[2024年01月13日] 最新CSSLPのPDF問題集リアル無料テスト本日更新です [Q44-Q62]

Share

[2024年01月13日] 最新CSSLPのPDF問題集リアル無料テスト本日更新です

CSSLP問題集には100%厳密検証された問題と解答で合格保証もしくは全額返金


ISC CSSLP 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Develop Security Testing Strategy and Plan
  • Evaluate and Select Reusable Secure Design
トピック 2
  • Incorporate Integrated Risk Management (IRM)
  • Develop Security Requirement Traceability Matrix (STRM)
トピック 3
  • Use Secure Architecture and Design Principles, Patterns, and Tools
  • Model (Non-Functional) Security Properties and Constraints
トピック 4
  • Securely Reuse Third-Party Code or Libraries
  • Identify Security Standards and Frameworks
トピック 5
  • Perform Verification and Validation Testing
  • Performing Architectural Risk Assessment
トピック 6
  • Apply Security During the Build Process
  • Define Secure Operational Architecture
トピック 7
  • Adhere to Relevant Secure Coding Practices
  • Identify Undocumented Functionality

 

質問 # 44
Which of the following NIST documents provides a guideline for identifying an information system as a National Security System?

  • A. NIST SP 800-53A
  • B. NIST SP 800-53
  • C. NIST SP 800-37
  • D. NIST SP 800-60
  • E. NIST SP 800-59

正解:E

解説:
NIST has developed a suite of documents for conducting Certification & Accreditation (C&A). These documents are as follows: NIST Special Publication 800-37: This document is a guide for the security certification and accreditation of Federal Information Systems. NIST Special Publication 800-53: This document provides a guideline for security controls for Federal Information Systems. NIST Special Publication 800-53A. This document consists of techniques and procedures for verifying the effectiveness of security controls in Federal Information System. NIST Special Publication 800-59: This document is a guideline for identifying an information system as a National Security System. NIST Special Publication 800-60: This document is a guide for mapping types of information and information systems to security objectives and risk levels.


質問 # 45
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of the disaster. In which of the following disaster recovery tests can this task be performed?

  • A. Parallel test
  • B. Full-interruption test
  • C. Structured walk-through test
  • D. Simulation test

正解:D

解説:
A simulation test is a method used to test the disaster recovery plans. It operates just like a structured walk-through test. In the simulation test, the members of a disaster recovery team present with a disaster scenario and then, discuss on appropriate responses. These suggested responses are measured and some of them are taken by the team. The range of the simulation test should be defined carefully for avoiding excessive disruption of normal business activities. Answer A is incorrect. The structured walk-through test is also known as the table-top exercise. In structured walk-through test, the team members walkthrough the plan to identify and correct weaknesses and how they will respond to the emergency scenarios by stepping in the course of the plan. It is the most effective and competent way to identify the areas of overlap in the plan before conducting more challenging training exercises. Answer B is incorrect. A full-interruption test includes the operations that shut down at the primary site and are shifted to the recovery site according to the disaster recovery plan. It operates just like a parallel test. The full-interruption test is very expensive and difficult to arrange. Sometimes, it causes a major disruption of operations if the test fails. Answer C is incorrect. A parallel test includes the next level in the testing procedure, and relocates the employees to an alternate recovery site and implements site activation procedures. These employees present with their disaster recovery responsibilities as they would for an actual disaster. The disaster recovery sites have full responsibilities to conduct the day-to-day organization's business.


質問 # 46
DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and confidentiality levels. Which of the following MAC levels requires high integrity and medium availability?

  • A. MAC I
  • B. MAC III
  • C. MAC IV
  • D. MAC II

正解:D

解説:
Explanation/Reference:
Explanation: The various MAC levels are as follows: MAC I: It states that the systems have high availability and high integrity. MAC II: It states that the systems have high integrity and medium availability. MAC III: It states that the systems have basic integrity and availability.


質問 # 47
Which of the following access control models are used in the commercial sector? Each correct answer represents a complete solution. Choose two.

  • A. Bell-LaPadula model
  • B. Clark-Wilson model
  • C. Biba model
  • D. Clark-Biba model

正解:B、C

解説:
Explanation/Reference:
Explanation: The Biba and Clark-Wilson access control models are used in the commercial sector. The Biba model is a formal state transition system of computer security policy that describes a set of access control rules designed to ensure data integrity. Data and subjects are grouped into ordered levels of integrity. The model is designed so that subjects may not corrupt data in a level ranked higher than the subject, or be corrupted by data from a lower level than the subject. The Clark-Wilson security model provides a foundation for specifying and analyzing an integrity policy for a computing system. Answer: D is incorrect. The Bell-LaPadula access control model is mainly used in military systems. Answer: B is incorrect. There is no such access control model as Clark-Biba.


質問 # 48
NIST SP 800-53A defines three types of interview depending on the level of assessment conducted. Which of the following NIST SP 800-53A interviews consists of informal and ad hoc interviews?

  • A. Comprehensive
  • B. Significant
  • C. Abbreviated
  • D. Substantial

正解:C

解説:
Abbreviated interview consists of informal and ad hoc interviews. Answer D is incorrect. Substantial interview consists of informal and structured interviews. Answer A is incorrect. Comprehensive interview consists of formal and structured interviews. Answer B is incorrect. There is no such type of interview in NIST SP 800-53A.


質問 # 49
Which of the following security design patterns provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data?

  • A. Account lockout
  • B. Password propagation
  • C. Secure assertion
  • D. Authenticated session

正解:B

解説:
Password propagation provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data. Answer D is incorrect. Account lockout implements a limit on the incorrect password attempts to protect an account from automated password-guessing attacks. Answer B is incorrect. Authenticated session allows a user to access more than one access-restricted Web page without re-authenticating every page. It also integrates user authentication into the basic session model. Answer A is incorrect. Secure assertion distributes application-specific sanity checks throughout the system.


質問 # 50
Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy?

  • A. Networks and Infrastructures
  • B. Supporting Infrastructures
  • C. Local Computing Environments
  • D. Enclave Boundaries

正解:D

解説:
Explanation/Reference:
Explanation: The areas of information system, as separated by Information Assurance Framework, are as follows: Local Computing Environments: This area includes servers, client workstations, operating system, and applications. Enclave Boundaries: This area consists of collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy. Networks and Infrastructures: This area provides the network connectivity between enclaves. It includes operational area networks (OANs), metropolitan area networks (MANs), and campus area networks (CANs). Supporting Infrastructures: This area provides security services for networks, client workstations, Web servers, operating systems, applications, files, and single-use infrastructure machines


質問 # 51
Which of the following characteristics are described by the DIAP Information Readiness Assessment function? Each correct answer represents a complete solution. Choose all that apply.

  • A. It provides for entry and storage of individual system data.
  • B. It provides data needed to accurately assess IA readiness.
  • C. It identifies and generates IA requirements.
  • D. It performs vulnerability/threat analysis assessment.

正解:B、C、D

解説:
The characteristics of the DIAP Information Readiness Assessment function are as follows: It provides data needed to accurately assess IA readiness. It identifies and generates IA requirements. It performs vulnerability/threat analysis assessment. Answer A is incorrect. It is a function performed by the ASSET system.


質問 # 52
Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee's computer while he is typing in his password at any access point such as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?

  • A. Integrity
  • B. Availability
  • C. Authenticity
  • D. Confidentiality

正解:D

解説:
Confidentiality is violated in a shoulder surfing attack. The CIA triad provides the following three tenets for which security practices are measured: Confidentiality: It is the property of preventing disclosure of information to unauthorized individuals or systems. Breaches of confidentiality take many forms. Permitting someone to look over your shoulder at your computer screen while you have confidential data displayed on it could be a breach of confidentiality. If a laptop computer containing sensitive information about a company's employees is stolen or sold, it could result in a breach of confidentiality. Integrity: It means that data cannot be modified without authorization. Integrity is violated when an employee accidentally or with malicious intent deletes important data files, when a computer virus infects a computer, when an employee is able to modify his own salary in a payroll database, when an unauthorized user vandalizes a web site, when someone is able to cast a very large number of votes in an online poll, and so on. Availability: It means that data must be available at every time when it is needed. Answer D is incorrect. Authenticity is not a tenet of the CIA triad.


質問 # 53
Which of the following security models dictates that subjects can only access objects through applications?

  • A. Biba-Clark model
  • B. Bell-LaPadula
  • C. Clark-Wilson
  • D. Biba model

正解:C

解説:
The Clark-Wilson security model dictates that subjects can only access objects through applications. Answer A is incorrect. The Biba model does not let subjects write to objects at a higher integrity level. Answer B is incorrect. The Bell-LaPadula model has a simple security rule, which means a subject cannot read data from a higher level. Answer D is incorrect. There is no such model as Biba-Clark model.


質問 # 54
Which of the following DoD policies establishes policies and assigns responsibilities to achieve DoD IA through a defense-in-depth approach that integrates the capabilities of personnel, operations, and technology, and supports the evolution to network-centric warfare?

  • A. DoD 8510.1-M DITSCAP
  • B. DoD 8500.2 Information Assurance Implementation
  • C. DoD 8500.1 Information Assurance (IA)
  • D. DoDI 5200.40

正解:C

解説:
DoD 8500.1 Information Assurance (IA) sets up policies and allots responsibilities to achieve DoD IA through a defense-in-depth approach that integrates the capabilities of personnel, operations, and technology, and supports the evolution to network-centric warfare. DoD 8500.1 also summarizes the roles and responsibilities for the persons responsible for carrying out the IA policies. Answer D is incorrect. The DoD 8500.2 Information Assurance Implementation pursues 8500.1. It provides assistance on how to implement policy, assigns responsibilities, and prescribes procedures for applying integrated, layered protection of the DoD information systems and networks. DoD Instruction 8500.2 allots tasks and sets procedures for applying integrated layered protection of the DOD information systems and networks in accordance with the DoD 8500.1 policy. It also provides some important guidelines on how to implement an IA program. Answer A is incorrect. DoDI 5200.40 executes the policy, assigns responsibilities, and recommends procedures under reference for Certification and Accreditation(C&A) of information technology (IT). Answer C is incorrect. DoD 8510.1-M DITSCAP provides standardized activities leading to accreditation, and establishes a process and management baseline.


質問 # 55
Which of the following models uses a directed graph to specify the rights that a subject can transfer to an object or that a subject can take from another subject?

  • A. Access Matrix
  • B. Take-Grant Protection Model
  • C. Biba Integrity Model
  • D. Bell-LaPadula Model

正解:B

解説:
Explanation/Reference:
Explanation: The take-grant protection model is a formal model used in the field of computer security to establish or disprove the safety of a given computer system that follows specific rules. It shows that for specific systems the question of safety is decidable in linear time, which is in general undecidable. The model represents a system as directed graph, where vertices are either subjects or objects. The edges between them are labeled and the label indicates the rights that the source of the edge has over the destination. Two rights occur in every instance of the model: take and grant. They play a special role in the graph rewriting rules describing admissible changes of the graph. Answer: D is incorrect. The access matrix is a straightforward approach that provides access rights to subjects for objects. Answer: C is incorrect. The Bell-LaPadula model deals only with the confidentiality of classified material. It does not address integrity or availability. Answer: B is incorrect. The integrity model was developed as an analog to the Bell-LaPadula confidentiality model and then became more sophisticated to address additional integrity requirements.


質問 # 56
The mission and business process level is the Tier 2. What are the various Tier 2 activities? Each correct answer represents a complete solution. Choose all that apply.

  • A. Defining the core missions and business processes for the organization
  • B. Defining the types of information that the organization needs, to successfully execute the stated missions and business processes
  • C. Developing an organization-wide information protection strategy and incorporating high-level information security requirements
  • D. Prioritizing missions and business processes with respect to the goals and objectives of the organization
  • E. Specifying the degree of autonomy for the subordinate organizations

正解:A、B、C、D、E

解説:
Explanation/Reference:
Explanation: The mission and business process level is the Tier 2. It addresses risks from the mission and business process perspective. It is guided by the risk decisions at Tier 1. The various Tier 2 activities are as follows: It defines the core missions and business processes for the organization. It also prioritizes missions and business processes, with respect to the goals and objectives of the organization. It defines the types of information that an organization requires, to successfully execute the stated missions and business processes. It helps in developing an organization-wide information protection strategy and incorporating high-level information security requirements. It specifies the degree of autonomy for the subordinate organizations.


質問 # 57
Which of the following is an example of penetration testing?

  • A. Implementing NIDS on a network
  • B. Implementing HIDS on a computer
  • C. Configuring firewall to block unauthorized traffic
  • D. Simulating an actual attack on a network

正解:D

解説:
Explanation/Reference:
Explanation: Penetration testing is a method of evaluating the security of a computer system or network by simulating an attack from a malicious source, known as a Black Hat Hacker, or Cracker. The process involves an active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known and/or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures. This analysis is carried out from the position of a potential attacker, and can involve active exploitation of security vulnerabilities. Any security issues that are found will be presented to the system owner together with an assessment of their impact and often with a proposal for mitigation or a technical solution. The intent of a penetration testing is to determine feasibility of an attack and the amount of business impact of a successful exploit, if discovered. It is a component of a full security audit. AnswerA, B, and D are incorrect. Implementing NIDS and HIDS and configuring firewall to block unauthorized traffic are not examples of penetration testing.


質問 # 58
Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States?

  • A. Lanham Act
  • B. Computer Fraud and Abuse Act
  • C. FISMA
  • D. Computer Misuse Act

正解:C

解説:
Explanation/Reference:
Explanation: The Federal Information Security Management Act of 2002 is a United States federal law enacted in 2002 as Title III of the E-Government Act of 2002. The act recognized the importance of information security to the economic and national security interests of the United States. The act requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. FISMA has brought attention within the federal government to cybersecurity and explicitly emphasized a 'risk-based policy for cost-effective security'. FISMA requires agency program officials, chief information officers, and Inspectors Generals (IGs) to conduct annual reviews of the agency's information security program and report the results to Office of Management and Budget (OMB). OMB uses this data to assist in its oversight responsibilities and to prepare this annual report to Congress on agency compliance with the act. Answer:
B is incorrect. The Lanham Act is a piece of legislation that contains the federal statutes of trademark law in the United States. The Act prohibits a number of activities, including trademark infringement, trademark dilution, and false advertising. It is also called Lanham Trademark Act. AnswerA is incorrect. The Computer Misuse Act 1990 is an act of the UK Parliament which states the following statement:
Unauthorized access to the computer material is punishable by 6 months imprisonment or a fine "not exceeding level 5 on the standard scale" (currently 5000). Unauthorized access with the intent to commit or facilitate commission of further offences is punishable by 6 months/maximum fine on summary conviction or 5 years/fine on indictment. Unauthorized modification of computer material is subject to the same sentences as section 2 offences.
AnswerC is incorrect. The Computer Fraud and Abuse Act is a law passed by the United States
Congress in 1984 intended to reduce cracking of computer systems and to address federal computer- related offenses. The Computer Fraud and Abuse Act (codified as 18 U.S.C. 1030) governs cases with a compelling federal interest, where computers of the federal government or certain financial institutions are involved, where the crime itself is interstate in nature, or computers used in interstate and foreign commerce. It was amended in 1986, 1994, 1996, in 2001 by the USA PATRIOT Act, and in 2008 by the Identity Theft Enforcement and Restitution Act. Section (b) of the act punishes anyone who not just commits or attempts to commit an offense under the Computer Fraud and Abuse Act but also those who conspire to do so.


質問 # 59
In which of the following deployment models of cloud is the cloud infrastructure operated exclusively for an organization?

  • A. Hybrid cloud
  • B. Private cloud
  • C. Public cloud
  • D. Community cloud

正解:B

解説:
In private cloud, the cloud infrastructure is operated exclusively for an organization.
The private cloud infrastructure is administered by the organization or a third party, and exists on premise and off premise.


質問 # 60
Which of the following statements best describes the difference between the role of a data owner and the role of a data custodian?

  • A. The custodian implements the information classification scheme after the initial assignment by the operations manager.
  • B. The data owner implements the information classification scheme after the initial assignment by the custodian.
  • C. The data custodian implements the information classification scheme after the initial assignment by the data owner.
  • D. The custodian makes the initial information classification assignments, and the operations manager implements the scheme.

正解:C

解説:
Explanation/Reference:
Explanation: The data owner is responsible for ensuring that the appropriate security controls are in place, for assigning the initial classification to the data to be protected, for approving access requests from other parts of the organization, and for periodically reviewing the data classifications and access rights. Data owners are primarily responsible for determining the data's sensitivity or classification levels, whereas the data custodian has the responsibility for backup, retention, and recovery of data. The data owner delegates these responsibilities to the custodian. Answer: B, A, and C are incorrect. These are not the valid answers.


質問 # 61
Which of the following statements describe the main purposes of a Regulatory policy? Each correct answer represents a complete solution. Choose all that apply.

  • A. It gives an organization the confidence that it is following the standard and accepted industry policy.
  • B. It acknowledges the importance of the computing resources to the business model
  • C. It ensures that an organization is following the standard procedures or base practices of operation in its specific industry.
  • D. It provides a statement of support for information security throughout the enterprise

正解:A、C

解説:
The main purposes of a Regulatory policy are as follows: It ensures that an organization is following the standard procedures or base practices of operation in its specific industry. It gives an organization the confidence that it is following the standard and accepted industry policy. Answer B and A are incorrect. These are the policy elements of Senior Management Statement of Policy.


質問 # 62
......

2024年最新の有効なCSSLPテスト解答ISC試験PDF:https://www.jpntest.com/shiken/CSSLP-mondaishu

合格させるISC CSSLP試験には練習テスト問題集豪華お試しセット:https://drive.google.com/open?id=1kdxGhJAgVAv2H7I63cI7B_T8_ZiIY0Y5

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡