Which of the following refers to a location away from the computer...
Which of the following is NOT a natural environmental threat that an...
Defining technology security architecture in relationship with other...
Which layer is not part of the OSI model?
Encryption is converting a message from ciphertext to plaintext.
Remote Access does what of the following?
The doors of a data center spring open in the event of a fire....
When outsourcing IT systems
Define and detail the aspects of password selection that distinguish...
Test outputs should be compared against expected outputs.
It can be said that IPSec
A botnet can be characterized as
__________ requires that a user of process be granted access to only...
Effective security management:
The major benefit of information classification is to
A disadvantage of single sign-on is
The integrity of a forensic bit stream image is determined by:
To maintain the security architecture, of the following, which is...
Modifying identifying information so as to make communication appear...
The monitoring of outbound network traffic for indicators of...
When sensitive information is no longer critical but still within...
The best way to ensure that there is no data remanence of sensitive...
Which of the following terms refers to a mechanism which proves that...
Polyalphabetic encryption techniques use multiple alphabets for each...
Role-based access control
What is not mentioned as a phase of an incident response?
Which of the following is the technology of indoor environmental...
Which one is a benefit of a enterprise security architecture?
NIST identifies three service models that represent different types of...
A new installation requires a network in a heavy manufacturing area...
Which of the following ensures constant redundancy and...
The strategy of forming layers of protection around an asset or...
Which of the following BEST describe three separate functions of CCTV?
What type of risk remains after the implementation of new or enhanced...
An emerging concept of highly-interconnected physical devices with...
A guard dog patrolling the perimeter of a data center is what type of...
Assuming a working IDS is in place, which of the following groups is...
Which of the following is most likely to detect DoS attacks?
Which one of the following is a common system component in the system...
Before applying a software update to production systems, it is MOST...
Which of the following is the technology of indoor environmental...
Within the realm of IT security, which of the following combinations...
Which of the following methods is not acceptable for exercising the...
The vast majority of Virtual Private Networks use
A potential vulnerability of the Kerberos authentication server is
In which of the following alternative site configurations is the...
Attempting to crack a password by using common words from a text file...
Which of the following uses a Key Distribution Center (KDC) to...
Which of the following terms BEST describes the effort to determine...
The best way to ensure that there is no data remanence of sensitive...
Which of the following security standards is internationally...
Which of the following is responsible for maintaining certificates in...
Which regulatory guidance pertains to any company that is publicly...
A customer requests to connect their LAN to the internet. Which of the...
What type of malware uses social engineering to trick a victim into...
What type of analysis emphasizes the formal study of what your...
Recently passed over for an executive promotion, Carol is anxious to...
Which of the following describes the type of anti-virus software that...
The only cipher system said to be unbreakable by brute force is
Which of the following is not a characteristic of continuous...
Which of the following end-point devices would MOST likely be...
When malware infects a host and allows it to be used in a botnet for...
Data access decisions are best made by:
Since 9/11, airport parking garages now keep cars further away from...
When a certificate is revoked, what is the proper procedure?
What are the three types of access control?
Many organizations purchase insurance policies to provide various...
What is the best protection measure against unauthorized access to...
Wi-Fi Protected Access (WPA-2) uses Advanced Encryption Standard (AES)...
Network information services (NIS) are used for what processes?
Security awareness training includes:
Which one do you like?
Asymmetric key cryptography is used for the following:
Authentication is
Which of the following is part of the five rules of evidence?
Which of the following is NOT a consideration when choosing data...
Management should decide when a system should be returned to...
Which of the following forms of attack can be used to disrupt even the...
What protocol solicits MAC address from devices on the network without...
Which of the following is MOST important for successful business...
When sensitive information is no longer critical but still within...
Which of the following BEST determines the employment suitability of...
How are smart cards and memory cars functionally different?
Which of the following supports asymmetric key cryptography?
Which of the following is correct about dynamic testing?
Which is a fundamental disadvantage of biometrics?
The main difference between a Security Event Information Management...
What is the BEST means of protecting the physical devices associated...
Which of the following is true about maintaining the chain of custody...
Which of the following categories of access control implementation...
Before applying a software update to production systems, it is MOST...
Ann installs a new Wireless Access Point (WAP) and users are able to...
Administrative law is concerned with confining government power,...
Which of the following attacks allow bypassing access control lists on...
Collusion is best mitigated by:
Sam is a software developer and has recently gone through secure...
Which is the BEST choice for implementing encryption on a smart card?
To ensure proper forensics action when needed, an incident response...
Which cable has a relatively low-speed transmission medium consisting...
Managing the dialogue between two or more communicating devices is...
Which protocol offers native encryption capability, for both...
Which intrusion detection system's efficiency decreases with...
A Security Event Management (SEM) service performs the following...
Which of the following is not one of the four typical elements of a...
Protection practices that can be used to prevent man-in-the middle...
Single loss expectancy (SLE) is calculated by using:
Which of the following steps should be performed first in a business...
Sam is a software developer and has recently gone through secure...
Which of the following is the primary desired result of any...
What is the output length of a RIPEMD-160 hash?
What is the optimal placement for network-based intrusion detection...
Multi-layer protocols such as Modbus used in industrial control...
A Service Organization Control (SOC) Report commonly covers a
The key to a successful physical protection system is the integration...
Which of the following processes identifies the threats that can...
Which type of law is derived from court decisions and codification of...
Well-written security program policies are BEST reviewed:
A service's recovery point objective is zero. Which approach...
The (ISC)2 code of ethics resolves conflicts between canons by:
Good data management practices include:
Formal acceptance of an evaluated system by management is known as:
What are the seven main categories of access control?
At a restricted facility, visitors are requested to provide...
Cross-functional teams formed to conceptualize, design, test, produce,...
Of the following plans, which is designed to protect critical business...
Which one of the following describes the Information Technology...
Your office is implementing an access control policy based on...
Users are reporting that some Internet websites are not accessible...
What are types of failures in biometric identification systems?
What would be the most appropriate interior sensor used for a building...
Which of the following electronically stored information (ESI) are not...
A basic component of an industrial control system (ICS) that is most...
What are the FOUR phases of the equipment lifecycle?
Which of the following can BEST be used to capture detailed security...
In the OSI reference model, on which layer can Ethernet (IEEE 802.3)...
Frame Relay and X.25 networks are part of which of the following?
A hard drive is recovered from a submerged vehicle. The drive is...
Substitution is mixing the location of plaintext throughout the...
Laws designed to protect individuals' privacy have been created...
All of the following is true about trade secrets EXCEPT:
Which one of the following is NOT a common security service in the...
Which of the following is not a form of identification?
Wireless transmission technologies include all of the following...
Information systems auditors help the organization:
Which of the following statements BEST describes the extent to which...
An accurate picture of the use and acceptance of biometrics is:
In mandatory access control the system controls access and the owner...
Which of the following is incorrect when considering privilege...
Triage encompasses which of the following incident response...
Which one of the following is designed to protect the goodwill and...
All of the following describes link encryption except:
Which network topology's use of tokens allows prediction of node...
Which phrase best defines a business continuity/disaster recovery...
Computer forensics is the marriage of computer science, information...
Which of the following approaches for identifying appropriate BIA...
What is an important disadvantage of using a public key algorithm...
Which of the following BEST describes fundamental methods of...
If speed is preferred over resilience, which of the following RAID...
What is the minimum and customary practice of responsible protection...
Each distinguished name (DN) in an LDAP directory represents a...
What is access control?
A customer wants to keep cost to a minimum and has only ordered a...
When the backup window is not long enough to backup all of the data...
Which of the following is a software protection mechanism where all...
What is the last phase of the TCP/IP three-way handshake sequence?
Which of the following vulnerabilities would best be countered by...
Information will not be disclosed to any unauthorized person on a...
Security is likely to be most expensive when addressed in which phase?
Audit trails, logs, CCTV, intrusion detection systems, antivirus...
With public key cryptography, confidential messages with proof of...
Which of the following models ensures that a subject with a clearance...
Which of the following ISO standards provides the evaluation criteria...
ANSI X9.17 is concerned primarily with
The NIST document that discusses the Information Security Continuous...
Which of the following processes is concerned with not only...
When dealing with digital evidence, the chain of custody:
To which legal and regulatory requirement are all organizations...
Building security into the application begins at _____________.
Which of the following layers of the OSI model offer non-repudiation...
The BEST reason to implement additional controls or safeguards is to:
In the event of a security incident, one of the primary objectives of...
Hamid is reviewing identity management (IDM) products for his...
Which of the following evaluation assurance level that is formally...
Which of the following BEST provides a method of quantifying risks...
Which one of the following is true about the criminal law?
Setting clear security roles has the following benefits:
Which of the following is a principal security risk of wireless LANs?
Which is BEST emphasizes the abstract concepts of law and is...
Which of the following is NOT associated with the access control...
The elements of risk are as follows:
Benefits of data standards include:
Which is true about link encryption?
During a disaster recovery test, several billing representatives need...
Which of the following are computer forensics guidelines?
Which security operation control enables checks and balances to reduce...
Which of the following is NOT an information assurance strategy?
A Certificate Authority (CA) provides which benefits to a user?
A two-dimensional grouping of individual subjects into groups or roles...
A system administrator grants rights to a group of individuals called...
Real User Monitoring (RUM) is an approach to Web monitoring that