- Home
- All questions
All 500 questions — CISSP — Certified Information Systems Security Professional
Every question in the free CISSP — Certified Information Systems Security Professional study material, one page each: the question, its options, the answer, the reasoning and a public source. Pick one of 10 topics or read them in order.
Challenge yourself → Study as cards
Topics
Every question
- 1. A regional insurer is finishing an authorisation package for a new claims platform. Assessors have documented three moderate findings, the system owner has drafted mitigation plans, and the chief information security officer wants the programme manager to sign off so the launch date holds. Who may formally accept the residual risk of operating the platform?
- 2. A federal agency wants to adopt a case-management application that a peer agency already runs under a current authorization to operate. The adopting agency will load its own records into the service and has no appetite for repeating the full assessment. Which authorisation decision fits this situation?
- 3. A shared services division publishes a hardened logging and identity stack that a dozen internal systems will inherit rather than build for themselves. Leadership asks what the authorisation decision covering that published stack must convey to the owners of the inheriting systems.
- 4. A manufacturer is standing up the Risk Management Framework for the first time. The security lead proposes to begin by categorising the first system in scope, while the enterprise architect argues that organisational groundwork must come first. Which activity does the framework place ahead of categorisation?
- 5. A bank is adopting the NIST Cybersecurity Framework 2.0 and the board asks which decisions belong to the Govern function that sits at the centre of the Core. Choose three.
- 6. An agency's authorisation for its payroll system expires every three years, and each renewal consumes a quarter of the security team's capacity while telling leadership little that is new in between. The chief information officer asks how the Risk Management Framework intends approval to be sustained instead.
- 7. A hospital group is chartering an information security continuous monitoring programme. Analysts propose to alert on every configuration change across the estate. The risk officer wants the programme scoped so its output actually drives decisions. Against what should the programme measure what it observes?
- 8. A retailer's risk team has finished assessing a new point-of-sale platform, weighing threats, vulnerabilities, cost against benefit, and the risk remaining once controls are applied. The team lead asks the security architect what the assessment report is entitled to conclude.
- 9. A defence supplier is building a cyber supply chain risk management (C-SCRM) programme guided by NIST SP 800-161 Rev. 1, which applies C-SCRM at several organisational levels. Which artefacts does that guidance expect the programme to produce? Choose three.
- 10. A software firm's leadership expects the NIST Cybersecurity Framework 2.0 to hand them a configuration standard for their cloud estate. The security lead has to reset that expectation before the programme starts. What does the framework itself provide?
- 11. A logistics company has recorded which NIST Cybersecurity Framework 2.0 outcomes it achieves today and, separately, the prioritised outcomes it intends to reach given new contractual requirements and threat trends. The programme manager asks what the organisation should do with the difference between the two.
- 12. A mid-sized utility sits at the Partial Tier under the NIST Cybersecurity Framework 2.0. A consultant urges an immediate push to Adaptive on the grounds that higher is always better. The chief risk officer wants a defensible position. When does moving to a higher Tier make sense?
- 13. A small water utility runs office IT and plant operational technology with one three-person team. It has worked from version 1.0.1 of CISA's Cross-Sector Cybersecurity Performance Goals and is moving to version 2.0. Which changes in 2.0 shape how the team plans its work? Choose two.
- 14. A hospital is retiring 400 laptop drives that held patient records. The security manager argues that only physical shredding can count as sanitisation and that a verified overwrite is worthless. The media sanitisation lead answers by citing the standard's own test for when media counts as sanitised. Which principle does the lead cite?
- 15. A cloud provider must decommission self-encrypting drives from a multi-tenant storage array inside a two-hour maintenance window far too short for a full-block overwrite of the array. Each drive holds ciphertext belonging to many tenants, and the drives are leased and must be returned to the lessor in working order. Which sanitisation method meets these constraints?
- 16. An agency system publishes public transit timetables. A falsified timetable would seriously mislead riders, an outage would merely inconvenience them, and the data is already public. The system owner wants one impact rating covering the whole system. How should the categorisation be performed?
- 17. A university drafts a single blanket handling rule covering every piece of personally identifiable information it holds, from published faculty office numbers to student health records. The privacy officer objects, citing the federal guidance on protecting such information. What does that guidance direct instead?
- 18. During an audit, a system owner claims the mapping of information types to impact categories binds the agency exactly as tightly as the requirement to categorise its systems. The auditor separates the two distinct assignments that legislation placed on the standards body. Which statement is accurate?
- 19. A logistics firm sends decommissioned equipment to a recycler. Some devices held only public route maps, while others held customer payment records, and the asset manager wants one defensible rule for choosing a disposal technique. Which rule matches the media sanitisation guidance?
- 20. A system owner is documenting, for each security objective, the kinds of compromise that could damage the mission. A colleague has written down only theft of data by an outsider. Which additional forms of compromise does the federal categorisation standard count? Choose three.
- 21. A privacy lead is scoping a programme against the federal guide to protecting personally identifiable information and must set the steering committee's expectations about the guide's actual reach. Which statements correctly describe its scope? Choose two.
- 22. A retailer is redesigning access after a breach in which an intruder who reached one internal subnet moved freely between servers. The architects want the model described in NIST SP 800-207 zero trust architecture. Which principle should drive the redesign?
- 23. An engineer is building the access flow for a zero trust architecture. A contractor signs in with MFA from a laptop the enterprise has never seen and requests a session to an internal application. Which sequencing matches the SP 800-207 model?
- 24. An architect records a boundary protection control as implemented because a next-generation firewall is deployed with a hardened ruleset. The assessor finds no evidence that the deployed rules behave as designed. Considering the two angles the SP 800-53 Rev. 5 catalogue applies to any control, what is missing?
- 25. A programme manager claims the systems security engineering principles in SP 800-160 Vol. 1 Rev. 1 suit large defence platforms only, so a small sensor gateway that has already been fielded sits outside their scope. How should the security architect answer?
- 26. A governance team wants one control catalogue to serve the whole organisation, so that a single register covers every obligation the board tracks. They ask which concerns beyond classic information security the twenty SP 800-53 Rev. 5 families already govern. Choose two.
- 27. A payments platform encrypts stored card tokens with AES-128. An architect proposes migrating to AES-256 so that each encrypted block becomes larger, cutting the number of blocks and the padding overhead on every record. How should the security engineer assess this proposal?
- 28. A developer encrypts customer records with AES in Cipher Block Chaining (CBC) mode and derives each initialisation vector (IV) from the record's primary key, so that decryption can recompute the IV without storing it. A reviewer objects to the design. Which change should the reviewer require?
- 29. A federal agency hardens a public web service and its internal client tooling against NIST SP 800-52 Rev. 2. Both endpoints currently negotiate TLS 1.2 and offer FIPS-approved cipher suites only. The architect asks what further protocol support the guidance obliges the agency to provide.
- 30. A protocol team needs a derivation step that emits 512 bits of keying material now and may need 1024 bits for a later revision, produced by a single primitive invocation rather than by concatenating several digests. The design is restricted to functions specified in FIPS 202. Which function meets the requirement?
- 31. A vendor tells a procurement team that its hardware security module is "FIPS validated" because its AES implementation passed algorithm testing. The security engineer reviewing the claim explains that cryptographic module validation under FIPS 140-3 examines considerably more than algorithm correctness. Which areas does that validation cover? Choose two.
- 32. A manufacturer is rebuilding remote access around a zero trust architecture. Engineers argue that company-issued laptops sitting on the plant's internal LAN should reach the production historian directly, since both the hardware and the segment are corporate property. The security architect rejects this. Which statement reflects the model the architect is applying?
- 33. A network architect is numbering an isolated test range that must stay unroutable on the public internet, and wants only address space set aside for private internets. Four candidate blocks appear in the addressing plan. Which blocks are reserved for private internets? Choose three.
- 34. An enterprise peers with an upstream provider and mistakenly advertises routes for its internal 10.0.0.0/8 space. The provider's router silently drops the advertisement, and the enterprise operations team raises a ticket claiming the peer is generating routing protocol errors. How should this behaviour be characterised?
- 35. A procurement team is comparing two IPsec gateways for a site-to-site deployment. One vendor implements Encapsulating Security Payload (ESP) only and calls that sufficient for a conforming implementation, while a reviewer insists Authentication Header (AH) is required so integrity-only protection remains available. Which position is correct?
- 36. An engineer is documenting the security associations required for a bidirectional IPsec tunnel carrying ordinary request and response traffic. A colleague proposes one association covering both directions and binding Authentication Header (AH) and Encapsulating Security Payload (ESP) together. How should the engineer describe the actual requirement?
- 37. A firewall team operates an IPsec security gateway that terminates site-to-site tunnels and also receives Simple Network Management Protocol (SNMP) polling addressed to the gateway itself. An auditor asserts that every association on the box must use tunnel mode because a security gateway is an endpoint. Which case still permits transport mode?
- 38. A security engineer is building the ordered policy table an IPsec implementation consults for every packet crossing the boundary, and a reviewer wants the test plan to cover every outcome a policy lookup can produce. Which dispositions can a lookup return? Choose three.
- 39. A team is migrating a payment gateway to TLS 1.3 and asks why its static RSA key exchange and its CBC-mode cipher preferences must be replaced by authenticated encryption with associated data (AEAD) suites. Which statements describe the changes made in TLS 1.3? Choose two.
- 40. A vendor is certifying a TLS 1.3 stack for a government customer and must document the minimum algorithm support a conforming implementation owes. To save code space the team proposes shipping ChaCha20-Poly1305 as the only bulk option. Which cipher suite does a conforming implementation have to support?
- 41. To cut handshake cost on a heavily loaded TLS 1.3 service, a platform team configures its servers to issue resumption tickets advertising a thirty-day lifetime. A reviewer warns that clients will ignore the advertised value long before then. Which description of ticket lifetime handling is correct?
- 42. A telemetry platform holds long-lived TLS 1.3 connections that stream millions of small records per session under AES-GCM, and some clients also send early data on resumption. An engineer asks what an endpoint owes as the record count climbs, and how early data is handled. Which response is correct?
- 43. A contractor is choosing authenticators for a system that must operate at Authentication Assurance Level 3 (AAL3) under NIST SP 800-63B-4. The security architect proposes passkeys synchronised across each staff member's phone and laptop through a cloud account. Why does this proposal fail the AAL3 requirement?
- 44. A credential service provider proofs applicants remotely at Identity Assurance Level 2 (IAL2), collecting one fair and one strong piece of evidence. A government customer now requires Identity Assurance Level 3 (IAL3), and the provider's analyst assumes the gap is stronger documents. Under NIST SP 800-63A-4, what actually distinguishes IAL3 proofing?
- 45. A bank is adding face recognition as an authentication factor. Testing shows the algorithm performs worse for one demographic group, so the vendor offers to lower the match threshold for that group so acceptance rates even out. Under NIST SP 800-63B-4, how should the bank respond to the offer?
- 46. A security manager is rewriting the password policy for a workforce portal to align with NIST SP 800-63B-4. The current policy mandates a mix of upper case, digits and symbols, expires every password after 90 days, and screens new passwords against a blocklist of breached values. Which two changes bring the policy into line? Choose two.
- 47. An agency runs a case-management system at Authentication Assurance Level 3 (AAL3). Analysts complain about being signed out during long reviews and ask to inherit the timings used by the intranet, which runs at Authentication Assurance Level 2 (AAL2). Under NIST SP 800-63B-4, which session limits must the case-management system keep?
- 48. A brokerage federates staff logins to an external identity provider. The risk team's worry is a breach of that provider itself: an attacker who controls it could mint assertions naming any employee. Which federation assurance level 3 (FAL3) requirement addresses that specific worry?
- 49. Two research institutes agree to federate under the SP 800-63C-4 federation guidance. They share no common public key infrastructure and neither will join the other's, yet their architects want federation assurance level 3 (FAL3) for a jointly funded data programme. Which binding approach suits this deployment?
- 50. A SaaS provider follows the SP 800-63C-4 back-channel presentation model between its identity provider and several relying parties. To cut load, its gateway caches each assertion reference and lets any registered relying party redeem it for up to an hour. Which change aligns the design with that model?
- 51. A penetration test of an internal staff portal reports that the administrative menu is hidden by JavaScript for standard users, but a command-line HTTP client calling the /admin/users endpoint with an ordinary user's session returns the full staff list. Which remediation addresses the underlying broken access control?
- 52. An architect replaces static group permissions on a research data platform with attribute based access control (ABAC), so that the particulars of each request decide the outcome rather than a fixed grant. Which inputs does the ABAC decision test against the rule set? Choose three.
- 53. A compliance analyst at a regional insurer must confirm that firewall change records and the current rulesets agree with documented policy, with no interruption to claims processing. The engagement letter allows the analyst to review artefacts only, with no interaction with live devices. Which assessment method fits this work?
- 54. An assessment team at a logistics firm has finished a hands-on technical test of the order platform and proposes to drop the document and configuration review to save budget. The chief information security officer resists. Which two statements support keeping the examination work? Choose two.
- 55. A bank's board wants to learn how far an intruder could get before the security operations centre reacts, so the exercise must run while operations staff remain unaware of it. The assessors ask what has to be in place before they begin. Which condition governs this kind of exercise?
- 56. During an authorised penetration test of a retailer's payment portal, the assessors gain a shell on a web host and immediately find stored credentials for a second server they had never enumerated. Which action matches the staged methodology they are following?
- 57. A vulnerability scan of a hospital's intranet returns findings ranked by the scanning product's own severity labels. Management proposes to publish that ranked list as the organisation's statement of risk. Which two objections should the assessment lead raise? Choose two.
- 58. Midway through an authorised assessment, a tester judges that a denial-of-service check falling outside the signed document would expose a serious weakness in a customer portal. The engagement is time-boxed and the sponsor who signed is travelling. How should the tester proceed?
- 59. An energy utility is standing up an information security continuous monitoring programme and already maintains a current inventory of the systems it owns. To deliver the remaining aims of such a programme, which two capabilities must it add? Choose two.
- 60. A government contractor runs the same exhaustive assessment procedures against a public brochure website and against a system holding claimant medical records. Auditors report that the programme misapplies its own guidance. Which change brings the programme into line?
- 61. A programme manager schedules the security control assessment for a new claims system as a single event in the week before the authorisation decision, arguing that any earlier assessment would examine an unfinished system. The assessment lead pushes back. Which correction should the lead offer?
- 62. A risk assessment of an acquisition target reports several high-likelihood exposures, and the assessors close their briefing by recommending that the board abandon the deal. The chief risk officer objects to how the assessors framed their role. Which statement explains that objection?
- 63. A security operations centre receives forty incident tickets during one shift, and a new analyst begins working them in the order they arrived. The incident manager wants a defensible handling order the organisation can justify to auditors. Which basis should determine which incident is worked first?
- 64. Ransomware is confirmed on three file servers, and the response team has isolated all three. Management asks the team to state how large the incident is before recovery planning begins. Which action best establishes the true scope of the incident?
- 65. An organisation is writing the mitigation section of its incident response plan for workloads hosted by a cloud provider whose platform contains some incidents automatically. Which two requirements should that section state? Choose two.
- 66. During an intrusion, an analyst proposes leaving the attacker's access in place and steering the session into an instrumented sandbox to observe their techniques before the incident is shut down. Which action should the incident commander take before that diversion begins?
- 67. An enterprise marks a patch as complete once its deployment console reports the package was pushed to the target group. An auditor later finds several of those servers still running the vulnerable version. Which activity closes the patch management cycle?
- 68. Mission owners at a manufacturer keep deferring maintenance windows because downtime costs production, while the technology owners want fixes applied promptly. The chief information security officer needs a framing that settles the standing disagreement about whether patching is worth its cost. Which approach should be adopted?
- 69. An adversary edits the endpoint detection agent's configuration and deletes the log forwarding pipeline, so alerts stop reaching the security operations centre and analysts can no longer trust their consoles. In the current MITRE ATT&CK Enterprise matrix of fifteen tactics, which tactic describes this behaviour?
- 70. An agency tracks the CISA Known Exploited Vulnerabilities catalog. Two vulnerabilities were added to the listing on the same day; one record is flagged as requiring forensic triage under Binding Operational Directive 26-04 and the other carries no such flag. How does that flag affect the two remediation deadlines?
- 71. A skilled intruder held access to a domain member server for weeks, and the full set of techniques they used remains unknown. The team plans to rebuild the server from a backup taken before the earliest known activity. Which three actions should the recovery include? Choose three.
- 72. A vulnerability management team wants to pull the CISA Known Exploited Vulnerabilities catalog into its scanner automatically each morning and to give priority to flaws that attackers have used in ransomware campaigns. Which two published features of the catalog support this? Choose two.
- 73. A financial services firm runs three delivery groups: one on a waterfall life cycle, one on Scrum, and one on continuous delivery. The CISO wants a single consistent set of secure-development expectations across all three without forcing them onto one common life-cycle model. Which approach fits the Secure Software Development Framework (SSDF) as it is published?
- 74. A product group adopting the Secure Software Development Framework (SSDF) scans dependencies every build and patches reported flaws within days, yet its vulnerability count returns to the same level each release. An architect argues the programme still misses one of the framework's stated objectives. Which objective is the group overlooking?
- 75. A retail platform authenticates users with stateless JSON Web Tokens (JWTs) that live twelve hours. After an account takeover, support uses "log out all devices" and the attacker's token keeps working until it expires. The team must make logout effective while still letting ordinary customer sessions last a long time. Which design meets both goals?
- 76. While mapping findings against the OWASP Top 10:2025, an application team looks for the XML External Entities category it tracked in earlier editions and finds the category gone. Its document parser still resolves external entity references by default. Where does the 2025 list account for this weakness?
- 77. An identity team is replacing an unsalted SHA-256 password store for a new consumer application. Policy demands a scheme that resists offline cracking on rented GPUs and lets defenders raise the attacker's cost as hardware improves. Following OWASP's 2025 cryptographic guidance, which choice should the team make?
- 78. A payments service fails part way through a multi-step transfer: funds have left the source ledger and the destination write has errored. Developers propose a handler that retries the remaining step and, failing that, marks the transfer complete so a nightly job can reconcile it. Which handling matches OWASP's 2025 guidance on exceptional conditions?
- 79. At a software vendor, one maintainer can merge a change and deploy it to production without another reviewer, and every environment rebuilds the application from source before deployment. A poisoned upstream dependency recently reached the entire customer fleet within an hour. Which two changes align with OWASP's 2025 supply chain guidance? Choose two.
- 80. An architect is rewriting the transport security standard for a bank's public APIs ahead of an audit. Legacy clients still negotiate TLS 1.0 and cipher block chaining (CBC) suites, and the bank holds customer records that must stay confidential for decades. Under OWASP's 2025 cryptographic guidance, which two requirements belong in the standard? Choose two.
- 81. A new chief information security officer finds the firm assesses risk once a year at audit time and does nothing with the results until the next audit. She wants to describe, in the vocabulary of NIST SP 800-39, what a complete risk management process should look like. Which set of components should she present?
- 82. The board asks what the output of the risk framing step should actually be, since framing produces no control decisions of its own. What does an organisation produce by framing risk?
- 83. An insurer will cover part of a firm's losses from a data breach in exchange for a premium. Under the risk response vocabulary of NIST SP 800-39, how should this arrangement be classified?
- 84. An enterprise architect is mapping where different risk decisions are made. The organisation sets its overall appetite centrally, designs business processes in each division, and authorises individual systems in a shared service. Which three-tier structure does NIST SP 800-39 use for this?
- 85. A holding company wants to know which risk activities belong at the organisation level rather than being delegated to divisions or system owners. Which activity sits at Tier 1?
- 86. A programme manager asks which risk activities their system team owns, given that the enterprise architecture and the risk tolerance are set elsewhere. Which set of activities belongs at Tier 3?
- 87. A mid-sized agency has no budget for a dedicated risk executive post, and its head asks whether SP 800-39 can therefore not be followed. What is the correct response?
- 88. Two peer organisations in the same sector adopt visibly different risk tolerances, and an auditor asks which one is set at the wrong level. What does NIST SP 800-39 say about this?
- 89. A distinctly risk-averse bank is choosing anti-malware protection. Which two behaviours does NIST SP 800-39 associate with a less risk-tolerant organisation? Choose two.
- 90. A shared hosting platform provides physical, environmental and network controls that thirty tenant systems inherit without implementing them. Who is accountable for developing, assessing and monitoring those inherited controls?
- 91. A firm has completed its risk responses and wants to define what its monitoring programme should establish. According to NIST SP 800-39, which three questions does risk monitoring answer? Choose three.
- 92. A conglomerate lets each subsidiary run its own risk governance while the parent sets only the strategy. An auditor argues this decentralised model breaches NIST SP 800-39. What does the publication actually require?
- 93. An assessment team reports that the organisation has no vulnerabilities because every system passed its scans. The risk executive disagrees. On what grounds, according to NIST SP 800-39?
- 94. A consultancy is asked to document the risk assessment methodology it will use for a client. Which four elements does NIST SP 800-30 expect that methodology to contain?
- 95. An assessor plans to score likelihood and impact on ordinal bands of low, moderate and high, with no monetary values attached. Under NIST SP 800-30, which assessment approach is this?
- 96. Two teams assess the same platform. One begins by cataloguing adversaries and their methods; the other begins by listing the data the platform holds and what its loss would cost. In SP 800-30 terms, what differs between them?
- 97. A risk model is being documented for a new programme. Which items does NIST SP 800-30 list as the typical risk factors such a model works with? Choose three.
- 98. A data centre loses power when a contractor cuts a feeder cable during unrelated works. Under the threat source taxonomy in NIST SP 800-30, how is this best classified?
- 99. An assessor is criticised for writing narratives that chain several events together instead of listing weaknesses individually. Why does NIST SP 800-30 favour the narrative form?
- 100. After a company hardens its externally facing portal, its attackers stop probing that portal and begin targeting a supplier with weaker controls instead. What does NIST SP 800-30 call this response?
- 101. Two identical systems are assessed. One sits in a coastal flood plain; the other is air-gapped in an inland facility. Under NIST SP 800-30, what is the correct name for these site characteristics?
- 102. An assessor records a single number for the likelihood that ransomware will damage a claims platform. A reviewer says the estimate has skipped a step. Which three-step approach does NIST SP 800-30 expect?
- 103. An assessment covers two events: a targeted intrusion by a criminal group, and a transformer failure in the building. The team uses the same estimation basis for both. Why is that wrong under NIST SP 800-30?
- 104. A programme wants its risk assessments to show trends over several years and to survive a change of assessor. Which two properties does NIST SP 800-30 name for this, and what does each mean? Choose two.
- 105. An assessor insists on pairing every catalogued threat with every catalogued vulnerability before estimating likelihood. What does NIST SP 800-30 say about this practice?
- 106. The same missing patch is rated critical on an internet-facing payment gateway and low on an isolated laboratory host. A reviewer objects that a vulnerability should have one severity. What does NIST SP 800-30 say?
- 107. A risk register records impact only as the cost of restoring service after an outage. Under NIST SP 800-30, what is missing from that definition of impact?
- 108. An assessor adds SQL injection to the risk register of a system that stores everything in flat files and runs no database engine. Why does NIST SP 800-30 treat this as an error?
- 109. A system was assessed as adequately controlled at authorisation four years ago and has not been reassessed since, on the grounds that nothing about it has changed. What does NIST SP 800-30 say about that reasoning?
- 110. A large agency uses one lightweight method for early-stage projects and a more rigorous one for operational systems holding sensitive data. Is this consistent with NIST SP 800-30?
- 111. A team says it has adopted the NIST Cybersecurity Framework because it has mapped its controls to the Core's subcategories. Which two further components does CSF 2.0 provide that they have not used? Choose two.
- 112. A newcomer to CSF 2.0 asks why the Govern Function is drawn at the centre of the wheel rather than as the first step in a sequence. What is the reason?
- 113. An assessor treats the CSF Core as a checklist and reports the organisation as non-compliant because it addressed subcategories out of order. What is wrong with this reading?
- 114. A retailer wants to show its board where its cybersecurity posture stands today and where it intends to be after a two-year programme. Which CSF 2.0 artefacts express these two things?
- 115. A regional hospital group wants a starting point for its CSF Target Profile that reflects health-sector expectations rather than being built from scratch. Which CSF 2.0 artefact is designed for that?
- 116. A team has written both a Current and a Target Profile and asks what comes next in the CSF 2.0 profile cycle. Which step follows?
- 117. An assessor finds risk practices that management has approved but that are not written as organisation-wide policy, and supplier risk that is recognised but never formally acted on. Which CSF Tier does this describe?
- 118. A supplier assurance lead wants to reach the CSF Tier at which supplier risk is acted on through written agreements, governance bodies and monitoring, with risk practices expressed as formal policy. Which Tier is that?
- 119. Which two characteristics does CSF 2.0 associate with Tier 4, Adaptive, rather than with Tier 3? Choose two.
- 120. A consultancy proposes replacing a client's existing risk methodology with the CSF Tiers, presenting them as a maturity model to be climbed. What is wrong with this proposal?
- 121. A team complains that the CSF 2.0 document tells them what outcomes to reach but never how to reach them. Where does CSF 2.0 direct them for the how?
- 122. A governance review finds a documented risk tolerance but no statement of risk appetite. What does CSF 2.0 expect under its Risk Management Strategy category?
- 123. During a CSF-aligned review, a manager argues that a proposal to move a service to a managed provider is an opportunity, not a risk, and so has no place in the risk discussion. How does CSF 2.0 treat this?
- 124. A CSF 2.0 assessment finds that cybersecurity plays no part in hiring, induction or performance management, and that no executive is accountable for cyber risk. Which two Govern outcomes are unmet? Choose two.
- 125. A firm signs a supplier before any security review, intending to assess the supplier once the service is live. Which CSF 2.0 supply chain expectation does this breach most directly?
- 126. An incident response plan lists only internal teams. The organisation's payroll, identity and hosting all sit with third parties. Which CSF 2.0 supply chain outcome does the plan miss?
- 127. A manufacturer argues that CSF 2.0 cannot apply to its plant floor because the framework was written for office information technology. What does CSF 2.0 actually say about its scope?
- 128. A programme schedules Govern, Identify, Protect, Detect, Respond and Recover as six sequential annual workstreams. Why does this conflict with CSF 2.0?
- 129. A small logistics firm believes the NIST Cybersecurity Framework is meant only for critical infrastructure operators. What changed with version 2.0 that answers this?
- 130. Under CSF 2.0, which category sits within the Identify Function and carries the work of feeding lessons learned back into the programme?
- 131. A continuity coordinator has interviewed process owners about outage impacts and tolerable downtime. Which two further steps complete the business impact analysis under NIST SP 800-34? Choose two.
- 132. A system owner states that claims processing can be unavailable for no more than 36 hours before the harm to the business becomes unacceptable, counting every kind of impact. Which measure has been stated?
- 133. An architect proposes a recovery time objective of 36 hours for a process whose maximum tolerable downtime is also 36 hours, arguing the two should match. Why does NIST SP 800-34 disagree?
- 134. A business owner accepts losing up to fifteen minutes of transactions in a disaster but insists service must return within four hours. Which two objectives has the owner stated, and to which does the fifteen minutes belong? Choose two.
- 135. A continuity coordinator finds the achievable recovery time objective is twelve hours while the maximum tolerable downtime, fixed by regulation, is six. Management will not fund a faster solution this year. What does NIST SP 800-34 direct?
- 136. A coordinator beginning a business impact analysis asks which existing artefact gives the starting point for judging outage consequences. Under NIST SP 800-34, what is it?
- 137. A project team plans to conduct its business impact analysis after the system goes live, when real usage data will be available. What does NIST SP 800-34 recommend instead?
- 138. Two divisions of the same firm choose different recovery solutions for systems with similar impact levels, and an auditor asks which one is wrong. What does NIST SP 800-34 say about the choice?
- 139. A low-impact reporting system has a generous recovery time objective and a small budget. Which recovery approach does NIST SP 800-34 describe as proportionate?
- 140. An agency must analyse both its continuity of operations functions and one of its information systems. Which pairing of analysis type to subject does NIST SP 800-34 describe?
- 141. A business impact analysis shows that a single air-conditioning unit failing would take down a computer room within an hour. The team proposes documenting a recovery procedure for that outage. What does NIST SP 800-34 prefer?
- 142. A study group is planning revision time in proportion to the CISSP exam outline. Which domain carries the largest average weight, and roughly what share is it?
- 143. A small water utility asks whether adopting CISA's Cross-Sector Cybersecurity Performance Goals will make it fully secure. How should the goals be characterised?
- 144. A team that adopted the first version of CISA's performance goals is reviewing what changed in version 2.0. Which two changes were made? Choose two.
- 145. An organisation with a mature enterprise risk programme is told it must discard that programme to adopt NIST SP 800-39. Is that correct?
- 146. A control is implemented centrally by a hosting platform, but each tenant system adds its own configuration on top of the inherited part. In the vocabulary of the Risk Management Framework, how is such a control described?
- 147. A programme adopting the Risk Management Framework wants to know what Revision 2 added beyond the earlier system-level focus. Which change does it describe?
- 148. A team reads SP 800-30 as guidance for assessing individual systems only. What does the publication actually say about where risk assessment applies?
- 149. A media disposal policy lists overwriting, degaussing and shredding as its three sanitization methods. Under NIST SP 800-88 Rev. 2, why is that the wrong framing?
- 150. A laptop is being reissued to another employee inside the same office, and the data on it was categorised low. Which sanitization method does NIST SP 800-88 describe as sufficient here, and why?
- 151. An asset manager can apply either clear or purge to a batch of drives being redeployed, at similar cost. What does NIST SP 800-88 Rev. 2 advise?
- 152. A records team asks which sanitization method applies to a cloud storage bucket that is being decommissioned. Why is destroy not available to them?
- 153. A department proposes to sanitize printed patient records by running them through a bulk degausser, arguing this parallels how it handles tapes. What is wrong with the proposal?
- 154. A batch of drives has failed and no longer responds to the host interface. A technician proposes overwriting them before disposal. Which two objections does NIST SP 800-88 support? Choose two.
- 155. An administrator overwrites every user-addressable block of a solid-state drive and reports it sanitized. Why does NIST SP 800-88 treat this as unreliable?
- 156. A standard operating procedure still requires seven overwrite passes citing an old defence manual. Which two points does NIST SP 800-88 Rev. 2 make about this? Choose two.
- 157. A hosting provider must sanitize thousands of self-encrypting drives within a maintenance window that would not allow a full overwrite. Which technique does NIST SP 800-88 offer, and how does it work?
- 158. A tenant must purge data from a public cloud object store and cannot obtain physical access to the underlying hardware. Which technique does NIST SP 800-88 identify as often the only viable one?
- 159. A team plans to degauss a batch of modern high-coercivity hard drives with an older degausser and then resell them. Which two risks does NIST SP 800-88 identify? Choose two.
- 160. An operator degausses a batch of solid-state drives and records them as purged. Why is that record wrong?
- 161. A disposal record classifies degaussing as a destroy technique because the drive is unusable afterwards. How does NIST SP 800-88 Rev. 2 classify degaussing?
- 162. Which set of processes does NIST SP 800-88 Rev. 2 give as the physical techniques associated with the destroy method?
- 163. A field team drills a hole through each retired drive and records the media as destroyed. Why does NIST SP 800-88 reject this?
- 164. A vendor offers shredding as the disposal route for drives that held highly sensitive records. What limitation does NIST SP 800-88 Rev. 2 place on shredding and pulverising?
- 165. An architect is checking whether a storage product's cryptographic erase can be relied on. Which two conditions does NIST SP 800-88 Rev. 2 set? Choose two.
- 166. A product datasheet says its cryptographic erase destroys the wrapping key rather than the data encryption key. What follows from this, under NIST SP 800-88 Rev. 2?
- 167. A firm is deciding whether to sanitize retired media in house or ship it to a contractor. Which two considerations does NIST SP 800-88 Rev. 2 raise? Choose two.
- 168. A drive is labelled as 1 terabyte, but its controller performs internal compression and holds additional physical capacity. What does NIST SP 800-88 Rev. 2 conclude about sanitizing it?
- 169. A team can either overwrite through ordinary write commands or issue the drive's dedicated sanitize command. What trade-off does NIST SP 800-88 Rev. 2 describe?
- 170. An analyst records that confidentiality was lost when an attacker altered records in place without reading them. Under FIPS 199, how should this be classified?
- 171. An analyst must translate FIPS 199 impact levels into plain language for a business audience. Which mapping is correct?
- 172. A hospital categorises a system whose failure would stop emergency admissions entirely and could endanger patients' lives. Which two conditions in the FIPS 199 definition of high impact does this meet? Choose two.
- 173. A payroll system outage would leave the organisation able to keep paying staff but with markedly reduced effectiveness, and would cause significant but not life-threatening harm to individuals. Which FIPS 199 impact level fits?
- 174. An analyst categorises a published statistics dataset and wants to record that confidentiality is irrelevant to it. What does FIPS 199 permit for an information type?
- 175. A system holds two information types. One is moderate for confidentiality and low for integrity; the other is low for confidentiality and high for integrity. What is the system's FIPS 199 category?
- 176. An analyst wants to record a system's confidentiality objective as not applicable because the system holds only public data. Why does FIPS 199 forbid this at system level?
- 177. A system's routing tables, password file and key management data are being categorised. What does FIPS 199 require for such system information?
- 178. A programme presents its FIPS 199 categorisation as the completed risk assessment for a new system. Why is that claim wrong?
- 179. A data owner asks who decides what counts as an information type such as investigative or proprietary data. What does FIPS 199 say?
- 180. An agency asks whether FIPS 199 governs the categorisation of its classified holdings and its national security systems. What is the position?
- 181. A privacy officer is told the PII confidentiality impact level is simply the FIPS 199 confidentiality level under another name. What distinguishes the two, under NIST SP 800-122?
- 182. A team is setting the PII confidentiality impact level for a new dataset. Which three factors does NIST SP 800-122 offer for that decision? Choose three.
- 183. A dataset covers only twenty individuals, and an analyst proposes lowering its PII impact level on that basis. What does NIST SP 800-122 say about using quantity this way?
- 184. Two lists hold identical fields - name, address and telephone number. One is newsletter subscribers, the other is undercover officers. A reviewer says they must carry the same PII impact level. Why is that wrong?
- 185. A customer record system and a billing table sit on the same host with no effective separation between them, and together identify individuals. Under NIST SP 800-122, how is that data described?
- 186. A dataset could be joined with a public electoral register to identify individuals, though no such join has been made. Under NIST SP 800-122, what is the correct term?
- 187. A research team removes direct identifiers from a dataset but keeps a sealed key allowing subjects to be re-identified if a safety issue arises. Under NIST SP 800-122, may they call the result anonymised?
- 188. A marketing team wants to keep every field it has ever collected in case it proves useful later. Which two practices does NIST SP 800-122 recommend instead? Choose two.
- 189. A privacy programme starts by writing encryption standards for the personal data it knows about. What does NIST SP 800-122 make its first recommendation, and why?
- 190. An analyst determines that a dataset does not meet the definition of personally identifiable information, and proposes to remove it from the protection programme entirely. What does NIST SP 800-122 advise?
- 191. A study guide written in 2019 describes media sanitization using clear, purge and destroy and cites the 2014 edition of NIST SP 800-88. What has changed since?
- 192. A privacy team wants to know how the protection owed to a given piece of personal data is pegged to a wider federal scale. Which relationship does NIST SP 800-122 set out?
- 193. A vendor claims its product delivers zero trust because it removes the perimeter firewall. Why does NIST SP 800-207 reject definitions framed this way?
- 194. A design grants unauthenticated access to a records service for any host on the corporate LAN, on the grounds that the LAN sits behind the firewall. Which zero trust tenet does this breach?
- 195. A single sign-on deployment issues a token at login that admits the user to every application in the estate for eight hours. Which two zero trust expectations does this arrangement fail? Choose two.
- 196. An access policy is written purely as a static list of groups and applications. Which inputs does SP 800-207 expect a zero trust policy to weigh instead? Choose three.
- 197. In the SP 800-207 conceptual model, which component makes and logs the access decision, and which one carries that decision out?
- 198. A session is approved. Which two things does the policy administrator do next, in the SP 800-207 model? Choose two.
- 199. An architect asks how the policy enforcement point may be realised in practice under SP 800-207. Which description is correct?
- 200. A design places zero trust component communication on the same network segment as application traffic. Which separation does SP 800-207 describe?
- 201. What does the policy engine feed into its trust algorithm before granting, denying or revoking access?
- 202. Which three pieces of information does a continuous diagnostics and mitigation system supply to the policy engine about a requesting asset? Choose three.
- 203. An architect writing a zero trust network plan asks what posture to adopt toward the enterprise's own private network. What does SP 800-207 assume?
- 204. A field engineer connects a corporate laptop to a hotel network. What posture does SP 800-207 tell that remote asset to take?
- 205. A workload is migrated from an on-premises data centre to a cloud instance and loses several of the controls it previously ran under. Which zero trust assumption does this violate?
- 206. A gateway grants access whenever the user presents valid credentials, without examining the device the request came from. Which two zero trust points does this miss? Choose two.
- 207. A retailer proposes applying its full zero trust tenets to anonymous shoppers browsing its public catalogue. What does SP 800-207 say about that scope?
- 208. A zero trust deployment restricts what each subject may open, but every subject can still enumerate the full catalogue of resources. Which aspect of least privilege does SP 800-207 say is missing?
- 209. An executive asks what changed in enterprise computing to prompt zero trust, and what zero trust protects as a result. Which answer matches SP 800-207?
- 210. A team must decide when an established session should be re-evaluated. Which triggers does SP 800-207 name? Choose three.
- 211. A procurement team insists zero trust requires certificate-based authentication specifically. What does SP 800-207 say about technology choices?
- 212. An enterprise allows staff to reach its resources from their own phones. Under the first zero trust tenet, how may those phones be treated?
- 213. A product implements the policy engine and policy administrator as one service. Is that consistent with SP 800-207, and why does the publication still separate them?
- 214. A team is testing whether a managed offering meets the NIST definition of cloud computing. Which three of the five essential characteristics are listed below? Choose three.
- 215. A provider requires customers to email an account manager before additional storage is allocated, with provisioning completed within two working days. Which essential characteristic does the offering fail?
- 216. A customer asks its cloud provider exactly which rack its virtual machines run on and is told only the country and datacentre. Which two facts about resource pooling explain this? Choose two.
- 217. A finance team asks how it can verify what a cloud service actually consumed last month, and how the provider justifies the invoice. Which essential characteristic covers this?
- 218. A customer of a hosted email service asks to patch the operating system underneath it. Under the NIST definition, what may a software as a service consumer actually control?
- 219. A development team deploys its own applications onto a provider's runtime, using languages and libraries the provider supports. Which two things does the NIST definition say the consumer controls in platform as a service? Choose two.
- 220. Which service model, under the NIST definition, lets a consumer run arbitrary software including operating systems and sometimes control select networking components such as a host firewall?
- 221. An auditor argues a cloud cannot be private because the hardware is owned and operated by an outside supplier in the supplier's own datacentre. What does the NIST definition say?
- 222. Several hospital trusts share an infrastructure provisioned for their exclusive use because they face the same regulatory regime. Which NIST deployment model is this, and who may run it?
- 223. An architect looking for privacy controls is told to consult a separate NIST publication from the security control catalogue. What changed in SP 800-53 Rev. 5?
- 224. An engineer is asked which NIST publication addresses building systems that must keep working while under attack, and what discipline it names for that work. Which answer is correct?
- 225. A procurement specification demands a module validated at FIPS 140-3 Level 3 and states that Level 3 requirements replace the general ones. How are the requirements at a given level actually composed?
- 226. Which three of the following are among the requirement areas FIPS 140-3 covers for a cryptographic module? Choose three.
- 227. An auditor asks on what basis FIPS 140-3 was written and what it does to its predecessor. Which statement is correct?
- 228. A Canadian subsidiary asks whether a module validated by the programme that tests against FIPS 140-3 will be accepted on both sides of the border. What is the position?
- 229. A vendor states that its module is FIPS 140-3 compliant on the strength of its own internal testing. Why is that claim insufficient?
- 230. An architect specifies FIPS 140-3 Level 4 for every module in a low-impact internal application, arguing that higher is always safer. What does the standard advise?
- 231. A buyer finds a module on the validation programme's historical list and proposes to purchase it. What does FIPS 140-3 say about that list?
- 232. A module implements a proprietary cipher the vendor considers stronger than any published one. May a FIPS 140-3 conformant module use it?
- 233. A key management policy uses the word cryptoperiod without defining it. Which definition matches NIST SP 800-57 Part 1?
- 234. A board asks what bounding a key's cryptoperiod actually buys. Which three purposes does NIST SP 800-57 give? Choose three.
- 235. A key with three months of its cryptoperiod remaining is found to have been exposed. An administrator proposes leaving it in service until the scheduled rotation. What does NIST SP 800-57 require?
- 236. A team is setting cryptoperiods and lists only key length and algorithm as inputs. Which three further factors does NIST SP 800-57 name? Choose three.
- 237. A remote site distributes keys by hand, with occasional transcription errors. The security team proposes halving the cryptoperiod to improve safety. What does NIST SP 800-57 caution?
- 238. An organisation uses approved algorithms at recommended key sizes. Which consideration does NIST SP 800-57 say usually drives cryptoperiod selection in that situation, and why?
- 239. An architect proposes the same cryptoperiod for the keys protecting a message channel and the keys protecting a 40-terabyte archive. Why does NIST SP 800-57 treat these differently?
- 240. A control system's availability matters more than anything else, and its re-keying process has a history of failures. The security team wants to shorten cryptoperiods sharply because the data is sensitive. What does NIST SP 800-57 caution?
- 241. A signing key pair is issued. Which two statements about the cryptoperiods of the two halves match NIST SP 800-57 Part 1? Choose two.
- 242. A certificate is issued with a keyUsage extension present but every bit left unset. Why does RFC 5280 treat this as invalid?
- 243. An intermediate certificate asserts keyCertSign but its basic constraints extension leaves the CA boolean unset. What must a conforming relying party do with the certificate's public key?
- 244. An engineer must decide which key usage bit to set for an RSA public key that will encrypt a symmetric content-decryption key. Which bit applies, and what does the neighbouring bit mean?
- 245. A certificate profile mandates the nonRepudiation bit and a reviewer notes recent editions of X.509 use a different name for it. What is the bit now called, and what does it cover?
- 246. A certificate sets encipherOnly but leaves keyAgreement unset. How should a relying party interpret the encipherOnly bit?
- 247. A certificate authority certificate carries a path length constraint of zero. What does that permit in a valid certification path?
- 248. A certificate authority includes a path length constraint on an end entity certificate that has no CA boolean set. Which two statements from RFC 5280 apply? Choose two.
- 249. An authority issues a certificate authority certificate whose key validates signatures on other certificates, and marks the basic constraints extension non-critical. What does RFC 5280 require?
- 250. A version 3 certificate carries no basic constraints extension at all. How must its public key be treated?
- 251. A certificate authority's signing key will only ever sign certificates and revocation lists. Which practice does RFC 5280 recommend for its keyUsage bits?
- 252. An engineer must permit a key to verify signatures on delta certificate revocation lists. Which keyUsage bit governs that?
- 253. A supplier states its module either passes or fails FIPS 140-3 validation. How does the standard actually grade modules?
- 254. A team wants federal policy and planning obligations for key management rather than general best practice. Which part of NIST SP 800-57 should they read?
- 255. A design document states that publication of the SHA-3 standard retired the SHA-2 family. Why is that wrong?
- 256. An architect asks how FIPS 140-3 relates to the international standards it is based on, and what adjusts those standards for federal use. Which answer is correct?
- 257. A border router applies access control lists that permit or deny packets by address and port. The security team asks why it cannot recognise that a reply belongs to a request it saw a moment earlier. What explains this?
- 258. Which pieces of information does a basic packet filter use to make its decision? Choose three.
- 259. A network team wants to stop compromised internal hosts sending traffic with forged source addresses out to the internet. Which measure does NIST SP 800-41 describe?
- 260. An architect argues that a stateless filter is adequate because it will catch spoofed packets and abusive header options. Which two limitations does NIST SP 800-41 identify? Choose two.
- 261. Which three states does a stateful inspection firewall track for TCP traffic, according to NIST SP 800-41? Choose three.
- 262. An engineer inspects a firewall's state table and expects to find only addresses. Which further items does NIST SP 800-41 say such an entry typically holds? Choose two.
- 263. A stateful firewall permits an inbound DNS response from an external server. On what basis does it do so, and what limits its handling of that traffic?
- 264. An attacker sends a packet whose header claims membership of an established connection, hoping to pass the firewall. Which two mechanisms does NIST SP 800-41 describe that defeat this? Choose two.
- 265. A firewall administrator configures the device to drop all fragmented packets, arguing fragments are only used in attacks. Which two objections does NIST SP 800-41 raise? Choose two.
- 266. A firewall is configured to reassemble fragments before passing them inward. Which two consequences does NIST SP 800-41 note? Choose two.
- 267. A design document lists network address translation among the firewall technologies it relies on for security. How does NIST SP 800-41 classify translation?
- 268. A compliance requirement demands that outbound web activity be attributed to named users and logged per user. Which firewall capability does NIST SP 800-41 say is needed?
- 269. A policy draft proposes writing most firewall rules against media access control addresses. What does NIST SP 800-41 observe about the data link layer?
- 270. A diagram labels a firewall's outside interface unprotected and its inside interface protected. Why does NIST SP 800-41 describe this labelling as often inappropriate?
- 271. Which two fragmentation behaviours does NIST SP 800-41 identify as characteristic of attacks rather than normal traffic? Choose two.
- 272. A procurement specification demands that an IPsec implementation support both AH and ESP as mandatory. What does RFC 4301 actually require, and why?
- 273. A design uses the authentication header to keep a management protocol's contents secret in transit. Why does this fail?
- 274. An engineer expects AH to cover every field of the IP header. Why does RFC 4302 describe its protection of the header as piecemeal?
- 275. An architect asks why AH became optional when it uniquely provides integrity without encryption. What does RFC 4301 say?
- 276. A deployment enables ESP encryption but disables its integrity service to save cycles. What does RFC 4303 say about this configuration?
- 277. Where does the ESP header sit in transport mode compared with tunnel mode?
- 278. A packet arrives at an IPsec boundary and matches no rule requiring protection. Which three outcomes does the security policy database allow for traffic at that boundary? Choose three.
- 279. Two hosts need bidirectional IPsec-protected traffic with both AH and ESP applied. How many security associations are involved, and why?
- 280. An engineer assumes the security parameters index alone is always enough to identify a security association. When does RFC 4301 say that is not so?
- 281. Which two statements about IPsec key management match RFC 4301? Choose two.
- 282. An organisation proposes to run RFC 4301-conformant IPsec using IKEv1. Which two capabilities does the document say IKEv1 lacks? Choose two.
- 283. An IPsec deployment relies on anti-replay protection but the receiving implementation never inspects sequence numbers. What does RFC 4302 say about the result?
- 284. How does ESP provide limited traffic flow confidentiality, and where is that most useful?
- 285. A network team asks how finely IPsec protection can be scoped between two sites. What does RFC 4301 permit?
- 286. Between which pairs of endpoints can IPsec security services be provided? Choose three.
- 287. A team proposes DNSSEC to stop an eavesdropper reading which sites employees look up. Why does this fail?
- 288. How is a DNSSEC authentication chain built, according to RFC 4033?
- 289. A validating resolver must report the security state of an answer. Which four states does RFC 4033 define?
- 290. A resolver receives an answer for a domain in a part of the namespace covered by no trust anchor it holds. Which DNSSEC state applies, and what is notable about it?
- 291. A resolver holds a trust anchor and a secure delegation, but the answer's signatures have expired. Which DNSSEC state results, and which other conditions produce it? Choose two.
- 292. An administrator plans to rely on DNSSEC to protect zone transfers and dynamic updates between name servers. What does RFC 4033 say?
- 293. A non-validating stub resolver asks a security-aware server for a record whose data is bogus. How is that communicated, and how is verified data signalled? Choose two.
- 294. A site sends a Strict-Transport-Security header carrying only the includeSubDomains directive. Why is the header incomplete?
- 295. A site needs to stop browsers enforcing its HSTS policy, having moved a service to a subdomain that cannot yet serve HTTPS. What effect does sending max-age of zero have?
- 296. An engineer asks what value should be given to the includeSubDomains directive to enable it. What does RFC 6797 specify?
- 297. A page on a known HSTS host contains an image referenced over plain HTTP. What does a conformant browser do before fetching it?
- 298. A user visits a known HSTS host whose certificate has just expired and wants to proceed anyway. What does RFC 6797 require of the browser?
- 299. A site emits its Strict-Transport-Security header on both its HTTP and HTTPS responses so that first-time visitors pick up the policy sooner. What does RFC 6797 say?
- 300. An office runs one wireless network for staff, guests and contractors alike, arguing that authentication separates them adequately. What does NIST SP 800-153 recommend?
- 301. A laptop is docked to the wired network while its wireless adapter remains associated with an external access point. What risk does NIST SP 800-153 identify, and what does it ask for?
- 302. A policy addresses only the case of a device connected to both wired and wireless networks at once. Which broader risk does NIST SP 800-153 identify?
- 303. Wireless clients at a manufacturing site need to reach two application servers on the wired network. What does NIST SP 800-153 recommend for their access?
- 304. A security team monitors its wireless networks for wireless-specific attacks but performs no patching or configuration verification on the wireless components. Which two expectations from NIST SP 800-153 are unmet? Choose two.
- 305. An organisation performs a wireless security assessment every two years and has no continuous monitoring. What cadence does NIST SP 800-153 expect?
- 306. Each site configures its own access points by hand. Which three benefits does NIST SP 800-153 attribute to standardising, automating and centralising that configuration instead? Choose three.
- 307. Which fields does the fixed IPv6 header carry before the source and destination addresses? Choose three.
- 308. An engineer computes an IPv6 packet's payload length excluding its extension headers. Why is that wrong?
- 309. A RADIUS deployment is reviewed for how it protects the exchange between the network access server and the RADIUS server. Which two properties does RFC 2865 describe? Choose two.
- 310. A misconfigured network device sends Access-Requests to a RADIUS server that holds no shared secret for it. What must the server do?
- 311. A RADIUS server answers an Access-Request with an Access-Challenge. Which three things does the client include when it resubmits? Choose three.
- 312. A team proposes meeting a phishing-resistance requirement by mandating 20-character passwords. What does NIST SP 800-63B say?
- 313. A device requires a six-digit PIN to unlock a hardware authenticator, and an auditor objects that six digits breaches the password length rules. Why does that objection fail?
- 314. A verifier rejects any password containing a substring found on its blocklist, so that a passphrase containing a common word is refused. What does NIST SP 800-63B actually require?
- 315. A blocklist is being assembled for a new service. Which three sources does NIST SP 800-63B suggest it draw on? Choose three.
- 316. A service rejects a blocklisted password with a generic failure message and no further help. Which two things does NIST SP 800-63B require or recommend instead? Choose two.
- 317. A security team wants to expand its password blocklist to hundreds of millions of entries for extra safety. What does NIST SP 800-63B say about very large blocklists?
- 318. Which three password handling behaviours does NIST SP 800-63B recommend of verifiers? Choose three.
- 319. A sign-up flow lets users store a password hint shown on the login page, and asks for a memorable childhood question as a recovery method. Which two rules of NIST SP 800-63B does this breach? Choose two.
- 320. A legacy banking portal asks for the third, fifth and ninth characters of a customer's password, and silently ignores anything beyond 20 characters. Which two requirements of NIST SP 800-63B does this violate? Choose two.
- 321. A login page disables pasting into the password field to discourage credential sharing. What does NIST SP 800-63B say?
- 322. A design team debates whether offering to reveal the password as it is typed weakens security. What does NIST SP 800-63B recommend?
- 323. A verifier trims leading and trailing whitespace from submitted passwords before checking them. Under what condition does NIST SP 800-63B permit such allowances?
- 324. An engineer proposes storing passwords as a single unsalted SHA-256 digest for speed. Which two properties does NIST SP 800-63B require of stored passwords instead? Choose two.
- 325. A password hashing cost factor was chosen in 2018 and has never changed. What does NIST SP 800-63B recommend?
- 326. A password store keeps only the hash of each password, with a fixed application-wide salt and no record of the scheme used. Which three requirements or recommendations of NIST SP 800-63B are missed? Choose three.
- 327. A verifier adds a keyed hashing step using a secret only it holds. Where does NIST SP 800-63B say that key should live, and what does the step achieve?
- 328. A service issues each user a printed sheet of one-time codes for use if their phone is lost. In NIST SP 800-63B terms, what is this authenticator, and which factor does it represent?
- 329. Which two requirements does NIST SP 800-63B place on the generation and form of look-up secrets? Choose two.
- 330. A provider plans to deliver a new set of recovery codes through the user's existing web session. What does NIST SP 800-63B require of that session?
- 331. A consumer service authenticating at AAL1 asks how long a session may run before reauthentication, and whether an inactivity timeout is compulsory. What does NIST SP 800-63B say?
- 332. An AAL2 session has passed its inactivity timeout but not its overall timeout. What lighter reauthentication does NIST SP 800-63B permit?
- 333. How do AAL3 reauthentication requirements differ from those at AAL2?
- 334. Which three properties must an AAL3 authenticator and its protocol have, according to NIST SP 800-63B? Choose three.
- 335. A team assumes an out-of-band authenticator must meet stricter technical requirements when used at AAL2 than at AAL1. What does NIST SP 800-63B say?
- 336. A verifier sends a code to the subscriber's registered mobile device, which the subscriber then enters into the browser session being authenticated. Which authenticator type is this, in NIST SP 800-63B terms?
- 337. An architect describes access control lists and role based access control as fundamentally different models from attribute based access control. How does NIST SP 800-162 frame the relationship?
- 338. In role based access control, who determines what a subject may reach? Choose two.
- 339. An architect argues that role based and attribute based control cannot coexist because roles are not attributes. What does NIST SP 800-162 say?
- 340. What effect does NIST SP 800-162 attribute to the spread of role based access control in enterprises?
- 341. An organisation relying on access control lists finds long-serving staff hold far more access than their current jobs require. Which characteristic of the list model does NIST SP 800-162 identify as the cause?
- 342. Which four inputs does an attribute based access control mechanism combine to reach a decision, according to NIST SP 800-162?
- 343. Which of the following are environment conditions in the attribute based access control model, as opposed to subject or object attributes? Choose three.
- 344. A document is owned by one organisation but includes a section carrying another organisation's intellectual property. What does NIST SP 800-162 say about attributes in such a case?
- 345. Which access control framework does NIST SP 800-162 name as consistent with the attribute based access control model?
- 346. An auditor must show that a stated access requirement is met across an estate using access control lists and roles. Which two difficulties does NIST SP 800-162 identify? Choose two.
- 347. A photo printing site lets a user grant it access to photos held in a separate storage service. Mapping this to the four OAuth 2.0 roles, which pairing is correct?
- 348. Which two statements about the OAuth 2.0 authorization server match RFC 6749? Choose two.
- 349. A developer asks whether an OAuth access token can be parsed by the client to read the granted scope. What does RFC 6749 say about token form?
- 350. Which two benefits does RFC 6749 attribute to the access token acting as an abstraction over the underlying authorization grant? Choose two.
- 351. Which two statements about OAuth 2.0 refresh tokens match RFC 6749? Choose two.
- 352. A single-page application running entirely in the browser is being registered with an authorization server. Which OAuth client type is it, and why?
- 353. An application has a server-side component that can hold a secret and a browser component that cannot. What does RFC 6749 recommend when the authorization server offers no explicit support for such clients?
- 354. A service receives a JSON web token whose audience claim names a different service. What does RFC 7519 require it to do?
- 355. A resource server accepts JSON web tokens up to an hour past their expiry to accommodate clock differences between hosts. What does RFC 7519 permit?
- 356. Two identity providers both issue tokens with the subject value "admin" and a relying party trusts both. Which requirement of RFC 7519 addresses this hazard?
- 357. A library accepts a JSON web token whose algorithm header is set to none. Under RFC 7519, what is such a token and when is it intended to be used?
- 358. A team assumes a JSON web token is malformed because it carries no expiry claim. What does RFC 7519 say about the registered claims?
- 359. An administrator who configures user permissions is also the person who reviews the audit logs recording permission changes. Which control does SP 800-53 name for this, and what example does it give?
- 360. A manager argues that separation of duties makes fraud impossible. What does SP 800-53 actually claim for the control?
- 361. A batch job runs as a domain administrator because that was the simplest way to grant it file access. Which two points from SP 800-53's least privilege control apply? Choose two.
- 362. A design permits a cleared analyst to read a classified report but must also stop that report being copied to a system rated for lower classification. Which SP 800-53 control addresses the second requirement?
- 363. An assessment plan proposes only automated scanning. Which three assessment methods does SP 800-115 recognise, and what distinguishes them? Choose three.
- 364. An assessor asks whether a documented procedure or an individual employee can be an assessment object. What does SP 800-115 say?
- 365. An assessment programme has phases for planning and execution but stops when the findings list is produced. Which three activities does SP 800-115 place in the post-execution phase? Choose three.
- 366. Into which three families does SP 800-115 sort its technical assessment techniques?
- 367. Which activities does SP 800-115 count among review techniques? Choose three.
- 368. A team wants to enumerate live hosts, the services they expose and the weaknesses those services may carry. Which family of SP 800-115 techniques covers this work, and how is it usually performed?
- 369. Which techniques does SP 800-115 place in the target vulnerability validation family? Choose three.
- 370. An organisation buys an annual penetration test and performs no other technical assessment. Which two points from SP 800-115 argue against relying on one technique? Choose two.
- 371. A team assumes examinations never affect the environment. Which exception does SP 800-115 identify, and why?
- 372. A scoping discussion asks how much operational disruption the organisation will accept from testing. What does SP 800-115 advise?
- 373. An organisation replaces its document and configuration reviews with an expanded programme of technical testing. Which weakness does SP 800-115 say it will now miss?
- 374. A board asks why a clean penetration test report does not mean the organisation is secure. Which two reasons does SP 800-115 give? Choose two.
- 375. An external test begins before any scanning takes place. Which three sources does SP 800-115 describe reconnaissance drawing on? Choose three.
- 376. An organisation wants to understand what damage a contractor with network access could cause. Which testing viewpoint does SP 800-115 describe for this?
- 377. Which two benefits does SP 800-115 attribute to overt testing performed with the knowledge of the organisation's technology staff? Choose two.
- 378. A team plans covert testing and asks whose approval is required. What does SP 800-115 specify?
- 379. During a covert test the organisation's operations team detects unusual activity. What arrangement does SP 800-115 describe to keep that from escalating into a real incident response?
- 380. A sponsor expects a covert test to deliver a complete inventory of the organisation's vulnerabilities. Which two corrections does SP 800-115 support? Choose two.
- 381. Which four phases does SP 800-115 use for penetration testing, and what is unusual about the ordering?
- 382. A client asks what technical work happens during the planning phase of a penetration test. What does SP 800-115 say?
- 383. Which two halves make up the discovery phase of a penetration test in SP 800-115? Choose two.
- 384. A tester records that a web server runs a particular product version by reading what the service returns on connection. What is this technique called, and which enumeration methods are generally available only from inside?
- 385. A penetration test's discovery phase includes searching discarded paperwork and walking through the client's offices. Is this within the scope SP 800-115 describes?
- 386. A tester supplements automated scanning with manual vulnerability analysis. Which trade-off does SP 800-115 describe?
- 387. Which findings does SP 800-115 say a vulnerability scanner can produce? Choose three.
- 388. A scanning programme produces shallow results and the team is considering credentialed scanning. What does SP 800-115 say about that approach?
- 389. A tester plans to rely on unusual scan types to slip past the client's perimeter filtering. What does SP 800-115 caution?
- 390. Which three benefits does SP 800-115 attribute to a documented, repeatable assessment methodology? Choose three.
- 391. An agency schedules its security control testing every eighteen months. What frequency does federal law require, as cited in SP 800-115?
- 392. A team asks which single assessment methodology NIST requires them to adopt. What does SP 800-115 say?
- 393. Which activities does SP 800-115 give as examples of non-technical assessment techniques? Choose two.
- 394. A manager suggests that a thorough testing programme can substitute for implementing several costly controls. How does SP 800-115 frame the purpose of testing and examination?
- 395. An assessor asks what distinguishes the three assessment methods in SP 800-53A from the objects being assessed. What is the distinction?
- 396. Which four kinds of assessment object does SP 800-53A define?
- 397. An assessor argues that locks, keypads and fireproof safes cannot be assessment objects because they contain no code. What does SP 800-53A say?
- 398. Two assessments examine the same control. One inspects three sample servers very thoroughly; the other inspects fifty servers superficially. Which attributes does SP 800-53A use to describe this difference?
- 399. Why does SP 800-53A tie each determination statement to the wording of the control it assesses?
- 400. Who uses the findings produced by applying an assessment procedure, and for what decision?
- 401. An assessor wants to record a determination statement as partially satisfied because most of the control is in place. What does SP 800-53A allow?
- 402. An assessor could not obtain the evidence needed to judge a determination statement before the assessment window closed. How should this be recorded under SP 800-53A?
- 403. An organisation wants its assessment reports to distinguish a minor documentation gap from a control that is entirely absent. What does SP 800-53A permit?
- 404. Why does SP 800-53A place organisation-defined parameters first among a control's determination statements?
- 405. On which counts does SP 800-53A judge the strength of a component's security functionality? Choose three.
- 406. A product is deployed in millions of systems worldwide. What does SP 800-53A observe about assessing the product itself rather than each deployment?
- 407. Match the third-party assessment body to its niche as SP 800-53A describes them. Which pairings are correct? Choose three.
- 408. A vendor supplies only a high-level design summary for a product under development. What does SP 800-53A say this limits?
- 409. Which steps make up the continuous monitoring cycle in NIST SP 800-137? Choose three.
- 410. An agency writes its continuous monitoring strategy solely around individual systems. What does NIST SP 800-137 expect?
- 411. An incident response plan cites the four-phase circular life cycle from the 2012 edition of NIST's incident handling guide. What changed in Revision 3?
- 412. In the SP 800-61 Rev. 3 life cycle, which Functions are preparation that supports response without being part of it, and which are the response itself?
- 413. A team holds every lesson learned until a formal review three months after recovery completes. What does NIST SP 800-61 Rev. 3 recommend?
- 414. Which two changes in the incident landscape does NIST SP 800-61 Rev. 3 give as reasons for recasting the life cycle? Choose two.
- 415. An analyst proposes that every event in the log stream be triaged as a potential incident. How does NIST SP 800-61 Rev. 3 define an event?
- 416. A power failure takes down a data hall. Under the vocabulary of NIST SP 800-61 Rev. 3, how is this classified, and is it in scope?
- 417. Which conditions bring an occurrence within the definition of a cybersecurity incident used by NIST SP 800-61 Rev. 3? Choose two.
- 418. A detection rule fires on an adverse cybersecurity event. What does NIST SP 800-61 Rev. 3 say about declaring an incident at that point?
- 419. A reader complains that Revision 3 of the incident response guidance no longer explains how to perform containment or eradication. What reason does the document give?
- 420. A board asks the security team to guarantee that no further incidents will occur. Which framing does NIST SP 800-61 Rev. 3 offer instead?
- 421. An operations team downloads a vendor patch and installs it straight onto a test host. Which step does NIST SP 800-40 Rev. 4 say must come first, and why?
- 422. A security lead argues patch testing is a security control. How does NIST SP 800-40 Rev. 4 characterise its purpose?
- 423. Two patches are available: one closes a critical flaw on internet-facing servers, the other a minor flaw on three test machines. On what basis does NIST SP 800-40 Rev. 4 say to order them?
- 424. After a patch deployment, an audit finds that several hardened settings have reverted to vendor defaults. Which risk does NIST SP 800-40 Rev. 4 identify here?
- 425. A monitoring dashboard shows a patch as installed but the vulnerability scanner still reports the flaw. Which explanation does NIST SP 800-40 Rev. 4 offer?
- 426. A patch causes an application to fail in production. Which three remedies does NIST SP 800-40 Rev. 4 name? Choose three.
- 427. An organisation records a patch as deployed once the distribution tool reports success. Which further step does NIST SP 800-40 Rev. 4 identify, and what does it need at scale?
- 428. Which four scenarios does NIST SP 800-40 Rev. 4 expect maintenance plans to cover?
- 429. A production line controller cannot be patched without vendor recertification that will take two years. Which approach does NIST SP 800-40 Rev. 4 prescribe? Choose two.
- 430. Which three tiers make up a log management infrastructure in NIST SP 800-92? Choose three.
- 431. A server receives logs from several hundred hosts and forwards them onward. What does NIST SP 800-92 call such a server, and where may the data live?
- 432. An architect places a first level of log servers close to the generators that simply receive and forward. Which two benefits does NIST SP 800-92 attribute to this arrangement? Choose two.
- 433. An organisation cannot fund a dedicated logging network. Which two points from NIST SP 800-92 apply? Choose two.
- 434. Which two things does NIST SP 800-92 say log rotation achieves, and what commonly happens to the closed file? Choose two.
- 435. An investigator asks the logging team to keep a set of firewall logs that the schedule would delete next week. Which form of archival is this, and how does it differ from the routine kind?
- 436. A logging team suppresses duplicate and routine informational entries from its analysis pipeline. What does NIST SP 800-92 say about the effect on the original logs?
- 437. A thousand log entries each recording part of one network scan are replaced by a single entry stating how many hosts were probed. Which log management function is this?
- 438. What distinguishes log reduction from event reduction in NIST SP 800-92, and when are they typically applied?
- 439. A team must correlate logs from sources that record time in different formats and label the field differently. Which function addresses this, and what is its cost?
- 440. Which two problems does NIST SP 800-92 identify when normalising times across log sources, and what does it recommend? Choose two.
- 441. An archive of log files must be shown to be unaltered months later. Which mechanism does NIST SP 800-92 describe, and what must be done with its output?
- 442. Why does NIST SP 800-92 insist that log management functions leave the original logs unaltered?
- 443. A team wants to find relationships between entries from a firewall and entries from an authentication server. Which function is this, and what is its commonest form?
- 444. A legacy appliance cannot forward its logs to any server and is not networked. What does NIST SP 800-92 suggest where those logs must still reach the infrastructure?
- 445. A large enterprise runs dozens of separate log management infrastructures and an auditor calls for consolidation into one. Which three objections does NIST SP 800-92 support? Choose three.
- 446. A tool reads database-held log records and writes them out as structured text files, filtering and normalising along the way. Which function does NIST SP 800-92 name for this?
- 447. Which three arrangements does NIST SP 800-34 recognise for obtaining an alternate site? Choose three.
- 448. A facility offers floor space, power, telecommunications connections and environmental controls, but no servers or network equipment. Which alternate site type is this?
- 449. A recovery facility holds some of the required servers and network equipment along with power and connectivity, but is not fully configured or staffed. Which site type does NIST SP 800-34 describe?
- 450. Which three characteristics does NIST SP 800-34 attribute to a hot site? Choose three.
- 451. A utility needs recovery capability that can be moved to wherever the disruption occurs. Which option does NIST SP 800-34 describe, and what is its practical timing?
- 452. Which two statements about a mirrored site match NIST SP 800-34? Choose two.
- 453. A budget review asks which alternate site type is cheapest to maintain and what it costs the organisation in return. What does NIST SP 800-34 say?
- 454. A firm proposes an alternate site five kilometres from its head office, in the same river valley, to keep travel short. Which two considerations from NIST SP 800-34 apply? Choose two.
- 455. A system categorised low impact under FIPS 199 has no alternate site strategy, and an auditor records this as a deficiency. What does NIST SP 800-34 actually require?
- 456. A team tests its backup media each quarter by restoring a sample in its own data centre. Which further test does NIST SP 800-34 call for?
- 457. An alternate site offers ample space, power and connectivity but cannot meet the system's access control and monitoring requirements. What does NIST SP 800-34 say about accepting it?
- 458. A ransomware group encrypts a victim's systems, having first copied the data out, and threatens to publish it unless paid. What is this pattern called, and what variant does CISA also describe?
- 459. An organisation keeps nightly backups on a network share reachable from the servers it protects. Which risk does CISA's ransomware guidance identify?
- 460. A recovery plan relies entirely on redeploying golden images. Which two additional measures does CISA's ransomware guidance recommend? Choose two.
- 461. An incident response plan is stored on the corporate file share and in the ticketing system. What does CISA's ransomware guidance ask for in addition?
- 462. A team proposes moving all backups to immutable cloud storage as a complete answer to ransomware. Which two cautions does CISA raise? Choose two.
- 463. A team reads that injection has fallen in the 2025 OWASP Top 10 and concludes it is now a minor concern. Which two facts from the 2025 entry contradict that? Choose two.
- 464. Which description matches OWASP's 2025 definition of an injection vulnerability?
- 465. Why does OWASP's 2025 injection entry have a lower average weighted impact than the severity of SQL injection alone would suggest?
- 466. A team lists input validation and output escaping as its primary defences against injection. What does OWASP name as the preferred option?
- 467. A developer argues that moving all database access into stored procedures removes injection risk. Under what condition does OWASP say a stored procedure can still be injectable?
- 468. A reporting feature lets users pick which database table to report on by supplying its name. Why does OWASP treat this as dangerous even with parameterised values?
- 469. A team relies solely on positive server-side input validation to stop injection. Why does OWASP describe this as incomplete?
- 470. Which approach does OWASP describe as best for detecting injection? Choose two.
- 471. An application passes unsanitised user input into an object-relational mapper's search parameters. What does OWASP's 2025 injection entry say about this?
- 472. A team asks whether prompt injection against a language model falls inside the OWASP web application injection category. What is the position in the 2025 list?
- 473. A team plans to fix an insecure design by improving code review and static analysis. Why does OWASP say this will not work?
- 474. How does OWASP define insecure design in the 2025 Top 10?
- 475. OWASP names a factor that contributes to insecure design and explains why the design was never made secure enough. What is it?
- 476. Which three parts does OWASP give for having a secure design? Choose three.
- 477. Which activities does OWASP place in the requirements and resource management part of secure design? Choose three.
- 478. A payments flow lets a user apply a discount code an unlimited number of times because nobody defined which state transitions were disallowed. Which OWASP 2025 category does this fall under?
- 479. Where does OWASP say threat modelling belongs in an agile process, and what should it watch for?
- 480. A vendor markets a tool it says will deliver secure design for any application. How does OWASP characterise secure design?
- 481. An attacker holding a breach corpus tries each leaked password and then variants such as the same password with an incremented digit. Which two OWASP terms describe these attacks? Choose two.
- 482. A forgot-password flow asks the user for their mother's maiden name. What does OWASP's 2025 authentication entry say about such mechanisms?
- 483. An application issues a session identifier at first visit and keeps the same value after the user authenticates. Which two authentication failures does OWASP's 2025 entry describe here? Choose two.
- 484. A single sign-on integration leaves its tokens valid after the user logs out and after long periods of inactivity. How does OWASP classify this?
- 485. A service offers a code by voice call whenever the user's authenticator app is unavailable, with no further checks. Why does OWASP count this among authentication failures?
- 486. Which three practices does OWASP's 2025 authentication entry recommend? Choose three.
- 487. Which situations does OWASP's 2025 entry on software and data integrity failures describe? Choose three.
- 488. An application checks for updates over HTTPS and installs whatever the endpoint returns without verifying a signature. What consequence does OWASP describe?
- 489. A team serialises user state and passes it back and forth with each request to keep their services stateless. Which risk does OWASP's integrity failures entry identify?
- 490. An API accepts serialised objects from untrusted clients. Which condition does OWASP require before that data is used?
- 491. An organisation with a high risk profile pulls its dependencies directly from public package registries. What does OWASP recommend instead?
- 492. Which two build pipeline measures does OWASP name as integrity controls under its 2025 integrity failures entry? Choose two.
- 493. A company maps support.example.com onto a support provider's infrastructure for convenience. Which consequence does OWASP's example describe?
- 494. Home routers and set-top boxes that accept unsigned firmware are described by OWASP as a growing target. What does it say about remediating the problem?
- 495. An application logs successful logins but not failed ones. How does OWASP's 2025 logging entry treat this?
- 496. Which two shortcomings does OWASP identify where an application's logs live only on the machine that produced them? Choose two.
- 497. Why does OWASP require log data to be correctly encoded before it is written?
- 498. An application writes full patient records into its application log and shows recent log lines on an administrative page any authenticated user can open. Which two failures does OWASP identify? Choose two.
- 499. An operations centre receives thousands of alerts a day, most of them noise. How does OWASP's 2025 entry treat this situation?
- 500. An alert fires for a use case whose response playbook was written three years ago and never revised. What does OWASP say about this?