CISSP PRACTICE QUESTIONS – 20210624

Effective CISSP Questions

Your company implemented a biometric-based system to control access to the computer room. When the threshold (1 to 10) is set to 5, both the False Acceptance Rate (FAR) and False Rejection Rate (FRR) are 5 out of 10. Which of the following is the best configuration to enforce the physical security of the computer room? (Wentz QOTD)
A. Lower the Crossover Error Rate (CER)
B. Raise the Equal Error Rate (EER).
C. Lower the sensitivity
D. Raise the threshold

Continue reading

CISSP PRACTICE QUESTIONS – 20210622

Effective CISSP Questions

OpenID Connect is a simple identity layer on top of the OAuth 2.0 protocol. Which of the following is incorrect? (Wentz QOTD)
A. OpenID 2.0 used XML and a custom message signature scheme, while OIDC employs JSON.
B. The OpenID Provider performs authentication and provides the ID Token as a JSON Web Token.
C. The OAuth 2.0 authorization server authenticates the end-user as a human participant.
D. OAuth 2.0 specifies access tokens to access resources and standard methods to provide identity information.

Continue reading

CISSP PRACTICE QUESTIONS – 20210618

Effective CISSP Questions

PPP connects a client to the network access server (NAS) using dialup POTS, ISDN, ADSL, etc. L2TP extends PPP and connects a client to a remote NAS over the packet switching network. Which of the following is incorrect? (Wentz QOTD)
A. L2TP tunnels PPP frames to the remote network access server.
B. L2TP data messages are retransmitted when packet loss occurs.
C. PPP can optionally authenticate clients to establish the connection.
D. PPP encapsulates multiprotocol packets sent across layer 2 point-to-point links.

Continue reading

CISSP PRACTICE QUESTIONS – 20210617

Effective CISSP Questions

To mitigate the impact of the pandemic of COVID-19, your company decides to have half of the employees work from home (WFH), who have to connect to the VPN server using L2TP/IPsec to access the intranet resources securely. Which of the following is the best configuration required to support the WFH initiative? (Wentz QOTD)
A. AH
B. ESP
C. Tunnel mode
D. Network Address Translation-Traversal (NAT-T)

Continue reading