首页 > 题库 > CISSP
« 返回题库列表

2026年新版CISSP全英文真题库|历年考试题+答案解析+备考资料

问题 #1
The general philosophy for DMZ's are that:
A': ") any system on the DMZ can be compromised because it's accessible from the Internet", 'B': ") any system on the DMZ cannot be compromised because it's not accessible from the Internet", 'C. some systems on the DMZ can be compromised because they are accessible from the Internet
正确答案:A
问题 #2
What is NOT an authentication method within IKE and IPsec:
A. CHAP
B. Pre-shared Key
C. certificate based authentication
D. Public Key authentication
正确答案:A
问题 #3
In IPSec, if the communication mode is gateway-gateway or host-gateway:
A. Only tunnel mode can be used
B. Only transport mode can be used
C. Encapsulating Security Payload (ESP) authentication must be used
D. Both tunnel and transport mode can be used
正确答案:D
问题 #4
Internet Protocol Security (IPSec) provides security service within the Internet Protocol (IP) by doing all of the following EXCEPT
A. Enabling a system to select required security protocols.
B. Providing traffic analysis protection.
C. Determining the algorithm(s) to use for the IPsec services.
D. Putting in place any cryptographic keys required to provide the requested services.
正确答案:A
问题 #5
Which of the following Internet Protocol (IP) security headers are defined by the Security Architecture for IP (IPSEC)?
A. The IPv4 and IPv5 Authentication Headers
B. The Authentication Header Encapsulating Security Payload
C. The Authentication Header and Digital Signature Tag
D. The Authentication Header and Message Authentication Code
正确答案:B
问题 #6
Which of the following statements is not true of IPSec Transport mode?
A. It is required for gateways providing access to internal systems
B. Set-up when end-point is host or communications terminates at end-points
C. If used in gateway-to-host communication, gateway must act as host
D. )Detective/Administrative Pairing
正确答案:A
问题 #7
What is called the standard format that was established to set up and manage Security Associations (SA) on the Internet in IPSec?
A. Internet Key Exchange
B. Secure Key Exchange Mechanism
C. Oakley
D. Internet Security Association and Key Management Protocol
正确答案:D
问题 #8
What is the purpose of the Encapsulation Security Payload (ESP) in the Internet Protocol (IP) Security Architecture for Internet Protocol Security?
A. To provide non-repudiation and confidentiality for IP transmission.
B. To provide integrity and confidentiality for IP transmissions.
C. To provide integrity and authentication for IP transmissions.
D. To provide key management and key distribution for IP transmissions.
正确答案:B
问题 #9
Which one of the following is a circuit level application gateway and works independent of any supported TCP/IP application protocol?
A. SOCK-et-S (SOCKS)
B. Common Information Model (CIM)
C. Secure Multipurpose Internet Mail Extension (S/MIME)
D. Generic Security Service Application Programming Interface (GSS-API)
正确答案:A
问题 #10
How does the SOCKS protocol secure Internet Protocol (IP) connections?
A. By negotiating encryption keys during the connection setup.
B. By attaching Authentication Headers (AH) to each packet.
C. By distributing encryption keys to SOCKS enabled applications.
D. By acting as a connection proxy.
正确答案:D
问题 #11
In the TCP/IP protocol stack, at what level is the SSL (Secure Sockets Layer) protocol provided?
A. Application
B. Network
C. Presentation
D. Session
正确答案:B
问题 #12
SSL (Secure Sockets Layer) has two possible 'session key' lengths, what are they?
A. 40 bit & 54 bit
B. 40 bit & 128 bit
C. 64 bit & 128 bit
D. 128 bit & 256 bit
正确答案:B
问题 #13
Which of the following is NOT true of SSL?
A': ") By convention is uses 's-http://' instead of 'http://'. ", 'B.It stands for Secure Sockets Layer
C. It was developed by Netscape
D. IT is used for transmitting private documents over the internet
正确答案:A
问题 #14
Which SSL version offers client-side authentication
A. SSL v1
B. SSL v2
C. SSL v3
D. SSL v4
正确答案:B
问题 #15
In which way does a Secure Socket Layer (SSL) server prevent a "man-in-the-middle" attack?
A': "It uses signed certificates to authenticate the server's public key. ", 'B. A 128 bit value is used during the handshake protocol that is unique to the connection.
C. It uses only 40 bits of secret key within a 128 bit key length.
D. Every message sent by the SSL includes a sequence number within the message contents.
正确答案:A
问题 #16
Secure Shell (SSH) and Secure Sockets Layer (SSL) are very heavily used for protecting
A. Internet transactions
B. Ethernet transactions
C. Telnet transactions
D. Electronic Payment transactions
正确答案:A
问题 #17
Which one of the following CANNOT be prevented by the Secure Shell (SSH) program?
A. Internet Protocol (IP) spoofing.
B. Data manipulation during transmissions.
C. Network based birthday attack.
D. Compromise of the source/destination host.
正确答案:D
问题 #18
Another name for a VPN is a:
A. tunnel
B. one-time password
C. pipeline
D. bypass
正确答案:A
问题 #19
Which one of the following attacks is MOST effective against an Internet Protocol Security (IPSEC) based virtual private network (VPN)?
A. Brute force
B. Man-in-the-middle
C. Traffic analysis
D. Replay
正确答案:B
问题 #20
Which of the following is NOT an essential component of a VPN?
A. VPN Server
B. NAT Server
C. authentication
D. encryption
正确答案:B
问题 #21
Virtual Private Network software typically encrypts all of the following EXCEPT
A. File transfer protocol
B. Data link messaging
C. HTTP protocol
D. Session information
正确答案:B
问题 #22
Which of the following is less likely to be used in creating a Virtual Private Network?
A. L2TP
B. PPTP
C. IPSec
D. L2F
正确答案:D
问题 #23
Which one of the following instigates a SYN flood attack?
A. Generating excessive broadcast packets.
B. Creating a high number of half-open connections.
C. Inserting repetitive Internet Relay Chat (IRC) messages.
D. A large number of Internet Control Message Protocol (ICMP) traces.
正确答案:B
问题 #24
Which one of the following is defined as the process of distributing incorrect Internet Protocol (IP) addresses/names with the intent of diverting traffic?
A. Network aliasing
B. Domain Name Server (DNS) poisoning
C. Reverse Address Resolution Protocol (ARP)
D. Port scanning
正确答案:B
问题 #25
A Packet containing a long string of NOP's followed by a command is usually indicative of what?
A. A syn scan
B. A half-port scan
C. A buffer overflow
正确答案:C
问题 #26
You are running a packet sniffer on a network and see a packet with a long string of long string of "90 90 90 90...." in the middle of it traveling to an x86-based machine. This could be indicative of what?
A. Over-subscription of the traffic on a backbone
B. A source quench packet
C. a FIN scan
D. A buffer overflow
正确答案:D
问题 #27
Which of the following is true related to network sniffing?
A. Sniffers allow an attacker to monitor data passing across a network.
B. Sniffers alter the source address of a computer to disguise and exploit weak authentication methods.
C. Sniffers take over network connections
D. Sniffers send IP fragments to a system that overlap with each other.
正确答案:A
问题 #28
Which one of the following threats does NOT rely on packet size or large volumes of data?
A. SYN flood
B. Spam
C. Ping of death
D. Macro virus
正确答案:D
问题 #29
A TCP SYN Attack:
A. requires a synchronized effort by multiple attackers
B. takes advantage of the way a TCP session is established
C. may result in elevation of privileges.
D. is not something system users would notice
正确答案:B
问题 #30
What attack is typically used for identifying the topology of the target network?
A. Spoofing
B. Brute force
C. Teardrop
D. Scanning
正确答案:D
问题 #31
Which one of the following is the reason for why hyperlink spoofing attacks are usually successful?
A. Most users requesting DNS name service do not follow hyperlinks.
B. The attack performs user authentication with audit logs.
C. The attack relies on modifications to server software.
D. Most users do not make a request to connect to a DNS names, they follow hyperlinks.
正确答案:D
问题 #32
Which of the following identifies the first phase of a Distributed Denial of Service attack?
A. Establishing communications between the handler and agent.
B. Disrupting the normal traffic to the host.
C. Disabling the router so it cannot filter traffic.
D. Compromising as many machines as possible.
正确答案:D
问题 #33
This type of vulnerability enables the intruder to re-route data traffic from a network device to a personal machine? This diversion enables the intruder to capture data traffic to and from the devices for analysis or modification, or to steal the passwor
A. Network Address Translation
B. Network Address Hijacking
C. Network Address Supernetting
D. Network Address Sniffing
正确答案:B
问题 #34
Which one of the following is an example of hyperlink spoofing?
A. Compromising a web server Domain Name Service reference.
B. Connecting the user to a different web server.
C. Executing Hypertext Transport Protocol Secure GET commands.
D': "Starting the user's browser on a secured page. "}
正确答案:B
问题 #35
Why are packet filtering routers NOT effective against mail bomb attacks?
A. The bomb code is obscured by the message encoding algorithm.
B. Mail bombs are polymorphic and present no consistent signature to filter on.
C. Filters do not examine the data portion of a packet.
D. The bomb code is hidden in the header and appears as a normal routing information.
正确答案:C
问题 #36
Which one of the following correctly identifies the components of a Distributed Denial of Service Attack?
A. Node, server, hacker, destination
B. Client, handler, agent, target
C. Source, destination, client, server
D. Attacker, proxy, handler, agent
正确答案:B
问题 #37
Which one of the following attacks will pass through a network layer intrusion detection system undetected?
A. A teardrop attack
B. A SYN flood attack
C. A DNS spoofing attack
D. A test.cgi attack
正确答案:D
问题 #38
Which one of the following is a passive network attack?
A. Spoofing
B. Traffic Analysis
C. Playback
D. Masquerading
正确答案:B
问题 #39
Which one of the following can NOT typically be accomplished using a Man-in-the-middle attack?
A. DNS spoofing
B. Session hijacking
C. Denial of service flooding
D. Digital signature spoofing
正确答案:D
问题 #40
What is called an attach where the attacker spoofs the source IP address in an ICMP ECHO broadcast packet so it seems to have originated at the victim's system, in order to flood it with REPLY packets?
A. SYN flood attack
B. Smurf attack
C. Ping of Dead Attack
D. Denial of Service (DOS) Attack
正确答案:B
问题 #41
Which type of attack involves the alteration of a packet at the IP level to convince a system that it is communicating with a known entity in order to gain access to a system?
A. TCP sequence number attack
B. IP spoofing attack
C. Piggybacking attack
D. Teardrop attack
正确答案:B
问题 #42
What attack takes advantage of operating system buffer overflows?
A. Spoofing
B. Brute force
C. DoS
D. Exhaustive
正确答案:C
问题 #43
What attack is primarily based on the fragmentation implementation of IP and large ICMP packet size?
A. Exhaustive
B. Brute force
C. Ping of Death
D. Spoofing
正确答案:C
问题 #44
Land attack attacks a target by:
A. Producing large volume of ICMP echos.
B. Producing fragmented IP packets.
C. Attacking an established TCP connection.
D. None of the choices.
正确答案:C
问题 #45
What attack is primarily based on the fragmentation implementation of IP?
A. Teardrop
B. Exhaustive
C. Spoofing
D. Brute force
正确答案:A
问题 #46
What attack floods networks with broadcast traffic so that the network is congested?
A. Spoofing
B. Teardrop
C. Brute force
D. SMURF
正确答案:D
问题 #47
What attack involves repeatedly sending identical e-message to a particular address?
A. SMURF
B. Brute force
C. Teardrop
D. Spamming
正确答案:D
问题 #48
A stack overflow attack that "crashes" a Transmission Control Protocol/Internet Protocol (TCP/IP) service daemon can result in a serious security breach because the
A. Process does not implement proper object reuse.
B. Process is executed by a privileged entity.
C. Network interface becomes promiscuous.
D. Daemon can be replaced by a trojan horse.
正确答案:B
问题 #49
The intrusion detection system at your site has detected Internet Protocol (IP) packets where the IP source address is the same as the destination address. This situation indicates
A. Misdirected traffic jammed to the internal network.
B. A denial of service attack.
C. An error in the internal address matrix.
D. A hyper overflow in the IP stack.
正确答案:B
问题 #50
What type of attacks occurs when a rogue application has been planted on an unsuspecting user's workstation?
A. Physical attacks
B. Logical attacks
C. Trojan Horse attacks
D. Social Engineering attacks
正确答案:C
问题 #51
Man-in-the-middle attacks are a real threat to what type of communication?
A. Communication based on random challenge.
B. Communication based on face to face contact.
C. Communication based on token.
D. Communication based on asymmetric encryption.
正确答案:D
问题 #52
Which of the following threats is not addressed by digital signature and token technologies?
A. Spoofing
B. replay attacks
C. password compromise
D. denial-of-service
正确答案:D
问题 #53
Which one of the following is concerned with masking the frequency, length, and origin-destination patterns of the communications between protocol entities?
A. Masking analysis
B. Protocol analysis
C. Traffic analysis
D. Pattern analysis
正确答案:C
问题 #54
Which of the following would NOT be considered a Denial of Service Attack?
A. Zone Transfer
B. Smurf
C. Syn Flood
D. TearDrop
正确答案:A
问题 #55
The connection using fiber optics from a phone company's branch office to local customers is which of the following?
A. new loop
B. local loop
C. loopback
D. indigenous loop
正确答案:B
问题 #56
Which step ensures the confidentiality of a facsimile transmission?
A. Pre-schedule the transmission of the information.
B. Locate the facsimile equipment in a private are
A.
C. Encrypt the transmission.
D. Phone ahead to the intended recipient.
正确答案:C
问题 #57
Which one of the following could a company implement to help reduce PBX fraud?
A. Call vectoring
B. Direct Inward System Access (DISA)
C. Teleconferencing bridges
D. Remote maintenance ports
正确答案:B
问题 #58
Phreakers are hackers who specialize in telephone fraud. What type of telephone fraud manipulates the line voltage to receive a toll-free call?
A. Red boxes
B. Blue boxes
C. White boxes
D. Black boxes
正确答案:D
问题 #59
Which one of the following devices might be used to commit telecommunications fraud using the "shoulder surfing" technique?
A. Magnetic stripe copier
B. Tone generator
C. Tone recorder
D. Video recorder
正确答案:C
问题 #60
What technique is used to prevent eavesdropping of digital cellular telephone conversations?
A. Encryption
B. Authentication
C. Call detail suppression
D. Time-division multiplexing
正确答案:D
问题 #61
Which of the following is a telecommunication device that translates data from digital to analog form and back to digital?
A. Multiplexer
B. Modem
C. Protocol converter
D. Concentrator
正确答案:B
问题 #62
Which of the following could lead to the conclusion that a disaster recovery plan may not be operational within the timeframe the business needs to recover? A.)The alternate site is a warm site B.) Critical recovery priority levels are not defined C.) Off
A. )The alternate site is a warm site
B. Critical recovery priority levels are not defined
C. Offsite backups are located away from the alternate site
D. The alternate site is located 70 miles away from the primary site
正确答案:B
问题 #63
What are the four domains of communication in the disaster planning and recovery process?
A. Plan manual, plan communication, primer for survival, warning and alarms
B. Plan communication, primer for survival, escalation, declaration
C. Plan manual, warning and alarm, declaration, primer for survival
D. Primer for survival, escalation, plan communication, warning and alarm
正确答案:C
问题 #64
The underlying reason for creating a disaster planning and recover strategy is to
A. Mitigate risks associated with disaster.
B. Enable a business to continue functioning without impact.
C': "Protect the organization's people, place and processes. ", 'D. Minimize financial profile.
正确答案:A
问题 #65
Which of the following is not a direct benefit of successful Disaster Recovery Planning?
A. Maintain Nance of Business Continuity
B. Protection of Critical Data
C. Increase in IS performance
D. Minimized Impact of a disaster
正确答案:C
问题 #66
Organizations should not view disaster recovery as which of the following?
A. committed expense
B. discretionary expense
C. enforcement of legal statues
D. compliance with regulations
正确答案:B
问题 #67
Which of the following statements pertaining to disaster recovery is incorrect?
A': ") A recovery team's primary task is to get the pre-defined critical business functions at the alternate backup processing site. ", 'B': ") A salvage team's task is to ensure that the primary site returns to normal processing conditions", 'C.The disaster recovery plan should include how the company will return from the alternate site to the primary site
D. When returning to the primary site, the most critical applications should be brought back first
正确答案:D
问题 #68
Which of the following statements pertaining to dealing with the media after a disaster occurred and disturbed the organization's activities is incorrect?
A. The CEO should always be the spokesperson for the company during a disaster
B. The disaster recovery plan must include how the media is to be handled during the disaster
C': ") The organization's spokesperson should report bad news before the press gets ahold of it through another channel", 'D. An emergency press conference site should be planned ahead
正确答案:A
问题 #69
What is a disaster recovery plan for a company's computer system usually focused on?
A. Alternative procedures to process transactions
B. The probability that a disaster will occur
C. Strategic long-range planning
D. Availability of compatible equipment at a hot site
正确答案:A
问题 #70
What is the most critical piece to disaster recovery and continuity planning?
A. Security Policy
B. Management Support
C. Availability of backup information processing facilities
D. Staff training
正确答案:B
问题 #71
Which of the following is the most important consideration in locating an alternate computing facility during the development of a disaster recovery plan?
A. it is unlikely to be affected by the same contingency
B. it is close enough to become operation quickly
C': ") is it close enough to serve it's users", 'D. it is convenient to airports and hotels
正确答案:A
问题 #72
Which of the following are PRIMARY elements that are required when designing a Disaster Recovery Plan (DRP)?
A. Back-up procedures, off-site storage, and data recover.
B. Steering committee, emergency response team, and reconstruction team.
C. Impact assessment, recover strategy, and testing.
D. Insurance coverage, alternate site, and manual procedures.
正确答案:C
问题 #73
Emergency actions are taken at the incipient stage of a disaster with the objectives of preventing injuries or loss of life and of:
A. determining the extent of property damage
B. protecting evidence
C. preventing looting and further damage
D. mitigating the damage to avoid the need for recovery
正确答案:D
问题 #74
Who should direct short-term recovery actions immediately following a disaster?
A. Chief Information Officer
B. Chief Operating Officer
C. Disaster Recovery Manager
D. Chief Executive Officer
正确答案:C
问题 #75
The environment that must be protected includes all personnel, equipment, data, communication devices, power supply and wiring. The necessary level of protection depends on the value of data, the computer systems, and the company assets within the facilit
A. Critical-channel analysis
B. Critical-route analysis
C. Critical-path analysis
D. Critical-conduit analysis
正确答案:C
问题 #76
Which of the following steps should be performed first in a business impact analysis (BIA)?
A. Identify all business units within the organization
B. Evaluate the impact of the disruptive events
C. Estimate the Recovery Time Objectives (RTO)
D. Evaluate the criticality of business functions
正确答案:A
问题 #77
Which of the following steps it NOT one of the four steps of a Business Impact Analysis (BIA)?
A. Notifying senior management
B. Gathering the needed assessment materials
C. Performing the vulnerability assessment
D. Analyzing the information compiled
正确答案:A
问题 #78
What methodology is commonly used in Business Continuity Program?
A. Work Group Recovery
B. Business Impact Analysis
C. Qualitative Risk Analysis
D. Quantitative Risk Analysis
正确答案:B
问题 #79
Which of the following steps should be performed first in a business impact analysis (BIA)?
A. Identify all business units within an organization
B. Evaluate the impact of disruptive events
C. Estimate the Recovery Time Objectives (RTO)
D. Evaluate the criticality of business functions
正确答案:A
问题 #80
Which is not one of the primary goals of BIA?
A. Criticality Prioritization
B. Down time estimation
C. Determining requirements for critical business functions
D. Deciding on various test to be performed to validate Business Continuity Plan
正确答案:D
问题 #81
Which of the following is used to help business units understand the impact of a disruptive event?
A. A risk analysis
B. A Business Impact assessment
C. A Vulnerability assessment
D. A disaster recovery plan
正确答案:B
问题 #82
A Business Impact Analysis (BIA) does not:
A. Recommend the appropriate recovery solution
B. Determine critical and necessary business functions and their resource dependencies
C. Identify critical computer applications and the associated outage tolerance
D. Estimate the financial and operation impact of a disruption
正确答案:A
问题 #83
What assesses potential loss that could be caused by a disaster?
A. The Business Assessment (BA)
B. The Business Impact Analysis (BIA)
C. The Risk Assessment (RA)
D. The Business Continuity Plan (BCP)
正确答案:B
问题 #84
During the course of a Business Impact Analysis (BIA) you will less likely:
A. Estimate the financial and operational impact of a disruption
B. Identify regulatory exposure
C. Determine if functions Recovery Time Objective (RTO)
D. Determine the impact upon the organizations market share and corporate image
正确答案:C
问题 #85
Which of the following tasks is not usually part of a Business Impact Analysis (BIA)?
A. Identify the type and quantity of resources required for recovery
B. Identify the critical processes and the dependencies between them
C. Identify organizational risks
D. Develop a mission statement
正确答案:D
问题 #86
Which of the following will a Business Impact Analysis (BIA) NOT identify?
A. Areas that would suffer the greatest financial or operation loss in the event of a disaster
B. Systems critical to the survival of the enterprise
C. The names of individuals to be contacted during a disaster
D. The outage time that can be tolerated by the enterprise as a result of a disaster
正确答案:C
问题 #87
Which one the following is the primary goal of Business Continuity Planning?
A. Sustain the organization.
B. Recover from a major data center outage.
C. Test the ability to prevent major outages.
D. Satisfy audit requirements.
正确答案:A
问题 #88
Most of unplanned downtime of information systems is attributed to which of the following?
A. Hardware failure
B. Natural disaster
C. Human error
D. Software failure
正确答案:A
问题 #89
System reliability s increased by:
A. A lower MTBF and a lower MTTR
B. A higher MTBF and a lower MTTR
C. A lower MTBF and a higher MTTR
D. A higher MTBF and a higher MTTR
正确答案:B
问题 #90
Which of the following is NOT a major element of Business Continuity Planning?
A. Creation of a BCP committee
B. Business Impact Assessment (BIA)
C. Business Continuity Plan Development
D. Scope plan initiation
正确答案:A
问题 #91
Which one of the following is a core infrastructure and service element of Business Continuity Planning (BCP) required to effectively support the business processes of an organization?
A. Internal and external support functions.
B. The change management process.
C. The risk management process.
D. Backup and restoration functions.
正确答案:C
问题 #92
A business continuity plan should list and prioritize the services that need to be brought back after a disaster strikes. Which of the following services is more likely to be of primary concern?
A. Marketing/Public relations
B. Data/Telecomm/IS facilities
C. IS Operations
D. Facilities security
正确答案:B
问题 #93
When preparing a business continuity plan, who of the following is responsible for identifying and prioritizing time-critical systems?
A. Executive management staff
B. Senior business unit management
C. BCP committee
D. Functional business units
正确答案:B
问题 #94
Classification of information systems is essential in business continuity planning. Which of the following system types can not be replaced by manual methods?
A. Critical System
B. Vital System
C. Sensitive System
D. Non-critical system
正确答案:A
问题 #95
Business Continuity Plan development depends most on:
A. Directives of Senior Management
B. Business Impact Analysis (BIA)
C. Scope and Plan Initiation
D. Skills of BCP committee
正确答案:B
问题 #96
Which primary element of BCP includes carrying out vulnerability analysis?
A. Scope and Plan Initiation
B. Business Impact Assessment
C. Business Continuity Plan Development
D. Plan Approval and Implementation
正确答案:B
问题 #97
To mitigate the impact of a software vendor going out of business, a company that uses vendor software should require which one of the following?
A. Detailed credit investigation prior to acquisition.
B. Source code held in escrow.
C. Standby contracts with other vendors.
D': "Substantial penalties for breech of contract. '"}
正确答案:B
问题 #98
Similarity between all recovery plans is:
A. They need extensive testing
B. They need to be developed by business continuity experts
C. They become obsolete quickly
D. The create employment opportunities
正确答案:C
问题 #99
Which of the following focuses on sustaining an organizations business functions during and after a disruption?
A. Business continuity plan
B. Business recovery plan
C. Continuity of operations plan
D. Disaster recovery plan
正确答案:A
问题 #100
What is not one of the drawbacks of a hot site?
A. Need Security controls, as it usually contain mirror copies of live production data
B. Full redundancy in hardware, software, communication lines, and applications lines is very expensive
C. The hot sites are available immediately or within maximum allowable downtime (MTD)
D. They are administratively resource intensive, as transaction redundancy controls need to be implemented to keep data up-to-date
正确答案:C

即刻预约

免费试听-咨询课程-获取免费资料