{"id":15496,"date":"2026-09-18T05:33:04","date_gmt":"2026-09-18T05:33:04","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15496"},"modified":"2026-09-18T05:33:04","modified_gmt":"2026-09-18T05:33:04","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 161<\/b><\/h3>\n<p><b>Which security principle requires an organization to collect only the personal information necessary for a specific legitimate purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data remanence<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data dispersion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization requires organizations to collect, process, and retain only the personal information necessary for an identified legitimate purpose. Limiting unnecessary data reduces privacy exposure, storage requirements, and the potential impact of a data breach. Organizations should define the purpose for collecting information and avoid gathering additional information merely because it might become useful later. Data minimization should be considered during application design, data collection, retention, sharing, and disposal. It supports privacy protection and can also reduce the organization&#8217;s overall security and compliance burden.<\/span><\/p>\n<h3><b>Question 162<\/b><\/h3>\n<p><b>An organization labels information as Public, Internal, Confidential, and Restricted. What is the primary purpose of this classification system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Determine employee salaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Establish appropriate protection requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Measure network bandwidth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Calculate system availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information classification categorizes data according to its sensitivity, value, or business importance so that appropriate security controls can be applied. Public information may require limited protection, while Restricted or Confidential information may require stronger access controls, encryption, monitoring, and handling procedures. Classification helps organizations avoid applying the same security requirements to every piece of information. Data owners typically determine classifications according to organizational policy, while custodians implement the required controls. Classification should also be reviewed when the information&#8217;s sensitivity or business context changes.<\/span><\/p>\n<h3><b>Question 163<\/b><\/h3>\n<p><b>Who is generally responsible for determining the classification and acceptable use requirements for organizational information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">End user<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The data owner is generally responsible for determining how organizational information should be classified and what protection requirements apply to it. The owner may establish access requirements, retention expectations, and acceptable handling procedures according to organizational policies and legal obligations. A data custodian typically implements and maintains the controls specified by the owner. End users must follow the established requirements but normally do not determine the official classification. Clearly assigning ownership helps ensure accountability for information throughout its lifecycle and supports consistent application of security controls.<\/span><\/p>\n<h3><b>Question 164<\/b><\/h3>\n<p><b>Which role is primarily responsible for implementing and maintaining security controls for information according to requirements established by the data owner?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data subject<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data custodian<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External auditor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business partner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data custodian is responsible for implementing and maintaining the technical and operational controls required to protect information. These responsibilities can include backups, access controls, storage management, encryption, system configuration, and other safeguards. The data owner generally determines the classification, business requirements, and acceptable access conditions, while the custodian implements those requirements. Separating ownership from custodianship provides clearer accountability and prevents technical administrators from independently deciding business-level data requirements. The exact responsibilities may vary according to organizational structure and applicable regulations.<\/span><\/p>\n<h3><b>Question 165<\/b><\/h3>\n<p><b>Which privacy concept requires an organization to use collected personal information only for the purpose for which it was originally obtained, unless additional authorization exists?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Purpose limitation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset valuation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network isolation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Purpose limitation requires personal information to be collected and used for specified, legitimate purposes rather than being repurposed arbitrarily. Before using data for a new purpose, an organization may need additional authorization, notice, consent, or another lawful basis depending on applicable requirements. Purpose limitation helps prevent unnecessary secondary uses and supports responsible privacy management. Organizations should document why information is collected and establish procedures that restrict inappropriate reuse. This principle works alongside data minimization, retention controls, access restrictions, and transparency requirements.<\/span><\/p>\n<h3><b>Question 166<\/b><\/h3>\n<p><b>Which technique replaces sensitive payment card information with a non-sensitive representative value that has no exploitable mathematical relationship to the original data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash cracking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deduplication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a token that represents the original value. The token itself generally does not contain the original information or provide a mathematical means of deriving it. A protected tokenization system maintains the relationship between the token and original value within a controlled environment. Tokenization is commonly used to reduce exposure of payment information and other sensitive data in systems that do not need the original value. It differs from encryption because encrypted data can generally be transformed back using the appropriate cryptographic key.<\/span><\/p>\n<h3><b>Question 167<\/b><\/h3>\n<p><b>Which technique transforms data into a fixed-length value that is designed to detect changes to the original information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encoding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hashing transforms input data into a fixed-length digest using a mathematical algorithm. A secure cryptographic hash function is designed so that even a small change to the input produces a substantially different digest. Hashes are commonly used to verify data integrity, store passwords with appropriate additional protections, and support digital signatures. Hashing is not encryption because a secure hash is intended to be one-way rather than reversible. Organizations should select modern, appropriate algorithms and avoid obsolete functions when stronger alternatives are available.<\/span><\/p>\n<h3><b>Question 168<\/b><\/h3>\n<p><b>Which cryptographic method uses the same secret key for both encryption and decryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Symmetric encryption uses the same secret key, or corresponding shared secret material, to encrypt and decrypt information. It is generally efficient and well suited for protecting large amounts of data. The major challenge is securely distributing and managing the secret key between authorized parties. AES is a widely used symmetric encryption algorithm. Asymmetric cryptography instead uses a related public and private key pair. In many secure protocols, asymmetric cryptography is used to establish or exchange secrets, while symmetric algorithms provide efficient protection for the actual data.<\/span><\/p>\n<h3><b>Question 169<\/b><\/h3>\n<p><b>Which cryptographic approach uses a public key and a corresponding private key for security operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric cryptography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric cryptography<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message digesting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asymmetric cryptography uses mathematically related public and private keys. The public key can generally be distributed openly, while the private key must be protected by its owner. Depending on the algorithm and operation, asymmetric cryptography can support encryption, digital signatures, authentication, and secure key establishment. RSA and elliptic-curve algorithms are examples of asymmetric cryptographic approaches. Compared with symmetric encryption, asymmetric operations are generally more computationally expensive, so systems often combine both approaches to achieve secure and efficient communication.<\/span><\/p>\n<h3><b>Question 170<\/b><\/h3>\n<p><b>Which technology is commonly used to establish an encrypted and authenticated connection between a web browser and a web server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transport Layer Security, or TLS, provides cryptographic protection for network communications and is widely used to secure web traffic. When HTTPS is used, HTTP operates over a TLS-protected connection. TLS can provide confidentiality, integrity, and server authentication through digital certificates. Depending on the configuration and protocol version, client authentication can also be supported. Plain HTTP does not inherently provide encryption, while Telnet and traditional FTP do not provide the same level of modern transport protection by default. Proper certificate validation and secure protocol configuration remain important.<\/span><\/p>\n<h3><b>Question 171<\/b><\/h3>\n<p><b>Which protocol is specifically designed to provide secure remote command-line access to a system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSH<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMPv1<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Shell, or SSH, provides encrypted remote access to systems and can support secure command-line administration, file transfer, tunneling, and related functions. SSH protects authentication and session data against interception when properly configured. It is commonly used by administrators to manage servers remotely. Telnet provides remote terminal access without strong built-in encryption and can expose credentials and commands to network interception. SSH security also depends on appropriate authentication, key management, configuration, patching, and restriction of unnecessary administrative access.<\/span><\/p>\n<h3><b>Question 172<\/b><\/h3>\n<p><b>Which authentication factor is represented by a password or PIN?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A password or PIN is an example of the \u201csomething you know\u201d authentication factor because the user must possess knowledge of a secret value. Other authentication factors include something you have, such as a hardware token or smartphone, and something you are, such as a fingerprint or facial characteristic. Strong authentication often combines two or more independent factor types. Simply using two passwords does not provide true multifactor authentication because both credentials belong to the same factor category. Proper factor independence is essential when designing MFA controls.<\/span><\/p>\n<h3><b>Question 173<\/b><\/h3>\n<p><b>Which authentication factor is represented by a hardware security token that generates or stores authentication credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you do<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security token represents the \u201csomething you have\u201d authentication factor because successful authentication depends on possession of the physical device. Examples include hardware OTP tokens and certain cryptographic security keys. Possession factors can strengthen authentication when combined with another independent factor, such as a password or biometric characteristic. Organizations should establish procedures for lost or stolen tokens, including revocation and replacement. A possession factor alone does not necessarily provide multifactor authentication; MFA requires multiple independent factor categories.<\/span><\/p>\n<h3><b>Question 174<\/b><\/h3>\n<p><b>Which biometric characteristic is generally considered a behavioral biometric rather than a physiological biometric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fingerprint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Retina pattern<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Voice pattern<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Iris pattern<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Voice pattern is commonly classified as a behavioral biometric because it reflects characteristics associated with how an individual speaks. Fingerprints, retinal patterns, and iris patterns are generally considered physiological biometrics because they are based on physical characteristics. Biometric systems compare a presented characteristic against an enrolled template and calculate whether the match satisfies a defined threshold. Biometrics can provide strong identity verification, but they also introduce privacy and enrollment considerations. Organizations should protect biometric templates carefully because biometric characteristics cannot simply be replaced like passwords.<\/span><\/p>\n<h3><b>Question 175<\/b><\/h3>\n<p><b>Which attack attempts to gain unauthorized access by trying many possible passwords until one succeeds?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Brute-force attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Salami attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A brute-force attack systematically attempts many possible passwords, keys, or other authentication values until the correct one is discovered. The feasibility of such attacks depends on factors such as password complexity, key length, rate limiting, account lockout, multifactor authentication, and the attacker&#8217;s available computing resources. Strong password policies, MFA, monitoring, and appropriate throttling can reduce the effectiveness of brute-force attempts. A dictionary attack is a related technique that focuses on likely words and commonly used passwords rather than trying every possible combination.<\/span><\/p>\n<h3><b>Question 176<\/b><\/h3>\n<p><b>An attacker captures a valid authentication message and later retransmits it to gain unauthorized access. What type of attack is this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A replay attack occurs when an attacker captures valid communication or authentication information and retransmits it later to impersonate an authorized party or repeat a previously accepted transaction. Countermeasures include timestamps, sequence numbers, nonces, session identifiers, challenge-response mechanisms, and cryptographic protections that prevent captured messages from being reused successfully. Encryption alone does not necessarily prevent replay if an attacker can capture and retransmit valid encrypted messages. Secure protocol design must therefore address both confidentiality and the freshness of communications.<\/span><\/p>\n<h3><b>Question 177<\/b><\/h3>\n<p><b>Which value is commonly used in cryptographic protocols to ensure that a message or transaction is fresh and not simply a reused previous message?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonce<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Salt<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ciphertext<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A nonce is a value intended to be used only once within a particular cryptographic context. Nonces can help prevent replay attacks by ensuring that a previously captured message cannot simply be reused as a valid response. They are commonly incorporated into challenge-response authentication and various cryptographic protocols. A nonce should be generated and managed according to the requirements of the protocol. A salt serves a different purpose, commonly adding uniqueness to password hashing. Certificates primarily bind identities or attributes to public keys through trusted mechanisms.<\/span><\/p>\n<h3><b>Question 178<\/b><\/h3>\n<p><b>Which security mechanism monitors network or system activity and automatically blocks traffic that matches known malicious patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion prevention system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intrusion detection system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security information repository<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion prevention system, or IPS, monitors activity and can take automated action to block or prevent detected malicious traffic. Depending on its implementation, an IPS may identify threats through signatures, behavioral analysis, protocol analysis, or other detection techniques. An intrusion detection system generally detects and alerts on suspicious activity without directly blocking it. Vulnerability scanners identify weaknesses rather than necessarily preventing active attacks. IPS deployment requires careful tuning because overly aggressive rules can block legitimate traffic and create operational problems.<\/span><\/p>\n<h3><b>Question 179<\/b><\/h3>\n<p><b>Which security technology collects and correlates security events from multiple systems to help analysts identify suspicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Security Information and Event Management, or SIEM, platform collects and correlates security-related events from multiple sources such as servers, applications, network devices, authentication systems, and security controls. Correlation can help identify patterns that may not be visible when examining individual logs. SIEM platforms can support alerting, investigation, compliance reporting, and security monitoring. Their effectiveness depends on appropriate data sources, time synchronization, detection rules, retention, and skilled analysis. A SIEM does not automatically eliminate threats; it primarily provides centralized visibility and analytical capabilities.<\/span><\/p>\n<h3><b>Question 180<\/b><\/h3>\n<p><b>Which control prevents unauthorized software from executing by allowing only explicitly approved applications to run?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting permits only approved software to execute on a system while blocking applications that are not explicitly authorized. This can significantly reduce the risk of malware and unauthorized software execution, particularly on systems with predictable workloads. Allowlisting can be implemented using application identities, cryptographic hashes, publishers, paths, or other criteria depending on the technology. Maintaining an accurate approved-software list is essential because legitimate applications and versions may change. Allowlisting is a preventive control and can complement endpoint monitoring, patch management, and least privilege.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 161 Which security principle requires an organization to collect only the personal information necessary for a specific legitimate purpose? Data minimization Data aggregation Data remanence Data dispersion Correct Answer: 1 Explanation Data minimization requires organizations to collect, process, and retain only the personal [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15496"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15496"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15496\/revisions"}],"predecessor-version":[{"id":15519,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15496\/revisions\/15519"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}