Which statement best reflects the security professional's obligation when a client instructs them to omit a material finding?
Professional ethics require honest reporting through the agreed escalation route, which protects both the public interest and the professional. A allows suppression of material findings. C breaches confidentiality and bypasses the agreed path. D leaves the finding unrecorded.
Question 2 of 10 · Asset Security
An organisation is retiring a database that held customer records under a seven-year retention obligation that has now expired.
What is the most important step before the storage is reused?
**Rationale:** Retention expiry does not override a legal hold, so the hold check comes first. Sanitisation must then match the data classification, not the convenience of the operations team. **Distractors:** A is required but does not protect the data. C retains the data rather than disposing of it, and creates a key-management obligation. D leaves recoverable data on most media.
Question 3 of 10 · Security Architecture and Engineering
Which best describes the reference monitor concept?
The reference monitor is the concept; the security kernel is its implementation, and the three properties define it. A describes auditing. C is one enforcement mechanism. D is broader than the security kernel.
Question 4 of 10 · Communication and Network Security
Which best describes zero trust network access compared with a traditional VPN?
Access is per application and continuously evaluated, which limits what a compromised device can reach. A is not the distinction. C is the opposite. D is untrue.
Question 5 of 10 · Identity and Access Management
An organisation implements just-in-time elevation. What additional control makes it effective for accountability?
Elevation limits exposure; recording and approval records provide the attribution and review evidence. A weakens the control. C removes attribution from the approval. D removes the control's purpose.
Question 6 of 10 · Security Assessment and Testing
What are complementary user entity controls?
If the customer does not operate them, the supplier's opinion does not carry for the customer's environment. A describes the report's scope. C understates their necessity. D describes subservice arrangements.
Question 7 of 10 · Security Operations
What distinguishes an intrusion prevention system from an intrusion detection system?
Being inline gives the ability to block and introduces availability risk from false positives. A, C and D describe variations rather than the defining difference.
Question 8 of 10 · Software Development Security
Which defence addresses SQL injection at its root cause?
Parameterisation removes the conditions in which input can be interpreted as code. A is error-prone and incomplete. C is a compensating control. D limits impact rather than preventing injection.
Question 9 of 10 · Security and Risk Management
An organisation wishes to demonstrate that its security programme adds business value.
Which measure best supports that?
It connects security work to a business outcome the organisation already measures, which is what value demonstration requires. A, B and D measure activity or detection volume, none of which translates directly into business value.
Question 10 of 10 · Asset Security
A department head asks the storage team to label a shared folder as confidential. The data inside came from the finance system.
Who decides the classification?
**Rationale:** Classification is an owner decision, based on the value and sensitivity of the data to the business. Custodians implement and protect the data at the level the owner sets. **Distractors:** A confuses custodian with owner. B is a request, not authority over data the department did not originate. D writes the scheme and advises, but does not own the data. ---
0 of 10
Security and Risk Management
Asset Security
Security Architecture and Engineering
Communication and Network Security
Identity and Access Management
Security Assessment and Testing
Security Operations
Software Development Security
Which domains cost you the points? Members see a breakdown by domain and a study plan built from it.