Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials CISSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam


733 Students Passed

87% Average Score

91% Same Questions
Viewing page 10 out of 14 pages
Viewing questions 136-150 out of questions
Questions # 136:

Which of the following prevents improper aggregation of privileges in Role Based Access Control (RBAC)?

Options:

A.

Hierarchical inheritance

B.

Dynamic separation of duties

C.

The Clark-Wilson security model

D.

The Bell-LaPadula security model

Questions # 137:

A vulnerability in which of the following components would be MOST difficult to detect?

Options:

A.

Kernel

B.

Shared libraries

C.

Hardware

D.

System application

Questions # 138:

The PRIMARY characteristic of a Distributed Denial of Service (DDoS) attack is that it

Options:

A.

exploits weak authentication to penetrate networks.

B.

can be detected with signature analysis.

C.

looks like normal network activity.

D.

is commonly confused with viruses or worms.

Questions # 139:

Which of the following is the BIGGEST weakness when using native Lightweight Directory Access Protocol (LDAP) for authentication?

Options:

A.

Authorizations are not included in the server response

B.

Unsalted hashes are passed over the network

C.

The authentication session can be replayed

D.

Passwords are passed in clear text

Questions # 140:

How does a Host Based Intrusion Detection System (HIDS) identify a potential attack?

Options:

A.

Examines log messages or other indications on the system.

B.

Monitors alarms sent to the system administrator

C.

Matches traffic patterns to virus signature files

D.

Examines the Access Control List (ACL)

Questions # 141:

Which organizational department is ultimately responsible for information governance related to e-mail and other e-records?

Options:

A.

Audit

B.

Compliance

C.

Legal

D.

Security

Questions # 142:

A recent security audit is reporting several unsuccessful login attempts being repeated at specific times during the day on an Internet facing authentication server. No alerts have been generated by the security information and event management (SIEM) system. What PRIMARY action should be taken to improve SIEM performance?

Options:

A.

Implement role-based system monitoring

B.

Audit firewall logs to identify the source of login attempts

C.

Enhance logging detail

D.

Confirm alarm thresholds

Questions # 143:

Which of the following is the MOST comprehensive Business Continuity (BC) test?

Options:

A.

Full functional drill

B.

Full table top

C.

Full simulation

D.

Full interruption

Questions # 144:

Which of the following activities should a forensic examiner perform FIRST when determining the priority of digital evidence collection at a crime scene?

Options:

A.

Gather physical evidence,

B.

Establish order of volatility.

C.

Assign responsibilities to personnel on the scene.

D.

Establish a list of files to examine.

Questions # 145:

What is considered the BEST explanation when determining whether to provide remote network access to a third-party security service?

Options:

A.

Contract negotiation

B.

Vendor demonstration

C.

Supplier request

D.

Business need

Questions # 146:

Which of the following access control models is MOST restrictive?

Options:

A.

Discretionary Access Control (DAC)

B.

Mandatory Access Control (MAC)

C.

Role Based Access Control (RBAC)

D.

Rule based access control

Questions # 147:

Which of the fallowing statements is MOST accurate regarding information assets?

Options:

A.

International Organization for Standardization (ISO) 27001 compliance specifies which information assets must be included in asset inventory.

B.

S3 Information assets include any information that is valuable to the organization,

C.

Building an information assets register is a resource-intensive job.

D.

Information assets inventory is not required for risk assessment.

Questions # 148:

An organization has implemented a password complexity and an account lockout policy enforcing five incorrect logins tries within ten minutes. Network users have reported significantly increased account lockouts. Which of the following security principles is this company affecting?

Options:

A.

Availability

B.

Integrity

C.

Confidentiality

D.

Authentication

Questions # 149:

The security organization is looking for a solution that could help them determine with a strong level of confidence that attackers have breached their network. Which solution is MOST effective at discovering a successful network breach?

Options:

A.

Deploying a honeypot

B.

Developing a sandbox

C.

Installing an intrusion prevention system (IPS)

D.

Installing an intrusion detection system (IDS)

Questions # 150:

Which of the following is included in change management?

Options:

A.

Business continuity testing

B.

User Acceptance Testing (UAT) before implementation

C.

Technical review by business owner

D.

Cost-benefit analysis (CBA) after implementation

Viewing page 10 out of 14 pages
Viewing questions 136-150 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.