wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CISSP Final

Total questions: 98

Worksheet time: 2hrs 38mins

Name
Class
Date
1.
In an infrastructure-as-a-service (IaaS) cloud model, who bears primary responsibility for securing physical and information assets?
a)

Responsibility primarily rests with the customer

b)

Responsibility primarily rests with the provider

c)

Responsibility is shared between the customer and provider

d)

Responsibility primarily rests with the cloud access security broker

2.

In a federated identity access management solution, what task is most commonly handled by the identity provider (IdP)?

a)

Identification

b)

Authorization

c)

Provisioning

d)

Authentication

3.
You are working with a team of software and hardware developers on the creation of a new product that will deploy sensors to factory floors and then analyze the data from those sensors using a back-end SaaS solution. Before you develop the software, you would like to understand the potential paths that an attacker could take to undermine the security of the system. What activity would best provide you with this perspective?
a)

Threat hunting

b)

Threat modeling

c)

Penetration testing

d)

Vulnerability scanning

4.

You recently performed a vulnerability assessment and found hundreds of vulnerabilities in your organization's infrastructure. It will take months to address all of these issues. What factors should you use to prioritize these vulnerabilities?

a)

Likelihood and probability

b)

Impact and exploitability

c)

Impact and CVSS score

d)

Likelihood and impact

5.

You are attempting to secure a wired network belonging to your organization. You would like to deploy technology that limits network access to authorized users. Which one of the following technologies would best meet that need?

a)

WiFi Protected Access v2 (WPA2)

b)

WiFi Protected Access v3 (WPA3)

c)

IEEE 802.1x

d)

MAC filtering

6.

A user connected a device to your network and, when they open their web browser, are redirected to a website advising them that they have been placed on an isolation network because their system does not meet the organization's security requirements. They are unable to access any network resources until they remediate their device to comply with the organization's security policy. What type of security solution is in use on this network?

a)

Intrusion Prevention System (IPS)

b)

Configuration Management (CM) platform

c)

Network Access Control (NAC)

d)

Endpoint Detection and Response (EDR) platform

7.
You have been asked to assist in the investigation of a security incident that took place in your organization. You are handed a laptop computer that is powered off and asked to analyze the data contained on its hard drive. What action should you take first?
a)

Remove the hard drive from the device

b)

Power on the laptop

c)

Connect to the hard drive with a forensic software package

d)

Connect a write blocker to the device

8.
Carla is conducting an assessment of an organization using the Software Assurance Maturity Model (SAMM). She notes that the organization seems to have difficulty with defect management and will be reporting that finding. Which business function of SAMM includes defect management?
a)

Implementation

b)

Governance

c)

Verification

d)

Operations

9.

You are working with the team developing a new web application and you would like to perform a test that evaluates whether the application is able to successfully handle malicious input that it receives through that interface. Which one of the following activities would best meet this need?

a)

Input validation

b)

Parameterized queries

c)

Stored procedures

d)

Fuzz testing

10.

What is the primary goal of change management in an organization?

a)

Reducing the likelihood of service disruptions

b)

Communicating to all affected stakeholders

c)

Creating an auditable record

d)

Organizing the work associated with a change

11.

Amy's organization uses quite a bit of open source software in their custom development work and she is concerned about the security impact of that use. What program can she deploy to help track the use of this software and identify outdated components?

a)

Software Configuration Management (SCM)

b)

Software as a Service (SaaS)

c)

Commericial-off-the-Shelf (COTS)

d)

Security Orchestration, Automation, and Response (SOAR)

12.
Which one of the following individuals or groups would be the most likely direct recipient of an audit report performed by an external auditor?
a)

Chief Information Security Officer (CISO)

b)

Chief Information Officer (CIO)

c)

Chief Financial Officer (CFO)

d)

Board of Directors

13.

You are encrypting a message that you plan to send to your supervisor using asymmetric encryption. Your goal is to protect the confidentiality of the message while it is in transit. What key should you use to encrypt the message?

a)

Your supervisor's private key

b)

Your own public key

c)

Your supervisor's public key

d)

Your own private key

14.
Rob is helping to conduct a risk assessment of a new web application that will shortly be deployed to production in his organization. To assist with his process, he sets up a web application scanning tool that will probe a test instance of the application overnight so that he can review the results in the morning. What term best describes the type of test that Rob is performing?
a)

Dynamic Application Security Testing (DAST)

b)

Interactive Application Security Testing (IAST)

c)

Static Application Security Testing (SAST)

d)

Code review

15.
You are reviewing the security controls around your organization's WiFi network and want to ensure that only authorized users are able to access the network and that they are able to do so in a seamless manner. Which one of the following approaches would best meet this requirement?
a)

WPA2 with PSK authentication

b)

WPA2 with WPS enabled

c)

WPA2 with enterprise authenticaiton

d)

WPA2 with a captive portal

16.
You are designing an access control system for your organization. The primary requirement is that individuals who are managing projects should be able to grant permissions to others in the organization to access information about those projects without going through a bureaucratic process. What access control model would best match this requirement?
a)

MAC

b)

RBAC

c)

DAC

d)

ABAC

17.

What is the most common standard of evidence used in a criminal investigation?

a)

Preponderance of the evidence

b)

Beyond a reasonable doubt

c)

Beyond a shadow of a doubt

d)

Clear and convincing evidence

18.

You are interviewing business leaders as part of a business impact assessment (BIA) of an enterprise resource planning (ERP) system. The goal of these conversations is to determine how long each business function can operate effectively during an incident that disrupts access to the ERP. What term describes the output of these conversations?

a)

MTD

b)

RTO

c)

RPO

d)

AV

19.
Your organization's system administrators are complaining that they do not want to have separate accounts for their routine work and their administrative activity. What technology could you use to allow administrators to assume their administrative roles from within their current accounts only when they need to perform privileged actions?
a)

ssh

b)

Nmap

c)

Kerberos

d)

sudo

20.
You are sending an important message to a client and would like to ensure that you can achieve the goal of non-repudiation through the use of a digital signature. What encryption key should you use to create the digital signature?
a)

Your own public key

b)

Your client's public key

c)

Your own private key

d)

Your client's private key

21.

Francis is an identity and access management professional at a very large corporation. She is reviewing her organization's process for revoking access assigned to terminated employees. What action would BEST protect the organization against the risks associated with a terminated employee's account?

a)

Delete the account

b)

Disable the account

c)

Revoke all permissions from the account

d)

Change the account's password

22.
You are creating a series of handling requirements for sensitive information processed by your organization and would like to document the specific encryption algorithms authorized for use in the organization. Which one of the following document types would be the best place to include these requirements?
a)

Policy

b)

Standard

c)

Guideline

d)

Procedure

23.

Which layer of the OSI model is primarily concerned with MAC addresses?

a)

Application layer

b)

Presentation layer

c)

Datalink layer

d)

Transport layer

24.

You are upgrading servers in your organization to use the latest version of the TLS protocol in conjunction with approved cipher suites. What type of data will this control best protect?

a)

Data in use

b)

Data in transit

c)

Data at rest

d)

Data in memory

25.
You are reviewing the report from a penetration test performed against one of your organization's web applications. The report includes a finding that the application is vulnerable to a cross-site request forgery (CSRF/XSRF) attack. Which one of the following controls would best defend against this type of attack?
a)

Secure tokens

b)

Stored procedures

c)

Parameterized queries

d)

Input validation

26.
You would like to enhance your security assessment and testing program by including automated techniques that seek to exploit security vulnerabilities and report on discovered deficiencies. Which of the following assessment techniques would best meet this need?
a)

Red team exercise

b)

Penetration test

c)

Vulnerability scan

d)

Breach and attack simulation (BAS)

27.

Carla is the security compliance officer for a large chain of retail stores. As part of her PCI DSS compliance work, Carla discovers that the organization routinely sends cardholder data to a service provider who helps detect fraudulent transactions. Under PCI DSS, what is Carla obligated to do?

a)

Perform an annual penetration test of the service provider

b)

Verify that the service provider appears on the list of validated service providers

c)

Perform quarterly vulnerability scanning of the service provider

d)

Review the results of an external audit of the service provider and ensure any criticalfindings are remediated

28.

In an organization's identity management (IdM) program, which one of the following technologies is commonly used as an authorization mechanism for internal users?

a)

Multifactor authentication (MFA)

b)

Passwords

c)

OAuth2

d)

Access control list (ACL)

29.
You recently received a request from a user in the sales department to have access to records of past employees for use in developing business leads. This type of access has never been granted in the past. What would be the best course of action for you to take?
a)

Refuse the request because it violates past precedent

b)

Refer the request to the data owner

c)

Grant the request because it aligns with business objectives

d)

Refer the request to the CISO

30.
You are concerned about the risk of data loss associated with the theft of laptops and mobile devices. You decide to deploy full disk encryption (FDE) technology to mitigate this risk. What control category best describes the use of this technology in this situation?
a)

Detective

b)

Preventive

c)

Corrective

d)

Compensating

31.

You are designing a back-end authentication system for your company and would like to choose an approach that allows you to implement single sign-on (SSO) and directly integrates with the Windows and Linux systems you have in place. Which one of the following technologies would best meet this need?

a)

OAuth2

b)

RADIUS

c)

Kerberos

d)

IEEE 802.1x

32.
Vincent's organization recently experienced an adverse situation where a customer who submitted an order by email later claimed that they did not actually send that email. Vincent believes that the customer did actually send the order but is not able to prove that fact. What security principle was most directly violated?
a)

Confidentiality

b)

Nonrepudiation

c)

Integrity

d)

Availability

33.

You are reviewing the security controls for a banking website and would like to ensure that the site is protected against man-in-the-middle (MITM) attacks. Which one of the following security controls would best protect against this type of attack?

a)

SSL

b)

SSH

c)

TLS

d)

AES

34.

You are evaluating possible upgrades to a physical data center used by your organization. Your primary concern is ensuring that the facility is able to continue operating during an extended power outage. What control would best meet this goal?

a)

Uninterruptible power supply

b)

Power conditioning

c)

Backup generator

d)

Alternate processing facility

35.
Which one of the following is the most common role for an IT professional to hold in an organization's data management program?
a)

Data steward

b)

Data custodian

c)

Data owner

d)

Data processor

36.

Which one of the following events should be considered the final deadline for discontinuing the use of an IT product or service in an organization?

a)

EOL

b)

EOS

c)

ETA

d)

ELA

37.

You are deploying a redundant array of inexpensive disks (RAID) to improve the redundancy of your storage system. You have chosen to implement RAID level 5. What is the minimum number of disks that you must use to implement this solution?

a)

2

b)

5

c)

3

d)

1

38.
You are developing a security standard for laptop computers that will be used by a new division within your organization. The employees in that division will travel constantly and require access to sensitive information. Which one of the following components is least likely to be part of this division's endpoint security strategy?
a)

Full disk encryption

b)

Host-based firewalls

c)

Containerization

d)

Endpoint detection and response

39.

Your organization recently signed a contract with a service provider who will be maintaining manufacturing equipment at a variety of field sites. The provider requires access to some of your internal systems in order to view and update work orders so you are establishing connectivity to your network for them. The connection will be an always-on virtual private network (VPN) between your locations. What is the most appropriate location on your network to terminate the connection?

a)

Intranet

b)

Internet

c)

Extranet

d)

Demilitarized Zone (DMZ) network

40.
As the Chief Information Security Officer (CISO) of a large organization, Justin is concerned that his team is unable to rapidly respond to many smaller incidents. He would like to have runbooks that automatically respond to simple events that occur on endpoints, network devices, and applications. What technology platform would best meet his needs?
a)

Security orchestration, automation, and response (SOAR)

b)

Security information and event management (SIEM)

c)

Endpoint detection and response (EDR)

d)

Managed detection and response (MDR)

41.

You are deploying a virtual private network (VPN) to support remote users who will be telecommuting but require access to internal resources. Where would be the most appropriate location to place the VPN server?

a)

Internal network

b)

Outside the firewall on the public Internet

c)

Demilitarized zone (DMZ) network

d)

Data center network

42.

Which one of the following is the best example of a security awareness activity that might be used as part of an organization's information security program?

a)

Mandatory computer-based training

b)

Posters in the hallway

c)

Specialized training for security administrators

d)

Optional classroom training

43.

You are responsible for managing your organization's firewall and require remote command-line access to the device. Which one of the following tools will best meet this requirement?

a)

HTTPS

b)

IPsec

c)

SSH

d)

Telnet

44.
Lisa is attempting to prevent her network from being targeted by IP spoofing attacks as well as preventing her network from being the source of those attacks. Which of the following rules are best practices that Lisa should configure at her network border? (Select all that apply.)
a)

Block packets with internal source addresses from entering the network.

b)

Block packets with external source addresses from leaving the network.

c)

Block packets with public IP addresses from entering the network.

d)

Block packets with private IP addresses from exiting the network.

45.
Fran is building a forensic analysis workstation and is selecting a forensic disk controller to include in the setup. Which of the following are functions of a forensic disk controller? (Select all that apply.)
a)

Preventing the modification of data on a storage device

b)

Returning data requested from the device

c)

Reporting errors sent by the device to the forensic host

d)

Blocking read commands sent to the device

46.
Darren is troubleshooting an authentication issue for a Kerberized application used by his organization. He believes the issue is with the generation of session keys. What Kerberos service should he investigate first?
a)

KDC

b)

TGT

c)

AS

d)

TGS

47.
Ivan is installing a motion detector to protect a sensitive work area that uses high-frequency microwave signal transmissions to identify potential intruders. What type of detector is he installing?
a)

Infrared

b)

Heat-based

c)

Wave pattern

d)

Capacitance

48.
Susan sets up a firewall that keeps track of the status of the communication between two systems and allows a remote system to respond to a local system only after the local system starts communication. What type of firewall is Susan using?
a)

A static packet filtering firewall

b)

An application-level gateway firewall

c)

A stateful packet inspection firewall

d)

A circuit-level gateway firewall

49.

Please refer to the following scenario: Ben owns a coffeehouse and wants to provide wireless internet service for his customers. Ben's network is simple and uses a single consumer-grade wireless router and a cable modem connected via a commercial cable data contract.  

Ben intends to run an open (unencrypted) wireless network. How should he connect his business devices?

a)

Run WPA3 on the same SSID.

b)

Set up a separate SSID using WPA3.

c)

Run the open network in Enterprise mode.

d)

Set up a separate wireless network using WEP.

50.
Tom is tuning his security monitoring tools in an attempt to reduce the number of alerts received by administrators without missing important security events. He decides to configure the system to only report failed login attempts if there are five failed attempts to access the same account within a one-hour period of time. What term best describes the technique that Tom is using?
a)

Thresholding

b)

Sampling

c)

Account lockout

d)

Clipping

51.
Kim is the system administrator for a small business network that is experiencing security problems. She is in the office in the evening working on the problem, and nobody else is there. As she is watching, she can see that systems on the other side of the office that were previously behaving normally are now exhibiting signs of infection one after the other. What type of malware is Kim likely dealing with?
a)

Virus

b)

Worm

c)

Trojan horse

d)

Logic bomb

52.
Barb is reviewing the compliance obligations facing her organization and the types of liability that each one might incur. Which of the following laws and regulations may involve criminal penalties if violated? (Select all that apply.)
a)

FERPA

b)

HIPAA

c)

SOX

d)

PCI DSS

53.
Gina recently took the CISSP certification exam and then wrote a blog post that included the text of many of the exam questions that she experienced. What aspect of the (ISC)2 Code of Ethics is most directly violated in this situation?
a)

Advance and protect the profession.

b)

Act honorably, honestly, justly, responsibly, and legally.

c)

Protect society, the common good, necessary public trust and confidence, and the infrastructure.

d)

Provide diligent and competent service to principals.

54.
Bob is configuring egress filtering on his network, examining traffic destined for the internet. His organization uses the public address range 12.8.195.0/24. Packets with which one of the following destination addresses should Bob permit to leave the network?
a)

12.8.195.15

b)

10.8.15.9

c)

192.168.109.55

d)

129.53.44.124

55.
William is reviewing log files that were stored on a system with a suspected compromise. He finds the log file shown here. What type of log file is this?
a)

Change log

b)

Application log

c)

System log

d)

Firewall log

56.
Roger is reviewing a list of security vulnerabilities in his organization and rating them based upon their severity. Which one of the following models would be most useful to his work?
a)

CVSS

b)

STRIDE

c)

PASTA

d)

ATT&CK

57.
Greg is evaluating a new vendor that will be supplying networking gear to his organization. Due to the nature of his organization's work, Greg is concerned that an attacker might attempt a supply chain exploit. Assuming that both Greg's organization and the vendor operate under reasonable security procedures, which one of the following activities likely poses the greatest supply chain risk to the equipment?
a)

Tampering by an unauthorized third party at the vendor's site

b)

Interception of devices in transit

c)

Misconfiguration by an administrator after installation

d)

Tampering by an unauthorized third party at Greg's site

58.

The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.

If availability of authentication services is the organization's biggest priority, what type of identity platform should Ben recommend?

a)

On-site

b)

Cloud-based

c)

Hybrid

d)

Outsourced

59.

The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.

If Ben needs to share identity information with the business partner shown, what should he investigate?

a)

Single sign-on

b)

Multifactor authentication

c)

Federation

d)

IDaaS

60.

The organization that Ben works for has a traditional on-site Active Directory environment that uses a manual provisioning process for each addition to their 350-employee company. As the company adopts new technologies, they are increasingly using software as a service applications to replace their internally developed software stack. Ben has been tasked with designing an identity management implementation that will allow his company to use cloud services while supporting their existing systems. Using the logical diagram shown here, answer the following questions about the identity recommendations Ben should make.

What technology is likely to be involved when Ben's organization needs to provide authentication and authorization assertions to their cloud e-commerce application?

a)

Active Directory

b)

SAML

c)

RADIUS

d)

SPML

61.
Jesse is looking at the /etc/passwd file on a system configured to use shadowed passwords. What should she expect to see in the password field of this file?
a)

Plaintext passwords

b)

Encrypted passwords

c)

Hashed passwords

d)

x

62.
Rob recently received a notice from a vendor that the EOL date is approaching for a firewall platform that is used in his organization. What action should Rob take?
a)

Prepare to discontinue use of the platform as soon as possible.

b)

Immediately discontinue use of the device.

c)

Prepare to discontinue use of the device as part of the organization's normal planning cycle.

d)

No action is necessary.

63.
What principle states that an individual should make every effort to complete his or her responsibilities in an accurate and timely manner?
a)

Least privilege

b)

Separation of duties

c)

Due care

d)

Due diligence

64.
When Ben records data and then replays it against his test website to verify how it performs based on a real production workload, what type of performance monitoring is he undertaking?
a)

Passive

b)

Proactive

c)

Reactive

d)

Replay

65.
Kailey is reviewing a set of old records maintained by her organization and wants to dispose of them securely. She is unsure how long the organization should keep the records because they involve tax data. How can Kailey determine whether the records may be disposed?
a)

Consult the organization's records retention policy.

b)

Consult IRS requirements.

c)

Retain the records for at least seven years.

d)

Retain the records permanently.

66.
During a security audit, Susan discovers that the organization is using hand geometry scanners as the access control mechanism for their secure data center. What recommendation should Susan make about the use of hand geometry scanners?
a)

They have a high FRR and should be replaced.

b)

A second factor should be added because they are not a good way to reliably distinguish individuals.

c)

The hand geometry scanners provide appropriate security for the data center and should be considered for other high-security areas.

d)

They may create accessibility concerns, and an alternate biometric system should be considered.

67.
Colleen is conducting a business impact assessment for her organization. What metric provides important information about the amount of time that the organization may be without a service before causing irreparable harm?
a)

MTD

b)

ALE

c)

RPO

d)

RTO

68.
Bailey is concerned that users around her organization are using sensitive information in a variety of cloud services and would like to enforce security policies consistently across those services. What security control would be best suited for her needs?
a)

DRM

b)

IPS

c)

CASB

d)

DLP

69.
Jerry is investigating an attack where the attacker stole an authentication token from a user's web session and used it to impersonate the user on the site. What term best describes this attack?
a)

Masquerading

b)

Replay

c)

Spoofing

d)

Modification

70.
Lisa wants to integrate with a cloud identity provider that uses OAuth 2.0, and she wants to select an appropriate authentication framework. Which of the following best suits her needs?
a)

OpenID Connect

b)

SAML

c)

RADIUS

d)

Kerberos

71.
Denise is preparing for a trial relating to a contract dispute between her company and a software vendor. The vendor is claiming that Denise made a verbal agreement that amended their written contract. What rule of evidence should Denise raise in her defense?
a)

Real evidence rule

b)

Best evidence rule

c)

Parol evidence rule

d)

Testimonial evidence rule

72.
While Lauren is monitoring traffic on two ends of a network connection, she sees traffic that is inbound to a public IP address show up inside the production network. It is headed for an internal host with an RFC 1918 reserved destination address. What technology should she expect is in use at the network border?
a)

NAT

b)

VLANs

c)

S/NAT

d)

BGP

73.
Elliott is using an asymmetric cryptosystem and would like to add a digital signature to a message. What key should he use to encrypt the message digest?
a)

Elliott's private key

b)

Elliott's public key

c)

Recipient's private key

d)

Recipient's public key

74.
Seth is designing the physical security controls for a new facility being constructed by his organization. He would like to deter attacks to the extent possible. Which of the following controls serve as deterrents? (Select all that apply.)
a)

Motion detectors

b)

Guard dogs

c)

Mantraps

d)

Lighting

75.
Thomas recently signed an agreement for a serverless computing environment where his organization's developers will be able to write functions in Python and deploy them on the cloud provider's servers for execution. The cloud provider will manage the servers. What term best describes this model?
a)

SaaS

b)

PaaS

c)

IaaS

d)

Containerization

76.
An attacker has intercepted a large amount of data that was all encrypted with the same algorithm and encryption key. With no further information, which of the following cryptanalytic attacks are possible? (Select all that apply.)
a)

Known plaintext

b)

Chosen ciphertext

c)

Frequency analysis

d)

Brute-force

77.

Alex has been with the university he works at for more than 10 years. During that time, he has been a system administrator and a database administrator, and he has worked in the university's help desk. He is now a manager for the team that runs the university's web applications.

Alex hires a new employee and the employee's account is provisioned after HR manually inputs information into the provisioning system based on data Alex provides via a series of forms, what type of provisioning has occurred?

a)

Discretionary account provisioning

b)

Workflow-based account provisioning

c)

Automated account provisioning

d)

Self-service account provisioning

78.
Robert is reviewing a system that has been assigned the EAL2 evaluation assurance level under the Common Criteria. What is the highest level of assurance that he may have about the system?
a)

It has been functionally tested.

b)

It has been structurally tested.

c)

It has been formally verified, designed, and tested.

d)

It has been semiformally designed and tested.

79.
Dana is selecting a hash function for use in her organization and would like to balance a concern for a cryptographically strong hash with the speed and efficiency of the algorithm. Which one of the following hash functions would best meet her needs?
a)

MD5

b)

RIPEMD

c)

SHA-2

d)

SHA-3

80.
What is the process that occurs when the Session layer removes the header from data sent by the Transport layer?
a)

Encapsulation

b)

Packet unwrapping

c)

De-encapsulation

d)

Payloading

81.
Rob is reviewing his organization's campus for physical security using the Crime Prevention Through Environmental Design (CPTED) framework. Which one of the following is NOT a strategy in this framework?
a)

Natural intrusion detection

b)

Natural access control

c)

Natural surveillance

d)

Natural territorial reinforcement

82.
What markup language uses the concepts of a requesting authority, a provisioning service point, and a provisioning service target to handle its core functionality?
a)

SAML

b)

SAMPL

c)

SPML

d)

XACML

83.
MAC models use three types of environments. Which of the following is not a mandatory access control design?
a)

Hierarchical

b)

Bracketed

c)

Compartmentalized

d)

Hybrid

84.
Mandy is the team leader for a project team that includes six people. She would like to provide those people with the ability to communicate privately, such that any pair of people can exchange communications that are not subject to interception by anyone else (team member or nonteam member). She is using an asymmetric encryption algorithm. How many keys are required to implement these requirements?
a)

6

b)

12

c)

15

d)

36

85.
Sally is wiring a gigabit Ethernet network. What cabling choices should she make to ensure she can use her network at the full 1000 Mbps she wants to provide to her users?
a)

Cat 5 and Cat 6

b)

Cat 5e and Cat 6

c)

Cat 4e and Cat 5e

d)

Cat 6 and Cat 7

86.
Ursula is seeking to expand the reach and scalability of her organization's website. She would like to position copies of her data around the world in locations close to website visitors to reduce loading time and the burden on her servers. What type of cloud service would best meet her needs?
a)

IaaS

b)

Containerization

c)

CDN

d)

SaaS

87.
Robert is the network administrator for a small business and recently installed a new firewall. After seeing signs of unusually heavy network traffic, he checked his intrusion detection system, which reported that a smurf attack was underway. What firewall configuration change can Robert make to most effectively prevent this attack?
a)

Block the source IP address of the attack.

b)

Block inbound UDP traffic.

c)

Block the destination IP address of the attack.

d)

Block inbound ICMP traffic.

88.
Which one of the following types of firewalls does not have the ability to track connection status between different packets?
a)

Stateful inspection

b)

Application proxy

c)

Packet filter

d)

Next generation

89.
Matthew is experiencing issues with the quality of network service on his organization's network. The primary symptom is that packets are occasionally taking too long to travel from their source to their destination. The length of this delay changes for individual packets. What term describes the issue Matthew is facing?
a)

Latency

b)

Jitter

c)

Packet loss

d)

Interference

90.
Gavin is an internal auditor working to assess his organization's cybersecurity posture. Which of the following would be appropriate recipients of the reports he generates from his work? (Select all that apply.)
a)

Managers

b)

Individual contributors

c)

Suppliers

d)

Board members

91.
Kim is conducting testing of a web application developed by her organization and would like to ensure that it is accessible from all commonly used web browsers. What type of testing should she conduct?
a)

Regression testing

b)

Interface testing

c)

Fuzzing

d)

White-box testing

92.
Ben wants to interface with the National Vulnerability Database using a standardized protocol. What option should he use to ensure that the tools he builds work with the data contained in the NVD?
a)

XACML

b)

SCML

c)

VSML

d)

SCAP

93.
Ron's organization does not have the resources to conduct penetration testing that uses time-intensive manual techniques, but he would like to achieve some of the benefits of penetration testing. Which one of the following techniques could he engage in that requires the least manual effort?
a)

White-box testing

b)

Black-box testing

c)

Gray-box testing

d)

Breach and attack simulation

94.
Norm is starting a new software project with a vendor that uses an SDLC approach to development. When he arrives on the job, he receives a document that has the sections shown here. What type of planning document is this? Executive Summary section with a high-level schedule of key activities and milestones Detailed project tasks for the applicable SDLC phases Special interest areas tracked outside the SDLC phase areas as required
a)

Functional requirements

b)

Work breakdown structure

c)

Test analysis report

d)

Project plan

95.

During a web application vulnerability scanning test, Steve runs Nikto against a web server he believes may be vulnerable to attacks. Using the Nikto output shown here, answer the following questions.

Why does Nikto identify directory indexing as an issue?

a)

It lists files in a directory.

b)

It may allow for XDRF.

c)

Directory indexing can result in a denial-of-service attack.

d)

Directory indexing is off by default, potentially indicating compromise.

96.

During a web application vulnerability scanning test, Steve runs Nikto against a web server he believes may be vulnerable to attacks. Using the Nikto output shown here, answer the following questions.

Nikto lists OSVDB-877, noting that the system may be vulnerable to XST. What would this type of attack allow an attacker to do?

a)

Use cross-site targeting.

b)

Steal a user's cookies.

c)

Counter SQL tracing.

d)

Modify a user's TRACE information.

97.
Who would be the most appropriate supervisor for an organization's chief audit executive (CAE)?
a)

CIO

b)

CISO

c)

CEO

d)

CFO

98.
Which one of the following technologies is designed to prevent a web server going offline from becoming a single point of failure in a web application architecture?
a)

Load balancing

b)

Dual-power supplies

c)

IPS

d)

RAID