Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 94 pages
Exam (elaborations)

CISSP Guide to Security Essentials, Gregory - Exam Preparation Test Bank (Downloadable Doc)

Document preview thumbnail
Preview 4 out of 94 pages

Description: Test Bank for CISSP Guide to Security Essentials, Gregory, 2e prepares you efficiently for your upcoming exams. It contains practice test questions tailored for your textbook. CISSP Guide to Security Essentials, Gregory, 2e Test bank allow you to access quizzes and multiple choice questions written specifically for your course. The test bank will most likely cover the entire textbook. Thus, you will get exams for each chapter in the book. You can still take advatange of the test bank even though you are using newer or older edition of the book. Simply because the textbook content will not significantly change in ne editions. In fact, some test banks remain identical for all editions. Disclaimer: We take copyright seriously. While we do our best to adhere to all IP laws mistakes sometimes happen. Therefore, if you believe the document contains infringed material, please get in touch with us and provide your electronic signature. and upon verification the doc will be deleted.

Content preview

CISSP Guide to Security Essentials, 2nd Edition


Chapter 1 Solutions




Review Questions
1. An organization that needs to understand vulnerabilities and threats needs to perform a:


a. Penetration test


b. Threat analysis


c. Qualitative risk assessment


d. Quantitative risk assessment


2. A risk manager has performed a risk analysis on a server that is worth $120,000. The

risk manager has determined that the single loss expectancy is $100,000. The exposure

factor is:


a. 83%


b. 1.2


c. 80%


d. 120%

,3. A risk manager has performed a risk analysis on a server that is worth $120,000. The

single loss expectancy (SLE) is $100,000, and the annual loss expectancy (ALE) is

$8,000. The annual rate of occurrence (ARO) is:


a. 12.5


b. 92%


c. 8


d. 8%


4. A risk manager needs to implement countermeasures on a critical server. What factors

should be considered when analyzing different solutions?


a. Original annualized loss expectancy (ALE)


b. Annualized loss expectancy (ALE) that results from the implementation of the

countermeasure


c. Original exposure factor (EF)


d. Original single loss expectancy (SLE)


5. The general approaches to risk treatment are:


a. Risk acceptance, risk avoidance, and risk reduction


b. Risk acceptance, risk reduction, and risk transfer


c. Risk acceptance, risk avoidance, risk reduction, and risk transfer

, d. Risk analysis, risk acceptance, risk reduction, and risk transfer


6. CIA refers to:


a. Confidence, integrity, and audit of information and systems


b. Confidentiality, integrity, and assessment of information and systems


c. Confidentiality, integrity, and availability of information and systems


d. Cryptography, integrity, and audit of information and systems


7. A recent failure in a firewall resulted in all incoming packets being blocked. This type

of failure is known as:


a. Fail open


b. Access failure


c. Circuit closed


d. Fail closed


8. The definition of PII:


a. Is name, date of birth, and home address


b. Is name, date of birth, home address, and home telephone number


c. Is name, date of birth, and social insurance number


d. Varies by jurisdiction and regulation

, 9. The statement, “All financial transactions are to be encrypted using 3DES” is an

example of a:


a. Procedure


b. Guideline


c. Standard


d. Policy


10. The purpose of information classification is:


a. To establish procedures for safely disposing of information


b. To establish procedures for the protection of information


c. To establish procedures for information labeling


d. To establish sensitivity levels for information


11. An organization is concerned that its employees will reveal its secrets to other parties.

The organization should implement:


a. Document marking


b. Non-disclosure agreements


c. Logon banners


d. Security awareness training


12. The purpose of a background verification is to:

Connected book
 image
Publisher: 2015 ISBN: 9781285060422 Edition: Unknown

Document information

Uploaded on
May 16, 2022
Number of pages
94
Written in
2021/2022
Type
Exam (elaborations)
Contains
Questions & answers
$40.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
tb4u
4.0
(158)
Sold
999
Followers
775
Items
2367
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions