SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Security Architecture And Design
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An imaginary line that separates the trusted components of the TCB from those elements that are NOT trusted?
The trustworthiness of an information system
Multilevel Security Policies
The security perimeter
A security domain
2. The Biba Model adresses _____________________.
The Integrity of data within applications
Trusted Distribution
Fail safe
Division B - Mandatory Protection
3. A portion of a process. When the thread is generated - it shares the same domain(resources) as its process.
The security perimeter
A1 - Rating
The Rule is talking about writing
A Thread
4. There is only only one class in Division D. Reserved for systems that have been evaluated but fail to meet the criteria and requirements of the higher divisions.
Division D - Minimal Protection
The National Computer Security Center (NCSC)
'Dominate'
The reference monitor
5. Which addresses a portion of the primary memory by specifying the actual address of the memory location?
Simple Security Rule
Thrashing
Documentation - Orange Book
Direct Addressing
6. In B1 the security policy is based on Informal statement and the design specifications are reviewed and verified where as in B2 the ___________________ - and the system design and implementation are subject to more thorough review and testing procedu
Polyinstantiation
Security Policy is clearly defined and documented
Complex Instruction Set Computers (CISC)
Ring 0
7. A form of ROM(Read-Only Memory) that can be modified after it has been manufactured. It can only be programmed only one time.
Orange Book ratings
attributability
Programmable Read-Only Memory (PROM)
No read down
8. Based on The Bell-LaPadula model - because it allows for multilevel security to be integrated into the code.
Totality of protection mechanisms
Reduced Instruction Set Computers (RISC)
Orange Book interpretations
All Mandatory Access Control (MAC) systems
9. Minimal Security
Multiprocessing
Thrashing
Orange Book - D
The Simple Security Property
10. Access control labels must be associated properly with objects.
Isolate processes
Labels - Orange Book
Scalar processors
Constrained
11. Trusted facility management is an assurance requirement only for ________________.
Orange Book B
Controls the checks
Highly secure systems (B2 - B3 and A1)
Prohibits
12. A set of objects that a subject is able to access
A Domain
B3
Isolate processes
Buffer (temporary data storage area)
13. Data in Cache can be accessed much more quickly than Data
Security Policy - Orange Book
Orange Book B
Stored in Reak Memory
Highly secure systems (B2 - B3 and A1)
14. Bell-LaPadula Model - ______________: A subject that has read and write capabilities can only perform those functions at the same security level - nothing higher and nothing lower.
Swap Space
First evaluation class
Overt channel
The Strong star property rule
15. The Reserved hard drive space used to to extend RAM capabilites.
Discretionary Security Property (ds-property)
Swap Space
Documentation - Orange Book
Accreditation
16. Based on the Bell-LaPadula Security model - and evidence of reference monitor enforcement must be available.
Orange Book ratings
A Domain
Division B - Mandatory Protection Architecture
No read up
17. The Physical memory address that the CPU uses
International Standard 15408
Networks and Communications
Absolute addresses
Constrained
18. In access control terms - the word "dominate" refers to ___________.
Absolute addresses
Higher or equal to access class
Secondary Storage
Prohibits
19. The total(sum)combination of protection mechanisms within a computer system. The TCB includes hardware - software - and firmware.
Security Policy
Models concerned with integrity
The Trusted Computing Base (TCB)
Scalar processors
20. TCB contains The Security Kernel and all ______________.
All Mandatory Access Control (MAC) systems
security protection mechanisms
Multitasking
An abstract machine
21. Which integrity model defines a constrained data item - an integrity verification procedure and a transformation procedure?
security protection mechanisms
B3 - Security Domains
Fail safe
The Clark Wilson integrity model
22. Another word for Primary storage and distinguishes physical memory from virtual memory.
The *-Property rule (Star property)
Real storage
Process isolation
Continuous protection - O/B
23. B3 is also called "Security Domains" and imposes more granularity in each protection mechanism.
Totality of protection mechanisms
Orange Book - B3
Stored in Reak Memory
Pipelining
24. Should always trace to individuals responsible for observing and recording the data
Certification
Attributable data
Orange Book - A1
Dominate the object's sensitivity label
25. For rhe type of environment that processes sensitive data that require a higher degree of security. It requires systems that are relatively resistant to peneration and compromise
B3 - Rating
C2
B2 rating
First evaluation class
26. TCSEC provides a means to evaluate ______________________.
Programmable Read-Only Memory (PROM)
Protection Rings Support
The trustworthiness of an information system
D
27. The C2 evaluation class of the _________________ offers controlled access protection.
System High Security Mode
Trusted Network Interpretation (TNI)
Types of covert channels
Orange Book C
28. In both the Bell-LaPadula and Biba Models if the word "* or Star is used - _______________.
B3 - Rating
Life Cycle Assurance Requirement
Orange Book - B2
The Rule is talking about writing
29. Certification is a Technical review that assesses the _____________ - where as Accreditation is management's Official acceptance of the information in the Certification process findings.
Security mechanisms and evalautes their effectivenes
Administrative declaration
Invocation Property
Trusted facility management
30. In ______________ the subject must have: Need to Know for ALL the information contained within the system.
The "No read Up" rule
C2
Dedicated Security Mode
Electrically Erasable and Programmable Read-Only Memory (EEPROM)
31. The Orange book requires protection against two_____________ - which are these Timing and Storage
Protection Rings Support
Documentation - Orange Book
Types of covert channels
B2 rating
32. I/O drivers and utilities
Ring 2
Integrity
Ring 1
Types of covert channels
33. The _________________ specified in the Orange Book are: System architecture - System integrity - Covert channel analysis - Trusted facility management and Trusted recovery.
The Clark Wilson integrity model
Operational assurance requirements
Bell-LaPadula Model
B3
34. The assignment of a specific individual to administer the security-related functions of a system.
Trusted facility management
Networks and Communications
B2
Stored in Reak Memory
35. What model use an access control triples and requires that the system maintain separation of duty ?
Most commonly used approach
Clark-Wilson
Life Cycle Assurance Requirement
Totality of protection mechanisms
36. When a computer spends more time moving data from one small portion of memory to another THAN Actually processing the data
Thrashing
Dedicated Security Mode
Erasable and Programmable Read-Only Memory (EPROM)
Subject to Object Model
37. What does the * (star) property mean in the Bell-LaPadula model?
Controls the checks
Scalar processors
Most commonly used approach
No write down
38. Mandatory Protection
Swap Space
Fail safe
Orange Book B
Security Policy - Orange Book
39. B1 is the ___________________ of the Trusted Network Interpretation (TNI) or TCSEC that offers labeled security protection.
Enforces the rules
First evaluation class
Physical security
Division B - Mandatory Protection
40. Mandatory Access requires that _____________ be attached to all objects.
Simple Integrity Axiom
The Biba Model
Sensitivity labels
Direct Addressing
41. What prevents a process from accessing another process' data?
Process isolation
B2 rating
Real storage
The Evaluated Products List (EPL) with their corresponding rating
42. Which uses Protection Profiles and Security Targets?
International Standard 15408
B3
Highly secure systems (B2 - B3 and A1)
Ring 3
43. Configuration management is also defined in the Orange Book BUT As a _____________________ and NOT an operational assurance requirement.
A Domain
Life Cycle Assurance Requirement
*-Integrity Axiom
Access Matrix model
44. Reference Monitor is responsible for ______________ it compares the security labels of a subject and an object
C2 - Controlled Access Protection
Pipelining
Continuous protection - O/B
Access control to the objects by the subjects
45. The Indexed memory addresses that software uses
B1
The Common Criteria
Orange Book A
Logical addresses
46. The Biba Model - ______________: A Subject cannot write data to an object at a higher integrity level (No write Up)
Absolute addresses
*-Integrity Axiom
Trusted hardware - Software and Firmware
The Simple Security Property
47. The reference monitor - in accordance with the security policy - ____________ that are made in the access control database.
The Biba Model
The trustworthiness of an information system
No write down
Controls the checks
48. Which Orange Book evaluation level is described as "Controlled Access Protection"? - This class requires a more granular method of providing access control. The system must enforce strict logon procedures and provide decision-making capabilites when
B3
Trusted hardware - Software and Firmware
C2
Complex Instruction Set Computers (CISC)
49. According to the Orange Book - trusted facility management is not required for which security levels?
B1
Direct addressing
C2 - Controlled Access Protection
The reference monitor
50. Which computer design approaches is based on the fact that in earlier technologies - the instruction fetch was the longest part of the cycle
Trusted Products Evaluation Program (TPEP)
Complex Instruction Set Computers (CISC)
Access Matrix model
No read down