WorksheetsCertified Information Systems Security Professional (CISSP)
Total questions: 40
Worksheet time: 30mins
Which of the following type of traffic can easily be filtered with a stateful packet filter by enforcingthe context or state of the request?
ICMP
TCP
UDP
IP
When referring to the data structures of a packet, the term Protocol Data Unit (PDU) is used, what is the proper term to refer to a single unit of TCP data at the transport layer?
TCP segment.
TCP datagram
TCP frame
TCP packet.
How do you distinguish between a bridge and a router?
A bridge simply connects multiple networks, a router examines each packet to determine which network to forward it to.
"Bridge" and "router" are synonyms for equipment used to join two networks.
The bridge is a specific type of router used to connect a LAN to the global Internet.
The bridge connects multiple networks at the data link layer, while router connects multiple networks at the network layer.
ICMP and IGMP belong to which layer of the OSI model?
Datagram Layer
Network Layer.
Transport Layer
Data Link Layer
What is a limitation of TCP Wrappers?
It cannot control access to running UDP services.
It stops packets before they reach the application layer, thus confusing some proxy servers.
The hosts.* access control system requires a complicated directory tree.
They are too expensive.
The IP header contains a protocol field. If this field contains the value of 1, what type of data is contained within the IP datagram?
TCP.
ICMP
UDP
IGMP
The IP header contains a protocol field. If this field contains the value of 2, what type of data is contained within the IP datagram?
TCP
ICMP
UDP
IGMP
What is the proper term to refer to a single unit of IP data?
IP segment.
IP datagram.
IP frame
IP fragment.
A packet containing a long string of NOP's followed by a command is usually indicative of what?
A syn scan
A half-port scan
A buffer overflow attack
A packet destined for the network's broadcast address
In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class C network?
The first bit of the IP address would be set to zero.
The first bit of the IP address would be set to one and the second bit set to zero.
The first two bits of the IP address would be set to one, and the third bit set to zero.
The first three bits of the IP address would be set to one
Which of the following is an IP address that is private (i.e. reserved for internal networks, and not a valid address to use on the Internet)?
192.168.42.5
192.166.42.5
192.175.42.5
192.1.42.5
In the days before CIDR (Classless Internet Domain Routing), networks were commonly organized by classes. Which of the following would have been true of a Class A network?
The first bit of the IP address would be set to zero.
The first bit of the IP address would be set to one and the second bit set to zero.
The first two bits of the IP address would be set to one, and the third bit set to zero.
The first three bits of the IP address would be set to one.
Which of the following is an IP address that is private (i.e. reserved for internal networks, and not a valid address to use on the Internet)?
10.0.42.5
11.0.42.5
12.0.42.5
13.0.42.5
Which one of the following authentication mechanisms creates a problem for mobile users?
Mechanisms based on IP addresses
Mechanism with reusable passwords
one-time password mechanism
challenge response mechanism
Which of the following media is MOST resistant to tapping?
microwave
twisted pair
coaxial cable
fiber optic
Which one of the following represents an ALE calculation?
single loss expectancy x annualized rate of occurrence.
gross loss expectancy x loss frequency.
actual replacement cost - proceeds of salvage.
asset value x loss expectancy
The control of communications test equipment should be clearly addressed by security policy for which of the following reasons?
Test equipment is easily damaged.
Test equipment can be used to browse information passing on a network.
Test equipment is difficult to replace if lost or stolen.
Test equipment must always be available for the maintenance personnel.
In discretionary access environments, which of the following entities is authorized to grant information access to other people?
Manager
Group Leader
Security Manager
Data Owner
Which of the following groups represents the leading source of computer crime losses?
Hackers
Industrial saboteurs
Foreign intelligence officers
Employe
Which of the following is the best reason for the use of an automated risk analysis tool?
Much of the data gathered during the review cannot be reused for subsequent analysis.
Automated methodologies require minimal training and knowledge of risk analysis.
Most software tools have user interfaces that are easy to use and does not require any training
Information gathering would be minimized and expedited due to the amount of information already built into the tool.
Who is ultimately responsible for the security of computer based information systems within an organization?
The tech support team
The Operation Team
The management team
The training team.
The major objective of system configuration management is which of the following?
system maintenance
system stability.
system operations.
system tracking.
Who should measure the effectiveness of Information System security related controls in an organization?
The local security specialist
The business manager
The systems auditor
The central security manager
A deviation from an organization-wide security policy requires which of the following?
Risk Acceptance
Risk Assignment
Risk Reduction
Risk Containment
Which must bear the primary responsibility for determining the level of protection needed for information systems resources?
IS security specialists
Senior Management
Senior security analysts
systems Auditors
Within the realm of IT security, which of the following combinations best defines risk?
Threat coupled with a breach
Threat coupled with a vulnerability
Vulnerability coupled with an attack
Threat coupled with a breach of security
Which of the following is considered the weakest link in a security system?
People
Software
Communications
Hardware
The ISO/IEC 27001:2005 is a standard for:
Information Security Management System
Implementation and certification of basic security measures
Evaluation criteria for the validation of cryptographic algorithms
Certification of public key infrastructures
What would be the Annualized Rate of Occurrence (ARO) of the threat "user input error", in the case where a company employs 100 data entry clerks and every one of them makes one input error each month?
100
120
1
1200
How is Annualized Loss Expectancy (ALE) derived from a threat?
ARO x (SLE - EF)
SLE x ARO
SLE/EF
AV x EF
Configuration Management controls what?
Auditing of changes to the Trusted Computing Base.
Control of changes to the Trusted Computing Base.
Changes in the configuration access to the Trusted Computing Base.
Auditing and controlling any changes to the Trusted Computing Base.
If an operating system permits shared resources such as memory to be used sequentially by multiple users/application or subjects without a refresh of the objects/memory area, what security problem is MOST likely to exist?
Disclosure of residual data.
Unauthorized obtaining of a privileged execution state.
Data leakage through covert channels.
Denial of service through a deadly embrace.
Operations Security seeks to primarily protect against which of the following?
object reuse
facility disaster
compromising emanations
asset threats
Which of the following components are considered part of the Trusted Computing Base?
trusted hardware and firmware
trusted hardware and software
trusted hardware, software and firmware
trusted computer operators and system managers
Which of the following is NOT an example of an operational control?
backup and recovery
Auditing
contingency planning
operations procedures
Degaussing is used to clear data from all of the following medias except:
Floppy Disks
Read-Only Media
Video Tapes
Magnetic Hard Disks
It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?
security administrator
security analyst
systems auditor
systems programmer
When backing up an applications system's data, which of the following is a key question to be answered first?
When to make backups
Where to keep backups
What records to backup
How to store backups
The number of violations that will be accepted or forgiven before a violation record is produced is called which of the following?
clipping level
acceptance level
forgiveness level
logging level
The Orange Book requires auditing mechanisms for any systems evaluated at which of the following levels?
C1 and above
C2 and above
B1 and above
B2 and above
