
Pass CISSP Exam with Updated CISSP Exam Dumps PDF 2021
CISSP Exam Dumps - Free Demo & 365 Day Updates
What to Know: (ISC)2 CISSP Exam Basics
(ISC)2 reveals very little concerning the details of its certification exams. However, it is possible to know that the CISSP test includes a mixture of advanced innovative and multiple-choice questions. The exam comes with about 250 questions across all 8 common knowledge domains for the non-English individuals. As for the standard format, you will have 100-150 questions. It is 6 hours long for the non-English speakers and 3 hours long as a standard. The passing score is 700 out of the possible 1000 points.
The exam costs $699 in the USA. The fee may vary from country to country due to tax policies. If you are not residing in the United States and want to take this test, you should check the official website to find out the exact actual cost.
To prepare for the CISSP exam with great deliberation, the candidates can choose from a variety of study approaches. The learners can sign up for an instructor-led training course, which is the most recommended preparation method. CISSP Accelerated Training Program is a paid training option designed for those IT professionals who already have 5 or more years of work experience in the field of IT security.
Understanding specialized and utilitarian abilities of CISSP test: Certified Information Systems Security Professional
The accompanying will be examined in ISC CISSP dumps:
- Integrate Third-Party Identity Services
- Manage Identification and Authentication of People and Devices
- Manage the Identity and Access Provisioning Life Cycle
- Control Physical and Logical Access to Assets
- Design and Establish Secure Communication Channels
- Apply Secure Design Principles to Network Architecture
- Prevent or Mitigate Network Attacks
- Integrate Identity as a Service (IDaaS)
- Identity and Access Management (Controlling Access and Managing Identity)
- Implement and Manage Authorization Mechanisms
- Prevent or Mitigate Access Control Attacks
- Securing Network Components
NEW QUESTION 459
Which of the following is an advantage of prototyping?
- A. It ensures that functions or extras are not added to the intended system.
- B. Strong internal controls are easier to implement.
- C. Prototype systems can provide significant time and cost savings.
- D. Change control is often less complicated with prototype systems.
Answer: C
Explanation:
The Prototype Phase is also called the "Proof of Concept" Phase. Whether it's called one or the other depends on what the creator is trying to "prove." If the main deliverable of the Phase includes a working version of the product's technical features, it's a "prototype." If the main deliverable just looks like it has the product's technical features, then it's a "proof of concept." Prototypes can save time and money because you can test some functionality earlier in the process. You don't have to make the whole final product to begin testing it.
NEW QUESTION 460
Which of the following BEST describes a Protection Profile (PP)?
- A. A document that expresses an implementation dependent set of security requirements which contains only the security functional requirements.
- B. A document that expresses an implementation independent set of security requirements for an IT product that meets specific consumer needs.
- C. A document that is used to develop an IT security product from its security requirements definition.
- D. A document that represents evaluated products where there is a one-to-one correspondence between a PP and a Security Target (ST).
Answer: B
NEW QUESTION 461
The primary role of cross certification is:
- A. Creating trust between different PKIs
- B. Build an overall PKI hierarchy
- C. Prevent the nullification of user certifications by CA certificate revocation
- D. set up direct trust to a second root CA
Answer: A
NEW QUESTION 462
Which of the following defines the key exchange for Internet Protocol Security (IPSEC)?
- A. Internet Key Exchange (IKE)
- B. Internet Communication Messaging Protocol (ICMP)
- C. Security Key Exchange (SKE)
- D. Internet Security Association Key Management Protocol (ISAKMP)
Answer: D
Explanation:
Because Ipsec is a framework, it does not dictate what hashing and encryption algorithms are to be used or how keys are to be exchanged between devices. Key management can be handled through manual process or automated a key management protocol. The Internet Security Association and Key management Protocol (ISAKMP) is an authentication and key exchange architecture that is independent of the type of keying mechanisms used. Pg 577 Shon Harris All-In-One CISSP Certification Exam Guide
NEW QUESTION 463
Which of the following is a LAN transmission method?
- A. Token ring
- B. Carrier-sense multiple access with collision detection (CSMA/CD)
- C. Broadcast
- D. Fiber Distributed Data Interface (FDDI)
Answer: C
Explanation:
LAN transmission methods refer to the way packets are sent on the network and are
either unicast, multicast or broadcast.
CSMA/CD is a common LAN media access method.
Token ring is a LAN Topology.
LAN transmission protocols are the rules for communicating between computers on a LAN.
Common LAN transmission protocols are: polling and token-passing.
A LAN topology defines the manner in which the network devices are organized to facilitate
communications.
Common LAN topologies are: bus, ring, star or meshed.
LAN transmission methods refer to the way packets are sent on the network and are either
unicast, multicast or broadcast.
LAN media access methods control the use of a network (physical and data link layers). They can
be Ethernet, ARCnet, Token ring and FDDI.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and
Network Security (page 103).
HERE IS A NICE OVERVIEW FROM CISCO:
LAN Transmission Methods
LAN data transmissions fall into three classifications: unicast, multicast, and broadcast. In each type of transmission, a single packet is sent to one or more nodes. In a unicast transmission, a single packet is sent from the source to a destination on a network. First, the source node addresses the packet by using the address of the destination node. The package is then sent onto the network, and finally, the network passes the packet to its destination. A multicast transmission consists of a single data packet that is copied and sent to a specific subset of nodes on the network. First, the source node addresses the packet by using a multicast address. The packet is then sent into the network, which makes copies of the packet and sends a copy to each node that is part of the multicast address. A broadcast transmission consists of a single data packet that is copied and sent to all nodes on the network. In these types of transmissions, the source node addresses the packet by using the broadcast address. The packet is then sent on to the network, which makes copies of the packet and sends a copy to every node on the network. LAN Topologies LAN topologies define the manner in which network devices are organized. Four common LAN topologies exist: bus, ring, star, and tree. These topologies are logical architectures, but the actual devices need not be physically organized in these configurations. Logical bus and ring topologies, for example, are commonly organized physically as a star. A bus topology is a linear LAN architecture in which transmissions from network stations propagate the length of the medium and are received by all other stations. Of the three most widely used LAN implementations, Ethernet/IEEE 802.3 networks-including 100BaseT-implement a bus topology
Sources: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 104). http://www.cisco.com/univercd/cc/td/doc/cisintwk/ito_doc/introlan.htm
NEW QUESTION 464
How many bits is the effective length of the key of the Data Encryption Standard algorithm?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
The correct answer is "56". This is actually a bit of a trick question, since the actual key length is 64 bits. However, every eighth bit is ignored because it is used for parity. This makes the "effective length of the key" that the question actually asks for 56 bits.
The other answers are not correct because:
168 - This is the number of effective bits in Triple DES (56 times 3).
128 - Many encryption algorithms use 128 bit key, but not DES. Note that you may see 128 bit encryption referred to as "military strength encryption" because many military systems use key of this length.
64 - This is the actual length of a DES encryption key, but not the "effective length" of the
DES key.
Reference:
Official ISC2 Guide page: 238
All in One Third Edition page: 622
NEW QUESTION 465
Which of the following packets should NOT be dropped at a firewall protecting an organization's internal network?
- A. Inbound packets with an internal source IP address
- B. Outbound packets with an external destination IP address
- C. Router information exchange protocols
- D. Inbound packets with Source Routing option set
Answer: B
NEW QUESTION 466
Why would a database be denormalized?
- A. To save storage space
- B. To ensure data integrity
- C. To prevent duplication of data
- D. To increase processing efficiency
Answer: D
Explanation:
A database is denormalized when there is a need to improve processing efficiency.
There is, however, a risk to data integrity when this occurs. Since it implies the introduction of
duplication, it will not likely allow saving of storage space.
Source: Information Systems Audit and Control Association, Certified Information Systems Auditor
2002 review manual, Chapter 3: Technical Infrastructure and Operational Practices (page 109).
NEW QUESTION 467
Which of the following is the MOST secure firewall implementation?
- A. Screened-host firewalls
- B. Screened-subnet firewalls
- C. Dual-homed host firewalls
- D. Packet-filtering firewalls
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A screened-subnet architecture is the most secure solution as it adds another layer of security to the screened-host architecture, which in turn is more secure than both Dual-homed host firewalls and Packet- filtering firewalls.
Incorrect Answers:
A: Dual-homed host firewalls are less secure compared to screened-host firewall.
C: Screened-host firewalls are less secure compared to Screened-subnet firewalls, as the screened- subnet architecture is missing.
A screened host is a firewall that communicates directly with a perimeter router and the internal network.
D: A packet-filtering firewall is part of a screened-host firewall architecture, but is less secure as the screened-host firewall is missing.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 646
NEW QUESTION 468
Frame relay uses a public switched network to provide:
- A. Wide Area Network (WAN) connectivity.
- B. World Area Network (WAN) connectivity.
- C. Local Area Network (LAN) connectivity.
- D. Metropolitan Area Network (MAN) connectivity.
Answer: A
Explanation:
Frame relay uses a public switched network to provide Wide Area Network (WAN)
connectivity.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, 2001, John Wiley & Sons, Page 73.
NEW QUESTION 469
Which of the following is held accountable for the risk to organizational systems and data that result from outsourcing Information Technology (IT) systems and services?
- A. The service provider
- B. The acquiring organization
- C. The IT manager
- D. The risk executive (function)
Answer: D
NEW QUESTION 470
Which of the following is the BEST reason to apply patches manually instead of automated patch management?
- A. The time during which systems will remain vulnerable to an exploit will be decreased.
- B. The target systems reside within isolated networks.
- C. The cost required to install patches will be reduced.
- D. The ability to cover large geographic areas is increased.
Answer: B
NEW QUESTION 471
The Physical Security domain focuses on three areas that are the basis to physically protecting enterprise's resources and sensitive information. Which of the following is not one of these areas?
- A. Risks
- B. Threats
- C. Countermeasures
- D. Vulnerabilities
Answer: C
Explanation:
Countermeasures are used to mitigate the risks, threats, and vulnerabilities and are not areas that are protected.
Security is very important to organizations and their infrastructures, and physical security is no exception. Physical security encompasses a different set of threats, vulnerabilities, and risks than the other types of security that have been addressed so far.
Physical security mechanisms include site design and layout, environmental components, emergency response readiness, training, access control, intrusion detection, and power andfire protection. Physical security mechanisms protect people, data, equipment, systems, facilities, and a long list of company assets.
NEW QUESTION 472
Identification usually takes the form of:
- A. User password.
- B. Passphrase
- C. None of the choices.
- D. Login ID.
Answer: D
Explanation:
Identification is a means to verify who you are. Authentication is what you are authorized to perform, access, or do. User identification enables accountability. It enables you to trace activities to individual users that may be held responsible for their actions. Identification usually takes the form of Logon ID or User ID. Some of the Logon ID characteristics are: they must be unique, not shared, and usually non descriptive of job function
NEW QUESTION 473
When considering the IT Development Life-Cycle, security should be:
- A. Treated as an integral part of the overall system design.
- B. Mostly considered during the development phase.
- C. Mostly considered during the initiation phase.
- D. Add once the design is completed.
Answer: A
NEW QUESTION 474
In finger scan technology,
- A. Features extracted from the fingerprint are stored.
- B. The technology is applicable to large, one-to-many database searches.
- C. The full fingerprint is stored.
- D. More storage is required than in fingerprint technology.
Answer: A
Explanation:
The correct answer is "Features extracted from the fingerprint are store". The features extracted from the fingerprint are stored. Answer "The full fingerprint is stored" is incorrect because the equivalent of the full fingerprint is not stored in finger scan technology.
Answers "More storage is required than in fingerprint technology" and "The technology is applicable to large, one-to-many database searches" are incorrect because the opposite is true of finger scan technology.
NEW QUESTION 475
What principle requires that changes to the plaintext affect many parts of the ciphertext?
- A. Encapsulation
- B. Obfuscation
- C. Diffusion
- D. Permutation
Answer: C
Explanation:
Section: Mixed questions
Explanation:
Diffusion, on the other hand, means that a single plaintext bit has influence over several of the ciphertext bits.
Changing a plaintext value should change many ciphertext values, not just one. In fact, in a strong block cipher, if one plaintext bit is changed, it will change every ciphertext bit with the probability of 50 percent. This means that if one plaintext bit changes, then about half of the ciphertext bits will change.
NEW QUESTION 476
Of the following, which is NOT a specific loss criteria that should be considered while developing a BIA?
- A. Loss in profits
- B. Loss of skilled workers knowledge
- C. Loss in reputation
- D. Loss in revenue
Answer: B
Explanation:
Although a loss of skilled workers knowledge would cause the company a great
loss, it is not identified as a specific loss criteria. It would fall under one of the three other criteria
listed as distracters.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002,
chapter 9: Disaster Recovery and Business continuity (page 598).
NEW QUESTION 477
The privacy provisions of the federal law, the Health Insurance Portability and Accountability Act of 1996 (HIPAA),
- A. apply to health information created or maintained by health care providers regardless of whether they engage in certain electronic transactions, health plans, and health care clearinghouses.
- B. apply to health information created or maintained by health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
- C. apply to certain types of critical health information created or maintained by health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
- D. apply to health information created or maintained by some large health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
Answer: B
NEW QUESTION 478
Within the realm of IT security, which of the following combinations best defines risk?
- A. Vulnerability coupled with an attack
- B. Threat coupled with a breach of security
- C. Threat coupled with a breach
- D. Threat coupled with a vulnerability
Answer: D
Explanation:
The answer: Threat coupled with a vulnerability. Threats are circumstances or actions with the ability to harm a system. They can destroy or modify data or result an a DoS. Threats by themselves are not acted upon unless there is a vulnerability that can be taken advantage of. Risk enters the equation when a vulnerability (Flaw or weakness) exists in policies, procedures, personnel management, hardware, software or facilities and can be exploited by a threat agent. Vulnerabilities do not cause harm, but they leave the system open to harm. The combination of a threat with a vulnerability increases the risk to the system of an intrusion.
The following answers are incorrect: Threat coupled with a breach. A threat is the potential that a particular threat-source will take advantage of a vulnerability. Breaches get around security. It does not matter if a breach is discovered or not, it has still occured and is not a risk of something occuring. A breach would quite often be termed as an incident or intrusion.
Vulnerability coupled with an attack. Vulnerabilities are weaknesses (flaws) in policies, procedures, personnel management, hardware, software or factilities that may result in a harmful intrusion to an IT system. An attack takes advantage of the flaw or vulnerability. Attacks are explicit attempts to violate security, and are more than risk as they are active.
Threat coupled with a breach of security. This is a detractor. Although a threat agent may take advantage of (Breach) vulnerabilities or flaws in systems security. A threat coupled with a breach of security is more than a risk as this is active.
The following reference(s) may be used to research the topics in this question: ISC2 OIG, 2007 p. 66-67 Shon Harris AIO v3 p. 71-72
NEW QUESTION 479
Windows 2000 uses which of the following as the primary mechanism
for authenticating users requesting access to a network?
- A. Kerberos
- B. Hash functions
- C. Public key certificates
- D. SESAME
Answer: A
Explanation:
While Kerberos is the primary mechanism, system administrators
may also use alternative authentication services running under the
Security Support Provider Interface (SSPI). Answer hash
functions, are used for digital signature implementations. Answer SESAME is incorrect. It is the Secure European System for
Applications in a Multivendor Environment. SESAME performs
similar functions to Kerberos, but uses public key cryptography to
distribute the secret keys. Answer "Public key certificates" is incorrect, since public key certificates are not used in the Windows 2000 primary authentication approach.
NEW QUESTION 480
Which of the following is NOT true concerning Application Control?
- A. It is non-transparent to the endpoint applications so changes are needed to the applications and databases involved
- B. Only specific records can be requested through the application controls
- C. Particular usage of the application can be recorded for audit purposes
- D. It limits end users use of applications in such a way that only particular screens are visible.
Answer: A
Explanation:
Source: TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 2, Auerbach.
NEW QUESTION 481
Which of the following is a PRIMARY challenge when running a penetration test?
- A. Establishing a business case
- B. Determining the cost
- C. Determining the depth of coverage
- D. Remediating found vulnerabilities
Answer: C
NEW QUESTION 482
Looking at the choices below, which ones would be the most suitable protocols/tools for securing e-mail?
- A. PGP and S/MIME
- B. TLS and SSL
- C. SSH
- D. IPsec and IKE
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Secure MIME (S/MIME) is a standard for encrypting and digitally signing electronic mail and for providing secure data transmissions.
PGP is often used for signing, encrypting, and decrypting texts, e-mails, files, directories, and whole disk partitions and to increase the security of e-mail communications.
Incorrect Answers:
B: IPSec is not used to protect e-mails. IPsec is used to secure Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session. IPSec can be implemented with the help of the IKE security architecture.
C: SSL and TLS are primarily used to protect HTTP traffic.
D: SSH is not used to protect e-mails. SSH allows remote login and other network services to operate securely over an unsecured network.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 850-851
NEW QUESTION 483
What is the MOST important step during forensic analysis when trying to learn the purpose of an unknown application?
- A. Isolate the system from the network
- B. Prepare another backup of the system
- C. Ensure chain of custody
- D. Disable all unnecessary services
Answer: A
Explanation:
Section: Security Operations
NEW QUESTION 484
......
CISSP Dumps - Pass Your Certification Exam: https://www.examcollectionpass.com/ISC/CISSP-practice-exam-dumps.html
Free Sales Ending Soon - Use Real CISSP PDF Questions: https://drive.google.com/open?id=1eJ5ICUCsxv2_NMbrPi4evJG5ze1uZhnw