
本帖最后由 宅男女神 于 2016-1-24 17:15 编辑 CISSP正版题库TestKing.v10 245Q
: H+ u5 J+ k1 O- \, P) n+ x7 _. S3 U9 y1 }
课程介绍、目录及截图:
$ \0 B2 g- U* ^1 h. g! b1 YExam A& w, H7 T8 O7 |! _
QUESTION 1
9 I8 A- L+ G) H& DAll of the following are basic components of a security policy EXCEPT the
& R! R/ Y2 o9 p9 m9 `A. definition of the issue and statement of relevant terms.- B0 `, M& O9 s4 ^- A
B. statement of roles and responsibilities
/ g6 w/ @- J2 j* G+ L( u6 OC. statement of applicability and compliance requirements.. u& D% k! M5 F% L8 v, R3 L
D. statement of performance of characteristics and requirements.1 `# O; Z9 R J6 T5 B( |: i
Correct Answer: D
2 `. s+ s$ d" M# S' E% g" K# p: X* D. VExplanation
" n( s6 _: [8 [% B% zExplanation/Reference:9 p! e: ~/ P/ ^. j; ~9 ]
Explanation: Policies are considered the first and highest level of documentation, from which the lower level
( d: Y+ k/ ~0 _; G2 s3 oelements of standards, procedures, and guidelines flow. This order, however, does not mean that policies are
; c ~. R% z# |3 {$ j% _7 P# t$ rmore important than the lower elements. These higher-level policies, which are the more general policies and- Z3 j7 a' ] c! S3 t
statements, should be created first in the process for strategic reasons, and then the more tactical elements6 D6 p; z& i0 I4 l) E V. z6 N
can follow. -Ronald Krutz The CISSP PREP Guide (gold edition) pg 13
3 D$ A) m. s% K2 n1 MQUESTION 2
3 N: w3 ~- I% @" ]; Z/ Q3 IA security policy would include all of the following EXCEPT
( O7 i$ y4 g& f- z5 _A. Background
% `9 t1 ], \0 b: @& w T |B. Scope statement6 t5 [/ d9 ^8 o4 _* u! o( i1 R
C. Audit requirements8 x8 z' e1 v: X
D. Enforcement
) ]* o- X' s! [* {. A# nCorrect Answer: B6 R& ~- ^. p/ `1 ?- n k; u1 a
Explanation5 W: \4 }. O/ w- F& _
Explanation/Reference:
& x, h. z' _4 \Explanation:4 U3 `' }- t; a" h
"Pass Any Exam. Any Time." - www.actualtests.com 2; t$ }6 h+ q8 g p1 H- H, B4 f
ISC CISSP Exam; T+ ~* A0 t/ S8 B' E9 l
QUESTION 3
& P! p3 ~# ]4 |/ IWhich one of the following is an important characteristic of an information security policy?
2 X2 g0 J" P1 \) d. J1 }9 x3 G- UA. Identifies major functional areas of information.
2 A" j3 |: I5 R2 z* qB. Quantifies the effect of the loss of the information.
5 l- x, ~1 v [, y% E7 jC. Requires the identification of information owners.
* {4 s8 d' J6 i, l VD. Lists applications that support the business function.3 M. G5 ~3 Q9 I! B
Correct Answer: A b2 n/ X/ h' ?% A% h
Explanation$ }( i+ k# p1 l( t, i
Explanation/Reference:
7 A6 l/ z6 S. VExplanation: Information security policies area high-level plans that describe the goals of the procedures.
% j5 @, U/ d/ g) ] O% TPolicies are not guidelines or standards, nor are they procedures or controls. Policies describe security in
/ \. @$ a3 k) t2 O0 ?7 @8 Wgeneral terms, not specifics. They provide the blueprints for an overall security program just as a specification
) I- Y* t/ q" P- h7 X1 Z( e* }6 Ndefines your next product - Roberta Bragg CISSP Certification Training Guide (que) pg 2066 H/ q+ O+ i' U2 q/ E; @& O
QUESTION 4
1 M! c; y! @: M5 X& B4 ]Ensuring the integrity of business information is the PRIMARY concern of6 L3 k- r: Y1 q) Z
/ f# L1 v# R) q3 C, u" @, u下载链接: 论坛便捷链接:8 ~6 S( m; D7 K5 A- G' ?: B' ]
& a! A* l! b. H) c
能帮助您和更多的人找到自己想要的资料并取得更大进步,是我们最大的愿望。 |
; O( C D" \% y/ U. r, Z9 K$ ` |
|