Best Quality CISSP Exam Questions ISC Test To Gain Brilliante Result! [Q334-Q357]

Share

Best Quality CISSP Exam Questions  ISC Test To Gain Brilliante Result!

Preparations of CISSP Exam 2021 ISC Certification Unlimited 990 Questions

NEW QUESTION 334
Which choice does NOT describe an element of configuration
management?

  • A. Configuration management documents the functional and physical characteristics of each configuration item.
  • B. Configuration management involves information capture and version control.
  • C. Configuration management reports the status of change processing.
  • D. Configuration management is the decomposition process of a verification system into Configuration Items (CIs).

Answer: D

Explanation:
Configuration management is a discipline applying technical and administrative direction to: Identify and document the functional and physical characteristics of each configuration item for the system Manage all changes to these characteristics Record and report the status of change processing and implementation Configuration management involves process monitoring, version control, information capture, quality control, bookkeeping, and an organizational framework to support these activities. The configuration being managed is the verification system plus all tools and documentation related to the configuration process. Source: NCSC-TG-014-89, Guidelines for Formal Verification Systems [Purple Book].

 

NEW QUESTION 335
Which of the following provides effective management assurance for a Wireless Local Area
Network (WLAN)?

  • A. Establishing a Virtual Private Network (VPN) tunnel between the WLAN client device and a VPN concentrator
  • B. Verifying that all default passwords have been changed
  • C. Maintaining an inventory of authorized Access Points (AP) and connecting devices
  • D. Setting the radio frequency to the minimum range required

Answer: C

 

NEW QUESTION 336
A key schedule is:

  • A. A set of subkeys derived from a secret key
  • B. A list of cryptographic keys to be used at specified dates and times
  • C. Using distributed computing resources to conduct a brute force attack on a symmetric algorithm
  • D. A method of generating keys by the use of random numbers

Answer: A

Explanation:
The subkeys are typically used in iterated block ciphers. In this type of cipher, the plaintext is broken into fixed-length blocks and enciphered in rounds. In a round, the same transformation is applied using one of the subkeys of the key schedule.

 

NEW QUESTION 337
Which choice below is NOT an element of BCP plan approval and implementation?

  • A. Executing a disaster scenario and documenting the results
  • B. Obtaining senior management approval of the results
  • C. Updating the plan regularly and as needed
  • D. Creating an awareness of the plan

Answer: A

Explanation:
Answer "Executing a disaster scenario and documenting the results" is a distracter, although it
could be considered a loose description of disaster recovery plan testing.
The other three choices are primary elements of BCP approval,
implementation, and maintenance.

 

NEW QUESTION 338
Who is responsible for initiating corrective measures and capabilities used when there are security violations?

  • A. Data owners
  • B. Security administrator
  • C. Management
  • D. Information systems auditor

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Management is responsible for initiating corrective measures and capabilities used when there are security violations.
Incorrect Answers:
A: The Information systems auditor ensures that the correct controls are in place and are being maintained securely. The information systems auditor is not responsible for initiating corrective measures and capabilities used when there are security violations.
B: The security administrator is responsible for implementing and maintaining specific security network devices and software in the enterprise. These controls commonly include firewalls, IDS, IPS, antimalware, security proxies, data loss prevention, etc. The security administrator is not responsible for initiating corrective measures and capabilities used when there are security violations.
D: The data owner decides upon the classification of the data she is responsible for. The data owner is also responsible for ensuring that the necessary security controls are in place, defining security requirements per classification and backup requirements, approving any disclosure activities, ensuring that proper access rights are being used, and defining user access criteria. The data owner is not responsible for initiating corrective measures and capabilities used when there are security violations.
References:
https://quizlet.com/31878633/cissp-domain-1-information-security-governance-and-risk-management- flash-cards/ Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 121-125

 

NEW QUESTION 339
Which access control model provides upper and lower bounds of access capabilities for a subject?

  • A. Biba access control
  • B. Content-dependent access control
  • C. Lattice-based access control
  • D. Role-based access control

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Lattice-based access control is a mathematical model that allows a system to easily represent the different security levels and control access attempts based on those levels. Every pair of elements has a highest lower bound and a lowest upper bound of access rights.
Incorrect Answers:
A: Role-based access control (RBAC) provides access to resources according to the role the user holds within the company or the tasks that the user has been assigned.
C: Biba is a security model, rather than an access control model. It centers on preventing information from flowing from a low integrity level to a high integrity level
D: Content-dependent access control is when the access decisions depend upon the value of an attribute of the object itself.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 224, 377, G-9
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.41.5365

 

NEW QUESTION 340
Data leakage of sensitive information is MOST often concealed by which of the following?

  • A. Secure Sockets Layer (SSL)
  • B. Secure Hash Algorithm (SHA)
  • C. Wired Equivalent Privacy (WEP)
  • D. Secure Post Office Protocol (POP)

Answer: A

 

NEW QUESTION 341
Another name for a VPN is a:

  • A. bypass
  • B. pipeline
  • C. one-time password
  • D. tunnel

Answer: D

Explanation:
Explanation/Reference:
Explanation:
A virtual private network (VPN) is a secure, private connection through an untrusted network. VPN technology requires a tunnel to work and it assumes encryption.
Incorrect Answers:
B: A one-time password is not the same as a VPN.
C: Tunnel, not pipeline, can be used as a name for a VPN.
D: Tunnel, not bypass, can be used as a name for a VPN.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 702

 

NEW QUESTION 342
Which one of the following factors is NOT one on which Authentication is based?

  • A. Type 1 Something you know, such as a PIN or password
  • B. Type 4 Something you are, such as a system administrator or security administrator
  • C. Type 2 Something you have, such as an ATM card or smart card
  • D. Type 3 Something you are (based upon one or more intrinsic physical or behavioral traits), such as a fingerprint or retina scan

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Something you are, or authentication by characteristic, is based on a unique physical attribute, not what role you fulfill.
Incorrect Answers:
A: Something you know, or authentication by knowledge, can be a password, PIN, mother's maiden name, or the combination to a lock.
B: Something you have, or authentication by ownership, can be a key, swipe card, access card, or badge.
C: Something you are, or authentication by characteristic, is based on a unique physical attribute, referred to as biometrics.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 163

 

NEW QUESTION 343
Which task below would normally be considered a BCP task, rather
than a DRP task?

  • A. Recovery procedures
  • B. Restoration procedures
  • C. Life safety processes
  • D. Project scoping

Answer: D

Explanation:
Although many processes in making business continuity plans are
similar to processes in creating disaster recovery plans, several
differences exist. Business continuity planning processes that are
unique to BCP could include:
Project scoping and assigning roles
Creating business impact and vulnerability assessments
Choosing alternate processing sites
whereas unique disaster recovery/emergency management processes
could include:
Implementing relocation procedures to the alternate site
Plan testing and training
Recovering data
Salvaging damaged equipment
Source: CISSP Examination Textbooks, Volume One: Theory, by S.
Rao Vallabhaneni, SRV Professional Publications first edition 2000
and Handbook of Information Security Management, by Micki
Krause and Harold F. Tipton, Auerback, 1999 edition.

 

NEW QUESTION 344
The Reference Validation Mechanism that ensures the authorized access relationships between subjects and objects is implementing which of the following concept:

  • A. The reference monitor.
  • B. Mandatory Access Control.
  • C. Discretionary Access Control.
  • D. The Security Kernel.

Answer: A

Explanation:
The reference monitor concept is an abstract machine that ensures that all subjects have the necessary access rights before accessing objects. Therefore, the kernel will mediates all accesses to objects by subjects and will do so by validating through the reference monitor concept.
The kernel does not decide whether or not the access will be granted, it will be the Reference Monitor which is a subset of the kernel that will say YES or NO.
All access requests will be intercepted by the Kernel, validated through the reference monitor, and then access will either be denied or granted according to the request and the subject privileges within the system.
1.The reference monitor must be small enough to be full tested and valided
2.The Kernel must MEDIATE all access request from subjects to objects
3.The processes implementing the reference monitor must be protected
4.The reference monitor must be tamperproof
The following answers are incorrect: The security kernel is the mechanism that actually enforces the rules of the reference monitor concept. The other answers are distractors. Shon Harris, All In One, 5th Edition, Security Architecture and Design, Page 330 also see http://en.wikipedia.org/wiki/Reference_monitor

 

NEW QUESTION 345
Which one of the following is the MOST crucial link in the computer security chain?

  • A. People
  • B. Awareness programs
  • C. Access controls
  • D. Management

Answer: D

 

NEW QUESTION 346
What are high-level policies?

  • A. They are the instructions on how to perform a Quantitative Risk
    Analysis.
  • B. They are recommendations for procedural controls.
  • C. They are statements that indicate a senior management's intention to support InfoSec.
  • D. They are step-by-step procedures to implement a safeguard.

Answer: C

Explanation:
The correct answer is "They are statements that indicate a senior management's intention to support InfoSec". High-level policies are senior management statements of recognition of the importance of InfoSec controls.

 

NEW QUESTION 347
What security model is dependant on security labels?

  • A. Mandatory access control
  • B. Discretionary access control
  • C. Label-based access control
  • D. Non-discretionary access control

Answer: A

Explanation:
With mandatory controls, only administrators and not owners of resources may make decisions that bear on or derive from policy. Only an administrator may change the category of a resource, and no one may grant a right of access that is explicitly forbidden in the access control policy. This kind of access control method is based on Security labels. It is important to note that mandatory controls are prohibitive (i.e., all that is not expressly permitted is forbidden).

 

NEW QUESTION 348
You've decided to authenticate the source who initiated a particular transfer while ensuring integrity of the data being transferred. You can do this by:

  • A. having the sender encrypt the message with his symmetric key.
  • B. having the sender encrypt the message with his private key.
  • C. having the sender encrypt the hash with his public key.
  • D. having the sender encrypt the hash with his private key.

Answer: D

Explanation:
Explanation/Reference:
A hash will ensure the integrity of the data being transferred. A private key will authenticate the source (sender). Only the sender has a copy of the private key. If the recipient is able to decrypt the hash with the public key, then the recipient will know that the hash was encrypted with the private key of the sender.
A cryptographic hash function is a hash function which is considered practically impossible to invert, that is, to recreate the input data from its hash value alone. The input data is often called the message, and the hash value is often called the message digest or simply the digest.
The ideal cryptographic hash function has four main properties:

it is easy to compute the hash value for any given message

it is infeasible to generate a message from its hash

it is infeasible to modify a message without changing the hash

it is infeasible to find two different messages with the same hash.

Incorrect Answers:
A: Having the sender encrypt the message with his private key would authenticate the sender. However, is would not ensure the integrity of the message. A hash is required to ensure the integrity of the message.
C: Having the sender encrypt the message with his symmetric key will not authenticate the sender or ensure the integrity of the message. A hash is required to ensure the integrity of the message and the hash should be encrypted with the sender's private key.
D: Having the sender encrypt the hash with his public key will not authenticate the sender. Anyone could have a copy of the sender's public key. The hash should be encrypted with the sender's private key as the sender is the only person in possession of the private key.
References:
https://en.wikipedia.org/wiki/Cryptographic_hash_function

 

NEW QUESTION 349
When should the public and media be informed about a disaster?

  • A. Whenever site emergencies extend beyond the facility
  • B. When any emergency occurs at the facility, internally or externally
  • C. When the disaster has been contained
  • D. When the publics health or safety is in danger

Answer: A

Explanation:
When an emergency occurs that could potentially have an impact
outside the facility, the public must be informed, regardless of
whether there is any immediate threat to public safety. The disaster
recovery plan should include determinations of the audiences that
may be affected by an emergency, and procedures to communicate
with them. Information the public will want to know could include
public safety or health concerns, the nature of the incident, the remediation effort, and future prevention steps. Common audiences for information could include:
The media
Unions and contractors
Shareholders
Neighbors
Employees families and retirees
Since the media is such an important link to the public, disaster plans and tests must contain procedures for addressing the media and communicating important information. A trained spokesperson should be designated, and established communications procedures should be prepared. Accurate and approved information should be released in a
timely manner, without speculation, blame, or obfuscation. Source:
Emergency Management Guide for Business and Industry, Federal
Emergency Management Agency, August, 1998.

 

NEW QUESTION 350
Which of the following keys has the SHORTEST lifespan?

  • A. Session key
  • B. Secret key
  • C. Public key
  • D. Private key

Answer: A

Explanation:
As session key is a symmetric key that is used to encrypt messages between two users. A session key is only good for one communication session between users.
For example , If Tanya has a symmetric key that she uses to encrypt messages between
Lance and herself all the time , then this symmetric key would not be regenerated or changed. They would use the same key every time they communicated using encryption.
However , using the same key repeatedly increases the chances of the key being captured and the secure communication being compromised. If , on the other hand , a new symmetric key were generated each time Lance and Tanya wanted to communicate , it would be used only during their dialog and then destroyed. if they wanted to communicate and hour later , a new session key would be created and shared.
The other answers are not correct because :
Public Key can be known to anyone.
Private Key must be known and used only by the owner.
Secret Keys are also called as Symmetric Keys, because this type of encryption relies on each user to keep the key a secret and properly protected.
REFERENCES:
SHON HARRIS , ALL IN ONE THIRD EDITION : Chapter 8 : Cryptography , Page : 619-
620

 

NEW QUESTION 351
Which access control model was proposed for enforcing access control in government and military applications?

  • A. Sutherland model
  • B. Brewer-Nash model
  • C. Biba model
  • D. Bell-LaPadula model

Answer: D

Explanation:
The Bell-LaPadula model, mostly concerned with confidentiality, was proposed for enforcing access control in government and military applications. It supports mandatory access control by determining the access rights from the security levels associated with subjects and objects. It also supports discretionary access control by checking access rights from an access matrix. The Biba model, introduced in 1977, the Sutherland model, published in 1986, and the Brewer-Nash model, published in 1989, are concerned with integrity. Source: ANDRESS, Mandy, Exam Cram CISSP, Coriolis, 2001, Chapter 2: Access Control Systems and Methodology (page 11).

 

NEW QUESTION 352
Which of the following is true of biometrics?

  • A. It is used for identification in physical controls and it is not used in logical controls.
  • B. It is used for identification in physical controls and for authentication in logical controls.
  • C. It is used for authentication in physical controls and for identification in logical controls.
  • D. Biometrics has no role in logical controls.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Biometrics is used for identification in physical controls and for authentication in logical controls. Physical controls are items put into place to protect facility, personnel, and resources. As a physical control, biometrics provides protection by identifying a person to see if that person is authorized to access a facility.
When a user is identified and granted physical access to a facility, biometrics can be used for authentication in logical controls to provide access to resources.
Controls are put into place to reduce the risk an organization faces, and they come in three main flavors:
administrative, technical, and physical. Administrative controls are commonly referred to as "soft controls" because they are more management-oriented. Examples of administrative controls are security documentation, risk management, personnel security, and training. Technical controls (also called logical controls) are software or hardware components, as in firewalls, IDS, encryption, identification and authentication mechanisms. And physical controls are items put into place to protect facility, personnel, and resources. Examples of physical controls are security guards, locks, fencing, and lighting.
Incorrect Answers:
A: Biometrics is used in logical controls.
B: Biometrics is used for identification in physical controls and for authentication in logical controls, not the other way round. Biometrics is used first as a physical control to identify a person to grant access to a facility, and then as a logical control to authenticate the user to provide access to resources.
D: Biometrics does have a role in logical controls.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 28 Krutz, Ronald L. and Russell Dean Vines, The CISSP Prep Guide: Mastering the CISSP and ISSEP Exams, 2nd Edition, Wiley Publishing, Indianapolis, 2004, p. 58

 

NEW QUESTION 353
The owner of a system should have the confidence that the system will behave according to its specifications. This is termed as:

  • A. Integrity
  • B. Assurance
  • C. Accountability
  • D. Availability

Answer: B

Explanation:
Explanation/Reference:
Explanation:
In a trusted system, all protection mechanisms work together to process sensitive data for many types of uses, and will provide the necessary level of protection per classification level. Assurance looks at the same issues but in more depth and detail. Systems that provide higher levels of assurance have been tested extensively and have had their designs thoroughly inspected, their development stages reviewed, and their technical specifications and test plans evaluated.
In the Trusted Computer System Evaluation Criteria (TCSEC), commonly known as the Orange Book, the lower assurance level ratings look at a system's protection mechanisms and testing results to produce an assurance rating, but the higher assurance level ratings look more at the system design, specifications, development procedures, supporting documentation, and testing results. The protection mechanisms in the higher assurance level systems may not necessarily be much different from those in the lower assurance level systems, but the way they were designed and built is under much more scrutiny. With this extra scrutiny comes higher levels of assurance of the trust that can be put into a system.
Incorrect Answers:
A: Integrity ensures that data is unaltered. This is not what is described in the question.
B: Accountability is a security principle indicating that individuals must be identifiable and must be held responsible for their actions. This is not what is described in the question.
D: Availability ensures reliability and timely access to data and resources to authorized individuals.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 390-391

 

NEW QUESTION 354
Which of the following protocols would BEST mitigate threats of sniffing attacks on web application traffic?

  • A. SSH - Secure Shell
  • B. SSL or TLS
  • C. 802.1X
  • D. ARP Cache Security

Answer: B

Explanation:
While it traverses the network, without some sort of encryption of web application
data is vulnerable to sniffing and interception by attackers on the network. If we observe sniffer
traffic on an unencrypted network we can clearly see the contents of user interaction with the web
server and its applications.
SSL - Secure Sockets Layer or TLS - Transport Layer Security
There are similarities between these two protocols but TLS 3.1 supersedes SSL 2.0 but they are
not interoperable. Today both protocols are commonly used on many web server. In either case
SSL/TLS encrypts network traffic as it traverses the wire and protects it from sniffing attacks.
The following answers are incorrect:
802.1X: This wouldn't secure data in transit but it would help prevent unauthorized devices from
connecting to your network and sniffing data. Also Known As "Dot 1 X" or "The Extensible
Authentication Protocol (EAP)" it provides infrastructure protection by requiring certificates to
connect.
ARP Cache Security: This wouldn't mitigate the threat of network sniffing of web app data.
SSH - Secure Shell: Incorrect. SSH is a TELNET replacement for that encrypts traffic to mitigate
the threat of network sniffers on SSH connections.
The following reference(s) were/was used to create this question:
2011. EC-COUNCIL Official Curriculum, Ethical Hacking and Countermeasures, v7.1, Module 13,
Page 569.

 

NEW QUESTION 355
Which of the following defines the software that maintains and provides access to the database?

  • A. relational database management system (RDBMS)
  • B. database management system (DBMS)
  • C. database identification system (DBIS)
  • D. Interface Definition Language system (IDLS)

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The database management system (DBMS) is a software suite that is used to manage access to the database and provides data integrity and redundancy. It is usually controlled by a database administrator.
Incorrect Answers:
B: A relational database management system (RDBMS) provides access to a relational database.
C: There is no database identification system.
D: An Interface Definition Language (IDL) is a language that is used to define the interface between a client and server process in a distributed system. It is not used to provide access to a database.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 1170
http://csis.pace.edu/~marchese/CS865/Papers/interface-definition-language.pdf

 

NEW QUESTION 356
Which statement below is accurate about the concept of Object Reuse?

  • A. Object reuse applies to removable media only.
  • B. Object reuse controls the granting of access rights to objects.
  • C. Object reuse ensures that users do not obtain residual information
    from system resources.
  • D. Object reuse protects against physical attacks on the storage
    medium.

Answer: C

Explanation:
Object reuse mechanisms ensure system resources are allocated and
reassigned among authorized users in a way that prevents the leak of
sensitive information, and ensure that the authorized user of the system does not obtain residual information from system resources. Object reuse is defined as The reassignment to some subject of a storage medium
(e.g., page frame, disk sector, magnetic tape) that contained one or more objects. To be securely reassigned, no residual data can be available to the new subject through standard system mechanisms.7 The object reuse requirement of the TCSEC is intended to assure that system resources, in particular storage media, are allocated and reassigned among system users in a manner which prevents the disclosure of sensitive information.
Answer a is incorrect. Object reuse does not necessarily protect
against physical attacks on the storage medium. Answer c is also
incorrect, as object reuse applies to all primary and secondary storage media, such as removable media, fixed media, real and virtual main memory (including registers), and cache memory. Answer d refers to authorization, the granting of access rights to a user, program, or
process. Source: NCSC-TG-018, A Guide To Understanding Object
Reuse in Trusted Systems [Light Blue Book].

 

NEW QUESTION 357
......

Focus on CISSP All-in-One Exam Guide For Quick Preparation: https://www.prepawaypdf.com/ISC/CISSP-practice-exam-dumps.html

CISSP All-in-One Exam Guide For Quick Preparation: https://drive.google.com/open?id=11-K4293-4lcpQ4JXHsnOGuqpIG2qI-2Y