CISSP-ISSAP Topic 1
QUESTION NO: 1
Which of the following elements of the planning gap measures the gap between the total potential for the market and the actual current usage by all the consumers in the market?
A. Project gap
B. Product gap
C. Competitive gap
D. Usage gap
Answer: D
QUESTION NO: 2
Which of the following terms refers to the method that allows or restricts specific types of packets from crossing over the firewall?
A. Hacking
B. Packet filtering
C. Web caching
D. Spoofing
Answer: B
QUESTION NO: 3
You work as a Network Administrator for NetTech Inc. The company wants to encrypt its emails. Which of the following will you use to accomplish this?
A. PGP
B. PPTP
C. IPSec
D. NTFS
Answer: A
QUESTION NO: 4
Peter works as a Network Administrator for Net World Inc. The company wants to allow remote users to connect and access its private network through a dial-up connection via the Internet. All the data will be sent across a public network. For security reasons, the management wants the data sent through the Internet to be encrypted. The company plans to use a Layer 2 Tunneling
Protocol (L2TP) connection. Which communication protocol will Peter use to accomplish the task?
A. IP Security (IPSec)
B. Microsoft Point-to-Point Encryption (MPPE)
C. Pretty Good Privacy (PGP)
D. Data Encryption Standard (DES)
Answer: A
QUESTION NO: 5
Which of the following protocols multicasts messages and information among all member devices in an IP multicast group?
A. ARP
B. ICMP
C. TCP
D. IGMP
Answer: D
QUESTION NO: 6
Which of the following security devices is presented to indicate some feat of service, a special accomplishment, a symbol of authority granted by taking an oath, a sign of legitimate employment or student status, or as a simple means of identification?
A. Sensor
B. Alarm
C. Motion detector
D. Badge
Answer: D
QUESTION NO: 7
Which of the following is a method for transforming a message into a masked form, together with a way of undoing the transformation to recover the message?
A. Cipher
B. CrypTool
C. Steganography
D. MIME
Answer: A
QUESTION NO: 8
Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that are required for them. Which of the following access control models will he use?
A. Policy Access Control
B. Mandatory Access Control
C. Discretionary Access Control
D. Role-Based Access Control
Answer: D
QUESTION NO: 9
Which of the following is used to authenticate asymmetric keys?
A. Digital signature
B. MAC Address
C. Demilitarized zone (DMZ)
D. Password
Answer: A
QUESTION NO: 10
IPsec VPN provides a high degree of data privacy by establishing trust points between communicating devices and data encryption. Which of the following encryption methods does
IPsec VPN use? Each correct answer represents a complete solution. Choose two.
A. MD5
B. LEAP
C. AES
D. 3DES
Answer: C,D
QUESTION NO: 11
A user is sending a large number of protocol packets to a network in order to saturate its resources and to disrupt connections to prevent communications between services. Which type of attack is this?
A. Denial-of-Service attack
B. Vulnerability attack
C. Social Engineering attack
D. Impersonation attack
Answer: A
QUESTION NO: 12
Which of the following types of firewall functions at the Session layer of OSI model?
A. Circuit-level firewall
B. Application-level firewall
C. Packet filtering firewall
D. Switch-level firewall
Answer: A
QUESTION NO: 13
Which of the following statements about a stream cipher are true? Each correct answer represents a complete solution. Choose three.
A. It typically executes at a higher speed than a block cipher.
B. It divides a message into blocks for processing.C. It typically executes at a slower speed than a block cipher.
D. It divides a message into bits for processing.
E. It is a symmetric key cipher.
Answer: A,D,E
QUESTION NO: 14
Which of the following types of attack can be used to break the best physical and logical security mechanism to gain access to a system?
A. Social engineering attack
B. Cross site scripting attack
C. Mail bombing
D. Password guessing attack
Answer: A
QUESTION NO: 15
You are the Security Consultant advising a company on security methods. This is a highly secure location that deals with sensitive national defense related data. They are very concerned about physical security as they had a breach last month. In that breach an individual had simply grabbed a laptop and ran out of the building. Which one of the following would have been most effective in preventing this?
A. Not using laptops.
B. Keeping all doors locked with a guard.
C. Using a man-trap.
D. A sign in log.
Answer: C
QUESTION NO: 16
You want to implement a network topology that provides the best balance for regional topologies in terms of the number of virtual circuits, redundancy, and performance while establishing a WAN network. Which of the following network topologies will you use to accomplish the task?
A. Bus topology
B. Fully meshed topology
C. Star topology
D. Partially meshed topology
Answer: D
QUESTION NO: 17
Which of the following protocols is an alternative to certificate revocation lists (CRL) and allows the authenticity of a certificate to be immediately verified?
A. RSTP
B. SKIPC. OCSP
D. HTTP
Answer: C
QUESTION NO: 18
Which of the following does PEAP use to authenticate the user inside an encrypted tunnel? Each correct answer represents a complete solution. Choose two.
A. GTC
B. MS-CHAP v2
C. AES
D. RC4
Answer: A,B
QUESTION NO: 19
Which of the following terms refers to a mechanism which proves that the sender really sent a particular message?
A. Integrity
B. Confidentiality
C. Authentication
D. Non-repudiation
Answer: D
QUESTION NO: 20
Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective. Which of the following types of hardware devices will Adam use to implement two-factor authentication?
A. Biometric device
B. One Time Password
C. Proximity cards
D. Security token
Answer: D
QUESTION NO: 21
Maria works as a Network Security Officer for Gentech Inc. She wants to encrypt her network traffic. The specific requirement for the encryption algorithm is that it must be a symmetric key block cipher. Which of the following techniques will she use to fulfill this requirement?
A. IDEA
B. PGP
C. DES
D. AES
Answer: C
QUESTION NO: 22
Which of the following protocols uses public-key cryptography to authenticate the remote computer?
A. SSH
B. Telnet
C. SCP
D. SSL
Answer: A
QUESTION NO: 23
Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
A. Authentication
B. Non-repudiation
C. Integrity
D. Confidentiality
Answer: D
QUESTION NO: 24
Which of the following are the examples of technical controls? Each correct answer represents a complete solution. Choose three.
A. Auditing
B. Network architecture
C. System access
D. Data backups
Answer: A,B,C
QUESTION NO: 25
Which of the following tenets does the CIA triad provide for which security practices are measured? Each correct answer represents a part of the solution. Choose all that apply.
A. Integrity
B. Accountability
C. Availability
D. Confidentiality
Answer: A,C,D
QUESTION NO: 26
Which of the following types of attacks cannot be prevented by technical measures only?
A. Social engineering
B. Brute force
C. Smurf DoS
D. Ping flood attack
Answer: A
QUESTION NO: 27
Which of the following attacks can be overcome by applying cryptography?
A. Web ripping
B. DoS
C. Sniffing
D. Buffer overflow
Answer: C
QUESTION NO: 28
Which of the following authentication methods prevents unauthorized execution of code on remote systems?
A. TACACS
B. S-RPC
C. RADIUS
D. CHAP
Answer: B
QUESTION NO: 29
The simplest form of a firewall is a packet filtering firewall. Typically a router works as a packet filtering firewall and has the capability to filter on some of the contents of packets. On which of the following layers of the OSI reference model do these routers filter information? Each correct answer represents a complete solution. Choose all that apply.
A. Transport layer
B. Physical layer
C. Data Link layer
D. Network layer
Answer: A,D
QUESTION NO: 30
Andrew works as a Network Administrator for Infonet Inc. The company’s network has a Web server that hosts the company’s Web site. Andrew wants to increase the security of the Web site by implementing Secure Sockets Layer (SSL). Which of the following types of encryption does SSL use? Each correct answer represents a complete solution. Choose two.
A. Synchronous
B. Secret
C. Asymmetric
D. Symmetric
Answer: C,D
QUESTION NO: 31
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. John notices that the We-are-secure network is vulnerable to a man-in-the-middle attack since the key exchange process of the cryptographic algorithm it is using does not thenticate participants. Which of the following cryptographic algorithms is being used by the We-are-secure server?
A. Blowfish
B. Twofish
C. RSA
D. Diffie-Hellman
Answer: D
QUESTION NO: 32
Which of the following electrical events shows a sudden drop of power source that can cause a wide variety of problems on a PC or a network?
A. Blackout
B. Power spike
C. Power sag
D. Power surge
Answer: A
QUESTION NO: 33
Which of the following is the duration of time and a service level within which a business process must be restored after a disaster in order to avoid unacceptable consequences associated with a break in business continuity?
A. RCO
B. RTO
C. RPO
D. RTA
Answer: B
QUESTION NO: 34
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?
A. Containment
B. Preparation
C. Recovery
D. Identification
Answer: A
QUESTION NO: 35
You have decided to implement video surveillance in your company in order to enhance network security. Which of the following locations must have a camera in order to provide the minimum level of security for the network resources? Each correct answer represents a complete solution.
Choose two.
A. Parking lot
B. All hallways
C. Server Rooms
D. All offices
E. All entrance doors
Answer: C,E
QUESTION NO: 36
You work as a Network Administrator for NetTech Inc. You want to have secure communication on the company’s intranet. You decide to use public key and private key pairs. What will you implement to accomplish this?
A. Microsoft Internet Information Server (IIS)
B. VPN
C. FTP server
D. Certificate server
Answer: D
QUESTION NO: 37
Which of the following protocols is used to compare two values calculated using the Message
Digest (MD5) hashing function?
A. CHAP
B. PEAP
C. EAP
D. EAP-TLS
Answer: A
QUESTION NO: 38
Which of the following is a technique used for modifying messages, providing Information and Cyber security, and reducing the risk of hacking attacks during communications and message passing over the Internet?
A. Risk analysis
B. OODA loop
C. Cryptography
D. Firewall security
Answer: C
QUESTION NO: 39
Which of the following statements about Public Key Infrastructure (PKI) are true? Each correct answer represents a complete solution. Choose two.
A. It uses symmetric key pairs.
B. It provides security using data encryption and digital signature.
C. It uses asymmetric key pairs.
D. It is a digital representation of information that identifies users.
Answer: B,C
QUESTION NO: 40
Which of the following types of halon is found in portable extinguishers and is stored as a liquid?
A. Halon-f
B. Halon 1301
C. Halon 11
D. Halon 1211
Answer: D
QUESTION NO: 41
Mark has been hired by a company to work as a Network Assistant. He is assigned the task to configure a dial-up connection. He is configuring a laptop. Which of the following protocols should he disable to ensure that the password is encrypted during remote access?
A. SPAP
B. MSCHAP
C. PAP
D. MSCHAP V2
Answer: C
QUESTION NO: 42
Which of the following disaster recovery tests includes the operations that shut down at the primary site, and are shifted to the recovery site according to the disaster recovery plan?
A. Structured walk-through test
B. Simulation test
C. Full-interruption test
D. Parallel test
Answer: C
QUESTION NO: 43
In which of the following network topologies does the data travel around a loop in a single direction and pass through each device?
A. Ring topology
B. Tree topology
C. Star topology
D. Mesh topology
Answer: A
QUESTION NO: 44
You are the Network Administrator for a small business. You need a widely used, but highly secure hashing algorithm. Which of the following should you choose?
A. AES
B. SHA
C. EAP
D. CRC32
Answer: B
QUESTION NO: 45
Which of the following can be configured so that when an alarm is activated, all doors lock and the suspect or intruder is caught between the doors in the dead-space?
A. Man trap
B. Biometric device
C. Host Intrusion Detection System (HIDS)
D. Network Intrusion Detection System (NIDS)
Answer: A
QUESTION NO: 46
Which of the following refers to a location away from the computer center where document copies and backup media are kept?
A. Storage Area network
B. Off-site storage
C. On-site storage
D. Network attached storage
Answer: B
QUESTION NO: 47
Which of the following encryption methods does the SSL protocol use in order to provide communication privacy, authentication, and message integrity? Each correct answer represents a part of the solution. Choose two.
A. Public key
B. IPsec
C. MS-CHAP
D. Symmetric
Answer: A,D
QUESTION NO: 48
John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the company. To do so, he takes an image file and simply uses a tool image hide and embeds the secret file within an image file of the famous actress, Jennifer Lopez, and sends it to his Yahoo mail id. Since he is using the image file to send the data, the mail server of his company is unable to filter this mail. Which of the following techniques is he performing to accomplish his task?
A. Email spoofing
B. Social engineering
C. Web ripping
D. Steganography
Answer: D
QUESTION NO: 49
Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?
A. Network-based
B. Anomaly-based
C. File-based
D. Signature-based
Answer: B
QUESTION NO: 50
Which of the following are the initial steps required to perform a risk analysis process? Each correct answer represents a part of the solution. Choose three.
A. Estimate the potential losses to assets by determining their value.
B. Establish the threats likelihood and regularity.
C. Valuations of the critical assets in hard costs.
D. Evaluate potential threats to the assets.
Answer: A,B,D