that does not depend on secrecy of system design. Economy of mechanism emphasizes simplicity.