Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials CISSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam


733 Students Passed

87% Average Score

91% Same Questions
Viewing page 9 out of 14 pages
Viewing questions 121-135 out of questions
Questions # 121:

Which of the following is a remote access protocol that uses a static authentication?

Options:

A.

Point-to-Point Tunneling Protocol (PPTP)

B.

Routing Information Protocol (RIP)

C.

Password Authentication Protocol (PAP)

D.

Challenge Handshake Authentication Protocol (CHAP)

Questions # 122:

A health care provider is considering Internet access for their employees and patients. Which of the following is the organization's MOST secure solution for protection of data?

Options:

A.

Public Key Infrastructure (PKI) and digital signatures

B.

Trusted server certificates and passphrases

C.

User ID and password

D.

Asymmetric encryption and User ID

Questions # 123:

An organization regularly conducts its own penetration tests. Which of the following scenarios MUST be covered for the test to be effective?

Options:

A.

Third-party vendor with access to the system

B.

System administrator access compromised

C.

Internal attacker with access to the system

D.

Internal user accidentally accessing data

Questions # 124:

Which of the following is a characteristic of the initialization vector when using Data Encryption Standard (DES)?

Options:

A.

It must be known to both sender and receiver.

B.

It can be transmitted in the clear as a random number.

C.

It must be retained until the last block is transmitted.

D.

It can be used to encrypt and decrypt information.

Questions # 125:

Which of the following is the PRIMARY concern when using an Internet browser to access a cloud-based service?

Options:

A.

Insecure implementation of Application Programming Interfaces (API)

B.

Improper use and storage of management keys

C.

Misconfiguration of infrastructure allowing for unauthorized access

D.

Vulnerabilities within protocols that can expose confidential data

Questions # 126:

The restoration priorities of a Disaster Recovery Plan (DRP) are based on which of the following documents?

Options:

A.

Service Level Agreement (SLA)

B.

Business Continuity Plan (BCP)

C.

Business Impact Analysis (BIA)

D.

Crisis management plan

Questions # 127:

How does an organization verify that an information system's current hardware and software match the standard system configuration?

Options:

A.

By reviewing the configuration after the system goes into production

B.

By running vulnerability scanning tools on all devices in the environment

C.

By comparing the actual configuration of the system against the baseline

D.

By verifying all the approved security patches are implemented

Questions # 128:

Which of the following disaster recovery test plans will be MOST effective while providing minimal risk?

Options:

A.

Read-through

B.

Parallel

C.

Full interruption

D.

Simulation

Questions # 129:

Which of the following BEST describes the purpose of performing security certification?

Options:

A.

To identify system threats, vulnerabilities, and acceptable level of risk

B.

To formalize the confirmation of compliance to security policies and standards

C.

To formalize the confirmation of completed risk mitigation and risk analysis

D.

To verify that system architecture and interconnections with other systems are effectively implemented

Questions # 130:

Which of the following provides the minimum set of privileges required to perform a job function and restricts the user to a domain with the required privileges?

Options:

A.

Access based on rules

B.

Access based on user's role

C.

Access determined by the system

D.

Access based on data sensitivity

Questions # 131:

By carefully aligning the pins in the lock, which of the following defines the opening of a mechanical lock without the proper key?

Options:

A.

Lock pinging

B.

Lock picking

C.

Lock bumping

D.

Lock bricking

Questions # 132:

Single Sign-On (SSO) is PRIMARILY designed to address which of the following?

Options:

A.

Confidentiality and Integrity

B.

Availability and Accountability

C.

Integrity and Availability

D.

Accountability and Assurance

Questions # 133:

Which of the following sets of controls should allow an investigation if an attack is not blocked by preventive controls or detected by monitoring?

Options:

A.

Logging and audit trail controls to enable forensic analysis

B.

Security incident response lessons learned procedures

C.

Security event alert triage done by analysts using a Security Information and Event Management (SIEM) system

D.

Transactional controls focused on fraud prevention

Questions # 134:

While inventorying storage equipment, it is found that there are unlabeled, disconnected, and powered off devices. Which of the following is the correct procedure for handling such equipment?

Options:

A.

They should be recycled to save energy.

B.

They should be recycled according to NIST SP 800-88.

C.

They should be inspected and sanitized following the organizational policy.

D.

They should be inspected and categorized properly to sell them for reuse.

Questions # 135:

Which of the following entities is ultimately accountable for data remanence vulnerabilities with data replicated by a cloud service provider?

Options:

A.

Data owner

B.

Data steward

C.

Data custodian

D.

Data processor

Viewing page 9 out of 14 pages
Viewing questions 121-135 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.