CISSP-ISSEP Practice Test

What document is key to the design and development processes?
NIST SP 800-37 does not address
Which of the following is not a requirement of OMB A-130?
Which statement most accurately defines residual risk?
A collection of information objects that share the same security policy for access is
Information Systems Security Engineering (ISSE) is best defined as:
Who is the best source of knowledge of potential threats?
Who is responsible for defining the solution space?
What phase of the ISSE defines the information management model and protections?
FISMA was created by what organization?
What is necessary in order to determine the appropriate security category?
What is the level of impact if the information label is LOW
What ISSE phase defines the security needed for a system?
FIPS Pub 199 uses what term when referring to a HIGH impact
Which is not a primary task included in the Information Management Plan (IMP)?
A Target of Evaluation could be described as:
The Information Management Plan (IMP) helps determine
Which of the following identifies the different function a system will need to perform in order to meet the documented business need?
Which step is not addressed during the NIST SP 800-60 analysis?
When should the System Design Review (SDR) take place?
Which philosophy is established by NSTISSI 7003 Protected Distribution Systems (PDS)?
Which statement is not correct?
DOD Information Systems should only be interconnected under the following circumstances
_____ defines the hardware, software, and interfaces used to develop a system.
Who provides and independent assessment of the security plan?
After Design System Architecture Phase is completed, what occurs next?
Risk assessment begins in which IATF phase?
The IATF has three primary elements for defense in depth. Which of the below is not one of these elements?
Which is not a class of attack according to the IATF?
Which requirement does NIST SP 800-59 tell us is required in order to be defined as a National Security System?
How does FIPS 199 define LOW impact items?
What is the level of impact if the information label is Moderate
The Waterfall design methodology is best described as:
What aspects are taken into account when defining a Mission Assurance Category (MAC)
Which IATF system engineering follows "Discover Needs"?
What IATF phase includes creating the Information Management Model (IMM)?
What is the level of impact if the information label is High
Which of the following describes the Discover Information Protection needs phase?
What is the correct order of the six IATF systems engineering activities?
Which is not an element in the IATF Defense in Depth Strategy?
Who SUPPORTS the C&A process during development?

Comments

  1. VickM says:

    These are really difficult, I hope the actual test isn’t this bad.

  2. s0ndra says:

    where are the ans?

  3. LT says:

    I have noticed a few incorrect answers in this practice exam. One question asks about the SE processes but the answer relates to ISSE processes. You can tell because the word “Security” is not in the question but appears in the answer. Be careful on the the exam as I have heard that this is a “gotcha” type of question.

  4. LT says:

    The answer to this question is incorrect.

    Who is responsible for defining the solution space?

    The answer given states it is the customer, but the customer defines the “problem” space and the SE and ISSE define the “solution” space.

Trackbacks

  1. [...] to see how much you may need to study prior to taking the test? Try taking our free CISSP-ISSEP practice test.  Use the results to focus your study plan toward areas where you didn’t do so [...]

Speak Your Mind

*