A corporation is considering a best authentication method for access control, which of the following method has the best authentication strength?
A security engineer is evaluating methods to store user passwords in an information system. What may be the best method for storing user passwords and meeting the confidentiality security objective?
What is the minimum and customary practice that constitutes “ responsible protection of information assets that affects a community or societal norm”?
A timely review of system access records would be an example of what type of basic security function?
What type of access control is implemented where a database administrator can grant “Update” privilege in a database to specific users or group?
A practicing CISSP may face an ethical conflict between his/her company’s interestsand the (ISC)2 Code of Ethics. According to the (ISC)2 Code of Ethics in which order of priority should ethical conflicts be resolved?
Company X is planning to implement rule based access control mechanism for controlling access to its information assets. What type of access control is this usually related to?
What security implementation principle is used for granting users only the rights that are necessary for them to perform their work?
As an information systems security manager (ISSM), how would you explain the purpose a system security policy?
A set of brief, high-level statements that defines what is and is not permitted during the operation of the system
In addition to ensure changes to the computer system taking place in an identifiable and controlled manner; configuration management provides assurance that changes...
In addition to performing cryptographic operation, w hat is another reason for using a symmetric key cryptography?
What type of crypto-analytical attack where an adversary has least amount of information to work with?
Company X is building a data center, what may be the most effective method for reducing security risks associated with building entrances?
When disposing magnetic storage media, all of the following methods ensure that data is unreadable except...
Prior to installation of an intrusion prevention system (IPS), a network engineer usually place packet sniffers on the network, what is the purpose for using a packet sniffer?
Which of the following is a reasonable response from an intrusion detection system (IDS) when it detects Internet Protocol (IP) packets where the source address is the same as the destination address?
As a security manager, how would you explain the primary goal of a security awareness program to senior management?
When engaging an external contractor for a software development project, source code escrow can be used to protect against...
All of the followings are goals for change control management process except ensuring the changes are... (
What type of access control where the security clearance of a subject must match the security classification of an object
Which of the following fire suppression system suppresses a Class C fire without harming the earth’s ozone?
When a communication link is subjected to monitoring, what is the advantage for using an end-to-end encryption solution over link encryption solution?
Senior management organizational structure, message distribution standards, and procedures for the operation of security management systems.
Disaster recovery and business continuity planning, and definition of access control requirements and human resources policies.
Security policy implementation, assignment of roles and responsibilities, and information asset classification.
Business impact, threat and vulnerability analysis, delivery of an information security awareness program, and physical security of key installations.
What are the objectives of emergency actions taken at the beginning stage of a disaster? Preventing injuries, loss of life, and ...
When handling electronic evidence, what is the implementation principle for chain of custody that documents the evidence life cycle?
After signing out a laptop computer from the company loaner pool, you discovered there is a memorandum stored in the loaner laptop written to a competitor containing sensitive information about a new product your company is about to release. What is the ethical action you should take?
nform the security awareness trainers that data disclosure prevention in a mobile computing environment needs to be added to their classes.
Which of the following is the least important information to record when logging a security violation?
Which of the following device might be used to commit telecommunications fraud using the “shoulder surfing” technique?
Sender gets a digitally signed acknowledgment from the recipient containing a copy or digest of the message
Sender computes a digest of the message and sends it to a Trusted Third Party (TTP) who signs it and stores it for later reference
Sender sends the message to a TTP who signs it together with a time stamp and sends it on to the recipient.
The deliberate planting of apparent flaws in a system for the purpose of detecting attempted penetrations or confusing an intruder about which flaws to exploit is called.
The concept that all accesses must be mediated, protected from unauthorized modification, and verifiable as correct is implemented through what?
Programmed procedure that ensures valid transactions are processed accurately and only once in the current timescale, are referred to as...
During a disaster, how does a closed-circuit television (CCTV) help management and security to minimize loss?
Which of the following can be identified when exceptions occur using operations security detective controls?
When downloading software from Internet, why do vendors publish MD5 hash values when they provide software to customers?
Role Based Access Control (RBAC), Layer Based Access Protocol (LBAP), and Target Based Access Protocol (TBAP)
Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Layer Based Access Protocol (LBAP).
Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Role Based Access Control (RBAC)
Discretionary Access Control (DAC), Mandatory Access Control (MAC), and Layer Based Access Protocol (LBAP).
rom a legal perspective, which of the following rules must be addressed when investigating a computer crime? (
.Before powering off a computer system, the computer crime investigator should record the contents of the monitor and...
The growth of Internet e-mail has contributed to the widespread propagation of which of the following
Which of the following transaction processing properties ensures once a transaction completes successfully (commits), the updates survive even if there is a system failure?
Which of the following describes the step prior to an encrypted session using Data Encryption Standard (DES)?
The security planning process must define: how security will be managed, who will be responsible, and...
Monitoring of electromagnetic pulse emanations from personal computers (PCs) and cathode ray televisions (CRTs) provides a hacker with what significant advantage?
The practice of embedding a message in a document, image, video or sound recording so that its very existence is hidden is called...
What characteristic of Digital Encryption Standard (DES) used in Electronic Code Book (ECB) mode makes it unsuitable for long messages? (
Which of the following is an advantage of the Rivest, Shamir, Adelman (RSA) public key system over the Digital Signature Algorithm (DSA)?
What common attack can be used against a system that stores one-way encrypted passwords if a copy of the password file can be obtained? (
When securing Internet connections, which of the following should be used to protect internal routing and labeling schemes
When establishing a violation tracking and analysis process, which of the following parameter is used to keep the quantity of data to manageable levels?
The accounting branch of a large organization requires an application to process expense vouchers. Each voucher must be input by one of many accounting clerks, verified by the clerk’s applicable supervisor then reconciled by an auditor before the reimbursement check is produced. What access control technique should be built into the application to meet the information protection needs?
What security implementation principle recommends division of responsibilities so that one person cannot commit an undetected fraud?
Which type of communication should an investigator use so the hacker is not aware of an ongoing investigation?
Looting of computing assets in a data center after Hurricane Katrina is considered as what type of physical security threat?
Why does fiber optic communication technology have a significant security advantage over other transmission technology?
Trusted computing base (TCB) is comprised of what combination of system components? 1.Hardware.2.Firmware.3.Software.
When verifying security controls in a system design, the security specialist should ensure that the...
What type of cryptographic attack enables an attacker to discover the cryptographic key by selecting a series of plaintext and corresponding ciphertext?
Defining the acceptable level of risk the organization can tolerate, and assigning any costs associated with loss or disruption to a third party such as an insurance carrier.