CISSP PRACTICE QUESTIONS – 20211203

Effective CISSP Questions

In a Zero Trust environment, subjects receive no implicit or inherent privileges based solely on the network location or asset ownership. Which of the following is the best design to avoid reconnaissance attacks and connect to transportation services? (Wentz QOTD)
A. 802.1X (EAP over LAN)
B. OpenID Connect (OIDC)
C. Single Packet Authorization (SPA)
D. eXtensible Access Control Markup Language (XACML)

Continue reading

CISSP PRACTICE QUESTIONS – 20211202

Effective CISSP Questions

Which of the following best describes configuration baselines, procedures, vulnerabilities, and related security contents to streamline patch management processes? (Wentz QOTD)
A. Security Content Automation Protocol (SCAP)
B. Common Vulnerabilities and Exposures (CVE)
C. Open Vulnerability and Assessment Language (OVAL)
D. eXtensible Configuration Checklist Description Format (XCCDF)

Continue reading

CISSP PRACTICE QUESTIONS – 20211201

Effective CISSP Questions

An online book retailer accepts orders from their website that turn into SQL statements like INSERT Orders(BookTitle, Price, CustomerId) VALUES (‘Effective CISSP Study Guide’, 59.99, 1001). To enforce security, which of the following controls is impractical and least likely to be implemented? (Wentz QOTD)
A. Acceptable use policy
B. Transaction control
C. Polyinstantiation
D. Address space layout randomization (ASLR)

Continue reading

CISSP PRACTICE QUESTIONS – 20211127

Effective CISSP Questions

You are developing a software solution with a service-oriented architecture. Which of the following is the most critical factor to enforce availability? (Wentz QOTD)
A. Discover and subscribe services from a well-known service registry using UDDI
B. Maintain and completely mediate sessions
C. Invoke services based on standard HTTP verbs
D. Invoke stateless services that follow the single-responsibility principle

Continue reading

CISSP PRACTICE QUESTIONS – 20211125

Effective CISSP Questions

You are developing an anomaly-based IDS that employs artificial intelligence to categorize intrusion examples into various groups. Which of the following is the most intelligent approach to train the model? (Wentz QOTD)
A. Comprehensive knowledge base
B. Pre-selected features by subject matter experts
C. Ubiquitous deployment of sensors and agents
D. Layers of processing for feature transformation and extraction

Continue reading