TechNuggets Academy

Security Operations

Free ISC2 Certified Information Systems Security Professional (CISSP) practice — 6 questions on Security Operations, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Operations
A security incident responder arrives at a compromised production server that must remain forensically sound. Per the order of volatility, which of the following should be collected FIRST?
The order of volatility dictates collecting the most transient data first. CPU registers and cache contents change or vanish within nanoseconds to seconds and are lost immediately on power-down or process termination, so they must be captured before anything else.
Question 2 of 6 · Security Operations
A financial services firm seizes a laptop suspected of being used in fraud. Two forensic examiners in different offices must independently analyze the drive. Which practice BEST preserves chain of custody integrity?
Chain of custody requires the original evidence to remain untouched and every access/transfer documented. Working from hash-validated copies with a full transfer log preserves integrity while allowing parallel independent analysis.
Question 3 of 6 · Security Operations
A security analyst has deployed UEBA in the SIEM. A user account triggers an alert for downloading an unusually large volume of data at 3 AM, a time and volume never seen for that user before. What most likely triggered this alert?
UEBA (User and Entity Behavior Analytics) builds a statistical baseline of normal behavior per user/entity and flags anomalies — such as atypical time and data volume — that deviate from that learned pattern, rather than relying on known signatures.
Question 4 of 6 · Security Operations
A company's database must not lose more than 15 minutes of data in a disaster (RPO), and operations must resume within 4 hours (RTO). The current strategy is a weekly full backup with nightly differentials. Which change BEST aligns the backup strategy with the stated RPO?
RPO defines the maximum acceptable data loss window. A 15-minute RPO requires near-continuous protection such as synchronous/asynchronous replication or transaction log shipping at sub-15-minute intervals; nightly or twice-daily backups cannot meet this requirement.
Question 5 of 6 · Security Operations
A zero-day vulnerability is being actively exploited against the organization's public-facing systems. The security team has a validated patch and needs to deploy it outside the normal change window. According to CISSP change management best practice, what should occur?
Mature change management processes include a defined emergency change procedure that allows expedited approval and deployment while still requiring documentation, a rollback plan, and retrospective review — balancing urgency with governance and accountability.
Question 6 of 6 · Security Operations
A security team deploys a honeypot designed to attract attackers who are already attempting unauthorized access, without inducing anyone who was not already predisposed to commit the act. This distinguishes the legally permissible practice of ______ from the illegal practice of ______.
Enticement lures an already-motivated attacker into a monitored environment without creating the criminal intent, and is generally legally acceptable. Entrapment induces someone to commit a crime they otherwise would not have committed, which is illegal and can void prosecution.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →