{"id":311,"date":"2022-06-12T18:48:16","date_gmt":"2022-06-12T18:48:16","guid":{"rendered":"https:\/\/blog.examboosts.com\/?p=311"},"modified":"2022-06-12T18:48:16","modified_gmt":"2022-06-12T18:48:16","slug":"csslp-braindumps-real-exam-updated-on-jun-12-2022-with-349-questions-q121-q143","status":"publish","type":"post","link":"https:\/\/blog.examboosts.com\/fr\/2022\/06\/csslp-braindumps-real-exam-updated-on-jun-12-2022-with-349-questions-q121-q143\/","title":{"rendered":"CSSLP Braindumps Real Exam Updated on Jun 12, 2022 with 349 Questions [Q121-Q143]"},"content":{"rendered":"\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-top\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;311&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;top&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;Rate this post&quot;,&quot;legend&quot;:&quot;0\\\/5 - (0 vote)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;CSSLP Braindumps Real Exam Updated on Jun 12, 2022 with 349 Questions [Q121-Q143]&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 0px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 19.2px;\">\n            <span class=\"kksr-muted\">Rate this post<\/span>\n    <\/div>\n    <\/div>\n<p><strong><span style=\"font-size: 18px;color: red\">CSSLP Braindumps Real Exam Updated on Jun 12, 2022 with 349 Questions<\/span><\/strong><\/p>\n<p><strong><span style=\"color: red\">Latest CSSLP PDF Dumps &amp; Real Tests Free Updated Today<\/span><\/strong><\/p>\n<p><\/p>\n<h3>Secure Software Lifecycle Management (11%):<\/h3>\n<ul>\n<li>Decommission software;<\/li>\n<li>Integrate IRM (Integrated Risk Management);<\/li>\n<li>Develop the security metrics, including defects-per-line-code, average remediation time, criticality level, and complexity;<\/li>\n<li>Establish the standards and frameworks for security;<\/li>\n<li>Explain roadmap and strategy;<\/li>\n<\/ul>\n<p><\/p>\n<h3>Why use ExamBoosts to study<\/h3>\n<p>ExamBoosts is a central hub for all people looking for information and resources regarding certification exams we create an extremely accurate and loyal web and mobile exam simulator. ExamBoosts is providing a set of CSSLP exam questions with the answers. CSSLP practice exams have been built to imitate the real exam.<\/p>\n<p>&nbsp;<\/p>\n<div id=\"watu_quiz\" class=\"quiz-area single-page-quiz\">\n<form action=\"\" method=\"post\" class=\"quiz-form \" id=\"quiz-150\" >\n<div class='watu-question' id='question-1'><div class='question-content'><p><strong>NO.121<\/strong> Which of the following are the scanning methods used in penetration testing? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2860' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11339' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2860[]' id='answer-id-11339' class='answer answer-1 php-answer-label answerof-2860' value='11339' \/>&nbsp;<label for='answer-id-11339' id='answer-label-11339' class='php-answer-label answer label-1'><span class='answer'>Vulnerability<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11340' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2860[]' id='answer-id-11340' class='answer answer-1 php-answer-label answerof-2860' value='11340' \/>&nbsp;<label for='answer-id-11340' id='answer-label-11340' class='php-answer-label answer label-1'><span class='answer'>Port<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11341' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2860[]' id='answer-id-11341' class='answer answer-1 js-answer-label answerof-2860' value='11341' \/>&nbsp;<label for='answer-id-11341' id='answer-label-11341' class='js-answer-label answer label-1'><span class='answer'>Services<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11342' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2860[]' id='answer-id-11342' class='answer answer-1 php-answer-label answerof-2860' value='11342' \/>&nbsp;<label for='answer-id-11342' id='answer-label-11342' class='php-answer-label answer label-1'><span class='answer'>Network<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The vulnerability, port, and network scanning tools are used in penetration testing.<br\/>Vulnerability scanning is a process in which a Penetration Tester uses various tools to assess computers, computer systems, networks or applications for weaknesses. There are a number of types of vulnerability scanners available today, distinguished from one another by a focus on particular targets. While functionality varies between different types of vulnerability scanners, they share a common, core purpose of enumerating the vulnerabilities present in one or more targets. Vulnerability scanners are a core technology component of Vulnerability management. Port scanning is the first basic step to get the details of open ports on the target system. Port scanning is used to find a hackable server with a hole or vulnerability. A port is a medium of communication between two computers. Every service on a host is identified by a unique 16-bit number called a port. A port scanner is a piece of software designed to search a network host for open ports. This is often used by administrators to check the security of their networks and by hackers to identify running services on a host with the view to compromising it. Port scanning is used to find the open ports, so that it is possible to search exploits related to that service and application.<br\/>Network scanning is a penetration testing activity in which a penetration tester or an attacker identifies active hosts on a network, either to attack them or to perform security assessment. A penetration tester uses various tools to identify all the live or responding hosts on the network and their corresponding IP addresses. AnswerC is incorrect. This option comes under vulnerability scanning.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(1,this)' id='btn-1' value='See Answer'  \/><input type='hidden' id='questionType1' value='checkbox' class=''><\/div><div class='watu-question' id='question-2'><div class='question-content'><p><strong>NO.122<\/strong> Which of the following are the benefits of information classification for an organization? Each correct answer represents a complete solution. Choose two.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2861' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11343' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2861[]' id='answer-id-11343' class='answer answer-2 js-answer-label answerof-2861' value='11343' \/>&nbsp;<label for='answer-id-11343' id='answer-label-11343' class='js-answer-label answer label-2'><span class='answer'>It helps reduce the Total Cost of Ownership (TCO).<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11344' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2861[]' id='answer-id-11344' class='answer answer-2 php-answer-label answerof-2861' value='11344' \/>&nbsp;<label for='answer-id-11344' id='answer-label-11344' class='php-answer-label answer label-2'><span class='answer'>It helps identify which protections apply to which information.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11345' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2861[]' id='answer-id-11345' class='answer answer-2 php-answer-label answerof-2861' value='11345' \/>&nbsp;<label for='answer-id-11345' id='answer-label-11345' class='php-answer-label answer label-2'><span class='answer'>It helps identify which information is the most sensitive or vital to an organization.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11346' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2861[]' id='answer-id-11346' class='answer answer-2 js-answer-label answerof-2861' value='11346' \/>&nbsp;<label for='answer-id-11346' id='answer-label-11346' class='js-answer-label answer label-2'><span class='answer'>It ensures that modifications are not made to data by unauthorized personnel or processes.<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Following are the benefits of information classification for an organization: It helps identify which protections apply to which information. It helps identify which information is the most sensitive or vital to an organization. It supports the tenets of confidentiality, integrity, and availability as it pertains to data. Answer D is incorrect. The concept of integrity ensures that modifications are not made to data by unauthorized personnel or processes. It also ensures that unauthorized modifications are not made to data by authorized personnel or processes. Answer A is incorrect. Information classification cannot reduce the Total Cost of Ownership (TCO).<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(2,this)' id='btn-2' value='See Answer'  \/><input type='hidden' id='questionType2' value='checkbox' class=''><\/div><div class='watu-question' id='question-3'><div class='question-content'><p><strong>NO.123<\/strong> The rights of an author or a corporation to make profit from the creation of their products (such as software, music, etc.) are protected by the Intellectual Property law. Which of the following are the components of the Intellectual Property law? Each correct answer represents a part of the solution. Choose two.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2862' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11347' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2862[]' id='answer-id-11347' class='answer answer-3 js-answer-label answerof-2862' value='11347' \/>&nbsp;<label for='answer-id-11347' id='answer-label-11347' class='js-answer-label answer label-3'><span class='answer'>Trademark law<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11348' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2862[]' id='answer-id-11348' class='answer answer-3 php-answer-label answerof-2862' value='11348' \/>&nbsp;<label for='answer-id-11348' id='answer-label-11348' class='php-answer-label answer label-3'><span class='answer'>Industrial Property law<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11349' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2862[]' id='answer-id-11349' class='answer answer-3 php-answer-label answerof-2862' value='11349' \/>&nbsp;<label for='answer-id-11349' id='answer-label-11349' class='php-answer-label answer label-3'><span class='answer'>Copyright law<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11350' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2862[]' id='answer-id-11350' class='answer answer-3 js-answer-label answerof-2862' value='11350' \/>&nbsp;<label for='answer-id-11350' id='answer-label-11350' class='js-answer-label answer label-3'><span class='answer'>Patent law<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The Industrial Property law and the Copyright law are the components of the Intellectual Property law.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(3,this)' id='btn-3' value='See Answer'  \/><input type='hidden' id='questionType3' value='checkbox' class=''><\/div><div class='watu-question' id='question-4'><div class='question-content'><p><strong>NO.124<\/strong> Adrian is the project manager of the NHP Project. In her project there are several work packages that deal with electrical wiring. Rather than to manage the risk internally she has decided to hire a vendor to complete all work packages that deal with the electrical wiring. By removing the risk internally to a licensed electrician Adrian feels more comfortable with project team being safe. What type of risk response has Adrian used in this example?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2863' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11351' \/><div class='watu-question-choice'><input type='radio' name='answer-2863[]' id='answer-id-11351' class='answer answer-4 js-answer-label answerof-2863' value='11351' \/>&nbsp;<label for='answer-id-11351' id='answer-label-11351' class='js-answer-label answer label-4'><span class='answer'>Acceptance<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11352' \/><div class='watu-question-choice'><input type='radio' name='answer-2863[]' id='answer-id-11352' class='answer answer-4 js-answer-label answerof-2863' value='11352' \/>&nbsp;<label for='answer-id-11352' id='answer-label-11352' class='js-answer-label answer label-4'><span class='answer'>Avoidance<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11353' \/><div class='watu-question-choice'><input type='radio' name='answer-2863[]' id='answer-id-11353' class='answer answer-4 js-answer-label answerof-2863' value='11353' \/>&nbsp;<label for='answer-id-11353' id='answer-label-11353' class='js-answer-label answer label-4'><span class='answer'>Mitigation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11354' \/><div class='watu-question-choice'><input type='radio' name='answer-2863[]' id='answer-id-11354' class='answer answer-4 php-answer-label answerof-2863' value='11354' \/>&nbsp;<label for='answer-id-11354' id='answer-label-11354' class='php-answer-label answer label-4'><span class='answer'>Transference<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: This is an example of transference. When the risk is transferred to a third party, usually for a fee, it creates a contractual-relationship for the third party to manage the risk on behalf of the performing organization. Risk response planning is a method of developing options to decrease the amount of threats and make the most of opportunities. The risk response should be aligned with the consequence of the risk and cost-effectiveness. This planning documents the processes for managing risk events. It addresses the owners and their responsibilities, risk identification, results from qualification and quantification processes, budgets and times for responses, and contingency plans. The various risk response planning techniques are as follows: Risk acceptance: It indicates that the project team has decided not to change the project management plan to deal with a risk, or is unable to identify any other suitable response strategy. Risk avoidance: It is a technique for a threat, which creates changes to the project management plan that are meant to either eliminate the risk or to protect the project objectives from this impact. Risk mitigation: It is a list of specific actions being taken to deal with specific risks associated with the threats and seeks to reduce the probability of occurrence or impact of risk below an acceptable threshold. Risk transference: It is used to shift the impact of a threat to a third party, together with the ownership of the response.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(4,this)' id='btn-4' value='See Answer'  \/><input type='hidden' id='questionType4' value='radio' class=''><\/div><div class='watu-question' id='question-5'><div class='question-content'><p><strong>NO.125<\/strong> Which of the following are the primary functions of configuration management?<br \/>Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2864' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11355' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2864[]' id='answer-id-11355' class='answer answer-5 js-answer-label answerof-2864' value='11355' \/>&nbsp;<label for='answer-id-11355' id='answer-label-11355' class='js-answer-label answer label-5'><span class='answer'>It removes the risk event entirely by adding additional steps to avoid the event.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11356' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2864[]' id='answer-id-11356' class='answer answer-5 php-answer-label answerof-2864' value='11356' \/>&nbsp;<label for='answer-id-11356' id='answer-label-11356' class='php-answer-label answer label-5'><span class='answer'>It ensures that the change is implemented in a sequential manner through formalized testing.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11357' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2864[]' id='answer-id-11357' class='answer answer-5 php-answer-label answerof-2864' value='11357' \/>&nbsp;<label for='answer-id-11357' id='answer-label-11357' class='php-answer-label answer label-5'><span class='answer'>It reduces the negative impact that the change might have had on the computing services and resources.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11358' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2864[]' id='answer-id-11358' class='answer answer-5 php-answer-label answerof-2864' value='11358' \/>&nbsp;<label for='answer-id-11358' id='answer-label-11358' class='php-answer-label answer label-5'><span class='answer'>It analyzes the effect of the change that is implemented on the system.<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The primary functions of configuration management are as follows: It ensures that the change is implemented in a sequential manner through formalized testing. It ensures that the user base is informed of the future change. It analyzes the effect of the change that is implemented on the system. It reduces the negative impact that the change might have had on the computing services and resources. AnswerA is incorrect. It is not one of the primary functions of configuration management. It is the function of risk avoidance.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(5,this)' id='btn-5' value='See Answer'  \/><input type='hidden' id='questionType5' value='checkbox' class=''><\/div><div class='watu-question' id='question-6'><div class='question-content'><p><strong>NO.126<\/strong> In which of the following IDS evasion attacks does an attacker send a data packet such that IDS accepts the data packet but the host computer rejects it?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2865' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11359' \/><div class='watu-question-choice'><input type='radio' name='answer-2865[]' id='answer-id-11359' class='answer answer-6 js-answer-label answerof-2865' value='11359' \/>&nbsp;<label for='answer-id-11359' id='answer-label-11359' class='js-answer-label answer label-6'><span class='answer'>Evasion attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11360' \/><div class='watu-question-choice'><input type='radio' name='answer-2865[]' id='answer-id-11360' class='answer answer-6 js-answer-label answerof-2865' value='11360' \/>&nbsp;<label for='answer-id-11360' id='answer-label-11360' class='js-answer-label answer label-6'><span class='answer'>Fragmentation overlap attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11361' \/><div class='watu-question-choice'><input type='radio' name='answer-2865[]' id='answer-id-11361' class='answer answer-6 js-answer-label answerof-2865' value='11361' \/>&nbsp;<label for='answer-id-11361' id='answer-label-11361' class='js-answer-label answer label-6'><span class='answer'>Fragmentation overwrite attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11362' \/><div class='watu-question-choice'><input type='radio' name='answer-2865[]' id='answer-id-11362' class='answer answer-6 php-answer-label answerof-2865' value='11362' \/>&nbsp;<label for='answer-id-11362' id='answer-label-11362' class='php-answer-label answer label-6'><span class='answer'>Insertion attack<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>In an insertion attack, an IDS accepts a packet and assumes that the host computer will also accept it. But in reality, when a host system rejects the packet, the IDS accepts the attacking string that will exploit vulnerabilities in the IDS. Such attacks can badly infect IDS signatures and IDS signature analysis. Answer B is incorrect. In this approach, an attacker sends packets in such a manner that one packet fragment overlaps data from a previous fragment. The information is organized in the packets in such a manner that when the victim&#8217;s computer reassembles the packets, an attack string is executed on the victim&#8217;s computer. Since the attacking string is in fragmented form, IDS is unable to detect it. Answer C is incorrect. In this approach, an attacker sends packets in such a manner that one packet fragment overwrites data from a previous fragment. The information is organized into the packets in such a manner that when the victim&#8217;s computer reassembles the packets, an attack string is executed on the victim&#8217;s computer. Since the attacking string is in fragmented form, IDS becomes unable to detect it. Answer A is incorrect. An evasion attack is one in which an IDS rejects a malicious packet but the host computer accepts it. Since an IDS has rejected it, it does not check the contents of the packet. Hence, using this technique, an attacker can exploit the host computer. In many cases, it is quite simple for an attacker to send such data packets that can easily perform evasion attacks on an IDSs.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(6,this)' id='btn-6' value='See Answer'  \/><input type='hidden' id='questionType6' value='radio' class=''><\/div><div class='watu-question' id='question-7'><div class='question-content'><p><strong>NO.127<\/strong> Which of the following are the principle duties performed by the BIOS during POST (power-on-self-test)?<br \/>Each correct answer represents a part of the solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2866' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11363' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11363' class='answer answer-7 php-answer-label answerof-2866' value='11363' \/>&nbsp;<label for='answer-id-11363' id='answer-label-11363' class='php-answer-label answer label-7'><span class='answer'>It provides a user interface for system&#8217;s configuration.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11364' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11364' class='answer answer-7 php-answer-label answerof-2866' value='11364' \/>&nbsp;<label for='answer-id-11364' id='answer-label-11364' class='php-answer-label answer label-7'><span class='answer'>It identifies, organizes, and selects boot devices.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11365' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11365' class='answer answer-7 php-answer-label answerof-2866' value='11365' \/>&nbsp;<label for='answer-id-11365' id='answer-label-11365' class='php-answer-label answer label-7'><span class='answer'>It delegates control to other BIOS, if it is required.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11366' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11366' class='answer answer-7 php-answer-label answerof-2866' value='11366' \/>&nbsp;<label for='answer-id-11366' id='answer-label-11366' class='php-answer-label answer label-7'><span class='answer'>It discovers size and verifies system memory.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11367' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11367' class='answer answer-7 php-answer-label answerof-2866' value='11367' \/>&nbsp;<label for='answer-id-11367' id='answer-label-11367' class='php-answer-label answer label-7'><span class='answer'>It verifies the integrity of the BIOS code itself.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11368' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2866[]' id='answer-id-11368' class='answer answer-7 js-answer-label answerof-2866' value='11368' \/>&nbsp;<label for='answer-id-11368' id='answer-label-11368' class='js-answer-label answer label-7'><span class='answer'>It interrupts the execution of all running programs.<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The principle duties performed by the BIOS during POST (power-on-self-test) are as follows:<br\/>It verifies the integrity of the BIOS code itself. It discovers size and verifies system memory. It discovers, initializes, and catalogs all system hardware. It delegates control to other BIOS if it is required. It provides a user interface for system&#8217;s configuration. It identifies, organizes, and selects boot devices. It executes the bootstrap program. AnswerF is incorrect. The BIOS does not interrupt the execution of all running programs.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(7,this)' id='btn-7' value='See Answer'  \/><input type='hidden' id='questionType7' value='checkbox' class=''><\/div><div class='watu-question' id='question-8'><div class='question-content'><p><strong>NO.128<\/strong> Penetration tests are sometimes called white hat attacks because in a pen test, the good guys are attempting to break in. What are the different categories of penetration testing? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2867' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11369' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11369' class='answer answer-8 php-answer-label answerof-2867' value='11369' \/>&nbsp;<label for='answer-id-11369' id='answer-label-11369' class='php-answer-label answer label-8'><span class='answer'>Open-box<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11370' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11370' class='answer answer-8 php-answer-label answerof-2867' value='11370' \/>&nbsp;<label for='answer-id-11370' id='answer-label-11370' class='php-answer-label answer label-8'><span class='answer'>Closed-box<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11371' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11371' class='answer answer-8 php-answer-label answerof-2867' value='11371' \/>&nbsp;<label for='answer-id-11371' id='answer-label-11371' class='php-answer-label answer label-8'><span class='answer'>Zero-knowledge test<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11372' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11372' class='answer answer-8 js-answer-label answerof-2867' value='11372' \/>&nbsp;<label for='answer-id-11372' id='answer-label-11372' class='js-answer-label answer label-8'><span class='answer'>Full-box<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11373' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11373' class='answer answer-8 php-answer-label answerof-2867' value='11373' \/>&nbsp;<label for='answer-id-11373' id='answer-label-11373' class='php-answer-label answer label-8'><span class='answer'>Full-knowledge test<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11374' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2867[]' id='answer-id-11374' class='answer answer-8 php-answer-label answerof-2867' value='11374' \/>&nbsp;<label for='answer-id-11374' id='answer-label-11374' class='php-answer-label answer label-8'><span class='answer'>Partial-knowledge test<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The different categories of penetration testing are as follows: Open-box: In this category of penetration testing, testers have access to internal system code. This mode is basically suited for Unix or Linux. Closed-box: In this category of penetration testing, testers do not have access to closed systems.<br\/>This method is good for closed systems. Zero-knowledge test: In this category of penetration testing, testers have to acquire information from scratch and they are not supplied with information concerning the IT system. Partial-knowledge test: In this category of penetration testing, testers have knowledge that may be applicable to a specific type of attack and associated vulnerabilities. Full-knowledge test: In this category of penetration testing, testers have massive knowledge concerning the information system to be evaluated. AnswerD is incorrect. There is no such category of penetration testing.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(8,this)' id='btn-8' value='See Answer'  \/><input type='hidden' id='questionType8' value='checkbox' class=''><\/div><div class='watu-question' id='question-9'><div class='question-content'><p><strong>NO.129<\/strong> Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2868' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11375' \/><div class='watu-question-choice'><input type='radio' name='answer-2868[]' id='answer-id-11375' class='answer answer-9 js-answer-label answerof-2868' value='11375' \/>&nbsp;<label for='answer-id-11375' id='answer-label-11375' class='js-answer-label answer label-9'><span class='answer'>FITSAF<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11376' \/><div class='watu-question-choice'><input type='radio' name='answer-2868[]' id='answer-id-11376' class='answer answer-9 js-answer-label answerof-2868' value='11376' \/>&nbsp;<label for='answer-id-11376' id='answer-label-11376' class='js-answer-label answer label-9'><span class='answer'>FIPS<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11377' \/><div class='watu-question-choice'><input type='radio' name='answer-2868[]' id='answer-id-11377' class='answer answer-9 php-answer-label answerof-2868' value='11377' \/>&nbsp;<label for='answer-id-11377' id='answer-label-11377' class='php-answer-label answer label-9'><span class='answer'>TCSEC<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11378' \/><div class='watu-question-choice'><input type='radio' name='answer-2868[]' id='answer-id-11378' class='answer answer-9 js-answer-label answerof-2868' value='11378' \/>&nbsp;<label for='answer-id-11378' id='answer-label-11378' class='js-answer-label answer label-9'><span class='answer'>SSAA<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Trusted Computer System Evaluation Criteria (TCSEC) is a United States Government Department of Defense (DoD) standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system. TCSEC was used to evaluate, classify, and select computer systems being considered for the processing, storage, and retrieval of sensitive or classified information. It was replaced with the development of the Common Criteria international standard originally published in 2005. The TCSEC, frequently referred to as the Orange Book, is the centerpiece of the DoD Rainbow Series publications. AnswerD is incorrect. System Security Authorization Agreement (SSAA) is an information security document used in the United States Department of Defense (DoD) to describe and accredit networks and systems. The SSAA is part of the Department of Defense Information Technology Security Certification and Accreditation Process, or DITSCAP (superseded by DIACAP). The DoD instruction (issues in December 1997, that describes DITSCAP and provides an outline for the SSAA document is DODI 5200.40. The DITSCAP application manual (DoD 8510.1- M), published in July 2000, provides additional details. Answer: A is incorrect. FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. It provides an approach for federal agencies. It determines how federal agencies are meeting existing policy and establish goals. The main advantage of FITSAF is that it addresses the requirements of Office of Management and Budget (OMB). It also addresses the guidelines provided by the National Institute of Standards and Technology (NIsT). Answer: B is incorrect. The Federal Information Processing Standards (FIPS) are publicly announced standards developed by the United States federal government for use by all non-military government agencies and by government contractors. Many FIPS standards are modified versions of standards used in the wider community (ANSI, IEEE, ISO, etc.). Some FIPS standards were originally developed by the U.S. government. For instance, standards for encoding data (e.g., country codes), but more significantly some encryption standards, such as the Data Encryption Standard (FIPS 46-<br\/>3) and the Advanced Encryption Standard (FIPS 197). In 1994, NOAA (Noaa) began broadcasting coded signals called FIPS (Federal Information Processing System) codes along with their standard weather broadcasts from local stations. These codes identify the type of emergency and the specific geographic area (such as a county) affected by the emergency.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(9,this)' id='btn-9' value='See Answer'  \/><input type='hidden' id='questionType9' value='radio' class=''><\/div><div class='watu-question' id='question-10'><div class='question-content'><p><strong>NO.130<\/strong> Certification and Accreditation (C&amp;A or CnA) is a process for implementing information security. Which of the following is the correct order of C&amp;A phases in a DITSCAP assessment?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2869' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11379' \/><div class='watu-question-choice'><input type='radio' name='answer-2869[]' id='answer-id-11379' class='answer answer-10 js-answer-label answerof-2869' value='11379' \/>&nbsp;<label for='answer-id-11379' id='answer-label-11379' class='js-answer-label answer label-10'><span class='answer'>Verification, Definition, Validation, and Post Accreditation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11380' \/><div class='watu-question-choice'><input type='radio' name='answer-2869[]' id='answer-id-11380' class='answer answer-10 js-answer-label answerof-2869' value='11380' \/>&nbsp;<label for='answer-id-11380' id='answer-label-11380' class='js-answer-label answer label-10'><span class='answer'>Definition, Validation, Verification, and Post Accreditation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11381' \/><div class='watu-question-choice'><input type='radio' name='answer-2869[]' id='answer-id-11381' class='answer answer-10 php-answer-label answerof-2869' value='11381' \/>&nbsp;<label for='answer-id-11381' id='answer-label-11381' class='php-answer-label answer label-10'><span class='answer'>Definition, Verification, Validation, and Post Accreditation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11382' \/><div class='watu-question-choice'><input type='radio' name='answer-2869[]' id='answer-id-11382' class='answer answer-10 js-answer-label answerof-2869' value='11382' \/>&nbsp;<label for='answer-id-11382' id='answer-label-11382' class='js-answer-label answer label-10'><span class='answer'>Verification, Validation, Definition, and Post Accreditation<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: C&amp;A consists of four phases in a DITSCAP assessment. These phases are the same as NIACAP phases. The order of these phases is as follows: 1.Definition: The definition phase is focused on understanding the IS business case, the mission, environment, and architecture. This phase determines the security requirements and level of effort necessary to achieve Certification &amp; Accreditation (C&amp;A).<br\/>2.Verification: The second phase confirms the evolving or modified system&#8217;s compliance with the information. The verification phase ensures that the fully integrated system will be ready for certification testing. 3.Validation: The third phase confirms abidance of the fully integrated system with the security policy. This phase follows the requirements slated in the SSAA. The objective of the validation phase is to show the required evidence to support the DAA in accreditation process. 4.Post Accreditation: The Post Accreditation is the final phase of DITSCAP assessment and it starts after the system has been certified and accredited for operations. This phase ensures secure system management, operation, and maintenance to save an acceptable level of residual risk.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(10,this)' id='btn-10' value='See Answer'  \/><input type='hidden' id='questionType10' value='radio' class=''><\/div><div class='watu-question' id='question-11'><div class='question-content'><p><strong>NO.131<\/strong> Which of the following describes the acceptable amount of data loss measured in time?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2870' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11383' \/><div class='watu-question-choice'><input type='radio' name='answer-2870[]' id='answer-id-11383' class='answer answer-11 php-answer-label answerof-2870' value='11383' \/>&nbsp;<label for='answer-id-11383' id='answer-label-11383' class='php-answer-label answer label-11'><span class='answer'>Recovery Point Objective (RPO)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11384' \/><div class='watu-question-choice'><input type='radio' name='answer-2870[]' id='answer-id-11384' class='answer answer-11 js-answer-label answerof-2870' value='11384' \/>&nbsp;<label for='answer-id-11384' id='answer-label-11384' class='js-answer-label answer label-11'><span class='answer'>Recovery Time Objective (RTO)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11385' \/><div class='watu-question-choice'><input type='radio' name='answer-2870[]' id='answer-id-11385' class='answer answer-11 js-answer-label answerof-2870' value='11385' \/>&nbsp;<label for='answer-id-11385' id='answer-label-11385' class='js-answer-label answer label-11'><span class='answer'>Recovery Consistency Objective (RCO)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11386' \/><div class='watu-question-choice'><input type='radio' name='answer-2870[]' id='answer-id-11386' class='answer answer-11 js-answer-label answerof-2870' value='11386' \/>&nbsp;<label for='answer-id-11386' id='answer-label-11386' class='js-answer-label answer label-11'><span class='answer'>Recovery Time Actual (RTA)<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>The Recovery Point Objective (RPO) describes the acceptable amount of data loss measured in time. It is the point in time to which data must be recovered as defined by the organization. The RPO is generally a definition of what an organization determines is an &#8220;acceptable loss&#8221; in a disaster situation. If the RPO of a company is 2 hours and the time it takes to get the data back into production is 5 hours, the RPO is still 2 hours. Based on this RPO the data must be restored to within 2 hours of the disaster. Answer B is incorrect. The Recovery Time Objective (RTO) is the duration of time and a service level within which a business process must be restored after a disaster or disruption in order to avoid unacceptable consequences associated with a break in business continuity. It includes the time for trying to fix the problem without a recovery, the recovery itself, tests and the communication to the users. Decision time for user representative is not included. The business continuity timeline usually runs parallel with an incident management timeline and may start at the same, or different, points. In accepted business continuity planning methodology, the RTO is established during the Business Impact Analysis (BIA) by the owner of a process (usually in conjunction with the Business Continuity planner). The RTOs are then presented to senior management for acceptance. The RTO attaches to the business process and not the resources required to support the process. Answer D is incorrect. The Recovery Time Actual (RTA) is established during an exercise, actual event, or predetermined based on recovery methodology the technology support team develops. This is the time frame the technology support takes to deliver the recovered infrastructure to the business. Answer C is incorrect. The Recovery Consistency Objective (RCO) is used in Business Continuity Planning in addition to Recovery Point Objective (RPO) and Recovery Time Objective (RTO). It applies data consistency objectives to Continuous Data Protection services.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(11,this)' id='btn-11' value='See Answer'  \/><input type='hidden' id='questionType11' value='radio' class=''><\/div><div class='watu-question' id='question-12'><div class='question-content'><p><strong>NO.132<\/strong> Which of the following techniques is used when a system performs the penetration testing with the objective of accessing unauthorized information residing inside a computer?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2871' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11387' \/><div class='watu-question-choice'><input type='radio' name='answer-2871[]' id='answer-id-11387' class='answer answer-12 js-answer-label answerof-2871' value='11387' \/>&nbsp;<label for='answer-id-11387' id='answer-label-11387' class='js-answer-label answer label-12'><span class='answer'>Biometrician<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11388' \/><div class='watu-question-choice'><input type='radio' name='answer-2871[]' id='answer-id-11388' class='answer answer-12 js-answer-label answerof-2871' value='11388' \/>&nbsp;<label for='answer-id-11388' id='answer-label-11388' class='js-answer-label answer label-12'><span class='answer'>Van Eck Phreaking<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11389' \/><div class='watu-question-choice'><input type='radio' name='answer-2871[]' id='answer-id-11389' class='answer answer-12 php-answer-label answerof-2871' value='11389' \/>&nbsp;<label for='answer-id-11389' id='answer-label-11389' class='php-answer-label answer label-12'><span class='answer'>Port scanning<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11390' \/><div class='watu-question-choice'><input type='radio' name='answer-2871[]' id='answer-id-11390' class='answer answer-12 js-answer-label answerof-2871' value='11390' \/>&nbsp;<label for='answer-id-11390' id='answer-label-11390' class='js-answer-label answer label-12'><span class='answer'>Phreaking<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Port scanning identifies open doors to a computer. Hackers and crackers use this technique to obtain unauthorized information.<br\/>Port scanning is the first basic step to get the details of open ports on the target system. Port scanning is used to find a hackable server with a hole or vulnerability. A port is a medium of communication between two computers. Every service on a host is identified by a unique 16-bit number called a port. A port scanner is a piece of software designed to search a network host for open ports. This is often used by administrators to check the security of their networks and by hackers to identify running services on a host with the view to compromising it. Port scanning is used to find the open ports, so that it is possible to search exploits related to that service and application. AnswerD is incorrect. Phreaking is a process used to crack the phone system. The main aim of phreaking is to avoid paying for long- distance calls. As telephone networks have become computerized, phreaking has become closely linked with computer hacking. This is sometimes called the H\/P culture (with H standing for Hacking and P standing for Phreaking). Answer: A is incorrect. It is defined as a system using a physical attribute for authenticating.<br\/>Only authorized users are provided access to network or application. AnswerB is incorrect. It is described as a form of eavesdropping in which special equipments are used to pick up the telecommunication signals or data within a computer device.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(12,this)' id='btn-12' value='See Answer'  \/><input type='hidden' id='questionType12' value='radio' class=''><\/div><div class='watu-question' id='question-13'><div class='question-content'><p><strong>NO.133<\/strong> You work as a systems engineer for BlueWell Inc. Which of the following tools will you use to look outside your own organization to examine how others achieve their performance levels, and what processes they use to reach those levels?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2872' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11391' \/><div class='watu-question-choice'><input type='radio' name='answer-2872[]' id='answer-id-11391' class='answer answer-13 php-answer-label answerof-2872' value='11391' \/>&nbsp;<label for='answer-id-11391' id='answer-label-11391' class='php-answer-label answer label-13'><span class='answer'>Benchmarking<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11392' \/><div class='watu-question-choice'><input type='radio' name='answer-2872[]' id='answer-id-11392' class='answer answer-13 js-answer-label answerof-2872' value='11392' \/>&nbsp;<label for='answer-id-11392' id='answer-label-11392' class='js-answer-label answer label-13'><span class='answer'>Six Sigma<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11393' \/><div class='watu-question-choice'><input type='radio' name='answer-2872[]' id='answer-id-11393' class='answer answer-13 js-answer-label answerof-2872' value='11393' \/>&nbsp;<label for='answer-id-11393' id='answer-label-11393' class='js-answer-label answer label-13'><span class='answer'>ISO 9001:2000<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11394' \/><div class='watu-question-choice'><input type='radio' name='answer-2872[]' id='answer-id-11394' class='answer answer-13 js-answer-label answerof-2872' value='11394' \/>&nbsp;<label for='answer-id-11394' id='answer-label-11394' class='js-answer-label answer label-13'><span class='answer'>SEI-CMM<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Benchmarking is the tool used by system assessment process to provide a point of reference by which performance measurements can be reviewed with respect to other organizations. Benchmarking is also recognized as Best Practice Benchmarking or Process Benchmarking. It is a process used in management and mostly useful for strategic management. It is the process of comparing the business processes and performance metrics including cost, cycle time, productivity, or quality to another that is widely considered to be an industry standard benchmark or best practice. It allows organizations to develop plans on how to implement best practice with the aim of increasing some aspect of performance.<br\/>Benchmarking might be a one-time event, although it is frequently treated as a continual process in which organizations continually seek out to challenge their practices. It allows organizations to develop plans on how to make improvements or adapt specific best practices, usually with the aim of increasing some aspect of performance. Answer: C is incorrect. The ISO 9001:2000 standard combines the three standards<br\/>9001, 9002, and 9003 into one, called 9001. Design and development procedures are required only if a company does in fact engage in the creation of new products. The 2000 version sought to make a radical change in thinking by actually placing the concept of process management front and center (&#8220;Process management&#8221; was the monitoring and optimizing of a company&#8217;s tasks and activities, instead of just inspecting the final product). The ISO 9001:2000 version also demands involvement by upper executives, in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators. Another goal is to improve effectiveness via process performance metrics numerical measurement of the effectiveness of tasks and activities. Expectations of continual process improvement and tracking customer satisfaction were made explicit. Answer: B is incorrect. Six Sigma is a business management strategy, initially implemented by Motorola. As of 2009 it enjoys widespread application in many sectors of industry, although its application is not without controversy. Six Sigma seeks to improve the quality of process outputs by identifying and removing the causes of defects and variability in manufacturing and business processes. It uses a set of quality management methods, including statistical methods, and creates a special infrastructure of people within the organization (&#8220;Black Belts&#8221;, &#8220;Green Belts&#8221;, etc.) who are experts in these methods. Each Six Sigma project carried out within an organization follows a defined sequence of steps and has quantified financial targets (cost reduction or profit increase).<br\/>The often used Six Sigma symbol is as follows:<br\/><img decoding=\"async\" src=\"https:\/\/blog.examboosts.com\/wp-content\/uploads\/2022\/06\/Csslp-ab378901bb167e59787db5c4951832b0.jpg\"\/><br\/>Answer D is incorrect. Capability Maturity Model Integration (CMMI) was created by Software Engineering<br\/>Institute (SEI). CMMI in software engineering and organizational development is a process improvement approach that provides organizations with the essential elements for effective process improvement. It can be used to guide process improvement across a project, a division, or an entire organization. CMMI can help integrate traditionally separate organizational functions, set process improvement goals and priorities, provide guidance for quality processes, and provide a point of reference for appraising current processes.<br\/>CMMI is now the de facto standard for measuring the maturity of any process. Organizations can be assessed against the CMMI model using Standard CMMI Appraisal Method for Process Improvement (SCAMPI).<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(13,this)' id='btn-13' value='See Answer'  \/><input type='hidden' id='questionType13' value='radio' class=''><\/div><div class='watu-question' id='question-14'><div class='question-content'><p><strong>NO.134<\/strong> Which of the following federal agencies has the objective to develop and promote measurement, standards, and technology to enhance productivity, facilitate trade, and improve the quality of life?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2873' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11395' \/><div class='watu-question-choice'><input type='radio' name='answer-2873[]' id='answer-id-11395' class='answer answer-14 js-answer-label answerof-2873' value='11395' \/>&nbsp;<label for='answer-id-11395' id='answer-label-11395' class='js-answer-label answer label-14'><span class='answer'>National Security Agency (NSA)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11396' \/><div class='watu-question-choice'><input type='radio' name='answer-2873[]' id='answer-id-11396' class='answer answer-14 php-answer-label answerof-2873' value='11396' \/>&nbsp;<label for='answer-id-11396' id='answer-label-11396' class='php-answer-label answer label-14'><span class='answer'>National Institute of Standards and Technology (NIST)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11397' \/><div class='watu-question-choice'><input type='radio' name='answer-2873[]' id='answer-id-11397' class='answer answer-14 js-answer-label answerof-2873' value='11397' \/>&nbsp;<label for='answer-id-11397' id='answer-label-11397' class='js-answer-label answer label-14'><span class='answer'>United States Congress<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11398' \/><div class='watu-question-choice'><input type='radio' name='answer-2873[]' id='answer-id-11398' class='answer answer-14 js-answer-label answerof-2873' value='11398' \/>&nbsp;<label for='answer-id-11398' id='answer-label-11398' class='js-answer-label answer label-14'><span class='answer'>Committee on National Security Systems (CNSS)<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The National Institute of Standards and Technology (NIST), known between 1901 and 1988 as the National Bureau of Standards (NBS), is a measurement standards laboratory which is a non- regulatory agency of the United States Department of Commerce. The institute&#8217;s official mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve quality of life. Answer D is incorrect.<br\/>The Committee on National Security Systems (CNSS) is a United States intergovernmental organization that sets policy for the security of the US security systems. The CNSS holds discussions of policy issues, sets national policy, directions, operational procedures, and guidance for the information systems operated by the U.S. Government, its contractors, or agents that contain classified information, involve intelligence activities, involve cryptographic activities related to national security, etc. Answer A is incorrect.<br\/>The National Security Agency\/Central Security Service (NSA\/CSS) is a crypto-logic intelligence agency of the United States government. It is administered as part of the United States Department of Defense. NSA is responsible for the collection and analysis of foreign communications and foreign signals intelligence, which involves cryptanalysis. NSA is also responsible for protecting U.S. government communications and information systems from similar agencies elsewhere, which involves cryptography. NSA is a key component of the U.S. Intelligence Community, which is headed by the Director of National Intelligence.<br\/>The Central Security Service is a co-located agency created to coordinate intelligence activities and co- operation between NSA and U.S. military cryptanalysis agencies. NSA&#8217;s work is limited to communications intelligence. It does not perform field or human intelligence activities. Answer C is incorrect. The United States Congress is the bicameral legislature of the federal government of the United States of America. It consists of the Senate and the House of Representatives. The Congress meets in the United States Capitol in Washington, D.C. Both senators and representatives are chosen through direct election. Each of the 435 members of the House of Representatives represents a district and serves a two-year term. House seats are apportioned among the states by population. The 100 Senators serve staggered six-year terms.<br\/>Each state has two senators, regardless of population. Every two years, approximately one-third of the Senate is elected at a time. The United States Congress main function is to make laws. The Office of the Law Revision Counsel organizes and publishes the United States Code (USC). It is a consolidation and codification by subject matter of the general and permanent laws of the United States.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(14,this)' id='btn-14' value='See Answer'  \/><input type='hidden' id='questionType14' value='radio' class=''><\/div><div class='watu-question' id='question-15'><div class='question-content'><p><strong>NO.135<\/strong> The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fundamental elements of cloud computing in its &#8220;Effectively and Securely Using the Cloud Computing Paradigm&#8221; presentation. Which of the following technologies are included in the primary technologies?<br \/>Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2874' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11399' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2874[]' id='answer-id-11399' class='answer answer-15 js-answer-label answerof-2874' value='11399' \/>&nbsp;<label for='answer-id-11399' id='answer-label-11399' class='js-answer-label answer label-15'><span class='answer'>Web application framework<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11400' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2874[]' id='answer-id-11400' class='answer answer-15 php-answer-label answerof-2874' value='11400' \/>&nbsp;<label for='answer-id-11400' id='answer-label-11400' class='php-answer-label answer label-15'><span class='answer'>Free and open source software<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11401' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2874[]' id='answer-id-11401' class='answer answer-15 php-answer-label answerof-2874' value='11401' \/>&nbsp;<label for='answer-id-11401' id='answer-label-11401' class='php-answer-label answer label-15'><span class='answer'>SOA<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11402' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2874[]' id='answer-id-11402' class='answer answer-15 php-answer-label answerof-2874' value='11402' \/>&nbsp;<label for='answer-id-11402' id='answer-label-11402' class='php-answer-label answer label-15'><span class='answer'>Virtualization<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The primary technologies defined by the NIST ITL Cloud Research Team in its &#8220;Effectively and Securely Using the Cloud Computing Paradigm&#8221; presentation are as follows: Virtualization Grid technology SOA (Service Oriented Architecture) Distributed computing Broadband network Browser as a platform Free and open source software AnswerA is incorrect. It is defined as the secondary technology.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(15,this)' id='btn-15' value='See Answer'  \/><input type='hidden' id='questionType15' value='checkbox' class=''><\/div><div class='watu-question' id='question-16'><div class='question-content'><p><strong>NO.136<\/strong> Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the U.S. Federal Government information security standards? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2875' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11403' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2875[]' id='answer-id-11403' class='answer answer-16 php-answer-label answerof-2875' value='11403' \/>&nbsp;<label for='answer-id-11403' id='answer-label-11403' class='php-answer-label answer label-16'><span class='answer'>IR Incident Response<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11404' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2875[]' id='answer-id-11404' class='answer answer-16 js-answer-label answerof-2875' value='11404' \/>&nbsp;<label for='answer-id-11404' id='answer-label-11404' class='js-answer-label answer label-16'><span class='answer'>Information systems acquisition, development, and maintenance<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11405' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2875[]' id='answer-id-11405' class='answer answer-16 php-answer-label answerof-2875' value='11405' \/>&nbsp;<label for='answer-id-11405' id='answer-label-11405' class='php-answer-label answer label-16'><span class='answer'>SA System and Services Acquisition<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11406' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2875[]' id='answer-id-11406' class='answer answer-16 php-answer-label answerof-2875' value='11406' \/>&nbsp;<label for='answer-id-11406' id='answer-label-11406' class='php-answer-label answer label-16'><span class='answer'>CA Certification, Accreditation, and Security Assessments<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Following are the various U.S. Federal Government information security standards: AC Access Control AT Awareness and Training AU Audit and Accountability CA Certification, Accreditation, and Security Assessments CM Configuration Management CP Contingency Planning IA Identification and Authentication IR Incident Response MA Maintenance MP Media Protection PE Physical and Environmental Protection PL Planning PS Personnel Security RA Risk Assessment SA System and Services Acquisition SC System and Communications Protection SI System and Information Integrity Answer B is incorrect. Information systems acquisition, development, and maintenance is an International information security standard.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(16,this)' id='btn-16' value='See Answer'  \/><input type='hidden' id='questionType16' value='checkbox' class=''><\/div><div class='watu-question' id='question-17'><div class='question-content'><p><strong>NO.137<\/strong> Which of the following classification levels defines the information that, if disclosed to the unauthorized parties, could be reasonably expected to cause exceptionally grave damage to the national security?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2876' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11407' \/><div class='watu-question-choice'><input type='radio' name='answer-2876[]' id='answer-id-11407' class='answer answer-17 js-answer-label answerof-2876' value='11407' \/>&nbsp;<label for='answer-id-11407' id='answer-label-11407' class='js-answer-label answer label-17'><span class='answer'>Secret information<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11408' \/><div class='watu-question-choice'><input type='radio' name='answer-2876[]' id='answer-id-11408' class='answer answer-17 js-answer-label answerof-2876' value='11408' \/>&nbsp;<label for='answer-id-11408' id='answer-label-11408' class='js-answer-label answer label-17'><span class='answer'>Unclassified information<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11409' \/><div class='watu-question-choice'><input type='radio' name='answer-2876[]' id='answer-id-11409' class='answer answer-17 js-answer-label answerof-2876' value='11409' \/>&nbsp;<label for='answer-id-11409' id='answer-label-11409' class='js-answer-label answer label-17'><span class='answer'>Confidential information<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11410' \/><div class='watu-question-choice'><input type='radio' name='answer-2876[]' id='answer-id-11410' class='answer answer-17 php-answer-label answerof-2876' value='11410' \/>&nbsp;<label for='answer-id-11410' id='answer-label-11410' class='php-answer-label answer label-17'><span class='answer'>Top Secret information<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Top Secret information is the highest level of classification of material on a national level.<br\/>Such material would cause &#8220;exceptionally grave damage&#8221; to national security if publicly available. Answer:<br\/>A is incorrect. Secret information is that, if disclosed to unauthorized parties, could be expected to cause serious damage to the national security, but it is not the best answer for the above question. AnswerC is incorrect. Such material would cause &#8220;damage&#8221; or be &#8220;prejudicial&#8221; to national security if publicly available.<br\/>AnswerB is incorrect. Unclassified information, technically, is not a classification level, but is used for<br\/>government documents that do not have a classification listed above. Such documents can sometimes be viewed by those without security clearance.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(17,this)' id='btn-17' value='See Answer'  \/><input type='hidden' id='questionType17' value='radio' class=''><\/div><div class='watu-question' id='question-18'><div class='question-content'><p><strong>NO.138<\/strong> Fill in the blank with an appropriate phrase The is a formal state transition system of computer security policy that describes a set of access control rules designed to ensure data integrity.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2877' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11411' \/><div class='watu-question-choice'><input type='radio' name='answer-2877[]' id='answer-id-11411' class='answer answer-18 php-answer-label answerof-2877' value='11411' \/>&nbsp;<label for='answer-id-11411' id='answer-label-11411' class='php-answer-label answer label-18'><span class='answer'>Biba model<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>The Biba model is a formal state transition system of computer security policy that describes a set of access control rules designed to ensure data integrity. Data and subjects are grouped into ordered levels of integrity. The model is designed so that subjects may not corrupt data in a level ranked higher than the subject, or be corrupted by data from a lower level than the subject.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(18,this)' id='btn-18' value='See Answer'  \/><input type='hidden' id='questionType18' value='radio' class=''><\/div><div class='watu-question' id='question-19'><div class='question-content'><p><strong>NO.139<\/strong> Which of the following vulnerabilities occurs when an application directly uses or concatenates potentially hostile input with data file or stream functions?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2878' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11412' \/><div class='watu-question-choice'><input type='radio' name='answer-2878[]' id='answer-id-11412' class='answer answer-19 js-answer-label answerof-2878' value='11412' \/>&nbsp;<label for='answer-id-11412' id='answer-label-11412' class='js-answer-label answer label-19'><span class='answer'>Insecure cryptographic storage<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11413' \/><div class='watu-question-choice'><input type='radio' name='answer-2878[]' id='answer-id-11413' class='answer answer-19 php-answer-label answerof-2878' value='11413' \/>&nbsp;<label for='answer-id-11413' id='answer-label-11413' class='php-answer-label answer label-19'><span class='answer'>Malicious file execution<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11414' \/><div class='watu-question-choice'><input type='radio' name='answer-2878[]' id='answer-id-11414' class='answer answer-19 js-answer-label answerof-2878' value='11414' \/>&nbsp;<label for='answer-id-11414' id='answer-label-11414' class='js-answer-label answer label-19'><span class='answer'>Insecure communication<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11415' \/><div class='watu-question-choice'><input type='radio' name='answer-2878[]' id='answer-id-11415' class='answer answer-19 js-answer-label answerof-2878' value='11415' \/>&nbsp;<label for='answer-id-11415' id='answer-label-11415' class='js-answer-label answer label-19'><span class='answer'>Injection flaw<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Malicious file execution is a vulnerability that occurs when an application directly uses or concatenates potentially hostile input with data file or stream functions. This leads to arbitrary remote and hostile data being included, processed, and invoked by the Web server. Malicious file execution can be prevented by using an indirect object reference map, input validation, or explicit taint checking mechanism. Answer D is incorrect. Injection flaw occurs when data is sent to an interpreter as a part of command or query. Answer A is incorrect. Insecure cryptographic storage occurs when applications have failed to encrypt data. Answer C is incorrect. Insecure communication occurs when applications have failed to encrypt network traffic.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(19,this)' id='btn-19' value='See Answer'  \/><input type='hidden' id='questionType19' value='radio' class=''><\/div><div class='watu-question' id='question-20'><div class='question-content'><p><strong>NO.140<\/strong> Which of the following are examples of passive attacks? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2879' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11416' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2879[]' id='answer-id-11416' class='answer answer-20 php-answer-label answerof-2879' value='11416' \/>&nbsp;<label for='answer-id-11416' id='answer-label-11416' class='php-answer-label answer label-20'><span class='answer'>Dumpster diving<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11417' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2879[]' id='answer-id-11417' class='answer answer-20 js-answer-label answerof-2879' value='11417' \/>&nbsp;<label for='answer-id-11417' id='answer-label-11417' class='js-answer-label answer label-20'><span class='answer'>Placing a backdoor<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11418' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2879[]' id='answer-id-11418' class='answer answer-20 php-answer-label answerof-2879' value='11418' \/>&nbsp;<label for='answer-id-11418' id='answer-label-11418' class='php-answer-label answer label-20'><span class='answer'>Eavesdropping<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11419' \/><div class='watu-question-choice'><input type='checkbox' name='answer-2879[]' id='answer-id-11419' class='answer answer-20 php-answer-label answerof-2879' value='11419' \/>&nbsp;<label for='answer-id-11419' id='answer-label-11419' class='php-answer-label answer label-20'><span class='answer'>Shoulder surfing<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: In eavesdropping, dumpster diving, and shoulder surfing, the attacker violates the confidentiality of a system without affecting its state. Hence, they are considered passive attacks.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(20,this)' id='btn-20' value='See Answer'  \/><input type='hidden' id='questionType20' value='checkbox' class=''><\/div><div class='watu-question' id='question-21'><div class='question-content'><p><strong>NO.141<\/strong> Harry is the project manager of the MMQ Construction Project. In this project, Harry has identified a supplier who can create stained glass windows for 1,000 window units in the construction project. The supplier is an artist who works by himself, but creates windows for several companies throughout the United States. Management reviews the proposal to use this supplier and while they agree that the supplier is talented, they do not think the artist can fulfill the 1,000 window units in time for the project&#8217;s deadline. Management asked Harry to find a supplier who can fulfill the completion of the windows by the needed date in the schedule. What risk response has management asked Harry to implement?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2880' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11420' \/><div class='watu-question-choice'><input type='radio' name='answer-2880[]' id='answer-id-11420' class='answer answer-21 js-answer-label answerof-2880' value='11420' \/>&nbsp;<label for='answer-id-11420' id='answer-label-11420' class='js-answer-label answer label-21'><span class='answer'>Transference<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11421' \/><div class='watu-question-choice'><input type='radio' name='answer-2880[]' id='answer-id-11421' class='answer answer-21 js-answer-label answerof-2880' value='11421' \/>&nbsp;<label for='answer-id-11421' id='answer-label-11421' class='js-answer-label answer label-21'><span class='answer'>Avoidance<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11422' \/><div class='watu-question-choice'><input type='radio' name='answer-2880[]' id='answer-id-11422' class='answer answer-21 php-answer-label answerof-2880' value='11422' \/>&nbsp;<label for='answer-id-11422' id='answer-label-11422' class='php-answer-label answer label-21'><span class='answer'>Mitigation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11423' \/><div class='watu-question-choice'><input type='radio' name='answer-2880[]' id='answer-id-11423' class='answer answer-21 js-answer-label answerof-2880' value='11423' \/>&nbsp;<label for='answer-id-11423' id='answer-label-11423' class='js-answer-label answer label-21'><span class='answer'>Acceptance<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>This is an example of mitigation. By changing to a more reliable supplier, Harry is reducing the probability the supplier will be late. It&#8217;s still possible that the vendor may not be able to deliver the stained glass windows, but the more reputable supplier reduces the probability of the lateness. Mitigation is a risk response planning technique associated with threats that seeks to reduce the probability of occurrence or impact of a risk to below an acceptable threshold. Risk mitigation involves taking early action to reduce the probability and impact of a risk occurring on the project. Adopting less complex processes, conducting more tests, or choosing a more stable supplier are examples of mitigation actions. Answer A is incorrect. Transference is when the risk is transferred to a third party, usually for a fee. While this question does include a contractual relationship, the risk is the lateness of the windows. Transference focuses on transferring the risk to a third party to manage the risk event. In this instance, the management of the risk is owned by a third party; the third party actually creates the risk event because of the possibility of the lateness of the windows. Answer B is incorrect. Avoidance changes the project plan to avoid the risk. If the project manager and management changed the window-type to a standard window in the project requirements, then this would be avoidance. Risk avoidance is a technique used for threats. It creates changes to the project management plan that are meant to either eliminate the risk completely or to protect the project objectives from its impact. Risk avoidance removes the risk event entirely either by adding additional steps to avoid the event or reducing the project scope requirements. It may seem the answer to all possible risks, but avoiding risks also means losing out on the potential gains that accepting (retaining) the risk might have allowed. Answer D is incorrect. Acceptance accepts the risk that the windows could be late and offers no response.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(21,this)' id='btn-21' value='See Answer'  \/><input type='hidden' id='questionType21' value='radio' class=''><\/div><div class='watu-question' id='question-22'><div class='question-content'><p><strong>NO.142<\/strong> Which of the following features of SIEM products is used in analysis for identifying potential problems and reviewing all available data that are associated with the problems?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2881' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11424' \/><div class='watu-question-choice'><input type='radio' name='answer-2881[]' id='answer-id-11424' class='answer answer-22 js-answer-label answerof-2881' value='11424' \/>&nbsp;<label for='answer-id-11424' id='answer-label-11424' class='js-answer-label answer label-22'><span class='answer'>Security knowledge base<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11425' \/><div class='watu-question-choice'><input type='radio' name='answer-2881[]' id='answer-id-11425' class='answer answer-22 php-answer-label answerof-2881' value='11425' \/>&nbsp;<label for='answer-id-11425' id='answer-label-11425' class='php-answer-label answer label-22'><span class='answer'>Graphical user interface<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11426' \/><div class='watu-question-choice'><input type='radio' name='answer-2881[]' id='answer-id-11426' class='answer answer-22 js-answer-label answerof-2881' value='11426' \/>&nbsp;<label for='answer-id-11426' id='answer-label-11426' class='js-answer-label answer label-22'><span class='answer'>Asset information storage and correlation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11427' \/><div class='watu-question-choice'><input type='radio' name='answer-2881[]' id='answer-id-11427' class='answer answer-22 js-answer-label answerof-2881' value='11427' \/>&nbsp;<label for='answer-id-11427' id='answer-label-11427' class='js-answer-label answer label-22'><span class='answer'>Incident tracking and reporting<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: SIEM product has a graphical user interface (GUI) which is used in analysis for identifying potential problems and reviewing all available data that are associated with the problems. A graphical user interface (GUI) is a type of user interface that allows people to interact with programs in more ways than typing commands on computers. The term came into existence because the first interactive user interfaces to computers were not graphical; they were text- and-keyboard oriented and usually consisted of commands a user had to remember and computer responses that were infamously brief. A GUI offers graphical icons, and visual indicators, as opposed to text-based interfaces, typed command labels or text navigation to fully represent the information and actions available to a user. The actions are usually performed through direct manipulation of the graphical elements.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(22,this)' id='btn-22' value='See Answer'  \/><input type='hidden' id='questionType22' value='radio' class=''><\/div><div class='watu-question' id='question-23'><div class='question-content'><p><strong>NO.143<\/strong> At which of the following levels of robustness in DRM must the security functions be immune to widely available tools and specialized tools and resistant to professional tools?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='2882' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11428' \/><div class='watu-question-choice'><input type='radio' name='answer-2882[]' id='answer-id-11428' class='answer answer-23 js-answer-label answerof-2882' value='11428' \/>&nbsp;<label for='answer-id-11428' id='answer-label-11428' class='js-answer-label answer label-23'><span class='answer'>Level 2<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11429' \/><div class='watu-question-choice'><input type='radio' name='answer-2882[]' id='answer-id-11429' class='answer answer-23 js-answer-label answerof-2882' value='11429' \/>&nbsp;<label for='answer-id-11429' id='answer-label-11429' class='js-answer-label answer label-23'><span class='answer'>Level 4<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11430' \/><div class='watu-question-choice'><input type='radio' name='answer-2882[]' id='answer-id-11430' class='answer answer-23 php-answer-label answerof-2882' value='11430' \/>&nbsp;<label for='answer-id-11430' id='answer-label-11430' class='php-answer-label answer label-23'><span class='answer'>Level 1<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='11431' \/><div class='watu-question-choice'><input type='radio' name='answer-2882[]' id='answer-id-11431' class='answer answer-23 js-answer-label answerof-2882' value='11431' \/>&nbsp;<label for='answer-id-11431' id='answer-label-11431' class='js-answer-label answer label-23'><span class='answer'>Level 3<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>At Level 1 of robustness in DRM, the security functions must be immune to widely available tools and specialized tools and resistant to professional tools.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(23,this)' id='btn-23' value='See Answer'  \/><input type='hidden' id='questionType23' value='radio' class=''><\/div><div style='display:none' id='question-24'><br \/><div class='question-content'><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.examboosts.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Chargement ...\" title=\"Chargement ...\" \/>&nbsp;Chargement &#8230;<\/div><\/div><br \/>\n<input type=\"button\" name=\"action\" onclick=\"Watu.submitResult()\" id=\"action-button\" style=\"margin:0 auto 20px auto;\" value=\"Voir les R\u00e9sultats\"  class=\"watu-submit-button\" \/>\n<input type=\"hidden\" name=\"no_ajax\" value=\"0\"><input type=\"hidden\" name=\"quiz_id\" value=\"150\" \/>\n<input type=\"hidden\" id=\"watuStartTime\" name=\"start_time\" value=\"2026-09-23 13:28:03\" \/>\n<\/form>\n<\/div>\n<div id=\"watu-loading-result\" style=\"display:none;\">\n\t<p align=\"center\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blog.examboosts.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Chargement\" title=\"Chargement\" \/><\/p>\n<\/div>\t\n<script type=\"text\/javascript\">\nvar exam_id=0;\nvar question_ids='';\nvar watuURL='';\njQuery(function($){\nquestion_ids = \"2860,2861,2862,2863,2864,2865,2866,2867,2868,2869,2870,2871,2872,2873,2874,2875,2876,2877,2878,2879,2880,2881,2882\";\nexam_id = 150;\nWatu.exam_id = exam_id;\nWatu.qArr = question_ids.split(',');\nWatu.post_id = 311;\nWatu.singlePage = '1';\nWatu.hAppID = \"0.57066000 1790170083\";\nwatuURL = \"https:\/\/blog.examboosts.com\/wp-admin\/admin-ajax.php\";\nWatu.noAlertUnanswered = 0;\n});\n\nfunction showanswer1(e,q) {\n\tvar check = new Array();\n\tjQuery('.answer-' + e).each(function (i) {\n\t\tcheck.push(this.checked)\n\t})\n\tlet textval = jQuery('.watu-textarea-' + e).val()\n\tif (jQuery.inArray(true, check) >= 0 || textval !== '' && textval !== undefined) {\n\t\tjQuery(q).stop().fadeOut(300)\n\t\tjQuery('.php-answer-label.label-' + e).addClass(\n\t\t\t'correct-answer'\n\t\t)\n\t\tjQuery('.answer-' + e).each(function (i) {\n\t\t\tif (this.checked && this.className.match(\/js\\-answer\/)) {\n\t\t\t\tvar number = this.id.toString().replace(\/\\D\/g, '')\n\t\t\t\tif (number) {\n\t\t\t\t\tjQuery('#answer-label-' + number).addClass('user-answer')\n\t\t\t\t}\n\t\t\t}\n\t\t})\n\t\tjQuery(q).siblings('.show-question-feedback').stop().fadeIn(300)\n\t\ttextval = ''\n\t} else if (textval == '' || textval == undefined){\n\t\t\/\/jQuery(\".hint\").stop().fadeIn(300)\n\t\talert('Please first answer the question');\n\t}\n}\nvar btnisshow = jQuery(\".php-answer-label\").length\nif (btnisshow > 0) {\n\tjQuery('.showchecked').show()\n} else {\n\tjQuery('.showchecked').hide()\n}\n<\/script>\n<p><strong>CSSLP Dumps With 100% Verified Q&amp;As &#8211; Pass Guarantee or Full Refund: <a href=\"https:\/\/www.examboosts.com\/ISC\/CSSLP-practice-exam-dumps.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.examboosts.com\/ISC\/CSSLP-practice-exam-dumps.html<\/a><\/strong><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>CSSLP Braindumps Real Exam Updated on Jun 12, 2022 with 349 Questions Latest CSSLP PDF Dumps &amp; Real Tests Free Updated Today Secure Software Lifecycle Management (11%) : D\u00e9classer les logiciels ; Int\u00e9grer la GIR (Gestion Int\u00e9gr\u00e9e des Risques) ; D\u00e9velopper les m\u00e9triques de s\u00e9curit\u00e9, y compris les d\u00e9fauts par code de ligne, le temps moyen de rem\u00e9diation, le niveau de criticit\u00e9, et la complexit\u00e9 ; \u00c9tablir les normes et les cadres pour la s\u00e9curit\u00e9 ; Expliquer... <br \/> <a class=\"button small blue\" href=\"https:\/\/blog.examboosts.com\/fr\/2022\/06\/csslp-braindumps-real-exam-updated-on-jun-12-2022-with-349-questions-q121-q143\/\">Lire la suite<\/a><\/p>","protected":false},"author":1,"featured_media":312,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1051,481],"tags":[1048,1043,1045,1044,1049,1047,1046,1050],"class_list":["post-311","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-csslp","category-isc","tag-csslp-detail-explanation","tag-csslp-exam-cram-questions","tag-csslp-exam-overview","tag-csslp-latest-dumps-questions","tag-csslp-latest-test-name","tag-csslp-pass-guaranteed","tag-csslp-reliable-test-tutorial","tag-new-csslp-exam-review"],"_links":{"self":[{"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/posts\/311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/comments?post=311"}],"version-history":[{"count":0,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/posts\/311\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/media\/312"}],"wp:attachment":[{"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/media?parent=311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/categories?post=311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.examboosts.com\/fr\/wp-json\/wp\/v2\/tags?post=311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}