Prepare for your exam certification with our CISSP Certified ISC [Q702-Q722]

Share

Prepare for your exam certification with our CISSP Certified ISC

Free ISC CISSP Exam 2024 Practice Materials Collection

NEW QUESTION # 702
What is the primary role of cross certification?

  • A. Build an overall PKI hierarchy
  • B. Creating trust between different PKIs
  • C. set up direct trust to a second root CA
  • D. Prevent the nullification of user certificates by CA certificate revocation

Answer: B

Explanation:
More and more organizations are setting up their own internal PKIs. When these
independent PKIs need to interconnect to allow for secure communication to take place (either
between departments or different companies), there must be a way for the two root CAs to trust
each other.
These two CAs do not have a CA above them they can both trust, so they must carry out cross
certification. A cross certification is the process undertaken by CAs to establish a trust relationship
in which they rely upon each other's digital certificates and public keys as if they had issued them
themselves.
When this is set up, a CA for one company can validate digital certificates from the other company
and vice versa.
Reference(s) used for this question:
For more information and illustration on Cross certification:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03qsw
p.mspx http://www.entrust.com/resources/pdf/cross_certification.pdf
also see:
Shon Harris, CISSP All in one book, 4th Edition, Page 727
and
RFC 2459: Internet X.509 Public Key Infrastructure Certificate and CRL Profile; FORD, Warwick &
BAUM, Michael S., Secure Electronic Commerce: Building the Infrastructure for Digital Signatures
and Encryption (2nd Edition), 2000, Prentice Hall PTR, Page 254.


NEW QUESTION # 703
How many layers are defined within the US Department of Defense (DoD) TCP/IP Model?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
The TCP/IP protocol model is similar to the OSI model but it defines only four layers:
Application
Host-to-host
Internet
Network access
Reference(s) used for this question:
http://www.novell.com/documentation/nw65/ntwk_ipv4_nw/data/hozdx4oj.html and
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 84).
also see:
http://en.wikipedia.org/wiki/Internet_Protocol_Suite#Layer_names_and_number_of_layers_ in_the_literature


NEW QUESTION # 704
Who is ultimately responsible to ensure that information assets are categorized and adequate measures are taken to protect them?

  • A. Data Custodian
  • B. Chief Information Security Officer
  • C. Executive Management
  • D. Data/Information/Business Owners

Answer: C


NEW QUESTION # 705
Which of the following components are considered part of the Trusted Computing Base?

  • A. Trusted hardware and software.
  • B. Trusted hardware and firmware.
  • C. Trusted hardware, software and firmware.
  • D. Trusted computer operators and system managers.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The trusted computing base (TCB) is a collection of all the hardware, software, and firmware components within a system that provide some type of security and enforce the system's security policy. The TCB does not address only operating system components, because a computer system is not made up of only an operating system. Hardware, software components, and firmware components can affect the system in a negative or positive manner, and each has a responsibility to support and enforce the security policy of that particular system. Some components and mechanisms have direct responsibilities in supporting the security policy, such as firmware that will not let a user boot a computer from a USB drive, or the memory manager that will not let processes overwrite other processes' data. Then there are components that do not enforce the security policy but must behave properly and not violate the trust of a system. Examples of the ways in which a component could violate the system's security policy include an application that is allowed to make a direct call to a piece of hardware instead of using the proper system calls through the operating system, a process that is allowed to read data outside of its approved memory space, or a piece of software that does not properly release resources after use.
To assist with the evaluation of secure products, TCSEC introduced the idea of the Trusted Computing Base (TCB) into product evaluation. In essence, TCSEC starts with the principle that there are some functions that simply must be working correctly for security to be possible and consistently enforced in a computing system. For example, the ability to define subjects and objects and the ability to distinguish between them is so fundamental that no system could be secure without it. The TCB then are these fundamental controls implemented in a given system, whether that is in hardware, software, or firmware.
Each of the TCSEC levels describes a different set of fundamental functions that must be in place to be certified to that level.
Incorrect Answers:
A: Software is also considered part of the Trusted Computing Base.
B: Firmware is also considered part of the Trusted Computing Base.
D: Trusted computer operators and system managers are not considered part of the Trusted Computing Base.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 360
https://www.freepracticetests.org/documents/TCB.pdf


NEW QUESTION # 706
A server cluster looks like a:

  • A. single server from the user's point of view.
  • B. quardle server from the user's point of view.
  • C. triple server from the user's point of view.
  • D. dual server from the user's point of view.

Answer: A

Explanation:
The cluster looks like a single server from the user's point of view.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, 2001, John Wiley & Sons, Page 67.


NEW QUESTION # 707
A security practitioner has just been assigned to address an ongoing Denial of Service (DoS) attack against the company's network, which includes an e-commerce web site. The strategy has to include defenses for any size of attack without rendering the company network unusable.
Which of the following should be a PRIMARY concern when addressing this issue?

  • A. Ensure the web sites are properly backed up on a daily basis.
  • B. Pay more for a dedicated path to the Internet.
  • C. Allow legitimate connections while blocking malicious connections.
  • D. Deal with end user education and training.

Answer: C


NEW QUESTION # 708
DRAG DROP
Order the below steps to create an effective vulnerability management process.

Answer:

Explanation:


NEW QUESTION # 709
Which of the following is a NOT a guideline necessary to enhance security in the critical Heating Ventilation Air Conditioning (HVAC) aspect of facility operations?

  • A. Restrict access to main air intake points to persons who have a work-related reason to be there
  • B. Ensure that all air intake points are adequately secured with locking devices
  • C. Maintain access rosters of maintenance personnel who are not authorized to work on the system
  • D. Escort all contractors with access to the system while on site

Answer: C

Explanation:
This is a DETAIL oriented question. While you may not know the answer to such questions, look for things that just do not seem logical. As far as the exam is concerned, there will be negative questions, most people will trip and miss the NOT keyword because they are reading too fast.
In this case, by changing just a few key words, a correct answer becomes a wrong one. The book has "Maintain access rosters of pre-approved maintenance personnel authorized to work on the system"
While you can theoretically keep rosters of people you don't want to work on the system, this not not really practical. A much better approach is to keep a list of those who ARE approved.
HVAC is commonly overlooked from a physical security standpoint. From the ISC2 guide
"Over the past several years there has been an increasing awareness dealing with anthrax and
airborne attacks. Harmful agents introduced into the HVAC systems can rapidly spread throughout
the structure and infect all persons exposed to the circulated air."
On a practical real world note; for those who work in smaller shops without a dedicated
maintenance team, where you have to outsource. It would be wise to make sure that NO ONE has
access other than when you call them for service. If a maintenance technician shows up on your
doorstep wanting access so they can service the equipment, CALL your vendors MAIN line using
the number that YOU have and verify that they sent someone out. Don't take the technicians word
for it, or you may just become a victim of social engineering.
The following answers are incorrect:
Restrict access to main air intake points to persons who have a work-related reason to be there
Escort all contractors with access to the system while on site
Ensure that all air intake points are adequately secured with locking devices
The following reference(s) were/was used to create this question:
Tipton, Harold F. (2010-04-20). Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2
Press), Chapter 8, Physical and Enviromental Security "Enviromental Controls, HVAC"


NEW QUESTION # 710
Which of the following is defined as the most recent point in time to which data must be synchronized without adversely affecting the organization (financial or operational impacts)?

  • A. Recovery Time Objective
  • B. Recovery Point Objective
  • C. Critical Time Objective
  • D. Point of Time Objective

Answer: B

Explanation:
The recovery point objective (RPO) is the maximum acceptable level of data loss following an unplanned "event", like a disaster (natural or man-made), act of crime or terrorism, or any other business or technical disruption that could cause such data loss. The RPO represents the point in time, prior to such an event or incident, to which lost data can be recovered (given the most recent backup copy of the data).
The recovery time objective (RTO) is a period of time within which business and / or technology capabilities must be restored following an unplanned event or disaster. The RTO is a function of the extent to which the interruption disrupts normal operations and the amount of revenue lost per unit of time as a result of the disaster.
These factors in turn depend on the affected equipment and application(s). Both of these numbers represent key targets that are set by key businesses during business continuity and disaster recovery planning; these targets in turn drive the technology and implementation choices for business resumption services, backup / recovery / archival services, and recovery facilities and procedures.
Many organizations put the cart before the horse in selecting and deploying technologies before understanding the business needs as expressed in RPO and RTO; IT departments later bear the brunt of user complaints that their service expectations are not being met. Defining the RPO and RTO can avoid that pitfall, and in doing so can also make for a compelling business case for recovery technology spending and staffing.
For the CISSP candidate studying for the exam, there are no such objectives for "point of time," and "critical time." Those two answers are simply detracters.
Reference:
http://www.wikibon.org/Recovery_point_objective_/_recovery_time_objective_strategy


NEW QUESTION # 711
Which of the following method is recommended by security professional to PERMANENTLY erase sensitive data on magnetic media?

  • A. Overwrite every sector of magnetic media with pattern of 1's and 0's
  • B. Format magnetic media
  • C. Delete File allocation table
  • D. Degaussing

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Degaussing is the most effective method out of all the provided choices to erase sensitive data on magnetic media.
A device that performs degaussing generates a coercive magnetic force that reduces the magnetic flux density of the storage media to zero. This magnetic force is what properly erases data from media. Data are stored on magnetic media by the representation of the polarization of the atoms. Degaussing changes this polarization (magnetic alignment) by using a type of large magnet to bring it back to its original flux (magnetic alignment).
Simply deleting files or formatting the media does not actually remove the information. File deletion and media formatting often simply remove the pointers to the information.
Specialized hardware devices known as degaussers can be used to erase data saved to magnetic media.
The measure of the amount of energy needed to reduce the magnetic field on the media to zero is known as coercivity. It is important to make sure that the coercivity of the degausser is of sufficient strength to meet object reuse requirements when erasing data. If a degausser is used with insufficient coercivity, then a remanence of the data will exist.
Remanence is the measure of the existing magnetic field on the media; it is the residue that remains after an object is degaussed or written over. Data is still recoverable even when the remanence is small. While data remanence exists, there is no assurance of safe object reuse. Some degaussers can destroy drives.
The security professional should exercise caution when recommending or using degaussers on media for reuse.
Incorrect Answers:
B: Software tools also exist that can provide object reuse assurance. These tools overwrite every sector of magnetic media with a random or predetermined bit pattern. Overwrite methods are effective for all forms of electronic media with the exception of read-only optical media. There is a drawback to using overwrite software. During normal write operations with magnetic media, the head of the drive moves back-and-forth across the media as data is written. The track of the head does not usually follow the exact path each time.
The result is a miniscule amount of data remanence with each pass. With specialized equipment, it is possible to read data that has been overwritten. Degaussing is more effective than overwriting the sectors.
C: Simply deleting files or formatting the media does not actually remove the information. File deletion and media formatting often simply removes the pointers to the information.
D: Deleting the File allocation table will not erase all data. The data can be recoverable using software tools.


NEW QUESTION # 712
What is the difference between the OCSP (Online Certificate Status Protocol) and a Certificate Revocation List (CRL)?

  • A. The OCSP (Online Certificate Status Protocol) is a proprietary certificate mechanism developed by Microsoft and a Certificate Revocation List (CRL) is an open standard.
  • B. The OCSP (Online Certificate Status Protocol) provides real-time certificate checks and a Certificate Revocation List (CRL) has a delay in the updates.
  • C. The OCSP (Online Certificate Status Protocol) is a way to check the attributes of a certificate and a Certificate Revocation List (CRL) is used by Certificate Authorities.
  • D. The OCSP (Online Certificate Status Protocol) is used only by Active Directory and a Certificate Revocation List (CRL) is used by Certificate Authorities

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The CA is responsible for creating and handing out certificates, maintaining them, and revoking them if necessary. Revocation is handled by the CA, and the revoked certificate information is stored on a certificate revocation list (CRL). This is a list of every certificate that has been revoked. This list is maintained and updated periodically.
Online Certificate Status Protocol (OCSP) is being used more and more rather than the cumbersome CRL approach. When using just a CRL, the user's browser must either check a central CRL to find out if the certification has been revoked or the CA has to continually push out CRL values to the clients to ensure they have an updated CRL. If OCSP is implemented, it does this work automatically in the background. It carries out real-time validation of a certificate and reports back to the user whether the certificate is valid, invalid, or unknown. OCSP checks the CRL that is maintained by the CA. So the CRL is still being used, but now we have a protocol developed specifically to check the CRL during a certificate validation process.
Incorrect Answers:
B: The OCSP (Online Certificate Status Protocol) is not a proprietary certificate mechanism developed by Microsoft; it is an open standard.
C: The OCSP (Online Certificate Status Protocol) is not used only by Active Directory.
D: The OCSP (Online Certificate Status Protocol) is not a way to check the attributes of a certificate; it is a way to check the revocation status of a certificate.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 836-837


NEW QUESTION # 713
Which security model introduces access to objects only through programs?

  • A. The Biba model
  • B. The Bell-LaPadula model
  • C. The Clark-Wilson model
  • D. The information flow model

Answer: C

Explanation:
In the Clark-Wilson model, the subject no longer has direct access to objects but
instead must access them through programs (well -formed transactions).
The Clark-Wilson integrity model provides a foundation for specifying and analyzing an integrity
policy for a computing system.
The model is primarily concerned with formalizing the notion of information integrity. Information
integrity is maintained by preventing corruption of data items in a system due to either error or
malicious intent. An integrity policy describes how the data items in the system should be kept
valid from one state of the system to the next and specifies the capabilities of various principals in
the system. The model defines enforcement rules and certification rules.
Clark-Wilson is more clearly applicable to business and industry processes in which the integrity
of the information content is paramount at any level of classification.
Integrity goals of Clark-Wilson model:
Prevent unauthorized users from making modification (Only this one is addressed by the Biba
model).
Separation of duties prevents authorized users from making improper modifications.
Well formed transactions: maintain internal and external consistency i.e. it is a series of operations
that are carried out to transfer the data from one consistent state to the other.
The following are incorrect answers:
The Biba model is incorrect. The Biba model is concerned with integrity and controls access to
objects based on a comparison of the security level of the subject to that of the object.
The Bell-LaPdaula model is incorrect. The Bell-LaPaula model is concerned with confidentiality
and controls access to objects based on a comparison of the clearence level of the subject to the
classification level of the object.
The information flow model is incorrect. The information flow model uses a lattice where objects
are labelled with security classes and information can flow either upward or at the same level. It is
similar in framework to the Bell-LaPadula model.
References:
ISC2 Official Study Guide, Pages 325 - 327
AIO3, pp. 284 - 287
AIOv4 Security Architecture and Design (pages 338 - 342)
AIOv5 Security Architecture and Design (pages 341 - 344)
Wikipedia at: https://en.wikipedia.org/wiki/Clark-Wilson_model


NEW QUESTION # 714
Configuring a Wireless Access Point (WAP) with the same Service Set Identifier (SSID) as another WAP in order to have users unknowingly connect is referred to as which of the following?

  • A. Internet Protocol (IP) spoofing
  • B. Man-irHht-Middk (MITM)
  • C. War driving
  • D. Jamming

Answer: B


NEW QUESTION # 715
DRAG DROP
Place the following information classification steps in sequential order.

Answer:

Explanation:


NEW QUESTION # 716
What is the MAIN reason for testing a Disaster Recovery Plan (DRP)?

  • A. To validate backup sites' effectiveness
  • B. To ensure Information Technology (IT) staff knows and performs roles assigned to each of them
  • C. To find out what does not work and fix it
  • D. To create a high level DRP awareness among Information Technology (IT) staff

Answer: A


NEW QUESTION # 717
Lack of which of the following options could cause a negative effect on an organization's reputation, revenue, and result in legal action, if the organization fails to perform due diligence?

  • A. Service Level Requirement (SLR)
  • B. Service Level Agreement (SLA)
  • C. Threat modeling methodologies
  • D. Third-party risk management

Answer: B


NEW QUESTION # 718
When should security isolation of the incident scene start?

  • A. As soon as the disaster plan is implemented
  • B. After all personnel have been evacuated
  • C. When hazardous materials have been discovered at the site
  • D. Immediately after the emergency is discovered

Answer: D

Explanation:
Isolation of the incident scene should begin as soon as the emergency has been discovered. Authorized personnel should attempt to secure the scene and control access; however, no one should be placed in physical danger to perform these functions. Its important for life safety that access be controlled immediately at the scene, and only by trained personnel directly involved in the disaster response. Additional injury or exposure to recovery personnel after the initial incident must be tightly controlled. Source: Emergency Management Guide for Business and Industry, Federal Emergency Management Agency, August, 1998.


NEW QUESTION # 719
A packet filtering firewall looks at the data packet to get information about the source and destination addresses of an incoming packet, the protocol (TCP, UDP, or ICMP), and the source and destination port for the:

  • A. desired service.
  • B. dedicated service.
  • C. delayed service.
  • D. distributed service.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Packet filtering is a firewall technology that makes access decisions based upon network-level protocol header values. The filters can make access decisions based upon the following basic criteria:
Source and destination port numbers (such as an application port or a service number)

Protocol types

Source and destination IP addresses

Inbound and outbound traffic direction

Incorrect Answers:
B: A packet filtering firewall can grant access to desired services, not dedicated services, through source and destination numbers.
C: A packet filtering firewall can grant access to desired services, not delayed services, through source and destination numbers.
D: A packet filtering firewall can grant access to desired services, not distributed services, through source and destination numbers.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 630


NEW QUESTION # 720
Which statement below is NOT correct regarding the role of the recovery team during the disaster?

  • A. The recovery team will need full access to all backup media.
  • B. The recovery teams primary task is to get predefined critical business functions operating at the alternate processing site.
  • C. The recovery team must be the same as the salvage team as they perform the same function.
  • D. The recovery team is often separate from the salvage team as they
    perform different duties.

Answer: C

Explanation:
The recovery team performs different functions
from the salvage team. The recovery teams primary mandate is
to get critical processing re-established at an alternate site. The salvage teams primary mandate is to return the original processing site to normal processing environmental conditions.


NEW QUESTION # 721
Which of the following European Union (EU) principles pertaining to the protection of information on private individuals is incorrect?

  • A. Transmission of personal information to locations where "equivalent" personal data protection cannot be assured is prohibited.
  • B. Records kept on an individual should be accurate and up to date.
  • C. Individuals have the right to correct errors contained in their personal data.
  • D. Data collected by an organization can be used for any purpose and for as long as necessary, as long as it is never communicated outside of the organization by which it was collected.

Answer: D

Explanation:
Data should be used only for the purposes for which it was collected, and it should be used only for a reasonable period of time. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 9: Law, Investigation, and Ethics (page 302).


NEW QUESTION # 722
......

Pass ISC CISSP Actual Free Exam Q&As Updated Dump: https://www.prepawaypdf.com/ISC/CISSP-practice-exam-dumps.html

CISSP Exam Info and Free Practice Test All-in-One Exam Guide Jan-2024: https://drive.google.com/open?id=1Z3gjIdlfnMGeltcNh9fSc7VM7bv-sWOB