A hospital's electronic health record (EHR) system must ensure that only
authorized clinicians can view patient records, but emergency room staff need
immediate access during life-threatening situations. Which access control
model best balances these requirements while adhering to the principle of least
privilege?
A. Mandatory Access Control (MAC) with strict sensitivity labels
B. Role-Based Access Control (RBAC) with break-the-glass emergency
override
C. Discretionary Access Control (DAC) where record owners set
permissions
D. Rule-Based Access Control (RuBAC) with static time-of-day
restrictions
Correct Answer: B - Role-Based Access Control (RBAC) with
break-the-glass emergency override
RATIONALE
RBAC assigns permissions based on roles (e.g., clinician, ER staff)
and supports emergency override ('break-the-glass') to grant temporary
access when needed, aligning with least privilege and availability.
MAC is too rigid for emergency access; DAC lacks centralized
control; RuBAC with static rules cannot adapt to emergencies.
Question 2
A security analyst is evaluating a new encryption scheme for protecting data at
rest. The scheme uses a single secret key for both encryption and decryption,
and the key must be shared securely between parties. Which cryptographic
approach is being described, and what is its primary limitation?
A. Asymmetric encryption; key distribution is easy but slow.
B. Symmetric encryption; key distribution is challenging.
C. Hashing; it is one-way and cannot decrypt.
Page 2
, D. Digital signature; it ensures non-repudiation but not confidentiality.
Correct Answer: B - Symmetric encryption; key distribution is
challenging.
RATIONALE
Symmetric encryption uses the same key for encryption and
decryption, making secure key distribution a major challenge.
Asymmetric encryption uses key pairs, hashing is one-way, and digital
signatures provide integrity and non-repudiation, not confidentiality.
Question 3
During a risk assessment, a company identifies a vulnerability in its web server
that could allow remote code execution. The likelihood of exploitation is high,
and the impact would be severe. Which risk response strategy involves
purchasing cyber insurance to transfer the financial impact?
A. Risk avoidance
B. Risk mitigation
C. Risk transference
D. Risk acceptance
Correct Answer: C - Risk transference
RATIONALE
Risk transference shifts the financial impact of a risk to a third party,
such as an insurance company. Avoidance eliminates the activity,
mitigation reduces likelihood or impact, and acceptance retains the
risk.
Question 4
A network administrator is configuring a firewall to allow only HTTP and
HTTPS traffic to a web server while blocking all other inbound traffic. Which
type of firewall rule is most appropriate?
Page 3
, A. Default deny with explicit allow rules for ports 80 and 443
B. Default allow with explicit deny rules for all other ports
C. Stateful inspection with no explicit rules
D. Application layer gateway with deep packet inspection
Correct Answer: A - Default deny with explicit allow rules for
ports 80 and 443
RATIONALE
A default deny posture with explicit allow rules for necessary services
(HTTP/HTTPS) follows the principle of least privilege and is a best
practice. Default allow is insecure, stateful inspection without rules is
ineffective, and application layer gateways add overhead but do not
replace basic rule sets.
Question 5
An organization implements a security awareness program that includes
simulated phishing campaigns. After the campaign, the number of employees
clicking on phishing links decreased significantly. Which security principle is
primarily being reinforced?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Human factor security
Correct Answer: D - Human factor security
RATIONALE
Security awareness training addresses the human factor, reducing the
likelihood of successful social engineering attacks. Defense in depth
involves layered controls, least privilege limits access rights, and
separation of duties prevents fraud.
Page 4