NSG6435 FINAL TEST PAPER QUESTIONS
AND SOLUTIONS EXPERT VERIFIED STUDY
CONTENT
●● Like the CISSP, the SSCP certification is more applicable to the
security _____ than to the security _____.
Answer: manager, technician
●● The _____ vulnerability assessment is a process designed to find and
document selected vulnerabilities that are likely to be present on the
organization's internal network.
Answer: intranet
●● The _____ involves collecting information about an organization's
objectives, its technical architecture, and its information security
environment.
Answer: SecSDLC
●● The _____ is a center of Internet security expertise and is located at
the Software Engineering Institute, a federally funded research and
development center operated by Carnegie Mellon University.
Answer: CERT/CC
,●● A _____ vulnerability scanner listens in on the network and identifies
vulnerable versions of both server and client software.
Answer: passive
●● The _____ is a statement of the boundaries of the RA.
Answer: scope
●● A _____ is the information used in conjunction with an algorithm to
create the ciphertext from the plaintext or derive the plaintext from the
ciphertext.
Answer: key
●● A _____ is the recorded condition of a particular revision of a
software or hardware configuration item.
Answer: version
●● The _____ layer of the bull's-eye model includes computers used as
servers, desktop computers, and systems used for process control and
manufacturing systems
Answer: systems
●● The ability to detect a target computer's _____ is very valuable to an
attacker.
Answer: operating systems
, ●● The _____ layer of the bull's-eye model receives attention last.
Answer: Applications
●● Using __________, the system reviews the log files generated by
servers, network devices, and even other IDPSs.
Answer: LFM
●● The Lewin change model consists of _____.
-unfreezing
-moving
-refreezing
Answer: all of the above
●● A(n) _____ works like a burglar alarm in that it detects a violation
(some system activities analogous to an opened or broken window) and
activities an alarm.
Answer: IDPS
●● A _____ is usually the bets approach to security project
implementation.
Answer: phased implementation
AND SOLUTIONS EXPERT VERIFIED STUDY
CONTENT
●● Like the CISSP, the SSCP certification is more applicable to the
security _____ than to the security _____.
Answer: manager, technician
●● The _____ vulnerability assessment is a process designed to find and
document selected vulnerabilities that are likely to be present on the
organization's internal network.
Answer: intranet
●● The _____ involves collecting information about an organization's
objectives, its technical architecture, and its information security
environment.
Answer: SecSDLC
●● The _____ is a center of Internet security expertise and is located at
the Software Engineering Institute, a federally funded research and
development center operated by Carnegie Mellon University.
Answer: CERT/CC
,●● A _____ vulnerability scanner listens in on the network and identifies
vulnerable versions of both server and client software.
Answer: passive
●● The _____ is a statement of the boundaries of the RA.
Answer: scope
●● A _____ is the information used in conjunction with an algorithm to
create the ciphertext from the plaintext or derive the plaintext from the
ciphertext.
Answer: key
●● A _____ is the recorded condition of a particular revision of a
software or hardware configuration item.
Answer: version
●● The _____ layer of the bull's-eye model includes computers used as
servers, desktop computers, and systems used for process control and
manufacturing systems
Answer: systems
●● The ability to detect a target computer's _____ is very valuable to an
attacker.
Answer: operating systems
, ●● The _____ layer of the bull's-eye model receives attention last.
Answer: Applications
●● Using __________, the system reviews the log files generated by
servers, network devices, and even other IDPSs.
Answer: LFM
●● The Lewin change model consists of _____.
-unfreezing
-moving
-refreezing
Answer: all of the above
●● A(n) _____ works like a burglar alarm in that it detects a violation
(some system activities analogous to an opened or broken window) and
activities an alarm.
Answer: IDPS
●● A _____ is usually the bets approach to security project
implementation.
Answer: phased implementation