ISC2 CISSP Remote Access Third Party And Secure Communication Channels Practice Test
4 Communication and Network Security • 26 original questions
This CISSP practice test focuses on remote access third party and secure communication channels through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
Lamna Healthcare is revising controls for its e-commerce application. A review highlights Voice, video, and collaboration. The incident response manager must address the control objective while protecting sensitive data throughout the change. Which action is the BEST next step? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while protecting sensitive data throughout the change.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while protecting sensitive data throughout the change.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
An auditor asks Fourth Coffee to demonstrate how it handles Remote access and network administration in the clinical records environment. The security governance lead must address the control objective while preserving availability of the critical business service. Which response is MOST appropriate? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving availability of the critical business service.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving availability of the critical business service.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
After a business change, Consolidated Messenger discovers that Data communications and backhaul networks is not handled consistently for the remote access service. The IAM architect needs to address the control objective without replacing governance with a technology-only shortcut. Which recommendation BEST addresses the issue? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks without replacing governance with a technology-only shortcut.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks without replacing governance with a technology-only shortcut.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Proseware Labs is preparing a security decision for the customer identity platform. The decision involves Third-party connectivity including telecom and hardware support. The application security architect must address the control objective while keeping the process defensible to auditors and business owners. Which option BEST reflects CISSP-level security practice? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while keeping the process defensible to auditors and business owners.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while keeping the process defensible to auditors and business owners.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a risk workshop for the data analytics lake, the team identifies Voice, video, and collaboration as the deciding issue. The incident response manager is expected to address the control objective while minimizing irreversible action until facts and authority are established. What is the MOST appropriate course of action? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while minimizing irreversible action until facts and authority are established.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while minimizing irreversible action until facts and authority are established.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
A control owner at Adventure Works proposes a quick technical fix for Remote access and network administration in the branch-office network. The security governance lead must address the control objective while preserving evidence needed for later review. What should happen FIRST? The environment spans 4 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving evidence needed for later review.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving evidence needed for later review.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
VanArsdel Energy is standardizing security across several business units. The industrial control network raises a question about Data communications and backhaul networks. The IAM architect needs to address the control objective without granting broader privilege than the business need requires. Which action provides the BEST governance and security outcome? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks without granting broader privilege than the business need requires.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks without granting broader privilege than the business need requires.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a business continuity exercise, Northwind Health asks the application security architect to address Third-party connectivity including telecom and hardware support for its research data repository. The requirement is to address the control objective without creating a new single point of failure. What should the organization do FIRST? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support without creating a new single point of failure.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support without creating a new single point of failure.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Coho Insurance is revising controls for its payment processing service. A review highlights Voice, video, and collaboration. The incident response manager must address the control objective while ensuring that emergency access cannot become permanent access. Which action is the BEST next step? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while ensuring that emergency access cannot become permanent access.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while ensuring that emergency access cannot become permanent access.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
An auditor asks A. Datum Analytics to demonstrate how it handles Remote access and network administration in the software delivery pipeline. The security governance lead must address the control objective while allowing independent verification of the control outcome. Which response is MOST appropriate? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while allowing independent verification of the control outcome.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while allowing independent verification of the control outcome.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
After a business change, Blue Yonder Airlines discovers that Voice, video, and collaboration is not handled consistently for the AI-assisted customer service platform. The IAM architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which recommendation BEST addresses the issue? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while accounting for third-party and lifecycle dependencies.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while accounting for third-party and lifecycle dependencies.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
City Power is preparing a security decision for the global collaboration platform. The decision involves Remote access and network administration. The application security architect must address the control objective while maintaining the organization’s stated risk appetite. Which option BEST reflects CISSP-level security practice? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while maintaining the organization’s stated risk appetite.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while maintaining the organization’s stated risk appetite.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a risk workshop for the e-commerce application, the team identifies Data communications and backhaul networks as the deciding issue. The incident response manager is expected to address the control objective while meeting the business objective with the least unnecessary operational complexity. What is the MOST appropriate course of action? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while meeting the business objective with the least unnecessary operational complexity.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
A control owner at Alpine Sports proposes a quick technical fix for Third-party connectivity including telecom and hardware support in the clinical records environment. The security governance lead must address the control objective while keeping the control sustainable for normal operations. What should happen FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while keeping the control sustainable for normal operations.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while keeping the control sustainable for normal operations.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Fabrikam Manufacturing is standardizing security across several business units. The remote access service raises a question about Voice, video, and collaboration. The IAM architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which action provides the BEST governance and security outcome? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while ensuring the decision can be repeated consistently across business units.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration while ensuring the decision can be repeated consistently across business units.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a post-incident improvement program, Trey Research asks the application security architect to address Remote access and network administration for its customer identity platform. The requirement is to address the control objective while preserving clear accountability and audit evidence. What should the organization do FIRST? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving clear accountability and audit evidence.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while preserving clear accountability and audit evidence.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Margie Travel is revising controls for its data analytics lake. A review highlights Data communications and backhaul networks. The incident response manager must address the control objective while protecting sensitive data throughout the change. Which action is the BEST next step? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while protecting sensitive data throughout the change.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while protecting sensitive data throughout the change.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
An auditor asks Wide World Importers to demonstrate how it handles Third-party connectivity including telecom and hardware support in the branch-office network. The security governance lead must address the control objective while preserving availability of the critical business service. Which response is MOST appropriate? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while preserving availability of the critical business service.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while preserving availability of the critical business service.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
After a business change, Bellows University discovers that Voice, video, and collaboration is not handled consistently for the industrial control network. The IAM architect needs to address the control objective without replacing governance with a technology-only shortcut. Which recommendation BEST addresses the issue? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration without replacing governance with a technology-only shortcut.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration without replacing governance with a technology-only shortcut.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Litware Services is preparing a security decision for the research data repository. The decision involves Remote access and network administration. The application security architect must address the control objective while keeping the process defensible to auditors and business owners. Which option BEST reflects CISSP-level security practice? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: A
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while keeping the process defensible to auditors and business owners.
Option review:
A: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration while keeping the process defensible to auditors and business owners.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a risk workshop for the payment processing service, the team identifies Data communications and backhaul networks as the deciding issue. The incident response manager is expected to address the control objective while minimizing irreversible action until facts and authority are established. What is the MOST appropriate course of action? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while minimizing irreversible action until facts and authority are established.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
A control owner at Woodgrove Bank proposes a quick technical fix for Third-party connectivity including telecom and hardware support in the software delivery pipeline. The security governance lead must address the control objective while preserving evidence needed for later review. What should happen FIRST? The environment spans 3 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while preserving evidence needed for later review.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while preserving evidence needed for later review.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Relecloud Systems is standardizing security across several business units. The AI-assisted customer service platform raises a question about Voice, video, and collaboration. The IAM architect needs to address the control objective without granting broader privilege than the business need requires. Which action provides the BEST governance and security outcome? The environment spans 2 network segments and carries both east-west and north-south traffic.
Correct answer: C
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration without granting broader privilege than the business need requires.
Option review:
A: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
C: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Voice, video, and collaboration without granting broader privilege than the business need requires.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Voice, video, and collaboration in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
During a quarterly security review, Contoso Financial asks the application security architect to address Remote access and network administration for its global collaboration platform. The requirement is to address the control objective without creating a new single point of failure. What should the organization do FIRST? The environment spans 7 network segments and carries both east-west and north-south traffic.
Correct answer: D
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
B: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
C: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Remote access and network administration in this scenario.
D: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Remote access and network administration without creating a new single point of failure.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Lucerne Publishing is revising controls for its e-commerce application. A review highlights Data communications and backhaul networks. The incident response manager must address the control objective while ensuring that emergency access cannot become permanent access. Which action is the BEST next step? The environment spans 6 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while ensuring that emergency access cannot become permanent access.
Option review:
A: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Data communications and backhaul networks while ensuring that emergency access cannot become permanent access.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data communications and backhaul networks in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
An auditor asks Lamna Healthcare to demonstrate how it handles Third-party connectivity including telecom and hardware support in the clinical records environment. The security governance lead must address the control objective while allowing independent verification of the control outcome. Which response is MOST appropriate? The environment spans 5 network segments and carries both east-west and north-south traffic.
Correct answer: B
Why: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while allowing independent verification of the control outcome.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
B: Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection. It directly addresses Third-party connectivity including telecom and hardware support while allowing independent verification of the control outcome.
C: Secure network architecture combines protocol security, segmentation, resilient design, and monitoring rather than relying on a single perimeter. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
D: Compromised infrastructure or media can bypass higher-level controls, so components require lifecycle security and physical as well as logical protection. That action can be useful in a different security decision, but it does not most directly address Third-party connectivity including telecom and hardware support in this scenario.
Learning point: Use authenticated, encrypted, least-privilege communication channels for remote, third-party, voice/video, and data links, with explicit trust boundaries and monitoring. Secure channels must protect confidentiality and integrity while limiting who and what can traverse the connection.
Popular posts
Recent Posts
