CISSP Practice Questions Exam Cram, 4th Edition Updated Latest.
CISSP Practice Questions Exam Cram, 4th Edition Updated Latest. CISSP Practice Questions Michael Gregg Fourth Edition 8 Chapter 1 ▶ Professional ethics ▶ Knowledge transfer: awareness, training, and education TIP Pay attention to the order of items listed in questions. Some questions might ask you about the order of activities. As an example, you would need to correctly prioritize what comes first, second, and third. Security and Risk Management 9 Quick Check Practice Questions 1. You have just won a contract for a small software development firm, which has asked you to perform a risk analysis. The firm provided you information on previous incidents and has a list of the known environmental threats in the geographic area. The firm’s president believes that risk is something that can be eliminated. As a CISSP, how should you respond to this statement? A. Although it can be prohibitively expensive, risk can be eliminated. B. Risk can be reduced, but cannot be eliminated. C. A qualitative risk analysis can eliminate risk. D. A quantitative risk assessment can eliminate risk. 2. Which term describes the method of identifying vulnerabilities and threats and assessing the possible damage to determine where to implement security safeguards? A. Information management B. Risk analysis C. Countermeasure selection D. Classification controls 3. Proper security management dictates separation of duties for all the following reasons except which one? A. It reduces the possibility of fraud. B. It reduces dependency on individual workers. C. It reduces the need for personnel. D. It provides integrity. 4. As a potential CISSP, you need to know common Request for Comments (RFCs) and National Institute of Standards and Technology (NIST) standards. One such RFC is 2196. This Internet Engineering Task Force (IETF) document provides basic guidance on security in a networked environment. What is the title of this document? A. “Ethics and the Internet” B. “Site Security Handbook” C. “Cracking and Hacking TCP/IP” D.“SecurityPoliciesandProcedures”Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 10 Chapter 1 5. Mr. Hunting, your former college math teacher, hears that you are Quick Check studying for your CISSP exam and asks if you know the formula for total risk. What is the correct response? A. Annual Loss Expectancy (ALE) ∗Vulnerability = Total Risk B. Threat ∗Vulnerability ∗Asset Value (AV) = Total Risk C. Residual Risk (RR)/AV ∗Vulnerability = Total Risk D. AV/RR = Total Risk 6. What document gives detailed instructions on how to perform specific operations, providing a step-by-step guide? A. Guidelines B. Policies C. Procedures D. Standards 7. Your CEO has hinted that security audits may be implemented next year. As a result, your director has become serious about performing some form of risk assessment. You are delegated the task of determining which type of risk assessment to perform. The director wants to learn more about the type of risk assessment that involves a team of internal business managers and technical staff. He does not want the assessment to place dollar amounts on identified risks. He wants the group to assign one of 26 common controls to each threat as it is identified. Which type of risk assessment does your manager want? A. Delphi B. Delegated C. Quantitative D. Facilitated Risk Assessment Process (FRAP) 8. Which of the following is a document that is considered high-level in that it defines formal rules by which employees of the organization must abide? A. Guidelines B. Policies C. Standards D. Procedures Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Security and Risk Management 11 9. Management requires that all employees with a company laptop Quick Check keep their virus signatures up to date and run a full system scan at least weekly. It is suggested, however, that they update signatures every night if possible. In what document type would such suggestions likely be made? A. Policies B. Procedures C. Guidelines D. Standards 10. What document is similar to a standard, but provides only broad guidance and recommendations? A. Policies B. Guidelines C. Procedures D. Baselines 11. You are asked to speak at the next staff meeting about security governance and discuss why risk analysis is important. What will you say? A. Risk analysis is something every company should perform to demonstrate that it is in control of its assets, resources, and destiny. B. Risk analysis is important because it is required before an organization can sell stock by means of an IPO. C. Risk analysis is important because it demonstrates profitability. D. Risk analysis is important because it helps ensure that your company will survive an audit. 12. One of your coworkers, who knows that you are studying for your CISSP exam, comes to you with the following question: What is a cost-benefit analysis? How will you answer? A. A cost-benefit analysis should identify safeguards that offer the maximum amount of protection for the minimum cost. B. A cost-benefit analysis should identify targets that have been identified as low risk. C. A cost-benefit analysis should identify safeguards that are easy to implement for the protection of low-value targets. Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 35 Quick Answer: 33 Detailed Answer: 36 12 Chapter 1 13. Your risk management team has just finished calculating the Quick Check threats to a company during a disaster. They determine that the company will suffer long-term reputation damage in the community that will reduce their future customer base in the event off a Personally Identifiable Information (PII) breach. The team believes that customers will go to another company. This is an example of: A. Delayed loss B. Aggregated risk C. Potential loss D. Immediate loss 14. Your consulting firm has won a contract for a small, yet growing, technology firm. The CEO has wisely decided that the firm’s proprietary technology is worth protecting and wants to find out whether anyone is in noncompliance. Which of the following is not a reason why this organization should develop information classification? A. Information classification should be implemented to demonstrate the organization’s commitment to good security practices. B. Information classification should be implemented to ensure successful prosecution of intellectual property violators. C. Information classification identifies which level of protection should be applied to the organization’s data. D. Information classification should be implemented to meet regulatory and industry standards. 15. Your administrative assistant has started an online risk assessment certificate program. She has a question: What primary security concept defines the rights and privileges of a validated user? What will your answer be? A. Authorization B. Identification C. Authentication D. Accountability 16. Which of the following can be used to protect confidentiality? A. Closed Circuit TV (CCTV) B. Encryption CChecksumsQuick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36 Security and Risk Management 13 17. Your company has brought in a group of contract programmers Quick Check and is concerned about the potential risk. Although management feels it is important to track these users’ activities, they also want to make sure that any changes to program code or data can be tied to a specific individual. Which of the following best describes the means by which an individual cannot deny having performed an action or caused an event? A. Identification B. Auditing C. Logging D. Nonrepudiation 18. Which of the following can be used to protect integrity? A. CCTV B. Encryption C. Checksums D. RAID 19. Christine has been given network access to pilot engineering design documents. Although she can view the documents, she cannot print them or make changes. Which of the following does she lack? A. Identification B. Authorization C. Authentication D. Validation 20. Which of the following can be used to provide accountability? A. CCTV B. RAID C. Checksums D. Symmetric encryption 21. Which of the following best describes estimating that a risk will happen, determining safeguards to mitigate a risk, assessing vulnerability, and assigning values to assets? A. Disaster recovery operation steps B. Penetration testing steps Quick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36 Quick Answer: 33 Detailed Answer: 36
Document information
- Uploaded on
- February 20, 2024
- Number of pages
- 402
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers