CISSP-ISSAP Exam Questions
236 real CISSP-ISSAP exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51Architect for Governance, Risk, and Compliance
(ISC)2 CISSP-ISSAP Exam You are advising a school district on disaster recovery plans. In case a disaster affects the main IT centers for the district they will need to be able to...
Disaster Recovery PlanningCold SiteBusiness ContinuityCost Optimization - Question #52Identity and Access Management (IAM) Architecture
Which of the following are the centralized administration technologies? Each correct answer represents a complete solution. Choose all that apply.
RADIUSTACACS+AAA protocolsCentralized authentication - Question #53Identity and Access Management (IAM) Architecture
You are implementing some security services in an organization, such as smart cards, biometrics, access control lists, firewalls, intrusion detection systems, and clipping levels....
Logical access controlAuthentication mechanismsSystem access controlsControl classification - Question #54Infrastructure Security
You work as a Network Administrator for Net World Inc. You are required to configure a VLAN for the company. Which of the following devices will you use to physically connect the c...
VLAN configurationSwitchLayer 2Inter-VLAN routing - Question #55Infrastructure Security
Which of the following protocols work at the Network layer of the OSI model? (ISC)2 CISSP-ISSAP Exam
OSI Layer 3Routing protocolsIGMPProtocol classification - Question #56Infrastructure Security
Which of the following are used to suppress paper or wood fires? Each correct answer represents a complete solution. Choose two.
Fire SuppressionClass A FiresExtinguishing Agents - Question #57Infrastructure Security
Mark works as a Network Administrator for NetTech Inc. He wants to connect the company's headquarter and its regional offices using a WAN technology. For this, he uses packet-switc...
Packet-switched WANX.25Frame RelayWAN protocols - Question #59Architect for Governance, Risk, and Compliance
In which of the following types of tests are the disaster recovery checklists distributed to the members of disaster recovery team and asked to review the assigned checklist?
Disaster Recovery TestingChecklist TestBusiness Continuity PlanningContinuity Testing - Question #60Infrastructure Security
Which of the following heights of fence deters only casual trespassers?
Physical perimeter securityFence standardsPhysical barriersAccess control - Question #61Security Architecture Modeling
In which of the following cryptographic attacking techniques does an attacker obtain encrypted messages that have been encrypted using the same encryption algorithm?
Ciphertext-only attackCryptanalysisAttack classificationEncryption vulnerabilities - Question #62Architect for Governance, Risk, and Compliance
Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?
Annualized Rate of OccurrenceRisk QuantificationThreat Frequency - Question #63Infrastructure Security
You work as a Chief Security Officer for Tech Perfect Inc. The company has a TCP/IP based network. You want to use a firewall that can track the state of active connections of the...
Stateful firewallPacket filteringConnection trackingNetwork security - Question #65Identity and Access Management (IAM) Architecture
Which of the following uses a Key Distribution Center (KDC) to authenticate a principle?
KerberosKey Distribution CenterAuthentication ProtocolsIdentity Authentication - Question #66Identity and Access Management (IAM) Architecture
Which of the following is a network service that stores and organizes information about a network users and network resources and that allows administrators to manage users' access...
Directory ServiceUser ManagementAccess Control - Question #67Infrastructure Security
You work as a Network Administrator for Net Soft Inc. You are designing a data backup plan for your company's network. The backup policy of the company requires high security and e...
Data backup strategyOffsite backupDisaster recoveryTape rotation - Question #68Security Architecture Modeling
Which of the following are types of asymmetric encryption algorithms? Each correct answer represents a complete solution. Choose two.
Public Key CryptographyRSAECCAsymmetric Encryption - Question #69Infrastructure Security
Which of the following attacks allows the bypassing of access control lists on servers or routers, and helps an attacker to hide? Each correct answer represents a complete solution...
MAC spoofingIP spoofingAccess Control ListsNetwork attacks - Question #70Identity and Access Management (IAM) Architecture
You are the Network Administrator at a large company. Your company has a lot of contractors and other outside parties that come in and out of the building. For this reason you are...
Hardware tokensMulti-factor authenticationCHAP protocolSmart cards - Question #71Infrastructure Security
Which of the following LAN protocols use token passing for exchanging signals among various stations on the network? Each correct answer represents a complete solution. Choose two.
Token RingFDDIToken PassingMAC protocols - Question #72Infrastructure Security
Which of the following components come under the network layer of the OSI model? Each correct answer represents a complete solution. Choose two.
Network LayerOSI ModelRoutersFirewalls - Question #73Infrastructure Security
Which of the following are examples of physical controls used to prevent unauthorized access to sensitive materials?
Physical ControlsAccess ControlPhysical SecurityPerimeter Security - Question #74Infrastructure Security
At which of the following layers of the Open System Interconnection (OSI) model the Internet Control Message Protocol (ICMP) and the Internet Group Management Protocol (IGMP) work?
ICMP protocolIGMP protocolOSI ModelNetwork layer - Question #75Infrastructure Security
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
NTFS EFSDigital certificatesPublic key cryptographyHybrid encryption - Question #76Identity and Access Management (IAM) Architecture
Which of the following statements about Discretionary Access Control List (DACL) is true?
DACLWindows ACLDiscretionary Access ControlAccess Control Entries - Question #77Infrastructure Security
(ISC)2 CISSP-ISSAP Exam Which of the following methods will allow data to be sent on the Internet in a secure format?
VPNSecure Data TransmissionEncrypted Tunneling - Question #78Infrastructure Security
Which of the following are used to suppress electrical and computer fires? Each correct answer represents a complete solution. Choose two.
Fire suppressionHalonCO2Electrical fires - Question #79Architect for Governance, Risk, and Compliance
Which of the following are natural environmental threats that an organization faces? Each correct answer represents a complete solution. Choose two.
Natural disastersRisk assessmentBusiness continuityThreat classification - Question #80Infrastructure Security
Which of the following keys are included in a certificate revocation list (CRL) of a public key infrastructure (PKI)? Each correct answer represents a complete solution. Choose two...
PKICertificate RevocationKey ManagementDigital Certificates - Question #81Security Architecture Modeling
Which of the following SDLC phases consists of the given security controls: Misuse Case Modeling Security Design and Architecture Review Threat and Risk Modeling Security Requireme...
SDLC Design PhaseThreat ModelingSecurity Architecture ReviewMisuse Case Modeling - Question #82Identity and Access Management (IAM) Architecture
A company named Money Builders Inc., hires you to provide consultancy for setting up their Windows network. The company's server room will be in a highly secured environment. You a...
Biometric authenticationFingerprint recognitionAuthentication methodsAccess control - Question #83Security Architecture Modeling
You are the Security Consultant and have been contacted by a client regarding their encryption and hashing algorithms. Their in-house network administrator tells you that their cur...
MD5 hashingCollision resistanceDeprecated algorithmsCryptographic weaknesses - Question #84Infrastructure Security
You work as a Network Administrator for Net Perfect Inc. The company has a Linux-based network. You need to configure a firewall for the company. The firewall should be able to kee...
Stateful FirewallConnection State TrackingFirewall ConfigurationLinux Network Security - Question #85Identity and Access Management (IAM) Architecture
Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptiti...
shoulder surfingsocial engineeringphysical securityauthentication - Question #86Architect for Governance, Risk, and Compliance
Which of the following plans is designed to protect critical business processes from natural or man-made failures or disasters and the resultant loss of capital due to the unavaila...
Business Continuity PlanningDisaster RecoveryBusiness ResilienceRisk Management - Question #87Infrastructure Security
Which of the following processes is used by remote users to make a secure connection to internal resources after establishing an Internet connection?
VPN tunnelingRemote access securitySecure connectionsTunneling protocols - Question #88Architect for Governance, Risk, and Compliance
You work as a Security Manager for Tech Perfect Inc. A number of people are involved with you in the DRP efforts. You have maintained several different types of plan documents, int...
Disaster Recovery PlanningExecutive SummaryStakeholder CommunicationDRP Documentation - Question #89Infrastructure Security
Which of the following protects against unauthorized access to confidential information via encryption and works at the network layer? (ISC)2 CISSP-ISSAP Exam
IPSecNetwork LayerEncryptionConfidentiality - Question #90Infrastructure Security
Which of the following statements are true about Public-key cryptography? Each correct answer represents a complete solution. Choose two.
Asymmetric cryptographyPublic/private key pairsDigital signaturesPKI fundamentals - Question #91Infrastructure Security
Which of the following backup types backs up files that have been added and all data that have been modified since the most recent backup was performed?
Incremental backupBackup strategiesDisaster recoveryData protection - Question #92Identity and Access Management (IAM) Architecture
You are responsible for security at a hospital. Since many computers are accessed by multiple employees 24 hours a day, 7 days a week, controlling physical access to computers is v...
Smart Card AuthenticationIdentity AuthenticationLogical Access ControlShared Workstations - Question #93Security Architecture Modeling
In which of the following cryptographic attacking techniques does the attacker pick up the information to be encrypted and take a copy of it with the encrypted data?
Cryptographic attacksChosen plaintext attackCryptanalysisEncryption - Question #94Infrastructure Security
Which of the following are the goals of a public key infrastructure (PKI)? Each correct answer represents a part of the solution. Choose all that apply.
Public Key InfrastructureDigital CertificatesCryptographic GoalsNonrepudiation - Question #95Security Architecture Modeling
Which of the following encryption modes has the property to allow many error correcting codes to function normally even when applied before encryption?
OFB modeError correcting codesStream cipher modesCipher mode error propagation - Question #96Architect for Application Security
In which of the following phases of the SDLC does the software and other components of the system faithfully incorporate the design specifications and provide proper documentation...
SDLC phasesProgramming phaseSystem documentationImplementation - Question #97Identity and Access Management (IAM) Architecture
You are the administrator for YupNo.com. You want to increase and enhance the security of your computers and simplify deployment. You are especially concerned with any portable com...
Smart Card AuthenticationMulti-factor AuthenticationRemote Access ControlPortable Device Security - Question #98Infrastructure Security
You have just set up a wireless network for customers at a coffee shop. Which of the following are good security measures to implement? Each correct answer represents a complete so...
Wireless SecurityEncryption StandardsNetwork Access ControlWPA/WEP - Question #99Infrastructure Security
Which of the following protocols provides the highest level of VPN security with a VPN connection that uses the L2TP protocol?
L2TP/IPSecVPN encryptionTunnel protocolsData confidentiality - Question #100Security Architecture Modeling
Which of the following encryption methods comes under symmetric encryption algorithm? Each correct answer represents a complete solution. Choose three.
Symmetric encryptionDESBlowfishRC5 - Question #101Infrastructure Security
Which of the following uses public key cryptography to encrypt the contents of files?
EFSPublic Key CryptographyFile-level EncryptionWindows Security - Question #102Identity and Access Management (IAM) Architecture
An access control secures the confidentiality, integrity, and availability of the information and data of an organization. In which of the following categories can you deploy the a...
Detective Access ControlPreventive Access ControlCorrective Access ControlCIA Implementation