NEW
Font size
S
M
L
XL
WorksheetsCISSP 7th ed PT5
Total questions: 60
Worksheet time: 30mins
Name
Class
Date
1.
Which of the following phases of a system development life-cycle is most concerned with maintaining proper authentication of users and processes to ensure appropriate access control decisions?
a)
Development/acquisition
b)
Implementation
c)
Operation/Maintenance
d)
Initiation
2.
What can be defined as: It confirms that users’ needs have been met by the supplied solution?
a)
Accreditation
b)
Certification
c)
Assurance
d)
Acceptance
3.
What is the name of the first mathematical model of a multi-level security policy used to define the concept of a secure state, the modes of access, and rules for granting access?
a)
Clark and Wilson Model
b)
Harrison-Ruzzo-Ullman Model
c)
Rivest and Shamir Model
d)
Bell-LaPadula Model
4.
A potential problem related to the physical installation of the Iris Scanner in regards to the usage of the iris pattern within a biometric system is:
a)
Concern that the laser beam may cause eye damage.
b)
The iris pattern changes as a person grows older.
c)
There is a relatively high rate of false accepts.
d)
The optical unit must be positioned so that the sun does not shine into the aperture.
5.
Which of the following is not classified as "Security and Audit Frameworks and Methodologies"?
a)
Bell LaPadula
b)
Committee of Sponsoring Organizations of the Treadway Commission (COSO)
c)
IT Infrastructure Library (ITIL)
d)
Control Objectives for Information and related Technology (COBIT)
6.
At which of the basic phases of the System Development Life Cycle are security requirements formalized?
a)
Disposal
b)
System Design Specifications
c)
Development and Implementation
d)
Functional Requirements Definition
7.
During which phase of an IT system life cycle are security requirements developed?
a)
Operation
b)
Initiation
c)
Functional design analysis and Planning
d)
Implementation
8.
Which of the following phases of a system development life-cycle is most concerned with establishing a good security policy as the foundation for design?
a)
Development/acquisition
b)
Implementation
c)
Initiation
d)
Maintenance
9.
When considering an IT System Development Life-cycle, security should be:
a)
Mostly considered during the initiation phase.
b)
Mostly considered during the development phase.
c)
Treated as an integral part of the overall system design
d)
Added once the design is completed.
10.
Risk reduction in a system development life-cycle should be applied:
a)
Mostly to the initiation phase.
b)
Mostly to the development phase
c)
Mostly to the disposal phase.
d)
Equally to all phases.
11.
Who developed one of the first mathematical models of a multilevel-security computer system?
a)
Diffie and Hellman.
b)
Clark and Wilson
c)
Bell and LaPadula
d)
Gasser and Lipner
12.
What mechanism automatically causes an alarm originating in a data center to be transmitted over the local municipal fire or police alarm circuits for relaying to both the local police/fire station and the appropriate headquarters?
a)
Central station alarm
b)
Proprietary alarm
c)
A remote station alarm
d)
An auxiliary station alarm
13.
Which security model introduces access to objects only through programs?
a)
The Biba model
b)
The Bell-LaPadula model
c)
The Clark-Wilson model
d)
The information flow model
14.
What security model implies a central authority that defines rules and sometimes global rules, dictating what subjects can have access to what objects?
a)
Flow Model
b)
Discretionary access control
c)
Mandatory access control
d)
Non-discretionary access control
15.
Which of the following is not a physical control for physical security?
a)
lighting
b)
fences
c)
training
d)
facility construction materials
16.
Which access control model would a lattice-based access control model be an example of?
a)
Mandatory access control
b)
Discretionary access control.
c)
Non-discretionary access control
d)
Rule-based access control
17.
Which of the following is an example of discretionary access control?
a)
Identity-based access control
b)
Task-based access control
c)
Role-based access control
d)
Rule-based access control
18.
Which of the following would be used to implement Mandatory Access Control (MAC)?
a)
Clark-Wilson Access Control
b)
Role-based access control
c)
Lattice-based access control
d)
User dictated access control
19.
Which of the following statements relating to the Bell-LaPadula security model is FALSE(assuming the Strong Star property is NOT being used)?
a)
A subject is not allowed to read up.
b)
The *- property restriction can be escaped by temporarily downgrading a high level subject
c)
A subject is not allowed to read down.
d)
It is restricted to confidentiality
20.
The Orange Book is founded upon which security policy model?
a)
The Biba Model
b)
The Bell LaPadula Model
c)
Clark-Wilson Model
d)
TEMPEST
21.
Which of the following is NOT a basic component of security architecture?
a)
Motherboard
b)
Central Processing Unit (CPU)
c)
Storage Devices
d)
Peripherals (input/output devices)
22.
Which of the following is the lowest TCSEC class wherein the systems must support separate operator and system administrator roles?
a)
B2
b)
B1
c)
A1
d)
A2
23.
In which of the following models are Subjects and Objects identified and the permissions applied to each subject/object combination are specified? Such a model can be used to quickly summarize what permissions a subject has for various system objects.
a)
Access Control Matrix model
b)
Take-Grant model
c)
Bell-LaPadula model
d)
Biba model
24.
Which of the following is NOT a precaution you can take to reduce static electricity?
a)
power line conditioning
b)
anti-static sprays
c)
maintain proper humidity levels
d)
anti-static flooring
25.
Which of the following is currently the most recommended water system for a computer room?
a)
preaction
b)
wet pipe
c)
dry pipe
d)
deluge
26.
Which of the following is electromagnetic interference (EMI) that is noise from the radiation generated by the difference between the hot and ground wires?
a)
traverse-mode noise
b)
common-mode noise
c)
crossover-mode noise
d)
transversal-mode noise
27.
The "vulnerability of a facility" to damage or attack may be assessed by all of the following EXCEPT:
a)
Inspection
b)
History of losses
c)
Security controls
d)
security budget
28.
Which of the following is not an EPA-approved replacement for Halon?
a)
Bromine
b)
Inergen
c)
FM-200
d)
FE-13
29.
Which of the following was developed by the National Computer Security Center (NCSC) for theUS Department of Defense?
a)
TCSEC
b)
ITSEC
c)
DIACAP
d)
NIACAP
30.
The Computer Security Policy Model the Orange Book is based on is which of the following?
a)
Bell-LaPadula
b)
Data Encryption Standard
c)
Kerberos
d)
Tempest
31.
The Information Technology Security Evaluation Criteria (ITSEC) was written to address which of the following that the Orange Book did not address?
a)
integrity and confidentiality
b)
confidentiality and availability
c)
integrity and availability
d)
none of the above
32.
Which of the following is NOT a type of motion detector?
a)
Photoelectric sensor
b)
Passive infrared sensors
c)
Microwave Sensor
d)
Ultrasonic Sensor.
33.
What is the minimum static charge able to cause disk drive data loss?
a)
550 volts
b)
1000 volts
c)
1500 volts
d)
2000 volts
34.
Which of the following statements relating to the Bell-LaPadula security model is FALSE(assuming the Strong Star property is not being used)?
a)
A subject is not allowed to read up.
b)
The *- property restriction can be escaped by temporarily downgrading a high level subject.
c)
A subject is not allowed to read down.
d)
It is restricted to confidentiality.
35.
Which of the following is a class A fire?
a)
common combustibles
b)
liquid
c)
electrical
d)
Halon
36.
Which of the following statements relating to the Biba security model is FALSE?
a)
It is a state machine model
b)
A subject is not allowed to write up.
c)
Integrity levels are assigned to subjects and objects
d)
Programs serve as an intermediate layer between subjects and objects
37.
Which of the following organizations PRODUCES and PUBLISHES the Federal Information Processing Standards (FIPS)?
a)
The National Computer Security Center (NCSC)
b)
The National Institute of Standards and Technology (NIST)
c)
The National Security Agency (NSA)
d)
The American National Standards Institute (ANSI)
38.
What is the main focus of the Bell-LaPadula security model?
a)
Accountability
b)
Integrity
c)
Confidentiality
d)
Availability
39.
Which of the following suppresses combustion by disrupting a chemical reaction, by doing so itkills the fire?
a)
Halon
b)
CO2
c)
water
d)
soda acid
40.
Which of the following is a class C fire?
a)
electrical
b)
liquid
c)
common combustibles
d)
soda acid
41.
Which of the following statements pertaining to the Bell-LaPadula model is TRUE if you are NOT making use of the strong star property?
a)
It allows "read up."
b)
It addresses covert channels
c)
It addresses management of access controls
d)
It allows "write up."
42.
Which security model ensures that actions that take place at a higher security level do not affect actions that take place at a lower level?
a)
The Bell-LaPadula model
b)
The information flow model
c)
The noninterference model
d)
The Clark-Wilson model
43.
Which of the following security models does NOT concern itself with the flow of data?
a)
The information flow model
b)
The Biba model
c)
The Bell-LaPadula model
d)
The noninterference model
44.
Which of the following is the preferred way to suppress an electrical fire in an information center?
a)
CO2
b)
CO2, soda acid, or Halon
c)
water or soda acid
d)
ABC Rated Dry Chemical
45.
What are the four basic elements of Fire?
a)
Heat, Fuel, Oxygen, and Chain Reaction
b)
Heat, Fuel, CO2, and Chain Reaction
c)
Heat, Wood, Oxygen, and Chain Reaction
d)
Flame, Fuel, Oxygen, and Chain Reaction
46.
Which Orange book security rating introduces the object reuse protection?
a)
C1
b)
C2
c)
B1
d)
B2
47.
Which Orange book security rating introduces security labels?
a)
C2
b)
B1
c)
B2
d)
B3
48.
Which Orange book security rating is the FIRST to be concerned with covert channels?
a)
A1
b)
B3
c)
B2
d)
B1
49.
Which of the following is true about a "dry pipe" sprinkler system?
a)
It is a substitute for carbon dioxide systems.
b)
It maximizes chances of accidental discharge of water.
c)
It reduces the likelihood of the sprinkler system pipes freezing.
d)
It uses less water than "wet pipe" systems.
50.
According to the Orange Book, which security level is the first to require a system to protect against covert timing channels?
a)
A1
b)
B3
c)
B2
d)
B1
51.
What does the Clark-Wilson security model focus on?
a)
Confidentiality
b)
Integrity
c)
Accountability
d)
Availability
52.
What does the simple security (ss) property mean in the Bell-LaPadula model?
a)
No read up
b)
No write down
c)
No read down
d)
No write up
53.
What does the * (star) property mean in the Bell-LaPadula model?
a)
No write up
b)
No read up
c)
No write down
d)
No read down
54.
What does the * (star) integrity axiom mean in the Biba model?
a)
No read up
b)
No write down
c)
No read down
d)
No write up
55.
What does the simple integrity axiom mean in the Biba model?
a)
No write down
b)
No read down
c)
No read up
d)
No write up
56.
What is the Biba security model concerned with?
a)
Confidentiality
b)
Reliability
c)
Availability
d)
Integrity
57.
Which security model uses division of operations into different parts and requires different users to perform each part?
a)
Bell-LaPadula model
b)
Biba model
c)
Clark-Wilson model
d)
Non-interference model
58.
What is the name of the FIRST mathematical model of a multi-level security policy used to define the concept of a secure state, the modes of access, and rules for granting access?
a)
Clark and Wilson Model
b)
Harrison-Ruzzo-Ullman Model
c)
Rivest and Shamir Model
d)
Bell-LaPadula Model
59.
Which of the following models does NOT include data integrity or conflict of interest?
a)
Biba
b)
Clark-Wilson
c)
Bell-LaPadula
d)
Brewer-Nash
60.
Which integrity model defines a constrained data item, an integrity verification procedure and a transformation procedure?
a)
The Take-Grant model
b)
The Biba integrity model
c)
The Clark Wilson integrity model
d)
The Bell-LaPadula integrity model
Reset
