CISSP-ISSEP Practice Test

When should the System Design Review (SDR) take place?
Who provides and independent assessment of the security plan?
Which of the following describes the Discover Information Protection needs phase?
Which is not a class of attack according to the IATF?
_____ defines the hardware, software, and interfaces used to develop a system.
Which of the following identifies the different function a system will need to perform in order to meet the documented business need?
Which IATF system engineering follows "Discover Needs"?
A collection of information objects that share the same security policy for access is
What is the correct order of the six IATF systems engineering activities?
Information Systems Security Engineering (ISSE) is best defined as:
Risk assessment begins in which IATF phase?
What aspects are taken into account when defining a Mission Assurance Category (MAC)
What ISSE phase defines the security needed for a system?
Which philosophy is established by NSTISSI 7003 Protected Distribution Systems (PDS)?
DOD Information Systems should only be interconnected under the following circumstances
What is the level of impact if the information label is Moderate
How does FIPS 199 define LOW impact items?
What IATF phase includes creating the Information Management Model (IMM)?
Which is not an element in the IATF Defense in Depth Strategy?
Which statement is not correct?
Who is responsible for defining the solution space?
What is the level of impact if the information label is LOW
Who SUPPORTS the C&A process during development?
What is the level of impact if the information label is High
Which statement most accurately defines residual risk?
NIST SP 800-37 does not address
Which of the following is not a requirement of OMB A-130?
Who is the best source of knowledge of potential threats?
What phase of the ISSE defines the information management model and protections?
Which is not a primary task included in the Information Management Plan (IMP)?
Which step is not addressed during the NIST SP 800-60 analysis?
FIPS Pub 199 uses what term when referring to a HIGH impact
The Waterfall design methodology is best described as:
After Design System Architecture Phase is completed, what occurs next?
What is necessary in order to determine the appropriate security category?
FISMA was created by what organization?
A Target of Evaluation could be described as:
What document is key to the design and development processes?
The IATF has three primary elements for defense in depth. Which of the below is not one of these elements?
Which requirement does NIST SP 800-59 tell us is required in order to be defined as a National Security System?
The Information Management Plan (IMP) helps determine

Comments

  1. VickM says:

    These are really difficult, I hope the actual test isn’t this bad.

  2. s0ndra says:

    where are the ans?

  3. LT says:

    I have noticed a few incorrect answers in this practice exam. One question asks about the SE processes but the answer relates to ISSE processes. You can tell because the word “Security” is not in the question but appears in the answer. Be careful on the the exam as I have heard that this is a “gotcha” type of question.

  4. LT says:

    The answer to this question is incorrect.

    Who is responsible for defining the solution space?

    The answer given states it is the customer, but the customer defines the “problem” space and the SE and ISSE define the “solution” space.

Trackbacks

  1. [...] to see how much you may need to study prior to taking the test? Try taking our free CISSP-ISSEP practice test.  Use the results to focus your study plan toward areas where you didn’t do so [...]

Speak Your Mind

*