WorksheetsCISSP CH2 Asset Security
Total questions: 34
Worksheet time: 2hrs 28mins
The ULTIMATE goal of data classification is to
Determine the sensitivity
Determine the criticality
Apply proper security controls
Integrate with security policy
Data Criticality means
The maximum acceptable amount of time the data is not available
The highest security clearance required to access data
The minimum acceptable loss of data
The maximum acceptable data exposure
Data classification is done by
Senior Management
Security Proffessional
Data Custodians
Data Owner
The BEST control to protect data hosted on Microsoft Windows is
Apply Windows EFS
Apply Windows NTFS
Apply Widows Strong Password Policy
Apply Trusted Platform Module Encryption
The FIRST step to protect the privacy of data while it is motion
Apply Encryption
Classify Data
Apply Hash
Setup Virtual Private Network
The process that compensates the system's functionality or lack of security
Incident Management process
Configuration Management process
Patch Management Process
None of the above
While working as a security professional, you noticed an egress connection going out of mission critical to a strange server on port 7777 TCP for long time. What is the FIRST thing you should do ?
Reroute the traffic to the Intrusion Prevention System for analysis
Block the port on the firewall
Invoke the incident management process
Try to connect to the destination IP and Port
"Meta data" is term that is used to describe
Sensitivity of the data
Data about the data
Criticality of the data
Completeness of the data
The BEST solution to protect data while it is in motion
Enable TLS 1.2
Enable NTFS
Enable SSL v5
Enable EFS
Company ABC has data retention policy for confidential data for 7 years on backup tapes. What is the BEST way to destroy the old backups
Wipe it
Delete it
Shred it
Label it
You are security professional. During a Disaster Recovery drill , your manager instructed you take the Firewall configuration on a flash drive. Now the drill is over what is FIRST action you should do ?
Advise the management about better ways to backup Firewall configuration
Delete the configuration files
Wipe the configuration files
Use flash drive's vendor tools to clean it and restore the factory defaults
Data Policy may include the following, Except
Cost
Ownership
Liability
Data Classification
Data Policy may NOT include the following, EXCEPT
Cost
Data verification
Data validation
Data Classification
What functions can the Data owner do
Create data
Use data
Destroy data
All mentioned
Credit Card Data custodians may be one of the following EXCEPT
Project Manager
Database Administrator
Application developer
Credit line department
Data quality standards may include the following EXCEPT
Accuracy
Resolution
Ability to audit
Access control
_____ is an assessment process based on external standards
Validation
Verification
Quality Assurance
Quality Control
_____ is an assessment process based on internal standards
Validation
Verification
Quality Assurance
Quality Control
Firewall administrator has configured the firewall logging function. The FIRST thing you need to check is logs
Validation
Verification
Quality Assurance
Quality Control
Matching the source data with the digitized data is called
Validation
Verification
Quality Assurance
Quality Control
Issues to be considered by the security practitioner when establishing a data policy include:
Cost, due care and due diligence, privacy, Liability, sensitivity , existing law , policy and process
Cost, ownership and custodianship, privacy, Liability, sensitivity , future law , policy and process
Cost, ownership and custodianship, privacy, Liability, sensitivity , existing law , policy and procedure
Cost, ownership and custodianship, privacy, Liability, sensitivity , existing law , policy and process
QC is designed to prevent data contamination, which occurs when a process or event introduces HIGHEST risk error into a data set
Errors of commission
Errors of Insertion
Errors of Omission
Errors of creation
In the event of a security incident. one of the primary objectives of the operation staff is ensure that
The attackers are detected and stopped
There is a minimal disruption to the organization's mission
Appropriate documentation abojut the event is maintained as chain of evidence
The affected systems are immediately shut off to limit the impact.
You are security pen tester, who just has discovered a buffer-over flow vulnerability in one your corporate C++ critical applications. What is BEST advise you can give to the developers ?
Place a Firewall
Use different programming language other than C++
Encrypt code
Use Canary words
You were hired by your company to perform risk assessment. You found the risk of Data loss, higher than the company risk appetite . Your next step is..
Purchase a Data Loss Prevention technology
Document the risk and update the risk registry
Perform qualitative risk analysis
Perform quantitative risk analysis
You are security administrator, and you are requested to configure the logging of one of the mission critical applications , what is the FIRST thing you need to do ?
Encrypt logs to maintain confidentiality
Hash logs to maintain integrity
Check the time stamp is correct
Backup logs
Your company outsourced the Customer Service Feedback services to a third party. What is the best way to detect if this TP leaked your company's data?***
Hash the data
Encrypt Data
Scramble the Data
Place the Dummy records
What is the BEST way to verify a system's Vulnerability ?
Perform Code review
Perform logs review
Perform Pen testing exercise
Check System documentation
The FIRST step in risk assessment is to perform...
Business Impact Analysis
Qualitative risk assessment
Perform Asset inventory
Quantitative risk assessment
Your company needs to exchange data with European company. In order to do so, your company needs to be
Serbanes-Oxley complient
Safe Harbor complient
HIPAA complient
ISO 27001 complient
A technique that is used to split the Personal Identifiable Information (PII) from Protected Health Information (PHI)
Data Annonymization
Data Scrambling
Data Pseudonymization
Data Encryption
Your company has identified a potential risk that employees may share secret trade information after leaving the company, what is your advise as a security professional ?
Encrypt secret trade information
implement Multi factor authentication mechanism
Force employees to sign NDA
Declassify the trade information
In General Data Protection Regulation (GDPR) , Data masking is one way to implement..
Annonymization
Pseudonymization
Artificial Identifiers
Data scrambling
A task the Data custodian may NOT do, EXCEPT
Classify data
Backup data
assign permission to data users
Access Data
