It is impossible to pass ISC2 CISSP-ISSEP exam without any help in the short term. Come to Actualtests soon and find the most advanced, correct and guaranteed ISC2 CISSP-ISSEP practice questions. You will get a surprising result by our Improve Information Systems Security Engineering Professional practice guides.
NEW QUESTION 1
Which of the CNSS policies describes the national policy on certification and accreditation of national security telecommunications and information systems
- A. NSTISSP N
- B. 7
- C. NSTISSP N
- D. 11
- E. NSTISSP N
- F. 6
- G. NSTISSP N
- H. 101
Answer: C
NEW QUESTION 2
Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the international information security standards Each correct answer represents a complete solution. Choose all that apply.
- A. Organization of information security
- B. Human resources security
- C. Risk assessment and treatment
- D. AU audit and accountability
Answer: ABC
NEW QUESTION 3
Certification and Accreditation (C&A or CnA) is a process for implementing information
security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation Each correct answer represents a complete solution. Choose two.
- A. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- B. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
- C. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- D. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
Answer: BC
NEW QUESTION 4
Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States
- A. Lanham Act
- B. FISMA
- C. Computer Fraud and Abuse Act
- D. Computer Misuse Act
Answer: B
NEW QUESTION 5
You work as a systems engineer for BlueWell Inc. You are working on translating system requirements into detailed function criteria. Which of the following diagrams will help you to show all of the function requirements and their groupings in one diagram
- A. Activity diagram
- B. Functional flow block diagram (FFBD)
- C. Functional hierarchy diagram
- D. Timeline analysis diagram
Answer: C
NEW QUESTION 6
Which of the following is a temporary approval to operate based on an assessment of the implementation status of the assigned IA Controls
- A. IATO
- B. DATO
- C. ATO
- D. IATT
Answer: A
NEW QUESTION 7
Which of the following agencies is responsible for funding the development of many technologies such as computer networking, as well as NLS
- A. DARPA
- B. DTIC
- C. DISA
- D. DIAP
Answer: A
NEW QUESTION 8
Which of the following is the application of statistical methods to the monitoring and control of a process to ensure that it operates at its full potential to produce conforming product
- A. Information Assurance (IA)
- B. Statistical process control (SPC)
- C. Information Protection Policy (IPP)
- D. Information management model (IMM)
Answer: B
NEW QUESTION 9
You work as a systems engineer for BlueWell Inc. You want to protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. Which of the following processes will you use to accomplish the task
- A. Information Assurance (IA)
- B. Risk Management
- C. Risk Analysis
- D. Information Systems Security Engineering (ISSE)
Answer: A
NEW QUESTION 10
Which of the following organizations incorporates building secure audio and video communications equipment, making tamper protection products, and providing trusted microelectronics solutions
- A. DTIC
- B. NSA IAD
- C. DIAP
- D. DARPA
Answer: B
NEW QUESTION 11
Which of the following types of CNSS issuances describes how to implement the policy or prescribes the manner of a policy
- A. Advisory memoranda
- B. Instructions
- C. Policies
- D. Directives
Answer: B
NEW QUESTION 12
Which of the following laws is the first to implement penalties for the creator of viruses, worms, and other types of malicious code that causes harm to the computer systems
- A. Computer Fraud and Abuse Act
- B. Computer Security Act
- C. Gramm-Leach-Bliley Act
- D. Digital Millennium Copyright Act
Answer: A
NEW QUESTION 13
The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer Each correct answer represents a complete solution. Choose all that apply.
- A. Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
- B. Preserving high-level communications and working group relationships in an organization
- C. Establishing effective continuous monitoring program for the organization
- D. Facilitating the sharing of security risk-related information among authorizing officials
Answer: ABC
NEW QUESTION 14
Which of the following NIST documents describes that minimizing negative impact on an organization and a need for sound basis in decision making are the fundamental reasons organizations implement a risk management process for their IT systems
- A. NIST SP 800-37
- B. NIST SP 800-30
- C. NIST SP 800-53
- D. NIST SP 800-60
Answer: B
NEW QUESTION 15
Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system
- A. SSAA
- B. TCSEC
- C. FIPS
- D. FITSAF
Answer: B
NEW QUESTION 16
Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment
- A. Phase 4
- B. Phase 2
- C. Phase 1
- D. Phase 3
Answer: D
NEW QUESTION 17
Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy
- A. Networks and Infrastructures
- B. Supporting Infrastructures
- C. Enclave Boundaries
- D. Local Computing Environments
Answer: C
NEW QUESTION 18
FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets, or individuals
- A. Moderate
- B. Medium
- C. High
- D. Low
Answer: D
NEW QUESTION 19
The DoD 8500 policy series represents the Department's information assurance strategy. Which of the following objectives are defined by the DoD 8500 series Each correct answer represents a complete solution. Choose all that apply.
- A. Providing IA Certification and Accreditation
- B. Providing command and control and situational awareness
- C. Defending systems
- D. Protecting information
Answer: BCD
NEW QUESTION 20
Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment
- A. Definition, Validation, Verification, and Post Accreditation
- B. Verification, Definition, Validation, and Post Accreditation
- C. Verification, Validation, Definition, and Post Accreditation
- D. Definition, Verification, Validation, and Post Accreditation
Answer: D
NEW QUESTION 21
Which of the following phases of the ISSE model is used to determine why the system needs to be built and what information needs to be protected
- A. Develop detailed security design
- B. Define system security requirements
- C. Discover information protection needs
- D. Define system security architecture
Answer: C
NEW QUESTION 22
You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems
- A. NIST Special Publication 800-59
- B. NIST Special Publication 800-37
- C. NIST Special Publication 800-60
- D. NIST Special Publication 800-53
Answer: B
NEW QUESTION 23
Which of the following memorandums reminds the Federal agencies that it is required by law and policy to establish clear privacy policies for Web activities and to comply with those policies
- A. OMB M-01-08
- B. OMB M-03-19
- C. OMB M-00-07
- D. OMB M-00-13
Answer: D
NEW QUESTION 24
Which of the following certification levels requires the completion of the minimum security checklist and more in-depth, independent analysis
- A. CL 3
- B. CL 4
- C. CL 2
- D. CL 1
Answer: A
NEW QUESTION 25
Stella works as a system engineer for BlueWell Inc. She wants to identify the performance thresholds of each build. Which of the following tests will help Stella to achieve her task
- A. Regression test
- B. Reliability test
- C. Functional test
- D. Performance test
Answer: D
NEW QUESTION 26
......
P.S. Simply pass now are offering 100% pass ensure CISSP-ISSEP dumps! All CISSP-ISSEP exam questions have been updated with correct answers: https://www.simply-pass.com/ISC2-exam/CISSP-ISSEP-dumps.html (213 New Questions)
