Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CISSP topic 1 question 23 discussion

Actual exam question from ISC's CISSP
Question #: 23
Topic #: 1
[All CISSP Questions]

A criminal organization is planning an attack on a government network. Which of the following scenarios presents the HIGHEST risk to the organization?

  • A. Organization loses control of their network devices.
  • B. Network is flooded with communication traffic by the attacker.
  • C. Network management communications is disrupted.
  • D. Attacker accesses sensitive information regarding the network topology.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
JAckThePip
Highly Voted 1 year, 7 months ago
ATTENTION the attacker is planning . If we consider that iy is need know the network to attack, the correct answer is D "attackers act like detectives, gathering information to truly understand their target. From examining email lists to open source information, their goal is to know the network better than the people who run and maintain it. They hone in on the security aspect of the technology, study the weaknesses, and use any vulnerability to their advantage." https://www.graylog.org/post/cyber-security-understanding-the-5-phases-of-intrusion
upvoted 10 times
...
Mgz156
Highly Voted 1 year, 8 months ago
Selected Answer: A
Answer is A Losing control of their network devices to Criminal organization is the Highest risk
upvoted 5 times
jackdryan
1 year ago
A is correct
upvoted 1 times
...
...
Jenkins3mol
Most Recent 1 week, 6 days ago
Selected Answer: A
Reconnaissance Weaponising Delivery Installation Exploitation <--- D when knows about sensitive information Command and control <--A is at this stage Action
upvoted 1 times
...
CCNPWILL
3 weeks, 3 days ago
IF you think its NOT A.... you are not reading the question closely enough. The answer is A.
upvoted 1 times
...
Rumor19
3 months, 1 week ago
Why not B? If we consider that, we have to answer the question "What is the highest risk for the (attacking) organization?" It should be B. A is easy to solve for an attacker. "Their network devices" means their own network devices like a internet router. Not the ones in the goverment network. Just use a new internet access or hardware. But if they flood the goverment network with (unnaturally) communication traffic, they get flagged by IDS/IPS and easily detected.
upvoted 1 times
...
Soleandheel
5 months, 1 week ago
Guys you have to read the question again. Try to understand the question better. The organization being refered to with regard to the highest risk is the Criminal Organization not the government network. A CRIMINAL ORGANIZATION is planning an attack on a government network. Which of the following scenarios presents the HIGHEST risk to the ORGANIZATION? (To the criminals organization) - A: Will compromise the criminal organization, cannot carry out planned attack. I agree with Markrlucas
upvoted 3 times
...
AlexJacobson
5 months, 3 weeks ago
Selected Answer: D
It's a GOVERNMENT network! I think this is the key hint that decides whether the answer is A or D. In my opinion, A can come as a consequence of D. By gaining access to sensitive information about the network topology, criminal organization would basically know everything about the network making the attacks on the network more effective and more dangerous. So for me, it's D.
upvoted 2 times
...
Law88
7 months, 2 weeks ago
Selected Answer: D
The scenario that presents the highest risk to the organization is D. Attacker accesses sensitive information regarding the network topology. The network topology is the arrangement and configuration of the network devices, such as routers, switches, firewalls, servers, etc., and the connections between them, such as cables, wireless links, protocols, etc. The network topology defines how the network operates, communicates, and performs.
upvoted 1 times
...
markrlucas
10 months, 2 weeks ago
Selected Answer: A
A CRIMINAL ORGANIZATION is planning an attack on a government network. Which of the following scenarios presents the HIGHEST risk to the ORGANIZATION? (To the criminals organization) - A: Will compromise the criminal organization, cannot carry out planned attack.
upvoted 4 times
...
s_n_
1 year, 3 months ago
D presents the highest risk to the organization because it implies that the attacker has gained access to sensitive information about the network topology. This could enable the attacker to more effectively exploit the network by understanding its structure and vulnerabilities, which could result in more significant damage and disruption.
upvoted 2 times
...
Cyber_Punk_Rock
1 year, 4 months ago
Why isn't D? like if attackers get Network topology, they have access to the IP ranges, Protocols being used, Ports, Operating system in use on the network including how many firewalls and switches in use.
upvoted 4 times
...
rootic
1 year, 6 months ago
Selected Answer: A
Agree with A.
upvoted 1 times
...
Boats
1 year, 7 months ago
Selected Answer: A
Seems B,C, and D can all be a result of A
upvoted 3 times
...
dev46
1 year, 7 months ago
C can be easily eliminated B could overwhelm network devices with a DDoS kind of attack and C may affect confidentiality. But, the biggest risk is losing network devices as there will be no comms and the impact will be financial and reputational. Hence, A sounds good.
upvoted 1 times
...
franbarpro
1 year, 8 months ago
Selected Answer: A
Going with "A" on this one
upvoted 1 times
...
Toa
1 year, 8 months ago
Answer D They can get critical data that can use to other attack types
upvoted 4 times
franbarpro
1 year, 8 months ago
Eternal Blues... lol
upvoted 1 times
...
crishnamohan
1 year, 2 months ago
It's only getting information about the network topology not the data if I understand correctly.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...