CSS Certified Security Sentinel — Questions and Answers
Question 1: Which attack floods a target server with half-open TCP connections to exhaust its resources?
- Teardrop attack
- Smurf attack
- Ping of death
- SYN flood (Correct answer)
Correct answer: SYN flood
A SYN flood sends massive numbers of TCP SYN packets without completing the handshake, consuming server connection table resources.
Question 2: What is the difference between a vulnerability scan and a penetration test?
- A penetration test is automated; a vulnerability scan requires manual effort
- They are the same process with different names
- A vulnerability scan identifies known weaknesses automatically; a penetration test actively attempts to exploit them (Correct answer)
- Vulnerability scans are more thorough than penetration tests
Correct answer: A vulnerability scan identifies known weaknesses automatically; a penetration test actively attempts to exploit them
Vulnerability scanning uses automated tools to identify potential weaknesses, while penetration testing involves skilled professionals who attempt to exploit those weaknesses to assess real impact.
Question 3: What is the security benefit of using software-defined networking (SDN) in enterprise environments?
- Centralized control plane enables consistent policy enforcement and rapid response to threats (Correct answer)
- Eliminates the need for encryption
- Increases physical hardware costs
- Removes the requirement for firewalls
Correct answer: Centralized control plane enables consistent policy enforcement and rapid response to threats
SDN's centralized control plane allows security policies to be applied uniformly across the network and updated dynamically in response to threats.
Question 4: Which attack targets authentication systems by using previously captured valid authentication tokens?
- Phishing attack
- Password spraying
- Pass-the-ticket / pass-the-hash attack (Correct answer)
- SQL injection
Correct answer: Pass-the-ticket / pass-the-hash attack
Pass-the-hash and pass-the-ticket attacks use stolen authentication tokens to authenticate as a victim without knowing the actual password.
Question 5: Which compliance framework specifically addresses security controls for US federal government cloud deployments?
- PCI DSS
- FedRAMP (Federal Risk and Authorization Management Program) (Correct answer)
- ISO 27001
- HITRUST
Correct answer: FedRAMP (Federal Risk and Authorization Management Program)
FedRAMP provides a standardized security assessment and authorization framework for cloud products and services used by US federal agencies.
Question 6: Which artifact type would BEST help an analyst determine the timeline of an attacker's lateral movement across Windows systems?
- Installed software registry keys
- Windows Event Log 4624 (logon events) (Correct answer)
- Browser history files
- Firewall rule configurations
Correct answer: Windows Event Log 4624 (logon events)
Windows Event ID 4624 records successful logons, making it the primary source for reconstructing lateral movement timelines.
Question 7: Which IAM control helps prevent privilege escalation by ensuring users cannot grant themselves higher permissions than they currently hold?
- Password complexity requirements
- Constrained delegation and permission boundary enforcement (Correct answer)
- Session timeout policies
- Group membership auto-assignment
Correct answer: Constrained delegation and permission boundary enforcement
Constrained delegation and IAM permission boundaries ensure that even if an account is compromised, the attacker cannot escalate to permissions beyond those already assigned.
Question 8: Which cloud service model gives customers the LEAST control over the underlying infrastructure?
- Software as a Service (SaaS) (Correct answer)
- Platform as a Service (PaaS)
- Infrastructure as a Service (IaaS)
- Function as a Service (FaaS)
Correct answer: Software as a Service (SaaS)
In SaaS, the provider manages all infrastructure, middleware, runtime, and application code, leaving customers with control only over their own data and user access settings.
Question 9: What does the 'dwell time' metric measure in the context of threat detection?
- How long a firewall rule has been active
- Time between alert generation and analyst acknowledgment
- Duration between initial compromise and detection of an attacker (Correct answer)
- Time taken to patch a vulnerability after disclosure
Correct answer: Duration between initial compromise and detection of an attacker
Dwell time measures how long an attacker remains undetected in an environment after initial compromise, a key indicator of detection effectiveness.
Question 10: What is end-to-end encryption (E2EE) designed to prevent?
- SQL injection in database systems
- Unauthorized physical access to devices
- Interception and decryption of data by intermediaries, including service providers (Correct answer)
- Privilege escalation on endpoints
Correct answer: Interception and decryption of data by intermediaries, including service providers
E2EE ensures that only the communicating endpoints can decrypt the data, preventing even the service provider from reading message content.
Question 11: What is the role of vulnerability assessments in security risk analysis?
- To improve employee performance.
- To analyze customer satisfaction.
- To identify potential business opportunities.
- To identify and prioritize security weaknesses and vulnerabilities (Correct answer)
Correct answer: To identify and prioritize security weaknesses and vulnerabilities
Vulnerability assessments play a crucial role in security risk analysis by systematically identifying and prioritizing weaknesses within an organization's systems, networks, and applications. These assessments pinpoint specific flaws that could be exploited by threats, such as unpatched software or misconfigurations. By understanding these vulnerabilities, organizations can develop targeted strategies to remediate them and reduce their overall risk exposure.
Question 12: Which vulnerability assessment approach tests systems from outside the network perimeter without credentials, simulating an external attacker's perspective?
- Gray-box hybrid assessment
- Black-box external scan (Correct answer)
- White-box source code review
- Credentialed internal scan
Correct answer: Black-box external scan
A black-box external scan is performed without credentials or insider knowledge, replicating what an unauthenticated external attacker would discover.
Question 13: What is a Cloud Access Security Broker (CASB)?
- A security policy enforcement point between cloud users and cloud services (Correct answer)
- A type of cloud-based firewall specifically for blocking malicious IP ranges
- A hardware device that encrypts cloud traffic at the network edge
- A government certification body for cloud service providers
Correct answer: A security policy enforcement point between cloud users and cloud services
A CASB acts as an intermediary security layer that enforces visibility and policy controls between users and cloud applications.
Question 14: What is an orphaned account and why is it a security risk?
- A shared service account with rotating credentials
- A temporary contractor account with limited privileges
- An account no longer associated with an active user that may be exploited by attackers (Correct answer)
- An account locked after failed login attempts
Correct answer: An account no longer associated with an active user that may be exploited by attackers
Orphaned accounts belong to users who have left the organization but were not properly deprovisioned, creating an entry point for attackers.
Question 15: What is the difference between data masking and data encryption?
- Masking is stronger than encryption
- Masking replaces data with fictitious values while encryption scrambles data reversibly with a key (Correct answer)
- Masking requires a decryption key to reverse
- Encryption permanently destroys data
Correct answer: Masking replaces data with fictitious values while encryption scrambles data reversibly with a key
Data masking permanently replaces sensitive data with realistic but fake values, while encryption scrambles data that can be restored with the correct key.
Question 16: What is the security purpose of just-in-time (JIT) privileged access?
- Provides persistent admin access to all systems
- Requires manual approval for every login attempt
- Grants elevated privileges only for the duration needed, then automatically revokes them (Correct answer)
- Replaces the need for multi-factor authentication
Correct answer: Grants elevated privileges only for the duration needed, then automatically revokes them
JIT access reduces the standing privilege attack surface by provisioning elevated rights only when requested and revoking them immediately after the task is complete.
Question 17: In cloud computing, what does 'data sovereignty' refer to?
- The encryption standard mandated for all cloud-stored data
- A cloud provider's contractual right to access customer data for maintenance
- An organization's ownership rights over data it stores with a cloud provider
- The legal principle that data is subject to the laws of the country where it resides (Correct answer)
Correct answer: The legal principle that data is subject to the laws of the country where it resides
Data sovereignty means data is governed by the laws and regulations of the nation in which it is physically stored, affecting cross-border transfer decisions.
Question 18: Which element is MOST important to include in a security policy to ensure legal enforceability against employees?
- References to specific security frameworks
- A detailed technical appendix
- An acknowledgment signature or consent confirmation (Correct answer)
- A list of all organizational assets
Correct answer: An acknowledgment signature or consent confirmation
Employee acknowledgment creates a documented agreement that the individual has read, understood, and agreed to comply with the policy, which is essential for legal enforcement.
Question 19: What is a primary security advantage of immutable infrastructure in cloud environments?
- It enforces MFA for all users accessing cloud resources
- It prevents all network-based attacks by blocking inbound connections
- It automatically encrypts all data stored on cloud volumes
- It eliminates configuration drift and reduces the attack surface of long-running systems (Correct answer)
Correct answer: It eliminates configuration drift and reduces the attack surface of long-running systems
Immutable infrastructure replaces instances rather than patching them, preventing configuration drift and ensuring every deployment starts from a known-good, consistent state.
Question 20: What does the term 'separation of duties' mean in access control?
- One person performs all privileged operations
- All users share the same administrative account
- No single user has enough access to commit fraud or error without detection from another user (Correct answer)
- Access is separated from authentication
Correct answer: No single user has enough access to commit fraud or error without detection from another user
Separation of duties requires that critical tasks be divided among multiple individuals so no single person can complete a sensitive process unilaterally.
Question 21: From a security perspective, what does a Service Level Agreement (SLA) with a cloud provider typically address?
- The number of certified security staff the provider is required to employ
- The maximum number of concurrent users permitted on the platform
- Guaranteed uptime commitments, incident response timelines, and division of security responsibilities (Correct answer)
- The specific encryption algorithms the provider will use to protect customer data
Correct answer: Guaranteed uptime commitments, incident response timelines, and division of security responsibilities
SLAs establish measurable commitments for availability, incident notification windows, and clarify the boundary of security responsibilities between provider and customer.
Question 22: What does the 'shared responsibility model' in cloud security primarily define?
- A framework for sharing encryption keys between cloud tenants
- The division of security responsibilities between the cloud provider and the customer (Correct answer)
- The process for dividing costs of security tools between teams
- A protocol for sharing security incidents between cloud vendors
Correct answer: The division of security responsibilities between the cloud provider and the customer
The shared responsibility model delineates which security tasks are managed by the cloud provider versus those that remain the customer's obligation.
Question 23: Which security control is MOST effective at preventing unauthorized data exfiltration from a cloud storage service?
- Enabling versioning on all cloud storage buckets
- Requiring all cloud users to complete annual security awareness training
- Implementing data loss prevention (DLP) policies with egress monitoring and blocking (Correct answer)
- Storing all cloud data in an encrypted format using provider-managed keys
Correct answer: Implementing data loss prevention (DLP) policies with egress monitoring and blocking
DLP policies inspect outbound data flows and can block or alert on unauthorized transfers of sensitive information, directly addressing exfiltration risk.
Question 24: Which of the following BEST describes the difference between a vulnerability assessment and a penetration test in the context of risk analysis?
- Vulnerability assessments identify and report weaknesses; penetration tests actively exploit them to demonstrate impact (Correct answer)
- Vulnerability assessments require regulatory approval; penetration tests do not
- Penetration tests are performed more frequently than vulnerability assessments
- Vulnerability assessments are always automated; penetration tests are always manual
Correct answer: Vulnerability assessments identify and report weaknesses; penetration tests actively exploit them to demonstrate impact
Vulnerability assessments enumerate and classify weaknesses, while penetration tests go further by safely exploiting those weaknesses to confirm real-world impact.
Question 25: What type of encryption is used in TLS handshakes to securely exchange session keys?
- Asymmetric encryption (e.g., RSA or ECDH) (Correct answer)
- Homomorphic encryption
- One-time pad encryption
- Symmetric AES encryption
Correct answer: Asymmetric encryption (e.g., RSA or ECDH)
TLS uses asymmetric cryptography during the handshake to securely establish a shared symmetric session key for bulk data encryption.
Question 26: Which approach to policy enforcement uses automated tools to prevent policy violations before they occur?
- Corrective enforcement
- Detective enforcement
- Administrative enforcement
- Preventive enforcement (Correct answer)
Correct answer: Preventive enforcement
Preventive enforcement uses technical controls such as DLP, firewalls, and access controls to block non-compliant actions before they happen.
Question 27: What is a digital signature's primary function in data security?
- Compresses data for transmission
- Encrypts data in transit
- Verifies the authenticity and integrity of a message or document (Correct answer)
- Generates a symmetric session key
Correct answer: Verifies the authenticity and integrity of a message or document
A digital signature uses asymmetric cryptography to prove the message originated from a specific sender and was not altered in transit.
Question 28: During eradication, a team removes malware but fails to identify all persistence mechanisms. Which outcome is MOST likely?
- Reinfection occurs as the attacker re-establishes access via remaining backdoors (Correct answer)
- The incident is considered resolved
- The attacker loses all access permanently
- The attacker pivots to physical intrusion methods
Correct answer: Reinfection occurs as the attacker re-establishes access via remaining backdoors
Incomplete eradication leaves surviving persistence mechanisms that allow the attacker to regain access, effectively restarting the incident.
Question 29: Which US regulatory framework mandates encryption of cardholder data at rest and in transit?
- FISMA
- PCI DSS (Payment Card Industry Data Security Standard) (Correct answer)
- HIPAA Security Rule
- SOX Section 404
Correct answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS Requirement 3 mandates protection of stored cardholder data and Requirement 4 mandates encryption of cardholder data in transit.
Question 30: Which principle best describes 'zero trust' architecture as applied to cloud environments?
- Allowing unrestricted traffic between cloud services within the same account
- Trusting all users and devices connected to the internal corporate network
- Completely delegating all security decisions to the cloud provider
- Never implicitly trusting any user, device, or network segment regardless of location (Correct answer)
Correct answer: Never implicitly trusting any user, device, or network segment regardless of location
Zero trust assumes no entity is inherently trustworthy and requires continuous verification of identity, device health, and authorization for every access request.
Question 31: What is the role of a certificate revocation list (CRL) in PKI?
- Stores encrypted private keys for recovery
- Lists certificates that have been invalidated before their expiration date (Correct answer)
- Lists all valid certificates issued by the CA
- Contains public keys of trusted root CAs
Correct answer: Lists certificates that have been invalidated before their expiration date
A CRL is a signed list published by a Certificate Authority of certificates that have been revoked due to compromise, policy violation, or other reasons.
Question 32: Which cryptographic concept ensures that a party cannot deny having performed an action?
- Confidentiality
- Integrity
- Availability
- Non-repudiation (Correct answer)
Correct answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, provides proof of origin so that a sender cannot later deny sending a message.
Question 33: Which key management practice ensures that encryption keys are protected from the data they encrypt?
- Encoding keys in application source code
- Storing keys in a separate hardware security module (HSM) (Correct answer)
- Sharing keys via unencrypted email
- Storing keys in the same database as encrypted data
Correct answer: Storing keys in a separate hardware security module (HSM)
An HSM is a dedicated hardware device that stores and processes cryptographic keys in a tamper-resistant environment, separate from the data.
Question 34: Why is it important to regularly review and update security policies?
- To reduce the organization’s security measures.
- To avoid following security best practices.
- To focus solely on compliance.
- To ensure policies stay relevant and address new threats (Correct answer)
Correct answer: To ensure policies stay relevant and address new threats
The threat landscape, technologies, and business operations constantly evolve, making regular review and updates of security policies essential. This ensures that policies remain current, address emerging threats and vulnerabilities, and reflect any changes in technology, regulations, or organizational structure. Keeping policies relevant guarantees they continue to provide effective protection for organizational assets.
Question 35: During the containment phase of incident response, which strategy isolates a compromised host while preserving its network traffic data for forensic analysis?
- Disable the user account only
- Shutdown the host immediately
- Network-based containment using ACLs or VLAN isolation (Correct answer)
- Wipe and reimage the host
Correct answer: Network-based containment using ACLs or VLAN isolation
Network-based containment via ACLs or VLAN isolation limits the attacker's lateral movement while keeping the host running for forensic evidence capture.
Question 36: What is credential stuffing and how does it differ from brute-force attacks?
- Credential stuffing is slower than brute force
- Brute force uses breached credentials; credential stuffing generates random passwords
- Both attacks use the same technique
- Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations (Correct answer)
Correct answer: Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations
Credential stuffing relies on real credentials from previous data breaches, making it more effective than random brute-force guessing.
Question 37: What is the purpose of a privileged access workstation (PAW)?
- A remote desktop server for multiple users
- A hardened, dedicated workstation used exclusively for privileged administrative tasks (Correct answer)
- A virtual machine for testing malware
- A shared workstation for general office use
Correct answer: A hardened, dedicated workstation used exclusively for privileged administrative tasks
A PAW is a dedicated, highly secured device used only for admin tasks, reducing exposure to phishing and malware that could compromise privileged credentials.
Question 38: What security vulnerability is MOST associated with serverless (Function as a Service) architectures?
- Event-data injection attacks via malicious data passed through function triggers (Correct answer)
- Unauthorized physical access to the servers running the functions
- Complete loss of network connectivity due to ephemeral compute nodes
- Inability to apply encryption to data processed by serverless functions
Correct answer: Event-data injection attacks via malicious data passed through function triggers
Serverless functions are triggered by events that can carry attacker-controlled data, making input validation against injection attacks a critical security concern.
Question 39: Why is containment important in incident response?
- To focus only on internal communication.
- To prevent the incident from spreading and minimize damage (Correct answer)
- To ignore the incident.
- To allow the incident to affect more areas.
Correct answer: To prevent the incident from spreading and minimize damage
Containment is a critical phase in incident response that aims to isolate the affected systems, networks, or data to prevent further damage or the spread of the attack. By containing the incident, organizations can limit its impact, preserve forensic evidence, and create a controlled environment for subsequent eradication and recovery efforts. This minimizes the overall harm caused by the security breach.
Question 40: What is behavioral analytics in the context of IAM security?
- Tracks network bandwidth usage per user
- Analyzes code for security vulnerabilities
- Uses baseline behavior patterns to detect anomalous user activity that may indicate account compromise (Correct answer)
- Monitors physical access logs only
Correct answer: Uses baseline behavior patterns to detect anomalous user activity that may indicate account compromise
User and entity behavior analytics (UEBA) establishes baselines of normal activity and flags deviations such as unusual login times, locations, or data access patterns.
Question 41: Which protocol is widely used for enterprise federated authentication and SSO?
- FTP
- SAML (Security Assertion Markup Language) (Correct answer)
- Kerberos only
- RADIUS only
Correct answer: SAML (Security Assertion Markup Language)
SAML is an XML-based open standard for exchanging authentication and authorization data between identity providers and service providers.
Question 42: An IR team discovers that an attacker maintained persistence via a scheduled task. Which recovery step should be performed FIRST?
- Patch the vulnerability used for initial access
- Remove the malicious scheduled task (Correct answer)
- Notify law enforcement
- Restore from backup
Correct answer: Remove the malicious scheduled task
Removing the persistence mechanism first ensures the attacker cannot regain access before other remediation steps are completed.
Question 43: What is the primary purpose of a Business Impact Analysis (BIA) in the context of risk assessment?
- To determine the financial and operational effects of disruption to critical business functions (Correct answer)
- To assign risk ratings to each identified threat
- To document the results of penetration testing exercises
- To enumerate all existing vulnerabilities in IT systems
Correct answer: To determine the financial and operational effects of disruption to critical business functions
A BIA identifies critical business functions and quantifies the impact—financial, reputational, and operational—if those functions were disrupted.
Question 44: Which technique does a next-generation firewall (NGFW) use that a traditional stateful firewall does NOT?
- IP address-based access control lists
- TCP three-way handshake tracking
- Application-layer deep packet inspection and user identity awareness (Correct answer)
- Packet header inspection
Correct answer: Application-layer deep packet inspection and user identity awareness
NGFWs add application-layer (Layer 7) inspection and can enforce policies based on application type and user identity, beyond what stateful firewalls provide.
Question 45: What is the principle of least privilege in identity and access management?
- Users are granted only the minimum permissions necessary to perform their job functions (Correct answer)
- Privileged accounts are never used for daily tasks
- Access is granted by default and revoked when abused
- All users share a common administrator account
Correct answer: Users are granted only the minimum permissions necessary to perform their job functions
Least privilege limits the blast radius of a compromised account by ensuring users can only access what they need for their specific role.
Question 46: Which network anomaly detection approach establishes normal traffic patterns first and then alerts on deviations?
- Hash-based file integrity monitoring
- Heuristic rule matching
- Baseline behavioral analytics (Correct answer)
- Signature-based detection
Correct answer: Baseline behavioral analytics
Baseline behavioral analytics profiles normal activity over time and generates alerts when observed behavior significantly deviates from the established baseline.
Question 47: An IR analyst needs to capture volatile memory from a live compromised system. Which tool is BEST suited for this task?
- Autopsy for file analysis
- Wireshark for packet capture
- FTK Imager (disk imaging)
- Winpmem or DumpIt for memory acquisition (Correct answer)
Correct answer: Winpmem or DumpIt for memory acquisition
Winpmem and DumpIt are purpose-built for acquiring physical memory from live Windows systems without disrupting running processes.
Question 48: What is the primary advantage of asymmetric encryption over symmetric encryption?
- It eliminates the need to securely share a secret key between parties (Correct answer)
- It is faster than symmetric encryption
- It uses shorter key lengths for equivalent security
- It requires less computational power
Correct answer: It eliminates the need to securely share a secret key between parties
Asymmetric encryption uses a public/private key pair, so parties can exchange encrypted data without first sharing a secret key.
Question 49: Why is it important to assess both internal and external risks in a security risk assessment?
- Because only external risks matter.
- Because both internal and external risks contribute to overall security (Correct answer)
- Because internal risks are easily controlled.
- Because external risks are less important.
Correct answer: Because both internal and external risks contribute to overall security
A comprehensive security risk assessment must consider both internal and external risks because both can significantly impact an organization's security posture. Internal risks often stem from employees, processes, or systems within the organization, while external risks originate from outside sources like cyber attackers or natural disasters. Addressing both categories provides a holistic view and ensures robust protection against a wider range of potential threats.
Question 50: What is the key security benefit of cloud-native security tools compared to third-party alternatives?
- They are always less expensive than equivalent third-party solutions
- They offer deeper integration with provider APIs and native telemetry for broader visibility (Correct answer)
- They require zero configuration or tuning by security teams after deployment
- They completely replace the need for identity and access management controls
Correct answer: They offer deeper integration with provider APIs and native telemetry for broader visibility
Cloud-native security tools leverage deep API integration and platform telemetry that third-party tools cannot always access, enabling more comprehensive detection and automated response.
Question 51: What is the first step in conducting a security risk assessment?
- Evaluating the financial implications.
- Identifying critical assets.
- Identifying potential threats and vulnerabilities (Correct answer)
- Designing a security system.
Correct answer: Identifying potential threats and vulnerabilities
The foundational first step in any security risk assessment is to identify potential threats and vulnerabilities. Threats represent potential harm, while vulnerabilities are weaknesses that threats could exploit. Understanding these elements is crucial because it lays the groundwork for evaluating risks and developing effective mitigation strategies.
Question 52: Which IAM concept involves automatically removing access rights when they are no longer needed?
- Access certification and deprovisioning (Correct answer)
- Credential harvesting
- Role explosion
- User self-service enrollment
Correct answer: Access certification and deprovisioning
Regular access reviews (certifications) and automated deprovisioning ensure that users who change roles or leave the organization do not retain unnecessary access.
Question 53: An attacker compromised a build server and inserted malicious code into a software release. Which type of incident does this represent?
- Denial-of-service attack
- Credential stuffing incident
- Supply chain attack (Correct answer)
- Insider threat incident
Correct answer: Supply chain attack
Compromising a build server to inject malicious code into software releases is a textbook supply chain attack targeting downstream users.
Question 54: What is the role of a data protection officer (DPO) as required by GDPR?
- Oversees data protection strategy, ensures GDPR compliance, and serves as the contact point for supervisory authorities (Correct answer)
- Approves all software purchases
- Conducts annual penetration tests
- Manages all cybersecurity operations
Correct answer: Oversees data protection strategy, ensures GDPR compliance, and serves as the contact point for supervisory authorities
GDPR requires certain organizations to appoint a DPO who independently oversees compliance with data protection laws and advises on data processing activities.
Question 55: Which standard is used to automate the provisioning and deprovisioning of user accounts across systems?
- SCIM (System for Cross-domain Identity Management) (Correct answer)
- OAuth 2.0
- X.509
- LDAP only
Correct answer: SCIM (System for Cross-domain Identity Management)
SCIM is an open API standard that automates user lifecycle management, enabling systems to create, update, and delete accounts automatically across identity providers and applications.
Question 56: What is Infrastructure as Code (IaC) security scanning?
- Encrypting all infrastructure configuration files stored in version control
- Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment (Correct answer)
- Reviewing the physical configurations of cloud data center servers for vulnerabilities
- Scanning cloud network traffic for malicious executable code
Correct answer: Analyzing IaC templates such as Terraform or CloudFormation for misconfigurations before deployment
IaC security scanning detects security misconfigurations in infrastructure templates before they are deployed, enabling shift-left security and preventing issues from reaching production.
Question 57: What does FedRAMP primarily govern?
- Security requirements for cloud services used by U.S. federal government agencies (Correct answer)
- International cloud data transfer agreements between allied nations
- Healthcare data protection standards for cloud-hosted patient records
- Financial data security requirements for cloud-based payment processors
Correct answer: Security requirements for cloud services used by U.S. federal government agencies
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services procured by U.S. federal agencies.
Question 58: During a policy review cycle, a security manager discovers that a control in the data classification policy conflicts with a recently enacted state privacy law. What is the FIRST action to take?
- Immediately suspend the conflicting policy control
- Notify legal counsel and initiate a formal policy exception
- Update the policy to align with the law after management approval (Correct answer)
- Continue using the existing policy until the next scheduled review
Correct answer: Update the policy to align with the law after management approval
Regulatory requirements supersede internal policy, so the policy must be updated through the formal change process to achieve legal compliance.
Question 59: What is the difference between authentication and authorization in IAM?
- Authentication verifies identity; authorization determines what an authenticated identity is permitted to do (Correct answer)
- Authorization verifies identity; authentication assigns permissions
- Authentication assigns roles; authorization validates passwords
- They are the same process
Correct answer: Authentication verifies identity; authorization determines what an authenticated identity is permitted to do
Authentication confirms who you are, while authorization determines what resources and actions you are permitted to access once your identity is confirmed.
Question 60: Which standard provides guidance specifically on information security risk management processes and is part of the ISO/IEC 27000 family?
- ISO/IEC 27001
- ISO/IEC 27035
- ISO/IEC 27017
- ISO/IEC 27005 (Correct answer)
Correct answer: ISO/IEC 27005
ISO/IEC 27005 provides guidelines for information security risk management, supporting the implementation of an ISMS as defined in ISO/IEC 27001.
Question 61: Which encryption mode of AES is considered most secure for bulk data encryption due to its use of an initialization vector and chaining?
- DES-CBC
- AES-CBC (Cipher Block Chaining) (Correct answer)
- AES-ECB (Electronic Codebook)
- AES-OFB without IV
Correct answer: AES-CBC (Cipher Block Chaining)
AES-CBC uses an initialization vector and chains each block to the previous ciphertext, preventing identical plaintext blocks from producing identical ciphertext.
Question 62: Which control best addresses the risk of a cloud provider outage disrupting business operations?
- Storing all disaster recovery backups on the same cloud provider
- Disabling automatic updates in the cloud environment to prevent change-related outages
- Reducing the total number of cloud services the organization uses
- Implementing multi-cloud or hybrid cloud redundancy strategies (Correct answer)
Correct answer: Implementing multi-cloud or hybrid cloud redundancy strategies
Distributing workloads across multiple cloud providers or a hybrid environment eliminates single-provider dependency and improves resilience against outages.
Question 63: What does tokenization do to protect sensitive data such as payment card numbers?
- Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault (Correct answer)
- Encrypts data using AES-256
- Compresses data to reduce storage size
- Hashes the data irreversibly
Correct answer: Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault
Tokenization substitutes sensitive data with a random token; the original value is stored in a secure token vault and can only be retrieved by authorized systems.
Question 64: Which concept describes the practice of ensuring that security policies align with and support the organization's overall business objectives?
- Security governance (Correct answer)
- Vulnerability management
- Risk appetite
- Defense in depth
Correct answer: Security governance
Security governance ensures that security policies, processes, and resources are aligned with business strategy and organizational objectives.
Question 65: During incident triage, an analyst finds an outbound connection to an IP on a threat intelligence blacklist. Before blocking, what should the analyst verify?
- Whether the endpoint's antivirus definitions are current
- Whether the firewall vendor has released a new rule set
- Whether the IP could be a shared hosting or CDN address used by legitimate services (Correct answer)
- Whether the connecting user has admin privileges
Correct answer: Whether the IP could be a shared hosting or CDN address used by legitimate services
Blacklisted IPs are sometimes shared infrastructure used by both malicious and legitimate services, so blindly blocking can cause unintended outages.
Question 66: Why is it important to conduct a post-incident review?
- To delay future incident responses.
- To increase organizational risks.
- To assess what went wrong and improve future responses (Correct answer)
- To ignore lessons learned.
Correct answer: To assess what went wrong and improve future responses
A post-incident review, often called a 'lessons learned' session, is essential for analyzing the entire incident response process after an event has been resolved. It helps identify the root cause of the incident, evaluate the effectiveness of the response actions taken, and pinpoint areas for improvement in policies, procedures, and technologies. This continuous improvement cycle enhances an organization's future incident response capabilities and overall security posture.
Question 67: What is the purpose of a Public Key Infrastructure (PKI) in enterprise environments?
- Stores plaintext passwords securely
- Monitors endpoint behavior
- Provides network access control
- Manages the lifecycle of digital certificates to enable trusted encrypted communications (Correct answer)
Correct answer: Manages the lifecycle of digital certificates to enable trusted encrypted communications
PKI provides the framework for issuing, managing, distributing, and revoking digital certificates used for authentication and encryption.
Question 68: An organization's password policy mandates a minimum 12-character length. A system cannot enforce this requirement due to a technical limitation. What control type should be applied?
- Corrective control
- Compensating control (Correct answer)
- Detective control
- Preventive control
Correct answer: Compensating control
A compensating control is used when the primary required control cannot be implemented, providing an alternative means of meeting the security objective.
Question 69: What is the primary purpose of Cloud Security Posture Management (CSPM)?
- To continuously assess cloud configurations for compliance gaps and security risks (Correct answer)
- To manage user password policies across cloud-based SaaS applications
- To back up cloud data to on-premises storage systems
- To monitor and optimize cloud network bandwidth usage
Correct answer: To continuously assess cloud configurations for compliance gaps and security risks
CSPM tools automatically and continuously evaluate cloud infrastructure configurations to surface misconfigurations, compliance violations, and security risks.
Question 70: Which data protection technique allows computations to be performed on encrypted data without decrypting it first?
- Homomorphic encryption (Correct answer)
- Data masking
- Symmetric encryption
- Tokenization
Correct answer: Homomorphic encryption
Homomorphic encryption allows mathematical operations to be performed on ciphertext such that the result, when decrypted, matches the result of operations on the plaintext.
Question 71: Which framework was specifically designed to address cloud computing security controls?
- PCI-DSS v4.0
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- NIST SP 800-53
- HIPAA Security Rule
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix is a cybersecurity control framework developed by the Cloud Security Alliance specifically for cloud computing environments.
Question 72: What is the primary purpose of a bug bounty program?
- Automates vulnerability scanning of web applications
- Incentivizes security researchers to responsibly disclose vulnerabilities in exchange for rewards (Correct answer)
- Hires full-time security testers as employees
- Pays attackers to stop ongoing intrusions
Correct answer: Incentivizes security researchers to responsibly disclose vulnerabilities in exchange for rewards
Bug bounty programs leverage the broader security research community to identify vulnerabilities that internal teams might miss, creating a responsible disclosure channel.
Question 73: Which access control model grants permissions based on a user's job role rather than individual identity?
- Attribute-Based Access Control (ABAC)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC) (Correct answer)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles, and users are granted access by being assigned to appropriate roles, simplifying administration at scale.
Question 74: What does single sign-on (SSO) provide to enterprise users?
- A single password shared across all users
- Access to multiple applications using one set of credentials authenticated once (Correct answer)
- Elimination of all password requirements
- Automatic privilege escalation for all users
Correct answer: Access to multiple applications using one set of credentials authenticated once
SSO allows users to authenticate once with an identity provider and gain access to multiple connected applications without re-entering credentials.
Question 75: What is the significance of risk assessments in security policy development?
- To delay security policy enforcement.
- To avoid identifying threats.
- To ignore the severity of threats.
- To identify and prioritize risks in security policy development (Correct answer)
Correct answer: To identify and prioritize risks in security policy development
Risk assessments are foundational to security policy development as they help identify potential threats, vulnerabilities, and their potential impact on organizational assets. This process allows organizations to prioritize which risks to address, enabling the creation of policies that are tailored, effective, and allocate resources appropriately to mitigate the most significant threats. Policies are then built upon a clear understanding of the risks involved.
Question 76: What does multi-factor authentication (MFA) require beyond a username and password?
- A second username and password combination
- An additional security question only
- At least one additional verification factor such as a token, biometric, or push notification (Correct answer)
- A hardware firewall device
Correct answer: At least one additional verification factor such as a token, biometric, or push notification
MFA combines something you know (password) with something you have (token) or something you are (biometric) to reduce account takeover risk.
Question 77: What is the primary purpose of key escrow in enterprise cryptography?
- Distributes encryption keys to all users automatically
- Speeds up encryption operations
- Prevents law enforcement from accessing data
- Allows authorized parties to recover encrypted data if the original key is lost (Correct answer)
Correct answer: Allows authorized parties to recover encrypted data if the original key is lost
Key escrow stores a copy of encryption keys with a trusted third party, enabling data recovery in case of key loss or employee departure.
Question 78: Which hashing algorithm is currently recommended by NIST for secure cryptographic applications?
- SHA-1
- MD5
- SHA-256 (Correct answer)
- CRC32
Correct answer: SHA-256
SHA-256 (part of the SHA-2 family) is NIST-recommended for cryptographic use, as MD5 and SHA-1 are vulnerable to collision attacks.
Question 79: What is the primary function of a privileged access management (PAM) solution?
- Encrypts all database records
- Manages network firewall rules
- Provides antivirus protection for servers
- Securely manages, monitors, and audits access to privileged accounts and credentials (Correct answer)
Correct answer: Securely manages, monitors, and audits access to privileged accounts and credentials
PAM solutions vault privileged credentials, enforce access workflows, and record privileged sessions to prevent misuse and support forensic investigation.
Question 80: A security analyst calculates that a server has a 25% chance of being compromised each year with an asset value of $200,000 and an exposure factor of 40%. What is the Annual Loss Expectancy (ALE)?
- $80,000
- $50,000
- $200,000
- $20,000 (Correct answer)
Correct answer: $20,000
ALE = SLE Ă— ARO; SLE = $200,000 Ă— 40% = $80,000; ALE = $80,000 Ă— 0.25 = $20,000.
Question 81: What is the main vulnerability addressed by salting a password hash?
- Prevents brute-force attacks entirely
- Replaces the need for password complexity requirements
- Prevents rainbow table and precomputed hash lookup attacks (Correct answer)
- Speeds up authentication
Correct answer: Prevents rainbow table and precomputed hash lookup attacks
A salt is a random value added to a password before hashing, ensuring that identical passwords produce different hashes and defeating precomputed lookup tables.
Question 82: A new remote work policy requires VPN use for all corporate data access. An employee working from a hotel reports the VPN is blocked. Which is the MOST appropriate immediate response?
- Have the employee defer work until VPN access is restored or provide a compliant alternative (Correct answer)
- Advise the employee to use personal hotspot and proceed without VPN
- Allow the employee to access data without VPN for the duration of the trip
- Ask IT to create a temporary VPN bypass for the employee
Correct answer: Have the employee defer work until VPN access is restored or provide a compliant alternative
Maintaining policy integrity requires either restoring compliant access or deferring work, rather than accepting an uncontrolled risk.
Question 83: Which cloud deployment model provides an organization with the highest level of control over its infrastructure?
- Private cloud (Correct answer)
- Hybrid cloud
- Community cloud
- Public cloud
Correct answer: Private cloud
A private cloud is dedicated exclusively to one organization, granting the greatest control over security configurations and infrastructure.
Question 84: What is a key security consideration when cloud services process data belonging to EU citizens?
- The data must be stored exclusively on U.S.-based servers to meet export controls
- GDPR compliance requirements including data subject rights and cross-border transfer restrictions (Correct answer)
- The data must be encrypted using only EU government-approved cryptographic algorithms
- Cloud providers must obtain annual security certification directly from the European Commission
Correct answer: GDPR compliance requirements including data subject rights and cross-border transfer restrictions
GDPR imposes obligations on any organization handling EU citizen data, including honoring data subject rights and restricting transfers of that data outside the European Economic Area.
Question 85: Which log source is MOST valuable for detecting pass-the-hash attacks in a Windows Active Directory environment?
- Network flow records from core routers
- Windows Security Event logs (Event IDs 4624, 4625, 4648) (Correct answer)
- Web server access logs
- DNS query logs from the recursive resolver
Correct answer: Windows Security Event logs (Event IDs 4624, 4625, 4648)
Windows Security Event logs capture authentication events including logon type 3 with NTLM, which is characteristic of pass-the-hash lateral movement.
Question 86: Which security concern is MOST unique to multi-tenant cloud environments?
- Antivirus software management across endpoints
- Data isolation and tenant separation failures (Correct answer)
- Password complexity and rotation requirements
- Phishing attacks targeting end users
Correct answer: Data isolation and tenant separation failures
Multi-tenancy creates the risk of data leaking between co-located tenants, making proper logical isolation the defining security concern.
Question 87: What is the recommended approach for managing privileged access in cloud environments?
- Using shared administrator accounts to improve operational efficiency
- Implementing just-in-time (JIT) access with least privilege principles (Correct answer)
- Storing privileged credentials directly in application environment variables
- Granting all administrators full access to simplify permissions management
Correct answer: Implementing just-in-time (JIT) access with least privilege principles
JIT access grants elevated permissions only when operationally required and for a limited duration, minimizing the attack surface while adhering to least privilege.
Question 88: What is a federated identity in the context of IAM?
- An identity that is trusted and shared across multiple organizations or systems using a common standard (Correct answer)
- A local account synchronized to Active Directory only
- An identity that requires manual admin approval
- A temporary guest account with limited access
Correct answer: An identity that is trusted and shared across multiple organizations or systems using a common standard
Federated identity allows users to authenticate with one organization's identity provider and access resources at a partner organization without creating separate accounts.
Question 89: What is the security risk of using weak or short RSA key lengths (e.g., 512-bit) in production systems?
- They are not compatible with TLS 1.3
- They consume excessive server memory
- They can be factored using modern computing power, allowing private key recovery (Correct answer)
- They cannot be used with digital signatures
Correct answer: They can be factored using modern computing power, allowing private key recovery
Short RSA keys can be broken through integer factorization attacks; NIST recommends at least 2048-bit keys for current applications.
Question 90: Which risk assessment methodology uses probability and impact ratings to produce a numerical risk score?
- Residual risk assessment
- Semi-quantitative risk assessment
- Quantitative risk assessment (Correct answer)
- Qualitative risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical values to probability and impact to calculate a numeric risk score such as Annual Loss Expectancy (ALE).
Question 91: Which chain-of-custody principle is MOST critical when handling digital evidence collected during an incident?
- Documenting every person who accessed the evidence (Correct answer)
- Compressing evidence files to save storage space
- Ensuring evidence is encrypted at rest
- Storing evidence on isolated network drives
Correct answer: Documenting every person who accessed the evidence
Chain of custody requires a complete, unbroken record of everyone who accessed the evidence to ensure its integrity and admissibility.
Question 92: An IR team is responding to a breach where the attacker exfiltrated data over HTTPS to an external server. Which log source would BEST help confirm this exfiltration?
- Active Directory Group Policy logs
- Windows Application Event Logs
- DHCP server lease logs
- Firewall or proxy logs showing large outbound HTTPS transfers to unknown IPs (Correct answer)
Correct answer: Firewall or proxy logs showing large outbound HTTPS transfers to unknown IPs
Firewall and proxy logs capture outbound connection details including destination IPs, data volumes, and protocols, making them ideal for detecting HTTPS-based exfiltration.
Question 93: During incident recovery, what is 'reconstitution' and when does it occur?
- Reconstitution is restoring systems to full operational status; it occurs after eradication is confirmed (Correct answer)
- Reconstitution is creating forensic images; it occurs during containment
- Reconstitution is notifying regulators; it occurs at incident discovery
- Reconstitution is identifying the root cause; it occurs during analysis
Correct answer: Reconstitution is restoring systems to full operational status; it occurs after eradication is confirmed
Reconstitution involves rebuilding and restoring affected systems to normal operations and is performed only after all threats have been confirmed as removed.
Question 94: Which encryption protocol version is considered best practice for protecting data in transit within cloud environments?
- Symmetric AES-128 with a shared key distributed to all service accounts
- MD5-based HMAC for lightweight authentication of cloud API calls
- SSL 3.0 for maximum compatibility with legacy systems
- TLS 1.2 or higher for all cloud communications (Correct answer)
Correct answer: TLS 1.2 or higher for all cloud communications
TLS 1.2 and TLS 1.3 are the current industry standards for securing data in transit; earlier versions contain known vulnerabilities and should not be used.
Question 95: Why is it important to align security policies with organizational goals?
- To ensure security measures are relevant and effective (Correct answer)
- To limit the scope of security policies.
- To avoid addressing security risks.
- To increase complexity of operations.
Correct answer: To ensure security measures are relevant and effective
Aligning security policies with organizational goals ensures that security measures directly support business objectives and risk tolerance. This prevents security from becoming a hindrance and instead makes it an enabler of business operations. When policies are aligned, they are more likely to be relevant, practical, and effectively contribute to the overall success and resilience of the organization.
Question 96: A security team implements egress filtering on the perimeter firewall. Which threat does this PRIMARILY help prevent?
- Unauthorized outbound data exfiltration and C2 communications from compromised internal hosts (Correct answer)
- Brute force attacks against internet-facing login portals
- Exploitation of unpatched vulnerabilities in web servers
- Inbound phishing emails reaching users
Correct answer: Unauthorized outbound data exfiltration and C2 communications from compromised internal hosts
Egress filtering controls outbound traffic, limiting what compromised internal systems can communicate with externally, which disrupts exfiltration and C2 channels.
Question 97: What is the significance of a 'right to audit' clause in a cloud service contract?
- It requires independent third-party auditors to review all cloud financial transactions quarterly
- It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture (Correct answer)
- It authorizes cloud providers to audit customer security practices and charge for findings
- It mandates government regulatory agencies to conduct annual audits of the cloud provider
Correct answer: It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture
A right-to-audit clause allows the customer to independently verify that the cloud provider's security controls and compliance posture meet contractual and regulatory obligations.
Question 98: What is the primary security concern with unmanaged or shadow IT assets in vulnerability management?
- They always contain critical vulnerabilities
- They automatically bypass firewall rules
- They are unknown to security teams and therefore not included in scanning, patching, or monitoring programs (Correct answer)
- They are too expensive to decommission
Correct answer: They are unknown to security teams and therefore not included in scanning, patching, or monitoring programs
Shadow IT assets — systems deployed without IT or security knowledge — create blind spots in vulnerability management programs, leaving them unpatched and unmonitored.
Question 99: Which term describes the risk that remains after all planned security controls have been implemented?
- Residual risk (Correct answer)
- Inherent risk
- Secondary risk
- Transferred risk
Correct answer: Residual risk
Residual risk is the level of risk that persists after an organization has applied its security controls and mitigation measures.
Question 100: What does 'perfect forward secrecy' (PFS) ensure in TLS connections?
- All traffic is encrypted with the same session key indefinitely
- Compromise of the server's private key does not expose past session keys (Correct answer)
- Sessions are never terminated by the server
- Certificates are automatically renewed before expiry
Correct answer: Compromise of the server's private key does not expose past session keys
PFS uses ephemeral key exchanges (like Diffie-Hellman) so each session generates a unique key that is discarded afterward, protecting past sessions.
CSS Certified Security Sentinel
The Certified Security Sentinel (CSS) is a vendor-neutral, entry-level cybersecurity certification by Mile2 that validates foundational knowledge in network security, data protection, identity management, cloud security, cryptography, and regulatory compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds