CISSP – Practice
Data Remanence (Ans- The remains of partial or even the entire data set of digital information
Disaster Recovery Planning (DRP) (Ans- Deals with restoring normal business operations after the disaster takes place...works to get the business back to normal
Maximum tolerable downtime (Ans- The maximum period of time that a critical business function can be inoperative before the company incurs significant and long-lasting damage.
802.5 (Ans- IEEE standard defines the Token Ring media access method
Recovery Time Objective (Ans- The balance against the cost of recover and the cost of disruption
Resource Requirements (Ans- portion of the BIA that lists the resources that an organization needs in order to continue operating each critical business function.
Checklist (Ans- Test is one in which copies of the plan are handed out to each functional area to ensure the plan deal with their needs
Information Owner (Ans- The one person responsible for data, its classification and control setting
Job Rotation (Ans- To move from location to location, keeping the same function 1 / 4
Differential power analysis (Ans- A side-channel attack carry-out on smart cards that examining the power emission release during processing
Mitigate (Ans- Defined as real-time monitoring and analysis of network activity and data for potential vulnerabilities and attacks in progress.
Electromagnetic analysis (Ans- A side-channel attack on smart cards that examine the frequencies emitted and timing
Analysis (Ans- Systematic assessment of threats and vulnerabilities that provides a basis for effective management of risk.
Change Control (Ans- Maintaining full control over requests, implementation, traceability, and proper documentation of changes.
Containment (Ans- Mitigate damage by isolating compromised systems from the network.
30 to 90 Days (Ans- Most organizations enforce policies to change password ranging from
Isochronous (Ans- Process must within set time constrains, applications are video related where audio and video must match perfectly
- / 4
Detection (Ans- Identification and notification of an unauthorized and/or undesired action
Electronic Vaulting (Ans- Periodic, automatic and transparent backup of data in bulk.
Fault Tolerance (Ans- Mitigation of system or component loss or interruption through use of backup capability.
Incremental (Ans- A backup method use when time and space are a high importance
Secure HTTP (Ans- Protocol designed to same individual message securely
Criminal (Ans- Conduct that violates government laws developed to protect society
Class C (Ans- Has 256 hosts
RAID 0
(Ans- Creates one large disk by using several disks
Trade secrets (Ans- Deemed proprietary to a company and often include information that provides a competitive edge, the information is protected as long the owner takes protective actions
X.400 (Ans- Active Directory standard
- / 4
Prevention (Ans- Controls deployed to avert unauthorized and/or undesired actions.
Redundant Array Of Independent Drives (RAID) (Ans- A group of hard drives working as one storage unit for the purpose of speed and fault tolerance
Proprietary (Ans- Define the way in which the organization operates.
Gateway (Ans- Used to connect two networks using dissimilar protocols at different layers of the OSI model
Classification (Ans- The assignment of a level of sensitivity to data (or information) that results in the specification of controls for each level of classification.
Data Integrity (Ans- The property that data meet with a priority expectation of quality and that the data can be relied upon.
Alarm Filtering (Ans- The process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks
Coaxial Cable (Ans- A cable consisting of a core, inner conductor that is surrounding by an insulator, an outer cylindrical conductor
Concentrator (Ans- Layer 1 network device that is used to connect network segments together, but provides no traffic control (a hub).
- / 4