0% fanden dieses Dokument nützlich (0 Abstimmungen)
7 Ansichten11 Seiten

Cissp 2017

Das Dokument enthält eine Sammlung von Fragen und Antworten zu CISSP (Certified Information Systems Security Professional) Schulungen, die sich auf verschiedene Aspekte der Informationssicherheit konzentrieren. Die Fragen decken Themen wie Risikomanagement, Zugriffskontrolle, Sicherheitsprotokolle und Datenklassifizierung ab. Es dient als Übungstest für die Vorbereitung auf die CISSP-Zertifizierung.

Hochgeladen von

Sunny Cho
Copyright
© All Rights Reserved
Wir nehmen die Rechte an Inhalten ernst. Wenn Sie vermuten, dass dies Ihr Inhalt ist, beanspruchen Sie ihn hier.
Verfügbare Formate
Als PDF herunterladen oder online auf Scribd lesen
0% fanden dieses Dokument nützlich (0 Abstimmungen)
7 Ansichten11 Seiten

Cissp 2017

Das Dokument enthält eine Sammlung von Fragen und Antworten zu CISSP (Certified Information Systems Security Professional) Schulungen, die sich auf verschiedene Aspekte der Informationssicherheit konzentrieren. Die Fragen decken Themen wie Risikomanagement, Zugriffskontrolle, Sicherheitsprotokolle und Datenklassifizierung ab. Es dient als Übungstest für die Vorbereitung auf die CISSP-Zertifizierung.

Hochgeladen von

Sunny Cho
Copyright
© All Rights Reserved
Wir nehmen die Rechte an Inhalten ernst. Wenn Sie vermuten, dass dies Ihr Inhalt ist, beanspruchen Sie ihn hier.
Verfügbare Formate
Als PDF herunterladen oder online auf Scribd lesen
KORNERSTONE BEE Training. Makes a difference. (| Certified Information Systems Security Professional, CISSP® Completion Test (Q51 - Q100) Makes a Differ ence CISSP Training 2018 CISSP Mock Exam Questions 51. Which of the following is the best reason for the use of an automated risk analysis tool? ‘A. Much of the data gathered during the review cannot be reused for subsequent analysis. B. Automated methodologies require minimal training and knowledge of risk analysis, C. Most software tools have user interfaces that are easy to use and do not require any training. B Alformation gathering would be minimized and expedited due to the amount of information already built into the tool. 52. Which one of these statements about the key elements of a good configuration process is NOT true? A. Accommodate the reuse of proven standards and best practices B. Ensure that all requirements remain clear, concise, and valid . Control modifications to system hardware in order to prevent resource /— changes D. Ensure changes, standards, and requirements are communicated promptly and precisely 53. Out of the steps listed below, which one is not one of the steps conducted during the Business Impact Analysis (BIA)? _Acaifernate site selection B. Create data-gathering techniques C. Identify the company’s critical business functions D. Select individuals to interview for data gathering 54, Which of the following would BEST classify as a management control? ‘A. Review of security controls me _BePersonnel security C. Physical and environmental protection D. Documentation Copyright @ 2038, KORNERSTONE Limited KORNERSTOUL x CISSP Training 2018 CISSP Mock Exam Questions 55. The control measures that are intended to reveal the violations of security policy using software and hardware are associated with: A. preventive/physical. __-8-Getective/technical C. detective/physical. D. detective/administr: 56. John is the product manager for an information system. His product has undergone under security review by an IS auditor. John has decided to apply appropriate security controls to reduce the security risks suggested by an IS auditor. Which of the following technique is used by John to treat the identified risk provided by an IS auditor? Risk Mitigation Risk Acceptance C. Risk Avoidance D. Risk transfer 57. Which of the following risk handling technique involves the practice of passing on the risk to another entity, such as an insurance company? A. Risk Mitigation B. Risk Acceptance C. Risk Avoidance D. _Riskctransfer 58. If your property Insurance has Replacement Cost Valuation (RCV) clause your damaged property will be compensated: ‘A. Based on the value of item on the date of loss i wses ‘on new, comparable, or identical item for old regardless of condition of lost item C. Based on value of m one month before the loss D. Based on the value listed on the Ebay auction web site 59. According to private sector data classification levels, how would salary levels and medical A. Public. Internal Use Only. C. Restricted De Confidential formation be classified? 7 Copyright @ 2018, KORNERSTONE Limited KORNERS 1 ‘CISSP Training 2018 CISSP Mock Exam Questions 60. Who is ultimately responsible for the security of computer based information systems within an organization? ‘A. The Tech Support Team B. The Operation Team. Cothe Management Team. D. The Training Team. 61. What Orange Book security rating is reserved for systems that have been evaluated but fail to meet the criteria and requirements of the higher divisions? AA Bo ae DF 62. Which of the following BEST defines add-on security? ‘A. Physical security complementing logical security measures. B. Protection mechanisms implemented as an integral part of an information system. C. Layer security. D. Protection mechanisms implemented after an information system has become operational. 63. Which of the following access control models introduces user security clearance and data classification? _ A. Role-based access control B. Discretionary access control. = [\C- C. Non-discretionary access control Mandatory access control Wher 64, Brute force attacks against encryption keys have increased in potency because of increased computing power. Which of the following is often considered a good protection against the brute force cryptography attack? A. The use of good key generators. B._The use of session keys. ©. Nothing can defend you against a brute force crypto key attack. D. Algorithms that are immune to brute force key attacks. Copyright @ 2018, KORNERSTONE Limited KORNERS TONE <7 ‘CISSP Training 2018 CISSP Mock Exam Questions 65. What is the main problem of the renewal of a root CA certificate? A. Itrequires key recovery of all end user keys _BMreauires the authentic distribution of the new root CA certificate to all PKI participants C. It requires the collection of the old root CA certificates from all the users D. It requires issuance of the new root CA certificate 66. A code, as is pertains to cryptography: A. is a generic term for encryption. B. is specific to substitution ciphers. _& deals with linguistic units. D. is specific to transposition ciphers. 67. Which of the following can best be defined as a cryptanalysis technique in which the analyst tries to determine the key from knowledge of some plaintext-ciphertext pairs? ‘A known-plaintext attack A known-algorithm attack C. Achosen-ciphertext attack D. Achosen-plaintext attack 68. An employee ensures all cables are shielded, builds concrete walls that extend from the true floor to the true ceiling and installs a white noise generator. What attack is the employee trying to protect against? A. Emanation Attacks B,_So¢ial Engineering C. Object reuse D. Wiretapping 69. Which of the following fire extinguishing systems incorporating a detection system is currently the most recommended water system for a computer room? A. Wet pipe B. Dry pipe C. Deluge D. _Preaction Copyright © 2018, KORNERSTONE Limited KORNERSTONE _——_— CISSP Training 2018 CISSP Mock Exam Questions 70. What is NOT true with pre shared key authentication within IKE / IPsec protocol? A. Pre shared key authentication is normally based on simple passwords ‘Needs a Public Key Infrastructure (PKI) to work C. IKE is used to setup Security Associations D. IKE builds upon the Oakley protocol and the ISAKMP protocol. 71. In which layer of the OS! Model are connection-oriented protocols located in the TCP/IP suite of protocols? ee fransport layer B. Application layer C. Physical layer D. Network layer 72. 1n IPSec, if the communication is to be gateway-to-gateway or host-to-gateway: Tunnel mode of operation is required B. Only transport mode can be used C. Encapsulating Security Payload (ESP) authentication must be used D. Both tunnel and transport mode can be used 73. One drawback of Application Level Firewall is that it reduces network performance due to the fact that it must analyze every packet and: A. decide what to do with each application. B. decide what to do with each user. C. decide what to do with each port. .ydecide what to do with each packet. 74. Which of the following should be used as a replacement for Telnet for secure remote login over an insecure network? A. S-Telnet B. SSL CC. Rlogin 2H 75. The Loki attack exploits a covert channel using which network protocol? A. TCP Copyright @ 2018, KORNERSTONE Limited KORNERS TOLLE eT C1SSP Training 2018 CcISSP Mock Exam Questions 76. In the Bell-LaPadula model, the *-property is also called: A, The simple security property (6 The confidentiality property ‘The confinement property D. The tranquility property 77. What can be defined as a table of subjects and objects indicating what actions individual subjects can take upon individual objects? A. Acapacity table BE An access control list C. An access control matrix D. Acapability table 78. Which of the following statements pertaining to Kerberos is TRUE? A. Kerberos uses public key cryptography. _ Be Kerberos uses X.509 certificates C. Kerberos is a credential-based authentication system. D. Kerberos was developed by Microsoft. \\, 79. What is considered the MOST important type of error to avoid for a biometric access control system? A, Type | Error Type Il Error C. Combined Error Rate D. Crossover Error Rate 80. What is the verification that the user's claimed identity is valid called and is usually implemented through a user password at log-on time? A. Authentication ~~ B. Identification C. Integrity D. Confidentiality 81. Which of the following would constitute the BEST example of a password to use for access to a system by a network administrator? A. Holiday B. Christmas12 C. Jenny D. GyN19Za! Copyright @ 2018, KORNERSTONE Limited KORNERS TONE CCISSP Training 2018 CCISSP Mack Exam Questions 82. Common Criteria 15408 generally outlines assurance and functional requirements through a security evaluation process concept of for Evaluated Assurance Levels (EALs) to certify a product or system. ‘A. EAL, Security Target, Target of Evaluation B, SER, Protection Profile, Security Target C~ Protection Profile, Target of Evaluation, Security Target D. SER, Security Target, Target of Evaluation 83. Which of the following would provide the BEST stress testing environment taking under consideration and avoiding possible data exposure and leaks of sensitive data? A. Test environment using test data. B. Test environment using sanitized live workloads data. C. Production environment using test data. De Production environment using sanitized live workloads data. 84. Which of the following is a NOT a preventative control? ‘A. Deny programmer access to production data. B._ Require change requests to include information about dates, descriptions, cost analysis and anticipated effects. _C--Run a source comparison program between control and current source ~ periodically. D. Establish procedures for emergency changes. 85, What setup should an administrator use for regularly testing the strength of user passwords? DB “Anetworked workstat accessed by the cracking program. n so the password database can easily be copied locally and processed by the cracking program. C. Astandalone workstation on which the password database is copied and processed by the cracking program. D. Apassword-cracking program is unethical; therefore it should not be used. nso that the live password database can easily be B. Anetworked workst: Copyright @ 2018, KORNERSTONE Limited KORNERS TON! x CISSP Training 2018 CISSP Mock Exam Questions 86. Who should measure the effectiveness of Information System security related controls in an organization? A. The local security specialist B. The business manager The systems auditor The central security manager 87. Which Orange Book evaluation level is described as "Verified Design"? AL AL B. BB ime information without 88. Which of the following usually provides reliable, real consuming network or host resources? ~B. host-based IDS . application-based IDS D. firewall-based IDS 89. Password management falls into which control category? A. Compensating B. Detective _Ce Preventive D. Technical 90. Ding Ltd. is a firm specializes itellectual property business. A new video streaming application needs to be installed for the purpose of conducting the annual awareness program as per the firm security program. The application will stream internally copyrighted computer based training videos. The requirements for the application installation are to use a single server, low cost technologies, high performance and no high availability capacities. In regards to storage technology, what is the most suitable configuration for the server hard drives? AcSingle hard disk (no RAID) B. RAIDO C. RAIDI D. RAID 10 Copyright @ 2018, KORNERSTONE Limited CISSP Training 2018 CISSP Mock Exam Questions y 91. Which of the following should be emphasized during the Business Impact ‘Analysis (BIA) considering that the BIA focus is on business processes? ‘A. Composition 8. Priorities C. Dependencies D. Service levels 92. A Differential backup process: ‘A. Backs up data labeled with archive bit 1 and leaves the data labeled as archive “bitd B. Backs up data labeled with archive bit 1 and changes the data label to archive bito C. Backs up data labeled with archive bit 0 and leaves the data labeled as archive bit o D. Backs up data labeled with archive bit 0 and changes the data label to archive bit1 93. A site that is owned by the company and mirrors the original production site is referred toasa___? A. Hot site. B. Warm Site. C. Reciprocal site D. Redundant Site. — 94, What is electronic vaulting? ‘A. Information is backed up to tape on a hourly basis and is stored in an on-site vault. B. Information is backed up to tape on a daily basis and is stored in an on-site vault. C. Transferring electronic journals or transaction logs to an off-site storage facility _De transfer of bulk information to @ remote central backup facility. 95. If an organization were to monitor their employees’ e-mail, it should not: A. Monitor only a limited number of employees. _-B. Inform all employees that e-mail is being monitored. C. Explain who can read the e-mail and how long it is backed up. D. Explain what is considered an acceptable use of the e-mail system. Copyright @ 2018, KORNERSTONE Limited KORNERS| CISSP Training 2018 CISSP Mock Exam Questions 96. Which of the following can be defined as a unique identifier in the table that unambiguously points to an individual tuple or record in the table? primary key candidate key secondary key foreign key 97. Why would a database be denormalized? ‘A. To ensure data integrity B increase processing efficiency C. To prevent duplication of data D. To save storage space 98. Java is not: Object-oriented. B. Distributed. C. Architecture Specific. D. Multithreaded. 99. In what way could Java applets pose a security threat? ‘A. Their transport can interrupt the secure distribution of World Wide Web pages over the Internet by removing SSL and S-HTTP B. Java interpreters do not provide the ability to limit system access that an applet could have on a client system. CC. Executables from the Internet may attempt an intentional attack when they are downloaded on a client system. D. Java does not check the bytecode at runtime or provide other safety mechanisms for program isolation from the client system. 100. What is NOT included in a data dictionary? A. Data Element Definitions B. Schema Objects C. Reference Keys D, Structured Query Language Copyright @ 2038, KORNERSTONE Limited KORNERSTOUE _————

Das könnte Ihnen auch gefallen