ISC2 CISSP Professional Ethics Security Concepts And Governance Practice Test

 

1 Security and Risk Management • 25 original questions

This CISSP practice test focuses on professional ethics security concepts and governance through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

After a business change, Humongous Insurance discovers that Organizational code of ethics is not handled consistently for the software delivery pipeline. The application security architect needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The decision affects 31 business processes and has a named executive risk owner.

  1. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: D

Why: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses Organizational code of ethics while preserving evidence needed for later review.

Option review:

A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses Organizational code of ethics while preserving evidence needed for later review.

Learning point: Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern. Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms.

Question 2

Woodgrove Bank is preparing a security decision for the AI-assisted customer service platform. The decision involves Confidentiality. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The decision affects 48 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Restrict access to authorized subjects and use encryption where disclosure risk exists.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property. It directly addresses Confidentiality without granting broader privilege than the business need requires.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

C: Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property. It directly addresses Confidentiality without granting broader privilege than the business need requires.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

Learning point: Restrict access to authorized subjects and use encryption where disclosure risk exists. Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property.

Question 3

During a risk workshop for the global collaboration platform, the team identifies Integrity as the deciding issue. The security governance lead is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The decision affects 65 business processes and has a named executive risk owner.

  1. Use integrity validation such as cryptographic hashes or signatures together with controlled write access.
  2. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Integrity requires detecting or preventing unauthorized modification, not merely hiding the data. It directly addresses Integrity without creating a new single point of failure.

Option review:

A: Integrity requires detecting or preventing unauthorized modification, not merely hiding the data. It directly addresses Integrity without creating a new single point of failure.

B: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

Learning point: Use integrity validation such as cryptographic hashes or signatures together with controlled write access. Integrity requires detecting or preventing unauthorized modification, not merely hiding the data.

Question 4

A control owner at Contoso Financial proposes a quick technical fix for Availability in the e-commerce application. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The decision affects 82 business processes and has a named executive risk owner.

  1. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Eliminate critical single points of failure and provide resilient capacity and tested recovery appropriate to the service objective.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Availability is protected through resilience, capacity, recovery, and operational readiness. It directly addresses Availability while ensuring that emergency access cannot become permanent access.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

C: Availability is protected through resilience, capacity, recovery, and operational readiness. It directly addresses Availability while ensuring that emergency access cannot become permanent access.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

Learning point: Eliminate critical single points of failure and provide resilient capacity and tested recovery appropriate to the service objective. Availability is protected through resilience, capacity, recovery, and operational readiness.

Question 5

Lucerne Publishing is standardizing security across several business units. The clinical records environment raises a question about Authenticity. The application security architect needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The decision affects 8 business processes and has a named executive risk owner.

  1. Use strong identity proofing and authentication so the origin or actor can be verified.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Authenticity is the assurance that an entity or message is genuine. It directly addresses Authenticity while allowing independent verification of the control outcome.

Option review:

A: Authenticity is the assurance that an entity or message is genuine. It directly addresses Authenticity while allowing independent verification of the control outcome.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

Learning point: Use strong identity proofing and authentication so the origin or actor can be verified. Authenticity is the assurance that an entity or message is genuine.

Question 6

During a secure software initiative, Lamna Healthcare asks the incident response manager to address Nonrepudiation for its remote access service. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The decision affects 25 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Use digital signatures and trustworthy audit evidence that binds an action to the signer.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Nonrepudiation requires evidence that makes denial of a performed action difficult. It directly addresses Nonrepudiation while accounting for third-party and lifecycle dependencies.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

B: Nonrepudiation requires evidence that makes denial of a performed action difficult. It directly addresses Nonrepudiation while accounting for third-party and lifecycle dependencies.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

Learning point: Use digital signatures and trustworthy audit evidence that binds an action to the signer. Nonrepudiation requires evidence that makes denial of a performed action difficult.

Question 7

Fourth Coffee is revising controls for its customer identity platform. A review highlights Alignment of security to business strategy, goals, mission, and objectives. The security governance lead must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The decision affects 42 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: A

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Alignment of security to business strategy, goals, mission, and objectives while maintaining the organization’s stated risk appetite.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Alignment of security to business strategy, goals, mission, and objectives while maintaining the organization’s stated risk appetite.

B: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 8

An auditor asks Consolidated Messenger to demonstrate how it handles Organizational processes such as acquisitions, divestitures, and governance committees in the data analytics lake. The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The decision affects 59 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.

Correct answer: B

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational processes such as acquisitions, divestitures, and governance committees while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational processes such as acquisitions, divestitures, and governance committees while meeting the business objective with the least unnecessary operational complexity.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 9

After a business change, Proseware Labs discovers that Organizational roles and responsibilities is not handled consistently for the branch-office network. The application security architect needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The decision affects 76 business processes and has a named executive risk owner.

  1. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: D

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational roles and responsibilities while keeping the control sustainable for normal operations.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational roles and responsibilities while keeping the control sustainable for normal operations.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 10

Southridge Media is preparing a security decision for the industrial control network. The decision involves Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The decision affects 93 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP while ensuring the decision can be repeated consistently across business units.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP while ensuring the decision can be repeated consistently across business units.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 11

During a risk workshop for the research data repository, the team identifies Due care and due diligence as the deciding issue. The security governance lead is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The decision affects 19 business processes and has a named executive risk owner.

  1. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: B

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Due care and due diligence while preserving clear accountability and audit evidence.

Option review:

A: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Due care and due diligence while preserving clear accountability and audit evidence.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 12

A control owner at VanArsdel Energy proposes a quick technical fix for ISC2 Code of Professional Ethics in the payment processing service. The IAM architect must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The decision affects 36 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: B

Why: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while protecting sensitive data throughout the change.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while protecting sensitive data throughout the change.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

Learning point: Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern. Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms.

Question 13

Northwind Health is standardizing security across several business units. The software delivery pipeline raises a question about Organizational code of ethics. The application security architect needs to address the control objective while preserving availability of the critical business service. Which action provides the BEST governance and security outcome? The decision affects 53 business processes and has a named executive risk owner.

  1. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses Organizational code of ethics while preserving availability of the critical business service.

Option review:

A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

C: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses Organizational code of ethics while preserving availability of the critical business service.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Organizational code of ethics in this scenario.

Learning point: Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern. Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms.

Question 14

During a third-party onboarding review, Coho Insurance asks the incident response manager to address Confidentiality for its AI-assisted customer service platform. The requirement is to address the control objective without replacing governance with a technology-only shortcut. What should the organization do FIRST? The decision affects 70 business processes and has a named executive risk owner.

  1. Restrict access to authorized subjects and use encryption where disclosure risk exists.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: A

Why: Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property. It directly addresses Confidentiality without replacing governance with a technology-only shortcut.

Option review:

A: Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property. It directly addresses Confidentiality without replacing governance with a technology-only shortcut.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Confidentiality in this scenario.

Learning point: Restrict access to authorized subjects and use encryption where disclosure risk exists. Confidentiality prevents unauthorized disclosure; access control and appropriate encryption directly protect that property.

Question 15

  1. Datum Analytics is revising controls for its global collaboration platform. A review highlights Integrity. The security governance lead must address the control objective while keeping the process defensible to auditors and business owners. Which action is the BEST next step? The decision affects 87 business processes and has a named executive risk owner.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  5. Use integrity validation such as cryptographic hashes or signatures together with controlled write access.

Correct answer: D

Why: Integrity requires detecting or preventing unauthorized modification, not merely hiding the data. It directly addresses Integrity while keeping the process defensible to auditors and business owners.

Option review:

A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Integrity in this scenario.

D: Integrity requires detecting or preventing unauthorized modification, not merely hiding the data. It directly addresses Integrity while keeping the process defensible to auditors and business owners.

Learning point: Use integrity validation such as cryptographic hashes or signatures together with controlled write access. Integrity requires detecting or preventing unauthorized modification, not merely hiding the data.

Question 16

An auditor asks Blue Yonder Airlines to demonstrate how it handles Availability in the e-commerce application. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which response is MOST appropriate? The decision affects 13 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Eliminate critical single points of failure and provide resilient capacity and tested recovery appropriate to the service objective.

Correct answer: D

Why: Availability is protected through resilience, capacity, recovery, and operational readiness. It directly addresses Availability while minimizing irreversible action until facts and authority are established.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Availability in this scenario.

D: Availability is protected through resilience, capacity, recovery, and operational readiness. It directly addresses Availability while minimizing irreversible action until facts and authority are established.

Learning point: Eliminate critical single points of failure and provide resilient capacity and tested recovery appropriate to the service objective. Availability is protected through resilience, capacity, recovery, and operational readiness.

Question 17

After a business change, City Power discovers that Authenticity is not handled consistently for the clinical records environment. The application security architect needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The decision affects 30 business processes and has a named executive risk owner.

  1. Use strong identity proofing and authentication so the origin or actor can be verified.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: A

Why: Authenticity is the assurance that an entity or message is genuine. It directly addresses Authenticity while preserving evidence needed for later review.

Option review:

A: Authenticity is the assurance that an entity or message is genuine. It directly addresses Authenticity while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Authenticity in this scenario.

Learning point: Use strong identity proofing and authentication so the origin or actor can be verified. Authenticity is the assurance that an entity or message is genuine.

Question 18

Tailspin Logistics is preparing a security decision for the remote access service. The decision involves Nonrepudiation. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The decision affects 47 business processes and has a named executive risk owner.

  1. Use digital signatures and trustworthy audit evidence that binds an action to the signer.
  2. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.

Correct answer: A

Why: Nonrepudiation requires evidence that makes denial of a performed action difficult. It directly addresses Nonrepudiation without granting broader privilege than the business need requires.

Option review:

A: Nonrepudiation requires evidence that makes denial of a performed action difficult. It directly addresses Nonrepudiation without granting broader privilege than the business need requires.

B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

D: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Nonrepudiation in this scenario.

Learning point: Use digital signatures and trustworthy audit evidence that binds an action to the signer. Nonrepudiation requires evidence that makes denial of a performed action difficult.

Question 19

During a risk workshop for the customer identity platform, the team identifies Alignment of security to business strategy, goals, mission, and objectives as the deciding issue. The security governance lead is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The decision affects 64 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: A

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Alignment of security to business strategy, goals, mission, and objectives without creating a new single point of failure.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Alignment of security to business strategy, goals, mission, and objectives without creating a new single point of failure.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Alignment of security to business strategy, goals, mission, and objectives in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 20

A control owner at Fabrikam Manufacturing proposes a quick technical fix for Organizational processes such as acquisitions, divestitures, and governance committees in the data analytics lake. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The decision affects 81 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: A

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational processes such as acquisitions, divestitures, and governance committees while ensuring that emergency access cannot become permanent access.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational processes such as acquisitions, divestitures, and governance committees while ensuring that emergency access cannot become permanent access.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Organizational processes such as acquisitions, divestitures, and governance committees in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 21

Trey Research is standardizing security across several business units. The branch-office network raises a question about Organizational roles and responsibilities. The application security architect needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The decision affects 7 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: B

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational roles and responsibilities while allowing independent verification of the control outcome.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Organizational roles and responsibilities while allowing independent verification of the control outcome.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Organizational roles and responsibilities in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 22

During a acquisition integration, Margie Travel asks the incident response manager to address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP for its industrial control network. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The decision affects 24 business processes and has a named executive risk owner.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  3. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: C

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP while accounting for third-party and lifecycle dependencies.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

B: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

C: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP while accounting for third-party and lifecycle dependencies.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Security control frameworks such as ISO, NIST, COBIT, SABSA, PCI, and FedRAMP in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 23

Wide World Importers is revising controls for its research data repository. A review highlights Due care and due diligence. The security governance lead must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The decision affects 41 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  3. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Due care and due diligence while maintaining the organization’s stated risk appetite.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. It directly addresses Due care and due diligence while maintaining the organization’s stated risk appetite.

B: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Due care and due diligence in this scenario.

Learning point: Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details. Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance.

Question 24

An auditor asks Bellows University to demonstrate how it handles ISC2 Code of Professional Ethics in the payment processing service. The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The decision affects 58 business processes and has a named executive risk owner.

  1. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: A

Why: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while meeting the business objective with the least unnecessary operational complexity.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

Learning point: Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern. Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms.

Question 25

After a business change, Litware Services discovers that ISC2 Code of Professional Ethics is not handled consistently for the software delivery pipeline. The application security architect needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The decision affects 75 business processes and has a named executive risk owner.

  1. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: B

Why: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while keeping the control sustainable for normal operations.

Option review:

A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. It directly addresses ISC2 Code of Professional Ethics while keeping the control sustainable for normal operations.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address ISC2 Code of Professional Ethics in this scenario.

Learning point: Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern. Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms.

Popular posts

img