CISSP CBK Review Final Exam CISSP CBK Review Page 1
- A risk is the likelihood of a threat source taking advantage of a vulnerability to an
information system. Risks left over after implementing safeguards is known as:
- Leftover risks.
- Residual risks.
- Remaining risks.
- Exposures.
2. Copyright provides what form of protection:
- Protects an author’s right to distribute his/her works.
- Protects information that provides a competitive advantage.
- Protects the right of an author to prevent unauthorized use of his/her works.
- Protects the right of an author to prevent viewing of his/her works.
- As an information systems security professional, what is the highest amount would
you recommend to a corporation to invest annually on a countermeasure for protecting their assets valued at $1 million from a potential threat that has an annualized rate of occurrence (ARO) of once every five years and an exposure factor
(EF) of 10% :
A. $100,000.
B. $20,000.
C. $200,000.
D. $40,000.
- Which of the following describes the first step in establishing an encrypted session
- Key clustering
- Key compression
- Key signing
- Key exchange
- In a typical information security program, what is the primary responsibility of
- Ensure the validity and accuracy of data.
- Determine the information sensitivity or classification level. 1 / 4
using a Data Encryption Standard (DES) key?
information (data) owner?
CISSP CBK Review Final Exam CISSP CBK Review Page 2
- Monitor and audit system users.
- Ensure availability of data.
6. Which of the following is not a component of “chain of evidence”:
- Location evidence obtained.
- Time evidence obtained.
- Who discovered the evidence.
- Identification of person who left the evidence.
- When an employee transfers within an organization …
- The employee must undergo a new security review.
- The old system IDs must be disabled.
- All access permission should be reviewed.
- The employee must turn in all access devices.
- A system security engineer is evaluation methods to store user passwords in an
- Password-protected file
- File restricted to one individual
- One-way encrypted file
- Two-way encrypted file
information system, so what may be the best method to store user passwords and meeting the confidentiality security objective?
- What is the inverse of confidentiality, integrity, and availability (C.I.A.) triad in risk
- misuse, exposure, destruction
- authorization, non-repudiation, integrity
- disclosure, alteration, destruction
- confidentiality, integrity, availability
- A CISSP may face with an ethical conflict between their company’s policies and the
- Duty to principals, profession, public safety, and individuals. 2 / 4
management?
(ISC) 2 Code of Ethics. According to the (ISC) 2 Code of Ethics, in which order of priority should ethical conflicts be resolved?
CISSP CBK Review Final Exam CISSP CBK Review Page 3
- Duty to public safety, principals, individuals, and profession.
- Duty to profession, public safety, individuals, and principals.
- Duty to public safety, profession, individuals, and principals.
- Company X is planning to implement rule based access control mechanism for
- Discretionary Access Control
- Task-initiated Access Control
- Subject-dependent Access Control
- Token- oriented Access Control
controlling access to its information assets, what type of access control is this usually related to?
- In the Common Criteria Evaluation and Validation Scheme (CCEVS), requirements
for future products are defined by:
- Protection Profile.
- Target of Evaluation.
- Evaluation Assurance Level 3.
- Evaluation Assurance Level 7.
- As an information systems security manager (ISSM), how would you explain the
- A definition of the particular settings that have been determined to provide
- A brief, high- level statement defining what is and is not permitted during the
- A definition of those items that must be excluded on the system
- A listing of tools and applications that will be used to protect the system
purpose for a system security policy?
optimum security
operation of the system
- Configuration management provides assurance that changes…?
- to application software cannot bypass system security features.
- do not adversely affect implementation of the security policy.
- to the operating system are always subjected to independent validation and
- in technical documentation maintain an accurate description of the Trusted
verification.
Computer Base. 3 / 4
CISSP CBK Review Final Exam CISSP CBK Review Page 4
- Under what circumstance might a certification authority (CA) revoke a certificate?
- The certificate owner has not utilized the certificate for an extended period.
- The certificate owner public key has been compromised.
- The certificate owner’ private key has been compromised.
- The certificate owner has upgraded his/her web browser.
- Which of the following entity is ultimate ly responsible for information security
- IT Security Officer
- Project Managers
- Department Directors
- Senior Management
- What type of cryptanalytic attack where an adversary has the least amount of
- Known-plaintext
- Ciphertext- only
- Plaintext-only
- Chosen- ciphertext
- In business continuity planning, which of the following is an advantage of a “hot site”
- Air Conditioning
- Cost
- Short period to become operational
- A & C
- Which of the following is the most effective method for reducing security risks
- Minimize the number of entrances
- Use solid metal doors and frames
- Brightly illuminate the entrances
- Install tamperproof hinges and glass
- / 4
within an organization?
information to work with?
over a “cold site”
associated with building entrances?