Test your basic knowledge |

CISSP Certified Information Systems Security Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A temporary public file to inform others of a compromised digital certificate






2. Forgery of the sender's email address in an email header.






3. System of law based upon precedence - with major divisions of criminal - tort - and administrative






4. Fragmented data is live data that has been broken up and stored in various locations on a single hard drive or disk.






5. Mathematical function that determines the cryptographic operations






6. A specification for wireless Metropolitan Area Networks (IEEE 802.16) that provides an alternative to the use of cable and DSL for last mile delivery.






7. Impossibility of denying authenticity and identity






8. Intellectual property protection for an invention






9. Just enough access to do the job






10. A test that answers the questions: Does the organization have the documentation and people it needs. Do they understand the documentation?






11. A backup of data located where staff can gain access immediately






12. Written step-by-step actions






13. Consume resources to a point of exhaustion - loss of availability






14. Subset of operating systems components dedicated to protection mechanisms






15. Requirement to take time off






16. Adversary intercepts encrypted communications - decrypts - views - encrypts - and send along to the true destination






17. Converts source code to an executable






18. A layer 2 device that used to connect two network segments and regulate traffic.






19. To load the first piece of software that starts a computer.






20. Responsibility for actions






21. Controls for logging and alerting






22. A risk assessment method - intrinsic value






23. Control type- that is communication based - typically written or oral






24. Record of system activity - which provides for monitoring and detection.






25. A set of laws that the organization agrees to be bound by






26. Information residing on computer systems - that is readily visible to the operating system with which it was created and is immediately accessible to users without deletion - modification or reconstruction.






27. Use of a backup server(s) to protect information and essential processes in the event of a primary system failure.






28. Define the way in which the organization operates.






29. Information that - if made public or even shared around the organization - could seriously impede the organization's operations






30. Lower frequency noise






31. Includes identification and collection of the evidence - its storage - preservation - transportation - presentation in court - and return to the owner






32. A program with an inappropriate second purpose






33. The current internationally accepted set of standards and processes for information security products evaluation and assurance - which joins function and assurance requirements






34. Someone who want to know how something works - typically by taking it apart






35. A perpetrator leaves something behind or takes something with them at the scene of a crime


36. The property that data meet with a priority expectation of quality and that the data can be relied upon.






37. Requires two of the three user authentication attributes (knows - is or has) - e.g. you have an ATM card and enter a PIN






38. Pertaining to law - high degree of veracity






39. Malware that uses the trust on a website to redirect users to untrusted websites which captures data or installs more malware






40. Highly sensitive internal documents that could seriously damage the organization if such information were lost or made public.






41. System mediation of access with the focus on the context of the request






42. Induces a crime - tricks a person - and is illegal






43. The process of recovering a database to the point of failure by applying active journal or log data to the current backup files of the database.






44. Inference about encrypted communications






45. The level and label given to an individual for the purpose of compartmentalization






46. Security Policy - Personnel Controls - Supervisory Structure - Security Awareness Training - Testing






47. Hitting a filed down key in a lock with a hammer to open without real key






48. Program instructions based upon the CPU's specific architecture






49. Pertaining to law - accepted by a court






50. A electronic attestation of identity by a certificate authority