{"id":15489,"date":"2026-09-18T05:34:36","date_gmt":"2026-09-18T05:34:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15489"},"modified":"2026-09-18T05:34:36","modified_gmt":"2026-09-18T05:34:36","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 21<\/b><\/h3>\n<p><b>Which security concept ensures that an organization can identify the individual or entity responsible for a specific action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privacy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accountability ensures that actions can be traced to the individual, process, or system responsible for performing them. It is commonly supported by identification, authentication, authorization, and auditing mechanisms. For example, unique user accounts combined with detailed audit logs can help determine which administrator changed a critical configuration. Accountability is important for investigations, compliance, and deterrence because users are less likely to misuse systems when their actions can be associated with their identities. Shared accounts can weaken accountability because they make it difficult to determine which individual performed a specific action.<\/span><\/p>\n<h3><b>Question 22<\/b><\/h3>\n<p><b>A security manager needs to determine the potential financial impact of a threat that could occur once every two years. Which calculation is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exposure factor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Annualized loss expectancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single loss expectancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Annualized rate of occurrence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Annualized Loss Expectancy, or ALE, estimates the expected yearly financial loss associated with a specific risk. It is calculated by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence. If a loss is expected to occur once every two years, the annualized rate of occurrence would be 0.5. ALE helps management compare potential losses against the cost of implementing security controls. Single Loss Expectancy represents the estimated loss from one occurrence, while exposure factor represents the percentage of an asset lost from a single incident.<\/span><\/p>\n<h3><b>Question 23<\/b><\/h3>\n<p><b>Which document establishes the formal agreement between a service provider and a customer regarding expected service performance and availability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memorandum of understanding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service-level agreement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable use policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Service-Level Agreement, or SLA, formally defines expected service performance between a provider and customer. It may specify availability targets, response times, support requirements, maintenance windows, escalation procedures, and remedies for failing to meet agreed service levels. SLAs are particularly important when organizations depend on external cloud, hosting, telecommunications, or managed security providers. A Memorandum of Understanding generally describes an intended relationship without necessarily establishing detailed service metrics. A Business Impact Analysis identifies business consequences of disruptions, while an Acceptable Use Policy defines appropriate use of organizational resources.<\/span><\/p>\n<h3><b>Question 24<\/b><\/h3>\n<p><b>Which type of control is primarily designed to identify that a security incident has already occurred or is currently occurring?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preventive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deterrent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Corrective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detective<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls are designed to identify security events, incidents, or policy violations that have occurred or are occurring. Examples include intrusion detection systems, security monitoring platforms, audit logs, security cameras, and certain alerting mechanisms. Their purpose is not necessarily to stop an event before it happens but to provide visibility so that appropriate action can follow. Preventive controls attempt to stop unwanted events, deterrent controls discourage unwanted behavior, and corrective controls help restore systems or conditions after an incident. Organizations commonly combine all these control categories.<\/span><\/p>\n<h3><b>Question 25<\/b><\/h3>\n<p><b>An organization needs to securely erase confidential data from storage media before the media is disposed of. Which process is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sanitization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Media sanitization is the process of removing sensitive information from storage media so that unauthorized individuals cannot reasonably recover it. Depending on the media type and organizational requirements, sanitization can involve clearing, purging, cryptographic erasure, or physical destruction. The appropriate method depends on factors such as sensitivity, media characteristics, reuse requirements, and applicable regulations. Classification determines how information should be protected, while tokenization replaces sensitive values with tokens. Proper sanitization is especially important when devices are retired, returned to vendors, transferred, or repurposed.<\/span><\/p>\n<h3><b>Question 26<\/b><\/h3>\n<p><b>Which access control model is most appropriate when permissions are assigned according to a user&#8217;s organizational job function?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-Based Access Control, or RBAC, assigns permissions according to organizational roles rather than individually granting every permission to every user. For example, employees assigned the accounting role may receive access to financial applications, while members of the human resources role receive access to personnel systems. RBAC simplifies administration and supports consistent authorization because permissions can be managed through defined roles. When a user&#8217;s job changes, administrators can modify the user&#8217;s role instead of manually adjusting numerous individual permissions. This approach can also support least privilege when roles are properly designed.<\/span><\/p>\n<h3><b>Question 27<\/b><\/h3>\n<p><b>Which type of authentication factor is represented by a fingerprint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A fingerprint is an example of the \u201csomething you are\u201d authentication factor because it is a biometric characteristic of an individual. Other biometric factors include facial characteristics, iris patterns, voice characteristics, and certain behavioral characteristics. \u201cSomething you know\u201d includes passwords and PINs, while \u201csomething you have\u201d includes smart cards, hardware tokens, and mobile devices. Location-based authentication can sometimes be described as \u201csomewhere you are.\u201d Authentication becomes multifactor when it combines evidence from different factor categories rather than using multiple methods from the same category.<\/span><\/p>\n<h3><b>Question 28<\/b><\/h3>\n<p><b>Which security architecture principle requires an access check to be performed every time a subject attempts to access an object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete mediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Complete mediation requires every access request to be checked against the applicable authorization rules rather than relying indefinitely on a previous access decision. This principle helps prevent unauthorized access when permissions, identities, or security conditions change. For example, a system should not assume that because a user previously accessed a resource, the user should automatically retain access later. Implementing complete mediation must be balanced with performance considerations because repeated authorization checks can introduce overhead. Caching decisions may be used carefully when the security architecture ensures that authorization remains reliable.<\/span><\/p>\n<h3><b>Question 29<\/b><\/h3>\n<p><b>During a business impact analysis, what does the Recovery Time Objective primarily define?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum acceptable data loss<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum tolerable downtime before recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Total cost of a disaster<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Required backup frequency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Time Objective, or RTO, defines the targeted maximum amount of time that a business process, application, or service can remain unavailable following a disruption before it must be restored. RTO helps organizations select appropriate recovery strategies and technologies. A system requiring a very short RTO may need highly available infrastructure or rapid failover capabilities. Recovery Point Objective, or RPO, addresses the maximum acceptable amount of data loss measured in time. Therefore, RTO focuses primarily on recovery time, while RPO focuses on recoverable data currency.<\/span><\/p>\n<h3><b>Question 30<\/b><\/h3>\n<p><b>A company determines that a critical application can tolerate losing no more than five minutes of transactional data after a disaster. Which metric describes this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery Time Objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum Tolerable Downtime<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery Point Objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time To Repair<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Point Objective, or RPO, identifies the maximum acceptable amount of data loss measured in time. If an organization can tolerate losing no more than five minutes of transactions, its RPO for that application is five minutes. This requirement influences backup frequency, replication methods, and recovery architecture. A shorter RPO generally requires more frequent replication or backup activity. RTO is different because it measures how quickly a service must be restored. RPO therefore addresses data recovery currency, while RTO addresses service recovery time after a disruption.<\/span><\/p>\n<h3><b>Question 31<\/b><\/h3>\n<p><b>Which type of business continuity exercise involves participants discussing how they would respond to a simulated scenario without actually disrupting production systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full interruption test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tabletop exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Parallel test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Functional test<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A tabletop exercise is a discussion-based business continuity or incident response exercise in which participants walk through a simulated scenario and explain how they would respond. It can test plans, responsibilities, communication procedures, escalation paths, and decision-making without creating the risks associated with an actual interruption. Tabletop exercises are relatively low-impact and can be performed before more disruptive testing. A full interruption test intentionally moves operations into a recovery environment, while parallel and functional exercises provide different levels of operational testing.<\/span><\/p>\n<h3><b>Question 32<\/b><\/h3>\n<p><b>Which disaster recovery site typically contains the equipment and infrastructure needed to restore operations quickly but may require current data to be restored before production resumes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mobile site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm site provides a partially prepared recovery environment with infrastructure and equipment available for restoring business operations. It generally requires more preparation and configuration than a hot site but can usually be activated faster than a cold site. A hot site is typically maintained in a highly ready state and may contain operational systems and current data, allowing rapid recovery. A cold site generally provides basic facilities and requires significant equipment installation and configuration. Organizations select among these options according to recovery requirements, cost, and acceptable downtime.<\/span><\/p>\n<h3><b>Question 33<\/b><\/h3>\n<p><b>Which security testing approach provides testers with no internal knowledge of the target environment before testing begins?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">White-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gray-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Black-box testing is performed with little or no prior knowledge of the internal design, architecture, source code, or implementation details of the target. It attempts to simulate an external attacker who must discover information during the assessment. White-box testing provides extensive internal knowledge, which can allow deeper examination of the environment. Gray-box testing provides partial information and represents an intermediate approach. Black-box testing can provide valuable insight into externally discoverable weaknesses, while other testing methods may identify vulnerabilities that require internal knowledge to uncover.<\/span><\/p>\n<h3><b>Question 34<\/b><\/h3>\n<p><b>Which security principle states that a system should remain secure even if its internal design is publicly known?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least common mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Work factor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The open design principle states that the security of a system should not depend on keeping its design or implementation secret. Instead, protection should rely on strong, well-designed security mechanisms and secret values such as cryptographic keys. This principle is important because security architectures may eventually become publicly known through documentation, reverse engineering, or disclosure. Open design encourages systems to remain secure even when attackers understand how they work. It contrasts with security through obscurity, which relies primarily on hiding implementation details rather than using robust security controls.<\/span><\/p>\n<h3><b>Question 35<\/b><\/h3>\n<p><b>An organization wants its security program to address confidentiality, integrity, and availability as its primary information security objectives. Which model represents these objectives?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AAA model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CIA triad<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSI model<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clark-Wilson model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The CIA triad represents confidentiality, integrity, and availability, which are fundamental objectives of information security. Confidentiality protects information from unauthorized disclosure. Integrity protects information against unauthorized or improper modification. Availability ensures that authorized users can access systems and information when required. Security controls are often evaluated according to how they support one or more of these objectives. The CIA triad provides a foundational framework for security planning, risk assessment, architecture, and control selection across applications, networks, systems, and organizational processes.<\/span><\/p>\n<h3><b>Question 36<\/b><\/h3>\n<p><b>Which privacy principle requires organizations to collect only the personal information necessary for a defined purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purpose limitation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transparency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting and retaining only the personal information necessary to accomplish a legitimate and defined purpose. Limiting the amount of personal information an organization holds can reduce privacy risks, storage requirements, exposure during a breach, and unnecessary processing. Organizations should identify what information is genuinely required rather than collecting excessive data simply because it might become useful later. Purpose limitation is related but focuses on using collected information consistently with specified purposes. Data minimization therefore emphasizes reducing unnecessary collection and retention of personal information.<\/span><\/p>\n<h3><b>Question 37<\/b><\/h3>\n<p><b>Which type of evidence is most directly concerned with demonstrating that a digital message or document was created or approved by a particular person?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash value<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Steganography<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature uses asymmetric cryptography to provide evidence that a message or document was signed using the private key associated with the signer. When properly implemented, it can provide integrity and support authentication of the signer, while also contributing to nonrepudiation depending on the legal and technical context. A hash value can detect changes but does not independently identify who created the data. Symmetric encryption primarily protects confidentiality, while steganography hides information within another medium. Digital signatures are therefore especially useful for verifying signed digital content.<\/span><\/p>\n<h3><b>Question 38<\/b><\/h3>\n<p><b>An organization wants to reduce the likelihood that two administrators will collude to misuse privileged access. Which control is most directly applicable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory vacation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least functionality<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among different individuals to reduce the risk that one person can independently complete an unauthorized process. Although it cannot eliminate collusion between multiple individuals, it raises the number of people required to perform certain activities and creates additional opportunities for detection. For example, one administrator may request a privileged change while another reviews and approves it. Job rotation can expose irregularities by moving personnel between roles, and mandatory vacation can sometimes reveal fraudulent activity. Separation of duties directly addresses concentrated authority and control over sensitive processes.<\/span><\/p>\n<h3><b>Question 39<\/b><\/h3>\n<p><b>Which metric measures the average amount of time required to repair or restore a failed system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time Between Failures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery Point Objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mean Time To Repair<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum Tolerable Downtime<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time To Repair, or MTTR, measures the average time required to repair a failed component or restore a system to an operational state. Organizations use MTTR to evaluate maintenance and recovery efficiency. A lower MTTR generally indicates that failures can be resolved more quickly, which can contribute to improved availability. Mean Time Between Failures measures the average operating time between failures. RPO measures acceptable data loss, while Maximum Tolerable Downtime represents the longest period a business process can remain unavailable before unacceptable consequences occur.<\/span><\/p>\n<h3><b>Question 40<\/b><\/h3>\n<p><b>Which principle recommends that access should be denied by default unless a subject is explicitly authorized to perform the requested action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete mediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Economy of mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fail-safe defaults means that when a security decision is uncertain or no explicit permission exists, access should be denied rather than automatically allowed. This approach reduces the risk that configuration errors, unexpected conditions, or missing authorization rules will unintentionally grant access. For example, a newly created account should not automatically receive access to sensitive resources unless appropriate permissions are explicitly assigned. Complete mediation requires access checks for each access request, while open design concerns security that does not depend on secrecy of system design. Economy of mechanism emphasizes simplicity.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 21 Which security concept ensures that an organization can identify the individual or entity responsible for a specific action? Accountability Availability Confidentiality Privacy Correct Answer: 1 Explanation Accountability ensures that actions can be traced to the individual, process, or system responsible for performing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15489"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15489"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15489\/revisions"}],"predecessor-version":[{"id":15526,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15489\/revisions\/15526"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}