CISSP-CN Exam Question 781
以下哪项最能描述“出口点数据丢失防护与端点检测和响应 (EDR) 集成”的目的?
Correct Answer: B
Integrating DLP with EDR allows security teams to correlate endpoint-level activity-such as which process accessed a sensitive file or attempted to copy it to removable media-with broader data movement events, providing more complete visibility into potential data exfiltration attempts that originate from or pass through an endpoint, rather than relying solely on network-level DLP visibility.
CISSP-CN Exam Question 782
至少應安排個人或群組帳戶的權限審核
Correct Answer: D
The minimum frequency for audits of permissions to individual or group accounts is continually.
Audits of permissions are the processes of reviewing and verifying the user accounts and access rights on a system or a network, and ensuring that they are appropriate, necessary, and compliant with the policies and standards. Audits of permissions can provide some benefits for security, such as enhancing the accuracy and the reliability of the user accounts and access rights, identifying and removing any excessive, obsolete, or unauthorized access rights, and supporting the audit and the compliance activities. Audits of permissions should be performed continually, which means that they should be conducted on a regular and consistent basis, without any interruption or delay. Continual audits of permissions can help to maintain the security and the integrity of the system or the network, by detecting and addressing any changes or issues that may affect the user accounts and access rights, such as role changes, transfers, promotions, or terminations. Continual audits of permissions can also help to ensure the effectiveness and the feasibility of the audit process, by reducing the workload and the complexity of the audit tasks, and by providing timely and relevant feedback and results. Annually, to correspond with staff promotions, and to correspond with terminations are not the minimum frequencies for audits of permissions to individual or group accounts, although they may be related or possible frequencies. Annually means that the audits of permissions are performed once a year, which may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated more frequently than that, due to various factors, such as role changes, transfers, promotions, or terminations. Annually audits of permissions may also increase the workload and the complexity of the audit process, as they may involve a large number of user accounts and access rights to review and verify, and they may not provide timely and relevant feedback and results. To correspond with staff promotions means that the audits of permissions are performed whenever a staff member is promoted to a higher or a different position within the organization, which may affect their user accounts and access rights. To correspond with staff promotions audits of permissions can help to ensure that the user accounts and access rights are aligned with the current roles or functions of the staff members, and that they follow the principle of least privilege. However, to correspond with staff promotions audits of permissions may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated due to other factors, such as role changes, transfers, or terminations, and they may not be performed on a regular and consistent basis. To correspond with terminations means that the audits of permissions are performed whenever a staff member leaves the organization, which may affect their user accounts and access rights. To correspond with terminations audits of permissions can help to ensure that the user accounts and access rights are revoked or removed from the system or the network, and that they prevent any unauthorized or improper access or use. However, to correspond with terminations audits of permissions may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated due to other factors, such as role changes, transfers, or promotions, and they may not be performed on a regular and consistent basis.
Audits of permissions are the processes of reviewing and verifying the user accounts and access rights on a system or a network, and ensuring that they are appropriate, necessary, and compliant with the policies and standards. Audits of permissions can provide some benefits for security, such as enhancing the accuracy and the reliability of the user accounts and access rights, identifying and removing any excessive, obsolete, or unauthorized access rights, and supporting the audit and the compliance activities. Audits of permissions should be performed continually, which means that they should be conducted on a regular and consistent basis, without any interruption or delay. Continual audits of permissions can help to maintain the security and the integrity of the system or the network, by detecting and addressing any changes or issues that may affect the user accounts and access rights, such as role changes, transfers, promotions, or terminations. Continual audits of permissions can also help to ensure the effectiveness and the feasibility of the audit process, by reducing the workload and the complexity of the audit tasks, and by providing timely and relevant feedback and results. Annually, to correspond with staff promotions, and to correspond with terminations are not the minimum frequencies for audits of permissions to individual or group accounts, although they may be related or possible frequencies. Annually means that the audits of permissions are performed once a year, which may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated more frequently than that, due to various factors, such as role changes, transfers, promotions, or terminations. Annually audits of permissions may also increase the workload and the complexity of the audit process, as they may involve a large number of user accounts and access rights to review and verify, and they may not provide timely and relevant feedback and results. To correspond with staff promotions means that the audits of permissions are performed whenever a staff member is promoted to a higher or a different position within the organization, which may affect their user accounts and access rights. To correspond with staff promotions audits of permissions can help to ensure that the user accounts and access rights are aligned with the current roles or functions of the staff members, and that they follow the principle of least privilege. However, to correspond with staff promotions audits of permissions may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated due to other factors, such as role changes, transfers, or terminations, and they may not be performed on a regular and consistent basis. To correspond with terminations means that the audits of permissions are performed whenever a staff member leaves the organization, which may affect their user accounts and access rights. To correspond with terminations audits of permissions can help to ensure that the user accounts and access rights are revoked or removed from the system or the network, and that they prevent any unauthorized or improper access or use. However, to correspond with terminations audits of permissions may not be sufficient or adequate to maintain the security and the integrity of the system or the network, as the user accounts and access rights may change or become outdated due to other factors, such as role changes, transfers, or promotions, and they may not be performed on a regular and consistent basis.
CISSP-CN Exam Question 783
以下哪项最能描述“加密擦除”(加密粉碎)作为一种数据清除方法?
Correct Answer: B
Cryptographic erasure (crypto-shredding) renders previously encrypted data permanently unrecoverable by securely deleting or destroying the encryption key used to protect it, rather than overwriting or physically destroying the underlying storage media itself. Since the data remains encrypted and the key is irrecoverably gone, the data is effectively rendered inaccessible-a particularly efficient sanitization method for large volumes of data or media that will be reused, such as in cloud environments where physical destruction is often impractical.
CISSP-CN Exam Question 784
攻擊模擬和威脅分析 (PASTA) 的威脅建模使用流程是什麼?
Correct Answer: A
Application decomposition, threat analysis, vulnerability detection, attack enumeration, risk/impact analysis is the threat modeling order using Process for Attack Simulation and Threat Analysis (PASTA). PASTA is a risk-centric threat modeling methodology that aims to identify and prioritize the most likely and impactful threats and vulnerabilities for a given system or application. PASTA consists of seven stages: definition, application decomposition, threat analysis, vulnerability analysis, attack enumeration, risk/impact analysis, and countermeasure selection. In each stage, PASTA uses various techniques and tools, such as data flow diagrams, attack trees, threat libraries, vulnerability scanners, risk matrices, and security controls, to perform a comprehensive and realistic threat assessment and mitigation plan.
CISSP-CN Exam Question 785
下列哪一項是最有效的糾正控制措施,可以最大限度地減少物理入侵的影響?
Correct Answer: B
A rapid response by guards or police to apprehend a possible intruder is the most effective corrective control to minimize the effects of a physical intrusion. A corrective control is a type of security control that aims to restore the normal operations and security level of a system or an organization after a security incident or violation has occurred. A physical intrusion is an unauthorized or unwanted entry into a physical facility or area that contains sensitive or valuable assets, such as IT equipment, data, or personnel. A physical intrusion can cause damage, theft, sabotage, or espionage to the assets, and compromise the confidentiality, integrity, or availability of the information or services provided by the organization. A rapid response by guards or police to apprehend a possible intruder can prevent or limit the extent of the damage or loss caused by the physical intrusion, and deter or punish the intruder. A rapid response can also provide evidence or information for further investigation or prosecution of the incident.
- Latest Upload
- 132Salesforce.Sales-Con-201.v2026-10-08.q104
- 132ACAMS.CAMS.v2026-10-08.q94
- 144CheckPoint.156-315.82.v2026-10-07.q59
- 151Microsoft.MB-820.v2026-10-07.q79
- 215CompTIA.SK0-005.v2026-10-07.q338
- 162Fortinet.NSE7_SSE_AR-26.v2026-10-05.q26
- 230IIA.IIA-CIA-Part1-CN.v2026-10-05.q321
- 352ISC.CISSP-CN.v2026-10-05.q802
- 158HP.HPE0-J81.v2026-10-05.q24
- 288Cisco.350-801.v2026-10-05.q313
[×]
Download PDF File
Enter your email address to download ISC.CISSP-CN.v2026-10-05.q802 Practice Test
