BLOGSPOT atas

Friday, May 29, 2015

Logo Design Inspiration - 29 May 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 298)

(298) Which one of the following is not one of the outcomes of a vulnerability analysis?

A. Quantative loss assessment
B. Qualitative loss assessment
C. Formal approval of BCP scope and initiation document
D. Defining critical support areas

Correct Answer: C


Explanation/Reference:

- Muhammad Idham Azhari

Friday, May 22, 2015

Logo Design Inspiration - 22 May 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 297)

(297) Risk analysis is MOST useful when applied during which phase of the system development process?

A. Project identification
B. Requirements definition
C. System construction
D. Implementation planning

Correct Answer: A

Explanation/Reference:

Reference: pg 684 Shon Harris: All-in-One CISSP Certification

- Muhammad Idham Azhari

Friday, May 15, 2015

Logo Design Inspiration - 15 May 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 296)

(296) Which of the following is not a compensating measure for access violations?

A. Backups
B. Business continuity planning
C. Insurance
D. Security awareness

Correct Answer: D


Explanation/Reference:

- Muhammad Idham Azhari

Friday, May 8, 2015

Logo Design Inspiration - 08 May 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 295)

(295) Which of the following best explains why computerized information systems frequently fail to meet the needs of users?

A. Inadequate quality assurance (QA) tools
B. Constantly changing user needs
C. Inadequate user participation in defining the system's requirements
D. Inadequate project management.

Correct Answer: C


Explanation/Reference:

- Muhammad Idham Azhari

Thursday, April 30, 2015

Logo Design Inspiration - 30 Apr 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 294)

(294) Which of the following would be best suited to provide information during a review of the controls over the process of defining IT service levels?

A. Systems programmer
B. Legal stuff
C. Business unit manager
D. Programmer

Correct Answer: C


Explanation/Reference:

- Muhammad Idham Azhari

Friday, April 24, 2015

Logo Design Inspiration - 24 Apr 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 293)

(293) In developing a security awareness program, it is MOST important to

A. Understand the corporate culture and how it will affect security.
B. Understand employees preferences for information security.
C. Know what security awareness products are available.
D. Identify weakness in line management support.

Correct Answer: A

Explanation/Reference:
The controls and procedures of a security program should reflect the nature of the data being

processed...These different types of companies would also have very different cultures. For a security awareness program to be effective, these considerations must be understood and the program should be developed in a fashion that makes sense per environment - Shon Harris All-in-one CISSP Certification Guide pg 109

- Muhammad Idham Azhari

Friday, April 17, 2015

Logo Design Inspiration - 17 Apr 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 292)

(292) Which one of the following is the MAIN goal of a security awareness program when addressing senior management?

A. Provide a vehicle for communicating security procedures.
B. Provide a clear understanding of potential risk and exposure.
C. Provide a forum for disclosing exposure and risk analysis.
D. Provide a forum to communicate user responsibilities.

Correct Answer: B

Explanation/Reference:

Explanation:
When the Security Officer is addressing Senior Management, the focus would not be on user
responsibilities, it would be on making sure the Senior Management have a clear understanding of the risk and potential liability is Not D: Item D would be correct in a situation where Senior Management is addressing organizational staff.

- Muhammad Idham Azhari

Friday, April 10, 2015

Logo Design Inspiration - 10 Apr 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 291)

(291) Which of the following is most relevant to determining the maximum effective cost of access control?

A. the value of information that is protected
B. management's perceptions regarding data importance
C. budget planning related to base versus incremental spending.
D. the cost to replace lost data

Correct Answer: A


Explanation/Reference:

- Muhammad Idham Azhari

Friday, April 3, 2015

Logo Design Inspiration - 03 Apr 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 290)

(290) What is the MAIN purpose of a change control/management system?

A. Notify all interested parties of the completion of the change.
B. Ensure that the change meets user specifications.
C. Document the change for audit and management review.
D. Ensure the orderly processing of a change request.

Correct Answer: C


Explanation/Reference:

- Muhammad Idham Azhari

Friday, March 27, 2015

Logo Design Inspiration - 27 Mar 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 289)

(289) Within the organizational environment, the security function should report to an organizational level that

A. Has information technology oversight.
B. Has autonomy from other levels.
C. Is an external operation.
D. Provides the internal audit function.

Correct Answer: B


Explanation/Reference:

- Muhammad Idham Azhari

Friday, March 20, 2015

Logo Design Inspiration - 20 Mar 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 288)

(288) Organizations develop change control procedures to ensure that

A. All changes are authorized, tested, and recorded.
B. Changes are controlled by the Policy Control Board (PCB).
C. All changes are requested, scheduled, and completed on time.
D. Management is advised of changes made to systems.

Correct Answer: A

Explanation/Reference:

"Change Control: Changes must be authorized, tested, and recorded. Changed systems may require recertificationvand re-accreditation." Pg 699 Shon Harris: All-in-One CISSP Certification

- Muhammad Idham Azhari

Friday, March 13, 2015

Logo Design Inspiration - 13 Mar 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 287)

(287) Information security is the protection of data. Information will be protected mainly based on:

A. Its sensitivity to the company.
B. Its confidentiality.
C. Its value.
D. All of the choices.

Correct Answer: D

Explanation/Reference:

Information security is the protection of data against accidental or malicious disclosure, modification, or destruction. Information will be protected based on its value, confidentiality, and/or sensitivity to the company, and the risk of loss or compromise. At a minimum, information will be update-protected so that only authorized individuals can modify or erase the information.

- Muhammad Idham Azhari

Friday, March 6, 2015

Logo Design Inspiration - 06 Mar 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 286)

(286) The security planning process must define how security will be managed, who will be responsible, and

A. Who practices are reasonable and prudent for the enterprise.
B. Who will work in the security department.
C. What impact security will have on the intrinsic value of data.
D. How security measures will be tested for effectiveness.

Correct Answer: D


Explanation/Reference:

- Muhammad Idham Azhari

Saturday, February 28, 2015

Friday, February 27, 2015

Logo Design Inspiration - 27 Feb 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 285)

(285) Which one of the following is the MOST crucial link in the computer security chain?

A. Access controls
B. People
C. Management
D. Awareness programs

Correct Answer: C


Explanation/Reference:

- Muhammad Idham Azhari

Thursday, February 26, 2015

Wednesday, February 25, 2015

Tuesday, February 24, 2015

Saturday, February 21, 2015

Friday, February 20, 2015

Logo Design Inspiration - 20 Feb 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 284)

(284) The Structures, transmission methods, transport formats, and security measures that are used to provide integrity, availability, and authentication, and confidentiality for transmissions over private and public communications networks and media includes:

A. The Telecommunications and Network Security domain
B. The Telecommunications and Netware Security domain
C. The Technical communications and Network Security domain
D. The Telnet and Security domain

Correct Answer: A

Explanation/Reference:

The Telecommunications, Network, and Internet Security Domain encompasses the structures, transmission methods, transport formats, and security measures used to provide integrity, availability, authentication, and confidentiality for transmissions over private and public communications networks and media." Pg 515 Hansche: Official (ISC)2 Guide to the CISSP Exam

- Muhammad Idham Azhari

Wednesday, February 18, 2015

Tuesday, February 17, 2015

Saturday, February 14, 2015

Friday, February 13, 2015

Logo Design Inspiration - 13 Feb 2015



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 283)

(283) An area of the Telecommunications and Network Security domain that directly affects the Information Systems Security tenet of Availability can be defined as:

A. Netware availability
B. Network availability
C. Network acceptability
D. Network accountability

Correct Answer: B


Explanation/Reference:

- Muhammad Idham Azhari

Thursday, February 12, 2015

Wednesday, February 11, 2015

Tuesday, February 10, 2015

Saturday, February 7, 2015

Friday, February 6, 2015

Logo Design Inspiration - 06 Feb 2015



- Muhammad Idham Azhari

People Are The Heart Of Security



- Muhammad Idham Azhari

CISSP Exam Preparation (Question 282)

(282) Which of the following are objectives of an information systems security program?

A. Threats, vulnerabilities, and risks
B. Security, information value, and threats
C. Integrity, confidentiality, and availability.
D. Authenticity, vulnerabilities, and costs.

Correct Answer: C

Explanation/Reference:

There are several small and large objectives of a security program, but the main three principles in all programs are confidentiality, integrity, and availability. These are referred to as the CIA triad. - Shon Harris All-in-one CISSP Certification Guide pg 62

- Muhammad Idham Azhari

Thursday, February 5, 2015

Wednesday, February 4, 2015