Font size
WorksheetsCISSP Final
Total questions: 98
Worksheet time: 2hrs 38mins
Responsibility primarily rests with the customer
Responsibility primarily rests with the provider
Responsibility is shared between the customer and provider
Responsibility primarily rests with the cloud access security broker
In a federated identity access management solution, what task is most commonly handled by the identity provider (IdP)?
Identification
Authorization
Provisioning
Authentication
Threat hunting
Threat modeling
Penetration testing
Vulnerability scanning
You recently performed a vulnerability assessment and found hundreds of vulnerabilities in your organization's infrastructure. It will take months to address all of these issues. What factors should you use to prioritize these vulnerabilities?
Likelihood and probability
Impact and exploitability
Impact and CVSS score
Likelihood and impact
You are attempting to secure a wired network belonging to your organization. You would like to deploy technology that limits network access to authorized users. Which one of the following technologies would best meet that need?
WiFi Protected Access v2 (WPA2)
WiFi Protected Access v3 (WPA3)
IEEE 802.1x
MAC filtering
A user connected a device to your network and, when they open their web browser, are redirected to a website advising them that they have been placed on an isolation network because their system does not meet the organization's security requirements. They are unable to access any network resources until they remediate their device to comply with the organization's security policy. What type of security solution is in use on this network?
Intrusion Prevention System (IPS)
Configuration Management (CM) platform
Network Access Control (NAC)
Endpoint Detection and Response (EDR) platform
Remove the hard drive from the device
Power on the laptop
Connect to the hard drive with a forensic software package
Connect a write blocker to the device
Implementation
Governance
Verification
Operations
You are working with the team developing a new web application and you would like to perform a test that evaluates whether the application is able to successfully handle malicious input that it receives through that interface. Which one of the following activities would best meet this need?
Input validation
Parameterized queries
Stored procedures
Fuzz testing
What is the primary goal of change management in an organization?
Reducing the likelihood of service disruptions
Communicating to all affected stakeholders
Creating an auditable record
Organizing the work associated with a change
Amy's organization uses quite a bit of open source software in their custom development work and she is concerned about the security impact of that use. What program can she deploy to help track the use of this software and identify outdated components?
Software Configuration Management (SCM)
Software as a Service (SaaS)
Commericial-off-the-Shelf (COTS)
Security Orchestration, Automation, and Response (SOAR)
Chief Information Security Officer (CISO)
Chief Information Officer (CIO)
Chief Financial Officer (CFO)
Board of Directors
You are encrypting a message that you plan to send to your supervisor using asymmetric encryption. Your goal is to protect the confidentiality of the message while it is in transit. What key should you use to encrypt the message?
Your supervisor's private key
Your own public key
Your supervisor's public key
Your own private key
Dynamic Application Security Testing (DAST)
Interactive Application Security Testing (IAST)
Static Application Security Testing (SAST)
Code review
WPA2 with PSK authentication
WPA2 with WPS enabled
WPA2 with enterprise authenticaiton
WPA2 with a captive portal
MAC
RBAC
DAC
ABAC
What is the most common standard of evidence used in a criminal investigation?
Preponderance of the evidence
Beyond a reasonable doubt
Beyond a shadow of a doubt
Clear and convincing evidence
You are interviewing business leaders as part of a business impact assessment (BIA) of an enterprise resource planning (ERP) system. The goal of these conversations is to determine how long each business function can operate effectively during an incident that disrupts access to the ERP. What term describes the output of these conversations?
MTD
RTO
RPO
AV
ssh
Nmap
Kerberos
sudo
Your own public key
Your client's public key
Your own private key
Your client's private key
Francis is an identity and access management professional at a very large corporation. She is reviewing her organization's process for revoking access assigned to terminated employees. What action would BEST protect the organization against the risks associated with a terminated employee's account?
Delete the account
Disable the account
Revoke all permissions from the account
Change the account's password
Policy
Standard
Guideline
Procedure
Which layer of the OSI model is primarily concerned with MAC addresses?
Application layer
Presentation layer
Datalink layer
Transport layer
You are upgrading servers in your organization to use the latest version of the TLS protocol in conjunction with approved cipher suites. What type of data will this control best protect?
Data in use
Data in transit
Data at rest
Data in memory
Secure tokens
Stored procedures
Parameterized queries
Input validation
Red team exercise
Penetration test
Vulnerability scan
Breach and attack simulation (BAS)
Carla is the security compliance officer for a large chain of retail stores. As part of her PCI DSS compliance work, Carla discovers that the organization routinely sends cardholder data to a service provider who helps detect fraudulent transactions. Under PCI DSS, what is Carla obligated to do?
Perform an annual penetration test of the service provider
Verify that the service provider appears on the list of validated service providers
Perform quarterly vulnerability scanning of the service provider
Review the results of an external audit of the service provider and ensure any criticalfindings are remediated
In an organization's identity management (IdM) program, which one of the following technologies is commonly used as an authorization mechanism for internal users?
Multifactor authentication (MFA)
Passwords
OAuth2
Access control list (ACL)
Refuse the request because it violates past precedent
Refer the request to the data owner
Grant the request because it aligns with business objectives
Refer the request to the CISO
Detective
Preventive
Corrective
Compensating
You are designing a back-end authentication system for your company and would like to choose an approach that allows you to implement single sign-on (SSO) and directly integrates with the Windows and Linux systems you have in place. Which one of the following technologies would best meet this need?
OAuth2
RADIUS
Kerberos
IEEE 802.1x
Confidentiality
Nonrepudiation
Integrity
Availability
You are reviewing the security controls for a banking website and would like to ensure that the site is protected against man-in-the-middle (MITM) attacks. Which one of the following security controls would best protect against this type of attack?
SSL
SSH
TLS
AES
You are evaluating possible upgrades to a physical data center used by your organization. Your primary concern is ensuring that the facility is able to continue operating during an extended power outage. What control would best meet this goal?
Uninterruptible power supply
Power conditioning
Backup generator
Alternate processing facility
Data steward
Data custodian
Data owner
Data processor
Which one of the following events should be considered the final deadline for discontinuing the use of an IT product or service in an organization?
EOL
EOS
ETA
ELA
You are deploying a redundant array of inexpensive disks (RAID) to improve the redundancy of your storage system. You have chosen to implement RAID level 5. What is the minimum number of disks that you must use to implement this solution?
2
5
3
1
Full disk encryption
Host-based firewalls
Containerization
Endpoint detection and response
Your organization recently signed a contract with a service provider who will be maintaining manufacturing equipment at a variety of field sites. The provider requires access to some of your internal systems in order to view and update work orders so you are establishing connectivity to your network for them. The connection will be an always-on virtual private network (VPN) between your locations. What is the most appropriate location on your network to terminate the connection?
Intranet
Internet
Extranet
Demilitarized Zone (DMZ) network
Security orchestration, automation, and response (SOAR)
Security information and event management (SIEM)
Endpoint detection and response (EDR)
Managed detection and response (MDR)
You are deploying a virtual private network (VPN) to support remote users who will be telecommuting but require access to internal resources. Where would be the most appropriate location to place the VPN server?
Internal network
Outside the firewall on the public Internet
Demilitarized zone (DMZ) network
Data center network
Which one of the following is the best example of a security awareness activity that might be used as part of an organization's information security program?
Mandatory computer-based training
Posters in the hallway
Specialized training for security administrators
Optional classroom training
You are responsible for managing your organization's firewall and require remote command-line access to the device. Which one of the following tools will best meet this requirement?
HTTPS
IPsec
SSH
Telnet
Block packets with internal source addresses from entering the network.
Block packets with external source addresses from leaving the network.
Block packets with public IP addresses from entering the network.
Block packets with private IP addresses from exiting the network.
Preventing the modification of data on a storage device
Returning data requested from the device
Reporting errors sent by the device to the forensic host
Blocking read commands sent to the device
KDC
TGT
AS
TGS
Infrared
Heat-based
Wave pattern
Capacitance
A static packet filtering firewall
An application-level gateway firewall
A stateful packet inspection firewall
A circuit-level gateway firewall
Please refer to the following scenario: Ben owns a coffeehouse and wants to provide wireless internet service for his customers. Ben's network is simple and uses a single consumer-grade wireless router and a cable modem connected via a commercial cable data contract.
Ben intends to run an open (unencrypted) wireless network. How should he connect his business devices?
Run WPA3 on the same SSID.
Set up a separate SSID using WPA3.
Run the open network in Enterprise mode.
Set up a separate wireless network using WEP.
Thresholding
Sampling
Account lockout
Clipping
Virus
Worm
Trojan horse
Logic bomb
FERPA
HIPAA
SOX
PCI DSS
Advance and protect the profession.
Act honorably, honestly, justly, responsibly, and legally.
Protect society, the common good, necessary public trust and confidence, and the infrastructure.
Provide diligent and competent service to principals.
12.8.195.15
10.8.15.9
192.168.109.55
129.53.44.124
Change log
Application log
System log
Firewall log
CVSS
STRIDE
PASTA
ATT&CK
Tampering by an unauthorized third party at the vendor's site
Interception of devices in transit
Misconfiguration by an administrator after installation
Tampering by an unauthorized third party at Greg's site
The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.
If availability of authentication services is the organization's biggest priority, what type of identity platform should Ben recommend?
On-site
Cloud-based
Hybrid
Outsourced
The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.
If Ben needs to share identity information with the business partner shown, what should he investigate?
Single sign-on
Multifactor authentication
Federation
IDaaS
The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.
What technology is likely to be involved when Ben's organization needs to provide authentication and authorization assertions to their cloud e-commerce application?
Active Directory
SAML
RADIUS
SPML
Plaintext passwords
Encrypted passwords
Hashed passwords
x
Prepare to discontinue use of the platform as soon as possible.
Immediately discontinue use of the device.
Prepare to discontinue use of the device as part of the organization's normal planning cycle.
No action is necessary.
Least privilege
Separation of duties
Due care
Due diligence
Passive
Proactive
Reactive
Replay
Consult the organization's records retention policy.
Consult IRS requirements.
Retain the records for at least seven years.
Retain the records permanently.
They have a high FRR and should be replaced.
A second factor should be added because they are not a good way to reliably distinguish individuals.
The hand geometry scanners provide appropriate security for the data center and should be considered for other high-security areas.
They may create accessibility concerns, and an alternate biometric system should be considered.
MTD
ALE
RPO
RTO
DRM
IPS
CASB
DLP
Masquerading
Replay
Spoofing
Modification
OpenID Connect
SAML
RADIUS
Kerberos
Real evidence rule
Best evidence rule
Parol evidence rule
Testimonial evidence rule
NAT
VLANs
S/NAT
BGP
Elliott's private key
Elliott's public key
Recipient's private key
Recipient's public key
Motion detectors
Guard dogs
Mantraps
Lighting
SaaS
PaaS
IaaS
Containerization
Known plaintext
Chosen ciphertext
Frequency analysis
Brute-force
Alex has been with the university he works at for more than 10 years. During that time, he has been a system administrator and a database administrator, and he has worked in the university's help desk. He is now a manager for the team that runs the university's web applications.
Alex hires a new employee and the employee's account is provisioned after HR manually inputs information into the provisioning system based on data Alex provides via a series of forms, what type of provisioning has occurred?
Discretionary account provisioning
Workflow-based account provisioning
Automated account provisioning
Self-service account provisioning
It has been functionally tested.
It has been structurally tested.
It has been formally verified, designed, and tested.
It has been semiformally designed and tested.
MD5
RIPEMD
SHA-2
SHA-3
Encapsulation
Packet unwrapping
De-encapsulation
Payloading
Natural intrusion detection
Natural access control
Natural surveillance
Natural territorial reinforcement
SAML
SAMPL
SPML
XACML
Hierarchical
Bracketed
Compartmentalized
Hybrid
6
12
15
36
Cat 5 and Cat 6
Cat 5e and Cat 6
Cat 4e and Cat 5e
Cat 6 and Cat 7
IaaS
Containerization
CDN
SaaS
Block the source IP address of the attack.
Block inbound UDP traffic.
Block the destination IP address of the attack.
Block inbound ICMP traffic.
Stateful inspection
Application proxy
Packet filter
Next generation
Latency
Jitter
Packet loss
Interference
Managers
Individual contributors
Suppliers
Board members
Regression testing
Interface testing
Fuzzing
White-box testing
XACML
SCML
VSML
SCAP
White-box testing
Black-box testing
Gray-box testing
Breach and attack simulation
Functional requirements
Work breakdown structure
Test analysis report
Project plan
During a web application vulnerability scanning test, Steve runs Nikto against a web server he believes may be vulnerable to attacks. Using the Nikto output shown here, answer the following questions.
Why does Nikto identify directory indexing as an issue?
It lists files in a directory.
It may allow for XDRF.
Directory indexing can result in a denial-of-service attack.
Directory indexing is off by default, potentially indicating compromise.
During a web application vulnerability scanning test, Steve runs Nikto against a web server he believes may be vulnerable to attacks. Using the Nikto output shown here, answer the following questions.
Nikto lists OSVDB-877, noting that the system may be vulnerable to XST. What would this type of attack allow an attacker to do?
Use cross-site targeting.
Steal a user's cookies.
Counter SQL tracing.
Modify a user's TRACE information.
CIO
CISO
CEO
CFO
Load balancing
Dual-power supplies
IPS
RAID
