ISC2 CISSP Configuration Operations Foundations And Resource Protection Practice Test

 

7 Security Operations • 20 original questions

This CISSP practice test focuses on configuration operations foundations and resource protection through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Northwind Health is standardizing security across several business units. The research data repository raises a question about Service-level agreements (SLA). The security assurance manager needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The operating team supports 44 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.

Correct answer: A

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Service-level agreements (SLA) without creating a new single point of failure.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Service-level agreements (SLA) without creating a new single point of failure.

B: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

D: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 2

During a internal audit response, Coho Insurance asks the enterprise security engineer to address Media management for its payment processing service. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The operating team supports 61 critical systems under documented recovery and escalation procedures.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  3. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.
  4. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.

Correct answer: C

Why: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media management while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

B: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

C: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media management while ensuring that emergency access cannot become permanent access.

D: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

Learning point: Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls. Resource protection must follow data and media across storage, movement, reuse, and disposal.

Question 3

  1. Datum Analytics is revising controls for its software delivery pipeline. A review highlights Media protection techniques. The chief information security officer must address the control objective while allowing independent verification of the control outcome. Which action is the BEST next step? The operating team supports 78 critical systems under documented recovery and escalation procedures.
  2. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  3. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  5. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.

Correct answer: B

Why: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media protection techniques while allowing independent verification of the control outcome.

Option review:

A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Media protection techniques in this scenario.

B: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media protection techniques while allowing independent verification of the control outcome.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Media protection techniques in this scenario.

D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Media protection techniques in this scenario.

Learning point: Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls. Resource protection must follow data and media across storage, movement, reuse, and disposal.

Question 4

An auditor asks Blue Yonder Airlines to demonstrate how it handles Data at rest and data in transit in the AI-assisted customer service platform. The risk manager must address the control objective while accounting for third-party and lifecycle dependencies. Which response is MOST appropriate? The operating team supports 4 critical systems under documented recovery and escalation procedures.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.
  3. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  4. Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan.

Correct answer: B

Why: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Data at rest and data in transit while accounting for third-party and lifecycle dependencies.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data at rest and data in transit in this scenario.

B: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Data at rest and data in transit while accounting for third-party and lifecycle dependencies.

C: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Data at rest and data in transit in this scenario.

D: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Data at rest and data in transit in this scenario.

Learning point: Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls. Resource protection must follow data and media across storage, movement, reuse, and disposal.

Question 5

After a business change, City Power discovers that Provisioning is not handled consistently for the global collaboration platform. The security assurance manager needs to address the control objective while maintaining the organization’s stated risk appetite. Which recommendation BEST addresses the issue? The operating team supports 21 critical systems under documented recovery and escalation procedures.

  1. Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned.
  2. Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority.
  3. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Provisioning while maintaining the organization’s stated risk appetite.

Option review:

A: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

C: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Provisioning while maintaining the organization’s stated risk appetite.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 6

Tailspin Logistics is preparing a security decision for the e-commerce application. The decision involves Baselining. The enterprise security engineer must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which option BEST reflects CISSP-level security practice? The operating team supports 38 critical systems under documented recovery and escalation procedures.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area.
  3. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  4. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.

Correct answer: D

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Baselining while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

B: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

D: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Baselining while meeting the business objective with the least unnecessary operational complexity.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 7

During a risk workshop for the clinical records environment, the team identifies Configuration automation as the deciding issue. The chief information security officer is expected to address the control objective while keeping the control sustainable for normal operations. What is the MOST appropriate course of action? The operating team supports 55 critical systems under documented recovery and escalation procedures.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.
  3. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  4. Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area.

Correct answer: C

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Configuration automation while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

C: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Configuration automation while keeping the control sustainable for normal operations.

D: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 8

A control owner at Fabrikam Manufacturing proposes a quick technical fix for Need-to-know and least privilege in the remote access service. The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. What should happen FIRST? The operating team supports 72 critical systems under documented recovery and escalation procedures.

  1. Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area.
  2. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.

Correct answer: D

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Need-to-know and least privilege while ensuring the decision can be repeated consistently across business units.

Option review:

A: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

B: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

D: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Need-to-know and least privilege while ensuring the decision can be repeated consistently across business units.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 9

Trey Research is standardizing security across several business units. The customer identity platform raises a question about Segregation of Duties (SoD) and responsibilities. The security assurance manager needs to address the control objective while preserving clear accountability and audit evidence. Which action provides the BEST governance and security outcome? The operating team supports 89 critical systems under documented recovery and escalation procedures.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  3. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  4. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.

Correct answer: C

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Segregation of Duties (SoD) and responsibilities while preserving clear accountability and audit evidence.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

B: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

C: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Segregation of Duties (SoD) and responsibilities while preserving clear accountability and audit evidence.

D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 10

During a identity modernization project, Margie Travel asks the enterprise security engineer to address Privileged account management for its data analytics lake. The requirement is to address the control objective while protecting sensitive data throughout the change. What should the organization do FIRST? The operating team supports 15 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.

Correct answer: A

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Privileged account management while protecting sensitive data throughout the change.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Privileged account management while protecting sensitive data throughout the change.

B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

D: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 11

Wide World Importers is revising controls for its branch-office network. A review highlights Job rotation. The chief information security officer must address the control objective while preserving availability of the critical business service. Which action is the BEST next step? The operating team supports 32 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  4. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.

Correct answer: A

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Job rotation while preserving availability of the critical business service.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Job rotation while preserving availability of the critical business service.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

C: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

D: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 12

An auditor asks Bellows University to demonstrate how it handles Service-level agreements (SLA) in the industrial control network. The risk manager must address the control objective without replacing governance with a technology-only shortcut. Which response is MOST appropriate? The operating team supports 49 critical systems under documented recovery and escalation procedures.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.
  3. Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority.
  4. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.

Correct answer: D

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Service-level agreements (SLA) without replacing governance with a technology-only shortcut.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Service-level agreements (SLA) in this scenario.

D: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Service-level agreements (SLA) without replacing governance with a technology-only shortcut.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 13

After a business change, Litware Services discovers that Media management is not handled consistently for the research data repository. The security assurance manager needs to address the control objective while keeping the process defensible to auditors and business owners. Which recommendation BEST addresses the issue? The operating team supports 66 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.

Correct answer: D

Why: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media management while keeping the process defensible to auditors and business owners.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

B: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Media management in this scenario.

D: Resource protection must follow data and media across storage, movement, reuse, and disposal. It directly addresses Media management while keeping the process defensible to auditors and business owners.

Learning point: Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls. Resource protection must follow data and media across storage, movement, reuse, and disposal.

Question 14

Humongous Insurance is preparing a security decision for the payment processing service. The decision involves Provisioning. The enterprise security engineer must address the control objective while minimizing irreversible action until facts and authority are established. Which option BEST reflects CISSP-level security practice? The operating team supports 83 critical systems under documented recovery and escalation procedures.

  1. Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area.
  2. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  3. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: C

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Provisioning while minimizing irreversible action until facts and authority are established.

Option review:

A: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

B: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

C: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Provisioning while minimizing irreversible action until facts and authority are established.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Provisioning in this scenario.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 15

During a risk workshop for the software delivery pipeline, the team identifies Baselining as the deciding issue. The chief information security officer is expected to address the control objective while preserving evidence needed for later review. What is the MOST appropriate course of action? The operating team supports 9 critical systems under documented recovery and escalation procedures.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  3. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.
  4. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.

Correct answer: B

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Baselining while preserving evidence needed for later review.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

B: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Baselining while preserving evidence needed for later review.

C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Baselining in this scenario.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 16

A control owner at Relecloud Systems proposes a quick technical fix for Configuration automation in the AI-assisted customer service platform. The risk manager must address the control objective without granting broader privilege than the business need requires. What should happen FIRST? The operating team supports 26 critical systems under documented recovery and escalation procedures.

  1. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.
  4. Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan.

Correct answer: A

Why: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Configuration automation without granting broader privilege than the business need requires.

Option review:

A: Baselines and drift control make systems predictable, auditable, and recoverable. It directly addresses Configuration automation without granting broader privilege than the business need requires.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

C: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

D: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Configuration automation in this scenario.

Learning point: Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management. Baselines and drift control make systems predictable, auditable, and recoverable.

Question 17

Contoso Financial is standardizing security across several business units. The global collaboration platform raises a question about Need-to-know and least privilege. The security assurance manager needs to address the control objective without creating a new single point of failure. Which action provides the BEST governance and security outcome? The operating team supports 43 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Need-to-know and least privilege without creating a new single point of failure.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

B: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Need-to-know and least privilege without creating a new single point of failure.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Need-to-know and least privilege in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 18

During a architecture design review, Lucerne Publishing asks the enterprise security engineer to address Segregation of Duties (SoD) and responsibilities for its e-commerce application. The requirement is to address the control objective while ensuring that emergency access cannot become permanent access. What should the organization do FIRST? The operating team supports 60 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.

Correct answer: A

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Segregation of Duties (SoD) and responsibilities while ensuring that emergency access cannot become permanent access.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Segregation of Duties (SoD) and responsibilities while ensuring that emergency access cannot become permanent access.

B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

D: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) and responsibilities in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 19

Lamna Healthcare is revising controls for its clinical records environment. A review highlights Privileged account management. The chief information security officer must address the control objective while allowing independent verification of the control outcome. Which action is the BEST next step? The operating team supports 77 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Privileged account management while allowing independent verification of the control outcome.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Privileged account management while allowing independent verification of the control outcome.

B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Privileged account management in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Question 20

An auditor asks Fourth Coffee to demonstrate how it handles Job rotation in the remote access service. The risk manager must address the control objective while accounting for third-party and lifecycle dependencies. Which response is MOST appropriate? The operating team supports 3 critical systems under documented recovery and escalation procedures.

  1. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.
  2. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.

Correct answer: B

Why: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Job rotation while accounting for third-party and lifecycle dependencies.

Option review:

A: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

B: Foundational operations controls reduce concentration of privilege and make accountability visible. It directly addresses Job rotation while accounting for third-party and lifecycle dependencies.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

D: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Job rotation in this scenario.

Learning point: Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments. Foundational operations controls reduce concentration of privilege and make accountability visible.

Popular posts

img