<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISSP questions in Exams</title>
    <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/42175#M1288</link>
    <description>&lt;P&gt;Unfortunately - you are wrong - the ultimate is the CIO&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2021 02:16:01 GMT</pubDate>
    <dc:creator>PuettK</dc:creator>
    <dc:date>2021-01-06T02:16:01Z</dc:date>
    <item>
      <title>Practice Questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18626#M93</link>
      <description>&lt;P&gt;Right.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For (and from) all the newbies out there who want help for studying, there have been numerous questions about, well, questions.&amp;nbsp; As in, "what's the best set of practice questions to use while studying for the exam?"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The answer is, none of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have looked at an awful lot of practice question sets, and they are uniformly awful.&amp;nbsp; Most try to be "hard" by bringing in trivia: that is not representative of the exam.&amp;nbsp; Most concentrate on a bunch of facts: that is not representative of the exam.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, from my own stash, collected and developed over the decades, I'm going to give you some samples that do represent the &lt;STRONG&gt;types&lt;/STRONG&gt; of questions that you will probably see on the exam.&amp;nbsp; Note that none of these questions will appear on the exam.&amp;nbsp; You can't pass the CISSP exam by memorizing a brain dump.&amp;nbsp; These will just give you a feel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For each question I'll give the answer, what type of question this represents, and possibly ways to approach this type of question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll be doing this over time, "replying" to this post to add questions.&amp;nbsp; Others are free to add sample questions if they wish, but be ready to be (possibly severely) critiqued.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:06:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18626#M93</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18627#M94</link>
      <description>&lt;P&gt;Which of the following is a key element during the initial security planning process?&lt;/P&gt;&lt;P&gt;a. Establish system review time frames&lt;BR /&gt;b. Implement a security awareness program&lt;BR /&gt;c. Defining reporting relationships&lt;BR /&gt;d. Institute a change management program&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Answer: c&lt;BR /&gt;Reference: Handbook of Information Security Management, edited by Ruthberg and Tipton, Auerbach, 1993, pg 75&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right, a few initial notes.&amp;nbsp; You will notice a reference.&amp;nbsp; Every exam question is (or was) backed up by at least two references from source security literature.&amp;nbsp; Note that CISSP study guides are &lt;STRONG&gt;not&lt;/STRONG&gt; source security literature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A key word in this question is "&lt;STRONG&gt;initial&lt;/STRONG&gt;."&amp;nbsp; Establishing system review time frames, security awareness programs, and change management programs are all important, but they come later in security planning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note also one rather important point.&amp;nbsp; All of these answers are "correct" in a way.&amp;nbsp; If you are confronted with four "right" answers, and one of them is the "management" answer, that one is probably the one that will get you the point.&amp;nbsp; Defining reporting relationships is both something you want to establish early in planning, and it's also the "management" answer.&amp;nbsp; (One person I helped coach through the exam said that this &lt;STRONG&gt;one tip&lt;/STRONG&gt; applied to about 10% of the total exam.)&lt;/P&gt;</description>
      <pubDate>Sun, 03 Feb 2019 19:57:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18627#M94</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-03T19:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18633#M95</link>
      <description>Is it possible for you to share your whole question database once as pdf and rather discuss the difficult question in this forum. It will be of great help for those who are preparing for exam and will save some time</description>
      <pubDate>Mon, 04 Feb 2019 12:24:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18633#M95</guid>
      <dc:creator>shahzadafridi</dc:creator>
      <dc:date>2019-02-04T12:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18637#M96</link>
      <description>&amp;gt; shahzadafridi (Viewer II) posted a new reply in Certifications on 02-04-2019&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Is it possible for you to share your whole question database once as pdf and&lt;BR /&gt;&amp;gt; rather discuss the difficult question in this forum.&lt;BR /&gt;&lt;BR /&gt;Some people are just *never* satisfied.&lt;BR /&gt;&lt;BR /&gt;(Alternatively, no good deed goes unpunished.)&lt;BR /&gt;&lt;BR /&gt;I tried that. Once. Having pointed out that you would never see any of these&lt;BR /&gt;questions on the exam, I got people who complained that they studied and&lt;BR /&gt;memorized the sample questions, took the exam, and didn't see any of questions&lt;BR /&gt;on the exam ...&lt;BR /&gt;&lt;BR /&gt;Pay attention. These questions are not for "studying," except incidentally. These&lt;BR /&gt;questions are to prepare you for the types of questions that you will see on the&lt;BR /&gt;exam.&lt;BR /&gt;&lt;BR /&gt;Actually, a good way to study is to try and *write* questions. That gets you into&lt;BR /&gt;the mindset of the exam itself. Try writing some questions, post them here, and&lt;BR /&gt;I'll tell you whether they are too easy, too hard, or not the type of thing you'll&lt;BR /&gt;see. Remember Bloom's Taxonomy: simple facts, synthesis of two or more facts,&lt;BR /&gt;analysis of the implications of two or more facts, and, most importantly,&lt;BR /&gt;questions requiring judgment and critical thinking.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;BEWARE OF GOD&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Mon, 04 Feb 2019 18:13:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18637#M96</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-04T18:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18641#M97</link>
      <description>&lt;P&gt;Which of the following is NOT an element of a security planning mission statement?&lt;/P&gt;&lt;P&gt;a. Objectives statement&lt;BR /&gt;b. Background statement&lt;BR /&gt;c. Scope statement&lt;BR /&gt;d. Confidentiality statement&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer: d&lt;BR /&gt;Reference: Handbook of Information Security Management, edited by Ruthberg and Tipton, Auerbach, 1993, page 73&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the type of question that ensures you do not just memorize a bunch of security buzzwords.&amp;nbsp; You have to understand the concepts behind them.&amp;nbsp; What is a "security planning mission statement"?&amp;nbsp; Well, it's more simply known as a policy.&amp;nbsp; What does a policy contain?&amp;nbsp; Among other things, the background of your enterprise, your objectives, and the scope of what you are trying to protect.&amp;nbsp; What you are going to do about confidentiality (unless you are an unusual company and either don't care about confidentiality, or it's really, really important) generally is in your subordinate standards or procedures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't get hung up on whether the question has exactly the wording you have studied.&amp;nbsp; That way lies failure.&amp;nbsp; Make sure you understand the fundamentals behind the words.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 18:13:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18641#M97</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-06T18:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18643#M98</link>
      <description>Can data classification or encryption (criteria to encrypt) be included in confidentiality statement?</description>
      <pubDate>Mon, 04 Feb 2019 19:32:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18643#M98</guid>
      <dc:creator>shahzadafridi</dc:creator>
      <dc:date>2019-02-04T19:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18646#M99</link>
      <description>&amp;gt; shahzadafridi (Viewer II) posted a new reply in Certifications on 02-04-2019&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Can data classification or encryption (criteria to encrypt) be included in&lt;BR /&gt;&amp;gt; confidentiality statement?&lt;BR /&gt;&lt;BR /&gt;Why not?&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Maybe we're all just part of God's `Sim Universe' video game.&lt;BR /&gt;Let's just hope that He's not playing on a Windows machine, or&lt;BR /&gt;we're all screwed. - Jeff Ehrhart&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Mon, 04 Feb 2019 19:58:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18646#M99</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-04T19:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18649#M100</link>
      <description>Then it is part of policy so why "D" option. I have doubts on background statement</description>
      <pubDate>Mon, 04 Feb 2019 20:13:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18649#M100</guid>
      <dc:creator>shahzadafridi</dc:creator>
      <dc:date>2019-02-04T20:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18653#M101</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;I agree with your answer D.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your question has "e&lt;SPAN&gt;lement of a security planning mission statement".&amp;nbsp; In the planning phase, I am not concerned with encryption or data classification.&amp;nbsp; I would suggest at this point in time, I do not understand either the data classification or encryption requirements.....do I need a 3 by 3 matrix for data classification or a 4X4, a 5X5? nor do I understand where or when I can apply encryption.&amp;nbsp; If I carefully read the question,&amp;nbsp; I am PLANNING the Security mission.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I recommend that folks read every word, and not read meaning or anything into the questions.&amp;nbsp; I have too often seen people rush through the exam and fail&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My nickel Canadian on a warm Monday (14 C or 57 F) here in Ontario.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Diana&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 21:48:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18653#M101</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-02-04T21:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18656#M102</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My nickel Canadian on a warm Monday (14 C or 57 F) here in Ontario.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Glad it's warmed up back there.&amp;nbsp; Out here there is actually &lt;STRONG&gt;snow&lt;/STRONG&gt; in my front yard, and it's apparently going down to minus nine overnight ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And thanks for jumping in on the policy question.&amp;nbsp; I was going to mention that you need to stick to the concepts, and that the concept here is that policy is high-level and abstract, and that protection details belong in the subordinate documents, but yours works, too&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh, and a strong Amen! on reading the questions carefully ...&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 22:32:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18656#M102</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-04T22:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18657#M103</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/714531689"&gt;@shahzadafridi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;Then it is part of policy so why "D" option. I have doubts on background statement&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Exactly what&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wanted you to think about.&amp;nbsp; One can make a case for any of the four answers, but &lt;A href="https://www.youtube.com/watch?v=rsRjQDrDnY8" target="_blank" rel="noopener"&gt;one of these things&lt;/A&gt;&amp;nbsp;(read some of the comments) is less "good" than the rest.&amp;nbsp; Since Rob gave you the reference, you can go to the source and understand why the particular answer was chosen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Rob is doing here is similar to what we know about the (ISC)² test development process.&amp;nbsp; The difference being that Rob follows up by explaining the thought process behind the answer, whereas (ISC)²'s next step is to use the question on actual exams, with zero-weighting until the answer is "proven" good, bad or indifferent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob is doing a wonderful thing here.&amp;nbsp; It is not about a building a "brain dump" of actual questions...&amp;nbsp; &amp;nbsp;It's learning to get inside the head of the test-writers, understanding how/why the questions were written and selecting the answer that matches their way of thinking.&amp;nbsp; In the case of CISSP, that person would be someone with many years of cross-functional IT security experience that keeps up with current trends and generally holds a position where they are making/leading decisions as part of the company's management.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;This is an important skill not just for the CISSP exam, but for communicating with people in general.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Understanding that this skill exists and learning to use it contributed more to my passing&amp;nbsp; than any of the time I spent with study materials.&amp;nbsp; It has also served me well as a go-between between management and techies and also between techies of different disciplines.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 22:37:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18657#M103</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-02-04T22:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18660#M104</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last time, I attended an item writing workshop, we not only had to provide the reference but we also had to write a justification for the correct answer and why the wrong answers were wrong.&amp;nbsp; &amp;nbsp;So a lot of thought goes into questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I appreciate what Rob is doing and his dedication to assisting, although, the Subject of the thread could be changed as the format and rigour should be the same with all exams.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 23:57:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18660#M104</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-02-04T23:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18672#M105</link>
      <description>If you are some credit card company or any company that deals with PII of customers i think the mission statement must include to protect this data in rest and transit. Policy statement as a high level objective will not include the technical specification off course.&lt;BR /&gt;&lt;BR /&gt;P.S just giving a thought for discussion otherwise i agree with your explanation</description>
      <pubDate>Tue, 05 Feb 2019 07:47:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18672#M105</guid>
      <dc:creator>shahzadafridi</dc:creator>
      <dc:date>2019-02-05T07:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18727#M106</link>
      <description>&lt;P&gt;In data processing systems, the value analysis should be performed in terms of which three properties?&lt;/P&gt;&lt;P&gt;a. Profit, loss, ROI&lt;BR /&gt;b. Intentional, accidental, natural disaster&lt;BR /&gt;c. Assets, personnel, services provided&lt;BR /&gt;d. Availability, integrity, confidentiality&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer: d.&lt;BR /&gt;Reference: Information Systems Security; Fites &amp;amp; Kratz; Thompson Press; 1996; pg 54.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK, in a sense this is kind of a trick question, for a couple of reasons.&amp;nbsp; But it does have a point.&amp;nbsp; The point is, choose the answer with the greatest breadth and application that does answer the question.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer a - incorrect - it's right, but applies only to business management.&lt;BR /&gt;Answer b - incorrect - it's right, but applies directly to threat analysis.&lt;BR /&gt;Answer c - incorrect - it's right, but considered mostly in business impact analysis.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;(There is a myth that says that if you see the CIA triad [confidentiality, integrity, availability] as an answer on &lt;STRONG&gt;any&lt;/STRONG&gt; question on the CISSP exam, that is the correct answer.&amp;nbsp; In fact, a friend, knowing of the myth, once specifically wrote a question so that CIA was &lt;STRONG&gt;wrong&lt;/STRONG&gt; ...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 18:12:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18727#M106</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-06T18:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18822#M107</link>
      <description>&lt;P&gt;Which of the following techniques MOST clearly indicates whether specific risk reduction controls should be implemented?&lt;/P&gt;&lt;P&gt;a. Threat and vulnerability analysis.&lt;BR /&gt;b. Risk evaluation.&lt;BR /&gt;c. ALE calculation.&lt;BR /&gt;d. Countermeasure cost/benefit analysis.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer: d.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Reference: Computer Security Handbook (3rd edition) Hutt, Boswirth, Hoyt; pg 3.3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A fairly simple question: it should be fairly obvious.&amp;nbsp; Again, the principle here is to choose the answer that most broadly answers the question.&amp;nbsp; All the answers are important parts of security and risk assessment, but:&lt;BR /&gt;Answer a - this analysis does not address whether &lt;STRONG&gt;specific&lt;/STRONG&gt; countermeasures should be implemented.&lt;BR /&gt;Answer b - risk evaluation studies existing risks but doesn’t address whether specific countermeasures should be implemented.&lt;BR /&gt;Answer c - ALE is the calculation of loss expectancy but does not address whether specific countermeasures should be implemented.&lt;BR /&gt;Answer d - correct - in a countermeasures cost/benefit analysis, the annualized cost of safeguards is compared with the expected cost of loss.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh, one more point: if you saw this question on an exam these days, it should be reworded slightly.&amp;nbsp; Acronyms in questions are now supposed to be spelled out in full.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 17:46:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18822#M107</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-08T17:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18844#M108</link>
      <description>&lt;P&gt;Prior to implementation, a complete description of an operational security issue should specify threat, vulnerability, and&lt;/P&gt;&lt;P&gt;a. safeguard.&lt;BR /&gt;b. asset.&lt;BR /&gt;c. exposure.&lt;BR /&gt;d. control.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer: b.&lt;/P&gt;&lt;P&gt;(Reference: Fitzgerald, Jerry, Internal Controls for Computerized Systems, 1978, pg 7)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This isn't really a &lt;STRONG&gt;type&lt;/STRONG&gt; of question, as such, it's just one that a surprising number of people get wrong.&amp;nbsp; We tend to concentrate on "problems" and forget what it is that we are trying to protect.&amp;nbsp; Don't get that (or any other kind) of tunnel vision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which, I suppose, is as good a segue as any to another point.&amp;nbsp; Remember that the CISSP is a general, and even international, certification.&amp;nbsp; When presented with a question, don't pick an answer that is specifically suited to your job or company: pick the answer that is most suited to security in general.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Feb 2019 19:35:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18844#M108</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-09T19:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18936#M109</link>
      <description>&lt;P&gt;What step can a company take to reduce the risk of its employees violating software copyright laws?&lt;/P&gt;&lt;P&gt;a. Remove copy programs from personal computers.&lt;BR /&gt;b. Install application licensing meters to prevent an excess of users for each license.&lt;BR /&gt;c. Establish a company policy prohibiting the unauthorized duplicating of software.&lt;BR /&gt;d. Prohibit the use of software on multiple computers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Answer: c.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is another question that lots and lots of people get wrong.&amp;nbsp; But, by this time, you should get it right because it illustrates points already made.&lt;BR /&gt;Answer a - wrong - Well, it's possible, and might work, but it's not really practical, is it?&amp;nbsp; Copying is a basic function of computers: users have a need to copy files.&amp;nbsp; Besides, even if you took it off, people could put it back.&lt;BR /&gt;Answer b - wrong - A meter notes and possibly alerts you to the use of software beyond the number of licensed copies.&amp;nbsp; It may or may not prevent copying.&amp;nbsp; It would help, but it is not a complete solution.&lt;BR /&gt;Answer c - correct - The policy doesn’t prevent copying, but does reduce the liability risk if employees are caught making illegal copies.&amp;nbsp; (And that's the &lt;STRONG&gt;real&lt;/STRONG&gt; risk in violating copyright, yes?)&amp;nbsp; And it means you can fire them if they do.&amp;nbsp; (If there's no policy against it, what did they do that was wrong?)&lt;BR /&gt;Answer d - wrong - It's kind of impractical because more than one user may need to use the program.&amp;nbsp; I mean, really ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh, and remember that earlier point about the management answer being the right one?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 19:31:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/18936#M109</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-11T19:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19023#M110</link>
      <description>&lt;P&gt;Who is ultimately responsible to ensure that information is categorized and that specific protective measures are taken?&lt;/P&gt;&lt;P&gt;a. Security Officer&lt;BR /&gt;b. Senior Management&lt;BR /&gt;c. Data Owner&lt;BR /&gt;d. Custodian&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Answer: b.&lt;BR /&gt;Reference: Commonsense Computer Security; Martin Smith; 1993; pg 63.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is possibly as close to a "trick" question that you'll get on the exam.&amp;nbsp; If you are just skimming the question, and the answers, the fact that the data owner is generally responsible for assigning data classification is going to jump out at you.&amp;nbsp; Again, read the whole question.&amp;nbsp; The key word here is "ultimately."&amp;nbsp; "Ultimately," senior management is responsible for everything.&amp;nbsp; The security officer may play some role in data classification, but unless you work in a MAC (Mandatory Access Control) environment won't be the one making individual decisions.&amp;nbsp; And the custodian just acts on behalf of the owner.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 19:42:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19023#M110</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-13T19:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP "sample" questions</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19038#M111</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;I agree with your answer but as a seasoned item writer, I would really object to this question being on an exam as it is a trick.&amp;nbsp; Sr. Management have the ultimate responsibility, however the Data Owner is the only person who truly understands the value of the data....and if they get it wrong, it doesn't matter what Sr. Management does in terms of data value, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also think that you would find the stats on a question like this would be poor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my nickel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 22:42:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19038#M111</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-02-13T22:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: dcontesti mentioned you in (ISC)Â² Community</title>
      <link>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19044#M112</link>
      <description>&amp;gt; dcontesti (Contributor I) mentioned you in a post! Join the conversation below:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;I agree with your answer but as a seasoned item writer, I would really&lt;BR /&gt;&amp;gt; object to this question being on an exam as it is a trick.&amp;nbsp; Sr. Management have&lt;BR /&gt;&amp;gt; the ultimate responsibility, however the Data Owner is the only person who truly&lt;BR /&gt;&amp;gt; understands the value of the data....and if they get it wrong, it doesn't matter&lt;BR /&gt;&amp;gt; what Sr. Management does in terms of data value, etc. &amp;nbsp; Also think that you&lt;BR /&gt;&amp;gt; would find the stats on a question like this would be poor. &amp;nbsp; Just my nickel&lt;BR /&gt;&lt;BR /&gt;I don't disagree with you.&lt;BR /&gt;&lt;BR /&gt;At the same time, I think that, as an example, it does emphasize two important&lt;BR /&gt;points:&lt;BR /&gt;1) the importance of the "management" answer, and&lt;BR /&gt;2) read the question carefully!&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;GOVERNMENT.SYS corrupted, reboot Ottawa? (Y/N)&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 13 Feb 2019 23:53:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/Practice-Questions/m-p/19044#M112</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-13T23:53:04Z</dc:date>
    </item>
  </channel>
</rss>

