Test your basic knowledge |

CISSP Certified Information Systems Security Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A copy of transaction data - designed for querying and reporting






2. To be admissible in court they have to be made and collected in the normal course of business - not specially generated for a case in court. They can easily be considered hearsay if no firsthand proof of their accuracy and reliability exists






3. An ongoing program supported and funded by executive staff to ensure business continuity requirements are assessed - resources are allocated and - recovery and continuity strategies and procedures are completed and tested.






4. Mitigation of spamming and other attacks by delaying incoming connections as long as possible.






5. High level design or model with a goal of consistency - integrity - and balance






6. Information that - if made public or even shared around the organization - could seriously impede the organization's operations






7. Real-time - automatic and transparent backup of data.






8. To reduce fire






9. Employment education done once per position or at significant change of function






10. Dedicated fast memory located on the same board as the CPU






11. Inappropriate data






12. The past internationally accepted set of standards and processes for information security products evaluation and assurance - which separates function and assurance requirements






13. Malware that makes small random changes to many data points






14. An asymmetric cryptography mechanism that provides authentication.






15. Portable media used to store data that is not presently in use by an organization to free up space but still allow for disaster recovery. May also be called "Backup Tapes."






16. A test conducted on a specific component of a plan - in isolation from other components - typically under simulated operating conditions.






17. A collection of data or information that has a name






18. Written step-by-step actions






19. Subset of operating systems components dedicated to protection mechanisms






20. A backup supply that provides continuous power to critical equipment in the event that commercial power is lost.






21. An activity that is performed for the purpose of training and conditioning team members - and improving their performance.






22. An alert or alarm that is triggered when no actual attack has taken place






23. Recovery alternative - complete duplication of services including personnel






24. The event signaling an IDS to produce an alarm when no attack has taken place






25. Siphoning out or leaking information by dumping computer files or stealing computer reports and tapes.






26. A document designed to periodically exercise specific action tasks and procedures to ensure viability in a real disaster or severe outage situation.






27. A list of team members and/or key players to be contacted including their backups. The list will include the necessary contact information (i.e. Home phone - pager - cell - etc.) And in most cases be considered confidential.






28. Not fulfilling legally recognized obligation - failure to conform to a standard of care that results in injury or damage - and proximate causation - not practicing due diligence - or due care - not following prudent person (doing due diligence in due






29. Intellectual property management technique for identifying after distribution






30. The property that data meet with a priority expectation of quality and that the data can be relied upon.






31. Intellectual property protection for marketing efforts






32. Granular decision by a system of permitting or denying access to a particular resource on the system






33. A programming design philosophy and a type of programming language - which breaks a program into smaller units. Each unit has its own function.






34. Information about a particular data set






35. A failure of an IDS to detect an actual attack






36. Individuals - normally managers or directors - who have responsibility .for the integrity - accurate reporting and use of computerized data.






37. Wrong against society






38. A type of multitasking that allows for more even distribution of computing time among competing request






39. Enclosure of electronic communication devices to prevent leakage of electromagnetic signals.






40. Pertaining to law - verified as real






41. A electronic attestation of identity by a certificate authority






42. Impossibility of denying authenticity and identity






43. Line noise that is superimposed on the supply circuit.






44. The process of planning for and/or implementing the restarting of defined business operations following a disaster - usually beginning with the most critical or time-sensitive functions






45. A test that answers the questions: Does the organization have the documentation and people it needs. Do they understand the documentation?






46. To execute more than one instruction at an instant in time






47. Threats x Vulnerability x Asset Value = Total Risk






48. Evidence must be: admissible - authentic - complete - accurate - and convincing






49. Maintaining full control over requests - implementation - traceability - and proper documentation of changes.






50. A cooperative collection of business processes and technologies used for the purpose of binding individuals to a digital certificate