SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Certified Information Systems Security Professional
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A shield against leakage of electromagnetic signals.
Inference
Concentrator
Faraday Cage/ Shield
Routers
2. An encryption method that has a key as long as the message
Steganography
One Time Pad
Running Key
Wireless Fidelity (Wi-Fi )
3. Asymmetric encryption of a hash of message
Off-Site Storage
Common Criteria
Digital Signature
Remote Journaling
4. A Trojan horse with the express underlying purpose of controlling host from a distance
Mirrored Site
Guidelines
Remote Access Trojan
Virus
5. A telephone exchange for a specific office or business.
Secondary Storage
Private Branch Exchange (PBX)
Evidence
Disaster Recovery Tape
6. Security Policy - Personnel Controls - Supervisory Structure - Security Awareness Training - Testing
Payload
Administrative Access Controls
Recovery
Modification
7. A social engineering attack that uses spoofed email or websites to persuade people to divulge information.
Content Dependent Access Control
Phishing
Confidence Value
Trusted Computing Base
8. Provides a physical cross connect point for devices.
Patch Panels
Conflict Of Interest
Transfer
System Downtime
9. Disk space it used to occupy has been designated by the computer as available for reuse. The deleted file remains intact until it has been overwritten with a new file.
Reciprocal Agreement
Service Bureau
Orange Book C2 Classification
Deleted File
10. Binary decision by a system of permitting or denying access to the entire system
Authentication
Architecture
Monitor
Worldwide Interoperability for Microwave Access (WI-MAX )
11. One method of testing a specific component of a plan. Typically - a team member makes a detailed presentation of the component to other team members (and possibly non-members) for their critique and evaluation.
HTTP Response Splitting
Chain Of Custody
Protection
Structured Walkthrough
12. Companies should have their own team - made up of ppl from management - IT leagal - HR - and public relations - security and other key areas
Recovery
Polyalphabetic
Incident Response Team
Orange Book B2 Classification
13. Enclosure of electronic communication devices to prevent leakage of electromagnetic signals.
Concatenation
Gateway
Shielding
Concentrator
14. Line noise that is superimposed on the supply circuit.
Burn
Simulation Test
Transients
Checklist Test
15. Memory management programming which make the limited RAM of the physical machine appear to be more by using a portion of the hard drive
Accurate
Virtual Memory
Recovery
Key Space
16. Subset of operating systems components dedicated to protection mechanisms
Security Kernel
Cache
Pointer
SYN Flooding
17. A peripheral data storage device that may be found inside a desktop or laptop as permanent storage solution. The hard disk may also be a transportable version and attached to a desktop or laptop.
Redundant Servers
Byte
Hard Disk
Non-Interference
18. The back up of system - application - program and/or production files to secondary media. Data backups can be used to restore corrupted or lost data or to recover entire systems and databases in the event of a disaster.
Data Backups
Compartmentalize
Cross Certification
Patch Panels
19. Unauthorized access of network devices.
Incident Response
Aggregation
Physical Tampering
Journaling
20. Information that - if made public or even shared around the organization - could seriously impede the organization's operations
Highly Confidential
Concatenation
Salami
Targeted Testing
21. Controls for logging and alerting
Intrusion Detection Systems
Rogue Access Points
Forward Recovery
Marking
22. The first rating that requires security labels
Orange Book B1 Classification
Admissible
Need-To-Know
Inference
23. Control type- that is communication based - typically written or oral
Repeaters
Quantitative
Architecture
Administrative
24. Pertaining to law - verified as real
Transfer
Honeypot
Threats
Authentic
25. A type a computer memory that temporarily stores frequently used information for quick access.
Criminal Law
Forensic Copy
Cache
Generator
26. Total number of keys available that may be selected by the user of a cryptosystem
Discretionary Access Control (DAC)
Disaster Recovery Tape
Key Space
Patch Panels
27. To assert or claim credentialing to an authentication system
Method
Memory Management
Identification
Business Interruption Insurance
28. The process of assessing damage - following a disaster - to computer hardware - vital records - office facilities - etc. And determining what can be salvaged or restored and what must be replaced.
Hijacking
Mandatory
Damage Assessment
Trade Secret
29. Responsibility of a user for the actions taken by their account which requires unique identification
Accreditation
Contact List
Accountability
Fault Tolerance
30. Use of specialized techniques for recovery - authentication - and analysis of electronic data
Computer Forensics
Asymmetric
Layering
Structured Walkthrough
31. The process of identifying - accessing - reducing risk to an acceptable level - and implementing the right countermeasure to maintain that level of risk
Information Risk Management (IRM)
Modems
Framework
Phishing
32. To collect many small pieces of data
Aggregation
Analysis
Cross-Site Scripting
Accurate
33. To ensure that evidence will be admissible in court by showing it was properly controlled and handled before being presented in court
2-Phase Commit
Plan Maintenance Procedures
Shadowing (file shadowing)
Chain of Custody
34. Text that does not include special formatting features and therefore can be exchanged and read by most computer systems
Acronym for American Standard Code for Information Interchange (ASCII)
False Attack Stimulus
Directive
Data Custodian
35. High level - pertaining to planning
Strategic
Security Blueprint
Cache
Information Technology Security Evaluation Criteria - ITSEC
36. A comprehensive set of controls comprising best practices in information security and provides guidelines on how to set up and maintain security programs.
Blind Testing
Maximum Tolerable Downtime (MTD)
ISO/IEC 27002
Liability
37. A critical event - which - if not handled in an appropriate manner - may dramatically impact an organization's profitability - reputation - or ability to operate.
Strong Authentication
Administrative Laws
Operating
Crisis
38. More than one process in the middle of executing at a time
Multi-Tasking
Data Hiding
Service Bureau
CobiT
39. Mediates communication between un-trusted hosts on behalf of the hosts that it protects.
Criminal Law
Inrush Current
Backup
Proxies
40. Intellectual property protection for an confidential and critical process
False (False Positive)
Assembler
Modems
Trade Secret
41. One way encryption
Hash Function
Hot Site
Reference Monitor
War Driving
42. Another subject cannot see an ongoing or pending update until it is complete
Sequence Attacks
Isolation
Remote Journaling
Operational Test
43. The past U.S. military accepted set of standards and processes for computer systems evaluation and assurance - which combines function and assurance requirements
TCSEC (Orange Book)
Total Risk
Plaintext
Walk Though
44. An unintended communication path
Alert
Custodian
Covert Channel
Codec
45. The hardware and software mediator of all subject and object interactions which has as its primary goal security policy enforcement.
Checklist Test (desk check)
Shift Cipher (Caesar)
Administrative Access Controls
Reference Monitor
46. The process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks
Business Unit Recovery
Alarm Filtering
Fault
Notification
47. For PKI - to have more than one person in charge of a sensitive function
Picking
Primary Storage
Wait
Multi-Party Control
48. A control before attack
Recovery Point Objective (RPO)
Administrative Access Controls
Safeguard
Crisis
49. Subjects will not interact with each other's objects
HTTP Response Splitting
Time Of Check/Time Of Use
Contingency Plan
Non-Interference
50. A specialized wireless receiver/ transmitter placed in orbit that facilitates long distance communication.
Byte
Satellite
Source Routing Exploitation
Guidelines