Get New 2021 Valid Practice ISC Certification CISSP Q&A - Testing Engine [Q551-Q566]

Share

Get New 2021 Valid Practice ISC Certification CISSP Q&A - Testing Engine

CISSP Dumps PDF - 100% Passing Guarantee


What to Get: (ISC)2 CISSP Certification Benefits

After gaining the required work experience, successfully passing the (ISC)2 CISSP exam and finally getting endorsement, you will become eligible for the CISSP certification. Some of the most popular positions you can apply for after getting certified include the following:

  • Internal Auditor;
  • Chief Information Officer;
  • Security Consultant;
  • Network Architect;
  • Cybersecurity Forensic Analyst;
  • Cloud Security Administrator.

Having the CISSP certification under your belt can also have a great impact on the financial bottom line after successfully completing the exam. Those who hold this sought-after certificate can earn an average salary of about $101,000.

 

NEW QUESTION 551
The primary function of this protocol is to send messages between network devices regarding the health of the network:

  • A. Address Resolution Protocol (AR)
  • B. Internet Protocol (IP)
  • C. Internet Control Message Protocol (ICMP)
  • D. Reverse Address Resolution Protocol (RARP)

Answer: C

 

NEW QUESTION 552
What is the effective key size of DES?

  • A. 64 bits
  • B. 56 bits
  • C. 1024 bits
  • D. 128 bits

Answer: B

Explanation:
Data Encryption Standard (DES) is a symmetric key algorithm. Originally developed by IBM, under project name Lucifer, this 128-bit algorithm was accepted by the
NIST in 1974, but the total key size was reduced to 64 bits, 56 of which make up the effective key, plus and extra 8 bits for parity. It somehow became a national cryptographic standard in 1977, and an American National Standard Institute (ANSI) standard in 1978.
DES was later replaced by the Advanced Encryption Standard (AES) by the NIST.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-
Hill/Osborne, 2002, chapter 8: Cryptography (page 525).

 

NEW QUESTION 553
Which of the following is a remote access protocol that uses a static authentication?

  • A. Challenge Handshake Authentication Protocol (CHAP)
  • B. Routing Information Protocol (RIP)
  • C. Password Authentication Protocol (PAP)
  • D. Point-to-Point Tunneling Protocol (PPTP)

Answer: C

 

NEW QUESTION 554
Which choice below is NOT an example of the appropriate external distribution
of classified information?

  • A. Upon senior-level approval after a confidentiality agreement
  • B. To influence the value of the company's stock price
  • C. IAW contract procurement agreements for a government project
  • D. Compliance with a court order

Answer: B

Explanation:
The correct answer is "To influence the value of the company's stock price". Answers "Compliance with a court order", "Upon senior-level approval after a confidentiality agreement", and "IAW contract procurement agreements for a government project" are all examples of the need for possible external distribution of internal classified information.

 

NEW QUESTION 555
In non-discretionary access control using Role Based Access Control (RBAC), a central authority determines what subjects can have access to certain objects based on the organizational security policy. The access controls may be based on:

  • A. The societies role in the organization
  • B. The group-dynamics as they relate to the individual's role in the organization
  • C. The group-dynamics as they relate to the master-slave role in the organization
  • D. The individual's role in the organization

Answer: D

Explanation:
In Non-Discretionary Access Control, when Role Based Access Control is being used, a central authority determines what subjects can have access to certain objects based on the organizational security policy. The access controls may be based on the individual's role in the organization.
Reference(S) used for this question: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 33

 

NEW QUESTION 556
Which inherent password weakness does a One Time Password (OTP) generator overcome?

  • A. Static passwords must be changed frequently.
  • B. Static passwords are easily disclosed.
  • C. Static passwords are too predictable.
  • D. Static passwords are difficult to generate.

Answer: B

 

NEW QUESTION 557
Which fire class can water be most appropriate for?

  • A. Class C fires
  • B. Class B fires
  • C. Class A fires
  • D. Class D fires

Answer: C

Explanation:
Water is appropriate for class A (common combustibles) fires. Class B fires
(liquid) are best handled by CO2, soda acid or Halon. Class C fires (electrical) are best handled by CO2 and Halon. Fire class D is used for combustible metals like magnesium.
Source: WALLHOFF, John, CBK#10 Physical Security (CISSP Study Guide), April 2002
(page 3).

 

NEW QUESTION 558
Which of the following steps should be performed first in a business impact analysis (BIA)?

  • A. Evaluate the impact of disruptive events.
  • B. Estimate the Recovery Time Objectives (RTO).
  • C. Evaluate the criticality of business functions.
  • D. Identify all business units within the organization.

Answer: D

Explanation:
Remember that when we talk about a BIA (Business Impact Analysis), we are analyzing and identifying possible issues about our infrastructure. It's an analysis about the business, the process that it relays on, the level of the systems and a estimative of the financial impact, or in other words, how much many we loose with our systems down. The first step on it should always be the identifying of the business units in the company. You can then go to other requirements like estimate losses and downtime costs.

 

NEW QUESTION 559
What is the MOST common component of a vulnerability management framework?

  • A. Threat analysis
  • B. Backup management
  • C. Risk analysis
  • D. Patch management

Answer: D

Explanation:
https://www.helpnetsecurity.com/2016/10/11/effective-vulnerability-management-process/

 

NEW QUESTION 560
The BEST method to mitigate the risk of a dictionary attack on a system is to

  • A. encrypt the access control list (ACL).
  • B. use a hardware token.
  • C. use complex passphrases.
  • D. implement password history.

Answer: B

 

NEW QUESTION 561
Referential integrity requires that for any foreign key attribute, the referenced
relation must have:

  • A. An attribute with the same value for its secondary key.
  • B. A tuple with the same value for its secondary key.
  • C. An attribute with the same value for its other foreign key.
  • D. A tuple with the same value for its primary key.

Answer: D

Explanation:
The correct answer is "A tuple with the same value for its primary key". Answers "A tuple with the same value for its secondary key." and "An attribute with the same value for its secondary key." are incorrect because a secondary key is not a valid term. Answer "An attribute with the same value for its other foreign key." is a distracter, because referential integrity has a foreign key referring to a primary key in another relation.

 

NEW QUESTION 562
Which of the following computer crime is MORE often associated with INSIDERS?

  • A. Denial of service (DoS)
  • B. Password sniffing
  • C. IP spoofing
  • D. Data diddling

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Data diddling refers to the alteration of existing data. Many times, this modification happens before the data is entered into an application or as soon as it completes processing and is outputted from an application. For instance, if a loan processor is entering information for a customer's loan of $100,000, but instead enters $150,000 and then moves the extra approved money somewhere else, this would be a case of data diddling. Another example is if a cashier enters an amount of $40 into the cash register, but really charges the customer $60 and keeps the extra $20.
This type of crime is extremely common and can be prevented by using appropriate access controls and proper segregation of duties. It will more likely be perpetrated by insiders, who have access to data before it is processed.
Incorrect Answers:
A: IP Spoofing attacks are more commonly performed by outsiders.
B: Password sniffing can be performed by insiders or outsiders. However, Data Diddling is MORE commonly performed by insiders.
D: Most Denial of service attacks occur over the internet and are performed by outsiders.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 1059

 

NEW QUESTION 563
What is the PRIMARY objective for conducting an internal security audit?

  • A. Verify that security controls are established following best practices.
  • B. Verify that all personnel supporting a system are knowledgeable of their responsibilities.
  • C. Verify that all systems and Standard Operating Procedures (SOP) are properly documented.
  • D. Verify that applicable security controls are implemented and effective.

Answer: D

 

NEW QUESTION 564
What is NOT true with pre shared key authentication within IKE / IPsec protocol?

  • A. IKE is used to setup Security Associations
  • B. IKE builds upon the Oakley protocol and the ISAKMP protocol.
  • C. Needs a Public Key Infrastructure (PKI) to work
  • D. Pre shared key authentication is normally based on simple passwords

Answer: C

Explanation:
Internet Key Exchange (IKE or IKEv2) is the protocol used to set up a security
association (SA) in the IPsec protocol suite. IKE builds upon the Oakley protocol and ISAKMP.
IKE uses X.509 certificates for authentication which are either pre-shared or distributed using DNS
(preferably with DNSSEC) and a Diffie-Hellman key exchange to set up a shared session secret
from which cryptographic keys are derived.
Internet Key Exchange (IKE) Internet key exchange allows communicating partners to prove their
identity to each other and establish a secure communication channel, and is applied as an
authentication component of IPSec.
IKE uses two phases:
Phase 1: In this phase, the partners authenticate with each other, using one of the following:
Shared Secret: A key that is exchanged by humans via telephone, fax, encrypted e-mail, etc.
Public Key Encryption: Digital certificates are exchanged.
Revised mode of Public Key Encryption: To reduce the overhead of public key encryption, a nonce (a Cryptographic function that refers to a number or bit string used only once, in security engineering) is encrypted with the communicating partner's public key, and the peer's identity is encrypted with symmetric encryption using the nonce as the key. Next, IKE establishes a temporary security association and secure tunnel to protect the rest of the key exchange. Phase 2: The peers' security associations are established, using the secure tunnel and temporary SA created at the end of phase 1.
The following reference(s) were used for this question: Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 7032-7048). Auerbach Publications. Kindle Edition. and RFC 2409 at http://tools.ietf.org/html/rfc2409 and http://en.wikipedia.org/wiki/Internet_Key_Exchange

 

NEW QUESTION 565
Which of the following would be the BEST criterion to consider in determining the classification of an information asset?

  • A. Useful life
  • B. Value
  • C. Personal association
  • D. Age

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The 'value' of an information asset should be used to classify the information asset.
The rationale behind assigning values to different types of data is that it enables a company to gauge the amount of funds and resources that should go toward protecting each type of data, because not all data has the same value to a company. After identifying all important information, it should be properly classified. A company has a lot of information that is created and maintained. The reason to classify data is to organize it according to its sensitivity to loss, disclosure, or unavailability. Once data is segmented according to its sensitivity level, the company can decide what security controls are necessary to protect different types of data. This ensures that information assets receive the appropriate level of protection, and classifications indicate the priority of that security protection.
Incorrect Answers:
B: The age of an information asset is not the best criterion to consider in determining the classification of the information asset.
C: The useful life of an information asset is not the best criterion to consider in determining the classification of the information asset.
D: The personal association of an information asset is not the best criterion to consider in determining the classification of the information asset.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 109

 

NEW QUESTION 566
......

CISSP Braindumps Real Exam Updated on Nov 17, 2021 with 990 Questions: https://www.examcollectionpass.com/ISC/CISSP-practice-exam-dumps.html

Latest CISSP PDF Dumps & Real Tests Free Updated Today: https://drive.google.com/open?id=1eJ5ICUCsxv2_NMbrPi4evJG5ze1uZhnw