Get New 2021 Valid Practice ISC Certification CISSP Q&A - Testing Engine
CISSP Dumps PDF - 100% Passing Guarantee
What to Get: (ISC)2 CISSP Certification Benefits
After gaining the required work experience, successfully passing the (ISC)2 CISSP exam and finally getting endorsement, you will become eligible for the CISSP certification. Some of the most popular positions you can apply for after getting certified include the following:
- Internal Auditor;
- Chief Information Officer;
- Cloud Security Administrator.
- Network Architect;
- Security Consultant;
- Cybersecurity Forensic Analyst;
Having the CISSP certification under your belt can also have a great impact on the financial bottom line after successfully completing the exam. Those who hold this sought-after certificate can earn an average salary of about $101,000.
NEW QUESTION 51
Which of the following is related to physical security and is NOT considered a technical control?
- A. Locks
- B. Access control Mechanisms
- C. Firewalls
- D. Intrusion Detection Systems
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Locks are an example of a physical control type, not a technical control.
Controls are put into place to reduce the risk an organization faces, and they come in three main flavors:
administrative, technical, and physical. Administrative controls are commonly referred to as "soft controls" because they are more management-oriented. Examples of administrative controls are security documentation, risk management, personnel security, and training. Technical controls (also called logical controls) are software or hardware components, as in firewalls, IDS, encryption, identification and authentication mechanisms. And physical controls are items put into place to protect facility, personnel, and resources. Examples of physical controls are security guards, locks, fencing, and lighting.
Incorrect Answers:
A: Access control Mechanisms are an example of a technical control. Therefore, this answer is incorrect.
B: Intrusion Detection Systems are an example of a technical control. Therefore, this answer is incorrect.
C: Firewalls are an example of a technical control. Therefore, this answer is incorrect.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 28
NEW QUESTION 52
Which one of the following describes a covert timing channel?
- A. Provides the timing trigger to activate a malicious program disguised as a legitimate function.
- B. Allows one process to signal information to another by modulating its own use of system resources.
- C. Modulated to carry an unintended information signal that can only be detected by special, sensitive receivers.
- D. Used by a supervisor to monitor the productivity of a user without their knowledge.
Answer: B
Explanation:
A covert channel in which one process signals information to another by modulating its own use of system resources (for example, CPU time) in such a way that this manipulation affects the real response time observed by the second process. - Shon Harris All-in-one CISSP Certification Guide pg 929
NEW QUESTION 53
Under the MAC control system, what is required?
- A. Labeling
- B. Performance monitoring
- C. None of the choices
- D. Sensing
Answer: A
Explanation:
It is important to note that mandatory controls are prohibitive (i.e., all that is not expressly permitted is forbidden), not permissive. Only within that context do discretionary controls operate, prohibiting still more access with the same exclusionary principle. In this type of control system decisions are based on privilege (clearance) of subject (user) and sensitivity (classification) of object (file). It requires labeling.
NEW QUESTION 54
Which of the following is the MOST
- A. Virtual Local Area Network (VLAN) tagging
- B. Error correction
- C. Compartmentalization
- D. Segmentation
Answer: D
NEW QUESTION 55
Smart cards are an example of which type of control?
- A. Administrative control
- B. Detective control
- C. Technical control
- D. Physical control
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Smart cards are an example of a Preventive/Technical control.
Incorrect Answers:
A: Detective controls include Motion detectors, Closed-circuit TVs, Monitoring and Supervising, Job rotation, Investigations, Audit logs, and IDS.
B: Administrative controls include Security policy, Monitoring and Supervising, Separation of duties, Job rotation, Information Classification, Personnel Procedures, Testing, and Security-awareness training.
D: Physical controls include Fences, Locks, Badge system, Security guard, Biometric system, Mantrap doors, Lighting, Motion detectors, and Closed-circuit TVs.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 32, 33
NEW QUESTION 56
Which of the following is not a one-way hashing algorithm?
- A. SHA-1
- B. MD2
- C. HAVAL
- D. RC4
Answer: D
Explanation:
Explanation/Reference:
Explanation:
RC4 is a Symmetric Key Algorithm.
Incorrect Answers:
A: MD2 is a one-way hashing algorithm.
C: SHA-1 is a one-way hashing algorithm.
D: HAVAL is a one-way hashing algorithm.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 831
NEW QUESTION 57
What is a method in an object-oriented system?
- A. The situation where a class inherits the behavioral characteristics of more that one parent class
- B. A guide to the programming of objects
- C. The means of communication among objects
- D. The code defining the actions that the object performs in response to a message
Answer: D
Explanation:
method in an object-oriented system is
the code that defines the actions that the object performs in response
to a message.
Answer "The means of communication among objects" is incorrect because it defines a message.
Answer "A guide to the programming of objects" is a distracter.
Answer "The situation where a class inherits the behavioral characteristics of more that one parent class" refers to multiple inheritance.
NEW QUESTION 58
An example of an individual point of verification in a computerized application is
- A. A check digit.
- B. A sensitive transaction.
- C. A boundary protection.
- D. An inference check.
Answer: A
Explanation:
Checkdigit: A one-digit checksum.
Checksum: A computed value which depends on the contents of a block of data and which is
transmitted or stored along with the data in order to detect corruption of the data. The receiving
system recomputes the checksum based upon the received data and compares this value with the
one sent with the data. If the two values are the same, the receiver has some confidence that the
data was received correctly.
The checksum may be 8 bits (modulo 256 sum), 16, 32, or some other size. It is computed by
summing the bytes or words of the data block ignoring overflow. The checksum may be negated
so that the total of the data words plus the checksum is zero.
NEW QUESTION 59
Drag and Drop Question
Match the name of access control model with its associated restriction.
Drag each access control model to its appropriate restriction access on the right.
Answer:
Explanation:
NEW QUESTION 60
The Wireless Transport Layer Security Protocol (WTLS) in the Wireless
Application Protocol (WAP) stack provides for security:
- A. Between the WAP gateway and the content server
- B. Between the WAP client and the gateway
- C. Between the WAP content server and the WAP client
- D. Between the Internet and the content server
Answer: B
Explanation:
Transport Layer Security (TLS) provides for security between the
content server on the Internet and the WAP gateway. (Answer "Between the WAP gateway and the content server" is, thus, incorrect.) Similarly, WTLS provides security between the WAP mobile device (client software) and the WAP gateway. Since WAP
cannot interface directly with the Internet, all WAP information has
to be converted to HTTP in the WAP gateway to enable it to exchange
information with the Internet content servers. The simple block diagram illustrates these concepts.
Exhibit:
image024
A vulnerability occurs since data encrypted with wireless protocols
has to be decrypted in the WAP gateway and then re-encrypted
with the Internet protocols. This process is reversed when data flows
from the Internet content servers to the WAP client. Thus, the information is vulnerable while it is in the decrypted state on the WAP gateway. This condition is known as the WAP Gap. In order to address this issue, the WAP Forum has put forth specifications that
will reduce this vulnerability and, thus, support e-commerce applications.
These specifications are defined in WAP 1.2 as WMLScript
Crypto Library and the WAP Identity Module (WIM). The
WMLScript Crypto Library supports end-to-end security by providing
for cryptographic functions to be initiated on the WAP client from
the Internet content server. These functions include digital signatures originating with the WAP client and encryption and decryption of data. The WIM is a tamper-resistant device, such as a smart card, that cooperates with WTLS and provides cryptographic operations during
the handshake phase.
The WAP Forum is also considering another alternative to providing
the end-to-end encryption for WAP. This alternative, described in
WAP specification 1.3, is the use of a client proxy server that communicates authentication and authorization information to the wireless network server.
*Answer "Between the Internet and the content server" is incorrect since the content server is on the Internet side of the communication and answer "Between the WAP content server and the WAP client" assumes a direct interface between the content server and the client without going through the necessary Internet and wireless protocols.
NEW QUESTION 61
As part of an application penetration testing process, session hijacking can BEST be achieved by which of the following?
- A. Structured Query Language (SQL) injection
- B. Cookie manipulation
- C. Denial of Service (DoS)
- D. Known-plaintext attack
Answer: B
Explanation:
Explanation
Section: Security Assessment and Testing
NEW QUESTION 62
Which of the following is an important part of database design that ensures that attributes in a table depend only on the primary key?
- A. Reduction
- B. Assimilation
- C. Normalization
- D. Compaction
Answer: C
Explanation:
Normalization is an important part of database design that ensures that attributes in a table depend only on the primary key. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 47.
NEW QUESTION 63
Which of the following is best defined as a mode of system termination that automatically leaves system processes and components in a secure state when a failure occurs or is detected in a system?
- A. Fail proof
- B. Fail Over
- C. Fail soft
- D. Fail safe
Answer: D
Explanation:
NOTE: This question is referring to a system which is Logical/Technical, so it is in the context of a system that you must choose the right answer. This is very important to read the question carefully and to identify the context whether it is in the Physical world or in the Technical/Logical world.
RFC 2828 (Internet Security Glossary) defines fail safe as a mode of system termination that automatically leaves system processes and components in a secure state when a failure occurs or is detected in the system.
A secure state means in the Logical/Technical world that no access would be granted or no packets would be allowed to flow through the system inspecting the packets such as a firewall for example.
If the question would have made reference to a building or something specific to the Physical world then the answer would have been different. In the Physical World everything becomes open and full access would be granted. See the valid choices below for the Physical context.
Fail-safe in the physical security world is when doors are unlocked automatically in case of
emergency. Used in environment where humans work around. As human safety is prime concern
during Fire or other hazards.
The following were all wrong choices:
Fail-secure in the physical security world is when doors are locked automatically in case of
emergency. Can be in an area like Cash Locker Room provided there should be alternative
manually operated exit door in case of emergency.
Fail soft is selective termination of affected non-essential system functions and processes when a
failure occurs or is detected in the system.
Fail Over is a redundancy mechanism and does not apply to this question.
According to the Official ISC2 Study Guide (OIG):
Fault Tolerance is defined as built-in capability of a system to provide continued correct execution
in the presence of a limited number of hardware or software faults. It means a system can operate
in the presence of hardware component failures. A single component failure in a fault-tolerant
system will not cause a system interruption because the alternate component will take over the
task transparently. As the cost of components continues to drop, and the demand for system
availability increases, many non-fault-tolerant systems have redundancy built-in at the subsystem
level. As a result, many non-fault-tolerant systems can tolerate hardware faults - consequently, the
line between a fault-tolerant system and a non-fault-tolerant system becomes increasingly blurred.
According to Common Criteria:
Fail Secure - Failure with preservation of secure state, which requires that the TSF (TOE security
functions) preserve a secure state in the face of the identified failures.
Acc. to The CISSP Prep Guide, Gold Ed.:
Fail over - When one system/application fails, operations will automatically switch to the backup
system.
Fail safe - Pertaining to the automatic protection of programs and/or processing systems to
maintain safety when a hardware or software failure is detected in a system.
Fail secure - The system preserves a secure state during and after identified failures occur.
Fail soft - Pertaining to the selective termination of affected non-essential processing when a
hardware or software failure is detected in a system.
Acc. to CISSP for Dummies:
Fail closed - A control failure that results all accesses blocked.
Fail open - A control failure that results in all accesses permitted.
Failover - A failure mode where, if a hardware or software failure is detected, the system
automatically transfers processing to a hot backup component, such as a clustered server.
Fail-safe - A failure mode where, if a hardware or software failure is detected, program execution
is terminated, and the system is protected from compromise.
Fail-soft (or resilient) - A failure mode where, if a hardware or software failure is detected, certain,
noncritical processing is terminated, and the computer or network continues to function in a
degraded mode.
Fault-tolerant - A system that continues to operate following failure of a computer or network
component.
It's good to differentiate this concept in Physical Security as well:
Fail-safe
Door defaults to being unlocked
Dictated by fire codes
Fail-secure
Door defaults to being locked
Reference(s) used for this question:
SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000.
NEW QUESTION 64
Public key infrastructure(PKI) consists of programs, data formats, procedures, communication protocols, security policies, and public key cryptographic mechanisms working in a comprehensive manner to enable a wide range of dispersed people to communicate in a secure and predictable fashion.
This infrastructure is based upon which of the following Standard?
- A. X.25
- B. X.509
- C. X.500
- D. X.400
Answer: B
Explanation:
X.509 was initially issued on July 3, 1988 and was begun in association with the
X.500 standard.
It assumes a strict hierarchical system of certificate authorities (CAs) for issuing the certificates.
This contrasts with web of trust models, like PGP, where anyone (not just special CAs) may sign
and thus attest to the validity of others' key certificates.
PKI establishes a level of trust within an environment.
PKI is an ISO authentication framework that uses public key cryptography and the X.509 standard.
The framework was set up to enable authentication to happen across different networks and the
Internet.
Particular protocols and algorithms are not specified, which is why PKI is called a framework and
not a specific technology.
In cryptography, X.509 is an ITU-T standard for a public key infrastructure (PKI) and Privilege
Management Infrastructure (PMI). X.509 specifies, amongst other things, standard formats for
public key certificates, certificate revocation lists, attribute certificates, and a certification path
validation algorithm.
The standard for how the CA creates the certificate is X.509, which dictates the different fields
used in the certificate and the valid values that can populate those fields.
The most commonly used version is v3 of this standard, which is often denoted as X.509v3.
Many cryptographic protocols use this type of certificate, including SSL.
The certificate includes the serial number, version number, identity information, algorithm information, lifetime dates, and the signature of the issuing authority
The following answers are incorrect:
X.500 is a Directory Access Protocol(LDAP)
X.400 is for Electronic Messaging (EMAILs)
X.25 is Frame Relay
The following reference(s) were/was used to create this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 833). McGraw-Hill .
Kindle Edition.
NEW QUESTION 65
In the area of disaster planning and recovery, what strategy entails the presentation of information about the plan?
- A. Communication
- B. Escalation
- C. Planning
- D. Recovery
Answer: A
NEW QUESTION 66
Why would a database be denormalized?
- A. To save storage space
- B. To ensure data integrity
- C. To prevent duplication of data
- D. To increase processing efficiency
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The purpose of denormalization is to improve the read performance and processing efficiency of a database by adding redundant data or by grouping data.
Incorrect Answers:
A: The duplication of data creates a problem for data integrity as the data needs to be updated in numerous places. Normalization, which eliminates the duplication of data, improves data integrity.
C: The purpose of normalization is to eliminate duplication of the data. All duplicated data items should be deleted and replaced by a pointer. Denormalization could reverse this process. It attempts to improve the read performance and processing efficiency of a database by adding redundant data or by grouping data.
D: The purpose of denormalization is to improve the read performance and processing efficiency of a database by adding redundant data or by grouping data. This increases storage space consumption.
References:
https://en.wikipedia.org/wiki/Denormalization
https://en.wikipedia.org/wiki/Database_normalization
Miller, David R., CISSP Training Kit, O'Reilly Media, Sebastopol, 2013, pp. 620, 622
NEW QUESTION 67
An Intrusion Detection System (IDS) has recently been deployed in a Demilitarized Zone (DMZ). The IDS detects a flood of malformed packets. Which of the following BEST describes what has occurred?
- A. Denial of Service (DoS) attack
- B. Buffer overflow
- C. Ping flood attack
- D. Address Resolution Protocol (ARP) spoof
Answer: A
Explanation:
Section: Software Development Security
NEW QUESTION 68
Enforcing minimum privileges for general system users can be easily achieved through the use of:
- A. RBAC
- B. TBAC
- C. TSTEC
- D. IPSEC
Answer: A
Explanation:
Ensuring least privilege requires identifying what the user's job is, determining the minimum set of privileges required to perform that job, and restricting the user to a domain with those privileges and nothing more. By denying to subjects transactions that are not necessary for the performance of their duties, those denied privileges couldn't be used to circumvent the organizational security policy. Although the concept of least privilege currently exists within the context of the TCSEC, requirements restrict those privileges of the system administrator. Through the use of RBAC, enforced minimum privileges for general system users can be easily achieved.
NEW QUESTION 69
There are some correlations between relational data base terminology
and object-oriented database terminology. Which of the following
relational model terms, respectively, correspond to the object model
terms of class, attribute and instance object?
- A. Domain, relation, and column
- B. Relation, column, and tuple
- C. Relation, tuple, and column
- D. Relation, domain, and column
Answer: B
Explanation:
Table shows the correspondence between the two models.
In comparing the two models, a class is similar to a relation; however, a relation does not have the inheritance property of a class. An attribute in the object model is similar to the column of a relational table. The column has limitations on the data types it can hold while
an attribute in the object model can use all data types that are supported by the Java and C++ languages. An instance object in the object model corresponds to a tuple in the relational model. Again
image011
the data structures of the tuple are limited while those of the instance object can use data structures of Java and C++.
NEW QUESTION 70
The goals of integrity do NOT include:
- A. Preservation of internal and external consistency
- B. Prevention of the unauthorized or unintentional modification of information by authorized users
- C. Accountability of responsible individuals
- D. Prevention of the modification of information by unauthorized users
Answer: C
Explanation:
The correct answer is "Accountability of responsible individuals". Accountability is holding individuals responsible for their actions. The other options are the three goals of integrity.
NEW QUESTION 71
In the network design below, where is the MOST secure Local Area Network (LAN) segment to deploy a Wireless Access Point (WAP) that provides contractors access to the Internet and authorized enterprise services?
Answer:
Explanation:
Explanation
LAN 4
NEW QUESTION 72
......
Study Tips
Below are some helpful study tips you can refer to while preparing for the CISSP test:
- Look at the security management prep exam questions to see what valuable knowledge you can collect.
- Attend online programs focused on the CISSP and best practices in security to increase your confidence in facing the real exam.
- Seek guidance from security practitioners who have already earned certification for their CISSP skills.
- Take advantage of the most up-to-date security materials and online webinars focused on security operations and software development security.
- Get an in-depth & real-life experience that your job and your certification can apply to.
ISC CISSP Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
CISSP Braindumps Real Exam Updated on Dec 28, 2021 with 990 Questions: https://www.pass4training.com/CISSP-pass-exam-training.html
Latest CISSP PDF Dumps & Real Tests Free Updated Today: https://drive.google.com/open?id=14yTtNfQGQgv52xiqO2QrV83LJ8or62eD

