Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC Other Certification CSSLP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CSSLP Premium Access

View all detail and faqs for the CSSLP exam


809 Students Passed

90% Average Score

90% Same Questions
Viewing page 6 out of 11 pages
Viewing questions 51-60 out of questions
Questions # 51:

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

Certification agent

B.

Designated Approving Authority

C.

IS program manager

D.

Information Assurance Manager

E.

User representative

Questions # 52:

The NIST Information Security and Privacy Advisory Board (ISPAB) paper "Perspectives on Cloud Computing and Standards" specifies potential advantages and disdvantages of virtualization. Which of the following disadvantages does it include? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It increases capabilities for fault tolerant computing using rollback and snapshot features.

B.

It increases intrusion detection through introspection.

C.

It initiates the risk that malicious software is targeting the VM environment.

D.

It increases overall security risk shared resources.

E.

It creates the possibility that remote attestation may not work.

F.

It involves new protection mechanisms for preventing VM escape, VM detection, and VM-VM interference.

G.

It increases configuration effort because of complexity and composite system.

Questions # 53:

You are the project manager of the NNN project for your company. You and the project team are working together to plan the risk responses for the project. You feel that the team has successfully completed the risk response planning and now you must initiate what risk process it is. Which of the following risk processes is repeated after the plan risk responses to determine if the overall project risk has been satisfactorily decreased?

Options:

A.

Quantitative risk analysis

B.

Risk identification

C.

Risk response implementation

D.

Qualitative risk analysis

Questions # 54:

Which of the following attacks causes software to fail and prevents the intended users from accessing software?

Options:

A.

Enabling attack

B.

Reconnaissance attack

C.

Sabotage attack

D.

Disclosure attack

Questions # 55:

To help review or design security controls, they can be classified by several criteria . One of these criteria is based on their nature. According to this criterion, which of the following controls consists of incident response processes, management oversight, security awareness, and training?

Options:

A.

Compliance control

B.

Physical control

C.

Procedural control

D.

Technical control

Questions # 56:

Which of the following types of redundancy prevents attacks in which an attacker can get physical control of a machine, insert unauthorized software, and alter data?

Options:

A.

Data redundancy

B.

Hardware redundancy

C.

Process redundancy

D.

Application redundancy

Questions # 57:

The IAM/CA makes certification accreditation recommendations to the DAA. The DAA issues accreditation determinations. Which of the following are the accreditation determinations issued by the DAA? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

IATT

B.

IATO

C.

DATO

D.

ATO

E.

ATT

Questions # 58:

You are the project manager for GHY Project and are working to create a risk response for a negative risk. You and the project team have identified the risk that the project may not complete on time, as required by the management, due to the creation of the user guide for the software you're creating. You have elected to hire an external writer in order to satisfy the requirements and to alleviate the risk event. What type of risk response have you elected to use in this instance?

Options:

A.

Transference

B.

Exploiting

C.

Avoidance

D.

Sharing

Questions # 59:

FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets, or individuals?

Options:

A.

Moderate

B.

Low

C.

Medium

D.

High

Questions # 60:

Which of the following methods offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling?

Options:

A.

Service-oriented modeling framework (SOMF)

B.

Service-oriented architecture (SOA)

C.

Sherwood Applied Business Security Architecture (SABSA)

D.

Service-oriented modeling and architecture (SOMA)

Viewing page 6 out of 11 pages
Viewing questions 51-60 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.