(ISC)2(TM) Systems Security Certified
Practitioner Course
The most common security weaknesses and exploits are in which standardized list? - correct answer
✔✔D. CVE - Common Vulnerabilities and Exposures
Choose the password configuration rules enforced by the Passfilt.dll Windows add-on. - correct answer
✔✔C. Password must have a combination of upper case, lower case, numbers, and special characters;
including a 6 character minimum password length
A computer forensics specialist should be attempting to attain which ultimate goal? - correct answer
✔✔B. Preserve electronic evidence and protect it from any alteration
What term is used to describe how data is transmitted between nodes on a network or between
networks, with the three common types being Broadcast, Multicast, and Unicast? - correct answer ✔✔A.
Casting
While conducting Quantitative risk analysis, which formula would be utilized? - correct answer ✔✔D. SLE
- Single Loss Expectancy
Which protocol listed below resolves a physical MAC address for a given logical IP address? - correct
answer ✔✔A. ARP
Providing optimal protection, what comprehensive array of layered security solutions resembles the
layers of an onion? - correct answer ✔✔B. Defense in Depth
Swiping a badge against a magnet reader at an entrance that unlocks the door for entry, would be which
of the following? - correct answer ✔✔B. Single-factor authentication
Encryption is attained at what layer of the OSI model? - correct answer ✔✔C. Presentation Layer - Layer
6
, What type of encrypted string is the output of a one way hash function on a string of random length? -
correct answer ✔✔A. fixed length
What is the main difference between a phreak and a hacker? - correct answer ✔✔A. Phreaks specifically
target telephone networks
Through what method of deduction is two-factor authentication achieved using your ATM card? - correct
answer ✔✔C. It combines something you have with something you know
Accountability for the timely distribution of information security intelligence data is assumed by which
organization(s)? - correct answer ✔✔D. All of the organizations listed
Which detail concerning risk analysis would you present to leadership regarding quantitative analysis ? -
correct answer ✔✔D. D. A and C
Which of the following are categories of a security incident? - correct answer ✔✔E. All of the above
A server offering AAA services must provide which services? - correct answer ✔✔C. Accounting,
Authentication, and Authorization
Working as a network administrator for your organization, which of the following choices should have
the BIND application disabled? - correct answer ✔✔A. All non DNS servers
Which attribute constitutes the ability to identify and/or audit a user and his/her actions? - correct
answer ✔✔C. Accountability
What program is designed to intentionally create a clandestine avenue of access or a security gap within
an information system? - correct answer ✔✔D. Backdoor
Which is NOT a characteristic of the RSA algorithm? - correct answer ✔✔C. Is based on a symmetric
algorithm
Practitioner Course
The most common security weaknesses and exploits are in which standardized list? - correct answer
✔✔D. CVE - Common Vulnerabilities and Exposures
Choose the password configuration rules enforced by the Passfilt.dll Windows add-on. - correct answer
✔✔C. Password must have a combination of upper case, lower case, numbers, and special characters;
including a 6 character minimum password length
A computer forensics specialist should be attempting to attain which ultimate goal? - correct answer
✔✔B. Preserve electronic evidence and protect it from any alteration
What term is used to describe how data is transmitted between nodes on a network or between
networks, with the three common types being Broadcast, Multicast, and Unicast? - correct answer ✔✔A.
Casting
While conducting Quantitative risk analysis, which formula would be utilized? - correct answer ✔✔D. SLE
- Single Loss Expectancy
Which protocol listed below resolves a physical MAC address for a given logical IP address? - correct
answer ✔✔A. ARP
Providing optimal protection, what comprehensive array of layered security solutions resembles the
layers of an onion? - correct answer ✔✔B. Defense in Depth
Swiping a badge against a magnet reader at an entrance that unlocks the door for entry, would be which
of the following? - correct answer ✔✔B. Single-factor authentication
Encryption is attained at what layer of the OSI model? - correct answer ✔✔C. Presentation Layer - Layer
6
, What type of encrypted string is the output of a one way hash function on a string of random length? -
correct answer ✔✔A. fixed length
What is the main difference between a phreak and a hacker? - correct answer ✔✔A. Phreaks specifically
target telephone networks
Through what method of deduction is two-factor authentication achieved using your ATM card? - correct
answer ✔✔C. It combines something you have with something you know
Accountability for the timely distribution of information security intelligence data is assumed by which
organization(s)? - correct answer ✔✔D. All of the organizations listed
Which detail concerning risk analysis would you present to leadership regarding quantitative analysis ? -
correct answer ✔✔D. D. A and C
Which of the following are categories of a security incident? - correct answer ✔✔E. All of the above
A server offering AAA services must provide which services? - correct answer ✔✔C. Accounting,
Authentication, and Authorization
Working as a network administrator for your organization, which of the following choices should have
the BIND application disabled? - correct answer ✔✔A. All non DNS servers
Which attribute constitutes the ability to identify and/or audit a user and his/her actions? - correct
answer ✔✔C. Accountability
What program is designed to intentionally create a clandestine avenue of access or a security gap within
an information system? - correct answer ✔✔D. Backdoor
Which is NOT a characteristic of the RSA algorithm? - correct answer ✔✔C. Is based on a symmetric
algorithm