首页 > 题库 > CISSP
« 返回题库列表

CISSP信息系统安全专家真题解析|历年考试题+答案详解汇总

问题 #1
Which one of the following processing alternatives involves a ready-to-use computing facility with telecommunications equipment, but not computers?
A. Company-owned hot site
B. Commercial hot site
C. Cold site
D. Warm site
正确答案:D
问题 #2
What is a hot-site facility?
A. A site with pre-installed computers, raised flooring, air conditioning, telecommunications, and networking equipment, and UPS
B. A site is which space is reserved with pre-installed wiring and raised floors
C. A site with raised flooring, air conditioning, telecommunications, and networking equipment, and UPS
D. A site with ready made work space with telecommunications equipment, LANs, PCs, and terminals with work groups
正确答案:A
问题 #3
Contracts and agreements are unenforceable in which of the following alternate back facilities?
A. hot site
B. warm site
C. cold site
D. reciprocal agreement
正确答案:D
问题 #4
Which of the following computer recovery sites is the least expensive and the most difficulty to test?
A. non-mobile hot site
B. mobile hot site
C. warm site
D. cold site
正确答案:D
问题 #5
Which of the following is an advantage of the use of hot sites as a backup alternative?
A. The costs associated with hot sites are low
B. Hot sites can be made ready for operation within a short period of time
C. Hot sites can be used for an extended amount of time
D. Hot sites do not require that equipment and systems software be compatible with the primary installation being backed up
正确答案:B
问题 #6
What is not a benefit of Cold Sites?
A. No resource contention with other organization
B. Quick Recovery
C. Geographical location that is not affected by the same disaster
D. low cost
正确答案:B
问题 #7
What is the PRIMARY reason that reciprocal agreements between independent organizations for backup processing capability are seldom used?
A. Lack of successful recoveries using reciprocal agreements.
B. Legal liability of the host site in the event that the recovery fails.
C. Dissimilar equipment used by disaster recovery organization members.
D. Difficulty in enforcing the reciprocal agreement.
正确答案:D
问题 #8
Which of the following alternative business recovery strategies would be LEAST appropriate in a large database and on-line communications network environment where the critical business continuity period is 7 days?
A. Hot site
B. Warm site
C. Duplicate information processing facilities
D. Reciprocal agreement
正确答案:D
问题 #9
A contingency plan should address:
A. Potential risks
B. Residual risks
C. Identified risks
D. All of the above
正确答案:B
问题 #10
Prior to a live disaster test, which of the following is most important?
A. Restore all files in preparation for the test
B. Document expected findings
C. Arrange physical security for the test site
D. Conduct a successful structured walk-through
正确答案:D
问题 #11
Which of the following business continuity stages ensures the continuity strategy remains visible?
A. Backup, Recover and Restoration
B. Testing Strategy Development
C. Post Recovery Transition Data Development
D. Implementation, Testing and Maintenance
正确答案:D
问题 #12
During the testing of the business continuity plan (BCP), which of the following methods of results analysis provides the BEST assurance that the plan is workable?
A. Measurement of accuracy
B. Elapsed time for completion of critical tasks
C. Quantitatively measuring the results of the test
D. Evaluation of the observed test results
正确答案:C
问题 #13
Which of the following recovery plan test results would be most useful to management?
A. elapsed time to perform various activities
B. list of successful and unsuccessful activities
C. amount of work completed
D. description of each activity
正确答案:B
问题 #14
Failure of a contingency plan is usually:
A. A technical failure
B. A management failure
C. Because of a lack of awareness
D. Because of a lack of training
正确答案:B
问题 #15
The first step in contingency planning is to perform:
A. A hardware backup
B. A data backup
C. An operating system software backup
D. An application software backup
正确答案:B
问题 #16
Which of the following server contingency solutions offers the highest availability?
A. System backups
B. Electronic vaulting/remote journaling
C. Redundant arrays of independent disks (RAID)
D. Load balancing/disk replication
正确答案:D
问题 #17
Which of the following statement pertaining to the maintenance of an IT contingency plan is incorrect?
A. The plan should be reviewed at least once a year for accuracy and completeness
B. The Contingency Planning Coordinator should make sure that every employee gets an up-to-date copy of the plan
C. Strict version control should be maintained
D. Copies of the plan should be provided to recovery personnel for storage at home and office
正确答案:B
问题 #18
Which disaster recovery plan test involves functional representatives meeting to review the plan in detail?
A. Simulation test
B. Checklist test
C. Parallel test
D. Structured walkthrough test
正确答案:D
问题 #19
What is the MAIN purpose of periodically testing off-site hardware backup facilities?
A. To eliminate the need to develop detailed contingency plans
B. To ensure that program and system documentation remains current
C. To ensure the integrity of the data in the database
D. To ensure the continued compatibility of the contingency facilities
正确答案:D
问题 #20
Scheduled tests of application contingency plans should be based on the
A. Size and complexity of the application.
B. Number of changes to the application.
C. Criticality of the application.
D. Reliability of the application.
正确答案:C
问题 #21
Which of the following is less likely to accompany a contingency plan, either within the plan itself or in the form of an appendix?
A. Contact information for all personnel
B. Vendor contract information, including offsite storage and alternate site
C. Equipment ad system requirements lists of hardware, software, firmware, and other resources required to support system operations
D. The Business Impact Analysis
正确答案:D
问题 #22
The first step in contingency planning is to perform:
A. A hardware backup
B. A data backup
C. An operating system software backup
D. An application software backup
正确答案:B
问题 #23
Which of the following teams should not be included in an organization's contingency plan?
A. Damage assessment team
B. Hardware salvage team
C. Tiger team
D. Legal affairs team
正确答案:C
问题 #24
In the public sector, as opposed to the private sector, due care is usually determined by
A. Minimum standard requirements.
B. Legislative requirements.
C. Insurance rates.
D. Potential for litigation.
正确答案:B
问题 #25
What is the minimum and customary practice of responsible protection of assets that affects a community or societal norm?
A. Due diligence
B. Risk mitigation
C. Asset protection
D. Due care
正确答案:D
问题 #26
Under the standard of due care, failure to achieve the minimum standards would be considered
A. Negligent
B. Unethical
C. Abusive
D. Illegal
正确答案:A
问题 #27
Under the principle of culpable negligence, executives can be held liable for losses that result from computer system breaches if:
A. the company is not a multi-national company
B. they have not exercised due care protecting computing resources
C. they have failed to properly insure computer resources against loss
D. the company does not prosecute the hacker that caused the breach
正确答案:B
问题 #28
The criteria for evaluating the legal requirements for implementing safeguards is to evaluate the cost (C) of instituting the protection versus the estimated loss (L) resulting from the exploitation f the corresponding vulnerability. Therefore, a legal li
A. C < L
B. C < L - (residual risk)
C. C > L
D. C > L - (residual risk)
正确答案:A
问题 #29
When companies come together to work in an integrated manner such as extranets, special care must be taken to ensure that each party promises to provide the necessary level of protection, liability and responsibility. These aspects should be defined in th
A. Cascade liabilities
B. Downstream liabilities
C. Down-flow liabilities
D. Down-set liabilities
正确答案:B
问题 #30
The typical computer felons are usually persons with which of the following characteristics?
A. The have had previous contact with law enforcement
B. The conspire with others
C. They hold a position of trust
D. They deviate from the accepted norms of security
正确答案:D
问题 #31
Which of the following is responsible for the most security issues?
A. Outside espionage
B. Hackers
C. Personnel
D. Equipment Failure
正确答案:C
问题 #32
Hackers are most often interested in:
A. Helping the community in securing their networks
B. Seeing how far their skills wll take them
C. Getting recognition for their actions
D. Money
正确答案:B
问题 #33
Which of the following categories of hackers poses the greatest threat?
A. Disgruntled employees
B. Student hackers
C. Criminal hackers
D. Corporate spies
正确答案:A
问题 #34
Individuals who have their sole aim as breaking into a computer system are being referred to as:
A. Crackers
B. Sniffers
C. Hackers
D. None of the choices.
正确答案:A
问题 #35
Which of the following tools is less likely to be used by a hacker?
A. l0phtcrack
B. Tripwire
C. Crack
D. John the ripper
正确答案:B
问题 #36
Which of the following tools is not likely to be used by a hacker?
A. Nessus
B. Saint
C. Tripwire
D. Nmap
正确答案:C
问题 #37
Supporting evidence used to help prove an idea of point is described as? It cannot stand on its own, but is used as a supplementary tool to help prove a primary piece of evidence:
A. Circumstantial evidence
B. Corroborative evidence
C. Opinion evidence
D. Secondary evidence
正确答案:B
问题 #38
Which of the following would best describe secondary evidence?
A. Oral testimony by a non-expert witness
B. Oral testimony by an expert witness
C. A copy of a piece of evidence
D. Evidence that proves a specific act
正确答案:C
问题 #39
Which of the following exceptions is less likely to make hearsay evidence admissible in court?
A. Records are collected during the regular conduct of business
B. Records are collected by senior or executive management
C. Records are collected at or near the time of occurrence of the act being investigated
D. Records are in the custody of the witness on a regular basis
正确答案:B
问题 #40
Once evidence is seized, a law enforcement officer should emphasize which of the following?
A. chain of command
B. chain of custody
C. chain of control
D. chain of communications
正确答案:B
问题 #41
Which of the following rules is less likely to allow computer evidence to be admissible in court?
A. It must prove a fact that is material to the case
B. Its reliability must be proven
C. The process for producing it must be documented
D. The chain of custody of evidence must show who collected, security, controlled, handled, transported, and tampered with the evidence
正确答案:C
问题 #42
A copy of evidence or oral description of this contents; not reliable as best evidence is what type of evidence?
A. Direct evidence
B. Circumstantial evidence
C. Hearsay evidence
D. Secondary evidence
正确答案:D
问题 #43
What is defined as inference of information from other, intermediate, relevant facts?
A. Secondary evidence
B. Conclusive evidence
C. Hearsay evidence
D. Circumstantial evidence
正确答案:D
问题 #44
In order to be able to successfully prosecute an intruder:
A. A point of contact should be designated to be responsible for communicating with law enforcement and other external agencies.
B. A proper chain of custody of evidence has to be preserved
C. Collection of evidence has to be done following predefined procedures
D. Whenever possible, analyze, a replica of the compromised resource, not the original, thereby avoiding inadvertently tamping with evidence
正确答案:B
问题 #45
Which of the following proves or disproves a specific act through oral testimony based on information gathered through the witness's five senses?
A. direct evidence
B. best evidence
C. conclusive evidence
D. hearsay evidence
正确答案:A
问题 #46
In order to preserver a proper chain of custody of evidence?
A. Evidence has to be collected following predefined procedures in accordance with all laws and legal regulations
B. Law enforcement officials should be contacted for advice on how and when to collect critical information
C. Verifiable documentation indicating the sequence of individuals who have handled a piece of evidence should be available.
D. Log files containing information regarding an intrusion are retained for at least as long as normal business records, and longer in the case of an ongoing investigation.
正确答案:A
问题 #47
What is the primary reason for the chain of custody of evidence?
A. To ensure that no evidence is lost
B. To ensure that all possible evidence is gathered
C. To ensure that it will be admissible in court
D. To ensure that incidents were handled with due care and due diligence
正确答案:C
问题 #48
Which element must computer evidence have to be admissible in court?
A. It must be relevant
B. It must be annotated
C. It must be printed
D. t must contain source code
正确答案:A
问题 #49
Which kind of evidence would printed business records, manuals, and, printouts classify as?
A. Direct evidence
B. Real evidence
C. Documentary evidence
D. Demonstrative evidence
正确答案:B
问题 #50
Since disks and other magnetic media are only copies of the actual or original evidence, what type of evidence are they are often considered to represent?
A. Hearsay
B. Irrelevant
C. Incomplete
D. Secondary
正确答案:A
问题 #51
Which of the following is LEAST necessary when creating evidence tags detailing the chain of custody for electronic evidence?
A. The mode and means of transportation.
B. Notifying the person who owns the information being seized.
C. Complete description of the evidence, including quality if necessary.
D. Who received the evidence.
正确答案:B
问题 #52
To be admissible in court, computer evidence must be which of the following?
A. relevant
B. decrypted
C. edited
D. incriminating
正确答案:A
问题 #53
Computer-generated evidence is considered:
A. Best evidence
B. Second hand evidence
C. Demonstrative evidence
D. Direct evidence
正确答案:B
问题 #54
Why would a memory dump be admissible as evidence in court?
A. Because it is used to demonstrate the truth of the contents
B. Because it is used to identify the state of the system
C. Because the state of the memory cannot be used as avidence
D. Because of the exclusionary rule
正确答案:B
问题 #55
Evidence corroboration is achieved by
A. Creating multiple logs using more than one utility.
B. Establishing secure procedures for authenticating users.
C. Maintaining all evidence under the control of an independent source.
D. Implementing disk mirroring on all devices where log files are stored.
正确答案:C
问题 #56
You are documenting a possible computer attack. Which one of the following methods is NOT appropriate for legal record keeping?
A. A bound paper notebook.
B. An electronic mail document.
C. A personal computer in "capture" mode that prints immediately.
D. Microcassette recorder for verbal notes
正确答案:D
问题 #57
Which one of the following is NOT a requirement before a search warrant can be issued?
A. There is a probable cause that a crime has been committed.
B. There is an expectation that evidence exists of the crime.
C': "There is probable cause to enter someone's home or business. ", 'D. There is a written document detailing the anticipated evidence.
正确答案:D
问题 #58
Once a decision is made to further investigate a computer crime incident, which one of the following is NOT employed?
A. Identifying what type of system is to be seized.
B. Identifying the search and seizure team members.
C. Identifying the cost of damage and plan for their recover.
D. Determining the risk that the suspect will destroy evidence.
正确答案:C
问题 #59
From a legal perspective, which of the following rules must be addressed when investigating a computer crime?
A. Search and seizure
B. Data protection
C. Engagement
D. Evidence
正确答案:D
问题 #60
Which of the following is not a problem regarding computer investigation issues?
A. Information is intangible
B. Evidence is difficult to gather
C. Computer-generated records are only considered secondary evidence, thus are no as reliable as best evidence
D. In many instances, an expert or specialist is required
正确答案:D
问题 #61
Why is the investigation of computer crime involving malicious damage especially challenging?
A. Information stored in a computer is intangible evidence.
B. Evidence may be destroyed in an attempt to restore the system.
C. Isolating criminal activity in a detailed audit log is difficult.
D. Reports resulting from common user error often obscure the actual violation.
正确答案:B
问题 #62
After law enforcement is informed of a computer crime, the organization's investigators constraints are
A. removed.
B. reduced.
C. increased.
D. unchanged.
正确答案:C
问题 #63
To understand the "whys" in crime, many times it is necessary to understand MOM. Which of the following is not a component of MOM? A.)Opportunities B.) Methods C.) Motivation D.) Means
A. )Opportunities
B. Methods
C. Motivation
D. Means
正确答案:B
问题 #64
What category of law deals with regulatory standards that regulate performance and conduct? Government agencies create these standards, which are usually applied to companies and individuals within those companies.
A. Standards law
B. Conduct law
C. Compliance law
D. Administrative law
正确答案:D
问题 #65
Something that is proprietary to that company and importance for its survival and profitability is what type of intellectual property law?
A. Trade Property
B. Trade Asset
C. Patent
D. Trade Secret
正确答案:D
问题 #66
Which of the following statements regarding trade secrets is false?
A. For a company to have a resource qualify as a trade secret, it must provide the company with some type of competitive value or advantage
B. The Trade Secret Law normally protects the expression of the idea of the resource.
C. Many companies require their employees to sign nondisclosure agreements regarding the protection of their trade secrets
D. A resource can be protected by law if it is not generally known and if it requires special skill, ingenuity, and/or expenditure of money and effort to develop it
正确答案:B
问题 #67
Which category of law is also referenced as a Tort law?
A. Civil law
B. Criminal law
C. Administrative law
D. Public law
正确答案:A
问题 #68
Which of the following European Union (EU) principles pertaining to the protection of information on private individuals is incorrect?
A. Data collected by an organization can be used for any purpose and for as long as necessary, as long as it is never communicated outside of the organization by which it was collected
B. Individuals have the right to correct errors contained in their personal data
C. Transmission of personal information to locations where "equivalent" personal data protection cannot be assured is prohibited.
D. Records kept on an individual should be accurate and up to date
正确答案:B
问题 #69
A country that fails to legally protect personal data in order to attract companies engaged in collection of such data is referred to as a
A. data pirate
B. data haven
C. country of convenience
D. sanctional nation
正确答案:B
问题 #70
Which of the following requires all communications carriers to make wiretaps possible?
A. 1994 U.S. Communications Assistance for Law Enforcement Act
B. 1996 U.S. Economic and Protection of Property Information Act
C. 1996 U.S. National Information Infrastructure Protection Act
D. 1986 U.S. Computer Security Act
正确答案:A
问题 #71
Which of the following U.S. federal government laws/regulations was the first to require the development of computer security plan?
A. Privacy Act of 1974
B. Computer Security Act of 1987
C. Federal Information Resources Management Regulations
D. Office of Management & Budget Circular A-130
正确答案:B
问题 #72
Which U.S. act places responsibility on senior organizational management for prevention and detection programs with fines of up to $290 million for nonperformance?
A. The 1987 U.S. Computer Security Act
B. The 1986 U.S. Computer Fraud and Abuse Act
C. The 1991 U.S. Federal Sentencing Guidelines
D. The 1996 U.S. National Information Infrastructure Protection Act
正确答案:C
问题 #73
What document made theft no longer restricted to physical constraints?
A. The Electronic Espionage Act of 1996
B. The Gramm Leach Bliley Act of 1999
C. The Computer Security Act of 1987
D. The Federal Privacy Act of 1974
正确答案:A
问题 #74
In the US, HIPPA addresses which of the following?
A. Availability and Accountability
B. Accuracy and Privacy
C. Security and Availability
D. Security and Privacy
正确答案:D
问题 #75
Which of the following placed requirements of federal government agencies to conduct security-related training, to identify sensitive systems, and to develop a security plan for those sensitive systems?
A. 1987 U.S. Computer Security Act
B. 1996 U.S. Economic and Protection of Proprietary Information Act
C. 1994 U.S. Computer Abuse Amendments Act
D. 1986 (Amended in 1996) U.S. Computer Fraud and Abuse Act
正确答案:A
问题 #76
Which of the following cannot be undertaken in conjunction with computer incident handling?
A. system development activity
B. help-desk function
C. system backup function
D. risk management process
正确答案:A
问题 #77
What is the primary goal of incident handling?
A. Successfully retrieve all evidence that can be used to prosecute
B': ") Improve the company's ability to be prepared for threats and disasters", 'C': ") Improve the company's disaster recovery plan", 'D. Contain and repair any damage caused by an event
正确答案:D
问题 #78
Which one of the following is NOT a factor to consider when establishing a core incident response team?
A. Technical knowledge
B. Communication skills
C. The recovery capability
D. Understanding business policy
正确答案:C
问题 #79
Which of the following specifically addresses cyber attacks against an organization's IT systems?
A. Continuity of support plan
B. Business continuity plan
C. Incident response plan
D. Continuity of operations plan
正确答案:C
问题 #80
When should a post-mortem review meeting be held after an intrusion has been properly taken care of?
A. Within the first three months after the investigation of the intrusion is completed
B. Within the first week after prosecution of intruders have taken place, weather successful or not
C. Within the first month after the investigation of the intrusion is completed
D. Within the first week of completing the investigation of the intrusion
正确答案:D
问题 #81
During a review of system logs of the enterprise, a security manager discovers that a colleague working on an exercise ran a job to collect confidential information on the company's clients. The colleague who ran the job has since left the company to work
A. The manager should call the colleague and explain what has been discovered. The manager should then ask for the return of the information in exchange for silence.
B. The manager should warn the competitor that a potential crime has been committed that could put their company at risk.
C. The manager should inform his or her appropriate company management, and secure the results of the recover exercise for future review.
D. The manager should call the colleague and ask the purpose of running the job prior to informing his or her company management of the situation.
正确答案:C
问题 #82
In what way could the use of "cookies" violate a person's privacy?
A. When they are used to tie together a set of unconnected requests for web pages to cause an electronic map of where one has been.
B. When they are used to keep logs of who is using an anonymizer to access a site instead of their regular userid.
C. When the e-mail addresses of users that have registered to access the web site are sold to marketing firms.
正确答案:A
问题 #83
Which of the following is the BEST way to prevent software license violations?
A. Implementing a corporate policy on copyright infringements and software use
B': ") Requiring that all PC's be diskless workstations", 'C. Installing metering software on the LAN so applications can be accessed through the metered software
正确答案:D
问题 #84
The ISC2 Code of Ethics does not include which of the following behaviors for a CISSP:
A. moral
B. ethical
C. legal
D. control
正确答案:D
问题 #85
Where can the phrase "Discourage unsafe practice" be found?
A. Computer Ethics Institute commandments
B. (ISC)2 Code of Ethics
C': ") Internet Activities Board's Ethics and the Internet (RFC1087)", 'D. CIAC Guidelines
正确答案:B
问题 #86
One of the offences an individual or company can commit is decompiling vendor code. This is usually done in the hopes of understanding the intricate details of its functionality. What best describes this type of non-ethical engineering?
A. Inverse Engineering
B. Backward Engineering
C. Subvert Engineering
D. Reverse Engineering
正确答案:D
问题 #87
Which one of the following is an ethical consideration of computer technology?
A. Ownership of proprietary software.
B. Information resource management.
C. Service level agreements.
D. System implementation and design.
正确答案:A
问题 #88
The Internet Activities Board characterizes which of the following as unethical behavior for Internet users?
A. Writing computer viruses
B. Monitoring data traffic
C. Westing computer resources
D. Concealing unauthorized accesses
正确答案:D
问题 #89
Which of the following is a potential problem when creating a message digest for forensic purposes?
A. The process if very slow.
B': "The file's last access time is changed. ", 'C. The message digest is almost as long as the data string.
D. One-way hashing technology invalidates message digest processing.
正确答案:D
问题 #90
A forensic examination should inspect slack space because it
A. Contains system level access control kernel.
B. Can contain a hidden file or dat
A.
C. Can contain vital system information.
D. Can be defeted to avoid detection.
正确答案:B
问题 #91
Forensic imaging of a workstation is initiated by
A. Booting the machine with the installed operating system.
B. Booting the machine with an operating system diskette.
C. Removing the hard drive to view the output of the forensic imaging software.
D. Directing the output of the forensic imaging software to the small computer system interface (SCSI).
正确答案:D
问题 #92
A disk image backup is used for forensic investigation because it
A. Is based on secured hardware technology.
B. Creates a bit level copy of the entire disk.
C. Time stamps the files with the date and time of the copy operation.
D. Excludes areas that have never been used to store dat
A.
正确答案:B
问题 #93
When it comes to magnetic media sanitization, what difference can be made between clearing and purging information?
A. Clearing completely erases the media whereas purging only remoes file headers, allowing the recovery of files
B. Clearing renders information unrecoverable by a keyboard attack and purging renders information unrecoverable against laboratory attack
C. They both involve rewriting the media
D. Clearing renders information unrecoverable against a laboratory attack and purging renders information unrecoverable to a keyboard attack
正确答案:B
问题 #94
What is HIPPA?
A. The Home Insurance Portability & Accountability Act of 1996 (August 21), Public Law 104-191, which amends the Internal Revenue Service Code of 1986. Also known as the Kennedy-Kassebaum Act.
B. The Public Health Insurance Portability & Accountability Act of 1996 (August 21), Public Law 104-191, which amends the Internal Revenue Service Code of 1986. Also known as the Kennedy-Kassebaum Act.
C. )The Health Insurance Privacy & Accountability Act of 1996 (August 2), public law 104-191, which amends the Internal Revenue Service Code of 1986. Also known as the Kennedy-Kassebaum Act.
D. The Health Insurance Privacy & Accountability Act of 1996 (August 2), Public Law 104-191, which amends the Internal Revenue Service Code of 1986. Also known as the Kennedy-Kassebaum Act.
正确答案:B
问题 #95
The privacy provisions of the federal law, the Health Insurance Portability and Accountability Act of 1996 (HIPPA),
A. apply to certain types of critical health information created or maintained by health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
B. apply to health information created or maintained by health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
C. apply to health information created or maintained by some large health care providers who engage in certain electronic transactions, health plans, and health care clearinghouses.
D. apply to health information created or maintained by health care providers regardless of whether they engage in certain electronic transactions, health plans, and health care clearinghouses.
正确答案:B
问题 #96
Gap analysis does not apply to
A. Transactions
B. availability
C. Privacy
D. Security
正确答案:B
问题 #97
A gap analysis for Privacy refers
A. to the practice of identifying the policies and procedures you currently have in place regarding the availability of protected health information.
B. to the practice of identifying the policies and procedures you currently have in place regarding the confidentiality of protected health information.
C. to the practice of identifying the policies and procedures you currently have in place regarding the authenticity of protected health information.
D. to the practices of identifying the legislation you currently have in place regarding the confidentiality of protected health information.
正确答案:B
问题 #98
A gap analysis for Privacy
A. includes a comparison of your proposed policies and procedures and the requirements established in the Security and Privacy Regulation in order to identify any necessary modifications in existing policies to satisfy HIPPA regulations when they are stricter than state privacy laws.
B. includes a comparison of your current policies and procedures and the requirements established in the Security and Privacy Regulation in order to identify any necessary modifications in existing policies to satisfy HIPPA regulations when they are stricter than state privacy laws
C. includes a comparison of your ideal policies and procedures and the requirements established in the Security and Privacy Regulation in order to identify any necessary modifications in existing policies to satisfy HIPPA regulations when they are stricter than state privacy laws.
D. includes a comparison of your exceptional policies and procedures and the requirements established in the Security and Privacy Regulation in order to identify any necessary modifications in existing policies to satisfy HIPPA regulations when they are stricter than state privacy laws
正确答案:B
问题 #99
What is a gap analysis in relationship to HIPPA?
A. In terms of HIPPA, a gap analysis cannot be defined.
B. In terms of HIPPA, a gap analysis defines what an organization currently is doing in a specific area of their organization and compares current operations to other requirements mandated by ethical standards.
C. In terms of HIPPA, a gap analysis defines what an organization currently is doing in a specific area of their organization and compares current operations to other requirements mandated by state or federal law
D. In terms of HIPPA, a gap analysis defines what an organization proposes to be doing in a specific area of their organization and compares proposed operations to other requirements mandated by state or federal law.
正确答案:C
问题 #100
The privacy provisions of the federal law, the Health Insurance Portability and Accountability Act of 1996 (HIPPA), apply to certain types of health information created or maintained by health care providers
A. who engage in certain electronic transactions, health plans, and health care clearinghouses
B. who do not engage in certain electronic transactions, health plans, and health care clearinghouses
C. regardless of whether they engage in certain electronic transactions, health plans, and health care clearinghouses
D. if they engage for a majority of days in a year in certain electronic transactions, health plans, and health care clearinghouses.
正确答案:A

即刻预约

免费试听-咨询课程-获取免费资料