Try Free and Start Using Realistic Verified CISSP-ISSEP Dumps Instantly [Q63-Q80]

Share

Try Free and Start Using Realistic Verified CISSP-ISSEP Dumps Instantly

CISSP-ISSEP Actual Questions - Instant Download 220 Questions


Certification Quality

The CISSP-ISSEP is in line with the requirements of ANSI/ISO/IEC Standard 17024. As further verification of the quality and relevance of this certification, (ISC)² ensures that the CISSP-ISSEP exam is up to date and aligns with the responsibilities of current practicing information security professionals. They do this via the Job Task Analysis (JTA) that carefully and methodically analyzes the tasks performed by ISSEPs.

 

NEW QUESTION # 63
You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities.
For your project archives, which one of the following is an output of risk monitoring and control?

  • A. Risk audits
  • B. Qualitative risk analysis
  • C. Quantitative risk analysis
  • D. Requested changes

Answer: D


NEW QUESTION # 64
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems.
Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed?

  • A. Level 3
  • B. Level 4
  • C. Level 2
  • D. Level 5
  • E. Level 1

Answer: B


NEW QUESTION # 65
Which of the following processes provides guidance to the system designers and form the basis of major events in the acquisition phases, such as testing the products for system integration

  • A. Performance requirements
  • B. Operational scenarios
  • C. Functional requirements
  • D. Human factors

Answer: B


NEW QUESTION # 66
Which of the following organizations assists the President in overseeing the preparation of the federal budget and to supervise its administration in Executive Branch agencies

  • A. NSACSS
  • B. DCAA
  • C. NIST
  • D. OMB

Answer: D


NEW QUESTION # 67
Fill in the blank with an appropriate section name. _________________ is a section of the SEMP template, which specifies the methods and reasoning planned to build the requisite trade-offs between functionality, performance, cost, and risk.

  • A. System Analysis

Answer: A


NEW QUESTION # 68
What are the responsibilities of a system owner Each correct answer represents a complete solution. Choose all that apply.

  • A. Ensures that the systems are properly assessed for vulnerabilities and must report any to the incident response team and data owner.
  • B. Ensures that the necessary security controls are in place.
  • C. Integrates security considerations into application and system purchasing decisions and development projects.
  • D. Ensures that adequate security is being provided by the necessary controls, password management, remote access controls, operating system configurations, and so on.

Answer: A,C,D


NEW QUESTION # 69
Which of the following individuals are part of the senior management and are responsible for authorization of individual systems, approving enterprise solutions, establishing security policies, providing funds, and maintaining an understanding of risks at all levels? Each correct answer represents a complete solution. Choose all that apply.

  • A. AO Designated Representative
  • B. User Representative
  • C. Senior Information Security Officer
  • D. Authorizing Official
  • E. Chief Information Officer

Answer: A,C,D,E


NEW QUESTION # 70
Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system. Which of the following phases of NIST SP 800-37 C&A methodology will define the above task

  • A. Security Certification
  • B. Security Accreditation
  • C. Initiation
  • D. Continuous Monitoring

Answer: D


NEW QUESTION # 71
Which of the following certification levels requires the completion of the minimum security checklist, and the system user or an independent certifier can complete the checklist

  • A. CL 3
  • B. CL 4
  • C. CL 2
  • D. CL 1

Answer: D


NEW QUESTION # 72
Which of the following agencies is responsible for funding the development of many technologies such as computer networking, as well as NLS

  • A. DARPA
  • B. DTIC
  • C. DISA
  • D. DIAP

Answer: A


NEW QUESTION # 73
The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer Each correct answer represents a complete solution. Choose all that apply.

  • A. Preserving high-level communications and working group relationships in an organization
  • B. Facilitating the sharing of security risk-related information among authorizing officials
  • C. Establishing effective continuous monitoring program for the organization
  • D. Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan

Answer: A,C,D


NEW QUESTION # 74
Which of the following cooperative programs carried out by NIST conducts research to advance the nation's technology infrastructure

  • A. Manufacturing Extension Partnership
  • B. Baldrige National Quality Program
  • C. Advanced Technology Program
  • D. NIST Laboratories

Answer: D


NEW QUESTION # 75
You work as an ISSE for BlueWell Inc.
You want to break down user roles, processes, and information until ambiguity is reduced to a satisfactory degree.
Which of the following tools will help you to perform the above task?

  • A. Information Management Model (IMM)
  • B. Gantt Chart
  • C. Functional Flow Block Diagram
  • D. PERT Chart

Answer: A


NEW QUESTION # 76
In which of the following phases of the interconnection life cycle as defined by NIST SP 800-47, do the organizations build and execute a plan for establishing the interconnection, including executing or configuring appropriate security controls

  • A. Establishing the interconnection
  • B. Planning the interconnection
  • C. Disconnecting the interconnection
  • D. Maintaining the interconnection

Answer: A


NEW QUESTION # 77
Which of the following elements of Registration task 4 defines the operating system, database management system, and software applications, and how they will be used

  • A. System software
  • B. System hardware
  • C. System interface
  • D. System firmware

Answer: A


NEW QUESTION # 78
Which of the CNSS policies describes the national policy on certification and accreditation of national security telecommunications and information systems

  • A. NSTISSP No. 7
  • B. NSTISSP No. 11
  • C. NSTISSP No. 101
  • D. NSTISSP No. 6

Answer: D


NEW QUESTION # 79
FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets, or individuals

  • A. High
  • B. Low
  • C. Medium
  • D. Moderate

Answer: B


NEW QUESTION # 80
......

Download Free Latest Exam CISSP-ISSEP Certified Sample Questions: https://www.test4sure.com/CISSP-ISSEP-pass4sure-vce.html

Prepare for your exam certification with our CISSP-ISSEP Certified ISC: https://drive.google.com/open?id=1UZzj6C4h3YcB7ZN6_XimmvIYNq4eUOHr