FITSP - AUDITOR
What lPSec protocol can be configured to provide compression for lPSec traffic?
a) AH
b) ESP
c) lPComp
d) rKE - ANSWERS-lPComp
Which of the following two protocols are actually different names for the same
protocol?
a) ssL 3.0
b) TLS 1.1
c) SSL 3.1
d) TLS 1.0 - ANSWERS-SSL 3.1 and TLS 1.0
Name the AES-based, wireless encryption mechanism used in the 802.11i wireless
Technical specification?
a) TKIP
b) WEP128
c) CCMP
d) CBC.MAC - ANSWERS-CCMP
,Bluetooth devices in this mode are "promiscuous" and do not employ any
mechanisms to prevent other Bluetooth-enabled devices from establishing
connections:
a) Security Mode 4
b) Encryption Level 1
c) Security Mode 1
d) EAL 4 - ANSWERS-Security Mode 1
Which security control requires the information system protect against an
individual falsely denying having performed a particular action?
a) AU-5 Response to Audit Processing Failures
b) SC-13 Use of Cryptography
c) A.12.2.3 Message integrity
d) AU-10 Non-Repudiation - ANSWERS-AU-10 Non-Repudiation
What are used between two parties that share a secret key to authenticate
information transmitted between these parties?
a) Digital Certificates
b) Message Authentication Codes
c) Pre-Master Secret
d) Elliptical Curve Token - ANSWERS-Message Authentication Codes
,This Standard defines a MAC that uses a cryptographic hash function in
conjunction with a secret key:
a) FIPS 186-4 Digital Signature Standard
b) SP 800-s7
c) FIPS 180-4 Secure Hash Standard
d) FIPS 198-1 Keyed-Hash Message Authentication Code (HMAC) - ANSWERS-FIPS
198-1 Keyed-Hash Message Authentication Code (HMAC)
What is the protocol, used by lPSec that negotiates connection settings,
authenticates endpoints to
each other, defines the security parameters of lPsec-protected connections,
negotiates secret keys,
and manages, updates, and deletes lPsec-protected communication channels? -
ANSWERS-Internet key Exchange (lKE)
Which VPN technologies are approved for use by Federal agencies? - ANSWERS-
lPSec, SSL/TLS (but not 55Lv3)
Name the AES-based, wireless encryption mechanism used in the 802.11i wireless
specification? - ANSWERS-CCMP
In which security mode are Bluetooth devices considered "promiscuous", and do
not employ any
mechanisms to prevent other Bluetooth-enabled devices from establishing
connections? - ANSWERS-Security Mode 1
, Non-repudiation is established by using what form of cryptographic service? -
ANSWERS-Digital Signature
Name the policy for a Common ldentification Standard for Federal Employees and
Contractors? - ANSWERS-HSPD-12
Which security control requires the information system protect against an
individualfalsely denying
having performed a particular action? - ANSWERS-AU-10 Non-repudiation
Which e-authentication level, described in the special publication 800-63, requires
multifactor
authentication, and the use of a hard token? - ANSWERS-Level 4
What is defined as a simulation of an emergency designed to validate the viability
of one or more aspects of an ISCP?
a) ISCP Test
b) ISCP Exercise
c) ISCP Training
d) ISCP Drill - ANSWERS-ISCP Exercise
What is the US-CERT incident category name and reporting timeframe for a CAT-3
incident?
What lPSec protocol can be configured to provide compression for lPSec traffic?
a) AH
b) ESP
c) lPComp
d) rKE - ANSWERS-lPComp
Which of the following two protocols are actually different names for the same
protocol?
a) ssL 3.0
b) TLS 1.1
c) SSL 3.1
d) TLS 1.0 - ANSWERS-SSL 3.1 and TLS 1.0
Name the AES-based, wireless encryption mechanism used in the 802.11i wireless
Technical specification?
a) TKIP
b) WEP128
c) CCMP
d) CBC.MAC - ANSWERS-CCMP
,Bluetooth devices in this mode are "promiscuous" and do not employ any
mechanisms to prevent other Bluetooth-enabled devices from establishing
connections:
a) Security Mode 4
b) Encryption Level 1
c) Security Mode 1
d) EAL 4 - ANSWERS-Security Mode 1
Which security control requires the information system protect against an
individual falsely denying having performed a particular action?
a) AU-5 Response to Audit Processing Failures
b) SC-13 Use of Cryptography
c) A.12.2.3 Message integrity
d) AU-10 Non-Repudiation - ANSWERS-AU-10 Non-Repudiation
What are used between two parties that share a secret key to authenticate
information transmitted between these parties?
a) Digital Certificates
b) Message Authentication Codes
c) Pre-Master Secret
d) Elliptical Curve Token - ANSWERS-Message Authentication Codes
,This Standard defines a MAC that uses a cryptographic hash function in
conjunction with a secret key:
a) FIPS 186-4 Digital Signature Standard
b) SP 800-s7
c) FIPS 180-4 Secure Hash Standard
d) FIPS 198-1 Keyed-Hash Message Authentication Code (HMAC) - ANSWERS-FIPS
198-1 Keyed-Hash Message Authentication Code (HMAC)
What is the protocol, used by lPSec that negotiates connection settings,
authenticates endpoints to
each other, defines the security parameters of lPsec-protected connections,
negotiates secret keys,
and manages, updates, and deletes lPsec-protected communication channels? -
ANSWERS-Internet key Exchange (lKE)
Which VPN technologies are approved for use by Federal agencies? - ANSWERS-
lPSec, SSL/TLS (but not 55Lv3)
Name the AES-based, wireless encryption mechanism used in the 802.11i wireless
specification? - ANSWERS-CCMP
In which security mode are Bluetooth devices considered "promiscuous", and do
not employ any
mechanisms to prevent other Bluetooth-enabled devices from establishing
connections? - ANSWERS-Security Mode 1
, Non-repudiation is established by using what form of cryptographic service? -
ANSWERS-Digital Signature
Name the policy for a Common ldentification Standard for Federal Employees and
Contractors? - ANSWERS-HSPD-12
Which security control requires the information system protect against an
individualfalsely denying
having performed a particular action? - ANSWERS-AU-10 Non-repudiation
Which e-authentication level, described in the special publication 800-63, requires
multifactor
authentication, and the use of a hard token? - ANSWERS-Level 4
What is defined as a simulation of an emergency designed to validate the viability
of one or more aspects of an ISCP?
a) ISCP Test
b) ISCP Exercise
c) ISCP Training
d) ISCP Drill - ANSWERS-ISCP Exercise
What is the US-CERT incident category name and reporting timeframe for a CAT-3
incident?