ISC2 CISSP Network Infrastructure NAC Endpoints And Transmission Media Practice Test
4 Communication and Network Security • 26 original questions
This CISSP practice test focuses on network infrastructure nac endpoints and transmission media through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Alpine Sports is standardizing security across several business units. The research data repository raises a question about Endpoint security. The security assurance manager needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while maintaining the organization’s stated risk appetite.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while maintaining the organization’s stated risk appetite.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a internal audit response, Fabrikam Manufacturing asks the enterprise security engineer to address Infrastructure operation including redundant power, warranty, and support for its payment processing service. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while meeting the business objective with the least unnecessary operational complexity.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Trey Research is revising controls for its software delivery pipeline. A review highlights Transmission media physical security and signal quality. The chief information security officer must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while keeping the control sustainable for normal operations.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while keeping the control sustainable for normal operations.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
An auditor asks Margie Travel to demonstrate how it handles Network Access Control (NAC) in the AI-assisted customer service platform. The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which response is MOST appropriate? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while ensuring the decision can be repeated consistently across business units.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while ensuring the decision can be repeated consistently across business units.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
After a business change, Wide World Importers discovers that Endpoint security is not handled consistently for the global collaboration platform. The security assurance manager needs to address the control objective while preserving clear accountability and audit evidence. Which recommendation BEST addresses the issue? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while preserving clear accountability and audit evidence.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Bellows University is preparing a security decision for the e-commerce application. The decision involves Infrastructure operation including redundant power, warranty, and support. The enterprise security engineer must address the control objective while protecting sensitive data throughout the change. Which option BEST reflects CISSP-level security practice? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while protecting sensitive data throughout the change.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while protecting sensitive data throughout the change.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a risk workshop for the clinical records environment, the team identifies Transmission media physical security and signal quality as the deciding issue. The chief information security officer is expected to address the control objective while preserving availability of the critical business service. What is the MOST appropriate course of action? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving availability of the critical business service.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving availability of the critical business service.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
A control owner at Humongous Insurance proposes a quick technical fix for Network Access Control (NAC) in the remote access service. The risk manager must address the control objective without replacing governance with a technology-only shortcut. What should happen FIRST? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) without replacing governance with a technology-only shortcut.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) without replacing governance with a technology-only shortcut.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Woodgrove Bank is standardizing security across several business units. The customer identity platform raises a question about Endpoint security. The security assurance manager needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while keeping the process defensible to auditors and business owners.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a identity modernization project, Relecloud Systems asks the enterprise security engineer to address Infrastructure operation including redundant power, warranty, and support for its data analytics lake. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while minimizing irreversible action until facts and authority are established.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while minimizing irreversible action until facts and authority are established.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Contoso Financial is revising controls for its branch-office network. A review highlights Transmission media physical security and signal quality. The chief information security officer must address the control objective while preserving evidence needed for later review. Which action is the BEST next step? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving evidence needed for later review.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving evidence needed for later review.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
An auditor asks Lucerne Publishing to demonstrate how it handles Infrastructure operation including redundant power, warranty, and support in the industrial control network. The risk manager must address the control objective without granting broader privilege than the business need requires. Which response is MOST appropriate? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support without granting broader privilege than the business need requires.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support without granting broader privilege than the business need requires.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
After a business change, Lamna Healthcare discovers that Transmission media physical security and signal quality is not handled consistently for the research data repository. The security assurance manager needs to address the control objective without creating a new single point of failure. Which recommendation BEST addresses the issue? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality without creating a new single point of failure.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality without creating a new single point of failure.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Fourth Coffee is preparing a security decision for the payment processing service. The decision involves Network Access Control (NAC). The enterprise security engineer must address the control objective while ensuring that emergency access cannot become permanent access. Which option BEST reflects CISSP-level security practice? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while ensuring that emergency access cannot become permanent access.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while ensuring that emergency access cannot become permanent access.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a risk workshop for the software delivery pipeline, the team identifies Endpoint security as the deciding issue. The chief information security officer is expected to address the control objective while allowing independent verification of the control outcome. What is the MOST appropriate course of action? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while allowing independent verification of the control outcome.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while allowing independent verification of the control outcome.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
A control owner at Proseware Labs proposes a quick technical fix for Infrastructure operation including redundant power, warranty, and support in the AI-assisted customer service platform. The risk manager must address the control objective while accounting for third-party and lifecycle dependencies. What should happen FIRST? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while accounting for third-party and lifecycle dependencies.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while accounting for third-party and lifecycle dependencies.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Southridge Media is standardizing security across several business units. The global collaboration platform raises a question about Transmission media physical security and signal quality. The security assurance manager needs to address the control objective while maintaining the organization’s stated risk appetite. Which action provides the BEST governance and security outcome? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while maintaining the organization’s stated risk appetite.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while maintaining the organization’s stated risk appetite.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a architecture design review, Adventure Works asks the enterprise security engineer to address Network Access Control (NAC) for its e-commerce application. The requirement is to address the control objective while meeting the business objective with the least unnecessary operational complexity. What should the organization do FIRST? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while meeting the business objective with the least unnecessary operational complexity.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
VanArsdel Energy is revising controls for its clinical records environment. A review highlights Endpoint security. The chief information security officer must address the control objective while keeping the control sustainable for normal operations. Which action is the BEST next step? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while keeping the control sustainable for normal operations.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while keeping the control sustainable for normal operations.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
An auditor asks Northwind Health to demonstrate how it handles Infrastructure operation including redundant power, warranty, and support in the remote access service. The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which response is MOST appropriate? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while ensuring the decision can be repeated consistently across business units.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support while ensuring the decision can be repeated consistently across business units.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
After a business change, Coho Insurance discovers that Transmission media physical security and signal quality is not handled consistently for the customer identity platform. The security assurance manager needs to address the control objective while preserving clear accountability and audit evidence. Which recommendation BEST addresses the issue? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while preserving clear accountability and audit evidence.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while protecting sensitive data throughout the change.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while protecting sensitive data throughout the change.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a risk workshop for the branch-office network, the team identifies Endpoint security as the deciding issue. The chief information security officer is expected to address the control objective while preserving availability of the critical business service. What is the MOST appropriate course of action? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while preserving availability of the critical business service.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Endpoint security while preserving availability of the critical business service.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Endpoint security in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
A control owner at City Power proposes a quick technical fix for Infrastructure operation including redundant power, warranty, and support in the industrial control network. The risk manager must address the control objective without replacing governance with a technology-only shortcut. What should happen FIRST? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support without replacing governance with a technology-only shortcut.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Infrastructure operation including redundant power, warranty, and support without replacing governance with a technology-only shortcut.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Infrastructure operation including redundant power, warranty, and support in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Tailspin Logistics is standardizing security across several business units. The research data repository raises a question about Transmission media physical security and signal quality. The security assurance manager needs to address the control objective while keeping the process defensible to auditors and business owners. Which action provides the BEST governance and security outcome? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Transmission media physical security and signal quality while keeping the process defensible to auditors and business owners.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Transmission media physical security and signal quality in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
During a internal audit response, Alpine Sports asks the enterprise security engineer to address Network Access Control (NAC) for its payment processing service. The requirement is to address the control objective while minimizing irreversible action until facts and authority are established. What should the organization do FIRST? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. It directly addresses Network Access Control (NAC) while minimizing irreversible action until facts and authority are established.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Network Access Control (NAC) in this scenario.
Learning point: Harden and maintain network infrastructure, protect transmission media, enforce network access control, and secure endpoints as managed components. Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection.
Popular posts
Recent Posts
