Test your basic knowledge |

CISSP Certified Information Systems Security Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A shield against leakage of electromagnetic signals.






2. An encryption method that has a key as long as the message






3. Asymmetric encryption of a hash of message






4. A Trojan horse with the express underlying purpose of controlling host from a distance






5. A telephone exchange for a specific office or business.






6. Security Policy - Personnel Controls - Supervisory Structure - Security Awareness Training - Testing






7. A social engineering attack that uses spoofed email or websites to persuade people to divulge information.






8. Provides a physical cross connect point for devices.






9. Disk space it used to occupy has been designated by the computer as available for reuse. The deleted file remains intact until it has been overwritten with a new file.






10. Binary decision by a system of permitting or denying access to the entire system






11. One method of testing a specific component of a plan. Typically - a team member makes a detailed presentation of the component to other team members (and possibly non-members) for their critique and evaluation.






12. Companies should have their own team - made up of ppl from management - IT leagal - HR - and public relations - security and other key areas






13. Enclosure of electronic communication devices to prevent leakage of electromagnetic signals.






14. Line noise that is superimposed on the supply circuit.






15. Memory management programming which make the limited RAM of the physical machine appear to be more by using a portion of the hard drive






16. Subset of operating systems components dedicated to protection mechanisms






17. A peripheral data storage device that may be found inside a desktop or laptop as permanent storage solution. The hard disk may also be a transportable version and attached to a desktop or laptop.






18. The back up of system - application - program and/or production files to secondary media. Data backups can be used to restore corrupted or lost data or to recover entire systems and databases in the event of a disaster.






19. Unauthorized access of network devices.






20. Information that - if made public or even shared around the organization - could seriously impede the organization's operations






21. Controls for logging and alerting






22. The first rating that requires security labels






23. Control type- that is communication based - typically written or oral






24. Pertaining to law - verified as real






25. A type a computer memory that temporarily stores frequently used information for quick access.






26. Total number of keys available that may be selected by the user of a cryptosystem






27. To assert or claim credentialing to an authentication system






28. The process of assessing damage - following a disaster - to computer hardware - vital records - office facilities - etc. And determining what can be salvaged or restored and what must be replaced.






29. Responsibility of a user for the actions taken by their account which requires unique identification






30. Use of specialized techniques for recovery - authentication - and analysis of electronic data






31. The process of identifying - accessing - reducing risk to an acceptable level - and implementing the right countermeasure to maintain that level of risk






32. To collect many small pieces of data






33. To ensure that evidence will be admissible in court by showing it was properly controlled and handled before being presented in court






34. Text that does not include special formatting features and therefore can be exchanged and read by most computer systems






35. High level - pertaining to planning






36. A comprehensive set of controls comprising best practices in information security and provides guidelines on how to set up and maintain security programs.






37. A critical event - which - if not handled in an appropriate manner - may dramatically impact an organization's profitability - reputation - or ability to operate.






38. More than one process in the middle of executing at a time






39. Mediates communication between un-trusted hosts on behalf of the hosts that it protects.






40. Intellectual property protection for an confidential and critical process






41. One way encryption






42. Another subject cannot see an ongoing or pending update until it is complete






43. The past U.S. military accepted set of standards and processes for computer systems evaluation and assurance - which combines function and assurance requirements






44. An unintended communication path






45. The hardware and software mediator of all subject and object interactions which has as its primary goal security policy enforcement.






46. The process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks






47. For PKI - to have more than one person in charge of a sensitive function






48. A control before attack






49. Subjects will not interact with each other's objects






50. A specialized wireless receiver/ transmitter placed in orbit that facilitates long distance communication.