CISSP DOMAIN 1 TEST QUESTIONS
AND CORRECT ANSWERS
What are the 6 steps of the NIST Risk Management Framework? - Answer- 1.
Categorize the system
2. Select security controls
3. Implement the security controls
4. Assess the security controls
5. Authorize the operation of the system
6. Monitor the security controls effectiveness
What Act made it illegal to access or harm federal computers and was amended in 1986
to include federal interest computers? - Answer- Comprehensive Crime Control Act
(CCCA)
What encryption standard uses a long series of XOR operations and repeats the
process 16 times for each encryption/decryption operation? - Answer- Data Encryption
Standard (DES)
What are 3 ways to exchange secret keys securely? - Answer- 1. Offline distribution
2. Public key infrastructure/CA
3. Diffie-Hellman key exchange
What Act complemented the US Computer Fraud and Abuse Act of 1986 and prohibited
eavesdropping, etc. without permission, which was later amended by the USA Patriot
Act authorizing it for felony violations? - Answer- US Electronic Communication Privacy
Act 1986
What control framework is required by all US government agencies and is also widely
adopted in private industry? - Answer- NIST SP800-53
Security and Privacy Controls
AES (Advanced Encryption Standard) uses what block cipher? - Answer- Rijndael
What algorithm does the alternative key escrow approach, Escrowed Encryption
Standard (aka Clipper), use? - Answer- Skipjack
ISACA and ITGI developed this control framework for IT management and IT
governance. - Answer- COBIT (Control Objectives for Information and Related
Technologies)
AND CORRECT ANSWERS
What are the 6 steps of the NIST Risk Management Framework? - Answer- 1.
Categorize the system
2. Select security controls
3. Implement the security controls
4. Assess the security controls
5. Authorize the operation of the system
6. Monitor the security controls effectiveness
What Act made it illegal to access or harm federal computers and was amended in 1986
to include federal interest computers? - Answer- Comprehensive Crime Control Act
(CCCA)
What encryption standard uses a long series of XOR operations and repeats the
process 16 times for each encryption/decryption operation? - Answer- Data Encryption
Standard (DES)
What are 3 ways to exchange secret keys securely? - Answer- 1. Offline distribution
2. Public key infrastructure/CA
3. Diffie-Hellman key exchange
What Act complemented the US Computer Fraud and Abuse Act of 1986 and prohibited
eavesdropping, etc. without permission, which was later amended by the USA Patriot
Act authorizing it for felony violations? - Answer- US Electronic Communication Privacy
Act 1986
What control framework is required by all US government agencies and is also widely
adopted in private industry? - Answer- NIST SP800-53
Security and Privacy Controls
AES (Advanced Encryption Standard) uses what block cipher? - Answer- Rijndael
What algorithm does the alternative key escrow approach, Escrowed Encryption
Standard (aka Clipper), use? - Answer- Skipjack
ISACA and ITGI developed this control framework for IT management and IT
governance. - Answer- COBIT (Control Objectives for Information and Related
Technologies)