Friday, July 31, 2015
CISSP Exam Preparation (Question 306)
(306) The absence or weakness in a system that may possibly be exploited
is called a(n)?
A. Threat
B. Exposure
C. Vulnerability
D. Risk
Correct Answer: C
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 24, 2015
CISSP Exam Preparation (Question 305)
(305) Which of the following is an advantage of a qualitative over
quantitative risk analysis?
A. It prioritizes the risks and
identifies areas for immediate improvement in addressing the vulnerabilities.
B. It provides specific
quantifiable measurements of the magnitude of the impacts
C. It makes cost-benefit analysis
of recommended controls easier
Correct Answer: A
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 10, 2015
CISSP Exam Preparation (Question 304)
(304) How should a risk be handled when the cost of the countermeasures
outweighs the cost of the risk?
A. Reject the risk
B. Perform another risk analysis
C. Accept the risk
D. Reduce the risk
Correct Answer: C
Explanation
Explanation/Reference:
- Muhammad Idham Azhari
Friday, July 3, 2015
CISSP Exam Preparation (Question 303)
(303) Risk is commonly expressed as a function of the
A. Systems vulnerabilities and
the cost to mitigate.
B. Types of countermeasures
needed and the system's vulnerabilities.
C. Likelihood that the harm will
occur and its potential impact.
D. Computer system-related assets
and their costs.
Correct Answer: C
Explanation
Explanation/Reference:
The likelihood of a threat agent taking advantage of
a vulnerability. A risk is the loss potential, or probability, that a threat
will exploit a vulnerability. - Shon Harris All-in-one CISSP Certification
Guide pg 937
- Muhammad Idham Azhari
Friday, June 26, 2015
CISSP Exam Preparation (Question 302)
(302) Which one of the following risk analysis terms characterizes the
absence or weakness of a risk-reducing safegaurd?
A. Threat
B. Probability
C. Vulnerability
D. Loss expectancy
Correct Answer: C
Explanation
Explanation/Reference:
A weakness in system security procedures, system
design, implementation, internal controls, and so on that could be exploited to
violate system security policy. -Ronald Krutz The CISSP PREP Guide (gold edition)
pg 927
- Muhammad Idham Azhari
Friday, June 19, 2015
CISSP Exam Preparation (Question 301)
(301) When conducting a risk assessment, which one of the following is
NOT an acceptable social engineering practice?
A. Shoulder surfing
B. Misrepresentation
C. Subversion
D. Dumpster diving
Correct Answer: A
Explanation/Reference:
Explanation:
Shoulder Surfing: Attackers can thwart
confidentiality mechanisms by network monitoring, shoulder surfing, stealing
password files, and social engineering. These topics will be address more
in-depth in later chapters, but shoulder surfing is when a person looks over
another person's shoulder and watches keystrokes or data as it appears on the
screen. Social engineering is tricking another person into sharing confidential
information by posing as an authorized individual to that information. Shon
Harris: CISSP Certification pg. 63. Shoulder surfing is not social engineering.
- Muhammad Idham Azhari
Friday, June 12, 2015
CISSP Exam Preparation (Question 300)
(300) A new worm has been released on the Internet. After investigation,
you have not been able to determine if you are at risk of exposure. Management
is concerned as they have heard that a number of their counterparts are being
affected by the worm. How could you determine if you are at risk?
A. Evaluate evolving environment.
B. Contact your anti-virus
vendor.
C. Discuss threat with a peer in
another organization.
D. Wait for notification from an
anti-virus vendor.
Correct Answer: B
Explanation/Reference:
- Muhammad Idham Azhari
Friday, June 5, 2015
CISSP Exam Preparation (Question 299)
(299) Which of the following is not a part of risk analysis?
A. Identify risks
B. Quantify the impact of
potential threats
C. Provide an economic balance
between the impact of the risk and the cost of the associated
countermeasures
D. Choose the best countermeasure
Correct Answer: D
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 29, 2015
CISSP Exam Preparation (Question 298)
(298) Which one of the following is not one of the outcomes of a
vulnerability analysis?
A. Quantative loss assessment
B. Qualitative loss assessment
C. Formal approval of BCP scope
and initiation document
D. Defining critical support
areas
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 22, 2015
CISSP Exam Preparation (Question 297)
(297) Risk analysis is MOST useful when applied during which phase of
the system development process?
A. Project identification
B. Requirements definition
C. System construction
D. Implementation planning
Correct Answer: A
Explanation/Reference:
Reference: pg 684 Shon Harris: All-in-One CISSP
Certification
- Muhammad Idham Azhari
Friday, May 15, 2015
CISSP Exam Preparation (Question 296)
(296) Which of the following is not a compensating measure for access violations?
A. Backups
B. Business continuity planning
C. Insurance
D. Security awareness
Correct Answer: D
Explanation/Reference:
- Muhammad Idham Azhari
Friday, May 8, 2015
CISSP Exam Preparation (Question 295)
(295) Which of the following best explains why computerized information
systems frequently fail to meet the needs of users?
A. Inadequate quality assurance
(QA) tools
B. Constantly changing user needs
C. Inadequate user participation
in defining the system's requirements
D. Inadequate project management.
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Thursday, April 30, 2015
CISSP Exam Preparation (Question 294)
(294) Which of the following would be best suited to provide information
during a review of the controls over the process of defining IT service levels?
A. Systems programmer
B. Legal stuff
C. Business unit manager
D. Programmer
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Friday, April 24, 2015
CISSP Exam Preparation (Question 293)
(293) In developing a security awareness program, it is MOST important
to
A. Understand the corporate
culture and how it will affect security.
B. Understand employees
preferences for information security.
C. Know what security awareness
products are available.
D. Identify weakness in line
management support.
Correct Answer: A
Explanation/Reference:
The controls and procedures of a security program
should reflect the nature of the data being
processed...These different types of companies would
also have very different cultures. For a security awareness program to be
effective, these considerations must be understood and the program should be developed
in a fashion that makes sense per environment - Shon Harris All-in-one CISSP Certification
Guide pg 109
- Muhammad Idham Azhari
Friday, April 17, 2015
CISSP Exam Preparation (Question 292)
(292) Which one of the following is the MAIN goal of a security
awareness program when addressing senior management?
A. Provide a vehicle for
communicating security procedures.
B. Provide a clear understanding
of potential risk and exposure.
C. Provide a forum for disclosing
exposure and risk analysis.
D. Provide a forum to communicate
user responsibilities.
Correct Answer: B
Explanation/Reference:
Explanation:
When the Security Officer is addressing Senior
Management, the focus would not be on user
responsibilities, it would be on making sure the
Senior Management have a clear understanding of the risk and
potential liability is Not D: Item D would be correct in a situation where
Senior Management is addressing organizational staff.
- Muhammad Idham Azhari
Friday, April 10, 2015
CISSP Exam Preparation (Question 291)
(291) Which of the following is most relevant to determining the maximum
effective cost of access control?
A. the value of information that
is protected
B. management's perceptions
regarding data importance
C. budget planning related to
base versus incremental spending.
D. the cost to replace lost data
Correct Answer: A
Explanation/Reference:
- Muhammad Idham Azhari
Friday, April 3, 2015
CISSP Exam Preparation (Question 290)
(290) What is the MAIN purpose of a change control/management system?
A. Notify all interested parties
of the completion of the change.
B. Ensure that the change meets
user specifications.
C. Document the change for audit
and management review.
D. Ensure the orderly processing
of a change request.
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Friday, March 27, 2015
CISSP Exam Preparation (Question 289)
(289) Within the organizational environment, the security
function should report to an organizational level that
A. Has information technology
oversight.
B. Has autonomy from other
levels.
C. Is an external operation.
D. Provides the internal audit
function.
Correct Answer: B
Explanation/Reference:
- Muhammad Idham Azhari
Friday, March 20, 2015
CISSP Exam Preparation (Question 288)
(288) Organizations develop change control procedures to
ensure that
A. All changes are authorized,
tested, and recorded.
B. Changes are controlled by the
Policy Control Board (PCB).
C. All changes are requested,
scheduled, and completed on time.
D. Management is advised of
changes made to systems.
Correct Answer: A
Explanation/Reference:
"Change Control: Changes must be authorized,
tested, and recorded. Changed systems may require recertificationvand
re-accreditation." Pg 699 Shon Harris: All-in-One CISSP Certification
- Muhammad Idham Azhari
Friday, March 13, 2015
CISSP Exam Preparation (Question 287)
(287) Information security is the protection of data. Information
will be protected mainly based on:
A. Its sensitivity to the
company.
B. Its confidentiality.
C. Its value.
D. All of the choices.
Correct Answer: D
Explanation/Reference:
Information security is the protection of data
against accidental or malicious disclosure, modification, or destruction.
Information will be protected based on its value, confidentiality, and/or
sensitivity to the company, and the risk of loss or compromise. At a
minimum, information will be update-protected so that only authorized
individuals can modify or erase the information.
- Muhammad Idham Azhari
Friday, March 6, 2015
CISSP Exam Preparation (Question 286)
(286) The security planning process must define how security will be
managed, who will be responsible, and
A. Who practices are reasonable
and prudent for the enterprise.
B. Who will work in the security
department.
C. What impact security will have
on the intrinsic value of data.
D. How security measures will be
tested for effectiveness.
Correct Answer: D
Explanation/Reference:
- Muhammad Idham Azhari
Saturday, February 28, 2015
Friday, February 27, 2015
CISSP Exam Preparation (Question 285)
(285) Which one of the following is the MOST crucial link in the
computer security chain?
A. Access controls
B. People
C. Management
D. Awareness programs
Correct Answer: C
Explanation/Reference:
- Muhammad Idham Azhari
Thursday, February 26, 2015
Wednesday, February 25, 2015
Tuesday, February 24, 2015
Monday, February 23, 2015
Sunday, February 22, 2015
Saturday, February 21, 2015
Friday, February 20, 2015
CISSP Exam Preparation (Question 284)
(284) The Structures, transmission methods, transport formats, and
security measures that are used to provide integrity, availability, and
authentication, and confidentiality for transmissions over private and public communications
networks and media includes:
A. The Telecommunications and
Network Security domain
B. The Telecommunications and
Netware Security domain
C. The Technical communications
and Network Security domain
D. The Telnet and Security domain
Correct Answer: A
Explanation/Reference:
The Telecommunications, Network, and Internet
Security Domain encompasses the structures, transmission methods,
transport formats, and security measures used to provide integrity,
availability, authentication, and confidentiality for
transmissions over private and public communications networks and media." Pg 515
Hansche: Official (ISC)2 Guide to the CISSP Exam
- Muhammad Idham Azhari
Thursday, February 19, 2015
Wednesday, February 18, 2015
Tuesday, February 17, 2015
Monday, February 16, 2015
Sunday, February 15, 2015
Saturday, February 14, 2015
Subscribe to:
Posts (Atom)



































