Who must approve modifications to an organization's production infrastructure configuration?
Correct Answer: D
CISSP Exam Question 142
A security consultant has been asked to research an organization's legal obligations to protect privacy-related information. What kind of reading material is MOST relevant to this project?
Correct Answer: C
CISSP Exam Question 143
Which of the following statements pertaining to disaster recovery is incorrect?
Correct Answer: D
Explanation/Reference: Explanation: The salvage team must ensure the reliability of primary site. This is done by returning the least-mission- critical processes to the restored original site to stress - test the rebuilt network. As the restored site shows resiliency, more important processes are transferred. Incorrect Answers: A: The restoration team should be responsible for getting the alternate site into a working and functioning environment B: The salvage team must ensure the reliability of primary site by returning it to normal processing conditions. C: Within the recovery plan the salvage team is responsible for starting the recovery of the original site. The recovery plan must include how the original site is recovered. References: Stewart, James M., Ed Tittel, and Mike Chapple, CISSP: Certified Information Systems Security Professional Study Guide, 5th Edition, Sybex, Indianapolis, 2011, p. 669
CISSP Exam Question 144
The general philosophy for DMZ's are that:
Correct Answer: A
CISSP Exam Question 145
Which of the following statements pertaining to the trusted computing base (TCB) is false?
Correct Answer: A
The ability of a TCB to correctly enforce a security policy depends solely on the mechanisms within it and the correct input by system administrative personnel of parameters related to security policy. For example, if Jane only has a "CONFIDENTIAL" clearence, a system administrator could foil the correct operation of a TCB by providing input to the system that gave her a "SECRET" clearence. "It is defined in the Orange Book" is an incorrect choice. The TCB is defined in the Orange Book (TCSEC or Trusted Computer System Evaluation Criteria). "It includes hardware, firmware and software" is incorrect. The TCB does includes the combination of all hardware, firmware and software responsible for enforcing the security policy. "A higher TCB rating will require that details of their testing procedures and documentation be reviewed with more granularity" is incorrect. As the level of trust increases (D through A), the level of scrutiny required during evaluation increases as well. References: CBK, pp. 323 - 324, 329 - 330 AIO3, pp. 269 - 272,