CISSP Chapter 1: Questions Answers

Study Guides Aug 1, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CISSP Chapter 1: Questions & Answers

Which of the following contains the primary goals and objectives of security?

  • A network's border perimeter
  • The CIA Triad
  • A stand-alone system
  • The Internet
  • (Ans- B. The primary goals and objectives of security are confidentiality, integrity, and availability, commonly referred to as the CIA Triad .

Vulnerabilities and risks are evaluated based on their threats against which of the following?

  • One or more of the CIA Triad principles
  • Data usefulness
  • Due care
  • Extent of liability
  • (Ans- A. Vulnerabilities and risks are evaluated based on their threats against one or more of the CIA Triad principles.

Which of the following is a principle of the CIA Triad that means authorized subjects are granted timely and uninterrupted access to objects?

  • Identification
  • Availability
  • Encryption
  • Layering
  • (Ans- B. Availability means that authorized subjects are granted timely and uninterrupted access to objects.

Which of the following is not considered a violation of confidentiality?

  • Stealing passwords
  • Eavesdropping
  • Hardware destruction
  • Social engineering 1 / 2

(Ans- C. Hardware destruction is a violation of availability and possibly integrity. Violations of confidentiality include capturing network traffic, stealing password files, social engineering, port scanning, shoulder surfing, eavesdropping, and sniffing.

Which of the following is not true?

  • Violations of confidentiality include human error.
  • Violations of confidentiality include management oversight.
  • Violations of confidentiality are limited to direct intentional attacks.
  • Violations of confidentiality can occur when a transmission is not
  • properly encrypted.(Ans- C. Violations of confidentiality are not limited to direct intentional attacks. Many instances of unauthorized disclosure of sensitive or confidential information are due to human error, oversight, or ineptitude.

STRIDE is often used in relation to assessing threats against applications or operating systems. Which of the following is not an element of STRIDE?

  • Spoofing
  • Elevation of privilege
  • Repudiation
  • Disclosure
  • (Ans- D. Disclosure is not an element of STRIDE. The elements of STRIDE are spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.

If a security mechanism offers availability, then it offers a high level of assurance that authorized subjects can ______ the data, objects, and resources.

  • Control
  • Audit
  • Access
  • Repudiate
  • (Ans- C. Accessibility of data, objects, and resources is the goal of availability. If a security mechanism offers availability, then it is highly likely that the data, objects, and resources are accessible to authorized subjects.

  • / 2

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Study Guides
Added: Aug 1, 2025
Description:

CISSP Chapter 1: Questions & Answers Which of the following contains the primary goals and objectives of security? A. A network's border perimeter B. The CIA Triad C. A stand-alone system D. The In...

Get this document $30.00