[Q568-Q588] CISSP Free Update With 100% Exam Passing Guarantee [2021]

Share

CISSP Free Update With 100% Exam Passing Guarantee [2021]

[Nov-2021] Verified ISC Exam Dumps with CISSP Exam Study Guide

NEW QUESTION 568
Which of the following protects a password from eavesdroppers and supports the encryption of communication?

  • A. Challenge Handshake Encryption Protocol (CHEP)
  • B. Challenge Handshake Identification Protocol (CHIP)
  • C. Challenge Handshake Authentication Protocol (CHAP)
  • D. Challenge Handshake Substitution Protocol (CHSP)

Answer: C

Explanation:
CHAP: A protocol that uses a three way hanbdshake The server sends the client a challenge which includes a random value(a nonce) to thwart replay attacks. The client responds with the MD5 hash of the nonce and the password.
The authentication is successful if the client's response is the one that the server expected.
Reference: Page 450, OIG 2007
CHAP protects the password from eavesdroppers and supports the encryption of communication.
Reference: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 44

 

NEW QUESTION 569
Making sure that the data has not been changed unintentionally, due to an accident or malice is:

  • A. Integrity.
  • B. Auditability.
  • C. Availability.
  • D. Confidentiality.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
Integrity is upheld when the assurance of the accuracy and reliability of information and systems is provided and any unauthorized modification is prevented. Hardware, software, and communication mechanisms must work in concert to maintain and process data correctly and to move data to intended destinations without unexpected alteration. The systems and network should be protected from outside interference and contamination.
Incorrect Answers:
B: Confidentiality is the assurance that information is not disclosed to unauthorized individuals, programs, or processes. This is not what is described in the question.
C: Availability ensures reliability and timely access to data and resources to authorized individuals. This is not what is described in the question.
D: Auditability is the ability of something to be audited. This is not what is described in the question.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 23, 159

 

NEW QUESTION 570
An organization regularly conducts its own penetration tests. Which of the following scenarios MUST be covered for the test to be effective?

  • A. System administrator access compromised
  • B. Internal user accidentally accessing data
  • C. Third-party vendor with access to the system
  • D. Internal attacker with access to the system

Answer: D

Explanation:
Section: Software Development Security

 

NEW QUESTION 571
What attribute is included in a X.509-certificate?

  • A. Telephone number of the department
  • B. Distinguished name of subject
  • C. the key pair of the certificate holder
  • D. secret key of the issuing CA

Answer: B

Explanation:
The key word is 'In create the certificate.." Certificates that conform to X.509 contain the following data: Version of X.509 to which the certificate conforms; Serial number (from the certificate creator); Signature algorithm identifier (specifies the technique used by the certificate authority to digitally sign the contents of the certificate); Issuer name (identification of the certificate authority that issues the certificate) Validity period (specifies the dates and times - a starting date and time and an ending date and time - during which the certificate is valid); Subject's name (contains the distinguished name, or DN, of the entity that owns the public key contained in the certificate); Subject's public key (the meat of the certificate - the actual public key of the certificate owner used to setup secure communications) pg 343-344 CISSP Study Guide byTittel

 

NEW QUESTION 572
Which of the following is an authentication protocol in which a new random number is generated uniquely for each login session?

  • A. Password Authentication Protocol (PAP)
  • B. Challenge Handshake Authentication Protocol (CHAP)
  • C. Extensible Authentication Protocol (EAP)
  • D. Point-to-Point Protocol (PPP)

Answer: B

 

NEW QUESTION 573
What is an IP routing table?

  • A. A list of current network interfaces on which IP routing is enabled.
  • B. A list of station and network addresses with corresponding gateway IP address.
  • C. A list of host names and corresponding IP addresses.
  • D. A list of IP addresses and corresponding MAC addresses.

Answer: B

Explanation:
A routing table is used when a destination IP address is not located on the current LAN segment. It consists of a list of station and network addresses and a corresponding gateway IP address further along to which a routing equipment should send packets that match that station or network address. A list of IP addresses and corresponding MAC addresses is an ARP table. A DNS is used to match host names and corresponding IP addresses. The last choice is a distracter. Source: STREBE, Matthew and PERKINS, Charles, Firewalls 24seven, Sybex 2000, Chapter 3: TCP/IP from a Security Viewpoint.

 

NEW QUESTION 574
Related to information security, the guarantee that the message sent is the message received with the assurance that the message was not intentionally or unintentionally altered is an example of which of the following?

  • A. Identity
  • B. Availability
  • C. Integrity
  • D. Confidentiality

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Information must be accurate, complete, and protected from unauthorized modification. When a security mechanism provides integrity, it protects data, or a resource, from being altered in an unauthorized fashion. If any type of illegitimate modification does occur, the security mechanism must alert the user or administrator in some manner.
Hashing can be used in emails to guarantee that the message sent is the message received with the assurance that the message was not intentionally or unintentionally altered.
Incorrect Answers:
B: Confidentiality is the assurance that information is not disclosed to unauthorized individuals, programs, or processes. This is not what is described in the question.
C: Availability ensures reliability and timely access to data and resources to authorized individuals. This is not what is described in the question.
D: Identity would be the sender or recipient of the email message. It does not guarantee that the message sent is the message received with the assurance that the message was not intentionally or unintentionally altered.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 23, 159

 

NEW QUESTION 575
Which of the following is NOT a proper component of Media Viability Controls?

  • A. Handling
  • B. Writing
  • C. Marking
  • D. Storage

Answer: B

Explanation:
Media Viability Controls include marking, handling and storage.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, 2001, John Wiley & Sons, Page 231.

 

NEW QUESTION 576
Which of the following is *NOT* a symmetric key algorithm?

  • A. Digital Signature Standard (DSS)
  • B. RC5
  • C. Blowfish
  • D. Triple DES (3DES)

Answer: A

Explanation:
Reference: pg 489 Shon Harris

 

NEW QUESTION 577
What does TFTP stand for?

  • A. Transport for TCP/IP
  • B. Transport File Transfer Protocol
  • C. Trivial File Transfer Protocol
  • D. Trivial File Transport Protocol

Answer: C

Explanation:
The correct answer is "Trivial File Transfer Protocol". The other acronyms do not exist.

 

NEW QUESTION 578
Common Criteria 15408 generally outlines assurance and functional requirements through a security evaluation process concept of ______________, ____________, __________ for Evaluated Assurance Levels (EALs) to certify a product or system.

  • A. SFR, Protection Profile, Security Target
  • B. EAL, Security Target, Target of Evaluation
  • C. Protection Profile, Target of Evaluation, Security Target
  • D. SFR, Security Target, Target of Evaluation

Answer: C

Explanation:
Common Criteria 15408 generally outlines assurance and functional requirements through a security evaluation process concept of Protection Profile (PP), Target of Evaluation (TOE), and Security Target (ST) for Evaluated Assurance Levels (EALs) to certify a product or system.
This lists the correct sequential order of these applied concepts to formally conducts tests that evaluate a product or system for the certification for federal global information systems. Common Criteria evaluations are performed on computer security products and systems. There are many terms related to Common Criteria and you must be familiar with them.
Target Of Evaluation (TOE) - the product or system that is the subject of the evaluation. The evaluation serves to validate claims made about the target. To be of practical use, the evaluation must verify the target's security features. This is done through the following: Protection Profile (PP) - a document, typically created by a user or user community, which identifies security requirements for a class of security devices (for example, smart cards used to provide digital signatures, or network firewalls) relevant to that user for a particular purpose. Product vendors can choose to implement products that comply with one or more PPs, and have their products evaluated against those PPs. In such a case, a PP may serve as a template for the product's ST (Security Target, as defined below), or the authors of the ST will at least ensure that all requirements in relevant PPs also appear in the target's ST document. Customers looking for particular types of products can focus on those certified against the PP that meets their requirements.
Security Target (ST) - the document that identifies the security properties of the target of evaluation. It is what the vendor claim the product can do. It may refer to one or more PPs. The TOE is evaluated against the SFRs (see below) established in its ST, no more and no less. This allows vendors to tailor the evaluation to accurately match the intended capabilities of their product. This means that a network firewall does not have to meet the same functional requirements as a database management system, and that different firewalls may in fact be evaluated against completely different lists of requirements. The ST is usually published so that potential customers may determine the specific security features that have been certified by the evaluation The evaluation process also tries to establish the level of confidence that may be placed in the product's security features through quality assurance processes: Security Assurance Requirements (SARs) - descriptions of the measures taken during development and evaluation of the product to assure compliance with the claimed security functionality. For example, an evaluation may require that all source code is kept in a change management system, or that full functional testing is performed. The Common Criteria provides a catalogue of these, and the requirements may vary from one evaluation to the next. The requirements for particular targets or types of products are documented in the ST and PP, respectively.
Evaluation Assurance Level (EAL) - the numerical rating describing the depth and rigor of an evaluation. Each EAL corresponds to a package of security assurance requirements (SARs, see above) which covers the complete development of a product, with a given level of strictness. Common Criteria lists seven levels, with EAL 1 being the most basic (and therefore cheapest to implement and evaluate) and EAL 7 being the most stringent (and most expensive). Normally, an ST or PP author will not select assurance requirements individually but choose one of these packages, possibly 'augmenting' requirements in a few areas with requirements from a higher level. Higher EALs do not necessarily imply "better security", they only mean that the claimed security assurance of the TOE has been more extensively verified.
Security Functional Requirements (SFRs) - specify individual security functions which may be provided by a product. The Common Criteria presents a standard catalogue of such functions. For example, a SFR may state how a user acting a particular role might be authenticated. The list of SFRs can vary from one evaluation to the next, even if two targets are the same type of product. Although Common Criteria does not prescribe any SFRs to be included in an ST, it identifies dependencies where the correct operation of one function (such as the ability to limit access according to roles) is dependent on another (such as the ability to identify individual roles).
So far, most PPs and most evaluated STs/certified products have been for IT components (e.g., firewalls, operating systems, smart cards). Common Criteria certification is sometimes specified for IT procurement. Other standards containing, e.g., interoperation, system management, user training, supplement CC and other product standards. Examples include the ISO/IEC 17799 (Or more properly BS 7799-1, which is now ISO/IEC 27002) or the German IT-Grundschutzhandbuch.
Details of cryptographic implementation within the TOE are outside the scope of the CC. Instead, national standards, like FIPS 140-2 give the specifications for cryptographic modules, and various standards specify the cryptographic algorithms in use.
More recently, PP authors are including cryptographic requirements for CC evaluations that would typically be covered by FIPS 140-2 evaluations, broadening the bounds of the CC through scheme-specific interpretations.
The following answers are incorrect:
1.Protection Profile, Security Target, Target of Evaluation
2.SFR, Protection Profile, Security Target, Target of Evaluation
4. SFR, Security Target, Protection Profile, Target of Evaluation
The following reference(s) were/was used to create this question: ISO/IEC 15408 Common Criteria for IT Security Evaluations and http://en.wikipedia.org/wiki/Common_Criteria

 

NEW QUESTION 579
Which of the following is NOT a property of a one-way hash function?

  • A. It converts a message of arbitrary length into a message digest of a fixed length.
  • B. It converts a message of a fixed length into a message digest of arbitrary length.
  • C. It is computationally infeasible to construct two different messages with the same digest.
  • D. Given a digest value, it is computationally infeasible to find the corresponding message.

Answer: B

Explanation:
An algorithm that turns messages or text into a fixed string of digits, usually for security or data management purposes. The "one way" means that it's nearly impossible to derive the original text from the string.
A one-way hash function is used to create digital signatures, which in turn identify and authenticate the sender and message of a digitally distributed message.
A cryptographic hash function is a deterministic procedure that takes an arbitrary block of data and returns a fixed-size bit string, the (cryptographic) hash value, such that an accidental or intentional change to the data will change the hash value. The data to be encoded is often called the "message," and the hash value is sometimes called the message digest or simply digest.
The ideal cryptographic hash function has four main or significant properties:
it is easy (but not necessarily quick) to compute the hash value for any given message it is infeasible to generate a message that has a given hash it is infeasible to modify a message without changing the hash it is infeasible to find two different messages with the same hash
Cryptographic hash functions have many information security applications, notably in digital signatures, message authentication codes (MACs), and other forms of authentication. They can also be used as ordinary hash functions, to index data in hash tables, for fingerprinting, to detect duplicate data or uniquely identify files, and as checksums to detect accidental data corruption. Indeed, in information security contexts, cryptographic hash values are sometimes called (digital) fingerprints, checksums, or just hash values, even though all these terms stand for functions with rather different properties and purposes.
Source:
TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.
and
http://en.wikipedia.org/wiki/Cryptographic_hash_function

 

NEW QUESTION 580
Which of the following questions is less likely to help in assessing an organization's contingency planning controls?

  • A. Are the backup storage site and alternate site geographically far enough from the primary site?
  • B. Is damaged media stored and/or destroyed?
  • C. Is there an up-to-date copy of the plan stored securely off-site?
  • D. Is the location of stored backups identified?

Answer: B

Explanation:
It also addresses how to keep an organization's critical functions operating in the
event of disruptions, large and small.
Handling of damaged media is an operational task related to regular production and is not specific
to contingency planning.
Source: SWANSON, Marianne, NIST Special Publication 800-26, Security Self-Assessment Guide
for Information Technology Systems, November 2001 (Pages A-27 to A-28).

 

NEW QUESTION 581
Packet Filtering Firewalls can also enable access for:

  • A. only unauthorized application port or service numbers.
  • B. only authorized application port or service integers.
  • C. only authorized application port or service numbers.
  • D. only authorized application port or ex-service numbers.

Answer: C

Explanation:
Explanation/Reference:
Explanation:
Packet filtering is a firewall technology that makes access decisions based upon network-level protocol header values. The filters can make access decisions based upon the following basic criteria:
Source and destination port numbers (such as an application port or a service number)

Protocol types

Source and destination IP addresses

Inbound and outbound traffic direction

Incorrect Answers:
B: Only authorized ports or service numbers, not unauthorized, would be granted access through the firewall.
C: Packet Filtering Firewalls do not grant access through ex-service numbers. They use service numbers.
D: Packet Filtering Firewalls do not grant access through service integers. A service has a number, not an integer.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 630

 

NEW QUESTION 582
Which of the following techniques is known to be effective in spotting resource exhaustion problems, especially with resources such as processes, memory, and connections?

  • A. Fuzzing
  • B. Automated dynamic analysis
  • C. Automated static analysis
  • D. Manual code review

Answer: B

Explanation:
Section: Software Development Security
Explanation

 

NEW QUESTION 583
Which of the following is the PRIMARY security concern associated with the implementation of smart cards?

  • A. Mobile code can be embedded in the card
  • B. The cards have limited memory
  • C. The cards can be misplaced
  • D. Vendor application compatibility

Answer: C

 

NEW QUESTION 584
Which of the following statements pertaining to using Kerberos without any extension is false?

  • A. Kerberos is mostly a third-party authentication protocol.
  • B. A client can be impersonated by password-guessing.
  • C. Kerberos provides robust authentication.
  • D. Kerberos uses public key cryptography.

Answer: D

Explanation:
Kerberos is a trusted, credential-based, third-party authentication protocol that uses symmetric (secret) key cryptography to provide robust authentication to clients accessing services on a network. Because a client's password is used in the initiation of the Kerberos request for the service protocol, password guessing can be used to impersonate a client.
Here is a nice overview of HOW Kerberos is implement as described in RFC 4556:
1 Introduction
The Kerberos V5 protocol [RFC4120] involves use of a trusted third party known as the Key Distribution Center (KDC) to negotiate shared session keys between clients and services and provide mutual authentication between them.
The corner-stones of Kerberos V5 are the Ticket and the Authenticator. A Ticket encapsulates a symmetric key (the ticket session key) in an envelope (a public message) intended for a specific service. The contents of the Ticket are encrypted with a symmetric key shared between the service principal and the issuing KDC. The encrypted part of the Ticket contains the client principal name, among other items. An Authenticator is a record that can be shown to have been recently generated using the ticket session key in the associated Ticket. The ticket session key is known by the client who requested the ticket. The contents of the Authenticator are encrypted with the associated ticket session key. The encrypted part of an Authenticator contains a timestamp and the client principal name, among other items.
As shown in Figure 1, below, the Kerberos V5 protocol consists of the following message exchanges between the client and the KDC, and the client and the application service:
-
The Authentication Service (AS) Exchange
The client obtains an "initial" ticket from the Kerberos authentication server (AS), typically a Ticket Granting Ticket (TGT). The AS-REQ message and the AS-REP message are the request and the reply message, respectively, between the client and the AS.
-
The Ticket Granting Service (TGS) Exchange
The client subsequently uses the TGT to authenticate and request a service ticket for a particular service, from the Kerberos ticket-granting server (TGS). The TGS-REQ message and the TGS-REP message are the request and the reply message respectively between the client and the TGS.
-
The Client/Server Authentication Protocol (AP) Exchange
The client then makes a request with an AP-REQ message, consisting
of a service ticket and an authenticator that certifies the
client's possession of the ticket session key. The server may
optionally reply with an AP-REP message. AP exchanges typically
negotiate session-specific symmetric keys.
Usually, the AS and TGS are integrated in a single device also known
as the KDC.
+--------------+
+--------->| KDC |
AS-REQ / +-------| |
/ / +--------------+
/ / ^ |
/ |AS-REP / |
| | / TGS-REQ + TGS-REP
| | / /
| | / /
| | / +---------+
| | / /
| | / /
| | / /
| v / v
++-------+------+ +-----------------+
| Client +------------>| Application |
| | AP-REQ | Server |
| |<------------| |
+---------------+ AP-REP +-----------------+
Figure 1: The Message Exchanges in the Kerberos V5 Protocol
In the AS exchange, the KDC reply contains the ticket session key,
among other items, that is encrypted using a key (the AS reply key)
shared between the client and the KDC. The AS reply key is typically
derived from the client's password for human users. Therefore, for
human users, the attack resistance strength of the Kerberos protocol
is no stronger than the strength of their passwords.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems
(page 40).
And
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, chapter
4: Access Control (pages 147-151). and http://www.ietf.org/rfc/rfc4556txt

 

NEW QUESTION 585
The underlying reason for creating a disaster planning and recover strategy is to

  • A. Enable a business to continue functioning without impact.
  • B. Mitigate risks associated with disaster.
  • C. Minimize financial profile.
  • D. Protect the organization's people, place and processes.

Answer: B

Explanation:
"Disaster recovery has the goal of minimizing the effects of a disaster and taking the necessary steps to ensure that the resources, personnel, and business processes are able to resume operation in a timely manner." Pg 550 Shon Harris: All-in-One CISSP Certification

 

NEW QUESTION 586
Refer to the information below to answer the question.
An organization has hired an information security officer to lead their security department.
The officer has adequate people resources but is lacking the other necessary components to have an effective security program. There are numerous initiatives requiring security involvement.
Given the number of priorities, which of the following will MOST likely influence the selection of top initiatives?

  • A. Complexity of strategy
  • B. Ongoing awareness
  • C. Frequency of incidents
  • D. Severity of risk

Answer: D

 

NEW QUESTION 587
Which choice below is considered the HIGHEST level of operator privilege?

  • A. Read Only
  • B. Write Only
  • C. Read/Write
  • D. Access Change

Answer: D

Explanation:
The correct answer is Access Change.
The three common levels of operator privileges,
based on the concept of least privilege, are:
Read Only Lowest level, view data only Read/Write View and modify data Access Change Highest level, right to change data/operator permissions Answer d is a distracter.

 

NEW QUESTION 588
......

Authentic Best resources for CISSP Online Practice Exam: https://www.examcollectionpass.com/ISC/CISSP-practice-exam-dumps.html

CISSP Test Engine Practice Exam: https://drive.google.com/open?id=1LdAGKv3aHwtP7CCtniAYBCq5k70QvSCn