Test your basic knowledge |

CISSP Certified Information Systems Security Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Dedicated fast memory located on the same board as the CPU






2. A description of a database






3. An attack involving the hijacking of a TCP session by predicting a sequence number.






4. Pertaining to law - accepted by a court






5. A unit of execution






6. Motive - opportunity - and means; when looking for suspects it is important to consider these 3 things






7. The duplication of data on separate disks in real time to ensure its continuous availability - currency and accuracy. True mirroring will enable a zero recovery point objective.






8. The study of cryptography and cryptanalysis






9. What is will remain - persistence






10. Malware that makes small random changes to many data points






11. A backup of data located where staff can gain access immediately






12. Communication of a security incident to stakeholders and data owners.






13. Converts source code to an executable






14. Information about data or records






15. A committee of decision makers - business owners - technology experts and continuity professionals - tasked with making strategic recovery and continuity planning decisions for the organization.






16. A programming design philosophy and a type of programming language - which breaks a program into smaller units. Each unit has its own function.






17. An event that triggers an IDS to produce an alarm and react as though a real attack were in progress






18. Text that does not include special formatting features and therefore can be exchanged and read by most computer systems






19. Most granular organization of controls






20. One of the most important first steps in the planning development. Qualitative and quantitative data needs to be gathered - analyzed - interpreted and presented to management






21. High level - pertaining to planning






22. Long term knowledge building






23. Layer 1 network device that is used to connect network segments together - but provides no traffic control (a hub).






24. Moving letters around






25. A test that answers the questions: Does the organization have the documentation it needs? Can it be located?






26. A secure connection to another network.






27. Copies of the plan are handed out to each functional area to ensure the plan properly deals with the area's needs and vulnerabilities






28. Location to perform the business function






29. Evaluation of a system without prior knowledge by the tester






30. To segregate for the purposes of labeling






31. A type of malformed input that takes advantage of an appropriate true conditional logic statement adding a request for data that is against the security policy






32. A social engineering attack that uses spoofed email or websites to persuade people to divulge information.






33. Moving the alphabet intact a certain number spaces






34. Security policy - procedures - and compliance enforcement






35. Indivisible - data field must contain only one value that either all transactions take place or none do






36. Joining two pieces of text






37. Asymmetric encryption of a hash of message






38. System of law based upon precedence - with major divisions of criminal - tort - and administrative






39. Uncleared buffers or media






40. Determines the impact of the loss of an operational or technological resource. The loss of a system - network or other critical resource may affect a number of business processes.






41. The managerial approval to operate a system based upon knowledge of risk to operate






42. Measures followed to restore critical functions following a security incident.






43. Two certificate authorities that trust each other






44. Program that inappropriately collects private data or activity






45. Using small special tools all tumblers of the lock are aligned - opening the door






46. Independent malware that requires user interaction to execute






47. Fragmented data is live data that has been broken up and stored in various locations on a single hard drive or disk.






48. Electronically forwarding backup data to an offsite server or storage facility. Vaulting eliminates the need for tape shipment and therefore significantly shortens the time required to move the data offsite.






49. Uses two or more legal systems






50. Used to code/decode a digital data stream.