CISSP-ISSEP: Information Systems Security Engineering Professional — Free Practice Questions
10 free sample questions from a bank of 10, with the correct answers and explanations. No signup required — start practising right now.
1FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which
of the following FITSAF levels shows that the procedures and controls are tested and reviewed
Level 4
Level 5
Level 1
Level 2
Level 3
Answer: A
2Which of the following is a type of security management for computers and networks in order to identify security breaches
IPS
IDS
ASA
EAP
Answer: B
3Which of the following types of firewalls increases the security of data packets by remembering the state of connection at the network and the session layers as
they pass through the filter
Stateless packet filter firewall
PIX firewall
Stateful packet filter firewall
Virtual firewall
Answer: C
4Which of the following federal laws is designed to protect computer data from theft
Federal Information Security Management Act (FISMA)
Computer Fraud and Abuse Act (CFAA)
Government Information Security Reform Act (GISRA)
Computer Security Act
Answer: B
5Which of the following is used to indicate that the software has met a defined quality level and is ready for mass distribution either by electronic means or by
physical media
ATM
RTM
CRO
DAA
Answer: B
6Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the
configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which
one
Configuration Item Costing
Configuration Identification
Configuration Verification and Auditing
Configuration Status Accounting
Answer: A
7Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process
Authorizing Official
Information system owner
Chief Information Officer (CIO)
Chief Risk Officer (CRO)
Answer: B
8Which of the following security controls is a set of layered security services that address communications and data security problems in the emerging Internet and
intranet application space
Internet Protocol Security (IPSec)
Common data security architecture (CDSA)
File encryptors
Application program interface (API)
Answer: B
9Which of the following protocols is used to establish a secure terminal to a remote network device
WEP
SMTP
SSH
IPSec
Answer: C
10Which of the following elements of Registration task 4 defines the system's external interfaces as well as the purpose of each external interface, and the
relationship between the interface and the system