ISC CISSP-ISSEP - Information Systems Security Engineering Professional - CISSP-ISSEP Exam Practice Test

Question 1
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site?

Correct Answer: B
Question 2
Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls.
Which of the following are the international information security standards? Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B,C,D
Question 3
Which of the following elements of Registration task 4 defines the system's external interfaces as well as the purpose of each external interface, and the relationship between the interface and the system?

Correct Answer: A
Question 4
FIPS 199 defines the three levels of potential impact on organizations low, moderate, and high.
Which of the following are the effects of loss of confidentiality, integrity, or availability in a high level potential impact?

Correct Answer: A,B,C,D
Question 5
Which of the following tasks describes the processes required to ensure that the project includes all the work required, and only the work required, to complete the project successfully?

Correct Answer: C
Question 6
You have been tasked with finding an encryption methodology that will encrypt most types of email attachments. The requirements are that your solution must use the RSA algorithm. Which of the following is your best choice?

Correct Answer: B
Question 7
Which of the following terms describes the measures that protect and support information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation?

Correct Answer: C
Question 8
Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?

Correct Answer: B
Question 9
Which of the following memorandums reminds the Federal agencies that it is required by law and policy to establish clear privacy policies for Web activities and to comply with those policies?

Correct Answer: C
Question 10
Which of the following are the ways of sending secure e-mail messages over the Internet? Each correct answer represents a complete solution. Choose two.

Correct Answer: C,D
Question 11
Which of the following memorandums reminds the departments and agencies of the OMB principles for including and funding security as an element of agency information technology systems and architectures and of the decision criteria which is used to evaluate security for information systems investments?

Correct Answer: C
Question 12
Which of the following is used to indicate that the software has met a defined quality level and is ready for mass distribution either by electronic means or by physical media?

Correct Answer: B
Question 13
Continuous Monitoring is the fourth phase of the security certification and accreditation process.
What activities are performed in the Continuous Monitoring process? Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B,C,D
Question 14
Fill in the blank with the appropriate phrase. __________ provides instructions and directions for completing the Systems Security Authorization Agreement (SSAA).

Correct Answer: A
Question 15
You work as a security engineer for BlueWell Inc. You are working on the ISSE model. In which of the following phases of the ISSE model is the system defined in terms of what security is needed?

Correct Answer: B