[Aug 04, 2023] Free ISC Certification CISSP Exam Question
CISSP dumps & ISC Certification sure practice dumps
The advantages of obtaining the ISC CISSP Certification
ISC CISSP Certification Benefits ISC recognizes the importance of professional development for current CISSPs. The ISC CISSP CBK Review Program was introduced to provide CISSPs with the opportunity to earn continuing professional education (CPE) credits or retain their certification status. ISC also offers the CPE library, which contains informative, educational content on various information security topics. Certified CISSPs receive additional opportunities to network with peers, get involved with industry events, learn new skills, and continue to acquire knowledge in the field of information security.
ISC's CISSP certification holds many advantages for those who obtain it. First, it is beneficial for companies because they are able to hire more secure employees. Secondly, obtaining the certification will make you eligible to receive incentives offered by Microsoft, Google, and other IT firms. Thirdly, individuals who obtain the certification are able to work in more advanced positions. Fourth, the credential is accepted worldwide and your compensation level will increase as a result of this recognition. Finally, ISC offers continuing professional education credits that give you an opportunity to earn credits or maintain your credentials with the program also offering informative CPE library content on various information security topics which can be accessed by certified professionals.
CISSP stands for Certified Information Systems Security Professional. It is a certification that shows that an individual possesses comprehensive, technical knowledge of the information security field. The CISSP preparation material preparation is available in numerous varieties online. You can use this CISSP exam material like CISSP Dumps, to pass your CISSP examination with great ease. The main purpose of the CISSP certification is to confirm professional competence in information security management and to enhance it continuously by learning new skills and techniques of cybersecurity.
NEW QUESTION # 65
Which type of attack is based on the probability of two different messages using the same hash function producing a common message digest?
- A. Birthday attack
- B. Differential cryptanalysis
- C. Differential linear cryptanalysis
- D. Statistical attack
Answer: A
Explanation:
A Birthday attack is usually applied to the probability of two different messages using the same hash function producing a common message digest.
The term "birthday" comes from the fact that in a room with 23 people, the probability of two of more people having the same birthday is greater than 50%.
Linear cryptanalysis is a general form of cryptanalysis based on finding affine approximations to the action of a cipher. Attacks have been developed for block ciphers and stream ciphers. Linear cryptanalysis is one of the two most widely used attacks on block ciphers; the other being differential cryptanalysis.
Differential Cryptanalysis is a potent cryptanalytic technique introduced by Biham and Shamir. Differential cryptanalysis is designed for the study and attack of DES-like cryptosystems. A DES-like cryptosystem is an iterated cryptosystem which relies on conventional cryptographic techniques such as substitution and diffusion.
Differential cryptanalysis is a general form of cryptanalysis applicable primarily to block ciphers, but also to stream ciphers and cryptographic hash functions. In the broadest sense, it is the study of how differences in an input can affect the resultant difference at the output. In the case of a block cipher, it refers to a set of techniques for tracing differences through the network of transformations, discovering where the cipher exhibits non-random behaviour, and exploiting such properties to recover the secret key. Source:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 4: Cryptography (page 163). and http://en.wikipedia.org/wiki/Differential_cryptanalysis
NEW QUESTION # 66
Which of the following is an initial consideration when developing an information security management system?
- A. Identify the contractual security obligations that apply to the organizations
- B. Understand the value of the information assets
- C. Identify the level of residual risk that is tolerable to management
- D. Identify relevant legislative and regulatory compliance requirements
Answer: B
Explanation:
Section: Asset Security
NEW QUESTION # 67
Checking routing information on e-mail to determine it is in a valid format and contains valid information is an example of which of the following anti-spam approaches?
- A. Hashing algorithm
- B. Header analysis
- C. Reverse Domain Name System (DNS) lookup
- D. Simple Mail Transfer Protocol (SMTP) blacklist
Answer: B
NEW QUESTION # 68
How many bits is the effective length of the key of the Data Encryption Standard algorithm?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Data Encryption Standard (DES) has had a long and rich history within the computer community. NIST invited vendors to submit data encryption algorithms to be used as a cryptographic standard. IBM had already been developing encryption algorithms to protect financial transactions. In 1974, IBM's 128-bit algorithm, named Lucifer, was submitted and accepted. The NSA modified this algorithm to use a key size of 64 bits (with 8 bits used for parity, resulting in an effective key length of 56 bits) instead of the original
128 bits, and named it the Data Encryption Algorithm (DEA).
NOTE DEA is the algorithm that fulfills DES, which is really just a standard. So DES is the standard and DEA is the algorithm, but in the industry we usually just refer to it as DES. The CISSP exam may refer to the algorithm by either name, so remember both.
Incorrect Answers:
A: The Data Encryption Standard algorithm has an effective key length of 56 bits, not 168 bits.
B: The Data Encryption Standard algorithm has an effective key length of 56 bits, not 128 bits.
D: The Data Encryption Standard algorithm has an effective key length of 56 bits, not 64 bits.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 800
NEW QUESTION # 69
The data transmission method in which data is sent continuously and
doesn't use either an internal clocking source or start/stop bits for
timing is known as:
- A. Synchronous
- B. Isochronous
- C. Pleisiochronous
- D. Asynchronous
Answer: B
Explanation:
Isochronous data is synchronous data transmitting without a
clocking source, with the bits sent continuously and no start or stop
bits. All bits are of equal importance and are anticipated to occur at
regular time intervals.
* asynchronous, is a data transmission method using a start bit at the beginning of the data value, and a stop bit at the end of the value.
* synchronous, is a messageframed transmission method that uses clocking pulses to match the speed of the data transmission.
* pleisiochronous, is a transmission method that uses more than one timing source, sometimes running at different speeds. This method may require master and slave clock devices. Source: Communications Systems and Networks by
Ray Horak (M&T Books, 2000).
NEW QUESTION # 70
A Distributed Denial of Service (DDoS) attack was carried out using malware called Mirai to create a large-scale command and control system to launch a botnet. Which of the following devices were the PRIMARY sources used to generate the attack traffic?
- A. Web servers running open source operating systems (OS)
- B. Internet of Things (IoT) devices
- C. Microsoft Windows hosts
- D. Mobile devices running Android
Answer: B
NEW QUESTION # 71
Alternate encoding such as hexadecimal representations is MOST often observed in which of the following forms of attack?
- A. Smurf
- B. Rootkit exploit
- C. Denial of Service (DoS)
- D. Cross site scripting (XSS)
Answer: D
NEW QUESTION # 72
Which of the following is a proximity identification device that does not require action by the user and works by responding with an access code to signals transmitted by a reader?
- A. A passive system sensing device
- B. A transponder
- C. A card swipe
- D. A magnetic card
Answer: B
Explanation:
A transponder is a proximity identification device that does not require action by the
user.
The reader transmits signals to the device and the device responds with an access code.
These transponder devices contain a radio receiver and transmitter, a storage place for the access
code, control logic, and a battery.
A passive device only uses the power from the reader to detect the presence of the card. Card
swipes and smart cards are not proximity identification devices.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002,
chapter 6: Physical Security (page 323).
NEW QUESTION # 73
Which of the following is TRUE of two-factor authentication?
- A. It uses the RSA public-key signature based on integers with large prime factors.
- B. It does not use single sign-on technology.
- C. It requires two measurements of hand geometry.
- D. It relies on two independent proofs of identity.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
There are three general factors that are used for authentication:
Something a person knows.
Something a person has.
Something a person is.
Two-factor authentication requires two of the three factors to be part of authentication process.
Incorrect Answers:
A: RSA encryption uses integers with exactly two prime factors, but the term "two-factor authentication" is not used in that context.
B: Measuring hand geometry twice only provides one factor.
C: Single sign-on (SSO) technology allows a user to enter their credentials once to gain access to multiple systems. Two-factor authentication could be used for SSO, not the other way around.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 162, 163, 207, 815
NEW QUESTION # 74
Which choice below BEST describes the difference between the System
Owner and the Information Owner?
- A. The System Owner is responsible for establishing the rules for
appropriate use of the information. - B. One system could have multiple information owners.
- C. There is a one-to-one relationship between system owners and
information owners. - D. The Information Owner is responsible for defining the system's
operating parameters.
Answer: B
Explanation:
The System Owner is responsible for ensuring that the security
plan is prepared and for implementing the plan and monitoring its
effectiveness. The System Owner is responsible for defining the system's operating parameters, authorized functions, and security requirements. The information owner for information stored within, processed by, or transmitted by a system may or may not be the same
as the System Owner. Also, a single system may utilize information
from multiple Information Owners.
The Information Owner is responsible for establishing the rules for
appropriate use and protection of the subject data/information (rules of behavior). The Information Owner retains that responsibility even when the data/information are shared with other organizations.
Source: NIST Special Publication 800-18, Guide for Developing Security
Plans for Information Technology Systems.
NEW QUESTION # 75
You've decided to authenticate the source who initiated a particular transfer while ensuring integrity of the data being transferred. You can do this by:
- A. Having the sender encrypt the message with his symmetric key.
- B. Having the sender encrypt the message with his private key.
- C. Having the sender encrypt the hash with his public key.
- D. Having the sender encrypt the hash with his private key.
Answer: D
Explanation:
Instead of using a shared-key to encrypt the hash of a given message, the sender's private key is used to encrypt the hash value of the message. This is the act of digitally signing the message.
Digital Signatures provide authentication of a sender and integrity of a sender's message.
A message is input into a hash function. Then the hash value is encrypted using the private key of the sender. The result of these two steps yields a digital signature. The receiver can verify the digital signature by decrypting the hash value using the signer's public key, then perform the same hash computation over the message, and then compare the hash values for an exact match. If the hash values are the same then the signature is valid.
The following answers are incorrect:
Having the sender encrypt the hash with his public key. This does not provide any benefit because only the sender cold decrypt using his own private key and nobody else.
Encrypting with a publick key only provide Confidentiality and not other service.
Having the sender encrypt the message with his private key. This is close but not good enough. It would only provide authenticity of the source.
Having the sender encrypt the message with his symmetric key. This would provide only
Confidentiality.
The following reference(s) were/was used to create this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third
Edition ((ISC)2 Press) (Kindle Locations 14885-14889). Auerbach Publications. Kindle
Edition.
NEW QUESTION # 76
Which of the following is TRUE about Disaster Recovery Plan (DRP) testing?
- A. Testing should continue even if components of the test fail.
- B. The company is fully prepared for a disaster if all tests pass.
- C. Operational networks are usually shut down during testing.
- D. Testing should not be done until the entire disaster plan can be tested.
Answer: A
NEW QUESTION # 77
What does electronic vaulting accomplish?
- A. It protects critical files.
- B. It stripes all database records
- C. It automates the Disaster Recovery Process (DRP)
- D. It ensures the fault tolerance of Redundant Array of Independent Disks (RAID) systems
Answer: A
Explanation:
Section: Security Operations
Explanation/Reference:
NEW QUESTION # 78
What is the main focus of the Bell-LaPadula security model?
- A. Accountability
- B. Availability
- C. Confidentiality
- D. Integrity
Answer: C
Explanation:
The Bell-LaPadula model is a formal model dealing with confidentiality.
The Bell-LaPadula Model (abbreviated BLP) is a state machine model used for enforcing access control in government and military applications. It was developed by David Elliott Bell and Leonard
J. LaPadula, subsequent to strong guidance from Roger R. Schell to formalize the U.S. Department of Defense (DoD) multilevel security (MLS) policy. The model is a formal state transition model of computer security policy that describes a set of access control rules which use security labels on objects and clearances for subjects. Security labels range from the most sensitive (e.g."Top Secret"), down to the least sensitive (e.g., "Unclassified" or "Public").
The Bell-LaPadula model focuses on data confidentiality and controlled access to classified
information, in contrast to the Biba Integrity Model which describes rules for the protection of data
integrity. In this formal model, the entities in an information system are divided into subjects and
objects.
The notion of a "secure state" is defined, and it is proven that each state transition preserves
security by moving from secure state to secure state, thereby inductively proving that the system
satisfies the security objectives of the model. The Bell-LaPadula model is built on the concept of a
state machine with a set of allowable states in a computer network system. The transition from
one state to another state is defined by transition functions.
A system state is defined to be "secure" if the only permitted access modes of subjects to objects
are in accordance with a security policy. To determine whether a specific access mode is allowed,
the clearance of a subject is compared to the classification of the object (more precisely, to the
combination of classification and set of compartments, making up the security level) to determine if
the subject is authorized for the specific access mode.
The clearance/classification scheme is expressed in terms of a lattice. The model defines two
mandatory access control (MAC) rules and one discretionary access control (DAC) rule with three
security properties:
The Simple Security Property - a subject at a given security level may not read an object at a
higher security level (no read-up).
The -property (read "star"-property) - a subject at a given security level must not write to any
object at a lower security level (no write-down). The -property is also known as the Confinement
property.
The Discretionary Security Property - use of an access matrix to specify the discretionary access
control.
The following are incorrect answers:
Accountability is incorrect. Accountability requires that actions be traceable to the user that
performed them and is not addressed by the Bell-LaPadula model.
Integrity is incorrect. Integrity is addressed in the Biba model rather than Bell-Lapadula.
Availability is incorrect. Availability is concerned with assuring that data/services are available to
authorized users as specified in service level objectives and is not addressed by the Bell-Lapadula
model.
References:
CBK, pp. 325-326
AIO3, pp. 279 - 284
AIOv4 Security Architecture and Design (pages 333 - 336)
AIOv5 Security Architecture and Design (pages 336 - 338)
Wikipedia at https://en.wikipedia.org/wiki/Bell-La_Padula_model
NEW QUESTION # 79
Which of the following allows two computers to coordinate in executing software?
- A. SNMP
- B. RPC
- C. RSH
- D. NFS
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The programmer of a piece of software can write a function call that calls upon a subroutine. The subroutine could be local to the system or be on a remote system. If the subroutine is on a remote system, it is a Remote Procedure Call (RPC). The RPC request is carried over a session layer protocol. The result that the remote system provides is then returned to the requesting system over the same session layer protocol. With RPC a piece of software can execute components that reside on another system.
Incorrect Answers:
A: The remote shell (rsh) is a command line computer program that can execute shell commands as another user, and on another computer across a computer network. RSH is not used to remotely execute software.
C: The Network File System (NFS) is not used to execute software remotely. NFS is a client/server application that lets a computer user view and optionally store and update file on a remote computer as though they were on the user's own computer.
D: SNMP is used for monitoring the network, not for remote software execution.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 525
NEW QUESTION # 80
Identity-based access control is a subset of which one of the following
access control categories?
- A. Non-discretionary access control
- B. Discretionary access control
- C. Lattice-based access control
- D. Mandatory access control
Answer: B
Explanation:
The correct answer is "Discretionary access control". Identity-based access control is a type of discretionary access control that grants access privileges based on the user's identity. A related type of discretionary access control is user-directed access control that gives the user, with certain limitations, the right to alter the access control to certain objects.
NEW QUESTION # 81
The Spiral Model of the software development process (B.W. Boehm, A
Spiral Model of Software Development and Enhancement, IEEE
Computer, May, 1988) uses the following metric relative to the spiral:
- A. The radial dimension represents the cost of each phase
- B. The radial dimension represents cumulative cost
- C. The angular dimension represents cumulative cost
- D. The radial dimension represents progress made in completing each cycle
Answer: B
Explanation:
The radial dimension represents cumulative cost and the angular dimension represents progress made in completing each cycle of the spiral. The spiral model is actually a meta-model for software development processes. Asummary of the stages in the spiral is as follows: The spiral begins in the top, left-hand quadrant by determining the objectives of the portion of the product being developed, the alternative means of implementing this portion of the product, and the constraints imposed on the application of the alternatives. Next, the risks of the alternatives are evaluated based on the objectives and constraints. Following this step, the relative balances of the perceived risks are determined. The spiral then proceeds to the lower right-hand quadrant where the development phases of the projects begin. A major review completes each cycle and then the process begins anew for succeeding phases of the project. Typical succeeding phases are software product design, integration and test plan development, additional risk analyses, operational prototype, detailed design, code, unit test, acceptance test, and implementation. The other answers are distracters.
NEW QUESTION # 82
Which of the following is an appropriate source for test data?
- A. Production data that is secured and maintained only in the production environment.
- B. Test data that is mirrored and kept up-to-date with production data.
- C. Production data that has been sanitized before loading into a test environment.
- D. Test data that has no similarities to production data.
Answer: C
NEW QUESTION # 83
Which of the following protocols would BEST mitigate threats of sniffing attacks on web application traffic?
- A. SSH - Secure Shell
- B. SSL or TLS
- C. ARP Cache Security
- D. 802.1X
Answer: B
Explanation:
While it traverses the network, without some sort of encryption of web application
data is vulnerable to sniffing and interception by attackers on the network. If we observe sniffer
traffic on an unencrypted network we can clearly see the contents of user interaction with the web
server and its applications.
SSL - Secure Sockets Layer or TLS - Transport Layer Security
There are similarities between these two protocols but TLS 3.1 supersedes SSL 2.0 but they are
not interoperable. Today both protocols are commonly used on many web server. In either case
SSL/TLS encrypts network traffic as it traverses the wire and protects it from sniffing attacks.
The following answers are incorrect:
802.1X: This wouldn't secure data in transit but it would help prevent unauthorized devices from
connecting to your network and sniffing data. Also Known As "Dot 1 X" or "The Extensible
Authentication Protocol (EAP)" it provides infrastructure protection by requiring certificates to
connect.
ARP Cache Security: This wouldn't mitigate the threat of network sniffing of web app data.
SSH - Secure Shell: Incorrect. SSH is a TELNET replacement for that encrypts traffic to mitigate
the threat of network sniffers on SSH connections.
The following reference(s) were/was used to create this question:
2011. EC-COUNCIL Official Curriculum, Ethical Hacking and Countermeasures, v7.1, Module 13,
Page 569.
NEW QUESTION # 84
Which Web Services Security (WS-Security) specification negotiates how security tokens will be issued, renewed and validated? Click on the correct specification in the image below.
Answer:
Explanation:
Explanation
WS-Trust
The protocol used for issuing security tokens is based on WS-Trust. WS-Trust is a Web service specification that builds on WS-Security. It describes a protocol used for issuance, exchange, and validation of security tokens. WS-Trust provides a solution for interoperability by defining a protocol for issuing and exchanging security tokens, based on token format, namespace, or trust boundaries.
Reference: https://msdn.microsoft.com/en-us/library/ff650503.aspx
NEW QUESTION # 85
......
ISC CISSP Actual Questions and Braindumps: https://www.examboosts.com/ISC/CISSP-practice-exam-dumps.html
Pass CISSP Exam with Updated CISSP Exam Dumps PDF 2023: https://drive.google.com/open?id=13Qn8_avCDUSf1K75d3KkTshObJtXQ49z