Our pass rate is high to 98.9% and the similarity percentage between our CISSP-ISSAP study guide and real exam is 90% based on our seven-year educating experience. Do you want achievements in the ISC2 CISSP-ISSAP exam in just one try? I am currently studying for the ISC2 CISSP-ISSAP exam. Latest ISC2 CISSP-ISSAP Test exam practice questions and answers, Try ISC2 CISSP-ISSAP Brain Dumps First.
NEW QUESTION 1
You have been assigned the task of selecting a hash algorithm. The algorithm will be specifically used to ensure the integrity of certain sensitive files. It must use a 128 bit hash value. Which of the following should you use?
- A. AES
- B. SHA
- C. MD5
- D. DES
Answer: C
NEW QUESTION 2
You work as a Chief Security Officer for Tech Perfect Inc. The company has an internal room without any window and is totally in darkness. For security reasons, you want to place a device in the room. Which of the following devices is best for that room?
- A. Photoelectric motion detector
- B. Badge
- C. Closed-circuit television
- D. Alarm
Answer: A
NEW QUESTION 3
Which of the following are man-made threats that an organization faces? Each correct answer represents a complete solution. Choose three.
- A. Theft
- B. Employee errors
- C. Strikes
- D. Frauds
Answer: ABD
NEW QUESTION 4
Which of the following is an entry in an object's discretionary access control list (DACL) that grants permissions to a user or group?
- A. Access control entry (ACE)
- B. Discretionary access control entry (DACE)
- C. Access control list (ACL)
- D. Security Identifier (SID)
Answer: A
NEW QUESTION 5
Which of the following two cryptography methods are used by NTFS Encrypting File System (EFS) to encrypt the data stored on a disk on a file-by-file basis?
- A. Twofish
- B. Digital certificates
- C. Public key
- D. RSA
Answer: BC
NEW QUESTION 6
Which of the following backup types backs up files that have been added and all data that have been modified since the most recent backup was performed?
- A. Differential backup
- B. Incremental backup
- C. Daily backup
- D. Full backup
Answer: B
NEW QUESTION 7
Which of the following firewalls inspects the actual contents of packets?
- A. Packet filtering firewall
- B. Stateful inspection firewall
- C. Application-level firewall
- D. Circuit-level firewall
Answer: C
NEW QUESTION 8
You are the Security Administrator for a consulting firm. One of your clients needs to encrypt traffic. However, he has specific requirements for the encryption algorithm. It must be a symmetric key block cipher. Which of the following should you choose for this client?
- A. PGP
- B. SSH
- C. DES
- D. RC4
Answer: C
NEW QUESTION 9
Which of the following protocols is designed to efficiently handle high-speed data over wide area networks (WANs)?
- A. PPP
- B. X.25
- C. Frame relay
- D. SLIP
Answer: C
NEW QUESTION 10
Which of the following can be configured so that when an alarm is activated, all doors lock and the suspect or intruder is caught between the doors in the dead-space?
- A. Man trap
- B. Biometric device
- C. Host Intrusion Detection System (HIDS)
- D. Network Intrusion Detection System (NIDS)
Answer: A
NEW QUESTION 11
Which of the following is the technology of indoor or automotive environmental comfort?
- A. HIPS
- B. HVAC
- C. NIPS
- D. CCTV
Answer: B
NEW QUESTION 12
Which of the following ports must be opened on the firewall for the VPN connection using Point-to- Point Tunneling Protocol (PPTP)?
- A. TCP port 110
- B. TCP port 443
- C. TCP port 5060
- D. TCP port 1723
Answer: D
NEW QUESTION 13
In which of the following cryptographic attacking techniques does an attacker obtain encrypted messages that have been encrypted using the same encryption algorithm?
- A. Chosen plaintext attack
- B. Ciphertext only attack
- C. Chosen ciphertext attack
- D. Known plaintext attack
Answer: B
NEW QUESTION 14
Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective. Which of the following types of hardware devices will Adam use to implement two-factor authentication?
- A. Biometric device
- B. One Time Password
- C. Proximity cards
- D. Security token
Answer: D
NEW QUESTION 15
Which of the following attacks allows the bypassing of access control lists on servers or routers, and helps an attacker to hide? Each correct answer represents a complete solution. Choose two.
- A. DNS cache poisoning
- B. MAC spoofing
- C. IP spoofing attack
- D. DDoS attack
Answer: BC
NEW QUESTION 16
Which of the following is an infrastructure system that allows the secure exchange of data over an unsecured network?
- A. PMK
- B. PTK
- C. PKI
- D. GTK
Answer: C
NEW QUESTION 17
At which of the following layers of the Open System Interconnection (OSI) model the Internet Control Message Protocol (ICMP) and the Internet Group Management Protocol (IGMP) work?
- A. The Physical layer
- B. The Data-Link layer
- C. The Network layer
- D. The Presentation layer
Answer: C
NEW QUESTION 18
Which of the following life cycle modeling activities establishes service relationships and message exchange paths?
- A. Service-oriented logical design modeling
- B. Service-oriented conceptual architecture modeling
- C. Service-oriented discovery and analysis modeling
- D. Service-oriented business integration modeling
Answer: A
NEW QUESTION 19
Which of the following is a correct sequence of different layers of Open System Interconnection (OSI) model?
- A. Physical layer, data link layer, network layer, transport layer, presentation layer, session layer, and application layer
- B. Physical layer, network layer, transport layer, data link layer, session layer, presentation layer, and application layer
- C. application layer, presentation layer, network layer, transport layer, session layer, data link layer, and physical layer
- D. Physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer
Answer: D
NEW QUESTION 20
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of the disaster. In which of the following disaster recovery tests can this task be performed?
- A. Full-interruption test
- B. Parallel test
- C. Simulation test
- D. Structured walk-through test
Answer: C
NEW QUESTION 21
What are the benefits of using AAA security service in a network? Each correct answer represents a part of the solution. Choose all that apply.
- A. It provides scalabilit
- B. It supports a single backup syste
- C. It increases flexibility and control of access configuratio
- D. It supports RADIUS, TACACS+, and Kerberos authentication method
Answer: ACD
NEW QUESTION 22
Which of the following types of attack can be used to break the best physical and logical security mechanism to gain access to a system?
- A. Social engineering attack
- B. Cross site scripting attack
- C. Mail bombing
- D. Password guessing attack
Answer: A
NEW QUESTION 23
Fill in the blank with the appropriate security device. ____ is a device that contains a physical mechanism or electronic sensor that quantifies motion that can be either integrated with or connected to other devices that alert the user of the presence of a moving object within the field of view.
- A. Motion detector
Answer: A
NEW QUESTION 24
Which of the following are used to suppress electrical and computer fires? Each correct answer represents a complete solution. Choose two.
- A. Halon
- B. Water
- C. CO2
- D. Soda acid
Answer: AC
NEW QUESTION 25
Which of the following authentication methods provides credentials that are only valid during a single session?
- A. Kerberos v5
- B. Smart card
- C. Certificate
- D. Token
Answer: D
NEW QUESTION 26
Which of the following methods for identifying appropriate BIA interviewees' includes examining the organizational chart of the enterprise to understand the functional positions?
- A. Executive management interviews
- B. Overlaying system technology
- C. Organizational chart reviews
- D. Organizational process models
Answer: C
NEW QUESTION 27
Which of the following tenets does the CIA triad provide for which security practices are measured? Each correct answer represents a part of the solution. Choose all that apply.
- A. Integrity
- B. Accountability
- C. Availability
- D. Confidentiality
Answer: ACD
NEW QUESTION 28
You are responsible for security at a hospital. Since many computers are accessed by multiple employees 24 hours a day, 7 days a week, controlling physical access to computers is very difficult. This is compounded by a high number of non employees moving through the building. You are concerned about unauthorized access to patient records. What would best solve this problem?
- A. The use of CHA
- B. Time of day restriction
- C. The use of smart card
- D. Video surveillance of all computer
Answer: C
NEW QUESTION 29
You are responsible for security at a defense contracting firm. You are evaluating various possible encryption algorithms to use. One of the algorithms you are examining is not integer based, uses shorter keys, and is public key based. What type of algorithm is this?
- A. Symmetric
- B. None - all encryptions are integer base
- C. Elliptic Curve
- D. RSA
Answer: C
NEW QUESTION 30
......
P.S. Easily pass CISSP-ISSAP Exam with 237 Q&As Certifytools Dumps & pdf Version, Welcome to Download the Newest Certifytools CISSP-ISSAP Dumps: https://www.certifytools.com/CISSP-ISSAP-exam.html (237 New Questions)