CISSP 50 Question Quiz

Which of the following would security personnel do during the remediation stage of an incident response?

Which one of the following is not a principle of Agile development?

Which of the following types of access control uses fences, security policies, security awareness training, and antivirus software to stop an unwanted or unauthorised activity from occurring?

Which one of the following types of attacks relies on the difference between the timing of two events?

Which of the following best identifies the benefit of a passphrase?

A central authority determines which file a user can access based on the organisation's hierarchy. Which of the following best describes this?

What ensures that the subject of an activity or event cannot deny that the event occurred?

What form of access control is primarily concerned with the data stored by a field?

What HTML tag is often used as part of a cross-site scripting (XSS) attack?

What kind of attack makes the Caesar cipher virtually unusable?

Which federal government agency has responsibility for ensuring the security of government computer systems that are not used to process sensitive and/or classified information?

What type of electrical component serves as the primary building block for dynamic RAM chips?

What type of interface testing would identify flaws in a program's command-line interface?

If somebody has developed a company formula that they would like to keep secret for as long as possible. What type of intellectual property protection best suits their needs?

Which one of the following is not normally included in a security assessment?

Which one of the following tests provides the most accurate and detailed information about the security state of a server?

What type of reconnaissance attack provides attackers with useful information about the services running on a system?

Some cloud-based service models require an organisation to perform some maintenance and take responsibility for some security. Which of the following is a service model that places most of these responsibilities on the organisation leasing the cloud-based resources?

During what type of penetration test does the tester always have access to the system configuration?

Which one of the following Data Encryption Standard (DES) operating modes can be used for large messages with the assurance that an error early in the encryption/decryption process won't spoil results throughout the communication?

Which one of the following storage devices is most likely to require encryption technology in order to maintain data security in a networked environment?

What portion of the change management process allows developers to prioritise tasks?

What approach to failure management places the system in a high level of security?

Which one of the following factors should not be taken into consideration when planning a security testing schedule for a particular system?

Which of the following is not a valid definition for risk?

Which of the following is a primary purpose of an exit interview?

What is both a benefit and a potentially harmful implication of multilayer protocols?

Which one of the following technologies is considered flawed and should no longer be used?

What database technology, if implemented for web forms, can limit the potential for SQL injection attacks?

What type of memory is directly available to the CPU and is often part of the CPU?

What is the main purpose of a military and intelligence attack?

Which of the following is not a security-focused design element of a facility or site?

What port is typically used to accept administrative connections using the SSH utility?

Which of the following is not a valid access control model?

Which one of the following risks is least likely to be adequately addressed by a quantitative risk assessment?

What is the typical time estimate to activate a warm site from the time a disaster is declared?

What is encapsulation?

If you were to build a databse table consisting of the names, telephone numbers, and customer IDs for a business and then insert information on 30 customers. What is the degree of this table?

What is the primary objective of data classification schemes?

In which of the following database recovery techniques is an exact, up-to-date copy of the database maintained at an alternative location?

What type of application vulnerability most directly allows an attacker to modify the content of a system's memory?

Which one of the following BIA terms identifies the amount of money a business expects to lose to a given risk each year?

An aircraft manufacturer expects that it would lose $10 million if a tornado struck its aircraft operations facility. It expects that a tornado might strike the facility once every 100 years. What is the annualised loss expectancy?

What type of disaster recovery plan test fully evaluates operations at the backup facility but does not shift primary operations responsibility from the main site?

Which criminal law first implemented penalties for the creators of viruses, worms, and other types of malware?

Which one of the following tools provides a solution to the problem of users forgetting complex passwords?

How does a SYN flood attack work?

What is the best type of water-based fire suppression system for a computer facility?

During an operational investigation, what type of analysis might an organisation undertake to prevent similar incidents in the future?

Which of the following is not a routing protocol?

