Showing posts with label CISSP (Certified Information Systems Security Professional). Show all posts
Showing posts with label CISSP (Certified Information Systems Security Professional). Show all posts
Thursday, September 10, 2015
Tuesday, September 8, 2015
Friday, January 23, 2015
CISSP Exam Preparation (Question 280)
(280) Which of the following describes elements that create
reliability and stability in networks and systems and which assures that
connectivity is accessible when needed?
A. Availability
B. Acceptability
C. Confidentiality
D. Integrity
Correct Answer: A
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 25, 2014
CISSP Exam Preparation (Question 254)
(254) Which choice below BEST
describes the process of data purging?
A. Complete physical destruction of the
media
B. Reusing data storage media after its
initial use
C. Overwriting of data media intended
to be reused in the same organization or area
D. Degaussing
or thoroughly overwriting media intended to be removed
the control of the organization or area
the control of the organization or area
Explanation:
Answer “Overwriting of data media intended to be reused in the same organization or area” refers to data clearing.
Answer “Complete physical destruction of the media” describes data destruction.
Answer “Reusing data storage media after its initial use” describes object reuse.
Answer “Overwriting of data media intended to be reused in the same organization or area” refers to data clearing.
Answer “Complete physical destruction of the media” describes data destruction.
Answer “Reusing data storage media after its initial use” describes object reuse.
- Muhammad Idham Azhari
Thursday, July 24, 2014
CISSP Exam Preparation (Question 253)
(253) The theft of a laptop
poses a threat to which tenet of the C.I.A. triad?
A. All
of the above
B. Availability
C. Integrity
D. Confidentiality
Explanation:
The correct answer is confidentiality, because the data can now
be read by someone outside of a monitored environment; availability,
because the user has lost the computing ability provided by the unit;
and integrity, because the data residing on and any telecommunications
from the portable are now suspect.
be read by someone outside of a monitored environment; availability,
because the user has lost the computing ability provided by the unit;
and integrity, because the data residing on and any telecommunications
from the portable are now suspect.
- Muhammad Idham Azhari
Wednesday, July 23, 2014
CISSP Exam Preparation (Question 252)
(252) seizure as established in the Fourth
Amendment to the U.S. Constitution.
These restrictions are still, essentially, more severe than those on private
citizens, who are not agents of a government entity. Thus, internal
investigators in an organization or private investigators are not subject to
the same restrictions as government officials. Private individuals are not
normally held to the same standards regarding search and seizure since
they are not conducting an unconstitutional government search.
However, there are certain exceptions where the Fourth Amendment
These restrictions are still, essentially, more severe than those on private
citizens, who are not agents of a government entity. Thus, internal
investigators in an organization or private investigators are not subject to
the same restrictions as government officials. Private individuals are not
normally held to the same standards regarding search and seizure since
they are not conducting an unconstitutional government search.
However, there are certain exceptions where the Fourth Amendment
applies to private citizens if they act as agents of
the government/police.
Which of the following is NOT one of these exceptions?
A. The private individual conducts a
warrantless search of company Which of the following is NOT one of these exceptions?
property for the company.
B. The private individual conducts a search that would require a search
warrant if conducted by a government entity.
C. The government is aware of the intent to search or is aware of a
search conducted by the private individual and does not object to
these actions.
D. The private individual performs the search to aid the government.
Explanation:
Since the private individual, say an employee of the company, conducts a search for evidence on property that is owned by the company and is not acting as an agent of the government, a warrantless search is permitted. The Fourth Amendment does not apply. For review, the Fourth Amendment guarantees: The right of the people to be secure in their persons, houses, papers,
and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. The exigent circumstances doctrine provides an exception to these guarantees if destruction of evidence is imminent. Then, a warrantless search and seizure of evidence can be conducted if there is probable cause to suspect criminal activity. The other answers describe exceptions where the private individual is subject to the
Fourth Amendment guarantees.
Since the private individual, say an employee of the company, conducts a search for evidence on property that is owned by the company and is not acting as an agent of the government, a warrantless search is permitted. The Fourth Amendment does not apply. For review, the Fourth Amendment guarantees: The right of the people to be secure in their persons, houses, papers,
and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. The exigent circumstances doctrine provides an exception to these guarantees if destruction of evidence is imminent. Then, a warrantless search and seizure of evidence can be conducted if there is probable cause to suspect criminal activity. The other answers describe exceptions where the private individual is subject to the
Fourth Amendment guarantees.
Tuesday, July 22, 2014
CISSP Exam Preparation (Question 251)
(251) Which of the following is
NOT a form of computer/network surveillance?
A. Use
of CCTV cameras
B. Use of network sniffers
C. Keyboard monitoring
D. Review of audit logs
Explanation:
CCTV cameras fall under the category of physical surveillance.
Answers a and b are forms of active surveillance. These types of surveillance require an organizational policy informing the employees that the surveillance is being conducted. Additionally, warning banners describing the surveillance at log-on to a computer or network should be prominently displayed. These banners usually state that by logging on, the user acknowledges the warning and agrees to the monitoring. Answer “Review of audit logs” is a passive form of computer/network surveillance.
Answers a and b are forms of active surveillance. These types of surveillance require an organizational policy informing the employees that the surveillance is being conducted. Additionally, warning banners describing the surveillance at log-on to a computer or network should be prominently displayed. These banners usually state that by logging on, the user acknowledges the warning and agrees to the monitoring. Answer “Review of audit logs” is a passive form of computer/network surveillance.
- Muhammad Idham Azhari
Monday, July 21, 2014
CISSP Exam Preparation (Question 250)
(250) The Internet Activities
Board (IAB) considers which of the following
behaviors relative to the Internet as unethical?
behaviors relative to the Internet as unethical?
A. Negligence
in the conduct of Internet experiments
B. Recordkeeping in which an individual
cannot find out what information
concerning that individual is in the record
C. Improper dissemination and use of
identifiable personal data
D. Recordkeeping whose very existence
is secret
Explanation:
The IAB document, Ethics and the Internet (RFC 1087) listed behaviors as unethical that:
Seek to gain unauthorized access to the resources of the Internet
Destroy the integrity of computer-based information
Disrupt the intended use of the Internet
Waste resources such as people, capacity and computers through such actions
Compromise the privacy of users
Seek to gain unauthorized access to the resources of the Internet
Destroy the integrity of computer-based information
Disrupt the intended use of the Internet
Waste resources such as people, capacity and computers through such actions
Compromise the privacy of users
Involve negligence in the conduct of Internetwide
experiments
The other answers are taken from the Code of Fair Information Practices of the U.S. Department of Health, Education of Welfare.
- Muhammad Idham Azhari
The other answers are taken from the Code of Fair Information Practices of the U.S. Department of Health, Education of Welfare.
- Muhammad Idham Azhari
Thursday, July 3, 2014
CISSP Exam Preparation (Question 239)
(239) What is the recommended height
of perimeter fencing to keep out casual trespassers?
A. 8 to 12 high
B. 6 to 7 high
C. 3
to 4 high
D. 1 to 2 high
Explanation:
3 to 4 high fencing is considered minimal protection, only for restricting casual trespassers.
Answers “6 to 7 high” and “8 to 12 high” are better protection against intentional intruders.
- Muhammad Idham Azhari
Monday, September 30, 2013
CISSP (Certified Information Systems Security Professional) Domains
Berikut 10 Domain yang ada dalam CISSP.
1. Access Control - a collection of mechanisms that work together to create security architecture to protect the assets of the information system.
2. Telecommunications and Network Security - discusses network structures, transmission methods, transport formats and security measures used to provide availability, integrity and confidentiality.
3. Information Security Governance and Risk Management - the identification of an organization's information assets and the development, documentation and implementation of policies, standards, procedures and guidelines.
4. Software Development Security - refers to the controls that are included within systems and applications software and the steps used in their development.
5. Cryptography - the principles, means and methods of disguising information to ensure its integrity, confidentiality and autheticity.
6. Security Architecture and Design - contains the concepts, principles, structures and standards used to design, implement, monitor, and secure, operating systems, equipment, networks, applications, and those controls used to enforce various levels of confidentiality, integrity and availability.
7. Operations Security - used to identify the controls over hardware, media and the operators with access privileges to any of these resources.
8. Business Continuity and Disaster Recovery Planning - addresses the preservation of the business in the face of major disruptions to normal business operations.
9. Legal, Regulations, Investigations and Compliance - addresses computer crime laws and regulations; the ivestigative measures and techniques which can be used to determine if a crime has been committed and methods to gather evidence.
10. Physical (Environmental) Security - addresses the threats, vulnerabilities and countermeasures that can be utilized to physically protect an enterprise's resources and sensitive information.
Quoted by Muhammad Idham Azhari from isc2.org
1. Access Control - a collection of mechanisms that work together to create security architecture to protect the assets of the information system.
- Concepts/methodologies/techniques
- Effectiveness
- Attacks
2. Telecommunications and Network Security - discusses network structures, transmission methods, transport formats and security measures used to provide availability, integrity and confidentiality.
- Network architecture and design
- Communications channels
- Network components
- Network attacks
3. Information Security Governance and Risk Management - the identification of an organization's information assets and the development, documentation and implementation of policies, standards, procedures and guidelines.
- Security governance and policy
- Information classification/ownership
- Contractual agreements and procurement processes
- Risk management concepts
- Personal security
- Security education, training and awareness
- Certification and accreditation
4. Software Development Security - refers to the controls that are included within systems and applications software and the steps used in their development.
- Systems development life cycle (SDLC)
- Application environment and security controls
- Effectiveness of application security
5. Cryptography - the principles, means and methods of disguising information to ensure its integrity, confidentiality and autheticity.
- Encryption concepts
- Digital signatures
- Cryptanalytic attacks
- Public Key Infrastructure (PKI)
- Information hiding alternatives
6. Security Architecture and Design - contains the concepts, principles, structures and standards used to design, implement, monitor, and secure, operating systems, equipment, networks, applications, and those controls used to enforce various levels of confidentiality, integrity and availability.
- Fundamental concepts of security models
- Capabilities of information systems (e.g. memory protection, virtualization)
- Countermeasure principles
- Vulnerabilities and threats (e.g. cloud computing, aggregation, data flow control)
7. Operations Security - used to identify the controls over hardware, media and the operators with access privileges to any of these resources.
- Resource protection
- Incident response
- Attack prevention and response
- Patch and vulnerability management
8. Business Continuity and Disaster Recovery Planning - addresses the preservation of the business in the face of major disruptions to normal business operations.
- Business impact analysis
- Recovery strategy
- Disaster recovery process
- Provide training
9. Legal, Regulations, Investigations and Compliance - addresses computer crime laws and regulations; the ivestigative measures and techniques which can be used to determine if a crime has been committed and methods to gather evidence.
- Legal issues
- Investigations
- Forensic procedures
- Compliance requirements/procedures
10. Physical (Environmental) Security - addresses the threats, vulnerabilities and countermeasures that can be utilized to physically protect an enterprise's resources and sensitive information.
- Site/facility design considerations
- Perimeter security
- Internal security
- Facilities security
Quoted by Muhammad Idham Azhari from isc2.org
Subscribe to:
Posts (Atom)