CISSP Exam Questions
1,535 real CISSP exam questions with expert-verified answers and explanations. Page 11 of 31.
- Question #501Communication and Network Security
Utilizing a public wireless Local Area network (WLAN) to connect to a private network should be done only in which of the following situations?
Public Wi-Fi securityVPNpersonal firewallnetwork security - Question #502Security Architecture and Engineering
Which of the following technologies would provide the BEST alternative to anti-malware software?
Application whitelistinganti-malware alternativeendpoint securitypreventative controls - Question #503Asset Security
Which of the following is MOST critical in a contract in a contract for data disposal on a hard drive with a third party?
Data disposalsecure erasurethird-party contractsasset sanitization - Question #504Security Architecture and Engineering
Which of the following attributes could be used to describe a protection mechanism of an open design methodology?
Open designsecurity principlesindependent reviewdesign security - Question #505Security and Risk Management
What is a common mistake in records retention?
Records retentiondata lifecyclelegal compliancepolicy mistakes - Question #506Identity and Access Management
Which inherent password weakness does a One Time Password (OTP) generator overcome?
One-time password (OTP)password weaknessauthentication factorscredential compromise - Question #507Identity and Access Management
What is the BEST way to establish identity over the internet?
Remote authenticationhardware tokensRADIUSstrong authentication - Question #508Security and Risk Management
The threat modeling identifies a man-in-the-middle (MITM) exposure. Which countermeasure should the information system security officer (ISSO) select to mitigate the risk of a prot...
Man-in-the-middle (MITM)data leak preventionprotected health information (PHI)data anonymization - Question #509Security Architecture and Engineering
Which security architecture strategy could be applied to secure an operating system (OS) baseline for deployment within the corporate enterprise?
OS hardeningsecurity baselinesecure defaultsecurity architecture principles - Question #510Security and Risk Management
What does the term "100-year floodplain" mean to emergency preparedness officials?
Risk assessmentnatural disasterfloodplainemergency preparedness - Question #511Communication and Network Security
Which layer of the Open system Interconnect (OSI) model is responsible for secure data transfer between applications, flow control, and error detection and correction?
OSI modelTransport Layerflow controlerror detection - Question #512Security Operations
Which of the following is the PRIMARY consideration when determining the frequency an automated control should be assessed or monitored?
Security controlsmonitoring frequencycontrol assessmentvolatility - Question #513Security and Risk Management
An organization that has achieved a Capability Maturity model Integration (CMMI) level of 4 has done which of the following?
CMMIprocess maturityquality managementorganizational processes - Question #514Security and Risk Management
What is the MOST effective way to protect privacy?
Data privacydata minimizationprivacy by designpersonal information - Question #515Communication and Network Security
Internet protocol security (IPSec), point-to-point tunneling protocol (PPTP), and secure sockets Layer (SSL) all use Which of the following to prevent replay attacks?
Replay attacksnoncesIPSecSSL/TLS - Question #516Security Operations
Which of the following job functions MUST be separated to maintain data and application integrity?
Separation of dutiesdata integrityapplication integrityproduction control - Question #517Identity and Access Management
Which of the following authorization standards is built to handle Application programming Interface (API) access for federated Identity management (FIM)?
OAuthAPI securityfederated identityauthorization standards - Question #518Security and Risk Management
What is the MOST effective way to determine a mission critical asset in an organization?
Mission-critical assetsbusiness process analysisasset valuationbusiness continuity - Question #519Security and Risk Management
Information security metrics provide the GREATEST value tp management when based upon the security manager's knowledge of which of the following?
Security metricsinformation asset valuemanagement reportingrisk management - Question #520Security Assessment and Testing
Who determines the required level of independence for security control Assessors (SCA)?
Authorizing Official (AO)security control assessor (SCA)independencesecurity governance - Question #521Security Architecture and Engineering
What high Availability (HA) option of database allows multiple clients to access multiple database servers simultaneously?
database HAreplicationhigh availability - Question #522Asset Security
Which is the best way to ensure camera security?
device securityauthenticationIoT securityphysical security systems - Question #523Security and Risk Management
Which of the following is considered the last line defense in regard to a Governance, Risk managements, and compliance (GRC) program?
GRCinternal auditcompliancegovernance - Question #524Security and Risk Management
Which of the following can be used to calculate the loss event probability?
risk assessmentprobability calculationloss event probability - Question #525Security and Risk Management
Which of the following is applicable to a publicly held company concerned about information handling and storage requirement specific to the financial reporting?
regulatory complianceSOXfinancial reportingdata handling laws - Question #526Security Operations
Which of the following is used to detect steganography?
steganography detectionstatistical analysisinformation hiding - Question #527Security Operations
Which is the MOST critical aspect of computer-generated evidence?
digital forensicsevidence integritychain of custody - Question #528Asset Security
Which of the following media is LEAST problematic with data remanence?
data remanencememory typesdata sanitization - Question #529Identity and Access Management
Which open standard could l large corporation deploy for authorization services for single sign-on (SSO) use across multiple internal and external application?
SSOSAMLfederated identityauthorization standards - Question #530Software Development Security
Which of the following statements is TRUE regarding equivalence class testing?
software testingequivalence class testingquality assurance - Question #531Communication and Network Security
A large corporation is looking for a solution to automate access based on where the request is coming from, who the user is, what device they are connecting with, and what and time...
NACcontext-aware accessaccess controlnetwork security - Question #532Security Operations
Which of the following techniques is MOST useful when dealing with Advanced persistent Threat (APT) intrusions on live virtualized environments?
APTmemory forensicsvirtualization securityincident response - Question #533Security and Risk Management
Which of the following MUST an organization do to effectively communicate is security strategy to all affected parties?
security awarenesssecurity communicationorganizational security strategy - Question #534Identity and Access Management
When using Security Assertion markup language (SAML), it is assumed that the principal subject
SAMLidentity providerfederated identitySSO - Question #535Security Assessment and Testing
A client has reviewed a vulnerability assessment report and has stated it is inaccurate. The client states that the vulnerabilities listed are not valid because the host's Operatin...
vulnerability assessmentdiscovery phaseOS fingerprintingscanning errors - Question #536Security and Risk Management
Which of the below strategies would MOST comprehensively address the risk of malicious insiders leaking sensitive information?
insider threatDLPleast privilegestaff vettingdata leakage prevention - Question #537Asset Security
What is the FIRST step required in establishing a records retention program?
records retentiondata lifecycle managementinformation governancedata inventory - Question #538Software Development Security
Functional security testing is MOST critical during which phase of the system development life cycle (SDLC)?
SDLCfunctional security testingsecurity in developmentsoftware assurance - Question #539Software Development Security
What is the threat modeling order using process for Attack simu-lation and threat analysis (PASTA)?
threat modelingPASTAapplication securityrisk assessment methodology - Question #540Communication and Network Security
Which is the RECOMMENDED configuration mode for sensors for an intrusion prevention system (IPS) if the prevention capabilities will be used?
IPSintrusion preventionnetwork securityinline mode - Question #541Communication and Network Security
An organization implements a remote access server (RAS), Once users connect to the server, digital certificates are used to authenticate their identity. What type of extensible Aut...
EAPdigital certificatesTLSauthentication protocols - Question #542Asset Security
An analysis finds unusual activity coming from a computer that was thrown away several months prior, which of the following steps ensure the proper removal of the system?
asset disposalsystem decommissioningdata sanitizationasset lifecycle - Question #543Security and Risk Management
As a security manger which of the following is the MOST effective practice for providing value to an organization?
risk managementbusiness alignmentsecurity strategyresource allocation - Question #544Security Operations
Which of the following BEST provides for non-repudiation od user account actions?
non-repudiationloggingauditingsecurity principles - Question #545Identity and Access Management (IAM)
What type of access control determines the authorization to resource based on pre-defined job titles within an organization?
RBACaccess control modelsauthorization - Question #546Identity and Access Management (IAM)
As users switch roles within an organization, their accounts are given additional permissions to perform the duties of their new position. After a recent audit, it was discovered t...
privilege creepaccess reviewuser provisioningIAM lifecycle - Question #547Security and Risk Management
Continuity of operations is BEST supported by which of the following?
business continuitydisaster recoveryavailabilityreliability - Question #548Security and Risk Management
Which of the following is true of Service Organization Control (SOC) reports?
SOC reportsthird-party riskauditing standardsservice organizations - Question #549Software Development Security
What testing technique enables the designer to develop mitigation strategies for potential vulnerabilities?
threat modelingvulnerability assessmentsecurity designmitigation strategies - Question #550Communication and Network Security
Asymmetric algorithms are used for which of the following when using Secure Sockets Layer/Transport Layer Security (SSL/TLS) for implementing network security?
TLS handshakeasymmetric encryptionauthenticationdigital certificates