« 返回题库列表2026 CISSP模拟题及答案|最新考试真题+题库资料下载
问题 #1
In Mandatory Access Control, sensitivity labels attached to objects contain what information?
A. The item's classification
B. The item's classification and category set
C. The item's category
D. The items' need to know
问题 #2
When it comes to magnetic media sanitization, what difference can be made between clearing and purging information?
A. Clearing completely erases the media whereas purging only removes file headers, allowing the recovery of files.
B. Clearing renders information unrecoverable by a keyboard attack and purging renders information unrecoverable against laboratory attack.
C. They both involve rewriting the medi
A.
D. Clearing renders information unrecoverable against a laboratory attack and purging renders information unrecoverable to a keyboard attack.
问题 #3
What security model is dependent on security labels?
A. Discretionary access control
B. Label-based access control
C. Mandatory access control
D. Non-discretionary access control
问题 #4
What is the window of time for recovery of information processing capabilities based on?
A. Quality of the data to be processed
B. Nature of the disaster
C. Criticality of the operations affected
D. Applications that are mainframe based
问题 #5
Chrissy is a new employee at a coffee shop. She meets three other co-workers on her first day. Since they all work different shifts, sometimes opening the store and sometimes closing the store, they have been given the store security code. Chrissy asks he
A. Physical control
B. Least privilege
C. Separation of duties
D. Collusion
问题 #6
Recently passed over for an executive promotion, Carol is anxious to hear about a major company announcement which will most likely reveal the new hire. Knowing that the PR department does not regularly shred documents, she snoops around the hallways afte
A. Social engineering
B. Eavesdropping
C. Passive attacking
D. Dumpster diving
问题 #7
Denial-of-service attacks are common tactics used by hackers to affect the service capabilities of companies' computer systems. Often times, they are brought forward by competing companies. Which attack below would not be considered a DoS attack?
A. Ping of Death
B. Smurf
C. SYN flooding
D. Man-in-the-middle
问题 #8
Which of the following virus types changes some of its characteristics as it spreads?
A. boot sector
B. parasitic
C. stealth
D. polymorphic
问题 #9
Each distinguished name (DN) in an LDAP directory represents a collection of attributes about a specific object, and is stored in the directory as an entry. DNs are composed of Common Name (CN) components which describe the object, and Domain Components (
A. dc=Shon Harris,cn=LogicalSecurity,dc=com
B. cn=Shon Harris,dc=LogicalSecurity,cn=com
C. cn=Shon Harris,cn=LogicalSecurity,dc=com
D. cn=Shon Harris,dc=LogicalSecurity,dc=com
问题 #10
Since 9/11, airport parking garages now keep cars further away from the terminal entrance. What is this an example of?
A. An administrative control
B. A technical control
C. An environmental control
D. A physical control
问题 #11
Macro viruses written in Visual Basic for Applications (VBA) are a major problem because
A. Floppy disks can propagate such viruses.
B. These viruses can infect many types of environments.
C. Anti-virus software is usable to remove the viral code.
D. These viruses almost exclusively affect the operating system.
问题 #12
The main differences between a software process assessment and a software capability evaluation are:
A. Software process assessments and software capability evaluations are essentially identical, and there are no major differences between the two.
B. Software capability evaluations determine the state of an organizations current software process and are used to gain support from within the organization for a software process improvement program; software process assessments are used to identify contractors who are qualified to develop software or to monitor the state of the software process in a current software project.
C. Software process assessments are used to develop a risk profile for source selection; software capability evaluations are used to develop an action plan for continuous process improvement.
D. Software process assessments determine the state of an organizations current software process and are used to gain support from within the organization for a software process improvement program; software capability evaluations are used to identify contractors who are qualified to develop software or to monitor the state of the software process in a current software project.
问题 #13
Controls provide accountability for individuals who are accessing sensitive information. This accountability is accomplished:
A. through access control mechanisms that require identification and authentication and through the audit function.
B. through logical or technical controls involving the restriction of access to systems and the protection of information
C. through logical or technical controls but not involving the restriction of access to systems and the protection of information.
D. through access control mechanisms that do not require identification and authentication and do not operate through the audit function.
问题 #14
What is the company benefit, in terms of risk, for people taking a vacation of a specified minimum length?
A. Reduces stress levels, thereby lowering insurance claims.
B. Improves morale, thereby decreasing errors.
C. Increases potential for discovering frauds.
D. Reduces dependence on critical individuals.
问题 #15
Why do vendors publish MD5 hash values when they provide software patches for their customers to download from the Internet?
A. Recipients can verify the software's integrity after downloading.", 'B. Recipients can confirm the authenticity of the site from which they are downloading the patch.
C. Recipients can request future updates to the software by using the assigned hash value.
D. Recipients need the hash value to successfully activate the new software.
问题 #16
What attribute is included in a X-509-certificate?
A. Distinguished name of the subject
B. Telephone number of the department
C. Secret key of the issuing CA
D. The key pair of the certificate holder
问题 #17
The "revocation request grace period" is defined as:
A. The period for to the user within he must make a revocation request upon a revocation reason
B. Minimum response time for performing a revocation by the CA
C. Maximum response time for performing a revocation by the CA
D. Time period between the arrival of a revocation reason and the publication of the revocation information
问题 #18
Digital signature users register their public keys with a certification authority, which distributes a certificate containing the user's public key and digital signature of the certification authority. In creating the certificate, the user's public key an
A. Certificate issuer and the Digital Signature Algorithm identifier', "B. User's private key and the identifier of the master key code", 'C. Name of secure channel and the identifier of the protocol type
D. Key authorization and identifier of key distribution center
问题 #19
Which one of the following instigates a SYN flood attack?
A. Generating excessive broadcast packets.
B. Creating a high number of half-open connections.
C. Inserting repetitive Internet Relay Chat (IRC) messages.
D. A large number of Internet Control Message Protocol (ICMP) traces.
问题 #20
Which of the following exceptions is less likely to make hearsay evidence admissible in court?
A. Records are collected during the regular conduct of business
B. Records are collected by senior or executive management
C. Records are collected at or near the time of occurrence of the act being investigated
D. Records are in the custody of the witness on a regular basis
问题 #21
Which model, based on the premise that the quality of a software product is a direct function of the quality of its associated software development and maintenance processes, introduced five levels with which the maturity of an organization involved in th
A. The Total Quality Model (TQM)
B. The IDEAL Model
C. The Software Capability Maturity Model
D. The Spiral Model
问题 #22
Which software development model is actually a meta-model that incorporates a number of the software development models?
A. The Waterfall model.
B. The modified Waterfall model.
C. The Spiral model.
D. The Critical Patch Model (CPM).
问题 #23
The IP header contains a protocol field. If this field contains the value of 17, what type of data is contained within the ip datagram?
A. TCP
B. ICMP
C. UDP
D. IGMP
问题 #24
Which of the following statements pertaining to software testing approaches is correct?
A. A bottom-up approach allows interface errors to be detected earlier
B. A top-down approach allows errors in critical modules to be detected earlier', "C. The test plan and results should be retained as part of the system's permanent documentation", 'D. Black box testing is predicated on a close examination of procedural detail
问题 #25
To be in compliance with the Montreal Protocol, which of the following options can be taken to refill a Halon flooding system in the event that Halon is fully discharged in the computer room?
A. Order an immediate refill with Halon 1201 from the manufacture
B. Contact a Halon recycling bank to make arrangements for a refill
C. Order a different chlorofluorocarbon compound from the manufacture
D. Order an immediate refill with Halon 1301 from the manufacture
问题 #26
Single sign-on systems have a main strength and a main weakness. Choose the best answer exposing this strength and weakness.
A. Users do not need to remember multiple passwords, but access to many systems can be obtained by cracking only one password, making it less secure.
B. They allow the user to make use of very simple passwords; it puts undue burden on IT to administer the system.
C. They force the user to make use of stronger passwords; it makes it easier for users but encourages little attention to security policies.
D. They remove the burden of remembering multiple passwords from users; users need to type the same password when confronted with authentication requests for different resources.
问题 #27
In what way could Java applets pose a security threat?
A. Their transport can interrupt the secure distribution of World Wide Web pages over the Internet by removing SSL and S-HTTP
B. Java interpreters do not provide the ability to limit system access that an applet could have on a client system
C. Executables from the Internet may attempt an intentional attack when they are downloaded on a client system
D. Java does not check the bytecode at runtime or provide other safety mechanisms for program isolation from the client system.
问题 #28
Under what conditions would the use of a Class C fire extinguisher be preferable to a Class A extinguisher?
A. When the fire involves paper products
B. When the fire is caused by flammable products
C. When the fire involves electrical equipment
D. When the fire is in an enclosed area
问题 #29
RAID Software can run faster in the operating system because neither use the hardware-level parity drives by?
A. Simple striping or mirroring.
B. Hard striping or mirroring.
C. Simple hamming code parity or mirroring.
D. Simple striping or hamming code parity.
问题 #30
The greatest risk related to a cutover test is:
A. If backup servers do not function correctly, the test will fail
B. A cutover test tests only the live load and not the switchover
C. A cutover test tests only the switchover and not the live load
D. If backup servers do not function correctly, critical business processes may fail
问题 #31
Your office is implementing an access control policy based on decentralized administration, which is controlled directly by the owners and creators of files. What is the major advantage and disadvantage of such an approach?
A. It puts access control into the hands of those most accountable for the information, but requires security labels for enforcement.
B. It puts access control into the hands of those most accountable for the information, but leads to inconsistencies in procedures and criteri
A.
C. It puts access control into the hands of IT administrators, but leads to procedures and criteria that are too rigid and inflexible.
D. It puts access control into the hands of IT administrators, but forces them to overly rely upon the file owners to implement the access controls IT puts in place.
问题 #32
An organization that is performing a disaster recovery planning project has determined that it needs to have on-site electric power available for as long as ten days, in the event of an electric utility failure. The best approach for this requirement is:
A. Uninterruptible power supply (UPS) and power distribution unit (PDU)
B. Electric generator
C. Uninterruptible power supply (UPS)
D. Uninterruptible power supply (UPS) and electric generator
问题 #33
A security manager has been asked to investigate employee behavior on the part of a senior manager. The investigation has shown that the subject has suffered a serious lapse in judgment and has violated the organization’s code of conduct. The security man
A. Leak the results of the investigation to the media
B. Cover up the results of the investigation
C. Deliver the results of the investigation and recommendations for next steps to his superiors
D. Notify law enforcement
问题 #34
Most operating systems and applications allow for administrators to configure the data that will be captured in audit logs for security purposes. Which of the following is the least important item to be captured in audit logs?
A. System performance output data
B. Last user who accessed the device
C. Number of unsuccessful access attempts
D. Number of successful access attempts
问题 #35
What is the difference between a session and a permanent cookie?
A. Permanent cookies are stored in memory and session cookies are stored on the
B. Session cookies are stored in memory and permanent cookies are stored on the hard drive
C. Sensitive information should be held in permanent cookies, not session
D. Session cookies are not erased when a computer is shut down
问题 #36
Monica is the IT director of a large printing press. She has been made aware of several attempts of brute force password attacks within the past weeks. Which of the following reactions would suit Monica best?
A. Reduce the clipping level
B. Find a more effective encryption mechanism
C. Increase employee awareness through warning banners and training
D. Implement spyware protection that is integrated into the current antivirus product
问题 #37
Why are biometric systems considered more accurate than many of the other types of authentication technologies in use today?
A. They are less accurate
B. They are harder to circumvent than other mechanisms
C. Biometric systems achieve high CER values
D. They have less Type I errors than Type II errors
问题 #38
Which of the following is UNTRUE of a database directory based on the X.500 standard?
A. The directory has a tree structure to organize the entries using a parent-child configuration.
B. Each entry has a unique name made up of attributes of a specific object.
C. The attributes used in the directory are dictated by the defined schem
A.
D. The unique identifiers are called fully qualified names.
问题 #39
You are comparing host based IDS with network based ID. Which of the following will you consider as an obvious disadvantage of host based IDS?
A. It cannot analyze encrypted information.
B. It is costly to remove.
C. It is affected by switched networks.
D. It is costly to manage.
问题 #40
Which of the following best describes the difference between content and context access control?
A. Content access control is based on the sensitivity of the data and context access control is based on the prior operations.
B. Content access control is based on the prior operations and context access control is based on the sensitivity of the dat
A.
C. Context pertains to the use of database views and content access control pertains to tracking the requestor previous access requests.
D. Context pertains to the use of the DAC model and content pertains to the use of the MAC model.
问题 #41
Why would an Ethernet LAN in a bus topology have a greater risk of unauthorized disclosure than switched Ethernet in a hub-and-spoke or star topology?
A. IEEE 802.5 protocol for Ethernet cannot support encryption.
B. Ethernet is a broadcast technology.
C. Hub and spoke connections are highly multiplexed.
D. TCP/IP is an insecure protocol.
问题 #42
How does RADIUS allow companies to centrally control remote user access?
A. Once a user is authenticated a profile is generated based on his security token, which outlines what he is authorized to do within the network.
B. Once a user is authenticated a pre-configured profile is assigned to him, which outlines what he is authorized to do within the network.
C. Once the RADIUS client authenticates the user, the RADIUS server assigns him a pre-configured profile.
D. Once the RADIUS client authenticates the user, the client assigns the user a pre-configured profile.
问题 #43
To support legacy applications that rely on risky protocols (e.g,, plain text passwords), which one of the following can be implemented to mitigate the risks on a corporate network?
A. Implement strong centrally generated passwords to control use of the vulnerable applications.
B. Implement a virtual private network (VPN) with controls on workstations joining the VPN.
C. Ensure that only authorized trained users have access to workstations through physical access control.
D. Ensure audit logging is enabled on all hosts and applications with associated frequent log reviews.
问题 #44
In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class C network?
A. The first bit of the ip address would be set to zero
B. The first bit of the ip address would be set to one and the second bit set to zero
C. The first two bits of the ip address would be set to one, and the third bit set to zero
D. The first three bits of the ip address would be set to one
问题 #45
TACACS+ uses the TCP transport protocol. RADIUS only encrypts the user's password as it is being transmitted from the RADIUS client to the RADIUS server. Other information, as in the username, accounting, and authorized services, are passed in cleartext.
A. AVPs are the constructs that outline how two entities will communicate. Diameter has many more AVPs, which allow for the protocol to have more capabilities than RADIUS.
B. AVPs are the protocol parameters used between communicating entities. Diameter has less AVPs, which allow for the protocol to have more capabilities than RADIUS.
C. AVPs are the security mechanisms that provide confidentiality and integrity for data being passed back and forth between entities. Diameter has many more AVPs, which allow for the protocol to have more security capabilities than RADIUS.
D. AVPs are part of the TCP protocol. Diameter uses AVPs, because it uses TCP and RADIUS uses UDP.
问题 #46
A computer user is listening to an audio broadcast on the Internet through an SSL VPN. The type of encryption cipher used in this case is:
A. Block cipher
B. Stream cipher
C. Running key cipher
D. Vernam cipher
问题 #47
In what way can violation clipping levels assist in violation tracking and analysis?
A. Clipping levels set a baseline for normal user errors, and violations exceeding that threshold will be recorded for analysis of why the violations occurred
B. Clipping levels enable a security administrator to customize the audit trail to record only those violations which are deemed to be security relevant
C. Clipping levels enable the security administrator to customize the audit trail to record only actions for users with access to usercodes with a privileged status
D. Clipping levels enable a security administrator to view all reductions in security levels which have been made to usercodes which have incurred violations
问题 #48
As head of sales, Jim is the information owner for the sales department. Which of the following is not Jim's responsibility as information owner?
A. Assigning information classifications
B. Dictating how data should be protected
C. Verifying the availability of data
D. Determining how long to retain data
问题 #49
Which of the following correctly describe Role based access control?
A. It allows you to specify and enforce enterprise-specific security policies in a way that maps to your user profile groups.
B. It allows you to specify and enforce enterprise-specific security policies in a way that maps to your organizations structure.
C. It allows you to specify and enforce enterprise-specific security policies in a way that maps to your ticketing system.
D. It allows you to specify and enforce enterprise-specific security policies in a way that maps to your ACL.
问题 #50
What is a Land attack and what type of IDS can identify it based on its pattern and not behavior?
A. Header has the same source and destination address and can be identified by a statistical anomaly-based IDS.
B. Header has no source and destination addresses and can be identified by a signature-based IDS.
C. Header has the same source and destination address and can be identified by a traffic-based IDS.
D. Header has the same source and destination address and can be identified by a signature-based IDS.
问题 #51
Within the Open Systems Interconnection (OSI) Reference Model, authentication addresses the need for a network entity to verify both
A. The identity of a remote communicating entity and the authenticity of the source of the data that are received.
B. The authenticity of a remote communicating entity and the path through which communications Are received.
C. The location of a remote communicating entity and the path through which communications Are received.
D. The identity of a remote communicating entity and the level of security of the path through Which data are received.
问题 #52
George is responsible for setting and tuning the thresholds for his company behavior-based IDS. Which of the following outlines the possibilities of not doing this activity properly?
A. If the threshold is set too low, non-intrusive activities are considered attacks (false positives). If the threshold is set too high, then malicious activities are not identified (false negatives).
B. If the threshold is set too low, non-intrusive activities are considered attacks (false negatives). If the threshold is set too high, then malicious activities are not identified (false positives).
C. If the threshold is set too high, non-intrusive activities are considered attacks (false positives). If the threshold is set too low, then malicious activities are not identified (false negatives).
D. If the threshold is set too high, non-intrusive activities are considered attacks (false positives). If the threshold is set too high, then malicious activities are not identified (false negatives).
问题 #53
Organizations that implement two-factor authentication often do not adequately plan. One result of this is:
A. Some users will lose their tokens, smart cards, or USB keys
B. Some users will store their tokens, smart cards, or USB keys with their computers, thereby defeating one of the advantages of two-factor authentication
C. Users will have trouble understanding how to use two-factor authentication
D. The cost of implementation and support can easily exceed the cost of the product itself
问题 #54
Steven's staff has asked for funding to implement technology that provides Mobile IP. Which of the following would be a reason for employing this type of technology?
A. Employees can move from one network to another
B. Peer-to-peer networks would not be allowed
C. Security staff could carry out sniffing
D. Users would not be allowed to move their wireless devices and still stay connected to the network
问题 #55
One reason an organization would consider a distributed application is:
A. Some components are easier to operate
B. Distributed applications have a simpler architecture than other types of applications
C. Some application components are owned and operated by other organizations
D. Distributed applications are easier to secure
问题 #56
An organization is located in an area that experiences frequent power blackouts. What will the effect of an electric generator be in this circumstance?
A. The organization will have a continuous supply of electric power.
B. The organization will have to establish fuel supply contracts with at least two fuel suppliers.
C. Electric utility blackouts will result in short electric power outages for the organization.
D. An electric generator will be of no help in this situation.
问题 #57
A resource server contains an access control system. When a user requests access to an object, the system examines the permission settings for the object and the permission settings for the user, and then makes a decision whether the user may access the o
A. Mandatory access control (MAC)
B. Discretionary access control (DAC)
C. Non-interference
D. Role based access control (RBAC)
问题 #58
A security manager is setting up resource permissions in an application. The security manager has discovered that he can establish objects that contain access permissions, and then assign individual users to those objects. The access control model that mo
A. Access matrix
B. Mandatory access control (MAC)
C. Discretionary access control (DAC)
D. Role based access control (RBAC)
问题 #59
A security officer has declared that a new information system must be certified before it can be used. This means:
A. The system must be evaluated according to established evaluation criteria
B. A formal management decision is required before the system can be used
C. Penetration tests must be performed against the system
D. A code review must be performed against the system
问题 #60
A computer running the Windows operating system has nearly exhausted available physical memory for active processes. In order to avoid exhausting all available memory, what should the operating system begin doing?
A. Swapping
B. Paging
C. Killing old processes
D. Running the garbage collector
问题 #61
A network engineer who is examining telecommunications circuits has found one that is labeled as a DS-1. What is the maximum throughput that may be expected from this circuit?
A. Approximately 7,000k chars/sec
B. Approximately 56k bits/sec
C. Approximately 170k chars/sec
D. Approximately 1,544M bits/sec
问题 #62
A security assessment discovered back doors in an application, and the security manager needs to develop a plan for detecting and removing back doors in the future. The most effective countermeasures that should be chosen are:
A. Application firewalls
B. Source code control
C. Outside code reviews
D. Peer code reviews
问题 #63
Why are macro viruses easy to write?
A. Active contents controls can make direct system calls
B. The underlying language is simple and intuitive to apply.
C. Only a few assembler instructions are needed to do damage.
D. Office templates are fully API compliant.
问题 #64
An organization’s data classification policy includes handling procedures for data at each level of sensitivity. The IT department backs up all data onto magnetic tape, resulting in tapes that contain data at all levels of sensitivity. How should these ba
A. According to procedures for the lowest sensitivity level
B. According to procedures for the highest sensitivity level
C. According to procedures in between the lowest and highest sensitivity levels
D. Data handling procedures do not apply to backup media, only original media
问题 #65
The purpose of the Diffie-Hellman key exchange protocol is:
A. To decrypt a symmetric encryption key
B. To encrypt a symmetric encryption key
C. To permit two parties who have never communicated to establish public encryption keys
D. To permit two parties who have never communicated to establish a secret encryption key
问题 #66
Voice recognition as a biometric authentication method is difficult to measure because:
A. Many factors, including current health and respiration rate, make sampling difficult
B. Computers are not yet fast enough to adequately sample a voice print
C. Voice recognition does not handle accents well
D. Impatience changes voice patterns, which leads to increased False Reject Rates
问题 #67
Which of the following is NOT a good password deployment guideline?
A. Passwords must not be the same as user id or login id.
B. Passwords must be changed at least once every 60 days, depending on your environment.
C. Password aging must be enforced on all systems.
D. Password must be easy to memorize.
问题 #68
With Java, what can be embedded in a web browser, allowing programs to be executed as they are downloaded from the World Wide Web?
A. JVM
B. Bytecode
C. Interpreter
D. Just-in-time compiler
问题 #69
Which is NOT true about Covert Channel Analysis?
A. It is an operational assurance requirement that is specified in the Orange Book.
B. It is required for B2 class systems in order to protect against covert storage channels.
C. It is required for B2 class systems to protect against covert timing channels.
D. It is required for B3 class systems to protect against both covert storage and covert timing channels.
问题 #70
The SEI Software Capability Maturity Model is based on the premise that:
A. Good software development is a function of the number of expert programmers in the organization.
B. The maturity of an organizations software processes cannot be measured.
C. The quality of a software product is a direct function of the quality of its associated software development and maintenance processes.
D. Software development is an art that cannot be measured by conventional means.
问题 #71
In the legal field, there is a term that is used to describe a computer system so that everyone can agree on a common definition. The term describes a computer for the purposes of computer security as can assembly of electronic equipment, hardware, softwa
A. A central processing unit (CPU)
B. A microprocessor
C. An arithmetic logic unit (ALU)
D. An automated information system (AIS)
问题 #72
What is the purpose of polyinstantiation?
A. To restrict lower-level subjects from accessing low-level information
B. To make a copy of an object and modify the attributes of the second copy
C. To create different objects that will react in different ways to the same input
D. To create different objects that will take on inheritance attributes from their class
问题 #73
In addition to ensuring that changes to the computer system take place in an identifiable and controlled environment, configuration management provides assurance that future changes:
A. The application software cannot bypass system security features.
B. Do not adversely affect implementation of the security policy.
C. To do the operating system are always subjected to independent validation and verification.
D. In technical documentation maintain an accurate description of the Trusted Computer Base.
问题 #74
Another type of artificial intelligence technology involves genetic algorithms. Genetic algorithms are part of the general class known as:
A. Neural networks
B. Suboptimal computing
C. Evolutionary computing
D. Biological computing
问题 #75
Which of the following items BEST describes the standards addressed by Title II, Administrative Simplification, of the Health Insurance Portability and Accountability Act (U.S. Kennedy-Kassebaum Health Insurance and Portability Accountability Act -HIPAA-P
A. Transaction Standards, to include Code Sets; Unique Health Identifiers; Security and Electronic Signatures and Privacy
B. Transaction Standards, to include Code Sets; Security and Electronic Signatures and Privacy
C. Unique Health Identifiers; Security and Electronic Signatures and Privacy
D. Security and Electronic Signatures and Privacy
问题 #76
Which media control below is the BEST choice to prevent data remanence on magnetic tapes or floppy disks?
A. Overwriting the media with new application data
B. Degaussing the media
C. Applying a concentration of hydriodic acid (55% to 58% solution) to the gamma ferric oxide disk surface
D. Making sure the disk is re-circulated as quickly as possible to prevent object reuse
问题 #77
In which way does a Secure Socket Layer (SSL) server prevent a "man-in-the-middle" attack?
A. It uses signed certificates to authenticate the server's public key.", 'B. A 128 bit value is used during the handshake protocol that is unique to the connection.
C. It uses only 40 bits of secret key within a 128 bit key length.
D. Every message sent by the SSL includes a sequence number within the message contents.
问题 #78
You are running a packet sniffer on a network and see a packet with a long string of long string of "90 90 90 90...." in the middle of it traveling to an x86-based machine. This could be indicative of what?
A. Over-subscription of the traffic on a backbone
B. A source quench packet
C. a FIN scan
D. A buffer overflow
问题 #79
Which of the following statements pertaining to air conditioning for an information processing facility is correct?
A. The AC units must be controllable from outside the area
B. The AC units must keep negative pressure in the room so that smoke and other gases are forced out of the room
C. The AC units must be n the same power source as the equipment in the room to allow for easier shutdown
D. The AC units must be dedicated to the information processing facilities
问题 #80
Which of the following correctly describe "good" security practice?
A. Accounts should be monitored regularly.
B. You should have a procedure in place to verify password strength.
C. You should ensure that there are no accounts without passwords.
D. All of the choices.
问题 #81
In Unix, which file is required for you to set up an environment such that every used on the other host is a trusted user that can log into this host without authentication?
A. /etc/shadow
B. /etc/host.equiv
C. /etc/passwd
D. None of the choices.
问题 #82
Which of the following would best describe the difference between white-box testing and black-box testing?
A. White-box testing is performed by an independent programmer team
B. Black-box testing uses the bottom-up approach
C. White-box testing examines the program internal logical structure
D. Black-box testing involves the business units
问题 #83
Which question is NOT true concerning Application Control?
A. It limits end users use of applications in such a way that only particular screens are visible
B. Only specific records can be requested choice
C. Particular uses of application can be recorded for audit purposes
D. Is non-transparent to the endpoint applications so changes are needed to the applications involved
问题 #84
Which one of the following control steps is usually NOT performed in data warehousing applications?
A. Monitor summary tables for regular use.
B. Control meta data from being used interactively.
C. Monitor the data purging plan.
D. Reconcile data moved between the operations environment and data warehouse.
问题 #85
Normalizing data within a database includes all of the following except which?
A. Eliminating repeating groups by putting them into separate tables
B. Eliminating redundant data
C. Eliminating attributes in a table that are not dependent on the primary key of that table
D. Eliminating duplicate key fields by putting them into separate tables
问题 #86
Which of the following statements pertaining to RADIUS is incorrect?
A. A RADIUS server can act as a proxy server, forwarding client requests to other authentication domains.
B. Most of RADIUS clients have a capability to query secondary RADIUS servers for redundancy
C. Most RADIUS servers have built-in database connectivity for billing and reporting purposes
D. Most RADIUS servers can work with DIAMETER servers.
问题 #87
A database administrator (DBA) is responsible for carrying out security policy, which includes controlling which users have access to which data. The DBA has been asked to make just certain fields in some database tables visible to some new users. What is
A. Implement column-based access controls
B. Export the table to a data warehouse, including only the fields that the users are permitted to see
C. Clone the table, including only the fields that the users are permitted to see
D. Create a view that contains only the fields that the users are permitted to see
问题 #88
An organization that is building a disaster recovery capability needs to reengineer its application servers to meet new recovery requirements of 40-hour RPO and 24-hour RTO. Which of the following approaches will best meet this objective?
A. Active/Passive server cluster with replication
B. Tape backup and restore to a hot site
C. Tape backup and restore to a cold site
D. Server cluster with shared storage
问题 #89
Why is it important to understand the cost of downtime of critical business processes?
A. Management will be able to make decisions about the cost of mitigating controls and contingency plans
B. Management will be able to determine which processes are the most critical
C. Management will be able to establish a training budget
D. Management will be able to compare recovery costs with those in similar organizations
问题 #90
What is the PRIMARY reason that reciprocal agreements between independent organizations for backup processing capability are seldom used?
A. Lack of successful recoveries using reciprocal agreements.
B. Legal liability of the host site in the event that the recovery fails.
C. Dissimilar equipment used by disaster recovery organization members.
D. Difficulty in enforcing the reciprocal agreement.
问题 #91
the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class C network?
A. The first bit of the ip address would be set to zero
B. The first bit of the ip address would be set to one and the second bit set to zero
C. The first two bits of the ip address would be set to one, and the third bit set to zero
D. The first three bits of the ip address would be set to one
问题 #92
rogrammer creates a virus producing tool in order to test the performance of a new virus diction product.
A. This is ethical because it was created to test and enhance the performance of a virus protection tool', "B. It's unethical because the virus creating tool may become available to the public.", 'C. All of the above
D. None of the above
问题 #93
The ANSI X9.52 standard defines a variant of DES encryption with keys k1, k2, and k3 as: C = Ek3 [Dk2 [Ek1 [M]]] What is this DES variant?
A. DESX
B. Triple DES in the EEE mode
C. Double DES with an encryption and decryption with different keys
D. Triple DES in the EDE mode
问题 #94
Wired Equivalency Privacy algorithm (WEP) of the 802.11 Wireless LAN Standard uses which of the following to protect the confidentiality of information being transmitted on the LAN?
A. A secret key that is shared between a mobile station (e.g., a laptop with a wireless Ethernet card) and a base station access point
B. A public/private key pair that is shared between a mobile station (e.g., a laptop with a wireless Ethernet card) and a base station access point
C. Frequency shift keying (FSK) of the message that is sent between a mobile station (e.g., a laptop with a wireless Ethernet card) and a base station access point
D. A digital signature that is sent between a mobile station (e.g., a laptop with a wireless Ethernet card) and a base station access point
问题 #95
The purpose of the Diffie-Hellman key exchange protocol is:
A. To decrypt a symmetric encryption key
B. To encrypt a symmetric encryption key
C. To permit two parties who have never communicated to establish public encryption keys
D. To permit two parties who have never communicated to establish a secret encryption key
问题 #96
different user groups with different security access levels need to access the same information, which of the following actions should management take?
A. Decrease the security level on the information to ensure accessibility and usability of the information.
B. Require specific written approval each time an individual needs to access the information.
C. Increase the security controls on the information.
D. Decrease the classification label on the information.
问题 #97
Which statement is true when looking at security objectives in the privatebusiness sector versus the military sector?
A. Only the military has true security.
B. Businesses usually care more about data integrity and availability, whereas the military is more concerned with confidentiality.
C. The military requires higher levels of security because the risks are so much higher.
D. The business sector usually cares most about data availability and confidentiality, whereas the military is most concerned with integrity.
问题 #98
Why should the team that will perform and review the risk analysis information be made up of people in different departments?
A. To make sure the process is fair and that no one is left out.', "B. It shouldn't. It should be a small group brought in from outside the organization because otherwise the analysis is biased and unusable.", 'C. Because people in different departments understand the risks of their department. Thus, it ensures the data going into the analysis is as close to reality as possible.
D. Because the people in the different departments are the ones causing the risks, so they should be the ones held accountable.
问题 #99
Which of the following best describes the Secure Electronic Transaction (SET) protocol?
A. Originated by VISA and MasterCard as an Internet credit card protocol.
B. Originated by VISA and MasterCard as an Internet credit card protocol using digital signatures.
C. Originated by VISA and MasterCard as an Internet credit card protocol using the transport layer.
D. Originated by VISA and MasterCard as an Internet credit card protocol using SSL.
问题 #100
Which of the following statements BEST describes the Public Key Cryptography Standards (PKCS)?
A. A set of public-key cryptography standards that support algorithms such as Diffie-Hellman and RSA as well as algorithm independent standards
B. A set of public-key cryptography standards that support only "standard" algorithms such as Diffie-Hellman and RSA
C. A set of public-key cryptography standards that support only algorithmindependent implementations
D. A set of public-key cryptography standards that support encryption algorithms such as Diffie-Hellman and RSA, but does not address digital signatures
问题 #101
The Payment Card Industry Data Security Standard (PCI DSS) requires encryption of credit card in which circumstances:
A. Stored in databases, stored in flat files, and transmitted over public and private networks
B. Stored in databases, and transmitted over public networks
C. Stored in databases, stored in flat files, and transmitted over public networks
D. Stored in databases, and transmitted over public and private networks