CertSafari

    Free ISC2 Certified Information Systems Security Professional (CISSP) Sample Questions

    35 free sample questions from our bank of 297+, covering every exam domain, with answers and detailed explanations. Updated August 2026.

    Domain 1: Security and Risk Management

    Subdomain 1.2: Understand and apply security concepts

    1.A healthcare provider uses a third-party billing service that processes patient medical records. An audit reveals that the service stores data on servers accessible over the public internet without encryption, and a recent breach exposed patient data. Which security pillar was MOST directly violated?

    1. A.Confidentiality
    2. B.Integrity
    3. C.Availability
    4. D.Nonrepudiation
    Show answer & explanation

    Correct answer: AConfidentiality

    • A. Correct. Confidentiality ensures that sensitive information is accessible only to authorized parties. The lack of encryption and exposure of patient data directly violates this pillar, as the breach resulted in unauthorized disclosure.
    • B. Incorrect. Integrity protects data from unauthorized modification or destruction. The scenario focuses on unauthorized access and exposure, not on data being altered.
    • C. Incorrect. Availability ensures systems and data are accessible when needed. Although the servers were accessible over the internet, the primary issue is unauthorized disclosure, not loss of access.
    • D. Incorrect. Nonrepudiation ensures actions or transactions cannot be denied, typically through logs or signatures. The breach and lack of encryption relate to data secrecy, not proof of origin or denial.

    Subdomain 1.7: Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements

    2.After completing a business impact analysis, the business continuity coordinator compiles the following maximum tolerable downtime values: Accounts Payable – 72 hours, Customer Support Chat – 1 hour, Internal Wiki – 2 weeks. Based on business continuity best practice, which function should receive the highest recovery priority?

    1. A.Accounts Payable
    2. B.Customer Support Chat
    3. C.Internal Wiki
    4. D.All Critical Functions
    Show answer & explanation

    Correct answer: BCustomer Support Chat

    • A. Incorrect. Accounts Payable has a maximum tolerable downtime (MTD) of 72 hours, which is longer than Customer Support Chat. In business continuity planning, functions with shorter MTD values require higher recovery priority, so Accounts Payable should not be the highest priority.
    • B. Correct. Customer Support Chat has the shortest MTD of 1 hour, making it the most time-sensitive function. Business continuity best practice prioritizes recovery based on the shortest MTD to minimize business disruption, so this function should receive the highest recovery priority.
    • C. Incorrect. Internal Wiki has the longest MTD of 2 weeks, meaning it can tolerate the most downtime without unacceptable impact. Therefore, it should receive the lowest recovery priority among the listed functions.
    • D. Incorrect. While all critical functions must be addressed, recovery priority is not equal across functions. Best practice is to sequence restoration based on business impact and MTD, with the most time-sensitive function first. Not all critical functions have the same urgency.

    Subdomain 1.11: Apply supply chain risk management (SCRM) concepts

    3.Which of the following approaches best demonstrates a comprehensive supply chain risk management (SCRM) strategy for a financial firm engaging a critical third-party service provider?

    1. A.Engage an external assessor to perform a one-time SOC 2 Type II audit of the provider’s infrastructure before signing the contract and accept the audit report as evidence of ongoing compliance.
    2. B.Include contractual clauses mandating continuous monitoring, annual independent assessments, baseline security standards, and enforceable service level requirements.
    3. C.Implement a real-time API to pull the provider’s security event logs into the firm’s SIEM for independent correlation and trigger automated alerts for suspicious activities.
    4. D.Require the provider to self-attest quarterly against a set of security controls and provide remediation plans with third-party verification of the remediation actions.
    Show answer & explanation

    Correct answer: BInclude contractual clauses mandating continuous monitoring, annual independent assessments, baseline security standards, and enforceable service level requirements.

    • A. Incorrect. A one-time SOC 2 Type II audit provides a snapshot of the provider’s controls at a specific point in time. While useful for pre-contract assessment, it does not guarantee ongoing compliance or address evolving threats after the contract is signed. SCRM requires sustained oversight, not a single point-in-time report.
    • B. Correct. Strong contractual language is the foundation of effective SCRM. Mandating continuous monitoring, annual independent assessments, baseline security standards, and enforceable service level requirements (SLAs) ensures ongoing accountability and alignment with the firm’s security requirements. This approach provides both ongoing assurance and legal recourse.
    • C. Incorrect. Real-time API integration for security logs can enhance visibility and threat detection, but it does not address contractual obligations, compliance validation, or remediation accountability. It is a technical control that supplements but does not replace comprehensive contractual and assessment-based SCRM practices. Additionally, technical and privacy constraints may limit feasibility.
    • D. Incorrect. Self-attestation is weaker than independent assurance and can be biased or incomplete. Even with third-party verification of remediation actions, quarterly self-attestation does not provide the same level of enforceable, ongoing oversight as contractual obligations with continuous monitoring and independent assessments. It lacks the accountability and depth of a comprehensive contractual framework.

    Subdomain 1.5: Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)

    4.Which type of investigation is conducted by law enforcement to determine if a crime has been committed?

    1. A.Administrative investigation
    2. B.Criminal investigation
    3. C.Civil investigation
    4. D.Regulatory investigation
    Show answer & explanation

    Correct answer: BCriminal investigation

    • A. Administrative investigations are internal to an organization, addressing policy violations or misconduct. They are not conducted by law enforcement and do not handle criminal matters.
    • B. Criminal investigations are conducted by law enforcement to determine whether a crime has been committed and to gather evidence for potential prosecution. This type involves strict evidentiary handling requirements and is focused on criminal law.
    • C. Civil investigations relate to disputes between private parties, such as lawsuits over damages or contract issues. While evidence may be collected, it does not involve law enforcement or criminal prosecution.
    • D. Regulatory investigations are performed by government or industry bodies to assess compliance with laws, rules, or industry regulations. They focus on compliance enforcement rather than criminal prosecution.

    Subdomain 1.10: Understand and apply threat modeling concepts and methodologies

    5.Which approach best integrates threat modeling into an Agile development process?

    1. A.Conduct a full STRIDE threat modeling workshop during release planning and update the model only for major version changes, treating it as a one-time security gate.
    2. B.Incorporate lightweight threat modeling in each sprint by abusing user stories, incrementally updating data flow diagrams, and employing automation to detect threats from code changes.
    3. C.Perform penetration testing after each sprint, then retroactively build threat models for critical findings to document residual risk for compliance.
    4. D.Apply DREAD scoring during the final sprint to evaluate all threats discovered throughout the project and create a treatment plan before launch.
    Show answer & explanation

    Correct answer: BIncorporate lightweight threat modeling in each sprint by abusing user stories, incrementally updating data flow diagrams, and employing automation to detect threats from code changes.

    • A. Incorrect. Threat modeling should be iterative and continuous, not a one-time security gate. Restricting updates to major version changes ignores threats introduced by regular sprint modifications, which undermines Agile's need for ongoing risk assessment.
    • B. Correct. Lightweight threat modeling integrated into each sprint aligns with Agile principles by enabling continuous assessment of evolving requirements, architecture, and code. Incrementally updating data flow diagrams and using automation helps detect threats early and keeps the model current.
    • C. Incorrect. Penetration testing is a validation activity that occurs after development, not a substitute for proactive threat modeling. Building threat models only for critical findings found during testing is reactive and delays risk identification until late in the lifecycle.
    • D. Incorrect. DREAD is a risk-ranking method, not a continuous threat modeling process. Applying it only in the final sprint misses opportunities for early design changes; threat treatment should be informed throughout development, not created solely at the end.

    Domain 2: Asset Security

    Subdomain 2.2: Establish information and asset handling requirements

    6.Which of the following controls is specifically designed to protect sensitive data from exposure while maintaining its usability for non-production purposes?

    1. A.Data encryption, which secures data integrity by preventing unauthorized modifications.
    2. B.Data cleansing, which detects and corrects inaccurate records within the dataset.
    3. C.Data masking, which obscures specific fields to protect sensitive information from exposure.
    4. D.Data retention, which applies time-based rules to archive or delete obsolete customer files.
    Show answer & explanation

    Correct answer: CData masking, which obscures specific fields to protect sensitive information from exposure.

    • A. Incorrect. Data encryption primarily protects confidentiality and integrity by preventing unauthorized access or modifications, but it does not address data accuracy or obscuring fields for non-production use.
    • B. Incorrect. Data cleansing detects and corrects inaccurate records to improve data quality, but it does not obscure sensitive fields or protect confidentiality.
    • C. Correct. Data masking obscures sensitive fields (e.g., PII) so that unauthorized users cannot see actual values, protecting confidentiality while allowing data to be used for testing, analysis, or support purposes.
    • D. Incorrect. Data retention defines how long data is kept and when it is archived or deleted based on policy or legal requirements, but it does not obscure sensitive information from exposure.

    Subdomain 2.1: Identify and classify information and assets

    7.What is the most appropriate method for determining the value of information assets for classification purposes?

    1. A.Calculate the cost to replace the data if lost.
    2. B.Determine its contribution to market capitalization.
    3. C.Estimate revenue from potential sales of the data.
    4. D.Assess the expense originally incurred to gather the data.
    Show answer & explanation

    Correct answer: BDetermine its contribution to market capitalization.

    • A. Incorrect. Replacement cost may be useful for some tangible assets, but it does not reflect the intrinsic business value of information. In CISSP terms, information value is usually tied to the business impact and potential revenue or advantage it provides, not just replacement expense.
    • B. Correct. A common way to value information is by its contribution to the organization's overall worth, including market capitalization. This reflects how the data affects business performance, investor confidence, and competitive advantage.
    • C. Incorrect. Potential sales revenue may apply if the data itself is being monetized, but that is not the broadest or most standard measure of information value. CISSP questions typically emphasize business value rather than hypothetical resale value.
    • D. Incorrect. Historical acquisition or collection cost is an accounting metric, not a true measure of the data's current value to the organization. Data can become far more valuable over time due to its strategic importance and use.

    Subdomain 2.3: Provision information and assets securely

    8.An organization is decommissioning a large number of hard drives that contain sensitive financial data. They need to select a data sanitization standard that ensures data cannot be recovered. Which of the following standards would be the MOST appropriate?

    1. A.NIST SP 800-88, providing procedures for clearing, purging, and destroying media to prevent data recovery.
    2. B.ISO 27001, a management standard for establishing an information security management system with control objectives.
    3. C.PCI DSS, a standard for protecting cardholder data that includes requirements for secure disposal of media.
    4. D.NIST SP 800-53, a control catalog for federal systems that includes media protection family but no specific methods.
    Show answer & explanation

    Correct answer: ANIST SP 800-88, providing procedures for clearing, purging, and destroying media to prevent data recovery.

    • A. Correct. NIST SP 800-88 is the authoritative guideline for media sanitization, providing detailed procedures such as clearing, purging, and destroying media to ensure data cannot be recovered. It is directly applicable to decommissioning hard drives containing sensitive financial data.
    • B. Incorrect. ISO 27001 is a management system standard for establishing and maintaining an information security management system. It does not provide specific technical methods for data sanitization or media destruction.
    • C. Incorrect. PCI DSS includes requirements for secure disposal of media containing cardholder data, but it is a compliance standard focused on payment card environments. It is not a comprehensive data sanitization standard and lacks the detailed methods of NIST SP 800-88.
    • D. Incorrect. NIST SP 800-53 provides a catalog of security controls, including media protection, but it does not offer specific sanitization procedures. It is broader in scope and less directly applicable to ensuring hard drives cannot be recovered.

    Subdomain 2.5: Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)

    9.A server has reached end-of-support but must be retained for 10 years due to regulatory requirements. Which of the following approaches minimizes risk while still meeting the retention requirement?

    1. A.Isolate the server on a dedicated VLAN with strict firewall rules and continue using it for 10 years to meet the retention requirement.
    2. B.Migrate all data to an encrypted cloud storage service and configure retention policies to preserve it for the required 10 years.
    3. C.Create a bit-by-bit disk image, store it offline in a secured safe, and then decommission the server to eliminate risk.
    4. D.Obtain an extended vendor support contract to receive critical patches and use the server for the full retention period.
    Show answer & explanation

    Correct answer: CCreate a bit-by-bit disk image, store it offline in a secured safe, and then decommission the server to eliminate risk.

    • A. Incorrect. Isolating an end-of-support server reduces exposure but does not eliminate the risk of unpatched vulnerabilities. Continuing to run the server for 10 years leaves it susceptible to attacks and compliance issues, increasing overall risk.
    • B. Incorrect. While migrating data to encrypted cloud storage can preserve data, it does not retain the server itself, which may be required. Additionally, relying on a third-party service introduces risks such as provider failure, data sovereignty, and potential compliance gaps. This option also does not provide forensically sound preservation of the original system.
    • C. Correct. Creating a bit-by-bit disk image preserves the server's contents in a forensically sound manner, allowing decommissioning of the vulnerable hardware. Storing the image offline in a secured safe eliminates ongoing risk while meeting retention requirements for the full 10 years.
    • D. Incorrect. Extended vendor support may not be available for the entire 10-year period and can be costly. It also keeps the unsupported server operational, maintaining the risk of hardware failure and eventual lack of patches, which does not minimize risk effectively.

    Domain 3: Security Architecture and Engineering

    Subdomain 3.9: Design site and facility security controls

    10.Which of the following physical security controls is specifically designed to prevent tailgating or piggybacking by trapping individuals between two interlocking doors?

    1. A.Turnstile
    2. B.Mantrap
    3. C.Security guard
    4. D.CCTV camera
    Show answer & explanation

    Correct answer: BMantrap

    • A. Incorrect. A turnstile allows one person at a time to pass, but it does not fully prevent tailgating as an unauthorized individual could still follow closely behind an authorized person.
    • B. Correct. A mantrap is a small, enclosed space with two interlocking doors that can only be opened one at a time, effectively trapping unauthorized individuals who attempt to tailgate or piggyback into a secure area.
    • C. Incorrect. A security guard can monitor and deter tailgating, but this is a human control that may be less consistent and reliable than a dedicated physical barrier like a mantrap.
    • D. Incorrect. A CCTV camera is a detective control that records activity but does not physically prevent unauthorized entry or tailgating.

    Subdomain 3.10: Manage the information system lifecycle

    11.A healthcare organization is developing a new mobile application to allow patients to access their medical records. The security team is involved early to ensure privacy and security requirements are properly captured. Which approach best ensures that security and privacy requirements are derived from stakeholder needs?

    1. A.Conduct threat modeling sessions with developers after requirements are finalized to identify potential security issues.
    2. B.Facilitate joint requirements workshops with patients, clinicians, and IT security to elicit functional and non-functional security needs.
    3. C.Review the application's architecture design to ensure it aligns with HIPAA technical safeguards before development begins.
    4. D.Deploy a web application firewall to monitor traffic and block common attacks during the testing phase.
    Show answer & explanation

    Correct answer: BFacilitate joint requirements workshops with patients, clinicians, and IT security to elicit functional and non-functional security needs.

    • A. Incorrect. Threat modeling is useful for identifying risks and validating security controls, but it is typically performed after or alongside requirements gathering. It does not directly capture requirements from stakeholders, making it a reactive rather than proactive approach for this purpose.
    • B. Correct. Joint requirements workshops bring together patients, clinicians, and IT security to directly elicit both functional and non-functional security needs. This proactive and collaborative method ensures security and privacy requirements are derived from stakeholder input early in the lifecycle.
    • C. Incorrect. Reviewing the architecture against HIPAA technical safeguards is a compliance and design-validation activity. While important, it occurs after requirements are defined and does not derive security and privacy requirements from stakeholder needs.
    • D. Incorrect. Deploying a web application firewall is an operational control implemented during testing or production. It mitigates common web threats but does not help determine what stakeholders need in terms of security and privacy requirements.

    Subdomain 3.3: Select controls based upon systems security requirements

    12.Which of the following controls would best detect unauthorized modifications to patient records as quickly as possible?

    1. A.Deploy a file integrity monitoring tool that generates real-time alerts when patient records are altered without authorization.
    2. B.Configure a login banner on clinical workstations that warns users actions are monitored and unauthorized changes lead to disciplinary action.
    3. C.Apply mandatory access control labels to all patient records so that only users with the matching clearance can modify them.
    4. D.Schedule monthly reviews of access logs by the compliance department to detect and investigate unauthorized record modifications.
    Show answer & explanation

    Correct answer: ADeploy a file integrity monitoring tool that generates real-time alerts when patient records are altered without authorization.

    • A. Correct. A file integrity monitoring (FIM) tool with real-time alerts is a detective control that can identify unauthorized changes to patient records immediately after they occur, enabling rapid detection and response.
    • B. Incorrect. A login banner is a deterrent and awareness control, not a detective control. It does not actively monitor or detect unauthorized modifications.
    • C. Incorrect. Mandatory access control (MAC) is a preventive control that restricts who can modify records, but it does not detect unauthorized changes quickly after they occur.
    • D. Incorrect. Monthly access log reviews are a detective control, but the monthly interval is too infrequent to detect unauthorized modifications as quickly as possible.

    Subdomain 3.1: Research, implement and manage engineering processes using secure design principles

    13.Which security principle ensures that no single individual has complete control over a critical process?

    1. A.Least privilege
    2. B.Segregation of duties
    3. C.Defense in depth
    4. D.Zero trust
    Show answer & explanation

    Correct answer: BSegregation of duties

    • A. Least privilege limits users to minimum necessary permissions but does not require dividing a process among multiple individuals; it reduces risk but does not prevent a single person from controlling an entire process alone.
    • B. Segregation of duties divides critical functions among multiple people to prevent fraud, errors, or abuse, ensuring no single person has complete control. This is a fundamental secure design principle.
    • C. Defense in depth uses multiple layers of security controls to protect assets, but it does not specifically address dividing responsibilities among different people.
    • D. Zero trust assumes no implicit trust and requires continuous verification, focusing on access control rather than dividing a process among multiple individuals.

    Subdomain 3.6: Select and determine cryptographic solutions

    14.Which statement about Quantum Key Distribution (QKD) is TRUE?

    1. A.QKD relies on the computational complexity of integer factorization and discrete logarithm problems to secure the key exchange.
    2. B.QKD uses quantum mechanical properties like the no-cloning theorem to detect any eavesdropping on the key distribution channel.
    3. C.QKD is implemented using post-quantum cryptographic algorithms such as lattice-based or code-based cryptography for key generation.
    4. D.QKD transmits the actual message encrypted with a quantum one-time pad over a dedicated quantum communication link.
    Show answer & explanation

    Correct answer: BQKD uses quantum mechanical properties like the no-cloning theorem to detect any eavesdropping on the key distribution channel.

    • A. Incorrect. QKD does not rely on computational hardness assumptions like integer factorization or discrete logarithms, which are the basis for classical public-key cryptography (e.g., RSA, Diffie-Hellman). Instead, QKD leverages quantum mechanical principles for security.
    • B. Correct. QKD uses quantum mechanical properties such as the no-cloning theorem and measurement disturbance to detect any eavesdropping on the key distribution channel. This is the core security feature of QKD, ensuring that the key exchange is secure.
    • C. Incorrect. Post-quantum cryptographic algorithms (e.g., lattice-based, code-based) are classical algorithms designed to resist attacks from quantum computers. They are not QKD. QKD is a quantum communication technique for distributing keys, not a category of algorithms.
    • D. Incorrect. QKD is used to distribute cryptographic keys, not to transmit the actual encrypted message. After key distribution, the message is typically encrypted using classical symmetric encryption. The concept of a quantum one-time pad is theoretical and not the standard implementation.

    Subdomain 3.8: Apply security principles to site and facility design

    15.A data center experiences frequent power fluctuations that cause the backup generator to start, but the existing UPS batteries drain before the generator assumes the load. The UPS power capacity is adequate for the equipment. Which solution directly addresses the runtime gap?

    1. A.Install additional battery strings to the existing UPS to extend runtime.
    2. B.Replace the entire UPS with a model that has double the power rating.
    3. C.Deploy a static transfer switch to instantly cut over to generator power.
    4. D.Replace the backup generator with one that has a faster automatic start.
    Show answer & explanation

    Correct answer: AInstall additional battery strings to the existing UPS to extend runtime.

    • A. Correct. Adding extra battery strings to the existing UPS increases its runtime capacity, directly bridging the gap between the UPS depletion and generator takeover. Since the UPS power capacity is already adequate for the equipment, the issue is runtime duration, not wattage.
    • B. Incorrect. Replacing the UPS with a higher power rating does not address the runtime gap; the problem is that the batteries drain too quickly, not that the power capacity is insufficient. The question explicitly states the existing UPS power capacity is adequate.
    • C. Incorrect. A static transfer switch provides fast switching between power sources but does not extend the UPS battery runtime. It cannot prevent the batteries from draining before the generator comes online.
    • D. Incorrect. A faster-starting generator could reduce the transition time, but it does not directly address the UPS runtime limitation. The root cause is that the UPS batteries cannot sustain the load long enough; extending battery runtime is the most direct solution.

    Subdomain 3.2: Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)

    16.A security analyst who previously worked at OilCo is now assigned to PetroCorp, a competitor. Which of the following best describes the access decision under the Chinese Wall (Brewer-Nash) model when the analyst requests data that may conflict with OilCo's interests?

    1. A.Access is granted only if a mandatory two-year cooling-off period has passed.
    2. B.Access is automatically granted because the analyst is now assigned to PetroCorp.
    3. C.Access is denied unless the analyst has not previously accessed OilCo's data.
    4. D.Access is granted only after a mandatory security review by the compliance team.
    Show answer & explanation

    Correct answer: CAccess is denied unless the analyst has not previously accessed OilCo's data.

    • A. Incorrect. A cooling-off period is not part of the Chinese Wall model's core rules. The model restricts access based on prior access history within the same conflict-of-interest class, not a fixed time delay. While some organizations implement cooling-off periods as an administrative control, the model itself does not require it.
    • B. Incorrect. Being assigned to PetroCorp does not automatically override the conflict-of-interest restriction. Under the Chinese Wall model, previous access to competing companies' data is the key factor; if the analyst already accessed OilCo's data, access to similar data at PetroCorp is blocked regardless of the new assignment.
    • C. Correct. The Chinese Wall model prevents access when a user has previously accessed data from a competing organization within the same conflict-of-interest class. If the analyst has not previously accessed OilCo's data, access may be allowed; however, if they have, access to competing data sets is denied. This matches the option: access is denied unless the analyst has not previously accessed OilCo's data.
    • D. Incorrect. A mandatory security review by the compliance team is an administrative process, not the defining rule of the Chinese Wall model. The model automatically enforces access control based on prior access history and conflict-of-interest classes, without requiring manual approval or review.

    Domain 5: Identity and Access Management (IAM)

    Subdomain 5.3: Federated identity with a third-party service

    17.During a penetration test, an assessor captures a SAML response from an IdP and replays it to the SP to gain unauthorized access as a different user. The SAML response is still within its validity period. Which security control would have most effectively prevented this attack?

    1. A.Encrypting the SAML assertion with the SP's public key.
    2. B.Including a nonce in the SAML response and verifying it.
    3. C.Using HTTP POST binding instead of Redirect binding.
    4. D.Signing the SAML assertion with the IdP's private key.
    Show answer & explanation

    Correct answer: BIncluding a nonce in the SAML response and verifying it.

    • A. Incorrect. Encrypting the SAML assertion with the SP's public key protects confidentiality, but it does not prevent replay attacks because the encrypted assertion can still be replayed if captured. The attacker does not need to read the content; they simply present it again to the SP.
    • B. Correct. Including a nonce (a one-time-use random value) in the SAML response and verifying it at the SP ensures that each response is unique and cannot be reused. This directly mitigates replay attacks because the captured response would be rejected on the second attempt, even if still within its validity period.
    • C. Incorrect. Using HTTP POST binding instead of Redirect binding may reduce exposure by avoiding URL-encoded data in the browser address bar, but it does not inherently prevent replay attacks. The core weakness is the lack of replay protection, not the transport binding choice.
    • D. Incorrect. Signing the SAML assertion with the IdP's private key ensures integrity and authenticity, but a replayed signed assertion is still valid if the SP does not enforce one-time use or replay detection. A signature does not stop reuse of a legitimate message.

    Subdomain 5.2: Design identification and authentication strategy (e.g., people, devices, and services)

    18.Which of the following best implements just-in-time privileged access for administrators?

    1. A.Use a password vault to check out a secondary admin account, manually resetting it after each use.
    2. B.Deploy a PAM solution that provisions temporary admin accounts with pre-defined expiration times.
    3. C.Use a gMSA that automatically rotates passwords and delegates the necessary permissions.
    4. D.Require manager approval for server login and manually revoke access after the task.
    Show answer & explanation

    Correct answer: BDeploy a PAM solution that provisions temporary admin accounts with pre-defined expiration times.

    • A. Incorrect. While a password vault improves credential security, requiring manual checkout and resetting introduces human error and delays, failing to provide automated, just-in-time access control.
    • B. Correct. A Privileged Access Management (PAM) solution provisions temporary admin accounts with predefined expiration times, automating just-in-time access, reducing standing privileges, and improving auditability and revocation.
    • C. Incorrect. Group Managed Service Accounts (gMSA) are designed for service-to-service authentication, not human admin access. They lack granular control and are not suited for just-in-time privileged access for individuals.
    • D. Incorrect. Requiring manager approval and manual revocation is inefficient, prone to delays, and does not scale. It lacks automation and timely access revocation needed for just-in-time control.

    Subdomain 5.4: Implement and manage authorization mechanisms

    19.Which access control model allows the resource owner to determine who can access the resource?

    1. A.Role-Based Access Control (RBAC)
    2. B.Discretionary Access Control (DAC)
    3. C.Attribute-Based Access Control (ABAC)
    4. D.Rule-Based Access Control
    Show answer & explanation

    Correct answer: BDiscretionary Access Control (DAC)

    • A. Incorrect. Role-Based Access Control (RBAC) grants access based on predefined roles assigned to users, not on the discretion of the resource owner. Access is centrally managed according to job functions.
    • B. Correct. Discretionary Access Control (DAC) allows the owner of a resource to decide who can access it and what permissions they have. This model is based on the owner's discretion, typically implemented via access control lists (ACLs).
    • C. Incorrect. Attribute-Based Access Control (ABAC) makes access decisions using attributes (e.g., user role, time, location). It is policy-driven and does not rely on the resource owner's direct discretion.
    • D. Incorrect. Rule-Based Access Control uses predefined rules or conditions (e.g., firewall rules) to grant or deny access. It is enforced by the system, not by the resource owner.

    Subdomain 5.1: Control physical and logical access to assets

    20.Which access control model is most appropriate for a healthcare organization that requires separation of duties between surgeons and billing specialists?

    1. A.Use Attribute-Based Access Control to evaluate user attributes, resource labels, and context for access decisions.
    2. B.Apply Role-Based Access Control with distinct roles for surgeons and billing specialists to limit access by function.
    3. C.Implement Discretionary Access Control where data owners set permissions on individual patient records for each user.
    4. D.Enforce Mandatory Access Control by labeling records and granting clearances based on staff security levels.
    Show answer & explanation

    Correct answer: BApply Role-Based Access Control with distinct roles for surgeons and billing specialists to limit access by function.

    • A. Incorrect. Attribute-Based Access Control (ABAC) evaluates user attributes, resource labels, and context, which can be complex and may not provide the clear role-based separation of duties required in a healthcare setting. Without a specific need for fine-grained context-aware decisions, RBAC is more straightforward.
    • B. Correct. Role-Based Access Control (RBAC) assigns permissions based on job functions, ensuring that surgeons and billing specialists have distinct roles with limited access. This aligns with the principle of least privilege and separation of duties, making it the best fit for healthcare environments.
    • C. Incorrect. Discretionary Access Control (DAC) allows data owners to set permissions on individual records, which can lead to inconsistent or overly permissive access. It does not enforce standardized, function-based separation of duties and can violate least privilege.
    • D. Incorrect. Mandatory Access Control (MAC) uses security labels and clearances, typically found in military or government settings. It is overly rigid and complex for a healthcare organization seeking role-based access by job function.

    Subdomain 5.6: Implement authentication systems

    21.Which protocol does Azure Active Directory natively use for modern authentication flows, including OAuth 2.0 authorization and token issuance?

    1. A.LDAP
    2. B.Kerberos
    3. C.SAML 2.0
    4. D.OpenID Connect (OIDC)
    Show answer & explanation

    Correct answer: DOpenID Connect (OIDC)

    • A. Incorrect. LDAP (Lightweight Directory Access Protocol) is used for directory services and querying directory data, not for modern web-based authentication flows like OAuth 2.0 or token issuance in Azure AD.
    • B. Incorrect. Kerberos is a network authentication protocol used for mutual authentication and single sign-on in Windows domain environments. It does not provide the modern OAuth 2.0 authorization and token issuance model used natively by Azure AD.
    • C. Incorrect. SAML 2.0 is used for federation and single sign-on, but Azure AD primarily uses OpenID Connect (built on OAuth 2.0) for modern authentication flows and token issuance. SAML is supported but not the native protocol for modern apps.
    • D. Correct. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. Azure Active Directory natively uses OIDC for modern authentication flows, including token issuance and identity verification.

    Domain 6: Security Assessment and Testing

    Subdomain 6.2: Conduct security control testing

    22.Which of the following activities is best suited for testing the effectiveness of security controls within an organization's internal network?

    1. A.External penetration test on internet assets
    2. B.Internal vulnerability scan with authenticated access
    3. C.Third-party ISO 27001 compliance audit
    4. D.Cloud security posture review of all SaaS platforms
    Show answer & explanation

    Correct answer: BInternal vulnerability scan with authenticated access

    • A. An external penetration test on internet assets simulates real-world attacks from an external perspective, actively identifying exploitable vulnerabilities in internet-facing systems. However, it is narrower in scope than an internal authenticated scan, focusing only on externally visible systems and not providing comprehensive testing of all internal security controls.
    • B. An internal vulnerability scan with authenticated access provides deeper visibility into systems, configurations, and missing patches. Authenticated scanning validates how well internal security controls are implemented and whether they are functioning as intended, making it a strong method for testing the effectiveness of security controls across the internal environment.
    • C. A third-party ISO 27001 compliance audit assesses whether the organization meets a management system standard, but it does not actively test for vulnerabilities or directly evaluate the effectiveness of technical security controls. It focuses more on governance and compliance than on direct control testing.
    • D. A cloud security posture review can identify misconfigurations across SaaS platforms, but it is primarily a configuration assessment rather than a comprehensive security control test. It does not provide the same direct validation of internal security control effectiveness as an authenticated internal scan.

    Subdomain 6.1: Design and validate assessment, test, and audit strategies

    23.A healthcare organization must comply with HIPAA and wants to implement a log review strategy that meets regulatory requirements and improves incident detection. The security team has limited resources and a high volume of logs from various systems. Which approach should they adopt to effectively design the log review process?

    1. A.Review all logs manually on a weekly basis, focusing on authentication failures and access to patient records.
    2. B.Implement a SIEM with correlation rules to automate log analysis and generate alerts for suspicious activities.
    3. C.Outsource log storage to a cloud provider and review summary reports quarterly for compliance.
    4. D.Use a centralized log management tool to collect logs and randomly sample 10% of log entries for daily review.
    Show answer & explanation

    Correct answer: BImplement a SIEM with correlation rules to automate log analysis and generate alerts for suspicious activities.

    • A. Incorrect. Manual weekly reviews are not scalable for high-volume logs, delay detection of incidents, and do not meet HIPAA's requirement for timely monitoring and response.
    • B. Correct. A SIEM automates log analysis, correlates events across systems, and generates alerts for suspicious activities, enabling efficient detection and compliance with HIPAA's monitoring requirements.
    • C. Incorrect. Outsourcing storage and quarterly reviews are insufficient; HIPAA requires continuous or frequent monitoring and active analysis, not just retention and infrequent summaries.
    • D. Incorrect. Randomly sampling 10% of logs is unreliable for incident detection and does not provide comprehensive coverage; centralized collection alone is not effective without automated analysis.

    Subdomain 6.4: Analyze test output and generate report

    24.During a penetration test, a tester discovers a critical vulnerability in a third-party vendor product used by the client. What is the most appropriate action?

    1. A.Immediately notify the client per the agreement and advise them to coordinate with the vendor for responsible disclosure, refraining from publicizing the flaw until a patch is released.
    2. B.Submit the vulnerability to a public bug bounty platform to ensure the widest possible notification, then inform the client during the final report presentation.
    3. C.Develop and release a proof-of-concept exploit to demonstrate the severity, providing it to the client and vendor simultaneously to pressure a quick fix.
    4. D.Keep the vulnerability confidential and use it in subsequent penetration tests to demonstrate the risk to other clients, as it is not explicitly covered by the current engagement.
    Show answer & explanation

    Correct answer: AImmediately notify the client per the agreement and advise them to coordinate with the vendor for responsible disclosure, refraining from publicizing the flaw until a patch is released.

    • A. Correct. This option adheres to responsible disclosure principles and the agreed rules of engagement. Immediately notifying the client allows them to coordinate with the vendor for a patch, minimizing risk of exploitation. Public disclosure is deferred until after remediation.
    • B. Incorrect. Submitting the vulnerability to a public bug bounty platform without prior client notification violates confidentiality and responsible disclosure norms. It may breach the engagement agreement and expose the client to unnecessary risk.
    • C. Incorrect. Developing and releasing a proof-of-concept exploit without authorization is unethical and dangerous. It increases the risk of malicious exploitation and does not follow professional standards for vulnerability disclosure.
    • D. Incorrect. Keeping the vulnerability confidential and reusing it in other engagements is unethical and potentially illegal. Findings from one client are confidential and must not be used against other clients without explicit permission and proper disclosure.

    Domain 7: Security Operations

    Subdomain 7.7: Operate and maintain detection and preventative measures

    25.A financial services company is launching a new public-facing web application that handles sensitive customer transactions. The current infrastructure includes a stateful network firewall filtering inbound traffic at the perimeter. The security team wants to mitigate risks from SQL injection, cross-site scripting, and other OWASP Top 10 threats. Which of the following should the team deploy NEXT to address these threats?

    1. A.Deploy a network-based intrusion detection system (NIDS) and configure custom signatures to detect SQL injection and cross-site scripting patterns.
    2. B.Implement a web application firewall (WAF) to inspect inbound HTTP/HTTPS traffic and block malicious requests using OWASP-based rule sets.
    3. C.Install host-based intrusion prevention system (HIPS) agents on each web server to intercept and block malicious application-layer calls at the host level.
    4. D.Upgrade the existing stateful firewall to a next-generation firewall (NGFW) and enable application-layer filtering with intrusion prevention capabilities.
    Show answer & explanation

    Correct answer: BImplement a web application firewall (WAF) to inspect inbound HTTP/HTTPS traffic and block malicious requests using OWASP-based rule sets.

    • A. Incorrect. A NIDS can detect malicious patterns but is primarily a detection control, not a prevention control. It does not block traffic by default, and operating at the network layer limits its effectiveness for application-layer attacks like SQL injection and XSS without extensive tuning. A WAF is better suited for inspecting and blocking these web-specific threats.
    • B. Correct. A WAF is purpose-built to inspect HTTP/HTTPS traffic and block application-layer attacks, including SQL injection, XSS, and other OWASP Top 10 threats. It provides pre-configured OWASP-based rule sets that are specifically designed to mitigate these risks, making it the most appropriate next step after a stateful firewall.
    • C. Incorrect. While a HIPS can intercept malicious calls at the host level, it is less efficient for public-facing web applications. HIPS requires deployment on each server, adding operational overhead, and it does not provide the same granularity or scalability for application-layer attack patterns as a dedicated WAF.
    • D. Incorrect. An NGFW adds application-layer filtering and IPS capabilities, but it is not as specialized as a WAF for OWASP Top 10 threats. NGFWs are broader in scope and may lack the depth of application-specific protections and rule sets that a dedicated WAF offers for web application attacks.

    Subdomain 7.11: Implement disaster recovery (DR) processes

    26.During a disaster recovery restoration, one of the two authorized operators for the escrowed recovery key is unavailable. What is the most appropriate action to maintain security controls?

    1. A.Retrieve the escrowed recovery key from the security officer, document that the operator is unavailable, and proceed with restoration.
    2. B.Postpone restoration until the operator becomes available, because dual control is required for key handling and no single person should have it.
    3. C.Report to management that recovery is blocked, request a formal risk acceptance for the delay, and await their decision.
    4. D.Use forensic password recovery tools to attempt extraction of the cryptographic keys from the backup system to continue restoration.
    Show answer & explanation

    Correct answer: BPostpone restoration until the operator becomes available, because dual control is required for key handling and no single person should have it.

    • A. Incorrect. While documenting the operator's unavailability is a good administrative step, proceeding with only the security officer providing the escrowed key bypasses the required dual-control process for cryptographic key handling. Dual control ensures that no single individual can access or use sensitive keys, and violating this policy introduces significant security risk.
    • B. Correct. Dual control is a fundamental principle in cryptographic key management, requiring at least two authorized individuals to access or use keys. Postponing restoration until the second operator is available preserves separation of duties and prevents unauthorized access or misuse of recovery keys. This maintains the integrity of the DR process and adheres to security best practices.
    • C. Incorrect. While escalating to management is appropriate if recovery is delayed, requesting a formal risk acceptance is not the immediate operational response when a required control cannot be met. The priority in disaster recovery is to follow the approved recovery procedure and maintain control integrity, not to accept risk as a substitute for mandatory dual control. This option also introduces unnecessary delays.
    • D. Incorrect. Using forensic password recovery tools to extract cryptographic keys from the backup system is risky, may violate security policies, and could compromise the integrity of the cryptographic system. DR should rely on authorized recovery mechanisms, such as escrowed keys and documented procedures, rather than attempting to circumvent key protection controls.

    Subdomain 7.15: Address personnel safety and security concerns

    27.Which of the following best describes a fail-secure lock's appropriate use in an emergency?

    1. A.Unlock a door under emergency conditions while simultaneously triggering a silent alarm.
    2. B.Provide access during fire evacuations without requiring a badge swipe.
    3. C.Allow security guards to bypass two-factor authentication during an armed intrusion.
    4. D.Permit building maintenance staff to enter sensitive areas after hours without logging.
    Show answer & explanation

    Correct answer: BProvide access during fire evacuations without requiring a badge swipe.

    • A. Incorrect. A fail-secure lock remains locked during a power failure and does not inherently unlock during emergencies. While life safety may override security in extreme cases, triggering a silent alarm is not a standard fail-secure function; this scenario typically requires a fail-safe or manual override mechanism.
    • B. Correct. Fail-secure locks are designed to remain locked during a power failure for security, but they can be integrated with fire alarm systems to unlock during fire evacuations. This balances life safety and security, ensuring personnel can exit without swiping badges while maintaining protection under normal conditions.
    • C. Incorrect. Bypassing two-factor authentication during an armed intrusion weakens access control and is not a feature of fail-secure locks. Emergency procedures should rely on predefined incident response plans, not ad hoc disabling of authentication.
    • D. Incorrect. Permitting unlogged after-hours access to sensitive areas violates accountability and security principles. Fail-secure locks do not override logging requirements; personnel safety concerns do not justify removing audit trails.

    Subdomain 7.6: Conduct incident management

    28.An organization has experienced a phishing attack that compromised several user accounts. Which of the following is the most effective immediate response action?

    1. A.Update the email gateway filter rules and retrain the machine learning models with the latest phishing email samples.
    2. B.Disable external email delivery for all employees in the finance department until a third-party security audit is conducted.
    3. C.Schedule a mandatory meeting with the employees who clicked the phishing links to review the acceptable use policy.
    4. D.Reconfigure email gateway filters and implement a new phishing training program with simulated exercises.
    Show answer & explanation

    Correct answer: DReconfigure email gateway filters and implement a new phishing training program with simulated exercises.

    • A. Incorrect. While updating email gateway filter rules and retraining machine learning models is a valid technical control, it alone does not address the immediate threat or provide a comprehensive corrective action. It focuses on detection and prevention but lacks administrative measures to reduce recurrence.
    • B. Incorrect. Disabling external email delivery for an entire department is overly disruptive and disproportionate for a phishing incident without evidence of broader compromise. Waiting for a third-party audit delays necessary immediate corrective actions and may not effectively contain the incident.
    • C. Incorrect. Scheduling a mandatory meeting to review the acceptable use policy is a reactive administrative measure. It does not directly mitigate the phishing threat or improve technical defenses. While useful as a follow-up, it is not the most effective primary response.
    • D. Correct. Reconfiguring email gateway filters provides an immediate technical corrective control to prevent further phishing emails from reaching users. Implementing a new phishing training program with simulated exercises addresses the human factor that phishing exploits, supporting lessons learned and reducing the chance of recurrence. This combination of technical and administrative controls is the most complete and effective incident response.

    Subdomain 7.8: Implement and support patch and vulnerability management

    29.A security assessment reveals a critical vulnerability in a server application for which no vendor patch is currently available. What is the BEST immediate action to mitigate risk while awaiting the patch?

    1. A.Isolate the server from the network to reduce exposure and await the vendor patch release.
    2. B.Deploy appropriate compensating controls like intrusion prevention rules or application firewalls.
    3. C.Formally accept the residual risk by management and continue operations with increased monitoring.
    4. D.Demand that the software vendor provide an out-of-band emergency fix within one business day.
    Show answer & explanation

    Correct answer: BDeploy appropriate compensating controls like intrusion prevention rules or application firewalls.

    • A. Incorrect. Isolating the server may be appropriate in extreme emergencies, but it can disrupt business operations unnecessarily if less impactful controls can sufficiently reduce risk. It should only be considered when the risk is unacceptable and no other mitigations are feasible.
    • B. Correct. Deploying compensating controls such as intrusion prevention system (IPS) signatures, web application firewall (WAF) rules, network segmentation, or configuration hardening is the preferred approach when an official patch is not yet available. These measures reduce exposure while maintaining business operations, aligning with risk management best practices.
    • C. Incorrect. Formally accepting residual risk is a management decision that should only occur after all other mitigations have been evaluated. It does not actively reduce the vulnerability and is not the best immediate response when compensating controls are available.
    • D. Incorrect. Demanding an out-of-band fix within one business day is unrealistic and may not be feasible for the vendor. This is not a practical security control; the organization should focus on implementing compensating controls and coordinating with the vendor through normal channels.

    Subdomain 7.13: Participate in Business Continuity (BC) planning and exercises

    30.Which type of alternate processing site provides a fully operational duplicate of the primary site with real-time data synchronization and immediate failover capability?

    1. A.Hot site
    2. B.Warm site
    3. C.Cold site
    4. D.Mirrored site
    Show answer & explanation

    Correct answer: DMirrored site

    • A. Incorrect. A hot site is fully equipped and can be brought online quickly, but it typically does not have real-time data synchronization. There may be minor data lag during failover.
    • B. Incorrect. A warm site has some hardware and possibly recent backups, but it is not a real-time duplicate. It requires hours or days to become fully operational.
    • C. Incorrect. A cold site provides only basic infrastructure like power and cooling, with no pre-installed equipment or data. Recovery time is longest and not suitable for immediate continuity.
    • D. Correct. A mirrored site is an exact duplicate with real-time data replication, enabling immediate failover with no data loss or downtime. It offers the highest level of availability among the listed options.

    Subdomain 7.2: Conduct logging and monitoring activities

    31.Which of the following activities is most directly associated with the conduct of logging and monitoring?(Select 2)

    1. A.Automatically isolate compromised endpoints from the network to prevent the spread of malware and contain threats.
    2. B.Establish baselines of normal activity to detect anomalies indicative of insider threats or compromised accounts.
    3. C.Monitor network traffic in real time and block connections that exhibit patterns matching known attack signatures.
    4. D.Aggregate and normalize logs from multiple sources to support centralized analysis and compliance reporting.
    Show answer & explanation

    Correct answers: B, DEstablish baselines of normal activity to detect anomalies indicative of insider threats or compromised accounts.; Aggregate and normalize logs from multiple sources to support centralized analysis and compliance reporting.

    • A. Incorrect. Automatically isolating compromised endpoints is a containment action aligned with incident response, not a core logging and monitoring activity. While monitoring may trigger such actions, the isolation itself is not part of logging and monitoring.
    • B. Correct. Establishing baselines of normal activity is a fundamental monitoring practice used to identify deviations that may indicate insider threats, compromised accounts, or other suspicious behavior. This directly aligns with detecting anomalies through logging and monitoring.
    • C. Incorrect. Real-time traffic monitoring and blocking based on known signatures is primarily associated with intrusion prevention systems (IPS) or firewall operations. While it involves monitoring, the active blocking component goes beyond the scope of logging and monitoring, which focuses on detection and analysis.
    • D. Correct. Aggregating and normalizing logs from multiple sources is a core logging activity that supports centralized analysis, event correlation, and compliance reporting. This is a key practice within the logging and monitoring domain.

    Domain 8: Software Development Security

    Subdomain 8.5: Define and apply secure coding guidelines and standards

    32.Which of the following is a language-specific secure coding standard for C and C++?

    1. A.ISO/IEC 27034 Application Security Standard
    2. B.CERT C/C++ Secure Coding Standard
    3. C.OWASP Secure Coding Practices Quick Reference Guide
    4. D.MISRA C and C++ Coding Standards
    Show answer & explanation

    Correct answer: BCERT C/C++ Secure Coding Standard

    • A. Incorrect. ISO/IEC 27034 is a broad application security framework that provides guidelines for integrating security into the development lifecycle, but it is not a language-specific coding standard for C/C++.
    • B. Correct. The CERT C/C++ Secure Coding Standard is a widely recognized set of guidelines specifically designed to help developers write secure code in C and C++ by addressing common vulnerabilities such as buffer overflows, undefined behavior, and injection issues.
    • C. Incorrect. The OWASP Secure Coding Practices Quick Reference Guide offers general secure coding best practices applicable to many languages, but it is not a prescriptive, language-specific standard like the CERT C/C++ standard.
    • D. Incorrect. MISRA C and C++ standards are primarily focused on safety-critical systems in industries like automotive and aerospace, emphasizing reliability and safety rather than security specifically.

    Subdomain 8.2: Identify and apply security controls in software development ecosystems

    33.Which of the following application security testing methods involves analyzing the source code of an application without executing it?

    1. A.Dynamic Application Security Testing (DAST)
    2. B.Interactive Application Security Testing (IAST)
    3. C.Static Application Security Testing (SAST)
    4. D.Software Composition Analysis (SCA)
    Show answer & explanation

    Correct answer: CStatic Application Security Testing (SAST)

    • A. Incorrect. Dynamic Application Security Testing (DAST) analyzes an application while it is running, typically by sending inputs and observing outputs from the outside-in. It does not inspect the source code directly without execution.
    • B. Incorrect. Interactive Application Security Testing (IAST) combines elements of static and dynamic testing by instrumenting the application during execution. Because it requires runtime analysis, it is not the method that analyzes source code without executing it.
    • C. Correct. Static Application Security Testing (SAST) examines source code, bytecode, or binaries without executing the application. It identifies vulnerabilities by analyzing the code structure and logic, making it a white-box testing method used early in the development lifecycle.
    • D. Incorrect. Software Composition Analysis (SCA) focuses on identifying known vulnerabilities in open-source and third-party components, libraries, and dependencies. It does not primarily analyze the application's own source code without execution.

    Subdomain 8.1: Understand and integrate security in the Software Development Life Cycle (SDLC)

    34.What is the best approach for deploying a critical security patch in a clustered production environment?

    1. A.Apply the patch directly to all nodes simultaneously to minimize the maintenance window.
    2. B.Test the patch on a mirrored staging environment, then deploy sequentially across cluster nodes.
    3. C.Deploy the patch during peak business hours to assess user-facing performance in real time.
    4. D.Skip testing because vendor patches are considered safe and the cluster provides redundancy.
    Show answer & explanation

    Correct answer: BTest the patch on a mirrored staging environment, then deploy sequentially across cluster nodes.

    • A. Incorrect. Applying the patch to all nodes simultaneously increases the risk of widespread failure and downtime. A staged rollout is safer to preserve availability and allow rollback if the patch introduces instability.
    • B. Correct. Testing the patch in a mirrored staging environment validates compatibility and identifies issues before production deployment. Sequential deployment across cluster nodes minimizes risk, maintains service availability, and allows for rollback if needed.
    • C. Incorrect. Peak business hours are the worst time to deploy changes because any disruption has maximum user impact. Security patches should be planned to minimize operational risk, not used as live performance tests.
    • D. Incorrect. Vendor patches still require validation because they can break dependencies, introduce regressions, or conflict with the environment. Redundancy does not protect against widespread deployment failures, so skipping testing is unsafe.

    Subdomain 8.4: Assess security impact of acquired software

    35.A law firm is transitioning from an on-premises email server to a cloud-based Software as a Service (SaaS) email solution to reduce operational overhead. The firm handles highly confidential client communications and is subject to strict data protection regulations. The IT director asks the security team to clarify the shared responsibility model for security. Which statement BEST describes the division of security responsibilities in this SaaS arrangement?

    1. A.The cloud provider is solely responsible for all security aspects because the SaaS application runs entirely in the provider’s environment, and the customer only accesses it via a web browser.
    2. B.The customer retains full responsibility for securing the email application, including patching the operating system and application, while the provider maintains physical infrastructure security.
    3. C.The provider manages physical, infrastructure, and application security, while the customer is responsible for access management, data classification, and securing endpoints that access the service.
    4. D.Both parties share equal responsibility for all security controls, meaning the customer must implement the same security measures as if the application were hosted on-premises.
    Show answer & explanation

    Correct answer: CThe provider manages physical, infrastructure, and application security, while the customer is responsible for access management, data classification, and securing endpoints that access the service.

    • A. Incorrect. In a SaaS model, the cloud provider is not solely responsible for all security aspects. The customer retains responsibility for certain areas, such as data governance, user access management, and endpoint security. The provider manages the application, infrastructure, and physical security, but the customer must still protect their own data and control access.
    • B. Incorrect. This describes an on-premises or IaaS model, not SaaS. In a SaaS arrangement, the provider handles patching of the operating system and application, as well as underlying infrastructure security. The customer does not have administrative access to the application stack and therefore cannot be responsible for patching it.
    • C. Correct. In a SaaS model, the provider is responsible for the physical data center security, network infrastructure, server OS, and the application itself, including patching and availability. The customer is responsible for identity and access management (IAM), data classification and protection, and securing the client devices (endpoints) that connect to the service.
    • D. Incorrect. The shared responsibility model does not imply equal responsibility for all controls. In SaaS, the provider takes on most operational security duties, while the customer retains responsibility for data and access. The customer does not need to implement the same security measures as an on-premises deployment; instead, the division is based on the service model.

    Want the full experience?

    These are just samples. Practice the full ISC2 Certified Information Systems Security Professional (CISSP) question bank in quiz mode — free, no signup, with domain practice and exam simulation.