[Jul-2026] Latest ISC CISSP exam dumps and online Test Engine
ISC CISSP: Selling ISC Certification Products and Solutions
NEW QUESTION # 75
You wish to make use of "port knocking" technologies. How can you BEST explain this?
- A. This is where all the ports are open on the server and the connecting client scans the open port to which he wants to connect to see if it's open and running.
- B. Port knocking is where the client will attempt to connect to a predefined set of ports to identify him as an authorized client.
- C. Port knocking is where the port sequence is encrypted with 3DES and only the server has the other key to decrypt the port sequence.
- D. Port knocking is where the user calls the server operator to have him start the service he wants to connect to.
Answer: B
Explanation:
The answer: Port
knocking is where the client will attempt to connect to a
predefined set of ports to identify him as an authorized client. The port knocking sequence is used
to identify the client as a legitimate user.
The other answers are incorrect
The following reference(s) were/was used to create this question:
http://www.portknocking.org/
NEW QUESTION # 76
In order to defend against unauthorized external users gaining access, a network design should contain which of the following?
- A. Host-Based Intrusion Detection System (HIDS)
- B. Physical Separation
- C. Gateway Authentication
- D. Spanning Tree Protocol (STP)
Answer: B
NEW QUESTION # 77
In the network design below, where is the MOST secure Local Area Network (LAN) segment to deploy a Wireless Access Point (WAP) that provides contractors access to the Internet and authorized enterprise services?
Answer:
Explanation:
Explanation
LAN 4
NEW QUESTION # 78
Which of the following would BEST support effective testing of patch compatibility when patches are applied to an organization's systems?
- A. Automated system patching
- B. Standardized configurations for devices
- C. Management support for patching
- D. Standardized patch testing equipment
Answer: B
Explanation:
Explanation
Section: Security Assessment and Testing
NEW QUESTION # 79
A packet filtering firewall looks at the data packet to get information about the source and destination addresses of an incoming packet, the protocol (TCP, UDP, or ICMP), and the source and destination port for the:
- A. delayed service.
- B. desired service.
- C. dedicated service.
- D. distributed service.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Packet filtering is a firewall technology that makes access decisions based upon network-level protocol header values. The filters can make access decisions based upon the following basic criteria:
Source and destination port numbers (such as an application port or a service number)
Protocol types
Source and destination IP addresses
Inbound and outbound traffic direction
Incorrect Answers:
B: A packet filtering firewall can grant access to desired services, not dedicated services, through source and destination numbers.
C: A packet filtering firewall can grant access to desired services, not delayed services, through source and destination numbers.
D: A packet filtering firewall can grant access to desired services, not distributed services, through source and destination numbers.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 630
NEW QUESTION # 80
Which conceptual approach to intrusion detection system is the MOST common?
- A. Knowledge-based intrusion detection
- B. Host-based intrusion detection
- C. Behavior-based intrusion detection
- D. Statistical anomaly-based intrusion detection
Answer: A
Explanation:
Explanation/Reference:
Explanation:
An IDS can detect malicious behavior using two common methods. One way is to use knowledge-based detection which is more frequently used. The second detection type is behavior-based detection.
Incorrect Answers:
A: behavior-based detection is less common compared to knowledge-based detection.
C: A Statistical anomaly-based IDS is a behavioral-based system.
D: Host-based intrusion detection is not a conceptual iDS approach. The two conventional approaches are knowledge-based detection and behavior-based detection.
References:
Stewart, James M., Ed Tittel, and Mike Chapple, CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition, Sybex, Indianapolis, 2011, p. 56
NEW QUESTION # 81
Why does fiber optic communication technology have significant security advantage over other transmission technology?
- A. Single and double-bit errors are correctable.
- B. Higher data rates can be transmitted.
- C. Interception of data traffic is more difficult.
- D. Traffic analysis is prevented by multiplexing.
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Because fiber-optic cable passes electrically non-conducting photons through a glass medium, it is very hard to intercept or wiretap.
Incorrect Answers:
A: High data rates are an advantage of fiber options, but speed in itself does not significantly increase speed.
C: Multiplexing would not prevent traffic analysis. It would just make it harder.
D: Correctable bits are not an advantage of fiber optic communication.
NEW QUESTION # 82
Which of the following is not a responsibility of an information (data) owner?
- A. Periodically review the classification assignments against business needs.
- B. Running regular backups and periodically testing the validity of the backup data.
- C. Determine what level of classification the information requires.
- D. Delegate the responsibility of data protection to data custodians.
Answer: B
Explanation:
This responsibility would be delegated to a data custodian rather than being
performed directly by the information owner.
"Determine what level of classification the information requires" is incorrect. This is one of the
major responsibilities of an information owner.
"Periodically review the classification assignments against business needs" is incorrect. This is
one of the major responsibilities of an information owner.
"Delegates responsibility of maintenance of the data protection mechanisms to the data custodian"
is incorrect. This is a responsibility of the information owner.
References:
CBK p. 105.
AIO3, p. 53-54, 960
NEW QUESTION # 83
At which layer of the Open Systems Interconnection (OSI) model does a circuit-level firewall operate?
- A. Session layer
- B. Network layer
- C. Transport layer
- D. Application layer
Answer: A
Explanation:
Circuit-level firewalls operate at the Session layer (Layer 5) of the OSI model rather than the Network layer (Layer 3) .
NEW QUESTION # 84
Which one of the following is NOT a fundamental component of a Regulatory Security Policy?
- A. When it is to be done.
- B. What is to be done.
- C. Why is it to be done
- D. Who is to do it.
Answer: D
Explanation:
Regulatory Security policies are mandated to the organization but it up to them to implement it. "Regulatory - This policy is written to ensure that the organization is following standards set by a specific industry and is regulated by law. The policy type is detailed in nature and specific to a type of industry. This is used in financial institutions, health care facilities, and public utilities." -Shon Harris All-in-one CISSP Certification Guide pg 93-94
NEW QUESTION # 85
Refer to the information below to answer the question.
An organization experiencing a negative financial impact is forced to reduce budgets and the number of Information Technology (IT) operations staff performing basic logical access security administration functions. Security processes have been tightly integrated into normal IT operations and are not separate and distinct roles.
When determining appropriate resource allocation, which of the following is MOST important to monitor?
- A. Number of system compromises
- B. Number of additional assets
- C. Number of audit findings
- D. Number of staff reductions
Answer: A
Explanation:
The most important factor to monitor when determining appropriate resource allocation is the number of system compromises. The number of system compromises is the count or the frequency of the security incidents or breaches that affect the confidentiality, the integrity, or the availability of the system data or functionality, and that are caused by the unauthorized or the malicious access or activity. The number of system compromises can help to determine appropriate resource allocation, as it can indicate the level of security risk or threat that the system faces, and the level of security protection or improvement that the system needs. The number of system compromises can also help to evaluate the effectiveness or the efficiency of the current resource allocation, and to identify the areas or the domains that require more or less resources. Number of audit findings, number of staff reductions, and number of additional assets are not the most important factors to monitor when determining appropriate resource allocation, as they are related to the results or the outcomes of the audit process, the changes or the impacts of the staff size, or the additions or the expansions of the system resources, not the security incidents or breaches that affect the system data or functionality.
NEW QUESTION # 86
A business continuity plan is an example of which of the following?
- A. Compensating control
- B. Corrective control
- C. Preventive control
- D. Detective control
Answer: B
Explanation:
Business Continuity Plans are designed to minimize the damage done by the event,
and facilitate rapid restoration of the organization to its full operational capacity. They are for use
"after the fact", thus are examples of corrective controls.
Reference(s) used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of
Computer Security, John Wiley & Sons, 2001, Chapter 8: Business Continuity Planning and
Disaster Recovery Planning (page 273).
and
Conrad, Eric; Misenar, Seth; Feldman, Joshua (2012-09-01). CISSP Study Guide (Kindle Location
8069). Elsevier Science (reference). Kindle Edition.
and
NEW QUESTION # 87
Which of the following disaster recovery test plans will be MOST effective while providing minimal risk?
- A. Full interruption
- B. Read-through
- C. Parallel
- D. Simulation
Answer: C
NEW QUESTION # 88
To control access by a subject (an active entity such as individual or process) to an object (a passive entity such as a file) involves setting up:
- A. Identification controls
- B. Access Matrix
- C. Access terminal
- D. Access Rules
Answer: D
Explanation:
Controlling access by a subject (an active entity such as individual or process) to an object (a passive entity such as a file) involves setting up access rules.
These rules can be classified into three access control models: Mandatory, Discretionary, and Non-Discretionary.
An access matrix is one of the means used to implement access control.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 33
NEW QUESTION # 89
Which of the following BEST describes the purpose of "Egress Point Certificate Pinning" in mobile application security?
- A. To encrypt data stored locally on the device
- B. To restrict an application to trust only a specific, pre-defined certificate or public key when establishing a secure connection, mitigating man-in-the-middle attacks even if a rogue CA-issued certificate is presented
- C. To store user passwords securely on the device
- D. To prevent an application from accessing the device's camera
Answer: B
Explanation:
Certificate pinning restricts a mobile (or other) application to trust only a specific, pre-defined certificate or public key for a given server, rather than any certificate signed by a trusted CA. This mitigates man-in-the-middle attacks that rely on a fraudulently issued or compromised CA certificate, since the pinned application will reject any certificate that does not match the expected pin.
NEW QUESTION # 90
Which of the following is not appropriate in addressing object reuse?
- A. Clearing buffered pages, documents, or screens from the local memory of a terminal or printer.
- B. Degaussing magnetic tapes when they're no longer needed.
- C. Deleting files on disk before reusing the space.
- D. Clearing memory blocks before they are allocated to a program or data.
Answer: C
Explanation:
Object reuse requirements, applying to systems rated TCSEC C2 and above, are used to protect files, memory, and other objects in a trusted system from being accidentally accessed by users who are not authorized to access them. Deleting files on disk merely erases file headers in a directory structure. It does not clear data from the disk surface, thus making files still recoverable. All other options involve clearing used space, preventing any unauthorized access.
Source: RUSSEL, Deborah & GANGEMI, G.T. Sr., Computer Security Basics, O'Reilly,
July 1992 (page 119).
NEW QUESTION # 91
A security engineer is conducting an audit of an organization's Voice over Internet Protocol (VoIP) phone network due to a large increase in charges from their phone provider. The engineer discovers unauthorized endpoints have connected to the phone server from the public internet and placed hundreds of unauthorized calls to parties around the globe. Which type of attack occurred?
- A. Control eavesdropping
- B. Address spoofing
- C. Toll fraud
- D. Call hijacking
Answer: C
NEW QUESTION # 92
The main categories of access control do NOT include:
- A. Physical Access Control
- B. Logical Access Control
- C. Administrative Access Control
- D. Random Access Control
Answer: D
Explanation:
There are several different categories of access control. The main categories are: --Physical Access Control --Administrative Access Control --Logical Access Control --Data Access Control
NEW QUESTION # 93
In which phase of the System Development Lifecycle (SDLC) is Security Accreditation Obtained?
- A. Postinstallation Phase
- B. Functional Requirements Phase
- C. Acceptance Phase
- D. Testing and evaluation control
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Within the SDLC framework Security Accreditation is obtained during the Implementation Phase, more specifically during Testing and evaluation control.
Incorrect Answers:
A: Security Accreditation is not used during the Functional Requirements Phase. It is used later during the Implementation phase.
C: Security Accreditation is not used during the Acceptance Phase. It is used earlier during the Implementation phase.
D: Security Accreditation is not used during the Postinstallation Phase. It is used earlier during the Implementation phase.
References:
Conrad, Eric, Seth Misenar and Joshua Feldman, CISSP Study Guide, 2nd Edition, Syngress, Waltham,
2012, p. 1088
NEW QUESTION # 94
DSV as an identification method check against users:
- A. Fingerprints
- B. Keystrokes
- C. Facial expression
- D. Signature
Answer: D
Explanation:
Signature identification, also known as Dynamic Signature Verification (DSV), is another natural fit in the world of biometrics since identification through one's signature occurs during many everyday transactions. Any process or transaction that requires an individual's signature is a prime contender for signature identification.
NEW QUESTION # 95
An internal audit for an organization recently identified malicious actions by a user account. Upon further investigation, it was determined the offending user account was used by multiple people at multiple locations simultaneously for various services and applications. What is the BEST method to prevent this problem in the future?
- A. Allow several users to share a generic account.
- B. Ensure the security information and event management (SIEM) is set to alert.
- C. Ensure each user has their own unique account,
- D. Inform users only one user should be using the account at a time.
Answer: B
NEW QUESTION # 96
Which one of the following is a KEY responsibility for the "Custodian of Data"?
- A. Integrity and security of data
- B. Authentication of user access
- C. Data content and backup
- D. Classification of data elements
Answer: A
Explanation:
Custodian - Preserves the information's CIA (chart) -Ronald Krutz The CISSP PREP Guide (gold edition) pg 15
NEW QUESTION # 97
A DMZ is also known as a:
- A. bastion host.
- B. screened subnet.
- C. three legged firewall.
- D. place to attract hackers.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
With a screened subnet, two firewalls are used to create a DMZ.
Incorrect Answers:
B: The three legged model is just one way of implementing a DMZ. A DMZ can be implemented in different ways.
C: A place to attract hackers is called a honeypot, not a DMZ.
D: A bastion host is not a DMZ. It is a computer that is fully exposed to attack.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 646
NEW QUESTION # 98
Which of the following BEST describes the purpose of "Egress Point Data Governance Councils" within an organization?
- A. A cross-functional group (often including legal, compliance, business, and IT/security stakeholders) responsible for establishing policies, standards, and accountability for how data is managed, classified, and protected across the organization
- B. A technical team responsible solely for configuring firewalls
- C. A group responsible exclusively for approving marketing campaigns
- D. An external auditing firm hired annually
Answer: A
Explanation:
A data governance council is typically a cross-functional group-including representatives from legal, compliance, business units, and IT/security-responsible for establishing organization-wide policies, standards, and accountability structures for how data is classified, managed, accessed, and protected, ensuring alignment between business needs, regulatory requirements, and security controls.
NEW QUESTION # 99
......
New 2026 CISSP Test Tutorial (Updated 1811 Questions): https://ucertify.examprepaway.com/ISC/braindumps.CISSP.ete.file.html