WorksheetsCISSP Domain 7
Total questions: 20
Worksheet time: 2hrs 40mins
An organization is found lacking the ability to properly establish performance indicators for its Web hosting solution during an audit. What would be the MOST probable cause?
Absence of a Business Intelligence (BI) solution
Inadequate cost modeling
Improper deployment of the Service-Oriented Architecture (SOA)
Insufficient Service Level Agreement (SLA)
What is the PRIMARY reason for implementing change management?
Certify and approve releases to the environment
Provide version rollbacks for system changes
Ensure that all applications are approved
Ensure accountability for changes to the environment
Which of the following is a PRIMARY advantage of using a third-party identity service?
Consolidation of multiple providers
Directory synchronization
Web based logon
Automated account management
With what frequency should monitoring of a control occur when implementing Information Security Continuous Monitoring (ISCM) solutions?
Continuously without exception for all security controls
Before and after each change of the control
At a rate concurrent with the volatility of the security control
Only during system implementation and decommissioning
A Business Continuity Plan/Disaster Recovery Plan (BCP/DRP) will provide which of the following?
Guaranteed recovery of all business functions
Minimization of the need decision making during a crisis
Insurance against litigation following a disaster
Protection from loss of organization resources
Which of the following is the FIRST step in the incident response process?
Determine the cause of the incident
Disconnect the system involved from the network
Isolate and contain the system involved
Investigate all symptoms to confirm the incident
A continuous information security monitoring program can BEST reduce risk through which of the following?
Collecting security events and correlating them to identify anomalies
Facilitating system-wide visibility into the activities of critical user accounts
Encompassing people, process, and technology
Logging both scheduled and unscheduled system changes
which of the following is MOST important to minimize potential impact when implementing a new vulnerability scanning tool in a production environment?
Negotiate schedule with the Information Technology (IT) operation’s team
Log vulnerability summary reports to a secured server
Enable scanning during off-peak hours
Establish access for Information Technology (IT) management
A Security Operations Center (SOC) receives an incident response notification on a server with an active intruder who has planted a backdoor. Initial notifications are sent and communications are established.
What MUST be considered or evaluated before performing the next step?
Notifying law enforcement is crucial before hashing the contents of the server hard drive
Identifying who executed the incident is more important than how the incident happened
Removing the server from the network may prevent catching the intruder
Copying the contents of the hard drive to another storage device may damage the evidence
Operations Security seeks to PRIMARILY protect against which of the following?
Risk Control
Facility Disaster
Compromisation
Asset Threats
Which of the following is a violation of the least privilege principle?
A user has access to only the files needed to perform their specific job functions
An administrator has unrestricted access to critical systems as well as non-essential systems
A temporary contractor is requesting access that expires when their contract ends
A software application is given permissions to only the resources it requires to run
Forensic
Alarm System
CCTV
Which of the following actions is typically performed by a SIEM system to improve threat detection?
Analyzing unauthorized IP addresses from accessing the network
Correlating events from various sources to identify suspicious patterns
Analyzing events to match risk register
Correlating risk knowledge to various events to help security goal
What type security control if organization decide to build Forensic team
Administrative Preventive
Technical Detective
Physical Correction
Administrative Deterrent
Which of the following scenarios best demonstrates the principle of segregation of duties?
One employee is responsible for both approving and processing expense reimbursements
The network administrator is responsible for managing and and security manager auditing firewall configurations.
A software developer can write code, but a different employee must review and approve the code before deployment.s
The security team monitors physical and digital access controls within the organization but vendors execute the operation
