
本帖最后由 宅男女神 于 2016-1-24 17:16 编辑 CISSP题库 1453Q) W: \. i% ~& B) S8 e
% I2 }$ Q4 }% Z- R$ K课程介绍、目录及截图:* M6 i; w& K' o1 \& w( Z. t) a3 F
QUESTION 1:1 \( c& \3 M1 y/ l& M; c0 X5 z
All of the following are basic components of a security policy EXCEPT the
; [3 w5 h/ N8 V; b ]A. definition of the issue and statement of relevant terms.7 [6 i* l2 J. p2 b, D8 G0 |1 o
B. statement of roles and responsibilities- t2 s/ a' H: j$ R2 X0 O% x
C. statement of applicability and compliance requirements.; F u) H* `/ h3 [
D. statement of performance of characteristics and requirements.
* X( p7 x: _/ T3 S: e" D8 xAnswer: D
( f, H' X1 V; e0 [ S5 aPolicies are considered the first and highest level of documentation, from which the lower level
& Y4 N* r- v$ P" f9 ]1 Helements of standards, procedures, and guidelines flow. This order, however, does not mean that& H2 l; c- }' e2 ~" U3 S$ x
policies are more important than the lower elements. These higher-level policies, which are the- s/ ?1 Z! ^' K1 ~2 i! _
more general policies and statements, should be created first in the process for strategic reasons,6 I1 t; r# Z! O/ i9 |
and then the more tactical elements can follow. -Ronald Krutz The CISSP PREP Guide (gold
I6 C: ?& \( P- R4 n. R* n4 nedition) pg 13
* H8 r! B- r7 d- ?. z+ b# ]QUESTION 2:
+ z1 l& S$ I- g' U c/ rA security policy would include all of the following EXCEPT
4 Z! G, G2 y# G% E9 r) @. ~A. Background
1 v; c2 C- a, ~ W# B1 I$ a( y% vB. Scope statement i% J9 W; T5 E
C. Audit requirements& J2 j- X2 q9 h D, a6 d5 M
D. Enforcement
% E q+ s: R7 j4 _Answer: B# f. q2 f2 O$ J9 {( V
QUESTION 3:
) A" D9 a _- c! [* SWhich one of the following is an important characteristic of an information security policy?
+ T$ y6 X x# \7 G7 i8 ?) o' U1 _A. Identifies major functional areas of information.' C5 Q. Q1 a, }4 e
B. Quantifies the effect of the loss of the information.
- C1 A ]9 A2 Q7 A/ `6 P1 DC. Requires the identification of information owners.
% E9 E6 j k! d* x; M! mD. Lists applications that support the business function.+ W$ Z* v6 V# {1 F H# g
Answer: A
0 A& |3 ]1 p/ w- e& lInformation security policies area high-level plans that describe the goals of the procedures.) Q- B7 t- f$ O# b5 E
Policies are not guidelines or standards, nor are they procedures or controls. Policies describe
. n' a- j6 [' s6 N- p. Isecurity in general terms, not specifics. They provide the blueprints for an overall security
( g, x9 Z% c0 i- h1 bprogram just as a specification defines your next product - Roberta Bragg CISSP Certification/ X- E9 }5 _7 f) F% O, g
Training Guide (que) pg 206
$ I5 k9 o/ }0 _
6 l( Q+ _% t/ A) X下载链接: 论坛便捷链接: G c% T3 r- Y- i7 \
; U& h+ l' l9 G' _; M1 J. ^- H7 h能帮助您和更多的人找到自己想要的资料并取得更大进步,是我们最大的愿望。 | * i$ P) P5 ~& g
|
|