Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CISSP - Chapter 16 Review Questions and Answers 2022

Rating
-
Sold
-
Pages
4
Grade
A+
Uploaded on
06-06-2022
Written in
2020/2021

CISSP - Chapter 16 Review Questions and Answers 2022 An organization ensures that users are granted access to only the data they need to perform specific work tasks. What principle are they following? A. Principle of least permission B. Separation of duties C. Need-to-know D. Role Based Access Control C An administrator is granting permissions to a database. What is the default level of access the administrator should grant to new users in the organization? A. Read B. Modify C. Full access D. No access D 00:02 01:09 Which of the following statements best describes why separation of duties is important for security purposes? A. It ensures that multiple people can do the same job. B. It prevents an organization from losing important information when they lose important people. C. It prevents any single IT security person from making major security changes without involving other individuals. D. It helps employees concentrate their talents where they will be most useful. C What is a primary benefit of job rotation and separation of duties policies? A. Preventing collusion B. Preventing fraud C. Encouraging collusion D. Correcting incidents B A financial organization commonly has employees switch duty responsibilities every six months. What security principle are they employing? A. Job rotation B. Separation of duties C. Mandatory vacations D. Least privilege A Which of the following is one of the primary reasons an organization enforces a mandatory vacation policy? A. To rotate job responsibilities B. To detect fraud C. To increase employee productivity D. To reduce employee stress levels B An organization wants to reduce vulnerabilities against fraud from malicious employees. Of the following choices, what would help with this goal? (Choose all that apply.) A. Job rotation B. Separation of duties C. Mandatory vacations D. Baselining A,B,C Of the following choices, what is not a valid security practice related to special privileges? A. Monitor special privilege assignments. B. Grant access equally to administrators and operators. C. Monitor special privilege usage. D. Grant access to only trusted employees. B Which of the following identifies vendor responsibilities and can include monetary penalties if the vendor doesn't meet the stated responsibilities? A. Service-level agreement (SLA) B. Memorandum of understanding (MOU) C. Interconnection security agreement (ISA) D. Software as a service (SaaS) A What should be done with equipment that is at the end of its lifecycle and is being donated to a charity? A. Remove all CDs and DVDs. B. Remove all software licenses. C. Sanitize it. D. Install the original software. C An organization is planning the layout of a new building that will house a datacenter. Where is the most appropriate place to locate the datacenter? A. In the center of the building B. Closest to the outside wall where power enters the building C. Closest to the outside wall where heating, ventilation, and air conditioning systems are located D. At the back of the building A Which of the following is a true statement regarding virtual machines (VMs) running as guest operating systems on physical servers? A. Updating the physical server automatically updates the VMs. B. Updating any VM automatically updates all the VMs. C. VMs do not need to be updated if the physical server is updated. D. VMs must be updated individually. D Some cloud-based service models require an organization to perform some maintenance and take responsibility for some security. Which of the following is a service model that places most of these responsibilities on the organization leasing the cloud-based resources? A. IaaS B. PaaS C. SaaS D. Hybrid A An organization is using a SaaS cloud-based service shared with another organization. What type of cloud-based deployment model does this describe? A. Public B. Private C. Community D. Hybrid C Backup tapes have reached the end of their lifecycle and need to be disposed of. Which of the following is the most appropriate disposal method? A. Throw them away. Because they are at the end of their lifecycle, it is not possible to read data from them. B. Purge the tapes of all data before disposing of them. C. Erase data off the tapes before disposing of them. D. Store the tapes in a storage facility. B Which of the following can be an effective method of configuration management using a baseline? A. Implementing change management B. Using images C. Implementing vulnerability management D. Implementing patch management B Which of the following steps would not be included in a change management process? A. Immediately implement the change if it will improve performance. B. Request the change. C. Create a rollback plan for the change. D. Document the change. A While troubleshooting a network problem, a technician realized the problem could be resolved by opening a port on a firewall. The technician opened the port and verified the system was now working. However, an attacker accessed this port and launched a successful attack. What could have prevented this problem? A. Patch management processes B. Vulnerability management processes C. Configuration management processes D. Change management processes D Which of the following is not a part of a patch management process? A. Evaluate patches. B. Test patches. C. Deploy all patches. D. Audit patches. C Servers within your organization were recently attacked causing an excessive outage. You are asked to check systems for known issues that attackers may use to exploit other systems in your network. Which of the following is the best choice to meet this need? A. Versioning tracker B. Vulnerability scanner C. Security audit D. Security review B

Show more Read less
Institution
Course

Content preview

CISSP - Chapter 16 Review Questions
An organization ensures that users are granted access to only the data they need to
perform specific work tasks. What principle are they following?
A. Principle of least permission
B. Separation of duties
C. Need-to-know
D. Role Based Access Control - Answer C

An administrator is granting permissions to a database. What is the default level of
access the administrator should grant to new users in the organization?
A. Read
B. Modify
C. Full access
D. No access - Answer D

Which of the following statements best describes why separation of duties is important
for security purposes?
A. It ensures that multiple people can do the same job.
B. It prevents an organization from losing important information when they lose
important people.
C. It prevents any single IT security person from making major security changes without
involving other individuals.
D. It helps employees concentrate their talents where they will be most useful. - Answer
C

What is a primary benefit of job rotation and separation of duties policies?
A. Preventing collusion
B. Preventing fraud
C. Encouraging collusion
D. Correcting incidents - Answer B

A financial organization commonly has employees switch duty responsibilities every six
months. What security principle are they employing?
A. Job rotation
B. Separation of duties
C. Mandatory vacations
D. Least privilege - Answer A

Which of the following is one of the primary reasons an organization enforces a
mandatory vacation policy?
A. To rotate job responsibilities
B. To detect fraud
C. To increase employee productivity
D. To reduce employee stress levels - Answer B

An organization wants to reduce vulnerabilities against fraud from malicious employees.
Of the following choices, what would help with this goal? (Choose all that apply.)

Written for

Course

Document information

Uploaded on
June 6, 2022
Number of pages
4
Written in
2020/2021
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$10.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EvaTee Phoenix University
Follow You need to be logged in order to follow users or courses
Sold
5233
Member since
4 year
Number of followers
3570
Documents
56250
Last sold
1 day ago
TIGHT DEADLINE? I CAN HELP

Many students don\'t have the time to work on their academic papers due to balancing with other responsibilities, for example, part-time work. I can relate. kindly don\'t hesitate to contact me, my study guides, notes and exams or test banks, are 100% graded

3.8

952 reviews

5
453
4
167
3
174
2
48
1
110

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions