Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC Other Certification CSSLP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CSSLP Premium Access

View all detail and faqs for the CSSLP exam


809 Students Passed

90% Average Score

90% Same Questions
Viewing page 2 out of 11 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site?

Options:

A.

NSA-IAM

B.

NIACAP

C.

ASSET

D.

DITSCAP

Questions # 12:

NIST SP 800-53A defines three types of interview depending on the level of assessment conducted. Which of the following NIST SP 800-53A interviews consists of informal and ad hoc interviews?

Options:

A.

Comprehensive

B.

Significant

C.

Abbreviated

D.

Substantial

Questions # 13:

Which of the following scanning techniques helps to ensure that the standard software configuration is currently with the latest security patches and software, and helps to locate uncontrolled or unauthorized software?

Options:

A.

Port Scanning

B.

Discovery Scanning

C.

Server Scanning

D.

Workstation Scanning

Questions # 14:

In which of the following architecture styles does a device receive input from connectors and generate transformed outputs?

Options:

A.

N-tiered

B.

Heterogeneous

C.

Pipes and filters

D.

Layered

Questions # 15:

The Software Configuration Management (SCM) process defines the need to trace changes, and the ability to verify that the final delivered software has all of the planned enhancements that are supposed to be included in the release. What are the procedures that must be defined for each software project to ensure that a sound SCM process is implemented? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Configuration status accounting

B.

Configuration change control

C.

Configuration identification

D.

Configuration audits

E.

Configuration implementation

F.

Configuration deployment

Questions # 16:

What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in the DIACAP process? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Conduct validation activities.

B.

Execute and update IA implementation plan.

C.

Combine validation results in DIACAP scorecard.

D.

Conduct activities related to the disposition of the system data and objects.

Questions # 17:

Fill in the blank with the appropriate security mechanism. is a computer hardware mechanism or programming language construct which handles the occurrence of exceptional events.

Options:

A.

Exception handling

Questions # 18:

You are the project manager for your organization. You are preparing for the quantitative risk analysis. Mark, a project team member, wants to know why you need to do quantitative risk analysis when you just completed qualitative risk analysis. Which one of the following statements best defines what quantitative risk analysis is?

Options:

A.

Quantitative risk analysis is the process of prioritizing risks for further analysis or action by assessing and combining their probability of occurrence and impact.

B.

Quantitative risk analysis is the review of the risk events with the high probability and the highest impact on the project objectives.

C.

Quantitative risk analysis is the planning and quantification of risk responses based on probability and impact of each risk event.

D.

Quantitative risk analysis is the process of numerically analyzing the effect of identified risks on overall project objectives.

Questions # 19:

Which of the following security models characterizes the rights of each subject with respect to every object in the computer system?

Options:

A.

Clark-Wilson model

B.

Bell-LaPadula model

C.

Biba model

D.

Access matrix

Questions # 20:

An attacker exploits actual code of an application and uses a security hole to carry out an attack before the application vendor knows about the vulnerability. Which of the following types of attack is this?

Options:

A.

Replay

B.

Zero-day

C.

Man-in-the-middle

D.

Denial-of-Service

Viewing page 2 out of 11 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.