Test your basic knowledge |

CISSP Security Architecture And Design

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. The TCB is the ________________ within a computer system that work together to enforce a security policy.






2. In Access Control terms it means to be higher than or equal to. In the Bell-Lapadula Model - this is refered to as the dominance relation - which is the relationship of the subject's clearance to the object's classification


3. This type of environment is highly secured environment that processes very sensitive information. It requires systems that are highly resistant to penetration.






4. What Orange Book security rating is reserved for systems that have been evaluated but fail to meet the criteria and requirements of the higher divisions?






5. The Bell-LaPadula model Subjects and Objects are ___________.






6. Simpler instructions that require fewer clock cycles to execute.






7. Requires more stringent authentication mechanisms and well-defined interfaces among layers.






8. The Simple Security rule is refered to as______________.






9. When a vendor submits a product for evaluation - it submits it to the ____________.






10. Execute one instruction at a time.






11. Which computer design approaches is based on the fact that in earlier technologies - the instruction fetch was the longest part of the cycle






12. What are the components of an object's sensitivity label?






13. For a subject to have read access to an object in a Multi-Level Security Policy - it is necessary that the subject's sensitivity label must ____________________.


14. Users are trusted but a certain level of accountability is required. C2 over is seen as the most reasonable class for commmercial applications - but the level of protection is still relatively weak.






15. A domain of trust that shares a single security policy and single management






16. Documentation must be provided - including test - design - and specification document - user guides and manuals






17. Which is an ISO standard product evaluation criteria that supersedes several different criteria






18. Data in Cache can be accessed much more quickly than Data






19. The security mechanisms and the system as a whole must perform predictably and acceptably in different situations continuously.






20. TCB contains The Security Kernel and all ______________.






21. The Bell-LaPadula Model is a _______________.






22. Which can be used as a covert channel?






23. A type of memory used for High-speed writing and reading activities.






24. Mandatory access control is enfored by the use of security labels.






25. The Physical memory address that the CPU uses






26. B1 is the ___________________ of the Trusted Network Interpretation (TNI) or TCSEC that offers labeled security protection.






27. Bell-LaPadula Model - ____________ : A subject at a given security level can NOT READ data that reside at a higher security level.






28. Verification Protection






29. In the Bell-LaPadula Model the Subject's Label contains ___________________.






30. The Bell-LaPadula Model is a _______________ that enforces Confidentiality aspect of access control. Formed by David Bell and Leonard LaPadula.






31. An organization within the National Security Agency (NSA) is responsible for Evaluating computer systems and products. The Trusted Product Evaluation program (TPEP) oversees the testing by approved entities of commercial products against a specific s






32. The Security Model Incorporates the ____________ that should be enforced in the system.






33. An abstract machine which must mediate all access to subjects to objects - be protected from modification - be verifiable as correct - and is always invoked






34. The Orange book does NOT Cover ________________ - And Database management systems






35. A process that resides in a privileged domain to be able to execute its instructions and process its data with the assurance that programs in a different domain can NOT negatively affect its environment.






36. Minimal Security






37. If a system initializes in a secure state and all allowed state transitions are secure - the every subsequent state will be secure no matter what inputs occur.






38. Audit data must be captured and protected to enforce accountability






39. Bell-LaPadula Model - ______________: A subject that has read and write capabilities can only perform those functions at the same security level - nothing higher and nothing lower.






40. Includes the security kernel as well as other security-related system functions that are within the boundary of the trusted computing base. System elements that are outside of the security perimeter need not be trusted.






41. An imaginary line that separates the trusted components of the TCB from those elements that are NOT trusted?






42. What is called the formal acceptance of the adequacy of a system's overall security by management?






43. Mandatory Protection






44. In both the Bell-LaPadula and Biba Models if the word "* or Star is used - _______________.






45. In both the Bell-LaPadula and Biba Models if the word "Simple is used ______________.






46. In which users are processing information at the same sensitivity level; thus - strict access control and auditing measures are not required. It would be a trusted envirnment with low security concerns.






47. Based on a known address with an offset value applied.






48. The group that oversees the processes of evaluation within TCSEC is?






49. Happen because input data is not checked for appropriate length at time of input






50. I/O drivers and utilities