100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
CISSP Cram Test Questions_ Domain 4 - Software Development Security. CA$11.47   Add to cart

Exam (elaborations)

CISSP Cram Test Questions_ Domain 4 - Software Development Security.

 1 view  0 purchase

CISSP Cram Test Questions_ Domain 4 - Software Development Security.

Preview 2 out of 13  pages

  • July 3, 2024
  • 13
  • 2023/2024
  • Exam (elaborations)
  • Questions & answers
All documents for this subject (1751)
avatar-seller
EXAMQA
CISSP Cram Test Questions: Domain 4 -
Software Development Security

Which of the following activities would not be included in the contingency planning
process phase? - ANS-Development of test procedures

In terms or Risk Analysis and dealing with risk, which of the four common ways listed
below seek to eliminate
involvement with the risk being evaluated? - ANS-Avoidance

Of the multiple methods of handling risks which we must undertake to carry out
business operations, which
one involves using controls to reduce the risk? - ANS-Mitigation

There is no way to completely abolish or avoid risks, you can only manage them. A risk
free environment does
not exist. If you have risks that have been identified, understood and evaluated to be
acceptable in order to
conduct business operations. What is this this approach to risk management called? -
ANS-Risk Acceptance

John is the product manager for an information system. His product has undergone
under security review by
an IS auditor. John has decided to apply appropriate security controls to reduce the
security risks suggested by
an IS auditor. Which of the following technique is used by John to treat the identified risk
provided by an IS
auditor? - ANS-Risk Mitigation

Sam is the security Manager of an financial institute. Senior management has
requested he performs a risk
analysis on all critical vulnerabilities reported by an IS auditor. After completing the risk
analysis, Sam has
observed that for a few of the risks, the cost benefit analysis shows that risk mitigation
cost (countermeasures,
controls, or safeguard) is more than the potential lost that could be incurred. What kind
of a strategy should

, Sam recommend to the senior management to treat these risks? - ANS-Risk
Acceptance

Which of the following risk handling technique involves the practice of being proactive
so that the risk in
question is not realized? - ANS-Risk Avoidance

Which of the following risk handling technique involves the practice of passing on the
risk to another entity,
such as an insurance company? - ANS-Risk transfer

Which of the following security control is intended to bring environment back to regular
operation? - ANS-Recovery

Which of the following is NOT an example of a detective control? - ANS-Backup data
restore

Which type of risk assessment is the formula ALE = ARO x SLE used for? -
ANS-Quantitative Analysis

Which of the following Confidentiality, Integrity, Availability (CIA) attribute supports the
principle of least
privilege by providing access to information only to authorized and intended users? -
ANS-Confidentiality

What does "System Integrity" mean? - ANS-Hardware and firmware have undergone
periodic testing to verify that they are functioning properly.

In computing what is the name of a non-self-replicating type of malware program
containing malicious code
that appears to have some useful purpose but also contains code that has a malicious
or harmful purpose
imbedded in it, when executed, carries out actions that are unknown to the person
installing it, typically causing
loss or theft of data, and possible system harm. - ANS-Trojan horse.

The security of a computer application is most effective and economical in which of the
following cases? - ANS-The system is originally designed to provide the necessary
security

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller EXAMQA. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for CA$11.47. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

67474 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
CA$11.47
  • (0)
  Add to cart