Terms and Definitions

You got 5 of 10 possible points.
Your score was: 50 %

Remember, these quizzes test your overall CISSP knowledge but should not be used as CISSP exam prep examples.

Question Results

Score 1 of 1

Question:

More key terms from Chapter 2

Response:

MatchUser answerFeedback

Weakness or lack of a countermeasure

Vulnerability

correct

Entity that can exploit a vulnerability

Threat agent

correct

The danger of having a vulnerability exploited

Threat

correct

The probability of a threat being realized

Risk

correct

Presence of a vulnerability which exposes the organization

Risk

incorrect
Score 1 of 1

Question:

Match the following control types to their purposes

Response:

MatchUser answerFeedback

Reducing Risk

Preventative

correct

Correcting violations and incidents

Recovery

Corrective controls also help improve existing preventative and detective controls

incorrect

Discouraging violations

Deterrent

correct

Providing alternate ways of accomplishing a task

Compensating

correct

Restoring systems and information

Recovery

correct
Score 1 of 1

Question:

A LAN is

Response:

a Local Authentication Node

a Local Account Name

a Linear Applebaum Network diagram

a Least Access Notification

a Local Area Network

Score 0 of 5
(skipped)

Question:

What is a cryptographic keystream that can only be used once?

Response:

Correct AnswerUser Answer
/one.*time.*pad/i
Score 1 of 1

Question:

A WAN is

Response:

a Wide Area Network

a Wide Array Node

a Working Authentication Name

the Westinghouse Address Naming convention

one of the Wilson-Adder Need types

Score 1 of 1

Question:

Match the following key terms

Response:

MatchUser answerFeedback

Availability

Reliable and timely access to data and resources

correct

Confidentiality

Necessary level of secrecy, unauthorized disclosure is prevented

correct

Shoulder surfing

Unauthorized viewing of information (screen peeking)

correct

Social Engineering

Tricking someone into giving sensitive information (to gain unauthorized access)

correct