{"id":15492,"date":"2026-09-18T05:34:02","date_gmt":"2026-09-18T05:34:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15492"},"modified":"2026-09-18T05:34:02","modified_gmt":"2026-09-18T05:34:02","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which security principle ensures that an organization can demonstrate that a person cannot credibly deny performing a specific digitally signed action?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Nonrepudiation provides evidence that can help establish the origin or involvement of a party in a digital transaction, making it difficult for that party to credibly deny the action later. Digital signatures are commonly associated with nonrepudiation because they can link signed data to a private key under appropriate conditions. Legal and organizational requirements also influence whether evidence provides nonrepudiation. Authentication confirms identity, while integrity helps demonstrate that information was not altered. Nonrepudiation therefore focuses on accountability for actions and transactions.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>A security team needs to identify weaknesses in thousands of network devices without actively exploiting those weaknesses. Which assessment technique is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Red team exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Social engineering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability scanning uses automated tools to identify known weaknesses, missing patches, insecure configurations, exposed services, and other potential security issues across many systems. It is particularly useful when an organization needs broad coverage across large environments. Unlike penetration testing, vulnerability scanning generally does not attempt to exploit identified weaknesses to demonstrate their practical impact. Red team exercises simulate adversarial activity more comprehensively, while social engineering tests human behavior. Vulnerability scanning should be followed by validation, prioritization, remediation, and periodic rescanning to verify improvements.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which type of penetration test provides the security team with detailed knowledge of the target&#8217;s architecture, source code, and internal documentation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gray-box<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">White-box<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blind-box<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">White-box penetration testing provides testers with extensive information about the target environment, potentially including source code, architecture diagrams, credentials, configuration information, and internal documentation. This knowledge allows testers to examine the system deeply and identify weaknesses that may not be discoverable from an external perspective. Black-box testing provides little or no internal information, while gray-box testing provides partial knowledge. White-box testing can therefore be valuable when an organization wants comprehensive technical analysis and wants testers to evaluate internal security controls and application logic.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>Which activity is primarily concerned with identifying potential threats and vulnerabilities during the design of a new application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Capacity planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling is a structured process used to identify potential threats, attack paths, trust boundaries, vulnerabilities, and security requirements during system or application design. Performing threat modeling early allows developers and architects to address security weaknesses before implementation becomes expensive to change. Common approaches examine assets, entry points, trust boundaries, attacker capabilities, and potential attack scenarios. Threat modeling does not replace penetration testing or vulnerability scanning, but it helps guide secure architecture and development decisions by identifying security concerns before systems are deployed.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which software vulnerability occurs when an application improperly handles data sent by a user and executes it as part of a database query?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site request forgery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when untrusted input is incorporated into database queries in an unsafe manner, allowing an attacker to alter the intended query logic. Depending on the application&#8217;s privileges and database configuration, successful SQL injection can expose, modify, or delete data and potentially enable additional attacks. Parameterized queries or prepared statements are among the primary defenses. Input validation, least privilege, secure error handling, and monitoring also reduce risk. Buffer overflows involve memory handling, while cross-site request forgery abuses authenticated sessions to induce unwanted actions.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which application security weakness occurs when malicious script content is inserted into a web page and executed in another user&#8217;s browser?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Command injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting, or XSS, occurs when an application allows attacker-controlled script content to be included in web pages viewed by other users. Depending on the type of XSS and application context, malicious scripts may access browser data, manipulate page content, perform actions using the victim&#8217;s session, or redirect users to malicious resources. Common defenses include context-aware output encoding, appropriate input handling, content security policies, and secure application design. SQL injection targets database queries, while command injection targets operating system commands.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which vulnerability occurs when two processes access shared resources concurrently and the outcome depends on the timing of their operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege creep<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A race condition occurs when the security or correctness of a system depends on the timing or order of concurrent operations. An attacker may attempt to exploit a small window between checking a condition and using a resource, commonly known as a time-of-check-to-time-of-use issue. Secure programming practices should use appropriate synchronization, atomic operations, locking mechanisms, and careful state management. Race conditions can be difficult to reproduce because timing affects the outcome. They can create serious security consequences when shared resources or authorization decisions are involved.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>A developer stores passwords using a secure one-way cryptographic function with unique random values added before hashing. What is the primary purpose of the random values?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To increase network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To prevent identical passwords from producing identical stored hashes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To enable password recovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To replace multifactor authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A unique random salt is added to each password before applying a password hashing function. Salting ensures that identical passwords do not produce identical stored hash values, making precomputed attacks such as rainbow tables less effective. The salt does not need to remain secret and is generally stored with the password hash. Passwords should be protected using dedicated password hashing algorithms designed to resist brute-force attacks, rather than general-purpose fast hashes alone. Salting complements strong password hashing but does not provide password recovery or replace multifactor authentication.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which security control helps prevent unauthorized execution of applications by allowing only approved software to run on managed endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full-disk encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts execution to software that has been explicitly approved by organizational policy. This can reduce the risk of unauthorized applications, malware, and potentially unwanted software executing on managed endpoints. Depending on the implementation, allowlisting may use file hashes, digital signatures, publisher information, paths, or application identities. It is particularly useful for systems requiring tightly controlled software environments. Full-disk encryption protects stored data, NAT translates network addresses, and data classification determines information sensitivity. Allowlisting should be carefully maintained so legitimate software remains available.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which endpoint security technology is designed to prevent unauthorized devices from connecting to an organization&#8217;s network based on security compliance requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Access Control, or NAC, controls whether devices are permitted to connect to a network based on defined security requirements. A NAC solution may evaluate factors such as device identity, authentication status, operating system version, security software, patch status, and compliance posture. Noncompliant devices can be denied access, placed into a restricted network, or directed toward remediation resources. SIEM platforms analyze security events, DLP protects sensitive information from unauthorized disclosure, and HSMs protect cryptographic keys. NAC therefore provides an important control at the point of network access.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which security mechanism is designed to securely store and perform cryptographic operations involving highly sensitive keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Hardware Security Module, or HSM, is a specialized device designed to protect cryptographic keys and perform sensitive cryptographic operations within a controlled hardware environment. HSMs can provide strong key protection and may support functions such as encryption, decryption, signing, verification, and key generation. They are commonly used by organizations with high-value cryptographic requirements, including payment systems, certificate authorities, and secure transaction platforms. SIEM systems analyze security events, IDS solutions detect suspicious activity, and proxies mediate communications. HSMs specifically address cryptographic key security.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>Which encryption mode is generally designed to provide confidentiality while also supporting authentication of encrypted data when used appropriately?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ECB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CBC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GCM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CFB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Galois\/Counter Mode, or GCM, is an authenticated encryption mode that can provide both confidentiality and integrity protection for data. It produces authenticated ciphertext and can also protect associated data that does not itself need encryption. Proper nonce management is essential because reusing a nonce with the same key can seriously compromise security. ECB has significant pattern-leakage weaknesses for many data types, while CBC and CFB primarily provide confidentiality and require additional mechanisms for authentication. GCM is widely used in modern secure communications and applications.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which cryptographic algorithm is commonly used as a modern symmetric encryption standard for protecting sensitive data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RSA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AES<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SHA-256<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Diffie-Hellman<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Advanced Encryption Standard, or AES, is a widely used symmetric encryption algorithm for protecting sensitive information. AES supports key sizes of 128, 192, and 256 bits and is commonly implemented through secure modes such as GCM or appropriately configured counter-based modes. RSA is an asymmetric cryptographic algorithm, SHA-256 is a cryptographic hash function, and Diffie-Hellman is primarily used to establish shared secrets. AES is efficient for encrypting substantial quantities of data and is therefore commonly used in storage, network, and application security.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which cryptographic process is specifically designed to produce a fixed-length representation of input data that changes significantly when the input changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key exchange<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital certificate issuance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic hashing transforms input data into a fixed-length digest. A secure cryptographic hash function is designed so that even a small change to the input produces a substantially different output, commonly referred to as the avalanche effect. Hashes can support integrity verification, password storage when used with appropriate password-hashing schemes, digital signatures, and other security functions. Hashing is not encryption because it is designed as a one-way transformation rather than a reversible process using a decryption key. SHA-256 is an example of a widely used cryptographic hash function.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which security technology can inspect encrypted network traffic by decrypting it at a controlled inspection point before forwarding it to its destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS inspection proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A TLS inspection proxy can terminate or inspect encrypted sessions at a controlled security point, allowing security technologies to examine traffic that would otherwise remain encrypted. Depending on the architecture, the proxy establishes separate encrypted connections with the client and destination while inspecting the traffic between them. This can improve visibility for malware detection, data loss prevention, and policy enforcement. However, TLS inspection introduces privacy, performance, certificate-management, and application-compatibility considerations. Organizations should carefully define which traffic can be inspected and ensure appropriate authorization and policy controls.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which authentication protocol is widely used to obtain tickets for accessing network resources in a centralized authentication environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Kerberos<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kerberos is a network authentication protocol that uses tickets and a trusted third party to authenticate users and services. It is widely associated with enterprise directory environments and supports mutual authentication and single sign-on capabilities. Instead of repeatedly transmitting passwords to individual services, clients obtain tickets that can be presented to authorized services. Kerberos relies on cryptographic mechanisms and synchronized system clocks for proper operation. FTP transfers files, ICMP supports network diagnostics and control messaging, and ARP maps network-layer addresses to link-layer addresses.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>Which attack attempts to deceive an employee into revealing credentials by pretending to be a trustworthy person or organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP poisoning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing is a social engineering attack that attempts to deceive individuals into revealing sensitive information, executing malicious actions, or visiting harmful resources. Attackers may impersonate trusted organizations, colleagues, service providers, or executives through email, messaging platforms, websites, or other communication channels. Effective defenses include security awareness training, phishing-resistant authentication, email security controls, URL filtering, reporting mechanisms, and careful verification of unusual requests. Technical controls are important, but human awareness remains an important layer because phishing specifically targets user decision-making and trust.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which social engineering attack involves an attacker following an authorized person through a secured physical entrance without using their own credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shoulder surfing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tailgating<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pretexting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Baiting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tailgating occurs when an unauthorized individual follows an authorized person into a restricted area without independently authenticating. Attackers may exploit social courtesy by carrying objects, appearing familiar with employees, or claiming to have forgotten an access badge. Physical security controls such as mantraps, security guards, badge readers, visitor management, and security awareness training can reduce this risk. Shoulder surfing involves observing sensitive information, pretexting uses a fabricated scenario to obtain information or access, and baiting uses an enticing object or offer to encourage a target to take an unsafe action.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which physical security control uses two interlocking doors to prevent an individual from entering a secure area while another person is exiting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Turnstile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mantrap is a physical access control mechanism consisting of two interlocking doors designed to prevent simultaneous entry and exit. Typically, one door must close before the second door can open. Mantraps can be combined with badge readers, biometric authentication, security personnel, and monitoring systems to provide stronger access control for highly restricted areas. Bollards protect against vehicle intrusion, turnstiles regulate pedestrian movement, and fences establish physical boundaries. Mantraps are particularly useful where controlling individual physical entry is important, such as data centers and secure facilities.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which physical security control is primarily designed to prevent vehicles from intentionally or accidentally entering a protected area?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bollard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Motion detector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mantrap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Visitor badge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bollards are physical barriers designed to prevent or limit vehicle access to protected areas. They can be fixed, removable, or retractable depending on the security and operational requirements. Bollards are commonly placed around building entrances, pedestrian areas, government facilities, and other locations where vehicle intrusion presents a risk. A mantrap controls pedestrian access, a motion detector identifies movement, and a visitor badge provides identification for people. Physical security controls should be selected based on the threats, facility layout, operational requirements, and consequences of unauthorized access.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which security principle ensures that an organization can demonstrate that a person cannot credibly deny performing a specific digitally signed action? Availability Nonrepudiation Confidentiality Separation of duties Correct Answer: 2 Explanation Nonrepudiation provides evidence that can help establish the origin or involvement [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15492"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15492"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15492\/revisions"}],"predecessor-version":[{"id":15523,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15492\/revisions\/15523"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}