首页 > 题库 > CISSP
« 返回题库列表

2026年CISSP全英文回忆题汇总|最新考试真题+答案解析

问题 #1
HIPPA preempts state laws
A. except to the extent that the state law is less stringent
B. regardless of the extent that the state law is more stringent
C. except to the extent that the state law more stringent
D. except to the extent that the state law is legislated later than HIPPA
正确答案:C
问题 #2
The Implementation Guides
A. are referred to in the Static Rule
B. are referred to in the Transaction Rule
C. are referred to in the Transitional Rule
D. are referred to in the Acquision Rule
正确答案:B
问题 #3
The HIPPA task force must first
正确答案:A
问题 #4
A covered healthcare provider which a direct treatment relationship with an individual need not:
A. provide the notice no later than the date of the first service delivery, including service delivered electronically
B. have the notice available at the service delivery site for individuals to request and keep
C. get a acknowledgement of the notice from each individual on stamped paper
D. post the notice in a clear and prominent location where it is reasonable to expect individuals seeking service from the covered healthcare provider to be able to read it
正确答案:C
问题 #5
A health plan may conduct its covered transactions through a clearinghouse, and may require a provider to conduct covered transactions with it through a clearinghouse. The incremental cost of doing so must be borne
A. by the HIPPA authorities
B. by the health plan
C. by any other entity but the health plan
D. by insurance companies
正确答案:B
问题 #6
Covered entities (certain health care providers, health plans, and health care clearinghouses) are not required to comply with the HIPPA Privacy Rule until the compliance date. Covered entities may, of course, decide to:
A. unvoluntarily protect patient health information before this date
B. voluntarily protect patient health information before this date
C. after taking permission, voluntarily protect patient health information before this date
D. compulsorily protect patient health information before this date
正确答案:B
问题 #7
The confidentiality of alcohol and drug abuse patient records maintained by this program is protected by federal law and regulations. Generally, the program may not say to a person outside the program that a patient attends the program, or disclose any in
A. )The person outside the program gives a written request for the information
B. the patient consent in writing
C. the disclosure is allowed by a court order
D. the disclosure is made to medical personnel in a medical emergency or to qualified personnel for research, audit, or program evaluation.
正确答案:D
问题 #8
What is a Covered Entity? The term "Covered Entity" is defined in 160.103 of the regulation.
A. The definition is complicate and long.
B. The definition is referred to in the Secure Computing Act
C. The definition is very detailed.
D. The definition is deceptively simple and short
正确答案:D
问题 #9
Are employers required to submit enrollments by the standard transactions?
A. Though Employers are not CEs and they have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards
B. Employers are not CEs and do not have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards.
C. Employers are CEs and have to send enrollment using HIPPA standard transactions. However, the employer health plan IS a CE and must be able to conduct applicable transactions using the HIPPA standards.
D. Employers are CEs and do not have to send enrollment using HIPPA standard transactions. Further, the employer health plan IS also a CE and must be able to conduct applicable transactions using the HIPPA standards.
正确答案:B
问题 #10
Employers
A. often advocate on behalf of their employees in benefit disputes and appeals, answer questions with regard to the health plan, and generally help them navigate their health benefits.
B. sometimes advocate on behalf of their employees in benefit disputes and appeals, answer questions with regard to the health plan, and generally help them navigate their health benefits.
C. never advocate on behalf of their employees in benefit disputes and appeals, answer questions with regard to health plan, and generally help them navigate their health benefits.
D. are prohibited by plan sponsors from advocating on behalf of group health plan participants or providing assistance in understanding their health plan.
正确答案:A
问题 #11
Employers
A. are covered entities if they do not use encryption
B. are covered entities
C. are not legal entities
D. are not covered entities
正确答案:D
问题 #12
The HIPPA task force must inventory the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient care and central to the organizations business. All must be inventoried and listed by
A. by priority as well as encryption levels, authenticity, storage-devices, availability, reliability, access and use. The person responsible for criticality analysis must remain mission-focused and carefully document all the criteria used.
B. by priority and cost as well as availability, reliability, access and use. The person responsible for criticality analysis must remain mission-focused and carefully document all the criteria used.
C. by priority as well availability, reliability, access and use. The person responsible for criticality analysis must remain mission-focused but need not document all the criteria used.
D. by priority as well as availability, reliability, access and use. The person responsible for criticality analysis must remain mission-focused and carefully document all the criteria used.
正确答案:D
问题 #13
Are there penalties under HIPPA?
A. No penalties
B. HIPPA calls for severe civil and criminal penalties for noncompliance, including: -- fines up to $25k for multiple violations of the same standard in a calendar year -- fines up to $250k and/or imprisonment up to 10 years for knowing misuse of individually identifiable health information.
C. HIPPA calls for severe civil and criminal penalties for noncompliance, includes: -- fines up to 50k for multiple violations of the same standard in a calendar year -- fines up to $500k and/or imprisonment up to 10 years for knowing misuse of individually identifiable health information
D. HIPPA calls for severe civil and criminal penalties for noncompliance, including: -- fines up to $100 for multiple violations of the same standard in a calendar year -- fines up to $750k and/or imprisonment up to 20 years for knowing misuse of individually identifiable health information
正确答案:B
问题 #14
HIPPA gave the option to adopt other financial and administrative transactions standards, "consistent with the goals of improving the operation of health care system and reducing administrative costs" to
A. ASCA prohibits HHS from paying Medicare claims that are not submitted electronically after October 16, 2003.
B. ASCA prohibits HHS from paying Medicare claims that are not submitted on paper after October 16, 2003
C. ASCA prohibits HHS from paying Medicare claims that are not submitted electronically after October 16, 2003, unless the Secretary grants a waiver from this requirement
D. No
正确答案:C
问题 #15
May a health plan require a provider to use a health care clearinghouse to conduct a HIPPA-covered transaction, or must the health plan acquire the ability to conduct the transaction directly with those providers capable of conducting direct transactions?
A. A health plan may conduct its covered transactions through a clearinghouse, and may require a provider to conduct covered transactions with it through a clearinghouse. But the incremental cost of doing so must be borne by the health plan. It is a cost-benefit decision on the part of the health plan whether to acquire the ability to conduct HIPPA transactions directly with other entities, or to require use of a clearinghouse.
B': ") A health plan may not conduct it's covered transactions through a clearinghouse", 'C. A health plan may after taking specific permission from HIPPA authorities conduct its covered transactions through a clearinghouse
D. is not as per HIPPA allowed to require provider to conduct covered transactions with it through a clearinghouse
正确答案:A
问题 #16
Business Associate Agreements are required by the regulation whenever a business associate relationship exists. This is true even when the business associates are both covered entities.
A. There are no specific elements which must be included in a Business Associate Agreement. However some recommended but not compulsory elements are listed in 164.504(e) (2)
B. There are specific elements which must be included in a Business Associate Agreement. These elements are listed Privacy Legislation
C. There are no specific elements which must be included in a Business Associate Agreement.
D. There are specific elements which must be included in a Business Associate Agreement. These elements are listed in 164.504(e) (2)
正确答案:D
问题 #17
The implementation Guides
A. are referred to in the Transaction Rule
B. are not referred to in the Transaction Rule
C. are referred to in the Compliance Rules
D. are referred to in the Confidentiality Rule
正确答案:A
问题 #18
Business Associates
A. are entities that perform services that require the use of Protected Health Information on behalf of Covered Entities. One covered entity may be a business partner of another covered entity
B. are entities that do not perform services that require the use of Protected Health Information on behalf of Covered Entities. One covered entity may be a business partner of another covered entity
C. are entities that perform services that require the use of Encrypted Insurance Information on behalf of Covered Entities. One covered entity may be a business partner of another covered entity
D. are entities that perform services that require the use of Protected Health Information on behalf of Covered Entities. One covered entity cannot be a business partner of another covered entity.
正确答案:A
问题 #19
Health Care Providers, however,
A. become the business associates of health plans even without joining a network
B. become the business associates of health plans by simply joining a network
C. do not become the business associates of health plans by simply joining a network
D. do not become the HIPPA associates of health plans by simply joining a network
正确答案:C
问题 #20
In terms of HIPPA what an organization currently is doing in a specific area of their organization and compared current operations to other requirements mandated by state or federal law is called
A. HIPPA status analysis
B. gap analysis
C. comparison analysis
D. stop-gap analysis
正确答案:B
问题 #21
Group Health Plans sponsored or maintained by employers, however,
A. ARE SOMETIMES covered entities.
B. ARE NOT covered entities.
C. ARE covered entities
D. ARE called uncovered entities
正确答案:C
问题 #22
Employers often advocate on behalf of their employees in benefit disputes and appeals, answer questions with regard to the health plan, and generally help them navigate their health benefits. Is this type of assistance allowed under the regulation?
A. The final rule does nothing to hinder or prohibit plan sponsors from advocating on behalf of group health plan participants or providing assistance in understanding their health plans.
B. The final rule prohibits plan sponsors from advocating on behalf of group health plan participants or providing assistance in understanding their health plans
C. The final rule does hinder but does not prohibit plan sponsors from advocating on behalf of group health plan participants or providing assistance in understanding their health plans
D. The final rule does no advocating on behalf of group health plan participants or provide assistance in understanding their health plan.
正确答案:A
问题 #23
HIPPA does not call for:
A. Standardization of electronic patient health, administrative and financial data
B. Unique health identifiers for individuals, employers, health plans, and health care providers.
C. Common health identifiers for individuals, employers, health plans and health care providers.
D. Security standards protecting the confidentiality and integrity of "individually identifiable health information," past, present or future.
正确答案:C
问题 #24
A gap analysis for the Transactions set refer to the practice of identifying the data content you currently have available
A. through your medical software
B. through your accounting software
C. through competing unit medical software
D. based on the statutory authorities report
正确答案:A
问题 #25
A gap analysis for the Transactions set does not refer to
A. the practice of identifying the data content you currently have available through your medical software
B. the practice of and comparing that content to what is required by HIPPA, and ensuring there is a match.
C. and requires that you study the specific format of a regulated transaction to ensure that the order of the information when sent electronically matches the order that is mandated in the Implementation Guides.
D. but does not require that you study the specific format of a regulated transaction to ensure that the order of information when sent electronically matches the order that is mandated in the Implementation Guides.
正确答案:D
问题 #26
Health Information Rights although your health record is the physical property of the healthcare practitioner or facility that compiled it, the information belongs to you. You do not have the right to:
A. obtain a paper copy of the notice of information practices upon request inspect and obtain a copy of your health record as provided for in 45 CFR 164.524
B. request a restriction on certain uses and disclosures of your information outside the terms as provided by 45 CFR 164.522
C. amend your health record as provided in 45 CFR 164.528 obtain an accounting of disclosures of your health information as provided in 45 CFR 164.528
D. revoke your authorization to use or disclose health information except to the extent that action has already been taken
正确答案:B
问题 #27
Employers often advocate on behalf of their employees in benefit disputes and appeals, answer questions with regard to the health plan, and generally help them navigate their health benefits. Is individual consent required?
A. No
B. Sometimes
C. Yes
D. The answer is indeterminate
正确答案:C
问题 #28
Who enforces HIPPA?
A. The Office of Civil Rights of the Department of Confidentiality Services is responsible for enforcement of these rules
B. The Office of Civil Rights of the Department of Health and Human Services is responsible for enforcement of these rules
C. The Office of Health Workers Rights of the Department of Health and Human Services in responsible for enforcement of these rules
D. The Department of Civil Rights of the Office of Health and Human Services is responsible for enforcement of these rules
正确答案:B
问题 #29
Gap analysis does not apply to
A. Transactions
B. availability
C. Privacy
D. Security
正确答案:B
问题 #30
A gap analysis for Security
A. refers to the practice of trusting the security policies and practices currently in place in your organization designed to protect all your data from unauthorized access, alternation or inadvertent disclose.
B. refers to the practice of modifying the security policies and practices currently in place in your organization designed to protect all your data from unauthorized access, alteration or inadvertent disclosure.
C. refers to the practice of identifying the security policies and practices currently in place in your organization designed to protect all your data from unauthorized access, alteration or inadvertent disclosure.
D. refers to the practice of improving the security policies and practices currently in place in your organization designed to protect all your data from unauthorized access alteration or inadvertent disclosure.
正确答案:C
问题 #31
The Implementation Guides are referred to in the Transaction Rule. The manuals are
A. non-technical in nature and do not specifically state what the data content should be for each HIPPA transaction. They also do not state the order in which this data must appear when transmitted electronically.
B. theoretical in nature and specifically state what the data content should be for each HIPPA transaction. They also state the order in which this data must appear when transmitted electronically.
C. technical in nature and specifically state what the data content should be for each HIPPA transaction. They do not state the order in which this data must appear when transmitted electronically.
D. technical in nature and specifically state what the data content should be for each HIPPA transaction. They also state the order in which this data must appear when transmitted electronically.
正确答案:D
问题 #32
Title II of HIPPA includes a section, Administrative Simplification, not requiring:
A. Improved efficiency in healthcare delivery by standardizing electronic data interchange
B. Protection of confidentiality of health data through setting and enforcing standards
C. Protection of security of health data through setting and enforcing standards
D. Protection of availability of health data through setting and enforcing standards
正确答案:D
问题 #33
Who is not affected by HIPPA?
A. clearing houses
B. banks
C. universities
D. billing agencies
正确答案:B
问题 #34
HIPPA results in
A. sweeping changed in some healthcare transaction and administrative information systems
B. sweeping changes in most healthcare transaction and administrative information systems
C. minor changes in most healthcare transaction and administrative information systems
D. no changes in most healthcare transaction and minor changes in administrative information systems
正确答案:B
问题 #35
Which one is an example of a man-in-the-middle attack?
A. Buffer overflow
B. DoS attack
C. All of the above
D. None of the above
正确答案:D
问题 #36
Which one of these is a basic firewall?
A. Packet Filtering Firewalls
B. Proxy Firewalls
C. All of the above
D. None of the above
正确答案:A
问题 #37
Why is there an exception area in a policy?
A': "Policy isn't valid without it", 'B. Management has to deal with various issues that may require exceptions
C. All of the above
D. None of the above
正确答案:B
问题 #38
Which is a characteristic of IDEA?
A. 56 bytes
B. 64 bits
C. 64 bytes
D. All of the above
E. None of the above
正确答案:B
问题 #39
Which of the following can be used to raise awareness of the importance of security and risk?
A. Money
B. All of the above
C. None of the above
正确答案:C
问题 #40
Which mechanism complements an IDS?
A. Activating the built in VPN capabilities
B. Configuring built in alerts
C. All of the above
D. None of the above
正确答案:B
问题 #41
A programmer creates a virus producing tool in order to test the performance of a new virus diction product.
A. This is ethical because it was created to test and enhance the performance of a virus protection tool
B': "It's unethical because the virus creating tool may become available to the public. ", 'C. All of the above
D. None of the above
正确答案:B
问题 #42
In a discretionary mode, which of the following entities is authorized to grant information access to other people?
A. Manager
B. Group leader
C. Security manager
D. User
正确答案:D
问题 #43
Which DES mode of operation is best suited for database encryption?
A. Cipher Block Chaining (CBC) mode
B. Cycling Redundancy Checking (CRC) mode
C. Electronic Code Book (ECB) mode
D. Cipher Feedback (CFB) mode
正确答案:C
问题 #44
Within the realm of IT security, which of the following combinations best defines risk?
A. Threat coupled with a breach.
B. Threat coupled with a vulnerability.
C. Vulnerability coupled with an attack.
D. Threat coupled with a breach of security.
正确答案:B
问题 #45
Which of the following would be the best reason for separating the test and development environments?
A. To restrict access to systems under test.
B. To control the stability of the test environment.
C. To segregate user and development staff.
D. To secure access to systems under development.
正确答案:B
问题 #46
Which of the following statements pertaining to dealing with the media after a disaster occurred and disturbed the organizations activities is incorrect?
A. The CEO should always be the spokesperson for the company during a disaster.
B. The disaster recover plan must include how the media is to be handled during the disaster.
C': "The organization's spokesperson should report bad news before the press gets a hold of it through another channel. ", 'D. An emergency press conference site should be planned ahead.
正确答案:A
问题 #47
Which Orange book security rating introduces security labels?
A. C2
B. B1
C. B2
D. B3
正确答案:B
问题 #48
A Business Impact Analysis (BIA) does not:
A. Recommend the appropriate recovery solution.
B. Determine critical and necessary business functions and their resource dependencies.
C. Identify critical computer applications and the associated outage tolerance.
D. Estimate the financial impact of a disruption.
正确答案:A
问题 #49
Which access control model enables the owner of the resource to specify what subjects can access specific resources?
A. Discretionary Access Control
B. Mandatory Access Control
C. Sensitive Access Control
D. Role-based Access Control
正确答案:A
问题 #50
What type of cable is used with 100Base-TX Fast Ethernet?
A. Fiber-optic cable
B. Four pairs of Category 3, 4 or 5 unshielded twisted-par (UTP) wires.
C. Two pairs of Category 5 unshielded twisted-pair (UTP) or Category 1 shielded twisted-pair (STP) wires.
D. RG.58 cable.
正确答案:C
问题 #51
Which of the following best describes the Secure Electronic Transaction (SET) protocol?
A. Originated by VISA and MasterCard as an Internet credit card protocol.
B. Originated by VISA and MasterCard as an Internet credit card protocol using digital signatures.
C. Originated by VISA and MasterCard as an Internet credit card protocol using the transport layer.
D. Originated by VISA and MasterCard as an Internet credit card protocol using SSL.
正确答案:B
问题 #52
At which of the following phases of a software development life cycle are security and access controls normally designed?
A. Coding
B. Product design
C. Software plans and requirements
D. Detailed design
正确答案:D
问题 #53
Which type of control would password management classify as?
A. Compensating control
B. Detective control
C. Preventive control
D. Technical control
正确答案:C
问题 #54
Due are is not related to:
A. Good faith
B. Prudent man
C. Profit
D. Best interest
正确答案:C
问题 #55
Which of the following is not an Orange Book-defined life cycle assurance requirement?
A. Security testing
B. Design specification and testing
C. Trusted distribution
D. System integrity
正确答案:D
问题 #56
What is another name for the Orange Book?
A. The Trusted Computer System Evaluation Criteria (TCSEC)
B. The Trusted Computing Base (TCB)
C. The Information Technology Security Evaluation Criteria (ITSEC)
D. The Common Criteria
正确答案:A
问题 #57
A password that is the same for each log-on session is called a?
A. "one-time password"
B. "two-time password"
C. static password
D. dynamic password
正确答案:C
问题 #58
Which of the following backup methods is most appropriate for off-site archiving?
A. Incremental backup method.
B. Off-site backup method.
C. Full backup method.
D. Differential backup method.
正确答案:C
问题 #59
Which of the following is not a weakness of symmetric cryptography?
A. Limited security
B. Key distribution
C. Speed
D. Scalability
正确答案:C
问题 #60
Which of the following is not a defined layer in the TCP/IP protocol model?
A. Application layer
B. Session layer
C. Internet layer
D. Network access layer
正确答案:B
问题 #61
Rewritable and erasable (CDR/W) optical disk are sometimes used for backups that require short time storage for changeable data, but require?
A. Faster file access than tape.
B. Slower file access than tape.
C. Slower file access than drive.
D. Slower file access than scale.
正确答案:A
问题 #62
Which one of the following is not a primary component or aspect of firewall systems?
A. Protocol filtering
B. Packet switching
C. Rule enforcement engine
D. Extended logging capability
正确答案:B
问题 #63
What are database views used for?
A. To ensure referential integrity.
B. To allow easier access to data in a database.
C. To restrict user access to data in a database.
D. To provide audit trails.
正确答案:C
问题 #64
Which of the following Common Data Network Services is used to send and receive email internally or externally through an email gateway device?
A. File services
B. Mail services
C. Print services
D. Client/Server services
正确答案:B
问题 #65
Intrusion detection has which of the following sets of characteristics.
A. It is adaptive rather than preventive.
B. It is administrative rather than preventive.
C. It is disruptive rather than preventative.
D. It is detective rather than preventative.
正确答案:D
问题 #66
Which type of password provides maximum security because a new password is required for each now log-on is defined to as?
A. One-time or dynamic password
B. Cognitive password
C. Static password
D. Pass phrase
正确答案:A
问题 #67
They in form of credit card-size memory cards or smart cards, or those resembling small calculators, are used to supply static and dynamic passwords are called?
A. Token Ring
B. Tokens
C. Token passing networks
D. Coupons
正确答案:B
问题 #68
Which of the following uses a directed graph to specify the rights that a subject can transfer to an object, or that a subject can take from another subject?
A. Take-Grant model
B. Access Matrix model
C. Biba model
D. Bell-Lapadula model
正确答案:A
问题 #69
Which of the following is the BEST way to prevent software license violations?
A. Implementing a corporate policy on copyright infringements and software use.
B. Requiring that all PCs be diskless workstations.
C. Installing metering software on the LAN so applications can be accessed through the metered software.
D. Regularly scanning used PCs to ensure that unauthorized copies of software have not been loaded on the PC.
正确答案:D
问题 #70
Zip/Jaz drives, SyQuest, and Bemoulli boxes are very transportable and are often the standard for?
A. Data exchange in many businesses.
B. Data change in many businesses.
C. Data compression in many businesses.
D. Data interchange in many businesses.
正确答案:A
问题 #71
What are two types of system assurance?
A. Operational Assurance and Architecture Assurance.
B. Design Assurance and Implementation Assurance.
C. Architecture Assurance and Implementation Assurance.
D. Operational Assurance and Life-Cycle Assurance.
正确答案:D
问题 #72
Why does compiled code pose more risk than interpreted code?
A. Because malicious code can be embedded in the compiled code and can be difficult to detect.
B. Because the browser can safely execute all interpreted applets.
C. Because compilers are not reliable.
D. It does not. Interpreted code poses more risk than compiled code.
正确答案:A
问题 #73
Which model, based on the premise that the quality of a software product is a direct function of the quality of its associated software development and maintenance processes, introduced five levels with which the maturity of an organization involved in th
A. The Total Quality Model (TQM)
B. The IDEAL Model
C. The Software Capability Maturity Model
D. The Spiral Model
正确答案:C
问题 #74
Phreakers are hackers who specialize in telephone fraud. What type of telephone fraud simulates the tones of coins being deposited into a payphone?
A. Red Boxes
B. Blue Boxes
C. White Boxes
D. Black Boxes
正确答案:A
问题 #75
What is the proper term to refer to a single unit of Ethernet data?
A. Ethernet segment
B. Ethernet datagram
C. Ethernet frame
D. Ethernet packet
正确答案:C
问题 #76
Which of the following represents an ALE calculation?
A. Singe loss expectancy x annualized rate of occurrence.
B. Gross loss expectancy x loss frequency.
C. Actual replacement cost - proceeds of salvage.
D. Asset value x loss expectancy.
正确答案:A
问题 #77
IF an operating system permits executable objects to be used simultaneously by multiple users without a refresh of the objects, what security problem is most likely to exist?
A. Disclosure of residual dat
A.
B. Unauthorized obtaining of a privileged execution state.
C. Data leakage through covert channels.
D. Denial of service through a deadly embrace.
正确答案:A
问题 #78
Tape arrays use a large device with multiple (sometimes 32 or 64) tapes that are configured as a?
A. Single array
B. Dual array
C. Triple array
D. Quadruple array
正确答案:A
问题 #79
Why would anomaly detection IDSs often generate a large number of false positives?
A. Because they can only identify correctly attacks they already know about.
B. Because they are application-based are more subject to attacks.
C. Because they cant identify abnormal behavior.
D. Because normal patterns of user and system behavior can vary wildly.
正确答案:D
问题 #80
According to private sector data classification levels, how would salary levels and medical information be classified?
A. Public
B. Sensitive
C. Private
D. Confidential
正确答案:C
问题 #81
Which of the following is used in database information security to hide information?
A. Inheritance
B. Polyinstantiation
C. Polymorphism
D. Delegation
正确答案:B
问题 #82
Which of the following evaluates the product against the specification?
A. Verification
B. Validation
C. Concurrence
D. Accuracy
正确答案:A
问题 #83
Application Level Firewalls are commonly a host computer running proxy server software, which makes a?
A. Proxy Client
B. Proxy Session
C. Proxy System
D. Proxy Server
正确答案:D
问题 #84
What attack involves the perpetrator sending spoofed packet(s) with the SYN flag set to the victim's machine on any open port that is listening?
A. Bonk attack
B. Land attack
C. Teardrop attack
D. Smurf attack
正确答案:B
问题 #85
The beginning and the end of each transfer during asynchronous communication data transfer are marked by?
A. Start and Stop bits.
B. Start and End bits.
C. Begin and Stop bits.
D. Start and Finish bits.
正确答案:A
问题 #86
Most of unplanned downtime of information systems is attributed to which of the following?
A. Hardware failure
B. Natural disaster
C. Human error
D. Software failure
正确答案:A
问题 #87
Raid that functions as part of the operating system on the file server
A. Software implementation
B. Hardware implementation
C. Network implementation
D. Netware implementation
正确答案:A
问题 #88
During which phase of an IT system life cycle are security requirements developed?
A. Operation
B. Initiation
C. Development
D. Implementation
正确答案:C
问题 #89
Ensuring that printed reports reach proper users and that receipts are signed before releasing sensitive documents are examples of?
A. Deterrent controls
B. Output controls
C. Information flow controls
D. Asset controls
正确答案:B
问题 #90
Non-Discretionary Access Control. A central authority determines what subjects can have access to certain objects based on the organizational security policy. The access controls may be based on?
A. The societies role in the organization.
B': "The individual's role in the organization. ", 'C': "The group-dynamics as they relate to the individual's role in the organization.", 'D. The group-dynamics as they relate to the master-slave role in the organization.
正确答案:B
问题 #91
An effective information security policy should not have which of the following characteristics?
A. Include separation of duties.
B. Be designed with a short-to mid-term focus.
C. Be understandable and supported by all stakeholders.
D. Specify areas of responsibility and authority.
正确答案:B
问题 #92
Which of the following statements pertaining to secure information processing facilities is incorrect?
A. Walls should have an acceptable fire rating.
B. Windows should be protected by bars.
C. Doors must resist forcible entry.
D. Location and type of fire suppression systems should be known.
正确答案:B
问题 #93
Making sure that the data is accessible when and where it is needed is which of the following?
A. Confidentiality
B. Integrity
C. Acceptability
D. Availability
正确答案:D
问题 #94
Business continuity plan development depends most on?
A. Directives of Senior Management
B. Business Impact Analysis (BIA)
C. Scope and Plan Initiation
D. Skills of BCP committee
正确答案:B
问题 #95
Which layer defines the X.25, V.35, X,21 and HSSI standard interfaces?
A. Transport layer
B. Network layer
C. Data link layer
D. Physical layer
正确答案:D
问题 #96
Related to information security, availability is the opposite of which of the following?
A. Delegation
B. Distribution
C. Documentation
D. Destruction
正确答案:D
问题 #97
Which of the following is a disadvantage of a behavior-based ID system?
A. The activity and behavior of the users while in the networked system may not be static enough to effectively implement a behavior-based ID system.
B. The activity and behavior of the users while in the networked system may be dynamic enough to effectively implement a behavior-based ID system.
C. The activity and behavior of the users while in the networked system may not be dynamic enough to effectively implement a behavior-based ID system.
D. The system is characterized by high false negative rates where intrusions are missed.
正确答案:A
问题 #98
Which of the following statements pertaining to VPN protocol standards is false?
A. L2TP is a combination of PPTP and L2F.
B. L2TP and PPTP were designed for single point-to-point client to server communication.
C. L2TP operates at the network layer.
D. PPTP uses native PPP authentication and encryption services.
正确答案:C
问题 #99
What is the most critical characteristic of a biometric identifying system?
A. Perceived intrusiveness
B. Storage requirements
C. Accuracy
D. Reliability
正确答案:C
问题 #100
RAID Software can run faster in the operating system because neither use the hardware-level parity drives by?
A. Simple striping or mirroring.
B. Hard striping or mirroring.
C. Simple hamming code parity or mirroring.
D. Simple striping or hamming code parity.
正确答案:A

即刻预约

免费试听-咨询课程-获取免费资料