View Full ISC CISSP Exam Dumps and Practice Test Dumps.
Question 341
Which physical security control is designed to prevent vehicles from entering a restricted area?
- Bollard
- Mantrap
- Turnstile
- Security camera
Correct Answer: 1
Explanation
A bollard is a physical security barrier commonly used to prevent or restrict vehicle access to protected areas. Bollards can be fixed, removable, retractable, or reinforced depending on the required level of protection. They are often positioned around building entrances, pedestrian areas, loading zones, and other locations where vehicle intrusion could create a security or safety risk. Physical security planning should consider the expected threat, vehicle types, placement, visibility, emergency access, and integration with other controls such as gates, barriers, surveillance, and access management.
Question 342
Which physical security measure is primarily intended to detect or deter unauthorized movement across a property boundary?
- Fence
- HVAC system
- Fire suppression system
- Lighting controller
Correct Answer: 1
Explanation
A security fence establishes a physical boundary around a facility and can help deter unauthorized entry while providing a visible indication of the protected perimeter. Fences can be combined with gates, locks, surveillance cameras, lighting, intrusion detection sensors, and security personnel. The appropriate height, construction, and placement depend on the facility’s risk profile and physical environment. A fence alone does not guarantee protection because determined attackers may climb, cut, or bypass it. Effective physical security uses layered controls appropriate to the identified threats.
Question 343
Which environmental control helps maintain appropriate temperature and humidity levels for sensitive computing equipment?
- HVAC
- UPS
- CCTV
- Bollard
Correct Answer: 1
Explanation
Heating, ventilation, and air conditioning, or HVAC, systems help maintain temperature, airflow, and humidity conditions suitable for computing equipment and personnel. Excessive heat can damage components or cause systems to shut down, while inappropriate humidity can contribute to condensation or static electricity problems. Data centers and other critical facilities may require environmental monitoring and redundant cooling systems. HVAC planning should account for equipment density, expected loads, maintenance requirements, power availability, and failure scenarios. Environmental monitoring can provide early warnings before conditions threaten system availability.
Question 344
Which fire suppression method is commonly used in areas containing sensitive electronic equipment because it does not leave water residue?
- Clean agent suppression
- Wet pipe sprinkler
- Water hose system
- Flood drainage system
Correct Answer: 1
Explanation
Clean agent fire suppression systems use gaseous agents designed to suppress fires without the water damage associated with traditional sprinkler systems. They can be appropriate for data centers, telecommunications rooms, and other environments containing sensitive electronic equipment. The specific agent and system design must comply with applicable safety and environmental requirements. Clean agent systems do not eliminate the need for smoke detection, alarms, emergency procedures, or appropriate building fire protections. Organizations should also ensure systems are inspected and maintained according to established requirements.
Question 345
Which physical security principle uses the design and arrangement of buildings, windows, lighting, and surrounding areas to increase the ability to observe suspicious activity?
- Natural surveillance
- Data minimization
- Tokenization
- Cryptographic separation
Correct Answer: 1
Explanation
Natural surveillance uses the physical design of an environment to improve visibility and the ability to observe people or activities. Examples include clear sight lines, strategically positioned windows, adequate lighting, open landscaping, and building layouts that reduce concealed areas. The goal is to increase the likelihood that unauthorized activity will be noticed and therefore deter potential intruders. Natural surveillance is often associated with broader physical security and crime-prevention design principles. It should complement, rather than replace, access controls, alarms, surveillance systems, and security personnel.
Question 346
Which physical security control records video footage to support monitoring and investigation of activity around a facility?
- CCTV
- HVAC
- UPS
- Firewall
Correct Answer: 1
Explanation
Closed-circuit television, or CCTV, uses cameras and associated recording or monitoring systems to observe physical areas. CCTV can provide deterrence, real-time monitoring, and evidence for investigations following security incidents. Cameras should be positioned based on identified risks and should protect important entrances, restricted areas, equipment rooms, and other sensitive locations where appropriate. Organizations should also establish policies for recording, retention, access, privacy, and evidence handling. CCTV is most effective when integrated with physical access controls, alarms, lighting, and established response procedures.
Question 347
Which power protection device provides short-term electrical power to equipment when the primary power source fails?
- UPS
- Firewall
- Proxy
- IDS
Correct Answer: 1
Explanation
An uninterruptible power supply, or UPS, provides temporary power when the primary electrical supply is interrupted or experiences certain disturbances. A UPS can help prevent abrupt system shutdowns, data corruption, and equipment damage while allowing systems to remain operational until power is restored or generators are brought online. UPS capacity and runtime should be selected according to business requirements and equipment loads. Critical facilities may use redundant UPS systems, generators, and power distribution controls to provide greater resilience against electrical failures.
Question 348
Which physical security control is designed to regulate pedestrian movement through a controlled entrance or exit?
- Turnstile
- Bollard
- HVAC
- Fire suppression
Correct Answer: 1
Explanation
A turnstile is a physical access control mechanism that regulates pedestrian movement through an entrance or exit. It can require users to authenticate with badges, biometric systems, or other mechanisms before allowing passage. Turnstiles can help prevent unauthorized entry and reduce the likelihood of multiple individuals passing through a controlled point under a single authorization event. High-security environments may combine turnstiles with mantraps, security guards, cameras, and anti-tailgating controls. Emergency evacuation requirements must be considered when designing and configuring these systems.
Question 349
Which process evaluates whether a third-party organization’s security practices are adequate before allowing it to handle sensitive information?
- Third-party risk assessment
- Data destruction
- Password rotation
- Incident containment
Correct Answer: 1
Explanation
A third-party risk assessment evaluates the security risks associated with vendors, suppliers, contractors, cloud providers, and other external organizations. The assessment may review security controls, certifications or independent reports, incident history, data handling practices, access requirements, business continuity capabilities, and regulatory obligations. The objective is to understand whether the third party introduces unacceptable risks and determine what controls or contractual requirements are necessary. Assessments should be proportionate to the sensitivity of the services and information involved and should continue throughout the relationship.
Question 350
Which contractual document defines specific measurable service expectations between a service provider and customer?
- SLA
- NDA
- MOU
- AUP
Correct Answer: 1
Explanation
A service-level agreement, or SLA, defines measurable service expectations between a provider and customer. It may specify availability, response times, recovery objectives, support responsibilities, security requirements, reporting obligations, and consequences for failing to meet agreed service levels. SLAs help establish clear expectations and provide a basis for monitoring vendor performance. Security-related requirements should be specific enough to measure and enforce. Organizations should periodically review SLAs because business requirements, service architectures, regulatory obligations, and risk conditions can change.
Question 351
Which agreement is primarily used to protect confidential information shared between parties?
- NDA
- SLA
- MOU
- BIA
Correct Answer: 1
Explanation
A nondisclosure agreement, or NDA, establishes obligations concerning confidential or proprietary information shared between parties. It can define what information is considered confidential, how it may be used, who may receive it, and what restrictions apply to disclosure. NDAs are commonly used with employees, contractors, vendors, partners, and other parties that may receive sensitive information. An NDA is a contractual protection and does not replace technical controls such as access restrictions, encryption, monitoring, or data loss prevention. Organizations should ensure agreements reflect applicable legal requirements.
Question 352
Which agreement establishes a general understanding and intent to cooperate between two or more organizations without necessarily creating the detailed obligations of a formal contract?
- MOU
- SLA
- NDA
- Incident report
Correct Answer: 1
Explanation
A memorandum of understanding, or MOU, documents a general understanding between parties concerning cooperation, responsibilities, objectives, or planned activities. It can be useful when organizations want to establish a framework for collaboration before creating more detailed contractual arrangements. The exact legal effect of an MOU depends on its wording and applicable law. Security responsibilities should be clearly defined when sensitive information or systems are involved. An MOU differs from an SLA because an SLA normally establishes measurable service commitments and performance expectations.
Question 353
Which document formally defines the security requirements and responsibilities that a third-party provider must meet?
- Contractual security requirements
- Network diagram
- Password policy
- Incident ticket
Correct Answer: 1
Explanation
Contractual security requirements establish security obligations that a third-party provider must satisfy as part of its relationship with an organization. Requirements can address access control, encryption, incident notification, vulnerability management, data handling, audit rights, personnel security, business continuity, and secure disposal. Clearly documented requirements make security expectations measurable and enforceable. Organizations should tailor requirements to the sensitivity and risk associated with the service. Vendor contracts should also define what happens when requirements are not met and how security responsibilities change when the relationship ends.
Question 354
Which risk response transfers some financial or operational consequences of a risk to another party?
- Risk transference
- Risk avoidance
- Risk acceptance
- Risk elimination
Correct Answer: 1
Explanation
Risk transference involves shifting some of the financial or operational consequences of a risk to another party. Examples can include purchasing insurance, outsourcing certain activities under contractual arrangements, or using agreements that allocate specific liabilities. Transference does not necessarily eliminate the underlying risk; the organization may retain responsibilities or consequences that cannot be transferred. Organizations should carefully review contracts and insurance terms to understand exclusions, limitations, responsibilities, and remaining exposure. Risk transfer should be evaluated as part of a broader risk management strategy.
Question 355
An organization decides to discontinue a high-risk service because the associated risk cannot be reduced to an acceptable level. Which risk treatment is being used?
- Risk avoidance
- Risk acceptance
- Risk transference
- Risk monitoring
Correct Answer: 1
Explanation
Risk avoidance involves eliminating the activity, process, technology, or condition that creates the unacceptable risk. An organization may choose to discontinue a service, stop collecting certain information, or avoid deploying a technology when other treatment options cannot bring exposure within acceptable limits. Avoidance can be effective but may also eliminate potential business benefits associated with the activity. Management should evaluate alternatives and document the decision. Risk avoidance should be distinguished from mitigation, which reduces risk while allowing the underlying activity to continue.
Question 356
Which risk metric represents the expected loss from a single occurrence of a specific risk event?
- SLE
- ALE
- ARO
- RTO
Correct Answer: 1
Explanation
Single Loss Expectancy, or SLE, represents the expected monetary loss from one occurrence of a particular risk event. It can be calculated using the asset value multiplied by the exposure factor, which represents the percentage of asset value expected to be lost during the event. SLE is useful in quantitative risk analysis and can contribute to calculating Annualized Loss Expectancy. Organizations should use reasonable estimates and document assumptions because inaccurate asset values or exposure estimates can significantly affect the resulting analysis.
Question 357
Which risk metric represents the expected frequency with which a particular loss event may occur during one year?
- ARO
- SLE
- ALE
- RPO
Correct Answer: 1
Explanation
Annualized Rate of Occurrence, or ARO, estimates how frequently a particular risk event is expected to occur within one year. It is used in quantitative risk analysis to help calculate Annualized Loss Expectancy. For example, if an event is expected to occur twice per year, the ARO would be 2. The estimate should be based on available historical information, threat intelligence, industry data, or informed analysis when reliable statistics are unavailable. Because occurrence rates can change, organizations should periodically review assumptions and update calculations.
Question 358
Which metric estimates the expected annual monetary loss from a particular risk?
- ALE
- SLE
- ARO
- MTTR
Correct Answer: 1
Explanation
Annualized Loss Expectancy, or ALE, estimates the expected annual financial loss associated with a particular risk. It is commonly calculated by multiplying Single Loss Expectancy by Annualized Rate of Occurrence. ALE can help organizations compare potential losses with the cost of proposed security controls and support quantitative risk decisions. The calculation depends on the quality of the underlying assumptions, including asset value, exposure factor, and expected occurrence rate. ALE should therefore be treated as an analytical estimate rather than an exact prediction of future losses.
Question 359
A company estimates that a security incident would cause a $50,000 loss per occurrence and expects the event to happen twice annually. What is the calculated ALE?
- $25,000
- $50,000
- $100,000
- $150,000
Correct Answer: 3
Explanation
Annualized Loss Expectancy is calculated by multiplying Single Loss Expectancy by Annualized Rate of Occurrence. In this scenario, the expected loss from one event is $50,000 and the event is expected to occur twice per year. Therefore, ALE equals $50,000 × 2, resulting in an expected annual loss of $100,000. This calculation can help management compare the estimated annual risk against the cost and effectiveness of potential security controls. The result remains an estimate based on the assumptions used in the analysis.
Question 360
Which recovery metric defines the maximum acceptable amount of data loss measured in time?
- RTO
- RPO
- MTTR
- SLA
Correct Answer: 2
Explanation
Recovery Point Objective, or RPO, defines the maximum acceptable amount of data loss measured in time. For example, an RPO of four hours means the organization should generally be prepared to recover data to a point no more than four hours before the disruption, depending on the recovery architecture. RPO influences backup frequency, replication strategies, and data protection design. RTO differs because it specifies how quickly a service or process should be restored. Both objectives should be established according to business impact and operational requirements.