
本帖最后由 宅男女神 于 2016-1-24 17:14 编辑 CISSP最接近真题的250道模拟Practice Questions
4 l7 |2 T1 t! m4 U9 m9 o7 T4 p" W* G$ ^7 n
课程介绍、目录及截图:
( B4 ~6 Q( g: Y+ V) i9 n' j7 Z/ vPractice Questions4 T% I r \& p! w( m
Chapter 1
$ _# b2 Q$ V9 L4 z9 ?8 s1. What is the correct approach for addressing security and organization
4 s! c6 l* j* k/ Y0 v4 u9 d( s/ Sobjectives?
& o# q: n" Q: `+ ^( e' h/ [6 Ia. Security and organization objectives should be developed separately./ v8 M" i& O1 [3 Q5 Y' `4 e
b. Security should drive organization objectives.
. p, L2 h! c& p% o5 uc. Security should support organization objectives.; Y' W2 Y; g2 W
d. The site security officer should approve or reject organization
. C8 V4 ~+ ?% T% s$ a. `* Qobjectives.! m4 M. q- O. g! B/ W3 {# M h
2. The statement, “Promote professionalism among information system
: ^3 j$ D5 z B+ M: }0 R" g' _security practitioners through the provisioning of professional certification
8 t1 f& D! `2 p- Sand training” is an example of a/an:% H5 p8 @7 i- W' G( I) S" c
a. Mission statement
( a2 p3 v. n4 y, I' ~b. Objective
) j4 [3 q/ z% M' N" |: k) n+ a! ec. Goal
" s ~1 T$ w8 S# vd. Requirement( K1 P9 X, r" e! i0 _
3. The two components of risk management are:
+ m5 ]. Y! D9 Q9 ]/ J# Na. Risk assessment and risk analysis4 A4 S3 B, E* r
b. Vulnerability assessment and risk treatment
1 Y4 W7 ^$ Q* x9 ~8 H% yc. Risk assessment and risk mitigation, b: O- I" @. Z9 H
d. Risk assessment and risk treatment
9 N% ^! n6 q2 m% x; {4 o$ u* H" r4. A security manager needs to perform a risk assessment on a critical
' d/ P% z2 b% Ibusiness application in order to determine what additional controls may be
7 Q5 d1 a9 t6 }8 w" Mneeded to protect the application and its databases. The best approach to
8 I5 c0 g, F" p. F- i; T5 O8 hperforming this risk assessment is:- n6 V& B" I3 z9 T# }
a. Perform a qualitative risk assessment only" U# N2 h% X, I) U
b. Perform a quantitative risk assessment only
8 I" J) \; c- d# n" a版权归原作者所有 本资料只供试读 更多资源请访问 攻城狮论坛 http://bbs.vlan5.com/
( o' s% S3 |: n, U% ~攻城狮论坛(技术+生活)群 2258097 CCNA|CCNP免费答疑题库 284340425
- f5 P5 |& {9 m% I: R! D/ ic. Perform a qualitative risk assessment first, then perform a quantitative6 c% q% j( ]' Q; {7 w6 M
risk assessment) o c. ~ ]" L
d. Perform a quantitative risk assessment, then perform a qualitative risk& J6 j8 D7 t) |# k
assessment4 @2 _" H( d) K. F. @- b
5. A qualitative risk assessment is used to identify:1 A, S/ |: X4 {4 K+ Q9 M* K$ W( A
a. Vulnerabilities, threats, and countermeasures
* `( y1 K) B9 V2 yb. Vulnerabilities, threats, threat probabilities, and countermeasures. ^. g- |0 l0 q" t1 X. d
c. Assets, risks, and mitigation plans
% E% B. D: \' n1 kd. Vulnerabilities and countermeasures
2 p3 z7 n4 f2 L3 x# |6. The impact of a specific threat is defined as:
- x5 v8 F- V4 ?) H; w. h5 Ha. The cost of recovering the asset! T) _, N5 B9 H
b. The cost required to protect the related asset$ j8 B2 w l& |5 }9 w! T& p" X& C% Q
c. The effect of the threat if it is realized# W0 Z- y, K4 i! }& j! H
d. The loss of revenue if it is realized- l7 Z% q# T' e& K z2 J8 H; E
7. Exposure factor is defined as:1 ] T. v& Y6 M9 P/ B0 r
a. The part of an asset's value that is likely to be lost by a particular threat
$ }/ `' j- P; L* cb. The probability that the threat will be realized
1 {# }4 F# W A# l0 T- qc. The probability that a loss will occur in a year’s time( I! U$ c. G4 x/ L1 J' C, Y8 n
d. The cost of a single loss
! p: e! f" j/ p: ~7 {8. A security manager is performing a quantitative risk assessment on a, P0 b$ i1 i6 U( ?
particular asset. The security manager wants to determine the quantitative
8 {7 o" c* s/ l# f1 t/ v% o( Closs for a single loss based on a particular threat. The correct way to9 B ~3 X: R+ ~2 M1 Q# F
calculate this is:$ E1 x Z& s' e# e/ ]
a. Divide the asset’s value by the exposure factor9 U% o" L4 n7 ^) `
b. Multiply the asset’s value times the annualized rate of occurrence# o2 |( n; m/ x/ n3 J" m
c. Multiply the asset’s value times the single loss expectancy1 Q/ E+ ^2 X9 k; ]2 e
d. Multiply the asset’s value times the exposure factor, g% f4 t( G' ^5 Q) J9 Q
9. A security manager is performing a quantitative risk assessment on a+ t- ^0 d) {/ P, ]' K) T7 h
particular asset. The security manager wants to estimate the yearly loss
9 |0 k1 z3 B$ y, \$ h# u. o* g6 @/ ibased on a particular threat. The correct way to calculate this is:
' S5 K- ^' J- k" i v1 {+ p! a
/ `% Y9 y9 D1 @& n下载链接: 论坛便捷链接:1 i: Z9 ^! ~. D' T
7 Y; K7 K. t1 Q& G2 m能帮助您和更多的人找到自己想要的资料并取得更大进步,是我们最大的愿望。 | K# A/ i% M% S3 o. ^" x b! `
|
|