[Q288-Q309] Exam Passing Guarantee Jul 09, 2023 CISSP Exam with Accurate Quastions!

Share

Exam Passing Guarantee Jul 09, 2023 CISSP Exam with Accurate Quastions!

Test Engine to Practice Test for CISSP Valid and Updated Dumps


ISC CISSP (Certified Information Systems Security Professional) Exam is one of the most respected and globally recognized certifications in the field of information security. It is designed for professionals who want to validate their expertise in designing, implementing, and managing information security programs to protect organizations from cybersecurity threats. CISSP exam is developed and maintained by the International Information System Security Certification Consortium (ISC2) and is accredited by the American National Standards Institute (ANSI).

 

NEW QUESTION # 288
What fencing height is likely to stop a determined intruder?

  • A. 6' to 7' high
  • B. 3' to 4' high
  • C. No fence can stop a determined intruder
  • D. 8' high and above with strands of barbed wire

Answer: D


NEW QUESTION # 289
DRAG DROP
In which order should the following steps be taken to perform a
vulnerability assessment?

Answer:

Explanation:

Explanation:

6 4-2
Common steps to performing a vulnerability assessment could be:
1 . List potential emergencies, both internally to your facility and
externally to the community. Natural, man-made, technological,
and human error are all categories of potential emergencies and
errors.
2 . Estimate the likelihood that each emergency could occur, in a
subjective analysis.
3 . Assess the potential impact of the emergency on the organization
in the areas of human impact (death or injury), property impact
(loss or damage), and business impact (market share or
credibility).
4 . Assess external and internal resources required to deal with
the emergency, and determine if they are located internally or
if external capabilities or procedures are required.
Source: Emergency Management Guide for Business and Industry,
Federal Emergency Management Agency, August 1998.

Figure A.12 shows a sample vulnerability matrix. This can be used
to create a subjective impact analysis for each type of emergency and
its probability. The lower the final number the better, as a high number means a high probability, impact, or lack of remediation resources.


NEW QUESTION # 290
A large corporation is locking for a solution to automate access based on where on request is coming from, who the user is, what device they are connecting with, and what time of day they are attempting this access. What type of solution would suit their needs?

  • A. Role Based Access Control (RBAC)
  • B. Discretionary Access Control (DAC)
  • C. Network Access Control (NAC)
  • D. Mandater Access Control (MAC)

Answer: C


NEW QUESTION # 291
Organization A is adding a large collection of confidential data records that it received when it acquired Organization B to its data store. Many of the users and staff from Organization B are no longer available.
Which of the following MUST Organization A 0do to property classify and secure the acquired data?

  • A. Archive audit records that refer to users from Organization A.
  • B. Change the data classification for data acquired from Organization B.
  • C. Assign data owners from Organization A to the acquired data.
  • D. Create placeholder accounts that represent former users from Organization B.

Answer: C


NEW QUESTION # 292
The Telecommunications Security Domain of information security is also concerned with the prevention and detection of the misuse or abuse of systems, which poses a threat to the tenets of:

  • A. Confidentiality, Integrity, and Authenticity (C.I.A.).
  • B. Confidentiality, Integrity, and Liability (C.I.L.).
  • C. Confidentiality, Integrity, and Entity (C.I.E.).
  • D. Confidentiality, Integrity, and Availability (I.A.).

Answer: D

Explanation:
The CIA acronym stands for Confidentiality, Integrity and Availability.
"Confidentiality, Integrity and Entity (CIE)" is incorrect. "Entity" is not part of the telecommunications domain definition.
"Confidentiality, Integrity and Authenticity (CIA)" is incorrect. While authenticity is included in the telecommunications domain, CIA is the acronym for confidentiality, integrity and availability.
"Confidentiality, Integrity, and Liability (CIL)" is incorrect. Liability is not part of the telecommunications domain definition.
References:
CBK, pp. 407 - 408


NEW QUESTION # 293
The Orange Book states that "Hardware and software features shall be provided that can be used to periodically validate the correct operation of the on-site hardware and firmware elements of the TCB [Trusted Computing Base]." This statement is the formal requirement for:

  • A. Design Verification.
  • B. Security Testing.
  • C. System Integrity.
  • D. System Architecture Specification.

Answer: C

Explanation:
This is a requirement starting as low as C1 within the TCSEC rating.
The Orange book requires the following for System Integrity Hardware and/or software features shall be provided that can be used to periodically validate the correct operation of the on-site hardware and firmware elements of the TCB.
NOTE FROM CLEMENT:
This is a question that confuses a lot of people because most people take for granted that the orange book with its associated Bell LaPadula model has nothing to do with integrity.
However you have to be careful about the context in which the word integrity is being used.
You can have Data Integrity and you can have System Integrity which are two completely different things.
Yes, the Orange Book does not specifically address the Integrity requirements, however it has to run on top of systems that must meet some integrity requirements.
This is part of what they call operational assurance which is defined as a level of confidence of a trusted system's architecture and implementation that enforces the system's security policy. It includes:
System architecture
Covert channel analysis
System integrity
Trusted recovery
DATA INTEGRITY
Data Integrity is very different from System Integrity. When you have integrity of the data, there are three goals:
1 . Prevent authorized users from making unauthorized modifications
2 . Preven unauthorized users from making modifications
3. Maintaining internal and external consistancy of the data
Bell LaPadula which is based on the Orange Book address does not address Integrity, it addresses only Confidentiality.
Biba address only the first goal of integrity.
Clark-Wilson addresses the three goals of integrity.
In the case of this question, there is a system integrity requirement within the TCB. As mentioned above here is an extract of the requirements: Hardware and/or software features shall be provided that can be used to periodically validate the correct operation of the on-site hardware and firmware elements of the TCB.
The following answers are incorrect:
Security Testing. Is incorrect because Security Testing has no set of requirements in the
Orange book.
Design Verification. Is incorrect because the Orange book's requirements for Design
Verification include: A formal model of the security policy must be clearly identified and documented, including a mathematical proof that the model is consistent with its axioms and is sufficient to support the security policy.
System Architecture Specification. Is incorrect because there are no requirements for
System Architecture Specification in the Orange book.
The following reference(s) were used for this question:
Trusted Computer Security Evaluation Criteria (TCSEC), DoD 5200.28-STD, page 15, 18,
25, 31, 40, 50.
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition, Security
Architecture and Design, Page 392-397, for users with the Kindle Version see Kindle
Locations 28504-28505.
and
DOD TCSEC - http://www.cerberussystems.com/INFOSEC/stds/d520028.htm


NEW QUESTION # 294
Which of the following prevents, detects, and corrects errors so that the integrity, availability, and confidentiality of transactions over networks may be maintained?

  • A. Networks security management and techniques
  • B. Clients security management and techniques
  • C. Communications security management and techniques
  • D. Servers security management and techniques

Answer: C


NEW QUESTION # 295
Which of the following cloud deployment model is provisioned for open use by the general public?

  • A. Public Cloud
  • B. Community Cloud
  • C. Private Cloud
  • D. Hybrid Cloud

Answer: A

Explanation:
In Public cloud, the cloud infrastructure is provisioned for open use by the general public. It may be owned, managed, and operated by a business, academic, or government organization, or some combination of them. It exists on the premises of the cloud provider.
For your exam you should know below information about Cloud Computing deployment models:
Private cloud The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by the organization, a third party, or some combination of them,and it may exist on or off premises.
Private Cloud
Image Reference - http://www.inflectionpoint.co.uk/Portals/5/VMware-vCloud.jpg
Community Cloud
The cloud infrastructure is provisioned for exclusive use by a specific community of consumers
from organizations that have shared concerns (e.g., mission,security requirements, policy, and
compliance considerations). It may be owned, managed, and operated by one or more of the
organizations in the community, a third party, or some combination of them, and it may exist on or
off premises.
Community Cloud
Image Reference - http://cloudcomputingksu.files.wordpress.com/2012/05/community-cloud.png
Public Cloud
The cloud infrastructure is provisioned for open use by the general public. It may be owned,
managed, and operated by a business, academic, or government organization, or some
combination of them. It exists on the premises of the cloud provider.
Public Cloud
Image reference - http://definethecloud.files.wordpress.com/2010/04/image3.png
Hybrid cloud
The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private,
community, or public) that remain unique entities, but are bound together by standardized or
proprietary technology that enables data and application portability (e.g., cloud bursting for load
balancing between clouds)
hybrid cloud
Image reference - http://www.virtualizationpractice.com/wp-content/uploads/2013/04/Hybrid-
Cloud-Computing-Solution1.jpg
The following answers are incorrect:
Private cloud - The cloud infrastructure is provisioned for exclusive use by a single organization
comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by
the organization, a third party, or some combination of them,and it may exist on or off premises.
Community cloud - The cloud infrastructure is provisioned for exclusive use by a specific
community of consumers from organizations that have shared concerns (e.g., mission,security
requirements, policy, and compliance considerations). It may be owned, managed, and operated
by one or more of the organizations in the community, a third party, or some combination of them,
and it may exist on or off premises.
Hybrid cloud - The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds)
The following reference(s) were/was used to create this question: CISA review manual 2014 page number 102 Official ISC2 guide to CISSP 3rd edition Page number 689 and 690


NEW QUESTION # 296
What is probing used for?

  • A. To give an attacker a road map of the network
  • B. To covertly listen to transmissions
  • C. To induce a user into taking an incorrect action
  • D. To use up all of a target's resources

Answer: A

Explanation:
The correct answer is "To give an attacker a road map of the network". Probing is a procedure whereby the intruder runs programs that scan the network to create a network map for later intrusion.
Answer "To induce a user into taking an incorrect action" is spoofing, c is the objective of a
DoS attack, and d is passive eavesdropping.


NEW QUESTION # 297
What is the term used to describe a virus that can infect both program files and boot sectors?

  • A. Polymorphic
  • B. Multiple encrypting
  • C. Stealth
  • D. Multipartite

Answer: D


NEW QUESTION # 298
Which of the following is the SIMPLEST type of firewall?

  • A. Application gateway
  • B. Dual-homed host firewall
  • C. Packet filtering firewall
  • D. Stateful packet filtering firewall

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Packet filtering was the first generation of firewalls and it is the most rudimentary type of all of the firewall technologies.
Incorrect Answers:
A: A stateful packet filtering firewall is more complicated compared to the Packet filtering firewall, since the latter is stateless.
C: Dual-homed is a firewall architecture, not a firewall type.
A Dual-homed firewall refers to a device that has two interfaces: one facing the external network and the other facing the internal network.
D: Application -level gateways are known as second generation firewalls, while packet filtering is a first generation firewall References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 630


NEW QUESTION # 299
An intranet provides more security and control than which of the following:

  • A. public posting on the Extranet.
  • B. private posting on the Internet.
  • C. public posting on the Internet.
  • D. public posting on the Ethernet.

Answer: C

Explanation:
An intranet provides more security and control than a public posting on the
Internet.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 99.


NEW QUESTION # 300
Which RAID implementation is commonly called mirroring?

  • A. RAID level 5
  • B. RAID level 3
  • C. RAID level 2
  • D. RAID level 1

Answer: D

Explanation:
RAID level 1 actually mirrors data from one disk or a set of disks to another disk or set of disks. Each drive is normally mirrored to an equal drive partner that is being updated at the same time, thus allowing to recover from the other drive should one drive fail. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 65).


NEW QUESTION # 301
A user downloads a file from the Internet, then applies the Secure Hash Algorithm 3 (SHA-3) to it. Which of the following is the MOST likely reason for doing so?

  • A. It ensures the entire file downloaded.
  • B. It encrypts the entire file.
  • C. It checks the file for malware.
  • D. It verifies the integrity of the file.

Answer: D

Explanation:
Reference: https://blog.logsign.com/how-to-check-the-integrity-of-a-file/


NEW QUESTION # 302
In the OSI/ISO model, at what level is SET (SECURE ELECTRONIC TRANSACTION
PROTOCOL) provided?

  • A. Session
  • B. Application
  • C. Network
  • D. Presentation

Answer: B

Explanation:
This protocol was created by VISA and MasterCard as a common effort to make the buying process over the Internet secure through the distribution line of those companies. It is located in layer 7 of the OSI model, the application layer. SET uses a system of locks and keys along with certified account IDs for both consumers and merchants. Then, through a unique process of "encrypting" or scrambling the information exchanged between the shopper and the online store, SET ensures a payment process that is convenient, private and most of all secure.


NEW QUESTION # 303
According to the Orange Book, which security level is the first to require trusted recovery?

  • A. A1
  • B. B1
  • C. B2
  • D. B3

Answer: D

Explanation:
"Trusted recovery is required only for B3 and A1 level systems." Pg 305 Krutz:
CISSP Prep Guide: Gold Edition.


NEW QUESTION # 304
Which statement below is NOT true about the difference between cutthrough and store-and-forward switching?

  • A. A cut-through switch introduces more latency than a store-andforward switch.
  • B. Both methods operate at layer two of the OSI reference model.
  • C. A store-and-forward switch reads the whole packet and checks its
    validity before sending it to the next destination.
  • D. A cut-through switch reads only the header on the incoming data
    packet.

Answer: A

Explanation:
A cut-through switch provides less latency than a store-andforward
switch, as it forwards the frame before it has received the
complete frame. However, cut-through switches may also forward
defective or empty packets. Source: Virtual LANs by Mariana Smith
(McGraw-Hill, 1998).


NEW QUESTION # 305
Which of the following is not a one-way hashing algorithm?

  • A. RC4
  • B. MD2
  • C. SHA-1
  • D. HAVAL

Answer: A

Explanation:
RC4 was designed by Ron Rivest of RSA Security in 1987. While it is officially
termed "Rivest Cipher 4", the RC acronym is alternatively understood to stand for "Ron's Code"
(see also RC2, RC5 and RC6).
RC4 was initially a trade secret, but in September 1994 a description of it was anonymously
posted to the Cypherpunks mailing list. It was soon posted on the sci.crypt newsgroup, and from
there to many sites on the Internet. The leaked code was confirmed to be genuine as its output
was found to match that of proprietary software using licensed RC4. Because the algorithm is
known, it is no longer a trade secret. The name RC4 is trademarked, so RC4 is often referred to
as ARCFOUR or ARC4 (meaning alleged RC4) to avoid trademark problems. RSA Security has
never officially released the algorithm; Rivest has, however, linked to the English Wikipedia article
on RC4 in his own course notes. RC4 has become part of some commonly used encryption
protocols and standards, including WEP and WPA for wireless cards and TLS.
The main factors in RC4's success over such a wide range of applications are its speed and
simplicity: efficient implementations in both software and hardware are very easy to develop.
The following answer were not correct choices:
SHA-1 is a one-way hashing algorithms. SHA-1 is a cryptographic hash function designed by the
United States National Security Agency and published by the United States NIST as a U.S.
Federal Information Processing Standard. SHA stands for "secure hash algorithm".
The three SHA algorithms are structured differently and are distinguished as SHA-0, SHA-1, and
SHA-2. SHA-1 is very similar to SHA-0, but corrects an error in the original SHA hash specification
that led to significant weaknesses. The SHA-0 algorithm was not adopted by many applications.
SHA-2 on the other hand significantly differs from the SHA-1 hash function.
SHA-1 is the most widely used of the existing SHA hash functions, and is employed in several
widely used security applications and protocols. In 2005, security flaws were identified in SHA-1,
namely that a mathematical weakness might exist, indicating that a stronger hash function would
be desirable. Although no successful attacks have yet been reported on the SHA-2 variants, they
are algorithmically similar to SHA-1 and so efforts are underway to develop improved alternatives.
A new hash standard, SHA-3, is currently under development - an ongoing NIST hash function
competition is scheduled to end with the selection of a winning function in 2012.
SHA-1 produces a 160-bit message digest based on principles similar to those used by Ronald L.
Rivest of MIT in the design of the MD4 and MD5 message digest algorithms, but has a more
conservative design.
MD2 is a one-way hashing algorithms. The MD2 Message-Digest Algorithm is a cryptographic
hash function developed by Ronald Rivest in 1989. The algorithm is optimized for 8-bit computers.
MD2 is specified in RFC 1319. Although MD2 is no longer considered secure, even as of 2010 it
remains in use in public key infrastructures as part of certificates generated with MD2 and RSA.
Haval is a one-way hashing algorithms. HAVAL is a cryptographic hash function. Unlike MD5, but
like most modern cryptographic hash functions, HAVAL can produce hashes of different lengths.
HAVAL can produce hashes in lengths of 128 bits, 160 bits, 192 bits, 224 bits, and 256 bits.
HAVAL also allows users to specify the number of rounds (3, 4, or 5) to be used to generate the
hash.
The following reference(s) were used for this question:
SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000. and https://en.wikipedia.org/wiki/HAVAL and https://en.wikipedia.org/wiki/MD2_%28cryptography%29 and https://en.wikipedia.org/wiki/SHA-1


NEW QUESTION # 306
Which choice below is NOT one of NIST's 33 IT security principles?

  • A. Minimize the system elements to be trusted.
  • B. Totally eliminate any level of risk.
  • C. Assume that external systems are insecure.
  • D. Implement least privilege.

Answer: B

Explanation:
Risk can never be totally eliminated. NIST IT security principle #4 states: Reduce risk to an acceptable level. The National Institute of Standards and Technology's (NIST) Information Technology Laboratory (ITL) released NIST Special Publication (SP) 800-27, Engineering Principles for Information Technology Security (EP-ITS) in June 2001 to assist in the secure design, development, deployment, and life-cycle of information systems. It presents 33 security principles which start at the design phase of the information system or application and continue until the system's retirement and secure disposal. Some of the other 33 principles are: Principle 1. Establish a sound security policy as the foundation for design. Principle 2. Treat security as an integral part of the overall system design. Principle 5. Assume that external systems are insecure. Principle 6. Identify potential trade-offs between reducing risk and increased costs and decrease in other aspects of operational effectiveness. Principle 7. Implement layered security (ensure no single point of vulnerability). Principle 11. Minimize the system elements to be trusted. Principle 16. Isolate public access systems from mission critical resources (e.g., data, processes, etc.). Principle 17. Use boundary mechanisms to separate computing systems and network infrastructures. Principle 22. Authenticate users and processes to ensure appropriate access control decisions both within and across domains. Principle 23. Use unique identities to ensure accountability.
Principle 24. Implement least privilege. Source: NIST Special Publication 800-27, Engineering Principles for Information Technology Security (A Baseline for Achieving Security), and Federal Systems Level Guidance for Securing Information Systems, James Corrie, August 16, 2001 .


NEW QUESTION # 307
Which of the following factors may render a token based solution unusable?

  • A. Card size
  • B. Battery lifespan
  • C. Token length
  • D. None of the choices.

Answer: B

Explanation:
Another limitation of some of the tokens is their battery lifespan. For example, in the case of SecurID you have a token that has a battery that will last from 1 to 3 years depending on the type of token you acquired. Some token companies such as Cryptocard have introduced tokens that have a small battery compartment allowing you to change the battery when it is discharged.


NEW QUESTION # 308
Which of the following defines when RAID separates the data into multiple units and stores it on multiple disks?

  • A. striping
  • B. screening
  • C. shadowing
  • D. scanning

Answer: A

Explanation:
Basically, RAID separates the data into multiple units and stores it on multiple disks by using a process called "striping". Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 65.


NEW QUESTION # 309
......


ISC CISSP (Certified Information Systems Security Professional) Exam is a globally recognized certification program that is designed to test the skills and knowledge of information security professionals. CISSP exam is intended for individuals who have extensive experience in the field of information security and want to demonstrate their expertise to potential employers. It covers a wide range of topics, including risk management, access control, cryptography, and network security.

 

Exam Questions for CISSP Updated Versions With Test Engine: https://www.verifieddumps.com/CISSP-valid-exam-braindumps.html

Pass CISSP Exam with Updated CISSP Exam Dumps PDF: https://drive.google.com/open?id=1UdCbOklsl8LPnRQSsneXv7dvreH7T1QC