Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the ISC Other Certification CSSLP Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the ISC CSSLP exam. To support your certification journey, we have made a selection of our premium 2026 ISC Other Certification practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

The DoD 8500 policy series represents the Department ' s information assurance strategy. Which of the following objectives are defined by the DoD 8500 series? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Defending systems

B.

Providing IA Certification and Accreditation

C.

Providing command and control and situational awareness

D.

Protecting information

Buy Now
Questions 5

Software Development Life Cycle (SDLC) is a logical process used by programmers to develop software. Which of the following SDLC phases meets the audit objectives defined below: System and data are validated. System meets all user requirements. System meets all control requirements.

Options:

A.

Evaluation and acceptance

B.

Programming and training

C.

Definition

D.

Initiation

Buy Now
Questions 6

Which of the following tiers addresses risks from an information system perspective?

Options:

A.

Tier 0

B.

Tier 3

C.

Tier 2

D.

Tier 1

Buy Now
Questions 7

Which of the following plans is designed to protect critical business processes from natural or man-made failures or disasters and the resultant loss of capital due to the unavailability of normal business processes?

Options:

A.

Contingency plan

B.

Business continuity plan

C.

Crisis communication plan

D.

Disaster recovery plan

Buy Now
Questions 8

What project management plan is most likely to direct the quantitative risk analysis process for a project in a matrix environment?

Options:

A.

Risk analysis plan

B.

Staffing management plan

C.

Risk management plan

D.

Human resource management plan

Buy Now
Questions 9

Which of the following is the process of finding weaknesses in cryptographic algorithms and obtaining the plaintext or key from the ciphertext?

Options:

A.

Cryptographer

B.

Cryptography

C.

Kerberos

D.

Cryptanalysis

Buy Now
Questions 10

Stella works as a system engineer for BlueWell Inc. She wants to identify the performance thresholds of each build. Which of the following tests will help Stella to achieve her task?

Options:

A.

Reliability test

B.

Performance test

C.

Regression test

D.

Functional test

Buy Now
Questions 11

Which of the following programming languages are compiled into machine code and directly executed by the CPU of a computer system? Each correct answer represents a complete solution. Choose two.

Options:

A.

C

B.

Microosft.NET

C.

Java EE

D.

C++

Buy Now
Questions 12

Which of the following is used by attackers to record everything a person types, including usernames, passwords, and account information?

Options:

A.

Packet sniffing

B.

Keystroke logging

C.

Spoofing

D.

Wiretapping

Buy Now
Questions 13

Which of the following access control models uses a predefined set of access privileges for an object of a system?

Options:

A.

Role-Based Access Control

B.

Discretionary Access Control

C.

Policy Access Control

D.

Mandatory Access Control

Buy Now
Questions 14

Billy is the project manager of the HAR Project and is in month six of the project. The project is scheduled to last for 18 months. Management asks Billy how often the project team is participating in risk reassessment in this project. What should Billy tell management if he ' s following the best practices for risk management?

Options:

A.

Project risk management happens at every milestone.

B.

Project risk management has been concluded with the project planning.

C.

Project risk management is scheduled for every month in the 18-month project.

D.

At every status meeting the project team project risk management is an agenda item.

Buy Now
Questions 15

Which of the following are the initial steps required to perform a risk analysis process? Each correct answer represents a part of the solution. Choose three.

Options:

A.

Valuations of the critical assets in hard costs.

B.

Evaluate potential threats to the assets.

C.

Estimate the potential losses to assets by determining their value.

D.

Establish the threats likelihood and regularity.

Buy Now
Questions 16

Adrian is the project manager of the NHP Project. In her project there are several work packages that deal with electrical wiring. Rather than to manage the risk internally she has decided to hire a vendor to complete all work packages that deal with the electrical wiring. By removing the risk internally to a licensed electrician Adrian feels more comfortable with project team being safe. What type of risk response has Adrian used in this example?

Options:

A.

Acceptance

B.

Avoidance

C.

Mitigation

D.

Transference

Buy Now
Questions 17

Which of the following technologies is used by hardware manufacturers, publishers, copyright holders and individuals to impose limitations on the usage of digital content and devices?

Options:

A.

Hypervisor

B.

Grid computing

C.

Code signing

D.

Digital rights management

Buy Now
Questions 18

In which of the following IDS evasion attacks does an attacker send a data packet such that IDS accepts the data packet but the host computer rejects it?

Options:

A.

Evasion attack

B.

Fragmentation overlap attack

C.

Fragmentation overwrite attack

D.

Insertion attack

Buy Now
Questions 19

Which of the following security architectures defines how to integrate widely disparate applications for a world that is Web-based and uses multiple implementation platforms?

Options:

A.

Sherwood Applied Business Security Architecture

B.

Enterprise architecture

C.

Service-oriented architecture

D.

Service-oriented modeling and architecture

Buy Now
Questions 20

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

NIST

B.

Office of Management and Budget (OMB)

C.

FIPS

D.

FISMA

Buy Now
Questions 21

Which of the following are the scanning methods used in penetration testing? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Vulnerability

B.

Port

C.

Services

D.

Network

Buy Now
Questions 22

Which of the following vulnerabilities occurs when an application directly uses or concatenates potentially hostile input with data file or stream functions?

Options:

A.

Insecure cryptographic storage

B.

Malicious file execution

C.

Insecure communication

D.

Injection flaw

Buy Now
Questions 23

Which of the following security models dictates that subjects can only access objects through applications?

Options:

A.

Biba model

B.

Bell-LaPadula

C.

Clark-Wilson

D.

Biba-Clark model

Buy Now
Questions 24

Which of the following are the levels of public or commercial data classification system? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Sensitive

B.

Private

C.

Unclassified

D.

Confidential

E.

Secret

F.

Public

Buy Now
Questions 25

Which of the following describes the acceptable amount of data loss measured in time?

Options:

A.

Recovery Point Objective (RPO)

B.

Recovery Time Objective (RTO)

C.

Recovery Consistency Objective (RCO)

D.

Recovery Time Actual (RTA)

Buy Now
Questions 26

Which of the following are the benefits of information classification for an organization? Each correct answer represents a complete solution. Choose two.

Options:

A.

It helps reduce the Total Cost of Ownership (TCO).

B.

It helps identify which protections apply to which information.

C.

It helps identify which information is the most sensitive or vital to an organization.

D.

It ensures that modifications are not made to data by unauthorized personnel or processes.

Buy Now
Questions 27

Which of the following elements of the BCP process emphasizes on creating the scope and the additional elements required to define the parameters of the plan?

Options:

A.

Business continuity plan development

B.

Plan approval and implementation

C.

Business impact analysis

D.

Scope and plan initiation

Buy Now
Questions 28

Which of the following classification levels defines the information that, if disclosed to the unauthorized parties, could be reasonably expected to cause exceptionally grave damage to the national security?

Options:

A.

Secret information

B.

Unclassified information

C.

Confidential information

D.

Top Secret information

Buy Now
Questions 29

John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. In order to do so, he performs the following steps of the pre-attack phase successfully: Information gathering Determination of network range Identification of active systems Location of open ports and applications Now, which of the following tasks should he perform next?

Options:

A.

Perform OS fingerprinting on the We-are-secure network.

B.

Map the network of We-are-secure Inc.

C.

Install a backdoor to log in remotely on the We-are-secure server.

D.

Fingerprint the services running on the we-are-secure network.

Buy Now
Questions 30

In which of the following processes are experienced personnel and software tools used to investigate, resolve, and handle process deviation, malformed data, infrastructure, or connectivity issues?

Options:

A.

Risk Management

B.

Exception management

C.

Configuration Management

D.

Change Management

Buy Now
Questions 31

You work as the senior project manager in SoftTech Inc. You are working on a software project using configuration management. Through configuration management you are decomposing the verification system into identifiable, understandable, manageable, traceable units that are known as Configuration Items (CIs). According to you, which of the following processes is known as the decomposition process of a verification system into Configuration Items?

Options:

A.

Configuration status accounting

B.

Configuration identification

C.

Configuration auditing

D.

Configuration control

Buy Now
Questions 32

Which of the following methods does the Java Servlet Specification v2.4 define in the HttpServletRequest interface that control programmatic security? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

getCallerIdentity()

B.

isUserInRole()

C.

getUserPrincipal()

D.

getRemoteUser()

Buy Now
Questions 33

Which of the following security controls will you use for the deployment phase of the SDLC to build secure software? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Change and Configuration Control

B.

Security Certification and Accreditation (C & A)

C.

Vulnerability Assessment and Penetration Testing

D.

Risk Adjustments

Buy Now
Questions 34

Which of the following testing methods tests the system efficiency by systematically selecting the suitable and minimum set of tests that are required to effectively cover the affected changes?

Options:

A.

Unit testing

B.

Integration testing

C.

Acceptance testing

D.

Regression testing

Buy Now
Questions 35

Which of the following security issues does the Bell-La Padula model focus on?

Options:

A.

Authorization

B.

Confidentiality

C.

Integrity

D.

Authentication

Buy Now
Questions 36

Which of the following penetration testing techniques automatically tests every phone line in an exchange and tries to locate modems that are attached to the network?

Options:

A.

Demon dialing

B.

Sniffing

C.

Social engineering

D.

Dumpster diving

Buy Now
Questions 37

In which of the following types of tests are the disaster recovery checklists distributed to the members of disaster recovery team and asked to review the assigned checklist?

Options:

A.

Parallel test

B.

Simulation test

C.

Full-interruption test

D.

Checklist test

Buy Now
Questions 38

Which of the following approaches can be used to build a security program? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Right-Up Approach

B.

Left-Up Approach

C.

Top-Down Approach

D.

Bottom-Up Approach

Buy Now
Questions 39

Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?

Options:

A.

Phase 2

B.

Phase 4

C.

Phase 1

D.

Phase 3

Buy Now
Questions 40

Which of the following security design patterns provides an alternative by requiring that a user ' s authentication credentials be verified by the database before providing access to that user ' s data?

Options:

A.

Secure assertion

B.

Authenticated session

C.

Password propagation

D.

Account lockout

Buy Now
Questions 41

Which of the following governance bodies directs and coordinates implementations of the information security program?

Options:

A.

Chief Information Security Officer

B.

Information Security Steering Committee

C.

Business Unit Manager

D.

Senior Management

Buy Now
Questions 42

You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used for computer system management and security auditing, as well as for generalized informational, analysis, and debugging messages. You want to prevent a denial of service (DoS) for the Syslog server and the loss of Syslog messages from other sources. What will you do to accomplish the task?

Options:

A.

Use a different message format other than Syslog in order to accept data.

B.

Enable the storage of log entries in both traditional Syslog files and a database.

C.

Limit the number of Syslog messages or TCP connections from a specific source for a certain time period.

D.

Encrypt rotated log files automatically using third-party or OS mechanisms.

Buy Now
Questions 43

DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and confidentiality levels. Which of the following MAC levels requires high integrity and medium availability?

Options:

A.

MAC III

B.

MAC IV

C.

MAC I

D.

MAC II

Buy Now
Questions 44

Information Security management is a process of defining the security controls in order to protect information assets. The first action of a management program to implement information security is to have a security program in place. What are the objectives of a security program? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Security education

B.

Security organization

C.

System classification

D.

Information classification

Buy Now
Questions 45

Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system?

Options:

A.

FITSAF

B.

FIPS

C.

TCSEC

D.

SSAA

Buy Now
Questions 46

What are the various benefits of a software interface according to the " Enhancing the Development Life Cycle to Produce Secure Software " document? Each correct answer represents a complete solution. Choose three.

Options:

A.

It modifies the implementation of a component without affecting the specifications of the interface.

B.

It controls the accessing of a component.

C.

It displays the implementation details of a component.

D.

It provides a programmatic way of communication between the components that are working with different programming languages.

Buy Now
Questions 47

FIPS 199 defines the three levels of potential impact on organizations: low, moderate, and high. Which of the following are the effects of loss of confidentiality, integrity, or availability in a high level potential impact?

Options:

A.

The loss of confidentiality, integrity, or availability might result in a major damage to organizational assets.

B.

The loss of confidentiality, integrity, or availability might result in severe damages like life threatening injuries or loss of life.

C.

The loss of confidentiality, integrity, or availability might result in major financial losses.

D.

The loss of confidentiality, integrity, or availability might cause severe degradation in or loss of mission capability to an extent.

Buy Now
Questions 48

Which of the following processes identifies the threats that can impact the business continuity of operations?

Options:

A.

Function analysis

B.

Risk analysis

C.

Business impact analysis

D.

Requirement analysis

Buy Now
Questions 49

Which of the following are the types of access controls? Each correct answer represents a complete solution. Choose three.

Options:

A.

Physical

B.

Technical

C.

Administrative

D.

Automatic

Buy Now
Questions 50

Which of the following attacks causes software to fail and prevents the intended users from accessing software?

Options:

A.

Enabling attack

B.

Reconnaissance attack

C.

Sabotage attack

D.

Disclosure attack

Buy Now
Questions 51

Martha registers a domain named Microsoft.in. She tries to sell it to Microsoft Corporation. The infringement of which of the following has she made?

Options:

A.

Copyright

B.

Trademark

C.

Patent

D.

Intellectual property

Buy Now
Questions 52

Which of the following access control models are used in the commercial sector? Each correct answer represents a complete solution. Choose two.

Options:

A.

Biba model

B.

Clark-Biba model

C.

Clark-Wilson model

D.

Bell-LaPadula model

Buy Now
Questions 53

Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?

Options:

A.

Authentication

B.

Integrity

C.

Non-repudiation

D.

Confidentiality

Buy Now
Questions 54

Certification and Accreditation (C & A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.

Options:

A.

Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.

B.

Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.

C.

Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.

D.

Certification is the official management decision given by a senior agency official to authorize operation of an information system.

Buy Now
Questions 55

Which of the following is a signature-based intrusion detection system (IDS) ?

Options:

A.

RealSecure

B.

StealthWatch

C.

Tripwire

D.

Snort

Buy Now
Questions 56

You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following purposes: Analyze the data from different log sources Correlate the events among the log entries Identify and prioritize significant events Initiate responses to events if required One of your log monitoring staff wants to know the features of SIEM product that will help them in these purposes. What features will you recommend? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Asset information storage and correlation

B.

Transmission confidentiality protection

C.

Incident tracking and reporting

D.

Security knowledge base

E.

Graphical user interface

Buy Now
Questions 57

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

What is being secured?

B.

Where is the vulnerability, threat, or risk?

C.

Who is expected to exploit the vulnerability?

D.

Who is expected to comply with the policy?

Buy Now
Questions 58

Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy?

Options:

A.

Local Computing Environments

B.

Networks and Infrastructures

C.

Supporting Infrastructures

D.

Enclave Boundaries

Buy Now
Questions 59

Which of the following rated systems of the Orange book has mandatory protection of the TCB?

Options:

A.

A-rated

B.

B-rated

C.

D-rated

D.

C-rated

Buy Now
Questions 60

Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one?

Options:

A.

Configuration Identification

B.

Configuration Verification and Auditing

C.

Configuration Status Accounting

D.

Configuration Item Costing

Buy Now
Questions 61

You work as a systems engineer for BlueWell Inc. Which of the following tools will you use to look outside your own organization to examine how others achieve their performance levels, and what processes they use to reach those levels?

Options:

A.

Benchmarking

B.

Six Sigma

C.

ISO 9001:2000

D.

SEI-CMM

Buy Now
Questions 62

Which of the following phases of DITSCAP includes the activities that are necessary for the continuing operation of an accredited IT system in its computing environment and for addressing the changing threats that a system faces throughout its life cycle?

Options:

A.

Phase 3, Validation

B.

Phase 1, Definition

C.

Phase 2, Verification

D.

Phase 4, Post Accreditation Phase

Buy Now
Questions 63

The IAM/CA makes certification accreditation recommendations to the DAA. The DAA issues accreditation determinations. Which of the following are the accreditation determinations issued by the DAA? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

IATT

B.

IATO

C.

DATO

D.

ATO

E.

ATT

Buy Now
Questions 64

Which of the following secure coding principles and practices defines the appearance of code listing so that a code reviewer and maintainer who have not written that code can easily understand it?

Options:

A.

Make code forward and backward traceable

B.

Review code during and after coding

C.

Use a consistent coding style

D.

Keep code simple and small

Buy Now
Questions 65

Which of the following life cycle modeling activities establishes service relationships and message exchange paths?

Options:

A.

Service-oriented logical design modeling

B.

Service-oriented conceptual architecture modeling

C.

Service-oriented discovery and analysis modeling

D.

Service-oriented business integration modeling

Buy Now
Questions 66

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?

Options:

A.

Level 2

B.

Level 3

C.

Level 5

D.

Level 1

E.

Level 4

Buy Now
Questions 67

Bill is the project manager of the JKH Project. He and the project team have identified a risk event in the project with a high probability of occurrence and the risk event has a high cost impact on the project. Bill discusses the risk event with Virginia, the primary project customer, and she decides that the requirements surrounding the risk event should be removed from the project. The removal of the requirements does affect the project scope, but it can release the project from the high risk exposure. What risk response has been enacted in this project?

Options:

A.

Mitigation

B.

Transference

C.

Acceptance

D.

Avoidance

Buy Now
Questions 68

Microsoft software security expert Michael Howard defines some heuristics for determining code review in " A Process for Performing Security Code Reviews " . Which of the following heuristics increase the application ' s attack surface? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Code written in C/C++/assembly language

B.

Code listening on a globally accessible network interface

C.

Code that changes frequently

D.

Anonymously accessible code

E.

Code that runs by default

F.

Code that runs in elevated context

Buy Now
Questions 69

The Phase 4 of DITSCAP C & A is known as Post Accreditation. This phase starts after the system has been accredited in Phase 3. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Security operations

B.

Maintenance of the SSAA

C.

Compliance validation

D.

Change management

E.

System operations

F.

Continue to review and refine the SSAA

Buy Now
Questions 70

The NIST Information Security and Privacy Advisory Board (ISPAB) paper " Perspectives on Cloud Computing and Standards " specifies potential advantages and disdvantages of virtualization. Which of the following disadvantages does it include? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It increases capabilities for fault tolerant computing using rollback and snapshot features.

B.

It increases intrusion detection through introspection.

C.

It initiates the risk that malicious software is targeting the VM environment.

D.

It increases overall security risk shared resources.

E.

It creates the possibility that remote attestation may not work.

F.

It involves new protection mechanisms for preventing VM escape, VM detection, and VM-VM interference.

G.

It increases configuration effort because of complexity and composite system.

Buy Now
Questions 71

You and your project team have identified the project risks and now are analyzing the probability and impact of the risks. What type of analysis of the risks provides a quick and high-level review of each identified risk event?

Options:

A.

Quantitative risk analysis

B.

Qualitative risk analysis

C.

Seven risk responses

D.

A risk probability-impact matrix

Buy Now
Questions 72

Which of the following is designed to detect unwanted attempts at accessing, manipulating, and disabling of computer systems through the Internet?

Options:

A.

DAS

B.

IPsec

C.

IDS

D.

ACL

Buy Now
Questions 73

Which of the following process areas does the SSE-CMM define in the ' Project and Organizational Practices ' category? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Provide Ongoing Skills and Knowledge

B.

Verify and Validate Security

C.

Manage Project Risk

D.

Improve Organization ' s System Engineering Process

Buy Now
Questions 74

Digital rights management (DRM) consists of compliance and robustness rules. Which of the following features does the robustness rule have? Each correct answer represents a complete solution. Choose three.

Options:

A.

It specifies the various levels of robustness that are needed for asset security.

B.

It specifies minimum techniques for asset security.

C.

It specifies the behaviors of the DRM implementation and applications accessing the implementation.

D.

It contains assets, such as device key, content key, algorithm, and profiling data.

Buy Now
Questions 75

Which of the following techniques is used when a system performs the penetration testing with the objective of accessing unauthorized information residing inside a computer?

Options:

A.

Biometrician

B.

Van Eck Phreaking

C.

Port scanning

D.

Phreaking

Buy Now
Questions 76

Continuous Monitoring is the fourth phase of the security certification and accreditation process. What activities are performed in the Continuous Monitoring process? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Security accreditation decision

B.

Security control monitoring and impact analyses of changes to the information system

C.

Security accreditation documentation

D.

Configuration management and control

E.

Status reporting and documentation

Buy Now
Questions 77

Which of the following provides an easy way to programmers for writing lower-risk applications and retrofitting security into an existing application?

Options:

A.

Watermarking

B.

ESAPI

C.

Encryption wrapper

D.

Code obfuscation

Buy Now
Questions 78

Which of the following provides an easy way to programmers for writing lower-risk applications and retrofitting security into an existing application?

Options:

A.

Watermarking

B.

Code obfuscation

C.

Encryption wrapper

D.

ESAPI

Buy Now
Questions 79

You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C & A effort of a legacy system?

Options:

A.

Validation

B.

Definition

C.

Verification

D.

Post Accreditation

Buy Now
Questions 80

Which of the following types of obfuscation transformation increases the difficulty for a de- obfuscation tool so that it cannot extract the true application from the obfuscated version?

Options:

A.

Preventive transformation

B.

Data obfuscation

C.

Control obfuscation

D.

Layout obfuscation

Buy Now
Questions 81

An attacker exploits actual code of an application and uses a security hole to carry out an attack before the application vendor knows about the vulnerability. Which of the following types of attack is this?

Options:

A.

Replay

B.

Zero-day

C.

Man-in-the-middle

D.

Denial-of-Service

Buy Now
Questions 82

Which of the following is an attack with IP fragments that cannot be reassembled?

Options:

A.

Password guessing attack

B.

Teardrop attack

C.

Dictionary attack

D.

Smurf attack

Buy Now
Questions 83

Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?

Options:

A.

Security Test and Evaluation (ST & E)

B.

Penetration testing

C.

Automated vulnerability scanning tool

D.

On-site interviews

Buy Now
Questions 84

Which of the following is generally used in packages in order to determine the package or product tampering?

Options:

A.

Tamper resistance

B.

Tamper evident

C.

Tamper data

D.

Tamper proof

Buy Now
Questions 85

Which of the following security objectives are defined for information and information systems by the FISMA? Each correct answer represents a part of the solution. Choose all that apply.

Options:

A.

Authenticity

B.

Availability

C.

Integrity

D.

Confidentiality

Buy Now
Questions 86

Which of the following security design principles supports comprehensive and simple design and implementation of protection mechanisms, so that an unintended access path does not exist or can be readily identified and eliminated?

Options:

A.

Least privilege

B.

Economy of mechanism

C.

Psychological acceptability

D.

Separation of duties

Buy Now
Questions 87

The Phase 2 of DITSCAP C & A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Certification analysis

B.

Assessment of the Analysis Results

C.

Configuring refinement of the SSAA

D.

System development

E.

Registration

Buy Now
Questions 88

John works as a security manager for SoftTech Inc. He is working with his team on the disaster recovery management plan. One of his team members has a doubt related to the most cost effective DRP testing plan. According to you, which of the following disaster recovery testing plans is the most cost-effective and efficient way to identify areas of overlap in the plan before conducting more demanding training exercises?

Options:

A.

Full-scale exercise

B.

Walk-through drill

C.

Structured walk-through test

D.

Evacuation drill

Buy Now
Questions 89

Which of the following statements describe the main purposes of a Regulatory policy? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It acknowledges the importance of the computing resources to the business model

B.

It provides a statement of support for information security throughout the enterprise

C.

It ensures that an organization is following the standard procedures or base practices of operation in its specific industry.

D.

It gives an organization the confidence that it is following the standard and accepted industry policy.

Buy Now
Questions 90

Which of the following are the primary functions of configuration management?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It removes the risk event entirely by adding additional steps to avoid the event.

B.

It ensures that the change is implemented in a sequential manner through formalized testing.

C.

It reduces the negative impact that the change might have had on the computing services and resources.

D.

It analyzes the effect of the change that is implemented on the system.

Buy Now
Questions 91

Which of the following governance bodies provides management, operational and technical controls to satisfy security requirements?

Options:

A.

Senior Management

B.

Business Unit Manager

C.

Information Security Steering Committee

D.

Chief Information Security Officer

Buy Now
Questions 92

Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that are required for them. Which of the following access control models will he use?

Options:

A.

Discretionary Access Control

B.

Mandatory Access Control

C.

Policy Access Control

D.

Role-Based Access Control

Buy Now
Questions 93

In which of the following deployment models of cloud is the cloud infrastructure administered by the organizations or a third party? Each correct answer represents a complete solution. Choose two.

Options:

A.

Private cloud

B.

Public cloud

C.

Hybrid cloud

D.

Community cloud

Buy Now
Questions 94

Which of the following concepts represent the three fundamental principles of information security? Each correct answer represents a complete solution. Choose three.

Options:

A.

Privacy

B.

Availability

C.

Integrity

D.

Confidentiality

Buy Now
Questions 95

Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee ' s computer while he is typing in his password at any access point such as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?

Options:

A.

Integrity

B.

Availability

C.

Confidentiality

D.

Authenticity

Buy Now
Questions 96

In which type of access control do user ID and password system come under?

Options:

A.

Physical

B.

Technical

C.

Power

D.

Administrative

Buy Now
Questions 97

Which of the following are the responsibilities of the owner with regard to data in an information classification program? Each correct answer represents a complete solution. Choose three.

Options:

A.

Reviewing the classification assignments at regular time intervals and making changes as the business needs change.

B.

Running regular backups and routinely testing the validity of the backup data.

C.

Delegating the responsibility of the data protection duties to a custodian.

D.

Determining what level of classification the information requires.

Buy Now
Questions 98

In which of the following phases of the SDLC does the software and other components of the system faithfully incorporate the design specifications and provide proper documentation and training?

Options:

A.

Design

B.

Evaluation and acceptance

C.

Programming and training

D.

Initiation

Buy Now
Questions 99

Which of the following characteristics are described by the DIAP Information Readiness Assessment function? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It provides for entry and storage of individual system data.

B.

It performs vulnerability/threat analysis assessment.

C.

It provides data needed to accurately assess IA readiness.

D.

It identifies and generates IA requirements.

Buy Now
Questions 100

Samantha works as an Ethical Hacker for we-are-secure Inc. She wants to test the security of the we-are-secure server for DoS attacks. She sends large number of ICMP ECHO packets to the target computer. Which of the following DoS attacking techniques will she use to accomplish the task?

Options:

A.

Smurf dos attack

B.

Land attack

C.

Ping flood attack

D.

Teardrop attack

Buy Now
Questions 101

You are the project manager of the GHY project for your organization. You are about to start the qualitative risk analysis process for the project and you need to determine the roles and responsibilities for conducting risk management. Where can you find this information?

Options:

A.

Risk register

B.

Staffing management plan

C.

Risk management plan

D.

Enterprise environmental factors

Buy Now
Questions 102

Which of the following security models focuses on data confidentiality and controlled access to classified information?

Options:

A.

Clark-Wilson model

B.

Biba model

C.

Take-Grant model

D.

Bell-La Padula model

Buy Now
Questions 103

Rob is the project manager of the IDLK Project for his company. This project has a budget of $5,600,000 and is expected to last 18 months. Rob has learned that a new law may affect how the project is allowed to proceed - even though the organization has already invested over $750,000 in the project. What risk response is the most appropriate for this instance?

Options:

A.

Transference

B.

Enhance

C.

Mitigation

D.

Acceptance

Buy Now
Questions 104

John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He finds that the We-are-secure server is vulnerable to attacks. As a countermeasure, he suggests that the Network Administrator should remove the IPP printing capability from the server. He is suggesting this as a countermeasure against __________.

Options:

A.

SNMP enumeration

B.

IIS buffer overflow

C.

NetBIOS NULL session

D.

DNS zone transfer

Buy Now
Exam Code: CSSLP
Exam Name: Certified Secure Software Lifecycle Professional
Last Update: Sep 11, 2026
Questions: 349

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11