Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials CISSP Questions and answers with ValidTests

Exam CISSP All Questions
Exam CISSP Premium Access

View all detail and faqs for the CISSP exam

Viewing page 3 out of 12 pages
Viewing questions 31-45 out of questions
Questions # 31:

The MAIN purpose of placing a tamper seal on a computer system's case is to:

Options:

A.

raise security awareness.

B.

detect efforts to open the case.

C.

expedite physical auditing.

D.

make it difficult to steal internal components.

Expert Solution
Questions # 32:

Which of the following terms BEST describes a system which allows a user to log in and access multiple related servers and applications?

Options:

A.

Remote Desktop Protocol (RDP)

B.

Federated identity management (FIM)

C.

Single sign-on (SSO)

D.

Multi-factor authentication (MFA)

Expert Solution
Questions # 33:

International bodies established a regulatory scheme that defines how weapons are exchanged between the signatories. It also addresses cyber weapons, including malicious software, Command and Control (C2) software, and internet surveillance software. This is a description of which of the following?

Options:

A.

General Data Protection Regulation (GDPR)

B.

Palermo convention

C.

Wassenaar arrangement

D.

International Traffic in Arms Regulations (ITAR)

Expert Solution
Questions # 34:

A manager identified two conflicting sensitive user functions that were assigned to a single user account that had the potential to result in financial and regulatory risk to the company. The manager MOST likely discovered this during which of the following?

Options:

A.

Security control assessment.

B.

Separation of duties analysis

C.

Network Access Control (NAC) review

D.

Federated identity management (FIM) evaluation

Expert Solution
Questions # 35:

When developing the entitlement review process, which of the following roles is responsible for determining who has a need for the information?

Options:

A.

Data Custodian

B.

Data Owner

C.

Database Administrator

D.

Information Technology (IT) Director

Expert Solution
Questions # 36:

Which of the following would be considered an incident if reported by a security information and event management (SIEM) system?

Options:

A.

An administrator is logging in on a server through a virtual private network (VPN).

B.

A log source has stopped sending data.

C.

A web resource has reported a 404 error.

D.

A firewall logs a connection between a client on the Internet and a web server using Transmission Control Protocol (TCP) on port 80.

Expert Solution
Questions # 37:

To minimize the vulnerabilities of a web-based application, which of the following FIRST actions will lock down the system and minimize the risk of an attack?

Options:

A.

Install an antivirus on the server

B.

Run a vulnerability scanner

C.

Review access controls

D.

Apply the latest vendor patches and updates

Expert Solution
Questions # 38:

Which section of the assessment report addresses separate vulnerabilities, weaknesses, and gaps?

Options:

A.

Key findings section

B.

Executive summary with full details

C.

Risk review section

D.

Findings definition section

Expert Solution
Questions # 39:

Which of the following technologies can be used to monitor and dynamically respond to potential threats on web applications?

Options:

A.

Security Assertion Markup Language (SAML)

B.

Web application vulnerability scanners

C.

Runtime application self-protection (RASP)

D.

Field-level tokenization

Expert Solution
Questions # 40:

Directive controls are a form of change management policy and procedures. Which of the following subsections are recommended as part of the change management process?

Options:

A.

Build and test

B.

Implement security controls

C.

Categorize Information System (IS)

D.

Select security controls

Expert Solution
Questions # 41:

Which of the following is the PRIMARY issue when analyzing detailed log information?

Options:

A.

Logs may be unavailable when required

B.

Timely review of the data is potentially difficult

C.

Most systems and applications do not support logging

D.

Logs do not provide sufficient details of system and individual activities

Expert Solution
Questions # 42:

A disadvantage of an application filtering firewall is that it can lead to

Options:

A.

a crash of the network as a result of user activities.

B.

performance degradation due to the rules applied.

C.

loss of packets on the network due to insufficient bandwidth.

D.

Internet Protocol (IP) spoofing by hackers.

Expert Solution
Questions # 43:

Which one of the following is a fundamental objective in handling an incident?

Options:

A.

To restore control of the affected systems

B.

To confiscate the suspect's computers

C.

To prosecute the attacker

D.

To perform full backups of the system

Expert Solution
Questions # 44:

The key benefits of a signed and encrypted e-mail include

Options:

A.

confidentiality, authentication, and authorization.

B.

confidentiality, non-repudiation, and authentication.

C.

non-repudiation, authorization, and authentication.

D.

non-repudiation, confidentiality, and authorization.

Expert Solution
Questions # 45:

Which one of the following is the MOST important in designing a biometric access system if it is essential that no one other than authorized individuals are admitted?

Options:

A.

False Acceptance Rate (FAR)

B.

False Rejection Rate (FRR)

C.

Crossover Error Rate (CER)

D.

Rejection Error Rate

Expert Solution
Viewing page 3 out of 12 pages
Viewing questions 31-45 out of questions