ISC2 CISSP-ISSAP Guidance 2021

High value of CISSP-ISSAP test preparation materials and item pool for ISC2 certification for client, Real Success Guaranteed with Updated CISSP-ISSAP pdf dumps vce Materials. 100% PASS Information Systems Security Architecture Professional exam Today!

NEW QUESTION 1
Your customer is concerned about security. He wants to make certain no one in the outside world can see the IP addresses inside his network. What feature of a router would accomplish this?

  • A. Port forwarding
  • B. NAT
  • C. MAC filtering
  • D. Firewall

Answer: B

NEW QUESTION 2
Which of the following can be configured so that when an alarm is activated, all doors lock and the suspect or intruder is caught between the doors in the dead-space?

  • A. Man trap
  • B. Biometric device
  • C. Host Intrusion Detection System (HIDS)
  • D. Network Intrusion Detection System (NIDS)

Answer: A

NEW QUESTION 3
Which of the following backup types backs up files that have been added and all data that have been modified since the most recent backup was performed?

  • A. Differential backup
  • B. Incremental backup
  • C. Daily backup
  • D. Full backup

Answer: B

NEW QUESTION 4
Which of the following security devices is presented to indicate some feat of service, a special accomplishment, a symbol of authority granted by taking an oath, a sign of legitimate employment or student status, or as a simple means of identification?

  • A. Sensor
  • B. Alarm
  • C. Motion detector
  • D. Badge

Answer: D

NEW QUESTION 5
Which of the following plans is designed to protect critical business processes from natural or man-made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes?

  • A. Disaster recovery plan
  • B. Contingency plan
  • C. Business continuity plan
  • D. Crisis communication plan

Answer: C

NEW QUESTION 6
Kerberos is a computer network authentication protocol that allows individuals communicating over a non-secure network to prove their identity to one another in a secure manner. Which of the following statements are true about the Kerberos authentication scheme? Each correct answer represents a complete solution. Choose all that apply.

  • A. Kerberos requires continuous availability of a central serve
  • B. Dictionary and brute force attacks on the initial TGS response to a client may reveal the subject's password
  • C. Kerberos builds on Asymmetric key cryptography and requires a trusted third part
  • D. Kerberos requires the clocks of the involved hosts to be synchronize

Answer: ABD

NEW QUESTION 7
CORRECT TEXT
In which of the following alternative processing sites is the backup facility maintained in a constant order, with a full complement of servers, workstations, and communication links ready to assume the primary operations responsibility?

  • A. Hot Site
  • B. Mobile Site
  • C. Warm Site
  • D. Cold Site

Answer: A

NEW QUESTION 8
Which of the following methods offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling?

  • A. Service-oriented modeling framework (SOMF)
  • B. Service-oriented modeling and architecture (SOMA)
  • C. Sherwood Applied Business Security Architecture (SABSA)
  • D. Service-oriented architecture (SOA)

Answer: A

NEW QUESTION 9
Which of the following types of ciphers are included in the historical ciphers? Each correct answer represents a complete solution. Choose two.

  • A. Block ciphers
  • B. Transposition ciphers
  • C. Stream ciphers
  • D. Substitution ciphers

Answer: BD

NEW QUESTION 10
Perfect World Inc., provides its sales managers access to the company's network from remote locations. The sales managers use laptops to connect to the network. For security purposes, the company's management wants the sales managers to log on to the network using smart cards over a remote connection. Which of the following authentication protocols should be used to accomplish this?

  • A. Challenge Handshake Authentication Protocol (CHAP)
  • B. Microsoft Challenge Handshake Authentication Protocol (MS-CHAP)
  • C. Open Shortest Path First (OSPF)
  • D. Extensible Authentication Protocol (EAP)

Answer: D

NEW QUESTION 11
Which of the following keys are included in a certificate revocation list (CRL) of a public key infrastructure (PKI)? Each correct answer represents a complete solution. Choose two.

  • A. A foreign key
  • B. A private key
  • C. A public key
  • D. A primary key

Answer: BC

NEW QUESTION 12
You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics of the detected virus. Which of the following phases in the Incident handling process will utilize the signature to resolve this incident?

  • A. Eradication
  • B. Identification
  • C. Recovery
  • D. Containment

Answer: A

NEW QUESTION 13
Which of the following heights of fence deters only casual trespassers?

  • A. 8 feet
  • B. 3 to 4 feet
  • C. 2 to 2.5 feet
  • D. 6 to 7 feet

Answer: B

NEW QUESTION 14
Which of the following algorithms is found to be suitable for both digital signature and encryption?

  • A. SHA-1
  • B. MD5
  • C. AES
  • D. RSA

Answer: D

NEW QUESTION 15
Which of the following describes the acceptable amount of data loss measured in time?

  • A. Recovery Consistency Objective (RCO)
  • B. Recovery Time Objective (RTO)
  • C. Recovery Point Objective (RPO)
  • D. Recovery Time Actual (RTA)

Answer: C

NEW QUESTION 16
IPsec VPN provides a high degree of data privacy by establishing trust points between communicating devices and data encryption. Which of the following encryption methods does IPsec VPN use? Each correct answer represents a complete solution. Choose two.

  • A. MD5
  • B. LEAP
  • C. AES
  • D. 3DES

Answer: CD

NEW QUESTION 17
An access control secures the confidentiality, integrity, and availability of the information and data of an organization. In which of the following categories can you deploy the access control? Each correct answer represents a part of the solution. Choose all that apply.

  • A. Detective access control
  • B. Corrective access control
  • C. Administrative access control
  • D. Preventive access control

Answer: ABD

NEW QUESTION 18
In which of the following cryptographic attacking techniques does an attacker obtain encrypted messages that have been encrypted using the same encryption algorithm?

  • A. Chosen plaintext attack
  • B. Ciphertext only attack
  • C. Chosen ciphertext attack
  • D. Known plaintext attack

Answer: B

NEW QUESTION 19
Which of the following encryption modes has the property to allow many error correcting codes to function normally even when applied before encryption?

  • A. OFB mode
  • B. CFB mode
  • C. CBC mode
  • D. PCBC mode

Answer: A

NEW QUESTION 20
Which of the following protocols is an alternative to certificate revocation lists (CRL) and allows the authenticity of a certificate to be immediately verified?

  • A. RSTP
  • B. SKIP
  • C. OCSP
  • D. HTTP

Answer: C

NEW QUESTION 21
Which of the following disaster recovery tests includes the operations that shut down at the primary site, and are shifted to the recovery site according to the disaster recovery plan?

  • A. Structured walk-through test
  • B. Simulation test
  • C. Full-interruption test
  • D. Parallel test

Answer: C

NEW QUESTION 22
You are implementing some security services in an organization, such as smart cards, biometrics, access control lists, firewalls, intrusion detection systems, and clipping levels. Which of the following categories of implementation of the access control includes all these security services?

  • A. Administrative access control
  • B. Logical access control
  • C. Physical access control
  • D. Preventive access control

Answer: B

NEW QUESTION 23
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of the disaster. In which of the following disaster recovery tests can this task be performed?

  • A. Full-interruption test
  • B. Parallel test
  • C. Simulation test
  • D. Structured walk-through test

Answer: C

NEW QUESTION 24
The Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates. Which of the following components does the PKI use to list those certificates that have been revoked or are no longer valid?

  • A. Certification Practice Statement
  • B. Certificate Policy
  • C. Certificate Revocation List
  • D. Certification Authority

Answer: C

NEW QUESTION 25
At which of the following layers of the Open System Interconnection (OSI) model the Internet Control Message Protocol (ICMP) and the Internet Group Management Protocol (IGMP) work?

  • A. The Physical layer
  • B. The Data-Link layer
  • C. The Network layer
  • D. The Presentation layer

Answer: C

NEW QUESTION 26
Which of the following attacks can be overcome by applying cryptography?

  • A. Web ripping
  • B. DoS
  • C. Sniffing
  • D. Buffer overflow

Answer: C

NEW QUESTION 27
You work as a technician for Trade Well Inc. The company is in the business of share trading. To enhance security, the company wants users to provide a third key (apart from ID and password) to access the company's Web site. Which of the following technologies will you implement to accomplish the task?

  • A. Smart cards
  • B. Key fobs
  • C. VPN
  • D. Biometrics

Answer: B

NEW QUESTION 28
In software development, which of the following analysis is used to document the services and functions that have been accidentally left out, deliberately eliminated or still need to be developed?

  • A. Gap analysis
  • B. Requirement analysis
  • C. Cost-benefit analysis
  • D. Vulnerability analysis

Answer: A

NEW QUESTION 29
A digital signature is a type of public key cryptography. Which of the following statements are true about digital signatures? Each correct answer represents a complete solution. Choose all that apply.

  • A. In order to digitally sign an electronic record, a person must use his/her public ke
  • B. In order to verify a digital signature, the signer's private key must be use
  • C. In order to digitally sign an electronic record, a person must use his/her private ke
  • D. In order to verify a digital signature, the signer's public key must be use

Answer: CD

NEW QUESTION 30
Which of the following uses a Key Distribution Center (KDC) to authenticate a principle?

  • A. CHAP
  • B. PAP
  • C. Kerberos
  • D. TACACS

Answer: C

NEW QUESTION 31
......

P.S. prep-labs.com now are offering 100% pass ensure CISSP-ISSAP dumps! All CISSP-ISSAP exam questions have been updated with correct answers: https://www.prep-labs.com/dumps/CISSP-ISSAP/ (237 New Questions)