Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials CISSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam


733 Students Passed

87% Average Score

91% Same Questions
Viewing page 3 out of 14 pages
Viewing questions 31-45 out of questions
Questions # 31:

Which of the following is the BEST way to verify the integrity of a software patch?

Options:

A.

Cryptographic checksums

B.

Version numbering

C.

Automatic updates

D.

Vendor assurance

Questions # 32:

What maintenance activity is responsible for defining, implementing, and testing updates to application systems?

Options:

A.

Program change control

B.

Regression testing

C.

Export exception control

D.

User acceptance testing

Questions # 33:

An engineer in a software company has created a virus creation tool. The tool can generate thousands of polymorphic viruses. The engineer is planning to use the tool in a controlled environment to test the company's next generation virus scanning software. Which would BEST describe the behavior of the engineer and why?

Options:

A.

The behavior is ethical because the tool will be used to create a better virus scanner.

B.

The behavior is ethical because any experienced programmer could create such a tool.

C.

The behavior is not ethical because creating any kind of virus is bad.

D.

The behavior is not ethical because such a tool could be leaked on the Internet.

Questions # 34:

Two companies wish to share electronic inventory and purchase orders in a supplier and client relationship. What is the BEST security solution for them?

Options:

A.

Write a Service Level Agreement (SLA) for the two companies.

B.

Set up a Virtual Private Network (VPN) between the two companies.

C.

Configure a firewall at the perimeter of each of the two companies.

D.

Establish a File Transfer Protocol (FTP) connection between the two companies.

Questions # 35:

In a basic SYN flood attack, what is the attacker attempting to achieve?

Options:

A.

Exceed the threshold limit of the connection queue for a given service

B.

Set the threshold to zero for a given service

C.

Cause the buffer to overflow, allowing root access

D.

Flush the register stack, allowing hijacking of the root account

Questions # 36:

A business has implemented Payment Card Industry Data Security Standard (PCI-DSS) compliant handheld credit card processing on their Wireless Local Area Network (WLAN) topology. The network team partitioned the WLAN to create a private segment for credit card processing using a firewall to control device access and route traffic to the card processor on the Internet. What components are in the scope of PCI-DSS?

Options:

A.

The entire enterprise network infrastructure.

B.

The handheld devices, wireless access points and border gateway.

C.

The end devices, wireless access points, WLAN, switches, management console, and firewall.

D.

The end devices, wireless access points, WLAN, switches, management console, and Internet

Questions # 37:

Which of the following is the BEST way to determine if a particular system is able to identify malicious software without executing it?

Options:

A.

Testing with a Botnet

B.

Testing with an EICAR file

C.

Executing a binary shellcode

D.

Run multiple antivirus programs

Questions # 38:

What is a common challenge when implementing Security Assertion Markup Language (SAML) for identity integration between on-premise environment and an external identity provider service?

Options:

A.

Some users are not provisioned into the service.

B.

SAML tokens are provided by the on-premise identity provider.

C.

Single users cannot be revoked from the service.

D.

SAML tokens contain user information.

Questions # 39:

A large university needs to enable student access to university resources from their homes. Which of the following provides the BEST option for low maintenance and ease of deployment?

Options:

A.

Provide students with Internet Protocol Security (IPSec) Virtual Private Network (VPN) client software.

B.

Use Secure Sockets Layer (SSL) VPN technology.

C.

Use Secure Shell (SSH) with public/private keys.

D.

Require students to purchase home router capable of VPN.

Questions # 40:

What is the PRIMARY advantage of using automated application security testing tools?

Options:

A.

The application can be protected in the production environment.

B.

Large amounts of code can be tested using fewer resources.

C.

The application will fail less when tested using these tools.

D.

Detailed testing of code functions can be performed.

Questions # 41:

Which of the following actions MUST be taken if a vulnerability is discovered during the maintenance stage in a System Development Life Cycle (SDLC)?

Options:

A.

Make changes following principle and design guidelines.

B.

Stop the application until the vulnerability is fixed.

C.

Report the vulnerability to product owner.

D.

Monitor the application and review code.

Questions # 42:

Which of the following BEST describes Recovery Time Objective (RTO)?

Options:

A.

Time of data validation after disaster

B.

Time of data restoration from backup after disaster

C.

Time of application resumption after disaster

D.

Time of application verification after disaster

Questions # 43:

Which of the following is a detective access control mechanism?

Options:

A.

Log review

B.

Least privilege

C.

Password complexity

D.

Non-disclosure agreement

Questions # 44:

When using third-party software developers, which of the following is the MOST effective method of providing software development Quality Assurance (QA)?

Options:

A.

Retain intellectual property rights through contractual wording.

B.

Perform overlapping code reviews by both parties.

C.

Verify that the contractors attend development planning meetings.

D.

Create a separate contractor development environment.

Questions # 45:

What is the BEST first step for determining if the appropriate security controls are in place for protecting data at rest?

Options:

A.

Identify regulatory requirements

B.

Conduct a risk assessment

C.

Determine business drivers

D.

Review the security baseline configuration

Viewing page 3 out of 14 pages
Viewing questions 31-45 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.