NEW
Font size
S
M
L
XL
WorksheetsCISSP 7th ed PT6
Total questions: 60
Worksheet time: 30mins
Name
Class
Date
1.
The BIGGEST difference between System High Security Mode and Dedicated Security Mode is:
a)
The clearance required
b)
Object classification
c)
Subjects cannot access all objects
d)
Need-to-know
2.
For competitive reasons, the customers of a large shipping company called the "Integrated International Secure Shipping Containers Corporation" (IISSCC) like to keep private the various cargos that they ship. IISSCC uses a secure database system based on the Bell-LaPadula access control model to keep this information private. Different information in this database is classified at different levels. For example, the time and date a ship departs is labeled Unclassified, so customers can estimate when their cargos will arrive, but the contents of all shipping containers on the ship are labeled Top Secret to keep different shippers from viewing each other's cargos.
An unscrupulous fruit shipper, the "Association of Private Fruit Exporters, Limited" (APFEL) wants to learn whether or not a competitor, the "Fruit Is Good Corporation" (FIGCO), is shipping pineapples on the ship "S.S. Cruise Pacific" (S.S. CP). APFEL can't simply read the top secret contents in the IISSCC database because of the access model. A smart APFEL worker, however,attempts to insert a false, unclassified record in the database that says that FIGCO is shipping pineapples on the S.S. CP, reasoning that if there is already a FIGCO-pineapple-SSCP record then the insertion attempt will fail. But the attempt does not fail, so APFEL can't be sure whether or not FIGCO is shipping pineapples on the S.S. CP.
What is the name of the access control model property that prevented APFEL from reading FIGCO's cargo information? What is a secure database technique that could explain why, when the insertion attempt succeeded, APFEL was still unsure whether or not FIGCO was shipping pineapples?
An unscrupulous fruit shipper, the "Association of Private Fruit Exporters, Limited" (APFEL) wants to learn whether or not a competitor, the "Fruit Is Good Corporation" (FIGCO), is shipping pineapples on the ship "S.S. Cruise Pacific" (S.S. CP). APFEL can't simply read the top secret contents in the IISSCC database because of the access model. A smart APFEL worker, however,attempts to insert a false, unclassified record in the database that says that FIGCO is shipping pineapples on the S.S. CP, reasoning that if there is already a FIGCO-pineapple-SSCP record then the insertion attempt will fail. But the attempt does not fail, so APFEL can't be sure whether or not FIGCO is shipping pineapples on the S.S. CP.
What is the name of the access control model property that prevented APFEL from reading FIGCO's cargo information? What is a secure database technique that could explain why, when the insertion attempt succeeded, APFEL was still unsure whether or not FIGCO was shipping pineapples?
a)
*-Property and Polymorphism
b)
Strong *-Property and Polyinstantiation
c)
Simple Security Property and Polymorphism
d)
Simple Security Property and Polyinstantiation
3.
Which security model uses an access control triple and also requires separation of duty?
a)
DAC
b)
Lattice
c)
Clark-Wilson
d)
Bell-LaPadula
4.
You have been approached by one of your clients. They are interested in doing some security re-engineering. The client is looking at various information security models. It is a highly secure environment where data at high classifications cannot be leaked to subjects at lower classifications. Of primary concern to them, is the identification of potential covert channel. As an Information Security Professional, which model would you recommend to the client?
a)
Information Flow Model combined with Bell LaPadula
b)
Bell LaPadula
c)
Biba
d)
Information Flow Model
5.
Which of the following security models introduced the idea of mutual exclusivity which generates dynamically changing permissions?
a)
Biba
b)
Brewer & Nash
c)
Graham-Denning
d)
Clark-Wilson
6.
Which of the following was the FIRST mathematical model of a multilevel security policy used to define the concepts of a security state and mode of access, and to outline rules of access?
a)
Biba
b)
Bell-LaPadula
c)
Clark-Wilson
d)
State machine
7.
Which of the following answers BEST describes the Bell La-Padula model of storage and access control of classified information?
a)
No read up and No write down
b)
No write up, no read down
c)
No read over and no write up
d)
No reading from higher classification levels
8.
Individual accountability does not include which of the following?
a)
unique identifiers
b)
policies and procedures
c)
access rules
d)
audit trails
9.
Which of the following components are considered part of the Trusted Computing Base?
a)
Trusted hardware and firmware.
b)
Trusted hardware and software.
c)
Trusted hardware, software and firmware.
d)
Trusted computer operators and system managers
10.
The high availability of multiple all-inclusive, easy-to-use hacking tools that do NOT require much technical knowledge has brought a growth in the number of which type of attackers?
a)
Black hats
b)
White hats
c)
Script kiddies
d)
Phreakers
11.
Which is the last line of defense in a physical security sense?
a)
people
b)
interior barriers
c)
exterior barriers
d)
perimeter barriers
12.
What is an error called that causes a system to be vulnerable because of the environment in which it is installed?
a)
Configuration error
b)
Environmental error
c)
Access validation error
d)
Exceptional condition handling error
13.
Devices that supply power when the commercial utility power system fails are called which of the following?
a)
power conditioners
b)
uninterruptible power supplies
c)
power filters
d)
power dividers
14.
Access control is the collection of mechanisms that permits managers of a system to exercise a directing or restraining influence over the behavior, use, and content of a system. It does not permit management to:
a)
specify what users can do
b)
specify which resources they can access
c)
specify how to restrain hackers
d)
specify what operations they can perform on a system.
15.
Which of the following was developed to address some of the weaknesses in Kerberos and uses public key cryptography for the distribution of secret keys and provides additional access control support?
a)
SESAME
b)
RADIUS
c)
KryptoKnight
d)
TACACS+
16.
Which of the following is NOT a system-sensing wireless proximity card?
a)
magnetically striped card
b)
passive device
c)
field-powered device
d)
transponder
17.
Which of the following is the most costly countermeasure to reducing physical security risks?
a)
Procedural Controls
b)
Hardware Devices
c)
Electronic Systems
d)
Security Guards
18.
Which one of the following authentication mechanisms creates a problem for mobile users?
a)
Mechanisms based on IP addresses
b)
Mechanism with reusable passwords
c)
One-time password mechanism
d)
Challenge response mechanism
19.
In what type of attack does an attacker try, from several encrypted messages, to figure out the key used in the encryption process?
a)
Known-plaintext attack
b)
Ciphertext-only attack
c)
Chosen-Ciphertext attack
d)
Plaintext-only attack
20.
The RSA algorithm is an example of what type of cryptography?
a)
Asymmetric Key.
b)
Symmetric Key.
c)
Secret Key.
d)
Private Key
21.
What algorithm was DES derived from?
a)
Twofish.
b)
Skipjack.
c)
Brooks-Aldeman.
d)
Lucifer.
22.
What is a characteristic of using the Electronic Code Book mode of DES encryption?
a)
A given block of plaintext and a given key will always produce the same ciphertext
b)
Repetitive encryption obscures any repeated patterns that may have been present in the plaintext
c)
Individual characters are encoded by combining output from earlier encryption routines with plaintext.
d)
The previous DES output is used as input.
23.
Where parties do not have a shared secret and large quantities of sensitive information must , the most efficient means of transferring information is to use Hybrid Encryption Methods. What does this mean?
a)
Use of public key encryption to secure a secret key, and message encryption using the secret key.
b)
Use of the recipient's public key for encryption and decryption based on the recipient's private key.
c)
Use of software encryption assisted by a hardware encryption accelerator.
d)
Use of elliptic curve encryption.
24.
Public Key Infrastructure (PKI) uses asymmetric key encryption between parties. The originator encrypts information using the intended recipient's "public" key in order to get confidentiality of the data being sent. The recipients use their own "private" key to decrypt the information. The"Infrastructure" of this methodology ensures that:
a)
The sender and recipient have reached a mutual agreement on the encryption key exchange that they will use.
b)
The channels through which the information flows are secure.
c)
The recipient's identity can be positively verified by the sender.
d)
The sender of the message is the only other person with access to the recipient's private key.
25.
Kerberos depends upon what encryption method?
a)
Public Key cryptography
b)
Secret Key cryptography.
c)
El Gamal cryptography.
d)
Blowfish cryptography.
26.
Which of the following statements is TRUE about data encryption as a method of protecting data?
a)
It should sometimes be used for password files
b)
It is usually easily administered
c)
It makes few demands on system resources
d)
It requires careful key management
27.
Which type of algorithm is considered to have the highest strength per bit of key length of any of the asymmetric algorithms?
a)
Rivest, Shamir, Adleman (RSA)
b)
El Gamal
c)
Elliptic Curve Cryptography (ECC)
d)
Advanced Encryption Standard (AES)
28.
How many bits is the effective length of the key of the Data Encryption Standard algorithm?
a)
168
b)
128
c)
56
d)
64
29.
The primary purpose for using one-way hashing of user passwords within a password file is which of the following?
a)
It prevents an unauthorized person from trying multiple passwords in one logon attempt.
b)
It prevents an unauthorized person from reading the password
c)
It minimizes the amount of storage required for user passwords
d)
It minimizes the amount of processing time used for encrypting passwords.
30.
Which of the following issues is not addressed by digital signatures?
a)
nonrepudiation
b)
authentication
c)
data integrity
d)
denial-of-service
31.
Brute force attacks against encryption keys have increased in potency because of increased computing power. Which of the following is often considered a good protection against the brute force cryptography attack?
a)
The use of good key generators.
b)
The use of session keys.
c)
Nothing can defend you against a brute force crypto key attack.
d)
Algorithms that are immune to brute force key attacks.
32.
The Data Encryption Standard (DES) encryption algorithm has which of the following characteristics?
a)
64 bits of data input results in 56 bits of encrypted output
b)
128 bit key with 8 bits used for parity
c)
64 bit blocks with a 64 bit total key length
d)
56 bits of data input results in 56 bits of encrypted output
33.
PGP uses which of the following to encrypt data?
a)
An asymmetric encryption algorithm
b)
A symmetric encryption algorithm
c)
A symmetric key distribution system
d)
An X.509 digital certificate
34.
A public key algorithm that does both encryption and digital signature is which of the following?
a)
RSA
b)
DES
c)
IDEA
d)
Diffie-Hellman
35.
Which of the following is NOT true of Secure Sockets Layer (SSL)?
a)
By convention it uses 's-http://' instead of 'http://'.
b)
Is the predecessor to the Transport Layer Security (TLS) protocol
c)
It was developed by Netscape.
d)
D.It is used for transmitting private information, data, and documents over the Internet.
36.
There are parallels between the trust models in Kerberos and Public Key Infrastructure (PKI).When we compare them side by side, Kerberos tickets correspond most closely to which of thefollowing?
a)
public keys
b)
private keys
c)
public-key certificates
d)
private-key certificates
37.
Which of the following identifies the encryption algorithm selected by NIST for the new Advanced Encryption Standard?
a)
Twofish
b)
Serpent
c)
RC6
d)
Rijndael
38.
Compared to RSA, which of the following is true of Elliptic Curve Cryptography (ECC)?
a)
It has been mathematically proved to be more secure
b)
It has been mathematically proved to be less secure
c)
It is believed to require longer key for equivalent security.
d)
It is believed to require shorter keys for equivalent security.
39.
Which of the following algorithms does NOT provide hashing?
a)
SHA-1
b)
MD2
c)
RC4
d)
MD5
40.
Which of the following protocols that provide integrity and authentication for IPSec, can also provide non-repudiation in IPSec?
a)
Authentication Header (AH)
b)
Encapsulating Security Payload (ESP)
c)
Secure Sockets Layer (SSL)
d)
Secure Shell (SSH-2)
41.
Which of the following is a cryptographic protocol and infrastructure developed to send encrypted credit card numbers over the Internet?
a)
Secure Electronic Transaction (SET)
b)
MONDEX
c)
Secure Shell (SSH-2)
d)
Secure Hypertext Transfer Protocol (S-HTTP)
42.
Which of the following cryptographic attacks describes when the attacker has a copy of the plaintext and the corresponding ciphertext?
a)
known plaintext
b)
brute force
c)
ciphertext only
d)
chosen plaintext
43.
Which of the following is NOT a true statement regarding the implementation of the 3DES modes?
a)
DES-EEE1 uses one key
b)
DES-EEE2 uses two keys
c)
DES-EEE3 uses three keys
d)
DES-EDE2 uses two keys
44.
Which one of the following is a key agreement protocol used to enable two entities to agree and generate a session key (secret key used for one session) over an insecure medium without any prior secrets or communications between the entities? The negotiated key will subsequently be used for message encryption using Symmetric Cryptography.
a)
RSA
b)
PKI
c)
Diffie-Hellman
d)
3DES
45.
Which of the following ciphers is a subset on which the Vigenere polyalphabetic cipher was based on?
a)
Caesar
b)
The Jefferson disks
c)
Enigma
d)
SIGABA
46.
In a known plaintext attack, the cryptanalyst has knowledge of which of the following?
a)
the ciphertext and the key
b)
the plaintext and the secret key
c)
both the plaintext and the associated ciphertext of several messages
d)
the plaintext and the algorithm
47.
What is the length of an MD5 message digest?
a)
128 bits
b)
160 bits
c)
256 bits
d)
varies depending upon the message size
48.
The Secure Hash Algorithm (SHA-1) creates:
a)
a fixed length message digest from a fixed length input message
b)
a variable length message digest from a variable length input message.
c)
a fixed length message digest from a variable length input message.
d)
a variable length message digest from a fixed length input message
49.
The RSA Algorithm uses which mathematical concept as the basis of its encryption?
a)
Geometry
b)
16-round ciphers
c)
PI (3.14159...)
d)
Two large prime numbers
50.
The Clipper Chip utilizes which concept in public key cryptography?
a)
Substitution
b)
Key Escrow
c)
An undefined algorithm
d)
Super strong encryption
51.
Which of the following are suitable protocols for securing VPN connections at the lower layers of the OSI model?
a)
S/MIME and SSH
b)
TLS and SSL
c)
IPsec and L2TP
d)
PKCS#10 and X.509
52.
What is the role of IKE within the IPsec protocol?
a)
peer authentication and key exchange
b)
data encryption
c)
data signature
d)
enforcing quality of service
53.
In which phase of Internet Key Exchange (IKE) protocol is peer authentication performed?
a)
Pre Initialization Phase
b)
Phase 1
c)
Phase 2
d)
No peer authentication is performed
54.
What is NOT an authentication method within IKE and IPsec?
a)
CHAP
b)
Pre shared key
c)
certificate based authentication
d)
Public key authentication
55.
What is NOT true with pre shared key authentication within IKE / IPsec protocol?
a)
Pre shared key authentication is normally based on simple passwords
b)
Needs a Public Key Infrastructure (PKI) to work
c)
IKE is used to setup Security Associations
d)
IKE builds upon the Oakley protocol and the ISAKMP protocol.
56.
In a hierarchical PKI the highest CA is regularly called Root CA, it is also referred to by which one of the following term?
a)
Subordinate CA
b)
Top Level CA
c)
Big CA
d)
Master CA
57.
What is the primary role of cross certification?
a)
Creating trust between different PKIs
b)
Build an overall PKI hierarchy
c)
set up direct trust to a second root CA
d)
Prevent the nullification of user certificates by CA certificate revocation
58.
What kind of encryption is realized in the S/MIME-standard?
a)
Asymmetric encryption scheme
b)
Password based encryption scheme
c)
Public key based, hybrid encryption scheme
d)
Elliptic curve based encryption
59.
What is the main problem of the renewal of a root CA certificate?
a)
It requires key recovery of all end user keys
b)
It requires the authentic distribution of the new root CA certificate to all PKI participants
c)
It requires the collection of the old root CA certificates from all the users
d)
It requires issuance of the new root CA certificate
60.
Critical areas should be lighted:
a)
Eight feet high and two feet out.
b)
Eight feet high and four feet out.
c)
Ten feet high and four feet out
d)
Ten feet high and six feet out
Reset
