View Full ISC CISSP Exam Dumps and Practice Test Dumps.
Question 141
Which security concept ensures that information is available to authorized users when needed while preventing unauthorized disclosure?
- Confidentiality
- Integrity
- Availability
- Accountability
Correct Answer: 3
Explanation
Availability ensures that authorized users can access systems, applications, and information when required to perform their responsibilities. Availability can be affected by hardware failures, software defects, network outages, natural disasters, cyberattacks, or insufficient capacity. Organizations improve availability through redundancy, fault tolerance, backups, disaster recovery, capacity planning, and business continuity measures. Confidentiality protects information from unauthorized disclosure, while integrity protects information from unauthorized modification. Availability is therefore one of the three primary objectives represented by the CIA triad and is particularly important for business-critical services.
Question 142
An organization wants to ensure that an employee cannot deny having approved a specific digital transaction. Which security property is most relevant?
- Availability
- Nonrepudiation
- Confidentiality
- Privacy
Correct Answer: 2
Explanation
Nonrepudiation provides evidence that can help establish that a particular party performed or approved an action. Digital signatures, secure audit records, and appropriate authentication mechanisms can contribute to nonrepudiation. In a transaction, a properly implemented digital signature can associate the signer with the signed information and help detect subsequent modification. Nonrepudiation differs from authentication because authentication establishes an identity at the time of access, while nonrepudiation focuses on providing evidence that can prevent a party from credibly denying a previous action. Legal requirements should also be considered when designing such controls.
Question 143
Which risk treatment option involves purchasing insurance to transfer the financial consequences of a potential security event to another party?
- Risk avoidance
- Risk acceptance
- Risk transference
- Risk mitigation
Correct Answer: 3
Explanation
Risk transference shifts some or all financial consequences of a risk to another party. Cyber insurance is a common example because an organization pays a premium in exchange for coverage against specified losses. Outsourcing certain activities under a contract can also transfer specific responsibilities, although the organization may retain some accountability and residual risk. Risk avoidance eliminates the activity that creates the risk, mitigation reduces its likelihood or impact, and acceptance means consciously retaining the risk. Risk transfer does not eliminate the underlying threat and should therefore be accompanied by appropriate contractual and security controls.
Question 144
A company decides to discontinue a service because the associated security risk cannot be reduced to an acceptable level. Which risk response has been selected?
- Risk avoidance
- Risk acceptance
- Risk transference
- Risk sharing
Correct Answer: 1
Explanation
Risk avoidance involves eliminating the activity, process, system, or condition that creates the unacceptable risk. In this scenario, discontinuing the service removes the organization’s exposure to the associated risk. Avoidance can be appropriate when the potential impact is severe and available mitigation measures are insufficient, impractical, or too expensive. It differs from risk acceptance, where the organization knowingly retains the risk. Risk transference moves some consequences to another party, while mitigation applies controls intended to reduce either the likelihood or impact of the risk.
Question 145
Which quantitative risk calculation represents the expected monetary loss from a single occurrence of a specific risk?
- Annualized rate of occurrence
- Single loss expectancy
- Annualized loss expectancy
- Exposure factor
Correct Answer: 2
Explanation
Single loss expectancy, or SLE, represents the expected monetary loss resulting from one occurrence of a risk event. It is commonly calculated by multiplying the asset value by the exposure factor, which represents the percentage of value expected to be lost during the event. For example, if an asset is valued at $100,000 and an event is expected to cause a 30 percent loss, the SLE would be $30,000. Annualized loss expectancy extends this calculation across an expected number of occurrences during a year.
Question 146
A risk is expected to occur four times per year, and each occurrence is estimated to cause a $20,000 loss. What is the annualized loss expectancy?
- $5,000
- $20,000
- $80,000
- $100,000
Correct Answer: 3
Explanation
Annualized loss expectancy, or ALE, estimates the expected monetary loss from a risk over one year. It is calculated by multiplying the single loss expectancy by the annualized rate of occurrence. In this scenario, each event produces an estimated $20,000 loss and is expected to occur four times annually. Therefore, ALE equals $20,000 multiplied by 4, resulting in $80,000. Organizations can use ALE as part of quantitative risk analysis to compare potential losses with the cost of security controls and support financially informed risk treatment decisions.
Question 147
Which metric estimates how frequently a particular threat event is expected to occur within a one-year period?
- Annualized rate of occurrence
- Exposure factor
- Single loss expectancy
- Asset value
Correct Answer: 1
Explanation
Annualized rate of occurrence, or ARO, estimates how many times a particular risk event is expected to occur within one year. It can be represented as a whole number or a fraction when an event is expected less frequently than once annually. ARO is used with single loss expectancy to calculate annualized loss expectancy. For example, if a specific incident is expected once every five years, the ARO can be represented as 0.2. Accurate estimates may require historical records, threat intelligence, industry information, and expert judgment.
Question 148
Which risk analysis method uses monetary values to estimate potential losses and compare the financial impact of different risks?
- Qualitative analysis
- Quantitative analysis
- Scenario analysis
- Gap analysis
Correct Answer: 2
Explanation
Quantitative risk analysis assigns numerical or monetary values to risk factors and potential losses. It can use metrics such as asset value, exposure factor, single loss expectancy, annualized rate of occurrence, and annualized loss expectancy. This approach can help organizations compare risks using financial measurements and evaluate whether proposed security controls are economically reasonable. Qualitative analysis instead commonly uses categories such as low, moderate, and high. Quantitative analysis may require substantial data and can still involve uncertainty because estimates about likelihood, impact, and future events are not always precise.
Question 149
Which document establishes the agreed level of service, performance expectations, and responsibilities between a service provider and its customer?
- Memorandum of understanding
- Service-level agreement
- Business impact analysis
- Acceptable use policy
Correct Answer: 2
Explanation
A service-level agreement, or SLA, defines measurable service expectations between a provider and customer. It may specify availability targets, response times, support requirements, maintenance windows, performance measures, reporting obligations, and remedies for failing to meet agreed service levels. SLAs are particularly important when critical business functions depend on external providers. They should align with business requirements and risk tolerance. An SLA does not replace security due diligence or technical controls; instead, it establishes contractual expectations that can be monitored and enforced throughout the service relationship.
Question 150
Which agreement is commonly used when two organizations want to document their mutual intentions without creating the same level of contractual commitment as a formal business contract?
- Memorandum of understanding
- Service-level agreement
- Business continuity plan
- Data retention policy
Correct Answer: 1
Explanation
A memorandum of understanding, or MOU, generally documents the intentions, responsibilities, or areas of cooperation between two or more parties. It is often used to establish a framework for collaboration before more detailed agreements are created. The legal effect of an MOU depends on its wording and applicable law, so organizations should obtain appropriate legal guidance when necessary. An SLA focuses specifically on measurable service commitments, while policies and continuity plans address internal organizational requirements. Security professionals should understand the purpose of agreements used in third-party relationships.
Question 151
Which document defines how an organization will restore critical systems and services after a major disruptive event?
- Incident response plan
- Disaster recovery plan
- Security awareness policy
- Configuration management plan
Correct Answer: 2
Explanation
A disaster recovery plan describes how an organization will restore technology infrastructure, systems, applications, and data after a disruptive event. It typically addresses recovery priorities, roles and responsibilities, recovery procedures, communication requirements, alternate facilities, backups, and restoration activities. Disaster recovery supports organizational resilience but is not identical to business continuity. Business continuity focuses more broadly on maintaining essential business functions during disruption. Disaster recovery is generally concerned with restoring technology and supporting services to an acceptable operational state within defined recovery objectives.
Question 152
Which activity identifies the business processes most critical to an organization and determines the impact if those processes become unavailable?
- Business impact analysis
- Vulnerability scanning
- Penetration testing
- Configuration auditing
Correct Answer: 1
Explanation
A business impact analysis, or BIA, identifies critical business processes, resources, dependencies, and potential consequences of disruptions. It helps determine how quickly functions must be restored and what level of disruption the organization can tolerate. BIA results can support recovery priorities and help establish objectives such as recovery time and recovery point requirements. The analysis may consider financial, operational, legal, regulatory, reputational, and customer impacts. Organizations use BIA findings to develop appropriate continuity and recovery strategies rather than treating every business process as equally important.
Question 153
A company determines that a critical application must be restored within two hours after an outage. Which recovery metric does this requirement represent?
- Mean time between failures
- Recovery point objective
- Recovery time objective
- Maximum tolerable downtime
Correct Answer: 3
Explanation
Recovery time objective, or RTO, specifies the maximum targeted amount of time required to restore a system or business service after a disruption. In this scenario, the requirement to restore the application within two hours represents an RTO of two hours. RTO helps organizations select appropriate recovery strategies, technologies, staffing, and alternate resources. Recovery point objective focuses on the acceptable amount of data loss measured in time. RTO and RPO are complementary but address different aspects of recovery planning and should be established according to business requirements.
Question 154
An organization determines that no more than 15 minutes of transaction data can be lost following a database failure. Which metric describes this requirement?
- Recovery time objective
- Recovery point objective
- Mean time to repair
- Maximum tolerable downtime
Correct Answer: 2
Explanation
Recovery point objective, or RPO, identifies the maximum acceptable amount of data loss measured in time. An RPO of 15 minutes means the organization should be able to recover data to a point no more than approximately 15 minutes before the disruption. Achieving a low RPO may require frequent backups, replication, journaling, or other data-protection mechanisms. RPO is different from RTO, which specifies how quickly the service should be restored. Both metrics should be derived from business requirements and incorporated into recovery architecture and procedures.
Question 155
Which continuity strategy uses a facility that has power and environmental controls available but requires installation or restoration of systems before normal operations can resume?
- Hot site
- Cold site
- Mirrored site
- Mobile site
Correct Answer: 2
Explanation
A cold site provides a location with basic infrastructure such as power, environmental controls, and physical space but generally lacks fully operational systems and applications. After a disaster, the organization must install, configure, restore, or otherwise prepare the required technology before operations can resume. Cold sites are generally less expensive than fully equipped alternatives but may require more recovery time. A hot site is prepared for rapid operational use, while a warm site provides an intermediate level of readiness. The appropriate option depends on business recovery requirements and available resources.
Question 156
Which continuity facility is generally maintained with systems and infrastructure ready to support rapid transition of critical operations?
- Cold site
- Hot site
- Empty facility
- Storage warehouse
Correct Answer: 2
Explanation
A hot site is designed to support rapid recovery because it typically contains operational infrastructure, systems, network connectivity, and other resources needed to resume critical functions. Depending on the architecture, data may also be replicated or regularly synchronized with the primary environment. Hot sites can significantly reduce recovery time but are generally more expensive to maintain than cold or warm alternatives. Organizations should select recovery facilities based on business requirements, acceptable downtime, data-loss tolerance, budget, geographic considerations, and the criticality of the services being recovered.
Question 157
Which backup type stores only the data that has changed since the most recent full or incremental backup?
- Full backup
- Differential backup
- Incremental backup
- Mirror backup
Correct Answer: 3
Explanation
An incremental backup stores data that has changed since the previous backup, regardless of whether that previous backup was full or incremental. This generally reduces backup time and storage requirements compared with repeatedly performing full backups. During restoration, however, the organization may need the latest full backup and the relevant sequence of incremental backups. A differential backup stores changes since the most recent full backup, so its size can grow as more changes accumulate. Backup strategy should consider recovery objectives, storage capacity, operational requirements, and restoration complexity.
Question 158
Which backup type captures changes made since the most recent full backup?
- Differential backup
- Incremental backup
- Snapshot only
- Transaction log deletion
Correct Answer: 1
Explanation
A differential backup stores data that has changed since the most recent full backup. As additional changes occur, subsequent differential backups generally become larger because they continue to include changes made since that full backup. During restoration, the organization typically needs the latest full backup and the latest differential backup. This can simplify restoration compared with a chain of incremental backups, although storage requirements may be greater. Organizations should choose backup methods according to recovery objectives, available storage, backup windows, network capacity, and restoration requirements.
Question 159
Which security control is intended to discourage unauthorized activity by making potential attackers aware that their actions may be detected or have consequences?
- Detective control
- Corrective control
- Deterrent control
- Compensating control
Correct Answer: 3
Explanation
A deterrent control is designed to discourage individuals from attempting unauthorized or harmful actions. Warning banners, visible security cameras, security guards, and clearly communicated disciplinary consequences can serve as deterrents. Unlike detective controls, which identify activity after or while it occurs, deterrent controls primarily aim to influence behavior before an incident takes place. Deterrent measures do not guarantee that attacks will not occur, so organizations should combine them with preventive, detective, corrective, and other controls. A layered control strategy provides broader protection than relying on deterrence alone.
Question 160
A security team reviews system logs after an incident to determine which account accessed a sensitive database and when the access occurred. Which security capability is being demonstrated?
- Accountability
- Data minimization
- Availability
- Risk avoidance
Correct Answer: 1
Explanation
Accountability ensures that actions can be associated with identifiable individuals, accounts, or processes. Proper authentication, authorization, audit logging, and monitoring help establish accountability by recording who performed an action and when it occurred. In this scenario, reviewing database logs to determine which account accessed sensitive information provides evidence that supports accountability and investigation. Strong logging should protect records from unauthorized alteration and should use accurate time synchronization where appropriate. Accountability also supports incident response, compliance investigations, forensic analysis, and enforcement of organizational security policies.