Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 32 pages
Exam (elaborations)

CISSP Official ISC2 practice tests - Domain 3 Exam Questions and Answers.

Document preview thumbnail
Preview 4 out of 32 pages

CISSP Official ISC2 practice tests - Domain 3Exam Questions and Answers. 1. Matthew is the security administrator for a consulting firm and must enforce access controls that restrict users' access based upon their previous activity. For example, once a consultant accesses data belonging to Acme Cola, a consulting client, they may no longer access data belonging to any of Acme's competitors. What security model best fits Matthew's needs? A. Clark-Wilson B. Biba C. Bell-LaPadula D. Brewer-Nash - Correct Answer D. The Brewer-Nash model allows access controls to change dynamically based upon a user's actions. It is often used in environments like Matthew's to implement a "Chinese wall" between data belonging to different clients. 2. Referring to the figure shown below (

Content preview

CISSP Official ISC2 practice tests - Domain 3 Exam Questions
and Answers.

1. Matthew is the security administrator for a consulting firm and must enforce access
controls that restrict users' access based upon their previous activity. For example, once a
consultant accesses data belonging to Acme Cola, a consulting client, they may no longer
access data belonging to any of Acme's competitors. What security model best fits
Matthew's needs?


A. Clark-Wilson
B. Biba
C. Bell-LaPadula
D. Brewer-Nash - Correct Answer D. The Brewer-Nash model allows access controls to
change dynamically based upon a user's actions. It is often used in environments like
Matthew's to implement a "Chinese wall" between data belonging to different clients.


2. Referring to the figure shown below (stage1:incipient, Stage2:smoke, Stage3:flame,
Stage4:heat), what is the earliest stage of a fire where it is possible to use detection
technology to identify it?


A. Incipient
B. Smoke
C. Flame
D. Heat - Correct Answer A. Fires may be detected as early as the incipient stage. During
this stage, air ionization takes place and specialized incipient fire detection systems can
identify these changes to provide early warning of a fire.


3. Ralph is designing a physical security infrastructure for a new computing facility that will
remain largely unstaffed. He plans to implement motion detectors in the facility but would
also like to include a secondary verification control for physical presence. Which one of
the following would best meet his needs?


A. CCTV
B. IPS
C. Turnstiles

,D. Faraday cages - Correct Answer A. Closed circuit television (CCTV) systems act as a
secondary verification mechanism for physical presence because they allow security
officials to view the interior of the facility when a motion alarm sounds to determine the
current occupants and their activities.


4. Harry would like to retrieve a lost encryption key from a database that uses m of n
control with m = 4 and n = 8. What is the minimum number of escrow agents required to
retrieve the key?


A. 2
B. 4
C. 8
D. 12 - Correct Answer B. In an m of n control system, at least m of n possible escrow
agents must collaborate to retrieve an encryption key from the escrow database.


5. Fran's company is considering purchasing a web-based email service from a vendor
and eliminating its own email server environment as a cost-saving measure. What type of
cloud computing environment is Fran's company considering?


A. SaaS
B. IaaS
C. CaaS
D. PaaS - Correct Answer A. This is an example of a vendor offering a fully functional
application as a web-based service. Therefore, it fits under the definition of Software as a
Service (SaaS). In Infrastructure as a Service (IaaS), Compute as a Service (CaaS), and
Platform as a Service (PaaS) approaches, the customer provides their own software. In
this example, the vendor is providing the email software, so none of those choices are
appropriate.


6. Bob is a security administrator with the federal government and wishes to choose a
digital signature approach that is an approved part of the federal Digital Signature
Standard under FIPS 186-4. Which one of the following encryption algorithms is not an
acceptable choice for use in digital signatures?


A. DSA
B. HAVAL

,C. RSA
D. ECDSA - Correct Answer B. The Digital Signature Standard approves three encryption
algorithms for use in digital signatures: the Digital Signature Algorithm (DSA); the Rivest,
Shamir, Adleman (RSA) algorithm; and the Elliptic Curve DSA (ECDSA) algorithm.
HAVAL is a hash function, not an encryption algorithm. While hash functions are used as
part of the digital signature process, they do not provide encryption.


7. Harry would like to access a document owned by Sally and stored on a file server.
Applying the subject/object model to this scenario, who or what is the subject of the
resource request?


A. Harry
B. Sally
C. Server
D. Document - Correct Answer A. In the subject/object model of access control, the user
or process making the request for a resource is the subject of that request. In this
example, Harry is requesting resource access and is, therefore, the subject.


8. Michael is responsible for forensic investigations and is investigating a medium severity
security incident that involved the defacement of a corporate website. The web server in
question ran on a virtualization platform, and the marketing team would like to get the
website up and running as quickly as possible. What would be the most reasonable next
step for Michael to take?


A. Keep the website offline until the investigation is complete.
B. Take the virtualization platform offline as evidence.
C. Take a snapshot of the compromised system and use that for the investigation.
D. Ignore the incident and focus on quickly restoring the website. - Correct Answer C.
Michael should conduct his investigation, but there is a pressing business need to bring
the website back online. The most reasonable course of action would be to take a
snapshot of the compromised system and use the snapshot for the investigation, restoring
the website to operation as quickly as possible while using the results of the investigation
to improve the security of the site.


9. Helen is a software engineer and is developing code that she would like to restrict to
running within an isolated sandbox for security purposes. What software development
technique is Helen using?

, A. Bounds
B. Input validation
C. Confinement
D. TCB - Correct Answer C. The use of a sandbox is an example of confinement, where
the system restricts the access of a particular process to limit its ability to affect other
processes running on the same system.


10. What concept describes the degree of confidence that an organization has that its
controls satisfy security requirements?


A. Trust
B. Credentialing
C. Verification
D. Assurance - Correct Answer D. Assurance is the degree of confidence that an
organization has that its security controls are correctly implemented. It must be continually
monitored and re-verified.


11. What type of security vulnerability are developers most likely to introduce into code
when they seek to facilitate their own access, for testing purposes, to software they
developed?


A. Maintenance hook
B. Cross-site scripting
C. SQL injection
D. Buffer overflow - Correct Answer A. Maintenance hooks, otherwise known as
backdoors, provide developers with easy access to a system, bypassing normal security
controls. If not removed prior to finalizing code, they pose a significant security
vulnerability if an attacker discovers the maintenance hook.


12. In the figure shown below(*), Sally is blocked from reading the file due to the Biba
integrity model. Sally has a Secret security clearance and the file has a Confidential
classification. What principle of the Biba model is being enforced?


A. Simple Security Property

Document information

Uploaded on
December 27, 2024
Number of pages
32
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
LECTME
3.5
(2)
Sold
8
Followers
4
Items
2894
Last sold
4 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions