CISSP-ISSAP Information Systems Security Architecture Exam Set 8

Which of the following methods will allow data to be sent on the Internet in a secure format?

Options are :

Answer : Virtual Private Networks

Which of the following components come under the network layer of the OSI model? Each correct

answer represents a complete solution. Choose two.

Options are :

  • B,C
  • C,D
  • A,C (Correct)
  • A,B

Answer : A,C

You work as a Chief Security Officer for Tech Perfect Inc. The company has a TCP/IP based

network. You want to use a firewall that can track the state of active connections of the network

and then determine which network packets are allowed to enter through the firewall. Which of the

following firewalls has this feature?

Options are :

Answer : Dynamic packet-filtering firewall

CISSP - Security Operations Mock Questions

Which of the following uses a Key Distribution Center (KDC) to authenticate a principle?

Options are :

Answer : Kerberos

Which of the following are examples of physical controls used to prevent unauthorized access to

sensitive materials?

Options are :

  • B,C,A
  • A,B,C (Correct)
  • A,D,C
  • B,C,D

Answer : A,B,C

You are the administrator for You want to increase and enhance the security of your

computers and simplify deployment. You are especially concerned with any portable computers

that are used by remote employees. What can you use to increase security, while still allowing

your users to perform critical tasks?

Options are :

Answer : Smart Cards

CISSP - Security Operations Mock Questions

You work as a Network Administrator for Net Perfect Inc. The company has a Linux-basednetwork. You need to configure a firewall for the company. The firewall should be able to keep

track of the state of network connections traveling across the network. Which of the following types

of firewalls will you configure to accomplish the task?

Options are :

Answer : Stateful firewall

Which of the following are the goals of a public key infrastructure (PKI)? Each correct answer

represents a part of the solution. Choose all that apply.

Options are :

  • C,D,B,A
  • A,B,C,D
  • F,E,D,A
  • A,D,E,F (Correct)

Answer : A,D,E,F

Which of the following protects against unauthorized access to confidential information via

encryption and works at the network layer?

Options are :

Answer : IPSec

CISSP Security Assessment Testing Security Operations Exam Set 6

Which of the following SDLC phases consists of the given security controls: Misuse Case

Modeling Security Design and Architecture Review Threat and Risk Modeling Security

Requirements and Test Cases Generation

Options are :

Answer : Design

Which of the following terms related to risk management represents the estimated frequency at

which a threat is expected to occur?

Options are :

Answer : Annualized Rate of Occurrence (ARO

You are the Network Administrator at a large company. Your company has a lot of contractors and

other outside parties that come in and out of the building. For this reason you are concerned that

simply having usernames and passwords is not enough and want to have employees use tokens

for authentication. Which of the following is not an example of tokens?

Options are :

Answer : CHAP

CISSP Security Engineering Certification Practice Exam Set 10

Which of the following statements are true about Public-key cryptography? Each correct answer

represents a complete solution. Choose two.

Options are :

  • C,D
  • B,D (Correct)
  • A,B
  • B,C

Answer : B,D

In which of the following phases of the SDLC does the software and other components of the

system faithfully incorporate the design specifications and provide proper documentation and


Options are :

Answer : Programming and training

Which of the following attacks allows the bypassing of access control lists on servers or routers,

and helps an attacker to hide? Each correct answer represents a complete solution. Choose two.

Options are :

  • D,A
  • A,B
  • B,C (Correct)
  • B,D

Answer : B,C

CISSP - Security Operations Mock Questions

Fill in the blank with the appropriate security device. ___________ is a device that contains a

physical mechanism or electronic sensor that quantifies motion that can be either integrated with

or connected to other devices that alert the user of the presence of a moving object within the field

of view.

Options are :

Answer : Motion detector

You are the Security Consultant and have been contacted by a client regarding their encryption

and hashing algorithms. Their in-house network administrator tells you that their current hashing

algorithm is an older one with known weaknesses and is not collision resistant.Which algorithm

are they most likely using for hashing?

Options are :

Answer : MD5

Which of the following are used to suppress electrical and computer fires? Each correct answer

represents a complete solution. Choose two.

Options are :

  • A,C (Correct)
  • B,C
  • A,B
  • C,D

Answer : A,C

CISSP Security Engineering Certification Practice Exam Set 7

Which of the following statements about Discretionary Access Control List (DACL) is true?

Options are :

Answer : It is a list containing user accounts, groups, and computers that are allowed (or denied) access to the object.

Shoulder surfing is a type of in-person attack in which the attacker gathers information about the

premises of an organization. This attack is often performed by looking surreptitiously at the

keyboard of an employee's computer while he is typing in his password at any access point such

as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?

Options are :

Answer : Confidentiality

Which of the following backup types backs up files that have been added and all data that have

been modified since the most recent backup was performed?

Options are :

Answer : Incremental backup

CISSP - Identity and Access Management (IAM)

Which of the following are types of asymmetric encryption algorithms? Each correct answer

represents a complete solution. Choose two.





Options are :

Answer : A,C

You work as a Security Manager for Tech Perfect Inc. A number of people are involved with you in

the DRP efforts. You have maintained several different types of plan documents, intended for

different audiences. Which of the following documents will be useful for you as well as public

relations personnel who require a non-technical perspective on the entire organization's disaster

recovery efforts?

Options are :

Answer : Executive summary

At which of the following layers of the Open System Interconnection (OSI) model the Internet

Control Message Protocol (ICMP) and the Internet Group Management Protocol (IGMP) work?

Options are :

Answer : The Network layer

CISSP-ISSEP Information Systems Security Engineering Exam Set 6

Which of the following heights of fence deters only casual trespassers?

Options are :

Answer : 3 to 4 feet

Which of the following processes is used by remote users to make a secure connection to internal

resources after establishing an Internet connection?

Options are :

Answer : Tunneling

Which of the following plans is designed to protect critical business processes from natural or

man-made failures or disasters and the resultant loss of capital due to the unavailability of normal

business processes?

Options are :

Answer : Business continuity plan

CISSP - Mock Questions with all domains

Which of the following is a network service that stores and organizes information about a network

users and network resources and that allows administrators to manage users' access to the


Options are :

Answer : Directory service

Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS)

to encrypt the data stored on a disk on a file-by-file basis?

Options are :

  • C,A
  • B,C (Correct)
  • B,C
  • A,B

Answer : B,C

You have just set up a wireless network for customers at a coffee shop. Which of the following are

good security measures to implement? Each correct answer represents a complete solution.

Choose two.

Options are :

  • C,D (Correct)
  • B,C
  • A,B
  • C,A

Answer : C,D

CISSP Security Engineering Certification Practice Exam Set 4

