CISSP DOMAIN 1 EXAM QUESTIONS
WITH REVIEWED CORRECT
DETAILED ANSWERS
What was the intent of the US Electronic Communications Privacy Act of 1986 (ECPA)?
1. To allow law-enforcement to use wiretaps without a warrant or oversight.
2. To protect electronic communication against warrantless wiretapping.
3. To allow search and seizure without immediate disclosure.
4. To protect electronic communication by mandating service providers to use strong
encryption. - Answer- 2. To protect electronic communication against warrantless
wiretapping.
Electronic Communications Privacy Act (ECPA) was designed for protection of
electronic communications against warrantless wiretapping, but it was very weakened
by the Patriot Act.
As an IT Security professional, you are expected to perform your due diligence. What
does this mean?
1. Apply patches annually.
2. Researching and acquiring the knowledge to do your job right.
3. Do what is right in the situation and your job. Act on the knowledge.
4. Continue the security practices of your company. - Answer- 2. Researching and
acquiring the knowledge to do your job right
Due Diligence - The research to build the IT Security architecture of your organization.
Best practices and common protection mechanisms. Research of new systems before
implementing.
We are using the CIA triad to, at a high level, explain IT security to our board of
directors. Which of these are the 3 legs of the CIA triad?
1. Confidentiality, Identity and Availability.
2. Identity, accountability and confidentiality.
3. Integrity, availability and confidentiality.
4. Confidentiality, Integrity and Accountability. - Answer- 3. Integrity, availability and
confidentiality.
, The CIA (Confidentiality, Integrity, Availability) Triad: Confidentiality - We keep our data
and secrets secret. Integrity - We ensure the data has not been altered. Availability - We
ensure authorized people can access the data they need, when they need to.
We are looking at our risk responses. We are choosing to ignore an identified risk. What
type of response would that be?
Risk avoidance.
Risk mitigation.
Risk rejection.
Risk transference. - Answer- Risk Rejection
Risk Rejection - You know the risk is there, but you are ignoring it. This is never
acceptable. (You are liable).
With the CIA triad in mind, when we choose to have too much integrity, which other
control will MOST LIKELY suffer?
Confidentiality.
Identity.
Accountability.
Availability. - Answer- Availability
Finding the right mix of Confidentiality, Integrity and Availability is a balancing act. This
is really the cornerstone of IT Security - finding the RIGHT mix for your organization.
Too much Integrity and the Availability can suffer.
When an attacker is attacking our encryption, they are MOSTLY targeting which leg of
the CIA triad?
Integrity.
Authentication.
Availability.
Confidentiality. - Answer- Confidentiality
To ensure confidentiality we use encryption for data at rest (for instance AES256), full
disk encryption. Secure transport protocols for data in motion. (SSL, TLS or IPSEC).
There are many attacks against encryption, it is almost always easier to steal the key
than breaking it, this is done with cryptanalysis.
In our risk analysis, we are looking at the risks, vulnerabilities, and threats. We use the
asset value to determine appropriate countermeasures. Which type of risk analysis are
we using?
Quadratic Risk Analysis
Cumulative Risk Analysis
WITH REVIEWED CORRECT
DETAILED ANSWERS
What was the intent of the US Electronic Communications Privacy Act of 1986 (ECPA)?
1. To allow law-enforcement to use wiretaps without a warrant or oversight.
2. To protect electronic communication against warrantless wiretapping.
3. To allow search and seizure without immediate disclosure.
4. To protect electronic communication by mandating service providers to use strong
encryption. - Answer- 2. To protect electronic communication against warrantless
wiretapping.
Electronic Communications Privacy Act (ECPA) was designed for protection of
electronic communications against warrantless wiretapping, but it was very weakened
by the Patriot Act.
As an IT Security professional, you are expected to perform your due diligence. What
does this mean?
1. Apply patches annually.
2. Researching and acquiring the knowledge to do your job right.
3. Do what is right in the situation and your job. Act on the knowledge.
4. Continue the security practices of your company. - Answer- 2. Researching and
acquiring the knowledge to do your job right
Due Diligence - The research to build the IT Security architecture of your organization.
Best practices and common protection mechanisms. Research of new systems before
implementing.
We are using the CIA triad to, at a high level, explain IT security to our board of
directors. Which of these are the 3 legs of the CIA triad?
1. Confidentiality, Identity and Availability.
2. Identity, accountability and confidentiality.
3. Integrity, availability and confidentiality.
4. Confidentiality, Integrity and Accountability. - Answer- 3. Integrity, availability and
confidentiality.
, The CIA (Confidentiality, Integrity, Availability) Triad: Confidentiality - We keep our data
and secrets secret. Integrity - We ensure the data has not been altered. Availability - We
ensure authorized people can access the data they need, when they need to.
We are looking at our risk responses. We are choosing to ignore an identified risk. What
type of response would that be?
Risk avoidance.
Risk mitigation.
Risk rejection.
Risk transference. - Answer- Risk Rejection
Risk Rejection - You know the risk is there, but you are ignoring it. This is never
acceptable. (You are liable).
With the CIA triad in mind, when we choose to have too much integrity, which other
control will MOST LIKELY suffer?
Confidentiality.
Identity.
Accountability.
Availability. - Answer- Availability
Finding the right mix of Confidentiality, Integrity and Availability is a balancing act. This
is really the cornerstone of IT Security - finding the RIGHT mix for your organization.
Too much Integrity and the Availability can suffer.
When an attacker is attacking our encryption, they are MOSTLY targeting which leg of
the CIA triad?
Integrity.
Authentication.
Availability.
Confidentiality. - Answer- Confidentiality
To ensure confidentiality we use encryption for data at rest (for instance AES256), full
disk encryption. Secure transport protocols for data in motion. (SSL, TLS or IPSEC).
There are many attacks against encryption, it is almost always easier to steal the key
than breaking it, this is done with cryptanalysis.
In our risk analysis, we are looking at the risks, vulnerabilities, and threats. We use the
asset value to determine appropriate countermeasures. Which type of risk analysis are
we using?
Quadratic Risk Analysis
Cumulative Risk Analysis