{"id":15506,"date":"2026-09-18T05:30:13","date_gmt":"2026-09-18T05:30:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15506"},"modified":"2026-09-18T05:30:13","modified_gmt":"2026-09-18T05:30:13","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which recovery metric defines the maximum acceptable amount of time that a system or business process can remain unavailable after a disruption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ALE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Time Objective, or RTO, defines the maximum acceptable period within which a system, service, or business process should be restored after a disruption. It is established according to business requirements and the consequences of prolonged unavailability. RTO influences recovery strategies, alternate facilities, staffing, technology requirements, and restoration procedures. RTO should be determined through business impact analysis rather than selected arbitrarily. It differs from RPO, which focuses on the acceptable amount of data loss measured in time rather than the time required to restore operations.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which recovery facility is typically equipped with the infrastructure necessary to support operations immediately or with minimal preparation after a major disruption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hot site is a recovery facility that is already equipped with substantial infrastructure and resources required to support business operations following a disruption. Depending on the design, systems and data may be maintained in a ready or near-ready state, allowing faster recovery than a cold site. Hot sites are generally more expensive because maintaining operational infrastructure and synchronization requires significant resources. Organizations should select recovery facilities according to business impact, RTO requirements, budget, geographic considerations, and the criticality of the services being protected.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>Which recovery facility provides infrastructure and equipment but generally requires additional preparation before operations can resume?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mobile storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm site provides more preparation and infrastructure than a cold site but is generally not maintained in a fully operational state like a hot site. It may contain servers, networking equipment, power, and environmental controls, but additional configuration, restoration, or data loading may be required before production operations can resume. Warm sites can provide a balance between recovery speed and cost. Organizations should determine whether the expected recovery capability meets the RTO established for the affected business functions.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which recovery facility provides basic infrastructure but generally requires significant equipment installation and configuration before it can support normal operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mirrored site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cold site provides basic facilities such as physical space, power, environmental controls, and connectivity but generally lacks fully configured production systems. Significant preparation, equipment installation, configuration, and data restoration may therefore be required before operations can resume. Cold sites are typically less expensive to maintain than hot sites but usually have longer recovery times. They may be appropriate when business functions can tolerate extended downtime or when budget constraints make fully equipped recovery facilities impractical. Recovery plans should account for equipment availability and transportation requirements.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which backup strategy copies all selected data each time the backup is performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A full backup copies all selected data during each backup operation. Because every backup contains a complete copy of the selected information, restoration can generally be simpler and faster compared with strategies that require multiple dependent backup sets. However, full backups typically require more storage capacity and may take longer to complete. Organizations may combine periodic full backups with incremental or differential backups to balance storage, backup windows, and recovery requirements. Backup schedules should also account for retention, encryption, offsite storage, and restoration testing.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which backup method contains changes made since the most recent full backup?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Differential backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incremental backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mirror backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A differential backup contains data that has changed since the most recent full backup. Each new differential backup continues to include all changes made after that full backup, so its size generally increases until another full backup is created. During restoration, the organization normally needs the latest full backup and the latest differential backup. This can make restoration simpler than using a long chain of incremental backups. The appropriate strategy depends on recovery requirements, available storage, backup windows, and the organization&#8217;s operational priorities.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which disaster recovery activity verifies that personnel and procedures can successfully execute the documented recovery plan without necessarily performing a full technical recovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tabletop exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A tabletop exercise is a discussion-based disaster recovery or incident response exercise in which participants work through a simulated scenario using documented plans and procedures. It can reveal unclear responsibilities, communication problems, missing dependencies, and weaknesses in decision-making without requiring a complete technical recovery. Participants discuss what actions they would take and how they would coordinate with other teams. Tabletop exercises are generally less disruptive and less expensive than full-scale technical exercises, making them useful for regularly validating plans and identifying improvement opportunities.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which disaster recovery exercise involves actually restoring systems or performing operational recovery activities to validate technical capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Document review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full interruption test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technical recovery test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy acknowledgment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A technical recovery test validates whether systems, infrastructure, procedures, and personnel can perform required recovery activities. Depending on the scope, the test may involve restoring backups, rebuilding servers, activating alternate infrastructure, testing network connectivity, or validating application dependencies. Technical testing provides stronger evidence of actual recovery capability than simply reviewing documentation. Organizations should carefully define scope and safeguards to prevent unnecessary disruption. Results should be documented, weaknesses assigned to responsible personnel, and recovery procedures updated based on lessons learned.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which business continuity concept identifies the resources and dependencies required for a critical business process to operate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource dependency analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security awareness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Resource dependency analysis identifies the resources and relationships necessary for a business process to function. Dependencies may include personnel, facilities, applications, databases, network services, suppliers, utilities, telecommunications, and other supporting resources. Understanding these relationships helps organizations identify potential single points of failure and determine appropriate continuity and recovery strategies. The analysis can also reveal dependencies that may not be immediately obvious, such as a critical application relying on a specific database or external service. Results should be incorporated into continuity and disaster recovery planning.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which activity establishes how quickly critical services must be restored and how much data loss can be tolerated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security awareness training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business impact analysis helps organizations determine the consequences of disruptions and establish recovery requirements for critical business functions. Among other outcomes, it supports the development of recovery time and recovery point objectives. The analysis considers factors such as financial loss, regulatory obligations, operational disruption, customer impact, and dependencies. BIA results help management prioritize recovery activities and determine which resources require stronger resilience. It differs from vulnerability assessment, which focuses on weaknesses that could be exploited or otherwise cause security problems.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which security governance document establishes management&#8217;s overall direction and expectations for protecting organizational information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">System log<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security policy establishes management&#8217;s high-level direction, expectations, and requirements concerning information security. It provides a foundation for standards, procedures, guidelines, and technical controls. Policies may address topics such as access control, acceptable use, data protection, incident response, risk management, and personnel responsibilities. Senior management approval is important because policies represent organizational authority and expectations. Policies should be communicated to relevant personnel and periodically reviewed to ensure they remain aligned with business objectives, legal requirements, technological changes, and current security risks.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which document provides mandatory, detailed requirements that support the implementation of an organizational security policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guideline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Memo<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security standard establishes mandatory and specific requirements for implementing a broader organizational policy. Standards can define approved technologies, configurations, security settings, password requirements, encryption methods, or other measurable requirements. Unlike guidelines, which are generally recommendations, standards are normally expected to be followed unless an approved exception exists. Standards translate management expectations into consistent technical or operational requirements. Organizations should maintain standards as environments change and should establish exception processes for situations where a mandatory requirement cannot reasonably be implemented.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which document provides recommended practices that personnel may follow but does not normally impose mandatory requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guideline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Regulation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A guideline provides recommended practices or advice intended to help personnel achieve security objectives. Unlike a standard, a guideline generally does not impose a mandatory requirement, although organizations may choose to make specific guidelines mandatory through policy or standards. Guidelines can be useful when different situations require flexibility or when personnel need practical recommendations for implementing security requirements. Examples include recommended configuration practices, secure handling advice, and suggested administrative procedures. Guidelines should remain aligned with organizational policies and should be reviewed as technologies and risks evolve.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which document describes the specific sequence of actions personnel should follow when performing a recurring security task?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procedure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guideline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mission statement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A procedure provides detailed, step-by-step instructions for performing a specific task or process. Procedures translate broader policies and standards into repeatable operational actions. Examples include account provisioning procedures, incident escalation procedures, backup restoration procedures, and employee termination procedures. Well-written procedures help promote consistency, reduce errors, and clarify responsibilities. They should identify prerequisites, required approvals, actions, validation steps, and documentation requirements where appropriate. Procedures should be reviewed periodically and updated when systems, responsibilities, technologies, or organizational requirements change.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which governance activity ensures that an organization continually monitors whether security objectives and controls remain aligned with business requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security governance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media destruction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security governance provides the structures, responsibilities, policies, and oversight mechanisms used to direct and control an organization&#8217;s security program. Effective governance helps ensure that security objectives remain aligned with business strategy, risk tolerance, legal obligations, and operational requirements. Governance may involve senior management oversight, security policies, risk reporting, performance measurements, compliance monitoring, and accountability structures. It is broader than implementing individual technical controls. Strong governance ensures that security decisions are made consistently and that management receives appropriate information about significant risks and control effectiveness.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which concept requires an organization to identify and manage the security responsibilities of external suppliers and service providers throughout their relationship?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Third-party risk management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deduplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network tunneling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party risk management addresses security risks introduced by vendors, contractors, suppliers, cloud providers, and other external parties. It should cover the full relationship lifecycle, including selection, assessment, contracting, onboarding, monitoring, changes, and termination. Organizations may establish security requirements, conduct assessments, review independent evidence, define incident notification obligations, and maintain audit rights. Risk should be evaluated according to the sensitivity of information and services involved. Ongoing monitoring is important because a vendor&#8217;s security posture can change after the initial assessment.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which personnel security practice helps determine whether an individual is suitable for a position before granting access to sensitive organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Background screening<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Background screening is a personnel security practice used to evaluate an individual&#8217;s suitability for a position based on applicable organizational, legal, and regulatory requirements. Depending on the role and jurisdiction, screening may consider employment history, education, references, identity, or other permitted information. Screening requirements should be risk-based and consistently applied according to organizational policy and applicable law. Screening is only one part of personnel security. Organizations should also address onboarding, security awareness, access management, role changes, disciplinary processes, and termination procedures.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which personnel security process ensures that an employee&#8217;s physical and logical access is removed when employment ends?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Offboarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Onboarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security awareness<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Offboarding is the controlled process used when an employee or contractor leaves an organization. It can include disabling accounts, collecting access badges and equipment, revoking credentials, removing application permissions, retrieving organizational information, and communicating relevant obligations. Prompt offboarding reduces the opportunity for former personnel to retain unauthorized access. The process should coordinate human resources, management, physical security, identity management, and information technology functions. Organizations should define different procedures for routine and involuntary termination because the timing and security requirements may differ.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which personnel security practice periodically moves employees between different job responsibilities to reduce the opportunity for fraud and improve organizational resilience?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory vacation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Background screening<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Job rotation periodically moves personnel between different responsibilities or positions. It can reduce the likelihood that one individual maintains exclusive control over a process for an extended period and may expose irregularities that another employee notices. Job rotation can also improve cross-training and organizational resilience by ensuring multiple employees understand important processes. It should be carefully planned because moving employees between roles can introduce temporary access and training requirements. Job rotation works well alongside separation of duties, mandatory vacations, monitoring, and access reviews.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which personnel security practice requires employees in sensitive positions to take a continuous period of leave so that another individual can perform their duties and potential irregularities may be identified?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory vacation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Background screening<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mandatory vacation requires personnel, particularly those in sensitive or privileged positions, to take a defined period of continuous leave. Another employee performs the individual&#8217;s responsibilities during the absence, which can expose fraudulent activity, policy violations, or unusual processes that might otherwise remain hidden. The practice can also support personnel wellbeing and operational continuity. Mandatory vacation is not a substitute for monitoring, access controls, or separation of duties. Organizations should establish appropriate requirements based on risk, role sensitivity, applicable employment rules, and operational needs.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which recovery metric defines the maximum acceptable amount of time that a system or business process can remain unavailable after a disruption? RPO RTO ALE ARO Correct Answer: 2 Explanation Recovery Time Objective, or RTO, defines the maximum acceptable period within which [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15506"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15506"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15506\/revisions"}],"predecessor-version":[{"id":15509,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15506\/revisions\/15509"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}