CISSP-CN Exam Question 776
一位安全顧問受邀研究某組織在保護隱私相關資訊方面的法律義務。哪種類型的閱讀材料與此項目最相關?
Correct Answer: B
The most relevant reading material for researching an organization's legal obligations to protect privacy-related information is the privacy-related regulations enforced by governing bodies applicable to the organization. These regulations define the legal requirements, standards, and penalties for collecting, processing, storing, and disclosing personal or sensitive information of individuals or entities. The organization must comply with these regulations to avoid legal liabilities, fines, or sanctions.
CISSP-CN Exam Question 777
下列哪一項可確保舊日誌資料不被覆蓋?
Correct Answer: D
Log retention is the process of keeping old log data for a certain period of time before deleting or archiving it. Log retention ensures that old log data is not overwritten by new log data, which could result in the loss of valuable information or evidence. Log retention also helps to comply with legal or regulatory requirements, such as the GDPR, that may mandate the retention of log data for a specific duration. Log retention can be implemented by using policies, procedures, and tools that define how long and where to store log data, how to protect log data from unauthorized access or modification, and how to dispose of log data securely when it is no longer needed.
CISSP-CN Exam Question 778
安全架構師計劃參考強制存取控制 (MAC) 模型進行實作。這顯示下列哪些屬性被優先考慮?
Correct Answer: A
According to the CISSP Official (ISC)2 Practice Tests, the property that is prioritized by a Mandatory Access Control (MAC) model for implementation is confidentiality. Confidentiality is the property that ensures that the data or information is only accessible or disclosed to the authorized parties, and is protected from unauthorized or unintended access or disclosure. A MAC model is a type of access control model that grants or denies access to an object based on the security labels of the subject and the object, and the security policy enforced by the system. A security label is a tag or a marker that indicates the classification, sensitivity, or clearance of the subject or the object, such as top secret, secret, or confidential. A security policy is a set of rules or criteria that defines how the access decisions are made based on the security labels, such as the Bell-LaPadula model or the Biba model. A MAC model prioritizes confidentiality, as it ensures that the data or information is only accessible or disclosed to the subjects that have the appropriate security labels and clearance, and that the data or information is not leaked or compromised by the subjects that have lower security labels or clearance. Integrity is not the property that is prioritized by a MAC model for implementation, although it may be a property that is supported or enhanced by a MAC model. Integrity is the property that ensures that the data or information is accurate, complete, and consistent, and is protected from unauthorized or unintended modification or corruption. A MAC model may support or enhance integrity, as it ensures that the data or information is only modified or corrupted by the subjects that have the appropriate security labels and clearance, and that the data or information is not altered or damaged by the subjects that have lower security labels or clearance. However, a MAC model does not prioritize integrity, as it does not prevent or detect the modification or corruption of the data or information by the subjects that have the same or higher security labels or clearance, or by the external factors or events, such as errors, failures, or accidents. Availability is not the property that is prioritized by a MAC model for implementation, although it may be a property that is supported or enhanced by a MAC model. Availability is the property that ensures that the data or information is accessible and usable by the authorized parties, and is protected from unauthorized or unintended denial or disruption of access or use. A MAC model may support or enhance availability, as it ensures that the data or information is accessible and usable by the subjects that have the appropriate security labels and clearance, and that the data or information is not denied or disrupted by the subjects that have lower security labels or clearance. However, a MAC model does not prioritize availability, as it does not prevent or detect the denial or disruption of access or use of the data or information by the subjects that have the same or higher security labels or clearance, or by the external factors or events, such as attacks, failures, or disasters. Accessibility is not the property that is prioritized by a MAC model for implementation, as it is not a security property, but a usability property. Accessibility is the property that ensures that the data or information is accessible and usable by the users with different abilities, needs, or preferences, such as the users with disabilities, impairments, or limitations. Accessibility is not a security property, as it does not protect the data or information from unauthorized or unintended access, disclosure, modification, corruption, denial, or disruption. Accessibility is a usability property, as it enhances the user experience and satisfaction of the data or information.
CISSP-CN Exam Question 779
在通用標準中,下列哪一項是表達一組獨立於實現的安全要求的正式文件?
Correct Answer: C
The common criteria is an international standard for evaluating the security and assurance of information technology products and systems. It defines a common framework and language for specifying, implementing, and evaluating security requirements and functions. In the common criteria, a Protection Profile (PP) is a formal document that expresses an implementation- independent set of security requirements for a category of products or systems that share a common security problem or objective. A PP defines the security problem, the security objectives, the security functional requirements, and the security assurance requirements for the intended products or systems. A PP can be used by customers, developers, or evaluators as a basis for selecting, developing, or evaluating security solutions.
CISSP-CN Exam Question 780
下列哪一項最能代表最小特權的概念?
Correct Answer: A
According to the CISSP CBK Official Study Guide, the concept of least privilege means that users and processes should only have the minimum access required to perform their tasks, and no more. This reduces the risk of unauthorized or malicious actions, as well as the impact of potential incidents. One way to implement the principle of least privilege is to use a default-deny policy, which means that access to an object is denied unless access is specifically allowed. This is also known as a whitelist approach, which only grants access to predefined and authorized entities. Access to an object is only available to the owner is not a good representation of the concept of least privilege, as it may prevent legitimate access by other authorized users or processes. Access to an object is allowed unless it is protected by the information security policy is not a good representation of the concept of least privilege, as it may allow unnecessary or excessive access by default. This is also known as a blacklist approach, which only denies access to predefined and unauthorized entities. Access to an object is only allowed to authenticated users via an Access Control List (ACL) is not a good representation of the concept of least privilege, as it may not consider the authorization and accountability aspects of access control. Authentication is the process of verifying the identity of a user or process, while authorization is the process of granting or denying access based on the identity and the access policy. An ACL is a mechanism that defines the permissions and restrictions for accessing an object, but it does not necessarily enforce the principle of least privilege.
- Latest Upload
- 132Salesforce.Sales-Con-201.v2026-10-08.q104
- 132ACAMS.CAMS.v2026-10-08.q94
- 144CheckPoint.156-315.82.v2026-10-07.q59
- 151Microsoft.MB-820.v2026-10-07.q79
- 215CompTIA.SK0-005.v2026-10-07.q338
- 162Fortinet.NSE7_SSE_AR-26.v2026-10-05.q26
- 230IIA.IIA-CIA-Part1-CN.v2026-10-05.q321
- 350ISC.CISSP-CN.v2026-10-05.q802
- 158HP.HPE0-J81.v2026-10-05.q24
- 288Cisco.350-801.v2026-10-05.q313
[×]
Download PDF File
Enter your email address to download ISC.CISSP-CN.v2026-10-05.q802 Practice Test
