ISC2 Certified in Cybersecurity (CC) practice questions
214 free questions with answers and explanations.
- 151.A security operations center (SOC) analyst is reviewing log data from various network devices. They notice a specific sequence of events: an external IP address attempts to connect to a web server, followed by an unsuccessful login attempt, then a port scan of other internal systems, and finally, a successful connection to a different internal server. The analyst correlates these events across multiple log sources to identify the full attack chain. This process is best described as an aspect of:Security Operations
- 152.A multinational corporation is expanding its operations into a new region. Before deploying new IT infrastructure, they must ensure that the environmental conditions of the new data center, such as temperature, humidity, and fire suppression systems, meet strict operational and security standards. Which security operations domain element is primarily concerned with these requirements?Security Operations
- 153.An organization is migrating its data to a new cloud service provider. During this transition, they must ensure that all data transferred and stored in the cloud is encrypted both in transit and at rest, and that access to this data is strictly controlled and logged. This is part of a broader effort to protect information throughout its lifecycle. Which security operations function is most directly concerned with these aspects?Security Operations
- 154.A global technology company is expanding its operations and introducing new cloud services and IoT devices into its network. The security team needs to ensure that these new components are integrated without introducing new vulnerabilities. Which security operations activity focuses on applying security updates and fixes to software and systems to mitigate known weaknesses?Security Operations
- 155.A security analyst is investigating a suspected insider threat. They need to review the activities of an employee who recently resigned under suspicious circumstances. The investigation requires looking at all network access attempts, file modifications, and email communications from the past six months. Which security operations concept would be MOST crucial for gathering this historical data?Security Operations
- 156.A government contractor is preparing for an audit of its information systems. The audit requires demonstrating that all production systems consistently adhere to a predefined security baseline, including specific operating system settings, installed software versions, and network configurations. Which security operation directly supports proving this consistent adherence?Security Operations
- 157.A government agency is procuring new IT equipment. Before any new server or workstation is deployed into the production environment, it must undergo a rigorous process to ensure it meets specific security baselines, including operating system hardening, required software installations, and disabled unnecessary services. Which security operations activity is responsible for establishing and maintaining these standards?Security Operations
- 158.A cybersecurity incident response team is investigating a sophisticated attack where an attacker has maintained a persistent presence within the network for several weeks. To effectively contain the threat and prevent future occurrences, the team needs to understand the attacker's tactics, techniques, and procedures (TTPs) and identify indicators of compromise (IOCs) across various systems. Which security operations capability is crucial for correlating events and detecting these advanced persistent threats?Security Operations
- 159.A legacy application running on an outdated operating system is critical for business operations but cannot be patched or upgraded due to compatibility issues and vendor support limitations. A recent vulnerability scan has identified several high-severity vulnerabilities on this system. To mitigate the risk, the security team decides to isolate the application within a dedicated network segment, implement strict firewall rules allowing only necessary traffic, and deploy an intrusion detection system (IDS) to monitor for suspicious activity specifically targeting this segment. This strategy is an example of which security control concept?Security Operations
- 160.A large e-commerce company is designing its disaster recovery plan. They require a secondary site that can be activated within minutes or hours, with all necessary hardware, software, and up-to-date data available immediately. This site must be fully functional and ready to take over operations with minimal disruption. Which type of alternate site best meets these stringent requirements?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 161.After a successful recovery from a major cybersecurity incident, an organization's incident response team holds a meeting to review what happened, what was done well, what could be improved, and to update documentation. Which phase of the incident response process is this activity part of?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 162.A financial institution is implementing a new business continuity plan. As part of this, they are defining the maximum acceptable period of time that a business process can be unavailable before the continuity of the business is severely impacted. What critical metric are they defining?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 163.A small e-commerce business relies heavily on its online storefront. They want to ensure that if their primary server fails, a backup system can take over immediately with minimal disruption to customer orders. Which of the following backup strategies would best meet this requirement?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 164.During the planning phase for business continuity, an organization defines the maximum time a business process can be inoperative before the disruption causes unacceptable damage to the organization. This critical metric is known as:Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 165.A small business is developing its cybersecurity strategy. They need to determine the maximum amount of time a critical business function can be offline before suffering unacceptable consequences. Which of the following metrics is MOST appropriate for this determination?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 166.A healthcare provider is establishing its disaster recovery plan. Due to regulatory requirements and the critical nature of patient data, they need a recovery site that can be operational within hours and fully equipped with hardware, software, and network connectivity. Which type of alternate site best fits these requirements?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 167.A global enterprise needs to ensure that its critical applications and data are continuously available across geographically dispersed data centers. They require a solution that automatically fails over to a secondary site in case of a primary site outage, with virtually no data loss and minimal downtime. Which technology would best support these requirements?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 168.An organization is implementing a new business continuity plan. As part of this, they are establishing clear communication channels and protocols for notifying employees, customers, and stakeholders during a disruption. This activity is a key component of which aspect of BC/DR planning?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 169.During a Business Impact Analysis (BIA), a cybersecurity analyst is tasked with identifying the financial and operational consequences of a disruption to the organization's critical e-commerce platform. Which of the following is a primary objective of this phase of the BIA?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 170.An organization is conducting a Business Impact Analysis (BIA). They have identified that the maximum acceptable data loss for their customer relationship management (CRM) system is 2 hours. What critical metric does this 2-hour window represent?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 171.An organization has experienced a ransomware attack that encrypted critical servers. The incident response team has successfully contained the spread and eradicated the malware. What is the NEXT logical phase in the incident response process?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 172.A cybersecurity team is reviewing its incident response plan. They are currently discussing the steps to ensure that the root cause of an incident is identified and eliminated, preventing recurrence. Which phase of the incident response process are they focusing on?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 173.A cybersecurity team is conducting an initial assessment after detecting suspicious network activity. They have isolated the affected systems to prevent further spread of potential malware. Which phase of the incident response process are they currently executing?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 174.A security operations center (SOC) receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address. After initial investigation, it's determined to be a data exfiltration attempt. The SOC team then follows documented procedures to contain the threat and gather evidence. This structured approach is best described as:Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 175.An organization is conducting a comprehensive review of its critical business functions to understand the potential impact of disruptions. They are analyzing the financial, reputational, and operational consequences of various outages. What type of analysis are they performing?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 176.An organization is evaluating different backup strategies to protect its critical data. They need a solution that offers the fastest recovery time for their entire system, including the operating system, applications, and data, but they are concerned about the storage space required. Which backup strategy best fits this requirement?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 177.A company is reviewing its disaster recovery plan. They realize that while they have backups, the time it would take to restore all critical systems and data from those backups is too long to meet their business's needs. Which metric is primarily being violated in this scenario?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 178.An organization's business continuity plan includes regular exercises. During a recent exercise, the team discovered that the recovery procedures for a critical database were outdated and failed to restore data correctly. What is the primary purpose of conducting such exercises, as demonstrated by this discovery?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 179.A cybersecurity analyst is investigating a suspected malware infection across several endpoints. After confirming the infection, their immediate priority is to isolate the affected systems to prevent further spread of the malware. Which phase of incident handling is the analyst currently executing?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 180.A critical server in a data center experiences a hardware failure. To ensure business continuity, a standby server immediately takes over its functions, and users experience no interruption of service. This scenario demonstrates the successful implementation of which concept?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 181.A cybersecurity team is conducting a tabletop exercise for their incident response plan. What is the primary purpose of this type of exercise?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 182.A critical server hosting customer data has been compromised. The incident response team determines that the attacker has established persistence and exfiltrated a significant amount of data. According to the standard incident response process, which activity should be prioritized IMMEDIATELY after containing the incident and before full recovery?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 183.A financial institution requires its core banking system to have near-instantaneous recovery capabilities with virtually no data loss. Which backup and recovery strategy would BEST meet these stringent requirements?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 184.A multinational corporation operates a crucial database that processes real-time financial transactions globally. Due to regulatory compliance and business demands, they must ensure that in the event of a primary data center failure, no more than 15 minutes of data can be lost. Which recovery metric does this requirement directly address?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 185.A critical server fails due to a hardware malfunction. The operations team immediately switches over to a redundant server that was already running in parallel and processing the same data. This scenario BEST exemplifies which of the following?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 186.During a routine audit, it is discovered that an organization's critical database, which processes customer transactions, has been operating without redundant systems for failover. The Business Impact Analysis (BIA) for this database indicates an MTD of 4 hours. Which of the following would be the MOST appropriate immediate action to reduce the risk of exceeding the MTD during an unforeseen outage?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 187.A company's primary data center is located in an area prone to natural disasters. To ensure the availability of critical services, they decide to implement a recovery strategy where a fully equipped and configured duplicate facility, with real-time data synchronization, is maintained at a geographically distinct location. This strategy BEST describes the use of a:Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 188.A multinational corporation is developing its business continuity strategy. They need a comprehensive plan that outlines how to maintain critical business functions during and after a disruption, focusing on the continuity of operations rather than solely IT recovery. This describes which type of plan?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 189.A company requires its critical manufacturing control systems to be operational 24/7 without any planned or unplanned downtime. To achieve this, they plan to implement redundant systems and automatic failover mechanisms. This approach is aimed at achieving:Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 190.A financial institution is implementing a new business continuity plan. As part of this, they are defining the systematic process for identifying, analyzing, and responding to security incidents. This process is formally known as:Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 191.A critical server hosting an organization's primary customer database experiences a sudden power surge, rendering it inoperable. The organization has a backup strategy in place that performs daily full backups to an offsite location. If the power surge occurred at 2:00 PM and the last successful backup was at 1:00 AM the same day, what is the maximum amount of data (measured in time) the organization stands to lose?Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
- 192.A government agency is designing a new access control system for highly sensitive, classified documents. The system must enforce strict rules where access decisions are based on a subject's clearance level and a document's classification level, with no discretion given to individual users or data owners. Which access control model is most appropriate for this scenario?Access Controls Concepts
- 193.A financial institution is implementing a new online banking platform. To ensure that transactions cannot be falsely denied by either the customer or the bank after they have occurred, which security principle is most critical to implement?Security Principles
- 194.A cybersecurity team is conducting an audit of user permissions across all critical systems. They discover that several employees who have transferred departments or left the company still retain active accounts or elevated privileges in their old systems. This situation indicates a failure in which critical aspect of access control lifecycle management?Access Controls Concepts
- 195.A cyber insurance company is assessing the potential financial losses for a client due to a data breach. They estimate that if a breach occurs, the direct costs (investigation, notification, fines) and indirect costs (reputation damage, lost business) would sum up to $2 million. This estimate represents which component of risk quantification?Security Principles
- 196.A system administrator is configuring firewall rules for a new secure network segment. The security policy dictates that only explicitly permitted traffic should be allowed, and all other traffic must be blocked by default. Which access control principle is being applied here?Access Controls Concepts
- 197.An organization is conducting a comprehensive review of its cybersecurity posture. They are evaluating the likelihood of various threats exploiting vulnerabilities and the resulting impact on business operations. The overall process of identifying, assessing, and treating these potential negative events is known as:Security Principles
- 198.A security team is conducting a post-incident review after a successful phishing attack led to a data breach. Their goal is to identify lessons learned, improve existing security measures, and update incident response plans to prevent similar incidents. This activity falls under which phase of incident response?Security Principles
- 199.A company is implementing a new system for managing access to its internal network resources. They want a robust system that can centralize user identities, authenticate users across various applications, and manage authorizations efficiently. Which security solution is designed to address these combined needs comprehensively?Access Controls Concepts
- 200.A critical infrastructure organization manages a Supervisory Control and Data Acquisition (SCADA) system. They have determined that a single outage event on a specific control server could lead to a loss of $50,000. Historical data indicates that this type of outage occurs approximately once every two years. What is the Annualized Loss Expectancy (ALE) for this specific risk?Security Principles