Free ISC CISSP Test Practice Test Questions Exam Dumps [Q155-Q175]

Share

Free ISC CISSP Test Practice Test Questions Exam Dumps

Prepare Top ISC CISSP Exam Audio Study Guide Practice Questions Edition


Certification path of CISSP test: Certified Information Systems Security Professional

Is it true that you are hoping to speed up your data security profession? Separate yourself to businesses and additionally customers? The CISSP is a tip top approach to exhibit your insight, advance your vocation, and join a local area of similar online protection pioneers. It shows you have everything necessary to configuration, specialist, carry out, and run an effective data security program.

By taking the CISSP test, you’ll get the opportunity to demonstrate you have the specialized and administrative information important to successfully configuration, engineer, and deal with the general security stance of an association. Procuring the CISSP demonstrates you have the stuff to adequately configuration, carry out and deal with a top tier network safety program. The CISSP test assesses your skill across eight security areas. Consider the areas subjects you need to dominate dependent on your expert experience and instruction.

NEW QUESTION 155
A new Chief Information Officer (CIO) created a group to write a data retention policy based on applicable laws. Which of the following is the PRIMARY motivation for the policy?

  • A. To classify data according to what it contains
  • B. To back up data that is used on a daily basis
  • C. To dispose of data in order to limit liability
  • D. To reduce costs by reducing the amount of retained data

Answer: A

 

NEW QUESTION 156
What does the simple integrity axiom mean in the Biba model?

  • A. No write down
  • B. No read up
  • C. No read down
  • D. No write up

Answer: C

Explanation:
The simple integrity axiom of the Biba access control model states that a subject at one level of integrity is not permitted to observe an object of a lower integrity (no read down).
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 5: Security
Architectures and Models (page 205).

 

NEW QUESTION 157
Which of the following method is recommended by security professional to PERMANENTLY erase sensitive data on magnetic media?

  • A. Overwrite every sector of magnetic media with pattern of 1's and 0's
  • B. Delete File allocation table
  • C. Degaussing
  • D. Format magnetic media

Answer: C

Explanation:
PERMANENTLY is the keyword used in the question. You need to find out data removal method which remove data permanently from magnetic media.
Degaussing is the most effective method out of all provided choices to erase sensitive data on magnetic media provided magnetic media is not require to be reuse. Some degaussers can destroy drives. The security professional should exercise caution when recommending or using degaussers on media for reuse.
A device that performs degaussing generates a coercive magnetic force that reduces the magnetic flux density of the storage media to zero. This magnetic force is what properly erases data from media. Data are stored on magnetic media by the representation of the polarization of the atoms. Degaussing changes this polarization (magnetic alignment) by using a type of large magnet to bring it back to its original flux (magnetic alignment).
For your exam you should know the information below:
When media is to be reassigned (a form of object reuse), it is important that all residual data is carefully removed.
Simply deleting files or formatting the media does not actually remove the information. File deletion and media formatting often simply remove the pointers to the information. Providing assurance for object reuse requires specialized tools and techniques according to the type of media on which the data resides.
Specialized hardware devices known as degaussers can be used to erase data saved to magnetic media. The measure of the amount of energy needed to reduce the magnetic field on the media to zero is known as coercivity. It is important to make sure that the coercivity of the degausser is of sufficient strength to meet object reuse requirements when erasing data. If a degausser is used with insufficient coercivity, then a remanence of the data will exist.
Remanence is the measure of the existing magnetic field on the media; it is the residue that remains after an object is degaussed or written over. Data is still recoverable even when the remanence is small. While data remanence exists, there is no assurance of safe object reuse. Some degaussers can destroy drives. The security professional should exercise caution when recommending or using degaussers on media for reuse.
Software tools also exist that can provide object reuse assurance. These tools overwrite every sector of magnetic media with a random or predetermined bit pattern. Overwrite methods are effective for all forms of electronic media with the exception of read-only optical media. There is a drawback to using overwrite software. During normal write operations with magnetic media, the head of the drive moves back-and-forth across the media as data is written. The track of the head does not usually follow the exact path each time. The result is a miniscule amount of data remanence with each pass. With specialized equipment, it is possible to read data that has been overwritten.
To provide higher assurance in this case, it is necessary to overwrite each sector multiple times. Security practitioners should keep in mind that a one-time pass may be acceptable for noncritical information, but sensitive data should be overwritten with multiple passes. Overwrite software can also be used to clear the sectors within solid-state media such as USB thumb drives. It is
suggested that physical destruction methods such as incineration or secure recycling should be
considered for solid-state media that is no longer used.
The last form of preventing unauthorized access to sensitive data is media destruction. Shredding,
burning, grinding, and pulverizing are common methods of physically destroying media.
Degaussing can also be a form of media destruction. High-power degaussers are so strong in
some cases that they can literally bend and warp the platters in a hard drive.
Shredding and burning are effective destruction methods for non-rigid magnetic media. Indeed,
some shredders are capable of shredding some rigid media such as an optical disk. This may be
an effective alternative for any optical media containing nonsensitive information due to the
residue size remaining after feeding the disk into the machine.
However, the residue size might be too large for media containing sensitive information.
Alternatively, grinding and pulverizing are acceptable choices for rigid and solid-state media.
Specialized devices are available for grinding the face of optical media that either sufficiently
scratches the surface to render the media unreadable or actually grinds off the data layer of the
disk. Several services also exist which will collect drives, destroy them on site if requested and
provide certification of completion. It will be the responsibility of the security professional to help,
select, and maintain the most appropriate solutions for media cleansing and disposal.
The following answers are incorrect:
Overwrite every sector of magnetic media with pattern of 1's and 0's- Less effective than
degaussing provided magnetic media is not require to be reuse.
Format magnetic media - Formatting magnetic media does not erase all data. Data can be
recoverable after formatting using software tools.
Delete File allocation table - It will not erase all data. Data can be recoverable using software
tools.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 338
Official ISC2 guide to CISSP CBK 3rd Edition Page number 720
Topic 8, Business Continuity and Disaster Recovery Planning

 

NEW QUESTION 158
What is called the act of a user professing an identity to a system, usually in the form of a log-on ID?

  • A. Confidentiality
  • B. Authentication
  • C. Identification
  • D. Authorization

Answer: C

Explanation:
Identification is the act of a user professing an identity to a system, usually in the form of a log-on ID to the system.
Identification is nothing more than claiming you are somebody. You identify yourself when you speak to someone on the phone that you don't know, and they ask you who they're speaking to. When you say, "I'm Jason.", you've just identified yourself.
In the information security world, this is analogous to entering a username. It's not analogous to entering a password. Entering a password is a method for verifying that you are who you identified yourself as.
NOTE: The word "professing" used above means: "to say that you are, do, or feel something when other people doubt what you say". This is exactly what happen when you provide your identifier (identification), you claim to be someone but the system cannot take your word for it, you must further Authenticate to the system to prove who you claim to be.
The following are incorrect answers:
Authentication: is how one proves that they are who they say they are. When you claim to be Jane Smith by logging into a computer system as "jsmith", it's most likely going to ask you for a password. You've claimed to be that person by entering the name into the username field (that's the identification part), but now you have to prove that you are really that person.
Many systems use a password for this, which is based on "something you know", i.e. a secret between you and the system.
Another form of authentication is presenting something you have, such as a driver's license, an RSA token, or a smart card.
You can also authenticate via something you are. This is the foundation for biometrics. When you do this, you first identify yourself and then submit a thumb print, a retina scan, or another form of bio-based authentication.
Once you've successfully authenticated, you have now done two things: you've claimed to be someone, and you've proven that you are that person. The only thing that's left is for the system to determine what you're allowed to do.
Authorization: is what takes place after a person has been both identified and authenticated; it's the step determines what a person can then do on the system.
An example in people terms would be someone knocking on your door at night. You say, "Who is it?", and wait for a response. They say, "It's John." in order to identify themselves. You ask them to back up into the light so you can see them through the peephole. They do so, and you authenticate them based on what they look like (biometric). At that point you decide they can come inside the house.
If they had said they were someone you didn't want in your house (identification), and you then verified that it was that person (authentication), the authorization phase would not include access to the inside of the house.
Confidentiality: Is one part of the CIA triad. It prevents sensitive information from reaching the wrong people, while making sure that the right people can in fact get it. A good example is a credit card number while shopping online, the merchant needs it to clear the transaction but you do not want your informaiton exposed over the network, you would use a secure link such as SSL, TLS, or some tunneling tool to protect the information from prying eyes between point A and point B. Data encryption is a common method of ensuring confidentiality.
The other parts of the CIA triad are listed below:
Integrity involves maintaining the consistency, accuracy, and trustworthiness of data over its entire life cycle. Data must not be changed in transit, and steps must be taken to ensure that data cannot be altered by unauthorized people (for example, in a breach of confidentiality). In addition, some means must be in place to detect any changes in data that might occur as a result of non-humancaused events such as an electromagnetic pulse (EMP) or server crash. If an unexpected change occurs, a backup copy must be available to restore the affected data to its correct state.
Availability is best ensured by rigorously maintaining all hardware, performing hardware repairs immediately when needed, providing a certain measure of redundancy and failover, providing adequate communications bandwidth and preventing the occurrence of bottlenecks, implementing emergency backup power systems, keeping current with all necessary system upgrades, and guarding against malicious actions such as denial-of-service (DoS) attacks.
Reference used for this question:
http://whatis.techtarget.com/definition/Confidentiality-integrity-and-availability-CIA
http://www.danielmiessler.com/blog/security-identification-authentication-and-authorization
http://www.merriam-webster.com/dictionary/profess
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 36

 

NEW QUESTION 159
After a thorough analysis, it was discovered that a perpetrator compromised a network by gaining access to the network through a Secure Socket Layer (SSL) Virtual Private Network (VPN) gateway. The perpetrator guessed a username and brute forced the password to gain access. Which of the following BEST mitigates this issue?

  • A. Implement strong passwords authentication for VPN
  • B. Integrate the VPN with centralized credential stores
  • C. Implement an Internet Protocol Security (IPSec) client
  • D. Use two-factor authentication mechanisms

Answer: D

 

NEW QUESTION 160
Which of the following statements pertaining to packet switching is NOT true?

  • A. Each network node or point examines each packet for routing.
  • B. Messages are divided into packets.
  • C. Most data sent today uses digital signals over network employing packet switching.
  • D. All packets from a message travel through the same route.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Packet switching does not set up a dedicated virtual link, and packets from one connection can pass through a number of different individual devices, instead of all of them following one another through the same devices.
Incorrect Answers:
A: Most traffic over the Internet uses packet switching and the Internet is basically a connectionless network.
B: In a packet-switching network, the data are broken up into packets containing frame check sequence numbers.
D: The packet switching packets go through different network nodes, and their paths can be dynamically altered by a router or switch that determines a better route for a specific packet to take.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 674

 

NEW QUESTION 161
When planning for disaster recovery it is important to know a chain of command should one or more people become missing, incapacitated or otherwise not available to lead the organization.
Which of the following terms BEST describes this process?

  • A. Business Impact Analysis
  • B. Succession Planning
  • C. Continuity of Operations
  • D. Business Continuity Planning

Answer: B

Explanation:
Succession Planning or "Chain of Command" in military terms is a list of people we would use in the event the leader becomes unavailable for whatever reason.
It is important to have this as part of a CONOPS - Continuity of Operations plan if the organization is going to effectively recover from a disaster, loss of key people or other impact to the business.
Knowing who is the next in charge can help an organization more quickly and recover to normalcy after the loss.
The following answers are incorrect: -Continuity of Operations: Sorry, this isn't correct because it is a broader process than succession planning. Continuity of operations or CONOPS is a larger project including succession planning.
-
Business Impact Analysis: Again, like CONOPS, BIA is a broader project including succession planning. BIA focuses on the effects of something on business processes and helps planning around them.
-
Business Continuity Planning: Like the other answers, CONOPS, BIA and BCP are broad projects aimed at sustaining a set of business processes that sustain the organization and how to prepare to recover in the event of disaster or other impacts.
The following reference(s) was used to create this question:
2013. Official Security+ Curriculum.
and
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition
((ISC)2 Press) (Kindle Location 19464). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 162
which of the following example is NOT an asymmetric key algorithms?

  • A. Elliptic curve cryptosystem(ECC)
  • B. Merkle-Hellman Knapsack
  • C. Diffie-Hellman
  • D. Advanced Encryption Standard(AES)

Answer: D

Explanation:
AES is an example of Symmetric Key algorithm. After DES was used as an encryption standard for over 20 years and it was cracked in a relatively short time once the necessary technology was available, NIST decided a new standard, the Advanced Encryption Standard (AES), needed to be put into place .
In January 1997 , NIST announced its request for AES candidates and outlined the requirements in FIPS PUB 197. AES was to be a symmetric block cipher supporting key sizes of 128, 192, and 256 bits.
The following five algorithms were the finalists:
MARS Developed by the IBM team that created Lucifer
RC6 Developed by RSA Laboratories
Serpent Developed by Ross Anderson, Eli Biham, and Lars Knudsen
Twofish Developed by Counterpane Systems
Rijndael Developed by Joan Daemen and Vincent Rijmen
Out of these contestants, Rijndael was chosen.
The block sizes that Rijndael supports are 128, 192 , and 256 bits.
The number of rounds depends upon the size of the block and the key length:
If both the key and block size are 128 bits, there are 10 rounds.
If both the key and block size are 192 bits, there are 12 rounds.
If both the key and block size are 256 bits, there are 14 rounds.
When preparing for my CISSP exam, i came across this post by Laurel Marotta at the URL below:
http://cissp-study.3965.n7.nabble.com/CCCure-CISSP-Study-Plan-to-crack-CISSP-clarificationtd401.html
This tips was originally contributed by Doug Landoll Here is an easy way to remember the types of crypto cipher: The sentence to remember is: DEER MRS H CARBIDS
Asymmetric: encrypt with 1 key, decrypt with other Key exchange. A key pair: Public and Private. Services: Confidentiality, Nonrepudiation, Integrity, Digital Signature D - Diffie-Hellman E - El Gamal: DH +nonrepudiation E - ECC R - RSA
Hash- one-way algorithm, no key
M - MD5
R - RIPEMD (160)
S - SHA (3)
H - Haval (v)
Symmetric: Encryption, one key
C - CAST
A - AES: 128k, 10r; 192k, 12 r; 256k, 14r
R - RC4, RC5, RC6
B - BLOWFISH:23-448k, 64bit block
I - IDEA : 128k, 64bit block
D - DES-64-bit block, 16r
S - SERPENT
The following answers are all incorrect because they are all Asymmetric Crypto ciphers:
Elliptic curve cryptosystem(ECC)
Diffie-Hellman
Merkle-Hellman Knapsack
The following reference(s) were/was used to create this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 809). McGraw-Hill .
Kindle Edition.

 

NEW QUESTION 163
On June 30, 2000, the U.S. Congress enacted the Electronic Signatures in Global and National Commerce Act (ESIGN) to facilitate the use of electronic records and signatures in interstate and foreign commerce by ensuring the validity and legal effect of contracts entered into electronically. An important provision of the Act requires that:

  • A. Businesses have the ability to use product price to persuade consumers to accept electronic records instead of paper.
  • B. Specific technologies be used to ensure technical compatibility.
  • C. Businesses obtain electronic consent or confirmation from consumers to receive information electronically that a law normally requires to be in writing.
  • D. The e-commerce businesses do not have to determine whether the consumer has the ability to receive an electronic notice before transmitting the legally required notices to the consumer.

Answer: C

Explanation:
The legislation is intent on preserving the consumers rights under consumer protection laws and went to extraordinary measures to meet this goal. Thus, a business must receive confirmation from the consumer in electronic format that the consumer consents to receiving information electronically that used to be in written form. This provision ensures that the consumer has access to the Internet and is familiar with the basics of electronic communications. Answer b is, therefore, incorrect. Answer c is also incorrect since the legislation reduces the ability of businesses to use product price unfairly to persuade consumers to accept electronic records. Answer d is incorrect since the legislation is specifically technology-neutral to permit the use of the best technology for the application.

 

NEW QUESTION 164
Which of the following Service Organization Control (SOC) report types should an organization request if they require a period of time report covering security and availability for a particular system?

  • A. SOC 1 Type 1
  • B. SOC 2 Type 2
  • C. SOC 1 Type 2
  • D. SOC 2 Type 1

Answer: C

 

NEW QUESTION 165
Which one of the following factors is NOT one on which Authentication is based?

  • A. Type 4 Something you are, such as a system administrator or security administrator
  • B. Type 2 Something you have, such as an ATM card or smart card
  • C. Type 1 Something you know, such as a PIN or password
  • D. Type 3 Something you are (based upon one or more intrinsic physical or behavioral traits), such as a fingerprint or retina scan

Answer: A

Explanation:
Authentication is based on the following three factor types:
Type 1 Something you know, such as a PIN or password
Type 2 Something you have, such as an ATM card or smart card
Type 3 Something you are (Unique physical characteristic), such as a fingerprint or retina scan
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 36
Also: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne,
2002, chapter 4: Access Control (pages 132-133).

 

NEW QUESTION 166
Which of the following is an example of an active attack? Select one.

  • A. Eavesdropping
  • B. Masquerading
  • C. Traffic analysis
  • D. Shoulder surfing

Answer: B

Explanation:
Shoulder surfing is passive, like eavesdropping and traffic analysis.
Masquerading is the only one where you are actually doing something by changing something -
actively doing something.

 

NEW QUESTION 167
What is considered the major disadvantage to employing a hot site for disaster recovery?

  • A. Exclusivity is assured for processing at the site.
  • B. The site is immediately available for recovery.
  • C. Maintaining the site is expensive.
  • D. Annual testing is required to maintain the site.

Answer: C

Explanation:
The correct answer is the expense of maintaining the site. A hot site is commonly used for those extremely time-critical functions that the business must have up and running to continue operating, but the expense of duplicating and maintaining all of the hardware, software, and application elements is a serious resource drain to most organizations.

 

NEW QUESTION 168
Which protocol makes USE of an electronic wallet on a customer's PC and sends encrypted credit card information to merchant's Web server, which digitally signs it and sends it on to its processing bank?

  • A. SET (Secure Electronic Transaction)
  • B. S/MIME (Secure MIME)
  • C. SSH ( Secure Shell)
  • D. SSL (Secure Sockets Layer)

Answer: A

Explanation:
As protocol was introduced by Visa and Mastercard to allow for more credit card transaction possibilities. It is comprised of three different pieces of software, running on the customer's PC (an electronic wallet), on the merchant's Web server and on the payment server of the merchant's bank. The credit card information is sent by the customer to the merchant's Web server, but it does not open it and instead digitally signs it and sends it to its bank's payment server for processing.
The following answers are incorrect because :
SSH (Secure Shell) is incorrect as it functions as a type of tunneling mechanism that provides terminal like access to remote computers.
S/MIME is incorrect as it is a standard for encrypting and digitally signing electronic mail and for providing secure data transmissions.
SSL is incorrect as it uses public key encryption and provides data encryption, server authentication, message integrity, and optional client authentication.
Reference : Shon Harris AIO v3 , Chapter-8: Cryptography , Page : 667-669

 

NEW QUESTION 169
Macro viruses written in Visual Basic for Applications (VBA) are a major problem because

  • A. These viruses can infect many types of environments.
  • B. These viruses almost exclusively affect the operating system.
  • C. Anti-virus software is usable to remove the viral code.
  • D. Floppy disks can propagate such viruses.

Answer: B

Explanation:
VBA is typically Windows OS base, so Unlikely many types of environments, but impact the OS (need a real reference source to justify this though).

 

NEW QUESTION 170
Public Key Infrastructure (PKI) uses asymmetric key encryption between parties. The originator encrypts information using the intended recipient's "public" key in order to get confidentiality of the data being sent. The recipients use their own "private" key to decrypt the information. The "Infrastructure" of this methodology ensures that:

  • A. The sender and recipient have reached a mutual agreement on the encryption key exchange that they will use.
  • B. The sender of the message is the only other person with access to the recipient's private key.
  • C. The recipient's identity can be positively verified by the sender.
  • D. The channels through which the information flows are secure.

Answer: C

Explanation:
Through the use of Public Key Infrastructure (PKI) the recipient's identity can be positively verified by the sender.
The sender of the message knows he is using a Public Key that belongs to a specific user.
He can validate through the Certification Authority (CA) that a public key is in fact the valid public key of the receiver and the receiver is really who he claims to be. By using the public key of the recipient, only the recipient using the matching private key will be able to decrypt the message. When you wish to achieve confidentiality, you encrypt the message with the recipient public key.
If the sender would wish to prove to the recipient that he is really who he claims to be then the sender would apply a digital signature on the message before encrypting it with the public key of the receiver. This would provide Confidentiality and Authenticity of the message.
A PKI (Public Key Infrastructure) enables users of an insecure public network, such as the
Internet, to securely and privately exchange data through the use of public key-pairs that are obtained and shared through a trusted authority, usually referred to as a Certificate
Authority.
The PKI provides for digital certificates that can vouch for the identity of individuals or organizations, and for directory services that can store, and when necessary, revoke those digital certificates. A PKI is the underlying technology that addresses the issue of trust in a normally untrusted environment.
The following answers are incorrect:
The sender and recipient have reached a mutual agreement on the encryption key exchange that they will use. Is incorrect because through the use of Public Key
Infrastructure (PKI), the parties do not have to have a mutual agreement. They have a trusted 3rd party Certificate Authority to perform the verification of the sender.
The channels through which the information flows are secure. Is incorrect because the use of Public Key Infrastructure (PKI) does nothing to secure the channels.
The sender of the message is the only other person with access to the recipient's private key. Is incorrect because the sender does not have access to the recipient's private key though Public Key Infrastructure (PKI).
Reference(s) used for this question:
OIG CBK Cryptography (pages 253 - 254)

 

NEW QUESTION 171
Which of the following biometrics devices has the highest Crossover Error Rate (CER)?

  • A. Iris scan
  • B. Voice pattern
  • C. Fingerprints
  • D. Hand geometry

Answer: B

Explanation:
The Crossover Error Rate (CER) is the point where false rejection rate (type I error) equals the false acceptance rate (type II error). The lower the CER, the better the accuracy of the device. At the time if this writing, response times and accuracy of some devices are:
System type Response time Accuracy (CER)
Fingerprints 5-7 secs. 5%
Hand Geometry 3-5 secs. 2%
Voice Pattern 10-14 secs. 10%
Retina Scan 4-7 secs. 15%
Iris Scan 25-4 secs. 05%
The term EER which means Equal Error Rate is sometimes use instead of the term CER. It has the same meaning.
Source: Chris Hare's CISSP Study Notes on Physical Security, based on ISC2 CBK document. Available at http://www.ccure.org.

 

NEW QUESTION 172
Which of the following rules is least likely to support the concept of least privilege?

  • A. Permissions on tools that are likely to be used by hackers should be as restrictive as possible.
  • B. The number of administrative accounts should be kept to a minimum.
  • C. Only data to and from critical systems and applications should be allowed through the firewall.
  • D. Administrators should use regular accounts when performing routine operations like reading mail.

Answer: C

Explanation:
Only data to and from critical systems and applications should be allowed through the firewall is a detractor. Critical systems or applications do not necessarily need to have traffic go through a firewall. Even if they did, only the minimum required services should be allowed. Systems that are not deemed critical may also need to have traffic go through the firewall.
Least privilege is a basic tenet of computer security that means users should be given only those rights required to do their jobs or tasks. Least privilege is ensuring that you have the minimum privileges necessary to do a task. An admin NOT using his admin account to check email is a clear example of this.
Reference(s) used for this question:
National Security Agency, Systems and Network Attack Center (SNAC), The 60 Minute
Network Security Guide, February 2002, page 9.

 

NEW QUESTION 173
CobiT was developed from the COSO framework. Which of the choices below best describe the COSO's main objectives and purpose?

  • A. COSO is risk management system used for the protection of federal systems.
  • B. COSO main purpose is to define a sound risk management approach within financial companies.
  • C. COSO main purpose is to help ensure fraudulent financial reporting cannot take place in an organization
  • D. COSO addresses corporate culture and policy development.

Answer: C

Explanation:
The Committee of Sponsoring Organizations of the Treadway Commission (COSO)2 was formed in 1985 to sponsor the National Commission on Fraudulent Financial Reporting, which studied factors that lead to fraudulent financial reporting and produced recommendations for public companies, their auditors, the Securities Exchange Commission, and other regulators. COSO identifies five areas of internal control necessary to meet the financial reporting and disclosure objectives.
These include:
(1)
control environment,
(2)
risk assessment,
(3)
control activities,
(4)
information and communication, and
(5)
monitoring.
The COSO internal control model has been adopted as a framework by some organizations working toward Sarbanes-Oxley Section 404 compliance.
COSO deals more at the strategic level, while CobiT focuses more at the operational level. CobiT is a way to meet many of the COSO objectives, but only from the IT perspective. COSO deals with non-IT items also, as in company culture, financial accounting principles, board
of director responsibility, and internal communication structures.
Its main purpose is to help ensure fraudulent financial reporting cannot take place in an
organization.
COBIT
Control Objectives for Information and related Technology (COBIT)4 is published by the IT
Governance Institute and integrates the following IT and risk frameworks:
CobiT 4.1
Val IT 2.0
Risk IT
IT Assurance Framework (ITAF)
Business Model for Information Security (BMIS)
The COBIT framework examines the effectiveness, efficiency, confidentiality, integrity, availability,
compliance, and reliability aspects of the high-level control objectives. The framework provides an
overall structure for information technology control and includes control objectives that can be
utilized to determine effective security control objectives that are driven from the business needs.
The Information Systems Audit and Control Association (ISACA) dedicates numerous resources to
the support and understanding of COBIT.
The following answers are incorrect:
COSO main purpose if to define a sound risk management approach within financial companies.
COSO addresses corporate culture and policy development.
COSO is risk management system used for the protection of federal systems.
The following reference(s) were/was used to create this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition
((ISC)2 Press) (Kindle Locations 9791-9800). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 174
Which type of cabling below is the most common type for recent Ethernet installations?

  • A. ThickNet
  • B. ThinNet
  • C. Twinax
  • D. Twisted Pair

Answer: D

Explanation:
Category 5 Unshielded Twisted Pair (UTP) is rated for very high data throughput (100 Mbps) at short distances (up to 100 meters), and is the standard cable type for Ethernet installations.
*ThickNet, also known as 10Base5, uses traditional thick coaxial (coax) cable at data rates of up
to 10 Mbps.
*ThinNet, uses a thinner gauge coax, and is known as 10Base2. It has a shorter maximum
segment distance than ThickNet, but is less expensive to install (also known as CheaperNet).
*Twinax, is like ThinNet, but has two conductors, and was used in IBM Systems 36 and earlier
AS/400 installations.
Source: Communications Systems and Networks by Ray
Horak (M&T Books, 2000).

 

NEW QUESTION 175
......


ISC2 CISSP Exam Certification Details:

Schedule ExamPearson VUE
Sample QuestionsISC2 CISSP Sample Questions
Exam Price$699 (USD)
Duration180 mins
Exam NameISC2 Certified Information Systems Security Professional (CISSP)
Number of Questions100-150
Exam CodeCISSP
Passing Score700/1000

Go to CISSP Questions - Try CISSP dumps pdf : https://www.prepawaypdf.com/ISC/CISSP-practice-exam-dumps.html

Dumps Practice Exam Questions Study Guide for the CISSP Exam: https://drive.google.com/open?id=18VbCJ6DmQxHXUZSlNrPnABmrHu484M8I