ISC2 CISSP Legal Regulatory Investigations And Security Policy Practice Test
1 Security and Risk Management • 25 original questions
This CISSP practice test focuses on legal regulatory investigations and security policy through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
During a risk workshop for the remote access service, the team identifies Import and export controls as the deciding issue. The security architect is expected to address the control objective while accounting for third-party and lifecycle dependencies. What is the MOST appropriate course of action? The decision affects 42 business processes and has a named executive risk owner.
Correct answer: C
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Import and export controls while accounting for third-party and lifecycle dependencies.
Option review:
A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Import and export controls while accounting for third-party and lifecycle dependencies.
D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
A control owner at Coho Insurance proposes a quick technical fix for Transborder data flow in the customer identity platform. The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. What should happen FIRST? The decision affects 59 business processes and has a named executive risk owner.
Correct answer: B
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Transborder data flow while maintaining the organization’s stated risk appetite.
Option review:
A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Transborder data flow while maintaining the organization’s stated risk appetite.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
Correct answer: D
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Privacy requirements such as GDPR, CCPA, PIPL, and PIPA while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Privacy requirements such as GDPR, CCPA, PIPL, and PIPA while meeting the business objective with the least unnecessary operational complexity.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
During a network segmentation redesign, Blue Yonder Airlines asks the privacy and compliance lead to address Contractual, legal, industry-standard, and regulatory requirements for its branch-office network. The requirement is to address the control objective while keeping the control sustainable for normal operations. What should the organization do FIRST? The decision affects 93 business processes and has a named executive risk owner.
Correct answer: C
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Contractual, legal, industry-standard, and regulatory requirements while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Contractual, legal, industry-standard, and regulatory requirements while keeping the control sustainable for normal operations.
D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
City Power is revising controls for its industrial control network. A review highlights Administrative investigations. The security architect must address the control objective while ensuring the decision can be repeated consistently across business units. Which action is the BEST next step? The decision affects 19 business processes and has a named executive risk owner.
Correct answer: A
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Administrative investigations while ensuring the decision can be repeated consistently across business units.
Option review:
A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Administrative investigations while ensuring the decision can be repeated consistently across business units.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
An auditor asks Tailspin Logistics to demonstrate how it handles Criminal investigations in the research data repository. The security operations manager must address the control objective while preserving clear accountability and audit evidence. Which response is MOST appropriate? The decision affects 36 business processes and has a named executive risk owner.
Correct answer: C
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Criminal investigations while preserving clear accountability and audit evidence.
Option review:
A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
C: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Criminal investigations while preserving clear accountability and audit evidence.
D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
After a business change, Alpine Sports discovers that Civil investigations is not handled consistently for the payment processing service. The business continuity lead needs to address the control objective while protecting sensitive data throughout the change. Which recommendation BEST addresses the issue? The decision affects 53 business processes and has a named executive risk owner.
Correct answer: C
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Civil investigations while protecting sensitive data throughout the change.
Option review:
A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
C: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Civil investigations while protecting sensitive data throughout the change.
D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
Fabrikam Manufacturing is preparing a security decision for the software delivery pipeline. The decision involves Regulatory investigations. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. Which option BEST reflects CISSP-level security practice? The decision affects 70 business processes and has a named executive risk owner.
Correct answer: B
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Regulatory investigations while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Regulatory investigations while preserving availability of the critical business service.
C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
D: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
During a risk workshop for the AI-assisted customer service platform, the team identifies Industry-standard investigations as the deciding issue. The security architect is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The decision affects 87 business processes and has a named executive risk owner.
Correct answer: B
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Industry-standard investigations without replacing governance with a technology-only shortcut.
Option review:
A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Industry-standard investigations in this scenario.
B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Industry-standard investigations without replacing governance with a technology-only shortcut.
C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Industry-standard investigations in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Industry-standard investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
A control owner at Margie Travel proposes a quick technical fix for Security policy in the global collaboration platform. The security operations manager must address the control objective while keeping the process defensible to auditors and business owners. What should happen FIRST? The decision affects 13 business processes and has a named executive risk owner.
Correct answer: C
Why: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Security policy while keeping the process defensible to auditors and business owners.
Option review:
A: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Security policy in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Security policy in this scenario.
C: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Security policy while keeping the process defensible to auditors and business owners.
D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Security policy in this scenario.
Learning point: Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices. A clear document hierarchy turns governance intent into consistent, auditable execution.
Wide World Importers is standardizing security across several business units. The e-commerce application raises a question about Standards. The business continuity lead needs to address the control objective while minimizing irreversible action until facts and authority are established. Which action provides the BEST governance and security outcome? The decision affects 30 business processes and has a named executive risk owner.
Correct answer: C
Why: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Standards while minimizing irreversible action until facts and authority are established.
Option review:
A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Standards in this scenario.
B: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Standards in this scenario.
C: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Standards while minimizing irreversible action until facts and authority are established.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Standards in this scenario.
Learning point: Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices. A clear document hierarchy turns governance intent into consistent, auditable execution.
During a data-governance workshop, Bellows University asks the privacy and compliance lead to address Procedures for its clinical records environment. The requirement is to address the control objective while preserving evidence needed for later review. What should the organization do FIRST? The decision affects 47 business processes and has a named executive risk owner.
Correct answer: D
Why: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Procedures while preserving evidence needed for later review.
Option review:
A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Procedures in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Procedures in this scenario.
C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Procedures in this scenario.
D: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Procedures while preserving evidence needed for later review.
Learning point: Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices. A clear document hierarchy turns governance intent into consistent, auditable execution.
Litware Services is revising controls for its remote access service. A review highlights Guidelines. The security architect must address the control objective without granting broader privilege than the business need requires. Which action is the BEST next step? The decision affects 64 business processes and has a named executive risk owner.
Correct answer: A
Why: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Guidelines without granting broader privilege than the business need requires.
Option review:
A: A clear document hierarchy turns governance intent into consistent, auditable execution. It directly addresses Guidelines without granting broader privilege than the business need requires.
B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Guidelines in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Guidelines in this scenario.
D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Guidelines in this scenario.
Learning point: Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices. A clear document hierarchy turns governance intent into consistent, auditable execution.
An auditor asks Humongous Insurance to demonstrate how it handles Cybercrimes and data breaches in the customer identity platform. The security operations manager must address the control objective without creating a new single point of failure. Which response is MOST appropriate? The decision affects 81 business processes and has a named executive risk owner.
Correct answer: B
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Cybercrimes and data breaches without creating a new single point of failure.
Option review:
A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Cybercrimes and data breaches without creating a new single point of failure.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
After a business change, Woodgrove Bank discovers that Licensing and intellectual property requirements is not handled consistently for the data analytics lake. The business continuity lead needs to address the control objective while ensuring that emergency access cannot become permanent access. Which recommendation BEST addresses the issue? The decision affects 7 business processes and has a named executive risk owner.
Correct answer: B
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Licensing and intellectual property requirements while ensuring that emergency access cannot become permanent access.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Licensing and intellectual property requirements while ensuring that emergency access cannot become permanent access.
C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
D: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
Relecloud Systems is preparing a security decision for the branch-office network. The decision involves Import and export controls. The privacy and compliance lead must address the control objective while allowing independent verification of the control outcome. Which option BEST reflects CISSP-level security practice? The decision affects 24 business processes and has a named executive risk owner.
Correct answer: B
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Import and export controls while allowing independent verification of the control outcome.
Option review:
A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Import and export controls while allowing independent verification of the control outcome.
C: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Import and export controls in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
During a risk workshop for the industrial control network, the team identifies Transborder data flow as the deciding issue. The security architect is expected to address the control objective while accounting for third-party and lifecycle dependencies. What is the MOST appropriate course of action? The decision affects 41 business processes and has a named executive risk owner.
Correct answer: D
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Transborder data flow while accounting for third-party and lifecycle dependencies.
Option review:
A: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
C: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Transborder data flow in this scenario.
D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Transborder data flow while accounting for third-party and lifecycle dependencies.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
A control owner at Lucerne Publishing proposes a quick technical fix for Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in the research data repository. The security operations manager must address the control objective while maintaining the organization’s stated risk appetite. What should happen FIRST? The decision affects 58 business processes and has a named executive risk owner.
Correct answer: D
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Privacy requirements such as GDPR, CCPA, PIPL, and PIPA while maintaining the organization’s stated risk appetite.
Option review:
A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Privacy requirements such as GDPR, CCPA, PIPL, and PIPA in this scenario.
D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Privacy requirements such as GDPR, CCPA, PIPL, and PIPA while maintaining the organization’s stated risk appetite.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
Lamna Healthcare is standardizing security across several business units. The payment processing service raises a question about Contractual, legal, industry-standard, and regulatory requirements. The business continuity lead needs to address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action provides the BEST governance and security outcome? The decision affects 75 business processes and has a named executive risk owner.
Correct answer: B
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Contractual, legal, industry-standard, and regulatory requirements while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Contractual, legal, industry-standard, and regulatory requirements while meeting the business objective with the least unnecessary operational complexity.
C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Contractual, legal, industry-standard, and regulatory requirements in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
During a regulatory readiness assessment, Fourth Coffee asks the privacy and compliance lead to address Administrative investigations for its software delivery pipeline. The requirement is to address the control objective while keeping the control sustainable for normal operations. What should the organization do FIRST? The decision affects 92 business processes and has a named executive risk owner.
Correct answer: B
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Administrative investigations while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Administrative investigations while keeping the control sustainable for normal operations.
C: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Administrative investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
Consolidated Messenger is revising controls for its AI-assisted customer service platform. A review highlights Criminal investigations. The security architect must address the control objective while ensuring the decision can be repeated consistently across business units. Which action is the BEST next step? The decision affects 18 business processes and has a named executive risk owner.
Correct answer: A
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Criminal investigations while ensuring the decision can be repeated consistently across business units.
Option review:
A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Criminal investigations while ensuring the decision can be repeated consistently across business units.
B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Criminal investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
An auditor asks Proseware Labs to demonstrate how it handles Civil investigations in the global collaboration platform. The security operations manager must address the control objective while preserving clear accountability and audit evidence. Which response is MOST appropriate? The decision affects 35 business processes and has a named executive risk owner.
Correct answer: D
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Civil investigations while preserving clear accountability and audit evidence.
Option review:
A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
C: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Civil investigations in this scenario.
D: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Civil investigations while preserving clear accountability and audit evidence.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
After a business change, Southridge Media discovers that Regulatory investigations is not handled consistently for the e-commerce application. The business continuity lead needs to address the control objective while protecting sensitive data throughout the change. Which recommendation BEST addresses the issue? The decision affects 52 business processes and has a named executive risk owner.
Correct answer: A
Why: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Regulatory investigations while protecting sensitive data throughout the change.
Option review:
A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. It directly addresses Regulatory investigations while protecting sensitive data throughout the change.
B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Regulatory investigations in this scenario.
Learning point: Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action. Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations.
Adventure Works is preparing a security decision for the clinical records environment. The decision involves Cybercrimes and data breaches. The privacy and compliance lead must address the control objective while preserving availability of the critical business service. Which option BEST reflects CISSP-level security practice? The decision affects 69 business processes and has a named executive risk owner.
Correct answer: C
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Cybercrimes and data breaches while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Cybercrimes and data breaches while preserving availability of the critical business service.
D: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Cybercrimes and data breaches in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
During a risk workshop for the remote access service, the team identifies Licensing and intellectual property requirements as the deciding issue. The security architect is expected to address the control objective without replacing governance with a technology-only shortcut. What is the MOST appropriate course of action? The decision affects 86 business processes and has a named executive risk owner.
Correct answer: A
Why: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Licensing and intellectual property requirements without replacing governance with a technology-only shortcut.
Option review:
A: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. It directly addresses Licensing and intellectual property requirements without replacing governance with a technology-only shortcut.
B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Licensing and intellectual property requirements in this scenario.
Learning point: Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed. Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation.
Popular posts
Recent Posts
