<< Prev Question Next Question >>

Question 685/1000

In computing what is the name of a non-self-replicating type of malware program containing malicious code that appears to have some useful purpose but also contains code that has a malicious or harmful purpose imbedded in it, when executed, carries out actions that are unknown to the person installing it, typically causing loss or theft of data, and possible system harm.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (1000q)
Question 1: What is the name of the protocol use to set up and manage Se...
Question 2: Which of the following statements is true about data encrypt...
Question 3: Which of the following can best define the "revocation reque...
Question 4: What is a TFTP server most useful for?...
Question 5: Which of the following models does NOT include data integrit...
Question 6: Most access violations are:
Question 7: What can be defined as a value computed with a cryptographic...
Question 8: What is the role of IKE within the IPsec protocol?...
Question 9: Which of the following biometric devices has the lowest user...
Question 10: Which of the following would BEST be defined as an absence o...
Question 11: The IP header contains a protocol field. If this field conta...
Question 12: Which of the following statements pertaining to a security p...
Question 13: Which of the following is the LEAST user accepted biometric ...
Question 14: What mechanism automatically causes an alarm originating in ...
Question 15: Virus scanning and content inspection of SMIME encrypted e-m...
Question 16: Whose role is it to assign classification level to informati...
Question 17: Which of the following is true about digital certificate?...
Question 18: Asynchronous Communication transfers data by sending:...
Question 19: Which type of control is concerned with restoring controls?...
Question 20: What is used to protect programs from all unauthorized modif...
Question 21: Which of the following devices enables more than one signal ...
Question 22: In which of the following model are Subjects and Objects ide...
Question 23: Which of the following would be used to detect and correct e...
Question 24: Which of the following layers provides end-to-end data trans...
Question 25: The type of discretionary access control (DAC) that is based...
Question 26: Which of the following would be true about Static password t...
Question 27: Which of the following service is a distributed database tha...
Question 28: Which of the following is most appropriate to notify an inte...
Question 29: What would be the name of a Logical or Virtual Table dynamic...
Question 30: Which of the following is most affected by denial-of-service...
Question 31: The Secure Hash Algorithm (SHA-1) creates:...
Question 32: What is defined as the hardware, firmware and software eleme...
Question 33: What is a decrease in amplitude as a signal propagates along...
Question 34: Which one of the following is used to provide authentication...
Question 35: Which of the following can be defined as an Internet protoco...
Question 36: Configuration Management controls what?...
Question 37: Physically securing backup tapes from unauthorized access is...
Question 38: A momentary low voltage, from 1 cycle to a few seconds, is a...
Question 39: The National Institute of Standards and Technology (NIST) st...
Question 40: Why is Network File System (NFS) used?...
Question 41: Which of the following is less likely to be used today in cr...
Question 42: Which of the following is not a preventive login control?...
Question 43: Which of the following is not a responsibility of an informa...
Question 44: If any server in the cluster crashes, processing continues t...
Question 45: Which of the following statements pertaining to disk mirrori...
Question 46: Which of the following is not a disadvantage of symmetric cr...
Question 47: What size is an MD5 message digest (hash)?...
Question 48: The scope and focus of the Business continuity plan developm...
Question 49: Which of the following encryption algorithms does not deal w...
Question 50: Which layer of the TCP/IP protocol stack corresponds to the ...
Question 51: Which of the following is the most important consideration i...
Question 52: What is called a sequence of characters that is usually long...
Question 53: Which backup method is additive because the time and tape sp...
Question 54: In Synchronous dynamic password tokens:...
Question 55: Which of the following type of traffic can easily be filtere...
Question 56: Which of the following can be used as a covert channel?...
Question 57: How would nonrepudiation be best classified as?...
Question 58: Which of the following would assist the most in Host Based i...
Question 59: In what way could Java applets pose a security threat?...
Question 60: Which of the following is an issue with signature-based intr...
Question 61: Which of the following would be an example of the best passw...
Question 62: Which of the following algorithms does NOT provide hashing?...
Question 63: Which one of the following represents an ALE calculation?...
Question 64: Which of the following protocols is designed to send individ...
Question 65: What is called the use of technologies such as fingerprint, ...
Question 66: For maximum security design, what type of fence is most effe...
Question 67: Kerberos can prevent which one of the following attacks?...
Question 68: What security model implies a central authority that define ...
Question 69: What is called the verification that the user's claimed iden...
Question 70: All hosts on an IP network have a logical ID called a(n):...
Question 71: As per RFC 1122, which of the following is not a defined lay...
Question 72: What can be defined as the maximum acceptable length of time...
Question 73: Which of the following is an advantage that UDP has over TCP...
Question 74: This type of attack is generally most applicable to public-k...
Question 75: Which of the following is not a one-way hashing algorithm?...
Question 76: Which of the following does not address Database Management ...
Question 77: What is the maximum allowable key size of the Rijndael encry...
Question 78: The number of violations that will be accepted or forgiven b...
Question 79: What is the RESULT of a hash algorithm being applied to a me...
Question 80: Which of the following was developed to address some of the ...
Question 81: What is called an exception to the search warrant requiremen...
Question 82: Which of the following tasks is NOT usually part of a Busine...
Question 83: Which of the following is the most reliable, secure means of...
Question 84: Which of the following can be defined as the process of reru...
Question 85: Which of the following concerning the Rijndael block cipher ...
Question 86: Attributes that characterize an attack are stored for refere...
Question 87: Which of the following is defined as an Internet, IPsec, key...
Question 88: To be admissible in court, computer evidence must be which o...
Question 89: Which of the following questions is less likely to help in a...
Question 90: The session layer provides a logical persistent connection b...
Question 91: Upon which of the following ISO/OSI layers does network addr...
Question 92: Which of the following statements pertaining to the Bell-LaP...
Question 93: An alternative to using passwords for authentication in logi...
Question 94: Why do buffer overflows happen? What is the main cause?...
Question 95: Which layer of the TCP/IP protocol model would best correspo...
Question 96: You work in a police department forensics lab where you exam...
Question 97: Which of the following questions is less likely to help in a...
Question 98: Which of the following ciphers is a subset on which the Vige...
Question 99: Risk analysis is MOST useful when applied during which phase...
Question 100: Packet Filtering Firewalls examines both the source and dest...
Question 101: Which layer of the OSI/ISO model handles physical addressing...
Question 102: Sensitivity labels are an example of what application contro...
Question 103: Controls to keep password sniffing attacks from compromising...
Question 104: Who should measure the effectiveness of Information System s...
Question 105: Which of the following describes a technique in which a numb...
Question 106: When preparing a business continuity plan, who of the follow...
Question 107: Which backup method is used if backup time is critical and t...
Question 108: Which of the following choice is NOT normally part of the qu...
Question 109: Which of the following reviews system and event logs to dete...
Question 110: What is defined as the manner in which the network devices a...
Question 111: Authentication Headers (AH) and Encapsulating Security Paylo...
Question 112: External consistency ensures that the data stored in the dat...
Question 113: Access Control techniques do not include which of the follow...
Question 114: Which of the following centralized access control mechanisms...
Question 115: What is called an attack where the attacker spoofs the sourc...
Question 116: If your property Insurance has Actual Cash Valuation (ACV) c...
Question 117: When a possible intrusion into your organization's informati...
Question 118: Which of the following Operation Security controls is intend...
Question 119: Which approach to a security program ensures people responsi...
Question 120: Compared to RSA, which of the following is true of Elliptic ...
Question 121: Which of the following is most likely to be useful in detect...
Question 122: What is malware that can spread itself over open network con...
Question 123: Computer-generated evidence is considered:...
Question 124: Why is traffic across a packet switched network difficult to...
Question 125: In the context of network enumeration by an outside attacker...
Question 126: Which of the following is an example of discretionary access...
Question 127: The Clipper Chip utilizes which concept in public key crypto...
Question 128: What is the greatest danger from DHCP?...
Question 129: What is called the percentage of valid subjects that are fal...
Question 130: Which of the following statements pertaining to PPTP (Point-...
Question 131: A timely review of system access audit records would be an e...
Question 132: Which of the following statements pertaining to software tes...
Question 133: In order to ensure the privacy and integrity of the data, co...
Question 134: What would be the Annualized Rate of Occurrence (ARO) of the...
Question 135: Which of the following is the biggest concern with firewall ...
Question 136: What is considered the most important type of error to avoid...
Question 137: When should a post-mortem review meeting be held after an in...
Question 138: Making sure that the data has not been changed unintentional...
Question 139: Which of the following monitors network traffic in real time...
Question 140: Which of the following elements of telecommunications is not...
Question 141: What is a packet sniffer?
Question 142: Which of the following is NOT a characteristic of a host-bas...
Question 143: What does the (star) property mean in the Bell-LaPadula mode...
Question 144: Which of the following phases of a system development life-c...
Question 145: Because ordinary cable introduces a toxic hazard in the even...
Question 146: Logical or technical controls involve the restriction of acc...
Question 147: Controlling access to information systems and associated net...
Question 148: When we encrypt or decrypt data there is a basic operation i...
Question 149: Which of the following identifies the encryption algorithm s...
Question 150: Which of the following exemplifies proper separation of duti...
Question 151: Which of the following media is MOST resistant to EMI interf...
Question 152: In a SSL session between a client and a server, who is respo...
Question 153: Which of the following LAN topologies offers the highest ava...
Question 154: What can best be defined as the detailed examination and tes...
Question 155: Which protocol makes USE of an electronic wallet on a custom...
Question 156: Which of the following cryptographic attacks describes when ...
Question 157: Which of the following access control models is based on sen...
Question 158: Which of the following access methods is used by Ethernet?...
Question 159: Which of the following is a symmetric encryption algorithm?...
Question 160: Which of the following usually provides reliable, real-time ...
Question 161: Which of the following rules is least likely to support the ...
Question 162: Which device acting as a translator is used to connect two n...
Question 163: The Information Technology Security Evaluation Criteria (ITS...
Question 164: Which of the following are REGISTERED PORTS as defined by IA...
Question 165: Which of the following is a problem regarding computer inves...
Question 166: Which of the following is the most reliable authentication m...
Question 167: Which of the following are not Remote Access concerns?...
Question 168: What is the proper term to refer to a single unit of Etherne...
Question 169: Which access model is most appropriate for companies with a ...
Question 170: Which of the following answers is described as a random valu...
Question 171: This type of supporting evidence is used to help prove an id...
Question 172: What can be defined as a batch process dumping backup data t...
Question 173: Another type of access control is lattice-based access contr...
Question 174: Which element must computer evidence have to be admissible i...
Question 175: Which of the following does NOT concern itself with key mana...
Question 176: Which of the following protects a password from eavesdropper...
Question 177: Which of the following classes is defined in the TCSEC (Oran...
Question 178: Which of the following is the most secure form of triple-DES...
Question 179: A business continuity plan is an example of which of the fol...
Question 180: Which of the following technologies has been developed to su...
Question 181: Which of the following is the simplest type of firewall ?...
Question 182: Computer security should be first and foremost which of the ...
Question 183: Which of the following is an unintended communication path t...
Question 184: The Diffie-Hellman algorithm is used for:...
Question 185: The information security staff's participation in which of t...
Question 186: Which of the following logical access exposures INVOLVES CHA...
Question 187: If an employee's computer has been used by a fraudulent empl...
Question 188: Why is infrared generally considered to be more secure to ea...
Question 189: Why does compiled code pose more of a security risk than int...
Question 190: Encapsulating Security Payload (ESP) provides some of the se...
Question 191: Which of the following is addressed by Kerberos?...
Question 192: The preliminary steps to security planning include all of th...
Question 193: Which of the following is a trusted, third party authenticat...
Question 194: What is NOT true with pre shared key authentication within I...
Question 195: Which of the following is implemented through scripts or sma...
Question 196: A security evaluation report and an accreditation statement ...
Question 197: Which of the following services is NOT provided by the digit...
Question 198: Which of the following steps is NOT one of the eight detaile...
Question 199: Which of the following standards is concerned with message h...
Question 200: When referring to a computer crime investigation, which of t...
Question 201: Which of the following elements is NOT included in a Public ...
Question 202: Making sure that only those who are supposed to access the d...
Question 203: Which of the following describes a logical form of separatio...
Question 204: The controls that usually require a human to evaluate the in...
Question 205: What is the main characteristic of a bastion host?...
Question 206: Which of the following is NOT a defined ISO basic task relat...
Question 207: Complete the blanks. When using PKI, I digitally sign a mess...
Question 208: Which of the following statements pertaining to message dige...
Question 209: Which of the following networking devices allows the connect...
Question 210: Which of the following is not appropriate in addressing obje...
Question 211: Which of the following would best classify as a management c...
Question 212: Which access control model is best suited in an environment ...
Question 213: Which of the following binds a subject name to a public key ...
Question 214: What works as an E-mail message transfer agent?...
Question 215: Which of the following is true about Kerberos?...
Question 216: Which of the following is NOT a compensating measure for acc...
Question 217: Which of the following services relies on UDP?...
Question 218: The RSA algorithm is an example of what type of cryptography...
Question 219: Which of the following best corresponds to the type of memor...
Question 220: When a station communicates on the network for the first tim...
Question 221: Which type of password provides maximum security because a n...
Question 222: What is the main objective of proper separation of duties?...
Question 223: Which of the following are additional access control objecti...
Question 224: Which of the following Intrusion Detection Systems (IDS) use...
Question 225: Which of the following outlined how senior management are re...
Question 226: Which of the following protocols operates at the session lay...
Question 227: Of the following, which is NOT a specific loss criteria that...
Question 228: Which xDSL flavour delivers both downstream and upstream spe...
Question 229: Which of the following is needed for System Accountability?...
Question 230: Rule-Based Access Control (RuBAC) access is determined by ru...
Question 231: Which of the following forms of authentication would most li...
Question 232: Java is not:
Question 233: Which of the following is NOT a property of a one-way hash f...
Question 234: What is called an event or activity that has the potential t...
Question 235: In the statement below, fill in the blank: Law enforcement a...
Question 236: Which of the following is an IP address that is private (i.e...
Question 237: Which of the following is BEST defined as a physical control...
Question 238: An effective information security policy should not have whi...
Question 239: Which of the following is used to monitor network traffic or...
Question 240: A trusted system does NOT involve which of the following?...
Question 241: What is defined as the rules for communicating between compu...
Question 242: Which is the last line of defense in a physical security sen...
Question 243: Like the Kerberos protocol, SESAME is also subject to which ...
Question 244: Considerations of privacy, invasiveness, and psychological a...
Question 245: The IP header contains a protocol field. If this field conta...
Question 246: In biometric identification systems, the parts of the body c...
Question 247: Remote Procedure Call (RPC) is a protocol that one program c...
Question 248: Which of the following is not a two-factor authentication me...
Question 249: Which division of the Orange Book deals with discretionary p...
Question 250: Which of the following floors would be most appropriate to l...
Question 251: Which of the following tools is NOT likely to be used by a h...
Question 252: Which of following is not a service provided by AAA servers ...
Question 253: Layer 4 of the OSI stack is known as:...
Question 254: Which type of password token involves time synchronization?...
Question 255: What is the effective key size of DES?...
Question 256: Which of the following is true about Kerberos?...
Question 257: The "vulnerability of a facility" to damage or attack may be...
Question 258: The Terminal Access Controller Access Control System (TACACS...
Question 259: How many rounds are used by DES?...
Question 260: Which protocol is NOT implemented in the Network layer of th...
Question 261: Which of the following is NOT true concerning Application Co...
Question 262: What is called the percentage at which the False Rejection R...
Question 263: What is the primary role of smartcards in a PKI?...
Question 264: What are the three most important functions that Digital Sig...
Question 265: Which of the following security models does NOT concern itse...
Question 266: If your property Insurance has Replacement Cost Valuation (R...
Question 267: At what stage of the applications development process should...
Question 268: Packet Filtering Firewalls can also enable access for:...
Question 269: The IP header contains a protocol field. If this field conta...
Question 270: Which security model is based on the military classification...
Question 271: Which of the following would be best suited to oversee the d...
Question 272: Identification and authentication are the keystones of most ...
Question 273: How are memory cards and smart cards different?...
Question 274: In which of the following security models is the subject's c...
Question 275: Which of the following is NOT a type of motion detector?...
Question 276: What can be defined as an event that could cause harm to the...
Question 277: In this type of attack, the intruder re-routes data traffic ...
Question 278: Which must bear the primary responsibility for determining t...
Question 279: Why would anomaly detection IDSs often generate a large numb...
Question 280: Which of the following is not a method to protect objects an...
Question 281: Who should DECIDE how a company should approach security and...
Question 282: Degaussing is used to clear data from all of the following m...
Question 283: Which of the following can best be defined as a key distribu...
Question 284: Almost all types of detection permit a system's sensitivity ...
Question 285: Which of the following was designed to support multiple netw...
Question 286: Making sure that the data is accessible when and where it is...
Question 287: Which of the following is less likely to accompany a conting...
Question 288: The communications products and services, which ensure that ...
Question 289: Which of the following is commonly used for retrofitting mul...
Question 290: How often should a Business Continuity Plan be reviewed?...
Question 291: In which layer of the OSI Model are connection-oriented prot...
Question 292: Which of the following backup methods is most appropriate fo...
Question 293: PGP uses which of the following to encrypt data?...
Question 294: Which of the following is NOT a basic component of security ...
Question 295: What is the most correct choice below when talking about the...
Question 296: In order to enable users to perform tasks and duties without...
Question 297: Which of the following questions is less likely to help in a...
Question 298: What would BEST define a covert channel?...
Question 299: Which of the following is a token-passing scheme like token ...
Question 300: In biometrics, the "one-to-one" search used to verify claim ...
Question 301: The International Standards Organization / Open Systems Inte...
Question 302: How should a doorway of a manned facility with automatic loc...
Question 303: Which type of algorithm is considered to have the highest st...
Question 304: A contingency plan should address:...
Question 305: At which layer of ISO/OSI does the fiber optics work?...
Question 306: Controls provide accountability for individuals who are acce...
Question 307: What can best be described as an abstract machine which must...
Question 308: Which of the following focuses on sustaining an organization...
Question 309: What is the essential difference between a self-audit and an...
Question 310: Which of the following best defines add-on security?...
Question 311: What is an IP routing table?
Question 312: Which of the following is NOT part of the Kerberos authentic...
Question 313: Which of the following technologies is a target of XSS or CS...
Question 314: A server cluster looks like a:
Question 315: Which of the following would MOST likely ensure that a syste...
Question 316: What is the main problem of the renewal of a root CA certifi...
Question 317: FTP, TFTP, SNMP, and SMTP are provided at what level of the ...
Question 318: Which of the following statements regarding an off-site info...
Question 319: When you update records in multiple locations or you make a ...
Question 320: Which of the following is NOT a common integrity goal?...
Question 321: Which type of attack is based on the probability of two diff...
Question 322: Which of the following is an advantage of prototyping?...
Question 323: After a company is out of an emergency state, what should be...
Question 324: What mechanism does a system use to compare the security lab...
Question 325: Which of the following is NOT a correct notation for an IPv6...
Question 326: What is called the formal acceptance of the adequacy of a sy...
Question 327: Which of the following is not an example of a block cipher?...
Question 328: What assesses potential loss that could be caused by a disas...
Question 329: Unshielded Twisted Pair (UTP) cables comes in several catego...
Question 330: Which of the following would provide the BEST stress testing...
Question 331: Which of the following cannot be undertaken in conjunction o...
Question 332: Which of the following is related to physical security and i...
Question 333: What is the PRIMARY reason to maintain the chain of custody ...
Question 334: A X.509 public key certificate with the key usage attribute ...
Question 335: Memory management in TCSEC levels B3 and A1 operating system...
Question 336: A channel within a computer system or network that is design...
Question 337: Which of the following ASYMMETRIC encryption algorithms is b...
Question 338: Step-by-step instructions used to satisfy control requiremen...
Question 339: What key size is used by the Clipper Chip?...
Question 340: What is it called when a computer uses more than one CPU in ...
Question 341: What algorithm has been selected as the AES algorithm, repla...
Question 342: Which of the following is covered under Crime Insurance Poli...
Question 343: This is a common security issue that is extremely hard to co...
Question 344: The three classic ways of authenticating yourself to the com...
Question 345: Each data packet is assigned the IP address of the sender an...
Question 346: Which of the following control pairing places emphasis on "s...
Question 347: Organizations should consider which of the following first b...
Question 348: Once evidence is seized, a law enforcement officer should em...
Question 349: What does the simple integrity axiom mean in the Biba model?...
Question 350: Before the advent of classless addressing, the address 128.1...
Question 351: What is the key size of the International Data Encryption Al...
Question 352: A potential problem related to the physical installation of ...
Question 353: Which of the following would constitute the best example of ...
Question 354: In an organization where there are frequent personnel change...
Question 355: Which communication method is characterized by very high spe...
Question 356: What can best be defined as a strongly protected computer th...
Question 357: Which of the following was developed as a simple mechanism f...
Question 358: Which of the following best describes remote journaling?...
Question 359: What Orange Book security rating is reserved for systems tha...
Question 360: Detective/Technical measures:
Question 361: Which backup method copies only files that have changed sinc...
Question 362: Which of the following is TRUE regarding Transmission Contro...
Question 363: What is RAD?
Question 364: Which of the following would be used to implement Mandatory ...
Question 365: In the course of responding to and handling an incident, you...
Question 366: Which of the following is not a form of passive attack?...
Question 367: Which of the following statements pertaining to Kerberos is ...
Question 368: What is the primary role of cross certification?...
Question 369: What is also known as 10Base5?
Question 370: Which protocol of the TCP/IP suite addresses reliable data t...
Question 371: In what way can violation clipping levels assist in violatio...
Question 372: Related to information security, integrity is the opposite o...
Question 373: What security model is dependent on security labels?...
Question 374: What is one disadvantage of content-dependent protection of ...
Question 375: What is a limitation of TCP Wrappers?...
Question 376: Which of the following is the most secure firewall implement...
Question 377: A confidential number used as an authentication factor to ve...
Question 378: IT security measures should:
Question 379: Which of the following would best describe certificate path ...
Question 380: Access control is the collection of mechanisms that permits ...
Question 381: All following observations about IPSec are correct except:...
Question 382: The Telecommunications Security Domain of information securi...
Question 383: Attributable data should be:
Question 384: Which of the following statements pertaining to link encrypt...
Question 385: Which of the following is a LAN transmission method?...
Question 386: Which of the following are suitable protocols for securing V...
Question 387: Which of the following statements pertaining to using Kerber...
Question 388: Buffer overflow and boundary condition errors are subsets of...
Question 389: Which type of attack involves impersonating a user or a syst...
Question 390: What is NOT true about a one-way hashing function?...
Question 391: Which of the following specifically addresses cyber attacks ...
Question 392: What is the primary reason why some sites choose not to impl...
Question 393: Access Control techniques do not include which of the follow...
Question 394: Brute force attacks against encryption keys have increased i...
Question 395: What is the primary difference between FTP and TFTP?...
Question 396: Which one of the following factors is NOT one on which Authe...
Question 397: Which one of the following is NOT one of the outcomes of a v...
Question 398: A network-based vulnerability assessment is a type of test a...
Question 399: Which of the following access control models requires securi...
Question 400: Which OSI/ISO layer is responsible for determining the best ...
Question 401: Which access control model provides upper and lower bounds o...
Question 402: Which backup method does not reset the archive bit on files ...
Question 403: In addition to the Legal Department, with what company funct...
Question 404: What is the main difference between a Smurf and a Fraggle at...
Question 405: Which of the following protocol was used by the INITIAL vers...
Question 406: Which of the following transmission media would NOT be affec...
Question 407: What is the highest amount a company should spend annually o...
Question 408: What can be defined as secret communications where the very ...
Question 409: Qualitative loss resulting from the business interruption do...
Question 410: Which of the following biometric parameters are better suite...
Question 411: Which of the following is a method of multiplexing data wher...
Question 412: What is the Maximum Tolerable Downtime (MTD)?...
Question 413: Which of the following algorithms is a stream cipher?...
Question 414: What is the maximum length of cable that can be used for a t...
Question 415: Which of the following security-focused protocols has confid...
Question 416: Which of the following is the MOST important aspect relating...
Question 417: Which of the following is not a physical control for physica...
Question 418: Which of the following is a device that is used to regenerat...
Question 419: Which one of the following statements about the advantages a...
Question 420: Which of the following statements pertaining to stream ciphe...
Question 421: Which of the following is NOT a form of detective administra...
Question 422: Which of the following statements pertaining to biometrics i...
Question 423: Which of the following statements pertaining to ethical hack...
Question 424: Which layer of the DoD TCP/IP Model ensures error-free deliv...
Question 425: The control measures that are intended to reveal the violati...
Question 426: Physical security is accomplished through proper facility co...
Question 427: Which of the following remote access authentication systems ...
Question 428: Which of the following is defined as the most recent point i...
Question 429: Which of the following statements pertaining to IPSec is inc...
Question 430: Which of the following proves or disproves a specific act th...
Question 431: Which of the following statements pertaining to the security...
Question 432: How should a risk be HANDLED when the cost of the countermea...
Question 433: Which of the following backup methods is primarily run when ...
Question 434: Which encryption algorithm is BEST suited for communication ...
Question 435: Which of the following is an IP address that is private (i.e...
Question 436: Which of the following security modes of operation involves ...
Question 437: Which of the following firewall rules found on a firewall in...
Question 438: Which of the following is most relevant to determining the m...
Question 439: Cryptography does NOT help in:
Question 440: The Data Encryption Algorithm performs how many rounds of su...
Question 441: Which of the following would NOT violate the Due Diligence c...
Question 442: Which access control model is also called Non Discretionary ...
Question 443: An Architecture where there are more than two execution doma...
Question 444: Which of the following is NOT a characteristic or shortcomin...
Question 445: A one-way hash provides which of the following?...
Question 446: Prior to a live disaster test also called a Full Interruptio...
Question 447: RADIUS incorporates which of the following services?...
Question 448: Which of the following does not apply to system-generated pa...
Question 449: What kind of certificate is used to validate a user identity...
Question 450: Which of the following is NOT an advantage that TACACS+ has ...
Question 451: A copy of evidence or oral description of its contents; whic...
Question 452: In the CIA triad, what does the letter A stand for?...
Question 453: Which of the following best ensures accountability of users ...
Question 454: Which of the following is not an encryption algorithm?...
Question 455: A Business Continuity Plan should be tested:...
Question 456: The typical computer fraudsters are usually persons with whi...
Question 457: What is called the access protection system that limits conn...
Question 458: Good security is built on which of the following concept?...
Question 459: Which of the following is most appropriate to notify an exte...
Question 460: What is the proper term to refer to a single unit of IP data...
Question 461: Which Network Address Translation (NAT) is the most convenie...
Question 462: Which of the following Kerberos components holds all users' ...
Question 463: Which of the following phases of a software development life...
Question 464: An application layer firewall is also called a:...
Question 465: Which of the following exemplifies proper separation of duti...
Question 466: Within the context of the CBK, which of the following provid...
Question 467: ICMP and IGMP belong to which layer of the OSI model?...
Question 468: Which one of the following authentication mechanisms creates...
Question 469: The first step in the implementation of the contingency plan...
Question 470: What are the components of an object's sensitivity label?...
Question 471: Which type of attack involves impersonating a user or a syst...
Question 472: Unshielded Twisted Pair cabling is a:...
Question 473: How is Annualized Loss Expectancy (ALE) derived from a threa...
Question 474: In a known plaintext attack, the cryptanalyst has knowledge ...
Question 475: A DMZ is located:
Question 476: What would be considered the biggest drawback of Host-based ...
Question 477: What does the Clark-Wilson security model focus on?...
Question 478: Which of the following is NOT an administrative control?...
Question 479: Which integrity model defines a constrained data item, an in...
Question 480: Which of the following statements do not apply to a hot site...
Question 481: Which of the following is best at defeating frequency analys...
Question 482: The throughput rate is the rate at which individuals, once e...
Question 483: In the UTP category rating, the tighter the wind:...
Question 484: What do the ILOVEYOU and Melissa virus attacks have in commo...
Question 485: The Computer Security Policy Model the Orange Book is based ...
Question 486: What is the framing specification used for transmitting digi...
Question 487: Which of the following was developed in order to protect aga...
Question 488: When first analyzing an intrusion that has just been detecte...
Question 489: In biometrics, "one-to-many" search against database of stor...
Question 490: Why should batch files and scripts be stored in a protected ...
Question 491: Which of the following is the most complete disaster recover...
Question 492: One of the following statements about the differences betwee...
Question 493: A Packet Filtering Firewall system is considered a:...
Question 494: Which of the following classes is the first level (lower) de...
Question 495: Within the OSI model, at what layer are some of the SLIP, CS...
Question 496: What can best be defined as high-level statements, beliefs, ...
Question 497: Which of the following should NOT be performed by an operato...
Question 498: Which of the following is NOT a valid reason to use external...
Question 499: Within the realm of IT security, which of the following comb...
Question 500: In Mandatory Access Control, sensitivity labels attached to ...
Question 501: In the Bell-LaPadula model, the Star-property is also called...
Question 502: Which of the following offers security to wireless communica...
Question 503: Why would a memory dump be admissible as evidence in court?...
Question 504: The absence of a safeguard, or a weakness in a system that m...
Question 505: Controls are implemented to:
Question 506: Which of the following security controls might force an oper...
Question 507: Which of the following standards concerns digital certificat...
Question 508: How do you distinguish between a bridge and a router?...
Question 509: The Diffie-Hellman algorithm is primarily used to provide wh...
Question 510: Which of the following statements pertaining to the maintena...
Question 511: Which of the following is a cryptographic protocol and infra...
Question 512: A packet containing a long string of NOP's followed by a com...
Question 513: In the days before CIDR (Classless Internet Domain Routing),...
Question 514: What security problem is most likely to exist if an operatin...
Question 515: A momentary high voltage is a:
Question 516: Which of the following is true related to network sniffing?...
Question 517: Which cable technology refers to the CAT3 and CAT5 categorie...
Question 518: Which of the following pairings uses technology to enforce a...
Question 519: What principle focuses on the uniqueness of separate objects...
Question 520: In the context of Biometric authentication, what is a quick ...
Question 521: When an outgoing request is made on a port number greater th...
Question 522: Which of the following is not a DES mode of operation?...
Question 523: Who first described the DoD multilevel military security pol...
Question 524: Where parties do not have a shared secret and large quantiti...
Question 525: In a stateful inspection firewall, data packets are captured...
Question 526: The security of a computer application is most effective and...
Question 527: Which security model ensures that actions that take place at...
Question 528: Which of the following would best describe a Concealment cip...
Question 529: Which of the following category of UTP cables is specified t...
Question 530: What kind of Encryption technology does SSL utilize?...
Question 531: A code, as is pertains to cryptography:...
Question 532: Which of the following is NOT a property of the Rijndael blo...
Question 533: The Reference Validation Mechanism that ensures the authoriz...
Question 534: Which of the following is true of two-factor authentication?...
Question 535: In an online transaction processing system (OLTP), which of ...
Question 536: The three classic ways of authenticating yourself to the com...
Question 537: Which of the following is NOT an advantage that TACACS+ has ...
Question 538: Which of the following is NOT a proper component of Media Vi...
Question 539: What is defined as inference of information from other, inte...
Question 540: Which of the following will a Business Impact Analysis NOT i...
Question 541: In addition to the accuracy of the biometric systems, there ...
Question 542: Which of the following BEST describes a function relying on ...
Question 543: What is the name of the first mathematical model of a multi-...
Question 544: What ensures that the control mechanisms correctly implement...
Question 545: What is the Biba security model concerned with?...
Question 546: Which of the following recovery plan test results would be m...
Question 547: Contracts and agreements are often times unenforceable or ha...
Question 548: Knowledge-based Intrusion Detection Systems (IDS) are more c...
Question 549: Virus scanning and content inspection of SMIME encrypted e-m...
Question 550: Who is ultimately responsible for the security of computer b...
Question 551: As a result of a risk assessment, your security manager has ...
Question 552: In which of the following phases of system development life ...
Question 553: The viewing of recorded events after the fact using a closed...
Question 554: Which of the following protocols suite does the Internet use...
Question 555: Which of the following NAT firewall translation modes offers...
Question 556: What is the primary role of smartcards in a PKI?...
Question 557: What ISO/OSI layer do switches primarily operate at? Do take...
Question 558: Frame relay uses a public switched network to provide:...
Question 559: The criteria for evaluating the legal requirements for imple...
Question 560: What is the most secure way to dispose of information on a C...
Question 561: An Intrusion Detection System (IDS) is what type of control?...
Question 562: Which type of attack would a competitive intelligence attack...
Question 563: Who can best decide what are the adequate technical security...
Question 564: Password management falls into which control category?...
Question 565: Which of the following is an extension to Network Address Tr...
Question 566: What attribute is included in a X.509-certificate?...
Question 567: Related to information security, confidentiality is the oppo...
Question 568: Which of the following computer crime is MORE often associat...
Question 569: To protect and/or restore lost, corrupted, or deleted inform...
Question 570: Which of the following protocols that provide integrity and ...
Question 571: Which of the following is used by RADIUS for communication b...
Question 572: There are parallels between the trust models in Kerberos and...
Question 573: Which expert system operating mode allows determining if a g...
Question 574: The control of communications test equipment should be clear...
Question 575: Which of the following statements pertaining to packet filte...
Question 576: When two or more separate entities (usually persons) operati...
Question 577: Which of the following packets should NOT be dropped at a fi...
Question 578: Which of the following are the two MOST common implementatio...
Question 579: Preservation of confidentiality within information systems r...
Question 580: Which of the following statements pertaining to Kerberos is ...
Question 581: Telnet and rlogin use which protocol?...
Question 582: What attack involves the perpetrator sending spoofed packet(...
Question 583: Which of the following statements pertaining to link encrypt...
Question 584: The primary service provided by Kerberos is which of the fol...
Question 585: Which of the following protection devices is used for spot p...
Question 586: Which of the following is not a logical control when impleme...
Question 587: What is the PRIMARY goal of incident handling?...
Question 588: Which of the following can best eliminate dial-up access thr...
Question 589: Which of the following is NOT a common category/classificati...
Question 590: The Orange Book states that "Hardware and software features ...
Question 591: Another example of Computer Incident Response Team (CIRT) ac...
Question 592: Communications and network security relates to transmission ...
Question 593: Which of the following is defined as a key establishment pro...
Question 594: Which of the following are suitable protocols for securing V...
Question 595: Domain Name Service is a distributed database system that is...
Question 596: What protocol is used on the Local Area Network (LAN) to obt...
Question 597: What is the primary goal of setting up a honeypot?...
Question 598: In order to be able to successfully prosecute an intruder:...
Question 599: How many bits of a MAC address uniquely identify a vendor, a...
Question 600: Which of the following would be MOST important to guarantee ...
Question 601: A department manager has read access to the salaries of the ...
Question 602: Which of the following is more suitable for a hardware imple...
Question 603: Related to information security, the guarantee that the mess...
Question 604: What is the main focus of the Bell-LaPadula security model?...
Question 605: In an organization, an Information Technology security funct...
Question 606: Which backup type run at regular intervals would take the le...
Question 607: During the testing of the business continuity plan (BCP), wh...
Question 608: Which of the following is an IP address that is private (i.e...
Question 609: Which of the following keys has the SHORTEST lifespan?...
Question 610: Which of the following statements pertaining to protection r...
Question 611: While using IPsec, the ESP and AH protocols both provides in...
Question 612: Which of the following is not a preventive operational contr...
Question 613: Which of the following is required in order to provide accou...
Question 614: Which of the following was designed as a more fault-tolerant...
Question 615: Which of the following rules appearing in an Internet firewa...
Question 616: A public key algorithm that does both encryption and digital...
Question 617: What is used to bind a document to its creation at a particu...
Question 618: Who of the following is responsible for ensuring that proper...
Question 619: The following is NOT a security characteristic we need to co...
Question 620: How can an individual/person best be identified or authentic...
Question 621: Which layer defines how packets are routed between end syste...
Question 622: In biometric identification systems, at the beginning, it wa...
Question 623: Hierarchical Storage Management (HSM) is commonly employed i...
Question 624: Which of the following is biggest factor that makes Computer...
Question 625: In a SSL session between a client and a server, who is respo...
Question 626: Which of the following attacks could capture network user pa...
Question 627: Crackers today are MOST often motivated by their desire to:...
Question 628: Which of the following is a large hardware/software backup s...
Question 629: Which of the following statements pertaining to Secure Socke...
Question 630: What kind of certificate is used to validate a user identity...
Question 631: What type of attack involves IP spoofing, ICMP ECHO and a bo...
Question 632: The property of a system or a system resource being accessib...
Question 633: In a hierarchical PKI the highest CA is regularly called Roo...
Question 634: Guards are appropriate whenever the function required by the...
Question 635: This baseline sets certain thresholds for specific errors or...
Question 636: What is the main concern with single sign-on?...
Question 637: Which of the following is best defined as a circumstance in ...
Question 638: What is the name of a one way transformation of a string of ...
Question 639: Which security model uses division of operations into differ...
Question 640: Which of the following offers advantages such as the ability...
Question 641: Ensuring least privilege does not require:...
Question 642: In discretionary access environments, which of the following...
Question 643: Which of the following choices describe a Challenge-response...
Question 644: Which of the following statements pertaining to software tes...
Question 645: Which of the following is NOT true about IPSec Tunnel mode?...
Question 646: The IP header contains a protocol field. If this field conta...
Question 647: Within the legal domain what rule is concerned with the lega...
Question 648: Which of the following assertions is NOT true about pattern ...
Question 649: Which of the following is needed for System Accountability?...
Question 650: What is called the act of a user professing an identity to a...
Question 651: Which of the following is NOT a true statement regarding the...
Question 652: Which of the following is less likely to be included in the ...
Question 653: In response to Access-request from a client such as a Networ...
Question 654: What does "residual risk" mean?...
Question 655: A prolonged complete loss of electric power is a:...
Question 656: Which access control model enables the OWNER of the resource...
Question 657: Which of the following IEEE standards defines the token ring...
Question 658: What is the main characteristic of a multi-homed host?...
Question 659: If an operating system permits shared resources such as memo...
Question 660: The major objective of system configuration management is wh...
Question 661: Which of the following would best describe secondary evidenc...
Question 662: What setup should an administrator use for regularly testing...
Question 663: Which of the following statements pertaining to disaster rec...
Question 664: Which of the following is an example of an active attack?...
Question 665: Which of the following is based on the premise that the qual...
Question 666: Which of the following is an Internet IPsec protocol to nego...
Question 667: Which of the following is a not a preventative control?...
Question 668: What would BEST define risk management?...
Question 669: Which virus category has the capability of changing its own ...
Question 670: Notifying the appropriate parties to take action in order to...
Question 671: According to private sector data classification levels, how ...
Question 672: Which of the following is NOT a transaction redundancy imple...
Question 673: Which of the following mechanisms was created to overcome th...
Question 674: Which of the following is NOT a technique used to perform a ...
Question 675: Who is responsible for initiating corrective measures and ca...
Question 676: What can be defined as a table of subjects and objects indic...
Question 677: Which SSL version offers client-side authentication?...
Question 678: Which of the following statements pertaining to biometrics i...
Question 679: Which type of control is concerned with avoiding occurrences...
Question 680: Which of the following biometric devices offers the LOWEST C...
Question 681: Which of the following best defines a Computer Security Inci...
Question 682: Which of the following phases of a software development life...
Question 683: This type of backup management provides a continuous on-line...
Question 684: Which of the following types of Intrusion Detection Systems ...
Question 685: In computing what is the name of a non-self-replicating type...
Question 686: Which of the following was developed by the National Compute...
Question 687: Which conceptual approach to intrusion detection system is t...
Question 688: Which of the following backup method must be made regardless...
Question 689: Secure Sockets Layer (SSL) uses a Message Authentication Cod...
Question 690: Which of the following algorithms is used today for encrypti...
Question 691: Which of the following statements pertaining to quantitative...
Question 692: Which of the following is an advantage of a qualitative over...
Question 693: Which of the following prevents, detects, and corrects error...
Question 694: Which of the following is NOT an example of an operational c...
Question 695: Which of the following is true of network security?...
Question 696: Which of the following are additional terms used to describe...
Question 697: Who is responsible for providing reports to the senior manag...
Question 698: All of the following can be considered essential business fu...
Question 699: What can be described as a measure of the magnitude of loss ...
Question 700: Which of the following division is defined in the TCSEC (Ora...
Question 701: What is called a password that is the same for each log-on s...
Question 702: The end result of implementing the principle of least privil...
Question 703: What is called a system that is capable of detecting that a ...
Question 704: Which of the following teams should NOT be included in an or...
Question 705: A momentary power outage is a:
Question 706: What IDS approach relies on a database of known attacks?...
Question 707: What does the simple security (ss) property mean in the Bell...
Question 708: A proxy is considered a:
Question 709: What is the maximum number of different keys that can be use...
Question 710: What is the MOST critical piece to disaster recovery and con...
Question 711: Which of the following would best describe the difference be...
Question 712: Which of the following countermeasures would be the most app...
Question 713: Business Continuity Planning (BCP) is not defined as a prepa...
Question 714: Which of the following would best define a digital envelope?...
Question 715: Which of the following biometric characteristics cannot be u...
Question 716: Similar to Secure Shell (SSH-2), Secure Sockets Layer (SSL) ...
Question 717: Communications devices must operate:...
Question 718: Which of the following is a disadvantage of a statistical an...
Question 719: In stateful inspection firewalls, packets are:...
Question 720: Which of the following remote access authentication systems ...
Question 721: At which OSI/ISO layer is an encrypted authentication betwee...
Question 722: Which of the following can be best defined as computing tech...
Question 723: Which of the following embodies all the detailed actions tha...
Question 724: The Data Encryption Standard (DES) encryption algorithm has ...
Question 725: Which of the following terms can be described as the process...
Question 726: Which OSI/ISO layer does a SOCKS server operate at?...
Question 727: Transport Layer Security (TLS) is a two-layered socket layer...
Question 728: Which of the following methods of providing telecommunicatio...
Question 729: You have been tasked to develop an effective information cla...
Question 730: Which of the following is not a property of the Rijndael blo...
Question 731: Which of the following items is NOT a benefit of cold sites?...
Question 732: The DES algorithm is an example of what type of cryptography...
Question 733: The Logical Link Control sub-layer is a part of which of the...
Question 734: Another name for a VPN is a:
Question 735: The RSA Algorithm uses which mathematical concept as the bas...
Question 736: Which of the following describes the major disadvantage of m...
Question 737: Which disaster recovery plan test involves functional repres...
Question 738: The fact that a network-based IDS reviews packets payload an...
Question 739: Which of the following statements pertaining to RADIUS is in...
Question 740: Which of the following is the act of performing tests and ev...
Question 741: A host-based IDS is resident on which of the following?...
Question 742: What does the (star) integrity axiom mean in the Biba model?...
Question 743: A DMZ is also known as a
Question 744: Which of the following is the WEAKEST authentication mechani...
Question 745: What is NOT an authentication method within IKE and IPsec?...
Question 746: Which of the following is NOT a common backup method?...
Question 747: Which of the following offers confidentiality to an e-mail m...
Question 748: In the Open Systems Interconnect (OSI) Reference Model, at w...
Question 749: What is the name of the third party authority that vouches f...
Question 750: Which of the following is the best reason for the use of an ...
Question 751: Passwords can be required to change monthly, quarterly, or a...
Question 752: Which of the following are required for Life-Cycle Assurance...
Question 753: What layer of the ISO/OSI model do routers normally operate ...
Question 754: Which of the following should NOT normally be allowed throug...
Question 755: Which of the following is given the responsibility of the ma...
Question 756: One of the following assertions is NOT a characteristic of I...
Question 757: Which of the following statements pertaining to access contr...
Question 758: In SSL/TLS protocol, what kind of authentication is supporte...
Question 759: A deviation from an organization-wide security policy requir...
Question 760: What is the name for a substitution cipher that shifts the a...
Question 761: What uses a key of the same length as the message where each...
Question 762: What is the goal of the Maintenance phase in a common develo...
Question 763: Because all the secret keys are held and authentication is p...
Question 764: A group of independent servers, which are managed as a singl...
Question 765: A central authority determines what subjects can have access...
Question 766: What kind of encryption is realized in the S/MIME-standard?...
Question 767: What is the role of IKE within the IPsec protocol?...
Question 768: Which of the following is NOT a symmetric key algorithm?...
Question 769: Which xDSL flavour, appropriate for home or small offices, d...
Question 770: Which of the following is NOT true of the Kerberos protocol?...
Question 771: What is the difference between Advisory and Regulatory secur...
Question 772: Which of the following is immune to the effects of electroma...
Question 773: Secure Sockets Layer (SSL) is very heavily used for protecti...
Question 774: Which xDSL flavour can deliver up to 52 Mbps downstream over...
Question 775: The high availability of multiple all-inclusive, easy-to-use...
Question 776: Which of the following type of cryptography is used when bot...
Question 777: Which of the following computer design approaches is based o...
Question 778: A common way to create fault tolerance with leased lines is ...
Question 779: Who can best decide what are the adequate technical security...
Question 780: An attack initiated by an entity that is authorized to acces...
Question 781: Which of the following best describes the purpose of debuggi...
Question 782: In non-discretionary access control using Role Based Access ...
Question 783: In telephony different types of connections are being used. ...
Question 784: What is the PRIMARY use of a password?...
Question 785: Which OSI/ISO layer is the Media Access Control (MAC) sublay...
Question 786: Which of the following is most concerned with personnel secu...
Question 787: Which of the following best describes what would be expected...
Question 788: For which areas of the enterprise are business continuity pl...
Question 789: A Security Kernel is defined as a strict implementation of a...
Question 790: Which of the following best allows risk management results t...
Question 791: Which of the following questions is less likely to help in a...
Question 792: Which of the following backup sites is the most effective fo...
Question 793: Which TCSEC class specifies discretionary protection?...
Question 794: A circuit level proxy is ___________________ when compared t...
Question 795: Which of the following is an example of a passive attack?...
Question 796: Which of the following is best provided by symmetric cryptog...
Question 797: Which of the following is not a security goal for remote acc...
Question 798: Which of the following steps should be one of the first step...
Question 799: Which of the following DoD Model layer provides non-repudiat...
Question 800: Which of the following is the FIRST step in protecting data'...
Question 801: Which of the following backup methods makes a complete backu...
Question 802: Which ISO/OSI layer establishes the communications link betw...
Question 803: A weakness or lack of a safeguard, which may be exploited by...
Question 804: Which access control model would a lattice-based access cont...
Question 805: What protocol is used to match an IP address to the appropri...
Question 806: Which of the following service is not provided by a public k...
Question 807: Network cabling comes in three flavors, they are:...
Question 808: What is electronic vaulting?
Question 809: During which phase of an IT system life cycle are security r...
Question 810: Which of the following rules pertaining to a Business Contin...
Question 811: Which of the following would be LESS likely to prevent an em...
Question 812: Which of the following is best defined as a mode of system t...
Question 813: The basic language of modems and dial-up remote access syste...
Question 814: Under the principle of culpable negligence, executives can b...
Question 815: The primary purpose for using one-way hashing of user passwo...
Question 816: Which of the following is unlike the other three choices pre...
Question 817: Which of the following should be emphasized during the Busin...
Question 818: What is the maximum key size for the RC5 algorithm?...
Question 819: Which of the following results in the most devastating busin...
Question 820: Which of the following is NOT a known type of Message Authen...
Question 821: Application Layer Firewalls operate at the:...
Question 822: In regards to information classification what is the main re...
Question 823: How many layers are defined within the US Department of Defe...
Question 824: Valuable paper insurance coverage does not cover damage to w...
Question 825: What are called user interfaces that limit the functions tha...
Question 826: In biometric identification systems, at the beginning, it wa...
Question 827: Risk mitigation and risk reduction controls for providing in...
Question 828: Which of the following is the core of fiber optic cables mad...
Question 829: Which of the following categories of hackers poses the great...
Question 830: What is the appropriate role of the security analyst in the ...
Question 831: What can best be described as a domain of trust that shares ...
Question 832: Which is NOT a suitable method for distributing certificate ...
Question 833: What algorithm was DES derived from?...
Question 834: Which of the following is a set of data processing elements ...
Question 835: What can be defined as an instance of two different keys gen...
Question 836: What can be best defined as the examination of threat source...
Question 837: How often should tests and disaster recovery drills be perfo...
Question 838: Which of the following is less likely to be used today in cr...
Question 839: Which of the following can be defined as a framework that su...
Question 840: A 'Pseudo flaw' is which of the following?...
Question 841: Which authentication technique best protects against hijacki...
Question 842: Which of the following protects Kerberos against replay atta...
Question 843: What is a common problem when using vibration detection devi...
Question 844: Which access control model achieves data integrity through w...
Question 845: Which of the following is NOT a factor related to Access Con...
Question 846: What is the most critical characteristic of a biometric iden...
Question 847: In what type of attack does an attacker try, from several en...
Question 848: When it comes to magnetic media sanitization, what differenc...
Question 849: Failure of a contingency plan is usually:...
Question 850: Which of the following can best be defined as a cryptanalysi...
Question 851: Which of the following is NOT an asymmetric key algorithm?...
Question 852: In the process of gathering evidence from a computer attack,...
Question 853: Controls like guards and general steps to maintain building ...
Question 854: Which protocol is used to send email?...
Question 855: An area of the Telecommunications and Network Security domai...
Question 856: Which of the following is a CHARACTERISTIC of a decision sup...
Question 857: Which of the following can best eliminate dial-up access thr...
Question 858: Which of the following is a tool often used to reduce the ri...
Question 859: Devices that supply power when the commercial utility power ...
Question 860: A variation of the application layer firewall is called a:...
Question 861: What enables users to validate each other's certificate when...
Question 862: The number of violations that will be accepted or forgiven b...
Question 863: Which of the following is considered the weakest link in a s...
Question 864: When a biometric system is used, which error type deals with...
Question 865: Organizations should not view disaster recovery as which of ...
Question 866: Which of the following is used in database information secur...
Question 867: A proxy can control which services (FTP and so on) are used ...
Question 868: What refers to legitimate users accessing networked services...
Question 869: Under the Business Exemption Rule to the hearsay evidence, w...
Question 870: Related to information security, the prevention of the inten...
Question 871: Which of the following offers security to wireless communica...
Question 872: A business continuity plan should list and prioritize the se...
Question 873: During the salvage of the Local Area Network and Servers, wh...
Question 874: When backing up an applications system's data, which of the ...
Question 875: Which type of encryption is considered to be unbreakable if ...
Question 876: If an organization were to monitor their employees' e-mail, ...
Question 877: The concept of best effort delivery is best associated with?...
Question 878: What is NOT an authentication method within IKE and IPsec?...
Question 879: Which of the following OSI layers provides routing and relat...
Question 880: What is a characteristic of using the Electronic Code Book m...
Question 881: A periodic review of user account management should not dete...
Question 882: Which of the following is often the greatest challenge of di...
Question 883: What best describes a scenario when an employee has been sha...
Question 884: Which of the following statements pertaining to Asynchronous...
Question 885: Which OSI/ISO layers are TCP and UDP implemented at?...
Question 886: Which of the following is used to interrupt the opportunity ...
Question 887: What is Kerberos?
Question 888: Which of the following statements pertaining to a Criticalit...
Question 889: What does "System Integrity" mean?...
Question 890: Which IPSec operational mode encrypts the entire data packet...
Question 891: Which of the following is the BEST way to detect software li...
Question 892: Which of the following would be the best reason for separati...
Question 893: Which software development model is actually a meta-model th...
Question 894: Several analysis methods can be employed by an IDS, each wit...
Question 895: Which of the following ports does NOT normally need to be op...
Question 896: Which port does the Post Office Protocol Version 3 (POP3) ma...
Question 897: Which of the following is an advantage in using a bottom-up ...
Question 898: Which of the following issues is not addressed by digital si...
Question 899: What are the three FUNDAMENTAL principles of security?...
Question 900: What enables a workstation to boot without requiring a hard ...
Question 901: The computations involved in selecting keys and in encipheri...
Question 902: What can be defined as: It confirms that users' needs have b...
Question 903: Which of the following is NOT a system-sensing wireless prox...
Question 904: What is called the type of access control where there are pa...
Question 905: Pin, Password, Passphrases, Tokens, smart cards, and biometr...
Question 906: Which of the following is the primary security feature of a ...
Question 907: Proxies works by transferring a copy of each accepted data p...
Question 908: Which of the following describes a computer processing archi...
Question 909: Recovery Site Strategies for the technology environment depe...
Question 910: Which of the following is not one of the three goals of Inte...
Question 911: Which of the following tools is less likely to be used by a ...
Question 912: Which of the following statements pertaining to key manageme...
Question 913: What can be defined as a data structure that enumerates digi...
Question 914: Which of the following choices describe a condition when RAM...
Question 915: A prolonged high voltage is a:
Question 916: An access system that grants users only those rights necessa...
Question 917: Which of the following are WELL KNOWN PORTS assigned by the ...
Question 918: Which of the following is responsible for MOST of the securi...
Question 919: Which of the following computer recovery sites is the least ...
Question 920: Which of the following protects Kerberos against replay atta...
Question 921: Examples of types of physical access controls include all EX...
Question 922: How many bits is the effective length of the key of the Data...
Question 923: What can be defined as a digital certificate that binds a se...
Question 924: How would an IP spoofing attack be best classified?...
Question 925: Which of the following control pairings include: organizatio...
Question 926: Which of the following enables the person responsible for co...
Question 927: Which of the following statements pertaining to VPN protocol...
Question 928: Which of the following are NOT a countermeasure to traffic a...
Question 929: Who is responsible for implementing user clearances in compu...
Question 930: Which of the following is an example of a connectionless com...
Question 931: What is the main purpose of Corporate Security Policy?...
Question 932: Which of the following is NOT a part of a risk analysis?...
Question 933: Which type of attack involves hijacking a session between a ...
Question 934: Which of the following protocols is not implemented at the I...
Question 935: You are running a packet sniffer on a network and see a pack...
Question 936: Which of the following access control techniques best gives ...
Question 937: Which of the following is NOT a task normally performed by a...
Question 938: Which of the following best describes signature-based detect...
Question 939: Why does fiber optic communication technology have significa...
Question 940: Which of the following statements pertaining to firewalls is...
Question 941: One of these statements about the key elements of a good con...
Question 942: Which of the following refers to the data left on the media ...
Question 943: To understand the 'whys' in crime, many times it is necessar...
Question 944: Which TCSEC level is labeled Controlled Access Protection?...
Question 945: Due care is not related to:
Question 946: Technical controls such as encryption and access control can...
Question 947: What is the act of obtaining information of a higher sensiti...
Question 948: Which of the following does NOT use token-passing?...
Question 949: The deliberate planting of apparent flaws in a system for th...
Question 950: Which of the following is true about link encryption?...
Question 951: Which common backup method is the fastest on a daily basis?...
Question 952: Which of the following access control models requires defini...
Question 953: Which of the following test makes sure the modified or new s...
Question 954: What is a hot-site facility?
Question 955: When considering an IT System Development Life-cycle, securi...
Question 956: What is the 802.11 standard related to?...
Question 957: Secure Electronic Transaction (SET) and Secure HTTP (S-HTTP)...
Question 958: Which of the following is a telecommunication device that tr...
Question 959: What is called an attack in which an attacker floods a syste...
Question 960: Which of the following access control models introduces user...
Question 961: Which of the following is true about link encryption?...
Question 962: Which of the following would be the best criterion to consid...
Question 963: Which of the following statements relating to the Bell-LaPad...
Question 964: Risk reduction in a system development life-cycle should be ...
Question 965: Who developed one of the first mathematical models of a mult...
Question 966: In Discretionary Access Control the subject has authority, w...
Question 967: One purpose of a security awareness program is to modify:...
Question 968: Which of the following questions are least likely to help in...
Question 969: Which access control model was proposed for enforcing access...
Question 970: Which of the following statements pertaining to disaster rec...
Question 971: What can be described as an imaginary line that separates th...
Question 972: Which of the following can prevent hijacking of a web sessio...
Question 973: Secure Shell (SSH) is a strong method of performing:...
Question 974: Which of the following protocols does not operate at the dat...
Question 975: What is called the probability that a threat to an informati...
Question 976: Which of the following addresses a portion of the primary me...
Question 977: Which of the following is not a component of a Operations Se...
Question 978: Organizations should consider which of the following first b...
Question 979: Business Continuity and Disaster Recovery Planning (Primaril...
Question 980: Which of the following protocols' primary function is to sen...
Question 981: What does the directive of the European Union on Electronic ...
Question 982: In the context of access control, locks, gates, guards are e...
Question 983: Which of the following statements is NOT true of IPSec Trans...
Question 984: Which of the following security mode of operation does NOT r...
Question 985: Which of the following BEST explains why computerized inform...
Question 986: Secure Shell (SSH-2) provides all the following services exc...
Question 987: Which of the following are the steps usually followed in the...
Question 988: Which security model introduces access to objects only throu...
Question 989: Which of the following is best defined as an administrative ...
Question 990: Controls provide accountability for individuals who are acce...
Question 991: Which one of the following is usually not a benefit resultin...
Question 992: Which of the following phases of a system development life-c...
Question 993: What type of cable is used with 100Base-TX Fast Ethernet?...
Question 994: Kerberos depends upon what encryption method?...
Question 995: The IP header contains a protocol field. If this field conta...
Question 996: Related to information security, availability is the opposit...
Question 997: It is a violation of the "separation of duties" principle wh...
Question 998: Which of the following statements is most accurate regarding...
Question 999: Under United States law, an investigator's notebook may be u...
Question 1000: When attempting to establish Liability, which of the followi...