CISSP DOMAIN 1 EXAM QUESTIONS
AND ANSWERS ALL CORRECT
Which of the following activities would not be included in the contingency planning
process phase?
A. Prioritization of applications
B. Development of test procedures
C. Assessment of threat impact on the organization
D. Development of recovery scenarios - Answer- B. Development of test procedures
In terms of Risk Analysis and dealing with risk, which of the four common ways listed
below seek to eliminate involvement with the risk being evaluated?
A. Avoidance
B. Acceptance
C. Transference
D. Mitigation - Answer- A. Avoidance
Of the multiple methods of handling risks which must we undertake to carry out
business operations, which one involves using controls to reduce the risk?
A. Mitigation
B. Avoidance
C. Acceptance
D. Transference - Answer- A. Mitigation
There is no way to completely abolish or avoid risks, you can only manage them. A risk
free environment does not exist. If you have risks that have been identified, understood
and evaluated to be acceptable in order to conduct business operations. What is this
this approach to risk management called?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Transference
D. Risk Mitigation - Answer- A. Risk Acceptance
John is the product manager for an information system. His product has undergone a
security review by an IS auditor. John has decided to apply appropriate security controls
to reduce the security risks suggested by an IS auditor. Which of the following technique
is used by John to treat the identified risk provided by an IS auditor?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- A. Risk Mitigation
,Sam is the security Manager of an financial institute. Senior management has
requested he performs a risk analysis on all critical vulnerabilities reported by an IS
auditor. After completing the risk analysis, Sam has observed that for a few of the risks,
the cost benefit analysis shows that risk mitigation cost (countermeasures, controls, or
safeguard) is more than the potential lost that could be incurred. What kind of a strategy
should Sam recommend to the senior management to treat these risks?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- B. Risk Acceptance
Which of the following risk handling technique involves the practice of being proactive
so that the risk in question is not realized?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- C. Risk Avoidance
Which of the following risk handling technique involves the practice of passing on the
risk to another entity, such as an insurance company?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- D. Risk transfer
Which of the following security control is intended to bring environment back to regular
operation?
A. Deterrent
B. Preventive
C. Corrective
D. Recovery - Answer- D. Recovery
Which of the following is NOT an example of a detective control?
A. System Monitor
B. IDS
C. Monitor detector
D. Backup data restore - Answer- D. Backup data restore
Which type of risk assessment is the formula ALE = ARO x SLE used for?
A. Quantitative Analysis
B. Qualitative Analysis
C. Objective Analysis
D. Expected Loss Analysis - Answer- A. Quantitative Analysis
, Which one of the following represents an ALE calculation?
A. single loss expectancy x annualized rate of occurrence.
B. gross loss expectancy x loss frequency.
C. actual replacement cost - proceeds of salvage.
D. asset value x loss expectancy - Answer- A. single loss expectancy x annualized rate
of occurrence.
The control of communications test equipment should be clearly addressed by security
policy for which of the following reasons?
A. Test equipment is easily damaged.
B. Test equipment can be used to browse information passing on a network.
C. Test equipment is difficult to replace if lost or stolen.
D. Test equipment must always be available for the maintenance personnel. - Answer-
B. Test equipment can be used to browse information passing on a network.
In discretionary access environments, which of the following entities is authorized to
grant information access to other people?
A. Manager
B. Group Leader
C. Security Manager
D. Data Owner - Answer- D. Data Owner
Which of the following groups represents the leading source of computer crime losses?
A. Hackers
B. Industrial saboteurs
C. Foreign intelligence officers
D. Employees - Answer- D. Employees
Which of the following is the best reason for the use of an automated risk analysis tool?
A. Much of the data gathered during the review cannot be reused for subsequent
analysis.
B. Automated methodologies require minimal training and knowledge of risk analysis.
C. Most software tools have user interfaces that are easy to use and does not require
any training.
D. Information gathering would be minimized and expedited due to the amount of
information already built into the tool. - Answer- D. Information gathering would be
minimized and expedited due to the amount of information already built into the tool.
Who is ultimately responsible for the security of computer based information systems
within an organization?
A. The tech support team
B. The Operation Team.
C. The management team.
D. The training team. - Answer- C. The management team.
The major objective of system configuration management is which of the following?
AND ANSWERS ALL CORRECT
Which of the following activities would not be included in the contingency planning
process phase?
A. Prioritization of applications
B. Development of test procedures
C. Assessment of threat impact on the organization
D. Development of recovery scenarios - Answer- B. Development of test procedures
In terms of Risk Analysis and dealing with risk, which of the four common ways listed
below seek to eliminate involvement with the risk being evaluated?
A. Avoidance
B. Acceptance
C. Transference
D. Mitigation - Answer- A. Avoidance
Of the multiple methods of handling risks which must we undertake to carry out
business operations, which one involves using controls to reduce the risk?
A. Mitigation
B. Avoidance
C. Acceptance
D. Transference - Answer- A. Mitigation
There is no way to completely abolish or avoid risks, you can only manage them. A risk
free environment does not exist. If you have risks that have been identified, understood
and evaluated to be acceptable in order to conduct business operations. What is this
this approach to risk management called?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Transference
D. Risk Mitigation - Answer- A. Risk Acceptance
John is the product manager for an information system. His product has undergone a
security review by an IS auditor. John has decided to apply appropriate security controls
to reduce the security risks suggested by an IS auditor. Which of the following technique
is used by John to treat the identified risk provided by an IS auditor?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- A. Risk Mitigation
,Sam is the security Manager of an financial institute. Senior management has
requested he performs a risk analysis on all critical vulnerabilities reported by an IS
auditor. After completing the risk analysis, Sam has observed that for a few of the risks,
the cost benefit analysis shows that risk mitigation cost (countermeasures, controls, or
safeguard) is more than the potential lost that could be incurred. What kind of a strategy
should Sam recommend to the senior management to treat these risks?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- B. Risk Acceptance
Which of the following risk handling technique involves the practice of being proactive
so that the risk in question is not realized?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- C. Risk Avoidance
Which of the following risk handling technique involves the practice of passing on the
risk to another entity, such as an insurance company?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer - Answer- D. Risk transfer
Which of the following security control is intended to bring environment back to regular
operation?
A. Deterrent
B. Preventive
C. Corrective
D. Recovery - Answer- D. Recovery
Which of the following is NOT an example of a detective control?
A. System Monitor
B. IDS
C. Monitor detector
D. Backup data restore - Answer- D. Backup data restore
Which type of risk assessment is the formula ALE = ARO x SLE used for?
A. Quantitative Analysis
B. Qualitative Analysis
C. Objective Analysis
D. Expected Loss Analysis - Answer- A. Quantitative Analysis
, Which one of the following represents an ALE calculation?
A. single loss expectancy x annualized rate of occurrence.
B. gross loss expectancy x loss frequency.
C. actual replacement cost - proceeds of salvage.
D. asset value x loss expectancy - Answer- A. single loss expectancy x annualized rate
of occurrence.
The control of communications test equipment should be clearly addressed by security
policy for which of the following reasons?
A. Test equipment is easily damaged.
B. Test equipment can be used to browse information passing on a network.
C. Test equipment is difficult to replace if lost or stolen.
D. Test equipment must always be available for the maintenance personnel. - Answer-
B. Test equipment can be used to browse information passing on a network.
In discretionary access environments, which of the following entities is authorized to
grant information access to other people?
A. Manager
B. Group Leader
C. Security Manager
D. Data Owner - Answer- D. Data Owner
Which of the following groups represents the leading source of computer crime losses?
A. Hackers
B. Industrial saboteurs
C. Foreign intelligence officers
D. Employees - Answer- D. Employees
Which of the following is the best reason for the use of an automated risk analysis tool?
A. Much of the data gathered during the review cannot be reused for subsequent
analysis.
B. Automated methodologies require minimal training and knowledge of risk analysis.
C. Most software tools have user interfaces that are easy to use and does not require
any training.
D. Information gathering would be minimized and expedited due to the amount of
information already built into the tool. - Answer- D. Information gathering would be
minimized and expedited due to the amount of information already built into the tool.
Who is ultimately responsible for the security of computer based information systems
within an organization?
A. The tech support team
B. The Operation Team.
C. The management team.
D. The training team. - Answer- C. The management team.
The major objective of system configuration management is which of the following?