[Nov 20, 2021] CISSP Test Prep Training Practice Exam Questions Practice Tests
Exam Questions Answers Braindumps CISSP Exam Dumps PDF Questions
What is the duration, language, and format of CISSP test: Certified Information Systems Security Professional
- Number of Questions: 60
- Type of Questions: Single and Multiple Choice.
- Language: English
- Length of Examination: 120 minutes
- Passing Score: 70%
NEW QUESTION 434
Random access memory is:
- A. Non-volatile.
- B. Programmed by using fusible links.
- C. Volatile.
- D. Sequentially addressable.
Answer: C
Explanation:
The correct answer is Volatile. RAM is volatile. The other answers are
incorrect because RAM is volatile, randomly accessible, and not programmed by fusible links.
NEW QUESTION 435
Which of the following is the act of performing tests and evaluations to test a system's security level to see if it complies with the design specifications and security requirements?
- A. Validation
- B. Accuracy
- C. Verification
- D. Assessment
Answer: C
Explanation:
Verification vs. Validation:
Verification determines if the product accurately represents and meets the specifications. A product can be developed that does not match the original specifications. This step ensures that the specifications are properly met.
Validation determines if the product provides the necessary solution intended real-world problem. In large projects, it is easy to lose sight of overall goal. This exercise ensures that the main goal of the project is met.
From DITSCAP:
6.3.2. Phase 2, Verification. The Verification phase shall include activities to verify compliance of the system with previously agreed security requirements. For each life-cycle development activity, DoD Directive 5000.1 (reference (i)), there is a corresponding set of security activities, enclosure 3, that shall verify compliance with the security requirements and evaluate vulnerabilities.
6.3.3. Phase 3, Validation. The Validation phase shall include activities to evaluate the fully integrated system to validate system operation in a specified computing environment with an acceptable level of residual risk. Validation shall culminate in an approval to operate.
You must also be familiar with Verification and Validation for the purpose of the exam. A simple definition for Verification would be whether or not the developers followed the design specifications along with the security requirements. A simple definition for Validation would be whether or not the final product meets the end user needs and can be use for a specific purpose.
Wikipedia has an informal description that is currently written as: Validation can be expressed by the query "Are you building the right thing?" and Verification by "Are you building it right?
NOTE:
DITSCAP was replaced by DIACAP some time ago (2007). While DITSCAP had defined both a verification and a validation phase, the DIACAP only has a validation phase. It may not make a difference in the answer for the exam; however, DIACAP is the cornerstone policy of DOD C&A and IA efforts today. Be familiar with both terms just in case all of a sudden the exam becomes updated with the new term.
Reference(s) used for this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 1106). McGraw-
Hill. Kindle Edition.
http://iase.disa.mil/ditscap/DITSCAP.html
https://en.wikipedia.org/wiki/Verification_and_validation
For the definition of "validation" in DIACAP, Click Here
Further sources for the phases in DIACAP, Click Here
NEW QUESTION 436
When a possible intrusion into your organization's information system has been detected, which of the following actions should be performed first?
- A. Communicate with relevant parties.
- B. Eliminate all means of intruder access.
- C. Contain the intrusion.
- D. Determine to what extent systems and data are compromised.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
If the event is determined to be a real incident, it is identified and classified. Once we understand the severity of the incident taking place, we move on to the next stage, which is investigation. Investigation involves the proper collection of relevant data, which will be used in the analysis and following stages. The goals of these stages are to reduce the impact of the incident, identify the cause of the incident, resume operations as soon as possible, and apply what was learned to prevent the incident from recurring.
Incorrect Answers:
A: Before we can eliminate intruder access we would have to determine the extent of the intrusion.
B: Before containing the intrusion we need to determine the extent of the intrusion.
D: Before we can communicate with the relevant parties we need to determine the extent of the intrusion.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 1038
NEW QUESTION 437
Which of the following is considered a secure coding practice?
- A. Use new code for common tasks
- B. Use dynamic execution functions to pass user supplied data
- C. Use concurrent access for shared variables and resources
- D. Use checksums to verify the integrity of libraries
Answer: D
Explanation:
Section: Software Development Security
NEW QUESTION 438
Which of the following is currently the most recommended water system for a computer room?
- A. preaction
- B. deluge
- C. wet pipe
- D. dry pipe
Answer: A
Explanation:
The_answer: Preaction combines both the dry and wet pipe systems and allows manual intervention before a full discharge of water on the equipment occurs.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, page 334.
NEW QUESTION 439
During which phase of an IT system life cycle are security requirements developed?
- A. Implementation
- B. Functional design analysis and Planning
- C. Initiation
- D. Operation
Answer: B
Explanation:
The software development life cycle (SDLC) (sometimes referred to as the System
Development Life Cycle) is the process of creating or altering software systems, and the models
and methodologies that people use to develop these systems.
The NIST SP 800-64 revision 2 has within the description section of para 3.2.1:
This section addresses security considerations unique to the second SDLC phase. Key security
activities for this phase include:
Conduct the risk assessment and use the results to supplement the baseline security controls;
Analyze security requirements;
Perform functional and security testing;
Prepare initial documents for system certification and accreditation; and
Design security architecture.
Reviewing this publication you may want to pick development/acquisition. Although initiation would be a decent choice, it is correct to say during this phase you would only brainstorm the idea of security requirements. Once you start to develop and acquire hardware/software components then you would also develop the security controls for these. The Shon Harris reference below is correct as well.
Shon Harris' Book (All-in-One CISSP Certification Exam Guide) divides the SDLC differently:
-Project initiation
-Functional design analysis and planning
-System design specifications
-Software development
-Installation
-Maintenance support
-Revision and replacement
According to the author (Shon Harris), security requirements should be developed during the functional design analysis and planning phase. SDLC POSITIONING FROM NIST 800-64
SDLC Positioning in the enterprise Information system security processes and activities provide valuable input into managing IT systems and their development, enabling risk identification, planning and mitigation. A risk management approach involves continually balancing the protection of agency information and assets with the cost of security controls and mitigation strategies throughout the complete information system development life cycle (see Figure 2-1 above). The most effective way to implement risk management is to identify critical assets and operations, as well as systemic vulnerabilities across the agency. Risks are shared and not bound by organization, revenue
source, or topologies. Identification and verification of critical assets and operations and their
interconnections can be achieved through the system security planning process, as well as
through the compilation of information from the Capital Planning and Investment Control (CPIC)
and Enterprise Architecture (EA) processes to establish insight into the agency's vital business
operations, their supporting assets, and existing interdependencies and relationships.
With critical assets and operations identified, the organization can and should perform a business
impact analysis (BIA). The purpose of the BIA is to relate systems and assets with the critical
services they provide and assess the consequences of their disruption. By identifying these
systems, an agency can manage security effectively by establishing priorities. This positions the
security office to facilitate the IT program's cost-effective performance as well as articulate its
business impact and value to the agency.
SDLC OVERVIEW FROM NIST 800-64
SDLC Overview from NIST 800-64 Revision 2
NIST 800-64 Revision 2 is one publication within the NISTstandards that I would recommend you
look at for more details about the SDLC. It describe in great details what activities would take
place and they have a nice diagram for each of the phases of the SDLC. You will find a copy at:
http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-Revision2.pdf
DISCUSSION:
Different sources present slightly different info as far as the phases names are concerned.
People sometimes gets confused with some of the NIST standards. For example NIST 800-64
Security Considerations in the Information System Development Life Cycle has slightly different
names, the activities mostly remains the same.
NIST clearly specifies that Security requirements would be considered throughout ALL of the
phases. The keyword here is considered, if a question is about which phase they would be
developed than Functional Design Analysis would be the correct choice.
Within the NIST standard they use different phase, howeverr under the second phase you will see
that they talk specifically about Security Functional requirements analysis which confirms it is not
at the initiation stage so it become easier to come out with the answer to this question. Here is
what is stated:
The security functional requirements analysis considers the system security environment,
including the enterprise information security policy and the enterprise security architecture. The
analysis should address all requirements for confidentiality, integrity, and availability of
information, and should include a review of all legal, functional, and other security requirements
contained in applicable laws, regulations, and guidance.
At the initiation step you would NOT have enough detailed yet to produce the Security
Requirements. You are mostly brainstorming on all of the issues listed but you do not develop
them all at that stage.
By considering security early in the information system development life cycle (SDLC), you may be
able to avoid higher costs later on and develop a more secure system from the start.
NIST says:
NIST`s Information Technology Laboratory recently issued Special Publication (SP) 800-64,
Security Considerations in the Information System Development Life Cycle, by Tim Grance, Joan
Hash, and Marc Stevens, to help organizations include security requirements in their planning for
every phase of the system life cycle, and to select, acquire, and use appropriate and cost-effective
security controls.
I must admit this is all very tricky but reading skills and paying attention to KEY WORDS is a must
for this exam.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, Fifth Edition,
Page 956
and
NIST S-64 Revision 2 at http://csrc.nist.gov/publications/nistpubs/800-64-Rev2/SP800-64-
Revision2.pdf
and
http://www.mks.com/resources/resource-pages/software-development-life-cycle-sdlc-system-
development
NEW QUESTION 440
Which of the following cloud computing service model provides a way to rent operating systems, storage and network capacity over the Internet?
- A. Software as a service
- B. Infrastructure as a service
- C. Data as a service
- D. Platform as a service
Answer: D
Explanation:
Platform as a Service (PaaS) is a way to rent operating systems, storage and network capacity over the Internet. The service delivery model allows the customer to rent virtualized servers and associated services for running existing applications or developing and testing new ones.
For your exam you should know below information about Cloud Computing:
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models.
Cloud Computing Image Reference http://osarena.net/wp-content/uploads/2013/04/cloud-computing3.jpg
Cloud computing service models:
Cloud computing service models Image Reference http://www.esri.com/news/arcwatch/0110/graphics/feature2.jpg
Software as a Service (SaaS) Software as a Service (SaaS) is a software distribution model in which applications are hosted by a vendor or service provider and made available to customers over a network, typically the Internet.SaaS is closely related to the ASP (application service provider) and on demand computing software delivery models. IDC identifies two slightly different delivery models for SaaS. The hosted application management (hosted AM) model is similar to ASP: a provider hosts commercially available software for customers and delivers it over the Web. In the software on demand model, the provider gives customers network-based access to a single copy of an application created specifically for SaaS distribution. Provider gives users access to specific application software (CRM, e-mail, games). The provider gives the customers network based access to a single copy of an application created specifically
for SaaS distribution and use.
Benefits of the SaaS model include:
easier administration
automatic updates and patch management
compatibility: All users will have the same version of software.
easier collaboration, for the same reason
global accessibility.
Platform as a Service (PaaS)
Platform as a Service (PaaS) is a way to rent operating systems, storage and network capacity
over the Internet. The service delivery model allows the customer to rent virtualized servers and
associated services for running existing applications or developing and testing new ones.
Cloud providers deliver a computing platform,which can include an operating system, database,
and web server as a holistic execution environment. Where IaaS is the "raw IT network," PaaS is
the software environment that runs on top of the IT network.
Platform as a Service (PaaS) is an outgrowth of Software as a Service (SaaS), a software
distribution model in which hosted software applications are made available to customers over the
Internet. PaaS has several advantages for developers. With PaaS, operating system features can
be changed and upgraded frequently. Geographically distributed development teams can work
together on software development projects. Services can be obtained from diverse sources that
cross international boundaries. Initial and ongoing costs can be reduced by the use of
infrastructure services from a single vendor rather than maintaining multiple hardware facilities that
often perform duplicate functions or suffer from incompatibility problems. Overall expenses can
also be minimized by unification of programming development efforts.
On the downside, PaaS involves some risk of "lock-in" if offerings require proprietary service
interfaces or development languages. Another potential pitfall is that the flexibility of offerings may
not meet the needs of some users whose requirements rapidly evolve.
Infrastructure as a Service (IaaS)
Cloud providers offer the infrastructure environment of a traditional data center in an on-demand
delivery method. Companies deploy their own operating systems, applications, and software onto
this provided infrastructure and are responsible for maintaining them.
Infrastructure as a Service is a provision model in which an organization outsources the equipment
used to support operations, including storage, hardware, servers and networking components. The
service provider owns the equipment and is responsible for housing, running and maintaining it.
The client typically pays on a per-use basis.
Characteristics and components of IaaS include:
Utility computing service and billing model.
Automation of administrative tasks.
Dynamic scaling.
Desktop virtualization.
Policy-based services.
Internet connectivity.
Infrastructure as a Service is sometimes referred to as Hardware as a Service (HaaS).
The following answers are incorrect:
Data as a service - Data Provided as a service rather than needing to be loaded and prepared on
premises.
Software as a service - Software as a Service (SaaS) is a software distribution model in which
applications are hosted by a vendor or service provider and made available to customers over a
network, typically the Internet. SaaS is closely related to the ASP (application service provider)
and on demand computing software delivery models.
Infrastructure as a service - Infrastructure as a Service is a provision model in which an
organization outsources the equipment used to support operations, including storage, hardware,
servers and networking components. The service provider owns the equipment and is responsible
for housing, running and maintaining it. The client typically pays on a per-use basis.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 102
Official ISC2 guide to CISSP 3rd edition Page number 689
http://searchcloudcomputing.techtarget.com/definition/Software-as-a-Service
http://searchcloudcomputing.techtarget.com/definition/Platform-as-a-Service-PaaS
http://searchcloudcomputing.techtarget.com/definition/Infrastructure-as-a-Service-IaaS
NEW QUESTION 441
In order to enable users to perform tasks and duties without having to go through extra steps it is important that the security controls and mechanisms that are in place have a degree of?
- A. Simplicity
- B. Complexity
- C. Transparency
- D. Non-transparency
Answer: C
Explanation:
The security controls and mechanisms that are in place must have a degree of transparency.
This enables the user to perform tasks and duties without having to go through extra steps
because of the presence of the security controls. Transparency also does not let the user know
too much about the controls, which helps prevent him from figuring out how to circumvent them. If
the controls are too obvious, an attacker can figure out how to compromise them more easily.
Security (more specifically, the implementation of most security controls) has long been a sore
point with users who are subject to security controls. Historically, security controls have been very
intrusive to users, forcing them to interrupt their work flow and remember arcane codes or
processes (like long passwords or access codes), and have generally been seen as an obstacle to
getting work done. In recent years, much work has been done to remove that stigma of security
controls as a detractor from the work process adding nothing but time and money. When
developing access control, the system must be as transparent as possible to the end user. The
users should be required to interact with the system as little as possible, and the process around
using the control should be engineered so as to involve little effort on the part of the user.
For example, requiring a user to swipe an access card through a reader is an effective way to
ensure a person is authorized to enter a room. However, implementing a technology (such as
RFID) that will automatically scan the badge as the user approaches the door is more transparent
to the user and will do less to impede the movement of personnel in a busy area.
In another example, asking a user to understand what applications and data sets will be required
when requesting a system ID and then specifically requesting access to those resources may
allow for a great deal of granularity when provisioning access, but it can hardly be seen as
transparent. A more transparent process would be for the access provisioning system to have a
role-based structure, where the user would simply specify the role he or she has in the
organization and the system would know the specific resources that user needs to access based
on that role. This requires less work and interaction on the part of the user and will lead to more
accurate and secure access control decisions because access will be based on predefined need,
not user preference.
When developing and implementing an access control system special care should be taken to
ensure that the control is as transparent to the end user as possible and interrupts his work flow as
little as possible.
The following answers were incorrect:
All of the other detractors were incorrect.
Reference(s) used for this question:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, 6th edition. Operations Security,
Page 1239-1240
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (Kindle Locations 25278-
25281). McGraw-Hill. Kindle Edition.
Schneiter, Andrew (2013-04-15). Official (ISC)2 Guide to the CISSP CBK, Third Edition : Access Control ((ISC)2 Press) (Kindle Locations 713-729). Auerbach Publications. Kindle Edition.
NEW QUESTION 442
The Bell-LaPadula model addresses which one of the following items?
- A. Covert channels
- B. The creation and destruction of subjects and objects
- C. Information flow from high to low
- D. Definition of a secure state transition
Answer: C
Explanation:
Information flow from high to low is addressed by the * -property of the Bell?LaPadula model, which states that a subject cannot write data from a higher level of classification to a lower level of classification. This property is also known as the confinement property or the no write down property.
*In answer "Covert channels", covert channels are not addressed by the model. The Bell-LaPadula model deals with information flow through normal channels and does not address the covert passing of information through unintended paths. The creation and destruction of subjects and objects, answer "The creation and destruction of subjects and objects", is not addressed by the model.
*Answer "Definition of a secure state transition" refers to the fact that the model discusses a secure transition from one secure state to another, but it never provides a definition of a secure transition.
NEW QUESTION 443
What ensures that the control mechanisms correctly implement the security policy for the entire life cycle of an information system?
- A. Assurance procedures
- B. Administrative controls
- C. Mandatory access controls
- D. Accountability controls
Answer: A
Explanation:
Controls provide accountability for individuals accessing information. Assurance procedures ensure that access control mechanisms correctly implement the security policy for the entire life cycle of an information system. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems (page 33).
NEW QUESTION 444
________ deemed proprietary to a company and can be information that provides a competitive edge.
- A. Information marked strictly private is
- B. Trade secrets are
- C. Restricted information is
- D. Copyrights are
Answer: B
Explanation:
Trade secrets are deemed proprietary to a company and can be information that provides a competitive edge. This information is protected as long as the owner takes the necessary security actions.
NEW QUESTION 445
If an attacker in a SYN flood attack uses someone else's valid host address as the source address, the system under attack will send a large number of Synchronize/Acknowledge (SYN/ACK) packets to the
- A. local interface being attacked.
- B. attacker's address.
- C. default gateway.
- D. specified source address.
Answer: D
NEW QUESTION 446
What is the 802.11 standard related to?
- A. Public Key Infrastructure (PKI)
- B. The OSI/ISO model
- C. Wireless network communications
- D. Packet-switching technology
Answer: C
Explanation:
The 802.11 standard outlines how wireless clients and APs communicate, lays out
the specifications of their interfaces, dictates how signal transmission should take place, and
describes how authentication, association, and security should be implemeted.
The following answers are incorrect:
Public Key Infrastructure (PKI) Public Key Infrastructure is a supporting infrastructure to manage
public keys. It is not part of the IEEE 802 Working Group standard.
Packet-switching technology A packet-switching technology is not included in the IEEE 802
Working Group standard. It is a technology where-in messages are broken up into packets, which
then travel along different routes to the destination.
The OSI/ISO model The Open System Interconnect model is a sevel-layer model defined as an
international standard describing network communications.
The following reference(s) were/was used to create this question:
Source: Shon Harris - "All-in-One CISSP Exam Guide" Fourth Edition; Chapter 7 -
Telecommunications and Network Security: pg. 624.
802.11 refers to a family of specifications developed by the IEEE for Wireless LAN technology.
802.11 specifies an over-the-air interface between a wireless client and a base station or between two wireless clients. The IEEE accepted the specification in 1997. There are several specifications in the 802.11 family:
802.11 # applies to wireless LANs and provides 1 or 2 Mbps transmission in the 2.4 GHz band using either frequency hopping spread spectrum (FHSS) or direct sequence spread spectrum (DSSS). 802.11a # an extension to 802.11 that applies to wireless LANs and provides up to 54 Mbps in the 5GHz band. 802.11a uses an orthogonal frequency division multiplexing encoding scheme rather than FHSS or DSSS. 802.11b (also referred to as 802.11 High Rate or Wi-Fi) # an extension to 802.11 that applies to wireless LANS and provides 11 Mbps transmission (with a fallback to 5.5, 2 and 1 Mbps) in the 2.4
GHz band. 802.11b uses only DSSS. 802.11b was a 1999 ratification to the original 802.11
standard, allowing wireless functionality comparable to Ethernet.
802.11g # applies to wireless LANs and provides 20+ Mbps in the 2.4 GHz band.
Source: 802.11 Planet's web site.
NEW QUESTION 447
In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class A network?
- A. The first two bits of the IP address would be set to one, and the third bit set to zero.
- B. The first bit of the IP address would be set to one and the second bit set to zero.
- C. The first three bits of the IP address would be set to one.
- D. The first bit of the IP address would be set to zero.
Answer: D
Explanation:
Each Class A network address has a 8-bit network prefix, with the first bit of the ipaddress set to zero. See the diagram below for more details.
The following answers are incorrect:
The first bit of the IP address would be set to one and the second bit set to zero. Is incorrect
because this would be a Class B network address.
The first two bits of the IP address would be set to one, and the third bit set to zero. Is incorrect
because, this would be a Class C network address.
The first three bits of the ipaddress would be set to one. Is incorrect because, this is a distractor.
Class D & E have the first three bits set to 1.
Class D the 4th bit is 0 and for
Class E the 4th bit to 1.
See diagram below from the 3COM tutorial on everything you ever wanted to know about IP
addressing:
Classful IP addressing format
Classless Internet Domain Routing (CIDR)
Classless Inter-Domain Routing (CIDR) is a method for allocating IP addresses and routing
Internet Protocol packets. The Internet Engineering Task Force introduced CIDR in 1993 to
replace the previous addressing architecture of classful network design in the Internet. Their goal
was to slow the growth of routing tables on routers across the Internet, and to help slow the rapid
exhaustion of IPv4 addresses.
For Class A, the addresses are 0.0.0.0 - 127.255.255.255.
For Class B networks, the addresses are 128.0.0.0 - 191.255.255.255.
For Class C, the addresses are 192.0.0.0 - 223.255.255.255.
For Class D, the addresses are 224.0.0.0 - 239.255.255.255.
For Class E, the addresses are 240.0.0.0 - 255.255.255.255.
References:
3Com http://www.3com.com/other/pdfs/infra/corpinfo/en_US/501302.pdf
and
AIOv3 Telecommunications and Networking Security (page 438)
and
https://secure.wikimedia.org/wikipedia/en/wiki/Classless_Inter-Domain_Routing
NEW QUESTION 448
The Trusted Computer Security Evaluation Criteria (TBSEC) provides
- A. a means of restricting access to objects based on the identity of subjects and groups to which they belong.
- B. a formal static transition model of computer security policy that describes a set of access control rules.
- C. a basis for assessing the effectiveness of security controls built into automatic data-processing system products
- D. a system analysis and penetration technique where specifications and document for the system are analyzed.
Answer: C
Explanation:
TBSEC provides guidelines to be used with evaluating a security product. The TBSEC guidelines address basic security functionality and allow evaluators to measure and rate the functionality of a system and how trustworthy it is. Functionality and assurance are combined and not separated, as in criteria developed later. TCSEC guidelines can be used for evaluating vendor products or by vendors to design necessary functionality into new products. CISSP Study Guide by Tittel pg. 413.
NEW QUESTION 449
Which of the following statements pertaining to fire suppression systems is TRUE?
- A. Gas masks provide an effective protection against use of CO2 systems. They are recommended for the protection of the employees within data centers.
- B. Halon is today the most common choice as far as agents are concerned because it is highly effective in the way that it interferes with the chemical reaction of the elements within a fire.
- C. Water Based extinguishers are NOT an effective fire suppression method for class C (electrical) fires.
- D. CO2 systems are NOT effective because they suppress the oxygen supply required to sustain the fire.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Class C fires are electrical fires which that may occur in electrical equipment or wiring. Class C fire extinguishers use gas, CO2 or dry powders. These extinguishing agents are non-conductive.
Class A fire extinguishers use water or foam. Water or foam used on an electrical fire would conduct the electricity and make the fire worse. Therefore, it is TRUE that water-based extinguishers are NOT an effective fire suppression method for class C (electrical) fires.
Incorrect Answers:
A: Halon is NOT the most common choice as far as agents are concerned. Halon is now known to be dangerous and no longer produced. Therefore, this answer is incorrect.
B: Gas masks DO NOT provide an effective protection against use of CO2 systems. CO2 systems work by removing the oxygen from the air. Therefore, this answer is incorrect.
C: CO2 systems ARE effective because they suppress the oxygen supply required to sustain the fire.
Therefore, this answer is incorrect.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 472
NEW QUESTION 450
Which element must computer evidence have to be admissible in court?
- A. It must be relevant.
- B. It must be printed.
- C. It must be annotated.
- D. It must contain source code.
Answer: A
Explanation:
Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.
NEW QUESTION 451
Which of the following statements pertaining to VPN protocol standards is false?
- A. L2TP operates at the network layer.
- B. PPTP uses native PPP authentication and encryption services.
- C. L2TP and PPTP were designed for single point-to-point client to server communication.
- D. L2TP is a combination of PPTP and L2F.
Answer: A
Explanation:
L2TP and PPTP were both designed for individual client to server connections; they enable only a single point-to-point connection per session. Dial-up VPNs use L2TP often. Both L2TP and PPTP operate at the data link layer (layer 2) of the OSI model. PPTP uses native PPP authentication and encryption services and L2TP is a combination of PPTP and Layer 2 Forwarding protocol (L2F). Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 95).
NEW QUESTION 452
The use of proximity card to gain access to a building is an example of what type of security control?
- A. Procedural
- B. Legal
- C. Logical
- D. Physical
Answer: D
NEW QUESTION 453
Aprocessor in which a single instruction specifies more than one CONCURRENT
operation is called:
- A. Very Long Instruction Word processor.
- B. Pipelined processor.
- C. Superscalar processor.
- D. Scalar processor.
Answer: A
Explanation:
The correct answer is Very Long Instruction Word processor.
*A pipelined processor overlaps the steps of different instructions.
*Answer a superscalar processor performs a concurrent execution of multiple instructions in the same pipeline stage.
*A scalar processor executes one instruction at a time.
NEW QUESTION 454
In order for evidence to be admissible in a court of law, it must be
relevant, legally permissible, reliable, properly identified, and properly preserved. Reliability of evidence means that:
- A. The evidence is identified without changing or damaging the
evidence. - B. It must tend to prove a material fact; the evidence is related to the crime in that it shows that the crime has been committed, can provide information describing the crime, can provide information
as to the perpetrators motives, can verify what had occurred, and
so on. - C. The evidence is not subject to damage or destruction.
- D. The evidence has not been tampered with or modified.
Answer: D
Explanation:
This requirement is a critical issue with computer evidence since
computer data may be easily modified without having an indication
that a change has taken place. Answer a defines the relevancy of
evidence, answer b describes the identification of evidence, and
answer d describes the preservation of evidence.
NEW QUESTION 455
Which of the following ensures that security is not breached when a system crash or other system failure occurs?
- A. secure boot
- B. hot swappable
- C. redundancy
- D. trusted recovery
Answer: D
Explanation:
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide:
Mastering the Ten Domains of Computer Security, page 222.
"System crash" and "system failure" are the key words. One "recovers" from a crash or failure.
NEW QUESTION 456
Place in order, from BEST (1) to WORST (4), the following methods to reduce the risk of data remanence on magnetic mediA.
Answer:
Explanation:
Explanation
NEW QUESTION 457
What is NOT true about a one-way hashing function?
- A. The results of a one-way hash is a message digest
- B. It provides authentication of the message
- C. It provides integrity of the message
- D. A hash cannot be reverse to get the message used to create the hash
Answer: B
Explanation:
A one way hashing function can only be use for the integrity of a message and not for authentication or confidentiality. Because the hash creates just a fingerprint of the message which cannot be reversed and it is also very difficult to create a second message with the same hash.
A hash by itself does not provide Authentication. It only provides a weak form or integrity. It would be possible for an attacker to perform a Man-In-The-Middle attack where both the hash and the digest could be changed without the receiver knowing it.
A hash combined with your session key will produce a Message Authentication Code (MAC) which will provide you with both authentication of the source and integrity. It is sometimes referred to as a Keyed Hash. A hash encrypted with the sender private key produce a Digital Signature which provide authentication, but not the hash by itself.
Hashing functions by themselves such as MD5, SHA1, SHA2, SHA-3 does not provide
authentication.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2001,
Page 548
NEW QUESTION 458
......
What to Get: (ISC)2 CISSP Certification Benefits
After gaining the required work experience, successfully passing the (ISC)2 CISSP exam and finally getting endorsement, you will become eligible for the CISSP certification. Some of the most popular positions you can apply for after getting certified include the following:
- Security Consultant;
- Network Architect;
- Internal Auditor;
- Cloud Security Administrator.
- Chief Information Officer;
- Cybersecurity Forensic Analyst;
Having the CISSP certification under your belt can also have a great impact on the financial bottom line after successfully completing the exam. Those who hold this sought-after certificate can earn an average salary of about $101,000.
Difficulty in Writing CISSP test: Certified Information Systems Security Professional
There are two primary sorts of assets for readiness of accreditation tests first there are the examination guides and the books that are point by point and reasonable for developing information from ground then there are video instructional exercise and talks that can by one way or another facilitate the agony of through investigation and are nearly less exhausting for certain up-and-comers yet these interest time and focus from the student. Keen Candidates who need to construct a strong establishment taking all things together test points and related advances as a rule consolidate video addresses with study advisers for receive the rewards of both however there is one critical readiness device as frequently neglected by most applicants the training tests. Practice tests are worked to make understudies alright with the genuine test climate. Measurements have shown that most understudies bomb not because of that planning however because of test tension the dread of the obscure. Certificate questions.com master group prescribes you to set up certain notes on these subjects alongside it remember to rehearse ISC CISSP practice exam and ISC CISSP practice tests which been composed by our master group, Both these will help you a ton to clear this test with great imprints.
For more info visit:
Download Free ISC CISSP Real Exam Questions: https://www.verifieddumps.com/CISSP-valid-exam-braindumps.html
CISSP Exam Dumps, CISSP Practice Test Questions: https://drive.google.com/open?id=1UdCbOklsl8LPnRQSsneXv7dvreH7T1QC
