최신ISC Certified Information Systems Security Professional (CISSP) - CISSP무료샘플문제
문제1
Which of the following roles has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization?
Which of the following roles has the obligation to ensure that a third party provider is capable of processing and handling data in a secure manner and meeting the standards set by the organization?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제2
Which of the following is the PRIMARY purpose of due diligence when an organization embarks on a merger or acquisition?
Which of the following is the PRIMARY purpose of due diligence when an organization embarks on a merger or acquisition?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제3
Refer to the information below to answer the question.
A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes.
What MUST the access control logs contain in addition to the identifier?
Refer to the information below to answer the question.
A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes.
What MUST the access control logs contain in addition to the identifier?
정답: A
설명: (ExamPassdump 회원만 볼 수 있음)
문제4
When dealing with compliance with the Payment Card Industry-Data Security Standard (PCI- DSS), an organization that shares card holder information with a service provider MUST do which of the following?
When dealing with compliance with the Payment Card Industry-Data Security Standard (PCI- DSS), an organization that shares card holder information with a service provider MUST do which of the following?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제5
A software developer installs a game on their organization-provided smartphone. Upon installing the game, the software developer is prompted to allow the game access to call logs, Short Message Service (SMS) messaging, and Global Positioning System (GPS) location data. What has the game MOST likely introduced to the smartphone?
A software developer installs a game on their organization-provided smartphone. Upon installing the game, the software developer is prompted to allow the game access to call logs, Short Message Service (SMS) messaging, and Global Positioning System (GPS) location data. What has the game MOST likely introduced to the smartphone?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제6
Which of the following is an essential element of a privileged identity lifecycle management?
Which of the following is an essential element of a privileged identity lifecycle management?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제7
"Stateful" differs from "Static" packet filtering firewalls by being aware of which of the following?
"Stateful" differs from "Static" packet filtering firewalls by being aware of which of the following?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제8
Which of the following attacks, if successful, could give an intruder complete control of a software-defined networking (SDN) architecture?
Which of the following attacks, if successful, could give an intruder complete control of a software-defined networking (SDN) architecture?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제9
Which of the following BEST describes the purpose of "code signing"?
Which of the following BEST describes the purpose of "code signing"?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제10
When constructing an Information Protection Policy (IPP), it is important that the stated rules are necessary, adequate, and
When constructing an Information Protection Policy (IPP), it is important that the stated rules are necessary, adequate, and
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제11
Which of the following mechanisms will BEST prevent a Cross-Site Request Forgery (CSRF) attack?
Which of the following mechanisms will BEST prevent a Cross-Site Request Forgery (CSRF) attack?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제12
Physical Access Control Systems (PACS) allow authorized security personnel to manage and monitor access control for subjects through which function?
Physical Access Control Systems (PACS) allow authorized security personnel to manage and monitor access control for subjects through which function?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)