<< Prev Question Next Question >>

Question 411/783

Secure Sockets Layer (SSL) uses a Message Authentication Code (MAC) for what purpose?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (783q)
Question 1: What is called the number of columns in a table?...
Question 2: Which access control model would a lattice-based access cont...
Question 3: Which of the following is not an EPA-approved replacement fo...
Question 4: What is the appropriate role of the security analyst in the ...
Question 5: Which of the following is NOT part of the Kerberos authentic...
Question 6: Which of the following is NOT a component of IPSec?...
Question 7: Which of the following statements pertaining to packet filte...
Question 8: Which of the following was developed as a simple mechanism f...
Question 9: Where in a PKI infrastructure is a list of revoked certifica...
Question 10: What is the essential difference between a self-audit and an...
Question 11: Which of the following NAT firewall translation modes allows...
Question 12: What would you call the process that takes advantages of the...
Question 13: Which of the following is often implemented by a one-for-one...
Question 14: Which answer BEST describes a computer software attack that ...
Question 15: FIPS-140 is a standard for the security of which of the foll...
Question 16: Which one of the following is usually not a benefit resultin...
Question 17: One of the following statements about the differences betwee...
Question 18: Which of the following is used to create and modify the stru...
Question 19: Which of the following protocols that provide integrity and ...
Question 20: A business continuity plan is an example of which of the fol...
Question 21: Which of the following rules pertaining to a Business Contin...
Question 22: What is called the use of technologies such as fingerprint, ...
Question 23: What is the most effective means of determining that control...
Question 24: Suppose you are a domain administrator and are choosing an e...
Question 25: Which of the following would be LESS likely to prevent an em...
Question 26: Which backup method is additive because the time and tape sp...
Question 27: Which of the following best describes the Secure Electronic ...
Question 28: The Domain Name System (DNS) is a global network of:...
Question 29: Which of the following protocols is designed to send individ...
Question 30: What is the main focus of the Bell-LaPadula security model?...
Question 31: Buffer overflow and boundary condition errors are subsets of...
Question 32: Which of the following is the marriage of object-oriented an...
Question 33: Which of the following was designed to support multiple netw...
Question 34: Which of the following is an extension to Network Address Tr...
Question 35: The exact requirements for the admissibility of evidence var...
Question 36: The ideal operating humidity range is defined as 40 percent ...
Question 37: Which of the following is NOT a way to secure a wireless net...
Question 38: For which areas of the enterprise are business continuity pl...
Question 39: The main issue with RAID Level 1 is that the one-for-one rat...
Question 40: How would nonrepudiation be BEST classified as?...
Question 41: Which of the following is the SIMPLEST type of firewall?...
Question 42: Which of the following statements pertaining to Kerberos is ...
Question 43: Which OSI/ISO layer is the Media Access Control (MAC) sublay...
Question 44: Which of the following activities would not be included in t...
Question 45: Which of the following is NOT true concerning Application Co...
Question 46: The fact that a network-based IDS reviews packets payload an...
Question 47: A central authority determines what subjects can have access...
Question 48: Which backup type run at regular intervals would take the le...
Question 49: Which type of control is concerned with avoiding occurrences...
Question 50: In SSL/TLS protocol, what kind of authentication is supporte...
Question 51: Which of the following questions is LESS likely to help in a...
Question 52: Which of the following security controls is intended to brin...
Question 53: When preparing a business continuity plan, who of the follow...
Question 54: Physically securing backup tapes from unauthorized access is...
Question 55: A packet filtering firewall looks at the data packet to get ...
Question 56: Which of the following identifies the encryption algorithm s...
Question 57: Which of the following specifically addresses cyber-attacks ...
1 commentQuestion 58: Public Key Infrastructure (PKI) uses asymmetric key encrypti...
Question 59: Which of the following is NOT a type of motion detector?...
Question 60: During the salvage of the Local Area Network and Servers, wh...
Question 61: In Synchronous dynamic password tokens:...
Question 62: What type of key would you find within a browser's list of t...
Question 63: What is the Maximum Tolerable Downtime (MTD)?...
Question 64: Which of the following determines that the product developed...
Question 65: Which of the following cryptographic attacks describes when ...
Question 66: What is considered the MOST important type of error to avoid...
Question 67: Access Control techniques do NOT include which of the follow...
Question 68: Which of the following choices is a valid Public Key Cryptog...
Question 69: Another example of Computer Incident Response Team (CIRT) ac...
Question 70: The International Organization for Standardization / Open Sy...
Question 71: What is a password called that is the same for each log-on s...
Question 72: What is a decrease in amplitude as a signal propagates along...
Question 73: Which of the following is a method of multiplexing data wher...
Question 74: Which of the following statements is TRUE about data encrypt...
Question 75: In which layer of the OSI Model are connection-oriented prot...
Question 76: Which security model introduces access to objects only throu...
Question 77: In the Bell-LaPadula model, the *-property (Star-property) i...
Question 78: Which of the following is NOT a system-sensing wireless prox...
Question 79: During the initial stage of configuration of your firewall, ...
Question 80: What is called the type of access control where there are pa...
Question 81: In computing what is the name of a non-self-replicating type...
Question 82: Which of the following is a reasonable response from the Int...
Question 83: Which of the following LAN devices only operates at the phys...
Question 84: Which of the following statements pertaining to firewalls is...
Question 85: Which protocol is used to send email?...
Question 86: Packet Filtering Firewalls can also enable access for:...
Question 87: The authenticator within Kerberos provides a requested servi...
Question 88: Domain Name Service is a distributed database system that is...
Question 89: Common Criteria has assurance level from EAL 1 to EAL 7 rega...
Question 90: You have been approached by one of your clients. They are in...
Question 91: Which of the following statements pertaining to ethical hack...
Question 92: What would you call an attack where an attacker can influenc...
Question 93: Which of the following biometrics devices has the highest Cr...
Question 94: What is the name of the FIRST mathematical model of a multi-...
Question 95: All of the following can be considered essential business fu...
Question 96: SMTP can best be described as:
Question 97: Which of the following is an issue with signature-based intr...
Question 98: Which of the following tape formats can be used to backup da...
Question 99: What is the primary difference between FTP and TFTP?...
Question 100: Password management falls into which control category?...
Question 101: Which security model uses an access control triple and also ...
Question 102: Which of the following was developed by the National Compute...
Question 103: In the UTP category rating, the tighter the wind:...
Question 104: What attribute is included in a X.509-certificate?...
Question 105: Which of the following attack is also known as Time of Check...
Question 106: What can be BEST defined as the examination of threat source...
Question 107: Which of the following attack is MOSTLY performed by an atta...
Question 108: Which of the following protocols does not operate at the dat...
Question 109: Which of the following DoD Model layer provides non-repudiat...
Question 110: What is the main concern with single sign-on?...
Question 111: Which device acting as a translator is used to connect two n...
Question 112: The Logical Link Control sub-layer is a part of which of the...
Question 113: Which of the following does NOT apply to system-generated pa...
Question 114: How many layers are defined within the US Department of Defe...
Question 115: Which of the following would be an example of the BEST passw...
Question 116: Which of the following is not a physical control for physica...
Question 117: Which xDSL flavor, appropriate for home or small offices, de...
Question 118: If any server in the cluster crashes, processing continues t...
Question 119: Which of the following statements pertaining to disaster rec...
Question 120: Why would a database be denormalized?...
Question 121: How many bits is the effective length of the key of the Data...
Question 122: Which of the following would describe a type of biometric er...
Question 123: Which of the following should be allowed through a firewall ...
Question 124: Which of the following is LESS likely to be used today in cr...
Question 125: The older coaxial cable has been widely replaced with twiste...
Question 126: Which of the following is most appropriate to notify an exte...
Question 127: Which one of the following is a key agreement protocol used ...
Question 128: The Diffie-Hellman algorithm is primarily used to provide wh...
Question 129: What sort of attack is described by the following: An attack...
Question 130: Which of the following is the act of performing tests and ev...
Question 131: Which of the following is a class A fire?...
Question 132: Which type of password provides maximum security because a n...
Question 133: Proxies work by transferring a copy of each accepted data pa...
Question 134: Which virus category has the capability of changing its own ...
Question 135: RADIUS incorporates which of the following services?...
Question 136: Which layer of the TCP/IP protocol model would BEST correspo...
Question 137: If an organization were to deploy only one Intrusion Detecti...
Question 138: During an IS audit, one of your auditors has observed that s...
Question 139: Why would anomaly detection IDSs often generate a large numb...
Question 140: The "vulnerability of a facility" to damage or attack may be...
Question 141: Controls provide accountability for individuals who are acce...
Question 142: What works as an E-mail message transfer agent?...
Question 143: Which of the following testing method examines the functiona...
Question 144: An Intrusion Detection System (IDS) is what type of control?...
Question 145: What uses a key of the same length as the message where each...
Question 146: Which of the following is less likely to be included in the ...
Question 147: What is one disadvantage of content-dependent protection of ...
Question 148: The BEST technique to authenticate to a system is to:...
Question 149: Which of the following security models does NOT concern itse...
Question 150: Organizations should consider which of the following first b...
Question 151: Which of the following BEST ensures accountability of users ...
Question 152: Which of the following would best describe the difference be...
Question 153: Which of the following is TRUE related to network sniffing?...
Question 154: Which of the following statements pertaining to biometrics i...
Question 155: In a stateful inspection firewall, data packets are captured...
Question 156: What kind of certificate is used to validate a user identity...
Question 157: The standard server port number for HTTP is which of the fol...
Question 158: Kerberos is vulnerable to replay in which of the following c...
Question 159: Which must bear the primary responsibility for determining t...
Question 160: Suppose that you are the COMSEC - Communications Security cu...
Question 161: The basic language of modems and dial-up remote access syste...
Question 162: What can be defined as a table of subjects and objects indic...
Question 163: When two or more separate entities (usually persons) operati...
Question 164: What is the percentage of invalid subjects that are falsely ...
Question 165: Which of the following is NOT a characteristic of a host-bas...
Question 166: How can an individual/person BEST be identified or authentic...
Question 167: Which of the following protects a password from eavesdropper...
Question 168: Public key infrastructure (PKI) consists of programs, data f...
Question 169: You have been tasked with developing a Business Continuity P...
Question 170: Which service usually runs on port 25?...
Question 171: In Operations Security trusted paths provide:...
Question 172: Brute force attacks against encryption keys have increased i...
Question 173: Under the principle of culpable negligence, executives can b...
Question 174: Which of the following backup methods is primarily run when ...
Question 175: Which of the following ciphers is a subset on which the Vige...
Question 176: Physical security is accomplished through proper facility co...
Question 177: Which OSI/ISO layer defines how to address the physical devi...
Question 178: Which of the following is less likely to accompany a conting...
Question 179: The Loki attack exploits a covert channel using which networ...
Question 180: Which Orange Book evaluation level is described as "Verified...
Question 181: Which of the following best describes signature-based detect...
Question 182: A business continuity plan should list and prioritize the se...
Question 183: To control access by a subject (an active entity such as ind...
Question 184: What are cognitive passwords?
Question 185: What are the four basic elements of Fire?...
Question 186: Ensuring that printed reports reach proper users and that re...
Question 187: Which of the following algorithms does NOT provide hashing?...
Question 188: Which of the following standards concerns digital certificat...
Question 189: A group of independent servers, which are managed as a singl...
Question 190: The MOST common threat that impacts a business's ability to ...
Question 191: How many bits is the address space reserved for the source I...
Question 192: The Data Encryption Standard (DES) encryption algorithm has ...
Question 193: Which of the following statements pertaining to software tes...
Question 194: The deliberate planting of apparent flaws in a system for th...
Question 195: Identity Management solutions include such technologies as D...
Question 196: Operations Security seeks to PRIMARILY protect against which...
Question 197: A host-based IDS is resident on which of the following?...
Question 198: Which of the following statements pertaining to IPSec is NOT...
Question 199: Which of the following is the most complete disaster recover...
Question 200: What is the PRIMARY use of a password?...
Question 201: Which type of attack involves hijacking a session between a ...
Question 202: Which of the following answers BEST describes the Bell La-Pa...
Question 203: Which of the following would best describe certificate path ...
Question 204: Which Orange book security rating introduces security labels...
Question 205: Which of the following is NOT an asymmetric key algorithm?...
Question 206: Which of the following media is MOST resistant to tapping?...
Question 207: Which of the following is NOT a two-factor authentication me...
Question 208: Which of the following answers is directly related to provid...
Question 209: Which of the following defines when RAID separates the data ...
Question 210: Which of the following defines the software that maintains a...
Question 211: Which of the following protocol is PRIMARILY used to provide...
Question 212: With regard to databases, which of the following has charact...
Question 213: Looking at the choices below, which ones would be the most s...
Question 214: The communications products and services, which ensure that ...
Question 215: Which of the following computer recovery sites is only parti...
Question 216: Which of the following encryption methods is known to be unb...
Question 217: In which mode of DES, will a block of plaintext and a key al...
Question 218: Which of the following test makes sure the modified or new s...
Question 219: A server cluster looks like a:
Question 220: Which of the following is the primary security feature of a ...
Question 221: At which OSI/ISO layer is an encrypted authentication betwee...
Question 222: A security evaluation report and an accreditation statement ...
Question 223: A demilitarized zone is:
Question 224: What is the act of obtaining information of a higher sensiti...
Question 225: Which of the following would constitute the BEST example of ...
Question 226: The equation used to calculate the total number of symmetric...
Question 227: Which one of the following factors is NOT one on which Authe...
Question 228: According to the Orange Book, which security level is the fi...
Question 229: What can be defined as the maximum acceptable length of time...
Question 230: Which of the following is a drawback of fiber optic cables?...
Question 231: Which of the following models does NOT include data integrit...
Question 232: Of the following, which multiple access method for computer ...
Question 233: Which of the following questions is LESS likely to help in a...
Question 234: In addition to the Legal Department, with what company funct...
Question 235: Which of the following is a Hashing Algorithm?...
Question 236: Which of the following effectively doubles the amount of har...
Question 237: Which is the last line of defense in a physical security sen...
Question 238: This type of control is used to ensure that transactions are...
Question 239: Which of the following is best defined as a circumstance in ...
Question 240: The act of requiring two of the three factors to be used in ...
Question 241: Which of the following protocols operates at the session lay...
Question 242: Kerberos depends upon what encryption method?...
Question 243: Which of the following is TRUE about Kerberos?...
Question 244: Which encryption algorithm is BEST suited for communication ...
Question 245: Which of the following are the two commonly defined types of...
Question 246: Which of the following protocols would BEST mitigate threats...
Question 247: Which access control model was proposed for enforcing access...
Question 248: Which of the following security controls might force an oper...
Question 249: Which of the following can prevent hijacking of a web sessio...
1 commentQuestion 250: What does "System Integrity" mean?...
Question 251: For competitive reasons, the customers of a large shipping c...
Question 252: An intranet is an Internet-like logical network that uses:...
Question 253: Which of the following statements pertaining to PPTP (Point-...
Question 254: Which of the following statements pertaining to the maintena...
Question 255: The DMZ does not normally contain:...
Question 256: What is RAD?
Question 257: What is called an attack where the attacker spoofs the sourc...
Question 258: The description of the database is called a schema. The sche...
Question 259: Single Sign-on (SSO) is characterized by which of the follow...
Question 260: Address Resolution Protocol (ARP) interrogates the network b...
Question 261: Which of the following would be the best reason for separati...
Question 262: Which layer of the DoD TCP/IP model controls the communicati...
Question 263: Which of the following is an IDS that acquires data and defi...
Question 264: Which of the following is NOT true about IPSec Tunnel mode?...
Question 265: Sensitivity labels are an example of what application contro...
Question 266: Which of the following protocol was used by the INITIAL vers...
Question 267: Which of the following is an advantage of prototyping?...
Question 268: Detective/Technical measures:
Question 269: An application layer firewall is also called a:...
Question 270: Which of the following is NOT an example of an operational c...
Question 271: Which of the following is the WEAKEST authentication mechani...
Question 272: In the context of Biometric authentication, there is a quick...
Question 273: Which of the following is TRUE regarding Transmission Contro...
Question 274: Which of the following Common Data Network Services is used ...
Question 275: Which of the following offers security to wireless communica...
Question 276: Which of the following is the most reliable authentication m...
Question 277: Which of the following statements pertaining to access contr...
Question 278: What can be defined as a list of subjects along with their a...
Question 279: Which of the following is NOT a symmetric key algorithm?...
Question 280: The BIGGEST difference between System High Security Mode and...
Question 281: Which of the following statements is NOT true of IPSec Trans...
Question 282: Which port does the Post Office Protocol Version 3 (POP3) ma...
Question 283: Which of the following is a problem regarding computer inves...
Question 284: The DES algorithm is an example of what type of cryptography...
Question 285: Which Network Address Translation (NAT) is the MOST convenie...
Question 286: What is a hot-site facility?
Question 287: Which of the following are the three classifications of RAID...
Question 288: Which Orange book security rating is the FIRST to be concern...
Question 289: Which of the following is an unintended communication path t...
Question 290: Which of the following plan provides procedures for sustaini...
Question 291: Which of the following represents the best programming?...
Question 292: Which of the following access control models requires securi...
Question 293: When we encrypt or decrypt data there is a basic operation i...
Question 294: Secure Electronic Transaction (SET) and Secure HTTP (S-HTTP)...
Question 295: Devices that supply power when the commercial utility power ...
Question 296: Like the Kerberos protocol, SESAME is also subject to which ...
Question 297: Which of the following items is NOT primarily used to ensure...
Question 298: Technical controls such as encryption and access control can...
Question 299: You are a security consultant who is required to perform pen...
Question 300: The type of discretionary access control (DAC) that is based...
Question 301: Which of the following IEEE standards defines the token ring...
Question 302: Which of the following statements pertaining to biometrics i...
Question 303: In biometric identification systems, the parts of the body c...
Question 304: Which of the following is often the GREATEST challenge of di...
Question 305: Which of the following is NOT a common weakness of packet fi...
Question 306: What is the difference between Access Control Lists (ACLs) a...
Question 307: What kind of encryption technology does SSL utilize?...
Question 308: Which of the following describes the sequence of steps requi...
Question 309: Which of the following keys has the SHORTEST lifespan?...
Question 310: Which of the following is a Wide Area Network that was origi...
Question 311: When a possible intrusion into your organization's informati...
Question 312: The object-relational and object-oriented models are better ...
Question 313: Complete the blanks. When using PKI, I digitally sign a mess...
1 commentQuestion 314: Tim is a network administrator of Acme Inc. He is responsibl...
Question 315: Which of the following is not a defined maturity level withi...
Question 316: What does the simple security (ss) property mean in the Bell...
Question 317: Which of the following answers best describes the type of pe...
Question 318: At what stage of the applications development process should...
Question 319: Which of the following was the FIRST mathematical model of a...
Question 320: The Information Technology Security Evaluation Criteria (ITS...
Question 321: Remote Procedure Call (RPC) is a protocol that one program c...
Question 322: Readable is to unreadable just as plain text is to:...
Question 323: In which LAN transmission method is a source packet copied a...
Question 324: Which of the following services is provided by S-RPC?...
Question 325: What is the primary role of smartcards in a PKI?...
Question 326: Where parties do not have a shared secret and large quantiti...
Question 327: A DMZ is also known as a:
Question 328: In a database management system (DBMS), what is the "cardina...
Question 329: During a test of a disaster recovery plan the IT systems are...
Question 330: Which of the following security-focused protocols has confid...
Question 331: Once evidence is seized, a law enforcement officer should em...
Question 332: How many bits compose an IPv6 address?...
Question 333: Which of the following item would best help an organization ...
Question 334: Which of the following is one of the oldest and most common ...
Question 335: Which of the following will a Business Impact Analysis NOT i...
Question 336: Which of the following is a cryptographic protocol and infra...
Question 337: Which of the following is NOT a disadvantage of Single Sign ...
Question 338: Which of the following is NOT a security characteristic we n...
Question 339: Of the reasons why a Disaster Recovery plan gets outdated, w...
Question 340: Which of the following is an advantage of using a high-level...
Question 341: Which of the following server contingency solutions offers t...
Question 342: Which of the following would be true about Static password t...
Question 343: What is the length of an MD5 message digest?...
Question 344: Which disaster recovery plan test involves functional repres...
Question 345: Which of the following is based on the premise that the qual...
Question 346: Which of the following RAID levels is not used in practice a...
Question 347: At which OSI layer does SSL reside in?...
Question 348: Which of the following are additional access control objecti...
Question 349: Legacy single sign on (SSO) is:...
Question 350: Who should measure the effectiveness of Information System s...
Question 351: What is used to hide data from unauthorized users by allowin...
Question 352: Which of the following would provide the BEST stress testing...
Question 353: Business Continuity Planning (BCP) is defined as a preparati...
Question 354: What algorithm has been selected as the AES algorithm, repla...
Question 355: Which of the following offers advantages such as the ability...
Question 356: What ensures that the control mechanisms correctly implement...
Question 357: What setup should an administrator use for regularly testing...
Question 358: Which of the following phases of a software development life...
Question 359: Which of the following is the MOST secure firewall implement...
Question 360: Which of the following is used to interrupt the opportunity ...
1 commentQuestion 361: What can be defined as a batch process dumping backup data t...
Question 362: Which of the following questions is LEAST likely to help in ...
Question 363: What is the percentage at which the False Rejection Rate equ...
Question 364: In order to ensure the privacy and integrity of the data, co...
Question 365: Which layer deals with Media Access Control (MAC) addresses?...
Question 366: Which of the following modes of DES is MOST likely used for ...
Question 367: Which of the following is used to monitor network traffic or...
Question 368: Which of the following are additional terms used to describe...
Question 369: What is the BEST answer pertaining to the difference between...
Question 370: What is the percentage of valid subjects that are falsely re...
Question 371: Which type of password token involves time synchronization?...
Question 372: When considering an IT System Development Life-cycle, securi...
Question 373: The primary service provided by Kerberos is which of the fol...
Question 374: Which of the following is true of biometrics?...
Question 375: Which element must computer evidence have to be admissible i...
Question 376: Which of following is NOT a service provided by AAA servers ...
Question 377: A packet containing a long string of NOP's followed by a com...
Question 378: Which of the following service is a distributed database tha...
Question 379: Why does compiled code pose more of a security risk than int...
Question 380: RAID levels 3 and 5 run:
Question 381: Which of the following can be defined as the process of reru...
Question 382: A Packet Filtering Firewall system is considered a:...
Question 383: What is the MOST important step in business continuity plann...
Question 384: Which of the following is NOT a property of the Rijndael blo...
Question 385: Which of the following is used in database information secur...
Question 386: What is the maximum allowable key size of the Rijndael encry...
Question 387: An Ethernet address is composed of how many bits?...
Question 388: In IPSec, if the communication is to be gateway-to-gateway o...
Question 389: One drawback of Application Level Firewall is that it reduce...
Question 390: Which of the following is an IP address that is private (i.e...
Question 391: Which IPSec operational mode encrypts the entire data packet...
Question 392: Which of the following statements relating to the Biba secur...
Question 393: Which of the following access control techniques BEST gives ...
Question 394: Which of the following is NOT a countermeasure to traffic an...
Question 395: What layer of the OSI/ISO model does Point-to-point tunnelin...
Question 396: Which access control model achieves data integrity through w...
Question 397: What is the PRIMARY purpose of using redundant array of inex...
Question 398: Which of the following describes the major disadvantage of m...
Question 399: What attack involves the perpetrator sending spoofed packet(...
Question 400: Attributes that characterize an attack are stored for refere...
Question 401: Communications devices must operate:...
Question 402: A business impact assessment is one element in business cont...
Question 403: Normalizing data within a database could include all or some...
Question 404: Which of the following is currently the most recommended wat...
Question 405: Hierarchical Storage Management (HSM) is commonly employed i...
Question 406: Which of the following best describes remote journaling?...
Question 407: A circuit level proxy is ____________ when compared to an ap...
Question 408: Which of the following type of cryptography is used when bot...
Question 409: Which of the following suppresses combustion by disrupting a...
Question 410: Which of the following is NOT a preventive login control?...
Question 411: Secure Sockets Layer (SSL) uses a Message Authentication Cod...
Question 412: Which model, based on the premise that the quality of a soft...
Question 413: Which of the following are placeholders for literal values i...
Question 414: Which of the following proves or disproves a specific act th...
Question 415: Which RAID implementation stripes data and parity at block l...
Question 416: Which of the following services is NOT provided by the digit...
Question 417: What is called the act of a user professing an identity to a...
Question 418: SQL commands do not include which of the following?...
Question 419: Which of the following translates source code one command at...
Question 420: Complete the following sentence. A digital signature is a:...
Question 421: This OSI layer has a service that negotiates transfer syntax...
Question 422: Data which is properly secured and can be described with ter...
Question 423: Which of the following is NOT an example of a detective cont...
Question 424: Configuration Management is a requirement for the following ...
Question 425: A hardware RAID implementation is usually:...
Question 426: Which RAID Level often implements a one-for-one disk to disk...
Question 427: A smart Card that has two chips with the Capability of utili...
Question 428: What is NOT true with pre shared key authentication within I...
Question 429: A copy of evidence or oral description of its contents; whic...
Question 430: When a biometric system is used, which error type deals with...
1 commentQuestion 431: Communications and network security relates to transmission ...
Question 432: A persistent collection of interrelated data items can be de...
1 commentQuestion 433: Layer 2 of the OSI model has two sublayers. What are those s...
Question 434: PGP uses which of the following to encrypt data?...
Question 435: What would you call a microchip installed on the motherboard...
Question 436: Which of the following is true about a "dry pipe" sprinkler ...
Question 437: The security of a computer application is MOST effective and...
Question 438: Who is responsible for initiating corrective measures and ca...
Question 439: What is defined as the rules for communicating between compu...
Question 440: What is Kerberos?
Question 441: The primary purpose for using one-way hashing of user passwo...
Question 442: Complex applications involving multimedia, computer aided de...
Question 443: Which Orange Book evaluation level is described as "Structur...
Question 444: Which of the following is an advantage of proxies?...
Question 445: Which of the following components are considered part of the...
Question 446: Which of the following can be defined as a framework that su...
Question 447: You are an information systems security officer at a mid-siz...
Question 448: Which of the following testing method examines internal stru...
Question 449: What is the minimum static charge able to cause disk drive d...
Question 450: A Business Continuity Plan should be tested:...
Question 451: Which of the following is TRUE about digital certificate?...
Question 452: In what way could Java applets pose a security threat?...
Question 453: Authentication Headers (AH) and Encapsulating Security Paylo...
Question 454: What is the framing specification used for transmitting digi...
Question 455: Which access model is most appropriate for companies with a ...
Question 456: Which of the following Common Data Network Services is used ...
Question 457: Which of the following is NOT an example of preventive contr...
Question 458: What is the maximum number of different keys that can be use...
Question 459: Which of the following is a tool often used to reduce the ri...
Question 460: Which BEST describes a tool (i.e. keyfob, calculator, memory...
Question 461: Several analysis methods can be employed by an IDS, each wit...
Question 462: Which of the following represents the rows of the table in a...
Question 463: Which of the following questions is LESS likely to help in a...
Question 464: Which of the following was developed to address some of the ...
Question 465: The RSA algorithm is an example of what type of cryptography...
Question 466: One of the following assertions is NOT a characteristic of I...
Question 467: An access system that grants users only those rights necessa...
Question 468: The throughput rate is the rate at which individuals, once e...
Question 469: Risk reduction in a system development life-cycle should be ...
Question 470: Which of the following statements pertaining to using Kerber...
Question 471: How often should tests and disaster recovery drills be perfo...
Question 472: There are parallels between the trust models in Kerberos and...
Question 473: Which of the following is NOT true of Secure Sockets Layer (...
Question 474: Which of the following allows two computers to coordinate in...
Question 475: What is the name for a substitution cipher that shifts the a...
Question 476: Secure Sockets Layer (SSL) is very heavily used for protecti...
Question 477: When an outgoing request is made on a port number greater th...
Question 478: Which type of attack involves the altering of a systems Addr...
Question 479: Unshielded Twisted Pair cabling is a:...
Question 480: When backing up an applications system's data, which of the ...
Question 481: Which access control type has a central authority that deter...
Question 482: Which of the following reviews system and event logs to dete...
Question 483: Which of the following is NOT a critical security aspect of ...
Question 484: What is the primary reason why some sites choose not to impl...
Question 485: Which of the following is a symmetric encryption algorithm?...
Question 486: Which of the following is TRUE of two-factor authentication?...
Question 487: When should a post-mortem review meeting be held after an in...
Question 488: What physical characteristic does a retinal scan biometric d...
Question 489: What is called an attack in which an attacker floods a syste...
Question 490: Which of the following is electromagnetic interference (EMI)...
Question 491: Which of the following is TRUE about link encryption?...
Question 492: Pin, Password, Passphrases, Tokens, smart cards, and biometr...
Question 493: What is an error called that causes a system to be vulnerabl...
Question 494: When RAID runs as part of the operating system on the file s...
Question 495: Which of the following Kerberos components holds all users' ...
Question 496: Which access control model is also called Non-Discretionary ...
Question 497: Similar to Secure Shell (SSH-2), Secure Sockets Layer (SSL) ...
Question 498: A public key algorithm that does both encryption and digital...
Question 499: Which of the following phases of a software development life...
Question 500: Failure of a contingency plan is usually:...
Question 501: Of the following, which is NOT a specific loss criteria that...
Question 502: Which access control model provides upper and lower bounds o...
Question 503: Behavioral-based systems are also known as?...
Question 504: What is the name of a one way transformation of a string of ...
Question 505: What assesses potential loss that could be caused by a disas...
Question 506: A database view is the results of which of the following ope...
Question 507: The environment that must be protected includes all personne...
Question 508: What is the verification that the user's claimed identity is...
Question 509: Which of the following is used to create parity information?...
Question 510: Of the seven types of Access Control Categories, which is de...
Question 511: Which of the following can be defined as THE unique attribut...
Question 512: In this type of attack, the intruder re-routes data traffic ...
Question 513: What algorithm was DES derived from?...
Question 514: Which of the following are well known ports assigned by the ...
Question 515: Which of the following is a Microsoft technology for communi...
Question 516: Which conceptual approach to intrusion detection system is t...
Question 517: What is an IP routing table?
Question 518: In an online transaction processing system (OLTP), which of ...
Question 519: Which of the following usually provides reliable, real-time ...
Question 520: This type of backup management provides a continuous on-line...
Question 521: Which of the following is the preferred way to suppress an e...
Question 522: According to the Orange Book, which security level is the fi...
Question 523: Which of the following transmission media would NOT be affec...
Question 524: This type of supporting evidence is used to help prove an id...
Question 525: In a known plaintext attack, the cryptanalyst has knowledge ...
Question 526: Which of the following is NOT a security goal for remote acc...
Question 527: RAID level 10 is created by combining which of the following...
Question 528: Network-based Intrusion Detection systems:...
Question 529: The International Standards Organization / Open Systems Inte...
Question 530: Which authentication technique BEST protects against hijacki...
Question 531: A DMZ is located:
Question 532: In which phase of Internet Key Exchange (IKE) protocol is pe...
Question 533: What is electronic vaulting?
Question 534: Which of the following technologies has been developed to su...
Question 535: Which Orange book security rating introduces the object reus...
Question 536: Which of the following services relies on UDP?...
Question 537: Compared to RSA, which of the following is true of Elliptic ...
Question 538: Which software development model is actually a meta-model th...
Question 539: Which of the following protects Kerberos against replay atta...
Question 540: An area of the Telecommunications and Network Security domai...
Question 541: Which OSI/OSI layer defines the X.24, V.35, X.21 and HSSI st...
Question 542: You are using an open source packet analyzer called Wireshar...
Question 543: What is the process that RAID Level 0 uses as it creates one...
Question 544: Which one of the following authentication mechanisms creates...
Question 545: Which of the following is an advantage in using a bottom-up ...
Question 546: Which type of algorithm is considered to have the highest st...
Question 547: Which of the following is NOT a VPN communications protocol ...
Question 548: A periodic review of user account management should NOT dete...
Question 549: Which of the following answers presents the MOST significant...
Question 550: The Secure Hash Algorithm (SHA-1) creates:...
Question 551: Which of the following statements pertaining to disaster rec...
Question 552: At which layer of ISO/OSI does the fiber optics work?...
Question 553: What would be considered the biggest drawback of Host-based ...
Question 554: In the process of gathering evidence from a computer attack,...
Question 555: Which of the following was designed as a more fault-tolerant...
Question 556: Which of the following security models introduced the idea o...
Question 557: The RSA Algorithm uses which mathematical concept as the bas...
Question 558: Which of the following is a class C fire?...
Question 559: Which of the following methods of providing telecommunicatio...
Question 560: In what LAN topology do all the transmissions of the network...
Question 561: Which of the following can be defined as a unique identifier...
Question 562: Which backup method usually resets the archive bit on the fi...
Question 563: What is the PRIMARY reason to maintain the chain of custody ...
Question 564: During a business impact analysis it is concluded that a sys...
Question 565: Which of the following stripes the data and the parity infor...
Question 566: Which of the following statements relating to Distributed Co...
Question 567: Which of the following is not a property of the Rijndael blo...
Question 568: Which of the following statements pertaining to the Bell-LaP...
Question 569: Common Criteria 15408 generally outlines assurance and funct...
Question 570: Which of the following is an important part of database desi...
Question 571: Which of the following is NOT a component of an Operations S...
Question 572: What is the 802.11 standard related to?...
Question 573: What are user interfaces that limit the functions that can b...
Question 574: What is a sequence of characters that is usually longer than...
Question 575: Which access control method allows the data owner (the perso...
Question 576: What is the maximum length of cable that can be used for a t...
Question 577: Which expert system operating mode allows determining if a g...
Question 578: Individual accountability does not include which of the foll...
Question 579: In telephony different types of connections are being used. ...
Question 580: What does the * (star) property mean in the Bell-LaPadula mo...
Question 581: The first step in the implementation of the contingency plan...
Question 582: Which of the following backup method must be made regardless...
Question 583: Why is infrared generally considered to be more secure to ea...
Question 584: All hosts on an IP network have a logical ID called a(n):...
Question 585: After a company is out of an emergency state, what should be...
Question 586: What does the * (star) integrity axiom mean in the Biba mode...
Question 587: Which of the following can BEST eliminate dial-up access thr...
Question 588: When attempting to establish liability, which of the followi...
Question 589: What is the role of IKE within the IPsec protocol?...
Question 590: Which of the following statements do apply to a hot site?...
Question 591: Referential Integrity requires that for any foreign key attr...
Question 592: Why do buffer overflows happen? What is the main cause?...
Question 593: Which of the following are suitable protocols for securing V...
Question 594: Which of the following security control is intended to avoid...
Question 595: Which protocol's primary function is to facilitate file and ...
Question 596: When submitting a passphrase for authentication, the passphr...
Question 597: Which of the following is a not a preventative control?...
Question 598: Which is NOT a suitable method for distributing certificate ...
Question 599: Notifying the appropriate parties to take action in order to...
Question 600: Which of the following control helps to identify an incident...
Question 601: Why does fiber optic communication technology have significa...
Question 602: Which of the following is not an element of a relational dat...
Question 603: Which of the following biometrics methods provides the HIGHE...
Question 604: Matches between which of the following are important because...
Question 605: Logical or technical controls involve the restriction of acc...
Question 606: What does the Clark-Wilson security model focus on?...
Question 607: Of the three types of alternate sites: hot, warm or cold, wh...
Question 608: Which layer of the OSI/ISO model handles physical addressing...
Question 609: What is a characteristic of using the Electronic Code Book m...
Question 610: The three classic ways of authenticating yourself to the com...
Question 611: Which security model uses division of operations into differ...
Question 612: A 'Pseudo flaw' is which of the following?...
Question 613: Which of the following virus types changes some of its chara...
Question 614: Which of the following teams should NOT be included in an or...
Question 615: Which of the following would not correspond to the number of...
Question 616: At which of the OSI/ISO model layer is IP implemented?...
Question 617: Another type of access control is lattice-based access contr...
Question 618: Which of the following is NOT a form of detective technical ...
Question 619: When considering all the reasons that buffer overflow vulner...
Question 620: Which of the following media is MOST resistant to EMI interf...
Question 621: Another name for a VPN is a:
Question 622: Why would a memory dump be admissible as evidence in court?...
Question 623: What is the RESULT of a hash algorithm being applied to a me...
Question 624: Which of the following protection devices is used for spot p...
Question 625: Which of the following is implemented through scripts or sma...
Question 626: Which of the following is NOT an advantage that TACACS+ has ...
Question 627: Transport Layer Security (TLS) is a two-layered socket layer...
Question 628: When planning for disaster recovery it is important to know ...
Question 629: Asynchronous Communication transfers data by sending:...
Question 630: What is the PRIMARY goal of incident handling?...
Question 631: The steps of an access control model should follow which log...
Question 632: RAID Level 1 is commonly called which of the following?...
Question 633: In what type of attack does an attacker try, from several en...
Question 634: The high availability of multiple all-inclusive, easy-to-use...
Question 635: Which of the following is NOT a correct notation for an IPv6...
Question 636: Which of the following statements pertaining to VPN protocol...
Question 637: Which of the following is immune to the effects of electroma...
Question 638: Which of the following Common Data Network Services allocate...
Question 639: In biometric identification systems, at the beginning, it wa...
Question 640: In the course of responding to and handling an incident, you...
Question 641: In what way can violation of clipping levels assist in viola...
Question 642: Which of the following is the BIGGEST concern with firewall ...
Question 643: Which of the following should be used as a replacement for T...
Question 644: The Computer Security Policy Model the Orange Book is based ...
Question 645: Which integrity model defines a constrained data item, an in...
Question 646: Which of the following are required for Life-Cycle Assurance...
Question 647: To be admissible in court, computer evidence must be which o...
Question 648: Which backup method is used if backup time is critical and t...
Question 649: What IDS approach relies on a database of known attacks?...
Question 650: Which backup method only copies files that have been recentl...
Question 651: Which of the following is required in order to provide accou...
Question 652: In a SSL session between a client and a server, who is respo...
Question 653: Which of the following would be MOST important to guarantee ...
Question 654: What is the effective key size of DES?...
Question 655: Which of the following statements pertaining to Kerberos is ...
Question 656: Which of the following is the most costly countermeasure to ...
Question 657: Which of the following is NOT true of the Kerberos protocol?...
Question 658: RAID Level 1 mirrors the data from one disk or set of disks ...
Question 659: You are part of a security staff at a highly profitable bank...
Question 660: Which of the following biometric devices offers the LOWEST C...
Question 661: Which of the following can be defined as an attribute in one...
Question 662: Which of the following best describes what would be expected...
Question 663: What does the simple integrity axiom mean in the Biba model?...
Question 664: The information security staff's participation in which of t...
Question 665: In the days before CIDR (Classless Internet Domain Routing),...
Question 666: What security model implies a central authority that defines...
Question 667: Which type of control is concerned with restoring controls?...
Question 668: Which of the following is NOT a technique used to perform a ...
Question 669: An X.509 public key certificate with the key usage attribute...
Question 670: The MAIN issue with Level 1 of RAID is which of the followin...
Question 671: Which type of encryption is considered to be unbreakable if ...
Question 672: Which of the following Operation Security controls is intend...
Question 673: Which of the following BEST explains why computerized inform...
Question 674: What is the main problem of the renewal of a root CA certifi...
Question 675: Application Layer Firewalls operate at the:...
Question 676: What is the MOST critical characteristic of a biometric iden...
Question 677: You work in a police department forensics lab where you exam...
Question 678: What kind of encryption is realized in the S/MIME-standard?...
Question 679: What is NOT an authentication method within IKE and IPsec?...
Question 680: Complete the following sentence. A message can be encrypted,...
Question 681: When referring to a computer crime investigation, which of t...
Question 682: Which of the following is TRUE of network security?...
Question 683: Which of the following issues is not addressed by digital si...
Question 684: What is the primary role of cross certification?...
Question 685: What mechanism automatically causes an alarm originating in ...
Question 686: When first analyzing an intrusion that has just been detecte...
Question 687: During an IS audit, auditor has observed that authentication...
Question 688: Which layer defines how packets are routed between end syste...
Question 689: The spare drives that replace the failed drives are usually ...
Question 690: Which of the following statements pertaining to packet switc...
Question 691: Which of the following devices enables more than one signal ...
Question 692: Which of the following packets should NOT be dropped at a fi...
Question 693: Which of the following enables the person responsible for co...
Question 694: View the image below and identify the attack (Exhibit)...
Question 695: Which of the following is NOT an example of an asymmetric ke...
Question 696: Which of the following BEST describes Configuration Manageme...
Question 697: Which TCSEC (Orange Book) rating or level requires the syste...
Question 698: In regards to relational database operations using the Struc...
Question 699: What is the Biba security model concerned with?...
Question 700: What would you call a network security control deployed in l...
Question 701: Access control is the collection of mechanisms that permits ...
Question 702: Which of the following Common Data Network Services is used ...
Question 703: Which access control model is BEST suited in an environment ...
Question 704: The Physical Security domain focuses on three areas that are...
Question 705: In non-discretionary access control using Role Based Access ...
Question 706: Which one of the following is NOT one of the outcomes of a v...
Question 707: Frame relay and X.25 networks are part of which of the follo...
Question 708: Ding Ltd. is a firm specialized in intellectual property bus...
Question 709: Which of the following is NOT a true statement regarding the...
Question 710: Which of the following can best define the "revocation reque...
Question 711: Within the OSI model, at what layer are some of the SLIP, CS...
Question 712: Which of the following asymmetric encryption algorithms is b...
Question 713: In the Open Systems Interconnect (OSI) Reference Model, at w...
Question 714: What is the access protection system that limits connections...
Question 715: Which of the following is commonly used for retrofitting mul...
Question 716: Which of the following monitors network traffic in real time...
Question 717: Frame relay uses a public switched network to provide:...
Question 718: Which cable technology refers to the CAT3 and CAT5 categorie...
Question 719: Which of the following is NOT a characteristic or shortcomin...
Question 720: An intranet provides more security and control than which of...
Question 721: In an organization where there are frequent personnel change...
Question 722: What is the primary goal of setting up a honey pot?...
Question 723: In regards to the query function of relational database oper...
Question 724: Which of the following statements relating to the Bell-LaPad...
Question 725: Smart cards are an example of which type of control?...
Question 726: Which layer of the TCP/IP protocol model defines the IP data...
Question 727: Which of the following backup methods makes a complete backu...
Question 728: The International Standards Organization / Open Systems Inte...
Question 729: Which of the following biometric devices has the lowest user...
Question 730: In the context of access control, locks, gates, guards are e...
Question 731: Which of the following is a LAN transmission method?...
Question 732: Knowledge-based Intrusion Detection Systems (IDS) are more c...
Question 733: Which of the following is NOT a preventive operational contr...
Question 734: Which of the following is NOT a valid reason to use external...
Question 735: Which RAID implementation is commonly called mirroring?...
Question 736: Which of the following statements pertaining to software tes...
Question 737: In order to be able to successfully prosecute an intruder:...
Question 738: The viewing of recorded events after the fact using a closed...
Question 739: Which backup method does not reset the archive bit on files ...
Question 740: Which of the following can be defined as the set of allowabl...
Question 741: Which of the following NAT firewall translation modes offers...
Question 742: In biometrics, "one-to-many" search against database of stor...
Question 743: Guards are appropriate whenever the function required by the...
Question 744: The only difference between RAID 3 and RAID 4 is that level ...
Question 745: Which of the following organizations PRODUCES and PUBLISHES ...
Question 746: When a station communicates on the network for the first tim...
Question 747: Which security model ensures that actions that take place at...
Question 748: Business Impact Analysis (BIA) is about:...
Question 749: Which ISO/OSI layer establishes the communications link betw...
Question 750: Which of the following is most affected by denial-of-service...
Question 751: What is the three-way handshake sequence used to initiate TC...
Question 752: Which of the following best describes the purpose of debuggi...
Question 753: Rule-Based Access Control (RuBAC) access is determined by ru...
Question 754: A virus is a program that can replicate itself on a system b...
Question 755: A network-based vulnerability assessment is a type of test a...
Question 756: Which of the following assertions is NOT true about pattern ...
Question 757: Which of the following characteristics pertaining to databas...
Question 758: Which of the following is an IP address that is private (i.e...
Question 759: What is the greatest danger from DHCP?...
Question 760: Which of the following does not address Database Management ...
Question 761: Which fire class can water be most appropriate for?...
Question 762: Which of the following cable types is limited in length to 1...
Question 763: Which of the following statements pertaining to IPSec is NOT...
Question 764: Which of the following should NOT normally be allowed throug...
Question 765: Which of the following cannot be undertaken in conjunction o...
Question 766: What is called an exception to the search warrant requiremen...
Question 767: Who developed one of the first mathematical models of a mult...
Question 768: Which of the following remote access authentication systems ...
Question 769: The Clipper Chip utilizes which concept in public key crypto...
Question 770: Which of the following phases of a system development life-c...
Question 771: Which of the following is addressed by Kerberos?...
Question 772: Which RAID level concept is considered more expensive and is...
Question 773: You wish to make use of "port knocking" technologies. How ca...
Question 774: What protocol is used on the Local Area Network (LAN) to obt...
Question 775: In a hierarchical PKI the highest CA is regularly called Roo...
Question 776: You are a criminal hacker and have infiltrated a corporate n...
Question 777: Java is not:
Question 778: Which layer of the TCP/IP protocol stack corresponds to the ...
Question 779: Which of the following represents a relation, which is the b...
Question 780: What can be defined as an instance of two different keys gen...
Question 781: Which of the following biometric parameters are better suite...
Question 782: Which of the following category of UTP cables is specified t...
Question 783: A confidential number used as an authentication factor to ve...