PDA

View Full Version : Difficult ques


CISSP_Candidate
08-30-2006, 08:12 AM
If anyone can help me clarify the following questions...i am really puzzled

Q1. The concentric circle approach is used to

A. evaluate environmental threats.
B. assess the physical security of a facility.
C. assess the communications network security.
D. develop a personnel security program.

ANSWER: Think its B, could not find any reference (the only one i find are related to disease propagation...).

Q2. Which one of the following BEST describes a password cracker?

A. A program that can locate and read a password file
B. A program that provides software registration passwords or keys
C. A program that performs comparative analysis
D. A program that obtains privileged access to the system

ANSWER: Think its C but not sure

Q3. Which one of the following is a good defense against worms?

A. Differentiating systems along the lines exploited by the attack
B. Placing limits on sharing, writing, and executing programs
C. Keeping data objects small, simple, and obvious as to their intent
D. Limiting connectivity by means of well-managed access controls

ANSWER: What about B ?

Q4. Which one of the following is an example of electronic piggybacking?

A. Attaching to a communications line and substituting data
B. Abruptly terminating a dial-up or direct-connect session
C. Following an authorized user into the computer room
D. Recording and playing back computer transactions

ANSWER: "electronic piggybacking" ??? C is "standard piggybacking"

Q5. Which one of the following is NOT a fundamental component of a Regulatory Security Policy?

A. What is to be done?
B. When is it to be done?
C. Who is to do it?
D. Why it is to be done?

ANSWER: no idea

Q6. Evidence corroboration is achieved by

A. creating multiple logs using more than one utility.
B. establishing secure procedures for authenticating users.
C. maintaining all evidence under the control of an independent source.
D. implementing disk mirroring on all devices where log files are stored.

ANSWER: I would say A but not sure

Jescoi
08-30-2006, 08:12 AM
Quite a long post.

Q1. My choice would be to B. Ref to CISSP Study guide by Ed Tittle book Pg 643.

Q2. My choice goes to C. A cracker program typically checks a character string with the password string and if it matches then deduces that it is correct . If not then other characters are picked up for comparison and it goes on till the match.

Q3. I would go for B. Worms are self replicating and could travel over network by shareing of files, executables etc. If the propogation is controlled then it would reduce the impact.

Q4. C. would be my answer. Others simply do not come closer.

Q5. It would be C. Think about the word 'Regulatory'. Regulatory is typically for specific industry so it is known who would be doing it. for eg HIPPA --> Healthcare....

Q6. C. is the correct answer. If a third party supports the log findings and its impact this would definitely be an evidence corroboration.


I would answer the questions this way...... Does anyone have any other thoughts????