Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials CISSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam


733 Students Passed

87% Average Score

91% Same Questions
Viewing page 11 out of 14 pages
Viewing questions 151-165 out of questions
Questions # 151:

Which of the following in the BEST way to reduce the impact of an externally sourced flood attack?

Options:

A.

Stock the source address at the firewall.

B.

Have this service provide block the source address.

C.

Block all inbound traffic until the flood ends.

D.

Have the source service provider block the address

Questions # 152:

A criminal organization is planning an attack on a government network. Which of the following is the MOST severe attack to the network availability?

Options:

A.

Network management communications is disrupted by attacker

B.

Operator loses control of network devices to attacker

C.

Sensitive information is gathered on the network topology by attacker

D.

Network is flooded with communication traffic by attacker

Questions # 153:

While performing a security review for a new product, an information security professional discovers that the organization's product development team is proposing to collect government-issued identification (ID) numbers from customers to use as unique customer identifiers. Which of the following recommendations should be made to the product development team?

Options:

A.

Customer identifiers should be a variant of the user’s government-issued ID number.

B.

Customer identifiers that do not resemble the user’s government-issued ID number should be used.

C.

Customer identifiers should be a cryptographic hash of the user's government-issued ID number.

D.

Customer identifiers should be a variant of the user’s name, for example, “jdoe” or “john.doe.”

Questions # 154:

Which of the following authorization standards is built to handle Application Programming Interface (API) access for Federated Identity Management (FIM)?

Options:

A.

Security Assertion Markup Language (SAML)

B.

Open Authentication (OAUTH)

C.

Remote Authentication Dial-in User service (RADIUS)

D.

Terminal Access Control Access Control System Plus (TACACS+)

Questions # 155:

Clothing retailer employees are provisioned with user accounts that provide access to resources at partner businesses. All partner businesses use common identity and access management (IAM) protocols and differing technologies. Under the Extended Identity principle, what is the process flow between partner businesses to allow this TAM action?

Options:

A.

Clothing retailer acts as identity provider (IdP), confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service

Provider and allows access to services.

B.

Clothing retailer acts as User Self Service, confirms identity of user using industry standards, then sends credentials to partner businesses that act as a Service

Provider and allows access to services.

C.

Clothing retailer acts as Service Provider, confirms identity of user using industry standards, then sends credentials to partner businesses that act as an identity

provider (IdP) and allows access to resources.

D.

Clothing retailer acts as Access Control Provider, confirms access of user using industry standards, then sends credentials to partner businesses that act as a Service

Provider and allows access to resources.

Questions # 156:

What is the PRIMARY objective of the post-incident phase of the incident response process in the security operations center (SOC)?

Options:

A.

improve the IR process.

B.

Communicate the IR details to the stakeholders.

C.

Validate the integrity of the IR.

D.

Finalize the IR.

Questions # 157:

What is the best way for mutual authentication of devices belonging to the same organization?

Options:

A.

Token

B.

Certificates

C.

User ID and passwords

D.

Biometric

Questions # 158:

What is the MOST important factor in establishing an effective Information Security Awareness Program?

Options:

A.

Obtain management buy-in.

B.

Conduct an annual security awareness event.

C.

Mandate security training.

D.

Hang information security posters on the walls,

Questions # 159:

What action should be taken by a business line that is unwilling to accept the residual risk in a system after implementing compensating controls?

Options:

A.

Notify the audit committee of the situation.

B.

Purchase insurance to cover the residual risk.

C.

Implement operational safeguards.

D.

Find another business line willing to accept the residual risk.

Questions # 160:

Which of the following is the GREATEST risk of relying only on Capability Maturity Models (CMM) for software to guide process improvement and assess capabilities of acquired software?

Options:

A.

Organizations can only reach a maturity level 3 when using CMMs

B.

CMMs do not explicitly address safety and security

C.

CMMs can only be used for software developed in-house

D.

CMMs are vendor specific and may be biased

Questions # 161:

An organization operates a legacy Industrial Control System (ICS) to support its core business service, which carrot be replaced. Its management MUST be performed remotely through an administrative console software, which in tum depends on an old version of the Java Runtime Environment (JPE) known to be vulnerable to a number of attacks, How is this risk BEST managed?

Options:

A.

Isolate the full ICS by moving It onto its own network segment

B.

Air-gap and harden the host used for management purposes

C.

Convince the management to decommission the ICS and mitigate to a modem technology

D.

Deploy a restrictive proxy between all clients and the vulnerable management station

Questions # 162:

Assume that a computer was powered off when an information security professional

arrived at a crime scene. Which of the following actions should be performed after

the crime scene is isolated?

Options:

A.

Turn the computer on and collect volatile data.

B.

Turn the computer on and collect network information.

C.

Leave the computer off and prepare the computer for transportation to the laboratory

D.

Remove the hard drive, prepare it for transportation, and leave the hardware ta the scene.

Questions # 163:

What technique used for spoofing the origin of an email can successfully conceal the sender s Internet Protocol (IP) address?

Options:

A.

Change In-Reply-To data

B.

Web crawling

C.

Onion routing

D.

Virtual Private Network (VPN)

Questions # 164:

An organization is considering outsourcing applications and data to a Cloud Service

Provider (CSP). Which of the following is the MOST important concern regarding

privacy?

Options:

A.

The CSP determines data criticality.

B.

The CSP provides end-to-end encryption services.

C.

The CSP’s privacy policy may be developer by the organization.

D.

The CSP may not be subject to the organization’s country legation.

Questions # 165:

What is the BEST way to restrict access to a file system on computing systems?

Options:

A.

Allow a user group to restrict access.

B.

Use a third-party tool to restrict access.

C.

Use least privilege at each level to restrict access.

D.

Restrict access to all users.

Viewing page 11 out of 14 pages
Viewing questions 151-165 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.