Item number 1
Chapter 2: Information Security Principles of Success
Section: Principle 2: The Three Security Goals Are Confidentiality, Integrity, and
Availability
Item type: Multiple Choice
Question: Which of the following is not one of the three parts of the CIA triad?
Options:
A. Availability
B. Encryption
C. Integrity
D. Confidentiality
Item number 2
Chapter 2: Information Security Principles of Success
Section: Principle 2: The Three Security Goals Are Confidentiality, Integrity, and
Availability
Item type: Multiple Choice
Question: The goal of which of the following is preventing unauthorized users from
modifying data?
Options:
A. Confidentiality
B. Integrity
C. Availability
D. Auditing
Item number 3
Chapter 2: Information Security Principles of Success
Section: Principle 2: The Three Security Goals Are Confidentiality, Integrity, and
Availability
Item type: Multiple Choice
Question: Backups can be used to protect which of the following?
Options:
A. Confidentiality
B. Integrity
C. Availability
D. Auditing
Item number 4
Chapter 2: Information Security Principles of Success
Section: Principle 3: Defense in Depth as Strategy
Item type: Multiple Choice
Question: Using multiple overlapping layers to secure data and resources is known as
which of the following?
Options:
A. Principle of least privilege
B. Separation of duties
C. Defense in depth
D. Security triad
Item number 5
Chapter 2: Information Security Principles of Success
Section: Principle 1: There Is No Such This As Absolute Security
Item type: Multiple Choice
Question: Assigning users only the minimum amount of privileges they need to perform
their job is known as which of the following?
Options:
A. Principle of least privilege
B. Separation of duties
C. Defense in depth
D. Security triad
Item number 6
Chapter 2: Information Security Principles of Success
Section: Principle 3: Defense in Depth as Strategy
Item type: Multiple Choice
Question: Using routers, firewalls, and intrusion detection systems in combination with
real-time human monitoring is an example of which of the following?
Options:
A. Separation of duties
B. Defense in depth
C. Principle of least privilege
D. Intrusion monitoring
Item number 7
Chapter 2: Information Security Principles of Success
Section: Principle 7: Security = Risk Management
Item type: Multiple Choice
Question: A buffer overflow is an example of which of the following?
Options:
A. Vulnerability
B. Exploit
C. Threat
D. Risk
Item number 8
Chapter 2: Information Security Principles of Success
Section: Principle 7: Security = Risk Management
Item type: Multiple Choice
Question: Which of the following is concerned with placing an economic value on assets
to determine appropriate countermeasures?
Options:
A. Risk mitigation
B. Risk assessment
C. Vulnerability assessment
D. Risk avoidance
Item number 9
Chapter 2: Information Security Principles of Success
Section: Principle 6: Security Through Obscurity is Not an Answer
Item type: Multiple Choice
Question: Which of the following statements is not true?
Options:
A. Computer security depends on two types of requirements: functional and
assurance.
B. Security through obscurity is an effective way to secure a system.
C. The three goals of security are confidentiality, integrity, and availability.
D. The three types of security controls are preventive, detective, and responsive.
Item number 10
Chapter 2: Information Security Principles of Success
Section: Principle 7: Security = Risk Management
Item type: Multiple Choice
Question: Which of the following risk types requires an immediate action?
Options:
A. Low risk
B. Moderate risk
C. High risk
D. Extreme risk
Item number 11
Chapter 2: Information Security Principles of Success
Section: Principle 7: Security = Risk Management
Item type: Multiple Choice
Question: Which of the following risk types is managed by routine procedures?
Options:
A. Low risk
B. Moderate risk
C. High risk
D. Extreme risk
Item number 12
Chapter 2: Information Security Principles of Success
Section: Principle 8: The Three Types of Security Controls Are Preventive, Detective,
and Responsive
Item type: Multiple Choice
Question: Which of the following is an example of a prevention control?
Options:
A. Intrusion detection system
B. Firewall
C. Motion sensors
D. Security alarm
Item number 13
Chapter 2: Information Security Principles of Success
Section: Principle 11: People, Process, and Technology Are All Needed to Adequately
Secure a System or Facility
Item type: Multiple Choice
Question: Which of the following best describes the goal of process controls?
Options:
A. Ensures that different people can perform the same operation exactly the same
way each time
B. Ensures that different people can perform operations differently
C. Ensures that the same people can perform the same operations differently each
time
D. Ensures that the same people can perform the same operation exactly the same
each time
Item number 14
Chapter 2: Information Security Principles of Success
Section: Principle 11: People, Process, and Technology Are All Needed to Adequately
Secure a System or Facility
Item type: Multiple Choice
Question: Which of the following statements best describes separation of duties?
Options:
A. No one person in an organization has the ability to control a security activity.
B. Different tasks are assigned to different people.
C. Each person is assigned the highest level of privileges needed to complete a
task.
D. Multiple people have the ability to control a security activity.
Item number 15
Chapter 2: Information Security Principles of Success
Section: Principle 11: People, Process, and Technology Are All Needed to Adequately
Secure a System or Facility
Item type: Multiple Choice
Question: Which of the following is not needed to create a secure system?
Options:
A. People
B. Processes
C. Technology
D. All the above are needed to create a secure system
Item number 16
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following CBK domains covers developing and implementing
security policies?
Options:
A. Information security governance and risk management
B. Business continuity and disaster recovery planning
C. Legal regulations, investigations, and compliance
D. Security architecture and design
Item number 17
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: Vendor-Specific and Other Certification Programs
Item type: Multiple Choice
Question: Which of the following certifications is not administered by (ISC)2 ?
Options:
A. CISSP
B. CEH
C. SSCP
D. CSSLP
Item number 18
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the information security
governance and risk management CBK domain?
Options:
A. Understanding forensic procedures
B. Following compliance requirements
C. Developing and implementing security policies
D. Understanding the fundamental concepts of security models
Item number 19
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the security architecture and
design CBK domain?
Options:
A. Understanding forensic procedures
B. Following compliance requirements
C. Developing and implementing security policies
D. Understanding the fundamental concepts of security models
Item number 20
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the business continuity and
disaster recovery planning CBK domain?
Options:
A. Developing a recovery strategy
B. Following compliance requirements
C. Developing and implementing security policies
D. Managing personnel security
Item number 21
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the legal regulations,
investigations, and compliance CBK domain?
Options:
A. Developing a recovery strategy
B. Following compliance requirements
C. Understanding encryption concepts
D. Managing personnel security
Item number 22
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the legal regulations,
investigations, and compliance CBK domain?
Options:
A. Developing a disaster recovery plan
B. Establishing secure communication channels
C. Supporting the protection and security of equipment
D. Using digital signatures
Item number 23
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the operations security CBK
domain?
Options:
A. Applying the SDLC
B. Establishing secure communication channels
C. Implementing patch and vulnerability management
D. Using digital signatures
Item number 24
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the access control CBK
domain?
Options:
A. Applying the SDLC
B. Establishing secure communication channels
C. Implementing patch and vulnerability management
D. Understanding access control attacks
Item number 25
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the cryptography CBK
domain?
Options:
A. Understanding and using digital certificates
B. Establishing secure communication channels
C. Managing incident response
D. Understanding access control attacks
Item number 26
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the telecommunications and
network CBK domain?
Options:
A. Understanding and using digital certificates
B. Understanding public key infrastructure
C. Understanding denial of service and spoofing attacks
D. Understanding access control attacks
Item number 27
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Which of the following topics is covered under the software development
security CBK domain?
Options:
A. Understanding the cryptographic life cycle
B. Understanding public key infrastructure
C. Assessing the effectiveness of software security
D. Securing network components
Item number 28
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Digital signatures and digital certificates are topics covered in which of the
following CBK domains?
Options:
A. Access control
B. Cryptography
C. Operations security
D. Software development security
Item number 29
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Using SSL and VPN to establish a secure communication channel is covered
in which of the following CBK domain?
Options:
A. Cryptography
B. Telecommunications and network security
C. Operations security
D. Security architecture and design
Item number 30
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding confidentiality and integrity models and defense in depth are
covered in which of the following CBK domains?
Options:
A. Cryptography
B. Telecommunications and network security
C. Operations security
D. Security architecture and design
Item number 31
Chapter 4: Governance and Risk Management
Section: Understanding the Four Types of Policies
Item type: Multiple Choice
Question: Which of the following best describes an issue-specific policy?
Options:
A. Used to create a management-sponsored computer security program
B. Focuses on policy issues that management has decided for a specific system
C. Establishes the overall approach to computer security
D. Addresses specific issues of concerns to the organization
Answer: D
Explanation: Issue-specific policies address specific issues of concern to the
organization, such as regulatory issues like HIPAA, SOX, PCI, and others.
Item number 32
Chapter 4: Governance and Risk Management
Section: Understanding the Four Types of Policies
Item type: Multiple Choice
Question: Which of the following best describes a system-specific policy
Options:
A. Used to create a management-sponsored computer security program
B. Focuses on policy issues that management has decided for a specific system
C. Establishes the overall approach to computer security
D. Addresses specific issues of concerns to the organization
Item number 33
Chapter 4: Governance and Risk Management
Section: Issue-Specific Policies
Item type: Multiple Choice
Question: Which of the following is an examples of an issue specific policy?
Options:
A. Email acceptable use
B. Wireless security policy
C. Laptop security policy
D. All the above
Item number 34
Chapter 4: Governance and Risk Management
Section: Providing Policy Support Documents
Item type: Multiple Choice
Question: Which of the following best describes a procedure?
Options:
A. Law passed by regulators and lawmakers
B. Specific security requirements, or what a system or a process needs to be
considered secure
C. Detailed step-by-step instructions on how to complete a task or a process
D. Documentation and guidance that aids in compliance
Item number 35
Chapter 4: Governance and Risk Management
Section: Asset and Data Classification
Item type: Multiple Choice
Question: Which of the following is an example of a trade secret?
Options:
A. Social Security numbers
B. Recipe for Coca-Cola
C. Departmental budget
D. Marketing information
Item number 36
Chapter 4: Governance and Risk Management
Section: Standards and Baselines
Item type: Multiple Choice
Question: The term standard is often used interchangeably with which of the following
terms?
Options:
A. Regulation
B. Procedure
C. Baseline
D. Guideline
Item number 37
Chapter 4: Governance and Risk Management
Section: Standards and Baselines
Item type: Multiple Choice
Question: Which of the following best describes a baseline?
Options:
A. Specific set of requirements for a technology implementation
B. Specific security requirements, or what a system or a process needs to be
considered secure
C. Detailed step-by-step instructions on how to complete a task or a process
D. Documentation and guidance that aids in compliance
Answer: C
Explanation: A baseline is a specific set of requirements for a technology
implementation, such as Windows Server security settings or database setting. A
procedure is a detailed step-by-step instructions on how to complete a task. A standard
refers to specific security requirements or what a system needs to be considered
secure. A guideline is a documentation that aids in compliance with a standard.
Item number 38
Chapter 4: Governance and Risk Management
Section: Risk Analysis and Management
Item type: Multiple Choice
Question: Quantitative risk analysis uses which of the following?
Options:
A. Annualized loss expectancy
B. Probability
C. Control
D. All the above
Item number 39
Chapter 4: Governance and Risk Management
Section: Risk Analysis and Management
Item type: Multiple Choice
Question: Which of the following statements about quantitative risk analysis is true?
Options:
A. It is the most widely used approach to risk analysis.
B. Probability data is not required for this type of risk analysis.
C. It uses annual loss expectancy to rank events.
D. It is reliable and accurate way to calculate risk.
Item number 40
Chapter 4: Governance and Risk Management
Section: Education, Training, and Awareness
Item type: Multiple Choice
Question: How often should training be conducted?
Options:
A. Monthly
B. Annually
C. Whenever the policies change
D. Both A and B
E. Both A and C
F. Both B and C
Item number 41
Chapter 4: Governance and Risk Management
Section: Qualitative Risk Analysis
Item type: Multiple Choice
Question: Which of the following best describes detective controls?
Options:
A. Reduce the likelihood of a deliberate attack.
B. Protect vulnerabilities.
C. Reduce the effect of an attack.
D. Discover attack and trigger preventive or corrective controls.
Item number 42
Chapter 4: Governance and Risk Management
Section: Qualitative Risk Analysis
Item type: Multiple Choice
Question: Which of the following best describes deterrent controls?
Options:
A. Reduce the likelihood of a deliberate attack.
B. Protect vulnerabilities.
C. Reduce the effect of an attack.
D. Discover attack and trigger preventive or corrective controls.
Item number 43
Chapter 4: Governance and Risk Management
Section: Qualitative Risk Analysis
Item type: Multiple Choice
Question: Which of the following statements about qualitative analysis is true?
Options:
A. Probability of data is required.
B. It uses annualized loss expectancy to rank events.
C. It is the most widely used approach to risk analysis.