What is the GREATEST challenge to identifying data leaks?
Correct Answer: C
CISSP Exam Question 312
An incremental backup process
Correct Answer: A
Explanation/Reference: Explanation: The incremental backup method backs up all the files that have changed since the last full or incremental backup and resets the archive bit to 0. This is known as "clearing the archive bit". A full backup backs up all files regardless of whether the archive bit is 1 or 0 and sets the archive bit to 0. The archive bit is used by the backup process to determine whether a file has been changed. When you modify a file or create a new file, the archive bit is set to 1. This tells the backups process that the file has changed (or is a new file) and needs to be backed up. When an incremental backup backs up the file, it sets the archive bit to 0. When the next incremental backup runs and sees that the archive bit is 0, the incremental backup knows that the file has not changed since the last backup and so will not back up the file again. Incorrect Answers: B: This answer describes the differential backup process. The differential backup does not change the archive bit value; an incremental backup does change the archive bit value to 0. C: This answer describes the full backup process. An incremental backup does not back up ALL files; it only backs up changed files. D: An incremental backup does not back up ALL files; it only backs up changed files. Furthermore, it changes the archive bit value to 0, not 1. References: Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 801-802
CISSP Exam Question 313
What is the primary goal of setting up a honey pot?
Correct Answer: D
The primary purpose of a honeypot is to study the attack methods of an attacker for the purposes of understanding their methods and improving defenses. "To lure hackers into attacking unused systems" is incorrect. Honeypots can serve as decoys but their primary purpose is to study the behaviors of attackers. "To entrap and track down possible hackers" is incorrect. There are a host of legal issues around enticement vs entrapment but a good general rule is that entrapment is generally prohibited and evidence gathered in a scenario that could be considered as "entrapping" an attacker would not be admissible in a court of law. "To set up a sacrificial lamb on the network" is incorrect. While a honeypot is a sort of sacrificial lamb and may attract attacks that might have been directed against production systems, its real purpose is to study the methods of attackers with the goals of better understanding and improving network defenses. References: AIO3, p. 213
CISSP Exam Question 314
Which of the following is a web application control that should be put into place to prevent exploitation of Operating System (OS) bugs?
Correct Answer: B
CISSP Exam Question 315
Which of the following protocol is PRIMARILY used to provide confidentiality in a web based application thus protecting data sent across a client machine and a server?
Correct Answer: A
Explanation/Reference: Explanation: SSL is primarily used to protect HTTP traffic. SSL capabilities are already embedded into most web browsers. Incorrect Answers: B: FTP is used to transfer files, not to secure data that are transferred. C: S/MIME is not to protect data sent in web applications. S/MIME, more specifically, is used to secure email messages. D: SSH is not used in a web based application. SSH allows remote login and other network services to operate securely over an unsecured network. References: Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 846