Pass the ISC ISC 2 Credentials CISSP Questions and answers with CertsForce

Viewing page 1 out of 16 pages
Viewing questions 1-15 out of questions
Questions # 1:

Which of the following is a web application control that should be put into place to prevent exploitation of Operating System (OS) bugs?

Options:

A.

Check arguments in function calls


B.

Test for the security patch level of the environment


C.

Include logging functions


D.

Digitally sign each application module


Expert Solution
Questions # 2:

When in the Software Development Life Cycle (SDLC) MUST software security functional requirements be defined?

Options:

A.

After the system preliminary design has been developed and the data security categorization has been performed


B.

After the vulnerability analysis has been performed and before the system detailed design begins


C.

After the system preliminary design has been developed and before the data security categorization begins


D.

After the business functional analysis and the data security categorization have been performed


Expert Solution
Questions # 3:

Which of the following is the PRIMARY risk with using open source software in a commercial software construction?

Options:

A.

Lack of software documentation


B.

License agreements requiring release of modified code


C.

Expiration of the license agreement


D.

Costs associated with support of the software


Expert Solution
Questions # 4:

A Java program is being developed to read a file from computer A and write it to computer B, using a third computer C. The program is not working as expected. What is the MOST probable security feature of Java preventing the program from operating as intended?

Options:

A.

Least privilege


B.

Privilege escalation


C.

Defense in depth


D.

Privilege bracketing


Expert Solution
Questions # 5:

The configuration management and control task of the certification and accreditation process is incorporated in which phase of the System Development Life Cycle (SDLC)?

Options:

A.

System acquisition and development


B.

System operations and maintenance


C.

System initiation


D.

System implementation


Expert Solution
Questions # 6:

What is the BEST approach to addressing security issues in legacy web applications?

Options:

A.

Debug the security issues


B.

Migrate to newer, supported applications where possible


C.

Conduct a security assessment


D.

Protect the legacy application with a web application firewall


Expert Solution
Questions # 7:

Which of the following is the BEST method to prevent malware from being introduced into a production environment?

Options:

A.

Purchase software from a limited list of retailers


B.

Verify the hash key or certificate key of all updates


C.

Do not permit programs, patches, or updates from the Internet


D.

Test all new software in a segregated environment


Expert Solution
Questions # 8:

A company whose Information Technology (IT) services are being delivered from a Tier 4 data center, is preparing a companywide Business Continuity Planning (BCP). Which of the following failures should the IT manager be concerned with?

Options:

A.

Application


B.

Storage


C.

Power


D.

Network


Expert Solution
Questions # 9:

Which of the following types of technologies would be the MOST cost-effective method to provide a reactive control for protecting personnel in public areas?

Options:

A.

Install mantraps at the building entrances


B.

Enclose the personnel entry area with polycarbonate plastic


C.

Supply a duress alarm for personnel exposed to the public


D.

Hire a guard to protect the public area


Expert Solution
Questions # 10:

All of the following items should be included in a Business Impact Analysis (BIA) questionnaire EXCEPT questions that

Options:

A.

determine the risk of a business interruption occurring


B.

determine the technological dependence of the business processes


C.

Identify the operational impacts of a business interruption


D.

Identify the financial impacts of a business interruption


Expert Solution
Questions # 11:

Intellectual property rights are PRIMARY concerned with which of the following?

Options:

A.

Owner’s ability to realize financial gain


B.

Owner’s ability to maintain copyright


C.

Right of the owner to enjoy their creation


D.

Right of the owner to control delivery method


Expert Solution
Questions # 12:

An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?

Options:

A.

Development, testing, and deployment


B.

Prevention, detection, and remediation


C.

People, technology, and operations


D.

Certification, accreditation, and monitoring


Expert Solution
Questions # 13:

What is the MOST important consideration from a data security perspective when an organization plans to relocate?

Options:

A.

Ensure the fire prevention and detection systems are sufficient to protect personnel


B.

Review the architectural plans to determine how many emergency exits are present


C.

Conduct a gap analysis of a new facilities against existing security requirements


D.

Revise the Disaster Recovery and Business Continuity (DR/BC) plan


Expert Solution
Questions # 14:

Which of the following actions will reduce risk to a laptop before traveling to a high risk area?

Options:

A.

Examine the device for physical tampering


B.

Implement more stringent baseline configurations


C.

Purge or re-image the hard disk drive


D.

Change access codes


Expert Solution
Questions # 15:

When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?

Options:

A.

Only when assets are clearly defined


B.

Only when standards are defined


C.

Only when controls are put in place


D.

Only procedures are defined


Expert Solution
Viewing page 1 out of 16 pages
Viewing questions 1-15 out of questions