When network management is outsourced to third parties, which of the following is the MOST effective method of protecting critical data assets?
Answer : D
The most effective method of protecting critical data assets when network management is outsourced to third parties is to employ strong access controls. Access controls are the measures or mechanisms that regulate who or what can view or use the resources in a network or system. Access controls can help to protect critical data assets from unauthorized or malicious access, modification, disclosure, or destruction by the third parties who manage the network. Access controls can be classified into different types, such as administrative, technical, physical, preventive, detective, corrective, deterrent, or compensating. Access controls can also be categorized into different models, such as discretionary access control (DAC), mandatory access control (MAC), role-based access control (RBAC), or attribute-based access control (ABAC). Employing strong access controls means implementing and enforcing the appropriate access policies, rules, and procedures, as well as selecting and applying the suitable access methods, techniques, and technologies. Employing strong access controls also means monitoring and auditing the access activities and events, and reviewing and updating the access controls regularly. Logging all activities associated with sensitive systems, providing links to security policies, and confirming that confidentiality agreements are signed are not the most effective methods of protecting critical data assets when network management is outsourced to third parties, although they may be useful or necessary steps. Logging all activities associated with sensitive systems is a technique to record and track the actions and events that occur on the systems that host or process the critical data assets. Logging can help to detect and investigate any anomalies, incidents, or breaches that may affect the critical data assets, but it does not prevent or mitigate them. Providing links to security policies is a technique to communicate and educate the third parties who manage the network about the security objectives, requirements, and expectations of the organization. Security policies can help to establish and enforce the security roles, responsibilities, and rules for the third parties, but they do not guarantee or verify their compliance or performance. Confirming that confidentiality agreements are signed is a technique to legally bind the third parties who manage the network to protect the confidentiality of the critical data assets. Confidentiality agreements can help to deter or penalize the third parties from disclosing or misusing the critical data assets, but they do not prevent or mitigate the risk of accidental or intentional exposure or compromise.
Which of the following protection is provided when using a Virtual Private Network (VPN) with Authentication Header (AH)?
Answer : C
A VPN is a secure tunnel that connects two or more networks over a public network, such as the internet. VPNs use encryption and authentication protocols to protect the data in transit from unauthorized access, modification, or disclosure. AH is one of the protocols used by IPsec, which is a suite of protocols for securing IP traffic. AH provides integrity, authentication, and anti-replay protection for the entire IP packet, including the header and the payload. AH does not provide payload encryption or sender confidentiality, which are provided by another IPsec protocol called Encapsulating Security Payload (ESP). AH also does not provide multi-factor authentication (MFA), which is a method of verifying the identity of a user or a device by requiring two or more factors, such as something you know, something you have, or something you are. AH does provide sender non-repudiation, which is the assurance that the sender of a message cannot deny sending it, because the message is authenticated with a digital signature or a keyed hash that only the sender can generate.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Communication and Network Security, page 215.Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 4: Communication and Network Security, page 463.
Which of the following is an indicator that a company's new user security awareness training module has been effective?
Answer : B
In the "Do" phase of the Plan-Do-Check-Act model, which of the following is performed?
Answer : C
The Plan-Do-Check-Act (PDCA) model is a four-step iterative process for implementing, maintaining, and improving a management system, such as a Business Continuity Management (BCM) system. The PDCA model consists of the following phases:
Plan: Establish the objectives, scope, and requirements of the BCM system, and develop the business continuity policy, strategy, plans, and procedures.
Do: Implement the business continuity policy, controls, processes, and procedures, and conduct the necessary training, awareness, and testing activities.
Check: Monitor and review the performance and effectiveness of the BCM system against the business continuity policy and objectives, and report the results and findings to the management for review.
Act: Maintain and improve the BCM system by taking corrective and preventive actions, based on the results of the management review and the feedback from the stakeholders. In the ''Do'' phase of the PDCA model, the main activity is to ensure the business continuity policy, controls, processes, and procedures have been implemented, as planned in the previous phase. This involves allocating the necessary resources, roles, and responsibilities, and executing the business continuity plans and procedures in accordance with the business continuity strategy. This also involves providing the appropriate training and awareness programs to the staff and the relevant parties, and conducting the regular testing and exercising of the business continuity plans and procedures, to verify their functionality and suitability.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 8: Security Operations, page 557.Official (ISC) CISSP CBK Reference, Fifth Edition, Domain 7: Security Operations, page 921.
Which of the following regulations dictates how data breaches are handled?
Answer : D
The General Data Protection Regulation (GDPR) is a regulation that dictates how data breaches are handled, among other data protection and privacy requirements. The GDPR applies to any organization that processes the personal data of individuals in the European Union (EU), regardless of the location of the organization. The GDPR defines a personal data breach as ''a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed''. The GDPR requires the organization to notify the supervisory authority of the data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the individuals. The GDPR also requires the organization to notify the affected individuals of the data breach without undue delay, if the breach is likely to result in a high risk to their rights and freedoms .Reference: [CISSP CBK, Fifth Edition, Chapter 1, page 64]; [CISSP Practice Exam -- FREE 20 Questions and Answers, Question 20].
When using third-party software developers, which of the following is the MOST effective method of providing software development Quality Assurance (QA)?
Answer : B
When using third-party software developers, the most effective method of providing software development Quality Assurance (QA) is to perform overlapping code reviews by both parties. Code reviews are the process of examining the source code of an application for quality, functionality, security, and compliance. Overlapping code reviews by both parties means that the code is reviewed by both the third-party developers and the contracting organization, and that the reviews cover the same or similar aspects of the code. This can ensure that the code meets the requirements and specifications, that the code is free of defects or vulnerabilities, and that the code is consistent and compatible with the existing system or environment. Retaining intellectual property rights through contractual wording, verifying that the contractors attend development planning meetings, and creating a separate contractor development environment are all possible methods of providing software development QA, but they are not the most effective method of doing so.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 8, Software Development Security, page 1026.Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 8, Software Development Security, page 1050.
A company developed a web application which is sold as a Software as a Service (SaaS) solution to the customer. The application is hosted by a web server running on a 'specific operating system (OS) on a virtual machine (VM). During the transition phase of the service, it is determined that the support team will need access to the application logs. Which of the following privileges would be the MOST suitable?
Answer : B
The most suitable privileges for the support team to access the application logs of a web application that is hosted by a web server running on a specific OS on a VM are administrative privileges on the web server. A web application is a type of software application that runs on a web server, and that can be accessed and used by the users or the customers through a web browser, over the internet or a network. A web application can generate and store various types of logs, such as access logs, error logs, or security logs, that record and provide information about the activities, events, or issues that occur on the web application. A web server is a type of software or hardware that hosts and delivers the web application and its content to the web browser, using the Hypertext Transfer Protocol (HTTP) or other protocols. A web server can run on a specific OS, such as Windows, Linux, or MacOS, and it can run on a physical or a virtual machine. A VM is a type of software that emulates a physical machine, and that can run multiple OSs and applications on the same physical machine, using a software layer called a hypervisor. Administrative privileges are a type of access rights or permissions that grant the user or the role the ability to perform various actions or tasks on a system or a service, such as installing, configuring, or managing the system or the service.Administrative privileges on the web server are the most suitable privileges for the support team to access the application logs of a web application that is hosted by a web server running on a specific OS on a VM, as they can provide the support team with the necessary and sufficient access rights or permissions to view, analyze, or troubleshoot the application logs, without compromising the security or the functionality of the OS, the VM, or the hypervisor56.Reference:CISSP CBK, Fifth Edition, Chapter 3, page 241;CISSP Practice Exam -- FREE 20 Questions and Answers, Question 16.