CISSP 復習解答例 - Certified Information Systems Security Professional


NO.1 Refer to the information below to answer the question.
A security practitioner detects client-based attacks on the organization's network. A plan will be
necessary to address these concerns.
In the plan, what is the BEST approach to mitigate future internal client-based attacks?
A. Remove all non-essential client-side web services from the network.
B. Screen for harmful exploits of client-side services before implementation.
C. Harden the client image before deployment.
D. Block all client side web exploits at the perimeter.
Answer: C

NO.2 A business has implemented Payment Card Industry Data Security Standard (PCI-DSS)
compliant handheld credit card processing on their Wireless Local Area Network (WLAN) topology.
The network team partitioned the WLAN to create a private segment for credit card processing using
a firewall to control device access and route traffic to the card processor on the Internet. What
components are in the scope of PCI-DSS?
A. The entire enterprise network infrastructure.
B. The handheld devices, wireless access points and border gateway.
C. The end devices, wireless access points, WLAN, switches, management console, and Internet
D. The end devices, wireless access points, WLAN, switches, management console, and firewall.
Answer: D

NO.3 Which of the following command line tools can be used in the reconnaisance phase of a
network vulnerability assessment?
A. dig
B. ipconfig
C. nbtstat
D. ifconfig
Answer: A

NO.4 Which of the following BEST describes a Protection Profile (PP)?
A. A document that represents evaluated products where there is a one-to-one correspondence
between a PP and a Security Target (ST).
B. A document that expresses an implementation independent set of security requirements for an IT
product that meets specific consumer needs.
C. A document that is used to develop an IT security product from its security requirements
D. A document that expresses an implementation dependent set of security requirements which
contains only the security functional requirements.
Answer: B

