
[Dec-2021] CISSP Exam Dumps - Free Demo & 365 Day Updates
Free Sales Ending Soon - Use Real CISSP PDF Questions
How to Prepare for CISSP exam: Certified Information Systems Security Professional
Preparation Guide for CISSP exam: Certified Information Systems Security Professional
Introduction to CISSP exam: Certified Information Systems Security Professional
The CISSP test is important for the ISC Institute Certification. This test estimates your capacity in researching Cyber Crimes and working ordinarily against noxious programmers following Digital Evidence to arraign Cyber Criminals. Ensured Information Systems Security Professional - CISSP test is an expert confirmation that actions your abilities to achieve progressed tasks to battle malignant programmers. This confirmation test is a first class approach to exhibit your insight, advance your vocation and become an individual from a local area of network safety world. It shows you have everything necessary to configuration, specialist, execute and run a data security program. The competitors ought to likewise have a solid arrangement over hacking assaults and they ought to appropriately separating proof to report the wrongdoing and direct reviews to forestall future assaults getting little and huge undertaking.
The certificate is ideal for those working in jobs, for example, Security Consultant, Security Analyst, Security Manager, IT Director/Manager, Network Architect, Director of Security, Security Auditor, Security Architect, Security Systems Engineer, Chief Information Security Officer. The crowd ordinarily incorporates spies, strategy man, execution advisors, security group leads and venture directors, police and other law implementation staff, Defense and Military work force, Systems executives, Banking, Insurance and different experts, Government offices and IT administrators. The Web Simulator with a ISC CISSP practice tests and ISC CISSP practice exams will help you in audit, invigorate and extend your data security information (counting data security ideas and industry best practices). The CISSP Exam is an extremely confounded test and its span depends on 3 Hours with 100-150 Questions to be replied.
NEW QUESTION 24
Which of the following is a characteristic of the independent testing of a program?
- A. Independent testing increases the likelihood that a test will expose the effect of a hidden feature.
- B. Independent testing teams help identify functional requirements and Service Level Agreements (SLA)
- C. Independent testing teams help decrease the cost of creating test data and system design specification.
- D. Independent testing decreases the likelihood that a test will expose the effect of a hidden feature.
Answer: A
NEW QUESTION 25
In the public sector, as opposed to the private sector, due care is usually determined by
- A. Potential for litigation.
- B. Minimum standard requirements.
- C. Insurance rates.
- D. Legislative requirements.
Answer: D
NEW QUESTION 26
The RSA algorithm is an example of what type of cryptography?
- A. Symmetric Key.
- B. Private Key.
- C. Secret Key.
- D. Asymmetric Key.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
RSA is a public key algorithm that is an example of asymmetric key algorithms. RSA is used for encryption, digital signatures, and key distribution.
Incorrect Answers:
B: RSA is not an example of symmetric key algorithms.
C: Secret Key cryptography is an encryption system where a common key is used to encrypt and decrypt the message. This is not the case in RSA.
D: RSA uses Private Keys for decryption, but it is not an example of Private Key cryptography.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 815, 831
http://www.webopedia.com/TERM/S/symmetric_key_cryptography.html
NEW QUESTION 27
Which of the following BEST describes the purpose of performing security certification?
- A. To formalize the confirmation of completed risk mitigation and risk analysis
- B. To identify system threats, vulnerabilities, and acceptable level of risk
- C. To formalize the confirmation of compliance to security policies and standards
- D. To verify that system architecture and interconnections with other systems are effectively implemented
Answer: C
NEW QUESTION 28
Public Key Infrastructure (PKI) uses asymmetric key encryption between parties. The originator encrypts information using the intended recipient's "public" key in order to get confidentiality of the data being sent.
The recipients use their own "private" key to decrypt the information. The "Infrastructure" of this methodology ensures that:
- A. The recipient's identity can be positively verified by the sender.
- B. The sender and recipient have reached a mutual agreement on the encryption key exchange that they will use.
- C. The sender of the message is the only other person with access to the recipient's private key.
- D. The channels through which the information flows are secure.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
When information is encrypted using a public key, it can only be decrypted by using the associated private key. As the recipient is the only person with the private key, the recipient is the only person who can decrypt the message. This provides a form of authentication in that the recipient's identity can be positively verified by the sender. If the receiver replies to the message, the sender knows that the intended recipient received the message.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 784-785
NEW QUESTION 29
Which of the following cloud deployment model is provisioned for open use by the general public?
- A. Community Cloud
- B. Hybrid Cloud
- C. Private Cloud
- D. Public Cloud
Answer: D
Explanation:
In Public cloud, the cloud infrastructure is provisioned for open use by the general public. It may be owned, managed, and operated by a business, academic, or government organization, or some combination of them. It exists on the premises of the cloud provider.
For your exam you should know below information about Cloud Computing deployment models:
Private cloud The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by the organization, a third party, or some combination of them,and it may exist on or off premises.
Private Cloud
Image Reference - http://www.inflectionpoint.co.uk/Portals/5/VMware-vCloud.jpg
Community Cloud
The cloud infrastructure is provisioned for exclusive use by a specific community of consumers
from organizations that have shared concerns (e.g., mission,security requirements, policy, and
compliance considerations). It may be owned, managed, and operated by one or more of the
organizations in the community, a third party, or some combination of them, and it may exist on or
off premises.
Community Cloud
Image Reference - http://cloudcomputingksu.files.wordpress.com/2012/05/community-cloud.png
Public Cloud
The cloud infrastructure is provisioned for open use by the general public. It may be owned,
managed, and operated by a business, academic, or government organization, or some
combination of them. It exists on the premises of the cloud provider.
Public Cloud
Image reference - http://definethecloud.files.wordpress.com/2010/04/image3.png
Hybrid cloud
The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private,
community, or public) that remain unique entities, but are bound together by standardized or
proprietary technology that enables data and application portability (e.g., cloud bursting for load
balancing between clouds)
hybrid cloud
Image reference - http://www.virtualizationpractice.com/wp-content/uploads/2013/04/Hybrid-
Cloud-Computing-Solution1.jpg
The following answers are incorrect:
Private cloud - The cloud infrastructure is provisioned for exclusive use by a single organization
comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by
the organization, a third party, or some combination of them,and it may exist on or off premises.
Community cloud - The cloud infrastructure is provisioned for exclusive use by a specific
community of consumers from organizations that have shared concerns (e.g., mission,security
requirements, policy, and compliance considerations). It may be owned, managed, and operated
by one or more of the organizations in the community, a third party, or some combination of them,
and it may exist on or off premises.
Hybrid cloud - The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds)
The following reference(s) were/was used to create this question: CISA review manual 2014 page number 102 Official ISC2 guide to CISSP 3rd edition Page number 689 and 690
NEW QUESTION 30
According to the Minimum Security Requirements (MSR) for Multi-User Operating Systems (NISTIR 5153) document, which of the following statements pertaining to audit data recording is incorrect?
- A. The system shall protect the security audit trail from unauthorized access
- B. For maintenance purposes, it shall be possible to disable the recording of activities that require privileges.
- C. The system shall provide end-to-end user accountability for all security-relevant events
- D. The system should support an option to maintain the security audit trail data in encrypted format
Answer: B
NEW QUESTION 31
Which of the following is NOT a component of configuration
management?
- A. Configuration status accounting
- B. Configuration audit
- C. Configuration control
- D. Configuration review
Answer: D
Explanation:
The correct answer is "Configuration review", a distracter.
*Answer configuration control involves controlling changes to configuration items and
issuingversions of configuration items from the software library.
*Configuration status accountingis the processing of changes.
* Configuration audit is the process of controlling the quality of configuration management procedures.
NEW QUESTION 32
Which of the following BEST describes an access control method utilizing cryptographic keys derived from a smart card private key that is embedded within mobile devices?
- A. Temporary security credential
- B. Mobile device credentialing service
- C. Derived credential
- D. Digest authentication
Answer: C
NEW QUESTION 33
Detective/Technical measures:
- A. do not include intrusion detection systems and automatically-generated violation reports from audit trail information.
- B. include intrusion detection systems and automatically-generated violation reports from audit trail information.
- C. include intrusion detection systems and customised-generated violation reports from audit trail information.
- D. include intrusion detection systems but do not include automatically-generated violation reports from audit trail information.
Answer: B
Explanation:
Detective/Technical measures include intrusion detection systems and automatically-generated violation reports from audit trail information. These reports can indicate variations from "normal" operation or detect known signatures of unauthorized access episodes. In order to limit the amount of audit information flagged and reported by automated violation analysis and reporting mechanisms, clipping levels can be set.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 35
NEW QUESTION 34
Who should DECIDE how a company should approach security and what security measures should be implemented?
- A. Auditor
- B. The information security specialist
- C. Senior management
- D. Data owner
Answer: C
Explanation:
They are responsible for security of the organization and the protection of its assets.
The following answers are incorrect because :
Data owner is incorrect as data owners should not decide as to what security measures should be
applied.
Auditor is also incorrect as auditor cannot decide as to what security measures should be applied.
The information security specialist is also incorrect as they may have the technical knowledge of
how security measures should be implemented and configured , but they should not be in a
position of deciding what measures should be applied.
Reference : Shon Harris AIO v3 , Chapter-3: Security Management Practices , Page : 51.
NEW QUESTION 35
Internet Protocol (IP) source address spoofing is used to defeat
- A. Transmission Control Protocol (TCP) hijacking.
- B. Reverse Address Resolution Protocol (RARP).
- C. Address Resolution Protocol (ARP).
- D. address-based authentication.
Answer: D
NEW QUESTION 36
Which choice below denotes a packet-switched connectionless wide area network (WAN) technology?
- A. ATM
- B. X.25
- C. Frame Relay
- D. SMDS
Answer: D
Explanation:
Switched Multimegabit Data Service (SMDS) is a high-speed, connectionless, packet-switching public network service that extends LAN-like performance to a metropolitan area network (MAN) or a wide area network (WAN). It's generally delivered over a SONET ring with a maximum effective service radius of around 30 miles.
*X.25, defines an interface to the first commercially successful connection-oriented
packet-switching network, in which the packets travel over virtual
circuits.
*Frame Relay, was a successor to X.25, and offers a connection-oriented packet-switching
network.
*Asynchronous Transfer Mode (ATM), was developed from an outgrowth of ISDN
standards, and is fast-packet, connection-oriented, cell-switching technology.
Source: Communications Systems and Networks by Ray Horak
(M&T Books, 2000).
NEW QUESTION 37
Which of the following was the first mathematical model of a multilevel security policy used to define the concepts of a security state and mode of access, and to outline rules of access?
- A. Clark-Wilson
- B. Bell-LaPadula
- C. Biba
- D. State machine
Answer: B
Explanation:
This is a formal definition of the Bell-LaPadula model, which was created and implemented to protect confidential government and military information.
In the 1970s, the U.S. military used time-sharing mainframe systems and was concerned about the security of these systems and leakage of classified information. The Bell-LaPadula model was developed to address these concerns.
It was the first mathematical model of a multilevel security policy used to define the concept of a secure state machine and modes of access, and outlined rules of access. Its development was funded by the U.S. government to provide a framework for computer systems that would be used to store and process sensitive information.
The model's main goal was to prevent secret information from being accessed in an unauthorized manner. A system that employs the Bell-LaPadula model is called a multilevel security system because users with different clearances use the system , and the system processes data at different classification levels.
The level at which information is classified determines the handling procedures that should be used. The Bell-LaPadula model is a state machine model that enforces the confidentiality aspects of access control. A matrix and security levels are used to determine if subjects can access different objects. The subject's clearance is compared to the object's classification and then specific rules are applied to control how subject-to-object interactions can take place.
The following answers are incorrect: Biba - The Biba model was developed after the Bell -LaPadula model. It is a state machine model similar to the Bell-LaPadula model. Biba addresses the integrity of data within applications. The Bell-LaPadula model uses a lattice of security levels (top secret, secret, sensitive, and so on). These security levels were developed mainly to ensure that sensitive data were only available to authorized individuals. The Biba model is not concerned with security levels and confidentiality, so it does not base access decisions upon this type of lattice. Instead, the Biba model uses a lattice of integrity levels.
Clark-Wilson - When an application uses the Clark -Wilson model, it separates data into one subset that needs to be highly protected, which is referred to as a constrained data item (CDI), and another subset that does not require a high level of protection, which is called an unconstrained data item (UDI). Users cannot modify critical data (CDI) directly. Instead, the subject (user) must be authenticated to a piece of software, and the software procedures (TPs) will carry out the operations on behalf of the user. For example, when Kathy needs to update information held within her company's database, she will not be allowed to do so without a piece of software controlling these activities. First, Kathy must authenticate to a program, which is acting as a front end for the database, and then the program will control what Kathy can and cannot do to the information in the database. This is referred to as access triple: subject (user), program (TP), and object (CDI). A user cannot modify CDI without using a TP.
State machine - In state machine models, to verify the security of a system, the state is used , which means that all current permissions and all current instances of subjects accessing objects must be captured. Maintaining the state of a system deals with each subject's association with objects. If the subjects can access objects only by means that are concurrent with the security policy, the system is secure. A state of a system is a snapshot of a system at one moment of time. Many activities can alter this state, which are referred to as state transitions. The developers of an operating system that will implement the state machine model need to look at all the different state
transitions that are possible and assess whether a system that starts up in a secure state can be
put into an insecure state by any of these events. If all of the activities that are allowed to happen
in the system do not compromise the system and put it into an insecure state, then the system
executes a secure state machine model.
The following reference(s) were/was used to create this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 369, 372-374, 367).
McGraw-Hill . Kindle Edition.
NEW QUESTION 38
Which choice describes the Forest Green Book?
- A. It is a Rainbow series book that defines guidelines for implementing access control lists.
- B. It is a Rainbow series book that defines the secure handling of storage media.
- C. It does not exist; there is no Forest Green Book.
- D. It is a tool that assists vendors in data gathering for certifiers.
Answer: B
Explanation:
The Forest Green book is a Rainbow series book that defines the secure handling of sensitive or classified automated information system memory and secondary storage media, such as degaussers, magnetic tapes, hard disks, floppy disks, and cards. The Forest Green book details procedures for clearing, purging, declassifying, or destroying automated information system (AIS) storage media to prevent data remanence. Data remanence is the residual physical representation of data that has been erased in some way. After storage media is erased there may be some physical characteristics that allow data to be reconstructed.
*Answer "It is a tool that assists vendors in data gathering for certifiers." is the Blue Book, NCSCTG-019 Trusted Product Evaluation Questionnaire Version-2. The Blue book is a tool to assist system developers and vendors in gathering data to assist evaluators and certifiers assessing trusted computer systems.
*Answer "It is a Rainbow series book that defines guidelines for implementing access control lists." is the Grey/Silver Book, NCSC-TG-020A, the Trusted UNIX Working Group (TRUSIX) Rationale for Selecting Access Control. The Grey/Silver book defines guidelines for implementing access control lists (ACLs) in the UNIX system. Source: NCSC-TG025 A Guide to Understanding Data Remanence in Automated Information Systems, NCSC-TG-020A Trusted UNIX Working Group (TRUSIX) Rationale for Selecting Access Control, and NCSC-TG-019 Trusted Product Evaluation Questionnaire Version-2.
NEW QUESTION 39
Which of the following is the marriage of object-oriented and relational technologies combining the attributes of both?
- A. object-management database
- B. object-relational database
- C. object-linking database
- D. object-oriented database
Answer: B
NEW QUESTION 40
......
CISSP Dumps - Pass Your Certification Exam: https://www.braindumpsit.com/CISSP_real-exam.html
Latest Real ISC CISSP Exam Dumps Questions: https://drive.google.com/open?id=1N-WdTqtuIN51vbNDd2fd9ECu3aaBMN2Z