« 返回题库列表2026最新CISSP模拟试题及答案|认证考试真题解析汇总
问题 #1
Valuable paper insurance coverage does cover damage to which of the following?
A. Inscribed, printed and Written documents
B. Manuscripts
C. Records
D. Money and Securities
问题 #2
Which of the following statements pertaining to a security policy is NOT true?
A. Its main purpose is to inform the users, administrators and managers of their obligatory requirements for protecting technology and information assets.
B. It specifies how hardware and software should be used throughout the organization.
C. It needs to have the acceptance and support of all levels of employees within the organization in order for it to be appropriate and effective.
D. It must be flexible to the changing environment.
问题 #3
If your property Insurance has Actual Cash Valuation (ACV) clause, your damaged property will be compensated based on:
A. Value of item on the date of loss
B. Replacement with a new item for the old one regardless of condition of lost item
C. Value of item one month before the loss
D. Value of item on the date of loss plus 10 percent
问题 #4
The preliminary steps to security planning include all of the following EXCEPT which of the following?
A. Establish objectives.
B. List planning assumptions.
C. Establish a security audit function.
D. Determine alternate courses of action
问题 #5
Step-by-step instructions used to satisfy control requirements are called a:
A. policy.
B. standard.
C. guideline.
D. procedure.
问题 #6
One purpose of a security awareness program is to modify:
A. employee's attitudes and behaviors towards enterprise's security posture.
B. management's approach towards enterprise's security posture.
C. attitudes of employees with sensitive dat
A.
D. corporate attitudes about safeguarding dat
A.
问题 #7
What is a security policy?
A. High level statements on management's expectations that must be met in regards to security
B. A policy that defines authentication to the network.
C. A policy that focuses on ensuring a secure posture and expresses management approval. It explains in detail how to implement the requirements.
D. A statement that focuses on the authorization process for a system
问题 #8
The end result of implementing the principle of least privilege means which of the following?
A. Users would get access to only the info for which they have a need to know
B. Users can access all systems.
C. Users get new privileges added when they change positions.
D. Authorization creep.
问题 #9
Which of the following exemplifies proper separation of duties?
A. Operators are not permitted modify the system time.
B. Programmers are permitted to use the system console.
C. Console operators are permitted to mount tapes and disks.
D. Tape operators are permitted to use the system console.
问题 #10
An access control policy for a bank teller is an example of the implementation of which of the following?
A. Rule-based policy
B. Identity-based policy
C. User-based policy
D. Role-based policy
问题 #11
At which of the Orange Book evaluation levels is configuration management required?
A. C1 and above.
B. C2 and above.
C. B1 and above.
D. B2 and above.
问题 #12
Which type of security control is also known as "Logical" control?
A. Physical
B. Technical
C. Administrative
D. Risk
问题 #13
Which Security and Audit Framework has been adopted by some organizations working towards Sarbanes-Oxley Section 404 compliance?.
A. Committee of Sponsoring Organizations of the Treadway Commission (COSO)
B. BIBA
C. National Institute of Standards and Technology Special Publication 800-66 (NIST SP 800-66)
D. CCTA Risk Analysis and Management Method (CRAMM)
问题 #14
The Widget Company decided to take their company public and while they were in the process of doing so had an external auditor come and look at their company. As part of the external audit they brought in a technology expert, who incidentally was a new CI
A. Only the Chief Financial Officer
B. Only the most Senior Management such as the Chief Executive Officer
C. Both the Chief Financial Officer and Technology Manager
D. Only The Technology Manager
问题 #15
The control measures that are intended to reveal the violations of security policy using software and hardware are associated with:
A. preventive/physical.
B. detective/technical.
C. detective/physical.
D. detective/administrative.
问题 #16
Which of the following steps is NOT one of the eight detailed steps of a Business Impact Assessment (BIA)?
A. Notifying senior management of the start of the assessment.
B. Creating data gathering techniques.
C. Identifying critical business functions.
D. Calculating the risk for each different business function.
问题 #17
Which of the following provides enterprise management with a prioritized list of time-critical business processes, and estimates a recovery time objective for each of the time critical processes and the components of the enterprise that support those proc
A. Business Impact Assessment
B. Current State Assessment
C. Risk Mitigation Assessment.
D. Business Risk Assessment.
问题 #18
Which of the following answers is the BEST example of Risk Transference?
A. Insurance
B. Results of Cost Benefit Analysis
C. Acceptance
D. Not hosting the services at all
问题 #19
Which of the following answer BEST relates to the type of risk analysis that involves committees, interviews, opinions and subjective input from staff?
A. Qualitative Risk Analysis
B. Quantitative Risk Analysis
C. Interview Approach to Risk Analysis
D. Managerial Risk Assessment
问题 #20
Regarding risk reduction, which of the following answers is BEST defined by the process of giving only just enough access to information necessary for them to perform their job functions?
A. Least Privilege Principle
B. Minimum Privilege Principle
C. Mandatory Privilege Requirement
D. Implicit Information Principle
问题 #21
Which term BEST describes a practice used to detect fraud for users or a user by forcing them to be away from the workplace for a while?
A. Mandatory Vacations
B. Least Privilege Principle
C. Obligatory Separation
D. Job Rotation
问题 #22
Which of the following is a fraud detection method whereby employees are moved from position to position?
A. Job Rotation
B. Mandatory Rotation
C. Mandatory Vacations
D. Mandatory Job Duties
问题 #23
The controls that usually require a human to evaluate the input from sensors or cameras to determine if a real threat exists are associated with:
A. preventive/physical.
B. detective/technical.
C. detective/physical.
D. detective/administrative.
问题 #24
Controls such as job rotation, the sharing of responsibilities, and reviews of audit records are associated with:
A. preventive/physical.
B. detective/technical.
C. detective/physical.
D. detective/administrative.
问题 #25
In terms or Risk Analysis and dealing with risk, which of the four common ways listed below seek to eliminate involvement with the risk being evaluated?
A. Avoidance
B. Acceptance
C. Transference
D. Mitigation
问题 #26
Of the multiple methods of handling risks which we must undertake to carry out business operations, which one involves using controls to reduce the risk?
A. Mitigation
B. Avoidance
C. Acceptance
D. Transference
问题 #27
There is no way to completely abolish or avoid risks, you can only manage them. A risk free environment does not exist. If you have risks that have been identified, understood and evaluated to be acceptable in order to conduct business operations. What is
A. Risk Acceptance
B. Risk Avoidance
C. Risk Transference
D. Risk Mitigation
问题 #28
John is the product manager for an information system. His product has undergone under security review by an IS auditor. John has decided to apply appropriate security controls to reduce the security risks suggested by an IS auditor. Which of the followin
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer
问题 #29
Sam is the security Manager of a financial institute. Senior management has requested he performs a risk analysis on all critical vulnerabilities reported by an IS auditor. After completing the risk analysis, Sam has observed that for a few of the risks,
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer
问题 #30
Which of the following risk handling technique involves the practice of being proactive so that the risk in question is not realized?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer
问题 #31
Which of the following risk handling technique involves the practice of passing on the risk to another entity, such as an insurance company?
A. Risk Mitigation
B. Risk Acceptance
C. Risk Avoidance
D. Risk transfer
问题 #32
Which of the following pairings uses technology to enforce access control policies?
A. Preventive/Administrative
B. Preventive/Technical
C. Preventive/Physical
D. Detective/Administrative
问题 #33
Which type of risk assessment is the formula ALE = ARO x SLE used for?
A. Quantitative Analysis
B. Qualitative Analysis
C. Objective Analysis
D. Expected Loss Analysis
问题 #34
Which of the following Confidentiality, Integrity, Availability (CIA) attribute supports the principle of least privilege by providing access to information only to authorized and intended users?
A. Confidentiality
B. Integrity
C. Availability
D. Accuracy
问题 #35
You are a manager for a large international bank and periodically move employees between positions in your department. What is this process called?
A. Job Rotation
B. Separation of Duties
C. Mandatory Vacation
D. Dual Control
问题 #36
Which of the following is a CHARACTERISTIC of a decision support system (DSS) in regards to Threats and Risks Analysis?
A. DSS is aimed at solving highly structured problems.
B. DSS emphasizes flexibility in the decision making approach of users.
C. DSS supports only structured decision-making tasks.
D. DSS combines the use of models with non-traditional data access and retrieval functions.
问题 #37
Which of the following is covered under Crime Insurance Policy Coverage?
A. Inscribed, printed and Written documents
B. Manuscripts
C. Accounts Receivable
D. Money and Securities
问题 #38
It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?
A. security administrator
B. security analyst
C. systems auditor
D. systems programmer
问题 #39
The number of violations that will be accepted or forgiven before a violation record is produced is called which of the following?
A. Clipping level
B. Acceptance level
C. Forgiveness level
D. Logging level
问题 #40
Which of the following ensures that security is NOT breached when a system crash or other system failure occurs?
A. Trusted recovery
B. Hot swappable
C. Redundancy
D. Secure boot
问题 #41
Which of the following ensures that a TCB is designed, developed, and maintained with formally controlled standards that enforces protection at each stage in the system's life cycle?
A. Life cycle assurance
B. Operational assurance
C. Covert timing assurance
D. Covert storage assurance
问题 #42
What is the MAIN objective of proper separation of duties?
A. To prevent employees from disclosing sensitive information.
B. To ensure access controls are in place.
C. To ensure that no single individual can compromise a system.
D. To ensure that audit trails are not tampered with.
问题 #43
This baseline sets certain thresholds for specific errors or mistakes allowed and the amount of these occurrences that can take place before it is considered suspicious?
A. Checkpoint level
B. Ceiling level
C. Clipping level
D. Threshold level
问题 #44
What is surreptitious transfer of information from a higher classification compartment to a lower classification compartment without going through the formal communication channels?
A. Object Reuse
B. Covert Channel
C. Security domain
D. Data Transfer
问题 #45
Which of the following is given the responsibility of the maintenance and protection of the data?
A. Data owner
B. Data custodian
C. User
D. Security administrator
问题 #46
In discretionary access environments, which of the following entities is authorized to grant information access to other people?
A. Manager
B. Group Leader
C. Security Manager
D. Data Owner
问题 #47
Who is ultimately responsible for the security of computer based information systems within an organization?
A. The tech support team
B. The Operation Team.
C. The management team.
D. The training team.
问题 #48
Which of the following embodies all the detailed actions that personnel are required to follow?
A. Standards
B. Guidelines
C. Procedures
D. Baselines
问题 #49
Who can best decide what are the adequate technical security controls in a computer-based application system in regards to the protection of the data being used, the criticality of the data, and its sensitivity level?
A. System Auditor
B. Data or Information Owner
C. System Manager
D. Data or Information user
问题 #50
Which of the following is NOT a responsibility of an information (data) owner?
A. Determine what level of classification the information requires.
B. Periodically review the classification assignments against business needs.
C. Delegate the responsibility of data protection to data custodians.
D. Running regular backups and periodically testing the validity of the backup dat
A.
问题 #51
In regards to information classification what is the main responsibility of information (data) owner?
A. determining the data sensitivity or classification level
B. running regular data backups
C. audit the data users
D. periodically check the validity and accuracy of the data
问题 #52
The owner of a system should have the confidence that the system will behave according to its specifications. This is termed as:
A. Integrity
B. Accountability
C. Assurance
D. Availability
问题 #53
The US department of Health, Education and Welfare developed a list of fair information practices focused on privacy of individually, personal identifiable information. Which one of the following is incorrect?
A. There must be a way for a person to find out what information about them exists and how it is used.
B. There must be a personal data record-keeping system whose very existence shall be kept secret.
C. There must be a way for a person to prevent information about them, which was obtained for one purpose, from being used or made available for another purpose without their consent.
D. Any organization creating, maintaining, using, or disseminating records of personal identifiable information must ensure reliability of the data for their intended use and must make precautions to prevent misuses of that dat
A.
问题 #54
The typical computer fraudsters are usually persons with which of the following characteristics?
A. They have had previous contact with law enforcement
B. They conspire with others
C. They hold a position of trust
D. They deviate from the accepted norms of society
问题 #55
The US-EU Safe Harbor process has been created to address which of the following?
A. Integrity of data transferred between U.S. and European companies
B. Confidentiality of data transferred between U.S and European companies
C. Protection of personal data transferred between U.S and European companies
D. Confidentiality of data transferred between European and international companies
问题 #56
What level of assurance for a digital certificate verifies a user's name, address, social security number, and other information against a credit bureau database?
A. Level 1/Class 1
B. Level 2/Class 2
C. Level 3/Class 3
D. Level 4/Class 4
问题 #57
According to Requirement 3 of the Payment Card Industry’s Data Security Standard (PCI DSS) there is a requirement to “protect stored cardholder data.” Which of the following items cannot be stored by the merchant?
A. Primary Account Number
B. Cardholder Name
C. Expiration Date
D. The Card Validation Code (CVV2)
问题 #58
Which of the following is NOT a proper component of Media Viability Controls?
A. Storage
B. Writing
C. Handling
D. Marking
问题 #59
Degaussing is used to clear data from all of the following media except:
A. Floppy Disks
B. Read-Only Media
C. Video Tapes
D. Magnetic Hard Disks
问题 #60
What is the main issue with media reuse?
A. Degaussing
B. Data remanence
C. Media destruction
D. Purging
问题 #61
Which of the following is the most reliable, secure means of removing data from magnetic storage media such as a magnetic tape, or a cassette?
A. Degaussing
B. Parity Bit Manipulation
C. Zeroization
D. Buffer overflow
问题 #62
Which of the following is NOT a media viability control used to protect the viability of data storage media?
A. clearing
B. marking
C. handling
D. storage
问题 #63
An electrical device (AC or DC) which can generate coercive magnetic force for the purpose of reducing magnetic flux density to zero on storage media or other magnetic media is called:
A. a magnetic field.
B. a degausser.
C. magnetic remanence.
D. magnetic saturation.
问题 #64
What is the most secure way to dispose of information on a CD-ROM?
A. Sanitizing
B. Physical damage
C. Degaussing
D. Physical destruction
问题 #65
Which of the following refers to the data left on the media after the media has been erased?
A. remanence
B. recovery
C. sticky bits
D. semi-hidden
问题 #66
What best describes a scenario when an employee has been shaving off pennies from multiple accounts and depositing the funds into his own bank account?
A. Data fiddling
B. Data diddling
C. Salami techniques
D. Trojan horses
问题 #67
Which of the following logical access exposures involvers changing data before, or as it is entered into the computer?
A. Data diddling
B. Salami techniques
C. Trojan horses
D. Viruses
问题 #68
When it comes to magnetic media sanitization, what difference can be made between clearing and purging information?
A. Clearing completely erases the media whereas purging only removes file headers, allowing the recovery of files.
B. Clearing renders information unrecoverable by a keyboard attack and purging renders information unrecoverable against laboratory attack.
C. They both involve rewriting the medi
A.
D. Clearing renders information unrecoverable against a laboratory attack and purging renders information unrecoverable to a keyboard attack.
问题 #69
Which of the following method is recommended by security professional to PERMANENTLY erase sensitive data on magnetic media?
A. Degaussing
B. Overwrite every sector of magnetic media with pattern of 1's and 0's
C. Format magnetic media
D. Delete File allocation table
问题 #70
Which protocol makes USE of an electronic wallet on a customer's PC and sends encrypted credit card information to merchant's Web server, which digitally signs it and sends it on to its processing bank?
A. SSH (Secure Shell)
B. S/MIME (Secure MIME)
C. SET (Secure Electronic Transaction)
D. SSL (Secure Sockets Layer)
问题 #71
In Mandatory Access Control, sensitivity labels attached to object contain what information?
A. The item's classification
B. The item's classification and category set
C. The item's category
D. The item's need to know
问题 #72
Which of the following European Union (EU) principles pertaining to the protection of information on private individuals is incorrect?
A. Data collected by an organization can be used for any purpose and for as long as necessary, as long as it is never communicated outside of the organization by which it was collected.
B. Individuals have the right to correct errors contained in their personal dat
A.
C. Transmission of personal information to locations where "equivalent" personal data protection cannot be assured is prohibited.
D. Records kept on an individual should be accurate and up to date.
问题 #73
Who should DECIDE how a company should approach security and what security measures should be implemented?
A. Senior management
B. Data owner
C. Auditor
D. The information security specialist
问题 #74
The Telecommunications Security Domain of information security is also concerned with the prevention and detection of the misuse or abuse of systems, which poses a threat to the tenets of:
A. Confidentiality, Integrity, and Entity (C.I.E.).
B. Confidentiality, Integrity, and Authenticity (C.I.
A. ).
C. Confidentiality, Integrity, and Availability (C.I.
A. ).
D. Confidentiality, Integrity, and Liability (C.I.L.).
问题 #75
Controlling access to information systems and associated networks is necessary for the preservation of their:
A. Authenticity, confidentiality and availability
B. Confidentiality, integrity, and availability.
C. Integrity and availability.
D. Authenticity, confidentiality, integrity and availability.
问题 #76
What security model is dependent on security labels?
A. Discretionary access control
B. Label-based access control
C. Mandatory access control
D. Non-discretionary access control
问题 #77
At which temperature does damage start occurring to magnetic media?
A. 100 degrees Fahrenheit or 37.7 degrees Celsius
B. 125 degrees Fahrenheit or 51.66 degrees Celsius
C. 150 degrees Fahrenheit or 65.5 degrees Celsius
D. 175 degrees Fahrenheit or 79.4 degrees Celsius
问题 #78
Which of the following access control models requires defining classification for objects?
A. Role-based access control
B. Discretionary access control
C. Identity-based access control
D. Mandatory access control
问题 #79
In which of the following security models is the subject's clearance compared to the object's classification such that specific rules can be applied to control how the subject-to-object interactions take place?
A. Bell-LaPadula model
B. Biba model
C. Access Matrix model
D. Take-Grant model
问题 #80
Which of the following classes is the first level (lower) defined in the TCSEC (Orange Book) as mandatory protection?
问题 #81
Which of the following classes is defined in the TCSEC (Orange Book) as discretionary protection?
问题 #82
Which of the following division is defined in the TCSEC (Orange Book) as minimal protection?
A. Division D
B. Division C
C. Division B
D. Division A
问题 #83
Which of the following establishes the minimal national standards for certifying and accrediting national security systems?
A. NIACAP
B. DIACAP
C. HIPAA
D. TCSEC
问题 #84
Which of the following places the Orange Book classifications in order from MOST secure to LEAST secure?
A. A, B, C, D
B. D, C, B, A
C. D, B, A, C
D. C, D, B, A
问题 #85
What would BEST define a covert channel?
A. An undocumented backdoor that has been left by a programmer in an operating system
B. An open system port that should be closed.
C. A communication channel that allows transfer of information in a manner that violates the system's security policy.
D. A Trojan horse.
问题 #86
Which of the following Orange Book ratings represents the highest level of trust?
问题 #87
What Orange Book security rating is reserved for systems that have been evaluated but fail to meet the criteria and requirements of the higher divisions?
问题 #88
Which division of the Orange Book deals with discretionary protection (need-to-know)?
问题 #89
Which of the following computer crime is MORE often associated with INSIDERS?
A. IP spoofing
B. Password sniffing
C. Data diddling
D. Denial of service (DoS)
问题 #90
Which of the following groups represents the leading source of computer crime losses?
A. Hackers
B. Industrial saboteurs
C. Foreign intelligence officers
D. Employees
问题 #91
Which of the following term BEST describes a weakness that could potentially be exploited?
A. Vulnerability
B. Risk
C. Threat
D. Target of evaluation (TOE)
问题 #92
Which of the following BEST describes an exploit?
A. An intentional hidden message or feature in an object such as a piece of software or a movie.
B. A chunk of data, or sequence of commands that take advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software.
C. An anomalous condition where a process attempts to store data beyond the boundaries of a fixed-length buffer.
D. A condition where a program (either an application or part of the operating system) stops performing its expected function and also stops responding to other parts of the system.
问题 #93
Virus scanning and content inspection of S/MIME encrypted e-mail without doing any further processing is:
A. Not possible
B. Only possible with key recovery scheme of all user keys
C. It is possible only if X509 Version 3 certificates are used
D. It is possible only by "brute force" decryption
问题 #94
What can be defined as secret communications where the very existence of the message is hidden?
A. Clustering
B. Steganography
C. Cryptology
D. Vernam cipher
问题 #95
Which of the following terms can be described as the process to conceal data into another file or media in a practice known as security through obscurity?
A. Steganography
B. ADS - Alternate Data Streams
C. Encryption
D. NTFS ADS
问题 #96
Which of the following can be best defined as computing techniques for inseparably embedding unobtrusive marks or labels as bits in digital data and for detecting or extracting the marks later?
A. Steganography
B. Digital watermarking
C. Digital enveloping
D. Digital signature
问题 #97
What is Dumpster Diving?
A. Going through dust bin
B. Running through another person's garbage for discarded document, information and other various items that could be used against that person or company
C. Performing media analysis
D. performing forensics on the deleted items
问题 #98
The control of communications test equipment should be clearly addressed by security policy for which of the following reasons?
A. Test equipment is easily damaged.
B. Test equipment can be used to browse information passing on a network.
C. Test equipment is difficult to replace if lost or stolen.
D. Test equipment must always be available for the maintenance personnel.
问题 #99
Which of the following would BEST be defined as an absence or weakness of safeguard that could be exploited?
A. A threat.
B. A vulnerability.
C. A risk.
D. An exposure.