最新的ISC Information Systems Security Engineering Professional Practice Test - ISSEP免費考試真題

問題1
Which of the following processes culminates in an agreement between key players that a system in its current configuration and operation provides adequate protection controls

正確答案: B
問題2
The risk transference is referred to the transfer of risks to a third party, usually for a fee, it creates a contractual-relationship for the third party to manage the risk on behalf of the performing organization. Which one of the following is NOT an example of the transference risk response

正確答案: B
問題3
Which of the following organizations incorporates building secure audio and video communications equipment, making tamper protection products, and providing trusted microelectronics solutions

正確答案: A
問題4
Which of the following assessment methodologies defines a six-step technical security evaluation

正確答案: D
問題5
What NIACAP certification levels are recommended by the certifier Each correct answer represents a complete solution. Choose all that apply.

正確答案: B,C,E,F
問題6
Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one

正確答案: C
問題7
Fill in the blank with an appropriate phrase. A ____________________ is defined as any activity that has an effect on defining, designing, building, or executing a task, requirement, or procedure.
正確答案:
technical effort
問題8
System Authorization is the risk management process. System Authorization Plan (SAP) is a comprehensive and uniform approach to the System Authorization Process. What are the different phases of System Authorization Plan Each correct answer represents a part of the solution. Choose all that apply.

正確答案: A,C,D,E
問題9
Fill in the blank with an appropriate phrase. The ______________ process is used for allocating
performance and designing the requirements to each function.
正確答案:
functional allocation
問題10
Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy

正確答案: A
問題11
Which of the following is the application of statistical methods to the monitoring and control of a process to ensure that it operates at its full potential to produce conforming product

正確答案: A
問題12
Which of the following CNSS policies describes the national policy on use of cryptomaterial by activities operating in high risk environments

正確答案: C
問題13
You work as an ISSE for BlueWell Inc. You want to break down user roles, processes, and information until ambiguity is reduced to a satisfactory degree. Which of the following tools will help you to perform the above task

正確答案: A