NEW
Font size
S
M
L
XL
WorksheetsCISSP 7th ed PT2
Total questions: 60
Worksheet time: 30mins
Name
Class
Date
1.
What is the main purpose of Corporate Security Policy?
a)
To transfer the responsibility for the information security to all users of the organization
b)
To communicate management's intentions in regards to information security
c)
To provide detailed steps for performing specific actions
d)
To provide a common framework for all development activities
2.
Which of the following is from the Internet Architecture Board (IAB) Ethics and the Internet (RFC1087)?
a)
Access to and use of the Internet is a privilege and should be treated as such by all users of the systems.
b)
Users should execute responsibilities in a manner consistent with the highest standards of their profession
c)
There must not be personal data record-keeping systems whose very existence is secret
d)
There must be a way for a person to prevent information about them, which was obtained for one purpose, from being used or made available for another purpose without their consent
3.
Out of the steps listed below, which one is not one of the steps conducted during the Business Impact Analysis (BIA)?
a)
Alternate site selection
b)
Create data-gathering techniques
c)
Identify the company’s critical business functions
d)
Select individuals to interview for data gathering
4.
In the CIA triad, what does the letter A stand for?
a)
Auditability
b)
Accountability
c)
Availability
d)
Authentication
5.
Controls are implemented to:
a)
eliminate risk and reduce the potential for loss.
b)
mitigate risk and eliminate the potential for loss
c)
mitigate risk and reduce the potential for loss.
d)
eliminate risk and eliminate the potential for loss
6.
What can be described as a measure of the magnitude of loss or impact on the value of an asset?
a)
Probability
b)
Exposure factor
c)
Vulnerability
d)
Threat
7.
The scope and focus of the Business continuity plan development depends most on:
a)
Directives of Senior Management
b)
Business Impact Analysis (BIA)
c)
Scope and Plan Initiation
d)
Skills of BCP committee
8.
Which of the following best allows risk management results to be used knowledgeably?
a)
A vulnerability analysis
b)
A likelihood assessment
c)
An uncertainty analysis
d)
Threat identification
9.
Which of the following control pairings include: organizational policies and procedures, preemployment background checks, strict hiring practices, employment agreements, employee termination procedures, vacation scheduling, labeling of sensitive materials, increased supervision, security awareness training, behavior awareness, and sign-up procedures to obtain access to information systems and networks?
a)
Preventive/Administrative Pairing
b)
Preventive/Technical Pairing
c)
Preventive/Physical Pairing
d)
Detective/Administrative Pairing
10.
What can best be defined as high-level statements, beliefs, goals and objectives?
a)
Standards
b)
Policies
c)
Guidelines
d)
Procedures
11.
In an organization, an Information Technology security function should:
a)
Be a function within the information systems function of an organization.
b)
Report directly to a specialized business unit such as legal, corporate security or insurance
c)
Be led by a Chief Security Officer and report directly to the CEO
d)
Be independent but report to the Information Systems function.
12.
Qualitative loss resulting from the business interruption does NOT usually include:
a)
Loss of revenue
b)
Loss of competitive advantage or market share
c)
Loss of public confidence and credibility
d)
Loss of market leadership
13.
Which of the following tasks is NOT usually part of a Business Impact Analysis (BIA)?
a)
Calculate the risk for each different business function
b)
Identify the company’s critical business functions
c)
Calculate how long these functions can survive without these resources.
d)
Develop a mission statement.
14.
Which of the following is NOT a common integrity goal?
a)
Prevent unauthorized users from making modifications
b)
Maintain internal and external consistency.
c)
Prevent authorized users from making improper modifications
d)
Prevent paths that could lead to inappropriate disclosure.
15.
At what Orange Book evaluation levels are design specification and verification FIRST required?
a)
C1 and above
b)
C2 and above.
c)
B1 and above.
d)
B2 and above.
16.
Which of the following is an advantage of a qualitative over a quantitative risk analysis?
a)
It prioritizes the risks and identifies areas for immediate improvement in addressing the vulnerabilities.
b)
It provides specific quantifiable measurements of the magnitude of the impacts.
c)
It makes a cost-benefit analysis of recommended controls easier.
d)
It can easily be automated.
17.
An effective information security policy should NOT have which of the following characteristic?
a)
Include separation of duties
b)
Be designed with a short- to mid-term focus
c)
Be understandable and supported by all stakeholders
d)
Specify areas of responsibility and authority
18.
Which of the following choices is NOT normally part of the questions that would be asked in regards to an organization's information security policy?
a)
Who is involved in establishing the security policy?
b)
Where is the organization's security policy defined?
c)
What are the actions that need to be performed in case of a disaster?
d)
Who is responsible for monitoring compliance to the organization's security policy?
19.
The property of a system or a system resource being accessible and usable upon demand by an authorized system entity, according to performance specifications for the system is referred to as?
a)
Confidentiality
b)
Availability
c)
Integrity
d)
Reliability
20.
Which of the following would BEST classify as a management control?
a)
Review of security controls
b)
Personnel security
c)
Physical and environmental protection
d)
Documentation
21.
Valuable paper insurance coverage does cover damage to which of the following?
a)
Inscribed, printed and Written documents
b)
Manuscripts
c)
Records
d)
Money and Securities
22.
Which of the following statements pertaining to a security policy is NOT true?
a)
Its main purpose is to inform the users, administrators and managers of their obligatory requirements for protecting technology and information assets.
b)
It specifies how hardware and software should be used throughout the organization.
c)
It needs to have the acceptance and support of all levels of employees within the organization in order for it to be appropriate and effective
d)
It must be flexible to the changing environment
23.
If your property Insurance has Actual Cash Valuation (ACV) clause, your damaged property will be compensated based on:
a)
Value of item on the date of loss
b)
Replacement with a new item for the old one regardless of condition of lost item
c)
Value of item one month before the loss
d)
Value of item on the date of loss plus 10 percent
24.
The preliminary steps to security planning include all of the following EXCEPT which of the following?
a)
Establish objectives
b)
List planning assumptions
c)
Establish a security audit function
d)
Determine alternate courses of action
25.
Step-by-step instructions used to satisfy control requirements are called a:
a)
policy.
b)
standard.
c)
guideline.
d)
procedure.
26.
One purpose of a security awareness program is to modify:
a)
employee's attitudes and behaviors towards enterprise's security posture.
b)
management's approach towards enterprise's security posture.
c)
attitudes of employees with sensitive data
d)
corporate attitudes about safeguarding data.
27.
What is a security policy?
a)
High level statements on management's expectations that must be met in regards to security
b)
A policy that defines authentication to the network.
c)
A policy that focuses on ensuring a secure posture and expresses management approval. It explains in detail how to implement the requirements.
d)
A statement that focuses on the authorization process for a system
28.
The end result of implementing the principle of least privilege means which of the following?
a)
Users would get access to only the info for which they have a need to know
b)
Users can access all systems
c)
Users get new privileges added when they change positions
d)
Authorization creep.
29.
Which of the following exemplifies proper separation of duties?
a)
Operators are not permitted modify the system time.
b)
Programmers are permitted to use the system console.
c)
Console operators are permitted to mount tapes and disks
d)
Tape operators are permitted to use the system console
30.
An access control policy for a bank teller is an example of the implementation of which of the following?
a)
Rule-based policy
b)
Identity-based policy
c)
User-based policy
d)
Role-based policy
31.
At which of the Orange Book evaluation levels is configuration management required?
a)
C1 and above.
b)
C2 and above
c)
B1 and above
d)
B2 and above
32.
Which type of security control is also known as "Logical" control?
a)
Physical
b)
Technical
c)
Administrative
d)
Risk
33.
Which Security and Audit Framework has been adopted by some organizations working towards Sarbanes—Oxley Section 404 compliance?
a)
Committee of Sponsoring Organizations of the Treadway Commission (COSO)
b)
BIBA
c)
National Institute of Standards and Technology Special Publication 800-66 (NIST SP 800-66)
d)
CCTA Risk Analysis and Management Method (CRAMM)
34.
The Widget Company decided to take their company public and while they were in the process of doing so had an external auditor come and look at their company. As part of the external audit they brought in a technology expert, who incidentally was a new CISSP. The auditor's expert asked to see their last risk analysis from the technology manager. The technology manager did not get back to him for a few days and then the Chief Financial Officer gave the auditors a 2 page risk assessment that was signed by both the Chief Financial Officer and the Technology Manager.While reviewing it, the auditor noticed that only parts of their financial data were being backed upon site and nowhere else; the Chief Financial Officer accepted the risk of only partial financial data being backed up with no off-site copies available.
Who owns the risk with regards to the data that is being backed up and where it is stored?
Who owns the risk with regards to the data that is being backed up and where it is stored?
a)
Only the Chief Financial Officer
b)
Only the most Senior Management such as the Chief Executive Officer
c)
Both the Chief Financial Officer and Technology Manager
d)
Only The Technology Manager
35.
The control measures that are intended to reveal the violations of security policy using software and hardware are associated with:
a)
preventive/physical.
b)
detective/technical.
c)
detective/physical.
d)
detective/administrative.
36.
Which of the following steps is NOT one of the eight detailed steps of a Business Impact Assessment (BIA)?
a)
Notifying senior management of the start of the assessment
b)
Creating data gathering techniques.
c)
Identifying critical business functions.
d)
Calculating the risk for each different business function
37.
Which of the following provides enterprise management with a prioritized list of time-critical business processes, and estimates a recovery time objective for each of the time critical processes and the components of the enterprise that support those processes?
a)
Business Impact Assessment
b)
Current State Assessment
c)
Risk Mitigation Assessment
d)
Business Risk Assessment
38.
Which of the following answers is the BEST example of Risk Transference?
a)
Insurance
b)
Results of Cost Benefit Analysis
c)
Acceptance
d)
Not hosting the services at all
39.
Which of the following answer BEST relates to the type of risk analysis that involves committees,interviews, opinions and subjective input from staff?
a)
Qualitative Risk Analysis
b)
Quantitative Risk Analysis
c)
Interview Approach to Risk Analysis
d)
Managerial Risk Assessment
40.
Regarding risk reduction, which of the following answers is BEST defined by the process of giving only just enough access to information necessary for them to perform their job functions?
a)
Least Privilege Principle
b)
Minimum Privilege Principle
c)
Mandatory Privilege Requirement
d)
Implicit Information Principle
41.
Which term BEST describes a practice used to detect fraud for users or a user by forcing them to be away from the workplace for a while?
a)
Mandatory Vacations
b)
Least Privilege Principle
c)
Obligatory Separation
d)
Job Rotation
42.
Which of the following is a fraud detection method whereby employees are moved from position to position?
a)
Job Rotation
b)
Mandatory Rotation
c)
Mandatory Vacations
d)
Mandatory Job Duties
43.
The controls that usually require a human to evaluate the input from sensors or cameras to determine if a real threat exists are associated with:
a)
preventive/physical.
b)
detective/technical.
c)
detective/physical.
d)
detective/administrative.
44.
Controls such as job rotation, the sharing of responsibilities, and reviews of audit records are associated with:
a)
preventive/physical.
b)
detective/technical.
c)
detective/physical.
d)
detective/administrative
45.
In terms or Risk Analysis and dealing with risk, which of the four common ways listed below seek to eliminate involvement with the risk being evaluated?
a)
Avoidance
b)
Acceptance
c)
Transference
d)
Mitigation
46.
Of the multiple methods of handling risks which we must undertake to carry out business operations, which one involves using controls to reduce the risk?
a)
Mitigation
b)
Avoidance
c)
Acceptance
d)
Transference
47.
There is no way to completely abolish or avoid risks, you can only manage them. A risk free environment does not exist. If you have risks that have been identified, understood and evaluated to be acceptable in order to conduct business operations. What is this this approach to risk management called?
a)
Risk Acceptance
b)
Risk Avoidance
c)
Risk Transference
d)
Risk Mitigation
48.
John is the product manager for an information system. His product has undergone under security review by an IS auditor. John has decided to apply appropriate security controls to reduce the security risks suggested by an IS auditor. Which of the following technique is used by John to treat the identified risk provided by an IS auditor?
a)
Risk Mitigation
b)
Risk Acceptance
c)
Risk Avoidance
d)
Risk transfer
49.
Sam is the security Manager of a financial institute. Senior management has requested he performs a risk analysis on all critical vulnerabilities reported by an IS auditor. After completing the risk analysis, Sam has observed that for a few of the risks, the cost benefit analysis shows that risk mitigation cost (countermeasures, controls, or safeguard) is more than the potential lost that could be incurred. What kind of a strategy should Sam recommend to the senior management to treat these risks?
a)
Risk Mitigation
b)
Risk Acceptance
c)
Risk Avoidance
d)
Risk transfer
50.
Which of the following risk handling technique involves the practice of being proactive so that the risk in question is not realized?
a)
Risk Mitigation
b)
Risk Acceptance
c)
Risk Avoidance
d)
Risk transfer
51.
Which of the following risk handling technique involves the practice of passing on the risk to another entity, such as an insurance company?
a)
Risk Mitigation
b)
Risk Acceptance
c)
Risk Avoidance
d)
Risk transfer
52.
Which of the following pairings uses technology to enforce access control policies?
a)
Preventive/Administrative
b)
Preventive/Technical
c)
Preventive/Physical
d)
Detective/Administrative
53.
Which type of risk assessment is the formula ALE = ARO x SLE used for?
a)
Quantitative Analysis
b)
Qualitative Analysis
c)
Objective Analysis
d)
Expected Loss Analysis
54.
Which of the following Confidentiality, Integrity, Availability (CIA) attribute supports the principle of least privilege by providing access to information only to authorized and intended users?
a)
Confidentiality
b)
Integrity
c)
Availability
d)
Accuracy
55.
You are a manager for a large international bank and periodically move employees between positions in your department. What is this process called?
a)
Job Rotation
b)
Separation of Duties
c)
Mandatory Vacation
d)
Dual Control
56.
Which of the following is a CHARACTERISTIC of a decision support system (DSS) in regards to Threats and Risks Analysis?
a)
DSS is aimed at solving highly structured problems
b)
DSS emphasizes flexibility in the decision making approach of users.
c)
DSS supports only structured decision-making tasks.
d)
DSS combines the use of models with non-traditional data access and retrieval functions.
57.
Which of the following is covered under Crime Insurance Policy Coverage?
a)
Inscribed, printed and Written documents
b)
Manuscripts
c)
Accounts Receivable
d)
Money and Securities
58.
It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?
a)
security administrator
b)
security analyst
c)
systems auditor
d)
systems programmer
59.
The number of violations that will be accepted or forgiven before a violation record is produced is called which of the following?
a)
Clipping level
b)
Acceptance level
c)
Forgiveness level
d)
Logging level
60.
Which of the following ensures that security is NOT breached when a system crash or other system failure occurs?
a)
Trusted recovery
b)
Hot swappable
c)
Redundancy
d)
Secure boot
Reset
