ISC2 CISSP Facility Security And Information System Lifecycle Practice Test
3 Security Architecture and Engineering • 26 original questions
This CISSP practice test focuses on facility security and information system lifecycle through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Consolidated Messenger is revising controls for its data analytics lake. A review highlights Architectural design. The risk manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The architecture contains 61 separately managed trust zones or platform components.
Correct answer: D
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Architectural design while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Architectural design in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Architectural design in this scenario.
C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Architectural design in this scenario.
D: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Architectural design while meeting the business objective with the least unnecessary operational complexity.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
An auditor asks Proseware Labs to demonstrate how it handles Development and implementation in the branch-office network. The security assurance manager must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The architecture contains 78 separately managed trust zones or platform components.
Correct answer: C
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Development and implementation while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Development and implementation in this scenario.
B: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Development and implementation in this scenario.
C: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Development and implementation while keeping the control sustainable for normal operations.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Development and implementation in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
After a business change, Southridge Media discovers that Integration is not handled consistently for the industrial control network. The enterprise security engineer needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The architecture contains 4 separately managed trust zones or platform components.
Correct answer: A
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Integration while ensuring the decision can be repeated consistently across business units.
Option review:
A: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Integration while ensuring the decision can be repeated consistently across business units.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Integration in this scenario.
C: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Integration in this scenario.
D: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Integration in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
Adventure Works is preparing a security decision for the research data repository. The decision involves Verification and validation. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The architecture contains 21 separately managed trust zones or platform components.
Correct answer: C
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Verification and validation while preserving clear accountability and audit evidence.
Option review:
A: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Verification and validation in this scenario.
B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Verification and validation in this scenario.
C: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Verification and validation while preserving clear accountability and audit evidence.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Verification and validation in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
During a risk workshop for the payment processing service, the team identifies Transition and deployment as the deciding issue. The risk manager is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The architecture contains 38 separately managed trust zones or platform components.
Correct answer: B
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Transition and deployment while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Transition and deployment in this scenario.
B: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Transition and deployment while protecting sensitive data throughout the change.
C: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Transition and deployment in this scenario.
D: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Transition and deployment in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
A control owner at Northwind Health proposes a quick technical fix for Operations and maintenance/sustainment in the software delivery pipeline. The security assurance manager must address the control objective while preserving availability of the critical business service. What should happen FIRST? The architecture contains 55 separately managed trust zones or platform components.
Correct answer: D
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Operations and maintenance/sustainment while preserving availability of the critical business service.
Option review:
A: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Operations and maintenance/sustainment in this scenario.
B: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Operations and maintenance/sustainment in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Operations and maintenance/sustainment in this scenario.
D: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Operations and maintenance/sustainment while preserving availability of the critical business service.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
Coho Insurance is standardizing security across several business units. The AI-assisted customer service platform raises a question about Retirement and disposal. The enterprise security engineer needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The architecture contains 72 separately managed trust zones or platform components.
Correct answer: D
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Retirement and disposal without replacing governance with a technology-only shortcut.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Retirement and disposal in this scenario.
B: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Retirement and disposal in this scenario.
C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Retirement and disposal in this scenario.
D: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Retirement and disposal without replacing governance with a technology-only shortcut.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
During a business continuity exercise, A. Datum Analytics asks the chief information security officer to address Site selection and facility design security principles for its global collaboration platform. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The architecture contains 89 separately managed trust zones or platform components.
Correct answer: B
Why: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. It directly addresses Site selection and facility design security principles while keeping the process defensible to auditors and business owners.
Option review:
A: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
B: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. It directly addresses Site selection and facility design security principles while keeping the process defensible to auditors and business owners.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
D: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
Learning point: Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response. Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality.
Blue Yonder Airlines is revising controls for its e-commerce application. A review highlights Wiring closets and intermediate distribution facilities. The risk manager must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The architecture contains 15 separately managed trust zones or platform components.
Correct answer: C
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Wiring closets and intermediate distribution facilities while minimizing irreversible action until facts and authority are established.
Option review:
A: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
C: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Wiring closets and intermediate distribution facilities while minimizing irreversible action until facts and authority are established.
D: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
An auditor asks City Power to demonstrate how it handles Server rooms and data centers in the clinical records environment. The security assurance manager must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The architecture contains 32 separately managed trust zones or platform components.
Correct answer: A
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Server rooms and data centers while preserving evidence needed for later review.
Option review:
A: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Server rooms and data centers while preserving evidence needed for later review.
B: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
D: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
After a business change, Tailspin Logistics discovers that Media storage facilities is not handled consistently for the remote access service. The enterprise security engineer needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The architecture contains 49 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Media storage facilities without granting broader privilege than the business need requires.
Option review:
A: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
B: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Media storage facilities without granting broader privilege than the business need requires.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Alpine Sports is preparing a security decision for the customer identity platform. The decision involves Evidence storage. The chief information security officer must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The architecture contains 66 separately managed trust zones or platform components.
Correct answer: B
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Evidence storage without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
B: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Evidence storage without creating a new single point of failure.
C: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
D: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
During a risk workshop for the data analytics lake, the team identifies Restricted and work-area security as the deciding issue. The risk manager is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The architecture contains 83 separately managed trust zones or platform components.
Correct answer: C
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Restricted and work-area security while ensuring that emergency access cannot become permanent access.
Option review:
A: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
B: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
C: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Restricted and work-area security while ensuring that emergency access cannot become permanent access.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
A control owner at Trey Research proposes a quick technical fix for Utilities and HVAC in the branch-office network. The security assurance manager must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The architecture contains 9 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Utilities and HVAC while allowing independent verification of the control outcome.
Option review:
A: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
B: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Utilities and HVAC while allowing independent verification of the control outcome.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Margie Travel is standardizing security across several business units. The industrial control network raises a question about Site selection and facility design security principles. The enterprise security engineer needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The architecture contains 26 separately managed trust zones or platform components.
Correct answer: D
Why: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. It directly addresses Site selection and facility design security principles while accounting for third-party and lifecycle dependencies.
Option review:
A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Site selection and facility design security principles in this scenario.
D: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. It directly addresses Site selection and facility design security principles while accounting for third-party and lifecycle dependencies.
Learning point: Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response. Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality.
During a post-incident improvement program, Wide World Importers asks the chief information security officer to address Wiring closets and intermediate distribution facilities for its research data repository. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The architecture contains 43 separately managed trust zones or platform components.
Correct answer: A
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Wiring closets and intermediate distribution facilities while maintaining the organization’s stated risk appetite.
Option review:
A: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Wiring closets and intermediate distribution facilities while maintaining the organization’s stated risk appetite.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
C: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
D: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Wiring closets and intermediate distribution facilities in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Bellows University is revising controls for its payment processing service. A review highlights Server rooms and data centers. The risk manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The architecture contains 60 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Server rooms and data centers while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
C: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Server rooms and data centers in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Server rooms and data centers while meeting the business objective with the least unnecessary operational complexity.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
An auditor asks Litware Services to demonstrate how it handles Media storage facilities in the software delivery pipeline. The security assurance manager must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The architecture contains 77 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Media storage facilities while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
C: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Media storage facilities in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Media storage facilities while keeping the control sustainable for normal operations.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
After a business change, Humongous Insurance discovers that Evidence storage is not handled consistently for the AI-assisted customer service platform. The enterprise security engineer needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The architecture contains 3 separately managed trust zones or platform components.
Correct answer: B
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Evidence storage while ensuring the decision can be repeated consistently across business units.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
B: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Evidence storage while ensuring the decision can be repeated consistently across business units.
C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
D: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Evidence storage in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Woodgrove Bank is preparing a security decision for the global collaboration platform. The decision involves Restricted and work-area security. The chief information security officer must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The architecture contains 20 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Restricted and work-area security while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
B: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
C: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Restricted and work-area security in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Restricted and work-area security while preserving clear accountability and audit evidence.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
During a risk workshop for the e-commerce application, the team identifies Utilities and HVAC as the deciding issue. The risk manager is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The architecture contains 37 separately managed trust zones or platform components.
Correct answer: A
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Utilities and HVAC while protecting sensitive data throughout the change.
Option review:
A: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Utilities and HVAC while protecting sensitive data throughout the change.
B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
D: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Utilities and HVAC in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
A control owner at Contoso Financial proposes a quick technical fix for Natural and man-made environmental issues in the clinical records environment. The security assurance manager must address the control objective while preserving availability of the critical business service. What should happen FIRST? The architecture contains 54 separately managed trust zones or platform components.
Correct answer: C
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Natural and man-made environmental issues while preserving availability of the critical business service.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Natural and man-made environmental issues in this scenario.
B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Natural and man-made environmental issues in this scenario.
C: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Natural and man-made environmental issues while preserving availability of the critical business service.
D: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Natural and man-made environmental issues in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Lucerne Publishing is standardizing security across several business units. The remote access service raises a question about Fire prevention, detection, and suppression. The enterprise security engineer needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The architecture contains 71 separately managed trust zones or platform components.
Correct answer: D
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Fire prevention, detection, and suppression without replacing governance with a technology-only shortcut.
Option review:
A: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Fire prevention, detection, and suppression in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Fire prevention, detection, and suppression in this scenario.
C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Fire prevention, detection, and suppression in this scenario.
D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Fire prevention, detection, and suppression without replacing governance with a technology-only shortcut.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
During a quarterly security review, Lamna Healthcare asks the chief information security officer to address Redundant and backup power for its customer identity platform. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The architecture contains 88 separately managed trust zones or platform components.
Correct answer: A
Why: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Redundant and backup power while keeping the process defensible to auditors and business owners.
Option review:
A: Data-center security includes environmental resilience and life-safety controls as well as access barriers. It directly addresses Redundant and backup power while keeping the process defensible to auditors and business owners.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Redundant and backup power in this scenario.
C: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Redundant and backup power in this scenario.
D: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Redundant and backup power in this scenario.
Learning point: Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure. Data-center security includes environmental resilience and life-safety controls as well as access barriers.
Fourth Coffee is revising controls for its data analytics lake. A review highlights Stakeholder needs and requirements. The risk manager must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The architecture contains 14 separately managed trust zones or platform components.
Correct answer: B
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Stakeholder needs and requirements while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Stakeholder needs and requirements in this scenario.
B: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Stakeholder needs and requirements while minimizing irreversible action until facts and authority are established.
C: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Stakeholder needs and requirements in this scenario.
D: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Stakeholder needs and requirements in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
An auditor asks Consolidated Messenger to demonstrate how it handles Requirements analysis in the branch-office network. The security assurance manager must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The architecture contains 31 separately managed trust zones or platform components.
Correct answer: A
Why: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Requirements analysis while preserving evidence needed for later review.
Option review:
A: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. It directly addresses Requirements analysis while preserving evidence needed for later review.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Requirements analysis in this scenario.
C: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Requirements analysis in this scenario.
D: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Requirements analysis in this scenario.
Learning point: Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle. Security decisions must be maintained and revalidated as the system moves from requirements through retirement.
Popular posts
Recent Posts
