CISSP DOMAIN 1 EXAM WITH 100%
CORRECT ANSWERS
Which type of goals are midterm goals? - Answer- tactical goals
What is International Standards Organization (ISO) 17799? - Answer- a standard that
provides recommendations on enterprise security
What is the number one criterion used to determine the classification of an information
object? - Answer- asset value
Which pillar of Basel II determines the lowest amount of funds that a financial institute
must keep on hand? - Answer- the Minimum Capital Requirements pillar
Which component of a computer use policy indicates that data stored on a company
computer is not guaranteed to remain confidential? - Answer- a no expectation of
privacy policy
Which standard applies to any entity that transmits, stores, or accepts credit card data?
- Answer- the Payment Card Industry Data Security Standard (PCI DSS)
Which federal agency is responsible for HIPAA enforcement? - Answer- the Office of
Civil Rights (OCR) of the Department of Health and Human Services (HHS)
Who should oversee the development of the information security policy? - Answer- an
organization's business operations manager
What is an exposure? - Answer- an instance of being exposed to losses from a threat
Which type of plan should address residual risks? - Answer- a contingency plan
In the United States, which body of government is responsible for the creation of
common law? - Answer- the judicial branch of government
Which European guidelines state that the data gathered for private individuals should
only be used for the purpose for which it is collected? - Answer- the European Union
Principles on Privacy
, What is the Clipping level? - Answer- the baseline that sets certain thresholds for
specific errors or mistakes allowed, and the number of these occurrences that can take
place before it is considered suspicious
What are the European Privacy Principles? - Answer- The reason for gathering data
must be stated when the data is collected.
Data cannot be used for other purposes other than those specifically stated at
collection.
Data that is not needed should not be collected.
Data should only be kept while it is needed to accomplish a stated task.
Only individuals who are required to accomplish a stated task should be given access
to the data.
The individuals responsible for securely storing the data should not allow unintentional
leaking of data.
What are the four strategic responses to negative risks? - Answer- avoid, transfer,
mitigate, and accept
How is annualized loss expectancy (ALE) calculated? - Answer- ALE = single loss
expectancy (SLE) x annualized rate of occurrence (ARO)
Which formula should you use to determine the single loss expectancy (SLE) of an
asset? - Answer- Asset value x exposure factor (EF)
What is another name for a security class in the lattice-based access control model? -
Answer- a security label
Which type of law governs the payment of compensation and fines without sentencing
the offenders to jail? - Answer- civil or tort law
Who is responsible for ensuring computer security in an organization? - Answer- all the
employees of the organization
What does the acronym NIST denote? - Answer- National Institute of Standards and
Technology
Who is primarily responsible for accepting ownership of organization security? -
Answer- senior management
What are standards? - Answer- the mandated rules that govern the acceptable level of
security for hardware and software
Which three security objectives are core to the protection of information assets of an
organization? - Answer- availability, integrity, and confidentiality
CORRECT ANSWERS
Which type of goals are midterm goals? - Answer- tactical goals
What is International Standards Organization (ISO) 17799? - Answer- a standard that
provides recommendations on enterprise security
What is the number one criterion used to determine the classification of an information
object? - Answer- asset value
Which pillar of Basel II determines the lowest amount of funds that a financial institute
must keep on hand? - Answer- the Minimum Capital Requirements pillar
Which component of a computer use policy indicates that data stored on a company
computer is not guaranteed to remain confidential? - Answer- a no expectation of
privacy policy
Which standard applies to any entity that transmits, stores, or accepts credit card data?
- Answer- the Payment Card Industry Data Security Standard (PCI DSS)
Which federal agency is responsible for HIPAA enforcement? - Answer- the Office of
Civil Rights (OCR) of the Department of Health and Human Services (HHS)
Who should oversee the development of the information security policy? - Answer- an
organization's business operations manager
What is an exposure? - Answer- an instance of being exposed to losses from a threat
Which type of plan should address residual risks? - Answer- a contingency plan
In the United States, which body of government is responsible for the creation of
common law? - Answer- the judicial branch of government
Which European guidelines state that the data gathered for private individuals should
only be used for the purpose for which it is collected? - Answer- the European Union
Principles on Privacy
, What is the Clipping level? - Answer- the baseline that sets certain thresholds for
specific errors or mistakes allowed, and the number of these occurrences that can take
place before it is considered suspicious
What are the European Privacy Principles? - Answer- The reason for gathering data
must be stated when the data is collected.
Data cannot be used for other purposes other than those specifically stated at
collection.
Data that is not needed should not be collected.
Data should only be kept while it is needed to accomplish a stated task.
Only individuals who are required to accomplish a stated task should be given access
to the data.
The individuals responsible for securely storing the data should not allow unintentional
leaking of data.
What are the four strategic responses to negative risks? - Answer- avoid, transfer,
mitigate, and accept
How is annualized loss expectancy (ALE) calculated? - Answer- ALE = single loss
expectancy (SLE) x annualized rate of occurrence (ARO)
Which formula should you use to determine the single loss expectancy (SLE) of an
asset? - Answer- Asset value x exposure factor (EF)
What is another name for a security class in the lattice-based access control model? -
Answer- a security label
Which type of law governs the payment of compensation and fines without sentencing
the offenders to jail? - Answer- civil or tort law
Who is responsible for ensuring computer security in an organization? - Answer- all the
employees of the organization
What does the acronym NIST denote? - Answer- National Institute of Standards and
Technology
Who is primarily responsible for accepting ownership of organization security? -
Answer- senior management
What are standards? - Answer- the mandated rules that govern the acceptable level of
security for hardware and software
Which three security objectives are core to the protection of information assets of an
organization? - Answer- availability, integrity, and confidentiality