ISC2 Certified Information Systems Security Professional CISSP Exam Questions

Page: 1 / 14
Total 1486 questions
Question 1

Of the following, which BEST provides non- repudiation with regards to access to a server room?



Answer : C

Biometric readers are the best option to provide non-repudiation with regards to access to a server room. Non-repudiation is the ability to prove that an action or event occurred and was performed by a specific entity. Biometric readers use physical characteristics such as fingerprints, iris patterns, or facial features to authenticate users, and they are hard to forge or share. Therefore, they can provide strong evidence of who accessed the server room and when. The other options are not as effective in providing non-repudiation, as they can be lost, stolen, copied, or shared by users. Fobs and PINs are examples of something you have and something you know, respectively. Locked and secured cages are physical barriers that can be bypassed by unauthorized persons. Proximity readers are devices that detect the presence of a nearby object, such as a card or a tag, and grant access accordingly.Reference:Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 5: Identity and Access Management, p. 615-616;CISSP All-in-One Exam Guide, Eighth Edition, Chapter 5: Identity and Access Management, p. 321-322.


Question 2

What is the FIRST step in developing a patch management plan?



Answer : C

The first step in developing a patch management plan is to inventory the hardware and software used. Patch management is the process of identifying, acquiring, testing, deploying, and verifying the patches or updates for the hardware and software components of a system. Patches are pieces of code that fix or improve the functionality, performance, or security of the system. Patch management is essential for maintaining the system's availability, reliability, and security, and for preventing or mitigating the vulnerabilities or exploits that could compromise the system. The first step in developing a patch management plan is to inventory the hardware and software used, which means to identify and document all the components of the system, such as the devices, operating systems, applications, or libraries. The inventory should include the following information for each component:

The name, version, and vendor of the component

The location, owner, and function of the component

The dependencies, interactions, and configurations of the component

The criticality, priority, and risk level of the component The inventory of the hardware and software used is the basis for the subsequent steps of the patch management plan, such as subscribing to the patch sources, assessing the patch applicability and urgency, testing the patch compatibility and functionality, deploying the patch to the target components, and verifying the patch effectiveness and status.Reference:CISSP All-in-One Exam Guide, Chapter 7: Security Operations, Section: Patch Management, pp. 855-856.


Question 3

Which of the following mechanisms will BEST prevent a Cross-Site Request Forgery (CSRF) attack?



Answer : C

The best mechanism to prevent a Cross-Site Request Forgery (CSRF) attack is to use synchronized session tokens. A CSRF attack is a type of web application vulnerability that exploits the trust that a site has in a user's browser. A CSRF attack occurs when a malicious site, email, or link tricks a user's browser into sending a forged request to a vulnerable site, where the user is already authenticated. The vulnerable site cannot distinguish between the legitimate and the forged requests, and may perform an unwanted action on behalf of the user, such as changing a password, transferring funds, or deleting data. Synchronized session tokens are a technique to prevent CSRF attacks by adding a random and unique value to each request that is generated by the server and verified by the server before processing the request. The token is usually stored in a hidden form field or a custom HTTP header, and is tied to the user's session. The token ensures that the request originates from the same site that issued it, and not from a malicious site. Synchronized session tokens are also known as CSRF tokens, anti-CSRF tokens, or state tokens. Parameterized database queries, whitelist input values, and use strong ciphers are not mechanisms to prevent CSRF attacks, although they may be useful for other types of web application vulnerabilities. Parameterized database queries are a technique to prevent SQL injection attacks by using placeholders or parameters for user input, instead of concatenating or embedding user input directly into the SQL query. Parameterized database queries ensure that the user input is treated as data and not as part of the SQL command. Whitelist input values are a technique to prevent input validation attacks by allowing only a predefined set of values or characters for user input, instead of rejecting or filtering out unwanted or malicious values or characters. Whitelist input values ensure that the user input conforms to the expected format and type. Use strong ciphers are a technique to prevent encryption attacks by using cryptographic algorithms and keys that are resistant to brute force, cryptanalysis, or other attacks. Use strong ciphers ensure that the encrypted data is confidential, authentic, and integral.


Question 4

Which of the following is an open standard for exchanging authentication and authorization data between parties?



Answer : D

Security Assertion Markup Language (SAML) is an open standard for exchanging authentication and authorization data between parties, such as a service provider and an identity provider. SAML is based on Extensible Markup Language (XML), which is a markup language that defines a set of rules for encoding and structuring data in a human-readable and machine-readable format. SAML enables single sign-on (SSO), which is a system that allows a user to log in and access multiple related servers and applications with a single authentication process. SAML uses assertions, which are statements that contain information about the user, such as their identity, attributes, or privileges, to communicate between the parties. SAML also uses protocols, which are sets of rules and messages that define how the parties request and respond to the assertions, to establish the trust and security of the communication. Wired markup language is not a term used in information security, but it could refer to a markup language that is used for creating web pages or applications that run on a wired network. Hypertext Markup Language (HTML) is a markup language that is used for creating and displaying web pages or applications that run on a web browser. HTML is not an open standard for exchanging authentication and authorization data between parties, but rather a standard for defining the structure and content of web pages or applications.


Question 5

Which of the following is used by the Point-to-Point Protocol (PPP) to determine packet formats?



Answer : B

Link Control Protocol (LCP) is used by the Point-to-Point Protocol (PPP) to determine packet formats. PPP is a data link layer protocol that provides a standard method for transporting network layer packets over point-to-point links, such as serial lines, modems, or dial-up connections. PPP supports various network layer protocols, such as IP, IPX, or AppleTalk, and it can encapsulate them in a common frame format. PPP also provides features such as authentication, compression, error detection, and multilink aggregation. LCP is a subprotocol of PPP that is responsible for establishing, configuring, maintaining, and terminating the point-to-point connection. LCP negotiates and agrees on various options and parameters for the PPP link, such as the maximum transmission unit (MTU), the authentication method, the compression method, the error detection method, and the packet format. LCP uses a series of messages, such as configure-request, configure-ack, configure-nak, configure-reject, terminate-request, terminate-ack, code-reject, protocol-reject, echo-request, echo-reply, and discard-request, to communicate and exchange information between the PPP peers.

The other options are not used by PPP to determine packet formats, but rather for other purposes. Layer 2 Tunneling Protocol (L2TP) is a tunneling protocol that allows the creation of virtual private networks (VPNs) over public networks, such as the Internet. L2TP encapsulates PPP frames in IP datagrams and sends them across the tunnel between two L2TP endpoints. L2TP does not determine the packet format of PPP, but rather uses it as a payload. Challenge Handshake Authentication Protocol (CHAP) is an authentication protocol that is used by PPP to verify the identity of the remote peer before allowing access to the network. CHAP uses a challenge-response mechanism that involves a random number (nonce) and a hash function to prevent replay attacks. CHAP does not determine the packet format of PPP, but rather uses it as a transport. Packet Transfer Protocol (PTP) is not a valid option, as there is no such protocol with this name. There is a Point-to-Point Protocol over Ethernet (PPPoE), which is a protocol that encapsulates PPP frames in Ethernet frames and allows the use of PPP over Ethernet networks. PPPoE does not determine the packet format of PPP, but rather uses it as a payload.


Question 6

What is the FIRST step in reducing the exposure of a network to Internet Control Message Protocol (ICMP) based attacks?



Answer : A

Internet Control Message Protocol (ICMP) is a protocol that is used to send and receive diagnostic and error messages between network devices, such as ping and traceroute. ICMP can also be used to launch various types of attacks, such as denial-of-service, reconnaissance, spoofing, redirection, and amplification. The first step in reducing the exposure of a network to ICMP based attacks is to implement egress filtering at the organization's network boundary, which is the point where the internal network connects to the external network, such as the internet. Egress filtering is the process of inspecting and filtering the outgoing network traffic, based on predefined rules or policies. Egress filtering can prevent or limit the ICMP traffic that originates from the internal network, which can reduce the chances of triggering or participating in ICMP attacks. The other options are not the first step in reducing the exposure of a network to ICMP based attacks, as they do not address the outgoing ICMP traffic from the internal network.Reference:CISSP All-in-One Exam Guide, Eighth Edition, Chapter 5: Communication and Network Security, p. 302;Free daily CISSP practice questions | CISSP, CISM, and CC training by, Question 2


Question 7

Which of the following wraps the decryption key of a full disk encryption implementation and ties the hard disk drive to a particular device?



Answer : A

A Trusted Platform Module (TPM) is a hardware device that wraps the decryption key of a full disk encryption implementation and ties the hard disk drive to a particular device. A TPM is a secure cryptoprocessor that generates, stores, and protects cryptographic keys and other sensitive data. A TPM can be used to implement full disk encryption, which is a technique that encrypts the entire contents of a hard disk drive, making it unreadable without the correct decryption key. A TPM can wrap the decryption key, which means that it encrypts the key with another key that is stored in the TPM and can only be accessed by authorized software. A TPM can also tie the hard disk drive to a particular device, which means that it verifies the identity and integrity of the device before allowing the decryption of the hard disk drive. This prevents unauthorized access to the data even if the hard disk drive is physically removed and attached to another device. A Preboot eXecution Environment (PXE), a Key Distribution Center (KDC), and a Simple Key-Management for Internet Protocol (SKIP) are not devices or techniques that wrap the decryption key of a full disk encryption implementation and tie the hard disk drive to a particular device. A PXE is a protocol that enables a device to boot from a network server without a local operating system or storage device. A KDC is a server that issues and manages cryptographic keys and tickets for authentication and encryption in a Kerberos system. A SKIP is a protocol that provides secure key exchange and authentication for IPsec.


Page:    1 / 14   
Total 1486 questions