
Free ISC CISSP-ISSEP Test Practice Test Questions Exam Dumps
Prepare Top ISC CISSP-ISSEP Exam Audio Study Guide Practice Questions Edition
NEW QUESTION # 51
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation Each correct answer represents a complete solution. Choose two.
- A. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
- B. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
- C. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- D. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
Answer: A,C
NEW QUESTION # 52
Diane is the project manager of the HGF Project. A risk that has been identified and analyzed in the project planning processes is now coming into fruition.
What individual should respond to the risk with the preplanned risk response?
- A. Diane
- B. Project sponsor
- C. Risk owner
- D. Subject matter expert
Answer: C
NEW QUESTION # 53
Which of the following individuals is responsible for monitoring the information system environment for factors that can negatively impact the security of the system and its accreditation
- A. Information System Owner
- B. Chief Information Officer
- C. Chief Risk Officer
- D. Chief Information Security Officer
Answer: A
NEW QUESTION # 54
Which of the following characteristics are described by the DIAP Information Readiness Assessment function Each correct answer represents a complete solution. Choose all that apply.
- A. It provides data needed to accurately assess IA readiness.
- B. It identifies and generates IA requirements.
- C. It provides for entry and storage of individual system data.
- D. It performs vulnerabilitythreat analysis assessment.
Answer: A,B,D
NEW QUESTION # 55
Which of the following roles is also known as the accreditor
- A. Data owner
- B. Chief Information Officer
- C. Chief Risk Officer
- D. Designated Approving Authority
Answer: D
NEW QUESTION # 56
The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation.
What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.
- A. Registration
- B. Certification analysis
- C. Configuring refinement of the SSAA
- D. System development
- E. Assessment of the Analysis Results
Answer: B,C,D,E
NEW QUESTION # 57
The Concept of Operations (CONOPS) is a document describing the characteristics of a proposed system from the viewpoint of an individual who will use that system. Which of the following points are included in CONOPS Each correct answer represents a complete solution. Choose all that apply.
- A. Statement of the structure of the system
- B. Statement of the goals and objectives of the system
- C. Organizations, activities, and interactions among participants and stakeholders
- D. Clear statement of responsibilities and authorities delegated
- E. Strategies, tactics, policies, and constraints affecting the system
Answer: B,C,D,E
NEW QUESTION # 58
Which of the following documents is described in the statement below It is developed along with all processes of the risk management. It contains the results of the qualitative risk analysis, quantitative risk analysis, and risk response planning.
- A. Risk management plan
- B. Risk register
- C. Project charter
- D. Quality management plan
Answer: B
NEW QUESTION # 59
Which of the following statements define the role of the ISSEP during the development of the detailed security design, as mentioned in the IATF document Each correct answer represents a complete solution. Choose all that apply.
- A. It identifies custom security products.
- B. It identifies candidate commercial off-the-shelf (COTS)government off-the-shelf (GOTS) security products.
- C. It identifies the information protection problems that needs to be solved.
- D. It allocates security mechanisms to system security design elements.
Answer: A,B,D
Explanation:
Explanation
NEW QUESTION # 60
Which of the following Security Control Assessment Tasks evaluates the operational, technical, and the management security controls of the information system using the techniques and measures selected or developed
- A. Security Control Assessment Task 2
- B. Security Control Assessment Task 3
- C. Security Control Assessment Task 4
- D. Security Control Assessment Task 1
Answer: B
NEW QUESTION # 61
Which of the following types of firewalls increases the security of data packets by remembering the state of connection at the network and the session layers as they pass through the filter
- A. PIX firewall
- B. Virtual firewall
- C. Stateful packet filter firewall
- D. Stateless packet filter firewall
Answer: C
NEW QUESTION # 62
Which of the following types of cryptography defined by FIPS 185 describes a cryptographic algorithm or a tool accepted by the National Security Agency for protecting sensitive, unclassified information in the systems as stated in Section 2315 of Title 10, United States Code
- A. Type II cryptography
- B. Type III (E) cryptography
- C. Type I cryptography
- D. Type III cryptography
Answer: A
NEW QUESTION # 63
Which of the following certification levels requires the completion of the minimum security checklist and more in-depth, independent analysis
- A. CL 1
- B. CL 3
- C. CL 2
- D. CL 4
Answer: B
NEW QUESTION # 64
Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the U.S. Federal Government information security standards Each correct answer represents a complete solution. Choose all that apply.
- A. CA Certification, Accreditation, and Security Assessments
- B. Information systems acquisition, development, and maintenance
- C. SA System and Services Acquisition
- D. IR Incident Response
Answer: A,C,D
NEW QUESTION # 65
Which of the following assessment methodologies defines a six-step technical security evaluation
- A. FITSAF
- B. FIPS 102
- C. DITSCAP
- D. OCTAVE
Answer: B
NEW QUESTION # 66
Which of the following individuals is responsible for the oversight of a program that is supported by a team of people that consists of, or be exclusively comprised of contractors
- A. Senior Analyst
- B. Quality Assurance Manager
- C. System Owner
- D. Federal program manager
Answer: D
NEW QUESTION # 67
TQM recognizes that quality of all the processes within an organization contribute to the quality of the product. Which of the following are the most important activities in the Total Quality Management Each correct answer represents a complete solution. Choose all that apply.
- A. Quality improvements
- B. Quality costs
- C. Maintenance of quality
- D. Quality renewal
Answer: A,C,D
NEW QUESTION # 68
Which of the following types of cryptography defined by FIPS 185 describes a cryptographic algorithm or a tool accepted by the National Security Agency for protecting classified information
- A. Type III (E) cryptography
- B. Type II cryptography
- C. Type III cryptography
- D. Type I cryptography
Answer: D
NEW QUESTION # 69
Which of the following techniques are used after a security breach and are intended to limit the extent of any damage caused by the incident
- A. Safeguards
- B. Preventive controls
- C. Corrective controls
- D. Detective controls
Answer: C
NEW QUESTION # 70
Which of the following types of CNSS issuances establishes or describes policy and programs, provides authority, or assigns responsibilities
- A. Instructions
- B. Directives
- C. Advisory memoranda
- D. Policies
Answer: B
NEW QUESTION # 71
The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the system has been accredited in Phase 3. What are the process activities of this phase Each correct answer represents a complete solution. Choose all that apply.
- A. System operations
- B. Maintenance of the SSAA
- C. Compliance validation
- D. Security operations
- E. Change management
- F. Continue to review and refine the SSAA
Answer: A,B,C,D,E
NEW QUESTION # 72
Which of the following is a type of security management for computers and networks in order to identify security breaches
- A. ASA
- B. IPS
- C. EAP
- D. IDS
Answer: D
NEW QUESTION # 73
The risk transference is referred to the transfer of risks to a third party, usually for a fee, it creates a contractual-relationship for the third party to manage the risk on behalf of the performing organization. Which one of the following is NOT an example of the transference risk response
- A. Life cycle costing
- B. Performance bonds
- C. Warranties
- D. Use of insurance
Answer: A
NEW QUESTION # 74
Which of the following is required to determine classification and ownership?
- A. System and data resources are properly identified
- B. System security controls are fully integrated
- C. Data file references are identified and linked
- D. Access violations are logged and audited
Answer: A
NEW QUESTION # 75
The principle of the SEMP is not to repeat the information, but rather to ensure that there are processes in place to conduct those functions. Which of the following sections of the SEMP template describes the work authorization procedures as well as change management approval processes
- A. Section 3.1.9
- B. Section 3.1.8
- C. Section 3.1.5
- D. Section 3.1.7
Answer: A
NEW QUESTION # 76
......
Go to CISSP-ISSEP Questions - Try CISSP-ISSEP dumps pdf: https://www.exam4labs.com/CISSP-ISSEP-practice-torrent.html
Dumps Practice Exam Questions Study Guide for the CISSP-ISSEP Exam: https://drive.google.com/open?id=1eUMeF0L86vDEeS9bpQgWR8RJ8WVpMYuX