ISC2 CISSP Physical And Logical Access To Information Systems And Services Practice Test

 

5 Identity and Access Management (IAM) • 26 original questions

This CISSP practice test focuses on physical and logical access to information systems and services through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

After a business change, Tailspin Logistics discovers that Facility access is not handled consistently for the branch-office network. The security operations manager needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The identity population includes 2,500 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: A

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while preserving evidence needed for later review.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while preserving evidence needed for later review.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 2

Alpine Sports is preparing a security decision for the industrial control network. The decision involves Application access. The business continuity lead must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The identity population includes 4,200 workforce, service, or device identities.

  1. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access without granting broader privilege than the business need requires.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access without granting broader privilege than the business need requires.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 3

During a risk workshop for the research data repository, the team identifies Service access as the deciding issue. The privacy and compliance lead is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The identity population includes 5,900 workforce, service, or device identities.

  1. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: C

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access without creating a new single point of failure.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access without creating a new single point of failure.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 4

A control owner at Trey Research proposes a quick technical fix for Authentication system implementation in the payment processing service. The security architect must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The identity population includes 7,600 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while ensuring that emergency access cannot become permanent access.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

B: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while ensuring that emergency access cannot become permanent access.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

Learning point: Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse. Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring.

Question 5

Margie Travel is standardizing security across several business units. The software delivery pipeline raises a question about Information access. The security operations manager needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The identity population includes 9,300 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while allowing independent verification of the control outcome.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while allowing independent verification of the control outcome.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 6

During a secure software initiative, Wide World Importers asks the business continuity lead to address Systems access for its AI-assisted customer service platform. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The identity population includes 1,900 workforce, service, or device identities.

  1. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while accounting for third-party and lifecycle dependencies.

Option review:

A: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while accounting for third-party and lifecycle dependencies.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 7

Bellows University is revising controls for its global collaboration platform. A review highlights Device access. The privacy and compliance lead must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The identity population includes 3,600 workforce, service, or device identities.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: C

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while maintaining the organization’s stated risk appetite.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while maintaining the organization’s stated risk appetite.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 8

An auditor asks Litware Services to demonstrate how it handles Facility access in the e-commerce application. The security architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The identity population includes 5,300 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while meeting the business objective with the least unnecessary operational complexity.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 9

After a business change, Humongous Insurance discovers that Application access is not handled consistently for the clinical records environment. The security operations manager needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The identity population includes 7,000 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access while keeping the control sustainable for normal operations.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access while keeping the control sustainable for normal operations.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 10

Woodgrove Bank is preparing a security decision for the remote access service. The decision involves Information access. The business continuity lead must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The identity population includes 8,700 workforce, service, or device identities.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while ensuring the decision can be repeated consistently across business units.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while ensuring the decision can be repeated consistently across business units.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 11

During a risk workshop for the customer identity platform, the team identifies Systems access as the deciding issue. The privacy and compliance lead is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The identity population includes 1,300 workforce, service, or device identities.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while preserving clear accountability and audit evidence.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while preserving clear accountability and audit evidence.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

D: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 12

A control owner at Contoso Financial proposes a quick technical fix for Device access in the data analytics lake. The security architect must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The identity population includes 3,000 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while protecting sensitive data throughout the change.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 13

Lucerne Publishing is standardizing security across several business units. The branch-office network raises a question about Facility access. The security operations manager needs to address the control objective while preserving availability of the critical business service. Which action provides the BEST governance and security outcome? The identity population includes 4,700 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while preserving availability of the critical business service.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while preserving availability of the critical business service.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 14

During a third-party onboarding review, Lamna Healthcare asks the business continuity lead to address Application access for its industrial control network. The requirement is to address the control objective without replacing governance with a technology-only shortcut. What should the organization do FIRST? The identity population includes 6,400 workforce, service, or device identities.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access without replacing governance with a technology-only shortcut.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access without replacing governance with a technology-only shortcut.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 15

Fourth Coffee is revising controls for its research data repository. A review highlights Service access. The privacy and compliance lead must address the control objective while keeping the process defensible to auditors and business owners. Which action is the BEST next step? The identity population includes 8,100 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access while keeping the process defensible to auditors and business owners.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access while keeping the process defensible to auditors and business owners.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 16

An auditor asks Consolidated Messenger to demonstrate how it handles Authentication system implementation in the payment processing service. The security architect must address the control objective while minimizing irreversible action until facts and authority are established. Which response is MOST appropriate? The identity population includes 700 workforce, service, or device identities.

  1. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.

Correct answer: D

Why: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while minimizing irreversible action until facts and authority are established.

Option review:

A: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while minimizing irreversible action until facts and authority are established.

Learning point: Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse. Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring.

Question 17

After a business change, Proseware Labs discovers that Information access is not handled consistently for the software delivery pipeline. The security operations manager needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The identity population includes 2,400 workforce, service, or device identities.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while preserving evidence needed for later review.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while preserving evidence needed for later review.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

D: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 18

Southridge Media is preparing a security decision for the AI-assisted customer service platform. The decision involves Systems access. The business continuity lead must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The identity population includes 4,100 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.

Correct answer: A

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access without granting broader privilege than the business need requires.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access without granting broader privilege than the business need requires.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

D: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 19

During a risk workshop for the global collaboration platform, the team identifies Device access as the deciding issue. The privacy and compliance lead is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The identity population includes 5,800 workforce, service, or device identities.

  1. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  2. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access without creating a new single point of failure.

Option review:

A: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

B: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access without creating a new single point of failure.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 20

A control owner at VanArsdel Energy proposes a quick technical fix for Facility access in the e-commerce application. The security architect must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The identity population includes 7,500 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Establish trustworthy identity proofing and use strong authentication, appropriate MFA or passwordless methods, secure session management, and centralized identity where it reduces risk.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

B: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

C: Authentication strength begins with a trustworthy identity and must continue through credential and session lifecycle management. That action can be useful in a different security decision, but it does not most directly address Facility access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Facility access while ensuring that emergency access cannot become permanent access.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 21

Northwind Health is standardizing security across several business units. The clinical records environment raises a question about Application access. The security operations manager needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The identity population includes 9,200 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access while allowing independent verification of the control outcome.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Application access while allowing independent verification of the control outcome.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Application access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 22

During a acquisition integration, Coho Insurance asks the business continuity lead to address Service access for its remote access service. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The identity population includes 1,800 workforce, service, or device identities.

  1. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  2. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  3. Choose the authorization model that matches the policy decision factors and enforce it through a clear policy decision and policy enforcement architecture.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access while accounting for third-party and lifecycle dependencies.

Option review:

A: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Service access while accounting for third-party and lifecycle dependencies.

B: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

C: RBAC, ABAC, MAC, DAC, rule-based, and risk-based models solve different authorization problems. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 23

  1. Datum Analytics is revising controls for its customer identity platform. A review highlights Authentication system implementation. The privacy and compliance lead must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The identity population includes 3,500 workforce, service, or device identities.
  2. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse.
  5. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: C

Why: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while maintaining the organization’s stated risk appetite.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

C: Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring. It directly addresses Authentication system implementation while maintaining the organization’s stated risk appetite.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. That action can be useful in a different security decision, but it does not most directly address Authentication system implementation in this scenario.

Learning point: Implement authentication systems with protected secrets, replay-resistant protocols, secure enrollment and recovery, and monitoring for credential abuse. Authentication is only as strong as its protocol, secret protection, enrollment, recovery, and operational monitoring.

Question 24

An auditor asks Blue Yonder Airlines to demonstrate how it handles Information access in the data analytics lake. The security architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The identity population includes 5,200 workforce, service, or device identities.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  3. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  4. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.

Correct answer: D

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

B: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

C: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Information access in this scenario.

D: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Information access while meeting the business objective with the least unnecessary operational complexity.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 25

After a business change, City Power discovers that Systems access is not handled consistently for the branch-office network. The security operations manager needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The identity population includes 6,900 workforce, service, or device identities.

  1. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  4. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.

Correct answer: C

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while keeping the control sustainable for normal operations.

Option review:

A: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

C: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Systems access while keeping the control sustainable for normal operations.

D: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Systems access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Question 26

Tailspin Logistics is preparing a security decision for the industrial control network. The decision involves Device access. The business continuity lead must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The identity population includes 8,600 workforce, service, or device identities.

  1. Automate joiner-mover-leaver provisioning, review entitlements regularly, tightly govern service accounts, and remove obsolete privileges promptly.
  2. Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed.
  3. Establish federation through a defined trust relationship with validated issuers, signed assertions or tokens, scoped claims, and controlled account lifecycle.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: B

Why: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while ensuring the decision can be repeated consistently across business units.

Option review:

A: Access risk accumulates when provisioning and deprovisioning lag behind role or employment changes. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

B: Access control should protect information, systems, devices, facilities, applications, and services according to risk. It directly addresses Device access while ensuring the decision can be repeated consistently across business units.

C: Federation reduces duplicate credentials but introduces trust dependencies that must be explicitly governed and validated. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Device access in this scenario.

Learning point: Enforce physical and logical access according to subject, asset sensitivity, business need, and least privilege, with access decisions consistently logged and reviewed. Access control should protect information, systems, devices, facilities, applications, and services according to risk.

Popular posts

img