
Monthly Archives: December 2020
CISSP PRACTICE QUESTIONS – 20201207

Your company develops and sells firewalls. Some models will be sent for evaluation based on the Common Criteria. Which of the following parties should develop the Security Target (ST)?
A. Your company
B. The government
C. The association of firewall vendors
D. The laboratory conducting the evaluation
CISSP PRACTICE QUESTIONS – 20201206

Your company is developing an E-Commerce system. As a tester, you shall evaluate if the system meets system security requirements. Which of the following should you do in terms of ISO 15288?
A. Certification
B. Accreditation
C. Verification
D. Validation
CISSP PRACTICE QUESTIONS – 20201205

After transforming stakeholder requirements into system requirements, you are selecting controls based upon system security requirements and allocating them to the security architecture. As a security architect, which of the following selection criteria is least likely used to select controls?
A. The attack surface
B. The result of risk assessment
C. The impact level of the system
D. The exploitability of vulnerabilities
CISSP PRACTICE QUESTIONS – 20201204

A switching hub in production is receiving a huge amount of traffic that leads to the overflow of context-addressable memory (CAM) table. It begins to flood traffic to all ports and becomes vulnerable to sniffing attacks. Which of the following security principles should have been first implemented to prevent the sniffing attacks?
A. Trusted recovery
B. Secure failure
C. Secure defaults
D. Least privilege
CISSP PRACTICE QUESTIONS – 20201203

Your company develops and sells firewalls. Some of the firewalls are sent for independent evaluation against the Common Criteria. Which of the following affects the level of evaluation assurance least significantly?
A. The evaluation methods, processes, and tools employed
B. The percentage of the system is considered in the evaluation
C. The evaluation granularity of the design, implementation, and processes of the system
D. The ability of the system to reestablish a secure state and to do so in a secure manner
SOC 1, 2, and 3 Reports Overview

CISSP PRACTICE QUESTIONS – 20201202

Your company is developing an E-Commerce system, which is a system of systems. It accepts orders on web servers, processes them on application servers, stores them on database servers, and sends short messages of transaction success to customers through external notification services. Internal DNS servers are deployed for domain name resolution, while external DNS servers are employed for failover. Which of the following is the best composition theory describing the DNS operations?
A. Cascading
B. Feedback
C. Hookup
D. Delegate