Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 11 Question 63 Discussion

Which of the following are the types of access controls? Each correct answer represents a complete solution. Choose three.
A) Physical
B) Technical
C) Administrative
D) Automatic

ISC2 CSSLP Exam - Topic 11 Question 63 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 63
Topic #: 11
[All CSSLP Questions]

Which of the following are the types of access controls? Each correct answer represents a complete solution. Choose three.

Show Suggested Answer Hide Answer
Suggested Answer: A

The Recovery Point Objective (RPO) describes the acceptable amount of data loss measured in time. It is the point in time to which data must

be recovered as defined by the organization. The RPO is generally a definition of what an organization determines is an 'acceptable loss' in a

disaster situation. If the RPO of a company is 2 hours and the time it takes to get the data back into production is 5 hours, the RPO is still 2

hours. Based on this RPO the data must be restored to within 2 hours of the disaster.

Answer B is incorrect. The Recovery Time Objective (RTO) is the duration of time and a service level within which a business process

must be restored after a disaster or disruption in order to avoid unacceptable consequences associated with a break in business continuity. It

includes the time for trying to fix the problem without a recovery, the recovery itself, tests and the communication to the users. Decision time

for user representative is not included. The business continuity timeline usually runs parallel with an incident management timeline and may

start at the same, or different, points.

In accepted business continuity planning methodology, the RTO is established during the Business Impact Analysis (BIA) by the owner of a

process (usually in conjunction with the Business Continuity planner). The RTOs are then presented to senior management for acceptance.

The RTO attaches to the business process and not the resources required to support the process.

Answer D is incorrect. The Recovery Time Actual (RTA) is established during an exercise, actual event, or predetermined based on

recovery methodology the technology support team develops. This is the time frame the technology support takes to deliver the recovered

infrastructure to the business.

Answer C is incorrect. The Recovery Consistency Objective (RCO) is used in Business Continuity Planning in addition to Recovery Point

Objective (RPO) and Recovery Time Objective (RTO). It applies data consistency objectives to Continuous Data Protection services.


Contribute your Thoughts:

0/2000 characters
Felton
8 months ago
Physical, Technical, and Administrative are the classics!
upvoted 0 times
...
Gearldine
8 months ago
Wait, are we sure Automatic isn't a thing?
upvoted 0 times
...
Adelle
9 months ago
100% agree with the first three!
upvoted 0 times
...
Marshall
9 months ago
I thought Automatic was a type too?
upvoted 0 times
...
Agustin
9 months ago
Definitely Physical, Technical, and Administrative!
upvoted 0 times
...
Berry
9 months ago
I feel like technical is definitely one of them, but I might be mixing up the others. Did we ever discuss automatic access controls?
upvoted 0 times
...
Izetta
9 months ago
I recall a practice question that asked about the same types, and I think it was definitely physical and administrative.
upvoted 0 times
...
Julieta
9 months ago
I'm not entirely sure about the automatic one; it seems like it could fit but I don't remember it being a standard type.
upvoted 0 times
...
Mitsue
9 months ago
I think physical, technical, and administrative are the main types of access controls we covered in class.
upvoted 0 times
...
Wayne
9 months ago
Tagging the user through the firewall's web UI or API - that makes sense. I'll make sure to choose those options.
upvoted 0 times
...
Fairy
10 months ago
From our practice questions, I think the sender is usually the threat actor since they're the one initiating the attack.
upvoted 0 times
...
Brittni
10 months ago
Option A looks good to me. It allows me to rename both columns in a single line of code, which seems efficient.
upvoted 0 times
...
Cherry
1 year ago
I was tempted to pick 'Automatic' just to see if the exam writer was trying to trick us. But I decided to play it safe with the standard options. Gotta love those good old-fashioned access controls!
upvoted 0 times
...
Shayne
1 year ago
Nailed it! Physical, technical, and administrative. These are the tried and true access control methods we need to keep our systems secure.
upvoted 0 times
Eveline
1 year ago
It's important to have a layered approach to access control for maximum protection.
upvoted 0 times
...
Gracia
1 year ago
I always make sure to implement all three types to have a comprehensive security strategy.
upvoted 0 times
...
Shannon
1 year ago
Yes, those are the three main types we use to secure our systems.
upvoted 0 times
...
Rolland
1 year ago
Physical, technical, and administrative are the types of access controls.
upvoted 0 times
...
...
Nu
1 year ago
Haha, 'Automatic' access control? That sounds like something out of a sci-fi movie. I'm glad I went with the classic options - physical, technical, and administrative.
upvoted 0 times
Mariann
1 year ago
I never even considered 'Automatic' as an access control type. Physical, technical, and administrative seem more practical.
upvoted 0 times
...
Hubert
1 year ago
Yeah, I think those three options cover all the bases when it comes to access control.
upvoted 0 times
...
Karina
1 year ago
I agree, 'Automatic' does sound futuristic. I prefer sticking to the traditional options like physical, technical, and administrative.
upvoted 0 times
...
...
Alonso
1 year ago
I was torn between B and D, but I guess D is not a real type of access control. Technical and administrative are definitely important.
upvoted 0 times
Nieves
1 year ago
C) Administrative
upvoted 0 times
...
Silvana
1 year ago
B) Technical
upvoted 0 times
...
Ligia
1 year ago
A) Physical
upvoted 0 times
...
...
Tyisha
1 year ago
A, B, and C are the correct answers. Physical, technical, and administrative controls are the main types of access controls.
upvoted 0 times
Micah
1 year ago
Definitely, it's important to have a well-rounded approach to access control.
upvoted 0 times
...
Vi
1 year ago
So, we should focus on implementing those three types of access controls for security.
upvoted 0 times
...
Sylvie
1 year ago
Yes, you're right. Physical, technical, and administrative controls are the main types of access controls.
upvoted 0 times
...
Anastacia
1 year ago
I think the correct answers are A, B, and C.
upvoted 0 times
...
Anglea
1 year ago
No, automatic is not one of the main types of access controls.
upvoted 0 times
...
Jade
1 year ago
So, automatic is not a type of access control?
upvoted 0 times
...
Ronny
1 year ago
Yes, you're right. Physical, technical, and administrative controls are the main types of access controls.
upvoted 0 times
...
Leigha
1 year ago
I think the correct answers are A, B, and C.
upvoted 0 times
...
Erasmo
1 year ago
C) Administrative
upvoted 0 times
...
Lili
1 year ago
B) Technical
upvoted 0 times
...
Georgene
1 year ago
A) Physical
upvoted 0 times
...
...
Hyman
1 year ago
I'm not sure about Automatic. I think it's Physical, Technical, and Administrative.
upvoted 0 times
...
Tracey
1 year ago
I agree with Ernestine. Those three types make sense for access controls.
upvoted 0 times
...
Ernestine
1 year ago
I think the types of access controls are Physical, Technical, and Administrative.
upvoted 0 times
...

Save Cancel