CISSP-ISSAP: Information Systems Security Architecture ProfessionalDemo
By ISC · Browse Mode
//
CISSP-ISSAP: Information Systems Security Architec… Practice Exam
QuestionQ1
Infrastructure and System Security
Save question
You have just configured a wireless network for customers at a coffee shop. Which of the following are appropriate security measures to implement? Each correct answer represents a complete solution.
Choose two
AMAC filtering the router
BNot broadcasting SSID
CUsing WEP encryption
DUsing WPA encryption
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Infrastructure and System Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Identity and Access Management (IAM) Architecture
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Infrastructure and System Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Infrastructure and System Security
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Governance, Risk, and Compliance (GRC)Security Architecture ModelingInfrastructure and System SecurityIdentity and Access Management (IAM) Architecture
Which disaster recovery test involves shutting down operations at the primary site and transferring them to the recovery site in accordance with the disaster recovery plan?
AStructured walk-through test
BSimulation test
CFull-interruption test
DParallel test
A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator said that he had forgotten the password for the root account on UNIX servers and requested it. Although the technician did not know any administrator at the branch office, the caller sounded very friendly; because the technician knew the root password, he provided it. What type of attack has just taken place?
ASocial Engineering attack
BBrute Force attack
CWar dialing attack
DReplay attack
Which of the following serve as countermeasures against a man-in-the-middle attack? Each correct answer is a complete solution. Choose all that apply.
Choose three
AUsing public key infrastructure authentication.
BUsing basic authentication.
CUsing Secret keys for authentication.
DUsing Off-channel verification.
As a Network Administrator for NetTech Inc., you need secure communication on the company intranet. You decide to use public and private key pairs. What will you implement to achieve this?
AMicrosoft Internet Information Server (IIS)
BVPN
CFTP server
DCertificate server
QuestionQ6
Governance, Risk, and Compliance (GRC)
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Infrastructure and System Security
QuestionQ8
Infrastructure and System Security
QuestionQ9
Governance, Risk, and Compliance (GRC)
QuestionQ10
Infrastructure and System Security
QuestionQ11
Infrastructure and System Security
QuestionQ12
Identity and Access Management (IAM) Architecture
QuestionQ13
Infrastructure and System Security
QuestionQ14
Infrastructure and System Security
QuestionQ15
Infrastructure and System Security
QuestionQ16
Identity and Access Management (IAM) Architecture
QuestionQ17
Security Architecture Modeling
QuestionQ18
Security Architecture Modeling
QuestionQ19
Infrastructure and System Security
QuestionQ20
Identity and Access Management (IAM) Architecture
QuestionQ21
Infrastructure and System Security
QuestionQ22
Security Architecture Modeling
QuestionQ23
Infrastructure and System Security
QuestionQ24
Infrastructure and System Security
QuestionQ25
Infrastructure and System Security
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which of the following are phases in the Certification and Accreditation (C&A) process? Each correct answer represents a complete solution.
Choose two
ADetection
BContinuous Monitoring
CInitiation
DAuditing
Which of the following firewall types operates at the Session layer of the OSI model?
ACircuit-level firewall
BApplication-level firewall
CPacket filtering firewall
DSwitch-level firewall
You are responsible for security at a defense-contracting firm and are evaluating several potential encryption algorithms. One algorithm under review is not integer-based, uses shorter keys, and is public-key based. What type of algorithm is it?
ASymmetric
BNone - all encryptions are integer based.
CElliptic Curve
DRSA
Which of the following are examples of technical controls? Each correct answer represents a complete solution.
Choose three
AAuditing
BNetwork acchitecture
CSystem access
DData backups
A customer is concerned about security and wants to ensure that no one outside the network can view the IP addresses within it. Which router feature would accomplish this?
APort forwarding
BNAT
CMAC filtering
DFirewall
Which of the following firewall types examines the actual contents of packets?
APacket filtering firewall
BStateful inspection firewall
CApplication-level firewall
DCircuit-level firewall
Money Builders Inc. hires you to consult on setting up its Windows network. The company’s server room will be in a highly secure environment, and you must recommend an authentication method. The company CFO wants the server to use thumb impressions for authentication. Which of the following authentication methods should you suggest?
ACertificate
BSmart card
CTwo-factor
DBiometrics
You are a Network Administrator for NetTech Inc. You can access the site when you enter http://66.111.64.227 in a browser’s address bar, but you cannot access it when you enter http://www.company.com. What is the most likely cause?
AThe site's Web server is offline.
BThe site's Web server has heavy traffic.
CWINS server has no NetBIOS name entry for the server.
DDNS entry is not available for the host name.
You are a remote support technician. A user named Rick calls for assistance. Rick wants to connect his LAN to the Internet. Which of the following devices would you recommend that he use?
AHub
BRepeater
CBridge
DSwitch
ERouter
Which of the following shows a correct sequence of the different layers in the Open Systems Interconnection (OSI) model?
APhysical layer, data link layer, network layer, transport layer, presentation layer, session layer, and application layer
BPhysical layer, network layer, transport layer, data link layer, session layer, presentation layer, and application layer
Capplication layer, presentation layer, network layer, transport layer, session layer, data link layer, and physical layer
DPhysical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer
Access control systems allow an authority to regulate access to areas and resources within a physical facility or computer-based information system. Which service supplied by access control systems determines what a subject is permitted to do?
AAuthentication
BAuthorization
CAccountability
DIdentification
Which of the following security architectures specifies how to integrate widely disparate applications in a Web-based world that uses multiple implementation platforms?
ASherwood Applied Business Security Architecture
BService-oriented modeling and architecture
CEnterprise architecture
DService-oriented architecture
The service-oriented modeling framework (SOMF) offers a common modeling notation for addressing alignment between business and IT organizations. Which of the following principles does SOMF focus on? Each correct answer represents part of the solution. Choose all that apply.
Choose four
ADisaster recovery planning
BSOA value proposition
CSoftware assets reuse
DArchitectural components abstraction
EBusiness traceability
Which of the following cipher types operates on a group of bits instead of an individual character or bit in a message?
ABlock cipher
BClassical cipher
CSubstitution cipher
DStream cipher
Public Key Infrastructure (PKI) comprises the hardware, software, people, policies, and procedures required to create, manage, distribute, use, store, and revoke digital certificates. Which PKI component is used to list certificates that have been revoked or are no longer valid?
ACertification Practice Statement
BCertificate Policy
CCertificate Revocation List
DCertification Authority
You are the administrator for YupNo.com. You want to improve and strengthen the security of your computers while simplifying deployment. You are particularly concerned about portable computers used by remote employees. What can you use to increase security while still allowing users to carry out critical tasks?
ABitLocker
BSmart Cards
CService Accounts
DAppLocker
The OSI model is the networking model most commonly used in the industry. Applications, network functions, and protocols are generally referenced by one or more of the seven OSI layers. From the following, select the two statements that best describe OSI layer functions. Each correct answer represents a complete solution.
Choose two
ALayers 1 and 2 deal with application functionality and data formatting. These layers reside at the top of the model.
BLayers 4 through 7 define the functionality of IP Addressing, Physical Standards, and Data Link protocols.
CLayers 5, 6, and 7 focus on the Network Application, which includes data formatting and session control.
DLayers 1, 2, 3, and 4 deal with physical connectivity, encapsulation, IP Addressing, and Error Recovery. These layers define the end-to-end functions of data
Which of the following describes a location away from the computer center where document copies and backup media are stored?
AStorage Area network
BOff-site storage
COn-site storage
DNetwork attached storage
Which of the following firewall ports must be open for a VPN connection that uses the Point-to-Point Tunneling Protocol (PPTP)?
ATCP port 110
BTCP port 443
CTCP port 5060
DTCP port 1723
Which electrical event indicates that the grid has sufficient power to avoid a total power loss, but insufficient power to meet the current electrical demand?
Community Discussion