Practice Questions for Cissp Certification

Certified Information Systems Securityimplementation of future updates without incurring
Professionalthe time and expense of recertification.
After you study your text books it is importantD. Large - in order to enable it to protect the
to test your newly acquired knowledge and seepotentially large number of resources in a typical
just how well you have absorbed the material.commercial system environment.
Practice exams...._____________________
* Reinforces what you learnt - fill in the gaps ofQuestion 6# - What is an error called that causes
what you misseda system to be vulnerable because of the
* Gets you used to answering questions to buildenvironment in which it is installed?
confidence and familiarityA.) Configuration error
Here are 10 Multiple choice exams questions forB.) Environmental error
you to practice on:C.) Access validation error
______________________________D.) Exceptional condition handling error
Question 1# - Which element must computer_____________________
evidence have to be admissible in court?Question 7# - Which one of the following
A.) It must be relevantdescribes a reference monitor?
B.) It must be annotatedA. Access control concept that refers to an
C.) It must be printedabstract machine that mediates all accesses to
D.) t must contain source codeobjects by subjects.
_____________________B. Audit concept that refers to monitoring and
Question 2# - What principle requires that a userrecording of all accesses to objects by subjects.
be given no more privilege then necessary toC. Identification concept that refers to the
perform a job?comparison of materialsupplied by a user with its
A. Principle of aggregate privilege.reference profile.
B. Principle of most privilege.D. Network control concept that distributes the
C. Principle of effective privilege.authorization of subject accesses to objects.
D. Principle of least privilege._____________________
_____________________Question 8# - Fault tolerance countermeasures
Question 3# - One method to simplify theare designed to combat threats to
administration of access controls is to groupA.) an uninterruptible power supply
A. Capabilities and privilegesB.) backup and retention capability
B. Objects and subjectsC.) design reliability
C. Programs and transactionsD.) data integrity
D. Administrators and managers_____________________
_____________________Question 9# - The Common Criteria construct
Question 4# - What is the act of willfully changingwhich allows prospective consumers or
data, using fraudulent input or removal of controlsdevelopers to create standardized sets of
called?security requirements to meet there needs is
A. Data diddlingA. a Protection Profile (PP).
B. Data contaminatingB. a Security Target (ST).
C. Data capturingC. an evaluation Assurance Level (EAL).
D. Data trashingD. a Security Functionality Component Catalog
_____________________(SFCC).
Question 5# - What should be the size of a_____________________
Trusted Computer Base?Question 10# - According to Common Criteria,
A. Small - in order to permit it to be implementedwhat can be described as an intermediate
in all critical system components without usingcombination of security requirement components?
excessive resources.A.) Protection profile (PP)
B. Small - in order to facilitate the detailed analysisB.) Security target (ST)
necessary to prove that it meets designC.) Package
requirements.D.
C. Large - in order to accommodate the