ISC2 Certified in Cybersecurity (CC) practice questions
214 free questions with answers and explanations.
- 201.A cybersecurity team is conducting an audit of user permissions across all critical systems. They discover that several employees who have transferred departments or left the company still retain active accounts or elevated privileges in their old systems. This situation indicates a failure in which critical aspect of access control lifecycle management?Access Controls Concepts
- 202.A financial institution is implementing a new online banking platform. To ensure that transactions cannot be falsely denied by either the customer or the bank after they have occurred, which security principle is most critical to implement?Security Principles
- 203.A government agency is designing a new access control system for highly sensitive, classified documents. The system must enforce strict rules where access decisions are based on a subject's clearance level and a document's classification level, with no discretion given to individual users or data owners. Which access control model is most appropriate for this scenario?Access Controls Concepts
- 204.A system administrator is configuring access to a new financial reporting application. The policy states that users should only be able to access the specific reports required for their job function, and nothing more. This approach directly aligns with which access control principle?Access Controls Concepts
- 205.A large e-commerce company is implementing a new customer loyalty program. They want to ensure that access to sensitive customer purchase history is restricted. Access should be granted based on the user's department (e.g., Marketing, Customer Service) and their specific role within that department (e.g., Senior Analyst, Team Lead). Which access control model best fits these requirements?Access Controls Concepts
- 206.A global technology company is developing a new social media platform. They are particularly focused on ensuring that any personal data collected is minimized, securely stored, and deleted when no longer needed, right from the initial design phase. This approach aligns with which privacy concept?Security Principles
- 207.A company is implementing a new policy for handling sensitive customer data. The policy states that all employees who interact with this data must undergo specific training modules annually and sign an acknowledgment of their responsibilities. Which aspect of security operations does this primarily address?Security Operations
- 208.A small business is setting up a new server room and wants to ensure the physical environment protects its hardware. Which of the following is the MOST important environmental control to implement first to prevent immediate damage to equipment?Security Operations
- 209.An organization is migrating its data to a new cloud service provider. To ensure compliance with data privacy regulations, they must categorize all data based on its sensitivity and regulatory requirements before migration. Which data management practice is being performed?Security Operations
- 210.A healthcare provider is decommissioning an old server that stored millions of patient records. Before the server is physically destroyed, the organization must ensure that all sensitive data is unrecoverable. Which method provides the highest assurance of data destruction for this scenario?Security Operations
- 211.A rapidly growing tech startup has numerous cloud-based applications and services. They notice that tracking software licenses, hardware warranties, and cloud subscription renewals has become chaotic, leading to unexpected costs and potential compliance issues. Which security operations practice should they prioritize to regain control and visibility over their IT environment?Security Operations
- 212.A financial institution is implementing a new system for processing customer transactions. Before going live, they want to ensure that the system's security controls are effective and meet regulatory requirements. Which type of assessment focuses on evaluating the design and implementation of these controls against established criteria?Security Operations
- 213.A security analyst is reviewing network traffic logs and notices an unusual number of failed login attempts originating from an external IP address trying to access the internal HR portal. This activity is inconsistent with normal user behavior. Which security monitoring technique is the analyst employing?Security Operations
- 214.A global technology company is expanding its operations and introducing new cloud services. To ensure the security of these new services, they need to establish a process for consistently applying security baselines and configurations across all new deployments. Which security operations practice is MOST directly responsible for this consistency?Security Operations