CISSP Certified Information Systems Security
Professional Practice Test Exam
1. Which security model focuses on preventing conflicts of
interest by dividing responsibilities?
A. Biba
B. Clark-Wilson
C. Brewer-Nash
D. Bell-LaPadula
Answer: C
Rationale: The Brewer-Nash model, also known as the Chinese
Wall model, prevents conflicts of interest by dynamically
separating access based on what the subject has already
accessed.
2. What is the primary purpose of the Bell-LaPadula model?
A. To ensure data integrity
B. To ensure data confidentiality
C. To prevent conflicts of interest
D. To enforce separation of duties
,Answer: B
Rationale: The Bell-LaPadula model focuses on data
confidentiality using no read up and no write down rules.
3. Which rule in the Bell-LaPadula model prevents a subject
from reading data at a higher classification?
A. No write down
B. No read up
C. No read down
D. No write up
Answer: B
Rationale: The no read up rule prevents subjects from reading
data at a higher classification level.
4. What does the Biba model focus on?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: B
,Rationale: The Biba model focuses on data integrity using no
read down and no write up rules.
5. Which access control model uses roles to assign permissions?
A. Discretionary access control
B. Mandatory access control
C. Role-based access control
D. Attribute-based access control
Answer: C
Rationale: Role-based access control assigns permissions based
on the roles users hold within an organization.
6. What is the purpose of the Clark-Wilson model?
A. To ensure integrity through well-formed transactions
B. To ensure confidentiality through labels
C. To prevent conflicts of interest
D. To enforce availability
Answer: A
Rationale: The Clark-Wilson model ensures integrity by
enforcing well-formed transactions and separation of duties.
, 7. Which type of attack involves an attacker intercepting
communication between two parties?
A. Denial of service
B. Man in the middle
C. Phishing
D. SQL injection
Answer: B
Rationale: A man in the middle attack occurs when an attacker
secretly intercepts and possibly alters communication between
two parties.
8. What is the purpose of a salt in password hashing?
A. To prevent rainbow table attacks
B. To speed up hashing
C. To encrypt passwords
D. To compress passwords
Answer: A
Rationale: A salt is random data added to a password before
hashing to prevent rainbow table attacks.
Professional Practice Test Exam
1. Which security model focuses on preventing conflicts of
interest by dividing responsibilities?
A. Biba
B. Clark-Wilson
C. Brewer-Nash
D. Bell-LaPadula
Answer: C
Rationale: The Brewer-Nash model, also known as the Chinese
Wall model, prevents conflicts of interest by dynamically
separating access based on what the subject has already
accessed.
2. What is the primary purpose of the Bell-LaPadula model?
A. To ensure data integrity
B. To ensure data confidentiality
C. To prevent conflicts of interest
D. To enforce separation of duties
,Answer: B
Rationale: The Bell-LaPadula model focuses on data
confidentiality using no read up and no write down rules.
3. Which rule in the Bell-LaPadula model prevents a subject
from reading data at a higher classification?
A. No write down
B. No read up
C. No read down
D. No write up
Answer: B
Rationale: The no read up rule prevents subjects from reading
data at a higher classification level.
4. What does the Biba model focus on?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: B
,Rationale: The Biba model focuses on data integrity using no
read down and no write up rules.
5. Which access control model uses roles to assign permissions?
A. Discretionary access control
B. Mandatory access control
C. Role-based access control
D. Attribute-based access control
Answer: C
Rationale: Role-based access control assigns permissions based
on the roles users hold within an organization.
6. What is the purpose of the Clark-Wilson model?
A. To ensure integrity through well-formed transactions
B. To ensure confidentiality through labels
C. To prevent conflicts of interest
D. To enforce availability
Answer: A
Rationale: The Clark-Wilson model ensures integrity by
enforcing well-formed transactions and separation of duties.
, 7. Which type of attack involves an attacker intercepting
communication between two parties?
A. Denial of service
B. Man in the middle
C. Phishing
D. SQL injection
Answer: B
Rationale: A man in the middle attack occurs when an attacker
secretly intercepts and possibly alters communication between
two parties.
8. What is the purpose of a salt in password hashing?
A. To prevent rainbow table attacks
B. To speed up hashing
C. To encrypt passwords
D. To compress passwords
Answer: A
Rationale: A salt is random data added to a password before
hashing to prevent rainbow table attacks.