{"id":15500,"date":"2026-09-18T05:31:26","date_gmt":"2026-09-18T05:31:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15500"},"modified":"2026-09-18T05:31:26","modified_gmt":"2026-09-18T05:31:26","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which process identifies, evaluates, and prioritizes organizational assets based on their importance and value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset management involves identifying, documenting, tracking, and maintaining information about organizational assets throughout their lifecycle. Assets can include hardware, software, data, applications, facilities, and services. Understanding what the organization owns and how important each asset is helps security teams determine appropriate protection priorities. Asset management also supports vulnerability management, risk assessment, incident response, and business continuity planning. Organizations should maintain accurate inventories because unknown or unmanaged assets can introduce significant security exposure. Asset ownership and classification should also be clearly assigned.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>An organization wants to determine which systems and business functions would suffer the greatest consequences if a major disruption occurred. Which activity should it perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business impact analysis, or BIA, identifies critical business functions and evaluates the consequences of their disruption. The analysis may consider financial losses, operational disruption, legal obligations, regulatory requirements, customer impact, and reputational consequences. BIA results help organizations establish recovery priorities and determine appropriate recovery objectives. It can also identify dependencies between applications, personnel, facilities, suppliers, and other resources. Unlike vulnerability scanning, which identifies technical weaknesses, a BIA focuses on business consequences and the requirements for maintaining or restoring critical operations.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which document identifies the order in which critical business processes should be restored after a disruptive event?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable use policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business continuity plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business continuity plan establishes strategies and procedures for maintaining or restoring essential business functions during and after a disruption. It can define recovery priorities, alternate processes, communication responsibilities, personnel roles, dependencies, and escalation procedures. Recovery priorities are generally informed by business impact analysis results. A business continuity plan is broader than a disaster recovery plan, which focuses more specifically on restoring technology and related infrastructure. Organizations should regularly test and update continuity plans because business processes, personnel, systems, suppliers, and risks can change over time.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which risk management activity involves comparing identified risks against established organizational risk criteria to determine whether treatment is required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk evaluation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security awareness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk evaluation involves comparing identified and analyzed risks against defined criteria such as risk appetite, tolerance, legal requirements, business priorities, and organizational objectives. The comparison helps determine whether a risk is acceptable or whether additional treatment is necessary. Risk evaluation follows risk identification and analysis and supports informed decisions about mitigation, avoidance, transfer, or acceptance. Organizations should document significant decisions and periodically reassess risks because threat conditions, business priorities, technologies, and regulatory requirements can change.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>A company knowingly retains a security risk because reducing it would cost more than the organization is willing to spend and the remaining exposure falls within approved tolerance. What response is being used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk mitigation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk transference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance occurs when an organization consciously decides to retain a known risk within its approved risk tolerance. Acceptance should be an informed management decision supported by documented analysis rather than an accidental failure to address the risk. Management may determine that additional controls are too expensive, impractical, or disproportionate to the expected benefit. Accepted risks should still be monitored because their likelihood or impact may change. If the risk later exceeds organizational tolerance, management may need to reconsider the treatment strategy and implement additional controls.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which risk treatment strategy reduces either the likelihood or impact of a threat by implementing additional security controls?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk mitigation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk avoidance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk mitigation involves implementing controls that reduce the likelihood of a threat occurring, reduce its potential impact, or both. Examples include deploying multifactor authentication, encrypting sensitive information, improving network segmentation, patching vulnerable systems, and increasing monitoring. Mitigation does not normally eliminate all risk, so some residual risk remains after controls are implemented. Organizations should evaluate whether the remaining exposure falls within acceptable limits. Mitigation decisions should consider effectiveness, cost, operational impact, legal requirements, and the organization&#8217;s overall risk tolerance.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which activity involves identifying potential sources of harm, weaknesses, and circumstances that could negatively affect organizational assets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk transference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk identification is the process of recognizing potential threats, vulnerabilities, assets, and conditions that could create undesirable outcomes. It provides the foundation for subsequent risk analysis and evaluation. Organizations may identify risks through interviews, threat intelligence, vulnerability assessments, audits, business impact analysis, historical incidents, and other techniques. Effective identification should consider both technical and nontechnical risks, including third-party dependencies, physical threats, legal obligations, and operational issues. Maintaining an updated risk register can help organizations track identified risks and their associated treatment decisions.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which document records identified risks, their potential impacts, owners, treatment decisions, and current status?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register is a structured record used to document identified risks and relevant information about them. Depending on organizational requirements, it may include risk descriptions, affected assets, likelihood, impact, risk ratings, owners, treatment strategies, target dates, and current status. A risk register supports ongoing monitoring and management rather than being a one-time document. It helps management understand outstanding exposures and track whether mitigation activities are progressing. Risk registers should be reviewed and updated when significant changes occur in the organization&#8217;s environment or threat landscape.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which principle requires an organization to ensure that information is accessed only by individuals with a legitimate business need?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Psychological acceptability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The need-to-know principle restricts access to information based on whether an individual has a legitimate requirement to use that information for an authorized purpose. Even if a user has a particular level of clearance or broad system access, need-to-know can further limit which specific information the user may access. This principle supports confidentiality and reduces unnecessary exposure of sensitive data. It works closely with least privilege, access control, classification, and authorization processes. Organizations should periodically review access to ensure that business needs remain valid.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which principle limits users to only the permissions required to perform their assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits the permissions available to a user, process, or system to only those necessary for authorized responsibilities. It reduces the potential damage caused by compromised accounts, malicious insiders, excessive privileges, and accidental actions. Least privilege can be implemented through role-based access control, privileged access management, administrative separation, and regular access reviews. Need-to-know focuses specifically on access to particular information based on business requirements, while least privilege focuses more broadly on the permissions and capabilities granted to an entity.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which security process ensures that an employee&#8217;s access is removed or adjusted promptly when employment status or job responsibilities change?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity lifecycle management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity lifecycle management governs identities and access throughout events such as hiring, role changes, transfers, extended leave, and termination. When an employee changes positions, old permissions should be removed and appropriate new permissions should be assigned. When employment ends, access should be disabled according to organizational procedures and risk requirements. Effective lifecycle management reduces orphaned accounts and privilege creep. Automation can improve consistency by integrating human resources records with identity systems. Regular access reviews provide additional assurance that permissions remain appropriate.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which access control approach makes authorization decisions using characteristics such as user role, device type, location, time, and requested resource?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-independent access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based access control, or ABAC, evaluates attributes associated with users, resources, actions, and environmental conditions when making authorization decisions. For example, a policy could allow access to a sensitive application only when the user belongs to an approved department, uses a managed device, connects during an approved period, and requests an authorized operation. ABAC supports detailed contextual decisions but can become complex when many attributes and policies interact. Organizations should document policies carefully and regularly review them to prevent conflicting, excessive, or outdated authorization rules.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>Which access control model allows resource owners to determine who can access their resources and what permissions they receive?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Discretionary access control, or DAC, allows resource owners or authorized users to control access to resources they own. Permissions can commonly be granted or revoked for individual users or groups. DAC provides flexibility but can create risks if users grant access too broadly or fail to maintain permissions properly. Mandatory access control is centrally enforced using security labels and rules, while role-based access control assigns permissions through organizational roles. Organizations using DAC should still enforce appropriate policies, auditing, least privilege, and access reviews to reduce excessive permissions.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which access control model uses centrally managed security labels to enforce information access restrictions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mandatory access control, or MAC, uses centrally established rules and security labels to control access. Users and resource owners generally cannot freely modify the security classifications or bypass the centrally enforced policy. MAC is useful in environments where strict information-flow requirements are necessary. For example, information can be assigned classification levels and subjects can receive corresponding authorization levels. MAC provides stronger centralized control than DAC, where resource owners can manage permissions. Implementing MAC requires carefully defined classifications, authorization rules, administrative procedures, and appropriate system support.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which authentication method requires a user to provide two or more independent categories of authentication factors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication, or MFA, requires authentication using two or more independent factor categories. Common categories include something you know, something you have, and something you are. For example, a password combined with a hardware security key uses knowledge and possession factors. MFA provides stronger protection than a password alone because compromising one factor does not necessarily provide everything required for authentication. Using two credentials from the same category does not constitute true multifactor authentication. Organizations should select factors appropriate to the sensitivity and risk of the protected resources.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which authentication technology allows a user to authenticate once and then access multiple authorized applications without repeatedly entering credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data loss prevention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on, or SSO, allows users to authenticate through a centralized identity service and then access multiple authorized applications without repeatedly providing credentials. SSO can improve usability and simplify identity management because authentication policies can be centrally administered. However, a compromised SSO account may provide access to multiple applications, making strong authentication and account protection particularly important. SSO should be combined with appropriate authorization, session management, monitoring, and lifecycle controls. Federated identity technologies can extend similar authentication capabilities across organizational boundaries.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which technology allows an organization to delegate authentication to an external identity provider while allowing users to access a separate service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity federation enables organizations to establish trust relationships between identity providers and service providers. A user can authenticate through an approved identity provider and then access a separate application or service without the service necessarily maintaining a separate password for that user. Federation can simplify identity management across organizational or cloud boundaries. Common technologies supporting federated identity include SAML, OAuth-based mechanisms, and OpenID Connect, depending on the use case. Strong trust configuration, secure token handling, appropriate authorization, and lifecycle management remain essential.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which protocol is commonly used to provide authentication and authorization services for users connecting to network access devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RADIUS provides centralized authentication, authorization, and accounting services and is widely used with network access technologies such as wireless networks, VPN gateways, and network access control systems. A network device can forward authentication requests to a RADIUS server, allowing centralized management of credentials and access policies. Accounting capabilities can record information about network sessions and usage. RADIUS should be deployed with appropriate security protections and integrated with strong authentication systems. Centralized authentication can simplify administration while improving consistency across multiple network access points.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which protocol is primarily used to retrieve and manage information stored in a directory service such as an enterprise user directory?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Lightweight Directory Access Protocol, or LDAP, is used to access and manage directory information. Enterprise directories can store identities, groups, organizational information, and other attributes used by authentication and authorization systems. LDAP supports operations such as searching, adding, modifying, and deleting directory entries according to permissions. Because directory information can be sensitive, organizations should protect LDAP communications using secure transport and appropriate authentication. LDAP itself is a directory access protocol rather than a complete identity management solution, although it commonly forms part of larger IAM architectures.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which protocol is designed to provide secure file transfer capabilities using an SSH connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Copy Protocol, or SCP, provides secure file transfer using the SSH protocol and its associated encryption and authentication mechanisms. It can protect files and credentials from interception while transferring information between systems. Traditional FTP does not inherently provide encryption, while TFTP is a lightweight file transfer protocol with minimal security features. SCP is commonly used for administrative file transfers in environments where SSH access is already available. Organizations should still apply least privilege, strong authentication, secure key management, and appropriate file permissions when using SCP.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which process identifies, evaluates, and prioritizes organizational assets based on their importance and value? Asset management Incident response Security monitoring Change management Correct Answer: 1 Explanation Asset management involves identifying, documenting, tracking, and maintaining information about organizational assets throughout their lifecycle. Assets [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15500"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15500"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15500\/revisions"}],"predecessor-version":[{"id":15515,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15500\/revisions\/15515"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15500"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15500"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15500"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}