01. In a clinic's shared consulting rooms, workstations stay signed in to the records system between appointments. An auditor observes an unattended session showing patient details for several minutes while the room is empty. The workstations are built from a hardened image and are fully patched.
Which change under Control 4, Secure Configuration of Enterprise Assets and Software, addresses the observation?
a) Enforce automatic session locking after a defined period of inactivity, so that an unattended session cannot be used by whoever reaches the machine next
b) Give each clinician a named account so the records system attributes every view to the person who made it
c) Post a notice in each consulting room reminding staff to sign out between appointments
d) Require a second authentication factor when the records system is opened from a shared workstation
02. A security manager has scoped an internal penetration test with an insider starting position on a user network segment. The operations team asks that the tester's source addresses be excluded from intrusion detection alerting for the duration of the engagement, so that the on-call rotation is not paged repeatedly.
Which response best reflects how Control 18, Penetration Testing, is meant to be used?
a) Substitute an authenticated vulnerability scan across the same hosts, which enumerates the exposures without generating alerts for the on-call team.
b) Leave the tester's traffic subject to normal monitoring, because the test also measures whether detection and response actually fire.
c) Launch the test from an external address instead, so that the enterprise's internal sensors take no part in the exercise at any stage of it.
d) Move the engagement into a maintenance window outside business hours, so the alert volume does not reach the on-call rotation during the working day.
03. Malware is detected on a domain controller at 02:00. The on-call engineer has a current response plan with named roles and out-of-hours contact numbers, but spends six hours consulting colleagues about whether the detection amounts to an incident and whether it justifies waking the response lead. Containment begins at 08:30.
Which addition to the response process under Control 17, Incident Response Management, addresses this delay?
a) A weekly review of anti-malware alerts by the security team, so detections on servers are examined promptly
b) A post-incident review after each event, recording what slowed detection and containment
c) An exercise program that puts the on-call engineers through the plan twice a year
d) Documented thresholds that state what counts as an incident and when to escalate
04. A warehouse supervisor notices that a shared terminal is displaying an unfamiliar remote-support window. She mentions it to her line manager the following morning, and he passes it to IT two days after that. The firm's response plan names its handlers and their out-of-hours numbers, but the plan is held in the security team's own folder.
Which requirement of Control 17, Incident Response Management, is not being met?
a) A reporting mechanism published to the whole workforce, stating where to report and how quickly
b) An asset record for the shared terminal, so handlers can establish who owns it and what runs on it
c) A defined authority stating which role may take an affected system offline once a report is received
d) A tested restore procedure for the terminal's image
05. Over three months, every malicious message that reached a user's inbox carried either a macro-enabled office document or a disk image file. The enterprise has no business process that requires either file type to arrive by email. Gateway anti-malware scanning is in place and current, but the samples were new enough that no signature matched.
Which measure under Control 9, Email and Web Browser Protections, addresses this pattern?
a) Deliver targeted awareness training so that recipients recognize macro-enabled attachments and report them promptly.
b) Add a second anti-malware engine at the gateway so more signature sets are applied.
c) Configure endpoint anti-malware to scan the attachments again once they are saved to disk.
d) Block the file types the enterprise has no business need to receive.
06. A consultancy's staff work from client sites, airports and hotels, and regularly join laptops to open wireless networks to send project files. The devices are encrypted and centrally patched, and a VPN client is installed but its use is left to each consultant's judgment.
Which topic must the awareness program cover under Control 14, Security Awareness and Skills Training?
a) How to identify sensitive data and apply the enterprise's classification scheme to it
b) The risks of connecting to and transmitting enterprise data over insecure networks
c) The steps for reporting a lost or stolen device to the service desk within the stated timeframe
d) How attackers construct phishing messages, and how to report one that reaches an inbox
07. The enterprise has completed the sender-authentication work for its own domain and reports that spoofing is addressed. Two weeks later, staff receive messages that claim to come from a supplier's domain and carry a payment-redirection request. The messages are delivered to inboxes.
What does this tell the reviewer about the enterprise's sender authentication work?
a) The enterprise's DMARC policy has been misconfigured, because a policy set to reject should have stopped these messages before delivery.
b) Publishing authentication records for the supplier's domain is part of the enterprise's own configuration and has evidently been missed.
c) The published records protect the enterprise's own domain from being spoofed, while rejecting these messages requires the mail gateway to enforce the sending domain's authentication results.
d) Sender authentication does not address payment fraud at all, so these messages fall outside the scope of the enterprise's email controls.
08. An engineering firm classifies its design files, encrypts them at rest and in transit, and limits the drawings share to the design and bid teams. A departing engineer copied three years of drawings to a personal drive across several evenings. The firm learned of it when a competitor's tender quoted one of the designs.
Which addition under Control 3, Data Protection, addresses the gap this exposed?
a) Tighter role-based permissions on the drawings share, reviewed each quarter so only current bid members retain access
b) Logging access to the sensitive data and monitoring for transfers that do not match normal use
c) A signed acceptable-use agreement covering personal storage
d) Encryption of the drawings with keys held in a separate key management service
09. The enterprise operates a DNS filtering service that all managed devices are expected to use. A review of the resolver logs shows that a third of managed laptops send no queries to that service at all. Those devices have public resolvers configured statically, and their browsers have encrypted DNS enabled.
How should the reviewer report this?
a) Coverage is adequate, since the browsers' encrypted resolution protects those queries from interception.
b) The filtering service has stopped logging queries from a third of the estate, and the reviewer should raise that as a logging defect.
c) Those laptops fall outside the enterprise asset inventory and should be added under Control 1.
d) The filtering control is bypassed on those devices, so resolver settings must be enforced and browser encrypted DNS disabled.
10. After a permanent move to hybrid working, a professional services firm's consultants reach internal file servers and line-of-business applications directly from home networks. Each of those applications authenticates against its own local user database. The laptops are encrypted and centrally patched.
Which change best meets the requirement of Control 12, Network Infrastructure Management?
a) Route remote device connections through the enterprise VPN and authenticate them against central authentication infrastructure
b) Require each of the applications to enforce a common password policy and lockout threshold inside its own local user database
c) Encrypt the file server volumes holding client work product
d) Publish a home working standard that sets out how consultants are to secure their own routers and wireless networks before they connect