{"id":15507,"date":"2026-09-18T05:30:02","date_gmt":"2026-09-18T05:30:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15507"},"modified":"2026-09-18T05:30:02","modified_gmt":"2026-09-18T05:30:02","slug":"isc-cissp-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"ISC CISSP Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-exam-dumps\"><b>ISC CISSP Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which security principle requires access rights to be limited to only the resources and actions necessary for a user to perform assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires users, processes, and systems to receive only the permissions necessary to perform their authorized functions. Limiting privileges reduces the potential damage caused by compromised accounts, malicious insiders, accidental actions, or exploited applications. Privileges should be reviewed regularly because job responsibilities can change over time. Least privilege applies to administrative accounts, applications, service accounts, operating systems, and other resources. Organizations can strengthen this principle through role-based access, privileged access management, periodic access reviews, and timely removal of unnecessary permissions.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>A security administrator wants to ensure that an employee can access confidential payroll information only when performing payroll-related duties. Which principle is most directly applicable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Need to know restricts access to information based on whether an individual has a legitimate business requirement to access that specific information. A person may have general authorization to use organizational systems but still should not receive access to confidential information unrelated to assigned responsibilities. Applying need to know can reduce unnecessary exposure of sensitive data and limit the consequences of compromised accounts. It is commonly used with least privilege and access control mechanisms to ensure that users receive only the information required for legitimate business activities.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which access control model assigns permissions based primarily on the functions or responsibilities associated with a user&#8217;s organizational role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rule-based encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based access control, or RBAC, assigns permissions according to predefined organizational roles. Users are assigned to roles such as payroll clerk, database administrator, or security analyst, and each role receives the permissions required for its responsibilities. This approach simplifies administration because permissions can be managed at the role level instead of individually for every user. RBAC also supports consistent access decisions and can help enforce least privilege. Organizations should periodically review role definitions and memberships because outdated assignments can result in excessive or inappropriate access.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which access control model makes authorization decisions using attributes associated with users, resources, actions, and environmental conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based access control, or ABAC, evaluates attributes to determine whether an access request should be permitted. Attributes can describe the user, requested resource, action, location, device, time, security classification, or other relevant conditions. For example, an organization could permit access to a sensitive application only when an authorized employee uses a managed device from an approved location during working hours. ABAC can support highly granular decisions and dynamic policies. However, effective implementation requires accurate attributes, well-designed policies, and reliable enforcement mechanisms.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which access control model allows resource owners to determine who can access their resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Discretionary access control, or DAC, allows the owner of a resource to determine access permissions. The owner can typically grant or revoke access to other users according to organizational rules. DAC provides flexibility but can create security risks if resource owners assign excessive permissions or fail to maintain access lists. It contrasts with mandatory access control, where access decisions are based on centrally defined security labels and rules. Organizations using DAC should combine it with appropriate access reviews, least privilege, and monitoring to reduce unauthorized information exposure.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which access control model uses centrally managed security labels and rules to determine access to classified information?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Discretionary access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Mandatory access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Role-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mandatory access control, or MAC, bases authorization decisions on centrally managed security labels and rules. Users and resources can receive classifications such as confidential, secret, or top secret, and access decisions are determined by the defined security policy rather than by individual resource owners. MAC is useful in environments where information classification and strict access enforcement are critical. Because users generally cannot freely change permissions, MAC provides stronger centralized control than DAC. Proper classification, labeling, and policy administration are essential for effective implementation.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>An organization requires users to provide a password and a hardware security token before accessing a privileged administrative system. What security mechanism is being implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires authentication evidence from two or more different factor categories. Common categories include something the user knows, something the user has, and something the user is. A password represents something the user knows, while a hardware security token represents something the user has. Combining different factors provides stronger protection than relying on a password alone because compromising one factor does not automatically provide all required authentication evidence. MFA is particularly valuable for privileged accounts, remote access, and systems containing sensitive information.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which authentication factor category includes fingerprints, facial characteristics, and iris patterns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you know<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you have<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Somewhere you are<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Something you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Biometric characteristics such as fingerprints, facial characteristics, iris patterns, and certain behavioral characteristics fall under the \u201csomething you are\u201d authentication factor category. Biometrics can provide convenient authentication because the characteristic is associated with the individual rather than being a memorized secret or physical token. However, biometric systems require careful consideration of false acceptance rates, false rejection rates, privacy, enrollment, storage, and template protection. Organizations should select biometric mechanisms appropriate for the risk and should consider alternative authentication methods when biometric verification is unavailable.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which identity management capability allows a user to authenticate once and then access multiple authorized applications without repeatedly providing credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Single sign-on, or SSO, allows a user to authenticate once and then access multiple authorized applications without repeatedly entering credentials for each application. SSO can improve usability and reduce the number of passwords users must remember. It can also centralize authentication and simplify account management. However, compromise of the primary authentication mechanism can potentially affect multiple applications, so strong authentication and appropriate session controls are important. SSO is distinct from federation, although federated identity architectures can be used to provide SSO across organizational boundaries.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which capability allows identities from one organization or security domain to be trusted by another domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account lockout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity federation allows organizations or security domains to establish trust relationships so that identities authenticated by one domain can be recognized by another. This can support access to external applications, cloud services, or partner resources without requiring separate local identities for every service. Federation commonly relies on established trust relationships and identity assertions exchanged between participating systems. Security administrators must carefully define trust boundaries, authentication requirements, attribute sharing, session management, and revocation processes to prevent inappropriate access across organizational boundaries.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which security principle requires an authorization check every time a subject attempts to access a protected object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least common mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete mediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Psychological acceptability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Complete mediation requires every access attempt to a protected resource to be checked against the applicable authorization policy. The principle prevents a system from relying on an earlier authorization decision indefinitely when circumstances or permissions may have changed. Implementing complete mediation helps prevent unauthorized access caused by stale permissions or bypassed checks. Security mechanisms should be designed so that protected resources cannot be accessed through an alternate path that avoids authorization enforcement. Performance considerations may require efficient implementations, but security checks should remain effective.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which security design principle recommends that security mechanisms should remain straightforward and contain as little unnecessary complexity as possible?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Economy of mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Economy of mechanism recommends keeping security mechanisms simple and minimizing unnecessary complexity. Simpler designs are generally easier to understand, implement, test, maintain, and audit. Excessive complexity can introduce configuration errors, hidden dependencies, and vulnerabilities that are difficult to identify. The principle does not mean eliminating necessary security controls; instead, it encourages efficient and understandable security mechanisms. Organizations should consider simplicity when designing authentication systems, access controls, network architectures, application security mechanisms, and administrative procedures.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which security design principle states that the security of a system should not depend on keeping its design secret?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Need to know<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The open design principle states that security should not depend on keeping the design or implementation approach secret. Instead, protection should rely on well-designed security mechanisms, properly protected keys, strong authentication, and appropriate access controls. Openly understood designs can receive broader review, testing, and analysis, potentially helping identify weaknesses. This principle is especially important in cryptography, where algorithms may be publicly known while secret keys provide confidentiality. Relying on secrecy of system design can create false confidence and may make independent security evaluation more difficult.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which security design principle requires a system to deny access by default unless explicit authorization has been granted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least common mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete mediation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fail-safe defaults require systems to deny access unless a request has been explicitly authorized. This approach reduces the chance that configuration errors or unexpected conditions will accidentally result in excessive access. For example, a newly created account should not automatically receive access to sensitive resources simply because permissions were not explicitly configured. Administrators should deliberately grant required permissions rather than relying on broad default access. Fail-safe defaults are particularly important for access control lists, firewall rules, application permissions, and other mechanisms that enforce security decisions.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which security design principle recommends minimizing the mechanisms shared between users or processes to reduce unintended interaction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Complete mediation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least common mechanism<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe defaults<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The least common mechanism principle recommends minimizing the amount of functionality or resources shared among users, processes, or security domains. Excessive sharing can create unintended communication paths and increase the potential impact of a compromise. Separating resources can reduce opportunities for information leakage, privilege abuse, and cross-process interference. Examples include isolating application processes, separating administrative interfaces, and limiting shared services. This principle complements least privilege and segmentation by reducing unnecessary dependencies and limiting the number of components that must be trusted across security boundaries.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which security concept is primarily concerned with proving that an individual or system performed a particular action and can be held responsible for it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accountability ensures that actions can be associated with identifiable individuals, systems, or processes so responsibility can be established. It commonly depends on authentication, authorization, logging, monitoring, and reliable time synchronization. For example, an audit trail that records which authenticated administrator changed a configuration can support accountability. Accountability is different from confidentiality, which protects information from unauthorized disclosure. Strong accountability mechanisms should protect logs from unauthorized alteration and should retain sufficient information to support investigations, compliance activities, and security monitoring.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which security property ensures that information is protected from unauthorized disclosure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accountability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidentiality ensures that information is accessible only to authorized individuals, systems, or processes. Controls supporting confidentiality include access controls, encryption, data classification, information handling procedures, network segmentation, and secure authentication. Confidentiality is one component of the CIA triad, along with integrity and availability. A confidentiality failure occurs when sensitive information is disclosed to an unauthorized party, whether through an attack, accidental exposure, misconfiguration, or inappropriate access. Organizations should identify sensitive information and apply protection measures based on its classification and associated risk.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which security property ensures that information remains accurate, complete, and protected from unauthorized modification?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privacy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity ensures that information remains accurate, complete, and protected against unauthorized or improper modification. Controls supporting integrity include hashing, digital signatures, file integrity monitoring, access controls, change management, and transaction validation. An integrity violation can occur when an attacker alters records, malware modifies files, or an authorized user makes an unauthorized change. Integrity is one component of the CIA triad. Organizations should protect both stored and transmitted information against unauthorized modification and establish mechanisms for detecting changes that should not have occurred.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which security property focuses on ensuring that authorized users can access systems and information when needed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Availability ensures that authorized users can access systems, applications, and information when required for legitimate business purposes. Availability can be supported through redundancy, fault tolerance, backups, disaster recovery, capacity management, monitoring, resilient architecture, and protection against denial-of-service attacks. Availability requirements should be aligned with business needs because different services may have different tolerance levels for downtime. Excessive focus on availability without considering confidentiality and integrity can create additional risks, so organizations should maintain a balanced approach across all three elements of the CIA triad.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which security concept provides evidence that a party cannot credibly deny having performed a specific action or transaction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Nonrepudiation provides evidence that can help prevent a party from credibly denying involvement in a specific transaction or action. Digital signatures are a common mechanism used to support nonrepudiation because they can associate signed information with a private key under appropriate key management and validation conditions. Reliable identity verification, protected private keys, timestamps, and audit records can further strengthen evidence. Nonrepudiation is distinct from authentication and accountability: authentication establishes identity, while accountability associates actions with entities, and nonrepudiation provides stronger evidence against later denial.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which security principle requires access rights to be limited to only the resources and actions necessary for a user to perform assigned responsibilities? Need to know Least privilege Job rotation Separation of duties Correct Answer: 2 Explanation Least privilege requires users, processes, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15507"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15507"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15507\/revisions"}],"predecessor-version":[{"id":15508,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15507\/revisions\/15508"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}