CISSP-ISSAP
Free trial
Verified
Question 1
Which of the following elements of planning gap measures the gap between the total potential for the market and the actual current usage by all the consumers in the market?
- A: Project gap
- B: Product gap
- C: Competitive gap
- D: Usage gap
Question 2
IPsec VPN provides a high degree of data privacy by establishing trust points between communicating devices and data encryption. Which of the following encryption methods does IPsec VPN use? Each correct answer represents a complete solution. Choose two.
- A: MD5
- B: LEAP
- C: AES
- D: 3DES
Question 3
A user is sending a large number of protocol packets to a network in order to saturate its resources and to disrupt connections to prevent communications between services. Which type of attack is this?
- A: Denial-of-Service attack
- B: Vulnerability attack
- C: Social Engineering attack
- D: Impersonation attack
Question 4
Which of the following types of firewall functions at the Session layer of OSI model?
- A: Circuit-level firewall
- B: Application-level firewall
- C: Packet filtering firewall
- D: Switch-level firewall
Question 5
Which of the following statements about a stream cipher are true? Each correct answer represents a complete solution. Choose three.
- A: It typically executes at a higher speed than a block cipher.
- B: It divides a message into blocks for processing.
- C: It typically executes at a slower speed than a block cipher.
- D: It divides a message into bits for processing.
- E: It is a symmetric key cipher.
Question 6
Which of the following types of attack can be used to break the best physical and logical security mechanism to gain access to a system?
- A: Social engineering attack
- B: Cross site scripting attack
- C: Mail bombing
- D: Password guessing attack
Question 7
You are the Security Consultant advising a company on security methods. This is a highly secure location that deals with sensitive national defense related data.
They are very concerned about physical security as they had a breach last month. In that breach an individual had simply grabbed a laptop and ran out of the building. Which one of the following would have been most effective in preventing this?
- A: Not using laptops.
- B: Keeping all doors locked with a guard.
- C: Using a man-trap.
- D: A sign in log.
Question 8
You want to implement a network topology that provides the best balance for regional topologies in terms of the number of virtual circuits, redundancy, and performance while establishing a WAN network. Which of the following network topologies will you use to accomplish the task?
- A: Bus topology
- B: Fully meshed topology
- C: Star topology
- D: Partially meshed topology
Question 9
Which of the following protocols is an alternative to certificate revocation lists (CRL) and allows the authenticity of a certificate to be immediately verified?
- A: RSTP
- B: SKIP
- C: OCSP
- D: HTTP
Question 10
Which of the following does PEAP use to authenticate the user inside an encrypted tunnel? Each correct answer represents a complete solution. Choose two.
- A: GTC
- B: MS-CHAP v2
- C: AES
- D: RC4
Question 11
Which of the following terms refers to a mechanism which proves that the sender really sent a particular message?
- A: Integrity
- B: Confidentiality
- C: Authentication
- D: Non-repudiation
Question 12
Which of the following terms refers to the method that allows or restricts specific types of packets from crossing over the firewall?
- A: Hacking
- B: Packet filtering
- C: Web caching
- D: Spoofing
Question 13
Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective. Which of the following types of hardware devices will Adam use to implement two-factor authentication?
- A: Biometric device
- B: One Time Password
- C: Proximity cards
- D: Security token
Question 14
Maria works as a Network Security Officer for Gentech Inc. She wants to encrypt her network traffic. The specific requirement for the encryption algorithm is that it must be a symmetric key block cipher. Which of the following techniques will she use to fulfill this requirement?
- A: IDEA
- B: PGP
- C: DES
- D: AES
Question 15
Which of the following protocols uses public-key cryptography to authenticate the remote computer?
- A: SSH
- B: Telnet
- C: SCP
- D: SSL
Question 16
Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
- A: Authentication
- B: Non-repudiation
- C: Integrity
- D: Confidentiality
Question 17
Which of the following are the examples of technical controls? Each correct answer represents a complete solution. Choose three.
- A: Auditing
- B: Network acchitecture
- C: System access
- D: Data backups
Question 18
Which of the following tenets does the CIA triad provide for which security practices are measured? Each correct answer represents a part of the solution. Choose all that apply.
- A: Integrity
- B: Accountability
- C: Availability
- D: Confidentiality
Question 19
Which of the following types of attacks cannot be prevented by technical measures only?
- A: Social engineering
- B: Brute force
- C: Smurf DoS
- D: Ping flood attack
Question 20
Which of the following attacks can be overcome by applying cryptography?
- A: Web ripping
- B: DoS
- C: Sniffing
- D: Buffer overflow
Question 21
You work as a Network Administrator for NetTech Inc. The company wants to encrypt its e-mails. Which of the following will you use to accomplish this?
- A: PGP
- B: PPTP
- C: IPSec
- D: NTFS
Question 22
Andrew works as a Network Administrator for Infonet Inc. The company's network has a Web server that hosts the company's Web site. Andrew wants to increase the security of the Web site by implementing Secure Sockets Layer (SSL). Which of the following types of encryption does SSL use? Each correct answer represents a complete solution. Choose two.
- A: Synchronous
- B: Secret
- C: Asymmetric
- D: Symmetric
That’s the end of your free questions
You’ve reached the preview limit for CISSP-ISSAPConsider upgrading to gain full access!
Free preview mode
Enjoy the free questions and consider upgrading to gain full access!