16 questions

Security Operations

A responder must collect evidence from a running compromised server. According to RFC 3227's order of volatility, what should be collected first?

  • a.Memory and the process table✓
  • b.Archived backup tapes
  • c.Remote log server records
  • d.The server's hard disk image

RFC 3227 orders collection from most to least volatile: registers and cache; then routing table, ARP cache, process table, kernel statistics and memory; then temporary file systems, disk, remote logging data, physical configuration and archival media. Disk images, remote logs and archives persist much longer than memory, so they come later.

Security Operations

A seized laptop was handed from the first responder to a forensic analyst and then to legal counsel. What must the chain-of-custody record capture for each transfer?

  • a.The analyst's preferred forensic software version
  • b.Each handler, the transfer time and the purpose✓
  • c.A summary of the suspected offender's motive
  • d.The laptop's purchase price and warranty status

NIST defines chain of custody as a process that tracks the movement of evidence through collection, safeguarding and analysis by documenting each person who handled it, the date/time it was collected or transferred, and the purpose for any transfer. Tool versions belong in the analysis notes, asset value is irrelevant to integrity, and motive is an investigative conclusion rather than custody data.

Security Operations

After acquiring a disk image, how should a forensic analyst conduct the examination?

  • a.On a hash-verified copy of the evidence✓
  • b.On an unverified copy
  • c.Directly on the original drive
  • d.On the original, noting the date

RFC 3227 advises minimizing changes to evidence and making a bit-level copy for analysis, because analysis alters file access times; comparing cryptographic hashes of the copy and original shows the copy is exact. Working on the original risks altering it, a date note does not prevent changes, and an unverified copy cannot be shown to match the evidence.

Security Operations

A junior administrator wants to power off a compromised server immediately so the attacker cannot do more damage, before any evidence is collected. What does RFC 3227 warn about this?

  • a.Volatile evidence can be lost✓
  • b.Shutting down resets the server's audit logs to empty
  • c.Shutting down automatically notifies law enforcement
  • d.Shutting down permanently encrypts the disk contents

RFC 3227 advises not shutting down until evidence collection is complete, because volatile evidence may be lost and an attacker may have altered startup or shutdown scripts to destroy evidence; network isolation can contain the host while memory is preserved. Powering off does not notify authorities, encrypt disks by itself, or clear persistent logs.

Security Operations

A team tunes its intrusion detection system to cut false negatives. According to NIST SP 800-94, what side effect should it expect?

  • a.Fewer false positives
  • b.Loss of all signatures
  • c.More false positives✓
  • d.No change in alerts

SP 800-94 explains that it is not possible to eliminate all false positives and false negatives and that reducing one usually increases the other; many organizations accept more false positives to reduce false negatives. Tuning does not delete signatures, and alert volume will not stay the same.

Security Operations

An organization needs to detect a novel attack for which no signature exists. Which detection methodology described in NIST SP 800-94 is best suited?

  • a.Hash blocklisting
  • b.Anomaly-based detection✓
  • c.Signature-based detection
  • d.Exact string matching

SP 800-94 describes signature-based detection as comparing activity to patterns of known threats, which is ineffective against previously unknown attacks, while anomaly-based detection compares activity to a baseline of normal behavior and can flag new attacks. Exact string matching and hash blocklists are forms of known-bad matching with the same limitation.

Security Operations

An integrity-monitoring tool reports that a production server's configuration no longer matches the approved baseline, and no change ticket exists. What does NIST SP 800-128 expect next?

  • a.Update the baseline to match the server
  • b.Investigate it as an unauthorized change✓
  • c.Ignore it unless the server stops working
  • d.Rebuild every server in the environment

SP 800-128 has organizations monitor systems against approved baseline configurations and include procedures for handling unauthorized changes, which may indicate compromise or process failure. Adopting the drift as the new baseline legitimizes an unknown change, ignoring it misses possible compromise, and rebuilding everything is disproportionate before investigation.

Security Operations

At 2 a.m. an administrator applies an emergency patch to stop active exploitation, with no time to convene the change board. What does NIST SP 800-128 say should happen?

  • a.No record is needed because it was an emergency
  • b.The patch must be rolled back until the board meets
  • c.It is put through change control afterward✓
  • d.The administrator's manager must approve every future patch

SP 800-128 says unscheduled (emergency) changes are still managed and controlled, and changes needing configuration control must go through the change control process even if it is after the fact, including a security impact analysis once implemented. Skipping the record loses control, rolling back reopens the exploited hole, and a blanket manager approval is not what the guidance calls for.

Security Operations

An audit finds that the same accounts-payable clerk can create new vendors and approve payments to them. Which principle does this violate?

  • a.Data minimisation
  • b.Separation of duties✓
  • c.Defense in depth
  • d.Need to know

RFC 4949 defines separation of duties as dividing the steps of a process among different entities so that no single entity acting alone can subvert it, and NIST SP 800-53 Rev. 5 AC-5 requires identifying and documenting duties to be separated. Need to know limits information access, defense in depth layers controls, and data minimisation limits personal data collected; none addresses one person controlling both steps.

Security Operations

A vendor announces a critical vulnerability but will not release a patch for three weeks. According to NIST SP 800-40 Rev. 4, what should the organization do meanwhile?

  • a.Uninstall all software from the same vendor
  • b.Mitigate or isolate until the patch arrives✓
  • c.Accept the risk automatically for three weeks
  • d.Wait for the patch because nothing else is effective

SP 800-40 Rev. 4 notes that patching is sometimes not immediately viable, for example when a patch is not yet available, and that organizations should then choose other risk responses, such as mitigating the risk with other controls or isolating the vulnerable asset. Waiting passively, removing an entire vendor's software, or automatic acceptance ignore the available options.

Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Security Operations

A recovery strategy calls for an alternate facility that already has operational equipment, current production software and recent backup data loaded, but the budget rules out real-time mirroring. Which site type described in NIST SP 800-34 Rev. 1 fits?

  • a.A hot site✓
  • b.A mirrored site
  • c.A cold site
  • d.A warm site

SP 800-34 Rev. 1 describes a hot site as having fully operational equipment and current software ready to take over quickly, a warm site as equipped but without the software and data loaded, and a cold site as space and infrastructure only, with the longest recovery. A mirrored site adds automated real-time mirroring, which the budget excludes.

Security Operations

A database is backed up nightly at midnight, and the business says it cannot lose more than one hour of transactions. Which objective does the current design fail to meet?

  • a.The mean time to repair
  • b.The recovery time objective
  • c.The maximum tolerable downtime
  • d.The recovery point objective✓

NIST SP 800-34 Rev. 1 defines the RPO as the point in time prior to a disruption to which data must be recovered; with nightly backups, up to 24 hours of transactions could be lost against a one-hour RPO. RTO and MTD concern how long the process can be down, and mean time to repair is a maintenance metric.

Security Operations

A server gets a full backup every Sunday and a differential backup every other night. It fails on Thursday morning. Which backups are needed to restore it?

  • a.Only Wednesday night's differential backup
  • b.Sunday's full backup and Wednesday night's differential✓
  • c.Sunday's full backup and every differential since Sunday
  • d.Every backup made in the previous two weeks

NIST SP 800-34 Rev. 1 explains that a differential backup stores all files changed since the last full backup, so a restore needs only the full backup and the most recent differential. Needing every backup since Sunday describes incremental backups, a differential alone lacks the unchanged files, and older backups are unnecessary.

Security Operations

Recovery team members meet in a conference room and talk through their roles in response to a ransomware scenario, without touching any systems. Which exercise type is this under NIST SP 800-34 Rev. 1?

  • a.Live failover drill
  • b.Tabletop exercise✓
  • c.Functional exercise
  • d.Full-scale exercise

SP 800-34 Rev. 1 describes tabletop exercises as discussion-based sessions in which personnel meet to discuss their roles and responses to a scenario. Functional and full-scale exercises have staff actually perform their duties in a simulated operational environment, and a live failover drill moves work onto recovery systems; all three go beyond discussion.

Security Operations

The recovery team restores a critical system at the alternate site from backup media and runs it in a simulated operational environment to confirm staff can perform their duties. Which NIST SP 800-34 Rev. 1 exercise type is this?

  • a.Functional exercise✓
  • b.Plan document review
  • c.Tabletop exercise
  • d.Checklist walkthrough

SP 800-34 Rev. 1 describes functional exercises as letting personnel validate their operational readiness by performing their duties in a simulated operational environment, ranging from specific aspects of a plan to full-scale exercises. Tabletop exercises, document reviews and checklist walkthroughs are discussion or paper-based and do not restore systems.

Security Operations

A trading firm cannot tolerate any meaningful downtime or data loss and has budget for the most capable recovery option. Which site type described in NIST SP 800-34 Rev. 1 fits?

  • a.A warm site with hardware but no current data
  • b.A mobile site delivered within 24 hours
  • c.A cold site with power and cooling ready
  • d.A mirrored site with real-time data mirroring✓

SP 800-34 Rev. 1 describes mirrored sites as fully redundant facilities with automated real-time information mirroring, identical to the primary site, and notes they are the most expensive choice but ensure virtually 100 percent availability. Cold, mobile and warm sites all need time to acquire equipment, deliver the unit or load current data.

Report