SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Certified Information Systems Security Professional
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A copy of transaction data - designed for querying and reporting
Data Warehouse
Policy
Examples of non-technical security components
Basics Of Secure Design
2. To be admissible in court they have to be made and collected in the normal course of business - not specially generated for a case in court. They can easily be considered hearsay if no firsthand proof of their accuracy and reliability exists
Common Law
Business Records
Total Risk
User
3. An ongoing program supported and funded by executive staff to ensure business continuity requirements are assessed - resources are allocated and - recovery and continuity strategies and procedures are completed and tested.
Data Integrity
Business Continuity Program
Evidence
Remanence
4. Mitigation of spamming and other attacks by delaying incoming connections as long as possible.
Tar Pits
Hub
Object
War Driving
5. High level design or model with a goal of consistency - integrity - and balance
Architecture
Hearsay
Content Dependent Access Control
Examples of technical security components
6. Information that - if made public or even shared around the organization - could seriously impede the organization's operations
Information Owner
Highly Confidential
Hearsay
Entrapment
7. Real-time - automatic and transparent backup of data.
Data Dictionary
Multi-Processing
On-Site
Remote Journaling
8. To reduce fire
Fire Suppression
Simulation Test
Information Flow Model
Fraggle
9. Employment education done once per position or at significant change of function
Deleted File
System Downtime
Job Training
Deletion
10. Dedicated fast memory located on the same board as the CPU
Key Escrow
ITSEC
CPU Cache
Central Processing Unit (CPU)
11. Inappropriate data
Compiler
Recovery
Malformed Input
Network Attached Storage (NAS)
12. The past internationally accepted set of standards and processes for information security products evaluation and assurance - which separates function and assurance requirements
Site Policy
Mobile Site
ITSEC
Standard
13. Malware that makes small random changes to many data points
Total Risk
2-Phase Commit
Data Diddler
Domain
14. An asymmetric cryptography mechanism that provides authentication.
Strong Authentication
Digital Signature
Multi-Party Control
Polyalphabetic
15. Portable media used to store data that is not presently in use by an organization to free up space but still allow for disaster recovery. May also be called "Backup Tapes."
Disaster Recovery Tape
Plaintext
Orange Book D Classification
Authentic
16. A test conducted on a specific component of a plan - in isolation from other components - typically under simulated operating conditions.
Operational
Standalone Test
Slack Space
Durability
17. A collection of data or information that has a name
System Downtime
Prevention
Repeaters
File
18. Written step-by-step actions
Contingency Plan
Procedure
Incident Response Team
Source Routing Exploitation
19. Subset of operating systems components dedicated to protection mechanisms
Cache
Security Kernel
Access Control Matrix
Packet Filtering
20. A backup supply that provides continuous power to critical equipment in the event that commercial power is lost.
Uninterruptible Power Supply (UPS)
Spiral
Enticement
Multi-Party Control
21. An activity that is performed for the purpose of training and conditioning team members - and improving their performance.
Threats
Recovery Time Objectives
Exercise
Cross Training
22. An alert or alarm that is triggered when no actual attack has taken place
Full-Interruption test
False (False Positive)
Business Interruption
Data Dictionary
23. Recovery alternative - complete duplication of services including personnel
Data Backup Strategies
Interpreter
Mirrored Site
Quantitative Risk Analysis
24. The event signaling an IDS to produce an alarm when no attack has taken place
Control
Symmetric
False Attack Stimulus
Corrective
25. Siphoning out or leaking information by dumping computer files or stealing computer reports and tapes.
Processes are Isolated By
Certificate Revocation List (CRL)
Data Leakage
Shielding
26. A document designed to periodically exercise specific action tasks and procedures to ensure viability in a real disaster or severe outage situation.
Data Custodian
Interference (Noise)
Test Plan
DR Or BC Coordinator
27. A list of team members and/or key players to be contacted including their backups. The list will include the necessary contact information (i.e. Home phone - pager - cell - etc.) And in most cases be considered confidential.
Contact List
CobiT
Shielding
Memory Management
28. Not fulfilling legally recognized obligation - failure to conform to a standard of care that results in injury or damage - and proximate causation - not practicing due diligence - or due care - not following prudent person (doing due diligence in due
Alert
False Attack Stimulus
Elements of Negligence
Transients
29. Intellectual property management technique for identifying after distribution
Watermarking
Multilevel Security System
Cache
Alarm Filtering
30. The property that data meet with a priority expectation of quality and that the data can be relied upon.
Metadata
Data Integrity
Mobile Site
File Server
31. Intellectual property protection for marketing efforts
Central Processing Unit (CPU)
Trademark
Accountability
Payload
32. Granular decision by a system of permitting or denying access to a particular resource on the system
Application Programming Interface
Authorization
Checklist Test
Parallel Test
33. A programming design philosophy and a type of programming language - which breaks a program into smaller units. Each unit has its own function.
Mixed Law System
Object Oriented Programming (OOP)
Quantitative
Electromagnetic Interference (EMI)
34. Information about a particular data set
Hearsay
Parallel Test
Metadata
Redundant Servers
35. A failure of an IDS to detect an actual attack
Database Replication
False Negative
Honeynet
Physical Tampering
36. Individuals - normally managers or directors - who have responsibility .for the integrity - accurate reporting and use of computerized data.
Information Flow Model
Data Owner
Entrapment
Brute Force
37. Wrong against society
Routers
Control Category
Aggregation
Criminal Law
38. A type of multitasking that allows for more even distribution of computing time among competing request
Preemptive
Mandatory Vacations
Business Records
Authentication
39. Enclosure of electronic communication devices to prevent leakage of electromagnetic signals.
Hot Spares
Domain
Shielding
True Attack Stimulus
40. Pertaining to law - verified as real
Authentic
Key Escrow
Tort
Watermarking
41. A electronic attestation of identity by a certificate authority
Supervisor Mode (monitor - system - privileged)
Alert/Alarm
Procedure
Digital Certificate
42. Impossibility of denying authenticity and identity
Non-Repudiation
Administrative Laws
Deadlock
Countermeasure
43. Line noise that is superimposed on the supply circuit.
System Downtime
Privacy Laws
Transients
Crisis
44. The process of planning for and/or implementing the restarting of defined business operations following a disaster - usually beginning with the most critical or time-sensitive functions
Control Type
Resumption
Picking
System Life Cycle
45. A test that answers the questions: Does the organization have the documentation and people it needs. Do they understand the documentation?
Orange Book A Classification
Kerckhoff's Principle
Desk Check Test
Object
46. To execute more than one instruction at an instant in time
Due Care
Highly Confidential
Shadowing (file shadowing)
Multi-Processing
47. Threats x Vulnerability x Asset Value = Total Risk
Substitution
Control
Ethics
Total Risk
48. Evidence must be: admissible - authentic - complete - accurate - and convincing
5 Rules Of Evidence
IDS Intrusion Detection System
Electrostatic Discharge
Access Control Matrix
49. Maintaining full control over requests - implementation - traceability - and proper documentation of changes.
Common Law
DR Or BC Coordinator
Physical Tampering
Change Control
50. A cooperative collection of business processes and technologies used for the purpose of binding individuals to a digital certificate
Chain of Custody
Data Warehouse
Public Key Infrastructure (PKI)
Mandatory Vacations