100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CISSP- Final Review Questions And Accurate Answers $9.99   Add to cart

Exam (elaborations)

CISSP- Final Review Questions And Accurate Answers

 12 views  0 purchase
  • Course
  • CISSP-
  • Institution
  • CISSP-

CISSP- Final Review Questions And Accurate Answers...

Preview 4 out of 53  pages

  • November 1, 2024
  • 53
  • 2024/2025
  • Exam (elaborations)
  • Questions & answers
  • cissp
  • cissp final review
  • CISSP-
  • CISSP-
avatar-seller
Easton
CISSP- Final Review Questions And
Accurate Answers

Which of the following would be an example of a policy statement?

A. Protect PII by hardening servers

B. Harden Windows 7 by first installing the pre-hardened OS image

C. You may create a strong password by choosing the first letter of each word in a
sentence and mixing in numbers and symbols

D. Download the CISecurity Windows benchmark and apply it - Answer A. Protect PII by
hardening servers (Policy)

Policies describe security in general terms, not specifics. They provide the blueprints
for an overall security program just as a specification defines your next product.



B. Harden is procedure

C. Guideline

D. Baseline



Which of the following describes the money saved by implementing a security control?

A. Total Cost of Ownership

B. Asset Value

C. Return on Investment

D. Control Savings - Answer C. Return on Investment (ROI)



A. TCO- Cost to implement

B. AV- Cost of asset

D. is ROI but not proper term

,Which of the following is an example of program policy?

A. Establish the information security program

B. Email Policy

C. Application development policy

D. Server policy - Answer A. Establish the information security program



B-D- Specific issue policies not a program



Which of the following proves an identity claim?

A. Authentication

B. Authorization

C. Accountability

D. Auditing - Answer A. Authentication



Authorization describes the actions a subject is allowed to take.

Accountability holds users accountable by providing audit data.

Auditing verifies compliance with an information security framework.

Which one of the following safeguards data against unauthorized modification?

A. Confidentiality

B. Integrity

C. Availability

D. Alteration - Answer B. Integrity

Confidentiality protects data against unauthorized disclosure.

Availability systems should be available for use in normal business operations

Alteration is unauthorized changes to data: the opposite of integrity.

Use the following scenario to answer questions 6-8:

,Your company sells Apple iPods online, and it has been subject to many denial of service
attacks. Assume your company has an average profit of $20,000 per week, and a typical
DoS attack diminishes sales by 40%. Assume you are subject on average to seven such
attacks per year. You can subscribe to a DoS-mitigation service for $10,000 per month.
You tested the service and believe that it would prevent the attacks.



What is the Annualized Rate of Occurrence in the above scenario?

A. $20,000

B. 40%

C. 7

D. $10,000 - Answer C. 7 (Know term ARO is amount attacks/year)



All others do not apply



Use the following scenario to answer questions 6-8:

Your company sells Apple iPods online and has suffered a number of denial of service
(DoS) attacks. Your firm generates, on average, $20,000 profit per week, and a typical
DoS attack cuts sales by 40%. You suffer through an average of seven DoS attacks per
year. A DoS-mitigation service is available for a subscription rate of $10,000 per month.
You have tried this service, and believe it will stop the attacks.



What is the ALE for lost iPod sales due to the DoS attacks?

A. $20,000

B. $8000

C. $84,000

D. $56,000 - Answer D. $56,000 (Know formulas ALE=SLE X ARO

SLE=20k x .4 (AV x EF)

ALE=8K x 7 or 56K



Use the following scenario to answer questions 6-8:

, Your company sells Apple iPods online and has suffered many denial of service DoS
attacks. Your company makes an average $20,000 profit per week, and a typical DoS
attack lowers sales by 40%. You suffer seven DoS attacks on average per year. A
DoS-mitigation service is available for a subscription fee of $10,000 per month. You have
tested this service, and believe it will mitigate the attacks.



Was the DoS mitigation service a good investment?

A. Yes, it will pay for itself

B. Yes, $10,000 is less than the $56,000 Annualized Loss Expectancy

C. No, the annual Total Cost of Ownership is higher than the Annualized Loss
Expectancy

D. No, the annual Total Cost of Ownership is lower than the Annualized Loss Expectancy
Answer C. No, the annual Total Cost of Ownership is higher than the Annualized Loss
Expectancy



TCO=10k/mo or 120k/annual vs data value 56K



Which of the following would be true while performing a Qualitative Risk Analysis?

A. Determine Asset Value

B. Determine ROI

C. Fill out the Risk Analysis Matrix

D. Fill out the ALE - C. Fill out the Risk Analysis Matrix



A,B,D involve quantity values



How does the standard differ from a guideline?

A. Standards are mandatory, guidelines are required

B. Standards are recommendations and guidelines are requirements

C. Standards are requirements and guidelines are recommendations

D. Standards are recommendations and guidelines are optional - Answer C. Standards

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller Easton. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $9.99. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

72042 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$9.99
  • (0)
  Add to cart