[Jan 17, 2023] Get to the Top with CISSP Practice Exam Questions [Q173-Q193]

Share

[Jan 17, 2023] Get to the Top with CISSP Practice Exam Questions

Use Real CISSP Dumps Free Sample Questions and Practice Test Engine


Introduction of ISC Certification

The CISSP certification was developed by the International Information Systems Security Certification Consortium (ISC) and is widely considered one of the most difficult certifications to attain. The CISSP exam tests for knowledge of concepts such as network security, software security, cryptography, physical security, and general security principles. Candidates must pass a rigorous 8-hour long exam and demonstrate proficiency in at least 10 out of 12 knowledge areas. Are worried about the study material for the exam? Keep calm, I have the solution. That solution is CISSP Dumps, that will guide and help in study for the CISSP exam.


ISC2 CISSP Exam Syllabus Topics:

TopicDetails

Security and Risk Management - 15%

Understand, adhere to, and promote professional ethics- (ISC)2 Code of Professional Ethics
- Organizational code of ethics
Understand and apply security concepts- Confidentiality, integrity, and availability, authenticity and nonrepudiation
Evaluate and apply security governance principles- Alignment of the security function to business strategy, goals, mission, and objectives
- Organizational processes (e.g., acquisitions, divestitures, governance committees)
- Organizational roles and responsibilities
- Security control frameworks
- Due care/due diligence
Determine compliance and other requirements- Contractual, legal, industry standards, and regulatory requirements
- Privacy requirements
Understand legal and regulatory issues that pertain to information security in a holistic context- Cybercrimes and data breaches
- Licensing and Intellectual Property (IP) requirements
- Import/export controls
- Transborder data flow
- Privacy
Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
Develop, document, and implement security policy, standards, procedures, and guidelines
Identify, analyze, and prioritize Business Continuity (BC) requirements- Business Impact Analysis (BIA)
- Develop and document the scope and the plan
Contribute to and enforce personnel security policies and procedures- Candidate screening and hiring
- Employment agreements and policies
- Onboarding, transfers, and termination processes
- Vendor, consultant, and contractor agreements and controls
- Compliance policy requirements
- Privacy policy requirements
Understand and apply risk management concepts- Identify threats and vulnerabilities
- Risk assessment/analysis
- Risk response
- Countermeasure selection and implementation
- Applicable types of controls (e.g., preventive, detective,
corrective)
- Control assessments (security and privacy)
- Monitoring and measurement
- Reporting
- Continuous improvement (e.g., Risk maturity modeling)
- Risk frameworks
Understand and apply threat modeling concepts and methodologies
Apply Supply Chain Risk Management (SCRM) concepts- Risks associated with hardware, software, and services
- Third-party assessment and monitoring
- Minimum security requirements
- Service level requirements
Establish and maintain a security awareness, education, and training program- Methods and techniques to present awareness and training (e.g., social engineering, phishing, security champions, gamification)
- Periodic content reviews
- Program effectiveness evaluation

Asset Security - 10%

Identify and classify information and assets- Data classification
- Asset Classification
Establish information and asset handling requirements
Provision resources securely- Information and asset ownership
- Asset inventory (e.g., tangible, intangible)
- Asset management
Manage data lifecycle- Data roles (i.e., owners, controllers, custodians, processors, users/subjects)
- Data collection
- Data location
- Data maintenance
- Data retention
- Data remanence
- Data destruction
Ensure appropriate asset retention (e.g., End-of-Life (EOL), End-of-Support (EOS))
Determine data security controls and compliance requirements- Data states (e.g., in use, in transit, at rest)
- Scoping and tailoring
- Standards selection
- Data protection methods (e.g., Digital Rights Management (DRM), Data Loss Prevention (DLP), Cloud Access Security Broker (CASB))

Security Architecture and Engineering - 13%

Research, implement and manage engineering processes using secure design principles- Threat modeling
- Least privilege
- Defense in depth
- Secure defaults
- Fail securely
- Separation of Duties (SoD)
- Keep it simple
- Zero Trust
- Privacy by design
- Trust but verify
- Shared responsibility
Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
Select controls based upon systems security requirements
Understand security capabilities of information systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements- Client-based systems
- Server-based systems
- Database systems
- Cryptographic systems
- Industrial Control Systems (ICS)
- Cloud-based systems (e.g., Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS))
- Distributed systems
- Internet of Things (IoT)
- Microservices
- Containerization
- Serverless
- Embedded systems
- High-Performance Computing (HPC) systems
- Edge computing systems
- Virtualized systems
Select and determine cryptographic solutions- Cryptographic life cycle (e.g., keys, algorithm selection)
- Cryptographic methods (e.g., symmetric, asymmetric, elliptic curves, quantum)
- Public Key Infrastructure (PKI)
- Key management practices
- Digital signatures and digital certificates
- Non-repudiation
- Integrity (e.g., hashing)
Understand methods of cryptanalytic attacks- Brute force
- Ciphertext only
- Known plaintext
- Frequency analysis
- Chosen ciphertext
- Implementation attacks
- Side-channel
- Fault injection
- Timing
- Man-in-the-Middle (MITM)
- Pass the hash
- Kerberos exploitation
- Ransomware
Apply security principles to site and facility design
Design site and facility security controls- Wiring closets/intermediate distribution facilities
- Server rooms/data centers
- Media storage facilities
- Evidence storage
- Restricted and work area security
- Utilities and Heating, Ventilation, and Air Conditioning (HVAC)
- Environmental issues
- Fire prevention, detection, and suppression
- Power (e.g., redundant, backup)

Communication and Network Security - 13%

Assess and implement secure design principles in network architectures- Open System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models
- Internet Protocol (IP) networking (e.g., Internet Protocol Security (IPSec), Internet Protocol (IP) v4/6)
- Secure protocols
- Implications of multilayer protocols
- Converged protocols (e.g., Fiber Channel Over Ethernet (FCoE), Internet Small Computer Systems Interface (iSCSI), Voice over Internet Protocol (VoIP))
- Micro-segmentation (e.g., Software Defined Networks (SDN), Virtual eXtensible Local Area Network (VXLAN), Encapsulation, Software-Defined Wide Area Network (SD WAN))
- Wireless networks (e.g., Li-Fi, Wi-Fi, Zigbee, satellite)
- Cellular networks (e.g., 4G, 5G)
- Content Distribution Networks (CDN)
Secure network components- Operation of hardware (e.g., redundant power, warranty, support)
- Transmission media
- Network Access Control (NAC) devices
- Endpoint security
Implement secure communication channels according to design- Voice
- Multimedia collaboration
- Remote access
- Data communications
- Virtualized networks
- Third-party connectivity

Identity and Access Management (IAM) - 13%

Control physical and logical access to assets- Information
- Systems
- Devices
- Facilities
- Applications
Manage identification and authentication of people, devices, and services- Identity Management (IdM) implementation
- Single/multi-factor authentication (MFA)
- Accountability
- Session management
- Registration, proofing, and establishment of identity
- Federated Identity Management (FIM)
- Credential management systems
- Single Sign On (SSO)
- Just-In-Time (JIT)
Federated identity with a third-party service- On-premise
- Cloud
- Hybrid
Implement and manage authorization mechanisms- Role Based Access Control (RBAC)
- Rule based access control
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Attribute Based Access Control (ABAC)
- Risk based access control
Manage the identity and access provisioning lifecycle- Account access review (e.g., user, system, service)
- Provisioning and deprovisioning (e.g., on /off boarding and transfers)
- Role definition (e.g., people assigned to new roles)
- Privilege escalation (e.g., managed service accounts, use of sudo, minimizing its use)
Implement authentication systems- OpenID Connect (OIDC)/Open Authorization (Oauth)
- Security Assertion Markup Language (SAML)
- Kerberos
- Remote Authentication Dial-In User Service (RADIUS)/Terminal Access Controller Access Control System Plus (TACACS+)

Security Assessment and Testing - 12%

Design and validate assessment, test, and audit strategies- Internal
- External
- Third-party
Conduct security control testing- Vulnerability assessment
- Penetration testing
- Log reviews
- Synthetic transactions
- Code review and testing
- Misuse case testing
- Test coverage analysis
- Interface testing
- Breach attack simulations
- Compliance checks

 

NEW QUESTION 173
The Information Technology Security Evaluation Criteria (ITSEC) was written to address which of the following that the Orange Book did not address?

  • A. integrity and availability
  • B. confidentiality and availability
  • C. integrity and confidentiality
  • D. none of the above

Answer: A

Explanation:
"ITSECTCSEC (Orange Book) E0D F1+E1C1 F2+E2C2 F3+E3B1 F4+E4B2 F5+E5B3 F5+E6A1 F6=Systems that provide high integrity F7=Systems that provide high availability F8=Systems that provide data integrity during communication F9=Systems that provide high confidentiality F10=Networks with high demands on confidentiality and integrity"
Pg. 230 Shon Harris: All-in-One CISSP Certification

 

NEW QUESTION 174
Match the name of access control model with its associated restriction.
Drag each access control model to its appropriate restriction access on the right.

Answer:

Explanation:

Explanation
Mandatory Access Control - End user cannot set controls
Discretionary Access Control (DAC) - Subject has total control over objects Role Based Access Control (RBAC) - Dynamically assigns roles permissions to particular duties based on job function Rule Based access control - Dynamically assigns roles to subjects based on criteria assigned by a custodian.

 

NEW QUESTION 175
Which of the following specifically addresses cyber attacks against an organization's IT systems?

  • A. Business continuity plan
  • B. Continuity of operations plan
  • C. Continuity of support plan
  • D. Incident response plan

Answer: D

Explanation:
The incident response plan focuses on information security responses to incidents affecting systems and/or networks. It establishes procedures to address cyber attacks against an organization's IT systems. These procedures are designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data, denial of service, or unauthorized changes to system hardware or software. The continuity of support plan is the same as an IT contingency plan. It addresses IT system disruptions and establishes procedures for recovering a major application or general support system. It is not business process focused. The business continuity plan addresses business processes and provides procedures for sustaining essential business operations while recovering from a significant disruption. The continuity of operations plan addresses the subset of an organization's missions that are deemed most critical and procedures to sustain these functions at an alternate site for up to 30 days. Source: SWANSON, Marianne, & al., National Institute of Standards and Technology (NIST), NIST Special Publication 800-34, Contingency Planning Guide for Information Technology Systems, December 2001 (page 8).

 

NEW QUESTION 176
The use of private and public encryption keys is fundamental in the implementation of which of the following?

  • A. Message Digest 5 (MD5)
  • B. Advanced Encryption Standard (AES)
  • C. Diffie-Hellman algorithm
  • D. Secure Sockets Layer (SSL)

Answer: D

 

NEW QUESTION 177
What should a company do first when disposing of personal computers that once were used to store confidential data?

  • A. Overwrite all data on the hard disk with zeroes
  • B. Delete all data contained on the hard disk
  • C. Demagnetize the hard disk
  • D. Low level format the hard disk

Answer: C

 

NEW QUESTION 178
Which of the following is a not a preventative control?

  • A. Establish procedures for emergency changes.
  • B. Run a source comparison program between control and current source periodically.
  • C. Deny programmer access to production data.
  • D. Require change requests to include information about dates, descriptions, cost analysis and anticipated effects.

Answer: B

Explanation:
Running the source comparison program between control and current source periodically allows detection, not prevention, of unauthorized changes in the production environment. Other options are preventive controls.
Source: Information Systems Audit and Control Association, Certified Information Systems
Auditor 2002 review manual, chapter 6: Business Application System Development,
Acquisition, Implementation and Maintenance (page 309).

 

NEW QUESTION 179
When conducting a security assessment of access controls, which activity is part of the data analysis phase?

  • A. Collect logs and reports.
  • B. Categorize and identify evidence gathered during the audit.
  • C. Present solutions to address audit exceptions.
  • D. Conduct statistical sampling of data transactions.

Answer: B

 

NEW QUESTION 180
Which of the following should NOT normally be allowed through a firewall?

  • A. SNMP
  • B. SSH
  • C. HTTP
  • D. SMTP

Answer: A

Explanation:
The Simple Network Management Protocol (SNMP) is a useful tool for remotely managing network devices.
Since it can be used to reconfigure devices, SNMP traffic should be blocked at the organization's firewall.
Using a VPN with encryption or some type of Tunneling software would be highly recommended in this case.
Source: STREBE, Matthew and PERKINS, Charles, Firewalls 24seven, Sybex 2000,
Chapter 4: Sockets and Services from a Security Viewpoint.

 

NEW QUESTION 181
Fault tolerance countermeasures are designed to combat threats to which of the following?

  • A. an uninterruptible power supply.
  • B. backup and retention capability.
  • C. data integrity.
  • D. design reliability.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
One of the ways to provide uninterrupted access to information assets is through redundancy and fault tolerance. Redundancy refers to providing multiple instances of either a physical or logical component such that a second component is available if the first fails. Fault tolerance is a broader concept that includes redundancy but refers to any process that allows a system to continue making information assets available in the case of a failure.
Fault tolerance countermeasures are designed to combat threats to design reliability. Although fault tolerance can include redundancy, it also refers to systems such as RAID where if a disk fails, the data can be made available from the remaining disks.
Incorrect Answers:
A: Fault tolerance countermeasures ensure that data assets remain available in the event of a failure of any component, not just an uninterruptible power supply.
B: Fault tolerance countermeasures ensure that data assets remain available in the event of a failure of any component, not just the backup and retention capability.
D: Fault tolerance countermeasures do not protect data integrity.

 

NEW QUESTION 182
Why should batch files and scripts be stored in a protected area?

  • A. Because of the need-to-know concept
  • B. Because they cannot be accessed by operators
  • C. Because of the least privilege concept
  • D. Because they may contain credentials

Answer: D

Explanation:
Topic 5, Operations Security

 

NEW QUESTION 183
Which of the following is not a defined maturity level within the Software Capability Maturity Model?

  • A. Defined
  • B. Managed
  • C. Repeatable
  • D. Oriented

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The Software Capability Maturity Model (CMM) is based on the premise that the quality of a software product is a direct function of the quality of its associated software development and maintenance processes. It introduces five maturity levels that serve as a foundation for conducting continuous process improvement and as an ordinal scale for measuring the maturity of the organization involved in the software processes.
CMM has Five Maturity Levels of Software Processes:
The initial level: processes are disorganized, even chaotic. Success is likely to depend on individual

efforts, and is not considered to be repeatable as processes would not be sufficiently defined and documented to allow them to be replicated.
The repeatable or managed level: basic project management techniques are established, and

successes could be repeated as the requisite processes would have been made established, defined, and documented.
The defined level: an organization has developed its own standard software process through greater

attention to documentation, standardization, and integration.
The quantatively managed level: an organization monitors and controls its own processes through data

collection and analysis.
The optimized level: processes are constantly being improved through monitoring feedback from

current processes and introducing innovative processes to better serve the organization's particular needs.
There is thus no Oriented level.
Incorrect Answers:
A: The repeatable level is the second maturity level. At this level basic project management techniques are established, and successes could be repeated as the requisite processes would have been made established, defined, and documented.
B: The defined level is the third maturity level. At this level an organization has developed its own standard software process through greater attention to documentation, standardization, and integration.
C: The (quantatively) managed level is the fourth maturity level. At this level an organization monitors and controls its own processes through data collection and analysis.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 62, 1120-1122
http://en.wikipedia.org/wiki/Capability_Maturity_Model

 

NEW QUESTION 184
What attack involves repeatedly sending identical e-message to a particular address?

  • A. SMURF
  • B. Brute force
  • C. Teardrop
  • D. Spamming

Answer: D

Explanation:
Spamming -- Involves repeatedly sending identical e-message to a particular address. It is a variant of bombing, and is made worse when the recipient replies -- i.e. recent cases where viruses or worms were attached to the e-mail message and ran a program that forwarded the message from the reader to any one on the user's distribution lists. This attack cannot be prevented, but you should ensure that entrance and exit of such mail is only through central mail hubs.

 

NEW QUESTION 185
What is the most secure way to dispose of information on a CD-ROM?

  • A. Degaussing
  • B. Physical damage
  • C. Sanitizing
  • D. Physical destruction

Answer: D

Explanation:
First you have to realize that the question is specifically talking about a CDROM.
The information stored on a CDROM is not in electro magnetic format, so a degausser woud be
inneffective.
You cannot sanitize a CDROM but you might be able to sanitize a RW/CDROM. A CDROM is a
write once device and cannot be overwritten like a hard disk or other magnetic device.
Physical Damage would not be enough as information could still be extracted in a lab from the
undamaged portion of the media or even from the pieces after the physical damage has been
done.
Physical Destruction using a shredder, your microwave oven, melting it, would be very effective
and the best choice for a non magnetic media such as a CDROM.
Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.

 

NEW QUESTION 186
What does secure authentication with logging provide?

  • A. Data integrity
  • B. Segregation of duties
  • C. Encryption logging format
  • D. Access accountability

Answer: D

 

NEW QUESTION 187
Which of the following phases of a system development life-cycle is most concerned with maintaining proper authentication of users and processes to ensure appropriate access control decisions?

  • A. Implementation
  • B. Initiation
  • C. Operation/Maintenance
  • D. Development/acquisition

Answer: C

Explanation:
The operation phase of an IT system is concerned with user authentication.
Authentication is the process where a system establishes the validity of a transmission, message, or a means of verifying the eligibility of an individual, process, or machine to carry out a desired action, thereby ensuring that security is not compromised by an untrusted source.
It is essential that adequate authentication be achieved in order to implement security policies and achieve security goals. Additionally, level of trust is always an issue when dealing with cross-domain interactions. The solution is to establish an authentication policy and apply it to cross-domain interactions as required.
Source: STONEBURNER, Gary & al, National Institute of Standards and Technology
(NIST), NIST Special Publication 800-27, Engineering Principles for Information
Technology Security (A Baseline for Achieving Security), June 2001 (page 15).

 

NEW QUESTION 188
What is NOT an authentication method within IKE and IPSec?

  • A. CHAP
  • B. certificate based authentication
  • C. Pre shared key
  • D. Public key authentication

Answer: A

Explanation:
CHAP is not used within IPSEC or IKE. CHAP is an authentication scheme used by Point to Point Protocol (PPP) servers to validate the identity of remote clients. CHAP periodically verifies the identity of the client by using a three-way handshake. This happens at the time of establishing the initial link (LCP), and may happen again at any time afterwards. The verification is based on a shared secret (such as the client user's password). After the completion of the link establishment phase, the authenticator sends a "challenge" message to the peer. The peer responds with a value calculated using a one-way hash function on the challenge and the secret combined. The authenticator checks the response against its own calculation of the expected hash value. If the values match, the authenticator acknowledges the authentication; otherwise it should terminate the connection. At random intervals the authenticator sends a new challenge to the peer and repeats steps 1 through 3.
The following were incorrect answers: Pre Shared Keys In cryptography, a pre-shared key or PSK is a shared secret which was previously shared between the two parties using some secure channel before it needs to be used. To build a key from shared secret, the key derivation function should be used. Such systems almost always use symmetric key cryptographic algorithms. The term PSK is used in WiFi encryption such as WEP or WPA, where both the wireless access points (AP) and all clients share the same key. The characteristics of this secret or key are determined by the system which uses it; some system designs require that such keys be in a particular format. It can be a password like 'bret13i', a passphrase like 'Idaho hung gear id gene', or a hexadecimal string like '65E4 E556 8622 EEE1'.
The secret is used by all systems involved in the cryptographic processes used to secure the traffic between the systems. Certificat Based Authentication The most common form of trusted authentication between parties in the wide world of Web commerce is the exchange of certificates. A certificate is a digital document that at a minimum includes a Distinguished Name (DN) and an associated public key. The certificate is digitally signed by a trusted third party known as the Certificate Authority (CA). The CA vouches for the authenticity of the certificate holder. Each principal in the transaction presents certificate as its credentials. The recipient then validates the certificate's signature against its cache of known and trusted CA certificates. A "personal certificate" identifies an end user in a transaction; a "server certificate" identifies the service provider. Generally, certificate formats follow the X.509 Version 3 standard. X.509 is part of the Open Systems Interconnect (OSI) X.500 specification.
Public Key Authentication Public key authentication is an alternative means of identifying yourself to a login server, instead of typing a password. It is more secure and more flexible, but more difficult to set up. In conventional password authentication, you prove you are who you claim to be by proving that you know the correct password. The only way to prove you know the password is to tell the server what you think the password is. This means that if the server has been hacked, or spoofed an attacker can learn your password. Public key authentication solves this problem. You generate a key pair, consisting of a public key (which everybody is allowed to know) and a private key (which you keep secret and do not give to anybody). The private key is able to generate signatures. A signature created using your private key cannot be forged by anybody who does not have a copy of that private key; but anybody who has your public key can verify that a particular signature is genuine. So you generate a key pair on your own computer, and you copy the public key to the server. Then, when the server asks you to prove who you are, you can generate a signature using your private key. The server can verify that signature (since it has your public key) and allow you to log in. Now if the server is hacked or spoofed, the attacker does not gain your private key or password; they only gain one signature. And signatures cannot be re-used, so they have gained nothing. There is a problem with this: if your private key is stored unprotected on your own computer, then anybody who gains access to your computer will be able to generate signatures as if they were you. So they will be able to log in to your server under your account. For this reason, your private key is usually encrypted when it is stored on your local machine, using a passphrase of your choice. In order to generate a signature, you must decrypt the key, so you have to type your passphrase. References: RFC 2409: The Internet Key Exchange (IKE); DORASWAMY, Naganand & HARKINS, Dan Ipsec: The New Security Standard for the Internet, Intranets, and Virtual Private Networks, 1999, Prentice Hall PTR; SMITH, Richard E.
Internet Cryptography, 1997, Addison-Wesley Pub Co.; HARRIS, Shon, All-In-One CISSP Certification Exam Guide, 2001, McGraw-Hill/Osborne, page 467.
http://en.wikipedia.org/wiki/Pre-shared_key
http://www.home.umk.pl/~mgw/LDAP/RS.C4.JUN.97.pdf
http://the.earth.li/~sgtatham/putty/0.55/htmldoc/Chapter8.html#S8.1

 

NEW QUESTION 189
You are comparing biometric systems. Security is the top priority. A low ________ is most important in this regard.

  • A. FRR
  • B. FAR
  • C. MTBF
  • D. ERR

Answer: B

Explanation:
When comparing biometric systems, a low false acceptance rate is most important when security is the priority. Whereas, a low false rejection rate is most important when convenience is the priority. All biometric implementations balance these two criteria. Some systems use very high FAR's such as 1 in 300. This means that the likelihood that the system will accept someone other than the enrolled user is 1 in 300. However, the likelihood that the system will reject the enrolled user (its FRR) is very low, giving them ease of use, but with low security. Most fingerprint systems should be able to run with FARs of 1 in 10,000 or better.

 

NEW QUESTION 190
Which statement below is accurate about the difference between
Ethernet II and 802.3 frame formats?

  • A. Ethernet II uses a 4-byte FCS field, whereas 802.3 uses an 8-byte Preamble field.
  • B. Ethernet II uses an 8-byte Preamble field, whereas 802.3 uses a 4-byte FCS field.
  • C. 802.3 uses a Length field, whereas Ethernet II uses a Type field.
  • D. 802.3 uses a Type field, whereas Ethernet II uses a Length field.

Answer: C

Explanation:
802.3 uses a Length field which indicates the number of data bytes that are in the data field. Ethernet II uses a Type field in the same 2 bytes to identify the message protocol type. Both frame formats use a 8-byte Preamble field at the start of the packet, and a 4byte Frame Check Sequence (FCS) field at the end of the packet, so

those choices would be incorrect as to a difference in the frame formats. Sources: Gigabit Ethernet by Jayant Kadambi, Ian Crayford, and Mohan Kalkunte (Prentice Hall PTR, 1998) and CCNA Study Guide by Todd Lammle, Donald Porter, and James Chellis (Sybex, 1999).

 

NEW QUESTION 191
Which of the following is an IDS that acquires data and defines a "normal" usage profile for the network or host?

  • A. Statistical Anomaly-Based IDS
  • B. inferential anomaly-based IDS
  • C. Signature-Based IDS
  • D. dynamical anomaly-based IDS

Answer: A

Explanation:
Explanation/Reference:
Explanation:
An IDS which is anomaly based monitors network traffic and compares it against an established baseline, which identifies what is "normal" for that network, and the alerts the relevant party when traffic is detected which is significantly different to the baseline.
Incorrect Answers:
B: A signature based IDS monitors packets and compares them against a database of signatures or attributes from known malicious threats.
C: Dynamical anomaly-based IDS is not a valid IDS type.
D: Inferential anomaly-based IDS is not a valid IDS type.
References:
https://en.wikipedia.org/wiki/Intrusion_detection_system
https://en.wikipedia.org/wiki/Anomaly-based_intrusion_detection_system

 

NEW QUESTION 192
Which of the following items BEST describes the standards addressed
by Title II, Administrative Simplification, of the Health Insurance
Portability and Accountability Act (US Kennedy-Kassebaum Health
Insurance and Portability Accountability Act -HIPAA-Public Law 104-19)?

  • A. Security and Electronic Signatures and Privacy
  • B. Transaction Standards, to include Code Sets; Unique Health
    Identifiers; Security and Electronic Signatures and Privacy
  • C. Unique Health Identifiers; Security and Electronic Signatures and
    Privacy
  • D. Transaction Standards, to include Code Sets; Security and Electronic
    Signatures and Privacy

Answer: B

Explanation:
HIPAA was designed to provide for greater access to personal
health care information, enable portability of health care insurance,
establish strong penalties for health care fraud, and streamline the
health care claims process through administrative simplification. To
accomplish the latter, Title II of the HIPAA law, Administrative Simplification, requires standardizing the formats for the electronic transmission of health care information. The transactions and code sets portion includes standards for submitting claims, enrollment information, premium payments, and others as adopted by HHS. The standard for transactions is the ANSI ASC X12N version 4010 EDI
Standard. Standard code sets are required for diagnoses and inpatient
services, professional services, dental services (replaces D'
codes), and drugs (instead of J' codes). Also, local codes are not to be used. Unique health identifiers are required to identify health care providers, health plans, employers, and individuals. Security and electronic signatures are specified to protect health care information. Pri- vacy protections are required to ensure that there is no unauthorized
disclosure of individually identifiable health care information.
The other answers are incorrect since they do not include all four
major standards. Additional information can be found at http://
aspe.hhs.gov/adminsimp.

 

NEW QUESTION 193
......


ISC2 CISSP Exam Certification Details:

Exam Price$699 (USD)
Exam CodeCISSP
Number of Questions100-150
Passing Score700/1000
Schedule ExamPearson VUE
Duration180 mins
Exam NameISC2 Certified Information Systems Security Professional (CISSP)

 

Pass ISC CISSP exam - questions - convert Tets Engine to PDF: https://www.actualtestsit.com/ISC/CISSP-exam-prep-dumps.html

2023 Realistic Verified Free ISC CISSP Exam Questions: https://drive.google.com/open?id=1_gqOSTFl8CvbTTNyt4R_MJJS-KgzPKFA