CISSP-ISSAP Exam Questions
236 real CISSP-ISSAP exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #103Identity and Access Management (IAM) Architecture
You are the Network Administrator for a bank. In addition to the usual security issues, you are concerned that your customers could be the victim of phishing attacks that use fake...
Mutual authenticationPhishing preventionServer authenticationTLS/SSL - Question #104Security Architecture Modeling
You are responsible for security at a defense contracting firm. You are evaluating various possible encryption algorithms to use. One of the algorithms you are examining is not int...
Elliptic Curve CryptographyPublic Key EncryptionCryptographic AlgorithmsKey Strength - Question #105Architect for Governance, Risk, and Compliance
Single Loss Expectancy (SLE) represents an organization's loss from a single threat. Which of the following formulas best describes the Single Loss Expectancy (SLE)?
Risk QuantificationSLE CalculationAsset ValuationExposure Factor - Question #106Architect for Governance, Risk, and Compliance
Which of the following are man-made threats that an organization faces? Each correct answer represents a complete solution. Choose three.
Threat classificationMan-made threatsOrganizational risk - Question #107Architect for Governance, Risk, and Compliance
Which of the following methods for identifying appropriate BIA interviewees' includes examining the organizational chart of the enterprise to understand the functional positions?
BIAOrganizational ChartsStakeholder IdentificationBusiness Continuity - Question #108Architect for Governance, Risk, and Compliance
Which of the following describes the acceptable amount of data loss measured in time?
RPODisaster RecoveryBusiness ContinuityRecovery Planning - Question #109Identity and Access Management (IAM) Architecture
In which of the following access control models, owner of an object decides who is allowed to access the object and what privileges they have?
Discretionary Access Control (DAC)Access Control ModelsOwner-based authorizationIAM - Question #110Infrastructure Security
Which of the following is the process of finding weaknesses in cryptographic algorithms and obtaining the plaintext or key from the ciphertext?
CryptanalysisCryptographic attacksKey recovery - Question #111Infrastructure Security
Which of the following encryption algorithms is used by the Clipper chip, which supports the escrowed encryption standard?
SkipjackClipper chipKey escrowEscrowed encryption standard - Question #112Infrastructure Security
Which of the following statements about Network Address Translation (NAT) are true? Each correct answer represents a complete solution. Choose three.
NATIP translationNetwork perimeter securityPrivate-public IP mapping - Question #113Identity and Access Management (IAM) Architecture
An organization has implemented a hierarchical-based concept of privilege management in which administrators have full access, HR managers have less permission than the administrat...
RBACAccess Control ModelsPrivilege ManagementRole Hierarchy - Question #114Security Operations Architecture
Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an ente...
Incident Response PreparationIncident Handling PhasesCrisis ManagementBusiness Continuity Planning - Question #115Identity and Access Management (IAM) Architecture
Which of the following is an entry in an object's discretionary access control list (DACL) that grants permissions to a user or group?
DACLACEAccess ControlAuthorization - Question #116Identity and Access Management (IAM) Architecture
Access control systems enable an authority to control access to areas and resources in a given physical facility or computer-based information system. Which of the following servic...
AuthorizationAccess ControlIAM ServicesCISSP Fundamentals - Question #117Security Architecture Modeling
You work as a Security Manager for Tech Perfect Inc. The management tells you to implement a hashing method in the organization that can resist forgery and is not open to the man-i...
Message Authentication CodeCryptographic hashingMITM resistanceData integrity - Question #118Infrastructure Security
You work as a Network Administrator for company Inc. The company has deployed an ASA at the network perimeter. Which of the following types of firewall will you use to create two d...
Proxy FirewallASACircuit-level GatewayNetwork Perimeter - Question #119Security Architecture Modeling
You are the Security Administrator for a consulting firm. One of your clients needs to encrypt traffic. However, he has specific requirements for the encryption algorithm. It must...
Symmetric EncryptionBlock CiphersCryptographic AlgorithmsDES - Question #120Identity and Access Management (IAM) Architecture
You work as an administrator for Techraft Inc. Employees of your company create 'products', which are supposed to be given different levels of access. You need to configure a secur...
Discretionary Access ControlAccess control modelsPrivilege delegationAccess authorization - Question #121Identity and Access Management (IAM) Architecture
Which of the following decides access control on an object in the mandatory access control (MAC) environment?
Mandatory Access ControlSensitivity LabelsAccess Decision MechanismSecurity Classification - Question #122Infrastructure Security
Which of the following protocols should a Chief Security Officer configure in the network of his company to protect sessionless datagram protocols?
SKIP ProtocolDatagram SecurityNetwork SecurityProtocol Selection - Question #123Infrastructure Security
Which of the following protocols supports encapsulation of encrypted packets in secure wrappers that can be transmitted over a TCP/IP connection?
PPTPVPN tunnelingEncapsulationTunnel protocols - Question #124Infrastructure Security
You work as a remote support technician. A user named Rick calls you for support. Rick wants to connect his LAN connection to the Internet. Which of the following devices will you...
Network RoutingInternet ConnectivityNetwork DevicesLayer 3 - Question #125Identity and Access Management (IAM) Architecture
Which of the following user authentications are supported by the SSH-1 protocol but not by the SSH-2 protocol? Each correct answer represents a complete solution. Choose all that a...
SSH-1 protocolSSH-2 protocolKerberosRhosts - Question #126Infrastructure Security
Fill in the blank with the appropriate encryption system. The ______ encryption system is an asymmetric key encryption algorithm for the public-key cryptography, which is based on...
ElGamalAsymmetric EncryptionDiffie-HellmanPublic-Key Cryptography - Question #127Security Operations Architecture
You are the Network Administrator for a large corporate network. You want to monitor all network traffic on your local network for suspicious activities and receive a notification...
Network-based IDSIntrusion DetectionNetwork Traffic MonitoringAttack Detection - Question #128Infrastructure Security
You work as a Network Administrator for McRoberts Inc. You are expanding your company's network. After you have implemented the network, you test the connectivity to a remote host...
ICMPOSI ModelNetwork TestingLayer Analysis - Question #129Infrastructure Security
In which of the following Person-to-Person social engineering attacks does an attacker pretend to be an outside contractor, delivery person, etc., in order to gain physical access...
Social EngineeringImpersonationPhysical AccessPretexting - Question #130Infrastructure Security
You work as a Chief Security Officer for Tech Perfect Inc. The company has an internal room without any window and is totally in darkness. For security reasons, you want to place a...
Motion DetectionPhysical SecurityFacility ControlsEnvironmental Security - Question #131Infrastructure Security
John works as an Ethical Hacker for company Inc. He wants to find out the ports that are open in company's server using a port scanner. However, he does not want to establish a ful...
Port scanningTCP SYN scanNetwork reconnaissanceEthical hacking - Question #132Security Architecture Modeling
Which of the following layers of the OSI model provides non-repudiation services?
Non-repudiationOSI ModelApplication LayerDigital signatures - Question #133Infrastructure Security
You work as a Network Administrator for McNeil Inc. The company has a TCP/IP-based network. Performance of the network is slow because of heavy traffic. A hub is used as a central...
LAN switchesNetwork traffic controlNetwork device selectionHub vs switch - Question #134Infrastructure Security
Which of the following categories of access controls is deployed in the organization to prevent all direct contacts with systems?
Physical Access ControlFacility SecurityPerimeter DefenseSystem Protection - Question #135Infrastructure Security
Which of the following is an infrastructure system that allows the secure exchange of data over an unsecured network?
PKIdigital certificatesencryptionasymmetric cryptography - Question #136Infrastructure Security
Which of the following algorithms is found to be suitable for both digital signature and encryption?
RSADigital SignaturesAsymmetric CryptographyPublic Key Infrastructure - Question #137Identity and Access Management (IAM) Architecture
Which of the following is responsible for maintaining certificates in a public key infrastructure (PKI)?
Certification AuthorityPKI CertificatesCertificate ManagementX.509 - Question #138Identity and Access Management (IAM) Architecture
Which of the following authentication methods is based on physical appearance of a user?
BiometricsAuthentication factorsIdentity verificationPhysical characteristics - Question #139Infrastructure Security
Which of the following is a correct sequence of different layers of Open System Interconnection (OSI) model?
OSI modelNetwork layersNetwork architecture - Question #140Infrastructure Security
Which of the following are used to suppress gasoline and oil fires? Each correct answer represents a complete solution. Choose three.
Fire suppression systemsClass B firesFire extinguishing agents - Question #141Architect for Governance, Risk, and Compliance
Fill in the blank with the appropriate phrase. The is a simple document that provides a high-level view of the entire organization's disaster recovery efforts. Answer: Executive su...
disaster recovery planningbusiness continuityexecutive summaryDR documentation - Question #142Infrastructure Security
You work as a Chief Security Officer for Tech Perfect Inc. You have configured IPSec and ISAKMP protocol in the company's network in order to establish a secure communication infra...
ISAKMP protocolIPSecKey managementPeer authentication - Question #143Security Architecture Modeling
Which of the following methods offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling?
Service-Oriented Modeling FrameworkArchitecture modelingLifecycle managementSOA design - Question #144Infrastructure Security
The Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and procedures needed to create, manage, distribute, use, store, and revoke digital certificat...
Certificate Revocation ListPKI ComponentsDigital CertificatesCryptography - Question #145Security Operations Architecture
You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it i...
Incident Response PhasesEmail SecurityEradicationRecovery - Question #146Infrastructure Security
Which of the following ports must be opened on the firewall for the VPN connection using Point-to- Point Tunneling Protocol (PPTP)?
PPTPVPN protocolsFirewall configurationPort 1723 - Question #147Architect for Governance, Risk, and Compliance
Which of the following plans is a comprehensive statement of consistent actions to be taken before, during, and after a disruptive event that causes a significant loss of informati...
Disaster Recovery PlanBusiness ContinuityContingency Planning - Question #148Identity and Access Management (IAM) Architecture
Perfect World Inc., provides its sales managers access to the company's network from remote locations. The sales managers use laptops to connect to the network. For security purpos...
Smart Card AuthenticationEAPRemote AccessAuthentication Protocols - Question #149Architect for Governance, Risk, and Compliance
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of...
Disaster Recovery TestingSimulation TestingBusiness Continuity PlanningRecovery Procedures - Question #150Infrastructure Security
Your customer is concerned about security. He wants to make certain no one in the outside world can see the IP addresses inside his network. What feature of a router would accompli...
NATIP maskingRouter configuration - Question #151Infrastructure Security
You are responsible for a Microsoft based network. Your servers are all clustered. Which of the following are the likely reasons for the clustering? Each correct answer represents...
Server ClusteringHigh AvailabilityFailoverInfrastructure Design - Question #152Identity and Access Management (IAM) Architecture
Which of the following is the most secure method of authentication? (ISC)2 CISSP-ISSAP Exam
BiometricsAuthentication MethodsSecurity ControlsAccess Control