ISC2 CC Security Operations 2 — Questions and Answers
Question 1: What is the purpose of security awareness training?
- To teach employees programming and technical security skills
- To help employees recognize and respond appropriately to security threats (Correct answer)
- To replace technical security controls with human vigilance
- To satisfy audit requirements without changing behavior
Correct answer: To help employees recognize and respond appropriately to security threats
Security awareness training educates employees about security threats, policies, and proper security behavior to reduce human-related security risks.
Question 2: What is data at rest?
- Data currently being transmitted over a network
- Data stored on physical media or storage devices (Correct answer)
- Data actively being processed by a running application
- Data that has been archived for long-term compliance retention
Correct answer: Data stored on physical media or storage devices
Data at rest refers to inactive data stored on drives, databases, or other storage media, as opposed to data being transmitted or processed.
Question 3: What is the purpose of a clean desk policy?
- Keeping workstations free of dust for equipment longevity
- Ensuring sensitive information is not left visible or unattended at workstations (Correct answer)
- Removing unnecessary software from employee computers
- Organizing files in a standardized directory structure
Correct answer: Ensuring sensitive information is not left visible or unattended at workstations
A clean desk policy requires employees to secure sensitive documents and information at the end of work sessions to prevent unauthorized access.
Question 4: What does change management in security ensure?
- That all changes are made as quickly as possible to reduce downtime
- That changes to systems are reviewed, approved, and documented before implementation (Correct answer)
- That only senior IT staff can request system changes
- That all systems are updated simultaneously during maintenance windows
Correct answer: That changes to systems are reviewed, approved, and documented before implementation
Change management ensures that modifications to systems and configurations are properly reviewed, approved, and documented to minimize security and operational risks.
Question 5: What is vulnerability scanning?
- Manually reviewing source code for security flaws
- Automated identification of known security weaknesses in systems and applications (Correct answer)
- Monitoring user activity logs for suspicious behavior patterns
- Testing physical security controls with simulated attacks
Correct answer: Automated identification of known security weaknesses in systems and applications
Vulnerability scanning uses automated tools to identify known security weaknesses in systems, applications, and network devices.
Question 6: What is the 3-2-1 backup rule?
- Back up 3 times a day using 2 methods with 1 cloud copy
- Keep 3 copies of data on 2 different media types with 1 copy stored off-site (Correct answer)
- Back up every 3 hours with 2 redundant copies and 1 full weekly backup
- Use 3 servers, 2 networks, and 1 firewall for data redundancy
Correct answer: Keep 3 copies of data on 2 different media types with 1 copy stored off-site
The 3-2-1 backup rule recommends keeping 3 copies of data, on 2 different types of storage media, with 1 copy stored off-site.
What is the purpose of security awareness training?