CISSP Official Practice Tests by Mike Chapple, David Seidl

(chelsyfait) #1

264 Chapter 11 ■ Practice Test 3



  1. Susan uses a span port to monitor traffic to her production website and uses a monitoring
    tool to identify performance issues in real time. What type of monitoring is she
    conducting?
    A. Passive monitoring
    B. Active monitoring
    C. Synthetic monitoring
    D. Signature-based monitoring

  2. The type of access granted to an object and the actions that you can take on or with the
    object are examples of what?
    A. Permissions
    B. Rights
    C. Privileges
    D. Roles

  3. Which one of the following would be considered an example of infrastructure as a service
    cloud computing?
    A. Payroll system managed by a vendor and delivered over the web
    B. Application platform managed by a vendor that runs customer code
    C. Servers provisioned by customers on a vendor-managed virtualization platform
    D. Web-based email service provided by a vendor


For questions 24–26, please refer to the following scenario:

Darcy is an information security risk analyst for Roscommon Agricultural Products. She is
currently trying to decide whether the company should purchase an upgraded fire suppres-
sion system for their primary data center. The data center facility has a replacement cost of
$2 million.

After consulting with actuaries, data center managers, and fire subject matter experts,
Darcy determined that a typical fire would likely require the replacement of all equipment
inside the building but not cause significant structural damage. Together, they estimated
that recovering from the fire would cost $750,000. They also determined that the com-
pany can expect a fire of this magnitude once every 50 years.


  1. Based on the information in this scenario, what is the exposure factor for the effect of a
    fire on the Roscommon Agricultural Products data center?
    A. 7. 5%
    B. 15.0%
    C. 27. 5%
    D. 37. 5%

Free download pdf