CSS Certified Security Sentinel — Questions and Answers
Question 1: Which hashing algorithm is currently recommended by NIST for secure cryptographic applications?
- CRC32
- SHA-256 (Correct answer)
- MD5
- SHA-1
Correct answer: SHA-256
SHA-256 (part of the SHA-2 family) is NIST-recommended for cryptographic use, as MD5 and SHA-1 are vulnerable to collision attacks.
Question 2: What is the purpose of patch management in vulnerability management?
- Systematically identifies, tests, and deploys software updates to remediate known vulnerabilities (Correct answer)
- Scans systems for malware after exploitation
- Generates vulnerability reports for auditors
- Blocks all external traffic until patches are available
Correct answer: Systematically identifies, tests, and deploys software updates to remediate known vulnerabilities
Patch management reduces the attack surface by ensuring that known vulnerabilities in software and firmware are remediated in a timely, tested manner.
Question 3: What is the main vulnerability addressed by salting a password hash?
- Speeds up authentication
- Replaces the need for password complexity requirements
- Prevents brute-force attacks entirely
- Prevents rainbow table and precomputed hash lookup attacks (Correct answer)
Correct answer: Prevents rainbow table and precomputed hash lookup attacks
A salt is a random value added to a password before hashing, ensuring that identical passwords produce different hashes and defeating precomputed lookup tables.
Question 4: Which control best addresses the risk of a cloud provider outage disrupting business operations?
- Storing all disaster recovery backups on the same cloud provider
- Reducing the total number of cloud services the organization uses
- Disabling automatic updates in the cloud environment to prevent change-related outages
- Implementing multi-cloud or hybrid cloud redundancy strategies (Correct answer)
Correct answer: Implementing multi-cloud or hybrid cloud redundancy strategies
Distributing workloads across multiple cloud providers or a hybrid environment eliminates single-provider dependency and improves resilience against outages.
Question 5: Which cloud service model gives customers the LEAST control over the underlying infrastructure?
- Infrastructure as a Service (IaaS)
- Function as a Service (FaaS)
- Software as a Service (SaaS) (Correct answer)
- Platform as a Service (PaaS)
Correct answer: Software as a Service (SaaS)
In SaaS, the provider manages all infrastructure, middleware, runtime, and application code, leaving customers with control only over their own data and user access settings.
Question 6: Which data protection technique allows computations to be performed on encrypted data without decrypting it first?
- Tokenization
- Data masking
- Symmetric encryption
- Homomorphic encryption (Correct answer)
Correct answer: Homomorphic encryption
Homomorphic encryption allows mathematical operations to be performed on ciphertext such that the result, when decrypted, matches the result of operations on the plaintext.
Question 7: Which chain-of-custody principle is MOST critical when handling digital evidence collected during an incident?
- Documenting every person who accessed the evidence (Correct answer)
- Ensuring evidence is encrypted at rest
- Storing evidence on isolated network drives
- Compressing evidence files to save storage space
Correct answer: Documenting every person who accessed the evidence
Chain of custody requires a complete, unbroken record of everyone who accessed the evidence to ensure its integrity and admissibility.
Question 8: Which cloud deployment model provides an organization with the highest level of control over its infrastructure?
- Community cloud
- Public cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud is dedicated exclusively to one organization, granting the greatest control over security configurations and infrastructure.
Question 9: What is the security purpose of just-in-time (JIT) privileged access?
- Grants elevated privileges only for the duration needed, then automatically revokes them (Correct answer)
- Requires manual approval for every login attempt
- Provides persistent admin access to all systems
- Replaces the need for multi-factor authentication
Correct answer: Grants elevated privileges only for the duration needed, then automatically revokes them
JIT access reduces the standing privilege attack surface by provisioning elevated rights only when requested and revoking them immediately after the task is complete.
Question 10: What is the key principle behind privacy by design?
- Privacy controls are implemented only after a data breach occurs
- Privacy protections are embedded into systems and processes from the outset rather than added as an afterthought (Correct answer)
- Privacy is solely a legal team responsibility
- Privacy requirements are documented but not technically enforced
Correct answer: Privacy protections are embedded into systems and processes from the outset rather than added as an afterthought
Privacy by design integrates data protection principles into the architecture and design of systems from the beginning, rather than bolting them on after development.
Question 11: An organization's acceptable use policy (AUP) is BEST described as which type of security policy?
- Issue-specific policy (Correct answer)
- Regulatory policy
- System-specific policy
- Program policy
Correct answer: Issue-specific policy
Issue-specific policies address particular topics such as acceptable use of organizational assets and systems.
Question 12: What is the difference between a security audit and a security assessment?
- An audit focuses on vulnerabilities; an assessment checks policies only
- An audit measures compliance against a defined standard; an assessment evaluates overall security posture and risk (Correct answer)
- An assessment is more formal and legally binding than an audit
- They are identical processes with different names
Correct answer: An audit measures compliance against a defined standard; an assessment evaluates overall security posture and risk
Audits verify adherence to specific requirements or standards, while assessments take a broader view of security effectiveness and risk exposure.
Question 13: What does tokenization do to protect sensitive data such as payment card numbers?
- Hashes the data irreversibly
- Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault (Correct answer)
- Compresses data to reduce storage size
- Encrypts data using AES-256
Correct answer: Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault
Tokenization substitutes sensitive data with a random token; the original value is stored in a secure token vault and can only be retrieved by authorized systems.
Question 14: What is the risk-based approach to vulnerability prioritization?
- Addresses vulnerabilities only after they are actively exploited
- Prioritizes remediation based on the combination of vulnerability severity, asset criticality, and exploitability (Correct answer)
- Remediates only critical CVSS-rated vulnerabilities
- Patches all vulnerabilities in alphabetical order by CVE ID
Correct answer: Prioritizes remediation based on the combination of vulnerability severity, asset criticality, and exploitability
Risk-based prioritization considers not just CVSS score but also how critical the affected asset is and whether active exploits exist, ensuring limited resources focus on the highest-risk items first.
Question 15: What security vulnerability is MOST associated with serverless (Function as a Service) architectures?
- Complete loss of network connectivity due to ephemeral compute nodes
- Event-data injection attacks via malicious data passed through function triggers (Correct answer)
- Unauthorized physical access to the servers running the functions
- Inability to apply encryption to data processed by serverless functions
Correct answer: Event-data injection attacks via malicious data passed through function triggers
Serverless functions are triggered by events that can carry attacker-controlled data, making input validation against injection attacks a critical security concern.
Question 16: During incident recovery, what is 'reconstitution' and when does it occur?
- Reconstitution is creating forensic images; it occurs during containment
- Reconstitution is identifying the root cause; it occurs during analysis
- Reconstitution is notifying regulators; it occurs at incident discovery
- Reconstitution is restoring systems to full operational status; it occurs after eradication is confirmed (Correct answer)
Correct answer: Reconstitution is restoring systems to full operational status; it occurs after eradication is confirmed
Reconstitution involves rebuilding and restoring affected systems to normal operations and is performed only after all threats have been confirmed as removed.
Question 17: What is end-to-end encryption (E2EE) designed to prevent?
- SQL injection in database systems
- Privilege escalation on endpoints
- Interception and decryption of data by intermediaries, including service providers (Correct answer)
- Unauthorized physical access to devices
Correct answer: Interception and decryption of data by intermediaries, including service providers
E2EE ensures that only the communicating endpoints can decrypt the data, preventing even the service provider from reading message content.
Question 18: What does the Common Vulnerability Scoring System (CVSS) Base Score measure?
- The likelihood that a vulnerability will be exploited in the next 90 days
- The number of systems affected by a given CVE
- The intrinsic characteristics of a vulnerability independent of time or environment (Correct answer)
- The estimated cost to remediate a vulnerability
Correct answer: The intrinsic characteristics of a vulnerability independent of time or environment
The CVSS Base Score reflects the intrinsic qualities of a vulnerability—such as attack vector, complexity, and impact—that are constant over time and across environments.
Question 19: Which US regulatory framework mandates encryption of cardholder data at rest and in transit?
- SOX Section 404
- PCI DSS (Payment Card Industry Data Security Standard) (Correct answer)
- HIPAA Security Rule
- FISMA
Correct answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS Requirement 3 mandates protection of stored cardholder data and Requirement 4 mandates encryption of cardholder data in transit.
Question 20: Which principle best describes 'zero trust' architecture as applied to cloud environments?
- Never implicitly trusting any user, device, or network segment regardless of location (Correct answer)
- Allowing unrestricted traffic between cloud services within the same account
- Trusting all users and devices connected to the internal corporate network
- Completely delegating all security decisions to the cloud provider
Correct answer: Never implicitly trusting any user, device, or network segment regardless of location
Zero trust assumes no entity is inherently trustworthy and requires continuous verification of identity, device health, and authorization for every access request.
Question 21: Why is it important to test incident response plans regularly?
- To reduce the complexity of the plan.
- To avoid practicing incident responses.
- To limit the training of personnel.
- To identify gaps and improve response readiness (Correct answer)
Correct answer: To identify gaps and improve response readiness
Regular testing of incident response plans, through drills, tabletop exercises, and simulations, is crucial for validating their effectiveness and identifying any weaknesses or gaps. This practice allows organizations to refine their procedures, train personnel, and ensure they are well-prepared to handle real-world security incidents efficiently and effectively. Testing helps improve response readiness and reduces potential chaos during an actual event.
Question 22: Why is continuous monitoring of security risks necessary?
- To avoid addressing risks until they escalate.
- To ignore regulatory requirements.
- To reduce the need for risk analysis.
- To detect and respond to new risks and changes in existing risks (Correct answer)
Correct answer: To detect and respond to new risks and changes in existing risks
Continuous monitoring of security risks is essential because the threat landscape is constantly evolving, and an organization's vulnerabilities can change over time. It allows for the real-time detection of new threats, emerging vulnerabilities, and changes in the likelihood or impact of existing risks. This ongoing vigilance ensures that security measures remain effective and that the organization can adapt quickly to protect its assets.
Question 23: What is the difference between data masking and data encryption?
- Masking is stronger than encryption
- Masking replaces data with fictitious values while encryption scrambles data reversibly with a key (Correct answer)
- Encryption permanently destroys data
- Masking requires a decryption key to reverse
Correct answer: Masking replaces data with fictitious values while encryption scrambles data reversibly with a key
Data masking permanently replaces sensitive data with realistic but fake values, while encryption scrambles data that can be restored with the correct key.
Question 24: Which protocol is widely used for enterprise federated authentication and SSO?
- SAML (Security Assertion Markup Language) (Correct answer)
- Kerberos only
- RADIUS only
- FTP
Correct answer: SAML (Security Assertion Markup Language)
SAML is an XML-based open standard for exchanging authentication and authorization data between identity providers and service providers.
Question 25: Which framework was specifically designed to address cloud computing security controls?
- HIPAA Security Rule
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- PCI-DSS v4.0
- NIST SP 800-53
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix is a cybersecurity control framework developed by the Cloud Security Alliance specifically for cloud computing environments.
Question 26: What is the purpose of a 'forensic hold' or litigation hold during an incident investigation?
- Suspending IR activities until law enforcement takes over
- Pausing forensic analysis until legal counsel arrives
- Encrypting evidence to protect confidentiality during legal proceedings
- Preserving all potentially relevant evidence to prevent destruction or modification (Correct answer)
Correct answer: Preserving all potentially relevant evidence to prevent destruction or modification
A forensic or litigation hold legally mandates that all relevant data be preserved intact to support potential legal proceedings following an incident.
Question 27: What does FedRAMP primarily govern?
- International cloud data transfer agreements between allied nations
- Healthcare data protection standards for cloud-hosted patient records
- Security requirements for cloud services used by U.S. federal government agencies (Correct answer)
- Financial data security requirements for cloud-based payment processors
Correct answer: Security requirements for cloud services used by U.S. federal government agencies
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services procured by U.S. federal agencies.
Question 28: What is the primary function of a privileged access management (PAM) solution?
- Provides antivirus protection for servers
- Manages network firewall rules
- Securely manages, monitors, and audits access to privileged accounts and credentials (Correct answer)
- Encrypts all database records
Correct answer: Securely manages, monitors, and audits access to privileged accounts and credentials
PAM solutions vault privileged credentials, enforce access workflows, and record privileged sessions to prevent misuse and support forensic investigation.
Question 29: What is the primary advantage of asymmetric encryption over symmetric encryption?
- It uses shorter key lengths for equivalent security
- It eliminates the need to securely share a secret key between parties (Correct answer)
- It requires less computational power
- It is faster than symmetric encryption
Correct answer: It eliminates the need to securely share a secret key between parties
Asymmetric encryption uses a public/private key pair, so parties can exchange encrypted data without first sharing a secret key.
Question 30: What does 'perfect forward secrecy' (PFS) ensure in TLS connections?
- Compromise of the server's private key does not expose past session keys (Correct answer)
- All traffic is encrypted with the same session key indefinitely
- Sessions are never terminated by the server
- Certificates are automatically renewed before expiry
Correct answer: Compromise of the server's private key does not expose past session keys
PFS uses ephemeral key exchanges (like Diffie-Hellman) so each session generates a unique key that is discarded afterward, protecting past sessions.
Question 31: What is a federated identity in the context of IAM?
- An identity that is trusted and shared across multiple organizations or systems using a common standard (Correct answer)
- A local account synchronized to Active Directory only
- A temporary guest account with limited access
- An identity that requires manual admin approval
Correct answer: An identity that is trusted and shared across multiple organizations or systems using a common standard
Federated identity allows users to authenticate with one organization's identity provider and access resources at a partner organization without creating separate accounts.
Question 32: Why is containment important in incident response?
- To allow the incident to affect more areas.
- To ignore the incident.
- To focus only on internal communication.
- To prevent the incident from spreading and minimize damage (Correct answer)
Correct answer: To prevent the incident from spreading and minimize damage
Containment is a critical phase in incident response that aims to isolate the affected systems, networks, or data to prevent further damage or the spread of the attack. By containing the incident, organizations can limit its impact, preserve forensic evidence, and create a controlled environment for subsequent eradication and recovery efforts. This minimizes the overall harm caused by the security breach.
Question 33: Why is it important to assess both internal and external risks in a security risk assessment?
- Because external risks are less important.
- Because both internal and external risks contribute to overall security (Correct answer)
- Because internal risks are easily controlled.
- Because only external risks matter.
Correct answer: Because both internal and external risks contribute to overall security
A comprehensive security risk assessment must consider both internal and external risks because both can significantly impact an organization's security posture. Internal risks often stem from employees, processes, or systems within the organization, while external risks originate from outside sources like cyber attackers or natural disasters. Addressing both categories provides a holistic view and ensures robust protection against a wider range of potential threats.
Question 34: What is the principle of least privilege in identity and access management?
- All users share a common administrator account
- Access is granted by default and revoked when abused
- Users are granted only the minimum permissions necessary to perform their job functions (Correct answer)
- Privileged accounts are never used for daily tasks
Correct answer: Users are granted only the minimum permissions necessary to perform their job functions
Least privilege limits the blast radius of a compromised account by ensuring users can only access what they need for their specific role.
Question 35: Which approach to policy enforcement uses automated tools to prevent policy violations before they occur?
- Administrative enforcement
- Corrective enforcement
- Preventive enforcement (Correct answer)
- Detective enforcement
Correct answer: Preventive enforcement
Preventive enforcement uses technical controls such as DLP, firewalls, and access controls to block non-compliant actions before they happen.
Question 36: Which security concern is MOST unique to multi-tenant cloud environments?
- Data isolation and tenant separation failures (Correct answer)
- Phishing attacks targeting end users
- Password complexity and rotation requirements
- Antivirus software management across endpoints
Correct answer: Data isolation and tenant separation failures
Multi-tenancy creates the risk of data leaking between co-located tenants, making proper logical isolation the defining security concern.
Question 37: Which vulnerability assessment approach tests systems from outside the network perimeter without credentials, simulating an external attacker's perspective?
- Credentialed internal scan
- White-box source code review
- Gray-box hybrid assessment
- Black-box external scan (Correct answer)
Correct answer: Black-box external scan
A black-box external scan is performed without credentials or insider knowledge, replicating what an unauthenticated external attacker would discover.
Question 38: What is responsible disclosure in the context of vulnerability research?
- Ignoring discovered vulnerabilities to avoid legal liability
- Selling vulnerability information to the highest bidder
- Reporting discovered vulnerabilities privately to the vendor first, allowing time for a patch before public disclosure (Correct answer)
- Immediately publishing vulnerability details publicly to pressure vendors to fix issues
Correct answer: Reporting discovered vulnerabilities privately to the vendor first, allowing time for a patch before public disclosure
Responsible disclosure (coordinated vulnerability disclosure) gives vendors an agreed-upon window to develop and release a patch before the vulnerability is publicly disclosed.
Question 39: What is the primary purpose of key escrow in enterprise cryptography?
- Prevents law enforcement from accessing data
- Speeds up encryption operations
- Distributes encryption keys to all users automatically
- Allows authorized parties to recover encrypted data if the original key is lost (Correct answer)
Correct answer: Allows authorized parties to recover encrypted data if the original key is lost
Key escrow stores a copy of encryption keys with a trusted third party, enabling data recovery in case of key loss or employee departure.
Question 40: What does the term 'separation of duties' mean in access control?
- No single user has enough access to commit fraud or error without detection from another user (Correct answer)
- One person performs all privileged operations
- Access is separated from authentication
- All users share the same administrative account
Correct answer: No single user has enough access to commit fraud or error without detection from another user
Separation of duties requires that critical tasks be divided among multiple individuals so no single person can complete a sensitive process unilaterally.
Question 41: A security policy requires encryption of all mobile devices. An executive refuses to apply encryption to their personal phone used for work email. How should this be handled?
- Apply a BYOD policy that requires encryption or prohibits work email on unencrypted devices (Correct answer)
- Grant a permanent exception to the executive given their seniority
- Allow the executive to use work email without encryption on a case-by-case basis
- Remove work email access from all personal devices to avoid the issue
Correct answer: Apply a BYOD policy that requires encryption or prohibits work email on unencrypted devices
A formal BYOD policy that mandates encryption as a condition of access applies consistently regardless of seniority and preserves policy integrity.
Question 42: What is a primary security advantage of immutable infrastructure in cloud environments?
- It prevents all network-based attacks by blocking inbound connections
- It enforces MFA for all users accessing cloud resources
- It eliminates configuration drift and reduces the attack surface of long-running systems (Correct answer)
- It automatically encrypts all data stored on cloud volumes
Correct answer: It eliminates configuration drift and reduces the attack surface of long-running systems
Immutable infrastructure replaces instances rather than patching them, preventing configuration drift and ensuring every deployment starts from a known-good, consistent state.
Question 43: Which encryption mode of AES is considered most secure for bulk data encryption due to its use of an initialization vector and chaining?
- AES-OFB without IV
- DES-CBC
- AES-ECB (Electronic Codebook)
- AES-CBC (Cipher Block Chaining) (Correct answer)
Correct answer: AES-CBC (Cipher Block Chaining)
AES-CBC uses an initialization vector and chains each block to the previous ciphertext, preventing identical plaintext blocks from producing identical ciphertext.
Question 44: What is the primary purpose of Cloud Security Posture Management (CSPM)?
- To continuously assess cloud configurations for compliance gaps and security risks (Correct answer)
- To monitor and optimize cloud network bandwidth usage
- To manage user password policies across cloud-based SaaS applications
- To back up cloud data to on-premises storage systems
Correct answer: To continuously assess cloud configurations for compliance gaps and security risks
CSPM tools automatically and continuously evaluate cloud infrastructure configurations to surface misconfigurations, compliance violations, and security risks.
Question 45: During scoping a risk assessment, an analyst applies the concept of 'risk appetite' vs. 'risk tolerance.' What does risk tolerance define?
- The financial budget allocated to risk mitigation activities
- The maximum amount of risk an organization is willing to accept in pursuit of its objectives
- The ranking of risks from highest to lowest priority
- The acceptable deviation from the risk appetite that the organization can withstand (Correct answer)
Correct answer: The acceptable deviation from the risk appetite that the organization can withstand
Risk tolerance is the acceptable variation or deviation around the risk appetite level—it defines the boundaries within which the organization can operate.
Question 46: Which cryptographic concept ensures that a party cannot deny having performed an action?
- Confidentiality
- Non-repudiation (Correct answer)
- Integrity
- Availability
Correct answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, provides proof of origin so that a sender cannot later deny sending a message.
Question 47: What is the primary role of an intrusion prevention system (IPS) compared to an IDS?
- An IPS can actively block malicious traffic, while an IDS only detects and alerts (Correct answer)
- An IPS operates at Layer 7 only
- An IPS only monitors encrypted traffic
- An IDS blocks traffic while an IPS only logs
Correct answer: An IPS can actively block malicious traffic, while an IDS only detects and alerts
An IPS sits inline with traffic and can drop or block malicious packets, whereas an IDS is passive and only generates alerts.
Question 48: What does the GDPR 72-hour breach notification requirement mandate?
- Security breaches must be resolved within 72 hours
- Organizations have 72 days to notify affected individuals
- Only breaches affecting more than 72,000 individuals require notification
- Organizations must notify the supervisory authority within 72 hours of becoming aware of a personal data breach (Correct answer)
Correct answer: Organizations must notify the supervisory authority within 72 hours of becoming aware of a personal data breach
GDPR Article 33 requires organizations to notify the relevant data protection authority within 72 hours of discovering a breach that poses a risk to individuals.
Question 49: Which standard is used to automate the provisioning and deprovisioning of user accounts across systems?
- OAuth 2.0
- SCIM (System for Cross-domain Identity Management) (Correct answer)
- LDAP only
- X.509
Correct answer: SCIM (System for Cross-domain Identity Management)
SCIM is an open API standard that automates user lifecycle management, enabling systems to create, update, and delete accounts automatically across identity providers and applications.
Question 50: What role does communication play during incident recovery?
- To ensure stakeholders are informed and recovery efforts are coordinated (Correct answer)
- To focus only on external communication.
- To avoid updating the public.
- To delay recovery efforts.
Correct answer: To ensure stakeholders are informed and recovery efforts are coordinated
Effective communication during incident recovery is paramount for ensuring that all relevant internal and external stakeholders are kept informed about the incident's status, recovery progress, and any necessary actions. This coordination ensures that everyone is aligned, resources are utilized efficiently, and trust is maintained throughout the restoration process. Clear communication helps manage expectations and facilitates a smoother return to normal operations.
Question 51: What is Infrastructure as Code (IaC) security scanning?
- Reviewing the physical configurations of cloud data center servers for vulnerabilities
- Scanning cloud network traffic for malicious executable code
- Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment (Correct answer)
- Encrypting all infrastructure configuration files stored in version control
Correct answer: Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment
IaC security scanning detects security misconfigurations in infrastructure templates before they are deployed, enabling shift-left security and preventing issues from reaching production.
Question 52: What does a gap analysis in compliance management assess?
- The number of unpatched vulnerabilities in production systems
- The cost of implementing security controls
- The time required to complete a security audit
- The difference between the organization's current security posture and the requirements of a target framework or standard (Correct answer)
Correct answer: The difference between the organization's current security posture and the requirements of a target framework or standard
A gap analysis identifies which required controls are not yet implemented or are insufficiently implemented, enabling the organization to prioritize remediation efforts.
Question 53: An IR team is responding to a breach where the attacker exfiltrated data over HTTPS to an external server. Which log source would BEST help confirm this exfiltration?
- Windows Application Event Logs
- Active Directory Group Policy logs
- DHCP server lease logs
- Firewall or proxy logs showing large outbound HTTPS transfers to unknown IPs (Correct answer)
Correct answer: Firewall or proxy logs showing large outbound HTTPS transfers to unknown IPs
Firewall and proxy logs capture outbound connection details including destination IPs, data volumes, and protocols, making them ideal for detecting HTTPS-based exfiltration.
Question 54: Which attack targets authentication systems by using previously captured valid authentication tokens?
- Phishing attack
- Password spraying
- Pass-the-ticket / pass-the-hash attack (Correct answer)
- SQL injection
Correct answer: Pass-the-ticket / pass-the-hash attack
Pass-the-hash and pass-the-ticket attacks use stolen authentication tokens to authenticate as a victim without knowing the actual password.
Question 55: What is the purpose of a Public Key Infrastructure (PKI) in enterprise environments?
- Stores plaintext passwords securely
- Monitors endpoint behavior
- Provides network access control
- Manages the lifecycle of digital certificates to enable trusted encrypted communications (Correct answer)
Correct answer: Manages the lifecycle of digital certificates to enable trusted encrypted communications
PKI provides the framework for issuing, managing, distributing, and revoking digital certificates used for authentication and encryption.
Question 56: What is an orphaned account and why is it a security risk?
- A temporary contractor account with limited privileges
- An account locked after failed login attempts
- An account no longer associated with an active user that may be exploited by attackers (Correct answer)
- A shared service account with rotating credentials
Correct answer: An account no longer associated with an active user that may be exploited by attackers
Orphaned accounts belong to users who have left the organization but were not properly deprovisioned, creating an entry point for attackers.
Question 57: What is the role of a 'scribe' during a major incident response operation?
- Managing evidence collection and chain of custody
- Communicating with executive leadership during the incident
- Documenting actions taken, decisions made, and timeline of events in real time (Correct answer)
- Performing technical containment actions on compromised hosts
Correct answer: Documenting actions taken, decisions made, and timeline of events in real time
The scribe maintains a real-time log of all IR activities, decisions, and timestamps to support post-incident review and potential legal requirements.
Question 58: Which IAM concept involves automatically removing access rights when they are no longer needed?
- Access certification and deprovisioning (Correct answer)
- Role explosion
- User self-service enrollment
- Credential harvesting
Correct answer: Access certification and deprovisioning
Regular access reviews (certifications) and automated deprovisioning ensure that users who change roles or leave the organization do not retain unnecessary access.
Question 59: What is the primary purpose of a 'lessons learned' meeting after a security incident?
- Assign blame to responsible team members
- Notify affected customers of the breach
- Document what happened and improve future response processes (Correct answer)
- Restore all compromised systems to production
Correct answer: Document what happened and improve future response processes
The lessons learned meeting captures what worked, what failed, and identifies process improvements to strengthen future incident response.
Question 60: What is the role of enforcement in security policy development?
- To ignore policy violations.
- To focus solely on physical security.
- To ensure policies are followed and violations addressed (Correct answer)
- To delay security policy implementation.
Correct answer: To ensure policies are followed and violations addressed
Enforcement is critical for the effectiveness of security policies, as it ensures that the defined rules and guidelines are actually adhered to by all personnel. This involves monitoring compliance, investigating policy violations, and applying appropriate disciplinary actions when necessary. Consistent enforcement reinforces the importance of security, deters non-compliance, and maintains a strong security posture.
Question 61: Which type of attack exploits weakly configured routers to redirect traffic through an attacker-controlled path?
- DNS amplification
- ARP spoofing
- SYN flooding
- BGP hijacking (Correct answer)
Correct answer: BGP hijacking
BGP hijacking manipulates Border Gateway Protocol routes to redirect internet traffic through malicious infrastructure.
Question 62: What is a digital signature's primary function in data security?
- Encrypts data in transit
- Verifies the authenticity and integrity of a message or document (Correct answer)
- Compresses data for transmission
- Generates a symmetric session key
Correct answer: Verifies the authenticity and integrity of a message or document
A digital signature uses asymmetric cryptography to prove the message originated from a specific sender and was not altered in transit.
Question 63: In cloud computing, what does 'data sovereignty' refer to?
- A cloud provider's contractual right to access customer data for maintenance
- The encryption standard mandated for all cloud-stored data
- The legal principle that data is subject to the laws of the country where it resides (Correct answer)
- An organization's ownership rights over data it stores with a cloud provider
Correct answer: The legal principle that data is subject to the laws of the country where it resides
Data sovereignty means data is governed by the laws and regulations of the nation in which it is physically stored, affecting cross-border transfer decisions.
Question 64: Which access control model grants permissions based on a user's job role rather than individual identity?
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles, and users are granted access by being assigned to appropriate roles, simplifying administration at scale.
Question 65: During the detection phase, a SIEM generates thousands of alerts but only a small number represent real threats. What challenge does this describe?
- Lack of threat intelligence feeds
- Insufficient logging coverage across systems
- Alert fatigue due to high false positive rates (Correct answer)
- Misconfigured network access control lists
Correct answer: Alert fatigue due to high false positive rates
Alert fatigue occurs when security teams are overwhelmed by high volumes of false positive alerts, increasing the risk of missing genuine threats.
Question 66: What is behavioral analytics in the context of IAM security?
- Monitors physical access logs only
- Uses baseline behavior patterns to detect anomalous user activity that may indicate account compromise (Correct answer)
- Tracks network bandwidth usage per user
- Analyzes code for security vulnerabilities
Correct answer: Uses baseline behavior patterns to detect anomalous user activity that may indicate account compromise
User and entity behavior analytics (UEBA) establishes baselines of normal activity and flags deviations such as unusual login times, locations, or data access patterns.
Question 67: Which metric is used to measure the effectiveness of an incident response team's detection capabilities?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Mean Time to Recover (MTTR)
- Mean Time to Detect (MTTD) (Correct answer)
Correct answer: Mean Time to Detect (MTTD)
MTTD measures the average time from when an incident occurs to when it is detected, directly reflecting detection capability effectiveness.
Question 68: What network security control is designed to detect and prevent unauthorized wireless access points?
- WPA2 encryption
- MAC address filtering
- SSID broadcasting
- Wireless intrusion prevention system (WIPS) (Correct answer)
Correct answer: Wireless intrusion prevention system (WIPS)
A WIPS monitors the radio frequency spectrum to detect rogue access points and automatically mitigate them.
Question 69: Which privacy law in the United States grants California residents rights over their personal data?
- HIPAA
- COPPA
- California Consumer Privacy Act (CCPA) (Correct answer)
- FERPA
Correct answer: California Consumer Privacy Act (CCPA)
The CCPA gives California residents rights to know what personal data is collected, delete it, and opt out of the sale of their data.
Question 70: What is credential stuffing and how does it differ from brute-force attacks?
- Both attacks use the same technique
- Brute force uses breached credentials; credential stuffing generates random passwords
- Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations (Correct answer)
- Credential stuffing is slower than brute force
Correct answer: Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations
Credential stuffing relies on real credentials from previous data breaches, making it more effective than random brute-force guessing.
Question 71: What is the security risk of using weak or short RSA key lengths (e.g., 512-bit) in production systems?
- They can be factored using modern computing power, allowing private key recovery (Correct answer)
- They cannot be used with digital signatures
- They consume excessive server memory
- They are not compatible with TLS 1.3
Correct answer: They can be factored using modern computing power, allowing private key recovery
Short RSA keys can be broken through integer factorization attacks; NIST recommends at least 2048-bit keys for current applications.
Question 72: What is the difference between an Incident Response Plan (IRP) and a Business Continuity Plan (BCP)?
- IRP and BCP are identical documents with different names
- IRP addresses security event response; BCP ensures critical business functions continue during disruptions (Correct answer)
- IRP is for physical incidents; BCP is for cyber incidents only
- IRP focuses on restoring IT systems; BCP focuses on security event investigation
Correct answer: IRP addresses security event response; BCP ensures critical business functions continue during disruptions
An IRP governs how to respond to and recover from security incidents, while a BCP ensures essential business operations continue under any disruptive condition.
Question 73: Why is it necessary to evaluate the likelihood and impact of each identified risk?
- To prioritize resources and mitigation efforts (Correct answer)
- Because some risks are too small to consider.
- Because the organization can handle all risks.
- To ignore unlikely risks.
Correct answer: To prioritize resources and mitigation efforts
Evaluating the likelihood and impact of each identified risk is essential for effective risk management. This analysis allows an organization to understand the potential severity and frequency of different risks. By quantifying these factors, resources can be strategically allocated to mitigate high-priority risks that pose the greatest threat, ensuring efficient and targeted security efforts.
Question 74: What is the role of a certificate revocation list (CRL) in PKI?
- Stores encrypted private keys for recovery
- Lists certificates that have been invalidated before their expiration date (Correct answer)
- Contains public keys of trusted root CAs
- Lists all valid certificates issued by the CA
Correct answer: Lists certificates that have been invalidated before their expiration date
A CRL is a signed list published by a Certificate Authority of certificates that have been revoked due to compromise, policy violation, or other reasons.
Question 75: What is the role of incident reporting in security policy enforcement?
- To reduce accountability.
- To avoid identifying violations.
- To ignore security incidents.
- To track violations and enforce corrective actions (Correct answer)
Correct answer: To track violations and enforce corrective actions
Incident reporting is a vital component of security policy enforcement as it provides a formal mechanism to document and track policy violations and security incidents. This information is used to investigate the root cause of the violation, apply appropriate corrective actions, and ensure accountability. Effective reporting reinforces the importance of adhering to security policies and helps prevent future occurrences.
Question 76: What is a key factor in effectively preventing insider threats?
- Focusing only on external threats.
- Allowing unrestricted access to sensitive data.
- Implementing access controls, monitoring, and policies (Correct answer)
- Ignoring employee behavior.
Correct answer: Implementing access controls, monitoring, and policies
Insider threats originate from individuals within an organization who have authorized access to systems or data. Preventing these threats requires a multi-faceted approach, including strict access controls based on the principle of least privilege, continuous monitoring of user activities for suspicious behavior, and clear security policies that employees must adhere to. These measures help detect and deter malicious or negligent insider actions.
Question 77: Which security mechanism prevents a compromised VLAN from accessing other VLANs through switch exploitation?
- Disabling trunk negotiation and using dedicated native VLANs (Correct answer)
- Enabling spanning tree protocol
- Using dynamic ARP inspection only
- Increasing VLAN ID numbers
Correct answer: Disabling trunk negotiation and using dedicated native VLANs
Disabling Dynamic Trunking Protocol and setting a dedicated unused native VLAN prevents VLAN hopping attacks.
Question 78: What is the key security benefit of cloud-native security tools compared to third-party alternatives?
- They offer deeper integration with provider APIs and native telemetry for broader visibility (Correct answer)
- They completely replace the need for identity and access management controls
- They require zero configuration or tuning by security teams after deployment
- They are always less expensive than equivalent third-party solutions
Correct answer: They offer deeper integration with provider APIs and native telemetry for broader visibility
Cloud-native security tools leverage deep API integration and platform telemetry that third-party tools cannot always access, enabling more comprehensive detection and automated response.
Question 79: What is the purpose of a System and Organization Controls (SOC 2) audit?
- Verifies network penetration testing results
- Audits financial statements for accuracy
- Certifies that products meet hardware safety standards
- Evaluates a service organization's controls for security, availability, processing integrity, confidentiality, and privacy (Correct answer)
Correct answer: Evaluates a service organization's controls for security, availability, processing integrity, confidentiality, and privacy
SOC 2 reports assess whether a service provider's controls meet the AICPA Trust Service Criteria, particularly relevant for cloud and SaaS providers handling customer data.
Question 80: What is the primary purpose of a next-generation firewall (NGFW) compared to a traditional stateful firewall?
- Support for IPv6 only
- Hardware-based encryption offloading
- Deep packet inspection and application-layer filtering (Correct answer)
- Faster packet forwarding speeds
Correct answer: Deep packet inspection and application-layer filtering
NGFWs add deep packet inspection and application-layer awareness beyond the port/protocol filtering of stateful firewalls.
Question 81: What does multi-factor authentication (MFA) require beyond a username and password?
- An additional security question only
- A second username and password combination
- A hardware firewall device
- At least one additional verification factor such as a token, biometric, or push notification (Correct answer)
Correct answer: At least one additional verification factor such as a token, biometric, or push notification
MFA combines something you know (password) with something you have (token) or something you are (biometric) to reduce account takeover risk.
Question 82: An employee shares confidential customer data via personal email in violation of the data handling policy. Which consequence framework BEST supports consistent enforcement?
- A verbal warning for first-time violations with no documentation
- An immediate termination for all policy violations
- A written reprimand issued at management's discretion
- A pre-defined disciplinary matrix tied to violation severity (Correct answer)
Correct answer: A pre-defined disciplinary matrix tied to violation severity
A disciplinary matrix provides consistent, documented, and graduated consequences based on violation type and severity, ensuring fair and defensible enforcement.
Question 83: From a security perspective, what does a Service Level Agreement (SLA) with a cloud provider typically address?
- Guaranteed uptime commitments, incident response timelines, and division of security responsibilities (Correct answer)
- The specific encryption algorithms the provider will use to protect customer data
- The number of certified security staff the provider is required to employ
- The maximum number of concurrent users permitted on the platform
Correct answer: Guaranteed uptime commitments, incident response timelines, and division of security responsibilities
SLAs establish measurable commitments for availability, incident notification windows, and clarify the boundary of security responsibilities between provider and customer.
Question 84: Which penetration testing phase involves gathering information about the target without directly interacting with its systems?
- Post-exploitation
- Active scanning
- Exploitation
- Passive reconnaissance (Correct answer)
Correct answer: Passive reconnaissance
Passive reconnaissance collects publicly available information (OSINT) about the target without sending any traffic to its systems, making it harder to detect.
Question 85: Which encryption protocol version is considered best practice for protecting data in transit within cloud environments?
- SSL 3.0 for maximum compatibility with legacy systems
- Symmetric AES-128 with a shared key distributed to all service accounts
- TLS 1.2 or higher for all cloud communications (Correct answer)
- MD5-based HMAC for lightweight authentication of cloud API calls
Correct answer: TLS 1.2 or higher for all cloud communications
TLS 1.2 and TLS 1.3 are the current industry standards for securing data in transit; earlier versions contain known vulnerabilities and should not be used.
Question 86: Which term describes the risk that remains after all planned security controls have been implemented?
- Secondary risk
- Inherent risk
- Residual risk (Correct answer)
- Transferred risk
Correct answer: Residual risk
Residual risk is the level of risk that persists after an organization has applied its security controls and mitigation measures.
Question 87: What is a key security consideration when cloud services process data belonging to EU citizens?
- The data must be stored exclusively on U.S.-based servers to meet export controls
- Cloud providers must obtain annual security certification directly from the European Commission
- GDPR compliance requirements including data subject rights and cross-border transfer restrictions (Correct answer)
- The data must be encrypted using only EU government-approved cryptographic algorithms
Correct answer: GDPR compliance requirements including data subject rights and cross-border transfer restrictions
GDPR imposes obligations on any organization handling EU citizen data, including honoring data subject rights and restricting transfers of that data outside the European Economic Area.
Question 88: What is the difference between authentication and authorization in IAM?
- Authentication verifies identity; authorization determines what an authenticated identity is permitted to do (Correct answer)
- Authentication assigns roles; authorization validates passwords
- They are the same process
- Authorization verifies identity; authentication assigns permissions
Correct answer: Authentication verifies identity; authorization determines what an authenticated identity is permitted to do
Authentication confirms who you are, while authorization determines what resources and actions you are permitted to access once your identity is confirmed.
Question 89: A new remote work policy requires VPN use for all corporate data access. An employee working from a hotel reports the VPN is blocked. Which is the MOST appropriate immediate response?
- Ask IT to create a temporary VPN bypass for the employee
- Allow the employee to access data without VPN for the duration of the trip
- Have the employee defer work until VPN access is restored or provide a compliant alternative (Correct answer)
- Advise the employee to use personal hotspot and proceed without VPN
Correct answer: Have the employee defer work until VPN access is restored or provide a compliant alternative
Maintaining policy integrity requires either restoring compliant access or deferring work, rather than accepting an uncontrolled risk.
Question 90: What is the purpose of a privileged access workstation (PAW)?
- A hardened, dedicated workstation used exclusively for privileged administrative tasks (Correct answer)
- A virtual machine for testing malware
- A remote desktop server for multiple users
- A shared workstation for general office use
Correct answer: A hardened, dedicated workstation used exclusively for privileged administrative tasks
A PAW is a dedicated, highly secured device used only for admin tasks, reducing exposure to phishing and malware that could compromise privileged credentials.
Question 91: What is a Cloud Access Security Broker (CASB)?
- A government certification body for cloud service providers
- A type of cloud-based firewall specifically for blocking malicious IP ranges
- A hardware device that encrypts cloud traffic at the network edge
- A security policy enforcement point between cloud users and cloud services (Correct answer)
Correct answer: A security policy enforcement point between cloud users and cloud services
A CASB acts as an intermediary security layer that enforces visibility and policy controls between users and cloud applications.
Question 92: What is the recommended approach for managing privileged access in cloud environments?
- Implementing just-in-time (JIT) access with least privilege principles (Correct answer)
- Using shared administrator accounts to improve operational efficiency
- Storing privileged credentials directly in application environment variables
- Granting all administrators full access to simplify permissions management
Correct answer: Implementing just-in-time (JIT) access with least privilege principles
JIT access grants elevated permissions only when operationally required and for a limited duration, minimizing the attack surface while adhering to least privilege.
Question 93: Which log source is MOST valuable for detecting pass-the-hash attacks in a Windows Active Directory environment?
- DNS query logs from the recursive resolver
- Web server access logs
- Windows Security Event logs (Event IDs 4624, 4625, 4648) (Correct answer)
- Network flow records from core routers
Correct answer: Windows Security Event logs (Event IDs 4624, 4625, 4648)
Windows Security Event logs capture authentication events including logon type 3 with NTLM, which is characteristic of pass-the-hash lateral movement.
Question 94: What is the significance of a 'right to audit' clause in a cloud service contract?
- It mandates government regulatory agencies to conduct annual audits of the cloud provider
- It requires independent third-party auditors to review all cloud financial transactions quarterly
- It authorizes cloud providers to audit customer security practices and charge for findings
- It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture (Correct answer)
Correct answer: It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture
A right-to-audit clause allows the customer to independently verify that the cloud provider's security controls and compliance posture meet contractual and regulatory obligations.
Question 95: What does single sign-on (SSO) provide to enterprise users?
- Automatic privilege escalation for all users
- Access to multiple applications using one set of credentials authenticated once (Correct answer)
- Elimination of all password requirements
- A single password shared across all users
Correct answer: Access to multiple applications using one set of credentials authenticated once
SSO allows users to authenticate once with an identity provider and gain access to multiple connected applications without re-entering credentials.
Question 96: Which security control is MOST effective at preventing unauthorized data exfiltration from a cloud storage service?
- Requiring all cloud users to complete annual security awareness training
- Storing all cloud data in an encrypted format using provider-managed keys
- Enabling versioning on all cloud storage buckets
- Implementing data loss prevention (DLP) policies with egress monitoring and blocking (Correct answer)
Correct answer: Implementing data loss prevention (DLP) policies with egress monitoring and blocking
DLP policies inspect outbound data flows and can block or alert on unauthorized transfers of sensitive information, directly addressing exfiltration risk.
Question 97: What does the 'shared responsibility model' in cloud security primarily define?
- A framework for sharing encryption keys between cloud tenants
- The process for dividing costs of security tools between teams
- The division of security responsibilities between the cloud provider and the customer (Correct answer)
- A protocol for sharing security incidents between cloud vendors
Correct answer: The division of security responsibilities between the cloud provider and the customer
The shared responsibility model delineates which security tasks are managed by the cloud provider versus those that remain the customer's obligation.
Question 98: What type of encryption is used in TLS handshakes to securely exchange session keys?
- One-time pad encryption
- Homomorphic encryption
- Symmetric AES encryption
- Asymmetric encryption (e.g., RSA or ECDH) (Correct answer)
Correct answer: Asymmetric encryption (e.g., RSA or ECDH)
TLS uses asymmetric cryptography during the handshake to securely establish a shared symmetric session key for bulk data encryption.
Question 99: Which key management practice ensures that encryption keys are protected from the data they encrypt?
- Sharing keys via unencrypted email
- Storing keys in a separate hardware security module (HSM) (Correct answer)
- Storing keys in the same database as encrypted data
- Encoding keys in application source code
Correct answer: Storing keys in a separate hardware security module (HSM)
An HSM is a dedicated hardware device that stores and processes cryptographic keys in a tamper-resistant environment, separate from the data.
Question 100: Which IAM control helps prevent privilege escalation by ensuring users cannot grant themselves higher permissions than they currently hold?
- Session timeout policies
- Group membership auto-assignment
- Password complexity requirements
- Constrained delegation and permission boundary enforcement (Correct answer)
Correct answer: Constrained delegation and permission boundary enforcement
Constrained delegation and IAM permission boundaries ensure that even if an account is compromised, the attacker cannot escalate to permissions beyond those already assigned.
CSS Certified Security Sentinel
The Certified Security Sentinel (CSS) is a vendor-neutral, entry-level cybersecurity certification by Mile2 that validates foundational knowledge in network security, data protection, identity management, cloud security, cryptography, and regulatory compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds