« 返回题库列表2026年CISSP考试题库和答案汇总|真题下载+模拟题+学习资料
问题 #1
David is preparing a server room at a new branch office. What locking mechanisms should he use for the primary and secondary server room entry doors?
A. The primary and secondary entrance doors should have access controlled through a swipe card or cipher lock.
B. The primary entrance door should have no access controlled through a security guard. The secondary doors should be secured from the inside and allow no entry.
C. The primary entrance door should have access controlled through a swipe card or cipher lock. The secondary doors should have a security guard.
D. The primary entrance door should have access controlled through a swipe card or cipher lock. Secondary doors should be secured from the inside and allow no entry.
问题 #2
Which of the following is not true of IDSs?
A. They can be hindered by items within the room.
B. They are expensive and require human intervention to respond to the alarms.
C. They usually come with a redundant power supply and emergency backup power.
D. They should detect, and be resistant to, tampering.
问题 #3
Before an effective physical security program can be rolled out, a number of steps must be taken. Which of the following steps comes first in the process of rolling out a security program?
A. Create countermeasure performance metrics.
B. Conduct a risk analysis.
C. Design the program.
D. Implement countermeasures.
问题 #4
The basic version of the Construction Cost Model (COCOMO), which proposes quantitative, life-cycle relationships, performs what function?
A. Estimates software development effort based on user function categories
B. Estimates software development effort and cost as a function of the size of the software product in source instructions
C. Estimates software development effort and cost as a function of the size of the software product in source instructions modified by manpower buildup and productivity factors
D. Estimates software development effort and cost as a function of the size of the software product in source instructions modified by hardware and input functions
问题 #5
A number of measures should be taken to help protect devices and the environment from electric power issues. Which of the following is best to keep voltage steady and power clean?
A. Power line monitor
B. Surge protector
C. Shielded cabling
D. Regulator
问题 #6
Layer 2 of the OSI model has two sublayers. What are those sublayers, and what are two IEEE standards that describe technologies at that layer?
A. LCL and MAC; IEEE 802.2 and 802.3
B. LCL and MAC; IEEE 802.1 and 802.3
C. Network and MAC; IEEE 802.1 and 802.3
D. LLC and MAC; IEEE 802.2 and 802.3
问题 #7
Which of the following is not an effective countermeasure against spam?
A. Open mail relay servers
B. Properly configured mail relay servers
C. Filtering on an e-mail gateway
D. Filtering on the client
问题 #8
Robert is responsible for implementing a common architecture used when customers need to access confidential information through Internet connections. Which of the following best describes this type of architecture?
A. Two-tiered model
B. Screened subnet
C. Three-tiered model
D. Public and private DNS zones
问题 #9
Two commonly used networking protocols are TCP and UPD. Which of the following correctly describes the two?
A. TCP provides best-effort delivery, and UDP sets up a virtual connection with the destination.
B. TCP provides more services and is more reliable in data transmission, whereas UDP takes less resources and overhead to transmit dat
A.
C. TCP provides more services and is more reliable, but UDP provides more security services.
D. TCP is reliable, and UDP deals with flow control and ACKs.
问题 #10
Which of the following correctly describes Bluejacking?
A. Bluejacking is a harmful, malicious attack.
B. It is the process of taking over another portable device via a Bluetooth-enabled device.
C. It is commonly used to send contact information.
D. The term was coined by the use of a Bluetooth device and the act of hijacking another device.
问题 #11
DNS is a popular target for attackers due to its strategic role on the Internet. What type of attack uses recursive queries to poison the cache of a DNS server?
A. DNS spoofing
B. Manipulation of the hosts file
C. Social engineering
D. Domain litigation
问题 #12
IP telephony networks require the same security measures as those implemented on an IP data network. Which of the following is unique to IP telephony?
A. Limiting IP sessions going through media gateways
B. Identification of rogue devices
C. Implementation of authentication
D. Encryption of packets containing sensitive information
问题 #13
Cross-site scripting (XSS) is an application security vulnerability usually found in Web applications. What type of XSS vulnerability occurs when a victim is tricked into opening a URL programmed with a rogue script to steal sensitive information?
A. Persistent XSS vulnerability
B. Nonpersistent XSS vulnerability
C. Second-order vulnerability
D. DOM-based vulnerability
问题 #14
Which of the following incorrectly describes how routing commonly takes place on the Internet?
A. EGP is used in the areas "between" each AS.
B. Regions of nodes that share characteristics and behaviors are called ASs.
C. CAs are specific nodes that are responsible for routing to nodes outside of their region.
D. Each AS uses IGP to perform routing functionality.
问题 #15
Which of the following does not describe IP telephony security?
A. VoIP networks should be protected with the same security controls used on a data network.
B. Softphones are more secure than IP phones.
C. As endpoints, IP phones can become the target of attacks.
D. The current Internet architecture over which voice is transmitted is less secure than physical phone lines.
问题 #16
When an organization splits naming zones, the names of its hosts that are only accessible from an intranet are hidden from the Internet. Which of the following best describes why this is done?
A. To prevent attackers from accessing servers
B. To prevent the manipulation of the hosts file
C. To avoid providing attackers with valuable information that can be used to prepare an attack
D. To avoid providing attackers with information needed for cybersquatting
问题 #17
Which of the following best describes why e-mail spoofing is easily executed?
A. SMTP lacks an adequate authentication mechanism.', "B. Administrators often forget to configure an SMTP server to prevent inbound SMTP connections for domains it doesn't serve.", 'C. Keyword filtering is technically obsolete.
D. Blacklists are undependable.
问题 #18
Today, satellites are used to provide wireless connectivity between different locations. What two prerequisites are needed for two different locations to communicate via satellite links?
A. They must be connected via a phone line and have access to a modem.', "B. They must be within the satellite's line of site and footprint.", 'C. They must have broadband and a satellite in low Earth orbit.', "D. They must have a transponder and be within the satellite's footprint.
问题 #19
Brad is a security manager at Thingamabobs Inc. He is preparing a presentation for his company's executives on the risks of using instant messaging (IM) and his reasons for wanting to prohibit its use on the company network. Which of the following should
A. Sensitive data and files can be transferred from system to system over IM.
B. Users can receive information—including malware—from an attacker posing as a legitimate sender.
C. IM use can be stopped by simply blocking specific ports on the network firewalls.
D. A security policy is needed specifying IM usage restrictions.
问题 #20
Which of the following correctly describes the relationship between SSL and TLS?
A. TLS is the open-community version of SSL.', "B. SSL can be modified by developers to expand the protocol's capabilities.", 'C. TLS is a proprietary protocol, while SSL is an open-community protocol.
D. SSL is more extensible and backward compatible with TLS.
问题 #21
Which of the following incorrectly describes steganography?
A. It is a type of security through obscurity.
B. Modifying the most significant bit is the most common method used.
C. Steganography does not draw attention to itself like encryption does.
D. Media files are ideal for steganographic transmission because of their large size.
问题 #22
Which of the following correctly describes a drawback of symmetric key systems?
A. Computationally less intensive than asymmetric systems
B. Work much more slowly than asymmetric systems
C. Carry out mathematically intensive tasks
D. Key must be delivered via secure courier
问题 #23
Which of the following occurs in a PKI environment?
A. The RA creates the certificate, and the CA signs it.
B. The CA signs the certificate.
C. The RA signs the certificate.
D. The user signs the certificate.
问题 #24
Which of the following correctly describes the difference between public key cryptography and public key infrastructure?
A. Public key cryptography is the use of an asymmetric algorithm, while public key infrastructure is the use of a symmetric algorithm.
B. Public key cryptography is used to create public/private key pairs, and public key infrastructure is used to perform key exchange and agreement.
C. Public key cryptography provides authentication and nonrepudiation, while public key infrastructure provides confidentiality and integrity.
D. Public key cryptography is another name for asymmetric cryptography, while public key infrastructure consists of public key cryptographic mechanisms.
问题 #25
Which of the following best describes Key Derivation Functions (KDFs)?
A. Keys are generated from a master key.
B. Session keys are generated from each other.
C. Asymmetric cryptography is used to encrypt symmetric keys.
D. A master key is generated from a session key.
问题 #26
An elliptic curve cryptosystem is an asymmetric algorithm. What sets it apart from other asymmetric algorithms?
A. It provides digital signatures, secure key distribution, and encryption.
B. It computes discrete logarithms in a finite field.
C. It uses a larger percentage of resources to carry out encryption.
D. It is more efficient.
问题 #27
If implemented properly, a one-time pad is a perfect encryption scheme. Which of the following incorrectly describes a requirement for implementation?
A. The pad must be securely distributed and protected at its destination.
B. The pad must be made up of truly random values.
C. The pad must always be the same length.
D. The pad must be used only one time.
问题 #28
There are two main types of symmetric ciphers: stream and block. Which of the following is not an attribute of a good stream cipher?
A. Statistically unbiased keystream
B. Statistically predictable
C. Long periods of no repeating patterns
D. Keystream not linearly related to key
问题 #29
Which of the following best describes how a digital signature is created?
A. The sender encrypts a message digest with his private key.
B. The sender encrypts a message digest with his public key.
C. The receiver encrypts a message digest with his private key.
D. The receiver encrypts a message digest with his public key.
问题 #30
SSL is a de facto protocol used for securing transactions that occur over untrusted networks. Which of the following best describes what takes place during an SSL connection setup process?
A. The server creates a session key and encrypts it with a public key.
B. The server creates a session key and encrypts it with a private key.
C. The client creates a session key and encrypts it with a private key.
D. The client creates a session key and encrypts it with a public key.
问题 #31
The CA is responsible for revoking certificates when necessary. Which of the following correctly describes a CRL and OSCP?
A. The CRL was developed as a more streamlined approach to OCSP.
B. OCSP is a protocol that submits revoked certificates to the CRL.
C. OCSP is a protocol developed specifically to check the CRL during a certificate validation process.
D. CRL carries out real-time validation of a certificate and reports to the OCSP.
问题 #32
End-to-end encryption is used by users, and link encryption is used by service providers. Which of the following correctly describes these technologies?
A. Link encryption does not encrypt headers and trailers.
B. Link encryption encrypts everything but data link messaging.
C. End-to-end encryption requires headers to be decrypted at each hop.
D. End-to-end encryption encrypts all headers and trailers.
问题 #33
The NIST organization has defined best practices for creating continuity plans. Which of the following phases deals with identifying and prioritizing critical functions and systems?
A. Identify preventive controls.
B. Develop the continuity planning policy statement.
C. Develop recovery strategies.
D. Conduct the business impact analysis.
问题 #34
As his company's business continuity coordinator, Matthew is responsible for helping recruit members to the business continuity planning (BCP) committee. Which of the following does not correctly describe this effort?
A. Committee members should be involved with the planning stages, as well as the testing and implementation stages.
B. The smaller the team the better, to keep meetings under control.
C. The business continuity coordinator should work with management to appoint committee members.
D. The team should consist of people from different departments across the company.
问题 #35
A business impact analysis is considered a functional analysis. Which of the following is not carried out during a business impact analysis?
A. A parallel or full-interruption test
B. The application of a classification scheme based on criticality levels
C. The gathering of information via interviews
D. Documentation of business functions
问题 #36
Which of the following is the best way to ensure that the company's backup tapes can be restored and used at a warm site?
A. Ask the offsite vendor to test them and label the ones that were properly read.', "B. Test them on the vendor's machine, which won't be used during an emergency.", 'C. Retrieve the tapes from the offsite facility and verify that the equipment from the original site can read them.', "D. Inventory each tape kept at the vendor's site twice a month.
问题 #37
An approach to alternate offsite facilities is to establish a reciprocal agreement. Which of the following describes the pros and cons of a reciprocal agreement?
A. It is fully configured and ready to operate within a few hours, but is the most expensive of the offsite choices.
B. It is an inexpensive option, but it takes the most time and effort to get up and running after a disaster.
C. It is a good alternative for companies that depend upon proprietary software, but annual testing is not usually available.
D. It is the cheapest of the offsite choices, but mixing operations could introduce many security issues.
问题 #38
Which of the following steps comes first in a business impact analysis?
A. Calculate the risk for each different business function.
B. Identify critical business functions.
C. Create data-gathering techniques.
D. Identify vulnerabilities and threats to business functions.
问题 #39
The operations team is responsible for defining which data gets backed up and how often. Which type of backup process backs up files that have been modified since the last time all data was backed up?
A. Incremental process
B. Full backup
C. Partial backup
D. Differential process
问题 #40
After a disaster occurs, a damage assessment needs to take place. Which of the following steps occurs last in a damage assessment?
A. Determine the cause of the disaster.
B. Identify the resources that must be replaced immediately.
C. Declare a disaster.
D. Determine how long it will take to bring critical functions back online.
问题 #41
It is not unusual for business continuity plans to become out of date. Which of the following is not a reason why plans become outdated?
A. Changes in hardware, software, and applications
B. Infrastructure and environment changes
C. Personnel turnover
D. That the business continuity process is integrated into the change management process
问题 #42
Preplanned business continuity procedures provide organizations a number of benefits. Which of the following is not a capability enabled by business continuity planning?
A. Resuming critical business functions
B. Letting business partners know your company is unprepared
C. Protecting lives and ensuring safety
D. Ensuring survivability of the business
问题 #43
Management support is critical to the success of a business continuity plan. Which of the following is the most important to be provided to management to obtain their support?
A. Business case
B. Business impact analysis
C. Risk analysis
D. Threat report
问题 #44
Gizmos and Gadgets has restored its original facility after a disaster. What should be moved in first?
A. Management
B. Most critical systems
C. Most critical functions
D. Least critical functions
问题 #45
Which of the following is a critical first step in disaster recovery and contingency planning?
A. Plan testing and drills.
B. Complete a business impact analysis.
C. Determine offsite backup facility alternatives.
D. Organize and create relevant documentation.
问题 #46
Which of the following is not a reason to develop and implement a disaster recovery plan?
A. Provide steps for a post-disaster recovery.
B. Extend backup operations to include more than just backing up dat
A.
C. Outline business functions and systems.
D. Provide procedures for emergency responses.
问题 #47
With what phase of a business continuity plan does a company proceed when it is ready to move back into its original site or a new site?
A. Reconstitution phase
B. Recovery phase
C. Project initiation phase
D. Damage assessment phase
问题 #48
Several teams should be involved in carrying out the business continuity plan. Which team is responsible for starting the recovery of the original site?
A. Damage assessment team
B. BCP team
C. Salvage team
D. Restoration team
问题 #49
ACME Inc. paid a software vendor to develop specialized software, and that vendor has gone out of business. ACME Inc. does not have access to the code and therefore cannot keep it updated. What mechanism should the company have implemented to prevent this
A. Reciprocal agreement
B. Software escrow
C. Electronic vaulting
D. Business interruption insurance
问题 #50
Which of the following incorrectly describes the concept of executive succession planning?
A. Predetermined steps protect the company if a senior executive leaves.
B. Two or more senior staff cannot be exposed to a particular risk at the same time.
C. It documents the assignment of deputy roles.
D. It covers assigning a skeleton crew to resume operations after a disaster.
问题 #51
Cyberlaw categorizes computer-related crime into three categories. Which of the following is an example of a crime in which the use of a computer would be categorized as incidental?
A. Carrying out a buffer overflow to take control of a system
B. The electronic distribution of child pornography
C. Attacking financial systems to steal funds
D. Capturing passwords as they are sent to the authentication server
问题 #52
Which organization has been developed to deal with economic, social, and governance issues, and with how sensitive data is transported over borders?
A. European Union
B. Council of Europe
C. Safe Harbor
D. Organisation for Economic Co-operation and Development
问题 #53
Different countries have different legal systems. Which of the following correctly describes customary law?
A. Not many countries work under this law purely; most instead use a mixed system where this law, which deals mainly with personal conduct and patterns of behavior, is an integrated component.
B. It covers all aspects of human life, but is commonly divided into responsibilities and obligations to others, and religious duties.
C. It is a rule-based law focused on codified law.', "D. Based on previous interpretations of laws, this system reflects the community's morals and expectations.
问题 #54
There are different types of approaches to regulations. Which of the following is an example of self-regulation?
A. The Health Insurance Portability and Accountability Act
B. The Sarbanes-Oxley Act
C. The Computer Fraud and Abuse Act
D. PCI Data Security Standard
问题 #55
Which of the following means that a company did all it could have reasonably done to prevent a security breach?
A. Downstream liability
B. Responsibility
C. Due diligence
D. Due care
问题 #56
There are three different types of incident response teams. Which of the following correctly describes a virtual team?
A. It consists of experts who have other duties within the organization.
B. It can be cost prohibitive to smaller organizations.
C. It is a hybrid model.
D. Core members are permanently assigned to the team.
问题 #57
A suspected crime has been reported within your organization. Which of the following steps should the incident response team take first?
A. Establish a procedure for responding to the incident.
B. Call in forensics experts.
C. Determine that a crime has been committed.
D. Notify senior management.
问题 #58
Which of the following is a correct statement regarding computer forensics?
A. It is the study of computer technology.
B. It is a set of hardware-specific processes that must be followed in order for evidence to be admissible in a court of law.
C. It encompasses network and code analysis, and may be referred to as electronic data discovery.
D. Computer forensics responsibilities should be assigned to a network administrator before an incident occurs.
问题 #59
Which of the following dictates that all evidence be labeled with information indicating who secured and validated it?
A. Chain of custody
B. Due care
C. Investigation
D. Motive, Opportunity, and Means
问题 #60
There are several categories of evidence. How is a witness's oral testimony categorized?
A. Best evidence
B. Secondary evidence
C. Circumstantial evidence
D. Conclusive evidence
问题 #61
Which of the following best describes exigent circumstances?
A. The methods used to capture a suspect's actions are neither legal nor ethical.", "B. Enticement is used to capture a suspect's actions.", 'C. Hacking does not actually hurt anyone.
D. The seizure of evidence by law enforcement because there is concern that a suspect will attempt to destroy it.
问题 #62
What role does the Internet Architecture Board play regarding technology and ethics?
A. It creates criminal sentencing guidelines.
B. It issues ethics-related statements concerning the use of the Internet.
C. It edits Request for Comments.
D. It maintains ten commandments for ethical behavior.
问题 #63
Which of the following is a legal form of eavesdropping when performed with prior consent or a warrant?
A. Denial of Service
B. Dumpster diving
C. Wiretapping
D. Data diddling
问题 #64
During what stage of incident response is it determined if the source of the incident was internal or external, and how the offender penetrated and gained access to the asset?
A. Analysis
B. Containment
C. Tracking
D. Follow-up
问题 #65
Which of the following is not true of a forensics investigation?
A. The crime scene should be modified as necessary.
B. A file copy tool may not recover all data areas of the device that are necessary for investigation.
C. Contamination of the crime scene may not negate derived evidence, but it should still be documented.
D. Only individuals with knowledge of basic crime scene analysis should have access to the crime scene.
问题 #66
Great care must be taken to capture clues from a computer or device during a forensics exercise. Which of the following does not correctly describe the efforts that should be taken to protect an image?
A. The original image should be hashed with MD5 and/or SHA-256.
B. Two time-stamped images should be created.
C. New media should be properly purged before images are created on them.
D. Some systems must be imaged while they are running.
问题 #67
As a CISSP candidate, you must sign a Code of Ethics. Which of the following is from the (ISC)2 Code of Ethics for the CISSP?
A. Information should be shared freely and openly; thus, sharing confidential information should be ethical.
B. Think about the social consequences of the program you are writing or the system you are designing.
C. Discourage unnecessary fear or doubt.
D. Do not participate in Internet-wide experiments in a negligent manner.
问题 #68
What concept states that a criminal leaves something behind and takes something with them?
A. Modus Operandi
B. Profiling', "C. Locard's Principle of Exchange", 'D. Motive, Opportunity, and Means
问题 #69
Data marts, databases, and data warehouses have distinct characteristics. Which of the following does not correctly describe a data warehouse?
A. It could increase the risk of privacy violations.
B. It is developed to carry out analysis.
C. It contains data from several different sources.
D. It is created and used for project-based tactical reasons.
问题 #70
Database software should meet the requirements of what is known as the ACID test. Why should database software carry out atomic transactions, which is one requirement of the ACID test, when OLTP is used?
A. So that the rules for database integrity can be established
B. So that the database performs transactions as a single unit without interruption
C. To ensure that rollbacks cannot take place
D. To prevent concurrent processes from interacting with each other
问题 #71
Lisa has learned that most databases implement concurrency controls. What is concurrency, and why must it be controlled?
A. Processes running at different levels, which can negatively affect the integrity of the database if not properly controlled.
B. The ability to deduce new information from reviewing accessible data, which can allow an inference attack to take place.
C. Processes running simultaneously, which can negatively affect the integrity of the database if not properly controlled.
D. Storing data in more than one place within a database, which can negatively affect the integrity of the database if not properly controlled.
问题 #72
Robert has been asked to increase the overall efficiency of the sales database by implementing a procedure that structures data to minimize duplication and inconsistencies. What procedure is this?
A. Polymorphism
B. Normalization
C. Implementation of database views
D. Constructing schema
问题 #73
Which of the following correctly best describes an object-oriented database?
A. When an application queries for data, it receives both the data and the procedure.
B. It is structured similarly to a mesh network for redundancy and fast data retrieval.
C. Subject must have knowledge of the well-defined access path in order to access dat
A.
D. The relationships between data entities provide the framework for organizing dat
A.
问题 #74
Fred has been told he needs to test a component of the new content management application under development to validate its data structure, logic, and boundary conditions. What type of testing should he carry out?
A. Acceptance testing
B. Regression testing
C. Integration testing
D. Unit testing
问题 #75
Which of the following is the best description of a component-based system development method?
A. Components periodically revisit previous stages to update and verify design requirements
B. Minimizes the use of arbitrary transfer control statements between components
C. Uses independent and standardized modules that are assembled into serviceable programs
D. Implemented in module-based scenarios requiring rapid adaptations to changing client requirements
问题 #76
There are many types of viruses that hackers can use to damage systems. Which of the following is not a correct description of a polymorphic virus?
A. Intercepts antivirus's call to the operating system for file and system information", 'B. Varies the sequence of its instructions using noise, a mutation engine, or random-number generator
C. Can use different encryption schemes requiring different decryption routines
D. Produces multiple, varied copies of itself
问题 #77
Which of the following best describes the role of the Java Virtual Machine in the execution of Java applets?
A. Converts the source code into bytecode and blocks the sandbox
B. Converts the bytecode into machine-level code
C. Operates only on specific processors within specific operating systems', "D. Develops the applets, which run in a user's browser
问题 #78
What type of database software integrity service guarantees that tuples are uniquely identified by primary key values?
A. Concurrent integrity
B. Referential integrity
C. Entity integrity
D. Semantic integrity
问题 #79
In computer programming, cohesion and coupling are used to describe modules of code. Which of the following is a favorable combination of cohesion and coupling?
A. Low cohesion, low coupling
B. High cohesion, high coupling
C. Low cohesion, high coupling
D. High cohesion, low coupling
问题 #80
Which of the following statements does not correctly describe SOAP and Remote Procedure Calls?
A. SOAP was designed to overcome the compatibility and security issues associated with Remote Procedure Calls.
B. Both SOAP and Remote Procedure Calls were created to enable application-layer communication.
C. SOAP enables the use of Remote Procedure Calls for information exchange between applications over the Internet.
D. HTTP was not designed to work with Remote Procedure Calls, but SOAP was designed to work with HTTP.
问题 #81
When an organization is unsure of the final nature of the product, what type of system development method is most appropriate for them?
A. Cleanroom
B. Exploratory Model
C. Modified Prototype Method
D. Iterative Development
问题 #82
Which of the following is a correct description of the pros and cons associated with third-generation programming languages?
A. The use of heuristics reduced programming effort, but the amount of manual coding for a specific task is usually more than the preceding generation.
B. The use of syntax similar to human language reduced development time, but the language is resource intensive.
C. The use of binary was extremely time consuming but resulted in fewer errors.
D. The use of symbols reduced programming time, but the language required knowledge of machine architecture.
问题 #83
Which of the following is considered the second generation of programming languages?
A. Machine
B. Very high-level
C. High-level
D. Assembly
问题 #84
Mary is creating malicious code that will steal a user's cookies by modifying the original client-side Java script. What type of cross-site scripting vulnerability is she exploiting?
A. Second order
B. DOM-based
C. Persistent
D. Nonpersistent
问题 #85
Of the following steps that describe the development of a botnet, which best describes the step that comes first?
A. Infected server sends attack commands to the botnet.
B. Spammer pays a hacker for use of a botnet.
C. Controller server instructs infected systems to send spam to mail servers.
D. Malicious code is sent out that has bot software as its payload.
问题 #86
Which of the following antivirus detection methods is the most recent to the industry and monitors suspicious code as it executes within the operating system?
A. Behavior blocking
B. Fingerprint detection
C. Signature-based detection
D. Heuristic detection
问题 #87
Which of the following describes object-oriented programming deferred commitment?
A. Autonomous objects, with cooperate through exchanges of messages
B. The internal components of an object can be refined without changing other parts of the system
C. Object-oriented analysis, design, and modeling maps to business needs and solutions
D. Other programs using same objects
问题 #88
Which of the following is not a common component of configuration management change control steps?
A. Tested and presented
B. Service-level agreement approval
C. Report change to management
D. Approval of the change
问题 #89
A change management process should include a number of procedures. Which of the following incorrectly describes a characteristic or component of a change control policy?
A. Changes that are unanimously approved by the change control committee must be tested to uncover any unforeseen results.
B. Changes approved by the change control committee should be entered into a change log.
C. A schedule that outlines the projected phases of the change should be developed.
D. An individual or group should be responsible for approving proposed changes.
问题 #90
The requirement of erasure is the end of the media life cycle if it contains sensitive information. Which of the following best describes purging?
A. Changing the polarization of the atoms on the medi
A.
B. It is unacceptable when media are to be reused in the same physical environment for the same purposes.
C. Data formerly on the media is made unrecoverable by overwriting it with a pattern.
D. Information is made unrecoverable, even with extraordinary effort.
问题 #91
Device backup and other availability solutions are chosen to balance the value of having information available against the cost of keeping that information available. Which of the following best describes fault-tolerant technologies?
A. They are among the most expensive solutions and are usually only for the most mission-critical information.
B. They help service providers identify appropriate availability services for the specific customer.
C. They are required to maintain integrity, regardless of the other technologies in place.
D. They allow a failed component to be replaced while the system continues to run.
问题 #92
Which of the following correctly describes Direct Access and Sequential Access storage devices?
A. Any point on a Direct Access Storage Device may be promptly reached, whereas every point in between the current position and the desired position of a Sequential Access Storage Device must be traversed in order to reach the desired position.
B. RAIT is an example of a Direct Access Storage Device, while RAID is an example of a Sequential Access Storage Device.
C. MAID is a Direct Access Storage Device, while RAID is an example of a Sequential Access Storage Device.
D. As an example of Sequential Access Storage, tape drives are faster than Direct Access Storage Devices.
问题 #93
There are classifications for operating system failures. Which of the following refers to what takes place when an unexpected kernel or media failure happens and the regular recovery procedure cannot recover the system to a more consistent state, requirin
A. Emergency system restart
B. Trusted recovery
C. System cold start
D. System reboot
问题 #94
Which of the following incorrectly describes IP spoofing and session hijacking?
A. Address spoofing helps an attacker to hijack sessions between two users without being noticed.
B. IP spoofing makes it harder to track down an attacker.
C. Session hijacking can be prevented with mutual authentication.
D. IP spoofing is used to hijack SSL and IPSec secure communications.
问题 #95
RAID systems use a number of techniques to provide redundancy and performance. Which of the following activities divides and writes data over several drives?
A. Parity
B. Mirroring
C. Striping
D. Hot-swapping
问题 #96
What is the difference between hierarchical storage management and storage area network technologies?
A. HSM uses optical or tape jukeboxes, and SAN is a standard of how to develop and implement this technology.
B. HSM and SAN are one and the same. The difference is in the implementation.
C. HSM uses optical or tape jukeboxes, and SAN is a network of connected storage.
D. SAN uses optical or tape jukeboxes, and HSM is a network of connected storage systems.
问题 #97
John and his team are conducting a penetration test of a client's network. The team will conduct its testing armed only with knowledge it acquired from the Web. The network staff is aware that the testing will take place, but the penetration testing team
A. Full knowledge; blind test
B. Partial knowledge; blind test
C. Partial knowledge; double-blind test
D. Zero knowledge; targeted test
问题 #98
What type of exploited vulnerability allows more input than the program has allocated space to store it?
A. Symbolic links
B. File descriptors
C. Kernel flaws
D. Buffer overflows
问题 #99
There are often scenarios where the IT staff must react to emergencies and quickly apply fixes or change configurations. When dealing with such emergencies, which of the following is the best approach to making changes?
A. Review the changes within 48 hours of making them.
B. Review and document the emergency changes after the incident is over.
C. Activity should not take place in this manner.
D. Formally submit the change to a change control committee and follow the complete change control process.
问题 #100
Organizations should keep system documentation on hand to ensure that the system is properly cared for, that changes are controlled, and that the organization knows what's on the system. What does not need to be in this type of documentation?
A. Functionality
B. Changes
C. Volume of transactions
D. Identity of system owner
问题 #101
Fred is a new security officer who wants to implement a control for detecting and preventing users who attempt to exceed their authority by misusing the access rights that have been assigned to them. Which of the following best fits this need?
A. Management review
B. Two-factor identification and authentication
C. Capturing this data in audit logs
D. Implementation of a strong security policy
问题 #102
Which of the following is the best way to reduce brute-force attacks that allow intruders to uncover users' passwords?
A. Increase the clipping level.
B. Lock out an account for a certain amount of time after the clipping level is reached.
C. After a threshold of failed login attempts is met, the administrator must physically lock out the account.
D. Choose a weaker algorithm that encrypts the password file.
问题 #103
Brandy could not figure out how Sam gained unauthorized access to her system, since he has little computer experience. Which of the following is most likely the attack Sam used?
A. Dictionary attack
B. Shoulder surfing attack
C. Covert channel attack
D. Timing attack
问题 #104
The relay agent on a mail server plays a role in spam prevention. Which of the following incorrectly describes mail relays?
A. Antispam features on mail servers are actually antirelaying features.
B. Relays should be configured "wide open" to receive any e-mail message.
C. Relay agents are used to send messages from one mail server to another.
D. If a relay is configured "wide open," the mail server can be used to send spam.
问题 #105
John is responsible for providing a weekly report to his manager outlining the week's security incidents and mitigation steps. What steps should he take if a report has no information?
A. Send his manager an e-mail telling her so.', "B. Deliver last week's report and make sure it's clearly dated.", 'C. Deliver a report that states "No output."', "D. Don't do anything.
问题 #106
Brian, a security administrator, is responding to a virus infection. The antivirus application reports that a file has been infected with a dangerous virus and disinfecting it could damage the file. What course of action should Brian take?
A. Replace the file with the file saved from the day before.
B. Disinfect the file and contact the vendor.
C. Restore an uninfected version of the patched file from backup medi
A.
D. Back up the data and disinfect the file.
问题 #107
Guidelines should be followed to allow secure remote administration. Which of the following is not one of those guidelines?
A. A small number of administrators should be allowed to carry out remote functionality.
B. Critical systems should be administered locally instead of remotely.
C. Strong authentication should be in place.
D. Telnet should be used to send commands and dat
A.
问题 #108
Which of the following establishes the minimal national standards for certifying and accrediting national security systems?
A. NIACAP
B. DIACAP
C. HIPAA
D. TCSEC
问题 #109
Which of the following BEST describes an exploit?
A. An intentional hidden message or feature in an object such as a piece of software or a movie.
B. A chunk of data, or sequence of commands that take advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software.
C. An anomalous condition where a process attempts to store data beyond the boundaries of a fixed-length buffer.
D. A condition where a program (either an application or part of the operating system) stops performing its expected function and also stops responding to other parts of the system.
问题 #110
Which of the following BEST defines add-on security?
A. Physical security complementing logical security measures.
B. Protection mechanisms implemented as an integral part of an information system.
C. Layer security.
D. Protection mechanisms implemented after an information system has become operational.
问题 #111
Which of the following is NOT appropriate in addressing object reuse?
A. Degaussing magnetic tapes when they're no longer needed.", 'B. Deleting files on disk before reusing the space.
C. Clearing memory blocks before they are allocated to a program or dat
A.
D. Clearing buffered pages, documents, or screens from the local memory of a terminal or printer.
问题 #112
Remote Procedure Call (RPC) is a protocol that one program can use to request a service from a program located in another computer in a network. Within which OSI/ISO layer is RPC implemented?
A. Session layer
B. Transport layer
C. Data link layer
D. Network layer
问题 #113
In SSL/TLS protocol, what kind of authentication is supported when you establish a secure session between a client and a server?
A. Peer-to-peer authentication
B. Only server authentication (optional)
C. Server authentication (mandatory) and client authentication (optional)
D. Role based authentication scheme
问题 #114
Which of the following technologies has been developed to support TCP/IP networking over low-speed serial interfaces?
A. ISDN
B. SLIP
C. xDSL
D. T1
问题 #115
Why is a system’s criticality classification important in large organizations?
A. It provides for proper prioritization and scheduling of security and maintenance tasks.
B. It reduces critical system support workload and reduces the time required to apply patches.
C. It allows for clear systems status communications to executive management.
D. It provides for easier determination of ownership, reducing confusion as to the status of the asset.
问题 #116
What are the purposes of Attribute Value Pairs and how do they different from RADIUS and Diameter?
A. AVPs are the constructs that outline how two entities will communicate. Diameter has many more AVPs, which allow for the protocol to have more capabilities than RADIUS.
B. AVPs are the protocol parameters used between communicating entities. Diameter has less AVPs, which allow for the protocol to have more capabilities than RADIUS.
C. AVPs are the security mechanisms that provide confidentiality and integrity for data being passed back and forth between entities. Diameter has many more AVPs, which allow for the protocol to have more security capabilities than RADIUS.
问题 #117
Which of the following is UNTRUE of a database directory based on the X.500 standard?
A. The directory has a tree structure to organize the entries using a parent-child configuration.
B. Each entry has a unique name made up of attributes of a specific object.
C. The attributes used in the directory are dictated by the defined schem
A.
D. The unique identifiers are called fully qualified names.
问题 #118
Which one of the following is commonly used for retrofitting multilevel security to a Database Management System?
A. Trusted kernel
B. Kernel controller
C. Front end controller
D. Trusted front-end"
问题 #119
___consider as an obvious disadvantage of host based IDS?
A. It cannot analyze encrypted information.
B. It is costly to remove.
C. It is affected by switched networks.
D. It is costly to manage.
问题 #120
A business impact analysis is considered a functional analysis. Which of the following is not carried out during a business impact analysis?
A. A parallel or full-interruption test
B. The application of a classification scheme based on criticality levels
C. The gathering of information via interviews
D. Documentation of business functions
问题 #121
Phishing and pharming are similar. Which of the following correctly describes the difference between phishing and pharming?
A. Personal information is collected from victims through legitimate-looking Web sites in phishing attacks, while personal information is collected from victims via e-mail in pharming attacks.
B. Phishing attacks point e-mail recipients to a form where victims input personal information, while pharming attacks use pop-up forms at legitimate Web sites to collect personal information from victims.', "C. Victims are pointed to a fake Web site with a domain name that looks similar to a legitimate site's in a phishing attack, while victims are directed to a fake Web site as a result of a legitimate domain name being incorrectly translated by the DNS server in a pharming attack.", 'D. Phishing is a technical attack, while pharming is a type of social engineering.
问题 #122
Why would anomaly detection IDSs often generate a large number of false positives?
A. Because they can only identify correctly attacks they already know about.
B. Because they are application-based are more subject to attacks.
C. Because they can’t identify abnormal behavior.
D. Because normal patterns of user and system behavior can vary wildly.
问题 #123
What attack involves the perpetrator sending spoofed packet(s) with the SYN flag set to the victim's machine on any open port that is listening?
A. Bonk attack
B. Land attack
C. Teardrop attack
D. Smurf attack
问题 #124
The beginning and the end of each transfer during asynchronous communication data transfer are marked by?
A. Start and Stop bits.
B. Start and End bits.
C. Begin and Stop bits.
D. Start and Finish bits.
问题 #125
Non-Discretionary Access Control. A central authority determines what subjects can have access to certain objects based on the organizational security policy. The access controls may be based on?
A. The societies role in the organization.', "B. The individual's role in the organization.", "C. The group-dynamics as they relate to the individual's role in the organization.", 'D. The group-dynamics as they relate to the master-slave role in the organization.
问题 #126
To what does covert channel eavesdropping refer?
A. Using a hidden, unauthorized network connection to communicate unauthorized information
B. The use of two-factor passwords
C. Nonbusiness or personal use of the Internet
D. Socially engineering passwords from an ISP
问题 #127
Which of the following is NOT a property of Token Ring networks?
A. All end stations are attached to a MSAU.
B. These networks were originally designed to serve sporadic and only occasionally heavy traffic.
C. These networks were originally designed to serve large, bandwidthconsuming applications.
D. Workstations cannot transmit until they receive a token.
问题 #128
In the National Information Assurance Certification and Accreditation Process (NIACAP), a type accreditation performs which one of the following functions?
A. Evaluates the applications and systems at a specific, self-contained location
B. Evaluates a major application or general support system', "C. Verifies the evolving or modified system's compliance with the information agreed on in the System Security Authorization Agreement (SSAA)", 'D. Evaluates an application or system that is distributed to a number of different locations