CISSP Practice Exam

CISSP Practice ExamA. Management controls
Certified Information Systems Security ProfessionalB. Operational controls
After you study your text books it is important toC. Technical controls
test your newly acquired knowledge and see justD. Human resources controls.
how well you have absorbed the material. Practice_____________________
exams....Question 6# - Which one of the following devices
* Reinforces what you learnt - fill in the gaps of whatmight be used to commit telecommunications fraud
you missedusing the "shoulder surfing" technique?
* Gets you used to answering questions to buildA. Magnetic stripe copier
confidence and familiarityB. Tone generator
Here are 10 Multiple choice exams questions for youC. Tone recorder
to practice on:D. Video recorder
___________________________________________________
Question 1# - Which risk management methodologyQuestion 7# - What are database views used for?
uses the exposure factor multiplied by the assetA. To ensure referential integrity.
value to determine its outcome?B. To allow easier access to data in a database.
A. Annualized Loss ExpectancyC. To restrict user access to data in a database.
B. Single Loss ExpectancyD. To provide audit trails.
C. Annualized Rate of Occurrence_____________________
D. Information Risk ManagementQuestion 8# - Which of the following services is not
_____________________provided by the digital signature standard (DSS)?
Question 2# - Which of the following is *NOT* aA.) Encryption
symmetric key algorithm?B.) Integrity
A.) BlowfishC.) Digital signature
B.) Digital Signature Standard (DSS)D.) Authentication
C.) Triple DES (3DES)_____________________
D.) RC5Question 9# - Which one of the following describes a
_____________________covert timing channel?
Question 3# - Related to information security,A. Modulated to carry an unintended information
availability is the opposite of which of the following?signal that can only be detected by special, sensitive
A. Delegationreceivers.
B. DistributionB. Used by a supervisor to monitor the productivity
C. Documentationof a user without their knowledge.
D. DestructionC. Provides the timing trigger to activate a malicious
_____________________program disguised as a legitimate function.
Question 4# - Why should organizations enforceD. Allows one process to signal information to
separation of duties?another by modulating its own use of system
A. It ensures compliance with federal union rulesresources.
B. It helps verify that all employees know their job_____________________
tasksQuestion 10# - Valuable paper insurance coverage
C. It provides for a better work environmentdoes not cover damage to which of the following?
D. It encourages collusionA.) Inscribed, printed and written documents
E. It is considered valuable in deterring fraudB.) Manuscripts
_____________________C.) Records
Question 5# - Which of the following is mostD.
concerned with personnel security?