Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials CISSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam


733 Students Passed

87% Average Score

91% Same Questions
Viewing page 12 out of 14 pages
Viewing questions 166-180 out of questions
Questions # 166:

Which of the following is a term used to describe maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions?

Options:

A.

Information Security Management System (ISMS)

B.

Information Sharing & Analysis Centers (ISAC)

C.

Risk Management Framework (RMF)

D.

Information Security Continuous Monitoring (ISCM)

Questions # 167:

All hosts on the network are sending logs via syslog-ng to the log collector. The log collector is behind its own firewall, The security professional wants to make sure not to put extra load on the firewall due to the amount of traffic that is passing through it. Which of the following types of filtering would MOST likely be used?

Options:

A.

Uniform Resource Locator (URL) Filtering

B.

Web Traffic Filtering

C.

Dynamic Packet Filtering

D.

Static Packet Filtering

Questions # 168:

The initial security categorization should be done early in the system life cycle and should be reviewed periodically. Why is it important for this to be done correctly?

Options:

A.

It determines the security requirements.

B.

It affects other steps in the certification and accreditation process.

C.

It determines the functional and operational requirements.

D.

The system engineering process works with selected security controls.

Questions # 169:

Which of the following is a PRIMARY challenge when running a penetration test?

Options:

A.

Determining the cost

B.

Establishing a business case

C.

Remediating found vulnerabilities

D.

Determining the depth of coverage

Questions # 170:

Who should formulate conclusions from a particular digital fore Ball, Submit a Toper Of Tags, and the results?

Options:

A.

The information security professional's supervisor

B.

Legal counsel for the information security professional's employer

C.

The information security professional who conducted the analysis

D.

A peer reviewer of the information security professional

Questions # 171:

A software architect has been asked to build a platform to distribute music to thousands of users on a global scale. The architect has been reading about content delivery networks (CDN). Which of the following is a principal task to undertake?

Options:

A.

Establish a service-oriented architecture (SOA).

B.

Establish a media caching methodology.

C.

Establish relationships with hundreds of Internet service providers (ISP).

D.

Establish a low-latency wide area network (WAN).

Questions # 172:

The security architect is designing and implementing an internal certification authority to generate digital certificates for all employees. Which of the following is the BEST solution to securely store the private keys?

Options:

A.

Physically secured storage device

B.

Encrypted flash drive

C.

Public key infrastructure (PKI)

D.

Trusted Platform Module (TPM)

Questions # 173:

Which of the following controls is the most for a system identified as critical in terms of data and function to the organization?

Options:

A.

Preventive controls

B.

Monitoring control

C.

Cost controls

D.

Compensating controls

Questions # 174:

Which evidence collecting technique would be utilized when it is believed an attacker is employing a rootkit and a quick analysis is needed?

Options:

A.

Memory collection

B.

Forensic disk imaging

C.

Malware analysis

D.

Live response

Questions # 175:

Which of the following would an internal technical security audit BEST validate?

Options:

A.

Whether managerial controls are in place

B.

Support for security programs by executive management

C.

Appropriate third-party system hardening

D.

Implementation of changes to a system

Questions # 176:

Which of the following factors contributes to the weakness of Wired Equivalent Privacy (WEP) protocol?

Options:

A.

WEP uses a small range Initialization Vector (IV)

B.

WEP uses Message Digest 5 (MD5)

C.

WEP uses Diffie-Hellman

D.

WEP does not use any Initialization Vector (IV)

Questions # 177:

In a Transmission Control Protocol/Internet Protocol (TCP/IP) stack, which layer is responsible for negotiating and establishing a connection with another node?

Options:

A.

Transport layer

B.

Application layer

C.

Network layer

D.

Session layer

Questions # 178:

Which of the following operates at the Network Layer of the Open System Interconnection (OSI) model?

Options:

A.

Packet filtering

B.

Port services filtering

C.

Content filtering

D.

Application access control

Questions # 179:

An external attacker has compromised an organization’s network security perimeter and installed a sniffer onto an inside computer. Which of the following is the MOST effective layer of security the organization could have implemented to mitigate the attacker’s ability to gain further information?

Options:

A.

Implement packet filtering on the network firewalls

B.

Install Host Based Intrusion Detection Systems (HIDS)

C.

Require strong authentication for administrators

D.

Implement logical network segmentation at the switches

Questions # 180:

What is the purpose of an Internet Protocol (IP) spoofing attack?

Options:

A.

To send excessive amounts of data to a process, making it unpredictable

B.

To intercept network traffic without authorization

C.

To disguise the destination address from a target’s IP filtering devices

D.

To convince a system that it is communicating with a known entity

Viewing page 12 out of 14 pages
Viewing questions 166-180 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.