CISSP Official Practice Tests by Mike Chapple, David Seidl

(chelsyfait) #1

236 Chapter 10 ■ Practice Test 2



  1. Vivian works for a chain of retail stores and would like to use a software product that
    restricts the software used on point-of-sale terminals to those packages on a preapproved
    list. What approach should Vivian use?
    A. Antivirus
    B. Heuristic
    C. Whitelist
    D. Blacklist


For questions 21–23, please refer to the following scenario:

Hunter is the facilities manager for DataTech, a large data center management firm. He is
evaluating the installation of a flood prevention system at one of DataTech’s facilities. The
facility and contents are valued at $100 million. Installing the new flood prevention system
would cost $10 million.

Hunter consulted with flood experts and determined that the facility lies within a 200-
year flood plain and that, if a flood occurred, it would likely cause $20 million in damage
to the facility.


  1. Based on the information in this scenario, what is the exposure factor for the effect of a
    flood on DataTech’s data center?
    A. 2%
    B. 20%
    C. 100%
    D. 200%

  2. Based on the information in this scenario, what is the annualized rate of occurrence for a
    flood at DataTech’s data center?
    A. 0.002
    B. 0.005
    C. 0.02
    D. 0.05

  3. Based on the information in this scenario, what is the annualized loss expectancy for a
    flood at DataTech’s data center?
    A. $40,000
    B. $100,000
    C. $400,000
    D. $1,000,000

  4. Which accounts are typically assessed during an account management assessment?
    A. A random sample
    B. Highly privileged accounts

Free download pdf