- Home
- ISC
- Certified in Cybersecurity (CC)
- ISC.CC.v2026-08-08.q343
- Question 267
Join the discussion
Add Comments
- Other Question (343q)
- Q1. Which of these is WEAKEST form of authentication we can implement?...
- Q2. Port forwarding is also known as
- Q3. What is an IP address
- Q4. Tina is an (ISC)² member and is invited to join an online group of IT security enthusiasts...
- Q5. Which of these is an example of a physical access control mechanism?...
- Q6. Which uses encrypted, machine-generated codes to verify a user's identity....
- Q7. To avoid bodily injury claims, a company decides not to offer high-risk services. This is ...
- Q8. The Bell-LaPadula access control model is a form of:...
- Q9. Which maintains that a user or entity should only have access to the spec data, resources ...
- Q10. What is privacy in the context of Information Security?...
- Q11. Which OSI layer associates MAC addresses with network devices?...
- Q12. A _____ is a record of something that has occurred....
- Q13. Within the organization, who can identify risk?...
- Q14. What is the importance of non-repudiation in today's world of e-commerce?...
- Q15. What is the main purpose of using digital signatures in communication security?...
- Q16. Access control used in in high-security situations such as military and government organiz...
- Q17. Which plan is activated when both the Incident response and BCP fails...
- Q18. Which one of the following groups is NOT normally part of an organization's cybersecurity ...
- Q19. Which is NOT a function of an Intrusion Prevention System (IPS)?...
- Q20. Data _____ is data left behind on systems/media after normal deletion procedures have been...
- Q21. Which protocol would be most suitable to fulfill the secure communication requirements bet...
- Q22. (ISC)² publishes a Common Body of Knowledge (CBK) that IT security practitioners should be...
- Q23. Aphrodite is a member of (ISC)² and a data analyst for Triffid Corporation. While Aphrodit...
- Q24. Which layer of OSI the Firewall works
- Q25. Raj wants aphysical deterrent controlto discourage unauthorized entry. Which option best s...
- Q26. What is the purpose of the CIA triad terms
- Q27. If a device is found that is not compliant with the security baseline, what will be the se...
- Q28. Hoshi is an (ISC)² member who works for the Triffid Corporation as a data manager. Triffid...
- Q29. Selvaa presents a user ID and password to log on. Which characteristic must the user ID ha...
- Q30. Government can imposes financial penalties as a consequence of breaking a...
- Q31. Exhibit. (Exhibit) What is the purpose of a Security Information and Event Management (SIE...
- Q32. How often should an organization test its BCP?...
- Q33. When responding to a security incident, your team determines that the vulnerability that w...
- Q34. A security event does not affect confidentiality, integrity, or availability. What is it?...
- Q35. An ISC2 member is offered an illicit copy of a movie. What should they do?...
- Q36. A logical group of workstations, servers, and network devices that appear to be on the sam...
- Q37. A one-way spinning door or barrier that allows only one person at a time to enter a buildi...
- Q38. The last phase in the data security cycle is
- Q39. Which works by encapsulating one packet inside another?...
- Q40. Which of the following is unlikely to be a member of the disaster recovery team?...
- Q41. The prevention of authorized access to resources or the delaying of time-critical operatio...
- Q42. A hacker gains unauthorized access and steals confidential data. What term best describes ...
- Q43. What is an IPSec replay attack?
- Q44. Is defined as the process of identifying, estimating, and prioritizing risks....
- Q45. Which of the following best describes a zero-day vulnerability?...
- Q46. What is the potential impact of an IPSec reply attack...
- Q47. Which of the following is NOT one of the three main components of a sql database?...
- Q48. What is the main challenge in achieving non-repudiation in electronic transactions?...
- Q49. In which access control model can the creator of an object delegate permissions?...
- Q50. Why is identifying roles and responsibilities important in IR planning?...
- Q51. Which type of attack takes advantage of vulnerabilities in validation?...
- Q52. Which plan is activated when Incident Response and BCP fail?...
- Q53. Which of the following cloud service models provides the most suitable environment for cus...
- Q54. Of the following, which would probably not be considered a threat?...
- Q55. What is the primary goal of implementing input validation in application security?...
- Q56. Which is a component of a Business Continuity (BC) plan?...
- Q57. An employee launched a privilege escalation attack to gain root access on one of the organ...
- Q58. A structured way to align IT with business goals while managing risk and regulations:...
- Q59. Which term describes a communication tunnel that provides point-to-point transmission of b...
- Q60. A power outage disrupts operations. Which plan helps sustain operations?...
- Q61. A security event, or combination of security events, that constitutes a secu incident in w...
- Q62. What principle states that individuals should only have the minimum set of permissions nec...
- Q63. An IP network protocol standardized by the Internet Engineering Task Force (IETF) through ...
- Q64. What is the process of verifying a users identity called?...
- Q65. An external entity has tried to gain access to your organization's IT environment without ...
- Q66. Preenka works at an airport. There are red lines painted on the ground next to the runway;...
- Q67. Which is strongly used for Securing Wi-Fi
- Q68. What is the primary goal of a risk management process in cybersecurity?...
- Q69. What cybersecurity principle focuses on granting users only the privileges necessary to pe...
- Q70. In information systems terms, the activities necessary to restore IT and communications se...
- Q71. Uses multiple types of access controls in literal or theoretical layers to help an organiz...
- Q72. Which type of authentication issomething which you know?...
- Q73. The concept that the deployment of multiple types of controls provides better security tha...
- Q74. Jengi is setting up security for a home network. Jengi decides to configure MAC address fi...
- Q75. A transaction over $50,000 requires approval from both a manager and an accountant. Which ...
- Q76. What is the most important aspect of security awareness/training?...
- Q77. WF attack in which a subscriber currently authenticated to an Server and connected through...
- Q78. When operating in a cloud environment, which cloud deployment model provides security team...
- Q79. What is the goal of an incident response effort?...
- Q80. What is the benefit of subnetting?
- Q81. What is meant by non-repudiation?
- Q82. The section of the IT environment that is closest to the external world; where we locate I...
- Q83. The city of Grampon wants to ensure that all of its citizens are protected from malware, s...
- Q84. Communication between end systems is encrypted using a key, often known as________?...
- Q85. The Bell and LaPadula access control model is a form of...
- Q86. organization experiences a security event that potentially jeopardizes the confidentiality...
- Q87. Exhibit. (Exhibit) How many keys would be required to support 50 users in an asymmetric cr...
- Q88. What is multi-factor authentication (MFA)?
- Q89. What is the purpose of the CIA triad?
- Q90. What is the purpose of immediate response procedures in a BCP?...
- Q91. Which is strongly used for securing Wi-Fi?
- Q92. A set of rules that everyone must comply with and that usually carry monetary penalties fo...
- Q93. Cyril wants to ensure all the devices on his company's internal IT environment are properl...
- Q94. Which of the following is NOT a feature of a cryptographic hash function?...
- Q95. A means to allow remote users to have secure access to the internal IT environment....
- Q96. Which of the following is not an appropriate control to add to privileged accounts?...
- Q97. A set of security controls or system settings used to ensure uniformity of configuration t...
- Q98. What security feature used in HTTPS
- Q99. Mark works in the security office. During research, Mark learns that a configuration chang...
- Q100. A security event in which an intruder gains or attempts unauthorized access to a system is...
- Q101. The amount of risk, at a broad level, that an organization is willing to accept in pursuit...
- Q102. Which of the following properties is NOT guaranteed by digital signatures?...
- Q103. Which of the following is not a typical benefit of cloud computing services?...
- Q104. John is concerned about a possible conflict of interest from a consulting side job. Which ...
- Q105. What is the purpose of immediate response procedures and checklists in a BCP...
- Q106. An integrated platform and graphical tool for security testing of web applications is:...
- Q107. A company experiences a major IT outage and cannot perform critical business functions. Wh...
- Q108. Dani is an ISC2 member and an employee of New Corporation. One of Dani's colleagues offers...
- Q109. What are registered port used for
- Q110. Which of the following statements is true?
- Q111. Which type of application can intercept sensitive information such as passwords on a netwo...
- Q112. Which of the following is a common security measure to prevent Cross Site Scripting (XSS) ...
- Q113. Which common cloud service model only offers the customer access to a given application?...
- Q114. What is the range of well-known ports?
- Q115. The process of how an organization is managed and how decisions are made is called:...
- Q116. Example of a deterrent control:
- Q117. What is the difference between Business Continuity Planning (BCP) and Disaster Recovery Pl...
- Q118. Which of the following is an endpoint?
- Q119. Example of dynamic authorization:
- Q120. Larry and Fern both work in the data center. In order to enter the data center to begin th...
- Q121. XenServer, LVM, Hyper-V, and ESXi are:
- Q122. The prevention of authorized access to resources or the delaying of time-critical operatio...
- Q123. provide integrity services that allow a recipient to verify that a message has not been al...
- Q124. What is the primary purpose of a honeytoken in cybersecurity?...
- Q125. Which allows extremely granular restrictions down to individual machines or users?...
- Q126. Which of these tools is commonly used to crack passwords?...
- Q127. An organization must always be prepared to ______ when applying a patch....
- Q128. What does Criticality represents?
- Q129. Why is security training important?
- Q130. Who should participate in creating a BCP?
- Q131. A Company IT system experienced a system crash that result in a loss of data. What term be...
- Q132. The means by which a threat actor carries out their objectives....
- Q133. Walmart has large ecommerce presence in world. Which of these solutions would ensure the L...
- Q134. Which OSI layer VPN works
- Q135. Dieter wants to send a message to Lupa and wants to be sure that Lupa knows the message ha...
- Q136. Which is the loopback address?
- Q137. What is privacy in the context of Information Security?...
- Q138. Which document serves as specifications for implementing policy and dictates mandatory req...
- Q139. An outward-facing IP address used to access the Internet....
- Q140. A company wants to ensure that its employees can evacuate the building in case of an emerg...
- Q141. Type of cyber attack carried out over a LAN that involves sending malicious packets to a d...
- Q142. Four main components of Incident Response are:...
- Q143. What is the purpose of defense in depth?
- Q144. Security needs to be provided to ____ data.
- Q145. Port used by DNS.
- Q146. A prolonged, targeted cyberattack where an intruder remains undetected for an extended per...
- Q147. A tool that aggregates log data from multiple sources, and typically analyzes it and repor...
- Q148. Natalia is concerned that users on her network may be storing sensitive information, such ...
- Q149. Modern solutions try to provide a more holistic approach detecting rootkits, ransomware an...
- Q150. Which prevents threats?
- Q151. Which of the following is not a protocol of the OSI layer 3...
- Q152. Ludwig is a security analyst at Triffid, Inc. Ludwig notices network traffic that might in...
- Q153. Who should participate in creation a business continuity plan...
- Q154. Which document serve as specifications for the implementation of policy and dictates manda...
- Q155. How often should an organization test its business continuity plan...
- Q156. A DLP solution should be deployed so it can inspect all forms of data leaving the organiza...
- Q157. Malicious code that acts like a remotely controlled "robot" for an attacker, with other Tr...
- Q158. What is multi-factor authentication (MFA)?
- Q159. Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access...
- Q160. The mitigation of violations of security policies and recommended practices is known as:...
- Q161. What does a breach refer to in the context of cybersecurity?...
- Q162. Ignoring a risk and continuing business operations is known as:...
- Q163. Which of the following is very likely to be used in a disaster recovery (DR) effort?...
- Q164. Organization experiences a security event that does not affect the confidentiality integri...
- Q165. Bluga works for Triffid, Inc. as a security analyst. Bluga wants to send a message to seve...
- Q166. In order for a biometric security to function properly, an authorized person's physiologic...
- Q167. What is the primary goal of input validation?
- Q168. Which principle states that users should have access only to the specific data and resourc...
- Q169. _______ are virtual separations within a switch used mainly to limit broadcast traffic....
- Q170. DNS operates at which OSI layer?
- Q171. You experienced a power outage that disrupted access to your data center. What type of sec...
- Q172. Which control identifies that an attack has occurred or is occurring?...
- Q173. What is the goal of Business Continuity efforts?...
- Q174. What does internal consistency of information refer to?...
- Q175. A tool used to inspect outbound traffic to reduce threats...
- Q176. "Wiring _____" is a common term meaning "a place where wires/conduits are often run, and e...
- Q177. Which of the following protocols is a secure alternative to using Telnet?...
- Q178. Actions, processes and tools for ensuring an organization can continue critical operations...
- Q179. What is the recommended temperature range for optimal data center uptime?...
- Q180. Which type of software testing focuses on examining the source code for vulnerabilities an...
- Q181. Actions, processes, and tools ensuring continuity of critical operations:...
- Q182. A measure of the degree to which an organization depends on the information or information...
- Q183. The testing or evaluation of security controls to determine the extent to which the contro...
- Q184. Which of the following is often associated with DR planning?...
- Q185. A scam where a malicious website is made to look exactly like a trusted site is called:...
- Q186. A collection of actions that must be followed in order to complete a task or process in ac...
- Q187. Finance Server and Transactions Server has restored its original facility after a disaster...
- Q188. A________creates an encrypted tunnel to protect your personal data and communications...
- Q189. The prevention of authorized access to resources or delaying time-critical operations is k...
- Q190. Which type of database combines related records and fields into a logical tree structure?...
- Q191. Governments can impose financial penalties as a consequence of breaking a:...
- Q192. Network traffic originating from outside the organization might be admitted to the interna...
- Q193. Which drives for the IPv6 introduction
- Q194. IDS can be described in terms of what fundamental functional components?...
- Q195. 255.255.255.0 represents:
- Q196. Triffid Corporation has a rule that all employees working with sensitive hardcopy document...
- Q197. Permitting authorized access while preventing improper disclosure....
- Q198. What is the difference between hub and switch
- Q199. Gary is an attacker. Gary is able to get access to the communication wire between Dauphine...
- Q200. A measure of an organization's baseline security performance is a:...
- Q201. Exhibit. (Exhibit) What is the purpose of a Security Information and Event Management (SIE...
- Q202. An authorized simulated attack to evaluate security is called:...
- Q203. Which of the following uses registered port
- Q204. Devid is worried about distributed denial of service attacks against his company's primary...
- Q205. Glen is an (ISC)² member. Glen receives an email from a company offering a set of answers ...
- Q206. Which of the following best describes the puposes of a business impact analysis?...
- Q207. Exhibit. (Exhibit) What is the PRIMARY purpose of a web application firewall (WAF)?...
- Q208. A security practitioner who needs step-by-step instructions to complete a provisioning tas...
- Q209. Phrenal is selling a used laptop in an online auction. Phrenal has estimated the value of ...
- Q210. What is the priority of incident response in the context of incident management...
- Q211. What is the primary goal of network segmentation in cybersecurity?...
- Q212. An attack in which an attacker listens passively to the authentication protocol to capture...
- Q213. Which component of the incident response plan involves identifying critical data and syste...
- Q214. What is the recommended fire suppression system for server rooms...
- Q215. True or False: The IT department is responsible for creating the organization's Business C...
- Q216. Which of the following is an example of a "something you are" authentication factor?...
- Q217. A structured approach used to oversee and manage risk for an enterprise...
- Q218. Which type of Intrusion Detection Systems (IDS) and Intrusion Prevention System (IPS) are ...
- Q219. Mark has purchased a Mac laptop. He is scared of losing his screen and is planning to buy ...
- Q220. Dylan is creating a cloud architecture that requires connections between systems in two di...
- Q221. Configuration settings or parameters stored as data and managed through a software graphic...
- Q222. A scammer will attempt to make a malicious website look exactly like a legitimate one that...
- Q223. Which attack attempts to gain information by observing a device's power consumption?...
- Q224. Provides confidentiality by hiding or obscuring a message so that it cannot be understood ...
- Q225. If two people want to use asymmetric communication to conduct a confidential conversation,...
- Q226. Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or del...
- Q227. Which type of network is set up similar to the internet but is private to an organization?...
- Q228. Risk tolerance is also known as:
- Q229. Which attack most effectively maintains remote access and control over a victim's computer...
- Q230. Which type of control is used to restore systems or processes to their normal state after ...
- Q231. An outward-facing IP address used to access the Internet is a:...
- Q232. An attacker places themselves between two communicating devices is known as:...
- Q233. What is the best practice to clear SSD storage after use?...
- Q234. What type of attack does the attacker store and reuse login information. Select the BEST a...
- Q235. Also known as a virtual machine monitor or VMM, is software that creates and runs virtual ...
- Q236. The means by which a threat actor carries out their objectives...
- Q237. Why is a "Red Book" important in Business Continuity Planning?...
- Q238. Which type of fire-suppression system is typically the safest for humans?...
- Q239. The DevOps team has updated the application source code. Tom discovered that many unauthor...
- Q240. Which is the first step in the risk management process?...
- Q241. How do you distinguish authentication and identification?...
- Q242. What is the benefit of subnet
- Q243. A newly enforced BYOD policy represents which control type?...
- Q244. A collection of actions that must be followed to complete a task or process in accordance ...
- Q245. An attack in which an attacker listens passively to the authentication protocol to capture...
- Q246. Proper alignment of security policy and business goals within the organization is importan...
- Q247. Which of the following is a characteristic of cloud computing?...
- Q248. The first phase of the System Development Life Cycle (SDLC) is:...
- Q249. Tekila works for a government agency. All data in the agency is assigned a particular sens...
- Q250. Security control used to protect against environmental threats such as fire, flood and ear...
- Q251. An approach using software-based controllers and APIs to direct network traffic:...
- Q252. Triffid, Inc., has many remote workers who use their own IT devices to process Triffid's i...
- Q253. What type of attack does the attacker store and reuse login information? Select the BEST a...
- Q254. What is remanence?
- Q255. You are reviewing log data from a router; there is an entry that shows a user sent traffic...
- Q256. Derrick logs on to a system in order to read a file. In this example, Derrick is the _____...
- Q257. Which of these components is very likely to be instrumental to any disaster recovery (DR) ...
- Q258. A DDoS attack flooding ICMP packets is called:...
- Q259. Security commensurate with risk and magnitude of harm is known as:...
- Q260. An employee launched a privilege escalation attack to gain root access on one of the organ...
- Q261. A prolonged and targeted cyberattack in which an intruder gains access to a network and re...
- Q262. Who must follow HIPAA compliance?
- Q263. Which security control is designed to prevent unauthorized access to sensitive information...
- Q264. A/hich layer of the OSI Layer model is the target of a buffer overflow attack...
- Q265. Which type of control minimizes the impact of an attack and restores normal operations as ...
- Q266. What is the shortened form of 2001:0db8:0000:0000:0000:ffff:0000:0001?...
- Q267. Which security control mostly used to prevent data breach...
- Q268. The practice of ensuring that an organizational process cannot be completed by a single pe...
- Q269. Which zero-trust component breaks LANs into very small, localized security zones?...
- Q270. A company security team detected a cyber attack against it information systems and activat...
- Q271. Finance Server and Transaction Server have restored their original facility after a disast...
- Q272. Business continuity planning is a reactive procedure that restores business operations aft...
- Q273. What does Personally Identifiable Information (Pll) pertain to?...
- Q274. What is meant by non-repudiation?
- Q275. Load balancing primarily safeguards which CIA triad element?...
- Q276. When is the Business Continuity Plan Enacted?
- Q277. What is the focus of disaster recovery planning after a data center outage?...
- Q278. A VLAN is a _____ method of segmenting networks....
- Q279. Why is an asset inventory so important?
- Q280. The practice of sending fraudulent communications that appear to come from a reputable sou...
- Q281. Which of the following is a characteristic of cloud...
- Q282. In what way do a victim's files get affected by ransomware?...
- Q283. An attacker outside the organization attempts to gain access to the organization's interna...
- Q284. What is the end goal of DRP
- Q285. A company network has been infected with malware and all its servers are down. What is the...
- Q286. An unusual occurrence in a system or network is best described as:...
- Q287. Trina is a security practitioner at Triffid, Inc. Trina has been tasked with selecting a n...
- Q288. IDS can be described in terms of what fundamental functional components?...
- Q289. Example of Type 1 authentication:
- Q290. Which of the following attacks can TLS help mitigate?...
- Q291. Which penetration testing technique requires the team to do the MOST work and effort?...
- Q292. 6 Which access control method uses attributes and rules to define access policies that are...
- Q293. Which type of encryption uses only one shared key to encrypt and decrypt?...
- Q294. In which of the following phases of an incident recovery plan the incident responses prior...
- Q295. Requires that all instances of the data be identical in form,...
- Q296. A company needs to protect its confidential data from unauthorized access which logical co...
- Q297. What is the highest priority during incident response?...
- Q298. Which threat is directly associated with malware?...
- Q299. Which is the Not the component of a Business Continuity (BC) plan...
- Q300. What federal law requires the use of vulnerability scanning on information systems operate...
- Q301. What is the most important goal of a business continuity effort?...
- Q302. The Triffid Corporation publishes a policy that states all personnel will act in a manner ...
- Q303. What is the purpose of defense in depth in information security...
- Q304. What is the primary purpose of a firewall?
- Q305. A set of instructions to detect, respond to, and recover from security incidents is a:...
- Q306. A previously unknown vulnerability with no public listing is called:...
- Q307. An employee unintentionally shares confidential information with an unauthorized party. Wh...
- Q308. Using Mandatory Access Control (MAC), we would use clearance for assigning which of these?...
- Q309. Which security control is most commonly used to prevent data breaches?...
- Q310. Which of the following is likely to be included in the business continuity plan?...
- Q311. What does the term "Two-factor authentication" refer to in cybersecurity?...
- Q312. What does the termbusinessin business continuity planning refer to?...
- Q313. Faking the sender address in a transmission to gain illegal entry into a secure system...
- Q314. A company wants employees to access resources from anywhere in the world. Which access con...
- Q315. A large organization is planning to create a DRP. Which of the following is the BEST docum...
- Q316. Firewalls operate at which OSI layers?
- Q317. A DDoS attack affects which OSI layers?
- Q318. Scans networks to determine everything that is connected as well as other information....
- Q319. The harmonization of automated computing tasks, providing a consolidated and reusable work...
- Q320. Mark has purchased a MAC LAPTOP. He is scared of losing his screen and planning to buy an ...
- Q321. What is a security token used to authenticate a user to a web application, typically after...
- Q322. Which layer provides the services to user?
- Q323. Uses multiple types of access controls in layered fashion to avoid monolithic security:...
- Q324. System capabilities designed to detect and prevent the unauthorized use and transmission o...
- Q325. Which of the following physical controls is used to protect against eavesdropping and data...
- Q326. When an attacker is using a brute force attack to break a password, what are they doing? R...
- Q327. Olaf is a member of (ISC)² and a security analyst for Triffid Corporation. During an audit...
- Q328. Which is related to Standard
- Q329. Exhibit. (Exhibit) IPSec works in which layer of OSI Model...
- Q330. For which of the following systems would the security concept of availability probably be ...
- Q331. Shaun is planning to protect data in all states (at rest, in motion, and in use), defendin...
- Q332. What is the access control model being implemented in Tekila's agency?...
- Q333. What is the range of private (dynamic/ephemeral) ports?...
- Q334. What is the potential impact of an IPSec replay attack?...
- Q335. Exhibit. (Exhibit) What kind of vulnerability is typically not identifiable through a stan...
- Q336. An analysis of system requirements and interdependencies used to prioritize recovery is kn...
- Q337. What is the primary goal of an incident management team?...
- Q338. System capabilities designed to detect and prevent unauthorized use and transmission of in...
- Q339. One of the benefits of computer-based training (CBT):...
- Q340. The primary functionality of Privileged Access Management (PAM) is:...
- Q341. The right of an individual to control the distribution of information about themselves is:...
- Q342. Devid's team recently implemented a new system that gathers information from a variety of ...
- Q343. In the context of cybersecurity, typical threat actors include the following:...
