[Sep-2025 Newly Released] CISSP Dumps for ISC Certification Certified [Q140-Q162]

Share

[Sep-2025 Newly Released] CISSP Dumps for ISC Certification Certified

Updated Verified CISSP dumps Q&As - 100% Pass


The CISSP certification exam is a comprehensive exam that covers eight domains of information security. These domains include security and risk management, asset security, security engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security. CISSP exam consists of 250 multiple-choice questions and is designed to test the candidate's knowledge, skills, and abilities in each of these domains. Passing the CISSP certification exam requires a score of at least 700 out of 1000 points and a minimum of five years of professional experience in the information security field.

 

NEW QUESTION # 140
When developing an electronic health record (EHR) in the United States (US), which of the following would be the BEST source of information for any compliance requirements?

  • A. Health and Human Services (HHS)
  • B. World Health Organization (WHO)
  • C. International Organization for Standardization (ISO)
  • D. American Public Health Association (APHA)

Answer: A


NEW QUESTION # 141
The design review for an application has been completed and is ready for release. What technique should an organization use to assure application integrity?

  • A. Device encryption
  • B. Input validation
  • C. Digital signing
  • D. Application authentication

Answer: B


NEW QUESTION # 142
Unshielded Twisted Pair cabling is a:

  • A. one-pair wire medium that is used in a variety of networks.
  • B. two-pair wire medium that is used in a variety of networks.
  • C. three-pair wire medium that is used in a variety of networks.
  • D. four-pair wire medium that is used in a variety of networks.

Answer: D

Explanation:
Unshielded Twisted Pair cabling is a four-pair wire medium that is used in a variety of networks
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 101.


NEW QUESTION # 143
Which of the following outlined how senior management are responsible for the computer and information security decisions that they make and what actually took place within their organizations?

  • A. The Computer Fraud and Abuse Act of 1986.
  • B. The Computer Security Act of 1987.
  • C. The Economic Espionage Act of 1996.
  • D. The Federal Sentencing Guidelines of 1991.

Answer: D

Explanation:
In 1991, U.S. Federal Sentencing Guidelines were developed to provide judges with courses of action in dealing with white collar crimes. These guidelines provided ways that companies and law enforcement should prevent, detect and report computer crimes. It also outlined how senior management are responsible for the computer and information security decisions that they make and what actually took place within their organizations.


NEW QUESTION # 144
Where can the Open Web Application Security Project (OWASP) list of associated vulnerabilities be found?

  • A. OWASP Top 10 Project
  • B. OWASP Software Assurance Maturity Model (SAMM) Project
  • C. OWASP Guide Project
  • D. OWASP Mobile Project

Answer: A

Explanation:
The OWASP Top 10 Project is a project that provides a list of the most critical web application security risks and associated vulnerabilities. The OWASP Top 10 Project aims to raise awareness and educate developers, designers, architects, managers, and organizations about the consequences of the most common and impactful web application security weaknesses. The OWASP Top 10 Project also provides guidance on how to prevent, detect, and mitigate these risks and vulnerabilities. The OWASP Top 10 Project is updated periodically based on the feedback from the security community and the data from various sources. The other options are not projects that provide a list of the associated vulnerabilities, as they either focus on different aspects of web application security, such as maturity model, guide, or mobile, or do not exist. References: CISSP - Certified Information Systems Security Professional, Domain 8. Software Development Security, 8.2 Enforce security controls in development environments, 8.2.1 Assess the effectiveness of software security, 8.2.1.1 OWASP; CISSP Exam Outline, Domain 8. Software Development Security, 8.2 Enforce security controls in development environments, 8.2.1 Assess the effectiveness of software security, 8.2.1.1 OWASP


NEW QUESTION # 145
Which of the following encryption algorithms does not deal with discrete logarithms?

  • A. El Gamal
  • B. Elliptic Curve
  • C. RSA
  • D. Diffie-Hellman

Answer: C


NEW QUESTION # 146
Which of the following was not designed to be a proprietary encryption algorithm?

  • A. Skipjack
  • B. RC2
  • C. Blowfish
  • D. RC4

Answer: C

Explanation:
Blowfish is a symmetric block cipher with variable-length key (32 to 448 bits)
designed in 1993 by Bruce Schneier as an unpatented, license-free, royalty-free replacement for
DES or IDEA. See attributes below:
Block cipher: 64-bit block
Variable key length: 32 bits to 448 bits
Designed by Bruce Schneier
Much faster than DES and IDEA
Unpatented and royalty-free
No license required
Free source code available
Rivest Cipher #2 (RC2) is a proprietary, variable-key-length block cipher invented by Ron Rivest
for RSA Data Security, Inc.
Rivest Cipher #4 (RC4) is a proprietary, variable-key-length stream cipher invented by Ron Rivest
for RSA Data Security, Inc.
The Skipjack algorithm is a Type II block cipher [NIST] with a block size of 64 bits and a key size
of 80 bits that was developed by NSA and formerly classified at the U.S. Department of Defense
"Secret" level. The NSA announced on June 23, 1998, that Skipjack had been declassified.
References:
RSA Laboratories
http://www.rsa.com/rsalabs/node.asp?id=2250
RFC 2828 - Internet Security Glossary
http://www.faqs.org/rfcs/rfc2828.html


NEW QUESTION # 147
When determining data and information asset handling, regardless of the specific toolset being used, which of the following is one of the common components of big data?

  • A. Consolidated data collection
  • B. Distributed storage locations
  • C. Distributed data collection
  • D. Centralized processing location

Answer: C


NEW QUESTION # 148
As part of an application penetration testing process, session hijacking can BEST be achieved by which of the following?

  • A. Denial of Service (DoS)
  • B. Cookie manipulation
  • C. Known-plaintext attack
  • D. Structured Query Language (SQL) injection

Answer: D


NEW QUESTION # 149
Who is responsible for providing reports to the senior management on the effectiveness of the security controls?

  • A. Information systems security professionals
  • B. Data owners
  • C. Information systems auditors
  • D. Data custodians

Answer: C

Explanation:
IT auditors determine whether systems are in compliance with the security policies, procedures, standards, baselines, designs, architectures, management direction and other requirements" and "provide top company management with an independent view of the controls
that have been designed and their effectiveness."
"Information systems security professionals" is incorrect. Security professionals develop the
security policies and supporting baselines, etc.
"Data owners" is incorrect. Data owners have overall responsibility for information assets and
assign the appropriate classification for the asset as well as ensure that the asset is protected with
the proper controls.
"Data custodians" is incorrect. Data custodians care for an information asset on behalf of the data
owner.
References;
CBK, pp. 38 - 42.
AIO3. pp. 99 - 104


NEW QUESTION # 150
The World Trade Organization's (WTO) agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS) requires authors of computer software to be given the

  • A. right to refuse or permit commercial rentals.
  • B. ability to tailor security parameters based on location.
  • C. ability to confirm license authenticity of their works.
  • D. right to disguise the software's geographic origin.

Answer: A


NEW QUESTION # 151
Which of the following is true?

  • A. UDP guarantees delivers of data. TCP does not guarantee delivery of data.
  • B. TCP is connection-oriented. UDP is not
  • C. UDP provides for Error Correction. TCP does not.
  • D. UDP is useful for longer messages

Answer: B


NEW QUESTION # 152
Legacy single sign on (SSO) is:

  • A. Technology to allow users to authenticate to every application by entering the same user ID and password each time, thus having to remember only a single password.
  • B. Technology to manage passwords consistently across multiple platforms, enforcing policies such as password change intervals.
  • C. A mechanism where users can authenticate themselves once, and then a central repository of their credentials is used to launch various legacy applications.
  • D. Another way of referring to SESAME and KryptoKnight, now that Kerberos is the de-facto
    industry standard single sign on mechanism.

Answer: C

Explanation:
A mechanism where users can authenticate themselves once, and then a central
repository of their credentials is used to launch various legacy applications.
The following answers are incorrect:
Technology to allow users to authenticate to every application by entering the same user ID and
password each time, thus having to remember only a single password.
This is a detractor. Note that it is not even a descripton of SSO, because the user is entering user
ID and password for EACH access attempt.
Technology to manage passwords consistently across multiple platforms, enforcing policies such
as password change intervals.
This is a good description for Identity Management Password Management system, but not for
Legacy SSO.
Another way of referring to SESAME and KryptoKnight, now that Kerberos is the de-facto industry
standard single sign on mechanism. This is a detractor.
The following reference(s) were/was used to create this question:
Official (ISC)2 Guide to the CISSP CBK 2007, pg 176:
"many legacy systems do not support an external means to identify and authenticate users.
Therefore, it is possible to store the credentials outside of the various applications and have them
automatically entered on behalf of the user when an application is launched."


NEW QUESTION # 153
Of the following, which is NOT a specific loss criteria that should be considered while developing a BIA?

  • A. Loss in profits
  • B. Loss in reputation
  • C. Loss of skilled workers knowledge
  • D. Loss in revenue

Answer: C

Explanation:
Although a loss of skilled workers knowledge would cause the company a great
loss, it is not identified as a specific loss criteria. It would fall under one of the three other criteria
listed as distracters.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002,
chapter 9: Disaster Recovery and Business continuity (page 598).


NEW QUESTION # 154
Which of the following events prompts a review of the disaster recovery plan (DRP)?

  • A. Organizational merger
  • B. Change in senior management
  • C. Completion of the security policy review
  • D. New members added to the steering committee

Answer: A

Explanation:
The event that prompts a review of the disaster recovery plan (DRP) is an organizational merger. A DRP is a plan that defines the procedures and actions to be taken in the event of a disaster or a disruption, to restore the normal operations and services of an organization as quickly as possible. A DRP covers the aspects such as the roles and responsibilities, the recovery strategies and objectives, the backup and restoration methods, the communication and coordination channels, and the testing and maintenance schedules of the disaster recovery process. An organizational merger is an event that involves the combination or integration of two or more organizations into one single organization, as a result of a business decision or a strategy. An organizational merger prompts a review of the DRP, as it can affect the scope, scale, and complexity of the DRP, and require the alignment, consolidation, or modification of the DRP. A review of the DRP can help to ensure that the DRP is updated and consistent with the current and future needs and requirements of the merged organization, and that the DRP is effective and efficient for the disaster recovery process. New members added to the steering committee, completion of the security policy review, and change in senior management are not events that prompt a review of the DRP. These are some of the factors or changes that may influence or impact the DRP, but they are not as significant or critical as an organizational merger. New members added to the steering committee are individuals who join or replace the existing members of the steering committee, which is a group of people who oversee and guide the DRP and the disaster recovery process. Completion of the security policy review is a process that evaluates and revises the security policy, which is a document that defines the security goals, principles, and rules of an organization. Change in senior management is a situation that involves the replacement or reassignment of the senior management or the executives of an organization, who are responsible for the strategic and operational decisions and actions of the organization.
References: Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 7, Security Operations, page 709. CISSP All-in-One Exam Guide, Eighth Edition, Chapter 7, Security Operations, page 674.


NEW QUESTION # 155
Which of the following is a detective access control mechanism?

  • A. Log review
  • B. Non-disclosure agreement
  • C. Least privilege
  • D. Password complexity

Answer: A


NEW QUESTION # 156
An international medical organization with headquarters in the United States (US) and branches in France wants to test a drug in both countries. What is the organization allowed to do with the test subject's data?

  • A. Process it in the US, but store the information in France
  • B. Share it with a third party
  • C. Anonymize it and process it in the US
  • D. Aggregate it into one database in the US

Answer: C

Explanation:
Section: Security Assessment and Testing


NEW QUESTION # 157
An attack utilizing social engineering and a malicious Uniform Resource Locator (URL) link to take advantage of a victim's existing browser session with a web application is an example of which of the following types of attack?

  • A. Cross-Site Scripting (XSS)
  • B. Injection
  • C. Click jacking
  • D. Cross-site request forgery (CSRF)

Answer: D


NEW QUESTION # 158
Extensible Authentication Protocol-Message Digest 5 (EAP-MD5) only provides which of the following?

  • A. Server authentication
  • B. Mutual authentication
  • C. Streaming ciphertext data
  • D. User authentication

Answer: A


NEW QUESTION # 159
The Linux root user password is typically kept in where?(Choose two)

  • A. cmd/passwd
  • B. var/sys
  • C. etc/passwd
  • D. var/password
  • E. windows/system32
  • F. etc/shadow

Answer: C,F

Explanation:
The Linux root user password is typically kept in /etc/passwd or etc/shadow.


NEW QUESTION # 160
Which of the following processes establish the minimum national standards for certifying and accrediting national security systems?

  • A. Defense audit
  • B. NIACAP
  • C. CIAP
  • D. DITSCAP

Answer: B

Explanation:
The NIACAP provides a standard set of activities, general tasks, and
a management structure to certify and accredit systems that will maintain the information assurance and security posture of a system or site.
The NIACAP is designed to certify that the information system meets
documented accreditation requirements and will continue to maintain
the accredited security posture throughout the system life cycle.
* Answer CIAP is being developed for the evaluation of critical commercial systems and uses the NIACAP methodology.
* DITSCAP establishes for the defense entities a standard process, set of activities, general task descriptions, and a management structure to certify and accredit IT systems that will maintain the required security posture. The process is designed to certify that the IT system meets the accreditation requirements and that the system will maintain the accredited security posture throughout the system life cycle. The four phases to the DITSCAP are Definition, Verification, Validation, and
Post Accreditation.
* Answer "Defense audit" is a distracter.


NEW QUESTION # 161
Which of the following cloud deployment model is formed by the composition of two or more cloud deployment mode?

  • A. Hybrid Cloud
  • B. Public Cloud
  • C. Community Cloud
  • D. Private Cloud

Answer: A

Explanation:
In Hybrid cloud, the cloud infrastructure is a composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds)
For your exam you should know below information about Cloud Computing deployment models:
Private cloud The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by the organization, a third party, or some combination of them,and it may exist on or off premises.
Private Cloud Image Reference - http://www.inflectionpoint.co.uk/Portals/5/VMware-vCloud.jpg
Community Cloud The cloud infrastructure is provisioned for exclusive use by a specific community of consumers from organizations that have shared concerns (e.g., mission,security requirements, policy, and
compliance considerations). It may be owned, managed, and operated by one or more of the
organizations in the community, a third party, or some combination of them, and it may exist on or
off premises.
Community Cloud
Image Reference - http://cloudcomputingksu.files.wordpress.com/2012/05/community-cloud.png
Public Cloud
The cloud infrastructure is provisioned for open use by the general public. It may be owned,
managed, and operated by a business, academic, or government organization, or some
combination of them. It exists on the premises of the cloud provider.
Public Cloud
Image reference - http://definethecloud.files.wordpress.com/2010/04/image3.png
Hybrid cloud
The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private,
community, or public) that remain unique entities, but are bound together by standardized or
proprietary technology that enables data and application portability (e.g., cloud bursting for load
balancing between clouds) hybrid cloud
Image reference - http://www.virtualizationpractice.com/wp-content/uploads/2013/04/Hybrid-
Cloud-Computing-Solution1.jpg
The following answers are incorrect:
Private cloud - The cloud infrastructure is provisioned for exclusive use by a single organization
comprising multiple consumers (e.g., business units). It may be owned,managed, and operated by
the organization, a third party, or some combination of them,and it may exist on or off premises.
Community cloud - The cloud infrastructure is provisioned for exclusive use by a specific
community of consumers from organizations that have shared concerns (e.g., mission,security
requirements, policy, and compliance considerations). It may be owned, managed, and operated
by one or more of the organizations in the community, a third party, or some combination of them,
and it may exist on or off premises.
Public cloud - The cloud infrastructure is provisioned for open use by the general public. It may be
owned, managed, and operated by a business, academic, or government organization, or some
combination of them. It exists on the premises of the cloud provider.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 102 Official ISC2 guide to CISSP 3rd edition Page number 689 and 690
Topic 8, Security Assessment and Testing


NEW QUESTION # 162
......


To be eligible to take the CISSP exam, candidates must have a minimum of five years of professional work experience in the field of information security. However, if the candidate has a four-year degree, the work experience requirement is reduced to four years. Candidates who pass the CISSP exam are required to maintain their certification by earning continuing education credits and paying an annual maintenance fee.

 

Latest CISSP Exam Dumps ISC Exam from Training: https://www.actual4labs.com/ISC/CISSP-actual-exam-dumps.html

New 2025 Latest Questions CISSP Dumps - Use Updated ISC Exam: https://drive.google.com/open?id=1yIFMr0y-UsEPojtvfKXU5hnB7CTOc8sE

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now