0 Bewertungen 0% fanden dieses Dokument nützlich (0 Abstimmungen) 7 Ansichten 11 Seiten Cissp 2017
Das Dokument enthält eine Sammlung von Fragen und Antworten zu CISSP (Certified Information Systems Security Professional) Schulungen, die sich auf verschiedene Aspekte der Informationssicherheit konzentrieren. Die Fragen decken Themen wie Risikomanagement, Zugriffskontrolle, Sicherheitsprotokolle und Datenklassifizierung ab. Es dient als Übungstest für die Vorbereitung auf die CISSP-Zertifizierung.
KI-verbesserte Titel und Beschreibungen
Copyright
© All Rights Reserved
Verfügbare Formate
Als PDF herunterladen oder online auf Scribd lesen
Go to previous items Go to next items
KORNERSTONE
BEE
Training. Makes a difference. (|
Certified Information Systems
Security Professional, CISSP®
Completion Test
(Q51 - Q100)
Makes a Differ enceCISSP Training 2018 CISSP Mock Exam Questions
51. Which of the following is the best reason for the use of an automated risk
analysis tool?
‘A. Much of the data gathered during the review cannot be reused for
subsequent analysis.
B. Automated methodologies require minimal training and knowledge of risk
analysis,
C. Most software tools have user interfaces that are easy to use and do not
require any training.
B Alformation gathering would be minimized and expedited due to the amount
of information already built into the tool.
52. Which one of these statements about the key elements of a good configuration
process is NOT true?
A. Accommodate the reuse of proven standards and best practices
B. Ensure that all requirements remain clear, concise, and valid
. Control modifications to system hardware in order to prevent resource
/— changes
D. Ensure changes, standards, and requirements are communicated promptly
and precisely
53. Out of the steps listed below, which one is not one of the steps conducted during
the Business Impact Analysis (BIA)?
_Acaifernate site selection
B. Create data-gathering techniques
C. Identify the company’s critical business functions
D. Select individuals to interview for data gathering
54, Which of the following would BEST classify as a management control?
‘A. Review of security controls
me
_BePersonnel security
C. Physical and environmental protection
D. Documentation
Copyright @ 2038, KORNERSTONE Limited KORNERSTOUL
xCISSP Training 2018 CISSP Mock Exam Questions
55. The control measures that are intended to reveal the violations of security policy
using software and hardware are associated with:
A. preventive/physical.
__-8-Getective/technical
C. detective/physical.
D. detective/administr:
56. John is the product manager for an information system. His product has
undergone under security review by an IS auditor. John has decided to apply
appropriate security controls to reduce the security risks suggested by an IS
auditor. Which of the following technique is used by John to treat the identified
risk provided by an IS auditor?
Risk Mitigation
Risk Acceptance
C. Risk Avoidance
D. Risk transfer
57. Which of the following risk handling technique involves the practice of passing on
the risk to another entity, such as an insurance company?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. _Riskctransfer
58. If your property Insurance has Replacement Cost Valuation (RCV) clause your
damaged property will be compensated:
‘A. Based on the value of item on the date of loss
i wses ‘on new, comparable, or identical item for old regardless of condition of
lost item
C. Based on value of
m one month before the loss
D. Based on the value listed on the Ebay auction web site
59. According to private sector data classification levels, how would salary levels and
medical
A. Public.
Internal Use Only.
C. Restricted
De Confidential
formation be classified?
7
Copyright @ 2018, KORNERSTONE Limited KORNERS 1‘CISSP Training 2018 CISSP Mock Exam Questions
60. Who is ultimately responsible for the security of computer based information
systems within an organization?
‘A. The Tech Support Team
B. The Operation Team.
Cothe Management Team.
D. The Training Team.
61. What Orange Book security rating is reserved for systems that have been
evaluated but fail to meet the criteria and requirements of the higher divisions?
AA
Bo
ae
DF
62. Which of the following BEST defines add-on security?
‘A. Physical security complementing logical security measures.
B. Protection mechanisms implemented as an integral part of an information
system.
C. Layer security.
D. Protection mechanisms implemented after an information system has
become operational.
63. Which of the following access control models introduces user security clearance
and data classification? _
A. Role-based access control
B. Discretionary access control. = [\C-
C. Non-discretionary access control
Mandatory access control Wher
64, Brute force attacks against encryption keys have increased in potency because of
increased computing power. Which of the following is often considered a good
protection against the brute force cryptography attack?
A. The use of good key generators.
B._The use of session keys.
©. Nothing can defend you against a brute force crypto key attack.
D. Algorithms that are immune to brute force key attacks.
Copyright @ 2018, KORNERSTONE Limited KORNERS TONE
<7‘CISSP Training 2018 CISSP Mock Exam Questions
65. What is the main problem of the renewal of a root CA certificate?
A. Itrequires key recovery of all end user keys
_BMreauires the authentic distribution of the new root CA certificate to all PKI
participants
C. It requires the collection of the old root CA certificates from all the users
D. It requires issuance of the new root CA certificate
66. A code, as is pertains to cryptography:
A. is a generic term for encryption.
B. is specific to substitution ciphers.
_& deals with linguistic units.
D. is specific to transposition ciphers.
67. Which of the following can best be defined as a cryptanalysis technique in which
the analyst tries to determine the key from knowledge of some
plaintext-ciphertext pairs?
‘A known-plaintext attack
A known-algorithm attack
C. Achosen-ciphertext attack
D. Achosen-plaintext attack
68. An employee ensures all cables are shielded, builds concrete walls that extend
from the true floor to the true ceiling and installs a white noise generator. What
attack is the employee trying to protect against?
A. Emanation Attacks
B,_So¢ial Engineering
C. Object reuse
D. Wiretapping
69. Which of the following fire extinguishing systems incorporating a detection
system is currently the most recommended water system for a computer room?
A. Wet pipe
B. Dry pipe
C. Deluge
D.
_Preaction
Copyright © 2018, KORNERSTONE Limited KORNERSTONE
_——_—CISSP Training 2018 CISSP Mock Exam Questions
70. What is NOT true with pre shared key authentication within IKE / IPsec protocol?
A. Pre shared key authentication is normally based on simple passwords
‘Needs a Public Key Infrastructure (PKI) to work
C. IKE is used to setup Security Associations
D. IKE builds upon the Oakley protocol and the ISAKMP protocol.
71. In which layer of the OS! Model are connection-oriented protocols located in the
TCP/IP suite of protocols?
ee fransport layer
B. Application layer
C. Physical layer
D. Network layer
72. 1n IPSec, if the communication is to be gateway-to-gateway or host-to-gateway:
Tunnel mode of operation is required
B. Only transport mode can be used
C. Encapsulating Security Payload (ESP) authentication must be used
D. Both tunnel and transport mode can be used
73. One drawback of Application Level Firewall is that it reduces network
performance due to the fact that it must analyze every packet and:
A. decide what to do with each application.
B. decide what to do with each user.
C. decide what to do with each port.
.ydecide what to do with each packet.
74. Which of the following should be used as a replacement for Telnet for secure
remote login over an insecure network?
A. S-Telnet
B. SSL
CC. Rlogin
2H
75. The Loki attack exploits a covert channel using which network protocol?
A. TCP
Copyright @ 2018, KORNERSTONE Limited KORNERS TOLLE
eTC1SSP Training 2018 CcISSP Mock Exam Questions
76. In the Bell-LaPadula model, the *-property is also called:
A, The simple security property
(6 The confidentiality property
‘The confinement property
D. The tranquility property
77. What can be defined as a table of subjects and objects indicating what actions
individual subjects can take upon individual objects?
A. Acapacity table
BE An access control list
C. An access control matrix
D. Acapability table
78. Which of the following statements pertaining to Kerberos is TRUE?
A. Kerberos uses public key cryptography.
_ Be Kerberos uses X.509 certificates
C. Kerberos is a credential-based authentication system.
D. Kerberos was developed by Microsoft. \\,
79. What is considered the MOST important type of error to avoid for a biometric
access control system?
A, Type | Error
Type Il Error
C. Combined Error Rate
D. Crossover Error Rate
80. What is the verification that the user's claimed identity is valid called and is
usually implemented through a user password at log-on time?
A. Authentication
~~ B. Identification
C. Integrity
D. Confidentiality
81. Which of the following would constitute the BEST example of a password to use
for access to a system by a network administrator?
A. Holiday
B. Christmas12
C. Jenny
D. GyN19Za!
Copyright @ 2018, KORNERSTONE Limited KORNERS TONECCISSP Training 2018 CCISSP Mack Exam Questions
82. Common Criteria 15408 generally outlines assurance and functional
requirements through a security evaluation process concept of
for Evaluated Assurance Levels (EALs) to certify a
product or system.
‘A. EAL, Security Target, Target of Evaluation
B, SER, Protection Profile, Security Target
C~ Protection Profile, Target of Evaluation, Security Target
D. SER, Security Target, Target of Evaluation
83. Which of the following would provide the BEST stress testing environment taking
under consideration and avoiding possible data exposure and leaks of sensitive
data?
A. Test environment using test data.
B. Test environment using sanitized live workloads data.
C. Production environment using test data.
De Production environment using sanitized live workloads data.
84. Which of the following is a NOT a preventative control?
‘A. Deny programmer access to production data.
B._ Require change requests to include information about dates, descriptions,
cost analysis and anticipated effects.
_C--Run a source comparison program between control and current source
~ periodically.
D. Establish procedures for emergency changes.
85, What setup should an administrator use for regularly testing the strength of user
passwords?
DB “Anetworked workstat
accessed by the cracking program.
n so the password database can easily be copied
locally and processed by the cracking program.
C. Astandalone workstation on which the password database is copied and
processed by the cracking program.
D. Apassword-cracking program is unethical; therefore it should not be used.
nso that the live password database can easily be
B. Anetworked workst:
Copyright @ 2018, KORNERSTONE Limited KORNERS TON!
xCISSP Training 2018 CISSP Mock Exam Questions
86. Who should measure the effectiveness of Information System security related
controls in an organization?
A. The local security specialist
B. The business manager
The systems auditor
The central security manager
87. Which Orange Book evaluation level is described as "Verified Design"?
AL AL
B. BB
ime information without
88. Which of the following usually provides reliable, real
consuming network or host resources?
~B. host-based IDS
. application-based IDS
D. firewall-based IDS
89. Password management falls into which control category?
A. Compensating
B. Detective
_Ce Preventive
D. Technical
90. Ding Ltd. is a firm specializes itellectual property business. A new video
streaming application needs to be installed for the purpose of conducting the
annual awareness program as per the firm security program. The application will
stream internally copyrighted computer based training videos. The requirements
for the application installation are to use a single server, low cost technologies,
high performance and no high availability capacities. In regards to storage
technology, what is the most suitable configuration for the server hard drives?
AcSingle hard disk (no RAID)
B. RAIDO
C. RAIDI
D. RAID 10
Copyright @ 2018, KORNERSTONE LimitedCISSP Training 2018 CISSP Mock Exam Questions
y 91. Which of the following should be emphasized during the Business Impact
‘Analysis (BIA) considering that the BIA focus is on business processes?
‘A. Composition
8. Priorities
C. Dependencies
D. Service levels
92. A Differential backup process:
‘A. Backs up data labeled with archive bit 1 and leaves the data labeled as archive
“bitd
B. Backs up data labeled with archive bit 1 and changes the data label to archive
bito
C. Backs up data labeled with archive bit 0 and leaves the data labeled as archive
bit o
D. Backs up data labeled with archive bit 0 and changes the data label to archive
bit1
93. A site that is owned by the company and mirrors the original production site is
referred toasa___?
A. Hot site.
B. Warm Site.
C. Reciprocal site
D. Redundant Site.
—
94, What is electronic vaulting?
‘A. Information is backed up to tape on a hourly basis and is stored in an on-site
vault.
B. Information is backed up to tape on a daily basis and is stored in an on-site
vault.
C. Transferring electronic journals or transaction logs to an off-site storage
facility
_De transfer of bulk information to @ remote central backup facility.
95. If an organization were to monitor their employees’ e-mail, it should not:
A. Monitor only a limited number of employees.
_-B. Inform all employees that e-mail is being monitored.
C. Explain who can read the e-mail and how long it is backed up.
D. Explain what is considered an acceptable use of the e-mail system.
Copyright @ 2018, KORNERSTONE Limited KORNERS|CISSP Training 2018 CISSP Mock Exam Questions
96. Which of the following can be defined as a unique identifier in the table that
unambiguously points to an individual tuple or record in the table?
primary key
candidate key
secondary key
foreign key
97. Why would a database be denormalized?
‘A. To ensure data integrity
B
increase processing efficiency
C. To prevent duplication of data
D. To save storage space
98. Java is not:
Object-oriented.
B. Distributed.
C. Architecture Specific.
D. Multithreaded.
99. In what way could Java applets pose a security threat?
‘A. Their transport can interrupt the secure distribution of World Wide Web
pages over the Internet by removing SSL and S-HTTP
B. Java interpreters do not provide the ability to limit system access that an
applet could have on a client system.
CC. Executables from the Internet may attempt an intentional attack when they
are downloaded on a client system.
D. Java does not check the bytecode at runtime or provide other safety
mechanisms for program isolation from the client system.
100. What is NOT included in a data dictionary?
A. Data Element Definitions
B. Schema Objects
C. Reference Keys
D, Structured Query Language
Copyright @ 2038, KORNERSTONE Limited KORNERSTOUE
_————
Das könnte Ihnen auch gefallen