Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC Other Certification CSSLP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CSSLP Premium Access

View all detail and faqs for the CSSLP exam


809 Students Passed

90% Average Score

90% Same Questions
Viewing page 5 out of 11 pages
Viewing questions 41-50 out of questions
Questions # 41:

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

What is being secured?

B.

Where is the vulnerability, threat, or risk?

C.

Who is expected to exploit the vulnerability?

D.

Who is expected to comply with the policy?

Questions # 42:

Della work as a project manager for BlueWell Inc. A threat with a dollar value of $250,000 is expected to happen in her project and the frequency of threat occurrence per year is 0.01. What will be the annualized loss expectancy in her project?

Options:

A.

$2,000

B.

$2,500

C.

$3,510

D.

$3,500

Questions # 43:

The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the system has been accredited in Phase 3. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Security operations

B.

Maintenance of the SSAA

C.

Compliance validation

D.

Change management

E.

System operations

F.

Continue to review and refine the SSAA

Questions # 44:

You work as a systems engineer for BlueWell Inc. Which of the following tools will you use to look outside your own organization to examine how others achieve their performance levels, and what processes they use to reach those levels?

Options:

A.

Benchmarking

B.

Six Sigma

C.

ISO 9001:2000

D.

SEI-CMM

Questions # 45:

Joseph works as a Software Developer for WebTech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the following laws are used to protect a part of software?

Options:

A.

Code Security law

B.

Patent laws

C.

Trademark laws

D.

Copyright laws

Questions # 46:

Which of the following statements about the availability concept of Information security management is true?

Options:

A.

It ensures that modifications are not made to data by unauthorized personnel or processes.

B.

It determines actions and behaviors of a single individual within a system.

C.

It ensures reliable and timely access to resources.

D.

It ensures that unauthorized modifications are not made to data by authorized personnel or processes.

Questions # 47:

Which of the following DITSCAP C&A phases takes place between the signing of the initial version of the SSAA and the formal accreditation of the system?

Options:

A.

Phase 4

B.

Phase 3

C.

Phase 1

D.

Phase 2

Questions # 48:

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.

Options:

A.

Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.

B.

Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.

C.

Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.

D.

Certification is the official management decision given by a senior agency official to authorize operation of an information system.

Questions # 49:

Which of the following are the types of access controls? Each correct answer represents a complete solution. Choose three.

Options:

A.

Physical

B.

Technical

C.

Administrative

D.

Automatic

Questions # 50:

Which of the following NIST Special Publication documents provides a guideline on network security testing?

Options:

A.

NIST SP 800-42

B.

NIST SP 800-53A

C.

NIST SP 800-60

D.

NIST SP 800-53

E.

NIST SP 800-37

F.

NIST SP 800-59

Viewing page 5 out of 11 pages
Viewing questions 41-50 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.