ISC CISSP-ISSEP - Information Systems Security Engineering Professional - CISSP-ISSEP Exam Practice Test

Which of the following processes culminates in an agreement between key players that a system in its current configuration and operation provides adequate protection controls?
Correct Answer: B Vote an answer
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: B,C,E Vote an answer
Which of the following NIST documents describes that minimizing negative impact on an organization and a need for sound basis in decision making are the fundamental reasons organizations implement a risk management process for their IT systems?
Correct Answer: A Vote an answer
You work as a security manager for BlueWell Inc. You are going through the NIST SP 800-37 C&A methodology, which is based on four well defined phases. In which of the following phases of NIST SP 800-37 C&A methodology does the security categorization occur?
Correct Answer: C Vote an answer
Which of the following CNSS policies describes the national policy on use of cryptomaterial by activities operating in high risk environments?
Correct Answer: C Vote an answer
Which of the following elements of Registration task 4 defines the operating system, database management system, and software applications, and how they will be used?
Correct Answer: C Vote an answer
Which of the following is the acronym of RTM?
Correct Answer: B Vote an answer
Which of the following Registration Tasks sets up the business or operational functional description and system identification?
Correct Answer: A Vote an answer
Which of the following organizations incorporates building secure audio and video communications equipment, making tamper protection products, and providing trusted microelectronics solutions?
Correct Answer: C Vote an answer
Which of the following phases of NIST SP 800-37 C&A methodology examines the residual risk for acceptability, and prepares the final security accreditation package?
Correct Answer: B Vote an answer
Fill in the blank with an appropriate phrase. __________ seeks to improve the quality of process outputs by identifying and removing the causes of defects and variability in manufacturing and business processes.
Correct Answer: A Vote an answer
Which of the following individuals reviews and approves project deliverables from a QA perspective?
Correct Answer: D Vote an answer
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution.
Choose all that apply.
Correct Answer: A,B,C Vote an answer
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,B,D,E,F Vote an answer