ISC2 CISSP Business Continuity And Personnel Security Practice Test

 

1 Security and Risk Management • 25 original questions

This CISSP practice test focuses on business continuity and personnel security through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Litware Services is standardizing security across several business units. The research data repository raises a question about Employment agreements and policy-driven requirements. The security assurance manager needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The decision affects 53 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.

Correct answer: A

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving clear accountability and audit evidence.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving clear accountability and audit evidence.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

D: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 2

During a internal audit response, Humongous Insurance asks the enterprise security engineer to address Onboarding, transfers, and termination processes for its payment processing service. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The decision affects 70 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: D

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes while protecting sensitive data throughout the change.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes while protecting sensitive data throughout the change.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 3

Woodgrove Bank is revising controls for its software delivery pipeline. A review highlights Vendor, consultant, and contractor agreements and controls. The chief information security officer must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The decision affects 87 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: D

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while preserving availability of the critical business service.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

C: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while preserving availability of the critical business service.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 4

An auditor asks Relecloud Systems to demonstrate how it handles Business impact analysis (BIA) in the AI-assisted customer service platform. The risk manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The decision affects 13 business processes and has a named executive risk owner.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.

Correct answer: B

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) without replacing governance with a technology-only shortcut.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

B: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) without replacing governance with a technology-only shortcut.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 5

After a business change, Contoso Financial discovers that External dependencies is not handled consistently for the global collaboration platform. The security assurance manager needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The decision affects 30 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: C

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while keeping the process defensible to auditors and business owners.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while keeping the process defensible to auditors and business owners.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 6

Lucerne Publishing is preparing a security decision for the e-commerce application. The decision involves Candidate screening and hiring. The enterprise security engineer must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The decision affects 47 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: A

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while minimizing irreversible action until facts and authority are established.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while minimizing irreversible action until facts and authority are established.

B: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 7

During a risk workshop for the clinical records environment, the team identifies Employment agreements and policy-driven requirements as the deciding issue. The chief information security officer is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The decision affects 64 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: A

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving evidence needed for later review.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving evidence needed for later review.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 8

A control owner at Fourth Coffee proposes a quick technical fix for Onboarding, transfers, and termination processes in the remote access service. The risk manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The decision affects 81 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes without granting broader privilege than the business need requires.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes without granting broader privilege than the business need requires.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 9

Consolidated Messenger is standardizing security across several business units. The customer identity platform raises a question about Vendor, consultant, and contractor agreements and controls. The security assurance manager needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The decision affects 7 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls without creating a new single point of failure.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls without creating a new single point of failure.

C: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 10

During a identity modernization project, Proseware Labs asks the enterprise security engineer to address Business impact analysis (BIA) for its data analytics lake. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The decision affects 24 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: C

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while ensuring that emergency access cannot become permanent access.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while ensuring that emergency access cannot become permanent access.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 11

Southridge Media is revising controls for its branch-office network. A review highlights External dependencies. The chief information security officer must address the control objective while allowing independent verification of the control outcome. Which action is the BEST next step? The decision affects 41 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.

Correct answer: A

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while allowing independent verification of the control outcome.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while allowing independent verification of the control outcome.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 12

An auditor asks Adventure Works to demonstrate how it handles Candidate screening and hiring in the industrial control network. The risk manager must address the control objective while accounting for third-party and lifecycle dependencies. Which response is MOST appropriate? The decision affects 58 business processes and has a named executive risk owner.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while accounting for third-party and lifecycle dependencies.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while accounting for third-party and lifecycle dependencies.

C: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 13

After a business change, VanArsdel Energy discovers that Employment agreements and policy-driven requirements is not handled consistently for the research data repository. The security assurance manager needs to address the control objective while maintaining the organization’s stated risk appetite. Which recommendation BEST addresses the issue? The decision affects 75 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: C

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while maintaining the organization’s stated risk appetite.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

B: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while maintaining the organization’s stated risk appetite.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 14

Northwind Health is preparing a security decision for the payment processing service. The decision involves Onboarding, transfers, and termination processes. The enterprise security engineer must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which option BEST reflects CISSP-level security practice? The decision affects 92 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes while meeting the business objective with the least unnecessary operational complexity.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 15

During a risk workshop for the software delivery pipeline, the team identifies Vendor, consultant, and contractor agreements and controls as the deciding issue. The chief information security officer is expected to address the control objective while keeping the control sustainable for normal operations. What is the MOST appropriate course of action? The decision affects 18 business processes and has a named executive risk owner.

  1. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while keeping the control sustainable for normal operations.

Option review:

A: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while keeping the control sustainable for normal operations.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 16

A control owner at A. Datum Analytics proposes a quick technical fix for Business impact analysis (BIA) in the AI-assisted customer service platform. The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. What should happen FIRST? The decision affects 35 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.

Correct answer: D

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while ensuring the decision can be repeated consistently across business units.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

D: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while ensuring the decision can be repeated consistently across business units.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 17

Blue Yonder Airlines is standardizing security across several business units. The global collaboration platform raises a question about External dependencies. The security assurance manager needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The decision affects 52 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: A

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while preserving clear accountability and audit evidence.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies while preserving clear accountability and audit evidence.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 18

During a architecture design review, City Power asks the enterprise security engineer to address Candidate screening and hiring for its e-commerce application. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The decision affects 69 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring while protecting sensitive data throughout the change.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 19

Tailspin Logistics is revising controls for its clinical records environment. A review highlights Employment agreements and policy-driven requirements. The chief information security officer must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The decision affects 86 business processes and has a named executive risk owner.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.

Correct answer: B

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Employment agreements and policy-driven requirements while preserving availability of the critical business service.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

D: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Employment agreements and policy-driven requirements in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 20

An auditor asks Alpine Sports to demonstrate how it handles Onboarding, transfers, and termination processes in the remote access service. The risk manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The decision affects 12 business processes and has a named executive risk owner.

  1. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.

Correct answer: C

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes without replacing governance with a technology-only shortcut.

Option review:

A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Onboarding, transfers, and termination processes without replacing governance with a technology-only shortcut.

D: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Onboarding, transfers, and termination processes in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 21

After a business change, Fabrikam Manufacturing discovers that Vendor, consultant, and contractor agreements and controls is not handled consistently for the customer identity platform. The security assurance manager needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The decision affects 29 business processes and has a named executive risk owner.

  1. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Identify the security property the business requirement depends on, then select controls that directly protect that property.

Correct answer: A

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while keeping the process defensible to auditors and business owners.

Option review:

A: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Vendor, consultant, and contractor agreements and controls while keeping the process defensible to auditors and business owners.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

D: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Vendor, consultant, and contractor agreements and controls in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Question 22

Trey Research is preparing a security decision for the data analytics lake. The decision involves Business impact analysis (BIA). The enterprise security engineer must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The decision affects 46 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: A

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while minimizing irreversible action until facts and authority are established.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while minimizing irreversible action until facts and authority are established.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 23

During a risk workshop for the branch-office network, the team identifies Business impact analysis (BIA) as the deciding issue. The chief information security officer is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The decision affects 63 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  4. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.

Correct answer: A

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while preserving evidence needed for later review.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses Business impact analysis (BIA) while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

C: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

D: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Business impact analysis (BIA) in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 24

A control owner at Wide World Importers proposes a quick technical fix for External dependencies in the industrial control network. The risk manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The decision affects 80 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: A

Why: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies without granting broader privilege than the business need requires.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. It directly addresses External dependencies without granting broader privilege than the business need requires.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address External dependencies in this scenario.

Learning point: Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions. Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology.

Question 25

Bellows University is standardizing security across several business units. The research data repository raises a question about Candidate screening and hiring. The security assurance manager needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The decision affects 6 business processes and has a named executive risk owner.

  1. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring without creating a new single point of failure.

Option review:

A: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

C: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. It directly addresses Candidate screening and hiring without creating a new single point of failure.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Candidate screening and hiring in this scenario.

Learning point: Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes. Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle.

Popular posts

img