{"id":15502,"date":"2026-09-18T05:31:02","date_gmt":"2026-09-18T05:31:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15502"},"modified":"2026-09-18T05:31:02","modified_gmt":"2026-09-18T05:31:02","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 281<\/b><\/h3>\n<p><b>Which security architecture principle recommends using multiple independent layers of protection so that failure of one control does not expose the entire environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of security controls so that the failure or bypass of one control does not automatically compromise the protected resource. Layers may include physical security, network segmentation, endpoint protection, access controls, encryption, monitoring, and incident response. The approach reduces dependence on a single security mechanism and can limit the impact of successful attacks. Effective defense in depth should use complementary controls rather than unnecessary duplication. Organizations should evaluate whether each layer addresses a meaningful threat and contributes to overall risk reduction.<\/span><\/p>\n<h3><b>Question 282<\/b><\/h3>\n<p><b>An organization separates development, testing, and production environments so that changes made by developers cannot directly affect live systems. What security practice is being implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Environment separation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Environment separation isolates systems according to their purpose, such as development, testing, staging, and production. This reduces the likelihood that experimental code, configuration changes, or unauthorized testing activities will affect live services. Access can also be restricted differently in each environment, limiting developers&#8217; direct access to production resources. Sensitive production data should not automatically be copied into development environments without appropriate authorization and protection. Strong separation supports change management, secure development practices, least privilege, and operational stability.<\/span><\/p>\n<h3><b>Question 283<\/b><\/h3>\n<p><b>Which security process ensures that changes to an information system are formally requested, reviewed, approved, tested, and documented before implementation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change management provides a controlled process for modifying systems, applications, infrastructure, and security configurations. A typical process includes documenting the proposed change, assessing its impact and risks, obtaining appropriate approval, testing where practical, scheduling implementation, and maintaining records. Emergency changes may follow an expedited process while still requiring appropriate documentation and review. Effective change management reduces unauthorized modifications and helps prevent outages caused by poorly planned changes. It also provides accountability and supports troubleshooting when a change produces unexpected results.<\/span><\/p>\n<h3><b>Question 284<\/b><\/h3>\n<p><b>Which document establishes the rules employees must follow when using an organization&#8217;s computers, networks, applications, and internet resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceptable use policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response report<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An acceptable use policy defines permitted and prohibited uses of organizational information systems and resources. It may address internet usage, email, removable media, personal devices, software installation, inappropriate content, monitoring, and other activities. The policy communicates management expectations and provides a basis for disciplinary or corrective action when violations occur. It should be clearly communicated to personnel and acknowledged where required. Organizations should review acceptable use policies periodically because technologies, working practices, legal requirements, and organizational risks can change.<\/span><\/p>\n<h3><b>Question 285<\/b><\/h3>\n<p><b>Which security activity involves identifying potential adversaries, their capabilities, motivations, and likely methods of attack?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat modeling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling is a structured process for identifying potential threats and understanding how attackers or other adverse events could affect a system. It may consider assets, entry points, trust boundaries, attack paths, adversary capabilities, and potential impacts. Threat modeling is particularly useful during system and application design because security weaknesses can often be addressed more efficiently before deployment. Organizations can use different methodologies, but the objective is to identify meaningful threats and determine appropriate security requirements and controls.<\/span><\/p>\n<h3><b>Question 286<\/b><\/h3>\n<p><b>A security team identifies a vulnerability in an application and determines that attackers could exploit it to gain unauthorized access. What should the team do first after confirming the vulnerability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore it until an incident occurs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess its risk and prioritize remediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete all application data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable every user account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After confirming a vulnerability, the organization should assess its risk and prioritize appropriate remediation based on factors such as exploitability, affected assets, business impact, exposure, and available compensating controls. Not every vulnerability has the same urgency, so risk-based prioritization helps security teams allocate resources effectively. Depending on the circumstances, remediation may involve patching, configuration changes, isolation, access restrictions, or temporary compensating controls. Organizations should document remediation decisions and verify that the vulnerability has been addressed or otherwise brought within acceptable risk tolerance.<\/span><\/p>\n<h3><b>Question 287<\/b><\/h3>\n<p><b>Which process continuously identifies, evaluates, prioritizes, and tracks weaknesses in organizational systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business continuity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability management is a continuous process for discovering, assessing, prioritizing, remediating, and verifying weaknesses in systems and applications. It can include asset discovery, vulnerability scanning, risk analysis, patching, configuration changes, exception management, and validation. Effective vulnerability management does not simply produce a list of vulnerabilities; it prioritizes weaknesses according to organizational risk and business context. Continuous monitoring is important because new vulnerabilities can emerge as software changes, new assets are deployed, or threat actors develop new exploitation techniques.<\/span><\/p>\n<h3><b>Question 288<\/b><\/h3>\n<p><b>Which type of security test provides the tester with complete knowledge of the target system&#8217;s architecture and source code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gray-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">White-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blind testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">White-box testing provides testers with extensive internal knowledge of the target environment, which may include source code, architecture diagrams, credentials, configuration information, or detailed documentation. This approach allows testers to examine internal logic and security controls more deeply than a test performed with no internal information. Black-box testing provides little or no internal knowledge, while gray-box testing provides partial knowledge. Organizations should select the testing approach based on objectives, available resources, scope, and the types of weaknesses they want to identify.<\/span><\/p>\n<h3><b>Question 289<\/b><\/h3>\n<p><b>Which testing approach simulates an attacker who has limited internal knowledge of the target environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">White-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gray-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gray-box testing provides testers with partial information about the target environment. This can represent realistic scenarios in which an attacker has obtained some credentials, documentation, or knowledge about internal systems but does not possess complete information. Gray-box assessments can balance the external perspective of black-box testing with some of the visibility available during white-box testing. The exact level of information should be defined in the test scope and rules of engagement. Testers should operate within authorized boundaries to avoid unnecessary disruption.<\/span><\/p>\n<h3><b>Question 290<\/b><\/h3>\n<p><b>Which security testing method evaluates an application without providing the tester with internal source code or architecture information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">White-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gray-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Black-box testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static code review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Black-box testing evaluates a target with little or no prior internal knowledge. Testers approach the system from an external perspective and attempt to identify vulnerabilities through observable behavior and authorized attack techniques. This approach can provide insight into how an external attacker might interact with the system. Because testers have less internal information, some weaknesses may require more time to discover compared with white-box testing. Black-box testing is often combined with other assessment methods to provide broader security coverage.<\/span><\/p>\n<h3><b>Question 291<\/b><\/h3>\n<p><b>Which security assessment technique analyzes application source code without executing the application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static application security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic application security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network traffic analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability exploitation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static application security testing, or SAST, analyzes application source code, bytecode, or compiled components without executing the application in its normal runtime environment. It can identify weaknesses such as insecure coding patterns, improper input handling, and certain configuration or implementation issues. SAST can be integrated into development pipelines to identify problems earlier in the software lifecycle. However, it does not detect every possible runtime or deployment issue. Organizations often combine SAST with dynamic testing, dependency analysis, code review, and other security testing techniques.<\/span><\/p>\n<h3><b>Question 292<\/b><\/h3>\n<p><b>Which application security testing method evaluates a running application from the outside by sending inputs and observing its behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static application security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic application security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source-code review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration baselining<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic application security testing, or DAST, evaluates an application while it is running. The testing system sends requests and inputs to the application and analyzes its responses and behavior for potential vulnerabilities. DAST can identify issues that become visible only during runtime, such as certain authentication, session management, input validation, and configuration weaknesses. It does not require access to source code, making it useful for applications where source code is unavailable. DAST should be performed in authorized environments to avoid disrupting production services.<\/span><\/p>\n<h3><b>Question 293<\/b><\/h3>\n<p><b>Which attack attempts to insert malicious database commands through an application&#8217;s input fields?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Buffer overflow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session hijacking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection occurs when an application improperly incorporates untrusted input into database queries, allowing an attacker to manipulate the query&#8217;s intended behavior. Depending on the vulnerability and database configuration, attackers may attempt to retrieve, modify, or delete data or perform other unauthorized actions. Strong defenses include parameterized queries, prepared statements, appropriate input validation, least-privileged database accounts, and secure application design. Security testing should verify that user-controlled input cannot alter the intended structure or meaning of database queries.<\/span><\/p>\n<h3><b>Question 294<\/b><\/h3>\n<p><b>Which attack injects malicious client-side script into content that is later executed by another user&#8217;s browser?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-site scripting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting, or XSS, occurs when an application allows untrusted content to be interpreted as executable script in a user&#8217;s browser. Depending on the vulnerability, an attacker may attempt to steal session information, manipulate page content, perform actions on behalf of a victim, or redirect users. Common defenses include context-appropriate output encoding, secure input handling, content security policies, and appropriate cookie protections. Developers should identify where untrusted data enters and leaves an application and ensure it cannot be interpreted as unintended executable content.<\/span><\/p>\n<h3><b>Question 295<\/b><\/h3>\n<p><b>Which attack exploits the timing between two operations to cause a system to behave incorrectly?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Race condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replay attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dictionary attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fragmentation attack<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A race condition occurs when the outcome of a process depends on the timing or ordering of concurrent operations. An attacker may attempt to exploit a gap between checking a condition and using the related resource. For example, an application might verify that a resource is available and then perform an operation after an attacker has altered the resource state. Secure programming techniques such as atomic operations, appropriate synchronization, transaction controls, and careful resource handling can reduce race-condition risks.<\/span><\/p>\n<h3><b>Question 296<\/b><\/h3>\n<p><b>Which technique adds a unique random value to a password before hashing to make precomputed attacks more difficult?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Salting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encoding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password salting adds a unique random value to each password before the password is processed by a password-hashing function. The resulting hash is different even when two users have the same password, making precomputed rainbow-table attacks substantially less useful. Salts are normally stored alongside password hashes because they are not intended to be secret. Strong password storage should use a password-specific hashing function designed to resist guessing attacks, along with appropriate work factors. Salting does not replace strong passwords or other authentication protections.<\/span><\/p>\n<h3><b>Question 297<\/b><\/h3>\n<p><b>Which control prevents unauthorized software from executing by allowing only explicitly approved applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts execution to software that has been explicitly approved according to organizational policy. It can reduce the risk of malware, unauthorized utilities, and unapproved applications executing on protected systems. Depending on implementation, allowlisting may use application identities, file hashes, publishers, paths, or other trusted attributes. Maintaining accurate allowlists is important because legitimate software changes over time. Organizations should also establish procedures for approving updates and exceptions. Allowlisting is particularly useful for systems where the software environment can be tightly controlled.<\/span><\/p>\n<h3><b>Question 298<\/b><\/h3>\n<p><b>Which security technology monitors endpoints for suspicious behavior and can support detection and response activities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint detection and response<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure file transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response, or EDR, continuously monitors endpoint activity and collects security-relevant information such as processes, network connections, file activity, and system behavior. Security teams can use this information to investigate suspicious activity and respond to potential threats. Depending on the platform, EDR can provide capabilities such as endpoint isolation, process termination, evidence collection, and threat hunting. EDR is different from traditional antivirus because it emphasizes broader behavioral visibility and investigation. Effective deployment requires appropriate policies, monitoring processes, and trained personnel.<\/span><\/p>\n<h3><b>Question 299<\/b><\/h3>\n<p><b>Which attack involves sending excessive traffic or requests to a service from many compromised systems in an attempt to make the service unavailable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Distributed denial-of-service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A distributed denial-of-service, or DDoS, attack attempts to overwhelm a service or network resource with traffic or requests originating from multiple systems. The objective is typically to exhaust bandwidth, processing capacity, connection resources, or application-level resources, reducing availability for legitimate users. Mitigation can include traffic filtering, rate limiting, load balancing, content delivery networks, upstream provider assistance, and specialized DDoS protection services. Organizations should identify critical services and establish response procedures because mitigation requirements can vary significantly depending on the attack&#8217;s scale and characteristics.<\/span><\/p>\n<h3><b>Question 300<\/b><\/h3>\n<p><b>Which security device is specifically designed to block or allow web requests based on application-layer rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web application firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless access point<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall, or WAF, protects web applications by inspecting HTTP and HTTPS requests and applying application-layer security rules. It can help detect or block attacks such as certain SQL injection and cross-site scripting attempts, malicious request patterns, and other application-layer threats. A WAF does not replace secure application development because it cannot reliably correct every underlying software vulnerability. Effective deployment requires appropriate rule tuning, monitoring, logging, and regular updates. Organizations should also combine WAF protection with secure coding, vulnerability management, authentication, and other controls.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 281 Which security architecture principle recommends using multiple independent layers of protection so that failure of one control does not expose the entire environment? Defense in depth Least privilege Open design Need to know Correct Answer: 1 Explanation Defense in depth uses multiple [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15502"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15502"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15502\/revisions"}],"predecessor-version":[{"id":15513,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15502\/revisions\/15513"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}