ISC2 CISSP Incident Detection Prevention Patching And Change Management Practice Test

 

7 Security Operations • 20 original questions

This CISSP practice test focuses on incident detection prevention patching and change management through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

Litware Services is revising controls for its e-commerce application. A review highlights IDS and IPS. The incident response manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The operating team supports 55 critical systems under documented recovery and escalation procedures.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned.

Correct answer: C

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses IDS and IPS while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address IDS and IPS in this scenario.

B: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address IDS and IPS in this scenario.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses IDS and IPS while meeting the business objective with the least unnecessary operational complexity.

D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address IDS and IPS in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 2

An auditor asks Humongous Insurance to demonstrate how it handles Allowlisting and blocklisting in the clinical records environment. The security governance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The operating team supports 72 critical systems under documented recovery and escalation procedures.

  1. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.

Correct answer: B

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Allowlisting and blocklisting while keeping the control sustainable for normal operations.

Option review:

A: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Allowlisting and blocklisting in this scenario.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Allowlisting and blocklisting while keeping the control sustainable for normal operations.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Allowlisting and blocklisting in this scenario.

D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Allowlisting and blocklisting in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 3

After a business change, Woodgrove Bank discovers that Third-party security services is not handled consistently for the remote access service. The IAM architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The operating team supports 89 critical systems under documented recovery and escalation procedures.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  3. Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority.
  4. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.

Correct answer: D

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Third-party security services while ensuring the decision can be repeated consistently across business units.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Third-party security services in this scenario.

B: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Third-party security services in this scenario.

C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Third-party security services in this scenario.

D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Third-party security services while ensuring the decision can be repeated consistently across business units.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 4

Relecloud Systems is preparing a security decision for the customer identity platform. The decision involves Sandboxing. The application security architect must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The operating team supports 15 critical systems under documented recovery and escalation procedures.

  1. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Sandboxing while preserving clear accountability and audit evidence.

Option review:

A: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Sandboxing in this scenario.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Sandboxing while preserving clear accountability and audit evidence.

C: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Sandboxing in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Sandboxing in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 5

During a risk workshop for the data analytics lake, the team identifies Honeypots and honeynets as the deciding issue. The incident response manager is expected to address the control objective while protecting sensitive data throughout the change. What is the MOST appropriate course of action? The operating team supports 32 critical systems under documented recovery and escalation procedures.

  1. Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.
  4. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.

Correct answer: D

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Honeypots and honeynets while protecting sensitive data throughout the change.

Option review:

A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address Honeypots and honeynets in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Honeypots and honeynets in this scenario.

C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Honeypots and honeynets in this scenario.

D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Honeypots and honeynets while protecting sensitive data throughout the change.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 6

A control owner at Lucerne Publishing proposes a quick technical fix for Anti-malware in the branch-office network. The security governance lead must address the control objective while preserving availability of the critical business service. What should happen FIRST? The operating team supports 49 critical systems under documented recovery and escalation procedures.

  1. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  2. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Anti-malware while preserving availability of the critical business service.

Option review:

A: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Anti-malware in this scenario.

B: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Anti-malware in this scenario.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Anti-malware while preserving availability of the critical business service.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Anti-malware in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 7

Lamna Healthcare is standardizing security across several business units. The industrial control network raises a question about Machine-learning and AI-based security tools. The IAM architect needs to address the control objective without replacing governance with a technology-only shortcut. Which action provides the BEST governance and security outcome? The operating team supports 66 critical systems under documented recovery and escalation procedures.

  1. Apply least privilege, separation of duties, privileged-access controls, job rotation where appropriate, and measurable operational service commitments.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.

Correct answer: C

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Machine-learning and AI-based security tools without replacing governance with a technology-only shortcut.

Option review:

A: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Machine-learning and AI-based security tools in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Machine-learning and AI-based security tools in this scenario.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Machine-learning and AI-based security tools without replacing governance with a technology-only shortcut.

D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Machine-learning and AI-based security tools in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Question 8

During a business continuity exercise, Fourth Coffee asks the application security architect to address Patch and vulnerability management for its research data repository. The requirement is to address the control objective while keeping the process defensible to auditors and business owners. What should the organization do FIRST? The operating team supports 83 critical systems under documented recovery and escalation procedures.

  1. Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  4. Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity.

Correct answer: A

Why: Risk-based vulnerability management is more effective than patching purely by severity score or release date. It directly addresses Patch and vulnerability management while keeping the process defensible to auditors and business owners.

Option review:

A: Risk-based vulnerability management is more effective than patching purely by severity score or release date. It directly addresses Patch and vulnerability management while keeping the process defensible to auditors and business owners.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Patch and vulnerability management in this scenario.

C: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Patch and vulnerability management in this scenario.

D: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Patch and vulnerability management in this scenario.

Learning point: Prioritize vulnerabilities by exploitability, exposure, asset criticality, and business impact; test and deploy patches through change control and track exceptions. Risk-based vulnerability management is more effective than patching purely by severity score or release date.

Question 9

Consolidated Messenger is revising controls for its payment processing service. A review highlights Change management processes. The incident response manager must address the control objective while minimizing irreversible action until facts and authority are established. Which action is the BEST next step? The operating team supports 9 critical systems under documented recovery and escalation procedures.

  1. Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  4. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.

Correct answer: A

Why: Controlled change reduces outages and security regressions while preserving accountability. It directly addresses Change management processes while minimizing irreversible action until facts and authority are established.

Option review:

A: Controlled change reduces outages and security regressions while preserving accountability. It directly addresses Change management processes while minimizing irreversible action until facts and authority are established.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Change management processes in this scenario.

C: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Change management processes in this scenario.

D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Change management processes in this scenario.

Learning point: Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan. Controlled change reduces outages and security regressions while preserving accountability.

Question 10

An auditor asks Proseware Labs to demonstrate how it handles Detection in the software delivery pipeline. The security governance lead must address the control objective while preserving evidence needed for later review. Which response is MOST appropriate? The operating team supports 26 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: A

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Detection while preserving evidence needed for later review.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Detection while preserving evidence needed for later review.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

C: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 11

After a business change, Southridge Media discovers that Response is not handled consistently for the AI-assisted customer service platform. The IAM architect needs to address the control objective without granting broader privilege than the business need requires. Which recommendation BEST addresses the issue? The operating team supports 43 critical systems under documented recovery and escalation procedures.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  3. Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned.
  4. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.

Correct answer: D

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Response without granting broader privilege than the business need requires.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

C: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

D: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Response without granting broader privilege than the business need requires.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 12

Adventure Works is preparing a security decision for the global collaboration platform. The decision involves Mitigation. The application security architect must address the control objective without creating a new single point of failure. Which option BEST reflects CISSP-level security practice? The operating team supports 60 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.
  3. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Mitigation without creating a new single point of failure.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Mitigation without creating a new single point of failure.

B: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

C: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 13

During a risk workshop for the e-commerce application, the team identifies Detection as the deciding issue. The incident response manager is expected to address the control objective while ensuring that emergency access cannot become permanent access. What is the MOST appropriate course of action? The operating team supports 77 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  4. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.

Correct answer: A

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Detection while ensuring that emergency access cannot become permanent access.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Detection while ensuring that emergency access cannot become permanent access.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

D: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Detection in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 14

A control owner at Northwind Health proposes a quick technical fix for Response in the clinical records environment. The security governance lead must address the control objective while allowing independent verification of the control outcome. What should happen FIRST? The operating team supports 3 critical systems under documented recovery and escalation procedures.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  3. Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan.
  4. Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity.

Correct answer: B

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Response while allowing independent verification of the control outcome.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

B: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Response while allowing independent verification of the control outcome.

C: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

D: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Response in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 15

Coho Insurance is standardizing security across several business units. The remote access service raises a question about Mitigation. The IAM architect needs to address the control objective while accounting for third-party and lifecycle dependencies. Which action provides the BEST governance and security outcome? The operating team supports 20 critical systems under documented recovery and escalation procedures.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Maintain approved configuration baselines, automate repeatable provisioning, detect drift, and route changes through controlled configuration management.
  4. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.

Correct answer: D

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Mitigation while accounting for third-party and lifecycle dependencies.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

C: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Mitigation in this scenario.

D: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Mitigation while accounting for third-party and lifecycle dependencies.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 16

During a post-incident improvement program, A. Datum Analytics asks the application security architect to address Reporting for its customer identity platform. The requirement is to address the control objective while maintaining the organization’s stated risk appetite. What should the organization do FIRST? The operating team supports 37 critical systems under documented recovery and escalation procedures.

  1. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  2. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  3. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  4. Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery.

Correct answer: C

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Reporting while maintaining the organization’s stated risk appetite.

Option review:

A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Reporting in this scenario.

B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Reporting in this scenario.

C: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Reporting while maintaining the organization’s stated risk appetite.

D: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Reporting in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 17

Blue Yonder Airlines is revising controls for its data analytics lake. A review highlights Recovery. The incident response manager must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which action is the BEST next step? The operating team supports 54 critical systems under documented recovery and escalation procedures.

  1. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders.
  4. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.

Correct answer: A

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Recovery while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Recovery while meeting the business objective with the least unnecessary operational complexity.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Recovery in this scenario.

C: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Recovery in this scenario.

D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Recovery in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 18

An auditor asks City Power to demonstrate how it handles Remediation in the branch-office network. The security governance lead must address the control objective while keeping the control sustainable for normal operations. Which response is MOST appropriate? The operating team supports 71 critical systems under documented recovery and escalation procedures.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.
  3. Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery.
  4. Protect media and resources according to classification using secure handling, encryption, transport, storage, sanitization, and disposal controls.

Correct answer: B

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Remediation while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Remediation in this scenario.

B: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Remediation while keeping the control sustainable for normal operations.

C: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Remediation in this scenario.

D: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Remediation in this scenario.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 19

After a business change, Tailspin Logistics discovers that Lessons learned is not handled consistently for the industrial control network. The IAM architect needs to address the control objective while ensuring the decision can be repeated consistently across business units. Which recommendation BEST addresses the issue? The operating team supports 88 critical systems under documented recovery and escalation procedures.

  1. Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence.

Correct answer: D

Why: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Lessons learned while ensuring the decision can be repeated consistently across business units.

Option review:

A: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Lessons learned in this scenario.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Lessons learned in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Lessons learned in this scenario.

D: Incident management minimizes business impact while supporting investigation and continuous improvement. It directly addresses Lessons learned while ensuring the decision can be repeated consistently across business units.

Learning point: Follow a coordinated incident process that detects, contains, mitigates, eradicates, recovers, reports, and captures lessons learned while preserving evidence. Incident management minimizes business impact while supporting investigation and continuous improvement.

Question 20

Alpine Sports is preparing a security decision for the research data repository. The decision involves Next-generation, web-application, and network firewalls. The application security architect must address the control objective while preserving clear accountability and audit evidence. Which option BEST reflects CISSP-level security practice? The operating team supports 14 critical systems under documented recovery and escalation procedures.

  1. Require authorized, tested, documented changes with impact assessment, segregation of duties where needed, and a rollback plan.
  2. Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Centralize protected, time-synchronized telemetry, tune detection logic, correlate events in SIEM/IDPS, and enrich monitoring with threat intelligence and behavioral analytics.

Correct answer: B

Why: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Next-generation, web-application, and network firewalls while preserving clear accountability and audit evidence.

Option review:

A: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Next-generation, web-application, and network firewalls in this scenario.

B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. It directly addresses Next-generation, web-application, and network firewalls while preserving clear accountability and audit evidence.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Next-generation, web-application, and network firewalls in this scenario.

D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Next-generation, web-application, and network firewalls in this scenario.

Learning point: Use layered, tuned detection and prevention controls appropriate to the threat, and validate that they provide useful signal without unacceptable operational impact. Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning.

Popular posts

img