wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Certified Information Systems Security Professional (CISSP)

Total questions: 40

Worksheet time: 30mins

Name
Class
Date
1.

Which of the following type of traffic can easily be filtered with a stateful packet filter by enforcingthe context or state of the request?

a)

ICMP

b)

TCP

c)

UDP

d)

IP

2.

When referring to the data structures of a packet, the term Protocol Data Unit (PDU) is used, what is the proper term to refer to a single unit of TCP data at the transport layer?

a)

TCP segment.

b)

TCP datagram

c)

TCP frame

d)

TCP packet.

3.

How do you distinguish between a bridge and a router?

a)

A bridge simply connects multiple networks, a router examines each packet to determine which network to forward it to.

b)

"Bridge" and "router" are synonyms for equipment used to join two networks.

c)

The bridge is a specific type of router used to connect a LAN to the global Internet.

d)

The bridge connects multiple networks at the data link layer, while router connects multiple networks at the network layer.

4.

ICMP and IGMP belong to which layer of the OSI model?

a)

Datagram Layer

b)

Network Layer.

c)

Transport Layer

d)

Data Link Layer

5.

What is a limitation of TCP Wrappers?

a)

It cannot control access to running UDP services.

b)

It stops packets before they reach the application layer, thus confusing some proxy servers.

c)

The hosts.* access control system requires a complicated directory tree.

d)

They are too expensive.

6.

The IP header contains a protocol field. If this field contains the value of 1, what type of data is contained within the IP datagram?

a)

TCP.

b)

ICMP

c)

UDP

d)

IGMP

7.

The IP header contains a protocol field. If this field contains the value of 2, what type of data is contained within the IP datagram?

a)

TCP

b)

ICMP

c)

UDP

d)

IGMP

8.

What is the proper term to refer to a single unit of IP data?

a)

IP segment.

b)

IP datagram.

c)

IP frame

d)

IP fragment.

9.

A packet containing a long string of NOP's followed by a command is usually indicative of what?

a)

A syn scan

b)

A half-port scan

c)

A buffer overflow attack

d)

A packet destined for the network's broadcast address

10.

In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class C network?

a)

The first bit of the IP address would be set to zero.

b)

The first bit of the IP address would be set to one and the second bit set to zero.

c)

The first two bits of the IP address would be set to one, and the third bit set to zero.

d)

The first three bits of the IP address would be set to one

11.

Which of the following is an IP address that is private (i.e. reserved for internal networks, and not a valid address to use on the Internet)?

a)

192.168.42.5

b)

192.166.42.5

c)

192.175.42.5

d)

192.1.42.5

12.

In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class A network?

a)

The first bit of the IP address would be set to zero.

b)

The first bit of the IP address would be set to one and the second bit set to zero.

c)

The first two bits of the IP address would be set to one, and the third bit set to zero.

d)

The first three bits of the IP address would be set to one.

13.

Which of the following is an IP address that is private (i.e. reserved for internal networks, and not a valid address to use on the Internet)?

a)

10.0.42.5

b)

11.0.42.5

c)

12.0.42.5

d)

13.0.42.5

14.

Which one of the following authentication mechanisms creates a problem for mobile users?

a)

Mechanisms based on IP addresses

b)

Mechanism with reusable passwords

c)

one-time password mechanism

d)

challenge response mechanism

15.

Which of the following media is MOST resistant to tapping?

a)

microwave

b)

twisted pair

c)

coaxial cable

d)

fiber optic

16.

Which one of the following represents an ALE calculation?

a)

single loss expectancy x annualized rate of occurrence.

b)

gross loss expectancy x loss frequency.

c)

actual replacement cost - proceeds of salvage.

d)

asset value x loss expectancy

17.

The control of communications test equipment should be clearly addressed by security policy for which of the following reasons?

a)

Test equipment is easily damaged.

b)

Test equipment can be used to browse information passing on a network.

c)

Test equipment is difficult to replace if lost or stolen.

d)

Test equipment must always be available for the maintenance personnel.

18.

In discretionary access environments, which of the following entities is authorized to grant information access to other people?

a)

Manager

b)

Group Leader

c)

Security Manager

d)

Data Owner

19.

Which of the following groups represents the leading source of computer crime losses?

a)

Hackers

b)

Industrial saboteurs

c)

Foreign intelligence officers

d)

Employe

20.

Which of the following is the best reason for the use of an automated risk analysis tool?

a)

Much of the data gathered during the review cannot be reused for subsequent analysis.

b)

Automated methodologies require minimal training and knowledge of risk analysis.

c)

Most software tools have user interfaces that are easy to use and does not require any training

d)

Information gathering would be minimized and expedited due to the amount of information already built into the tool.

21.

Who is ultimately responsible for the security of computer based information systems within an organization?

a)

The tech support team

b)

The Operation Team

c)

The management team

d)

The training team.

22.

The major objective of system configuration management is which of the following?

a)

system maintenance

b)

system stability.

c)

system operations.

d)

system tracking.

23.

Who should measure the effectiveness of Information System security related controls in an organization?

a)

The local security specialist

b)

The business manager

c)

The systems auditor

d)

The central security manager

24.

A deviation from an organization-wide security policy requires which of the following?

a)

Risk Acceptance

b)

Risk Assignment

c)

Risk Reduction

d)

Risk Containment

25.

Which must bear the primary responsibility for determining the level of protection needed for information systems resources?

a)

IS security specialists

b)

Senior Management

c)

Senior security analysts

d)

systems Auditors

26.

Within the realm of IT security, which of the following combinations best defines risk?

a)

Threat coupled with a breach

b)

Threat coupled with a vulnerability

c)

Vulnerability coupled with an attack

d)

Threat coupled with a breach of security

27.

Which of the following is considered the weakest link in a security system?

a)

People

b)

Software

c)

Communications

d)

Hardware

28.

The ISO/IEC 27001:2005 is a standard for:

a)

Information Security Management System

b)

Implementation and certification of basic security measures

c)

Evaluation criteria for the validation of cryptographic algorithms

d)

Certification of public key infrastructures

29.

What would be the Annualized Rate of Occurrence (ARO) of the threat "user input error", in the case where a company employs 100 data entry clerks and every one of them makes one input error each month?

a)

100

b)

120

c)

1

d)

1200

30.

How is Annualized Loss Expectancy (ALE) derived from a threat?

a)

ARO x (SLE - EF)

b)

SLE x ARO

c)

SLE/EF

d)

AV x EF

31.

Configuration Management controls what?

a)

Auditing of changes to the Trusted Computing Base.

b)

Control of changes to the Trusted Computing Base.

c)

Changes in the configuration access to the Trusted Computing Base.

d)

Auditing and controlling any changes to the Trusted Computing Base.

32.

If an operating system permits shared resources such as memory to be used sequentially by multiple users/application or subjects without a refresh of the objects/memory area, what security problem is MOST likely to exist?

a)

Disclosure of residual data.

b)

Unauthorized obtaining of a privileged execution state.

c)

Data leakage through covert channels.

d)

Denial of service through a deadly embrace.

33.

Operations Security seeks to primarily protect against which of the following?

a)

object reuse

b)

facility disaster

c)

compromising emanations

d)

asset threats

34.

Which of the following components are considered part of the Trusted Computing Base?

a)

trusted hardware and firmware

b)

trusted hardware and software

c)

trusted hardware, software and firmware

d)

trusted computer operators and system managers

35.

Which of the following is NOT an example of an operational control?

a)

backup and recovery

b)

Auditing

c)

contingency planning

d)

operations procedures

36.

Degaussing is used to clear data from all of the following medias except:

a)

Floppy Disks

b)

Read-Only Media

c)

Video Tapes

d)

Magnetic Hard Disks

37.

It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?

a)

security administrator

b)

security analyst

c)

systems auditor

d)

systems programmer

38.

When backing up an applications system's data, which of the following is a key question to be answered first?

a)

When to make backups

b)

Where to keep backups

c)

What records to backup

d)

How to store backups

39.

The number of violations that will be accepted or forgiven before a violation record is produced is called which of the following?

a)

clipping level

b)

acceptance level

c)

forgiveness level

d)

logging level

40.

The Orange Book requires auditing mechanisms for any systems evaluated at which of the following levels?

a)

C1 and above

b)

C2 and above

c)

B1 and above

d)

B2 and above