CISSP PRACTICE QUESTIONS – 20211213

Effective CISSP Questions

As the system owner, you are categorizing an information system to determine baseline security controls. Which of the following criteria is the best for system categorization? (Wentz QOTD)
A. Resilience of the information system
B. Availability of information and information system
C. The safety and experience of system users
D. Security properties of information types processed by the system

Continue reading

CISSP PRACTICE QUESTIONS – 20211212

Effective CISSP Questions

Your company decides to retreat a branch from a foreign country and sanitize data stored in hard drives so that the media cannot be reused. Which of the following sanitization methods is the most effective? (Wentz QOTD)
A. Single-pass overwrite all sectors on a hard drive
B. Clear the master boot record (MBR) of the hard drive
C. Destroy the key used to encrypt the whole drive
D. Eliminate the remnant magnetic field of the hard drive

Continue reading

CISSP PRACTICE QUESTIONS – 20211209

Effective CISSP Questions

You conducted vulnerability scanning against a website and identified a SQL injection defect. Which of the following actions should you take first? (Wentz QOTD)
A. Validate inputs at both the client and server-side.
B. Use parameterized SQL queries at the server-side
C. Evaluate the risk exposure
D. Submit a change request to fix the defect

Continue reading

CISSP PRACTICE QUESTIONS – 20211208

Effective CISSP Questions

The Bell-LaPadula Model (BLP) model was first proposed and published in 1973, refined in 1974, interpreted in 1976, and retrospected in 2005 by authors David Elliott Bell et al. Which of the following statements about the model is incorrect? (Wentz QOTD)
A. The model considers clearance levels only but not need-to-know.
B. The model introduces five access attributes: read-only, append, execute, read/write, and control access.
C. The model formally defines the access matrix which remembers a list of access attributes associated with a subject-object pairing.
D. The model provides a clear definition of “security” being addressed.

Continue reading

CISSP PRACTICE QUESTIONS – 20211207

Effective CISSP Questions

You are selecting controls based on the NIST Risk Management Framework (RMF). Which of the following situations most likely requires tailoring the selected security control baseline? (Wentz QOTD)
A. Insider threats exist within organizations.
B. Organizational systems are multi-user (either serially or concurrently) in operation.
C. Organizations have the necessary structure, resources, and infrastructure to implement the controls.
D. Some information in organizational systems is not shareable with other users who have authorized access to the same systems.

Continue reading

CISSP PRACTICE QUESTIONS – 20211206

Effective CISSP Questions

Software-defined networking (SDN) attempts to provide more flexibility and easy troubleshooting in networks to cope with business dynamics. Which of the following is correct? (Wentz QOTD)
A. SDN can address both ISO OSI layer two and layer three concerns
B. OpenFlow provides the southbound interface for management commands
C. OpenStack provides the northbound interface for controls over devices
D. SDN turns devices on the data plane into virtualization workloads

Continue reading

CISSP PRACTICE QUESTIONS – 20211205

Effective CISSP Questions

Success is the result of achieving a goal. Performance is a measurable result used to measure the progress to the objective or goal. Which of the following is the first step for goal setting? (Wentz QOTD)
A. Determine key risk indicator
B. Define key goal indicator
C. Select key performance indicator
D. Identify related measures and metrics

Continue reading