Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Download Full Version CISSP ISC Exam

Page: 33 / 45
Total 1486 questions

Certified Information Systems Security Professional (CISSP) Questions and Answers

Question 129

When conducting a third-party risk assessment of a new supplier, which of the following reports should be reviewed to confirm the operating effectiveness of the security, availability, confidentiality, and privacy trust principles?

Options:

A.

Service Organization Control (SOC) 1, Type 2

B.

Service Organization Control (SOC) 2, Type 2

C.

International Organization for Standardization (ISO) 27001

D.

International Organization for Standardization (ISO) 27002

Question 130

What is the MAIN objective of risk analysis in Disaster Recovery (DR) planning?

Options:

A.

Establish Maximum Tolerable Downtime (MTD) Information Systems (IS).

B.

Define the variable cost for extended downtime scenarios.

C.

Identify potential threats to business availability.

D.

Establish personnel requirements for various downtime scenarios.

Question 131

Which of the following are mandatory canons for the (ISC)* Code of Ethics?

Options:

A.

Develop comprehensive security strategies for the organization.

B.

Perform is, honestly, fairly, responsibly, and lawfully for the organization.

C.

Create secure data protection policies to principals.

D.

Provide diligent and competent service to principals.

Question 132

Which of the following is a common term for log reviews, synthetic transactions, and code reviews?

Options:

A.

Security control testing

B.

Application development

C.

Spiral development functional testing

D.

DevOps Integrated Product Team (IPT) development

Page: 33 / 45
Total 1486 questions