<< Prev Question Next Question >>

Question 571/699

Which one of the following can be identified when exceptions occur using operations security detective controls?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (699q)
Question 1: Which of the following is typically NOT a consideration in t...
Question 2: What is the name for a substitution cipher that shifts the a...
Question 3: What does CSMA stand for?
Question 4: Mandatory Access Controls (MAC) are based on:...
Question 5: Which of the following would present the highert annualized ...
Question 6: Which of the following is an example of an active attack?...
Question 7: What is it called when a computer uses more than one CPU in ...
Question 8: Which of the following protocols does not operate at the dat...
Question 9: What is called the access protection system that limits conn...
Question 10: In developing an emergency or recovery plan, which choice be...
Question 11: In Business Continuity Planning (BCP), what is the importanc...
Question 12: What is the primary purpose of using redundant array of inex...
Question 13: Which choice below is NOT an element of BCP plan approval an...
Question 14: Which one of the following is a security issue related to ag...
Question 15: What is the second phase of Public Key Infrastructure (PKI) ...
Question 16: Which of the following provides the MOST protection against ...
Question 17: Which statement accurately describes the difference between ...
Question 18: Which of the following does NOT concern itself with key mana...
Question 19: Which of the following is BEST suited for exchanging authent...
Question 20: Law enforcement officials in the United States, up until pas...
Question 21: Which of the following is the MOST relevant risk indicator a...
Question 22: DRAG DROP Place the following information classification ste...
Question 23: Which International Organization for Standardization standar...
Question 24: Which of the following remote access authentication systems ...
Question 25: Which type of attack involves the altering of a systems Addr...
Question 26: Making sure that only those who are supposed to access the d...
Question 27: Which OSI/ISO layer is the Media Access Control (MAC) sublay...
Question 28: Why do certificate Authorities (CA) add value to the securit...
Question 29: Refer to the information below to answer the question. A lar...
Question 30: In finger scan technology,
Question 31: Data remanence refers to which of the following?...
Question 32: A Business Impact Analysis (BIA) does not:...
Question 33: What is the BEST approach for controlling access to highly s...
Question 34: The most prevalent cause of computer center fires is which o...
Question 35: Which of the following biometrics devices has the highs Cros...
Question 36: Refer to the information below to answer the question. In a ...
Question 37: Under intellectual property law what would you call informat...
Question 38: A message can be encrypted and digitally signed, which provi...
Question 39: Which category of law is also referenced as a Tort law?...
Question 40: Which one of the following security technologies provides sa...
Question 41: Which access control would a lattice-based access control be...
Question 42: Which choice is NOT an accurate description of C.I.A.?...
Question 43: The implementation of which features of an identity manageme...
Question 44: Which protocol makes USE of an electronic wallet on a custom...
Question 45: Compared with hardware cryptography, software cryptography i...
Question 46: A chemical plan wants to upgrade the Industrial Control Syst...
Question 47: What is called an attack where the attacker spoofs the sourc...
Question 48: Which type of risk assessment is the formula ALE = ARO x SLE...
Question 49: In which phase of the System Development Lifecycle (SDLC) is...
Question 50: What is the percentage of valid subjects that are falsely re...
Question 51: The termination of selected, non-critical processing when a ...
Question 52: Which of the following is NOT part of the Kerberos authentic...
Question 53: Which of the following could elicit a Denial of Service (DoS...
Question 54: According to the Orange Book, which security level is the fi...
Question 55: Physical assets defined in an organization's Business Impact...
Question 56: Which attack defines a piece of code that is inserted into s...
Question 57: Which of the following cloud deployment model can be shared ...
Question 58: An organization publishes and periodically updates its emplo...
Question 59: Which of the following statements relating to the Biba secur...
Question 60: Which of the following should be performed by an operator?...
Question 61: What is RAD?
Question 62: Prior to a live disaster test, which of the following is mos...
Question 63: From a cryptographic perspective, the service of non-repudia...
Question 64: Which of the following would be defined as an absence of saf...
Question 65: Controls such as job rotation, the sharing of responsibiliti...
Question 66: Retaining system logs for six months or longer can be valuab...
Question 67: Which book of the Rainbow series addresses the Trusted Netwo...
Question 68: What is a security requirement that is unique to Compartment...
Question 69: The type of authorized interactions a subject can have with ...
Question 70: Which of the following are computer investigation issues? S...
Question 71: Crime Prevention Through Environmental Design (CPTED) is a d...
Question 72: What does it mean to say that sensitivity labels are "incomp...
Question 73: A security architect plans to reference a Mandatory Access C...
Question 74: Which of the following is the primary advantage of segmentin...
Question 75: In what LAN topology do all the transmissions of the network...
Question 76: Which of the following is not an Orange book-defined life cy...
Question 77: The primary service provided by Kerberos is which of the fol...
Question 78: Why do buffer overflows happen? What is the main cause?...
Question 79: Which answer best describes a computer software attack that ...
Question 80: Which of the following statements regarding trade secrets is...
Question 81: Which one of the following activities would present a signif...
Question 82: Which of the following BEST describes how access to a system...
Question 83: Which of the following is NOT a true statement about Network...
Question 84: A security professional is assessing the risk in an applicat...
Question 85: Who can best decide what are the adequate technical security...
Question 86: Which is not one of the primary goals of BIA?...
Question 87: Which layer of the Open system Interconnect (OSI) model is r...
Question 88: In computing what is the name of a non-self-replicating type...
Question 89: The environment that must be protected includes all personne...
Question 90: Which Orange book security rating is the FIRST to be concern...
Question 91: As per the Orange Book, what are two types of system assuran...
Question 92: What is a disaster recovery plan for a company's computer sy...
Question 93: What is one disadvantage of content-dependent protection of ...
Question 94: An organization publishes and periodically updates its emplo...
Question 95: The Number Field Sieve (NFS) is a:...
Question 96: Which of the following is a transaction redundancy implement...
Question 97: Which of the following BEST describes the purpose of the sec...
Question 98: This backup method must be made regardless of whether Differ...
Question 99: Which one of these statements about the key elements of a go...
Question 100: Why is infrared generally considered to be more secure to ea...
Question 101: A security professional should consider the protection of wh...
Question 102: Which of the following statements pertaining to PPTP (Point-...
Question 103: Which of the following is considered best practice for preve...
Question 104: Related to information security, the guarantee that the mess...
Question 105: Making sure that the data has not been changed unintentional...
Question 106: Which is NOT a property of Fiber Optic cabling?...
Question 107: Address Resolution Protocol (ARP) interrogates the network b...
Question 108: Which of the following is NOT a media viability control used...
Question 109: In a PKI infrastructure where are list of revoked certificat...
Question 110: The PRIMARY outcome of a certification process is that it pr...
Question 111: Refer to the information below to answer the question. In a ...
Question 112: Which of the following operates at the Network Layer of the ...
Question 113: Operations Security seeks to primarily protect against which...
Question 114: Hierarchical Storage Management (HSM) is commonly employed i...
Question 115: Which of the following adds end-to-end security inside a Lay...
Question 116: Which Orange book security rating is the FIRST to be concern...
Question 117: What does "residual risk" mean?...
Question 118: Which of the following is the biggest concern with firewall ...
Question 119: What is the main issue with media reuse?...
Question 120: How often should logging be run?...
Question 121: In which layer of the OSI Model are connection-oriented prot...
Question 122: How fast is private key cryptography compared to public key ...
Question 123: The privacy provisions of the federal law, the Health Insura...
Question 124: Which of the following are required components for implement...
Question 125: Why is planning in Disaster Recovery (DR) an interactive pro...
Question 126: Which of the following is a weakness of both statistical ano...
Question 127: Which of the following is an ip address that is private? (i....
Question 128: Which integrity model defines a constrained data item, an in...
Question 129: What is the term commonly used to refer to a technique of au...
Question 130: Why MUST a Kerberos server be well protected from unauthoriz...
Question 131: When in the Software Development Life Cycle (SDLC) MUST soft...
Question 132: Which risk management methodology uses the exposure factor m...
Question 133: The definition A mark used in the sale or advertising of ser...
Question 134: Which of the following security models does NOT concern itse...
Question 135: A system administration office desires to implement the foll...
Question 136: Which one of the following is NOT a check for Input or Infor...
Question 137: Which of the following is a characteristic of a decision sup...
Question 138: Which Web Services Security (WS-Security) specification main...
Question 139: Refer to the information below to answer the question. An or...
Question 140: What is the primary goal of setting up a honey pot?...
Question 141: A computer system that employs the necessary hardware and so...
Question 142: Which of the following would BEST describe the role directly...
Question 143: The confidentiality of alcohol and drug abuse patient record...
Question 144: What BEST describes the National Security Agency-developed C...
Question 145: Which of the following is needed for System Accountability?...
Question 146: Several analysis methods can be employed by an IDS, each wit...
Question 147: The core component of Role Based Access Control (RBAC) must ...
Question 148: Which of the following is defined as a key establishment pro...
Question 149: Refer to the information below to answer the question. An or...
Question 150: Which of the following command line tools can be used in the...
Question 151: Who can best decide what are the adequate technical security...
Question 152: Crime Prevention Through Environmental Design (CPTED) is a d...
Question 153: Which of the following method is recommended by security pro...
Question 154: A group of organizations follows the same access standards a...
Question 155: An application team is running tests to ensure that user ent...
Question 156: A group of independent servers, which are managed as a singl...
Question 157: Which of the following is NOT considered a natural disaster?...
Question 158: What can be defined as a digital certificate that binds a se...
Question 159: Which of the following is NOT an encryption algorithm?...
Question 160: Degaussing is used to clear data from all of the following m...
Question 161: Which statement below is accurate about the concept of Objec...
Question 162: DRAG DROP Place in order, from BEST (1) to WORST (4), the fo...
Question 163: The Reference Validation Mechanism that ensures the authoriz...
Question 164: Which of the following is a reason to institute output contr...
Question 165: In which of the following programs is it MOST important to i...
Question 166: Of the various types of "Hackers" that exist, the ones who a...
Question 167: Which one of the following should be employed to protect dat...
Question 168: Which type of password token involves time synchronization?...
Question 169: An acceptable biometric throughput rate is:...
Question 170: The British Standard 7799/ISO Standard 17799 discusses crypt...
Question 171: Password management falls into which control category?...
Question 172: Which of the following ensures that security is not breached...
Question 173: Which of the following would present the higher annualized l...
Question 174: Secure Electronic Transaction (SET) and Secure HTTP (S-HTTP)...
Question 175: Match the objectives to the assessment questions in the gove...
Question 176: Which of the following type of lock uses a numeric keypad or...
Question 177: Which security model uses an access control triple and also ...
Question 178: Regarding risk reduction, which of the following answers is ...
Question 179: Which of the following is not a responsibility of a database...
1 commentQuestion 180: Which of the following MUST a security policy include to be ...
Question 181: Degaussing is used to clear data from all of the following m...
Question 182: What layer of the OSI/ISO model does Point-to-point tunnelli...
Question 183: Which access model is most appropriate for companies with a ...
Question 184: What part of an access control matrix shows capabilities tha...
Question 185: Which of the following would BEST describe the role directly...
Question 186: Which of the following MUST be scalable to address security ...
Question 187: What is the PRIMARY reason that reciprocal agreements betwee...
Question 188: Why are computer generated documents not considered reliable...
Question 189: When implementing a data classification program, why is it i...
Question 190: Which IPSec operational mode encrypts the entire data packet...
Question 191: Which of the following would best describe a cold backup sit...
Question 192: Notifying the appropriate parties to take action in order to...
Question 193: When writing security assessment procedures, what is the MAI...
Question 194: Which is NOT a packet-switched technology?...
Question 195: RAID Level 1 is commonly called which of the following?...
Question 196: Which of the following service is not provided by a public k...
Question 197: The type of discretionary access control that is based on an...
Question 198: A business has implemented Payment Card Industry Data Securi...
Question 199: A new Chief Information Officer (CIO) created a group to wri...
Question 200: A user has infected a computer with malware by connecting a ...
Question 201: Which BEST describes a tool (i.e. keyfob, calculator, memory...
Question 202: Which of the following should be emphasized during the Busin...
Question 203: The quality of finger prints is crucial to maintain the nece...
Question 204: You are using an open source packet analyzer called Wireshar...
Question 205: Which of the following is not a defined maturity level withi...
Question 206: What is the most secure way to dispose of information on a C...
Question 207: Who can best decide what are the adequate technical security...
Question 208: Which of the following is a strategy of grouping requirement...
Question 209: Which of the following is not a property of the Rijndael blo...
Question 210: Controls like guards and general steps to maintain building ...
Question 211: Single Sign-on (SSO) is characterized by which of the follow...
Question 212: A proxy firewall operates at what layer of the Open System I...
Question 213: Which of the following is not a two-factor authentication me...
Question 214: An electrical device (AC or DC) which can generate coercive ...
Question 215: The information security staff's participation in which of t...
Question 216: How should a risk be HANDLED when the cost of the countermea...
Question 217: What attribute is included in a X.509-certificate?...
Question 218: Which of the following encryption algorithms does not deal w...
Question 219: The Object Request Architecture (ORA) is a high-level framew...
Question 220: Which of the following represents the GREATEST risk to data ...
Question 221: Sandra is studying for her CISSP exam. Sandra has come to yo...
Question 222: Which of the following RAID levels is not used in practice a...
Question 223: Which of the following MUST a security policy include to be ...
Question 224: When preparing a business continuity plan, who of the follow...
Question 225: Which is NOT a packet-switched technology?...
Question 226: Qualitative loss resulting from the business interruption do...
Question 227: Which of the following is an ip address that is private (i.e...
Question 228: Kerberos depends upon what encryption method?...
Question 229: Which of the following classes is defined in the TCSEC (Oran...
Question 230: What is the MAIN reason for testing a Disaster Recovery Plan...
Question 231: What is an advantage of Elliptic Curve Cryptography (ECC)?...
Question 232: Which of the following actions should be taken by a security...
Question 233: During the risk assessment phase of the project the CISO dis...
Question 234: Business Associates
Question 235: Which utility below can create a server-spoofing attack?...
Question 236: Which choice below BEST describes the difference between the...
Question 237: Which of the following would assist in intrusion detection?...
Question 238: Which one of the following considerations has the LEAST impa...
Question 239: One important tool of computer forensics is the disk image b...
Question 240: Which of the following statements regarding an off-site info...
Question 241: Which property ensures that only the intended recipient can ...
Question 242: Enigma was:
Question 243: Which of the following is considered the PRIMARY security is...
Question 244: Because ordinary cable introduces a toxic hazard in the even...
Question 245: Which of the following is the best reason for the use of an ...
Question 246: Which of the following statements pertaining to air conditio...
Question 247: An internal Service Level Agreement (SLA) covering security ...
Question 248: Which of the following is needed to securely distribute symm...
Question 249: When we encrypt or decrypt data there is a basic operation i...
Question 250: Which of the following RAID levels is not used in practice a...
Question 251: Which statement below is accurate about Evaluation Assurance...
Question 252: Which of the following is a communication mechanism that ena...
Question 253: What can be defined as an abstract machine that mediates all...
Question 254: What principle requires corporate officers to institute appr...
Question 255: Similarity between all recovery plans is:...
Question 256: Which of the following is NOT true of the Kerberos protocol?...
Question 257: Which of the following service is not provided by a public k...
Question 258: What security procedure forces an operator into collusion wi...
Question 259: Of the various types of "Hackers" that exist, the ones who a...
Question 260: What is the correct order of steps in an information securit...
Question 261: Which of the following is not a compensating measure for acc...
Question 262: What would you call a microchip installed on the motherboard...
Question 263: Which of the following are WELL KNOWN PORTS assigned by the ...
Question 264: In a wireless General Packet Radio Services (GPRS) Virtual P...
Question 265: Which of the following IEEE standards defines the token ring...
Question 266: Refer to the information below to answer the question. An or...
Question 267: When comparing host based IDS with network based ID, which o...
Question 268: What is called an attack in which an attacker floods a syste...
Question 269: Smart cards are an example of which type of control?...
Question 270: Which integrity model defines a constrained data item, an in...
Question 271: The RSA Algorithm uses which mathematical concept as the bas...
Question 272: From an asset security perspective, what is the BEST counter...
Question 273: Which of the following violates identity and access manageme...
Question 274: If any server in the cluster crashes, processing continues t...
Question 275: You are using an open source packet analyzer called Wireshar...
Question 276: A business impact assessment is one element in business cont...
Question 277: What is the main concern with single sign-on?...
Question 278: An input validation and exception handling vulnerability has...
Question 279: In which of the following security models is the subject's c...
Question 280: Which choice below most accurately describes a business impa...
Question 281: Which of the following phases of a system development life-c...
Question 282: Which of the following embodies all the detailed actions tha...
Question 283: The International Standards Organization / Open Systems Inte...
Question 284: A portion of a VigenEre cipher square is given below using f...
Question 285: Which of the following is the most costly countermeasure to ...
Question 286: Which of the following provides the MOST secure method for N...
Question 287: Which of the following testing method examines the functiona...
Question 288: Once an intrusion into your organizations information system...
Question 289: Which of the following statements pertaining to firewalls is...
Question 290: What is the main purpose of Corporate Security Policy?...
Question 291: Another type of artificial intelligence technology involves ...
Question 292: What is the maximum allowable key size of the Rijndael encry...
Question 293: What is a Covered Entity? The term "Covered Entity" is defin...
Question 294: Which of the following does not apply to system-generated pa...
Question 295: Which of the following biometrics methods provides the HIGHE...
Question 296: Who would be the BEST person to approve an organizations inf...
Question 297: A Denial of Service (DoS) attack on a syslog server exploits...
Question 298: The European Union (EU) has enacted a Conditional Access Dir...
Question 299: Which type of attack involves the altering of a systems Addr...
Question 300: Frame relay and X.25 networks are part of which of the follo...
Question 301: What is one way to mitigate the risk of security flaws in cu...
Question 302: Which of the following is not an EPA-approved replacement fo...
Question 303: Once evidence is seized, a law enforcement officer should em...
Question 304: The property of a system or a system resource being accessib...
Question 305: Which of the following statements pertaining to software tes...
Question 306: What should be the INITIAL response to Intrusion Detection S...
Question 307: Which of the following media sanitization techniques is MOST...
Question 308: What Service Organization Controls (SOC) report can be freel...
Question 309: Secure Sockets Layer (SSL) encryption protects...
Question 310: During a business impact analysis it is concluded that a sys...
Question 311: Which of the following can best be defined as a key distribu...
Question 312: Which Hyper Text Markup Language 5 (HTML5) option presents a...
Question 313: Which of the following will you consider as most secure?...
Question 314: Which of the following European Union (EU) principles pertai...
Question 315: Which of the following is not a part of risk analysis?...
Question 316: Although code using a specific program language may not be s...
Question 317: Which of the following is the MOST effective preventative me...
Question 318: Which of the following statements pertaining to IPSec is inc...
Question 319: Which of the following is the MOST difficult to enforce when...
Question 320: What is a method in an object-oriented system?...
Question 321: Which Security and Audit Framework has been adopted by some ...
Question 322: What security model is dependant on security labels?...
Question 323: Which choices below are commonly accepted definitions for a ...
Question 324: Which of the following is best defined as an administrative ...
Question 325: A business has implemented Payment Card Industry Data Securi...
Question 326: A cryptographic algorithm is also known as:...
Question 327: Which of the following statements pertaining to using Kerber...
Question 328: Extensible Authentication Protocol-Message Digest 5 (EAP-MD5...
Question 329: Which layer defines how packets are routed between end syste...
Question 330: What is NOT true of a star-wired topology?...
Question 331: Which of the following keys has the SHORTEST lifespan?...
Question 332: What assesses potential loss that could be caused by a disas...
Question 333: How many rounds are used by DES?...
Question 334: The computations involved in selecting keys and in encipheri...
Question 335: Which statement is NOT true about the SOCKS protocol?...
Question 336: A security engineer is designing a Customer Relationship Man...
Question 337: What is the company benefit, in terms of risk, for people ta...
Question 338: Multi-threaded applications are more at risk than single-thr...
Question 339: Which of the following statements pertaining to firewalls is...
Question 340: Which of the following protocols operates at the session lay...
Question 341: Which of the following items is NOT primarily used to ensure...
Question 342: Which of the following is NOT a disadvantage of Single Sign ...
Question 343: Which of the following is the PRIMARY risk with using open s...
Question 344: Which of the following focuses on the basic features and arc...
Question 345: Which of the following is the proper lifecycle of evidence?...
Question 346: Which of the following packets should NOT be dropped at a fi...
Question 347: Which of the following is not an example of an operational c...
Question 348: Recovery Site Strategies for the technology environment depe...
Question 349: Users require access rights that allow them to view the aver...
Question 350: Which of the following is often implemented by a one-for-one...
Question 351: ____________ is the means by which the ability to do somethi...
Question 352: Memory management in TCSEC levels B3 and A1 operating system...
Question 353: Why are mobile devices something difficult to investigate in...
Question 354: What is necessary for a subject to have write access to an o...
Question 355: What is electronic vaulting?
Question 356: What capability would typically be included in a commerciall...
Question 357: A database administrator is asked by a high-ranking member o...
Question 358: Which IEEE standard defines wireless networking in the 5GHz ...
Question 359: How do the Information Labels of Compartmented Mode Workstat...
Question 360: When two different keys encrypt a plaintext message into the...
Question 361: To what does logon abuse refer?...
Question 362: Which International Organization for Standardization standar...
Question 363: Hierarchical Storage Management (HSM) is commonly employed i...
Question 364: The IP address, 178.22.90.1, is considered to be in which cl...
Question 365: Which type of attack involves hijacking a session between a ...
Question 366: Which of the following methodologies is appropriate for plan...
Question 367: Which of the following risk handling technique involves the ...
Question 368: Which technique can be used to make an encryption scheme mor...
Question 369: Immune to the effects of electromagnetic interference (EMI) ...
Question 370: What determines the level of security of a combination lock?...
Question 371: Which choice below represents an application or system demon...
Question 372: Which ISO/OSI layer establishes the communications link betw...
Question 373: What is the simple security property of which one of the fol...
Question 374: Frame relay and X.25 networks are part of which of the follo...
Question 375: At a MINIMUM, a formal review of any Disaster Recovery Plan ...
Question 376: Which one of the following can NOT typically be accomplished...
Question 377: Activity to baseline, tailor, and scope security controls ti...
Question 378: Sensor is:
Question 379: Data remanence refers to which of the following?...
Question 380: Which one of the following network attacks takes advantages ...
Question 381: How can an individual/person BEST be identified or authentic...
Question 382: How often should an independent review of the security contr...
Question 383: Which of the following BEST describes Recovery Time Objectiv...
Question 384: A Differential backup process will:...
Question 385: Order the below steps to create an effective vulnerability m...
Question 386: Which of the following is not a detective technical control?...
Question 387: Which of the following is a NOT a guideline necessary to enh...
Question 388: Which choice below is the BEST description of the criticalit...
Question 389: Which of the following is used to monitor network traffic or...
Question 390: To be admissible in court, computer evidence must be which o...
Question 391: A large corporation is locking for a solution to automate ac...
Question 392: Which Orange book security rating introduces security labels...
Question 393: Which of the following methods MOST efficiently manages user...
Question 394: RAID levels 3 and 5 run:
Question 395: In the Open System Interconnection (OSI) model, which layer ...
Question 396: In the context of legal proceedings and trial practice, disc...
Question 397: From a security perspective, which of the following is a bes...
Question 398: Which of the following would be used to implement Mandatory ...
Question 399: Which of the following statements pertaining to software tes...
Question 400: Drag and Drop Question Given a file containing ordered numbe...
Question 401: Which type of fire extinguishing method contains standing wa...
Question 402: Which of the following terms can be described as the process...
Question 403: Which of the following is an operating system security archi...
Question 404: If an operating system permits shared resources such as memo...
Question 405: Which of the following is often the greatest challenge of di...
Question 406: Which choice below is NOT a generally accepted benefit of se...
Question 407: For a given hash function H, to prevent substitution of a me...
Question 408: Match the functional roles in an external audit to their res...
Question 409: Java is not:
Question 410: In an object-oriented system, the situation wherein objects ...
Question 411: Which of the following is considered the last line defense i...
Question 412: Why are coaxial cables called "coaxial"?...
Question 413: Business Continuity and Disaster Recovery Planning (Primaril...
Question 414: Which of the following is a reasonable response from the int...
Question 415: Which choice below is NOT considered an information classifi...
Question 416: RAID Software can run faster in the operating system because...
Question 417: An application team is running tests to ensure that user ent...
Question 418: Which of the following is NOT a component of IPSec?...
Question 419: Which of the following is not one of the three goals of Inte...
Question 420: The implementation of which features of an identity manageme...
Question 421: Which entity of the US legal system makes common laws?...
Question 422: Which type of control below is NOT an example of a physical ...
Question 423: What is the maximum key size for the RC5 algorithm?...
Question 424: Which of the following type of traffic can easily be filtere...
Question 425: When a biometric system is used, which error type deals with...
Question 426: What is a common mistake in records retention?...
Question 427: The standard server port number for HTTP is which of the fol...
Question 428: Context-dependent control uses which of the following to mak...
Question 429: In terms of the order of effectiveness, which of the followi...
Question 430: which of the following is a Hashing Algorithm?...
Question 431: In most security protocols that support authentication, inte...
Question 432: What is the PRIMARY role of a scrum master in agile developm...
Question 433: What is NOT an authentication method within IKE and IPsec?...
Question 434: The type of access control that is used in local, dynamic si...
Question 435: Match the name of access control model with its associated r...
Question 436: The standard server port number for HTTP is which of the fol...
Question 437: Which of the following countermeasures would be the most app...
Question 438: Which one of the following describes a reference monitor?...
Question 439: Frame relay uses a public switched network to provide:...
Question 440: Which of the following is the MOST important consideration w...
Question 441: This type of supporting evidence is used to help prove an id...
Question 442: Which of the following statements pertaining to air conditio...
Question 443: Which of the following is not appropriate in addressing obje...
Question 444: Which of the following encryption types is used in Hash Mess...
Question 445: A Differential backup process will:...
Question 446: By examining the "state" and "context" of the incoming data ...
Question 447: A new Chief Information Officer (CIO) created a group to wri...
Question 448: Which of the following computer design approaches is based o...
Question 449: Order the below steps to create an effective vulnerability m...
Question 450: Which of the following command line tools can be used in the...
Question 451: In the Information Flow Model, what relates two versions of ...
Question 452: What is called the probability that a threat to an informati...
Question 453: Which choice below is the BEST description of operational as...
Question 454: During an IS audit, auditor has observed that authentication...
Question 455: Which one of the following is an advantage of an effective r...
Question 456: Which of the following proves or disproves a specific act th...
Question 457: In which of the following cloud computing service model are ...
Question 458: Which of the following is a key principle in the evolution o...
Question 459: Which of the following protocols is designed to send individ...
Question 460: Who should NOT have access to the log files?...
Question 461: Which of the following is the PRIMARY benefit of a formalize...
Question 462: In a SSL session between a client and a server, who is respo...
Question 463: Which of the following is NOT a characteristic of a host-bas...
Question 464: Which of the following provides the minimum set of privilege...
Question 465: Which of the following concerning the Rijndael block cipher ...
Question 466: Which of the following is covered under Crime Insurance Poli...
Question 467: Which of the following MUST be part of a contract to support...
Question 468: Within the company, desktop clients receive Internet Protoco...
Question 469: When it comes to magnetic media sanitization, what differenc...
Question 470: Which of the following is the act of performing tests and ev...
Question 471: The two categories of the policy of separation of duty are:...
Question 472: Which of the following statements is TRUE regarding equivale...
Question 473: In biometrics, a good measure of performance of a system is ...
Question 474: Which of the following answer BEST relates to the type of ri...
Question 475: A software security engineer is developing a black box-based...
Question 476: In biometric identification systems, the parts of the body c...
Question 477: Which of the following statements pertaining to dealing with...
Question 478: What should happen when an emergency change to a system must...
Question 479: Which of the following is an example of two-factor authentic...
Question 480: Which of the following BEST mitigates a replay attack agains...
Question 481: Which step of the Risk Management Framework (RMF) identifies...
Question 482: At which layer of ISO/OSI does the fiber optics work?...
Question 483: Which of the following are suitable protocols for securing V...
Question 484: Which of the following is the key requirement for test resul...
Question 485: What is the MOST critical factor to achieve the goals of a s...
Question 486: Like the Kerberos protocol, SESAME is also subject to which ...
Question 487: What is the motivation for use of the Online Certificate Sta...
Question 488: Which of the following is an effective control in preventing...
Question 489: Why is lexical obfuscation in software development discourag...
Question 490: Which protocol is used to send email?...
Question 491: The FIRST step in building a firewall is to...
Question 492: A common Limitation of information classification systems is...
Question 493: A brownout can be defined as a:...
Question 494: Of the reasons why a Disaster Recovery plan gets outdated, w...
Question 495: As per the Orange Book, what are two types of system assuran...
Question 496: The use of private and public encryption keys is fundamental...
Question 497: Which of the following is the FIRST step during digital iden...
Question 498: Which of the following methods of providing telecommunicatio...
Question 499: What is the best way for mutual authentication of devices be...
Question 500: Which of the following is the final phase of the identity an...
Question 501: Which of the following refers to a US Government program tha...
Question 502: Which of the following is NOT considered an element of a bac...
Question 503: Which ISO/OSI layer establishes the communications link betw...
Question 504: Which OSI/ISO layer defines how to address the physical devi...
Question 505: Which one of the following authentication mechanisms creates...
Question 506: Qualitative loss resulting from the business interruption do...
Question 507: What is the name for a substitution cipher that shifts the a...
Question 508: Which of the following provides enterprise management with a...
Question 509: You've decided to authenticate the source who initiated a pa...
Question 510: Which of the following is the MOST effective practice in man...
Question 511: What is the RESULT of a hash algorithm being applied to a me...
Question 512: Which of the following statements pertaining to quantitative...
Question 513: Given a file containing ordered number, i.e. "123456789," ma...
Question 514: Attributes that characterize an attack are stored for refere...
Question 515: In order to avoid mishandling of media or information, you s...
Question 516: How should a doorway of a manned facility with automatic loc...
Question 517: Which access control model was proposed for enforcing access...
Question 518: Communications and network security relates to transmission ...
Question 519: Which of the following is an initial consideration when deve...
Question 520: Which UTP cable category is rated for 16 Mbps?...
Question 521: Researchers have recently developed a tool that imitates a 1...
Question 522: When designing a vulnerability test, which one of the follow...
Question 523: Business Impact Analysis (BIA) is about...
Question 524: Which RAID level concept is considered more expensive and is...
Question 525: Which of the following is used to create parity information?...
Question 526: Which of the following is a disadvantage of a memory only ca...
Question 527: Which of the following is the MOST important element of chan...
Question 528: In which of the following security models is the subject's c...
Question 529: A business continuity plan is an example of which of the fol...
Question 530: What mechanism does a system use to compare the security lab...
Question 531: What would be the MOST cost effective solution for a Disaste...
Question 532: Which of the following are the advantages of using passphras...
Question 533: The US department of Health, Education and Welfare developed...
Question 534: Which of the following is less likely to be included in the ...
Question 535: What is the MOST critical piece to disaster recovery and con...
Question 536: What is the MOST important step during forensic analysis whe...
Question 537: When designing a networked Information System (IS) where the...
Question 538: Application Layer Firewalls operate at the:...
Question 539: Who should direct short-term recovery actions immediately fo...
Question 540: You are comparing host based IDS with network based ID. Whic...
Question 541: What is used to hide data from unauthorized users by allowin...
Question 542: What should an auditor do when conducting a periodic audit o...
Question 543: When building a data center, site location and construction ...
Question 544: Which of the following embodies all the detailed actions tha...
Question 545: Security categorization of a new system takes place during w...
Question 546: In terms or Risk Analysis and dealing with risk, which of th...
Question 547: What size is an MD5 message digest (hash)?...
Question 548: In general, servers that are facing the Internet should be p...
Question 549: A back door into a network refers to what?...
Question 550: A new worm has been released on the Internet. After investig...
Question 551: Directive controls are a form of change management policy an...
Question 552: Java is not:
Question 553: Which of the following is the BEST method to assess the effe...
Question 554: Identity Management solutions include such technologies as D...
Question 555: What does the * (star) integrity axiom mean in the Biba mode...
Question 556: The main approach to obtaining the true biometric informatio...
Question 557: Which of the following are Systems Engineering Life Cycle (S...
Question 558: Which of the following can be defined as THE unique attribut...
Question 559: A security professional should ensure that clients support w...
Question 560: Which of the following provides effective management assuran...
Question 561: Which of the following is the key requirement for test resul...
Question 562: Operations Security seeks to primarily protect against which...
Question 563: How is authentication implemented in GSM?...
Question 564: Which of the following is the MOST important action regardin...
Question 565: Which of the following is true about digital certificate?...
Question 566: Which of the following is NOT a security characteristic we n...
Question 567: The BEST method to mitigate the risk of a dictionary attack ...
Question 568: Which of the following are the three classifications of RAID...
Question 569: Which of the following is NOT a specific loss criteria that ...
Question 570: What is the BEST answer pertaining to the difference between...
Question 571: Which one of the following can be identified when exceptions...
Question 572: A client has reviewed a vulnerability assessment report and ...
Question 573: What are the three conditions that must be met by the refere...
Question 574: Attack trees are MOST useful for which of the following?...
Question 575: Which of the following is NOT a symmetric key algorithm?...
Question 576: Which of the following rules is less likely to support the c...
Question 577: Which of the following is the most complete disaster recover...
Question 578: What does the simple integrity axiom mean in the Biba model?...
Question 579: Change management policies and procedures belong to which of...
Question 580: The typical computer fraudsters are usually persons with whi...
Question 581: Under the Business Exemption Rule to the hearsay evidence, w...
Question 582: At which of the OSI/ISO model layer is IP implemented?...
Question 583: Why do buffer overflows happen? What is the main cause?...
Question 584: What would be the MOST cost effective solution for a Disaste...
Question 585: Which IEEE standard defines wireless networking in the 5GHz ...
Question 586: Which type of attack is based on the probability of two diff...
Question 587: Which of the following is not a method to protect objects an...
Question 588: Which choice below BEST describes the type of control that a...
Question 589: The steps of an access control model should follow which log...
Question 590: Which of the following was developed to address some of the ...
Question 591: In the access control matrix, the rows are:...
Question 592: The Clark-Wilson Integrity Model (d. Clark, d. Wilson, A Com...
Question 593: Which of the following secures web transactions at the Trans...
Question 594: Which choice below is an accurate statement about standards?...
Question 595: The design review for an application has been completed and ...
Question 596: An organization adopts a new firewall hardening standard. Ho...
Question 597: Which of the following methods protects Personally Identifia...
Question 598: Contracts and agreements are often times unenforceable or ha...
Question 599: Which of the following assertions is NOT true about pattern ...
Question 600: An engineer in a software company has created a virus creati...
Question 601: Which of the following phases of a system development life-c...
Question 602: Of the three types of alternate sites: hot, warm or cold, wh...
Question 603: Which is a property of a circuit-switched network as opposed...
Question 604: What can be defined as an instance of two different keys gen...
Question 605: Are there penalties under HIPAA?...
Question 606: What is the name of the protocol use to set up and manage Se...
Question 607: Which of the following is a process within a Systems Enginee...
Question 608: A business has implemented Payment Card Industry Data Securi...
Question 609: Which of the following items is NOT a component of a knowled...
Question 610: Which type of fire extinguisher is most appropriate for a di...
Question 611: Data which is properly secured and can be described with ter...
Question 612: Which of the following statements pertaining to the (ISC)2 C...
Question 613: Which of the following is NOT an attack against operations?...
Question 614: Which term below BEST describes the concept of least privile...
Question 615: Which of the following categories of hackers poses the great...
Question 616: A smart card represents:
Question 617: Which of the following is an example of an asymmetric key al...
Question 618: Which one of the following, if embedded within the ciphertex...
Question 619: What is the role of IKE within the IPsec protocol:...
Question 620: What is the MOST important consideration from a data securit...
Question 621: Health Care Providers, however,...
Question 622: Acryptographic attack in which portions of the ciphertext ar...
Question 623: Which of the following encryption algorithms does NOT deal w...
Question 624: Which of the following wraps the decryption key of a full di...
Question 625: What is the Biba security model concerned with?...
Question 626: Which of the following is the MOST important aspect relating...
Question 627: The Orange Book requires auditing mechanisms for any systems...
Question 628: What is the best way for mutual authentication of devices be...
Question 629: Which of the following attack could be avoided by creating m...
Question 630: What can be defined as an abstract machine that mediates all...
Question 631: Frame-relay uses a public switched network to provide:...
Question 632: Which of the following are additional terms used to describe...
Question 633: Which of the following is the simplest type of firewall?...
Question 634: Which of the following is currently the most recommended wat...
Question 635: When planning for disaster recovery it is important to know ...
Question 636: A public key algorithm that does both encryption and digital...
Question 637: What IDS approach relies on a database of known attacks?...
Question 638: You have been approached by one of your clients . They are i...
Question 639: Which choice below would NOT be considered a benefit of empl...
Question 640: Configuration Management controls what?...
Question 641: Which of the following statements pertaining to VPN protocol...
Question 642: Which security access policy contains fixed security attribu...
Question 643: What can be defined as a digital certificate that binds a se...
Question 644: Which of the following was not designed to be a proprietary ...
Question 645: Which of the following is typically NOT a consideration in t...
Question 646: Which choice below is a role of the Information Systems Secu...
Question 647: Which one the following is NOT one of the three major parts ...
Question 648: What is Dumpster Diving?
Question 649: What is the PRIMARY purpose of auditing, as it relates to th...
Question 650: Who is responsible for setting user clearances to computer-b...
Question 651: Which of the following statements pertaining to the Trusted ...
Question 652: Data which is properly secured and can be described with ter...
Question 653: The fact that a network-based IDS reviews packets payload an...
Question 654: Keeping in mind that these are objectives that are provided ...
Question 655: When logging on to a workstation, the log-on process should:...
Question 656: Which one of the following affects the classification of dat...
Question 657: Which of the following is NOT a symmetric key algorithm?...
Question 658: For an organization considering two-factor authentication fo...
Question 659: What is called an attack in which an attacker floods a syste...
Question 660: When developing a business case for updating a security prog...
Question 661: A minimal implementation of endpoint security includes which...
Question 662: Which standard below does NOT specify fiber optic cabling as...
Question 663: Which of the following statements is incorrect?...
Question 664: Which of the following encryption types is used in Hash Mess...
Question 665: Which of the following security controls might force an oper...
Question 666: Which of the following can best be defined as a key distribu...
Question 667: The Kennedy-Kassebaum Act is also known as:...
Question 668: The RSA Algorithm uses which mathematical concept as the bas...
Question 669: Identify the component that MOST likely lacks digital accoun...
Question 670: What is the key size of the International Data Encryption Al...
Question 671: Which of the following is a MAJOR consideration in implement...
Question 672: Who is responsible for providing reports to the senior manag...
Question 673: The recording of events with a closed-circuit TV camera is c...
Question 674: What uses a key of the same length as the message where each...
Question 675: What are cognitive passwords?
Question 676: Which of the following should NOT normally be allowed throug...
Question 677: Which of the following is used to create and delete views an...
Question 678: This type of backup management provides a continuous on-line...
Question 679: A disadvantage of an application filtering firewall is that ...
Question 680: To ensure dependable and secure logging, all computers must ...
Question 681: Which of the following is NOT true about IPSec Tunnel mode?...
Question 682: Which of the following statements pertaining to Kerberos is ...
Question 683: Due to system constraints, a group of system administrators ...
Question 684: Which of the following is a symmetric encryption algorithm?...
Question 685: Drag and Drop Question Match the level of evaluation to the ...
Question 686: If an internal database holds a number of printers in every ...
Question 687: In Identity Management (IdM), when is the verification stage...
Question 688: copyright provides protection for which of the following?...
Question 689: In fault-tolerant systems, what do rollback capabilities per...
Question 690: What ensures that the control mechanisms correctly implement...
Question 691: By carefully aligning the pins in the lock, which of the fol...
Question 692: In an organization, an Information Technology security funct...
Question 693: Which of the following provide network redundancy in a local...
Question 694: Which of the following statements relating to the Bell-LaPad...
Question 695: A group of processes that share access to the same resources...
Question 696: In which situation would TEMPEST risks and technologies be o...
Question 697: Which choice below is NOT an accurate statement about the vi...
Question 698: Which of the following term BEST describes a weakness that c...
Question 699: Which of the following is NOT a known type of Message Authen...