<< Prev Question Next Question >>

Question 70/320

In which type of access control do user ID and password system come under?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (320q)
Question 1: Which of the following is a name, symbol, or slogan with whi...
Question 2: Which of the following recovery plans includes specific stra...
Question 3: The LeGrand Vulnerability-Oriented Risk Management method is...
Question 4: DRAG DROP Drop the appropriate value to complete the formula...
Question 5: Which of the following security design principles supports c...
Question 6: John works as a professional Ethical Hacker. He has been ass...
Question 7: Which of the following are the benefits of information class...
Question 8: You work as a Security Manager for Tech Perfect Inc. You hav...
Question 9: Which of the following phases of NIST SP 800-37 C&amp;A meth...
Question 10: A part of a project deals with the hardware work. As a proje...
Question 11: The Chief Information Officer (CIO), or Information Technolo...
Question 12: Which of the following refers to the ability to ensure that ...
Question 13: You work as a project manager for BlueWell Inc. You are work...
Question 14: SIMULATION Fill in the blank with an appropriate phrase. is ...
Question 15: A number of security patterns for Web applications under the...
Question 16: Which of the following attacks causes software to fail and p...
Question 17: Which of the following phases of DITSCAP includes the activi...
Question 18: Which of the following statements reflect the 'Code of Ethic...
Question 19: Certification and Accreditation (C&amp;A or CnA) is a proces...
Question 20: Which of the following processes identifies the threats that...
Question 21: You work as a CSO (Chief Security Officer) for Tech Perfect ...
Question 22: Martha works as a Project Leader for BlueWell Inc. She and h...
Question 23: Numerous information security standards promote good securit...
Question 24: Part of your change management plan details what should happ...
Question 25: You work as a systems engineer for BlueWell Inc. Which of th...
Question 26: A service provider guarantees for end-to-end network traffic...
Question 27: Which of the following plans is documented and organized for...
Question 28: Maria has been recently appointed as a Network Administrator...
Question 29: Which of the following specifies the behaviors of the DRM im...
Question 30: Which of the following can be used to accomplish authenticat...
Question 31: You work as the senior project manager in SoftTech Inc. You ...
Question 32: In which of the following SDLC phases is the system's securi...
Question 33: The IAM/CA makes certification accreditation recommendations...
Question 34: You work as a project manager for a company. The company has...
Question 35: An assistant from the HR Department calls you to ask the Ser...
Question 36: DRAG DROP A number of security design patterns are developed...
Question 37: The DARPA paper defines various procedural patterns to perfo...
Question 38: The Project Risk Management knowledge area focuses on which ...
Question 39: Numerous information security standards promote good securit...
Question 40: Which of the following DITSCAP C&amp;A phases takes place be...
Question 41: Which of the following activities are performed by the 'Do' ...
Question 42: Which of the following terms ensures that no intentional or ...
Question 43: Audit trail or audit log is a chronological sequence of audi...
Question 44: Which of the following process areas does the SSE-CMM define...
Question 45: Which of the following are the primary functions of configur...
Question 46: Who amongst the following makes the final accreditation deci...
Question 47: Which of the following access control models uses a predefin...
Question 48: Which of the following governance bodies directs and coordin...
Question 49: What are the various activities performed in the planning ph...
Question 50: Which of the following steps of the LeGrand Vulnerability-Or...
Question 51: In which of the following levels of exception safety are ope...
Question 52: Which of the following statements are true about declarative...
Question 53: Which of the following is a standard that sets basic require...
Question 54: Which of the following actions does the Data Loss Prevention...
Question 55: Which of the following provides an easy way to programmers f...
Question 56: Which of the following coding practices are helpful in simpl...
Question 57: SIMULATION Fill in the blank with the appropriate security m...
Question 58: Which of the following is the process of finding weaknesses ...
Question 59: The National Information Assurance Certification and Accredi...
Question 60: Which of the following US Acts emphasized a "risk-based poli...
Question 61: What are the subordinate tasks of the Implement and Validate...
Question 62: Joseph works as a Software Developer for WebTech Inc. He wan...
Question 63: Which of the following are the tasks performed by the owner ...
Question 64: Which of the following plans is designed to protect critical...
Question 65: SIMULATION Fill in the blank with an appropriate phrase. mod...
Question 66: Which of the following security models characterizes the rig...
Question 67: Which of the following concepts represent the three fundamen...
Question 68: You are responsible for network and information security at ...
Question 69: Which of the following terms refers to the protection of dat...
Question 70: In which type of access control do user ID and password syst...
Question 71: In which of the following cryptographic attacking techniques...
Question 72: Which of the following techniques is used when a system perf...
Question 73: You work as a security manager for BlueWell Inc. You are per...
Question 74: Which of the following are the types of intellectual propert...
Question 75: An organization monitors the hard disks of its employees' co...
Question 76: In which of the following processes are experienced personne...
Question 77: You work as a Security Manager for Tech Perfect Inc. You wan...
Question 78: The Systems Development Life Cycle (SDLC) is the process of ...
Question 79: Which of the following models manages the software developme...
Question 80: Which of the following elements sets up a requirement to rec...
Question 81: Which of the following access control models are used in the...
Question 82: Which of the following NIST Special Publication documents pr...
Question 83: You work as a security manager for BlueWell Inc. You are goi...
Question 84: Which of the following statements about the authentication c...
Question 85: Which of the following is a variant with regard to Configura...
Question 86: According to U.S. Department of Defense (DoD) Instruction 85...
Question 87: You are advising a school district on disaster recovery plan...
Question 88: Which of the following refers to a process that is used for ...
Question 89: Which of the following security models focuses on data confi...
Question 90: Security is a state of well-being of information and infrast...
Question 91: SIMULATION Fill in the blank with an appropriate phrase. A i...
Question 92: Which of the following security related areas are used to pr...
Question 93: Which of the following are the responsibilities of the owner...
Question 94: Which of the following types of redundancy prevents attacks ...
Question 95: Which of the following security controls will you use for th...
Question 96: You work as a Security Manager for Tech Perfect Inc. You fin...
Question 97: Which of the following characteristics are described by the ...
Question 98: Which of the following roles is also known as the accreditor...
Question 99: Which of the following requires all general support systems ...
Question 100: You work as a Security Manager for Tech Perfect Inc. In the ...
Question 101: The mission and business process level is the Tier 2. What a...
Question 102: DoD 8500.2 establishes IA controls for information systems a...
Question 103: Della work as a project manager for BlueWell Inc. A threat w...
Question 104: There are seven risks responses that a project manager can c...
Question 105: The Phase 3 of DITSCAP C&amp;A is known as Validation. The g...
Question 106: Microsoft software security expert Michael Howard defines so...
Question 107: Which of the following are the goals of risk management? Eac...
Question 108: Which of the following areas of information system, as separ...
Question 109: How can you calculate the Annualized Loss Expectancy (ALE) t...
Question 110: Which of the following types of activities can be audited fo...
1 commentQuestion 111: Which of the following cryptographic system services ensures...
Question 112: Which of the following phases of DITSCAP includes the activi...
Question 113: In which of the following deployment models of cloud is the ...
Question 114: In which of the following IDS evasion attacks does an attack...
Question 115: A Web-based credit card company had collected financial and ...
Question 116: Software Development Life Cycle (SDLC) is a logical process ...
Question 117: Which of the following DITSCAP phases validates that the pre...
Question 118: A security policy is an overall general statement produced b...
Question 119: Which of the following NIST documents provides a guideline f...
Question 120: Which of the following processes does the decomposition and ...
Question 121: Which of the following methods is a means of ensuring that s...
Question 122: Frank is the project manager of the NHH Project. He is worki...
Question 123: Which of the following NIST Special Publication documents pr...
Question 124: Which of the following types of attacks occurs when an attac...
Question 125: Which of the following statements best describes the differe...
Question 126: Which of the following approaches can be used to build a sec...
Question 127: Which of the following DoD directives defines DITSCAP as the...
Question 128: Copyright holders, content providers, and manufacturers use ...
Question 129: Which of the following agencies is responsible for funding t...
Question 130: A security policy is an overall general statement produced b...
Question 131: Which of the following types of obfuscation transformation i...
Question 132: FIPS 199 defines the three levels of potential impact on org...
Question 133: Which of the following federal agencies has the objective to...
Question 134: Which of the following persons in an organization is respons...
Question 135: SIMULATION Fill in the blank with an appropriate security ty...
Question 136: You work as a Network Auditor for Net Perfect Inc. The compa...
Question 137: NIST SP 800-53A defines three types of interview depending o...
Question 138: An authentication method uses smart cards as well as usernam...
Question 139: John works as a professional Ethical Hacker. He has been ass...
Question 140: Which of the following processes culminates in an agreement ...
Question 141: Which of the following strategies is used to minimize the ef...
Question 142: FIPS 199 defines the three levels of potential impact on org...
Question 143: Adrian is the project manager of the NHP Project. In her pro...
Question 144: Which of the following provides an easy way to programmers f...
Question 145: Which of the following software review processes increases t...
Question 146: The Software Configuration Management (SCM) process defines ...
Question 147: Which of the following are the phases of the Certification a...
Question 148: Which of the following security issues does the Bell-La Padu...
Question 149: John works as a professional Ethical Hacker. He is assigned ...
Question 150: FITSAF stands for Federal Information Technology Security As...
Question 151: Mark is the project manager of the NHQ project in StarTech I...
Question 152: According to the NIST SAMATE, dynamic analysis tools operate...
Question 153: Which of the following are the levels of public or commercia...
Question 154: Which of the following tools is used to attack the Digital W...
Question 155: In which of the following phases of the SDLC does the softwa...
Question 156: Which of the following terms related to risk management repr...
Question 157: Which of the following is an example of penetration testing?...
Question 158: Which of the following security objectives are defined for i...
Question 159: You are the project manager of the CUL project in your organ...
Question 160: What are the various phases of the Software Assurance Acquis...
Question 161: Which of the following individuals inspects whether the secu...
Question 162: In which of the following phases of the DITSCAP process does...
Question 163: You work as an analyst for Tech Perfect Inc. You want to pre...
Question 164: Shoulder surfing is a type of in-person attack in which the ...
Question 165: DRAG DROP RCA (root cause analysis) is an iterative and reac...
Question 166: What NIACAP certification levels are recommended by the cert...
Question 167: An attacker exploits actual code of an application and uses ...
Question 168: Adam works as a Computer Hacking Forensic Investigator for a...
Question 169: Which of the following are the important areas addressed by ...
Question 170: DRAG DROP Drag and drop the appropriate principle documents ...
Question 171: Which of the following tiers addresses risks from an informa...
Question 172: Which of the following plans is a comprehensive statement of...
Question 173: Which of the following are the initial steps required to per...
Question 174: Which of the following scanning techniques helps to ensure t...
Question 175: The service-oriented modeling framework (SOMF) provides a co...
Question 176: Which of the following acts is used to recognize the importa...
Question 177: Which of the following models uses a directed graph to speci...
Question 178: You are the project manager of the NNN project for your comp...
Question 179: Which of the following is a formula, practice, process, desi...
Question 180: Which of the following security architectures defines how to...
Question 181: Which of the following features of SIEM products is used in ...
Question 182: Which of the following testing methods tests the system effi...
Question 183: Which of the following DoD policies establishes policies and...
Question 184: Elizabeth is a project manager for her organization and she ...
Question 185: You and your project team have identified the project risks ...
Question 186: Which of the following methods offers a number of modeling p...
Question 187: You are the project manager of the GHY project for your orga...
Question 188: Digital rights management (DRM) consists of compliance and r...
Question 189: Which of the following statements about the integrity concep...
Question 190: Which of the following are the common roles with regard to d...
Question 191: You work as a Security Manager for Tech Perfect Inc. The com...
Question 192: The service-oriented modeling framework (SOMF) introduces fi...
Question 193: Which of the following penetration testing techniques automa...
Question 194: DIACAP applies to the acquisition, operation, and sustainmen...
Question 195: DRAG DROP Drag and drop the various SSE-CMM levels at the ap...
Question 196: In which of the following testing methods is the test engine...
Question 197: In 2003, NIST developed a new Certification &amp; Accreditat...
Question 198: Which of the following ensures that a party to a dispute can...
Question 199: Which of the following is an example of over-the-air (OTA) p...
Question 200: Which of the following test methods has the objective to tes...
Question 201: You work as a project manager for BlueWell Inc. You are prep...
Question 202: Which of the following allows multiple operating systems (gu...
Question 203: Which of the following configuration management system proce...
Question 204: In digital rights management, the level of robustness depend...
Question 205: Which of the following are the types of access controls? Eac...
Question 206: The DoD 8500 policy series represents the Department's infor...
Question 207: Which of the following security design patterns provides an ...
Question 208: Which of the following is a signature-based intrusion detect...
Question 209: In which of the following types of tests are the disaster re...
Question 210: What project management plan is most likely to direct the qu...
Question 211: Which of the following processes provides a standard set of ...
Question 212: Certification and Accreditation (C&amp;A or CnA) is a proces...
Question 213: Single Loss Expectancy (SLE) represents an organization's lo...
Question 214: Rob is the project manager of the IDLK Project for his compa...
Question 215: Which of the following methods can be helpful to eliminate s...
Question 216: In which of the following alternative processing sites is th...
Question 217: In which of the following deployment models of cloud is the ...
Question 218: Which of the following intrusion detection systems (IDS) mon...
Question 219: Della works as a security engineer for BlueWell Inc. She wan...
Question 220: Which of the following DoD directives is referred to as the ...
Question 221: In which of the following DIACAP phases is residual risk ana...
Question 222: Gary is the project manager for his project. He and the proj...
Question 223: What component of the change management system is responsibl...
Question 224: Samantha works as an Ethical Hacker for we-are-secure Inc. S...
Question 225: Fred is the project manager of the CPS project. He is workin...
Question 226: An asset with a value of $600,000 is subject to a successful...
Question 227: Which of the following is NOT a responsibility of a data own...
Question 228: You work as a security engineer for BlueWell Inc. Which of t...
Question 229: Mark works as a Network Administrator for NetTech Inc. The c...
Question 230: The NIST Information Security and Privacy Advisory Board (IS...
Question 231: You are the project manager for your organization. You are p...
Question 232: Which of the following are examples of the application progr...
Question 233: Which of the following methods determines the principle name...
Question 234: Which of the following terms refers to a mechanism which pro...
Question 235: To help review or design security controls, they can be clas...
Question 236: Which of the following is a patch management utility that sc...
Question 237: Which of the following elements of BCP process includes the ...
Question 238: You work as the Senior Project manager in Dotcoiss Inc. Your...
Question 239: The organization level is the Tier 1 and it addresses risks ...
Question 240: You work as a Network Administrator for uCertify Inc. You ne...
Question 241: Which of the following documents were developed by NIST for ...
Question 242: John works as a professional Ethical Hacker. He has been ass...
Question 243: Which of the following fields of management focuses on estab...
Question 244: Which of the following security models dictates that subject...
Question 245: The Phase 2 of DITSCAP C&amp;A is known as Verification. The...
Question 246: Which of the following is designed to detect unwanted attemp...
Question 247: DRAG DROP Drag and drop the correct DoD Policy Series at the...
Question 248: Which of the following testing methods verifies the interfac...
Question 249: Which of the following processes describes the elements such...
Question 250: You work as a security engineer for BlueWell Inc. You want t...
Question 251: Which of the following components of configuration managemen...
Question 252: Security Test and Evaluation (ST&amp;E) is a component of ri...
Question 253: Which of the following rated systems of the Orange book has ...
Question 254: The Web resource collection is a security constraint element...
Question 255: Harry is the project manager of the MMQ Construction Project...
Question 256: In which of the following testing methodologies do assessors...
Question 257: The NIST ITL Cloud Research Team defines some primary and se...
Question 258: Which of the following is the most secure method of authenti...
Question 259: Which of the following documents is defined as a source docu...
Question 260: DRAG DROP Drag and drop the appropriate external constructs ...
Question 261: You work as a CSO (Chief Security Officer) for Tech Perfect ...
Question 262: You work as a system engineer for BlueWell Inc. You want to ...
Question 263: Which of the following processes will you involve to perform...
Question 264: Which of the following statements is true about residual ris...
Question 265: John works as a systems engineer for BlueWell Inc. He has mo...
Question 266: Which of the following technologies is used by hardware manu...
Question 267: Which of the following life cycle modeling activities establ...
Question 268: Which of the following elements of the BCP process emphasize...
Question 269: Continuous Monitoring is the fourth phase of the security ce...
Question 270: The build environment of secure coding consists of some tool...
Question 271: Which of the following are examples of passive attacks? Each...
Question 272: Which of the following specifies access privileges to a coll...
Question 273: The Information System Security Officer (ISSO) and Informati...
Question 274: FITSAF stands for Federal Information Technology Security As...
Question 275: Which of the following SDLC phases consists of the given sec...
Question 276: Which of the following techniques is used to identify attack...
Question 277: You are responsible for network and information security at ...
Question 278: Which of the following security controls works as the totali...
Question 279: John works as a security manager for SoftTech Inc. He is wor...
Question 280: Which of the following policies can explain how the company ...
Question 281: Which of the following are included in Technical Controls? E...
Question 282: Which of the following sections come under the ISO/IEC 27002...
Question 283: Which of the following is a chronological record of system a...
Question 284: Which of the following statements describe the main purposes...
Question 285: Which of the following ISO standards is entitled as "Informa...
Question 286: Henry is the project manager of the QBG Project for his comp...
Question 287: You are the project manager for a construction project. The ...
Question 288: Which of the following are the responsibilities of a custodi...
Question 289: Which of the following vulnerabilities occurs when an applic...
Question 290: Which of the following methods does the Java Servlet Specifi...
Question 291: Which of the following is the duration of time and a service...
Question 292: Which of the following phases of the DITSCAP C&amp;A process...
Question 293: Penetration tests are sometimes called white hat attacks bec...
Question 294: Which of the following are the principle duties performed by...
Question 295: Which of the following is used by attackers to record everyt...
Question 296: Information Security management is a process of defining the...
Question 297: DRAG DROP Security code review identifies the unvalidated in...
Question 298: Which of the following classification levels defines the inf...
Question 299: Penetration testing (also called pen testing) is the practic...
Question 300: You are the project manager of QSL project for your organiza...
Question 301: Which of the following is a malicious exploit of a website, ...
Question 302: Stella works as a system engineer for BlueWell Inc. She want...
Question 303: What are the differences between managed and unmanaged code ...
Question 304: Which of the following describes a residual risk as the risk...
Question 305: Which of the following are Service Level Agreement (SLA) str...
Question 306: You have a storage media with some data and you make efforts...
Question 307: "Enhancing the Development Life Cycle to Produce Secure Soft...
Question 308: Which of the following types of attacks is targeting a Web s...
Question 309: The Phase 4 of DITSCAP C&amp;A is known as Post Accreditatio...
Question 310: Which of the following disaster recovery tests includes the ...
Question 311: Which of the following programming languages are compiled in...
Question 312: Which of the following is generally used in packages in orde...
Question 313: The National Information Assurance Certification and Accredi...
Question 314: DRAG DROP Auditing is used to track user accounts for file a...
Question 315: You work as a project manager for BlueWell Inc. You with you...
Question 316: Which of the following is a set of exclusive rights granted ...
Question 317: Which of the following organizations assists the President i...
Question 318: Which of the following types of signatures is used in an Int...
Question 319: You are the project manager for GHY Project and are working ...
Question 320: Which of the following ISO standards provides guidelines for...