ISC2 Certified in Cybersecurity (CC) practice questions

214 free questions with answers and explanations.

Practice test
  1. 51.A small business is setting up its first public-facing web server. To protect its internal network from direct attacks while still allowing external users to access the web server, which network security zone should the web server be placed in?Network Security
  2. 52.A global technology company is developing a new social media platform. They are particularly concerned about adhering to the General Data Protection Regulation (GDPR) and other international privacy laws. To proactively address these concerns, they decide to embed privacy considerations into the platform's architecture and development process from the very beginning. This approach is best described as:Security Principles
  3. 53.A retail company experiences a data breach where customer credit card information is stolen. Under specific regulations like PCI DSS, they are mandated to notify affected customers, regulatory bodies, and payment card brands within a defined timeframe. This obligation falls under which aspect of security management?Security Principles
  4. 54.A security team is evaluating potential threats to a new cloud-based customer database. They identify a scenario where a disgruntled former employee, who still retains some old system credentials, could attempt to access and delete customer records. This scenario represents a specific type of risk component. Which component is being described?Security Principles
  5. 55.A security team is deploying a new web application that will handle sensitive customer data. They need to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is verified. Which protocol combination should be implemented?Network Security
  6. 56.A multinational corporation is considering processing sensitive customer data in a cloud environment. Before migrating any data, the legal department conducts a thorough review of the cloud provider's data handling practices, security controls, and contractual agreements to ensure they align with the General Data Protection Regulation (GDPR) and other applicable regional data protection laws. What key aspect of security principles is the legal department primarily focusing on?Security Principles
  7. 57.A software developer signs a digitally signed code module before releasing it to production. This signature allows anyone to verify that the code has not been altered since it was signed and confirms the identity of the developer. Which security principle is primarily enforced by this digital signature process?Security Principles
  8. 58.A cybersecurity team is performing a comprehensive assessment of an organization's network infrastructure. They discover that several legacy servers are running outdated operating systems with known vulnerabilities for which no patches are available. Management decides to isolate these servers on a separate, heavily restricted network segment and implement an intrusion detection system (IDS) to monitor all traffic to and from them. Which risk treatment strategy is the organization primarily employing in this scenario?Security Principles
  9. 59.A financial services company processes millions of transactions daily. To ensure that each transaction can be undeniably linked to the specific user who initiated it, preventing them from later denying their actions, which security principle must be enforced?Security Principles
  10. 60.A network administrator is configuring a new switch for a department that handles sensitive customer data. To prevent unauthorized devices from connecting to specific switch ports, the administrator enables a feature that binds specific MAC addresses to individual ports. What security feature is being implemented?Network Security
  11. 61.A company is implementing a new network-based Intrusion Detection System (IDS). To ensure the IDS can monitor all traffic traversing between the internal network and the internet without interfering with the traffic flow, where should the IDS sensor typically be placed?Network Security
  12. 62.A healthcare organization is implementing a new electronic health record (EHR) system. They are particularly concerned about ensuring that patient data remains accurate and unaltered during storage and transmission. Which security principle is this organization primarily focused on maintaining?Security Principles
  13. 63.An organization is conducting a risk assessment for its new cloud-based email system. They identify that a successful phishing attack could lead to a data breach, resulting in regulatory fines and reputational damage. What component of risk is being described by 'regulatory fines and reputational damage'?Security Principles
  14. 64.A company is implementing a new policy that requires all employees to complete a mandatory online course on phishing awareness. What type of security control is this policy primarily categorized as?Security Principles
  15. 65.A network administrator is implementing a new wireless network in a corporate office. The security policy mandates the strongest available encryption and authentication protocols for Wi-Fi. Which Wi-Fi security standard should the administrator configure?Network Security
  16. 66.During a routine security audit, an organization discovers an unpatched server running an outdated operating system directly exposed to the internet. This server hosts non-critical but publicly accessible information. What does the unpatched server represent in the context of risk management?Security Principles
  17. 67.A software development team is adopting a 'shift-left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security testing be MOST emphasized in this approach?Security Principles
  18. 68.A critical infrastructure organization operates a Supervisory Control and Data Acquisition (SCADA) system that manages power distribution. A recent risk assessment identified a severe vulnerability in an outdated component of the SCADA system, which, if exploited, could lead to widespread power outages. The organization has calculated the Single Loss Expectancy (SLE) for a successful attack at $5,000,000 and the Annualized Rate of Occurrence (ARO) as 0.2 (meaning an attack is expected once every five years). What is the Annualized Loss Expectancy (ALE) for this risk?Security Principles
  19. 69.A small e-commerce company is developing a new online payment gateway. To ensure that the payment process is secure and that only authorized transactions occur, they implement a system where each transaction must be approved by two different managers before it is processed. This control aims to prevent a single point of failure or malicious activity by one individual. Which security principle is primarily being addressed by this two-manager approval process?Security Principles
  20. 70.A government agency is updating its data handling procedures to comply with new legislation regarding classified information. The new rules specify that data classified as 'Top Secret' must be stored on systems physically isolated from all other networks and accessed only by personnel with specific clearances in a secured facility. This approach primarily aims to enforce which security principle?Security Principles
  21. 71.A healthcare provider is deploying a new electronic health record (EHR) system. The system must meet HIPAA regulations, which dictate strict rules for protecting patient data. The organization develops a document outlining mandatory actions and prohibitions for employees using the EHR, ensuring compliance and security. What type of security document is this?Security Principles
  22. 72.A small startup company is developing a new mobile application that will collect user location data. The company wants to ensure they minimize the risk of a data breach and comply with future privacy regulations. Which principle should guide their design and development process from the very beginning?Security Principles
  23. 73.A small business is implementing a new customer relationship management (CRM) system. To ensure that only authorized sales personnel can view customer contact details and only managers can approve discounts, which security principle is being primarily addressed?Security Principles
  24. 74.A security analyst is reviewing logs and notices a sudden, unexplained spike in network traffic originating from an internal server to an unknown external IP address. This server typically has minimal outbound traffic. Which phase of the incident response process would this observation typically fall under?Security Principles
  25. 75.A healthcare provider is developing a new mobile application for patients to access their medical records. The application will store sensitive patient health information (PHI). Before launching, the provider must ensure compliance with HIPAA regulations. Which aspect of security is primarily being addressed by focusing on HIPAA compliance?Security Principles
  26. 76.A manufacturing company relies heavily on its industrial control systems (ICS) for production. Any downtime of these systems would result in significant financial losses and potential safety hazards. The company decides to invest in redundant systems, offline backups, and robust physical security for its ICS infrastructure. This approach demonstrates a primary focus on which security principle?Security Principles
  27. 77.A cybersecurity team is concerned about the increasing sophistication of malware that can evade traditional signature-based antivirus solutions. They want to implement a solution that can detect and prevent threats based on suspicious behavior, even if the specific malware signature is unknown. Which technology would best address this requirement?Network Security
  28. 78.A multinational corporation operates in various countries, each with its own data protection laws, such as GDPR in Europe and CCPA in California. The corporation must adapt its data handling practices to meet the specific requirements of each region. Which aspect of security principles is this scenario primarily focused on?Security Principles
  29. 79.A company's email server experiences a major outage, rendering all email services unavailable for 8 hours. The company estimates this outage cost them $5,000 per hour in lost productivity and business. They are considering implementing a redundant email system that costs $30,000. What is the single loss expectancy (SLE) for this email server outage?Security Principles
  30. 80.A company is reviewing its security controls. They have implemented a policy that states all employees must complete mandatory security awareness training annually. This control aims to educate employees about cyber threats and best practices. Which type of security control does this represent?Security Principles
  31. 81.A network engineer is troubleshooting a connectivity issue where a new server cannot reach resources on a different subnet, even though its IP address, subnet mask, and gateway are correctly configured. The server's firewall is temporarily disabled for testing. Other devices on the same subnet can reach the remote resources. What is the MOST likely cause of the problem?Network Security
  32. 82.A global conglomerate is evaluating potential threats to its intellectual property, which includes highly sensitive research and development data. They are particularly concerned about industrial espionage from state-sponsored actors. What term best describes this type of malicious activity aimed at stealing trade secrets?Security Principles
  33. 83.A security analyst is reviewing network traffic logs and observes an unusually high volume of SYN packets originating from various external IP addresses targeting a specific server on the perimeter network, but very few corresponding SYN-ACKs are being sent back. What type of attack is most likely occurring?Network Security
  34. 84.A financial institution is implementing a new system for processing high-value transactions. They want to ensure that if a system failure or data corruption occurs, the system can be restored to a known good state from a recent backup with minimal data loss. The goal is to limit the maximum acceptable period of data loss measured in time. Which metric is the institution primarily concerned with when addressing this requirement?Security Principles
  35. 85.A global manufacturing company uses a complex network of industrial control systems (ICS) and IT systems. Due to the critical nature of their operations, they need an access control model that can dynamically grant or deny access based on a combination of factors such as the user's role, the time of day, the location from which they are accessing, and the sensitivity of the data being requested. Which access control model is best suited for this highly granular and context-aware requirement?Access Controls Concepts
  36. 86.A system administrator is configuring access to a new project folder. They assign permissions to the 'Project_A_Team' group, granting them read and write access, and to the 'Project_A_Managers' group, granting them full control. Individual users are then added to these respective groups to inherit their access rights. Which access control model is being implemented?Access Controls Concepts
  37. 87.A company wants to implement a system where access decisions are based on predefined rules or policies, rather than the discretion of the resource owner. For example, all employees in the 'Finance' department automatically get access to the 'Accounting Software' and 'Budget Reports'. Which access control model best fits this description?Access Controls Concepts
  38. 88.A highly secure research facility requires that all personnel entering sensitive laboratory areas must pass through a mantrap, which is a small room with two interlocking doors. One door must close and lock before the other can open. What type of physical access control is primarily being enforced by this system?Access Controls Concepts
  39. 89.An organization is designing a new access control system for its highly sensitive data. The requirement states that access to specific data objects must be explicitly granted by the owner of that data, and the owner retains full control over who can access their data and what actions they can perform. Which access control model is being described?Access Controls Concepts
  40. 90.An organization is implementing an access control model where a central authority strictly defines and enforces access rules based on security labels assigned to subjects and objects. Users cannot modify these access permissions, even for files they own. Which access control model is being described?Access Controls Concepts
  41. 91.A company is implementing a new physical access control system for its data center. The system requires employees to swipe an access card and then provide a fingerprint scan before entry. What type of authentication is being implemented here?Access Controls Concepts
  42. 92.A user attempts to log into a system. They first enter their username, then their password, and finally, they are prompted to enter a one-time code generated by an app on their smartphone. Which authentication factor category does the smartphone app code represent?Access Controls Concepts
  43. 93.A company is implementing a new security policy that requires all remote employees to use a VPN and then provide a password and a one-time code from a mobile authenticator app to access internal network resources. Which access control concept is being strengthened by combining these authentication methods?Access Controls Concepts
  44. 94.A system administrator implements a new access control model where users are assigned to groups, and permissions are then granted to those groups. For example, all users in the 'Developers' group automatically inherit read, write, and execute permissions on specific code repositories. Which access control model is being utilized?Access Controls Concepts
  45. 95.A large enterprise uses a centralized system that allows users to log in once and gain access to multiple independent software systems without re-authenticating. This streamlines user experience and reduces password fatigue. What is this technology called?Access Controls Concepts
  46. 96.A company is implementing a new payroll system and wants to ensure that no single employee can initiate, approve, and disburse payments. The system is designed so that different individuals are required for each of these distinct steps. Which security principle is being enforced?Access Controls Concepts
  47. 97.A small business is setting up its first network and needs to ensure that only authorized employees can access the company's shared drive. Which of the following access control concepts is primarily concerned with verifying the identity of an individual before granting access?Access Controls Concepts
  48. 98.A system administrator is configuring network access for a new secure segment. The policy states that if a connection attempt does not explicitly match an 'allow' rule, it must be automatically blocked. This ensures that only services and users specifically permitted can establish connections. What access control principle is being applied?Access Controls Concepts
  49. 99.A company is implementing logical access controls for its cloud-based applications. They want to ensure that access rights are automatically adjusted when an employee's job role changes or when they leave the company. This approach aims to reduce the risk of orphaned accounts and unauthorized access. Which of the following IAM components is primarily responsible for managing these lifecycle events?Access Controls Concepts
  50. 100.A system administrator is configuring access permissions for a new project folder. They want to ensure that if no specific rule grants access to a user, that user is automatically denied access. Which access control principle is being applied here?Access Controls Concepts