[May 15, 2024] CISSP Dumps PDF and Test Engine Exam Questions - PassCollection
Verified CISSP exam dumps Q&As with Correct 1481 Questions and Answers
Achieving the ISC CISSP Certification Exam demonstrates a high level of competence and expertise in the field of information security. It validates the skills and knowledge required to design, implement, and manage a comprehensive security program. Certified Information Systems Security Professional certification is highly valued by employers and is recognized globally as a standard of excellence in information security. It can also lead to greater career opportunities and higher salaries for certified professionals.
The CISSP exam covers a broad range of topics related to information security, including security and risk management, asset security, security engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security. CISSP exam is designed for professionals with at least five years of experience in information security, and passing the exam requires a deep understanding of these topics and their practical application in real-world scenarios.
The CISSP certification exam covers a wide range of topics related to information security. CISSP exam is designed to test the candidate's knowledge and understanding of information security concepts, techniques, and best practices. Some of the topics covered in the exam include security and risk management, asset security, security engineering, communication and network security, and software development security. CISSP exam also covers topics related to security operations and business continuity.
NEW QUESTION # 366
Which cable technology refers to the CAT 3 and Cat5 Categories?
- A. Axial cables
- B. Fiber Optic cables
- C. Twisted Pair cables
- D. Coaxial cables
Answer: C
NEW QUESTION # 367
When submitting a passphrase for authentication, the passphrase is converted into ...
- A. a new passphrase by the encryption technology D. a real password by the system which can be used forever.
- B. a new passphrase by the system.
- C. a virtual password by the system.
Answer: C
Explanation:
Passwords can be compromised and must be protected. In the ideal case, a password should only be used once. The changing of passwords can also fall between these two extremes. Passwords can be required to change monthly, quarterly, or at other intervals, depending on the criticality of the information needing protection and the password's frequency of use. Obviously, the more times a password is used, the more chance there is of it being compromised. It is recommended to use a passphrase instead of a password. A passphrase is more resistant to attacks. The passphrase is converted into a virtual password by the system. Often time the passphrase will exceed the maximum length supported by the system and it must be trucated into a Virtual Password.
Reference(s) used for this question: http://www.itl.nist.gov/fipspubs/fip112htm and KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 36 & 37
NEW QUESTION # 368
What is the purpose of code signing?
- A. The signer verifies that the software being loaded is free of malicious code.
- B. Both vendor and the signer certify the software being loaded is free of malicious code and it was originated by the signer.
- C. The vendor certifies the software being loaded is free of malicious code and that it was originated by the signer.
- D. The signer verifies that the software being loaded is the software originated by the signer.
Answer: D
NEW QUESTION # 369
Which of the following questions is less likely to help in assessing physical and environmental protection?
- A. Are appropriate fire suppression and prevention devices installed and working?
- B. Is physical access to data transmission lines controlled?
- C. Are there processes to ensure that unauthorized individuals cannot read, copy, alter, or steal printed or electronic information?
- D. Are entry codes changed periodically?
Answer: C
NEW QUESTION # 370
Which of the following is not appropriate in addressing object reuse?
- A. Clearing memory blocks before they are allocated to a program or data.
- B. Degaussing magnetic tapes when they're no longer needed.
- C. Deleting files on disk before reusing the space.
- D. Clearing buffered pages, documents, or screens from the local memory of a terminal or printer.
Answer: C
Explanation:
Object reuse requirements, applying to systems rated TCSEC C2 and above, are used to protect files, memory, and other objects in a trusted system from being accidentally accessed by users who are not authorized to access them. Deleting files on disk merely erases file headers in a directory structure. It does not clear data from the disk surface, thus making files still recoverable. All other options involve clearing used space, preventing any unauthorized access.
Source: RUSSEL, Deborah & GANGEMI, G.T. Sr., Computer Security Basics, O'Reilly,
July 1992 (page 119).
NEW QUESTION # 371
When reviewing vendor certifications for handling and processing of company data, which of the following is the BEST Service Organization Controls (SOC) certification for the vendor to possess?
- A. SOC 2 Type 2
- B. SOC 1 Type 1
- C. SOC 3
- D. SOC 2 Type 1
Answer: A
NEW QUESTION # 372
In Federated Identity Management (FIM), which of the following represents the concept of federation?
- A. Collection of domains that have established trust among themselves
- B. Collection of information for common identities in a system
- C. Collection, maintenance, and deactivation of user objects and attributes in one or more systems, directories or applications
- D. Collection of information logically grouped into a single entity
Answer: A
NEW QUESTION # 373
The RSA Algorithm uses which mathematical concept as the basis of its encryption?
- A. Two large prime numbers
- B. Geometry
- C. 16-round ciphers
- D. PI (3.14159...)
Answer: A
Explanation:
Explanation/Reference:
Explanation:
RSA is derived from the last names of its inventors, Rivest, Shamir, and Addleman.
This algorithm is based on the difficulty of factoring a number, N, which is the product of two large prime numbers. These numbers may be 200 digits each. Thus, the difficulty in obtaining the private key from the public key is a hard, one-way function that is equivalent to the difficulty of finding the prime factors of N.
In RSA, public and private keys are generated as follows:
Choose two large prime numbers, p and q, of equal length, compute p3q 5 n, which is the public
modulus.
Choose a random public key, e, so that e and (p - 1)(q - 1) are relatively prime.
Compute e x d = 1 mod (p - 1)(q - 1), where d is the private key.
Thus, d = e-1 mod [(p - 1)(q - 1)]
From these calculations, (d, n) is the private key and (e, n) is the public key.
Incorrect Answers:
A: The RSA Algorithm does not use Geometry as the basis of its encryption.
B: The RSA Algorithm does not use 16-round ciphers as the basis of its encryption.
C: The RSA Algorithm does not use PI as the basis of its encryption.
References:
Krutz, Ronald L. and Russel Dean Vines, The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, New York, 2001, p. 148
NEW QUESTION # 374
Because the development of new technology usually outpaces the law,
law enforcement uses which traditional laws to prosecute computer criminals?
- A. Conspiracy and elimination of competition
- B. Malicious mischief
- C. Immigration
- D. Embezzlement, fraud, and wiretapping
Answer: D
Explanation:
*Answer Malicious mischief is not a law
*answer Immigration is not applicable because it applies to obtaining visas and so on
*answer Conspiracy and elimination of competition is not correct because the crimes in answer "Embezzlement, fraud, and wiretapping" are more commonly used to prosecute computer crimes.
NEW QUESTION # 375
An organization has doubled in size due to a rapid market share increase. The size of the Information Technology (IT) staff has maintained pace with this growth. The organization hires several contractors whose onsite time is limited. The IT department has pushed its limits building servers and rolling out workstations and has a backlog of account management requests.
Which contract is BEST in offloading the task from the IT staff?
- A. Software as a Service (SaaS)
- B. Desktop as a Service (DaaS)
- C. Platform as a Service (PaaS)
- D. Identity as a Service (IDaaS)
Answer: D
Explanation:
Section: Asset Security
NEW QUESTION # 376
What is the maximum key size for the RC5 algorithm?
- A. 256 bits
- B. 2040 bits
- C. 1024 bits
- D. 128 bits
Answer: B
Explanation:
RC5 is a fast block cipher created by Ron Rivest and analyzed by RSA Data
Security, Inc.
It is a parameterized algorithm with a variable block size, a variable key size, and a variable
number of rounds.
Allowable choices for the block size are 32 bits (for experimentation and evaluation purposes
only), 64 bits (for use a drop-in replacement for DES), and 128 bits.
The number of rounds can range from 0 to 255, while the key can range from 0 bits to 2040 bits in
size.
Please note that some sources such as the latest Shon Harris book mentions that RC5 maximum
key size is of 2048, not 2040 bits. I would definitively use RSA as the authoritative source which
specifies a key of 2040 bits. It is an error in Shon's book.
The OIG book says:
RC5 was developed by Ron Rivest of RSA and is deployed in many of RSA's products. It is a very
adaptable product useful for many applications, ranging from software to hardware
implementations. The key for RC5 can vary from 0 to 2040 bits, the number of rounds it executes
can be adjusted from 0 to 255, and the length of the input words can also be chosen from 16-, 32-,
and 64-bit lengths.
The following answers were incorrect choices:
All of the other answers were wrong.
Reference(s) used for this question:
Schneiter, Andrew (2013-04-15). Official (ISC)2 Guide to the CISSP CBK, Third Edition :
Cryptography (Kindle Locations 1098-1101). . Kindle Edition.
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (Kindle Locations 16744-
16747). McGraw-Hill. Kindle Edition.
http://www.rsa.com/rsalabs/node.asp?id=2251, What are RC5 and RC6, RSA The Security
Division of EMC.
From Rivest himself, see http://people.csail.mit.edu/rivest/Rivest-rc5rev.pdf
Also see the draft IETF IPSEC standard which clearly mention that it is in fact 2040 bits as a
MAXIMUM key size:
http://www.tools.ietf.org/html/draft-ietf-ipsec-esp-rc5-cbc-00
http://en.wikipedia.org/wiki/RC5, Mention a maximum key size of 2040 as well.
NEW QUESTION # 377
Which of the following is true related to network sniffing?
- A. Sniffers take over network connections.
- B. Sniffers alter the source address of a computer to disguise and exploit weak authentication methods,
- C. Sniffers send IP fragments to a system that overlap with each other.
- D. Sniffers allow an attacker to monitor data passing across a network.
Answer: D
Explanation:
Sniffing is the action of capture / monitor the traffic going over the network. Because, in a normal networking environment, account and password information is passed along Ethernet in clear-text, it is not hard for an intruder to put a machine into promiscuous mode and by sniffing, compromise all the machines on the net by capturing password in an illegal fashion.
NEW QUESTION # 378
As users switch roles within an organization, their accounts are given additional permissions to perform the duties of their new position. After a recent audit, it was discovered that many of these accounts maintained their old permissions as well. The obsolete permissions identified by the audit have been remediated and accounts have only the appropriate permissions to complete their jobs.
Which of the following is the BEST way to prevent access privilege creep?
- A. Trigger-based review and certification
- B. Implementing Identity and Access Management (IAM) solution
- C. Time-based review and certification
- D. Internet audit
Answer: B
NEW QUESTION # 379
Which of the following can be defined as a unique identifier in the table that unambiguously points to an individual tuple or record in the table?
- A. foreign key
- B. candidate key
- C. secondary key
- D. primary key
Answer: D
Explanation:
A primary key is a unique identifier in the table that unambiguously points to an individual tuple or record in the table. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 45.
NEW QUESTION # 380
Which of the following countermeasures would be the most appropriate to prevent possible intrusion or damage from wardialing attacks?
- A. Monitoring and auditing for such activity
- B. Making sure only necessary phone numbers are made public
- C. Require user authentication
- D. Using completely different numbers for voice and data accesses
Answer: C
Explanation:
Knowlege of modem numbers is a poor access control method as an attacker can discover modem numbers by dialing all numbers in a range. Requiring user authentication before remote access is granted will help in avoiding unauthorized access over a modem line. "Monitoring and auditing for such activity" is incorrect. While monitoring and auditing can assist in detecting a wardialing attack, they do not defend against a successful wardialing attack. "Making sure that only necessary phone numbers are made public" is incorrect. Since a wardialing attack blindly calls all numbers in a range, whether certain numbers in the range are public or not is irrelevant. "Using completely different numbers for voice and data accesses" is incorrect. Using different number ranges for voice and data access might help prevent an attacker from stumbling across the data lines while wardialing the public voice number range but this is not an adequate countermeaure.
References: CBK, p. 214 AIO3, p. 534-535
NEW QUESTION # 381
Which of the following protocols operates at the session layer (layer 5)?
- A. RPC
- B. SPX
- C. LDP
- D. IGMP
Answer: A
Explanation:
The socket method of network use is a message-based system, in which one process writes a message to another. This is a long way from the procedural model. The remote procedure call is intended to act like a procedure call, but to act across the network transparently. The process makes a remote procedure call by pushing its parameters and a return address onto the stack, and jumping to the start of the procedure. The procedure itself is responsible for accessing and using the network. After the remote execution is over, the procedure jumps back to the return address. The calling process then continues. RPC works at the Session layer of the OSI model.
NEW QUESTION # 382
Which one of the following is an asymmetric algorithm?
- A. Knapsack
- B. Data Encryption Standard
- C. Enigma
- D. Data Encryption Algorithm.
Answer: A
Explanation:
Merkle-Hellman Knapsack is a Public Key Algorithm Pg 206 Krutz: CISSP Prep Guide: Gold Edition.
Not A:
"DES describes the Data Encryption Algorithm (DEA) and is the name of the Federal Information Processing Standard (FIPS) 46-1 that was adopted in 1977..." pg 195 Krutz: CISSP Prep Guide: Gold Edition.
Not B:
"The best-known symmetric key system is probably the Data Encryption Standard (DES)." pg 195 Krutz: CISSP Prep Guide: Gold Edition.
Not C:
"The German military used a polyalphabetic substitution cipher machine called the Enigma as its principal encipherment system during World War II." Pg 185 Krutz: CISSP Prep Guide: Gold Edition.
NEW QUESTION # 383
In terms of the order of acceptance, which of the following technologies is the LEAST accepted?
- A. Fingerprint
- B. Handprint
- C. Iris
- D. Retina patterns
Answer: D
Explanation:
The order of acceptance has slightly changed in the past years. It was Iris that was the most accepted method three years ago but today we have Voice Pattern that is by far the most accepted. Here is the list from most accepted first to least accepted at the bottom of the list: Voice Pattern Keystroke pattern Signature Hand geometry Handprint Fingerprint Iris Retina pattern
NEW QUESTION # 384
Which of the following uses a directed graph to specify the rights that a subject can transfer to an object, or that a subject can take from another subject?
- A. Access Matrix model
- B. Bell-Lapadula model
- C. Take-Grant model
- D. Biba model
Answer: C
Explanation:
The Take-Grant System is a model that helps in determining the protection rights (e.g., read or write) in a computer system. The Take-Grant system was introduced by
Jones, Lipton, and Snyder to show that it is possible to decide on the safety of a computer system even when the number of subjects and objects are very large, or unbound. This can be accomplished in linear time based on the initial size of the system. The take-grant system models a protection system which consists of a set of states and state transitions. A directed graph shows the connections between the nodes of this system. These nodes are representative of the subjects or objects of the model. The directed edges between the nodes represent the rights that one node has over the linked node.
NEW QUESTION # 385
When can a security program be considered effective?
- A. Audits are rec/Jarty performed and reviewed.
- B. Risk is lowered to an acceptable level.
- C. Vulnerabilities are proactively identified.
- D. Badges are regiiartv performed and validated
Answer: B
NEW QUESTION # 386
Which of the following is the BIGGEST concern with firewall security?
- A. Complex configuration rules leading to misconfiguration
- B. Buffer overflows
- C. Distributed denial of service (DDoS) attacks
- D. Internal hackers
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Firewalls filter traffic based on a defined set of rules. The rules must be configured correctly for the firewall to provide the intended security.
Incorrect Answers:
A: Firewalls main duty is to defend against external, not internal, threats.
C: Firewalls do not product from buffer overflows attacks.
D: Firewalls can help in defending from DDoS attacks, but the main concern with firewall is to configure them correctly.
References:
Stewart, James M., Ed Tittel, and Mike Chapple, CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition, Sybex, Indianapolis, 2011, p. 25
NEW QUESTION # 387
Which layer of the Open System Interconnection (OSI) model is reliant on other layers and is concerned with the structure, interpretation and handling of information?
- A. Presentation Layer
- B. Transport Layer
- C. Application Layer
- D. Session Layer
Answer: A
NEW QUESTION # 388
......
ISC CISSP Test Engine PDF - All Free Dumps: https://guidetorrent.passcollection.com/CISSP-valid-vce-dumps.html

