0% fanden dieses Dokument nützlich (0 Abstimmungen)
2 Ansichten11 Seiten

Cissp 2017

Das Dokument enthält eine Sammlung von Übungsfragen für die CISSP-Zertifizierung, die verschiedene Aspekte der Informationssicherheit abdecken. Die Fragen behandeln Themen wie Sicherheitsrichtlinien, Risikomanagement, Authentifizierungsmethoden und Netzwerksicherheit. Ziel ist es, die Kenntnisse der Teilnehmer in Bezug auf Sicherheitskonzepte und -praktiken zu testen.

Hochgeladen von

Sunny Cho
Copyright
© All Rights Reserved
Wir nehmen die Rechte an Inhalten ernst. Wenn Sie vermuten, dass dies Ihr Inhalt ist, beanspruchen Sie ihn hier.
Verfügbare Formate
Als PDF herunterladen oder online auf Scribd lesen
0% fanden dieses Dokument nützlich (0 Abstimmungen)
2 Ansichten11 Seiten

Cissp 2017

Das Dokument enthält eine Sammlung von Übungsfragen für die CISSP-Zertifizierung, die verschiedene Aspekte der Informationssicherheit abdecken. Die Fragen behandeln Themen wie Sicherheitsrichtlinien, Risikomanagement, Authentifizierungsmethoden und Netzwerksicherheit. Ziel ist es, die Kenntnisse der Teilnehmer in Bezug auf Sicherheitskonzepte und -praktiken zu testen.

Hochgeladen von

Sunny Cho
Copyright
© All Rights Reserved
Wir nehmen die Rechte an Inhalten ernst. Wenn Sie vermuten, dass dies Ihr Inhalt ist, beanspruchen Sie ihn hier.
Verfügbare Formate
Als PDF herunterladen oder online auf Scribd lesen
KORNERS TONE EE Training. Makes a difference. ; Certified Information Systems Security Professional, CISSP® Completion Test (Q1 - Q50) ? CISSP Training 2017 CCISSP Mock Exam Questions Which of the following is considered the weakest link in a security system? as B. Software C. Communication D. Hardware 2. One of these statements about the key elements of a good configuration process is NOT true ‘A. Accommodate the reuse of proven standards and best practices B._ Ensure that all requirements: remain clear, concise, and valid \G/ Control modifications to system hardware in order to prevent resource changes D. Ensure changes, standards, and requirements are communicated promptly and precisely 3. What are the three FUNDAMENTAL principles of security? ‘A. Accountability, confidentiality and integrity Confidentiality, integrity and availability C. Integrity, availability and accountability D. Availability, accountability and confidentiality 4. Which of the following tasks is NOT usually part of a Business Impact Analysis (BIA)? A. Calculate the risk for each different business function. B. Identify the company’s critical business functions, C. Calculate how long these functions can survive without these resources. \~ Develop a mission statement. 5. Whatis a security policy? High level statements on management's expectations that must be met in regard to security B. Apolicy that defines authentication to the network. C. Apolicy that focuses on ensuring a secure posture and expresses management approval. It explains in detail how to implement the requirements. D. Astatement that focuses on the authorization process for a system 7, KORNERSTONE Limited 1 KORNERS LOnlt ro CISSP Training 2017 ISS? Mock Exam Questions 6. Which of the following steps is NOT one of the eight detailed steps of a Business act Assessment (BIA)? Notifying senior management of the start of the assessment. 8. Creating data gathering techniques. C. Identifying critical business functions. D. Calculating the risk for each different business function. 7. Which of the following risk handling technique involves the practice of being proactive so that the risk in question is not realized? A. Risk Mitigation B. Risk Acceptance \.G0 Risk Avoidance D. Risk transfer 8. Which of the following Confidentiality, integrity, Availability (CIA) attribute supports the principle of least privilege by providing access to information only to Pas and intended users? Confidentiality B. Integrity C. Availability D. Accuracy 9. Whose role is it to assign classification level to information? A. Security Administrator B., User Owner D. Auditor 10. According to private sector data classification levels, how would salary levels and medical information be classified? A. Public. B. Internal Use Only. C. Restricted. _D. Confidential. 11. According to Requirement 3 of the Payment Card Industry's Data Security Standard (PCI DSS) there is a requirement to “protect stored cardholder data.” Which of the following items cannot be stored by the merchant? Copyright @ 2017, KORNERSTONE Limited 2 CISSP Training 2017 CCISSP Mock Exam Questions > Primary Account Number » Cardholder Name Expiration Date (The Card Validation Code (CVV2) 9 12. Computer security should be first and foremost which of the following? A. Cover all identified risks Be cost-effective. C. Be examined in both monetary and non-monetary terms. D. Be proportionate to the value of IT systems, 13. Which of the following countermeasures would be the most appropriate to prevent possible intrusion or damage from war-dialing attacks? ‘A,/ Monitoring and auditing for such activity _B. Require user authentication C. Making sure only necessary phone numbers are made public D. Using completely different numbers for voice and data accesses 14, Which of the following organizations PRODUCES and PUBLISHES the Federal Information Processing Standards (FIPS)? rs ‘A. The National Computer Security Center (NCSC) 'ahlic 4, s me National Institute of Standards and Technology (NIST) C. The National Security Agency (NSA) Sr icy D. The American National Standards Institute (ANSI) —).,)\ 15. PGP’uses which of the following to encrypt data? \A asymmetric encryption algorithm B. symmetric encryption algorithm 4 oa C._ symmetric key distribution system we Beqyuse\ ~~ D. X.509 digital certificate Fr Cet — @ F Crgesgyen 16. In which mode of DES, will a block of plaintext and a key always give the same ciphertext? pitinsig Web eter Electronic Code Book (ECB) —y) 2S 4% Vake 8 Output Feedback (OFB) €. Counter Mode (CTR) ee D. Cipher Feedback (cra) —> Dla (:p ight @ 2017, KORNERSTONE Limited 3 Digital — Senger priat Moe 17. A one-way hash provides which of the following? A. Confidentiality B. Availability wen D. Authentication 18. To be in compliance with the Montreal Protocol, which of the following options can be taken to refill a Halon flooding system in the event that Halon is fully discharged in the computer room? A. Order an immediate refill with Halon 1201 from the manufacturer. B. Contact a Halon recycling bank to make arrangements for a refill as a Non-Hydrochlorofluorocarbon compound from the manufacturer. D. Order an immediate refill with Halon 1301 from the manufacturer. 19. Which type of fire extinguisher is MOST appropriate for a digital information processing facility? A. Type TypeB Sh Type C Type D 20. How do you distinguish between a bridge and a router? A. Abridge simply connects multiple networks, a router examines each packet to determine which network to forward it to. "Bridge" and "router" are synonyms for equipment used to join two networks. C. The bridge is a specific type of router used to connect a LAN to the global Internet. \® The bridge connects multiple networks at the data link layer, while router connects multiple networks at the network layer. 21. Which device acting as a translator is used to connect two networks or applications from Layer 4 up to Layer 7 of the ISO/OSI Model? A. Bridge Loyey B. Repeater ' C. Router pf teway Copyright @ 2017, KORNERSTONE Limited 4 KORNERS TONE a (CISSP Training 2017 CCISSP Mock Exam Questions 22, What is the maximum length of cable that can be used for a twisted-pait, Category 5 10Base-T cable? 80 meters 100 meters C. 185 meters D. 500 meters 23. Which of the following is an advantage of proxies? \Ae Proxies provide a single point of access, control, and logging. B. Proxies must exist for each service. C. Proxies create a single point of failure. D. Proxies do not protect the base operating system 24. Which cable technology refers to the CAT3 and CATS categories? ‘A. Coaxial cables B. Fiber Optic cables C. Axial cables \D: Twisted Pair cables 25. Which type of attack involves the altering of a systems Address Resolution Protocol (ARP) table so that incorrect IP to MAC address mappings? ‘A. Reverse ARP B. Poisoning ARP cache ARP table poisoning D. Reverse ARP table poisoning 26. Data which is properly secured and can be described with terms like genuine or not corrupted from the original refers to data that has a high level of what? A. Authenticity 8. Authorization C. Availability 1 0/NoerRapudtation c 4 27. Which of the following is NOT part of the Kerberos authentication protocol? A. Symmetric key cryptography B. Authentication service (AS) C. Principals D, Public Key 7, KORNERSTONE Limited 5 Copyright CISSP Training 2017 CCISSP Mack Exam Questions 28. In the context of access control, locks, gates, guards are examples of which of the following? A. Adi B. Technical controls Ce Physical controls D. Logical controls istrative controls 29. Which of the following biometric parameters are better suited for authentication use over a long period of time? \ Be Tris pattern B. Voice pattern C. Signature dynamics D. Retina pattern 30. How can an individual/person BEST be identified or authenticated to prevent local masquerading attacks? ‘A. User Id and password B. Smart card and PIN code C. Two-factor authentic 7 ition Dé Biometrics 31. The authenticator within Kerberos provides a requested service to the client after validating which of the following? A. Timestamp Be Client public key C. Client private key D. Server public key 32. Which type of password provides maximum security because a new password is required for each new log-on? , A. One-time or dynamic password Cognitive password C. Static password D. Passphrase 33. You are a security consultant who is required to perform penetration testing on a client's network. During penetration testing, you are required to use a (compromised system to attack other systems on the network to avoid network \ Copyright @ 2017, KORNERSTONE Limited 6 KORNERS TON! La] (ISSP Training 2017 CIssP Mock Exam Questions restrictions like firewalls. Which method would you use in this scenario: lack box Method wir method C. White Box Method. D. Grey Box Method 34. A network-based vulnerability assessment is a type of test also referred to as: A. Anactive vulnerability assessment. B. A routing vulnerability assessment. C. Ahost-based vulnerability assessment. DA passive vulnerability assessment. 35. Which of the following testing method examines internal structure or working of an application? Nas Whe bax testing B. Parallel Test C. Regression Testing D. Pilot Testing 36. Which of the following would best describe the difference between white-box testing and black-box testing? ‘A. White-box testing is performed by an independent programmer team. B. Black-box testing uses the bottom-up approach. White-box testing examines the program internal logical structure. D. Black-box testing involves the business units 37. Which must bear the primary responsibility for determining the level of protection needed for information systems resources? A. IS security specialists \B« Senior Management C. Senior security analysts D. systems Auditors 38. When attempting to establish liability, which of the following would be described as performing the ongoing maintenance necessary to keep something in proper working order, updated, effective, or to abide by what is commonly expected in a situation? A Due care Copyright @ 2017, KORNERSTONE Limited 7 KORNERS TON! —- CISSP Training 2017 CISSP Mock Exam Questions B. Due concern C. Due diligence D. Due practice 39. Which of the following is NOT a component of an Operations Security "triples"? A. Asset B. Threat C. Vulnerability D/ Risk 40. RAID level 10 is created by combining which of the following? A. level 0 (striping) with level 1 (mirroring). B. level 0 (striping) with level 2 (hamming). C. level 0 (striping) with level 1 (clustering). D. level 0 (striping) with level 1 (hamming). 41. Which of the following backup methods is primarily run when time and tape space permits, and is used for the system archive or baselined tape sets? full backup method. B. incremental backup method . differential backup method D. tape backup method. 42. Which of the following answers BEST indicates the most important part of a data backup plan? Testing the backups with restore operati B. An effective backup plan C. Areliable network infrastructure D. Expensive backup hardware TSE 43, The Orange Book requires auditing mechanisms for any systems evaluated at which of the following levels? A. Cland above. B/ C2 and above. C. Bland above. D. B2 and above. 44. Which of the following is a large hardware/software backup system that uses the Copyright @ 2017, KORNERSTONE Limited a KORNERS | CISSP Training 2017 CISSP Mock Exam Questions we technology? Tape Array. B. Scale Array. C. Crimson Array. D. Table Array. 45. What is the Maximum Tolerable Downtime (MTD)? ‘A. Maximum elapsed time required to complete recovery of application data B. Minimum elapsed time required to complete recovery of application data C. Maximum elapsed time required to move back to primary site after a major disruption of Itis maximum delay businesses can tolerate and still remain viable 46. In an online transaction processing system (OLTP), which of the following actions should be taken when erroneous or invalid transactions are detected? «The transactions should be dropped from processing. B. The transactions should be processed after the program makes adjustments. C. The transactions should be written to a report and reviewed, D. The transactions should be corrected and reprocessed. 47. Which of the following statements relating to Distributed Computing Environment (DCE) is FALSE? A. Itis a layer of software that sits on the top of the network layer and provides services to the applications above it. B. It uses a Universal Unique Identifier (UID) to uniquely identify users, resources and components. C/ It provides the same functionality as DCOM, but it is more proprietary than Dcom. D. It is a set of management services with a communication layer based on RPC. 48, Which of the following BEST explains why computerized information systems frequently fail to meet the needs of users? A. Inadequate quality assurance (QA) tools. B. Constantly changing user needs.

Das könnte Ihnen auch gefallen