thinQmaster

Find your exam

Four questions free, before you decide.

Step 1 · choose a vendor

In one of our camps? Your practice exams come with the tuition — they are on your study page already.

thinQmaster — free preview

CISSP. Set it up and run it.

This is not a sample sheet — it is the application, running. Pick your mode, your length, your domain, the same way you would inside the full title. Study mode marks each answer and tells you why the right one is right and why each wrong one is wrong; Simulation puts a clock on it and chooses each question from whatever you are weakest in. No account, no e-mail address, no card.

Free · nothing to sign up for
thinQmaster engine · preview session

The four questions

1. The Widget Company decided to take their company public and while they were in the process of doing so had an external auditor come and look at their company. As part of the external audit they brought in a technology expert, who incidentally was a new CISSP. The auditor's expert asked to see their last risk analysis from the technology manager. The technology manager did not get back to him for a few days and then the Chief Financial Officer gave the auditors a 2 page risk assessment that was signed by both the Chief Financial Officer and the Technology Manager. While reviewing it, the auditor noticed that only parts of their financial data were being backed up on site and nowhere else; the Chief Financial Officer accepted the risk of only partial financial data being backed up with no off-site copies available. Who owns the risk with regards to the data that is being backed up and where it is stored?

  • A. Only the Chief Financial Officer
  • B. Only the most Senior Management such as the Chief Executive Officer
  • C. Both the Chief Financial Officer and Technology Manager
  • D. Only The Technology Manager

Correct answer: A. The chief financial officer (CFO) is a member of the board. The board members are responsible for setting the organization's strategy and risk appetite (how much risk the company should take on). In this question, the Chief Financial Officer accepted the risk of only partial financial data being backed up with no off-site copies available. The Chief Financial Officer therefore owns the risk.

Why the others are wrong. The most Senior Management such as the Chief Executive Officer does not own the risk. The Chief Financial Officer is responsible for company finances and accepted the risk. This means that the CFO owns the risk, not the CEO. The Technology Manager signed the risk assessment but he did not accept the risk.

2. In Mandatory Access Control, sensitivity labels attached to objects contain what information?

  • A. The item's classification
  • B. The item's classification and category set
  • C. The item's category
  • D. The items' need to know

Correct answer: B. Mandatory Access Control begins with security labels assigned to all resource objects on the system. These security labels contain two pieces of information - a classification (top secret, confidential etc.) and a category (which is essentially an indication of the management level, department or project to which the object is available). Similarly, each user account on the system also has classification and category properties from the same set of properties applied to the resource objects. When a user attempts to access a resource under Mandatory Access Control the operating system checks the user's classification and categories and compares them to the properties of the object's security label. If the user's credentials match the MAC security label properties of the object access is allowed. It is important to note that both the classification and categories must match. A user with top secret classification, for example, cannot access a resource if they are not also a member of one of the required categories for that object.

Why the others are wrong. In Mandatory Access Control, the sensitivity labels attached to objects contain a category set as well as the item's classification. In Mandatory Access Control, the sensitivity labels attached to objects contain the item's classification as well as a category. An item's need to know is not something that is included in the sensitivity label. The categories portion of the label is used to enforce need-to-know rules.

3. Which of the following is the preferred way to suppress an electrical fire in an information center?

  • A. CO2
  • B. CO2, soda acid, or Halon
  • C. water or soda acid
  • D. ABC Rated Dry Chemical

Correct answer: A. Class C fire extinguishers are used for fires involving electrical equipment. Class C fires are electrical fires which that may occur in electrical equipment or wiring. Class C fire extinguishers use gas, CO2 or dry powders as these extinguishing agents are non-conductive. Of the answers given, CO2 is the preferred way to suppress an electrical fire in an information center.

Why the others are wrong. Soda acid is corrosive. For this reason, it is not suitable for use in an information center. Therefore, this answer is incorrect. Soda acid is corrosive. For this reason, it is not suitable for use in an information center. Water is conductive which makes it unsuitable for electrical fires. Therefore, this answer is incorrect. ABC Rated Dry Chemical is corrosive. For this reason, it is not suitable for use in an information center. Therefore, this answer is incorrect.

4. Which of the following type of traffic can easily be filtered with a stateful packet filter by enforcing the context or state of the request?

  • A. ICMP
  • B. TCP
  • C. UDP
  • D. IP

Correct answer: B. The TCP protocol is stateful. In a TCP connection, the sender sends a SYN packet, the receiver sends a SYN/ ACK, and then the sender acknowledges that packet with an ACK packet. A stateful firewall understands these different steps and will not allow packets to go through that do not follow this sequence. So, if a stateful firewall receives a SYN/ACK and there was not a previous SYN packet that correlates with this connection, the firewall understands this is not right and disregards the packet. This is what stateful means--something that understands the necessary steps of a dialog session. And this is an example of context-dependent access control, where the firewall understands the context of what is going on and includes that as part of its access decision.

Why the others are wrong. A: The ICMP protocol is stateless, not stateful. C: The UDP protocol is stateless, not stateful. D: The IP protocol is stateless, not stateful.

5. The control measures that are intended to reveal the violations of security policy using software and hardware are associated with:

  • A. preventive/physical.
  • B. detective/technical.
  • C. detective/physical.
  • D. detective/administrative.

Correct answer: B. The detective/technical controls helps to identify an incident's activities and potentially an intruder using software or hardware components, which include Audit logs and IDS.

Why the others are wrong. Preventive/physical controls are meant to discourage a potential attacker using items put into place to protect facility, personnel, and resources. These items include locks, badge systems, security guards, biometric system, and mantrap doors. The detective/physical controls helps to identify an incident's activities and potentially an intruder using items put into place to protect facility, personnel, and resources. These items include motion detectors and closed- circuit TVs. The detective/administrative controls helps to identify an incident's activities and potentially an intruder using management-oriented controls, which include monitoring and supervising, job rotation, and investigations.

6. The Orange Book describes four hierarchical levels to categorize security systems. Which of the following levels require mandatory protection?

  • A. Verified protection
  • B. Mandatory protection
  • C. Discretionary protection
  • D. Minimal security

Correct answer: A. The U.S. Department of Defense developed the Trusted Computer System Evaluation Criteria (TCSEC), which was used to evaluate operating systems, applications, and different products. These evaluation criteria are published in a book known as the Orange Book. TCSEC provides a classification system that is divided into hierarchical divisions of assurance levels: Verified protection Mandatory protection Discretionary protection Minimal security Cassification A represents the highest level of assurance, and D represents the lowest level of assurance. Level B is the lowest level that requires mandatory protection. Level A, being a higher level also requires mandatory protection.

Why the others are wrong. Mandatory protection is not required for level C. Level C is Discretionary protection. Mandatory protection is not required for level C. Level C is Discretionary protection. Mandatory protection is not required for level D. Level D is Minimal security.

7. What are the four basic elements of Fire?

  • A. Heat, Fuel, Oxygen, and Chain Reaction
  • B. Heat, Fuel, CO2, and Chain Reaction
  • C. Heat, Wood, Oxygen, and Chain Reaction
  • D. Flame, Fuel, Oxygen, and Chain Reaction

Correct answer: A. The fire triangle or combustion triangle is a simple model for understanding the necessary ingredients for most fires. The triangle illustrates the three elements a fire needs to ignite: heat, fuel, and an oxidizing agent (usually oxygen). A fire naturally occurs when the elements are present and combined in the right mixture, meaning that fire is actually an event rather than a thing. A fire can be prevented or extinguished by removing any one of the elements in the fire triangle. For example, covering a fire with a fire blanket removes the oxygen part of the triangle and can extinguish a fire. The fire tetrahedron represents the addition of a component, the chemical chain reaction, to the three already present in the fire triangle. Once a fire has started, the resulting exothermic chain reaction sustains the fire and allows it to continue until or unless at least one of the elements of the fire is blocked. Foam can be used to deny the fire the oxygen it needs. Water can be used to lower the temperature of the fuel below the ignition point or to remove or disperse the fuel. Halon can be used to remove free radicals and create a barrier of inert gas in a direct attack on the chemical reaction responsible for the fire.

Why the others are wrong. CO2 is not one of the four basic elements of fire. CO2 is a fire suppressant. Therefore, this answer is incorrect. Wood is not one of the four basic elements of fire. Wood would be an example of the `fuel' element of fire. Therefore, this answer is incorrect. Flame is not one of the four basic elements of fire. Flame is just another name for fire. Therefore, this answer is incorrect.

8. When referring to the data structures of a packet, the term Protocol Data Unit (PDU) is used, what is the proper term to refer to a single unit of TCP data at the transport layer?

  • A. TCP segment.
  • B. TCP datagram.
  • C. TCP frame.
  • D. TCP packet.

Correct answer: A. In the OSI model layer 4 is the transport layer. In the TCP/IP model, Application Layer data is encapsulated in a Layer 4 TCP segment. That TCP segment is encapsulated in a Layer 3 IP packet. Data, segments, and packets are examples of Protocol Data Units (PDUs).

Why the others are wrong. B: TCP datagrams is not a notion that is used in the TCP/IP model. C: The TCP frame is at the Layer 2 Ethernet layer, not at the transport level which is layer 4. D: A TCP packet is at the application layer, not at the transport level.