Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CISSP CH2 Asset Security

Total questions: 34

Worksheet time: 2hrs 28mins

Name
Class
Date
1.

The ULTIMATE goal of data classification is to

a)

Determine the sensitivity

b)

Determine the criticality

c)

Apply proper security controls

d)

Integrate with security policy

2.

Data Criticality means

a)

The maximum acceptable amount of time the data is not available

b)

The highest security clearance required to access data

c)

The minimum acceptable loss of data

d)

The maximum acceptable data exposure

3.

Data classification is done by

a)

Senior Management

b)

Security Proffessional

c)

Data Custodians

d)

Data Owner

4.

The BEST control to protect data hosted on Microsoft Windows is

a)

Apply Windows EFS

b)

Apply Windows NTFS

c)

Apply Widows Strong Password Policy

d)

Apply Trusted Platform Module Encryption

5.

The FIRST step to protect the privacy of data while it is motion

a)

Apply Encryption

b)

Classify Data

c)

Apply Hash

d)

Setup Virtual Private Network

6.

The process that compensates the system's functionality or lack of security

a)

Incident Management process

b)

Configuration Management process

c)

Patch Management Process

d)

None of the above

7.

While working as a security professional, you noticed an egress connection going out of mission critical to a strange server on port 7777 TCP for long time. What is the FIRST thing you should do ?

a)

Reroute the traffic to the Intrusion Prevention System for analysis

b)

Block the port on the firewall

c)

Invoke the incident management process

d)

Try to connect to the destination IP and Port

8.

"Meta data" is term that is used to describe

a)

Sensitivity of the data

b)

Data about the data

c)

Criticality of the data

d)

Completeness of the data

9.

The BEST solution to protect data while it is in motion

a)

Enable TLS 1.2

b)

Enable NTFS

c)

Enable SSL v5

d)

Enable EFS

10.

Company ABC has data retention policy for confidential data for 7 years on backup tapes. What is the BEST way to destroy the old backups

a)

Wipe it

b)

Delete it

c)

Shred it

d)

Label it

11.

You are security professional. During a Disaster Recovery drill , your manager instructed you take the Firewall configuration on a flash drive. Now the drill is over what is FIRST action you should do ?

a)

Advise the management about better ways to backup Firewall configuration

b)

Delete the configuration files

c)

Wipe the configuration files

d)

Use flash drive's vendor tools to clean it and restore the factory defaults

12.

Data Policy may include the following, Except

a)

Cost

b)

Ownership

c)

Liability

d)

Data Classification

13.

Data Policy may NOT include the following, EXCEPT

a)

Cost

b)

Data verification

c)

Data validation

d)

Data Classification

14.

What functions can the Data owner do

a)

Create data

b)

Use data

c)

Destroy data

d)

All mentioned

15.

Credit Card Data custodians may be one of the following EXCEPT

a)

Project Manager

b)

Database Administrator

c)

Application developer

d)

Credit line department

16.

Data quality standards may include the following EXCEPT

a)

Accuracy

b)

Resolution

c)

Ability to audit

d)

Access control

17.

_____ is an assessment process based on external standards

a)

Validation

b)

Verification

c)

Quality Assurance

d)

Quality Control

18.

_____ is an assessment process based on internal standards

a)

Validation

b)

Verification

c)

Quality Assurance

d)

Quality Control

19.

Firewall administrator has configured the firewall logging function. The FIRST thing you need to check is logs

a)

Validation

b)

Verification

c)

Quality Assurance

d)

Quality Control

20.

Matching the source data with the digitized data is called

a)

Validation

b)

Verification

c)

Quality Assurance

d)

Quality Control

21.

Issues to be considered by the security practitioner when establishing a data policy include:

a)

Cost, due care and due diligence, privacy, Liability, sensitivity , existing law , policy and process

b)

Cost, ownership and custodianship, privacy, Liability, sensitivity , future law , policy and process

c)

Cost, ownership and custodianship, privacy, Liability, sensitivity , existing law , policy and procedure

d)

Cost, ownership and custodianship, privacy, Liability, sensitivity , existing law , policy and process

22.

QC is designed to prevent data contamination, which occurs when a process or event introduces HIGHEST risk error into a data set

a)

Errors of commission

b)

Errors of Insertion

c)

Errors of Omission

d)

Errors of creation

23.

In the event of a security incident. one of the primary objectives of the operation staff is ensure that

a)

The attackers are detected and stopped

b)

There is a minimal disruption to the organization's mission

c)

Appropriate documentation abojut the event is maintained as chain of evidence

d)

The affected systems are immediately shut off to limit the impact.

24.

You are security pen tester, who just has discovered a buffer-over flow vulnerability in one your corporate C++ critical applications. What is BEST advise you can give to the developers ?

a)

Place a Firewall

b)

Use different programming language other than C++

c)

Encrypt code

d)

Use Canary words

25.

You were hired by your company to perform risk assessment. You found the risk of Data loss, higher than the company risk appetite . Your next step is..

a)

Purchase a Data Loss Prevention technology

b)

Document the risk and update the risk registry

c)

Perform qualitative risk analysis

d)

Perform quantitative risk analysis

26.

You are security administrator, and you are requested to configure the logging of one of the mission critical applications , what is the FIRST thing you need to do ?

a)

Encrypt logs to maintain confidentiality

b)

Hash logs to maintain integrity

c)

Check the time stamp is correct

d)

Backup logs

27.

Your company outsourced the Customer Service Feedback services to a third party. What is the best way to detect if this TP leaked your company's data?***

a)

Hash the data

b)

Encrypt Data

c)

Scramble the Data

d)

Place the Dummy records

28.

What is the BEST way to verify a system's Vulnerability ?

a)

Perform Code review

b)

Perform logs review

c)

Perform Pen testing exercise

d)

Check System documentation

29.

The FIRST step in risk assessment is to perform...

a)

Business Impact Analysis

b)

Qualitative risk assessment

c)

Perform Asset inventory

d)

Quantitative risk assessment

30.

Your company needs to exchange data with European company. In order to do so, your company needs to be

a)

Serbanes-Oxley complient

b)

Safe Harbor complient

c)

HIPAA complient

d)

ISO 27001 complient

31.

A technique that is used to split the Personal Identifiable Information (PII) from Protected Health Information (PHI)

a)

Data Annonymization

b)

Data Scrambling

c)

Data Pseudonymization

d)

Data Encryption

32.

Your company has identified a potential risk that employees may share secret trade information after leaving the company, what is your advise as a security professional ?

a)

Encrypt secret trade information

b)

implement Multi factor authentication mechanism

c)

Force employees to sign NDA

d)

Declassify the trade information

33.

In General Data Protection Regulation (GDPR) , Data masking is one way to implement..

a)

Annonymization

b)

Pseudonymization

c)

Artificial Identifiers

d)

Data scrambling

34.

A task the Data custodian may NOT do, EXCEPT

a)

Classify data

b)

Backup data

c)

assign permission to data users

d)

Access Data