Free HCISPP Exam Braindumps (page: 17)

Page 16 of 77

Which of the following BEST describes the purpose of performing security certification?

  1. To identify system threats, vulnerabilities, and acceptable level of risk
  2. To formalize the confirmation of compliance to security policies and standards
  3. To formalize the confirmation of completed risk mitigation and risk analysis
  4. To verify that system architecture and interconnections with other systems are effectively implemented

Answer(s): B



The BEST method to mitigate the risk of a dictionary attack on a system is to

  1. use a hardware token.
  2. use complex passphrases.
  3. implement password history.
  4. encrypt the access control list(ACL).

Answer(s): A



In general, servers that are facing the Internet should be placed in ademilitarized zone (DMZ). What is MAIN purpose of the DMZ?

  1. Reduced risk to internal systems.
  2. Prepare the server for potential attacks.
  3. Mitigate the risk associated with the exposed server.
  4. Bypass the need for a firewall.

Answer(s): A



DRAG DROP (Drag & Drop is not supported)
Drag the following Security Engineering terms on the left to the BEST definition on the right.

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Risk - A measure of the extent to which an entity is threatened by a potential circumstance of event, the adverse impacts that would arise if the circumstance or event occurs, and the likelihood of occurrence.
Protection Needs Assessment - The method used to identify the confidentiality, integrity, and availability requirements for organizational and system asset and to characterizerize the adverse impact or consequences should be asset be lost, modified, degraded, disrupted, compromised, or become unavailable.
Threat assessment - The method used to identify and characterize the dangers anticipated throughout the life cycle of the system.
Security Risk Treatment - The method used to identify feasible security risk mitigation options and plans.






Post your Comments and Discuss ISC2 HCISPP exam with other Community members:

HCISPP Discussions & Posts