CISSP PRACTICE QUESTIONS – 20210616

Effective CISSP Questions

You are evaluating cloud service providers to migrate the on-premises ERP system to the cloud and considering shared responsibility between various service models. Which of the following best describes the principle you are exercising in the evaluation process? (Wentz QOTD)
A. Due diligence
B. Trust but verify
C. Defense in depth
D. Acceptable use policy

Continue reading

CISSP PRACTICE QUESTIONS – 20210615

Effective CISSP Questions

An IP packet can be divided into two parts: the header and the payload. IPsec encapsulates IP packets in transport mode and tunnel mode and protects them through AH and ESP. AH supports authenticity only, while ESP, a mandatory requirement in IPsec implementation, supports confidentiality and authenticity. Which of the following is incorrect? (Wentz QOTD)
A. AH in the transport mode authenticates the IP packet
B. AH in the tunnel mode authenticates the new IP packet
C. ESP in the transport mode encrypts and authenticates the IP payload
D. ESP in the tunnel mode encrypts and authenticates the new IP packet

Continue reading

CISSP PRACTICE QUESTIONS – 20210614

Effective CISSP Questions

You are conducting penetration testing for a customer with a tight schedule. You are now trying to gain control over a server in the DMZ. Which of the following is least likely to happen? (Wentz QOTD)
A. Scan ports using nmap
B. Gather host information using nslookup
C. Send ICMP messages with routes using ping
D. Install the weapon payload and reboot to take effect

Continue reading

CISSP PRACTICE QUESTIONS – 20210613

Effective CISSP Questions

Your company has implemented an on-premises master DNS server in the DMZ protected by a firewall. You are deploying a slave DNS to the cloud for availability concerns. Which of the following is the most feasible firewall policy to allow zone transfer? (Wentz QOTD)
A. Allow UCP port = 53 and RR = AXFR
B. Allow TCP port = 53 and RR = AXFR
C. Allow UDP port = 53 and Source IP = the slave DNS
D. Allow TCP port = 53 and Source IP = the slave DNS

Continue reading

CISSP PRACTICE QUESTIONS – 20210612

Effective CISSP Questions

A firewall with an external interface configured as 10.10.10.10/24 and a sole internal interface, 192.168.0.254/25, receives egress traffic having a source address 192.168.0.7. Which one of the following actions will the firewall most likely take? (Wentz QOTD)
A. Drop the traffic
B. Forward the traffic as is
C. Forward the traffic after replacing 192.168.0.7 with 10.10.10.10
D. Send an ICMP echo request to 192.168.0.7 to validate the traffic

Continue reading