Certified Information Systems Security Professional – CISSP – Question013

Which of the following entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership responsibilities?

A.
Security governance
B. Risk management
C. Security portfolio management
D. Risk assessment

Correct Answer: B

Certified Information Systems Security Professional – CISSP – Question009

Intellectual property rights are PRIMARY concerned with which of the following?

A.
Owner’s ability to realize financial gain
B. Owner’s ability to maintain copyright
C. Right of the owner to enjoy their creation
D. Right of the owner to control delivery method

Correct Answer: D

Certified Information Systems Security Professional – CISSP – Question008

An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?

A.
Development, testing, and deployment
B. Prevention, detection, and remediation
C. People, technology, and operations
D. Certification, accreditation, and monitoring

Correct Answer: C

Explanation:

Certified Information Systems Security Professional – CISSP – Question007

Which of the following types of technologies would be the MOST cost-effective method to provide a reactive control for protecting personnel in public areas?

A.
Install mantraps at the building entrances
B. Enclose the personnel entry area with polycarbonate plastic
C. Supply a duress alarm for personnel exposed to the public
D. Hire a guard to protect the public area

Correct Answer: D

Certified Information Systems Security Professional – CISSP – Question006

When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?

A.
Only when assets are clearly defined
B. Only when standards are defined
C. Only when controls are put in place
D. Only procedures are defined

Correct Answer: A

Certified Information Systems Security Professional – CISSP – Question005

A company whose Information Technology (IT) services are being delivered from a Tier 4 data center, is preparing a companywide Business Continuity Planning (BCP). Which of the following failures should the IT manager be concerned with?

A.
Application
B. Storage
C. Power
D. Network