CISSP Exam Info and Free Practice Test Professional Quiz Study Materials
Accurate Hot Selling CISSP Exam Dumps 2025 Newly Released
ISC2 CISSP Exam Syllabus Topics:
| Topic | Details |
Security and Risk Management - 15% | |
| Understand, adhere to, and promote professional ethics | - (ISC)2 Code of Professional Ethics - Organizational code of ethics |
| Understand and apply security concepts | - Confidentiality, integrity, and availability, authenticity and nonrepudiation |
| Evaluate and apply security governance principles | - Alignment of the security function to business strategy, goals, mission, and objectives - Organizational processes (e.g., acquisitions, divestitures, governance committees) - Organizational roles and responsibilities - Security control frameworks - Due care/due diligence |
| Determine compliance and other requirements | - Contractual, legal, industry standards, and regulatory requirements - Privacy requirements |
| Understand legal and regulatory issues that pertain to information security in a holistic context | - Cybercrimes and data breaches - Licensing and Intellectual Property (IP) requirements - Import/export controls - Transborder data flow - Privacy |
| Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards) | |
| Develop, document, and implement security policy, standards, procedures, and guidelines | |
| Identify, analyze, and prioritize Business Continuity (BC) requirements | - Business Impact Analysis (BIA) - Develop and document the scope and the plan |
| Contribute to and enforce personnel security policies and procedures | - Candidate screening and hiring - Employment agreements and policies - Onboarding, transfers, and termination processes - Vendor, consultant, and contractor agreements and controls - Compliance policy requirements - Privacy policy requirements |
| Understand and apply risk management concepts | - Identify threats and vulnerabilities - Risk assessment/analysis - Risk response - Countermeasure selection and implementation - Applicable types of controls (e.g., preventive, detective, corrective) - Control assessments (security and privacy) - Monitoring and measurement - Reporting - Continuous improvement (e.g., Risk maturity modeling) - Risk frameworks |
| Understand and apply threat modeling concepts and methodologies | |
| Apply Supply Chain Risk Management (SCRM) concepts | - Risks associated with hardware, software, and services - Third-party assessment and monitoring - Minimum security requirements - Service level requirements |
| Establish and maintain a security awareness, education, and training program | - Methods and techniques to present awareness and training (e.g., social engineering, phishing, security champions, gamification) - Periodic content reviews - Program effectiveness evaluation |
Asset Security - 10% | |
| Identify and classify information and assets | - Data classification - Asset Classification |
| Establish information and asset handling requirements | |
| Provision resources securely | - Information and asset ownership - Asset inventory (e.g., tangible, intangible) - Asset management |
| Manage data lifecycle | - Data roles (i.e., owners, controllers, custodians, processors, users/subjects) - Data collection - Data location - Data maintenance - Data retention - Data remanence - Data destruction |
| Ensure appropriate asset retention (e.g., End-of-Life (EOL), End-of-Support (EOS)) | |
| Determine data security controls and compliance requirements | - Data states (e.g., in use, in transit, at rest) - Scoping and tailoring - Standards selection - Data protection methods (e.g., Digital Rights Management (DRM), Data Loss Prevention (DLP), Cloud Access Security Broker (CASB)) |
Security Architecture and Engineering - 13% | |
| Research, implement and manage engineering processes using secure design principles | - Threat modeling - Least privilege - Defense in depth - Secure defaults - Fail securely - Separation of Duties (SoD) - Keep it simple - Zero Trust - Privacy by design - Trust but verify - Shared responsibility |
| Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula) | |
| Select controls based upon systems security requirements | |
| Understand security capabilities of information systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption) | |
| Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements | - Client-based systems - Server-based systems - Database systems - Cryptographic systems - Industrial Control Systems (ICS) - Cloud-based systems (e.g., Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS)) - Distributed systems - Internet of Things (IoT) - Microservices - Containerization - Serverless - Embedded systems - High-Performance Computing (HPC) systems - Edge computing systems - Virtualized systems |
| Select and determine cryptographic solutions | - Cryptographic life cycle (e.g., keys, algorithm selection) - Cryptographic methods (e.g., symmetric, asymmetric, elliptic curves, quantum) - Public Key Infrastructure (PKI) - Key management practices - Digital signatures and digital certificates - Non-repudiation - Integrity (e.g., hashing) |
| Understand methods of cryptanalytic attacks | - Brute force - Ciphertext only - Known plaintext - Frequency analysis - Chosen ciphertext - Implementation attacks - Side-channel - Fault injection - Timing - Man-in-the-Middle (MITM) - Pass the hash - Kerberos exploitation - Ransomware |
| Apply security principles to site and facility design | |
| Design site and facility security controls | - Wiring closets/intermediate distribution facilities - Server rooms/data centers - Media storage facilities - Evidence storage - Restricted and work area security - Utilities and Heating, Ventilation, and Air Conditioning (HVAC) - Environmental issues - Fire prevention, detection, and suppression - Power (e.g., redundant, backup) |
Communication and Network Security - 13% | |
| Assess and implement secure design principles in network architectures | - Open System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models - Internet Protocol (IP) networking (e.g., Internet Protocol Security (IPSec), Internet Protocol (IP) v4/6) - Secure protocols - Implications of multilayer protocols - Converged protocols (e.g., Fiber Channel Over Ethernet (FCoE), Internet Small Computer Systems Interface (iSCSI), Voice over Internet Protocol (VoIP)) - Micro-segmentation (e.g., Software Defined Networks (SDN), Virtual eXtensible Local Area Network (VXLAN), Encapsulation, Software-Defined Wide Area Network (SD WAN)) - Wireless networks (e.g., Li-Fi, Wi-Fi, Zigbee, satellite) - Cellular networks (e.g., 4G, 5G) - Content Distribution Networks (CDN) |
| Secure network components | - Operation of hardware (e.g., redundant power, warranty, support) - Transmission media - Network Access Control (NAC) devices - Endpoint security |
| Implement secure communication channels according to design | - Voice - Multimedia collaboration - Remote access - Data communications - Virtualized networks - Third-party connectivity |
Identity and Access Management (IAM) - 13% | |
| Control physical and logical access to assets | - Information - Systems - Devices - Facilities - Applications |
| Manage identification and authentication of people, devices, and services | - Identity Management (IdM) implementation - Single/multi-factor authentication (MFA) - Accountability - Session management - Registration, proofing, and establishment of identity - Federated Identity Management (FIM) - Credential management systems - Single Sign On (SSO) - Just-In-Time (JIT) |
| Federated identity with a third-party service | - On-premise - Cloud - Hybrid |
| Implement and manage authorization mechanisms | - Role Based Access Control (RBAC) - Rule based access control - Mandatory Access Control (MAC) - Discretionary Access Control (DAC) - Attribute Based Access Control (ABAC) - Risk based access control |
| Manage the identity and access provisioning lifecycle | - Account access review (e.g., user, system, service) - Provisioning and deprovisioning (e.g., on /off boarding and transfers) - Role definition (e.g., people assigned to new roles) - Privilege escalation (e.g., managed service accounts, use of sudo, minimizing its use) |
| Implement authentication systems | - OpenID Connect (OIDC)/Open Authorization (Oauth) - Security Assertion Markup Language (SAML) - Kerberos - Remote Authentication Dial-In User Service (RADIUS)/Terminal Access Controller Access Control System Plus (TACACS+) |
Security Assessment and Testing - 12% | |
| Design and validate assessment, test, and audit strategies | - Internal - External - Third-party |
| Conduct security control testing | - Vulnerability assessment - Penetration testing - Log reviews - Synthetic transactions - Code review and testing - Misuse case testing - Test coverage analysis - Interface testing - Breach attack simulations - Compliance checks |
| Collect security process data (e.g., technical and administrative) | - Account management - Management review and approval - Key performance and risk indicators - Backup verification data - Training and awareness - Disaster Recovery (DR) and Business Continuity (BC) |
| Analyze test output and generate report | - Remediation - Exception handling - Ethical disclosure |
| Conduct or facilitate security audits | - Internal - External - Third-party |
Security Operations - 13% | |
| Understand and comply with investigations | - Evidence collection and handling - Reporting and documentation - Investigative techniques - Digital forensics tools, tactics, and procedures - Artifacts (e.g., computer, network, mobile device) |
| Conduct logging and monitoring activities | - Intrusion detection and prevention - Security Information and Event Management (SIEM) - Continuous monitoring - Egress monitoring - Log management - Threat intelligence (e.g., threat feeds, threat hunting) - User and Entity Behavior Analytics (UEBA) |
| Perform Configuration Management (CM) (e.g., provisioning, baselining, automation) | |
| Apply foundational security operations concepts | - Need-to-know/least privilege - Separation of Duties (SoD) and responsibilities - Privileged account management - Job rotation - Service Level Agreements (SLAs) |
| Apply resource protection | - Media management - Media protection techniques |
| Conduct incident management | - Detection - Response - Mitigation - Reporting - Recovery - Remediation - Lessons learned |
| Operate and maintain detective and preventative measures | - Firewalls (e.g., next generation, web application, network) - Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) - Whitelisting/blacklisting - Third-party provided security services - Sandboxing - Honeypots/honeynets - Anti-malware - Machine learning and Artificial Intelligence (AI) based tools |
| Implement and support patch and vulnerability management | |
| Understand and participate in change management processes | |
| Implement recovery strategies | - Backup storage strategies - Recovery site strategies - Multiple processing sites - System resilience, High Availability (HA), Quality of Service (QoS), and fault tolerance |
| Implement Disaster Recovery (DR) processes | - Response - Personnel - Communications - Assessment - Restoration - Training and awareness - Lessons learned |
| Test Disaster Recovery Plans (DRP) | - Read-through/tabletop - Walkthrough - Simulation - Parallel - Full interruption |
| Participate in Business Continuity (BC) planning and exercises | |
| Implement and manage physical security | - Perimeter security controls - Internal security controls |
Elaborate the Format of the ISC CISSP exam
The format of the ISC CISSP exam is:
- Free Response: The free-response section consists of one multiple-choice and three open-ended (short answer and essay questions). Performance Exam: This section includes performance tasks consisting of both open-ended and multiple-choice questions.
- Audio Questions: Audio questions are presented in this section. The candidate will listen to English language questions and read the related information from a provided reference document.
To be eligible for the CISSP certification exam, candidates must have a minimum of five years of professional experience in information security. Candidates who do not meet this requirement may still be eligible for the exam if they have a relevant bachelor's or master's degree or other applicable certifications.
NEW QUESTION # 475
Which of the following is used to create parity information?
- A. a striping code
- B. a mirroring code
- C. a hamming code
- D. a clustering code
Answer: C
Explanation:
RAID Level 2 :- The parity information is created using a hamming code that detects errors and stablishes which part of which drive is in error.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 66.
NEW QUESTION # 476
How many rounds are used by DES?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
DES is a block encryption algorithm using 56-bit keys and 64-bit blocks that are divided in half and each character is encrypted one at a time. The characters are put through 16 rounds of transposition and substitution functions. Triple DES uses 48 rounds. Source: WALLHOFF, John, CBK#5 Cryptography (CISSP Study Guide), April 2002 (page 3).
NEW QUESTION # 477
Refer to the information below to answer the question.
An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles.
Which of the following will be the PRIMARY security concern as staff is released from the organization?
- A. Inadequate IT support
- B. Loss of data and separation of duties
- C. Additional responsibilities for remaining staff
- D. Undocumented security controls
Answer: B
Explanation:
The primary security concern as staff is released from the organization is the loss of data and separation of duties. The loss of data is the event or the situation where the data is deleted, corrupted, stolen, or leaked by the staff who are leaving the organization, either intentionally or unintentionally, and where the data is no longer available or recoverable by the organization. The loss of data can compromise the confidentiality, the integrity, and the availability of the data, and can cause damage or harm to the organization's operations, reputation, or objectives. The separation of duties is the principle or the practice of dividing the tasks or the responsibilities among different staff or roles, to prevent or reduce the conflicts of interest, the collusion, the fraud, or the errors. The separation of duties can be compromised when the staff is released from the organization, as it can create the gaps or the overlaps in the tasks or the responsibilities, and it can increase the risk of the unauthorized or the malicious access or activity. Inadequate IT support, undocumented security controls, and additional responsibilities for remaining staff are not the primary security concerns as staff is released from the organization, as they are related to the quality, the transparency, or the workload of the IT operations, not the loss of data or the separation of duties. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 1, Security and Risk Management, page 29. Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 1, Security and Risk Management, page 44.
NEW QUESTION # 478
One of the following statements about the differences between PPTP and L2TP is NOT true
- A. L2TP supports AAA servers
- B. L2TP works well with all firewalls and network devices that perform NAT.
- C. PPTP can run only on top of IP networks.
- D. PPTP is an encryption protocol and L2TP is not.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
L2TP is not compatible with NAT.
Incorrect Answers:
A: PPTP was designed to provide a way to tunnel PPP connections through an IP network.
B: PPTP uses PPP data packets that encrypted using Microsoft Point to Point Encryption (MPPE), while L2TP on the other hand does not provide any encryption or confidentiality by itself.
D: Radius AAA servers can be configured to use L2TP tunnels.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 702-703
NEW QUESTION # 479
Match the functional roles in an external audit to their responsibilities.
Drag each role on the left to its corresponding responsibility on the right.
Select and Place:
Answer:
Explanation:
NEW QUESTION # 480
How can a security engineer maintain network separation from a secure environment while allowing remote users to work in the secure environment?
- A. Install anti-virus on all enceinte
- B. Enforce port security on access switches
- C. Implement a bastion host
- D. Use a Virtual Local Area Network (VLAN) to segment the network
Answer: C
Explanation:
A bastion host is a hardened system that acts as a gateway between a secure environment and an untrusted network, such as the internet. A bastion host can be used to maintain network separation from a secure environment while allowing remote users to work in the secure environment, by providing controlled access and logging services. A bastion host can also implement additional security measures, such as encryption, authentication, and firewalls, to protect the communication and data. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 4: Communication and Network Security, page 181; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4: Communication and Network Security, page 255]
NEW QUESTION # 481
An organization is trying to secure instant messaging (IM) communications through its network perimeter. Which of the following is the MOST significant challenge?
- A. IM clients can run without administrator privileges.
- B. IM clients can utilize random port numbers.
- C. IM clients can run as executable that do not require installation.
- D. IM clients can interoperate between multiple vendors.
Answer: B
Explanation:
IM clients find ways to tunnel through firewalls, creating risk. Most IM services come through well- publicized ports (5190 for AOL Instant Messenger, 1863 for MSN and 5050 for Yahoo), but IM clients also can exploit any open port on the firewall, including those used by other applications (such as Port 80 for Web and HTTP traffic). Some clients also can connect via peer-to-peer connections or establish connections on randomly negotiated ports.
NEW QUESTION # 482
Which of the following cloud computing service model provides a way to rent operating systems, storage and network capacity over the Internet?
- A. Software as a service
- B. Data as a service
- C. Platform as a service
- D. Infrastructure as a service
Answer: C
Explanation:
Platform as a Service (PaaS) is a way to rent operating systems, storage and network capacity over the Internet. The service delivery model allows the customer to rent virtualized servers and associated services for running existing applications or developing and testing new ones.
For your exam you should know below information about Cloud Computing:
Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models.
Cloud Computing
Image Reference http://osarena.net/wp-content/uploads/2013/04/cloud-computing3.jpg
Cloud computing service models:
Cloud computing service models
Image Reference http://www.esri.com/news/arcwatch/0110/graphics/feature2.jpg
Software as a Service (SaaS)
Software as a Service (SaaS) is a software distribution model in which applications are hosted by a vendor or service provider and made available to customers over a network, typically the Internet.SaaS is closely related to the ASP (application service provider) and on demand computing software delivery models. IDC identifies two slightly different delivery models for SaaS. The hosted application management (hosted AM) model is similar to ASP: a provider hosts commercially available software for customers and delivers it over the Web. In the software on demand model, the provider gives customers network- based access to a single copy of an application created specifically for SaaS distribution.
Provider gives users access to specific application software (CRM, e-mail, games). The provider gives the customers network based access to a single copy of an application created specifically for SaaS distribution and use.
Benefits of the SaaS model include:
easier administration
automatic updates and patch management
compatibility: All users will have the same version of software.
easier collaboration, for the same reason
global accessibility.
Platform as a Service (PaaS)
Platform as a Service (PaaS) is a way to rent operating systems, storage and network capacity over the Internet. The service delivery model allows the customer to rent virtualized servers and associated services for running existing applications or developing and testing new ones.
Cloud providers deliver a computing platform,which can include an operating system, database, and web server as a holistic execution environment. Where IaaS is the "raw IT network," PaaS is the software environment that runs on top of the IT network.
Platform as a Service (PaaS) is an outgrowth of Software as a Service (SaaS), a software distribution model in which hosted software applications are made available to customers over the Internet. PaaS has several advantages for developers. With PaaS, operating system features can be changed and upgraded frequently. Geographically distributed development teams can work together on software development projects. Services can be obtained from diverse sources that cross international boundaries. Initial and ongoing costs can be reduced by the use of infrastructure services from a single vendor rather than maintaining multiple hardware facilities that often perform duplicate functions or suffer from incompatibility problems. Overall expenses can also be minimized by unification of programming development efforts.
On the downside, PaaS involves some risk of "lock-in" if offerings require proprietary service interfaces or development languages. Another potential pitfall is that the flexibility of offerings may not meet the needs of some users whose requirements rapidly evolve.
Infrastructure as a Service (IaaS)
Cloud providers offer the infrastructure environment of a traditional data center in an on- demand delivery method. Companies deploy their own operating systems, applications, and software onto this provided infrastructure and are responsible for maintaining them.
Infrastructure as a Service is a provision model in which an organization outsources the equipment used to support operations, including storage, hardware, servers and networking components. The service provider owns the equipment and is responsible for housing, running and maintaining it. The client typically pays on a per-use basis.
Characteristics and components of IaaS include:
Utility computing service and billing model.
Automation of administrative tasks.
Dynamic scaling.
Desktop virtualization.
Policy-based services.
Internet connectivity.
Infrastructure as a Service is sometimes referred to as Hardware as a Service (HaaS).
The following answers are incorrect:
Data as a service - Data Provided as a service rather than needing to be loaded and prepared on premises.
Software as a service - Software as a Service (SaaS) is a software distribution model in which applications are hosted by a vendor or service provider and made available to customers over a network, typically the Internet. SaaS is closely related to the ASP
(application service provider) and on demand computing software delivery models.
Infrastructure as a service - Infrastructure as a Service is a provision model in which an organization outsources the equipment used to support operations, including storage, hardware, servers and networking components. The service provider owns the equipment and is responsible for housing, running and maintaining it. The client typically pays on a per-use basis.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 102
Official ISC2 guide to CISSP 3rd edition Page number 689
http://searchcloudcomputing.techtarget.com/definition/Software-as-a-Service
http://searchcloudcomputing.techtarget.com/definition/Platform-as-a-Service-PaaS
http://searchcloudcomputing.techtarget.com/definition/Infrastructure-as-a-Service-IaaS
NEW QUESTION # 483
A channel within a computer system or network that is designed for the authorized transfer of information is identified as a(n)?
- A. Covert channel
- B. Opened channel
- C. Closed channel
- D. Overt channel
Answer: D
Explanation:
"An overt channel is a channel of communication that was developed specifically for communication purposes. Processes should be communicating through overt channels, not covert channels." Pg 237 Shon Harris: All-In-One CISSP Certification Guide.
NEW QUESTION # 484
At which temperature does damage start occurring to magnetic media?
- A. 150 degrees Fahrenheit or 65.5 degrees Celsius
- B. 125 degrees Fahrenheit or 51.66 degrees Celsius
- C. 175 degrees Fahrenheit or 79.4 degrees Celsius
- D. 100 degrees Fahrenheit or 37.7 degrees Celsius
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Maintaining appropriate temperature and humidity is important in any facility, especially facilities with computer systems. Improper levels of either can cause damage to computers and electrical devices.
Lower temperatures can cause mechanisms to slow or stop, and higher temperatures can cause devices to use too much fan power and eventually shut down.
Damage can start to occur on magnetic media at 100 degrees Fahrenheit or 37'7ยบ Celsius.
Incorrect Answers:
B: Damage can start to occur on magnetic media at 100 degrees Fahrenheit, not 125 degrees Fahrenheit.
Therefore, this answer is incorrect.
C: Damage can start to occur on magnetic media at 100 degrees Fahrenheit, not 150 degrees Fahrenheit.
Therefore, this answer is incorrect.
D: Damage can start to occur on magnetic media at 100 degrees Fahrenheit, not 175 degrees Fahrenheit.
Damage can start to occur in computer systems and peripheral devices at 175 degrees Fahrenheit.
Therefore, this answer is incorrect.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 466
NEW QUESTION # 485
In a distributed environment, a surrogate program that performs services
in one environment on behalf of a principal in another environment is
called:
- A. A virtual processor.
- B. An agent.
- C. A proxy.
- D. A slave.
Answer: B
Explanation:
The correct answer is An agent.
* Proxy is similar in nature but might hide the characteristics of the principal it is representing. Answers A slave and A virtual processor are distracters.
NEW QUESTION # 486
Drag the following Security Engineering terms on the left to the BEST definition on the right.
Answer:
Explanation:
NEW QUESTION # 487
In what type of attack does an attacker try, from several encrypted messages, to figure out the key used in the encryption process?
- A. Plaintext-only attack
- B. Known-plaintext attack
- C. Chosen-Ciphertext attack
- D. Ciphertext-only attack
Answer: D
Explanation:
In a ciphertext-only attack, the attacker has the ciphertext of several messages encrypted with the same encryption algorithm. Its goal is to discover the plaintext of the messages by figuring out the key used in the encryption process. In a known-plaintext attack, the attacker has the plaintext and the ciphertext of one or more messages. In a chosen-ciphertext attack, the attacker can chose the ciphertext to be decrypted and has access to the resulting plaintext. Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, Chapter 8: Cryptography (page 578).
NEW QUESTION # 488
Which of the following is unlike the other three?
- A. El Gamal
- B. Buffer Overflow
- C. Smurf
- D. Teardrop
Answer: A
Explanation:
Options B, C and D are all Denial of Service attacks. El Gamal is the
Diffie-Hellman key exchange algorithm and is usually described as an active exchange of keys by two parties. The buffer overflow attack objective is consume the available memory for the TCP/IP protocol stack to make the machine crash.
Teardrop and Smurf are DoS attacks that make use of spoofing.
NEW QUESTION # 489
Which of the following is covered under Crime Insurance Policy Coverage?
- A. Accounts Receivable
- B. Manuscripts
- C. Money and Securities
- D. Inscribed, printed and Written documents
Answer: C
Explanation:
Source: TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 1, Property Insurance overview, Page 589.
NEW QUESTION # 490
Which of the following is often the greatest challenge of distributed computing solutions?
- A. security
- B. heterogeneity
- C. usability
- D. scalability
Answer: A
Explanation:
The correct answer to this "security". It is a major factor in deciding if a centralized
or decentralized environment is more appropriate.
Example: In a centralized computing environment, you have a central server and workstations
(often "dumb terminals") access applications, data, and everything else from that central servers.
Therefore, the vast majority of your security resides on a centrally managed server. In a
decentralized (or distributed) environment, you have a collection of PC's each with their own
operating systems to maintain, their own software to maintain, local data storage requiring
protection and backup. You may also have PDA's and "smart phones", data watches, USB
devices of all types able to store data... the list gets longer all the time.
It is entirely possible to reach a reasonable and acceptable level of security in a distributed
environment. But doing so is significantly more difficult, requiring more effort, more money, and
more time.
The other answers are not correct because:
scalability - A distributed computing environment is almost infinitely scalable. Much more so than a
centralized environment. This is therefore a bad answer.
heterogeneity - Having products and systems from multiple vendors in a distributed environment is
significantly easier than in a centralized environment. This would not be a "challenge of distributed
computing solutions" and so is not a good answer.
usability - This is potentially a challenge in either environment, but whether or not this is a problem
has very little to do with whether it is a centralized or distributed environment. Therefore, this
would not be a good answer.
Reference:
Official ISC2 Guide page: 313-314
All in One Third Edition page: (unavailable at this time)
NEW QUESTION # 491
Drag the following Security Engineering terms on the left to the BEST definition on the right.
Answer:
Explanation:
Explanation
NEW QUESTION # 492
You work in a police department forensics lab where you examine computers for evidence of crimes. Your work is vital to the success of the prosecution of criminals.
One day you receive a laptop and are part of a two-man team responsible for examining it together.
However, it is lunch time and after receiving the laptop you leave it on your desk and you both head out to lunch.
What critical step in forensic evidence have you forgotten?
- A. Chain of custody
- B. Cracking the admin password with chntpw
- C. Making a disk image for examination
- D. Locking the laptop in your desk
Answer: A
Explanation:
Explanation/Reference:
Explanation:
By leaving the laptop, which contains unique data, unguarded, you cannot guarantee that the data on it remain untampered. This breaks the chain of custody.
When evidence is seized, it is important to make sure a proper chain of custody is maintained to ensure any data collected can later be properly and accurately represented in case it needs to be used for later events such as criminal proceedings or a successful prosecution.
Incorrect Answers:
B: Locking the desktop to the desktop would not protect the data on it from being changed.
C: It is a good idea to make a disk image of the Laptop, but the critical step here is to ensure that the laptop is preserved. By leaving it alone the chain of custody is broken.
D: Cracking the admin password is not vital for the forensic investigation.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 248
NEW QUESTION # 493
An organization seeks to use a cloud identity and access management (IAM) provider whose protocols and data formats are Incompatible with existing systems. Which of the following techniques addresses the compatibility Issue?
- A. Apply Transport Layer Security (TLS) to the cloud-based authentication checks
- B. Require the cloud IAM provider to use declarative security instead of programmatic authentication checks
- C. Install a on-premise authentication gateway service in front of the service provider
- D. Integrate a web-application firewall (WAF) in reverse-proxy mode In front of the service provider
Answer: C
NEW QUESTION # 494
......
Get 100% Authentic ISC CISSP Dumps with Correct Answers: https://www.examprepaway.com/ISC/braindumps.CISSP.ete.file.html
New Training Course CISSP Tutorial Preparation Guide: https://drive.google.com/open?id=1kDdmOB4EuDWXAiGVafvVEg4zIOH1H69O