SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Certified Information Systems Security Professional
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A hash that has been further encrypted with a symmetric algorithm
Analysis
Cipher Text
DR Or BC Coordinator
Keyed-Hashing For Message Authentication
2. High level - pertaining to planning
Strategic
Record Level Deletion
Separation Of Duties
Risk Assessment
3. Event(s) that cause harm
Incident
Analysis
Malformed Input
Wireless Fidelity (Wi-Fi )
4. The restoration of computer files from backup media to restore programs and production data to the state that existed at the time of the last safe backup.
Data Recovery
Memory Management
Digital Certificate
Record Level Deletion
5. Layer 1 network device that is used to connect network segments together - but provides no traffic control (a hub).
Durability
Intrusion Detection Systems
Internal Use Only
Concentrator
6. Systematic assessment of threats and vulnerabilities that provides a basis for effective management of risk.
Consistency
War Driving
Civil Law
Analysis
7. A telephone exchange for a specific office or business.
Debriefing/Feedback
State Machine Model
Private Branch Exchange (PBX)
Discretionary Access Control (DAC)
8. A plan of action to commence immediately to prevent the loss of life and minimize injury and property damage.
Proxies
Due Diligence
Walk Though
Emergency Procedures
9. Alerts personnel to the presence of a fire
Record Level Deletion
Trojan Horse
Fire Detection
Mobile Recovery
10. An access policy that uses a security label system. Users have clearances - and resources have security labels that contain data classifications. MAC compares these two attributes to determine access control capabilies - most commonly used in governm
Residual Risk
Mandatory Access Control (MAC)
Total Risk
Noise
11. Real-time data backup ( Data Mirroring)
Compiler
Database Shadowing
File Extension
Mock Disaster
12. Vehicle stopping object
Bollard
Ethics
Logic Bomb
Burn
13. A Denial of Service attack initiated by sending spoofed ICMP echo request to IP broadcast addresses. (See Fraggle)
Fraggle
Full Test (Full Interruption)
Residual Data
Smurf
14. Program that inappropriately collects private data or activity
Spyware
Coaxial Cable
Payload
Accountability
15. For PKI - to store another copy of a key
Information Owner
Pervasive Computing and Mobile Computing Devices
System Life Cycle
Key Escrow
16. Information about a particular data set
Metadata
Acronym for American Standard Code for Information Interchange (ASCII)
Radio Frequency Interference (RFI)
Operational
17. The document that defines the resources - actions - tasks and data required to manage the business recovery process in the event of a business interruption within the stated disaster recovery goals.
Disaster Recovery Plan
Uninterruptible Power Supply (UPS)
Network Attached Storage (NAS)
Site Policy
18. Abstract and mathematical in nature - defining all possible states - transitions and operations
Investigation
Vital Record
State Machine Model
Faraday Cage/ Shield
19. Is secondhand and usually not admissible in court
Trusted Computing Base
Hearsay Evidence
Fiber Optics
Double Blind Testing
20. Maximum tolerance for loss of certain business function - basis of strategy
Resumption
Wait
Fiber Optics
Recovery Time Objectives
21. Memory management technique which allows subjects to use the same resource
Executive Succession
Failure Modes and Effect Analysis (FEMA)
Sharing
CobiT
22. Regular operations are stopped and where processing is moved to the alternate site.
Directive
Tar Pits
Multi-Core
Full-Interruption test
23. An activity that is performed for the purpose of training and conditioning team members - and improving their performance.
Isolation
Exercise
Disk Mirroring
Sequence Attacks
24. To evaluate the current situation and make basic decisions as to what to do
Data Backup Strategies
Process Isolation
Relocation
Triage
25. A process state - to be either be unable to run waiting for an external event or terminated
Interference (Noise)
Stopped
On-Site
Record Level Deletion
26. The one person responsible for data - its classification and control setting
Picking
Information Owner
Full Test (Full Interruption)
EMI
27. A document designed to periodically exercise specific action tasks and procedures to ensure viability in a real disaster or severe outage situation.
Man-In-The-Middle Attack
Patch Management
Embedded Systems
Test Plan
28. Responsibility of a user for the actions taken by their account which requires unique identification
Polyalphabetic
Accountability
Mobile Site
Procedure
29. Subset of operating systems components dedicated to protection mechanisms
Risk Mitigation
Governance
Data Diddler
Security Kernel
30. The collection and summation of risk data relating to a particular asset and controls for that asset
Hacker
Data Marts
Risk Assessment
Fragmented Data
31. Object reuse protection and auditing
File Extension
Orange Book C2 Classification
Authorization
Tracking
32. A disturbance that degrades performance of electronic devices and electronic communications.
Work Factor
Total Risk
Computer Forensics
Radio Frequency Interference (RFI)
33. A formal announcement by pre-authorized personnel that a disaster or severe outage is predicted or has occurred and that triggers pre-arranged mitigating actions (e.g. A move to an alternate site.)
Interception
Declaration
TCSEC (Orange Book)
Standard
34. The process of planning for and/or implementing the restarting of defined business operations following a disaster - usually beginning with the most critical or time-sensitive functions
State Machine Model
Resumption
Privacy Laws
File
35. Mitigation of system or component loss or interruption through use of backup capability.
Attacker (Black hat - Hacker)
Fault Tolerance
Standard
Fire Suppression
36. Tool which mediates access
Control
Processes are Isolated By
Patent
Detective
37. Representatives from each functional area or department get together and walk through the plan from beginning to end.
Convincing
TNI (Red Book)
True Attack Stimulus
Structured Walk-Through Test
38. Small data files written to a user's hard drive by a web server.
Incident
Repeaters
Spam
Cookie
39. Periodic - automatic and transparent backup of data in bulk.
Mirrored Site
Data Recovery
Electronic Vaulting
Cold Site
40. Memory management programming which make the limited RAM of the physical machine appear to be more by using a portion of the hard drive
Infrastructure
Mobile Recovery
Virtual Memory
Mirroring
41. Robust project management process of new systems with at least the following phases: design and development - production - distribution - operation - maintenance - retirement - and disposal
System Life Cycle
Storage Area Network (SAN)
Top Secret
Orange Book B2 Classification
42. One of the most important first steps in the planning development. Qualitative and quantitative data needs to be gathered - analyzed - interpreted and presented to management
Business Impact Analysis
Evidence
Declaration
Data Dictionary
43. Measures followed to restore critical functions following a security incident.
Authentication
Total Risk
Recovery
Hearsay
44. A backup supply that provides continuous power to critical equipment in the event that commercial power is lost.
Activation
Uninterruptible Power Supply (UPS)
Digital Certificate
Polyalphabetic
45. Unauthorized access of network devices.
Information Flow Model
Recovery Time Objectives
Physical Tampering
Embedded
46. The assignment of a level of sensitivity to data (or information) that results in the specification of controls for each level of classification.
Classification
Moore's Law
Data Backup Strategies
Alternate Site
47. Transaction controls for a database - a return to a previous state
Fire Suppression
Rollback
Open Mail Relay Servers
File Shadowing
48. To reduce sudden rises in current
Total Risk
Surge Suppressor
Codec
Digital Signature
49. Security Policy - Personnel Controls - Supervisory Structure - Security Awareness Training - Testing
Data Hiding
Side Channel Attack
Administrative Access Controls
Threat Agent
50. State of computer - to be running a process
Data Dictionary
Simulation Test
Operating
Disaster Recovery Tape