for ISC2 certification, Real Success Guaranteed with Updated . 100% PASS CISSP-ISSEP Information Systems Security Engineering Professional exam Today!
Online CISSP-ISSEP free questions and answers of New Version:
NEW QUESTION 1
Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production
Each correct answer represents a part of the solution. Choose all that apply.
- A. Office of Management and Budget (OMB)
- B. NIST
- C. FISMA
- D. FIPS
Answer: C
NEW QUESTION 2
Which of the following is an Information Assurance (IA) model that protects and defends information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation
- A. Parkerian Hexad
- B. Five Pillars model
- C. Capability Maturity Model (CMM)
- D. Classic information security model
Answer: B
NEW QUESTION 3
Which of the following federal laws is designed to protect computer data from theft
- A. Federal Information Security Management Act (FISMA)
- B. Computer Fraud and Abuse Act (CFAA)
- C. Government Information Security Reform Act (GISRA)
- D. Computer Security Act
Answer: B
NEW QUESTION 4
The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment Each correct answer represents a part of the solution. Choose all that apply.
- A. Information Assurance Manager
- B. Designated Approving Authority
- C. Certification agent
- D. IS program manager
- E. User representative
Answer: BCDE
NEW QUESTION 5
Which of the following configuration management system processes keeps track of the changes so that the latest acceptable configuration specifications are readily available
- A. Configuration Identification
- B. Configuration Verification and Audit
- C. Configuration Status and Accounting
- D. Configuration Control
Answer: C
NEW QUESTION 6
Which of the following rated systems of the Orange book has mandatory protection of the TCB
- A. C-rated
- B. B-rated
- C. D-rated
- D. A-rated
Answer: B
NEW QUESTION 7
Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy
- A. Networks and Infrastructures
- B. Supporting Infrastructures
- C. Enclave Boundaries
- D. Local Computing Environments
Answer: C
NEW QUESTION 8
Which of the following organizations assists the President in overseeing the preparation of the federal budget and to supervise its administration in Executive Branch agencies
- A. NSACSS
- B. OMB
- C. DCAA
- D. NIST
Answer: B
NEW QUESTION 9
Fill in the blank with an appropriate phrase. seeks to improve the quality of process outputs by identifying and removing the causes of defects and variability in manufacturing and business processes.
- A. Six Sigma
Answer: A
NEW QUESTION 10
Which of the following are the functional analysis and allocation tools Each correct answer represents a complete solution. Choose all that apply.
- A. Functional flow block diagram (FFBD)
- B. Activity diagram
- C. Timeline analysis diagram
- D. Functional hierarchy diagram
Answer: ACD
NEW QUESTION 11
Which of the following roles is also known as the accreditor
- A. Data owner
- B. Chief Information Officer
- C. Chief Risk Officer
- D. Designated Approving Authority
Answer: D
NEW QUESTION 12
Which of the following tools demands involvement by upper executives, in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators
- A. ISO 90012000
- B. Benchmarking
- C. SEI-CMM
- D. Six Sigma
Answer: A
NEW QUESTION 13
Which of the following types of firewalls increases the security of data packets by remembering the state of connection at the network and the session layers as they pass through the filter
- A. Stateless packet filter firewall
- B. PIX firewall
- C. Stateful packet filter firewall
- D. Virtual firewall
Answer: C
NEW QUESTION 14
Which of the following federal laws are related to hacking activities Each correct answer represents a complete solution. Choose three.
- A. 18 U.S.
- B. 1030
- C. 18 U.S.
- D. 1029
- E. 18 U.S.
- F. 2510
- G. 18 U.S.
- H. 1028
Answer: ABC
NEW QUESTION 15
There are seven risk responses for any project. Which one of the following is a valid risk response for a negative risk event
- A. Acceptance
- B. Enhance
- C. Share
- D. Exploit
Answer: A
NEW QUESTION 16
Which of the following statements is true about residual risks
- A. It can be considered as an indicator of threats coupled with vulnerability.
- B. It is a weakness or lack of safeguard that can be exploited by a threat.
- C. It is the probabilistic risk after implementing all security measures.
- D. It is the probabilistic risk before implementing all security measures.
Answer: C
NEW QUESTION 17
Which of the following federal laws establishes roles and responsibilities for information security, risk management, testing, and training, and authorizes NIST and NSA to provide guidance for security planning and implementation
- A. Computer Fraud and Abuse Act
- B. Government Information Security Reform Act (GISRA)
- C. Federal Information Security Management Act (FISMA)
- D. Computer Security Act
Answer: B
NEW QUESTION 18
In which of the following phases of the interconnection life cycle as defined by NIST SP
800-47 does the participating organizations perform the following tasks Perform preliminary activities. Examine all relevant technical, security and administrative issues. Form an agreement governing the management, operation, and use of the interconnection.
- A. Establishing the interconnection
- B. Disconnecting the interconnection
- C. Planning the interconnection
- D. Maintaining the interconnection
Answer: C
NEW QUESTION 19
Which of the following policies describes the national policy on the secure electronic messaging service
- A. NSTISSP N
- B. 11
- C. NSTISSP N
- D. 7
- E. NSTISSP N
- F. 6
- G. NSTISSP N
- H. 101
Answer: B
NEW QUESTION 20
Fill in the blank with an appropriate phrase. The process is used for allocating performance and designing the requirements to each function.
- A. functional allocation
Answer: A
P.S. Easily pass CISSP-ISSEP Exam with 213 Q&As prep-labs.com Dumps & pdf Version, Welcome to Download the Newest prep-labs.com CISSP-ISSEP Dumps: https://www.prep-labs.com/dumps/CISSP-ISSEP/ (213 New Questions)