ISC CISSP Practice Test Pdf Exam Material
CISSP Answers CISSP Free Demo Are Based On The Real Exam
NEW QUESTION # 756
In a wireless General Packet Radio Services (GPRS) Virtual Private Network (VPN) application, which of the following security protocols is
commonly used?
- A. IPSEC
- B. WTP
- C. SSL
- D. TLS
Answer: A
Explanation:
An example is the use of a GPRS-enabled laptop that connects to a corporate intranet via a VPN. The laptop is given an IP address and a RADIUS server authenticates the user. IPSEC is used to create the VPN. As background, GPRS is a second-generation (2G) packet data technology that is overlaid on existing Global System for Mobile communications (GSM). GSM is the wireless analog of the ISDN landline system. The key features of GPRS are that it is always on line (no dial-up needed), existing GSM networks can be upgraded with GPRS, and it can serve as the packet data core of third generation (3G) systems.
Answers SSL and TLS are similar security protocols that are used on the Internet side of the Wireless Application Protocol (WAP) Gateway.
For answer WTP is the Wireless Transaction Protocol that is part of the WAP suite of protocols. WTP is a lightweight, message-oriented, transaction protocol that provides more reliable connections than UDP, but does not have the robustness of TCP.
NEW QUESTION # 757
Refer to the information below to answer the question.
An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles.
When determining appropriate resource allocation, which of the following is MOST important to monitor?
- A. Number of system compromises
- B. Number of additional assets
- C. Number of staff reductions
- D. Number of audit findings
Answer: D
NEW QUESTION # 758
The Advanced Encryption Standard (Rijndael) block cipher
requirements regarding keys and block sizes have now evolved to
which configuration?
- A. Both the key and block sizes can be 128, 192, and 256 bits each.
- B. The key size is 128 bits, and the block size can be 128, 192, or 256 bits.
- C. The block size is 128 bits, and the key can be 128, 192, or 256 bits.
- D. The block size is 128 bits, and the key size is 128 bits.
Answer: C
Explanation:
AES is comprised of the three key sizes, 128, 192, and 256 bits with
a fixed block size of 128 bits. The Advanced Encryption Standard
(AES) was announced on November 26, 2001 , as Federal Information
Processing Standard Publication (FIPS PUB 197). FIPS PUB 197 states
that This standard may be used by Federal departments and agencies
when an agency determines that sensitive (unclassified) information
(as defined in P.L. 100-235) requires cryptographic protection.
Other FIPS-approved cryptographic algorithms may be used in addition
to, or in lieu of, this standard. Depending upon which of the
three keys is used, the standard may be referred to as AES-128,
AES-192 or AES-256.
The number of rounds used in the Rijndael cipher is a function of
the key size as follows:
256-bit key 14 rounds
192-bit key 12 rounds
128-bit key 10 rounds
Rijndael has a symmetric and parallel structure that provides for
flexibility of implementation and resistance to cryptanalytic attacks.
Attacks on Rijndael would involve the use of differential and linear
cryptanalysis.
NEW QUESTION # 759
Primary storage is the:
- A. Memory used in conjunction with real memory to present a CPU with a larger, apparent address space.
- B. Memory, such as magnetic disks, that provide non-volatile storage.
- C. Memory where information must be obtained by sequentially searching from the beginning of the memory space.
- D. Memory directly addressable by the CPU, which is for the storage of instructions and data that are associated with the program being executed.
Answer: D
Explanation:
*Answer "Memory, such as magnetic disks, that provide non-volatile storage" refers to secondary storage.
*Answer "Memory used in conjunction with real memory to present a CPU with a larger, apparent address space" refers to virtual memory, and answer "Memory where information must be obtained by sequentially searching from the beginning of the memory space" refers to sequential memory.
NEW QUESTION # 760
Which of the following is an indicator that a company's new user security awareness training module has been effective?
- A. There are more secure connections to the internal database servers.
- B. More incidents of phishing attempts are being reported.
- C. There are more secure connections to internal e-mail servers.
- D. Fewer incidents of phishing attempts are being reported.
Answer: B
NEW QUESTION # 761
Which of the following is the FINAL step when implementing an information security awareness program?
- A. Collect feedback from staff
- B. Measure the effectiveness
- C. Identify areas not covered for future programs
- D. Ensure that the target audience has received training
Answer: A
NEW QUESTION # 762
Who would be the BEST person to approve an organizations information security policy?
- A. Chief Information Security Officer (CISO)
- B. Chief Information Officer (CIO)
- C. Chief Executive Officer (CEO)
- D. Chief internal auditor
Answer: A
NEW QUESTION # 763
Refer to the information below to answer the question.
In a Multilevel Security (MLS) system, the following sensitivity labels are used in increasing levels of sensitivity: restricted, confidential, secret, top secret. Table A lists the clearance levels for four users, while Table B lists the security classes of four different files.
In a Bell-LaPadula system, which user cannot write to File 3?
- A. User A
- B. User B
- C. User C
- D. User D
Answer: D
NEW QUESTION # 764
The ISO/IEC 27001:2005 is a standard for:
- A. Information Security Management System
- B. Implementation and certification of basic security measures
- C. Evaluation criteria for the validation of cryptographic algorithms
- D. Certification of public key infrastructures
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The ISO 27000 Directory at: http://www.27000.org/index.htm has great coverage of the ISO 27000 series.
The text below was extracted from their website.
As mention by Belinda the ISO 27001 standard is the certification controls criteria while ISO 27002 is the actual standard. ISO 27002 used to be called ISO 17799 before being renamed.
The ISO 27001 standard was published in October 2005, essentially replacing the old BS7799-2 standard.
It is the specification for an ISMS, an Information Security Management System. BS7799 itself was a long standing standard, first published in the nineties as a code of practice. As this matured, a second part emerged to cover management systems. It is this against which certification is granted. Today in excess of a thousand certificates are in place, across the world.
ISO 27001 enhanced the content of BS7799-2 and harmonized it with other standards. A scheme has been introduced by various certification bodies for conversion from BS7799 certification to ISO27001 certification.
The objective of the standard itself is to "provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an Information Security Management System".
Regarding its adoption, this should be a strategic decision. Further, "The design and implementation of an organization's ISMS is influenced by their needs and objectives, security requirements, the process employed and the size and structure of the organization".
The standard defines its 'process approach' as "The application of a system of processes within an organization, together with the identification and interactions of these processes, and their management". It employs the PDCA, Plan-Do-Act model to structure the processes, and reflects the principles set out in the OECG guidelines (see oecd.org).
THE CONTENTS OF ISO 27001
The content sections of the standard are:
Context Of The Organization
Information Security Leadership
Planning An ISMS
Support
Operation
Performance Evaluation
Improvement
Annex A - List of controls and their objectives
The ISO 27002 standard is the rename of the ISO 17799 standard, and is a code of practice for information security. It basically outlines hundreds of potential controls and control mechanisms, which may be implemented, in theory, subject to the guidance provided within ISO 27001.
The standard "established guidelines and general principles for initiating, implementing, maintaining, and improving information security management within an organization". The actual controls listed in the standard are intended to address the specific requirements identified via a formal risk assessment. The standard is also intended to provide a guide for the development of "organizational security standards and effective security management practices and to help build confidence in inter-organizational activities".
The basis of the standard was originally a document published by the UK government, which became a standard 'proper' in 1995, when it was re-published by BSI as BS7799. In 2000 it was again re-published, this time by ISO, as ISO 17799. A new version of this appeared in 2005, along with a new publication, ISO
27001. These two documents are intended to be used together, with one complimenting the other.
ISO's future plans for this standard are focused largely around the development and publication of industry specific versions (for example: health sector, manufacturing, and so on). Note that this is a lengthy process, so the new standards will take some time to appear
THE CONTENTS OF ISO 17799 / 27002
The content sections are:
Structure
Risk Assessment and Treatment
Security Policy
Organization of Information Security
Asset Management
Human Resources Security
Physical Security
Communications and Ops Management
Access Control
Information Systems Acquisition, Development, Maintenance
Information Security Incident management
Business Continuity
Compliance
References:
http://www.iso.org/iso/catalogue_detail?csnumber=42103
http://www.27000.org/index.htm
NEW QUESTION # 765
Which of the following is a common term for log reviews, synthetic transactions, and code reviews?
- A. Security control testing
- B. Spiral development functional testing
- C. Application development
- D. DevOps Integrated Product Team (IPT) development
Answer: A
Explanation:
Security control testing is a common term for various methods of assessing the effectiveness and compliance of security controls in an information system. Log reviews, synthetic transactions, and code reviews are examples of security control testing techniques that can be used to verify the functionality, performance, and security of an application or system. Log reviews involve analyzing the records of events and activities that occurred in an information system, such as user actions, system errors, or security incidents. Synthetic transactions are simulated user interactions with an application or system that are designed to test its functionality and performance under different scenarios and conditions. Code reviews are inspections of the source code of an application or system that are performed to identify errors, vulnerabilities, or deviations from best practices. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 10: Security Assessment and Testing, pp. 1015-1016; [Official (ISC)2 CISSP CBK Reference, Fifth Edition], Domain 6:
Security Assessment and Testing, pp. 1019-1020.
NEW QUESTION # 766
Which Orange book security rating introduces security labels?
- A. B2
- B. C2
- C. B3
- D. B1
Answer: D
Explanation:
Class (B1) or "Labeled Security Protection" systems require all the features required for class (C2). In addition, an informal statement of the security policy model, data labeling, and mandatory access control over named subjects and objects must be present.
The capability must exist for accurately labeling exported information. Any flaws identified by testing must be removed.
NEW QUESTION # 767
RAID Software can run faster in the operating system because neither use the hardware-level parity drives by?
- A. Simple striping or mirroring.
- B. Simple striping or hamming code parity.
- C. Simple hamming code parity or mirroring.
- D. Hard striping or mirroring.
Answer: A
Explanation:
This is true, if we do not use parity in our RAID implementation, like RAID 1 (Mirroring) or RAID 0 (Stripping) we can improve performance because the CPU does not need waste cycles to make the parity calculations. For example this can be achieved in Windows 2000 server through the use of RAID 0 (No fault tolerance, just stripping in 64kb chunks) or RAID 1 (Mirroring through a file system driver). This is not the case of RAID 5 that actually use parity to provide fault tolerance.
NEW QUESTION # 768
What High Availability (HA) option of database allow multiple clients to access multiple database servers simultaneously?
- A. Relational database
- B. Non-Structured Query Language (NoSQL) database
- C. Shadow database
- D. Replicated database
Answer: D
Explanation:
Database Replication mirrors a live database, allowing simultaneous reads and writes by clients to multiple replicated databases.
NEW QUESTION # 769
Which of the following is the BEST way to protect against Structured Query language (SQL) injection?
- A. Use stored procedures.
- B. Enforce boundary checking.
- C. Ratfrict um of SELECT command.
- D. Restrict HyperText Markup Language (HTML) source code
Answer: A
NEW QUESTION # 770
In which OSI layer does the MIDI digital music protocol standard reside?
- A. Presentation Layer
- B. Application Layer
- C. Session Layer
- D. Transport Layer
Answer: A
Explanation:
The correct answer is Presentation Layer. MIDI is a Presentation layer protocol.
NEW QUESTION # 771
Rotating password can be restricted by the use of:
- A. All of the choices
- B. Complex password
- C. Password history
- D. Password age
Answer: C
Explanation:
Passwords must be changed at least once every 60 days (depending on your environment).
Password aging or expiration must be enforced on all systems. Upon password expiration,
if the password is not changed, only three grace logins must be allowed then the
account must be disable until reset by an administrator or the help desk. Password
reuse is not allowed (rotating passwords).
NEW QUESTION # 772
Which part of the 48-bit, 12-digit hexadecimal number known as the
Media Access Control (MAC) address identifies the manufacturer of the
network device?
- A. The last three bytes
- B. The first two bytes
- C. The first three bytes
- D. The second half of the MAC address
Answer: C
Explanation:
The first three bytes (or first half) of the six-byte MAC address is the manufacturer's identifier (see
Table). This can be a good troubleshooting aid if a network device is acting up, as it will isolate the
brand of the failing device. The other answers are distracters. Source:
Mastering Network Security by Chris Brenton (Sybex, 1999).
NEW QUESTION # 773
Network-based Intrusion Detection systems:
- A. commonly reside on a discrete network segment and does not monitor the traffic on that network segment.
- B. commonly reside on a discrete network segment and monitor the traffic on that network segment.
- C. commonly will not reside on a discrete network segment and monitor the traffic on that network segment.
- D. commonly reside on a host and monitor the traffic on that specific host.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A network - based IDS (Intrusion Detection systems) watches for questionable activity occurring on the network medium by inspecting packets and observing network traffic patterns.
Incorrect Answers:
B: The networked-based ISD must be present on the network segment it is monitoring.
C: The purpose of an Intrusion Detection system is to monitor the traffic.
D: A host-based, not a network-based, IDS watches for questionable activity on a single computer system.
References:
Stewart, James M., Ed Tittel, and Mike Chapple, CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition, Sybex, Indianapolis, 2011, p. 54
NEW QUESTION # 774
Which term below BEST describes the concept of least privilege?
- A. A formal separation of command, program, and interface functions.
- B. Active monitoring of facility entry access points.
- C. A combination of classification and categories that represents the sensitivity of information.
- D. Each user is granted the lowest clearance required for their tasks.
Answer: D
Explanation:
The least privilege principle requires that each subject in a system be granted the most restrictive set of privileges (or lowest clearance) needed for the performance of authorized tasks. The application of this principle limits the damage that can result from accident, error, or unauthorized use. Applying this principle may limit the damage resulting from accidents, errors, or unauthorized use of system resources. *Answer "A formal separation of command, program, and interface functions." describes separation of privilege, which is the separation of functions, namely between the commands, programs, and interfaces implementing those functions, such that malicious or erroneous code in one function is prevented from affecting the code or data of another function. *Answer "A combination of classification and categories that represents the sensitivity of information." is a security level. A security level is the combination of hierarchical classification and a set of non-hierarchical categories that represents the sensitivity of information. *Answer "Active monitoring of facility entry access points." is a distracter. Source: DoD 5200.28STD Department of Defense Trusted Computer System Evaluation Criteria.
NEW QUESTION # 775
Which of the following is immune to the effects of electromagnetic interference (EMI) and therefore has a much longer effective usable length?
- A. Coaxial cable
- B. Twisted Pair cable
- C. Axial cable
- D. Fiber Optic cable
Answer: D
Explanation:
Fiber Optic cable is immune to the effects of electromagnetic interference (EMI) and therefore has a much longer effective usable length (up to two kilometers in some cases). Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 72.
NEW QUESTION # 776
An organization adopts a new firewall hardening standard. How can the security professional verify that the technical staff correct implemented the new standard?
- A. Perform a penetration test
- B. Survey the technical staff
- C. Train the technical staff
- D. Perform a compliance review
Answer: D
Explanation:
Section: Security Operations
NEW QUESTION # 777
......
CISSP [Nov-2025] Newly Released] Exam Questions For You To Pass: https://www.crampdf.com/CISSP-exam-prep-dumps.html
ISC CISSP Exam: Basic Questions With Answers: https://drive.google.com/open?id=1_LdHsm9QDC_JJg8kz-YwtUMkV2Tyjgcb