1. A risk is the likelihood of a threat source taking advantage of a vulnerability to an information system. Risks left over after implementing safeguards is known as:
3.As an information systems security professional, what is the highest amount would you recommend to a corporation to invest annually on a countermeasure for protecting their assets valued at $1 million from a potential threat that has an annualized rate of occurrence (ARO) of once every five years and an exposure factor (EF) of 10%
4.Which of the following describes the first step in establishing an encrypted session using a Data Encryption Standard (DES) key?
5.In a typical information security program, what is the primary responsibility of information (data) owner?
8.A system security engineer is evaluation methods to store user passwords in an information system, so what may be the best method to store user passwords and meeting the confidentiality security objective?
9.What is the inverse of confidentiality, integrity, and availability (C.I .A .) triad in risk management?
10.A CISSP may face with an ethical conflict between their company’s policies and the (ISC)2 Code of Ethics. According to the (ISC)2 Code of Ethics, in which order of priority should ethical conflicts be resolved?
11.Company X is planning to implement rule based access control mechanism for controlling access to its information assets, what type of access control is this usually related to?
12.In the Common Criteria Evaluation and Validation Scheme (CCEVS), requirements for future products are defined by:
13.As an information systems security manager (ISSM), how would you explain the purpose for a system security policy?
A brief, high-level statement defining what is and is not permitted during the operation of the system
16.Which of the following entity is ultimately responsible for information security within an organization?
17.What type of cryptanalytic attack where an adversary has the least amount of information to work with?
18.In business continuity planning, which of the following is an advantage of a “hot site” over a “cold site”
19.Which of the following is the most effective method for reducing security risks associated with building entrances?
21.Prior to installation of an intrusion prevention system (IPS), a network engineer would place a packet sniffer on the network, what is the purpose for using a packet sniffer?
22.What determines the assignment of data classifications in a mandatory access control(MAC) philosophy?
23.A type cryptographic attack where it is based on the probability of two different messages using the same hash function to produce the same message digest is?2
24.An access control system that grants users only those rights necessary for them to perform their work is operating on which security principle?
28.When a security administrator wants to conduct regular test on the strength of user passwords, what may be the best setup for this test?
29.When engaging an external contractor for a software development project, source code escrow can be used to protect against...?
30.Which answer lists the proper steps required to develop a disaster recovery and business continuity plan (DRP/BCP)?
Business impact analysis, project initiation, strategy development, plan development, testing, maintenance.
Project initiation, plan development, business impact analysis, strategy development, testing, maintenance.
Project initiation, business impact analysis, strategy development, plan development, testing, maintenance.
Strategy development, project initiation, business impact analysis, plan development, testing, maintenance.
Disaster recovery and business continuity planning, and definition of access control requirements and human resources policies
Security policy implementation, assignment of roles and responsibilities, and information asset classification.
Business impact, threat and vulnerability analysis, delivery of an information security awareness program, and physical security of key installations.
Senior management organizational structure, message distribution standards, and procedures for the operation of security management systems.
36.Act of obtaining information of a higher level of sensitivity by combining information from lower level of sensitivity is called?
40.After signing out a laptop computer from the company loaner pool, you discovered there is a memorandum stored in the loaner laptop written to a competitor containing sensitive information about a new product your company is about to release. Based on the (ISC)2 Code of Ethics, what is the first action you should take?
Inform the security awareness trainers that data disclosure prevention in a mobile computing environment needs to be added to their classes.
does not make it harder for an employee to commit fraudulent activities without other fining out, especially since it aids in obscuring who did what.
requires that more than one person fulfill the tasks of one position within the company, thereby providing both backup and redundancy.
42.Which of the following is the least important information to record when logging a security violation?
Sender computes a digest of the message and sends it to a Trusted Third Party (TTP) who signs it and stores it for later reference.
Sender gets a digitally signed acknowledgment from the recipient containing a copy or digest of the message.
Sender sends the message to a TTP who signs it together with a time stamp and sends it on to the recipien
45.The concept that all accesses must be mediated, protected from unauthorized modification, and verifiable as correct is implemented through what?
48.During a disaster or emergency, how does a closed-circuit television (CCTV) help management and security to minimize loss?
48.During a disaster or emergency, how does a closed-circuit television (CCTV) help management and security to minimize loss?
53.Which of the following can be identified when exceptions occur using operations security detective controls?
54.When downloading software from Internet, why do vendors publish MD5 hash values when they provide software to customers
56.Before powering off a computer system, a computer crime investigator should record contents of the monitor and...?
57.Which of the following transaction processing properties ensures once a transaction completes successfully (commits), the updates survive even if there is a system failure?
59.A security planning process must defines: how security will be managed, who will be responsible, and...?
63.The practice of embedding a message in a document, image, video or sound recording so that its very existence is hidden is called?
64.What characteristic of Digital Encryption Standard (DES) used in Electronic Code Book (ECB) mode makes it unsuitable for long messages?
66.What is the advantage of Rivest, Shamir, Adelman (RSA) public key system over the Digital Signature Algorithm (DSA)?
67.In IPsec, what is the standard format that helps to establish and manage the security association (SA) between two internetworking entities?
68.When securing Internet connections which of the following should be used to protect internal routing and labeling schemes?
69.Which of the following describes the step prior to an encrypted session using Data Encryption Standard (DES)?
71.The accounting branch of a large organization requires an application to process expense vouchers. Each voucher must be input by one of many accounting clerks, verified by the clerk’s applicable supervisor, then reconciled by an auditor before the reimbursement check is produced. Which access control technique should be built into the application to best serve these requirements?
72.What principle recommends division of responsibilities so that one person cannot commit an undetected fraud?
74.Which of the following is true about information that is designated with the highest level of confidentiality in a private sector organization?
It is classified only by the information security officer and restricted to those who have made formal requests for access.
It is available to anyone in the organization whose work relates to the subject and requires authorization for each access
75.When verifying key control objectives of a system design, the security specialist should ensure that the...?
82.A person in possession of a sample of ciphertext and corresponding plaintext is capable of what type of attack?
85.Which of the following describes the activities that assure protection mechanisms are maintained and operational?
87.Which of the following is not a generally accepted benefit of security awareness, training and education?
A security awareness and training program can help an organization reduce the number and severity of errors and omissions
A security education program can help system administrators recognize unauthorized intrusion attempts.
89.Physical security is accomplished through proper facility construction, fire and water protection, anti-theft mechanisms, intrusion detection systems, and security procedures that are adhered to and enforced. Which of the following is not a component that achieves this type of security?
90.In a typical information security program, who would be responsible for providing reports to the corporate executives and senior management on the effectiveness of the instituted program controls?
92.If risk is defined as “the potential that a given threat will exploit vulnerabilities of an asset or group of assets to cause loss or damage to the assets” the risk has all of the following elements except?
Defining the acceptable level of risk the organization can tolerate, and assigning any costs associated with loss or disruption to a third party such as an insurance carrier.
Standards are the high-level statements made by senior management in support of information systems security
97.A memory address location specified in a program instruction that contains the address of final memory location is known as:
98.Which one of the following hardware devices can be re-programmed? 1 Read Only Memory (ROM). 2 Programmable Read Only Memory (PROM). 3 Erasable Programmable Read Only Memory (EPROM).4 Electrically Erasable Programmable Read Only Memory (EEPROM).
Unauthorized access to a secured network could be made through remote control or terminal server programs running on a desktop.
102.Trusted Computing Base (TCB) is comprised of what combination of system components? 1 Hardware.2 Firmware.3 Software.
104.Which security mode best defines where users have both the required clearance and the need-to-know for all data on a system?
108.In the following top-down Common Criteria evaluation process, what is the missing component:Protection Profile Target of Evaluation Security Functionality/Assurance Requirements Evaluation Evaluation Assurance Level
It eliminates the need for a key-distribution center. It eliminates the need for a key-distribution center.
118.Which type of network is more likely to include Frame Relay, Switched Multi-megabit Data Services (SMDS), and X.25?
121.Match the correct network connection speed to the correct standard. a:802.11 b:802.11b c:802.11g 1.1 & 2 Mbps2.4 & 8 Mbps3.11 Mbps4.54 Mbps
123.MAC (Media Access Control) and LLC (Logical Link Control) have been designated to which layer by the IEEE
124.____ is when a layer 3 packet is modified to fit into a layer 2 network with different characteristics.
128.Use the unique response from a given system to identify the operating system running on a host is also known as _____.
132.A system where a user authenticates, is disconnected, and the receiving system connects back to a number in a pre-defined database is also known as which?
135.RFC 1918 extended IPv4 with the introduction of non-routable addresses in support of which technology below?
The version of the operating system, which is operating on the work station, that provides information security services.
Each step can be completed and finalized without any effect from the later stages that may require rework.
139.What can best be described as an abstract machine which it must mediate all access of subjects to objects?
140.Which provides a physical connection between the network cabling and the computer’s internal bus?
141.What is defined as the hardware, firmware and software elements of a trusted computing base that implement the reference monitor concept?
145.Referential integrity requires that for any foreign key attribute, the referenced relation must have a tuple with the same value for which of the following?
146.What type of malware is self-contained and it does not need to be part of another computer program to propagate?
148.What type of malware that is capable of infect a file with an encrypted copy of itself, then modify itself when decoded to make almost impossible to detect by signature-based virus scanner?
150.Which of the following is a reasonable response from the intrusion detection system when it detects Internet Protocol (IP) packets where the IP source address is the same as the IP destination address?
152.Which of the following can be identified when exceptions occur using operations security detective controls?
153.An access system that grants users only those rights necessary for them to perform their work is operating on follows which security principle?
Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Layer Based Access Protocol (LBAP).
Role Based Access Control (RBAC), Layer Based Access Protocol (LBAP), and Target Based Access Protocol (TBAP).
andatory Access Control (MAC), Layer Based Access Protocol (LBAP), and Target Based Access Protocol (TBAP)
Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Role Based Access Control (RBAC)
155.When a communication link is subject to monitoring, what is the advantage for using an end-to-end encryption solution over link encryption solution?
159.When establishing a violation tracking and analysis process, which one of the following parameters is used to keep the quantity of data to manageable levels?
160.The accounting branch of a large organization requires an application to process expense vouchers. Each voucher must be input by one of many accounting clerks, verified by the clerk’s applicable supervisor, then reconciled by an auditor before the reimbursement check is produced. What access control technique should be built into the application to meet the information protection needs?
163.Which protocol makes use of an electronic wallet on a customer's PC and sends encrypted credit card information to merchant's Web server, which digitally signs it and sends it on to its processing bank?
165.Which of the following identifies the encryption algorithm selected by NIST for the new Advanced Encryption Standard (AES)?
167.Which type of attack is based on the probability of two different messages using the same hash function producing a common message digest?
174.A public key algorithm that does both encryption and digital signature is which of the following?
Diffie-Hellman gets its strength from the complexity of factoring the product of two large prime numbers
187.When an organization is determining which data is sensitive, it must consider all of the following except:
190.Which choice below most accurately describes the organization’s responsibilities during an unfriendly termination?
The immediate implementation of all requested changes so as to assure ultimate customer satisfaction.
Procedures that restore a system and its data in a trusted manner after the system was disrupted or a system failure occurred.
The system, TCB, and user objects may remain in an inconsistent state while the system attempts to recover itself
203.Which of the following questions is less likely to help in assessing physical and environmental protection?
Are there processes to ensure that unauthorized individuals cannot read, copy, alter, or steal printed or electronic information?
204.Security guards are appropriate whenever the function required by the security program involves which of the following?
205.______ communications rely on clocking systems at the sending and receiving ends to sync, rather than stop and start bits
209.Which security measure would be the best deterrent to the theft of corporate information from a laptop which was left in a hotel room?
Halon is commonly used because it is highly effective in the fact that it interferes with the chemical combustion of the elements within a fire.
214.When handling electronic evidence, what is the implementation principle for chain of custody that documents the evidence life cycle?
215.Which of the following is a proximity identification device that does not require action by the user and works by responding with an access code to signals transmitted by a reader?
218.The ideal operating humidity range is defined as 40 percent to 60 percent. Low humidity (less than 40 percent) can produce what type of problem on computer parts?
Is the operating system configured to prevent circumvention of the security software and application controls?
221.The National Institute of Standards and Technology (NIST) standard pertaining to perimeter protection states that critical areas should be illuminated up to?
224.Which of the following asymmetric encryption algorithm is based on the difficulty of factoring large numbers?
225.Under what conditions would the use of a Class C fire suppression system be preferable to the use of a Class A fire suppression system
A brief section on incident and risk assessment covering all the organization's key business activities
A detailed section on incident and risk assessment covering all the organization's business activities.
A detailed section on incident and risk assessment covering all the organization's key business activities.
228.What should take place in order to restore a server, its files and data after a major system failure?
229.It is recommended that your disaster recovery plan (DRP) and business continuity plan (BCP) be tested at a minimum of what intervals?
230.In addition to preventing loss of life and further injury, what other reason is there to immediately initiate an emergency plan after a disaster?
231.When shopping for an off-site backup facility that will ultimately be used to store all your backup media, what is the most important factor to consider?
Operations are shifted to the emergency site and senior management reviews the plan on a line item by line item basis
Government agencies may not use data for a purpose other than that for which it was initially collected
245.What is the minimum and customary practice of responsible protection of assets that affects a community or societal norm?
The sender must encrypt the message with his/her private key so the receiver can decrypt it with her/his public key
250.What are the objectives of emergency actions taken at the beginning stage of a disaster? Preventing injuries, loss of life, and ...