CISSP Certification Guide / Chapter 34
Full Practice Exam II: Questions 64–125
The second sitting of the book's complete 125-question practice exam: 62 original questions at the current blueprint weights across all eight domains, run as one timed session, with a combined-scoring method, a full answer key, and a rationale for every question.
How to run this sitting
This chapter is the second half of the full practice exam: questions 64 through 125, 62 items at the current blueprint weights. Chapter 33 carried the first 63. The two sittings together are the book’s complete 125-question practice exam, and the score sheet that matters is the combined one, because the real exam is a single session with a single adaptive pass or fail.
The domains appear in the proportions the public outline assigns. This sitting carries 9 items from Domain 1, 6 from Domain 2, 8 from each of Domains 3 through 7, and 7 from Domain 8. The section headings are a scoring convenience only. The adaptive exam interleaves domains and never announces which domain an item tests, so use the headings to score, not to warm up your focus for a subject you know is coming.
Run this sitting under the same protocol as the first. Set the clock for ninety minutes: 62 items at the exam’s working pace of roughly 1.4 minutes per item is about 87 minutes, and ninety keeps a round number. Apply the two-minute cap per item. Read the question line first, name the shape and the qualifier, kill what you can kill, choose among the survivors with the decision hierarchy from Chapter 2, confirm, and move. Answer every question, including the ones that force a guess. No skipping, no review, no returning, no notes, no phone, no comfort stop in the middle.
If you want the full-session simulation, run this sitting immediately after Chapter 33 under one 180-minute clock and treat the pause between the two chapters as your only stop. If you are running this on a separate day, that is fine for scoring, just not for fatigue practice: the last-hour discipline from Chapter 32 is exactly what a split session does not train.
When the clock stops, score before you open the key. Count the total, then the per-domain totals using the section headings. Then combine with the first sitting: add the 63 questions from Chapter 33 to these 62, and compute the full-exam domain percentages against the combined counts of 19 for Domain 1, 12 for Domain 2, 16 for Domains 3 through 7, and 14 for Domain 8. Those combined numbers are the ones Chapter 35’s readiness review will be built from, so record both sittings on the same score sheet.
Domain 1: Security and Risk Management (Questions 64–72)
- A security manager is choosing a control for the entrance to a data center. The control’s function is to stop an unauthorized person from entering the building before the person reaches the server floor. Which control type is this function?
A. Deterrent B. Detective C. Preventive D. Corrective
- A threat modeling team classifies threats as spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. Which mnemonic names this classification scheme?
A. DREAD B. PASTA C. OCTAVE D. STRIDE
- A risk analyst interviews department managers, who sort each risk into high, medium, or low using their judgment and experience rather than monetary estimates. Which approach is the analyst using?
A. Quantitative risk assessment B. Qualitative risk assessment C. Annualized loss expectancy D. Monte Carlo simulation
- A customer asks a controller to erase the customer’s personal data. Under the GDPR, which response is correct?
A. The controller must erase the data without undue delay when a ground in Article 17 applies, such as the data no longer being necessary, unless a legal obligation requires retention B. The controller may refuse whenever erasure is technically difficult or costly C. Erasure can be ordered only by a court after a formal complaint D. The right to erasure covers only data processed by automated means
- After an organization implements its planned controls, the risk that remains is called:
A. Inherent risk B. Residual risk C. Transfer risk D. Systematic risk
- A business continuity planner conducts a business impact analysis. Which output is the BIA’s primary product, the one the recovery strategy is built from?
A. Identification of the critical business processes and an estimate of the impact of their loss over time B. A list of software licenses that must be renewed C. The floor plan of the alternate work site D. A schedule of security awareness briefings
- Each quarter, employees watch a short briefing that defines phishing, shows examples, and reminds them how to report suspicious email. It changes no job skills. Which personnel security activity is this?
A. Security education B. Security training C. Security awareness D. Background screening
- A company protects the formula for its flagship product by keeping it confidential, restricting access on a need-to-know basis, and requiring employees to sign non-disclosure agreements. Which form of intellectual property protection is this?
A. Trade secret B. Patent C. Copyright D. Trademark
- To keep the information security audit trustworthy, the internal audit function must be independent of the operations it examines. Which reporting line best preserves that independence?
A. The chief information officer B. The chief information security officer C. The head of network operations D. The board of directors or audit committee
Domain 2: Asset Security (Questions 73–78)
- An organization separates the role that sets the day-to-day rules for how a data set may be used and maintains its quality from the role that implements and operates the technical controls. Which role defines the usage rules and quality standards?
A. Data custodian B. Data steward C. Data subject D. Data processor
- A researcher downloads a data set from a portal to her laptop over a TLS connection. The encryption in this transfer protects the data in which state?
A. At rest B. In transit C. In use D. In archive
- An organization plans to launch a service that will collect and combine sensitive personal data in ways it has never processed before. When should it carry out a privacy impact assessment?
A. Before the processing begins, because the new processing raises privacy risks that need evaluation and mitigation B. Only after a regulator requests one C. During the annual security audit, whatever the system’s age D. Only when the service is decommissioned
- Under the GDPR, personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Which principle does this express?
A. Accuracy B. Storage limitation C. Integrity and confidentiality D. Data minimization
- An organization is retiring solid-state drives that held confidential data. Per NIST SP 800-88 Rev 1, which approach is appropriate for the SSDs?
A. A single overwrite pass, because SSDs behave like magnetic disks B. Degaussing, which works on every storage technology C. Purge by cryptographic erase or physical destruction, because wear leveling and over-provisioning make overwriting unreliable on SSDs D. Deleting the files and emptying the recycle bin
- A regulation requires that citizens’ health records be stored and processed within the country’s borders. Which concept does this requirement express?
A. Data classification B. Data sovereignty C. Data remanence D. Data aggregation
Domain 3: Security Architecture and Engineering (Questions 79–86)
- A bank requires that every transaction pass through a certified transformation procedure run by an authorized user, and that no single user can both create and approve a transaction. Which security model enforces these two requirements?
A. Clark-Wilson B. Bell-LaPadula C. Biba D. Brewer-Nash
- A consulting firm serves two competing clients and must prevent any consultant who has seen one client’s data from accessing the other client’s data. Which model addresses this conflict-of-interest case?
A. Bell-LaPadula B. Biba C. Brewer-Nash (Chinese Wall) D. Clark-Wilson
- A system’s protection mechanisms span hardware, firmware, and software. What is the term for the totality of these mechanisms that enforce the system’s security policy?
A. Trusted computing base B. Reference monitor C. Security kernel D. Protection profile
- Which arrangement best illustrates defense in depth for a web application?
A. A single, very strong next-generation firewall B. The strongest possible encryption on one server C. Exclusive reliance on one vendor’s product suite D. A network firewall, a web application firewall, host-based controls, and access management, layered so that no single failure collapses the protection
- A badge reader is designed so that when its control electronics fail, the door stays locked and the server room remains protected. What is this behavior called?
A. Fail open B. Fail secure C. Fail safe D. Fail quiet
- Two parties want to agree on a shared secret over an insecure channel. Which mechanism establishes the shared secret but does not by itself authenticate either party?
A. Diffie-Hellman key exchange B. Digital signature C. AES encryption D. Certificate revocation
- A relying party needs to check, at the moment of use, whether a certificate has been revoked. Which mechanism queries an online responder for current revocation status?
A. CRL B. Certificate signing request C. OCSP D. Key escrow
- In the assessment and authorization lineage that NIST SP 800-37 codified, which pairing is correct?
A. Certification is the management decision; accreditation is the technical evaluation B. Both are performed by the system owner alone C. Certification is a one-time vendor warranty that never needs review D. Certification is the technical evaluation that controls are implemented correctly; accreditation (authorization) is the management decision to accept residual risk and authorize operation
Domain 4: Communication and Network Security (Questions 87–94)
- A firewall permits outbound TCP connections and allows return traffic only for connections it has observed being established. What distinguishes this behavior from a stateless packet filter?
A. It decrypts all application traffic B. It blocks all UDP traffic C. It inspects only the source IP address D. It tracks connection state and applies rules based on that state
- An attacker sends a continuous stream of TCP SYN packets without completing the three-way handshake, exhausting the firewall’s connection table. Which defense is most direct?
A. Blocking all inbound TCP traffic B. SYN cookies, which defer connection-table allocation until the handshake completes C. Increasing the DNS cache timeout D. Enabling MAC address filtering
- An attacker on a LAN sends forged ARP replies so that frames intended for the default gateway are redirected through the attacker’s machine. Which attack is this?
A. ARP poisoning B. DNS cache poisoning C. Smurf attack D. VLAN hopping
- A user types the bank’s web address correctly, but the browser lands on a fraudulent site because the machine’s DNS resolution has been altered. Which attack is this?
A. Phishing B. Spear phishing C. Pharming D. Vishing
- A site-to-site VPN between two offices wraps each original IP packet inside a new IP header with the gateways’ addresses. Which IPsec mode is in use?
A. Tunnel mode B. Transport mode C. Pass-through mode D. Transparent mode
- An employee connects a consumer access point to the corporate network, creating an unmanaged wireless entry point. Which control is most effective against this?
A. Wireless intrusion prevention with radio frequency monitoring, together with port-based access control that rejects the unknown device B. Requiring strong passwords on laptop accounts C. Encrypting files on the employee’s laptop D. Disabling DHCP on the network
- An organization wants every HTTP request to its web application inspected and filtered before it reaches the origin server. Which placement implements this?
A. A forward proxy used only for outbound web traffic B. A firewall positioned only on the ISP uplink C. Browser extensions on client machines D. A reverse proxy or web application firewall positioned in front of the origin servers
- An attacker floods a switch with frames carrying random source MAC addresses, overflowing the switch’s MAC address table so the switch forwards frames to all ports like a hub. Which control addresses this attack?
A. Increasing the DHCP lease time B. Disabling the address resolution protocol C. Port security that limits the number of MAC addresses per port D. Using longer network cables
Domain 5: Identity and Access Management (Questions 95–102)
- In which access control model does the owner of an object decide who may access it and with what privileges?
A. Mandatory access control B. Attribute-based access control C. Rule-based access control D. Discretionary access control
- An organization assigns permissions through job-based roles, and no user may hold roles that would let one person both request and approve a payment. Which model is in use?
A. Discretionary access control B. Mandatory access control C. Role-based access control D. Access control lists
- A mobile authenticator app displays a six-digit code that changes every 30 seconds, generated from a shared secret and the current time. Which mechanism is this?
A. TOTP B. HOTP C. Static password D. X.509 certificate
- An attacker obtains a large set of usernames and passwords leaked from one service and tries each pair against many unrelated services. Which attack is this?
A. Password spraying B. Dictionary attack C. Credential stuffing D. Brute force
- An application wants to slow automated guessing against its login endpoint. Which control is most direct and consistent with NIST SP 800-63B?
A. Requiring users to rotate passwords every 30 days B. Displaying detailed messages about which password rule was violated C. Increasing the session timeout to eight hours D. Locking the account after a small number of consecutive failures with a timed reset, together with throttling repeated attempts
- A third-party application asks a user for permission to read the user’s calendar, then receives an access token that lets it call the calendar API on the user’s behalf. Which framework governs this delegated authorization?
A. OAuth 2.0 B. Kerberos C. RADIUS D. LDAP
- Per NIST SP 800-63A, identity assurance levels describe how strongly a person’s claimed identity was verified. Which level permits identity proofing to be performed remotely, with the applicant submitting and the system validating strong evidence without an in-person visit?
A. IAL1 B. IAL2 C. IAL3 D. FAL1
- A user inserts a smart card and enters a PIN. The system sends a random challenge that the card signs with its private key. What does the successful signature prove?
A. The card holder is on the certificate revocation list B. The user’s password matches the directory C. The card was manufactured by the issuing vendor D. Possession of the private key, the something-you-have factor, combined with the PIN as something you know
Domain 6: Security Assessment and Testing (Questions 103–110)
- A testing team is given only the public-facing address of a web application and must discover its behavior the way an external attacker would, with no internal documentation or source code. Which test type is this?
A. White box B. Black box C. Gray box D. Open box
- An organization forms a team that deliberately simulates realistic adversary tactics against its own environment so the defensive team can practice detection and response. Which team is the simulated adversary?
A. Blue team B. Purple team C. White team D. Red team
- Which statement best distinguishes a vulnerability scan from a penetration test?
A. A scan identifies potential weaknesses without confirming exploitability; a penetration test validates whether a weakness can actually be exploited and what impact follows B. A scan exploits every weakness it finds; a penetration test only counts hosts C. Both require production systems to be taken offline D. A penetration test replaces patching
- An administrator removes default accounts, disables unneeded services, applies vendor security baselines, and verifies the result against a recognized configuration benchmark. Which activity is this?
A. Penetration testing B. Log archival C. System hardening D. Certificate renewal
- Per NIST SP 800-92, which practice is essential for correlating events recorded across many systems into a single timeline?
A. Storing logs only on each individual system B. Synchronizing system clocks from a trusted time source so timestamps align C. Deleting logs after 24 hours to conserve space D. Encrypting log files with a different key on every system
- A scanner sends a SYN packet and, on receiving the SYN-ACK, sends RST instead of completing the handshake, leaving no established connection in the target’s logs. Which scan technique is this?
A. Half-open (SYN) scan B. Full connect scan C. UDP flood D. Ping sweep
- An analyst studies a recent report of a specific adversary technique, then searches the environment’s telemetry for subtle traces of that technique rather than waiting for an alert. Which activity is this?
A. Patch management B. Log retention C. Configuration management D. Threat hunting
- Per NIST SP 800-115, which grouping names the three basic information security assessment techniques?
A. Patch, scan, and report B. Design, build, and run C. Review, interview, and test D. Harden, monitor, and audit
Domain 7: Security Operations (Questions 111–118)
- An investigator must collect the contents of a suspect’s hard drive in a way that preserves the evidence. Which procedure is correct?
A. Copying only the visible files with the operating system B. A bit-for-bit image taken through a write blocker, with the hash of the original verified against the hash of the copy C. Booting the suspect system to copy its active files D. Opening files to preview them before imaging
- A backup strategy calls for three copies of the data, on two different media types or locations, with one copy stored offsite. Which rule does this describe?
A. Grandfather-father-son rotation B. Continuous data protection C. Snapshot chaining D. The 3-2-1 backup rule
- An organization deploys a decoy server that looks like a real asset, attracts attackers, and records their activity without exposing production data. Which control is this?
A. Honeypot B. SIEM correlation engine C. Vulnerability scanner D. Backup appliance
- An organization must decide which of many disclosed vulnerabilities to remediate first. Which standard provides the severity score that supports this ranking?
A. CVE B. CWE C. CVSS D. MITRE ATT&CK
- A server room holds live electronics that must keep operating. Which fire suppression approach is appropriate?
A. A standard water sprinkler system B. Foam suppression C. Halon, which is still manufactured for new systems D. A clean agent system using an inert gas or a chemical agent that leaves no residue
- An organization wants to detect an employee who begins downloading unusual volumes of customer data at odd hours. Which capability models each user’s normal behavior and flags deviations from it?
A. Antivirus scanning B. User and entity behavior analytics C. Network segmentation D. Disk encryption
- An organization configures its endpoints so that only executables on an approved list can run, and everything else is blocked by default. Which control is this?
A. Denylisting B. Sandboxing C. Application allowlisting D. Data loss prevention
- Which statement about power protection is accurate?
A. A generator covers brownouts instantly, so a UPS is unnecessary B. A UPS eliminates the need for a generator in every case C. A UPS provides ride-through for short outages and clean power for an orderly shutdown, while a generator provides extended runtime after it starts D. Surge suppressors protect against total power loss
Domain 8: Software Development Security (Questions 119–125)
- An application checks that a file is writable, then opens it for writing. An attacker replaces the file between the check and the open. Which flaw is this?
A. Buffer overflow B. Integer overflow C. Time-of-check-to-time-of-use race condition D. Session fixation
- An attacker sends input longer than a fixed-size buffer, overwriting adjacent stack memory including the return address. Which flaw and mitigation class is this?
A. A format string flaw, mitigated by stronger passwords B. A cross-site request forgery, mitigated by rate limiting C. A race condition, mitigated by longer timeouts D. A buffer overflow, mitigated by bounds checking, stack canaries, and address space layout randomization
- An application needs a database credential. Where should the credential live?
A. In a secrets manager that stores it encrypted, restricts access, and supports rotation B. Hardcoded in the source code for clarity C. In a configuration file committed to the source repository D. In the browser’s local storage
- An attacker submits a file path using alternate encodings, such as encoded dots and slashes, to slip past a filter that blocks literal ../ sequences. Which control addresses this class of bypass?
A. Adding more entries to the audit log B. Increasing password length C. Canonicalizing input to a single standard form before validation D. Enabling TLS
- A web application’s error page displays a full stack trace with internal file paths and library versions. Which risk does this create, and what is the fix?
A. Authentication bypass; rotate the database password B. Information disclosure; return generic error messages to users and log the details server-side C. Denial of service; add a second web server D. Injection; parameterize the query
- A build pipeline inventories every third-party component in the application and flags components with known vulnerabilities before the artifact ships. Which practice is this?
A. Software composition analysis B. Dynamic application security testing C. Runtime application self-protection D. Fuzzing
- Which statement about runtime application self-protection is accurate?
A. It is a network appliance placed in front of the application B. It scans source code at build time C. It eliminates the need for patching D. It runs inside the application runtime and can block attacks using application-level context
Score this sitting before you open the key
The answer key and the rationales are below. Do not open them until the ninety minutes are up and you have written your totals. Score two ways. First the total: count correct answers and convert to a percentage of 62. Then the per-domain count, using the section headings: 9 for Domain 1, 6 for Domain 2, 8 for each of Domains 3 through 7, and 7 for Domain 8. Apply the thresholds from Chapter 1: below 60 percent in a domain sends that domain through the re-read, redo, retest loop; 60 to 80 percent earns targeted rationale review; above 80 percent gets one weekly pass. Then combine with the first sitting and recompute the domain percentages against the full-exam counts of 19, 12, 16, 16, 16, 16, 16, and 14. Record both layers on the same score sheet, because Chapter 35’s readiness review is built from the combined numbers.
Answer key
| Question | Answer | Question | Answer | Question | Answer |
|---|---|---|---|---|---|
| 64 | C | 65 | D | 66 | B |
| 67 | A | 68 | B | 69 | A |
| 70 | C | 71 | A | 72 | D |
| 73 | B | 74 | B | 75 | A |
| 76 | D | 77 | C | 78 | B |
| 79 | A | 80 | C | 81 | A |
| 82 | D | 83 | B | 84 | A |
| 85 | C | 86 | D | 87 | D |
| 88 | B | 89 | A | 90 | C |
| 91 | A | 92 | A | 93 | D |
| 94 | C | 95 | D | 96 | C |
| 97 | A | 98 | C | 99 | D |
| 100 | A | 101 | B | 102 | D |
| 103 | B | 104 | D | 105 | A |
| 106 | C | 107 | B | 108 | A |
| 109 | D | 110 | C | 111 | B |
| 112 | D | 113 | A | 114 | C |
| 115 | D | 116 | B | 117 | C |
| 118 | C | 119 | C | 120 | D |
| 121 | A | 122 | C | 123 | B |
| 124 | A | 125 | D |
Rationales
-
C. Preventive controls act before the event: they stop the unauthorized entry itself. Deterrent controls discourage through signs and warnings but do not block, detective controls identify an event after it happens, and corrective controls restore after the fact. The question describes a control whose function is to stop the entry, which is prevention.
-
D. STRIDE is the Microsoft mnemonic for Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege. DREAD is a rating scheme for ranking threats, PASTA is a process for attack simulation and threat analysis, and OCTAVE is a Carnegie Mellon risk assessment methodology; none of them is this classification.
-
B. Qualitative assessment sorts risks into categories such as high, medium, and low using judgment; quantitative assessment uses numeric estimates such as SLE, ARO, and ALE. Annualized loss expectancy is a quantitative product and Monte Carlo is a simulation technique, so both belong to the numeric family the analyst is not using.
-
A. GDPR Article 17 gives data subjects the right to erasure without undue delay on grounds that include the data no longer being necessary, consent withdrawal, and unlawful processing, subject to exceptions such as legal obligations and legal claims. Difficulty or cost is not a refusal ground, a court order is not required, and the right covers all personal data, not just automated processing.
-
B. Inherent risk is the risk before controls; residual risk is what remains after controls are applied, and it is the figure the risk owner decides to accept, transfer, or treat further. Acceptance is the documented decision about residual risk, transfer, such as insurance, is a treatment option, and systematic risk is a financial term rather than a risk-management state.
-
A. The BIA identifies critical business processes and estimates the impact of their loss over time, which produces the recovery priorities and feeds the RTO and RPO figures. License lists, floor plans, and training schedules are operational outputs that follow the BIA rather than feed it.
-
C. Awareness changes attention and behavior with brief, recurring exposure; training builds specific skills; education develops a professional’s broad understanding over a career. This briefing teaches no job skill, so awareness is the category.
-
A. A trade secret is information kept confidential that derives value from not being generally known, and protection lasts as long as secrecy is maintained, which is what the non-disclosure agreements and restricted access preserve. Patents require public disclosure of the invention, copyright protects expression, and trademarks identify source in commerce.
-
D. Independence means the audit function does not report to the functions it examines, so reporting to the board or audit committee is the classic structure. Reporting to the CIO, the CISO, or the network head puts the auditor under the people being audited, which weakens the independence the audit exists to provide.
-
B. The steward administers the data day to day under the owner’s authority: defining usage rules, quality standards, and handling guidance, while the custodian implements and operates the technical controls. The data subject is the person the data is about, and a processor is a contract-party concept from privacy regulation.
-
B. Data in transit is the state of data moving between locations, and TLS protects it while it moves. At rest is stored data, in use is data in memory during processing, and archive is a storage state, not the movement the question describes.
-
A. The privacy impact assessment belongs before the processing begins, because its job is to evaluate the new privacy risks and shape mitigations before they become operational. GDPR Article 35 requires an assessment where processing is likely to result in a high risk; waiting for a regulator, an audit, or decommissioning defeats the assessment’s purpose.
-
D. Article 5(1)(c) of the GDPR is data minimization: adequate, relevant, and limited to what is necessary. Accuracy, storage limitation, and integrity and confidentiality are separate Article 5 principles with different meanings.
-
C. NIST SP 800-88 Rev 1 notes that overwriting does not reliably sanitize SSDs because wear leveling and over-provisioning keep cells outside the overwrite’s reach, so purge by cryptographic erase or physical destruction is the appropriate path. Degaussing is not effective on solid-state media, deleting files removes the references but not the data, and a single overwrite pass is the magnetic-disk expectation that does not transfer to flash.
-
B. Data sovereignty is the principle that data is subject to the laws of the jurisdiction where it resides, and residency rules force storage and processing inside a border. Classification is about labels and controls, remanence about residual data on media, and aggregation about combining data to derive new insight.
-
A. Clark-Wilson enforces well-formed transactions, where data can be changed only through certified transformation procedures run by authorized users, and separation of duties, so no single user can both create and approve a transaction. Bell-LaPadula is confidentiality labels, Biba is integrity labels, and Brewer-Nash handles conflict of interest.
-
C. Brewer-Nash, the Chinese Wall model, is designed for conflict-of-interest environments: once a subject accesses one client’s data, the model blocks access to the competing client’s data. Bell-LaPadula and Biba enforce label-based confidentiality and integrity, and Clark-Wilson enforces transaction integrity and separation of duties.
-
A. The trusted computing base is the totality of the hardware, firmware, and software protection mechanisms that enforce the security policy. The reference monitor is the abstract concept of complete, tamperproof, verifiable mediation, the security kernel is the portion of the TCB that implements the reference monitor, and a protection profile is a Common Criteria specification.
-
D. Defense in depth layers independent controls so that a failure in one layer does not collapse the protection: the network firewall, the web application firewall, the host-based controls, and the access management each impose a separate hurdle. A single strong control, the best encryption on one server, or one vendor’s suite each concentrates the risk instead of distributing it.
-
B. Fail secure, also called fail closed, means the system fails to the state that protects the assets: the door stays locked. Fail open would unlock it, and fail safe in life-safety contexts means failing to the state that protects people, which for an exit door is the unlocked state, so the two terms must not be conflated. The locked-on-failure behavior described is fail secure.
-
A. Diffie-Hellman is a key agreement protocol that lets two parties derive a shared secret over an insecure channel, and it does not authenticate either party by itself, which is why it is vulnerable to man-in-the-middle when used alone. A digital signature authenticates, AES is symmetric encryption of data, and revocation checks a certificate’s status.
-
C. OCSP, defined in RFC 6960, queries an online responder for the certificate’s current revocation status at the moment of use. A CRL is a periodically published list that can be stale relative to its issue date, a certificate signing request starts enrollment, and key escrow is a recovery mechanism.
-
D. In the assessment and authorization lineage that NIST SP 800-37 codified, certification is the technical evaluation that the controls are implemented correctly, and accreditation, now called authorization, is the management decision to accept the residual risk and authorize operation. Reversing the pairing, letting the owner alone decide, or treating the process as a one-time warranty all misstate the relationship between the two decisions.
-
D. Stateful inspection keeps a table of established connections and matches return traffic to them, so traffic that arrives without a prior outbound establishment is dropped. Decrypting application traffic, blocking UDP, and inspecting only source addresses are behaviors of other devices or filters, not the state tracking that defines this behavior.
-
B. SYN cookies defer the allocation of connection-table state until the handshake completes, so a flood of half-open connections cannot exhaust the table. Blocking all inbound TCP kills legitimate service, DNS cache settings and MAC filtering do not touch the TCP handshake state, and the cookie approach is the defense designed for this exact exhaustion.
-
A. ARP poisoning, also called ARP spoofing, sends forged ARP replies that bind the attacker’s MAC address to the gateway’s IP, redirecting LAN traffic through the attacker. DNS cache poisoning corrupts name resolution, a smurf attack amplifies ICMP traffic, and VLAN hopping crosses VLAN boundaries; none of them works at the ARP layer.
-
C. Pharming redirects the victim to a fraudulent site by altering the resolution itself, here the machine’s DNS, so the typed address is correct but the answer is not. Phishing lures the user through deceptive messages, spear phishing targets a specific person, and vishing uses voice; each depends on the user’s action or a voice channel rather than on altered resolution.
-
A. Tunnel mode encapsulates the entire original IP packet inside a new IP header with the gateways’ addresses, which is the mode used between security gateways in a site-to-site VPN under RFC 4301. Transport mode protects only the payload and leaves the original IP header in place, and pass-through and transparent are not IPsec modes.
-
A. Wireless intrusion prevention uses radio frequency monitoring to detect the unapproved access point, and port-based access control under IEEE 802.1X rejects the device at the wired port it is plugged into, so the rogue entry point cannot carry traffic. Passwords, file encryption, and DHCP settings do not find or stop the unauthorized radio and its port connection.
-
D. A reverse proxy or web application firewall sits in front of the origin servers and inspects every request before it reaches the application. A forward proxy serves outbound client traffic, an uplink firewall filters the network edge rather than the application, and browser extensions protect one client at a time rather than the server-side application.
-
C. MAC flooding overflows the switch’s MAC address table, and port security counters it by limiting the number of MAC addresses a port may learn, so the flood cannot push the switch into fail-open hub behavior. DHCP lease time, ARP, and cable length have no bearing on the MAC table overflow.
-
D. Discretionary access control puts the object’s owner in charge of granting access, as the question describes. Mandatory access control is system-enforced labels with no owner override, attribute-based access control evaluates attributes, and rule-based access control applies rules, typically within another model.
-
C. Role-based access control grants permissions through membership in roles, which makes separation of duties enforceable by assigning incompatible duties to different roles. Discretionary access control is owner discretion, mandatory access control is labels, and access control lists are a mechanism that any model may use.
-
A. TOTP, defined in RFC 6238, generates one-time codes from a shared secret and the current time, which is why the code changes every 30 seconds. HOTP uses an event counter instead of time, a static password never changes, and an X.509 certificate is an identity credential rather than a rolling code.
-
C. Credential stuffing replays credentials stolen from one service against many others, exploiting password reuse. Password spraying tries a few common passwords against many accounts, a dictionary attack guesses likely words against a target, and brute force exhausts the password space; only stuffing uses the victim’s actual leaked credentials at scale.
-
D. NIST SP 800-63B directs verifiers to slow automated guessing with throttling and lockout, with the account unlocked after a timed reset rather than frozen permanently. Forced rotation at 30 days is the pattern the guidance moved away from, verbose error messages feed the attacker, and a longer session timeout works in the attacker’s favor.
-
A. OAuth 2.0, defined in RFC 6749, is the delegated authorization framework: the user authorizes the third-party application, which receives an access token to call the resource API on the user’s behalf. Kerberos is a ticket-based network authentication protocol, RADIUS authenticates network access, and LDAP is a directory protocol.
-
B. NIST SP 800-63A defines IAL2 as allowing identity proofing to be performed remotely, with the applicant providing evidence that the system validates. IAL1 is self-asserted with no evidence, IAL3 requires in-person proofing with biometrics, and FAL is a federation assurance level from the same family with a different meaning.
-
D. The random-challenge signature proves possession of the private key, which is the something-you-have factor carried by the card, and the PIN adds something you know, so the pair is multifactor. A revocation list shows status rather than identity, a directory password is a different factor class, and the card’s manufacturer says nothing about this session.
-
B. Black box testing gives the tester no internal knowledge, so the tester explores the target as an external attacker would. White box provides full access to source and internals, gray box provides partial knowledge, and open box is not a standard test type.
-
D. The red team plays the simulated adversary; the blue team defends; the purple team coordinates the two so each improves; the white team referees an exercise. The question asks for the team acting as the adversary, which is the red team.
-
A. A vulnerability scan identifies potential weaknesses from the outside, often with false positives, while a penetration test goes further and validates whether a weakness is exploitable and what the impact would be. Exploiting every finding, taking production offline, and replacing patching all misstate what the two activities do.
-
C. Hardening is the process of reducing attack surface: removing default accounts and unneeded services, applying vendor baselines, and verifying against benchmarks such as the CIS Benchmarks. Penetration testing probes the environment, log archival stores events, and certificate renewal is identity material; none of them is the configuration activity described.
-
B. NIST SP 800-92 treats synchronized time as a foundation of log management, because events from different systems can be correlated into one timeline only when their timestamps agree. Storing logs locally, deleting them after 24 hours, and using different encryption keys per system all fail the correlation job.
-
A. A half-open SYN scan sends SYN and responds to the SYN-ACK with RST, so no connection is ever fully established and the target’s connection logs do not record it. A full connect scan completes the handshake and is easily logged, a UDP flood is a denial-of-service attack, and a ping sweep discovers live hosts.
-
D. Threat hunting is hypothesis-driven: analysts propose a technique or adversary and search the environment’s data for its traces instead of waiting for an alert. Patch management, log retention, and configuration management keep the environment running but do not actively seek out attacker behavior.
-
C. NIST SP 800-115, the technical guide to information security testing and assessment, names three assessment technique families: examination (review), interviewing, and testing. Patching, scanning, reporting, and the other groupings mix operational activity with the assessment techniques the standard defines.
-
B. Defensible evidence collection images the drive bit for bit through a write blocker, so the original cannot be altered, and verifies hashes of the original against the copy so integrity is provable. Copying visible files loses deleted data and metadata, booting the suspect system modifies it, and previewing files changes their access times.
-
D. The 3-2-1 rule: three copies of the data, on two different media types or locations, with one copy offsite. Grandfather-father-son is a rotation scheme, continuous data protection captures ongoing changes, and snapshot chaining is a storage technique; each is compatible with 3-2-1 but is not the rule the scenario states.
-
A. A honeypot is a decoy that invites attackers so their activity is observed and analyzed without touching production data. A SIEM correlates security events, a vulnerability scanner finds weaknesses, and a backup appliance stores data; none of them is a decoy.
-
C. CVSS, the Common Vulnerability Scoring System, produces the 0.0 to 10.0 severity score used to rank remediation. CVE is the identifier registry for disclosed vulnerabilities, CWE is a taxonomy of weakness types, and MITRE ATT&CK catalogs adversary techniques; none of them is the scoring scale.
-
D. Clean agent systems, inert gases or chemical agents such as FM-200 and Novec 1230, extinguish without leaving residue that would destroy electronics. Water and foam damage live equipment, and halon production was phased out under the Montreal Protocol because it depletes the ozone layer, so new systems use the clean agents.
-
B. User and entity behavior analytics builds a baseline of each user’s normal activity and flags deviations, which is how the unusual download volume and odd hours become visible. Antivirus scans files for malware, segmentation limits reach, and disk encryption protects data at rest; none of them models user behavior.
-
C. Application allowlisting blocks everything except approved executables, a deny-by-default posture. Denylisting blocks known bad files and lets everything else run, sandboxing isolates execution, and data loss prevention controls data movement; only allowlisting is the approved-list posture the question describes.
-
C. A UPS carries the load through brief outages and sags and provides clean power for an orderly shutdown, while a generator covers extended outages after its startup delay, which is why the two are paired rather than either replacing the other. Surge suppressors clamp voltage spikes and do nothing for total power loss.
-
C. Time-of-check-to-time-of-use (TOCTOU) is the race between a check and the use of a resource; the attacker wins the race by swapping the file between the two steps. Buffer and integer overflows corrupt memory, and session fixation hijacks a session; none of them matches the check-then-use window.
-
D. The flaw is a stack buffer overflow: input overruns a fixed-size buffer and overwrites adjacent memory such as the return address. Bounds checking prevents the overflow, stack canaries detect the overwrite, and address space layout randomization makes predictable target addresses unusable. The other pairings match flaws to unrelated mitigations.
-
A. A secrets manager stores credentials encrypted, restricts access to the applications and people that need them, and supports rotation, so a leak of source or configuration does not leak the credential. Hardcoding, committing configuration files with credentials, and storing secrets in browser storage all place the credential where an attacker can find it.
-
C. Canonicalization reduces input to a single standard form before validation, so alternate encodings cannot smuggle a path past a filter that checks only the literal form. More audit entries, longer passwords, and TLS do not change how the input is interpreted.
-
B. Stack traces expose internal paths, library versions, and code structure, which is information disclosure that feeds further attacks; the fix is generic user-facing errors with the full details written to server-side logs. Rotating a password, adding a server, and parameterizing a query address different flaws.
-
A. Software composition analysis inventories the third-party components in a build and matches them against known-vulnerability data, so a vulnerable dependency can be caught before shipment. DAST tests a running application, RASP protects at runtime, and fuzzing supplies malformed inputs; none of them catalogs the component supply chain.
-
D. RASP runs inside the application runtime and uses application-level context to detect and block attacks in real time. It is not a network appliance, which is a web application firewall’s role, it does not scan source at build time, which is static analysis, and it does not remove the need for patching; it is a runtime control that complements the others.
Reading the two sittings together
The combined score sheet, not either sitting alone, is the deliverable of the full practice exam. A total percentage tells you where you stand against the pass mentality of the real exam, but the per-domain numbers tell you what to do next, and that is the material Chapter 35’s readiness review is built on.
Combine the two sittings before you draw conclusions. Against the combined counts of 19 for Domain 1, 12 for Domain 2, 16 for Domains 3 through 7, and 14 for Domain 8, compute the full-exam domain percentages. A domain that stayed below 60 percent across both sittings is a re-read, redo, retest domain: back to the study chapter, back to the domain practice test, back to a fresh set of questions. A domain in the 60 to 80 percent band gets targeted rationale review, starting with the questions you missed here and the chapters they came from. A domain above 80 percent gets one weekly pass to hold it warm.
Pay attention to the pattern of the misses, not just the count. If the misses cluster on standards you did not name correctly in the rationale, that is a vocabulary problem and the fix is the standard itself: read the clause, the RFC, or the control family you misquoted. If the misses cluster on judgment questions where the standard was right but the qualifier was wrong, that is a technique problem, and the fix is the elimination and hierarchy work from Chapter 32. The two failures look the same on the score sheet and respond to different study.
Chapter 35 is the final readiness review: how to read these combined numbers, triage the weak domains into a concrete plan, compress the mnemonics and the last-week review, and handle the days after the exam, including endorsement and the path to the certification. Bring the combined score sheet to it, with both sittings recorded, because that is the document the final plan is written from.
Continue reading
Full table of contents