Which of the following refers to a location away from the computer...
Which of the following is NOT a natural environmental threat that an...
Defining technology security architecture in relationship with other...
Which layer is not part of the OSI model?
The doors of a data center spring open in the event of a fire....
Encryption is converting a message from ciphertext to plaintext.
Remote Access does what of the following?
When outsourcing IT systems
Define and detail the aspects of password selection that distinguish...
Test outputs should be compared against expected outputs.
It can be said that IPSec
__________ requires that a user of process be granted access to only...
The major benefit of information classification is to
A botnet can be characterized as
The integrity of a forensic bit stream image is determined by:
To maintain the security architecture, of the following, which is...
Modifying identifying information so as to make communication appear...
Effective security management:
When sensitive information is no longer critical but still within...
The best way to ensure that there is no data remanence of sensitive...
Which one is a benefit of a enterprise security architecture?
NIST identifies three service models that represent different types of...
A new installation requires a network in a heavy manufacturing area...
Role-based access control
A disadvantage of single sign-on is
Which of the following ensures constant redundancy and...
What is not mentioned as a phase of an incident response?
What type of risk remains after the implementation of new or enhanced...
The strategy of forming layers of protection around an asset or...
Which of the following is the technology of indoor environmental...
Which of the following terms refers to a mechanism which proves that...
Polyalphabetic encryption techniques use multiple alphabets for each...
The monitoring of outbound network traffic for indicators of...
A guard dog patrolling the perimeter of a data center is what type of...
Which of the following BEST describe three separate functions of CCTV?
Which one of the following is a common system component in the system...
Which of the following methods is not acceptable for exercising the...
Which of the following is the technology of indoor environmental...
An emerging concept of highly-interconnected physical devices with...
Which of the following uses a Key Distribution Center (KDC) to...
Within the realm of IT security, which of the following combinations...
The best way to ensure that there is no data remanence of sensitive...
The vast majority of Virtual Private Networks use
Assuming a working IDS is in place, which of the following groups is...
Which of the following is most likely to detect DoS attacks?
Which regulatory guidance pertains to any company that is publicly...
Which of the following terms BEST describes the effort to determine...
A potential vulnerability of the Kerberos authentication server is
In which of the following alternative site configurations is the...
Attempting to crack a password by using common words from a text file...
A customer requests to connect their LAN to the internet. Which of the...
Recently passed over for an executive promotion, Carol is anxious to...
Which of the following security standards is internationally...
Before applying a software update to production systems, it is MOST...
Which of the following is responsible for maintaining certificates in...
What type of malware uses social engineering to trick a victim into...
What type of analysis emphasizes the formal study of what your...
Which of the following is not a characteristic of continuous...
When malware infects a host and allows it to be used in a botnet for...
Which of the following describes the type of anti-virus software that...
Network information services (NIS) are used for what processes?
Many organizations purchase insurance policies to provide various...
Wi-Fi Protected Access (WPA-2) uses Advanced Encryption Standard (AES)...
Security awareness training includes:
Data access decisions are best made by:
When sensitive information is no longer critical but still within...
Since 9/11, airport parking garages now keep cars further away from...
When a certificate is revoked, what is the proper procedure?
The only cipher system said to be unbreakable by brute force is
Which of the following end-point devices would MOST likely be...
What are the three types of access control?
The main difference between a Security Event Information Management...
Which of the following is NOT a consideration when choosing data...
Which of the following is MOST important for successful business...
Asymmetric key cryptography is used for the following:
Authentication is
Management should decide when a system should be returned to...
Administrative law is concerned with confining government power,...
Which of the following forms of attack can be used to disrupt even the...
What is the best protection measure against unauthorized access to...
What protocol solicits MAC address from devices on the network without...
Which one do you like?
Which of the following BEST determines the employment suitability of...
How are smart cards and memory cars functionally different?
Which of the following is correct about dynamic testing?
Which of the following is part of the five rules of evidence?
What is the BEST means of protecting the physical devices associated...
Which cable has a relatively low-speed transmission medium consisting...
Which protocol offers native encryption capability, for both...
Before applying a software update to production systems, it is MOST...
Ann installs a new Wireless Access Point (WAP) and users are able to...
Which of the following is true about maintaining the chain of custody...
Protection practices that can be used to prevent man-in-the middle...
Which of the following attacks allow bypassing access control lists on...
Which of the following categories of access control implementation...
Sam is a software developer and has recently gone through secure...
Which of the following supports asymmetric key cryptography?
Which is the BEST choice for implementing encryption on a smart card?
Which is a fundamental disadvantage of biometrics?
To ensure proper forensics action when needed, an incident response...
Which of the following processes identifies the threats that can...
Managing the dialogue between two or more communicating devices is...
Which intrusion detection system's efficiency decreases with...
A service's recovery point objective is zero. Which approach...
Formal acceptance of an evaluated system by management is known as:
What is the output length of a RIPEMD-160 hash?
A Security Event Management (SEM) service performs the following...
Multi-layer protocols such as Modbus used in industrial control...
What are the seven main categories of access control?
Which of the following is not one of the four typical elements of a...
Single loss expectancy (SLE) is calculated by using:
Which of the following steps should be performed first in a business...
Collusion is best mitigated by:
Which of the following is the primary desired result of any...
Sam is a software developer and has recently gone through secure...
Users are reporting that some Internet websites are not accessible...
What are types of failures in biometric identification systems?
A Service Organization Control (SOC) Report commonly covers a
At a restricted facility, visitors are requested to provide...
Cross-functional teams formed to conceptualize, design, test, produce,...
Of the following plans, which is designed to protect critical business...
The (ISC)2 code of ethics resolves conflicts between canons by:
Good data management practices include:
What are the FOUR phases of the equipment lifecycle?
The key to a successful physical protection system is the integration...
What would be the most appropriate interior sensor used for a building...
Which type of law is derived from court decisions and codification of...
A basic component of an industrial control system (ICS) that is most...
Well-written security program policies are BEST reviewed:
What is the optimal placement for network-based intrusion detection...
Laws designed to protect individuals' privacy have been created...
Which of the following electronically stored information (ESI) are not...
Which one of the following describes the Information Technology...
Your office is implementing an access control policy based on...
Which of the following can BEST be used to capture detailed security...
In mandatory access control the system controls access and the owner...
Triage encompasses which of the following incident response...
A hard drive is recovered from a submerged vehicle. The drive is...
Which one of the following is NOT a common security service in the...
Which phrase best defines a business continuity/disaster recovery...
In the OSI reference model, on which layer can Ethernet (IEEE 802.3)...
Frame Relay and X.25 networks are part of which of the following?
Substitution is mixing the location of plaintext throughout the...
All of the following is true about trade secrets EXCEPT:
Wireless transmission technologies include all of the following...
Which of the following statements BEST describes the extent to which...
Which of the following is not a form of identification?
An accurate picture of the use and acceptance of biometrics is:
Which one of the following is designed to protect the goodwill and...
All of the following describes link encryption except:
Which network topology's use of tokens allows prediction of node...
Information systems auditors help the organization:
Which of the following BEST describes fundamental methods of...
Which of the following is incorrect when considering privilege...
Computer forensics is the marriage of computer science, information...
Which of the following vulnerabilities would best be countered by...
Which of the following approaches for identifying appropriate BIA...
Information will not be disclosed to any unauthorized person on a...
What is the minimum and customary practice of responsible protection...
What is an important disadvantage of using a public key algorithm...
If speed is preferred over resilience, which of the following RAID...
With public key cryptography, confidential messages with proof of...
Each distinguished name (DN) in an LDAP directory represents a...
What is access control?
When the backup window is not long enough to backup all of the data...
Which of the following processes is concerned with not only...
Which of the following is a software protection mechanism where all...
What is the last phase of the TCP/IP three-way handshake sequence?
The BEST reason to implement additional controls or safeguards is to:
Hamid is reviewing identity management (IDM) products for his...
A customer wants to keep cost to a minimum and has only ordered a...
Audit trails, logs, CCTV, intrusion detection systems, antivirus...
Building security into the application begins at _____________.
Security is likely to be most expensive when addressed in which phase?
Which of the following models ensures that a subject with a clearance...
Which of the following ISO standards provides the evaluation criteria...
ANSI X9.17 is concerned primarily with
The NIST document that discusses the Information Security Continuous...
To which legal and regulatory requirement are all organizations...
In the event of a security incident, one of the primary objectives of...
Which of the following evaluation assurance level that is formally...
When dealing with digital evidence, the chain of custody:
Which one of the following is true about the criminal law?
Which of the following layers of the OSI model offer non-repudiation...
Setting clear security roles has the following benefits:
The elements of risk are as follows:
Which of the following BEST provides a method of quantifying risks...
Which of the following is a principal security risk of wireless LANs?
Which is BEST emphasizes the abstract concepts of law and is...
Which of the following are computer forensics guidelines?
Which security operation control enables checks and balances to reduce...
Which of the following is NOT associated with the access control...
Benefits of data standards include:
Which is true about link encryption?
Which of the following is NOT an information assurance strategy?
A Certificate Authority (CA) provides which benefits to a user?
During a disaster recovery test, several billing representatives need...
What are the two main testing strategies in software testing?
Which of the following can help with ensuring that only the needed...
What type of detected incident allows the most time for an...