Certified Security Leadership Officer Exam Prep
Free practice questions

Free C)SLO Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free C)SLO questions are organized by exam domain, so you can see how each part of the Certified Security Leadership Officer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Security Management

Question 1

After a security-platform migration, confirmed incidents fall from 30 per quarter to 12. Over the same period, the proportion of business-critical servers sending usable security logs falls from 96% to 58%. The board asks whether the migration reduced cyber risk. Which conclusion can the C)SLO defend?

Show answer & explanation

Correct answer: D - The decline does not establish improvement because detection coverage also fell.

Question 2

A company has standardized its security change procedures, documented them, and trained the staff who use them. Similar changes now follow the same process. Managers do not measure adherence or track whether deviations are corrected. Under the COBIT 4.1 generic maturity model, what is the highest level demonstrated by this evidence?

Show answer & explanation

Correct answer: B - Level 3 - Defined Process

Domain 2: Risk Management

Question 3

A service has an asset value of $1,000,000, an exposure factor of 20%, and an annualized rate of occurrence of 0.5. Control X would reduce the occurrence rate to 0.1 and cost $45,000 per year. Control Y would reduce the exposure factor to 10% and cost $10,000 per year. All other inputs remain unchanged. Both controls satisfy mandatory requirements and approved residual-risk limits, but only one can be funded. Which choice produces the greatest annual net financial benefit?

Show answer & explanation

Correct answer: A - Choose Y; its annual net benefit is $40,000.

Domain 3: Encryption

Question 4

An attacker can replace both an installer and its displayed SHA-256 digest on an authorized distribution mirror. The publisher's signing private key remains secure, and customer devices already hold an authenticated copy of the publisher's verification key. What would detect unauthorized changes to the installer despite the mirror compromise?

Show answer & explanation

Correct answer: D - Verify the installer's digital signature using the independently trusted publisher public key.

Domain 4: Information Security Access Control Concepts

Question 5

An investigation finds that an external client tried the same two common passwords against 600 employee accounts. No account received more than two attempts that day, so the per-account lockout threshold was never reached. The attacker repeated the process the next day with two different common passwords. Identify the attack technique.

Show answer & explanation

Correct answer: C - Password spraying

Question 6

A secure records facility is tuning its fingerprint entry system. Comparable trials produced the operating points below. Facility policy requires the false acceptance rate (FAR) to remain below 0.05%. Among compliant settings, management wants the fewest rejected legitimate users, measured by the false rejection rate (FRR). Which operating point meets that objective?

Show answer & explanation

Correct answer: C - FAR 0.02%; FRR 1.8%.

Domain 5: Incident Handling and Evidence

Question 7

Responders declare an incident after confirming that a workstation is uploading confidential design files to an external server. There is no destructive local activity or safety dependency. Network isolation is immediately available, and the forensic lead wants to preserve RAM. Select the immediate containment action.

Show answer & explanation

Correct answer: C - Immediately isolate the workstation from the network; preserve power for authorized volatile-memory collection.

Domain 6: Operations Security

Question 8

During an authorized review, a supplier signs in legitimately and changes only the invoice number in a request. The portal returns an invoice belonging to another supplier. The number is valid, and no script or query syntax is submitted. Which correction addresses the underlying flaw rather than merely making it harder to discover?

Show answer & explanation

Correct answer: A - Enforce supplier-specific authorization on every server-side invoice lookup.

Question 9

A recovery exercise simulates an outage at 14:00. The full backup is from 02:00, but verified transaction logs can restore data through 13:48. The database becomes available at 15:10; reconciliation and business acceptance finish at 16:20. The recovery point objective is 20 minutes. The two-hour recovery time objective ends at business acceptance, not database startup. How should the recovery results be assessed?

Show answer & explanation

Correct answer: B - RPO met; RTO missed: 12 minutes of data loss and 140 minutes until service restoration.

Domain 7: Network Security

Question 10

A stateful firewall checks new connections from the top of its rule list and stops at the first match. Rule 1 permits 10.40.0.0/16 to reach 10.60.0.20 on destination TCP port 443. Rule 2 denies host 10.40.8.12 access to that same destination and service. A new connection from this host succeeds. Which change fixes this access-control failure?

Show answer & explanation

Correct answer: A - Place the host-specific deny before the subnet-wide permit.

That's 10 of 1,030

The full bank has 1,020 more C)SLO questions with explanations.

Continue in the free practice test →

View plans