CISSP Practice Test — Questions and Answers
Question 1: Which statement is most accurate if one of your responsibilities is to manually monitor audit logs to detect suspicious activity, as stated in your job description?
- This particular job duty is a compensating control for the audit logs themselves
- The mechanism that creates audit logs is a technical control that supplements manual processes (Correct answer)
- The audit logs are a compensating control for the detection of malicious activity
- The audit logs are a detective control when combined with review processes
Correct answer: The mechanism that creates audit logs is a technical control that supplements manual processes
The mechanism that creates audit logs is a technical control, as it's a system or software component designed to perform a security function. While audit logs themselves are a detective control, the act of manually monitoring them is a procedural control. Therefore, the technical control (log creation) provides the necessary data that supplements and enables the manual review process.
Question 2: To authenticate the company's public users, your CIO wishes to employ Lightweight Directory Access Protocol (LDAP). The following should be your initial consideration:
- Whether the considered version of LDAP has sufficient support for transport layer security (Correct answer)
- Whether the software can support LDAP using a hierarchical tree structure
- Whether the Domain Component (DC) is included in the entry
- Whether the LDAP entry includes the appropriate Common Name (CN)
Correct answer: Whether the considered version of LDAP has sufficient support for transport layer security
When using LDAP for authenticating public users, the primary concern should be the security of the credentials and data transmitted. LDAP itself is not inherently secure, so ensuring that the version considered has sufficient support for Transport Layer Security (TLS) or Secure Sockets Layer (SSL) is critical. This encryption protects the authentication process from eavesdropping and man-in-the-middle attacks, safeguarding user information.
Question 3: Configuration management is most likely handled during which phase (s) of the asset lifecycle?
- Secure, Monitor
- Identify and classify, Secure
- Secure (Correct answer)
- Monitor, Recover
Correct answer: Secure
Configuration management is the systematic process of managing changes to a system's configuration to maintain its integrity, security, and performance. While it impacts all phases, it is most critically handled during the 'Secure' phase of the asset lifecycle. This is where controls are implemented, maintained, and updated to protect the asset from unauthorized access, use, disclosure, disruption, modification, or destruction, ensuring its ongoing security posture.
Question 4: To acquire access to a database and begin his work as an administrator, Jeffrey utilizes a secret code. He must also offer a thumbprint, a retina scan, and the system checks the position of his terminal's authentication. What is most likely being described?
- Since there are four categories provided and three itemized provisions, this is a form of type 3 authentication
- Since there are four items required and three categories provided, this is a form of multi-factor authentication (Correct answer)
- Since there are four items provided and three categories of factors, this is a form of hybrid authentication
- Since there are two biometrics, one item of knowledge, and a location based factor, this is a form of tri-factor authentication
Correct answer: Since there are four items required and three categories provided, this is a form of multi-factor authentication
Multi-factor authentication (MFA) requires a user to provide two or more distinct authentication factors from different categories. Jeffrey uses 'something he knows' (secret code), 'something he is' (thumbprint, retina scan - biometrics), and 'where he is' (terminal's position). Since these factors belong to different categories, this scenario clearly describes multi-factor authentication, enhancing security beyond a single factor.
Question 5: Both the principal and mirror sites of Astrotek Company have recently gone down due to an unplanned outage. The outage will last at least three weeks, according to officials. What is the first category of items you should check for while reviewing the contingency plan?
- Reconstitution steps to the warm site that exceed the maximum allowable downtime
- Recovery steps to the hot site within the given recovery time objective
- Recovery steps to the alternate site within the recovery time objective (Correct answer)
- Reconstitution steps to the cold site within the recovery point objective
Correct answer: Recovery steps to the alternate site within the recovery time objective
With both the principal and mirror sites down for an extended period, the company must activate its disaster recovery plan to an alternate site. The first category of items to check in the contingency plan would be the recovery steps to this alternate site. It is crucial to ensure these steps can be completed within the defined Recovery Time Objective (RTO), which dictates the maximum acceptable downtime for the business.
Question 6: A negative test is described by which of the following?
- Where the expected result is a graceful rejection of data without crashing the application
- Providing evidence of application behavior when unexpected or invalid data is used
- Where the application fails a test if it does not provide the expected result (Correct answer)
- An attempt to provoke an application’s failure
Correct answer: Where the application fails a test if it does not provide the expected result
Personnel security focuses on ensuring that individuals with access to sensitive information or systems are trustworthy and that their access is appropriately managed. Detailed job descriptions, non-disclosure agreements, and employment contracts are all direct tools or elements of personnel security. A current revision of an employee handbook that has not been released, however, is a document management issue, not an active control or concern related to an individual's trustworthiness or access management.
Question 7: You receive a message from Jeff. On his message, the cryptosystem does a hash. After that, Jeff's private key is used to encrypt the digest. This method is most likely to describe:
- Jeff’s digital signature that may have used a weak hashing algorithm (Correct answer)
- A messaging system with strong cryptographic solutions and possibly weak hashing algorithms
- An asymmetric cryptosystem with public and non-public keys
- A digital hashing system with strong digests and collision resistant algorithms
Correct answer: Jeff’s digital signature that may have used a weak hashing algorithm
The process described—hashing a message and then encrypting the digest with a private key—is the standard method for creating a digital signature. This signature provides authenticity and integrity. The mention of a 'weak hashing algorithm' highlights a potential vulnerability in the digital signature process, as a weak hash could be susceptible to collision attacks, undermining the integrity of the signature.
Question 8: What has most likely happened if a colleague uses publicly available information from social media to guess one of your system administrator's passwords and then takes classified information?
- Spoofing without repudiation or recourse
- Tampering, one of the damaging steps within the STRIDE model
- Escalation of privilege with non-repudiation
- Masquerading, where audit logs could still be useful (Correct answer)
Correct answer: Masquerading, where audit logs could still be useful
Masquerading occurs when an attacker successfully assumes the identity of an authorized user, in this case, a system administrator, by guessing their password. Even though the attacker is impersonating a legitimate user, audit logs would still record the actions performed under that administrator's account. These logs would be invaluable for detecting the intrusion, investigating the incident, and performing forensic analysis after the fact.
Question 9: The CIO asks for a solution to prevent digital squatting; the Board of Directors asks for a solution to safeguard digital rights; the CEO asks for a solution to safeguard intellectual property; and the CFO asks for a solution to safeguard digital real estate. Which of the following is only appropriate for one of the above requests?
- Implementing multiprotocol labeled switching
- Finding the appropriate security framework
- Employing a group of attorneys
- Using a digital rights management solution (Correct answer)
Correct answer: Using a digital rights management solution
Digital Rights Management (DRM) solutions are specifically designed to control access to, usage of, and distribution of copyrighted material and intellectual property in digital form. Therefore, a DRM solution is uniquely appropriate for safeguarding digital rights (Board of Directors' request) and intellectual property (CEO's request). While other options might be broadly related to security, DRM directly addresses these specific concerns.
Question 10: Which of the following does not belong in the category of personnel security?
- Current revision of the employee handbook that has not been released (Correct answer)
- Detailed job description with some missing elements
- Non disclosure agreement that fails to cite legal authority
- Employment contract with no signatures
Correct answer: Current revision of the employee handbook that has not been released
Senior management commitment is absolutely critical at the very beginning of the Business Continuity Plan (BCP) development process, during the Project Initiation phase. Without their explicit support, funding, and endorsement, the BCP project lacks the necessary resources, authority, and organizational buy-in to be successfully developed, implemented, and maintained throughout its lifecycle.
Question 11: The “State Machine Concept” security model stipulates that a system must be secure in all of its states (Startup, Function, and Shutdown) or it will not be secure. This requirement demands responding to security events in order to prevent further compromises. What security aspect is exemplified by this way of response?
- Closed Design
- Trusted Recovery (Correct answer)
- Least Privilege
- Open Design
Correct answer: Trusted Recovery
To proactively reduce the chance of an attacker gaining network access and sniffing data, the best strategy involves implementing preventative network security measures. Disabling unused switch ports and implementing MAC filtering prevents unauthorized devices from physically connecting. Additionally, software restriction policies prevent attackers from installing unauthorized sniffing tools. This combination directly addresses the threat at multiple layers, making it highly effective and preventative.
Question 12: The possibility of a user's private key becoming lost is a security problem when employing private keys. A practitioner can mitigate this risk by using a key recovery agent that can backup and recover his keys. Because another party has key access, granting a single individual the capacity to recover users' private keys increases the risk of nonrepudiation. Which of the following principles could be used to reduce the risk?
- Principle of least privilege
- Segregation of duties
- Need to know
- Dual control (Correct answer)
Correct answer: Dual control
Explanation: <br> Dual Control is a security principle that requires multiple parties to be present for a task that might have severe security implications. In this instance, it is likely best to have at least two network administrators present before a private key can be recovered. A subset of dual control is called M of N control. M and N are variables, but this control requires M out of a total of N administrators to be present to recover a key. Segregation of Duties is the concept of having more than one person required to complete a sensitive task. The principle of least privilege (PoLP) refers to an information security concept in which a user is given the minimum levels of access or permissions needed to perform his job functions. The need-to-know principle is that access to secured data must be necessary for the conduct of the users’ job functions.
Question 13: Because versions of OpenSSL were vulnerable to memory content read attempts, the Heartbleed virus recently compromised OpenSSL, resulting in the exposing of protected information, including services provider private keys. Many people believe that open design is preferable to closed design. What one factor is usually required for an open design to give increased security?
- Security through obscurity
- Trusted hierarchy
- Peer Review (Correct answer)
- The complexity of design
Correct answer: Peer Review
Explanation: <br> Open design is often thought to be better than closed design, as the openness allows for review from others in the community. The idea is that if others have access to the code, they will help examine and review the code, and ultimately improve it. That was not the case unfortunately with OpenSSL. If the code is not reviewed, it might as well be a closed source. Also, ultimately the quality of the code dictates the security, much more so than whether it is open or closed. Security through obscurity is the opposite of peer review and open design and could also be referred to as the complexity of the design. The hierarchical trust model is like an upside-down tree structure, the root is the starting point of trust. All nodes of the model have to trust the root CA and keep a root CA’s public-key certificate.
Question 14: At what point in the BCP development process must Senior Management commit to supporting, funding, and assisting the BCP's creation?
- Planning
- Implementation
- Development
- Project Initiation (Correct answer)
Correct answer: Project Initiation
Explanation: <br> Project Initiation is traditionally the phase in which senior management pledges its support for the project. Often in this phase, management provides a project charter, which is a formal written document in which the project is officially authorized, a project manager is selected and named, and management makes a commitment to support. Management’s BCP support must continue through the whole development process and include review and feedback as well as resources for the BCP to be successful.
Question 15: What's the best proactive (and least time-consuming) strategy to reduce the chance of an attacker acquiring network access and sniffing unencrypted data with a protocol analyzer?
- Scan the network periodically to determine if unauthorized devices are connected. If those devices are detected, disconnect them immediately, and provide management a report on the violation.
- Install anti-spyware software on all systems on the network.
- Implement a policy that forbids the use of packet analyzers/sniffers. Monitor the network frequently.
- Provide security such as disabling ports and mac filtering on the enterprise switches to prevent an unauthorized device from connecting to the network. Implement software restriction policies to prevent unauthorized software from being installed on systems. (Correct answer)
Correct answer: Provide security such as disabling ports and mac filtering on the enterprise switches to prevent an unauthorized device from connecting to the network. Implement software restriction policies to prevent unauthorized software from being installed on systems.
Explanation: <br> To significantly mitigate risks on the network, we have to implement security that limits connectivity to our network from external devices. Additionally, we are concerned with monitoring software being installed on our hosts, so we want to limit the ability of such software to be installed. Further, we want to ensure that other basic security requirements are satisfied, such as using strong passwords, lockout policies on systems, physical security, etc. <br> Remember: Proactive devices PREVENT an attack, as opposed to responding to it. Network scans often detect these devices, but they rarely prevent them. Policies describe high-level enterprise intentions which can then be implemented. Installing antispyware is a detective/corrective control, not a proactive/preventative one.
Question 16: The security of a system is determined by its individual components. The system's trust is a reflection of the components' trust. The __________ of the system refers to all of these parts.
- Operating System Kernel
- Firmware
- Ring 1 elements
- Trusted Computing Base (Correct answer)
Correct answer: Trusted Computing Base
The Trusted Computing Base (TCB) refers to the entire collection of hardware, firmware, and software components within a system that are critical to enforcing its security policy. If any part of the TCB is compromised, the security of the entire system is at risk. Therefore, the overall trust in a system is directly derived from the trustworthiness of all these underlying components working together.
Question 17: Social engineering attacks can be used to compromise security. Although training can help reduce the amount of attacks, it cannot completely eliminate the risk. Which of the following options is the most likely to assist lessen this risk?
- Job Rotation
- Formal Off-boarding Policies
- Segregation of Duties (Correct answer)
- Formal onboarding Policies
Correct answer: Segregation of Duties
Segregation of Duties (SoD) is a control that prevents a single individual from having complete control over a critical process or transaction. By requiring multiple people to complete different parts of a task, it significantly reduces the risk of fraud, error, or a successful social engineering attack. Even if one person is tricked, they cannot complete the malicious action alone, thus lessening the overall risk.
Question 18: Security measures must be matched with business goals, according to a fundamental security principle. Why is business alignment important when it comes to the influence security has on an organization's success?
- Security is cheap and easily implemented compared to the potential for loss. Security should be implemented everywhere possible.
- There is always a tradeoff for security, so an organization has to weigh the cost vs. benefits of the security measures. (Correct answer)
- Security is too costly to implement in small organizations.
- Security is so important that every organization must implement as much as possible.
Correct answer: There is always a tradeoff for security, so an organization has to weigh the cost vs. benefits of the security measures.
Security measures always involve a trade-off between protection, cost, and operational efficiency. Implementing excessive security can be prohibitively expensive and hinder business operations, while insufficient security leaves the organization vulnerable. Business alignment ensures that security investments are proportionate to the risks faced and support the organization's strategic goals and financial health, rather than impeding them.
Question 19: Trust and Assurance are two elements that are included in the evaluation scope when evaluating a system using the TCSEC and the more modern Common Criteria. Which of the following best describes assurance and trust?
- Assurance describes how secure the system is, while trust describes performance capabilities.
- Trust describes how secure the system is, while assurance describes performance capabilities.
- Assurance describes the function of the product, while trust describes the reliability of the process used to create the product.
- Trust describes the function of the product, while assurance describes the reliability of the process used to create the product. (Correct answer)
Correct answer: Trust describes the function of the product, while assurance describes the reliability of the process used to create the product.
In security evaluations like TCSEC and Common Criteria, 'trust' describes the confidence that a system will behave as expected and enforce its security policy, focusing on *what* the product does. 'Assurance,' on the other hand, refers to the degree of confidence that the system meets its security requirements through rigorous development, testing, and evaluation processes, focusing on *how* the product was built and verified. Together, they provide a comprehensive view of a system's security posture.
Question 20: The least acceptable security configuration for a given environment is referred to as a system's minimum security baseline. Before defining the MSB, the system must be classified according to the Confidentiality, Integrity, and Availability requirements of its data. What is the overall category of a system where the potential impact of unauthorized disclosure is "high," the impact of an integrity breach is "mid," and the impact of data being momentarily unavailable is "low"?
- Medium
- High (Correct answer)
- Medium-high
- Low
Correct answer: High
When categorizing a system based on Confidentiality, Integrity, and Availability (CIA) impacts, the overall system category is determined by the highest potential impact level across all three security objectives. In this scenario, the potential impact of unauthorized disclosure (Confidentiality) is 'high.' Therefore, the system's overall classification must be 'High' to ensure adequate protection for its most critical security aspect.
Question 21: Gilbert Vernam invented a way to provide theoretically unbreakable encryption using a one-time pad as a key in 1918. Which modern encryption technology is based on the Vernam Cipher's concepts?
- Session keys (Correct answer)
- The handshake process used by IPSec and numerous other frameworks
- Asymmetric Cryptography
- Digital Signatures that provide authenticity
Correct answer: Session keys
The Vernam Cipher, or one-time pad, achieves perfect secrecy by using a truly random key that is as long as the message and used only once. While impractical for most modern uses, its core principle of using a unique, random, and secret key for each communication instance is reflected in the concept of session keys. Session keys are temporary, unique symmetric keys generated for a single communication session, providing strong, ephemeral encryption for that specific exchange.
Question 22: A user receives an email that he or she believes came from a coworker. An attacker spoofed the email. What security services would have alerted you to the fact that the mail had been spoofed?
- Authorization
- Integrity
- Non-repudiation (Correct answer)
- Privacy
Correct answer: Non-repudiation
Non-repudiation provides undeniable proof of origin and integrity, preventing a sender from falsely denying they sent a message or that its content was altered. If an email were digitally signed, the recipient could verify the sender's identity and the message's integrity, thus detecting the spoofing attempt. Without non-repudiation, an attacker can easily forge the sender's address, as seen in email spoofing.
Question 23: The contents of mail communications are frequently encrypted using a symmetric technique, most typically AES. However, non-repudiation is achieved using a mix of hashing and an asymmetric algorithm. What is the process of non-repudiation?
- By encrypting the document with the sender’s public key, then hashing the document
- By encrypting the document with the sender’s private key, then hashing document
- By hashing the document then encrypting the hash with the receiver’s public key
- By hashing the document and then encrypting the hash with the sender’s private key (Correct answer)
Correct answer: By hashing the document and then encrypting the hash with the sender’s private key
To achieve non-repudiation, the sender first creates a hash (a unique digital fingerprint) of the document. This hash is then encrypted using the sender's *private* key, creating a digital signature. Anyone can then use the sender's *public* key to decrypt the hash and compare it to a newly generated hash of the document, verifying both the sender's identity and that the document hasn't been tampered with.
Question 24: The source contents of a message or file should not be revealed by reversing a hash. In a hashing algorithm, what provides the secrecy?
- A digital signature
- A public key
- A private key
- One-way math (Correct answer)
Correct answer: One-way math
Hashing algorithms are designed to be one-way functions, meaning it is computationally infeasible to reverse the process and derive the original input from the hash output. This 'one-way math' property ensures that the source content remains secret, as the hash value cannot be used to reconstruct the original data. This characteristic is fundamental to their use in integrity checks and password storage.
Question 25: What does a birthday attack imply?
- An attack that attempts to find collisions in separate messages. (Correct answer)
- An attack that focuses on personnel databases in an attempt to compromise personal information for the purpose of identity theft.
- An attack on passwords based on the idea that many users choose weak passwords based on personal information such as birthdays.
- A logic bomb that triggers on the date of the attacker’s birthday.
Correct answer: An attack that attempts to find collisions in separate messages.
A birthday attack exploits the mathematics behind the 'birthday paradox,' which states that in a relatively small group, there's a surprisingly high probability of two people sharing the same birthday. In cryptography, this translates to finding two different inputs that produce the same hash output (a collision) much faster than brute-forcing the entire hash space. This weakens the integrity provided by hashing functions.
Which statement is most accurate if one of your responsibilities is to manually monitor audit logs to detect suspicious activity,
as stated in your job description?