ISC2 CISSP Supply Chain Risk And Security Awareness Practice Test

 

1 Security and Risk Management • 28 original questions

This CISSP practice test focuses on supply chain risk and security awareness through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

After a business change, Bellows University discovers that Software bill of materials (SBOM) is not handled consistently for the branch-office network. The security operations manager needs to address the control objective while allowing independent verification of the control outcome. Which recommendation BEST addresses the issue? The decision affects 75 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) while allowing independent verification of the control outcome.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) while allowing independent verification of the control outcome.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 2

Litware Services is preparing a security decision for the industrial control network. The decision involves Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification. The business continuity lead must address the control objective while accounting for third-party and lifecycle dependencies. Which option BEST reflects CISSP-level security practice? The decision affects 92 business processes and has a named executive risk owner.

  1. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: C

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while accounting for third-party and lifecycle dependencies.

Option review:

A: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while accounting for third-party and lifecycle dependencies.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 3

During a risk workshop for the research data repository, the team identifies Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain as the deciding issue. The privacy and compliance lead is expected to address the control objective while maintaining the organization’s stated risk appetite. What is the MOST appropriate course of action? The decision affects 18 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: A

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while maintaining the organization’s stated risk appetite.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while maintaining the organization’s stated risk appetite.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 4

A control owner at Woodgrove Bank proposes a quick technical fix for Program effectiveness evaluation in the payment processing service. The security architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. What should happen FIRST? The decision affects 35 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  3. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: C

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

C: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while meeting the business objective with the least unnecessary operational complexity.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 5

Relecloud Systems is standardizing security across several business units. The software delivery pipeline raises a question about Supplier and provider risks such as tampering, counterfeits, and implants. The security operations manager needs to address the control objective while keeping the control sustainable for normal operations. Which action provides the BEST governance and security outcome? The decision affects 52 business processes and has a named executive risk owner.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  3. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: B

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

B: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while keeping the control sustainable for normal operations.

C: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 6

During a secure software initiative, Contoso Financial asks the business continuity lead to address Third-party assessment and monitoring for its AI-assisted customer service platform. The requirement is to address the control objective while ensuring the decision can be repeated consistently across business units. What should the organization do FIRST? The decision affects 69 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: A

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring while ensuring the decision can be repeated consistently across business units.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring while ensuring the decision can be repeated consistently across business units.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 7

Lucerne Publishing is revising controls for its global collaboration platform. A review highlights Minimum supplier security requirements. The privacy and compliance lead must address the control objective while preserving clear accountability and audit evidence. Which action is the BEST next step? The decision affects 86 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements while preserving clear accountability and audit evidence.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements while preserving clear accountability and audit evidence.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 8

An auditor asks Lamna Healthcare to demonstrate how it handles Service-level security requirements in the e-commerce application. The security architect must address the control objective while protecting sensitive data throughout the change. Which response is MOST appropriate? The decision affects 12 business processes and has a named executive risk owner.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while protecting sensitive data throughout the change.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while protecting sensitive data throughout the change.

D: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 9

After a business change, Fourth Coffee discovers that Silicon root of trust and physically unclonable functions is not handled consistently for the clinical records environment. The security operations manager needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The decision affects 29 business processes and has a named executive risk owner.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

C: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while preserving availability of the critical business service.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 10

Consolidated Messenger is preparing a security decision for the remote access service. The decision involves Software bill of materials (SBOM). The business continuity lead must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The decision affects 46 business processes and has a named executive risk owner.

  1. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  2. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) without replacing governance with a technology-only shortcut.

Option review:

A: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

B: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) without replacing governance with a technology-only shortcut.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 11

During a risk workshop for the customer identity platform, the team identifies Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification as the deciding issue. The privacy and compliance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The decision affects 63 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: A

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while keeping the process defensible to auditors and business owners.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while keeping the process defensible to auditors and business owners.

B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 12

A control owner at Southridge Media proposes a quick technical fix for Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in the data analytics lake. The security architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The decision affects 80 business processes and has a named executive risk owner.

  1. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: B

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while minimizing irreversible action until facts and authority are established.

Option review:

A: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while minimizing irreversible action until facts and authority are established.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 13

Adventure Works is standardizing security across several business units. The branch-office network raises a question about Program effectiveness evaluation. The security operations manager needs to address the control objective while preserving evidence needed for later review. Which action provides the BEST governance and security outcome? The decision affects 6 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.

Correct answer: D

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while preserving evidence needed for later review.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

B: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

D: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while preserving evidence needed for later review.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 14

During a third-party onboarding review, VanArsdel Energy asks the business continuity lead to address Supplier and provider risks such as tampering, counterfeits, and implants for its industrial control network. The requirement is to address the control objective without granting broader privilege than the business need requires. What should the organization do FIRST? The decision affects 23 business processes and has a named executive risk owner.

  1. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  2. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants without granting broader privilege than the business need requires.

Option review:

A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

B: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants without granting broader privilege than the business need requires.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 15

Northwind Health is revising controls for its research data repository. A review highlights Third-party assessment and monitoring. The privacy and compliance lead must address the control objective without creating a new single point of failure. Which action is the BEST next step? The decision affects 40 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Perform or update the business impact analysis, identify critical dependencies, and set recovery priorities from business impact before choosing continuity solutions.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring without creating a new single point of failure.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

C: Business continuity priorities should be driven by business impact and dependencies, not by the convenience of a particular technology. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring without creating a new single point of failure.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 16

An auditor asks Coho Insurance to demonstrate how it handles Minimum supplier security requirements in the payment processing service. The security architect must address the control objective while ensuring that emergency access cannot become permanent access. Which response is MOST appropriate? The decision affects 57 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Preserve evidence and follow the procedural and evidentiary requirements appropriate to the type of investigation before taking irreversible action.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: A

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements while ensuring that emergency access cannot become permanent access.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements while ensuring that emergency access cannot become permanent access.

B: Administrative, civil, criminal, regulatory, and industry investigations can have different authorities, standards, and evidence-handling expectations. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 17

After a business change, A. Datum Analytics discovers that Service-level security requirements is not handled consistently for the software delivery pipeline. The security operations manager needs to address the control objective while allowing independent verification of the control outcome. Which recommendation BEST addresses the issue? The decision affects 74 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while allowing independent verification of the control outcome.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while allowing independent verification of the control outcome.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 18

Blue Yonder Airlines is preparing a security decision for the AI-assisted customer service platform. The decision involves Silicon root of trust and physically unclonable functions. The business continuity lead must address the control objective while accounting for third-party and lifecycle dependencies. Which option BEST reflects CISSP-level security practice? The decision affects 91 business processes and has a named executive risk owner.

  1. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.
  2. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while accounting for third-party and lifecycle dependencies.

Option review:

A: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

B: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while accounting for third-party and lifecycle dependencies.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 19

During a risk workshop for the global collaboration platform, the team identifies Software bill of materials (SBOM) as the deciding issue. The privacy and compliance lead is expected to address the control objective while maintaining the organization’s stated risk appetite. What is the MOST appropriate course of action? The decision affects 17 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: A

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) while maintaining the organization’s stated risk appetite.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Software bill of materials (SBOM) while maintaining the organization’s stated risk appetite.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Software bill of materials (SBOM) in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 20

A control owner at Tailspin Logistics proposes a quick technical fix for Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in the e-commerce application. The security architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. What should happen FIRST? The decision affects 34 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Use the policy hierarchy correctly: policy states management intent, standards make mandatory rules, procedures define steps, and guidelines provide recommended practices.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Align the security decision with business objectives, defined governance roles, and an appropriate control framework before selecting implementation details.

Correct answer: A

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification while meeting the business objective with the least unnecessary operational complexity.

B: A clear document hierarchy turns governance intent into consistent, auditable execution. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

D: Governance establishes decision rights, accountability, and alignment; technology should implement rather than substitute for governance. That action can be useful in a different security decision, but it does not most directly address Awareness methods such as social engineering simulations, phishing exercises, security champions, and gamification in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 21

Alpine Sports is standardizing security across several business units. The clinical records environment raises a question about Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain. The security operations manager needs to address the control objective while keeping the control sustainable for normal operations. Which action provides the BEST governance and security outcome? The decision affects 51 business processes and has a named executive risk owner.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: B

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while keeping the control sustainable for normal operations.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain while keeping the control sustainable for normal operations.

C: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Periodic content review for emerging technologies such as cryptocurrency, AI, and blockchain in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 22

During a acquisition integration, Fabrikam Manufacturing asks the business continuity lead to address Program effectiveness evaluation for its remote access service. The requirement is to address the control objective while ensuring the decision can be repeated consistently across business units. What should the organization do FIRST? The decision affects 68 business processes and has a named executive risk owner.

  1. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Assess likelihood and impact in context, choose a risk treatment consistent with risk appetite, document residual risk ownership, and monitor the result.

Correct answer: B

Why: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while ensuring the decision can be repeated consistently across business units.

Option review:

A: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. It directly addresses Program effectiveness evaluation while ensuring the decision can be repeated consistently across business units.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

D: Risk management is a continuing business process that links threats, vulnerabilities, controls, treatment, ownership, and residual risk. That action can be useful in a different security decision, but it does not most directly address Program effectiveness evaluation in this scenario.

Learning point: Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness. Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed.

Question 23

Trey Research is revising controls for its customer identity platform. A review highlights Supplier and provider risks such as tampering, counterfeits, and implants. The privacy and compliance lead must address the control objective while preserving clear accountability and audit evidence. Which action is the BEST next step? The decision affects 85 business processes and has a named executive risk owner.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Determine the applicable jurisdictions, contracts, regulations, privacy obligations, and legal authority before changing how protected information is processed or disclosed.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Follow the applicable professional code, disclose conflicts, and escalate through appropriate governance channels rather than concealing a material security concern.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while preserving clear accountability and audit evidence.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

B: Legal and regulatory obligations depend on jurisdiction, data type, contracts, and processing context; identifying applicability precedes implementation. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while preserving clear accountability and audit evidence.

D: Professional ethics require protecting society and the organization while acting honestly, competently, and within established escalation mechanisms. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 24

An auditor asks Margie Travel to demonstrate how it handles Supplier and provider risks such as tampering, counterfeits, and implants in the data analytics lake. The security architect must address the control objective while protecting sensitive data throughout the change. Which response is MOST appropriate? The decision affects 11 business processes and has a named executive risk owner.

  1. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  2. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.

Correct answer: A

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while protecting sensitive data throughout the change.

Option review:

A: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Supplier and provider risks such as tampering, counterfeits, and implants while protecting sensitive data throughout the change.

B: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

D: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Supplier and provider risks such as tampering, counterfeits, and implants in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 25

After a business change, Wide World Importers discovers that Third-party assessment and monitoring is not handled consistently for the branch-office network. The security operations manager needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The decision affects 28 business processes and has a named executive risk owner.

  1. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring while preserving availability of the critical business service.

Option review:

A: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

C: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Third-party assessment and monitoring in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Third-party assessment and monitoring while preserving availability of the critical business service.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 26

Bellows University is preparing a security decision for the industrial control network. The decision involves Minimum supplier security requirements. The business continuity lead must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The decision affects 45 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Apply personnel security controls across the full joiner-mover-leaver and third-party lifecycle, with responsibilities and access changing when the relationship changes.
  3. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements without replacing governance with a technology-only shortcut.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

B: Personnel risk changes during hiring, transfers, termination, and third-party engagement; controls must follow that lifecycle. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

C: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Minimum supplier security requirements without replacing governance with a technology-only shortcut.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Minimum supplier security requirements in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 27

During a risk workshop for the research data repository, the team identifies Service-level security requirements as the deciding issue. The privacy and compliance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The decision affects 62 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Model threats early around assets, actors, trust boundaries, attack paths, and abuse cases, then use the results to prioritize design mitigations.

Correct answer: B

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while keeping the process defensible to auditors and business owners.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

B: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Service-level security requirements while keeping the process defensible to auditors and business owners.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

D: Threat modeling is most useful before implementation choices become expensive to change and when it informs concrete mitigations. That action can be useful in a different security decision, but it does not most directly address Service-level security requirements in this scenario.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Question 28

A control owner at Humongous Insurance proposes a quick technical fix for Silicon root of trust and physically unclonable functions in the payment processing service. The security architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The decision affects 79 business processes and has a named executive risk owner.

  1. Identify the security property the business requirement depends on, then select controls that directly protect that property.
  2. Run a role-based, recurring awareness and training program that is updated for emerging threats and measured for effectiveness.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously.

Correct answer: D

Why: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while minimizing irreversible action until facts and authority are established.

Option review:

A: Security controls should be tied to the required confidentiality, integrity, availability, authenticity, or nonrepudiation outcome rather than deployed by habit. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

B: Effective awareness programs are continuous and measurable; completion rates alone do not prove that risky behavior changed. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Silicon root of trust and physically unclonable functions in this scenario.

D: Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed. It directly addresses Silicon root of trust and physically unclonable functions while minimizing irreversible action until facts and authority are established.

Learning point: Evaluate supplier risk before and during the relationship, impose minimum security and transparency requirements, and monitor the supplier and product supply chain continuously. Supply-chain risk cannot be transferred away simply by outsourcing; contractual, technical, provenance, and monitoring controls are needed.

Popular posts

img