ISC2 Certified in Cybersecurity (CC) practice questions
214 free questions with answers and explanations.
- 101.A security architect is designing a system where access permissions are granted or denied based on a dynamic set of conditions, including the user's department, the time of day, the sensitivity of the data being accessed, and the location from which the access request originates. Which access control model would be most appropriate for this complex, context-aware requirement?Access Controls Concepts
- 102.A financial institution is implementing a new system for managing customer loan applications. To prevent any single individual from having complete control over a loan approval, the process is designed such that one employee initiates the application, another reviews the credit score, and a third employee provides final approval. This practice is a core principle in access control. What is this principle called?Access Controls Concepts
- 103.A government agency is updating its security protocols for accessing classified information. Their new policy states that all employees must only be granted access to the absolute minimum information and resources required to perform their specific job functions. Any access beyond this is strictly prohibited. Which access control principle is being enforced here?Access Controls Concepts
- 104.A large enterprise is struggling with managing user identities and their corresponding access rights across hundreds of disparate applications and systems. Employees frequently experience delays in getting necessary access, and auditors find inconsistencies in permissions. Which solution would best address these challenges by centralizing identity management and automating access provisioning and deprovisioning?Access Controls Concepts
- 105.An organization implemented a security policy where users are only granted the minimum level of access necessary to perform their job functions. This prevents employees from accessing data or systems beyond their specific duties. Which access control principle is being applied?Access Controls Concepts
- 106.A healthcare organization is implementing a new electronic health record (EHR) system. They need to ensure that patient data is protected according to strict regulatory requirements, meaning that access decisions are based on the sensitivity of the data and the clearance level of the user, rather than user discretion. Which access control model best fits this requirement?Access Controls Concepts
- 107.A security policy dictates that all high-security data centers must have a mantrap at their entrance. This mantrap requires an individual to pass through an outer door, be verified, and then pass through an inner door, ensuring only one person enters at a time. What type of access control is a mantrap primarily an example of?Access Controls Concepts
- 108.A new cybersecurity initiative mandates that all employees must use a unique identifier to claim their digital identity before presenting credentials. What access control concept does this requirement primarily address?Access Controls Concepts
- 109.A security analyst is investigating a potential insider threat where an employee is suspected of accessing sensitive project files unrelated to their current role. The company's access control system logs every attempt to access files, successful or not, along with the user's identity and timestamp. Which access control concept is most crucial for identifying and investigating this activity?Access Controls Concepts
- 110.An organization is migrating its on-premises applications to a cloud environment. They want a solution that allows employees to use a single set of credentials to access all authorized cloud services and internal applications without re-entering their username and password multiple times. This approach aims to improve user experience and reduce password fatigue. What is the most appropriate access control technology for this requirement?Access Controls Concepts
- 111.A large university campus is installing a new system to control access to various buildings, including dormitories, academic halls, and research labs. They need a system that can manage access for thousands of students, faculty, and staff, with different access levels based on their roles and specific course enrollments or lab projects. The system must also integrate with existing HR and student information systems to automatically update access rights. Which overarching access control framework is most suitable for managing identities and their access across such a diverse and dynamic environment?Access Controls Concepts
- 112.A security team is conducting an audit of user permissions for a critical financial application. They need to regularly verify that all users still have the appropriate level of access, particularly for those whose roles have changed or who have been inactive. This ensures that access rights align with current business needs and security policies. What is this recurring process called?Access Controls Concepts
- 113.A critical server room's access log shows an entry at 2:30 AM indicating 'Door Forced Open' followed immediately by 'Motion Detected Inside Room'. The security team reviews surveillance footage but finds no physical evidence of forced entry and no individuals captured on camera entering the room. This discrepancy suggests a potential issue with the physical security system's integration or configuration. What is the most likely cause of this discrepancy?Access Controls Concepts
- 114.A new employee, Jane, needs access to specific HR documents and the company's internal wiki. Her manager submits a request detailing the resources she needs. Which phase of the access control lifecycle is being performed when Jane is granted these specific permissions?Access Controls Concepts
- 115.A government agency is implementing an access control system for classified documents. The system must ensure that a user with a 'Secret' clearance can read documents classified as 'Secret' or 'Confidential', but cannot read 'Top Secret' documents. Conversely, a user with 'Top Secret' clearance can read all documents. Users cannot downgrade a document's classification or grant themselves higher access. Which access control model does this scenario best represent?Access Controls Concepts
- 116.A manufacturing plant uses key cards to grant entry to various production areas. The security manager notices an increase in incidents where unauthorized personnel gain access by using lost or stolen key cards, even though surveillance footage shows the card being used by an individual who is clearly not the cardholder. Which of the following is the most effective administrative control to mitigate this specific vulnerability?Access Controls Concepts
- 117.A company requires employees to log into their work accounts using a password and a fingerprint scan. Which of the following best describes the authentication method being used?Access Controls Concepts
- 118.A financial institution requires that all employees involved in processing customer transactions must have their actions logged and attributable to their individual user account. This ensures that in case of an error or fraudulent activity, the responsible party can be identified. Which access control principle is being emphasized here?Access Controls Concepts
- 119.A security auditor is reviewing the effectiveness of an organization's access control system. The auditor discovers that several former employees still have active accounts with full access privileges to critical systems. Which access control concept has been most clearly violated in this scenario?Access Controls Concepts
- 120.A healthcare provider is decommissioning an old server that stored millions of patient records. Due to strict HIPAA regulations, they must ensure that all data on the server is permanently unrecoverable before the server leaves their premises. Which security operation dictates the specific methods and procedures required to achieve this goal?Security Operations
- 121.A critical infrastructure organization operates a Supervisory Control and Data Acquisition (SCADA) system that controls essential services. Due to the high impact of any disruption, they require continuous, real-time analysis of network traffic, system logs, and security events from their industrial control systems (ICS) to detect anomalies and potential threats immediately. Which security operation is designed to provide this continuous, real-time threat detection capability?Security Operations
- 122.A financial institution is under strict regulatory requirements to prove that only authorized personnel have accessed sensitive customer financial records. They need a system that can collect, centralize, and analyze security-relevant data from various sources across their IT infrastructure to provide an auditable trail of access events. Which security operation is best suited to provide this capability?Security Operations
- 123.A small medical clinic is implementing a new electronic health record (EHR) system. They need to ensure that patient data, which is highly sensitive, is protected from unauthorized access during all stages of its lifecycle, from creation to destruction. Which security operation is primarily concerned with defining and enforcing policies for how this sensitive data is handled?Security Operations
- 124.A forensic investigator is examining a compromised server. They need to collect volatile data first to ensure no critical evidence is lost before the system is powered down for a full disk image. Which of the following data types would the investigator prioritize collecting immediately?Security Operations
- 125.A security analyst is reviewing network traffic logs and notices an unusual number of failed login attempts to a critical server from an external IP address. This activity occurs outside of business hours and is not associated with any known legitimate remote access. Which of the following security monitoring activities is being performed?Security Operations
- 126.A security analyst is investigating a potential data breach. They need to determine who accessed a critical server, when they accessed it, and what actions they performed. The analyst realizes that detailed records of system events, user activities, and network connections are crucial for this investigation. Which security operations practice is essential for providing this information?Security Operations
- 127.A small business is reviewing its security posture and wants to proactively identify weaknesses in its applications and network infrastructure before malicious actors can exploit them. They are looking for an automated, non-invasive method to achieve this. Which of the following security operations activities would best meet their requirements?Security Operations
- 128.A security operations center (SOC) analyst is reviewing log data from various network devices. They notice a specific sequence of events: an external IP address attempts to connect to a web server, followed by an unsuccessful login attempt, then a port scan of other internal systems, and finally, a successful connection to a different internal server. The analyst correlates these events across multiple log sources to identify the full attack chain. This process is best described as an aspect of:Security Operations
- 129.A multinational corporation is expanding its operations into a new region. Before deploying new IT infrastructure, they must ensure that the environmental conditions of the new data center, such as temperature, humidity, and fire suppression systems, meet strict operational and security standards. Which security operations domain element is primarily concerned with these requirements?Security Operations
- 130.An organization is migrating its data to a new cloud service provider. During this transition, they must ensure that all data transferred and stored in the cloud is encrypted both in transit and at rest, and that access to this data is strictly controlled and logged. This is part of a broader effort to protect information throughout its lifecycle. Which security operations function is most directly concerned with these aspects?Security Operations
- 131.A global technology company is expanding its operations and introducing new cloud services and IoT devices into its network. The security team needs to ensure that these new components are integrated without introducing new vulnerabilities. Which security operations activity focuses on applying security updates and fixes to software and systems to mitigate known weaknesses?Security Operations
- 132.A security analyst is investigating a suspected insider threat. They need to review the activities of an employee who recently resigned under suspicious circumstances. The investigation requires looking at all network access attempts, file modifications, and email communications from the past six months. Which security operations concept would be MOST crucial for gathering this historical data?Security Operations
- 133.A government contractor is preparing for an audit of its information systems. The audit requires demonstrating that all production systems consistently adhere to a predefined security baseline, including specific operating system settings, installed software versions, and network configurations. Which security operation directly supports proving this consistent adherence?Security Operations
- 134.A government agency is procuring new IT equipment. Before any new server or workstation is deployed into the production environment, it must undergo a rigorous process to ensure it meets specific security baselines, including operating system hardening, required software installations, and disabled unnecessary services. Which security operations activity is responsible for establishing and maintaining these standards?Security Operations
- 135.A cybersecurity incident response team is investigating a sophisticated attack where an attacker has maintained a persistent presence within the network for several weeks. To effectively contain the threat and prevent future occurrences, the team needs to understand the attacker's tactics, techniques, and procedures (TTPs) and identify indicators of compromise (IOCs) across various systems. Which security operations capability is crucial for correlating events and detecting these advanced persistent threats?Security Operations
- 136.A legacy application running on an outdated operating system is critical for business operations but cannot be patched or upgraded due to compatibility issues and vendor support limitations. A recent vulnerability scan has identified several high-severity vulnerabilities on this system. To mitigate the risk, the security team decides to isolate the application within a dedicated network segment, implement strict firewall rules allowing only necessary traffic, and deploy an intrusion detection system (IDS) to monitor for suspicious activity specifically targeting this segment. This strategy is an example of which security control concept?Security Operations
- 137.A security manager is designing a new onboarding process for all employees, including contractors and temporary staff. A key requirement is to ensure that all new personnel understand their security responsibilities, acceptable use policies, and the proper handling of sensitive information from day one. Which security operations activity is fundamental to achieving this goal?Security Operations
- 138.An organization is deploying a new web application that will process sensitive customer payment information. Before going live, the security team wants to identify and remediate any potential weaknesses in the application's code and infrastructure that could be exploited by an attacker. They decide to use automated tools to methodically check the system against known vulnerabilities. Which security operation are they performing?Security Operations
- 139.A national retail chain is expanding its online presence and now accepts credit card payments directly through its website. To comply with PCI DSS (Payment Card Industry Data Security Standard) requirements, they must regularly test their systems by attempting to exploit vulnerabilities to determine if security controls are effective and to identify any potential entry points for attackers. Which security operation is mandated by PCI DSS for this purpose?Security Operations
- 140.A software development team is adopting a DevOps methodology and needs to ensure that all changes to code, configurations, and infrastructure are tracked, approved, and auditable. This is crucial for maintaining system stability and security. Which security operations activity directly addresses this requirement?Security Operations
- 141.A global financial institution is redesigning its incident response plan. A key objective is to ensure that all security incidents, regardless of their origin or severity, are handled consistently and documented thoroughly. Which security operations concept is fundamental to achieving this consistency and detailed record-keeping?Security Operations
- 142.A software development company is experiencing a high turnover rate among its developers. The security team is concerned about the potential for former employees to retain access to sensitive source code repositories and development environments. Which security operation should be prioritized to mitigate this specific risk efficiently?Security Operations
- 143.A security team is conducting a comprehensive evaluation of an organization's cloud infrastructure to identify misconfigurations, weak access controls, and potential vulnerabilities from an attacker's perspective. The goal is to simulate real-world attacks to uncover exploitable flaws. Which security assessment technique are they employing?Security Operations
- 144.A company has identified a critical vulnerability in its widely used web server software. A patch has been released by the vendor. Before deploying the patch to production, the IT team tests it in a staging environment to ensure it does not introduce new issues or break existing functionalities. This process is a key step within which security operation activity?Security Operations
- 145.A company policy mandates that all customer data must be securely deleted from all storage media, including backups, within 30 days after the customer terminates their service. For hard drives, this involves degaussing or physical destruction. For cloud-based storage, it involves verified cryptographic erasure. This policy directly addresses which aspect of data handling?Security Operations
- 146.An organization is implementing a new BYOD (Bring Your Own Device) policy. To ensure that sensitive company data accessed on personal devices remains protected even if the device is lost or stolen, they need a mechanism to remotely erase corporate data without affecting personal data. Which data handling practice is most relevant here?Security Operations
- 147.A new employee is being onboarded at an organization. As part of their initial training, they are required to complete an interactive online module that covers topics such as phishing awareness, password best practices, and the company's data handling policies. This module concludes with a short quiz to ensure understanding. This activity is a core component of which security operation?Security Operations
- 148.An organization is preparing for a security audit. As part of this preparation, they are compiling documentation of their security policies, incident response plans, and records of past security assessments. The auditor will review these documents to determine if the organization's security posture aligns with established standards and regulations. What is the primary objective of this security audit?Security Operations
- 149.A global e-commerce company experiences a power outage at one of its primary data centers due to a severe thunderstorm. The uninterruptible power supplies (UPS) provided temporary power, but the outage extended beyond their capacity. Which environmental control failed to adequately protect the data center's operations in this scenario?Security Operations
- 150.An organization is implementing a new bring your own device (BYOD) policy. To mitigate the risk of corporate data residing on personal devices, the security team mandates that all BYOD devices capable of accessing company resources must be enrolled in a Mobile Device Management (MDM) solution. Which security operation is being primarily addressed by this MDM requirement?Security Operations