KORNERS TONE
EE
Training. Makes a difference.
; Certified Information Systems
Security Professional, CISSP®
Completion Test
(Q1 - Q50)
?CISSP Training 2017 CCISSP Mock Exam Questions
Which of the following is considered the weakest link in a security system?
as
B. Software
C. Communication
D. Hardware
2. One of these statements about the key elements of a good configuration process
is NOT true
‘A. Accommodate the reuse of proven standards and best practices
B._ Ensure that all requirements: remain clear, concise, and valid
\G/ Control modifications to system hardware in order to prevent resource
changes
D. Ensure changes, standards, and requirements are communicated promptly
and precisely
3. What are the three FUNDAMENTAL principles of security?
‘A. Accountability, confidentiality and integrity
Confidentiality, integrity and availability
C. Integrity, availability and accountability
D. Availability, accountability and confidentiality
4. Which of the following tasks is NOT usually part of a Business Impact Analysis
(BIA)?
A. Calculate the risk for each different business function.
B. Identify the company’s critical business functions,
C. Calculate how long these functions can survive without these resources.
\~ Develop a mission statement.
5. Whatis a security policy?
High level statements on management's expectations that must be met in
regard to security
B. Apolicy that defines authentication to the network.
C. Apolicy that focuses on ensuring a secure posture and expresses
management approval. It explains in detail how to implement the
requirements.
D. Astatement that focuses on the authorization process for a system
7, KORNERSTONE Limited 1 KORNERS LOnlt
roCISSP Training 2017 ISS? Mock Exam Questions
6. Which of the following steps is NOT one of the eight detailed steps of a Business
act Assessment (BIA)?
Notifying senior management of the start of the assessment.
8. Creating data gathering techniques.
C. Identifying critical business functions.
D. Calculating the risk for each different business function.
7. Which of the following risk handling technique involves the practice of being
proactive so that the risk in question is not realized?
A. Risk Mitigation
B. Risk Acceptance
\.G0 Risk Avoidance
D. Risk transfer
8. Which of the following Confidentiality, integrity, Availability (CIA) attribute
supports the principle of least privilege by providing access to information only to
Pas and intended users?
Confidentiality
B. Integrity
C. Availability
D. Accuracy
9. Whose role is it to assign classification level to information?
A. Security Administrator
B., User
Owner
D. Auditor
10. According to private sector data classification levels, how would salary levels and
medical information be classified?
A. Public.
B. Internal Use Only.
C. Restricted.
_D. Confidential.
11. According to Requirement 3 of the Payment Card Industry's Data Security
Standard (PCI DSS) there is a requirement to “protect stored cardholder data.”
Which of the following items cannot be stored by the merchant?
Copyright @ 2017, KORNERSTONE Limited 2CISSP Training 2017 CCISSP Mock Exam Questions
>
Primary Account Number
»
Cardholder Name
Expiration Date
(The Card Validation Code (CVV2)
9
12. Computer security should be first and foremost which of the following?
A. Cover all identified risks
Be cost-effective.
C. Be examined in both monetary and non-monetary terms.
D. Be proportionate to the value of IT systems,
13. Which of the following countermeasures would be the most appropriate to
prevent possible intrusion or damage from war-dialing attacks?
‘A,/ Monitoring and auditing for such activity
_B. Require user authentication
C. Making sure only necessary phone numbers are made public
D. Using completely different numbers for voice and data accesses
14, Which of the following organizations PRODUCES and PUBLISHES the Federal
Information Processing Standards (FIPS)? rs
‘A. The National Computer Security Center (NCSC) 'ahlic 4, s
me National Institute of Standards and Technology (NIST)
C. The National Security Agency (NSA) Sr icy
D. The American National Standards Institute (ANSI) —).,)\
15. PGP’uses which of the following to encrypt data?
\A asymmetric encryption algorithm
B. symmetric encryption algorithm 4 oa
C._ symmetric key distribution system we Beqyuse\ ~~
D. X.509 digital certificate Fr Cet —
@ F Crgesgyen
16. In which mode of DES, will a block of plaintext and a key always give the same
ciphertext? pitinsig Web eter
Electronic Code Book (ECB) —y) 2S 4% Vake
8 Output Feedback (OFB)
€. Counter Mode (CTR) ee
D. Cipher Feedback (cra) —> Dla (:p
ight @ 2017, KORNERSTONE Limited 3Digital — Senger priat Moe
17. A one-way hash provides which of the following?
A. Confidentiality
B. Availability
wen
D. Authentication
18. To be in compliance with the Montreal Protocol, which of the following options
can be taken to refill a Halon flooding system in the event that Halon is fully
discharged in the computer room?
A. Order an immediate refill with Halon 1201 from the manufacturer.
B. Contact a Halon recycling bank to make arrangements for a refill
as a Non-Hydrochlorofluorocarbon compound from the manufacturer.
D. Order an immediate refill with Halon 1301 from the manufacturer.
19. Which type of fire extinguisher is MOST appropriate for a digital information
processing facility?
A. Type
TypeB
Sh Type C
Type D
20. How do you distinguish between a bridge and a router?
A. Abridge simply connects multiple networks, a router examines each packet
to determine which network to forward it to.
"Bridge" and "router" are synonyms for equipment used to join two
networks.
C. The bridge is a specific type of router used to connect a LAN to the global
Internet.
\® The bridge connects multiple networks at the data link layer, while router
connects multiple networks at the network layer.
21. Which device acting as a translator is used to connect two networks or
applications from Layer 4 up to Layer 7 of the ISO/OSI Model?
A. Bridge Loyey
B. Repeater '
C. Router
pf teway
Copyright @ 2017, KORNERSTONE Limited 4 KORNERS TONE
a(CISSP Training 2017 CCISSP Mock Exam Questions
22, What is the maximum length of cable that can be used for a twisted-pait,
Category 5 10Base-T cable?
80 meters
100 meters
C. 185 meters
D. 500 meters
23. Which of the following is an advantage of proxies?
\Ae Proxies provide a single point of access, control, and logging.
B. Proxies must exist for each service.
C. Proxies create a single point of failure.
D. Proxies do not protect the base operating system
24. Which cable technology refers to the CAT3 and CATS categories?
‘A. Coaxial cables
B. Fiber Optic cables
C. Axial cables
\D: Twisted Pair cables
25. Which type of attack involves the altering of a systems Address Resolution
Protocol (ARP) table so that incorrect IP to MAC address mappings?
‘A. Reverse ARP
B. Poisoning ARP cache
ARP table poisoning
D. Reverse ARP table poisoning
26. Data which is properly secured and can be described with terms like genuine or
not corrupted from the original refers to data that has a high level of what?
A. Authenticity
8. Authorization
C. Availability
1 0/NoerRapudtation
c 4
27. Which of the following is NOT part of the Kerberos authentication protocol?
A. Symmetric key cryptography
B. Authentication service (AS)
C. Principals
D, Public Key
7, KORNERSTONE Limited 5
CopyrightCISSP Training 2017 CCISSP Mack Exam Questions
28. In the context of access control, locks, gates, guards are examples of which of the
following?
A. Adi
B. Technical controls
Ce Physical controls
D. Logical controls
istrative controls
29. Which of the following biometric parameters are better suited for authentication
use over a long period of time?
\ Be Tris pattern
B. Voice pattern
C. Signature dynamics
D. Retina pattern
30. How can an individual/person BEST be identified or authenticated to prevent
local masquerading attacks?
‘A. User Id and password
B. Smart card and PIN code
C. Two-factor authentic
7 ition
Dé Biometrics
31. The authenticator within Kerberos provides a requested service to the client after
validating which of the following?
A. Timestamp
Be Client public key
C. Client private key
D. Server public key
32. Which type of password provides maximum security because a new password is
required for each new log-on?
, A. One-time or dynamic password
Cognitive password
C. Static password
D. Passphrase
33. You are a security consultant who is required to perform penetration testing on a
client's network. During penetration testing, you are required to use a
(compromised system to attack other systems on the network to avoid network
\
Copyright @ 2017, KORNERSTONE Limited 6 KORNERS TON!
La](ISSP Training 2017 CIssP Mock Exam Questions
restrictions like firewalls. Which method would you use in this scenario:
lack box Method
wir method
C. White Box Method.
D. Grey Box Method
34. A network-based vulnerability assessment is a type of test also referred to as:
A. Anactive vulnerability assessment.
B. A routing vulnerability assessment.
C. Ahost-based vulnerability assessment.
DA passive vulnerability assessment.
35. Which of the following testing method examines internal structure or working of
an application?
Nas Whe bax testing
B. Parallel Test
C. Regression Testing
D. Pilot Testing
36. Which of the following would best describe the difference between white-box
testing and black-box testing?
‘A. White-box testing is performed by an independent programmer team.
B. Black-box testing uses the bottom-up approach.
White-box testing examines the program internal logical structure.
D. Black-box testing involves the business units
37. Which must bear the primary responsibility for determining the level of
protection needed for information systems resources?
A. IS security specialists
\B« Senior Management
C. Senior security analysts
D. systems Auditors
38. When attempting to establish liability, which of the following would be described
as performing the ongoing maintenance necessary to keep something in proper
working order, updated, effective, or to abide by what is commonly expected in a
situation?
A Due care
Copyright @ 2017, KORNERSTONE Limited 7 KORNERS TON!
—-CISSP Training 2017 CISSP Mock Exam Questions
B. Due concern
C. Due diligence
D. Due practice
39. Which of the following is NOT a component of an Operations Security "triples"?
A. Asset
B. Threat
C. Vulnerability
D/ Risk
40. RAID level 10 is created by combining which of the following?
A. level 0 (striping) with level 1 (mirroring).
B. level 0 (striping) with level 2 (hamming).
C. level 0 (striping) with level 1 (clustering).
D. level 0 (striping) with level 1 (hamming).
41. Which of the following backup methods is primarily run when time and tape
space permits, and is used for the system archive or baselined tape sets?
full backup method.
B. incremental backup method
. differential backup method
D. tape backup method.
42. Which of the following answers BEST indicates the most important part of a data
backup plan?
Testing the backups with restore operati
B. An effective backup plan
C. Areliable network infrastructure
D. Expensive backup hardware
TSE
43, The Orange Book requires auditing mechanisms for any systems evaluated at
which of the following levels?
A. Cland above.
B/ C2 and above.
C. Bland above.
D. B2 and above.
44. Which of the following is a large hardware/software backup system that uses the
Copyright @ 2017, KORNERSTONE Limited a KORNERS |CISSP Training 2017 CISSP Mock Exam Questions
we technology?
Tape Array.
B. Scale Array.
C. Crimson Array.
D. Table Array.
45. What is the Maximum Tolerable Downtime (MTD)?
‘A. Maximum elapsed time required to complete recovery of application data
B. Minimum elapsed time required to complete recovery of application data
C. Maximum elapsed time required to move back to primary site after a major
disruption
of Itis maximum delay businesses can tolerate and still remain viable
46. In an online transaction processing system (OLTP), which of the following actions
should be taken when erroneous or invalid transactions are detected?
«The transactions should be dropped from processing.
B. The transactions should be processed after the program makes adjustments.
C. The transactions should be written to a report and reviewed,
D. The transactions should be corrected and reprocessed.
47. Which of the following statements relating to Distributed Computing
Environment (DCE) is FALSE?
A. Itis a layer of software that sits on the top of the network layer and provides
services to the applications above it.
B. It uses a Universal Unique Identifier (UID) to uniquely identify users,
resources and components.
C/ It provides the same functionality as DCOM, but it is more proprietary than
Dcom.
D. It is a set of management services with a communication layer based on RPC.
48, Which of the following BEST explains why computerized information systems
frequently fail to meet the needs of users?
A. Inadequate quality assurance (QA) tools.
B. Constantly changing user needs.
Das könnte Ihnen auch gefallen