CISSP CBK Review Final Exam

Study Guides Aug 1, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CISSP CBK Review Final Exam CISSP CBK Review Page 1

  • A risk is the likelihood of a threat source taking advantage of a vulnerability to an

information system. Risks left over after implementing safeguards is known as:

  • Leftover risks.
  • Residual risks.
  • Remaining risks.
  • Exposures.

2. Copyright provides what form of protection:

  • Protects an author’s right to distribute his/her works.
  • Protects information that provides a competitive advantage.
  • Protects the right of an author to prevent unauthorized use of his/her works.
  • Protects the right of an author to prevent viewing of his/her works.
  • As an information systems security professional, what is the highest amount would
  • you recommend to a corporation to invest annually on a countermeasure for protecting their assets valued at $1 million from a potential threat that has an annualized rate of occurrence (ARO) of once every five years and an exposure factor

(EF) of 10% :

A. $100,000.

B. $20,000.

C. $200,000.

D. $40,000.

  • Which of the following describes the first step in establishing an encrypted session
  • using a Data Encryption Standard (DES) key?

  • Key clustering
  • Key compression
  • Key signing
  • Key exchange
  • In a typical information security program, what is the primary responsibility of
  • information (data) owner?

  • Ensure the validity and accuracy of data.
  • Determine the information sensitivity or classification level. 1 / 4

CISSP CBK Review Final Exam CISSP CBK Review Page 2

  • Monitor and audit system users.
  • Ensure availability of data.

6. Which of the following is not a component of “chain of evidence”:

  • Location evidence obtained.
  • Time evidence obtained.
  • Who discovered the evidence.
  • Identification of person who left the evidence.
  • When an employee transfers within an organization …
  • The employee must undergo a new security review.
  • The old system IDs must be disabled.
  • All access permission should be reviewed.
  • The employee must turn in all access devices.
  • A system security engineer is evaluation methods to store user passwords in an
  • information system, so what may be the best method to store user passwords and meeting the confidentiality security objective?

  • Password-protected file
  • File restricted to one individual
  • One-way encrypted file
  • Two-way encrypted file
  • What is the inverse of confidentiality, integrity, and availability (C.I.A.) triad in risk
  • management?

  • misuse, exposure, destruction
  • authorization, non-repudiation, integrity
  • disclosure, alteration, destruction
  • confidentiality, integrity, availability
  • A CISSP may face with an ethical conflict between their company’s policies and the
  • (ISC) 2 Code of Ethics. According to the (ISC) 2 Code of Ethics, in which order of priority should ethical conflicts be resolved?

  • Duty to principals, profession, public safety, and individuals. 2 / 4

CISSP CBK Review Final Exam CISSP CBK Review Page 3

  • Duty to public safety, principals, individuals, and profession.
  • Duty to profession, public safety, individuals, and principals.
  • Duty to public safety, profession, individuals, and principals.
  • Company X is planning to implement rule based access control mechanism for
  • controlling access to its information assets, what type of access control is this usually related to?

  • Discretionary Access Control
  • Task-initiated Access Control
  • Subject-dependent Access Control
  • Token- oriented Access Control
  • In the Common Criteria Evaluation and Validation Scheme (CCEVS), requirements

for future products are defined by:

  • Protection Profile.
  • Target of Evaluation.
  • Evaluation Assurance Level 3.
  • Evaluation Assurance Level 7.
  • As an information systems security manager (ISSM), how would you explain the
  • purpose for a system security policy?

  • A definition of the particular settings that have been determined to provide
  • optimum security

  • A brief, high- level statement defining what is and is not permitted during the
  • operation of the system

  • A definition of those items that must be excluded on the system
  • A listing of tools and applications that will be used to protect the system
  • Configuration management provides assurance that changes…?
  • to application software cannot bypass system security features.
  • do not adversely affect implementation of the security policy.
  • to the operating system are always subjected to independent validation and
  • verification.

  • in technical documentation maintain an accurate description of the Trusted
  • Computer Base. 3 / 4

CISSP CBK Review Final Exam CISSP CBK Review Page 4

  • Under what circumstance might a certification authority (CA) revoke a certificate?
  • The certificate owner has not utilized the certificate for an extended period.
  • The certificate owner public key has been compromised.
  • The certificate owner’ private key has been compromised.
  • The certificate owner has upgraded his/her web browser.
  • Which of the following entity is ultimate ly responsible for information security
  • within an organization?

  • IT Security Officer
  • Project Managers
  • Department Directors
  • Senior Management
  • What type of cryptanalytic attack where an adversary has the least amount of
  • information to work with?

  • Known-plaintext
  • Ciphertext- only
  • Plaintext-only
  • Chosen- ciphertext
  • In business continuity planning, which of the following is an advantage of a “hot site”
  • over a “cold site”

  • Air Conditioning
  • Cost
  • Short period to become operational
  • A & C
  • Which of the following is the most effective method for reducing security risks
  • associated with building entrances?

  • Minimize the number of entrances
  • Use solid metal doors and frames
  • Brightly illuminate the entrances
  • Install tamperproof hinges and glass
  • / 4

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Study Guides
Added: Aug 1, 2025
Description:

CISSP CBK Review Final Exam CISSP CBK Review Page 1 1. A risk is the likelihood of a threat source taking advantage of a vulnerability to an information system. Risks left over after implementing s...

Get this document $30.00