CISSP PRACTICE QUESTIONS – 20201207

Effective CISSP Questions

Your company develops and sells firewalls. Some models will be sent for evaluation based on the Common Criteria. Which of the following parties should develop the Security Target (ST)?
A. Your company
B. The government
C. The association of firewall vendors
D. The laboratory conducting the evaluation

Continue reading

CISSP PRACTICE QUESTIONS – 20201205

Effective CISSP Questions

After transforming stakeholder requirements into system requirements, you are selecting controls based upon system security requirements and allocating them to the security architecture. As a security architect, which of the following selection criteria is least likely used to select controls?
A. The attack surface
B. The result of risk assessment
C. The impact level of the system
D. The exploitability of vulnerabilities

Continue reading

CISSP PRACTICE QUESTIONS – 20201204

Effective CISSP Questions

A switching hub in production is receiving a huge amount of traffic that leads to the overflow of context-addressable memory (CAM) table. It begins to flood traffic to all ports and becomes vulnerable to sniffing attacks. Which of the following security principles should have been first implemented to prevent the sniffing attacks?
A. Trusted recovery
B. Secure failure
C. Secure defaults
D. Least privilege

Continue reading

CISSP PRACTICE QUESTIONS – 20201203

Effective CISSP Questions

Your company develops and sells firewalls. Some of the firewalls are sent for independent evaluation against the Common Criteria. Which of the following affects the level of evaluation assurance least significantly?
A. The evaluation methods, processes, and tools employed
B. The percentage of the system is considered in the evaluation
C. The evaluation granularity of the design, implementation, and processes of the system
D. The ability of the system to reestablish a secure state and to do so in a secure manner

Continue reading

CISSP PRACTICE QUESTIONS – 20201202

Effective CISSP Questions

Your company is developing an E-Commerce system, which is a system of systems. It accepts orders on web servers, processes them on application servers, stores them on database servers, and sends short messages of transaction success to customers through external notification services. Internal DNS servers are deployed for domain name resolution, while external DNS servers are employed for failover. Which of the following is the best composition theory describing the DNS operations?
A. Cascading
B. Feedback
C. Hookup
D. Delegate

Continue reading