CCISO Core IT Security 4 — Questions and Answers
Question 1: A CISO must develop a Business Continuity Plan (BCP). Which metric defines the maximum acceptable amount of time a system can be offline before causing unacceptable business impact?
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Time Objective (RTO)
RTO specifies the target time within which a system must be restored after a disruption to avoid unacceptable consequences.
Question 2: During a forensic investigation, which principle ensures that evidence is collected and handled in a manner that preserves its admissibility in court?
- Non-repudiation
- Chain of custody (Correct answer)
- Due diligence
- Data minimization
Correct answer: Chain of custody
Chain of custody documents every person who handled evidence and every action taken, ensuring its integrity and legal admissibility.
Question 3: An organization's security policy requires that employees use multi-factor authentication. An employee uses a password and a hardware token. These represent which two authentication factor types?
- Something you know and something you have (Correct answer)
- Something you are and something you know
- Something you have and something you are
- Something you know and something you are
Correct answer: Something you know and something you have
A password is 'something you know' and a hardware token is 'something you have,' satisfying two distinct MFA factor categories.
Question 4: A CISO is evaluating cloud security controls. Which framework specifically addresses cloud security best practices and provides a Cloud Controls Matrix (CCM)?
- NIST SP 800-53
- ISO/IEC 27001
- Cloud Security Alliance (CSA) (Correct answer)
- CIS Controls
Correct answer: Cloud Security Alliance (CSA)
The CSA publishes the Cloud Controls Matrix, a framework of security controls specifically mapped to cloud service delivery models.
Question 5: Which type of social engineering attack involves sending fraudulent emails to a small, highly targeted group of individuals within a specific organization?
- Phishing
- Vishing
- Spear phishing (Correct answer)
- Whaling
Correct answer: Spear phishing
Spear phishing targets a specific individual or small group with personalized messages, unlike broad phishing campaigns.
Question 6: An organization implements encryption for data at rest in its database. Which threat does this control primarily mitigate?
- SQL injection attacks
- Unauthorized access to stolen storage media (Correct answer)
- Man-in-the-middle attacks
- Denial of service attacks
Correct answer: Unauthorized access to stolen storage media
Encrypting data at rest protects data stored on disk from being read if physical storage media is stolen or improperly disposed of.
Question 7: A CISO is reviewing a third-party vendor's security posture as part of supply chain risk management. Which document should the vendor provide to demonstrate its security controls?
- Non-disclosure agreement (NDA)
- Service Level Agreement (SLA)
- SOC 2 Type II report (Correct answer)
- Master Service Agreement (MSA)
Correct answer: SOC 2 Type II report
A SOC 2 Type II report provides an independent auditor's assessment of a vendor's security, availability, and confidentiality controls over a period of time.
A CISO must develop a Business Continuity Plan (BCP).
Which metric defines the maximum acceptable amount of time a system can be offline before causing unacceptable business impact?