Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Checkpoint Other Certification 156-110 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 156-110 Premium Access

View all detail and faqs for the 156-110 exam


847 Students Passed

95% Average Score

98% Same Questions
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following best describes an external intrusion attempt on a local-area network (LAN)?

Options:

A.

Internal users try to gain unauthorized access to information assets outside the organizational perimeter.

B.

External-intrusion attempts from sources outside the LAN are not granted permissions or rights to an organization's information assets.

C.

External users attempt to access public resources.

D.

External intruders attempt exploitation of vulnerabilities, to remove their own access.

E.

Internal users perform inappropriate acts on assets to which they have been given rights or permissions.

Questions # 12:

Which of these choices correctly describe denial-of-service (DoS) attacks? (Choose THREE.)

Options:

A.

DoS attacks do not require attackers to have any privileges on a target system.

B.

DoS attacks are nearly impossible to stop, once they begin.

C.

DoS attacks free the target system of excessive overhead.

D.

DoS ties up a system with so many requests, system resources are consumed, and performance degrades.

E.

DoS attacks cause the attacked system to accept legitimate access requests.

Questions # 13:

Why should each system user and administrator have individual accounts? (Choose TWO.)

Options:

A.

Using generic user names and passwords increases system security and reliability.

B.

Using separate accounts for each user reduces resource consumption, particularly disk space.

C.

By using individual login names and passwords, user actions can be traced.

D.

If users do not have individual login names, processes can automatically run with root/administrator access.

E.

A generic user name and password for users and security administrators provides anonymity, which prevents useful logging and auditing.

Questions # 14:

Why does the (ISC)2 access-control systems and methodology functional domain address both the confidentiality and integrity aspects of the Information Security Triad? Access-control systems and methodologies:

Options:

A.

are required standards in health care and banking.

B.

provide redundant systems and data backups.

C.

control who is allowed to view and modify information.

D.

are academic models not suitable for implementation.

E.

set standards for acceptable media-storage devices.

Questions # 15:

_______________________________ occurs when an individual or process acquires a higher level of privilege, or access, than originally intended.

Options:

A.

Security Triad

B.

Privilege aggregation

C.

Need-to-know

D.

Privilege escalation

E.

Least privilege

Questions # 16:

What is mandatory sign-on? An authentication method that:

Options:

A.

uses smart cards, hardware tokens, and biometrics to authenticate users; also known as three-factor authentication

B.

requires the use of one-time passwords, so users authenticate only once, with a given set of credentials

C.

requires users to re-authenticate at each server and access control

D.

stores user credentials locally, so that users need only authenticate the first time a local machine is used

E.

allows users to authenticate once, and then uses tokens or other credentials to manage subsequent authentication attempts

Questions # 17:

Which of the following entities review partner-extranet requirements?

Options:

A.

Information systems

B.

Shipping and receiving

C.

Marketing

D.

Requesting department

E.

Chief Information Officer

Questions # 18:

Which of the following is a cost-effective solution for securely transmitting data between remote offices?

Options:

A.

Standard e-mail

B.

Fax machine

C.

Virtual private network

D.

Bonded courier

E.

Telephone

Questions # 19:

Which of the following is NOT a concern for enterprise physical security?

Options:

A.

Network Intrusion Detection Systems

B.

Social engineering

C.

Dumpster diving

D.

Property theft

E.

Unauthorized access to a facility

Questions # 20:

_______ can mimic the symptoms of a denial-of-service attack, and the resulting loss in productivity can be no less devastating to an organization.

Options:

A.

ICMP traffic

B.

Peak traffic

C.

Fragmented packets

D.

Insufficient bandwidth

E.

Burst traffic

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.