<< Prev Question Next Question >>

Question 113/1000

Access Control techniques do not include which of the following?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (1000q)
Question 1: What is the name of the protocol use to set up and manage Se...
Question 2: Which of the following statements is true about data encrypt...
Question 3: Which of the following can best define the "revocation reque...
Question 4: What is a TFTP server most useful for?...
Question 5: Which of the following models does NOT include data integrit...
Question 6: Most access violations are:
Question 7: What can be defined as a value computed with a cryptographic...
Question 8: What is the role of IKE within the IPsec protocol?...
Question 9: Which of the following biometric devices has the lowest user...
Question 10: Which of the following would BEST be defined as an absence o...
Question 11: The IP header contains a protocol field. If this field conta...
Question 12: Which of the following statements pertaining to a security p...
Question 13: Which of the following is the LEAST user accepted biometric ...
Question 14: What mechanism automatically causes an alarm originating in ...
Question 15: Virus scanning and content inspection of SMIME encrypted e-m...
Question 16: Whose role is it to assign classification level to informati...
Question 17: Which of the following is true about digital certificate?...
Question 18: Asynchronous Communication transfers data by sending:...
Question 19: Which type of control is concerned with restoring controls?...
Question 20: What is used to protect programs from all unauthorized modif...
Question 21: Which of the following devices enables more than one signal ...
Question 22: In which of the following model are Subjects and Objects ide...
Question 23: Which of the following would be used to detect and correct e...
Question 24: Which of the following layers provides end-to-end data trans...
Question 25: The type of discretionary access control (DAC) that is based...
Question 26: Which of the following would be true about Static password t...
Question 27: Which of the following service is a distributed database tha...
Question 28: Which of the following is most appropriate to notify an inte...
Question 29: What would be the name of a Logical or Virtual Table dynamic...
Question 30: Which of the following is most affected by denial-of-service...
Question 31: The Secure Hash Algorithm (SHA-1) creates:...
Question 32: What is defined as the hardware, firmware and software eleme...
Question 33: What is a decrease in amplitude as a signal propagates along...
Question 34: Which one of the following is used to provide authentication...
Question 35: Which of the following can be defined as an Internet protoco...
Question 36: Configuration Management controls what?...
Question 37: Physically securing backup tapes from unauthorized access is...
Question 38: A momentary low voltage, from 1 cycle to a few seconds, is a...
Question 39: The National Institute of Standards and Technology (NIST) st...
Question 40: Why is Network File System (NFS) used?...
Question 41: Which of the following is less likely to be used today in cr...
Question 42: Which of the following is not a preventive login control?...
Question 43: Which of the following is not a responsibility of an informa...
Question 44: If any server in the cluster crashes, processing continues t...
Question 45: Which of the following statements pertaining to disk mirrori...
Question 46: Which of the following is not a disadvantage of symmetric cr...
Question 47: What size is an MD5 message digest (hash)?...
Question 48: The scope and focus of the Business continuity plan developm...
Question 49: Which of the following encryption algorithms does not deal w...
Question 50: Which layer of the TCP/IP protocol stack corresponds to the ...
Question 51: Which of the following is the most important consideration i...
Question 52: What is called a sequence of characters that is usually long...
Question 53: Which backup method is additive because the time and tape sp...
Question 54: In Synchronous dynamic password tokens:...
Question 55: Which of the following type of traffic can easily be filtere...
Question 56: Which of the following can be used as a covert channel?...
Question 57: How would nonrepudiation be best classified as?...
Question 58: Which of the following would assist the most in Host Based i...
Question 59: In what way could Java applets pose a security threat?...
Question 60: Which of the following is an issue with signature-based intr...
Question 61: Which of the following would be an example of the best passw...
Question 62: Which of the following algorithms does NOT provide hashing?...
Question 63: Which one of the following represents an ALE calculation?...
Question 64: Which of the following protocols is designed to send individ...
Question 65: What is called the use of technologies such as fingerprint, ...
Question 66: For maximum security design, what type of fence is most effe...
Question 67: Kerberos can prevent which one of the following attacks?...
Question 68: What security model implies a central authority that define ...
Question 69: What is called the verification that the user's claimed iden...
Question 70: All hosts on an IP network have a logical ID called a(n):...
Question 71: As per RFC 1122, which of the following is not a defined lay...
Question 72: What can be defined as the maximum acceptable length of time...
Question 73: Which of the following is an advantage that UDP has over TCP...
Question 74: This type of attack is generally most applicable to public-k...
Question 75: Which of the following is not a one-way hashing algorithm?...
Question 76: Which of the following does not address Database Management ...
Question 77: What is the maximum allowable key size of the Rijndael encry...
Question 78: The number of violations that will be accepted or forgiven b...
Question 79: What is the RESULT of a hash algorithm being applied to a me...
Question 80: Which of the following was developed to address some of the ...
Question 81: What is called an exception to the search warrant requiremen...
Question 82: Which of the following tasks is NOT usually part of a Busine...
Question 83: Which of the following is the most reliable, secure means of...
Question 84: Which of the following can be defined as the process of reru...
Question 85: Which of the following concerning the Rijndael block cipher ...
Question 86: Attributes that characterize an attack are stored for refere...
Question 87: Which of the following is defined as an Internet, IPsec, key...
Question 88: To be admissible in court, computer evidence must be which o...
Question 89: Which of the following questions is less likely to help in a...
Question 90: The session layer provides a logical persistent connection b...
Question 91: Upon which of the following ISO/OSI layers does network addr...
Question 92: Which of the following statements pertaining to the Bell-LaP...
Question 93: An alternative to using passwords for authentication in logi...
Question 94: Why do buffer overflows happen? What is the main cause?...
Question 95: Which layer of the TCP/IP protocol model would best correspo...
Question 96: You work in a police department forensics lab where you exam...
Question 97: Which of the following questions is less likely to help in a...
Question 98: Which of the following ciphers is a subset on which the Vige...
Question 99: Risk analysis is MOST useful when applied during which phase...
Question 100: Packet Filtering Firewalls examines both the source and dest...
Question 101: Which layer of the OSI/ISO model handles physical addressing...
Question 102: Sensitivity labels are an example of what application contro...
Question 103: Controls to keep password sniffing attacks from compromising...
Question 104: Who should measure the effectiveness of Information System s...
Question 105: Which of the following describes a technique in which a numb...
Question 106: When preparing a business continuity plan, who of the follow...
Question 107: Which backup method is used if backup time is critical and t...
Question 108: Which of the following choice is NOT normally part of the qu...
Question 109: Which of the following reviews system and event logs to dete...
Question 110: What is defined as the manner in which the network devices a...
Question 111: Authentication Headers (AH) and Encapsulating Security Paylo...
Question 112: External consistency ensures that the data stored in the dat...
Question 113: Access Control techniques do not include which of the follow...
Question 114: Which of the following centralized access control mechanisms...
Question 115: What is called an attack where the attacker spoofs the sourc...
Question 116: If your property Insurance has Actual Cash Valuation (ACV) c...
Question 117: When a possible intrusion into your organization's informati...
Question 118: Which of the following Operation Security controls is intend...
Question 119: Which approach to a security program ensures people responsi...
Question 120: Compared to RSA, which of the following is true of Elliptic ...
Question 121: Which of the following is most likely to be useful in detect...
Question 122: What is malware that can spread itself over open network con...
Question 123: Computer-generated evidence is considered:...
Question 124: Why is traffic across a packet switched network difficult to...
Question 125: In the context of network enumeration by an outside attacker...
Question 126: Which of the following is an example of discretionary access...
Question 127: The Clipper Chip utilizes which concept in public key crypto...
Question 128: What is the greatest danger from DHCP?...
Question 129: What is called the percentage of valid subjects that are fal...
Question 130: Which of the following statements pertaining to PPTP (Point-...
Question 131: A timely review of system access audit records would be an e...
Question 132: Which of the following statements pertaining to software tes...
Question 133: In order to ensure the privacy and integrity of the data, co...
Question 134: What would be the Annualized Rate of Occurrence (ARO) of the...
Question 135: Which of the following is the biggest concern with firewall ...
Question 136: What is considered the most important type of error to avoid...
Question 137: When should a post-mortem review meeting be held after an in...
Question 138: Making sure that the data has not been changed unintentional...
Question 139: Which of the following monitors network traffic in real time...
Question 140: Which of the following elements of telecommunications is not...
Question 141: What is a packet sniffer?
Question 142: Which of the following is NOT a characteristic of a host-bas...
Question 143: What does the (star) property mean in the Bell-LaPadula mode...
Question 144: Which of the following phases of a system development life-c...
Question 145: Because ordinary cable introduces a toxic hazard in the even...
Question 146: Logical or technical controls involve the restriction of acc...
Question 147: Controlling access to information systems and associated net...
Question 148: When we encrypt or decrypt data there is a basic operation i...
Question 149: Which of the following identifies the encryption algorithm s...
Question 150: Which of the following exemplifies proper separation of duti...
Question 151: Which of the following media is MOST resistant to EMI interf...
Question 152: In a SSL session between a client and a server, who is respo...
Question 153: Which of the following LAN topologies offers the highest ava...
Question 154: What can best be defined as the detailed examination and tes...
Question 155: Which protocol makes USE of an electronic wallet on a custom...
Question 156: Which of the following cryptographic attacks describes when ...
Question 157: Which of the following access control models is based on sen...
Question 158: Which of the following access methods is used by Ethernet?...
Question 159: Which of the following is a symmetric encryption algorithm?...
Question 160: Which of the following usually provides reliable, real-time ...
Question 161: Which of the following rules is least likely to support the ...
Question 162: Which device acting as a translator is used to connect two n...
Question 163: The Information Technology Security Evaluation Criteria (ITS...
Question 164: Which of the following are REGISTERED PORTS as defined by IA...
Question 165: Which of the following is a problem regarding computer inves...
Question 166: Which of the following is the most reliable authentication m...
Question 167: Which of the following are not Remote Access concerns?...
Question 168: What is the proper term to refer to a single unit of Etherne...
Question 169: Which access model is most appropriate for companies with a ...
Question 170: Which of the following answers is described as a random valu...
Question 171: This type of supporting evidence is used to help prove an id...
Question 172: What can be defined as a batch process dumping backup data t...
Question 173: Another type of access control is lattice-based access contr...
Question 174: Which element must computer evidence have to be admissible i...
Question 175: Which of the following does NOT concern itself with key mana...
Question 176: Which of the following protects a password from eavesdropper...
Question 177: Which of the following classes is defined in the TCSEC (Oran...
Question 178: Which of the following is the most secure form of triple-DES...
Question 179: A business continuity plan is an example of which of the fol...
Question 180: Which of the following technologies has been developed to su...
Question 181: Which of the following is the simplest type of firewall ?...
Question 182: Computer security should be first and foremost which of the ...
Question 183: Which of the following is an unintended communication path t...
Question 184: The Diffie-Hellman algorithm is used for:...
Question 185: The information security staff's participation in which of t...
Question 186: Which of the following logical access exposures INVOLVES CHA...
Question 187: If an employee's computer has been used by a fraudulent empl...
Question 188: Why is infrared generally considered to be more secure to ea...
Question 189: Why does compiled code pose more of a security risk than int...
Question 190: Encapsulating Security Payload (ESP) provides some of the se...
Question 191: Which of the following is addressed by Kerberos?...
Question 192: The preliminary steps to security planning include all of th...
Question 193: Which of the following is a trusted, third party authenticat...
Question 194: What is NOT true with pre shared key authentication within I...
Question 195: Which of the following is implemented through scripts or sma...
Question 196: A security evaluation report and an accreditation statement ...
Question 197: Which of the following services is NOT provided by the digit...
Question 198: Which of the following steps is NOT one of the eight detaile...
Question 199: Which of the following standards is concerned with message h...
Question 200: When referring to a computer crime investigation, which of t...
Question 201: Which of the following elements is NOT included in a Public ...
Question 202: Making sure that only those who are supposed to access the d...
Question 203: Which of the following describes a logical form of separatio...
Question 204: The controls that usually require a human to evaluate the in...
Question 205: What is the main characteristic of a bastion host?...
Question 206: Which of the following is NOT a defined ISO basic task relat...
Question 207: Complete the blanks. When using PKI, I digitally sign a mess...
Question 208: Which of the following statements pertaining to message dige...
Question 209: Which of the following networking devices allows the connect...
Question 210: Which of the following is not appropriate in addressing obje...
Question 211: Which of the following would best classify as a management c...
Question 212: Which access control model is best suited in an environment ...
Question 213: Which of the following binds a subject name to a public key ...
Question 214: What works as an E-mail message transfer agent?...
Question 215: Which of the following is true about Kerberos?...
Question 216: Which of the following is NOT a compensating measure for acc...
Question 217: Which of the following services relies on UDP?...
Question 218: The RSA algorithm is an example of what type of cryptography...
Question 219: Which of the following best corresponds to the type of memor...
Question 220: When a station communicates on the network for the first tim...
Question 221: Which type of password provides maximum security because a n...
Question 222: What is the main objective of proper separation of duties?...
Question 223: Which of the following are additional access control objecti...
Question 224: Which of the following Intrusion Detection Systems (IDS) use...
Question 225: Which of the following outlined how senior management are re...
Question 226: Which of the following protocols operates at the session lay...
Question 227: Of the following, which is NOT a specific loss criteria that...
Question 228: Which xDSL flavour delivers both downstream and upstream spe...
Question 229: Which of the following is needed for System Accountability?...
Question 230: Rule-Based Access Control (RuBAC) access is determined by ru...
Question 231: Which of the following forms of authentication would most li...
Question 232: Java is not:
Question 233: Which of the following is NOT a property of a one-way hash f...
Question 234: What is called an event or activity that has the potential t...
Question 235: In the statement below, fill in the blank: Law enforcement a...
Question 236: Which of the following is an IP address that is private (i.e...
Question 237: Which of the following is BEST defined as a physical control...
Question 238: An effective information security policy should not have whi...
Question 239: Which of the following is used to monitor network traffic or...
Question 240: A trusted system does NOT involve which of the following?...
Question 241: What is defined as the rules for communicating between compu...
Question 242: Which is the last line of defense in a physical security sen...
Question 243: Like the Kerberos protocol, SESAME is also subject to which ...
Question 244: Considerations of privacy, invasiveness, and psychological a...
Question 245: The IP header contains a protocol field. If this field conta...
Question 246: In biometric identification systems, the parts of the body c...
Question 247: Remote Procedure Call (RPC) is a protocol that one program c...
Question 248: Which of the following is not a two-factor authentication me...
Question 249: Which division of the Orange Book deals with discretionary p...
Question 250: Which of the following floors would be most appropriate to l...
Question 251: Which of the following tools is NOT likely to be used by a h...
Question 252: Which of following is not a service provided by AAA servers ...
Question 253: Layer 4 of the OSI stack is known as:...
Question 254: Which type of password token involves time synchronization?...
Question 255: What is the effective key size of DES?...
Question 256: Which of the following is true about Kerberos?...
Question 257: The "vulnerability of a facility" to damage or attack may be...
Question 258: The Terminal Access Controller Access Control System (TACACS...
Question 259: How many rounds are used by DES?...
Question 260: Which protocol is NOT implemented in the Network layer of th...
Question 261: Which of the following is NOT true concerning Application Co...
Question 262: What is called the percentage at which the False Rejection R...
Question 263: What is the primary role of smartcards in a PKI?...
Question 264: What are the three most important functions that Digital Sig...
Question 265: Which of the following security models does NOT concern itse...
Question 266: If your property Insurance has Replacement Cost Valuation (R...
Question 267: At what stage of the applications development process should...
Question 268: Packet Filtering Firewalls can also enable access for:...
Question 269: The IP header contains a protocol field. If this field conta...
Question 270: Which security model is based on the military classification...
Question 271: Which of the following would be best suited to oversee the d...
Question 272: Identification and authentication are the keystones of most ...
Question 273: How are memory cards and smart cards different?...
Question 274: In which of the following security models is the subject's c...
Question 275: Which of the following is NOT a type of motion detector?...
Question 276: What can be defined as an event that could cause harm to the...
Question 277: In this type of attack, the intruder re-routes data traffic ...
Question 278: Which must bear the primary responsibility for determining t...
Question 279: Why would anomaly detection IDSs often generate a large numb...
Question 280: Which of the following is not a method to protect objects an...
Question 281: Who should DECIDE how a company should approach security and...
Question 282: Degaussing is used to clear data from all of the following m...
Question 283: Which of the following can best be defined as a key distribu...
Question 284: Almost all types of detection permit a system's sensitivity ...
Question 285: Which of the following was designed to support multiple netw...
Question 286: Making sure that the data is accessible when and where it is...
Question 287: Which of the following is less likely to accompany a conting...
Question 288: The communications products and services, which ensure that ...
Question 289: Which of the following is commonly used for retrofitting mul...
Question 290: How often should a Business Continuity Plan be reviewed?...
Question 291: In which layer of the OSI Model are connection-oriented prot...
Question 292: Which of the following backup methods is most appropriate fo...
Question 293: PGP uses which of the following to encrypt data?...
Question 294: Which of the following is NOT a basic component of security ...
Question 295: What is the most correct choice below when talking about the...
Question 296: In order to enable users to perform tasks and duties without...
Question 297: Which of the following questions is less likely to help in a...
Question 298: What would BEST define a covert channel?...
Question 299: Which of the following is a token-passing scheme like token ...
Question 300: In biometrics, the "one-to-one" search used to verify claim ...
Question 301: The International Standards Organization / Open Systems Inte...
Question 302: How should a doorway of a manned facility with automatic loc...
Question 303: Which type of algorithm is considered to have the highest st...
Question 304: A contingency plan should address:...
Question 305: At which layer of ISO/OSI does the fiber optics work?...
Question 306: Controls provide accountability for individuals who are acce...
Question 307: What can best be described as an abstract machine which must...
Question 308: Which of the following focuses on sustaining an organization...
Question 309: What is the essential difference between a self-audit and an...
Question 310: Which of the following best defines add-on security?...
Question 311: What is an IP routing table?
Question 312: Which of the following is NOT part of the Kerberos authentic...
Question 313: Which of the following technologies is a target of XSS or CS...
Question 314: A server cluster looks like a:
Question 315: Which of the following would MOST likely ensure that a syste...
Question 316: What is the main problem of the renewal of a root CA certifi...
Question 317: FTP, TFTP, SNMP, and SMTP are provided at what level of the ...
Question 318: Which of the following statements regarding an off-site info...
Question 319: When you update records in multiple locations or you make a ...
Question 320: Which of the following is NOT a common integrity goal?...
Question 321: Which type of attack is based on the probability of two diff...
Question 322: Which of the following is an advantage of prototyping?...
Question 323: After a company is out of an emergency state, what should be...
Question 324: What mechanism does a system use to compare the security lab...
Question 325: Which of the following is NOT a correct notation for an IPv6...
Question 326: What is called the formal acceptance of the adequacy of a sy...
Question 327: Which of the following is not an example of a block cipher?...
Question 328: What assesses potential loss that could be caused by a disas...
Question 329: Unshielded Twisted Pair (UTP) cables comes in several catego...
Question 330: Which of the following would provide the BEST stress testing...
Question 331: Which of the following cannot be undertaken in conjunction o...
Question 332: Which of the following is related to physical security and i...
Question 333: What is the PRIMARY reason to maintain the chain of custody ...
Question 334: A X.509 public key certificate with the key usage attribute ...
Question 335: Memory management in TCSEC levels B3 and A1 operating system...
Question 336: A channel within a computer system or network that is design...
Question 337: Which of the following ASYMMETRIC encryption algorithms is b...
Question 338: Step-by-step instructions used to satisfy control requiremen...
Question 339: What key size is used by the Clipper Chip?...
Question 340: What is it called when a computer uses more than one CPU in ...
Question 341: What algorithm has been selected as the AES algorithm, repla...
Question 342: Which of the following is covered under Crime Insurance Poli...
Question 343: This is a common security issue that is extremely hard to co...
Question 344: The three classic ways of authenticating yourself to the com...
Question 345: Each data packet is assigned the IP address of the sender an...
Question 346: Which of the following control pairing places emphasis on "s...
Question 347: Organizations should consider which of the following first b...
Question 348: Once evidence is seized, a law enforcement officer should em...
Question 349: What does the simple integrity axiom mean in the Biba model?...
Question 350: Before the advent of classless addressing, the address 128.1...
Question 351: What is the key size of the International Data Encryption Al...
Question 352: A potential problem related to the physical installation of ...
Question 353: Which of the following would constitute the best example of ...
Question 354: In an organization where there are frequent personnel change...
Question 355: Which communication method is characterized by very high spe...
Question 356: What can best be defined as a strongly protected computer th...
Question 357: Which of the following was developed as a simple mechanism f...
Question 358: Which of the following best describes remote journaling?...
Question 359: What Orange Book security rating is reserved for systems tha...
Question 360: Detective/Technical measures:
Question 361: Which backup method copies only files that have changed sinc...
Question 362: Which of the following is TRUE regarding Transmission Contro...
Question 363: What is RAD?
Question 364: Which of the following would be used to implement Mandatory ...
Question 365: In the course of responding to and handling an incident, you...
Question 366: Which of the following is not a form of passive attack?...
Question 367: Which of the following statements pertaining to Kerberos is ...
Question 368: What is the primary role of cross certification?...
Question 369: What is also known as 10Base5?
Question 370: Which protocol of the TCP/IP suite addresses reliable data t...
Question 371: In what way can violation clipping levels assist in violatio...
Question 372: Related to information security, integrity is the opposite o...
Question 373: What security model is dependent on security labels?...
Question 374: What is one disadvantage of content-dependent protection of ...
Question 375: What is a limitation of TCP Wrappers?...
Question 376: Which of the following is the most secure firewall implement...
Question 377: A confidential number used as an authentication factor to ve...
Question 378: IT security measures should:
Question 379: Which of the following would best describe certificate path ...
Question 380: Access control is the collection of mechanisms that permits ...
Question 381: All following observations about IPSec are correct except:...
Question 382: The Telecommunications Security Domain of information securi...
Question 383: Attributable data should be:
Question 384: Which of the following statements pertaining to link encrypt...
Question 385: Which of the following is a LAN transmission method?...
Question 386: Which of the following are suitable protocols for securing V...
Question 387: Which of the following statements pertaining to using Kerber...
Question 388: Buffer overflow and boundary condition errors are subsets of...
Question 389: Which type of attack involves impersonating a user or a syst...
Question 390: What is NOT true about a one-way hashing function?...
Question 391: Which of the following specifically addresses cyber attacks ...
Question 392: What is the primary reason why some sites choose not to impl...
Question 393: Access Control techniques do not include which of the follow...
Question 394: Brute force attacks against encryption keys have increased i...
Question 395: What is the primary difference between FTP and TFTP?...
Question 396: Which one of the following factors is NOT one on which Authe...
Question 397: Which one of the following is NOT one of the outcomes of a v...
Question 398: A network-based vulnerability assessment is a type of test a...
Question 399: Which of the following access control models requires securi...
Question 400: Which OSI/ISO layer is responsible for determining the best ...
Question 401: Which access control model provides upper and lower bounds o...
Question 402: Which backup method does not reset the archive bit on files ...
Question 403: In addition to the Legal Department, with what company funct...
Question 404: What is the main difference between a Smurf and a Fraggle at...
Question 405: Which of the following protocol was used by the INITIAL vers...
Question 406: Which of the following transmission media would NOT be affec...
Question 407: What is the highest amount a company should spend annually o...
Question 408: What can be defined as secret communications where the very ...
Question 409: Qualitative loss resulting from the business interruption do...
Question 410: Which of the following biometric parameters are better suite...
Question 411: Which of the following is a method of multiplexing data wher...
Question 412: What is the Maximum Tolerable Downtime (MTD)?...
Question 413: Which of the following algorithms is a stream cipher?...
Question 414: What is the maximum length of cable that can be used for a t...
Question 415: Which of the following security-focused protocols has confid...
Question 416: Which of the following is the MOST important aspect relating...
Question 417: Which of the following is not a physical control for physica...
Question 418: Which of the following is a device that is used to regenerat...
Question 419: Which one of the following statements about the advantages a...
Question 420: Which of the following statements pertaining to stream ciphe...
Question 421: Which of the following is NOT a form of detective administra...
Question 422: Which of the following statements pertaining to biometrics i...
Question 423: Which of the following statements pertaining to ethical hack...
Question 424: Which layer of the DoD TCP/IP Model ensures error-free deliv...
Question 425: The control measures that are intended to reveal the violati...
Question 426: Physical security is accomplished through proper facility co...
Question 427: Which of the following remote access authentication systems ...
Question 428: Which of the following is defined as the most recent point i...
Question 429: Which of the following statements pertaining to IPSec is inc...
Question 430: Which of the following proves or disproves a specific act th...
Question 431: Which of the following statements pertaining to the security...
Question 432: How should a risk be HANDLED when the cost of the countermea...
Question 433: Which of the following backup methods is primarily run when ...
Question 434: Which encryption algorithm is BEST suited for communication ...
Question 435: Which of the following is an IP address that is private (i.e...
Question 436: Which of the following security modes of operation involves ...
Question 437: Which of the following firewall rules found on a firewall in...
Question 438: Which of the following is most relevant to determining the m...
Question 439: Cryptography does NOT help in:
Question 440: The Data Encryption Algorithm performs how many rounds of su...
Question 441: Which of the following would NOT violate the Due Diligence c...
Question 442: Which access control model is also called Non Discretionary ...
Question 443: An Architecture where there are more than two execution doma...
Question 444: Which of the following is NOT a characteristic or shortcomin...
Question 445: A one-way hash provides which of the following?...
Question 446: Prior to a live disaster test also called a Full Interruptio...
Question 447: RADIUS incorporates which of the following services?...
Question 448: Which of the following does not apply to system-generated pa...
Question 449: What kind of certificate is used to validate a user identity...
Question 450: Which of the following is NOT an advantage that TACACS+ has ...
Question 451: A copy of evidence or oral description of its contents; whic...
Question 452: In the CIA triad, what does the letter A stand for?...
Question 453: Which of the following best ensures accountability of users ...
Question 454: Which of the following is not an encryption algorithm?...
Question 455: A Business Continuity Plan should be tested:...
Question 456: The typical computer fraudsters are usually persons with whi...
Question 457: What is called the access protection system that limits conn...
Question 458: Good security is built on which of the following concept?...
Question 459: Which of the following is most appropriate to notify an exte...
Question 460: What is the proper term to refer to a single unit of IP data...
Question 461: Which Network Address Translation (NAT) is the most convenie...
Question 462: Which of the following Kerberos components holds all users' ...
Question 463: Which of the following phases of a software development life...
Question 464: An application layer firewall is also called a:...
Question 465: Which of the following exemplifies proper separation of duti...
Question 466: Within the context of the CBK, which of the following provid...
Question 467: ICMP and IGMP belong to which layer of the OSI model?...
Question 468: Which one of the following authentication mechanisms creates...
Question 469: The first step in the implementation of the contingency plan...
Question 470: What are the components of an object's sensitivity label?...
Question 471: Which type of attack involves impersonating a user or a syst...
Question 472: Unshielded Twisted Pair cabling is a:...
Question 473: How is Annualized Loss Expectancy (ALE) derived from a threa...
Question 474: In a known plaintext attack, the cryptanalyst has knowledge ...
Question 475: A DMZ is located:
Question 476: What would be considered the biggest drawback of Host-based ...
Question 477: What does the Clark-Wilson security model focus on?...
Question 478: Which of the following is NOT an administrative control?...
Question 479: Which integrity model defines a constrained data item, an in...
Question 480: Which of the following statements do not apply to a hot site...
Question 481: Which of the following is best at defeating frequency analys...
Question 482: The throughput rate is the rate at which individuals, once e...
Question 483: In the UTP category rating, the tighter the wind:...
Question 484: What do the ILOVEYOU and Melissa virus attacks have in commo...
Question 485: The Computer Security Policy Model the Orange Book is based ...
Question 486: What is the framing specification used for transmitting digi...
Question 487: Which of the following was developed in order to protect aga...
Question 488: When first analyzing an intrusion that has just been detecte...
Question 489: In biometrics, "one-to-many" search against database of stor...
Question 490: Why should batch files and scripts be stored in a protected ...
Question 491: Which of the following is the most complete disaster recover...
Question 492: One of the following statements about the differences betwee...
Question 493: A Packet Filtering Firewall system is considered a:...
Question 494: Which of the following classes is the first level (lower) de...
Question 495: Within the OSI model, at what layer are some of the SLIP, CS...
Question 496: What can best be defined as high-level statements, beliefs, ...
Question 497: Which of the following should NOT be performed by an operato...
Question 498: Which of the following is NOT a valid reason to use external...
Question 499: Within the realm of IT security, which of the following comb...
Question 500: In Mandatory Access Control, sensitivity labels attached to ...
Question 501: In the Bell-LaPadula model, the Star-property is also called...
Question 502: Which of the following offers security to wireless communica...
Question 503: Why would a memory dump be admissible as evidence in court?...
Question 504: The absence of a safeguard, or a weakness in a system that m...
Question 505: Controls are implemented to:
Question 506: Which of the following security controls might force an oper...
Question 507: Which of the following standards concerns digital certificat...
Question 508: How do you distinguish between a bridge and a router?...
Question 509: The Diffie-Hellman algorithm is primarily used to provide wh...
Question 510: Which of the following statements pertaining to the maintena...
Question 511: Which of the following is a cryptographic protocol and infra...
Question 512: A packet containing a long string of NOP's followed by a com...
Question 513: In the days before CIDR (Classless Internet Domain Routing),...
Question 514: What security problem is most likely to exist if an operatin...
Question 515: A momentary high voltage is a:
Question 516: Which of the following is true related to network sniffing?...
Question 517: Which cable technology refers to the CAT3 and CAT5 categorie...
Question 518: Which of the following pairings uses technology to enforce a...
Question 519: What principle focuses on the uniqueness of separate objects...
Question 520: In the context of Biometric authentication, what is a quick ...
Question 521: When an outgoing request is made on a port number greater th...
Question 522: Which of the following is not a DES mode of operation?...
Question 523: Who first described the DoD multilevel military security pol...
Question 524: Where parties do not have a shared secret and large quantiti...
Question 525: In a stateful inspection firewall, data packets are captured...
Question 526: The security of a computer application is most effective and...
Question 527: Which security model ensures that actions that take place at...
Question 528: Which of the following would best describe a Concealment cip...
Question 529: Which of the following category of UTP cables is specified t...
Question 530: What kind of Encryption technology does SSL utilize?...
Question 531: A code, as is pertains to cryptography:...
Question 532: Which of the following is NOT a property of the Rijndael blo...
Question 533: The Reference Validation Mechanism that ensures the authoriz...
Question 534: Which of the following is true of two-factor authentication?...
Question 535: In an online transaction processing system (OLTP), which of ...
Question 536: The three classic ways of authenticating yourself to the com...
Question 537: Which of the following is NOT an advantage that TACACS+ has ...
Question 538: Which of the following is NOT a proper component of Media Vi...
Question 539: What is defined as inference of information from other, inte...
Question 540: Which of the following will a Business Impact Analysis NOT i...
Question 541: In addition to the accuracy of the biometric systems, there ...
Question 542: Which of the following BEST describes a function relying on ...
Question 543: What is the name of the first mathematical model of a multi-...
Question 544: What ensures that the control mechanisms correctly implement...
Question 545: What is the Biba security model concerned with?...
Question 546: Which of the following recovery plan test results would be m...
Question 547: Contracts and agreements are often times unenforceable or ha...
Question 548: Knowledge-based Intrusion Detection Systems (IDS) are more c...
Question 549: Virus scanning and content inspection of SMIME encrypted e-m...
Question 550: Who is ultimately responsible for the security of computer b...
Question 551: As a result of a risk assessment, your security manager has ...
Question 552: In which of the following phases of system development life ...
Question 553: The viewing of recorded events after the fact using a closed...
Question 554: Which of the following protocols suite does the Internet use...
Question 555: Which of the following NAT firewall translation modes offers...
Question 556: What is the primary role of smartcards in a PKI?...
Question 557: What ISO/OSI layer do switches primarily operate at? Do take...
Question 558: Frame relay uses a public switched network to provide:...
Question 559: The criteria for evaluating the legal requirements for imple...
Question 560: What is the most secure way to dispose of information on a C...
Question 561: An Intrusion Detection System (IDS) is what type of control?...
Question 562: Which type of attack would a competitive intelligence attack...
Question 563: Who can best decide what are the adequate technical security...
Question 564: Password management falls into which control category?...
Question 565: Which of the following is an extension to Network Address Tr...
Question 566: What attribute is included in a X.509-certificate?...
Question 567: Related to information security, confidentiality is the oppo...
Question 568: Which of the following computer crime is MORE often associat...
Question 569: To protect and/or restore lost, corrupted, or deleted inform...
Question 570: Which of the following protocols that provide integrity and ...
Question 571: Which of the following is used by RADIUS for communication b...
Question 572: There are parallels between the trust models in Kerberos and...
Question 573: Which expert system operating mode allows determining if a g...
Question 574: The control of communications test equipment should be clear...
Question 575: Which of the following statements pertaining to packet filte...
Question 576: When two or more separate entities (usually persons) operati...
Question 577: Which of the following packets should NOT be dropped at a fi...
Question 578: Which of the following are the two MOST common implementatio...
Question 579: Preservation of confidentiality within information systems r...
Question 580: Which of the following statements pertaining to Kerberos is ...
Question 581: Telnet and rlogin use which protocol?...
Question 582: What attack involves the perpetrator sending spoofed packet(...
Question 583: Which of the following statements pertaining to link encrypt...
Question 584: The primary service provided by Kerberos is which of the fol...
Question 585: Which of the following protection devices is used for spot p...
Question 586: Which of the following is not a logical control when impleme...
Question 587: What is the PRIMARY goal of incident handling?...
Question 588: Which of the following can best eliminate dial-up access thr...
Question 589: Which of the following is NOT a common category/classificati...
Question 590: The Orange Book states that "Hardware and software features ...
Question 591: Another example of Computer Incident Response Team (CIRT) ac...
Question 592: Communications and network security relates to transmission ...
Question 593: Which of the following is defined as a key establishment pro...
Question 594: Which of the following are suitable protocols for securing V...
Question 595: Domain Name Service is a distributed database system that is...
Question 596: What protocol is used on the Local Area Network (LAN) to obt...
Question 597: What is the primary goal of setting up a honeypot?...
Question 598: In order to be able to successfully prosecute an intruder:...
Question 599: How many bits of a MAC address uniquely identify a vendor, a...
Question 600: Which of the following would be MOST important to guarantee ...
Question 601: A department manager has read access to the salaries of the ...
Question 602: Which of the following is more suitable for a hardware imple...
Question 603: Related to information security, the guarantee that the mess...
Question 604: What is the main focus of the Bell-LaPadula security model?...
Question 605: In an organization, an Information Technology security funct...
Question 606: Which backup type run at regular intervals would take the le...
Question 607: During the testing of the business continuity plan (BCP), wh...
Question 608: Which of the following is an IP address that is private (i.e...
Question 609: Which of the following keys has the SHORTEST lifespan?...
Question 610: Which of the following statements pertaining to protection r...
Question 611: While using IPsec, the ESP and AH protocols both provides in...
Question 612: Which of the following is not a preventive operational contr...
Question 613: Which of the following is required in order to provide accou...
Question 614: Which of the following was designed as a more fault-tolerant...
Question 615: Which of the following rules appearing in an Internet firewa...
Question 616: A public key algorithm that does both encryption and digital...
Question 617: What is used to bind a document to its creation at a particu...
Question 618: Who of the following is responsible for ensuring that proper...
Question 619: The following is NOT a security characteristic we need to co...
Question 620: How can an individual/person best be identified or authentic...
Question 621: Which layer defines how packets are routed between end syste...
Question 622: In biometric identification systems, at the beginning, it wa...
Question 623: Hierarchical Storage Management (HSM) is commonly employed i...
Question 624: Which of the following is biggest factor that makes Computer...
Question 625: In a SSL session between a client and a server, who is respo...
Question 626: Which of the following attacks could capture network user pa...
Question 627: Crackers today are MOST often motivated by their desire to:...
Question 628: Which of the following is a large hardware/software backup s...
Question 629: Which of the following statements pertaining to Secure Socke...
Question 630: What kind of certificate is used to validate a user identity...
Question 631: What type of attack involves IP spoofing, ICMP ECHO and a bo...
Question 632: The property of a system or a system resource being accessib...
Question 633: In a hierarchical PKI the highest CA is regularly called Roo...
Question 634: Guards are appropriate whenever the function required by the...
Question 635: This baseline sets certain thresholds for specific errors or...
Question 636: What is the main concern with single sign-on?...
Question 637: Which of the following is best defined as a circumstance in ...
Question 638: What is the name of a one way transformation of a string of ...
Question 639: Which security model uses division of operations into differ...
Question 640: Which of the following offers advantages such as the ability...
Question 641: Ensuring least privilege does not require:...
Question 642: In discretionary access environments, which of the following...
Question 643: Which of the following choices describe a Challenge-response...
Question 644: Which of the following statements pertaining to software tes...
Question 645: Which of the following is NOT true about IPSec Tunnel mode?...
Question 646: The IP header contains a protocol field. If this field conta...
Question 647: Within the legal domain what rule is concerned with the lega...
Question 648: Which of the following assertions is NOT true about pattern ...
Question 649: Which of the following is needed for System Accountability?...
Question 650: What is called the act of a user professing an identity to a...
Question 651: Which of the following is NOT a true statement regarding the...
Question 652: Which of the following is less likely to be included in the ...
Question 653: In response to Access-request from a client such as a Networ...
Question 654: What does "residual risk" mean?...
Question 655: A prolonged complete loss of electric power is a:...
Question 656: Which access control model enables the OWNER of the resource...
Question 657: Which of the following IEEE standards defines the token ring...
Question 658: What is the main characteristic of a multi-homed host?...
Question 659: If an operating system permits shared resources such as memo...
Question 660: The major objective of system configuration management is wh...
Question 661: Which of the following would best describe secondary evidenc...
Question 662: What setup should an administrator use for regularly testing...
Question 663: Which of the following statements pertaining to disaster rec...
Question 664: Which of the following is an example of an active attack?...
Question 665: Which of the following is based on the premise that the qual...
Question 666: Which of the following is an Internet IPsec protocol to nego...
Question 667: Which of the following is a not a preventative control?...
Question 668: What would BEST define risk management?...
Question 669: Which virus category has the capability of changing its own ...
Question 670: Notifying the appropriate parties to take action in order to...
Question 671: According to private sector data classification levels, how ...
Question 672: Which of the following is NOT a transaction redundancy imple...
Question 673: Which of the following mechanisms was created to overcome th...
Question 674: Which of the following is NOT a technique used to perform a ...
Question 675: Who is responsible for initiating corrective measures and ca...
Question 676: What can be defined as a table of subjects and objects indic...
Question 677: Which SSL version offers client-side authentication?...
Question 678: Which of the following statements pertaining to biometrics i...
Question 679: Which type of control is concerned with avoiding occurrences...
Question 680: Which of the following biometric devices offers the LOWEST C...
Question 681: Which of the following best defines a Computer Security Inci...
Question 682: Which of the following phases of a software development life...
Question 683: This type of backup management provides a continuous on-line...
Question 684: Which of the following types of Intrusion Detection Systems ...
Question 685: In computing what is the name of a non-self-replicating type...
Question 686: Which of the following was developed by the National Compute...
Question 687: Which conceptual approach to intrusion detection system is t...
Question 688: Which of the following backup method must be made regardless...
Question 689: Secure Sockets Layer (SSL) uses a Message Authentication Cod...
Question 690: Which of the following algorithms is used today for encrypti...
Question 691: Which of the following statements pertaining to quantitative...
Question 692: Which of the following is an advantage of a qualitative over...
Question 693: Which of the following prevents, detects, and corrects error...
Question 694: Which of the following is NOT an example of an operational c...
Question 695: Which of the following is true of network security?...
Question 696: Which of the following are additional terms used to describe...
Question 697: Who is responsible for providing reports to the senior manag...
Question 698: All of the following can be considered essential business fu...
Question 699: What can be described as a measure of the magnitude of loss ...
Question 700: Which of the following division is defined in the TCSEC (Ora...
Question 701: What is called a password that is the same for each log-on s...
Question 702: The end result of implementing the principle of least privil...
Question 703: What is called a system that is capable of detecting that a ...
Question 704: Which of the following teams should NOT be included in an or...
Question 705: A momentary power outage is a:
Question 706: What IDS approach relies on a database of known attacks?...
Question 707: What does the simple security (ss) property mean in the Bell...
Question 708: A proxy is considered a:
Question 709: What is the maximum number of different keys that can be use...
Question 710: What is the MOST critical piece to disaster recovery and con...
Question 711: Which of the following would best describe the difference be...
Question 712: Which of the following countermeasures would be the most app...
Question 713: Business Continuity Planning (BCP) is not defined as a prepa...
Question 714: Which of the following would best define a digital envelope?...
Question 715: Which of the following biometric characteristics cannot be u...
Question 716: Similar to Secure Shell (SSH-2), Secure Sockets Layer (SSL) ...
Question 717: Communications devices must operate:...
Question 718: Which of the following is a disadvantage of a statistical an...
Question 719: In stateful inspection firewalls, packets are:...
Question 720: Which of the following remote access authentication systems ...
Question 721: At which OSI/ISO layer is an encrypted authentication betwee...
Question 722: Which of the following can be best defined as computing tech...
Question 723: Which of the following embodies all the detailed actions tha...
Question 724: The Data Encryption Standard (DES) encryption algorithm has ...
Question 725: Which of the following terms can be described as the process...
Question 726: Which OSI/ISO layer does a SOCKS server operate at?...
Question 727: Transport Layer Security (TLS) is a two-layered socket layer...
Question 728: Which of the following methods of providing telecommunicatio...
Question 729: You have been tasked to develop an effective information cla...
Question 730: Which of the following is not a property of the Rijndael blo...
Question 731: Which of the following items is NOT a benefit of cold sites?...
Question 732: The DES algorithm is an example of what type of cryptography...
Question 733: The Logical Link Control sub-layer is a part of which of the...
Question 734: Another name for a VPN is a:
Question 735: The RSA Algorithm uses which mathematical concept as the bas...
Question 736: Which of the following describes the major disadvantage of m...
Question 737: Which disaster recovery plan test involves functional repres...
Question 738: The fact that a network-based IDS reviews packets payload an...
Question 739: Which of the following statements pertaining to RADIUS is in...
Question 740: Which of the following is the act of performing tests and ev...
Question 741: A host-based IDS is resident on which of the following?...
Question 742: What does the (star) integrity axiom mean in the Biba model?...
Question 743: A DMZ is also known as a
Question 744: Which of the following is the WEAKEST authentication mechani...
Question 745: What is NOT an authentication method within IKE and IPsec?...
Question 746: Which of the following is NOT a common backup method?...
Question 747: Which of the following offers confidentiality to an e-mail m...
Question 748: In the Open Systems Interconnect (OSI) Reference Model, at w...
Question 749: What is the name of the third party authority that vouches f...
Question 750: Which of the following is the best reason for the use of an ...
Question 751: Passwords can be required to change monthly, quarterly, or a...
Question 752: Which of the following are required for Life-Cycle Assurance...
Question 753: What layer of the ISO/OSI model do routers normally operate ...
Question 754: Which of the following should NOT normally be allowed throug...
Question 755: Which of the following is given the responsibility of the ma...
Question 756: One of the following assertions is NOT a characteristic of I...
Question 757: Which of the following statements pertaining to access contr...
Question 758: In SSL/TLS protocol, what kind of authentication is supporte...
Question 759: A deviation from an organization-wide security policy requir...
Question 760: What is the name for a substitution cipher that shifts the a...
Question 761: What uses a key of the same length as the message where each...
Question 762: What is the goal of the Maintenance phase in a common develo...
Question 763: Because all the secret keys are held and authentication is p...
Question 764: A group of independent servers, which are managed as a singl...
Question 765: A central authority determines what subjects can have access...
Question 766: What kind of encryption is realized in the S/MIME-standard?...
Question 767: What is the role of IKE within the IPsec protocol?...
Question 768: Which of the following is NOT a symmetric key algorithm?...
Question 769: Which xDSL flavour, appropriate for home or small offices, d...
Question 770: Which of the following is NOT true of the Kerberos protocol?...
Question 771: What is the difference between Advisory and Regulatory secur...
Question 772: Which of the following is immune to the effects of electroma...
Question 773: Secure Sockets Layer (SSL) is very heavily used for protecti...
Question 774: Which xDSL flavour can deliver up to 52 Mbps downstream over...
Question 775: The high availability of multiple all-inclusive, easy-to-use...
Question 776: Which of the following type of cryptography is used when bot...
Question 777: Which of the following computer design approaches is based o...
Question 778: A common way to create fault tolerance with leased lines is ...
Question 779: Who can best decide what are the adequate technical security...
Question 780: An attack initiated by an entity that is authorized to acces...
Question 781: Which of the following best describes the purpose of debuggi...
Question 782: In non-discretionary access control using Role Based Access ...
Question 783: In telephony different types of connections are being used. ...
Question 784: What is the PRIMARY use of a password?...
Question 785: Which OSI/ISO layer is the Media Access Control (MAC) sublay...
Question 786: Which of the following is most concerned with personnel secu...
Question 787: Which of the following best describes what would be expected...
Question 788: For which areas of the enterprise are business continuity pl...
Question 789: A Security Kernel is defined as a strict implementation of a...
Question 790: Which of the following best allows risk management results t...
Question 791: Which of the following questions is less likely to help in a...
Question 792: Which of the following backup sites is the most effective fo...
Question 793: Which TCSEC class specifies discretionary protection?...
Question 794: A circuit level proxy is ___________________ when compared t...
Question 795: Which of the following is an example of a passive attack?...
Question 796: Which of the following is best provided by symmetric cryptog...
Question 797: Which of the following is not a security goal for remote acc...
Question 798: Which of the following steps should be one of the first step...
Question 799: Which of the following DoD Model layer provides non-repudiat...
Question 800: Which of the following is the FIRST step in protecting data'...
Question 801: Which of the following backup methods makes a complete backu...
Question 802: Which ISO/OSI layer establishes the communications link betw...
Question 803: A weakness or lack of a safeguard, which may be exploited by...
Question 804: Which access control model would a lattice-based access cont...
Question 805: What protocol is used to match an IP address to the appropri...
Question 806: Which of the following service is not provided by a public k...
Question 807: Network cabling comes in three flavors, they are:...
Question 808: What is electronic vaulting?
Question 809: During which phase of an IT system life cycle are security r...
Question 810: Which of the following rules pertaining to a Business Contin...
Question 811: Which of the following would be LESS likely to prevent an em...
Question 812: Which of the following is best defined as a mode of system t...
Question 813: The basic language of modems and dial-up remote access syste...
Question 814: Under the principle of culpable negligence, executives can b...
Question 815: The primary purpose for using one-way hashing of user passwo...
Question 816: Which of the following is unlike the other three choices pre...
Question 817: Which of the following should be emphasized during the Busin...
Question 818: What is the maximum key size for the RC5 algorithm?...
Question 819: Which of the following results in the most devastating busin...
Question 820: Which of the following is NOT a known type of Message Authen...
Question 821: Application Layer Firewalls operate at the:...
Question 822: In regards to information classification what is the main re...
Question 823: How many layers are defined within the US Department of Defe...
Question 824: Valuable paper insurance coverage does not cover damage to w...
Question 825: What are called user interfaces that limit the functions tha...
Question 826: In biometric identification systems, at the beginning, it wa...
Question 827: Risk mitigation and risk reduction controls for providing in...
Question 828: Which of the following is the core of fiber optic cables mad...
Question 829: Which of the following categories of hackers poses the great...
Question 830: What is the appropriate role of the security analyst in the ...
Question 831: What can best be described as a domain of trust that shares ...
Question 832: Which is NOT a suitable method for distributing certificate ...
Question 833: What algorithm was DES derived from?...
Question 834: Which of the following is a set of data processing elements ...
Question 835: What can be defined as an instance of two different keys gen...
Question 836: What can be best defined as the examination of threat source...
Question 837: How often should tests and disaster recovery drills be perfo...
Question 838: Which of the following is less likely to be used today in cr...
Question 839: Which of the following can be defined as a framework that su...
Question 840: A 'Pseudo flaw' is which of the following?...
Question 841: Which authentication technique best protects against hijacki...
Question 842: Which of the following protects Kerberos against replay atta...
Question 843: What is a common problem when using vibration detection devi...
Question 844: Which access control model achieves data integrity through w...
Question 845: Which of the following is NOT a factor related to Access Con...
Question 846: What is the most critical characteristic of a biometric iden...
Question 847: In what type of attack does an attacker try, from several en...
Question 848: When it comes to magnetic media sanitization, what differenc...
Question 849: Failure of a contingency plan is usually:...
Question 850: Which of the following can best be defined as a cryptanalysi...
Question 851: Which of the following is NOT an asymmetric key algorithm?...
Question 852: In the process of gathering evidence from a computer attack,...
Question 853: Controls like guards and general steps to maintain building ...
Question 854: Which protocol is used to send email?...
Question 855: An area of the Telecommunications and Network Security domai...
Question 856: Which of the following is a CHARACTERISTIC of a decision sup...
Question 857: Which of the following can best eliminate dial-up access thr...
Question 858: Which of the following is a tool often used to reduce the ri...
Question 859: Devices that supply power when the commercial utility power ...
Question 860: A variation of the application layer firewall is called a:...
Question 861: What enables users to validate each other's certificate when...
Question 862: The number of violations that will be accepted or forgiven b...
Question 863: Which of the following is considered the weakest link in a s...
Question 864: When a biometric system is used, which error type deals with...
Question 865: Organizations should not view disaster recovery as which of ...
Question 866: Which of the following is used in database information secur...
Question 867: A proxy can control which services (FTP and so on) are used ...
Question 868: What refers to legitimate users accessing networked services...
Question 869: Under the Business Exemption Rule to the hearsay evidence, w...
Question 870: Related to information security, the prevention of the inten...
Question 871: Which of the following offers security to wireless communica...
Question 872: A business continuity plan should list and prioritize the se...
Question 873: During the salvage of the Local Area Network and Servers, wh...
Question 874: When backing up an applications system's data, which of the ...
Question 875: Which type of encryption is considered to be unbreakable if ...
Question 876: If an organization were to monitor their employees' e-mail, ...
Question 877: The concept of best effort delivery is best associated with?...
Question 878: What is NOT an authentication method within IKE and IPsec?...
Question 879: Which of the following OSI layers provides routing and relat...
Question 880: What is a characteristic of using the Electronic Code Book m...
Question 881: A periodic review of user account management should not dete...
Question 882: Which of the following is often the greatest challenge of di...
Question 883: What best describes a scenario when an employee has been sha...
Question 884: Which of the following statements pertaining to Asynchronous...
Question 885: Which OSI/ISO layers are TCP and UDP implemented at?...
Question 886: Which of the following is used to interrupt the opportunity ...
Question 887: What is Kerberos?
Question 888: Which of the following statements pertaining to a Criticalit...
Question 889: What does "System Integrity" mean?...
Question 890: Which IPSec operational mode encrypts the entire data packet...
Question 891: Which of the following is the BEST way to detect software li...
Question 892: Which of the following would be the best reason for separati...
Question 893: Which software development model is actually a meta-model th...
Question 894: Several analysis methods can be employed by an IDS, each wit...
Question 895: Which of the following ports does NOT normally need to be op...
Question 896: Which port does the Post Office Protocol Version 3 (POP3) ma...
Question 897: Which of the following is an advantage in using a bottom-up ...
Question 898: Which of the following issues is not addressed by digital si...
Question 899: What are the three FUNDAMENTAL principles of security?...
Question 900: What enables a workstation to boot without requiring a hard ...
Question 901: The computations involved in selecting keys and in encipheri...
Question 902: What can be defined as: It confirms that users' needs have b...
Question 903: Which of the following is NOT a system-sensing wireless prox...
Question 904: What is called the type of access control where there are pa...
Question 905: Pin, Password, Passphrases, Tokens, smart cards, and biometr...
Question 906: Which of the following is the primary security feature of a ...
Question 907: Proxies works by transferring a copy of each accepted data p...
Question 908: Which of the following describes a computer processing archi...
Question 909: Recovery Site Strategies for the technology environment depe...
Question 910: Which of the following is not one of the three goals of Inte...
Question 911: Which of the following tools is less likely to be used by a ...
Question 912: Which of the following statements pertaining to key manageme...
Question 913: What can be defined as a data structure that enumerates digi...
Question 914: Which of the following choices describe a condition when RAM...
Question 915: A prolonged high voltage is a:
Question 916: An access system that grants users only those rights necessa...
Question 917: Which of the following are WELL KNOWN PORTS assigned by the ...
Question 918: Which of the following is responsible for MOST of the securi...
Question 919: Which of the following computer recovery sites is the least ...
Question 920: Which of the following protects Kerberos against replay atta...
Question 921: Examples of types of physical access controls include all EX...
Question 922: How many bits is the effective length of the key of the Data...
Question 923: What can be defined as a digital certificate that binds a se...
Question 924: How would an IP spoofing attack be best classified?...
Question 925: Which of the following control pairings include: organizatio...
Question 926: Which of the following enables the person responsible for co...
Question 927: Which of the following statements pertaining to VPN protocol...
Question 928: Which of the following are NOT a countermeasure to traffic a...
Question 929: Who is responsible for implementing user clearances in compu...
Question 930: Which of the following is an example of a connectionless com...
Question 931: What is the main purpose of Corporate Security Policy?...
Question 932: Which of the following is NOT a part of a risk analysis?...
Question 933: Which type of attack involves hijacking a session between a ...
Question 934: Which of the following protocols is not implemented at the I...
Question 935: You are running a packet sniffer on a network and see a pack...
Question 936: Which of the following access control techniques best gives ...
Question 937: Which of the following is NOT a task normally performed by a...
Question 938: Which of the following best describes signature-based detect...
Question 939: Why does fiber optic communication technology have significa...
Question 940: Which of the following statements pertaining to firewalls is...
Question 941: One of these statements about the key elements of a good con...
Question 942: Which of the following refers to the data left on the media ...
Question 943: To understand the 'whys' in crime, many times it is necessar...
Question 944: Which TCSEC level is labeled Controlled Access Protection?...
Question 945: Due care is not related to:
Question 946: Technical controls such as encryption and access control can...
Question 947: What is the act of obtaining information of a higher sensiti...
Question 948: Which of the following does NOT use token-passing?...
Question 949: The deliberate planting of apparent flaws in a system for th...
Question 950: Which of the following is true about link encryption?...
Question 951: Which common backup method is the fastest on a daily basis?...
Question 952: Which of the following access control models requires defini...
Question 953: Which of the following test makes sure the modified or new s...
Question 954: What is a hot-site facility?
Question 955: When considering an IT System Development Life-cycle, securi...
Question 956: What is the 802.11 standard related to?...
Question 957: Secure Electronic Transaction (SET) and Secure HTTP (S-HTTP)...
Question 958: Which of the following is a telecommunication device that tr...
Question 959: What is called an attack in which an attacker floods a syste...
Question 960: Which of the following access control models introduces user...
Question 961: Which of the following is true about link encryption?...
Question 962: Which of the following would be the best criterion to consid...
Question 963: Which of the following statements relating to the Bell-LaPad...
Question 964: Risk reduction in a system development life-cycle should be ...
Question 965: Who developed one of the first mathematical models of a mult...
Question 966: In Discretionary Access Control the subject has authority, w...
Question 967: One purpose of a security awareness program is to modify:...
Question 968: Which of the following questions are least likely to help in...
Question 969: Which access control model was proposed for enforcing access...
Question 970: Which of the following statements pertaining to disaster rec...
Question 971: What can be described as an imaginary line that separates th...
Question 972: Which of the following can prevent hijacking of a web sessio...
Question 973: Secure Shell (SSH) is a strong method of performing:...
Question 974: Which of the following protocols does not operate at the dat...
Question 975: What is called the probability that a threat to an informati...
Question 976: Which of the following addresses a portion of the primary me...
Question 977: Which of the following is not a component of a Operations Se...
Question 978: Organizations should consider which of the following first b...
Question 979: Business Continuity and Disaster Recovery Planning (Primaril...
Question 980: Which of the following protocols' primary function is to sen...
Question 981: What does the directive of the European Union on Electronic ...
Question 982: In the context of access control, locks, gates, guards are e...
Question 983: Which of the following statements is NOT true of IPSec Trans...
Question 984: Which of the following security mode of operation does NOT r...
Question 985: Which of the following BEST explains why computerized inform...
Question 986: Secure Shell (SSH-2) provides all the following services exc...
Question 987: Which of the following are the steps usually followed in the...
Question 988: Which security model introduces access to objects only throu...
Question 989: Which of the following is best defined as an administrative ...
Question 990: Controls provide accountability for individuals who are acce...
Question 991: Which one of the following is usually not a benefit resultin...
Question 992: Which of the following phases of a system development life-c...
Question 993: What type of cable is used with 100Base-TX Fast Ethernet?...
Question 994: Kerberos depends upon what encryption method?...
Question 995: The IP header contains a protocol field. If this field conta...
Question 996: Related to information security, availability is the opposit...
Question 997: It is a violation of the "separation of duties" principle wh...
Question 998: Which of the following statements is most accurate regarding...
Question 999: Under United States law, an investigator's notebook may be u...
Question 1000: When attempting to establish Liability, which of the followi...