CISSP- Domain 2: Asset Security

Business Aug 2, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CISSP- Domain 2: Asset Security

Angela is an information security architect at bank and has been assigned to ensure that transactions are secure as they traverse the network. She recommends that all transactions us TLS. What threat is she most likely attempting to stop, and what method is she using to protect against it?(Ans- Sniffing, encryption

COBIT, Control Objectives for Information and Related Technology, is a framework for IT management and governance. Which data management role is most likely to select and apply COBIT to balance the need for security controls against business requirements?(Ans- Business owners have to balance the need to provide value with regulatory, security, and other requirements

What term is used to describe a starting point for a minimum security standard?(Ans- A baseline is used to ensure minimum security standard.

When media is labeled based on the classification of the data it contains, what rule is typically applied regarding labels?(Ans- Media is typically labeled with the highest classification level of data it contains.

The need to protect sensitive data drives what administrative process?(Ans- Information process . allows organizations to focus on data that needs to be protected.

How can data retention policy help reduce liabilities?(Ans- ensures outdated data is purged, removing potential additional costs for discovery.

  • / 3

Staff in an IT department who are delegated responsibility for day-to-day tasks hold what data role?(Ans- Data custodians are delegated the role of handling day-to-day tasks by managing overseeing how data is handled, stored and protected.

Susan works for an American company that conducts business with customers in the EU. What is she likely to have to do if she is respoonsible for handling PII from those customers?(Ans- Comply with Safe Harbor US-EU requirements

Benn has been tasked with identifying security controls for systems covered by his organization’s information classification system. Why migh Ben choose to use a security baseline?(Ans- Provide a good starting point to scope and tailor security controls towards organization's needs

What term in used to describe overwriting media to allow for its resue in an environment operating at the same sensitivity level?(Ans- Clearing prepares media for reuse.

Which of the following classification levels is the US government's classification label for data that could cause damage but wouldn't cause serious ro grave damage?(Ans- Confidential

What issue is common to spare sectors and bad sectors on hard drives as well as overprovisioned space on modern SSDs?(Ans- They may not be cleared, resulting in data remanence

What term describes data that remains after attempts have been made to remove the data?(Ans- Data remanence

Your organization regularly handled three types of data: information that is

shares with customers, information that is used internally to conduct 2 / 3

business, and trade secret information that offers the organization significant competitive advantages. Information shared with customers is used and stored on web servers, while both the internal business data and trade secret information are stored on internal file servers and employee workstations. What civilian data classifications best fit this d (Ans- public (information shared w/customers), sensitive, proprietary

Your organization regularly handled three types of data: information that is

shares with customers, information that is used internally to conduct business, and trade secret information that offers the organization significant competitive advantages. Information shared with custoemrs is used and stored on web servers, while both the internal business data and trade secret information are stored on internal file servers and employee workstations. What technique could you use to mark your trade se (Ans- A watermark. used to digitally id and indicate ownership.

Your organization regularly handled three types of data: information that is

shares with customers, information that is used internally to conduct business, and trade secret information that offers the organization significant competitive advantages. Information shared with custoemrs is used and stored on web servers, while both the internal business data and trade secret information are stored on internal file servers and employee workstations. What type of encryption should you use on the file (Ans- TLS (used for protecting data in transit)

What does labeling data allow a DLP system to do?(Ans- Allows for appropriate application of controls to the data

What is it cost effective to purchase high-quality media to contain sensitive data? (Ans- The value of the data often far exceeds the cost of the media.

  • / 3

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Business
Added: Aug 2, 2025
Description:

CISSP- Domain 2: Asset Security Angela is an information security architect at bank and has been assigned to ensure that transactions are secure as they traverse the network. She recommends that al...

Get this document $30.00