[Q468-Q488] Use the best ways of preparing for CISSP Exam Dumps with VerifiedDumps ISC CISSP PDF Dumps [2021]

Share

Use the best ways of preparing for CISSP Exam Dumps with VerifiedDumps ISC CISSP dump PDF [2021]

ISC CISSP exam candidates will surely pass the Exam if they consider the CISSP dumps learning material presented by VerifiedDumps.

NEW QUESTION 468
Which of the following media is LEAST problematic with data remanence?

  • A. Dynamic Random Access Memory (DRAM)
  • B. Flash memory
  • C. Magnetic disk
  • D. Electrically Erasable Programming Read-Only Memory (BPRCM)

Answer: A

 

NEW QUESTION 469
Which of the following is the lowest TCSEC class wherein the systems must support separate operator and system administrator roles?

  • A. A2
  • B. A1
  • C. B2
  • D. B1

Answer: C

Explanation:
Explanation/Reference:
Explanation:
B2: Structured Protection: The security policy is clearly defined and documented, and the system design and implementation are subjected to more thorough review and testing procedures. This class requires more stringent authentication mechanisms and well-defined interfaces among layers. Subjects and devices require labels, and the system must not allow covert channels. A trusted path for logon and authentication processes must be in place, which means the subject communicates directly with the application or operating system, and no trapdoors exist. There is no way to circumvent or compromise this communication channel. Operator and administration functions are separated within the system to provide more trusted and protected operational functionality. Distinct address spaces must be provided to isolate processes, and a covert channel analysis is conducted. This class adds assurance by adding requirements to the design of the system.
The type of environment that would require B2 systems is one that processes sensitive data that require a higher degree of security. This type of environment would require systems that are relatively resistant to penetration and compromise.
Incorrect Answers:
B: Separate operator and system administrator roles are not required at level B1.
C: Separate operator and system administrator roles are required at level A1. However, they are also required at the lower level of B2.
D: Separate operator and system administrator roles are required at level A2. However, they are also required at the lower level of B2.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 396
http://csrc.nist.gov/publications/secpubs/rainbow/std001.txt

 

NEW QUESTION 470
Which of the following is true regarding a secure access model?

  • A. None of the choices.
  • B. Secure information cannot flow to a less secure user.
  • C. Secure information cannot flow to a more secure user.
  • D. Secure information can flow to a less secure user.

Answer: B

Explanation:
Access restrictions such as access control lists and capabilities sometimes are not enough. In some cases, information needs to be tightened further, sometimes by an authority higher than the owner of the information. For example, the owner of a top-secret document in a government office might deem the information available to many users, but his manager might know the information should be restricted further than that. In this case, the flow of information needs to be controlled -- secure information cannot flow to a less secure user.

 

NEW QUESTION 471
Which of the following is the MOST important output from a mobile application threat modeling exercise according to Open Web Application Security Project (OWASP)?

  • A. Application interface entry and endpoints
  • B. Countermeasures and mitigations for vulnerabilities
  • C. The likelihood and impact of a vulnerability
  • D. A data flow diagram for the application and attack surface analysis

Answer: D

 

NEW QUESTION 472
Which choice below is NOT considered an information classification role?

  • A. Data custodian
  • B. Data alterer
  • C. Data owner
  • D. Data user

Answer: B

Explanation:
The correct answer is "Data alterer". Data owners, custodians, and users all have defined roles in the process of information classification. Answer "Data alterer" is a distracter.

 

NEW QUESTION 473
You have been tasked with developing a Business Continuity Plan/Disaster Recovery (BCP/DR) plan. After several months of researching the various areas of the organization, you are ready to present the plan to Senior Management.
During the presentation meeting, the plan that you have dutifully created is not received positively. Senior Management is convinced that they need to enact your plan, nor are they prepared to invest any money in the plan.
What is the BEST reason, as to why Senior Management is not willing to enact your plan?

  • A. They were not included in any of the Risk Assessment meetings.
  • B. A Business Impact Assessment was not performed.
  • C. They were not included in any of the Business Impact Assessment meetings.
  • D. The business case was not initially made and thus did not secure their support.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The most critical part of establishing and maintaining a current continuity plan is management support.
Management must be convinced of the necessity of such a plan. Therefore, a business case must be made to obtain this support.
In order to convince Senior Management of the viability of the plan you need to convince them of the business case. The Senior Management usually wants information stated in monetary, quantitative terms, not in subjective, qualitative terms.
Incorrect Answers:
B: Senior Management does not need to attend the Risk Assessment meetings.
C: Senior Management does not need to attend the Business Impact Assessment meetings.
D: The Business Impact Assessment is made after the BCP plan has been approved. To make a Business Impact Assessment the BCP team must sit down and discuss, preferably with the involvement of senior management, qualitative concerns to develop a comprehensive approach that satisfies all stakeholders.

 

NEW QUESTION 474
Secure Shell (SSH) and Secure Sockets Layer (SSL) are very heavily used for protecting

  • A. Telnet transactions
  • B. Electronic Payment transactions
  • C. Ethernet transactions
  • D. Internet transactions

Answer: D

 

NEW QUESTION 475
An input validation and exception handling vulnerability has been discovered on a critical web-based system.
Which of the following is MOST suited to quickly implement a control?

  • A. Patch the application source code
  • B. Block access to the service
  • C. Install an Intrusion Detection System (IDS)
  • D. Add a new rule to the application layer firewall

Answer: D

Explanation:
Section: Communication and Network Security

 

NEW QUESTION 476
Which of the following is NOT a critical security aspect of Operations Controls?

  • A. Controls over hardware.
  • B. Environmental controls.
  • C. Data media used.
  • D. Operators using resources.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
While it is important that environmental concerns are addressed they are part of the Physical Security Domain.
The Operations Security domain is concerned with the controls that are used to protect hardware, software, and media resources from the following:
Threats in an operating environment

Internal or external intruders

Operators who are inappropriately accessing resources

Incorrect Answers:
A: Controls over hardware are a critical security aspect of Operations Controls.
B: Controls over the data media used are a critical security aspect of Operations Controls.
C: Controls over the operators using resources are a critical security aspect of Operations Controls.
References:
Krutz, Ronald L. and Russel Dean Vines, The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, New York, 2001, p. 207

 

NEW QUESTION 477
Devices that supply power when the commercial utility power system fails are called which of the following?

  • A. power dividers
  • B. power conditioners
  • C. uninterruptible power supplies
  • D. power filters

Answer: C

Explanation:
From Shon Harris AIO Fifth Edition:
Protecting power can be done in three ways: through UPSs, power line conditioners, and backup
sources.
UPSs use battery packs that range in size and capacity. A UPS can be online or standby.
Online UPS systems use AC line voltage to charge a bank of batteries. When in use, the UPS has
an inverter that changes the DC output from the batteries into the required AC form and that
regulates the voltage as it powers computer devices.
Online UPS systems have the normal primary power passing through them day in and day out.
They constantly provide power from their own inverters, even when the electric power is in proper
use. Since the environment's electricity passes through this type of UPS all the time, the UPS
device is able to quickly detect when a power failure takes place. An online UPS can provide the
necessary electricity and picks up the load after a power failure much more quickly than a standby
UPS.
Standby UPS devices stay inactive until a power line fails. The system has sensors that detect a
power failure, and the load is switched to the battery pack. The switch to the battery pack is what
causes the small delay in electricity being provided.
So an online UPS picks up the load much more quickly than a standby UPS, but costs more of
course.

 

NEW QUESTION 478
Which of the following statements pertaining to VPN protocol standards is false?

  • A. L2TP and PPTP were designed for single point-to-point client to server communication.
  • B. L2TP operates at the network layer.
  • C. PPTP uses native PPP authentication and encryption services.
  • D. L2TP is a combination of PPTP and L2F.

Answer: B

Explanation:
L2TP and PPTP were both designed for individual client to server connections; they enable only a single point-to-point connection per session. Dial-up VPNs use L2TP often. Both L2TP and PPTP operate at the data link layer (layer 2) of the OSI model. PPTP uses native PPP authentication and encryption services and L2TP is a combination of PPTP and Layer 2 Forwarding protocol (L2F).
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3:
Telecommunications and Network Security (page 95).

 

NEW QUESTION 479
Firewalls filter incoming traffic according to

  • A. A security process.
  • B. The packet composition.
  • C. Stateful packet rules.
  • D. A security policy.

Answer: D

 

NEW QUESTION 480
Which of the following is true about link encryption?

  • A. This mode does not provide protection if anyone of the nodes along the transmission path is compromised.
  • B. Each entity has a common key with the destination node.
  • C. Encrypted messages are only decrypted by the final node.
  • D. Only secure nodes are used in this type of transmission.

Answer: A

Explanation:
In link encryption, each entity has keys in common with its two neighboring nodes in the transmission chain.
Thus, a node receives the encrypted message from its predecessor, decrypts it, and then re-encrypts it with a new key, common to the successor node. Obviously, this mode does not provide protection if anyone of the nodes along the transmission path is compromised.
Encryption can be performed at different communication levels, each with different types of protection and implications. Two general modes of encryption implementation are link encryption and end-to-end encryption.
Link encryption encrypts all the data along a specific communication path, as in a satellite link, T3 line, or telephone circuit. Not only is the user information encrypted, but the header, trailers, addresses, and routing data that are part of the packets are also encrypted. The only traffic not encrypted in this technology is the data link control messaging information, which includes instructions and parameters that the different link devices use to synchronize communication methods. Link encryption provides protection against packet sniffers and eavesdroppers.
In end-to-end encryption, the headers, addresses, routing, and trailer information are not encrypted, enabling attackers to learn more about a captured packet and where it is headed.
Reference(s) used for this question:
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (pp. 845-846). McGraw-Hill.
And:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of
Computer Security, John Wiley & Sons, 2001, Chapter 4: Cryptography (page 132).

 

NEW QUESTION 481
How should an organization determine the priority of its remediation efforts after a vulnerability assessment has been conducted?

  • A. Use a risk-based approach.
  • B. Use a threat-based approach.
  • C. Use a criticality-based approach.
  • D. Use an impact-based approach.

Answer: A

Explanation:
Section: Software Development Security

 

NEW QUESTION 482
Secure Sockets Layer (SSL) is very heavily used for protecting which of the following?

  • A. EDI transactions.
  • B. Web transactions.
  • C. Telnet transactions.
  • D. Electronic Payment transactions.

Answer: B

Explanation:
SSL was developed Netscape Communications Corporation to improve security and
privacy of HTTP transactions.
SSL is one of the most common protocols used to protect Internet traffic.
It encrypts the messages using symmetric algorithms, such as IDEA, DES, 3DES, and Fortezza,
and also calculates the MAC for the message using MD5 or SHA-1. The MAC is appended to the
message and encrypted along with the message data.
The exchange of the symmetric keys is accomplished through various versions of Diffie-Hellmann
or RSA. TLS is the Internet standard based on SSLv3. TLSv1 is backward compatible with SSLv3.
It uses the same algorithms as SSLv3; however, it computes an HMAC instead of a MAC along
with other enhancements to improve security.
The following are incorrect answers:
"EDI transactions" is incorrect. Electronic Data Interchange (EDI) is not the best answer to this
question though SSL could play a part in some EDI transactions.
"Telnet transactions" is incorrect. Telnet is a character mode protocol and is more likely to be
secured by Secure Telnet or replaced by the Secure Shell (SSH) protocols.
"Eletronic payment transactions" is incorrect. Electronic payment is not the best answer to this
question though SSL could play a part in some electronic payment transactions.
Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition
((ISC)2 Press) (Kindle Locations 16615-16619). Auerbach Publications. Kindle Edition.
and
http://en.wikipedia.org/wiki/Transport_Layer_Security

 

NEW QUESTION 483
Which of the following devices enables more than one signal to be sent out simultaneously over one physical circuit?

  • A. Wan switch
  • B. Router
  • C. Multiplexer
  • D. Channel service unit/Data service unit (CSU/DSU)

Answer: C

Explanation:
Explanation/Reference:
Explanation:
An electronic multiplexer makes it possible for several signals to share one device or resource. A multiplexer (or mux) is a device that selects one of several analog or digital input signals and forwards the selected input into a single line.
Incorrect Answers:
A: A router forwards data packets. A router does not handle signals.
C: A CSU/DSU is a digital-interface device used to connect a data terminal equipment (DTE), such as a router, to a digital circuit, such as a Digital Signal 1 (T1) line.
D: A switch forwards traffic at the data link layer of the OSI model. It does operate with multiple signals.
References:
https://en.wikipedia.org/wiki/Multiplexer

 

NEW QUESTION 484
Which of the following MUST be part of a contract to support electronic discovery of data stored in a cloud environment?

  • A. Accommodation of hybrid deployment models
  • B. Tokenization of data
  • C. Integration with organizational directory services for authentication
  • D. Identification of data location

Answer: D

 

NEW QUESTION 485
What is the name for a substitution cipher that shifts the alphabet by 13 places?

  • A. Caesar cipher
  • B. Polyalphabetic cipher
  • C. Transposition cipher
  • D. ROT13 cipher

Answer: D

Explanation:
An extremely simple example of conventional cryptography is a substitution cipher.
A substitution cipher substitutes one piece of information for another. This is most frequently done
by offsetting letters of the alphabet. Two examples are Captain Midnight's Secret Decoder Ring,
which you may have owned when you were a kid, and Julius Caesar's cipher. In both cases, the
algorithm is to offset the alphabet and the key is the number of characters to offset it. So the offset
could be one, two, or any number you wish. ROT-13 is an example where it is shifted 13 spaces.
The Ceaser Cipher is another example where it is shifted 3 letters to the left.
ROT13 ("rotate by 13 places", sometimes hyphenated ROT-13) is a simple letter substitution
cipher that replaces a letter with the letter 13 letters after it in the alphabet. ROT13 is an example
of the Caesar cipher, developed in ancient Rome.
In the basic Latin alphabet, ROT13 is its own inverse; that is, to undo ROT13, the same algorithm
is applied, so the same action can be used for encoding and decoding. The algorithm provides
virtually no cryptographic security, and is often cited as a canonical example of weak encryption.
ROT13 is used in online forums as a means of hiding spoilers, puzzle solutions, and offensive
materials from the casual glance. ROT13 has been described as the "Usenet equivalent of a
magazine printing the answer to a quiz upside down". ROT13 has inspired a variety of letter and
word games on-line, and is frequently mentioned in newsgroup conversations. See diagram
Below:
Rot 13 Cipher
The following are incorrect:
The Caesar cipher is a simple substitution cipher that involves shifting the alphabet three positions
to the right. In cryptography, a Caesar cipher, also known as Caesar's cipher, the shift cipher,
Caesar's code or Caesar shift, is one of the simplest and most widely known encryption
techniques. It is a type of substitution cipher in which each letter in the plaintext is replaced by a
letter some fixed number of positions down the alphabet. For example, with a left shift of 3, D
would be replaced by A, E would become B, and so on. The method is named after Julius Caesar,
who used it in his private correspondence.
Caesar Cipher
Polyalphabetic cipher refers to using multiple alphabets at a time. A polyalphabetic cipher is any
cipher based on substitution, using multiple substitution alphabets. The Vigenere cipher is
probably the best-known example of a polyalphabetic cipher, though it is a simplified special case.
Viginere Cipher
Transposition cipher is a different type of cipher. In cryptography, a transposition cipher is a
method of encryption by which the positions held by units of plaintext (which are commonly
characters or groups of characters) are shifted according to a regular system, so that the
ciphertext constitutes a permutation of the plaintext. That is, the order of the units is changed. See
the reference below for multiple examples of Transpositio Ciphers.
An exemple of Transposition cipher could be columnar transposition, the message is written out in rows of a fixed length, and then read out again column by column, and the columns are chosen in some scrambled order. Both the width of the rows and the permutation of the columns are usually defined by a keyword. For example, the word ZEBRAS is of length 6 (so the rows are of length 6), and the permutation is defined by the alphabetical order of the letters in the keyword. In this case, the order would be "6 3 2 4 1 5".
In a regular columnar transposition cipher, any spare spaces are filled with nulls; in an irregular columnar transposition cipher, the spaces are left blank. Finally, the message is read off in columns, in the order specified by the keyword. For example, suppose we use the keyword ZEBRAS and the message WE ARE DISCOVERED. FLEE AT ONCE. In a regular columnar transposition, we write this into the grid as Follows:
Transposition Cipher Providing five nulls (QKJEU) at the end. The ciphertext is then read off as: EVLNE ACDTK ESEAQ ROFOJ DEECU WIREE
Reference(s) used for this question: http://en.wikipedia.org/wiki/ROT13 http://en.wikipedia.org/wiki/Caesar_cipher http://en.wikipedia.org/wiki/Polyalphabetic_cipher http://en.wikipedia.org/wiki/Transposition_cipher

 

NEW QUESTION 486
For maximum security design, what type of fence is most effective and cost-effective method (Foot are being used as measurement unit below)?

  • A. 8' high and above with strands of barbed wire.
  • B. 6' to 7' high.
  • C. Double fencing
  • D. 3' to 4' high.

Answer: C

Explanation:
The most commonly used fence is the chain linked fence and it is the most affordable. The standard is a six-foot high fence with two-inch mesh square openings. The material should consist of nine-gauge vinyl or galvanized metal. Nine-gauge is a typical fence material installed in residential areas.
Additionally, it is recommended to place barbed wire strands angled out from the top of the fence at a 45(o) angle and away from the protected area with three strands running across the top. This
will provide for a seven-foot fence. There are several variations of the use of "top guards" using V-
shaped barbed wire or the use of concertina wire as an enhancement, which has been a
replacement for more traditional three strand barbed wire "top guards."
The fence should be fastened to ridged metal posts set in concrete every six feet with additional
bracing at the corners and gate openings. The bottom of the fence should be stabilized against
intruders crawling under by attaching posts along the bottom to keep the fence from being pushed
or pulled up from the bottom. If the soil is sandy, the bottom edge of the fence should be installed
below ground level.
For maximum security design, the use of double fencing with rolls of concertina wire positioned
between the two fences is the most effective deterrent and cost-efficient method. In this design, an
intruder is required to use an extensive array of ladders and equipment to breach the fences.
Most fencing is largely a psychological deterrent and a boundary marker rather than a barrier,
because in most cases such fences can be rather easily penetrated unless added security
measures are taken to enhance the security of the fence. Sensors attached to the fence to provide
electronic monitoring of cutting or scaling the fence can be used.
Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition
((ISC)2 Press) (Kindle Locations 24416-24431). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 487
Which of the following is the MAIN reason that system re-certification and re-accreditation are needed?

  • A. To assure the software development team that all security issues have been addressed
  • B. To assist data owners in making future sensitivity and criticality determinations
  • C. To verify that security protection remains acceptable to the organizational security policy
  • D. To help the security team accept or reject new systems for implementation and production

Answer: C

 

NEW QUESTION 488
......

Full CISSP Practice Test and 990 unique questions with explanations waiting just for you, get it now: https://drive.google.com/open?id=1wDDAPlHLfAwi36OSBPhwIFT19QDlkxcA

Accurate & Verified Answers As Seen in the Real Exam here: https://www.verifieddumps.com/CISSP-valid-exam-braindumps.html