Give Push to your Success with ISC Certification CISSP Exam Questions [Q781-Q797]

Share

Give Push to your Success with ISC Certification CISSP Exam Questions

CISSP 100% Guarantee Download CISSP Exam PDF Q&A


The CISSP certification exam is designed to test an individual's knowledge of the eight domains of information security, which include security and risk management, asset security, security engineering, communications and network security, identity and access management, security assessment and testing, security operations, and software development security. CISSP exam is intended for professionals with at least five years of experience in the field of information security.


ISC CISSP Certification Exam is designed to ensure that professionals who hold the certification have a comprehensive understanding of information security and are equipped with the skills to manage and mitigate security risks. Certified Information Systems Security Professional certification is recognized by a wide range of organizations, including government agencies, financial institutions, and multinational corporations. Certified Information Systems Security Professional certification is also recognized by the U.S. Department of Defense (DoD) for its Information Assurance Technical (IAT) and Information Assurance Managerial (IAM) categories.


ISC CISSP (Certified Information Systems Security Professional) Certification Exam is a challenging and respected certification that can help professionals to advance their careers in the field of information security. Certified Information Systems Security Professional certification covers a wide range of topics related to information security and requires candidates to have a minimum of five years of professional experience in the field. The benefits of obtaining the certification are numerous, including career advancement opportunities, access to a network of professionals, and recognition by organizations and businesses worldwide.

 

NEW QUESTION # 781
Compared with hardware cryptography, software cryptography is generally

  • A. less expensive and faster.
  • B. more expensive and faster.
  • C. less expensive and slower.
  • D. more expensive and slower.

Answer: C

Explanation:
Section: Mixed questions
Explanation/Reference: https://www.ontrack.com/uk/blog/making-data-simple/hardware-encryption-vs-software-encryption- the-simple-guide/


NEW QUESTION # 782
Which of the following virus types changes some of its characteristics as it spreads?

  • A. Polymorphic
  • B. Stealth
  • C. Parasitic
  • D. Boot Sector

Answer: A

Explanation:
A Polymorphic virus produces varied but operational copies of itself in hopes of evading anti-virus software.
The following answers are incorrect:
boot sector. Is incorrect because it is not the best answer. A boot sector virus attacks the boot sector of a drive. It describes the type of attack of the virus and not the characteristics of its composition.
parasitic. Is incorrect because it is not the best answer. A parasitic virus attaches itself to other files but does not change its characteristics.
stealth. Is incorrect because it is not the best answer. A stealth virus attempts to hide changes of the affected files but not itself.


NEW QUESTION # 783
What can be defined as an instance of two different keys generating the same ciphertext from the same plaintext?

  • A. Ciphertext collision
  • B. Key clustering
  • C. Hashing
  • D. Key collision

Answer: B

Explanation:
Key clustering happens when a plaintext message generates identical ciphertext messages using the same transformation algorithm, but with different keys.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 4: Cryptography
(page 130).


NEW QUESTION # 784
A large university needs to enable student access to university resources from their homes. Which of the following provides the BEST option for low maintenance and ease of deployment?

  • A. Use Secure Sockets Layer (SSL) VPN technology.
  • B. Provide students with Internet Protocol Security (IPSec) Virtual Private Network (VPN) client software.
  • C. Require students to purchase home router capable of VPN.
  • D. Use Secure Shell (SSH) with public/private keys.

Answer: A


NEW QUESTION # 785
Which security approach will BEST minimize Personally Identifiable Information (PII) loss from a data breach?

  • A. A strong breach notification process
  • B. End-to-end data encryption for data in transit
  • C. Continuous monitoring of potential vulnerabilities
  • D. Limited collection of individuals' confidential data

Answer: D


NEW QUESTION # 786
Which of the following is true of two-factor authentication?

  • A. It requires two measurements of hand geometry
  • B. It does not use single sign-on technology
  • C. It relies on two independent proofs of identity
  • D. It uses the RSA public-key signature based algorithm on integers with large prime factors

Answer: C


NEW QUESTION # 787
What is the window of time for recovery of information processing capabilities based on?

  • A. Quality of the data to be processed
  • B. Criticality of the operations affected
  • C. Applications that are mainframe based
  • D. Nature of the disaster

Answer: B


NEW QUESTION # 788
Which security model ensures that actions that take place at a higher security level do not affect actions that take place at a lower level?

  • A. The Clark-Wilson model
  • B. The information flow model
  • C. The noninterference model
  • D. The Bell-LaPadula model

Answer: C

Explanation:
The goal of a noninterference model is to strictly separate differing security levels to assure that higher-level actions do not determine what lower-level users can see. This is in contrast to other security models that control information flows between differing levels of users, By maintaining strict separation of security levels, a noninterference model minimizes leakages that might happen through a covert channel.
The model ensures that any actions that take place at a higher security level do not affect, or interfere with, actions that take place at a lower level.
It is not concerned with the flow of data, but rather with what a subject knows about the state of
the system. So if an entity at a higher security level performs an action, it can not change the state
for the entity at the lower level.
The model also addresses the inference attack that occurs when some one has access to some
type of information and can infer(guess) something that he does not have the clearance level or
authority to know.
The following are incorrect answers:
The Bell-LaPadula model is incorrect. The Bell-LaPadula model is concerned only with
confidentiality and bases access control decisions on the classfication of objects and the
clearences of subjects.
The information flow model is incorrect. The information flow models have a similar framework to
the Bell-LaPadula model and control how information may flow between objects based on security
classes. Information will be allowed to flow only in accordance with the security policy.
The Clark-Wilson model is incorrect. The Clark-Wilson model is concerned with change control
and assuring that all modifications to objects preserve integrity by means of well-formed
transactions and usage of an access triple (subjet - interface - object).
References:
CBK, pp 325 - 326
AIO3, pp. 290 - 291
AIOv4 Security Architecture and Design (page 345)
AIOv5 Security Architecture and Design (pages 347 - 348)
https://en.wikibooks.org/wiki/Security_Architecture_and_Design/Security_Models#Noninterference
_Models


NEW QUESTION # 789
Which of the following is the most important consideration in locating an alternate computing facility during the development of a disaster recovery plan?

  • A. it is convenient to airports and hotels
  • B. is it close enough to serve it's users
  • C. it is unlikely to be affected by the same contingency
  • D. it is close enough to become operation quickly

Answer: C


NEW QUESTION # 790
What is the MOST effective countermeasure to a malicious code attack against a mobile system?

  • A. Public-Key Infrastructure (PKI)
  • B. Sandbox
  • C. Memory management
  • D. Change control

Answer: B


NEW QUESTION # 791
When a biometric system is used, which error type deals with the possibility of GRANTING access to impostors who should be REJECTED?

  • A. Type III error
  • B. Type I error
  • C. Type II error
  • D. Crossover error

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A Type II error, or false acceptance rate, is when the system accepts impostors who should be rejected.
Incorrect Answers:
A: A Type I error, or false rejection rate, is when a biometric system rejects an authorized individual.
C: A Type III error does not exist in biometrics.
D: The crossover error rate (CER) is a percentage that signifies the point at which the false rejection rate equals the false acceptance rate.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 188
http://www.technovelgy.com/ct/Technology-Article.asp?ArtNum=93


NEW QUESTION # 792
Which of the following is the MOST appropriate action when reusing media that contains sensitive data?

  • A. Erase
  • B. Encrypt
  • C. Degauss
  • D. Sanitize

Answer: D

Explanation:
Section: Asset Security


NEW QUESTION # 793
Which access control model provides upper and lower bounds of access capabilities for a subject?

  • A. Role-based access control
  • B. Lattice-based access control
  • C. Content-dependent access control
  • D. Biba access control

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Lattice-based access control is a mathematical model that allows a system to easily represent the different security levels and control access attempts based on those levels. Every pair of elements has a highest lower bound and a lowest upper bound of access rights.
Incorrect Answers:
A: Role-based access control (RBAC) provides access to resources according to the role the user holds within the company or the tasks that the user has been assigned.
C: Biba is a security model, rather than an access control model. It centers on preventing information from flowing from a low integrity level to a high integrity level
D: Content-dependent access control is when the access decisions depend upon the value of an attribute of the object itself.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 224, 377, G-9
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.41.5365


NEW QUESTION # 794
A copy of a computer disk would be what type of evidence?

  • A. Hearsay
  • B. Best
  • C. Indirect
  • D. Direct
  • E. Secondary

Answer: A

Explanation:
A copy of a computer disk is considered hearsay, because unless it has been copied in a forensically approved manner, it is not credible evidence.


NEW QUESTION # 795
What is the primary role of cross certification?

  • A. Build an overall PKI hierarchy
  • B. Prevent the nullification of user certificates by CA certificate revocation
  • C. set up direct trust to a second root CA
  • D. Creating trust between different PKIs

Answer: D

Explanation:
More and more organizations are setting up their own internal PKIs. When these independent PKIs need to interconnect to allow for secure communication to take place (either between departments or different companies), there must be a way for the two root CAs to trust each other.
These two CAs do not have a CA above them they can both trust, so they must carry out cross certification. A cross certification is the process undertaken by CAs to establish a trust relationship in which they rely upon each other's digital certificates and public keys as if they had issued them themselves.
When this is set up, a CA for one company can validate digital certificates from the other company and vice versa.
Reference(s) used for this question:
For more information and illustration on Cross certification:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/w s03qswp.mspx http://www.entrust.com/resources/pdf/cross_certification.pdf also see:
Shon Harris, CISSP All in one book, 4th Edition, Page 727
and
RFC 2459: Internet X.509 Public Key Infrastructure Certificate and CRL Profile; FORD,
Warwick & BAUM, Michael S., Secure Electronic Commerce: Building the Infrastructure for
Digital Signatures and Encryption (2nd Edition), 2000, Prentice Hall PTR, Page 254.


NEW QUESTION # 796
Which statement below is NOT true regarding the relationship of the
organization with the media during and after a disaster?

  • A. The company should be honest and accurate about what they know
    about the event and its effects.
  • B. The organization should establish a unified organizational response to the media during and after the disruptive event.
  • C. The companys response should be delivered by a credible, informed
    spokesperson.
  • D. The organization must avoid dealing with the media at all costs during and after the disruptive event.

Answer: D


NEW QUESTION # 797
......

Get CISSP Actual Free Exam Q&As to Prepare Certification: https://examcollection.dumpsvalid.com/CISSP-brain-dumps.html