CISSP Exam Question 186
Which of the following answers is directly related to providing High Availability to your users?
Correct Answer: A
When planning for high availability, any critical component of your data network should have some sort of redundancy or backup plan in case it does fail.
Usually this involves things like backup data circuits, fault tolerant systems and otherwise redundant technology across the board.
This can include items like these:
- RAID array disks on servers so that if any single drive fails the server remains available.
- Backup network connections. Many internet services providers provide these for a fee.
- Backup power for all systems and circuits.
- Fire suppression and evacuation plans.
- A data backup practice to backup and restore data while storing backups offsite in a safe, remote location.
Also critical to high availability is a well-planned and tested disaster recovery plan. You can either develop one, find one free online or pay a contract agency to develop one for you.
The lines get a little blurry between fault tolerance and high availability because one is the direct result of the other but the questions on the exam should be pretty clear.
The following answers are incorrect:
- Good hiring practices: High Availability doesn't really involve good hiring practices but when you higher good technicians you availability would definitely improve.
- Updated Antivirus Software: This isn't directly related to high availability, although it's a critical part of defense in depth.
- Senior Executive Support: While this is important for funding equipment for high availability it isn't directly related to providing the high availability.
The following reference(s) was used to create this question:
2013. Official Security+ Curriculum.
Usually this involves things like backup data circuits, fault tolerant systems and otherwise redundant technology across the board.
This can include items like these:
- RAID array disks on servers so that if any single drive fails the server remains available.
- Backup network connections. Many internet services providers provide these for a fee.
- Backup power for all systems and circuits.
- Fire suppression and evacuation plans.
- A data backup practice to backup and restore data while storing backups offsite in a safe, remote location.
Also critical to high availability is a well-planned and tested disaster recovery plan. You can either develop one, find one free online or pay a contract agency to develop one for you.
The lines get a little blurry between fault tolerance and high availability because one is the direct result of the other but the questions on the exam should be pretty clear.
The following answers are incorrect:
- Good hiring practices: High Availability doesn't really involve good hiring practices but when you higher good technicians you availability would definitely improve.
- Updated Antivirus Software: This isn't directly related to high availability, although it's a critical part of defense in depth.
- Senior Executive Support: While this is important for funding equipment for high availability it isn't directly related to providing the high availability.
The following reference(s) was used to create this question:
2013. Official Security+ Curriculum.
CISSP Exam Question 187
Of the various types of "Hackers" that exist, the ones who are not worried about being caught and spending time in jail and have a total disregard for the law or police force, are labeled as what type of hackers?
Correct Answer: A
Suicide Hackers are a type of hackers without fear, who disregard the authority, the police, or law. Suicide Hackers hack for a cause important to them and find the end goal more important than their individual freedom.
The term "Hacker" originally meant a Unix computer enthusiast but has been villainized in the media as a "Criminal Hacker" for a mass audience. A hacker used to be known as a good person who would add functionality within software or would make things work better.
To most people today "Hacker" means criminal "Criminal Cracker", it is synonymous with
Cracker or someone who get access to a system without the owner authorization.
As seen in news reports in 2011 and later hackers associated with the "Anonymous" movement have attacked finance and/or credit card companies, stolen enough information to make contributions to worthy charities on behalf of organizations they see as contrary to the public good. These sorts of attackers/hackers could be considered suicide hackers.
Some did get caught and prosecuted while carrying out their cause. Nobody can know if they knew their activities would land them in court and/or prison but they had to have known of the risk and proceeded anyway.
The following answers are incorrect:
Black Hat hackers are also known as crackers and are merely hackers who "violates computer security for little reason beyond maliciousness or for personal gain". Black Hat
Hackers are "the epitome of all that the public fears in a computer criminal". Black Hat
Hackers break into secure networks to destroy data or make the network unusable for those who are authorized to use the network.
White Hat Hackers are law-abiding, reputable experts defending assets and not breaking laws. A white hat hacker breaks security for non-malicious reasons, for instance testing their own security system. The term "white hat" in Internet slang refers to an ethical hacker.
This classification also includes individuals who perform penetration tests and vulnerability assessments within a contractual agreement. Often, this type of 'white hat' hacker is called an ethical hacker. The International Council of Electronic Commerce Consultants, also known as the EC-Council has developed certifications, courseware, classes, and online training covering the diverse arena of Ethical Hacking.
Note about White Hat: As reported by Adin Kerimov, a white hat would not be worried about going to jail as he is doing a test with authorization as well and he has a signed agreement. While this is a true point he BEST choice is Suicide Hackers for the purpose of the exam, a white hat hacker would not disregard law and the autority. .
Gray Hat Hackers work both offensively and defensively and can cross the border between legal/ethical behavior and illegal/unethical behavior. A grey hat hacker is a combination of a
Black Hat and a White Hat Hacker. A Grey Hat Hacker may surf the internet and hack into a computer system for the sole purpose of notifying the administrator that their system has been hacked, for example. Then they may offer to repair their system for a small fee.
OTHER TYPES OF HACKERS
Elite hacker is a social status among hackers, elite is used to describe the most skilled.
Newly discovered exploits will circulate among these hackers. Elite groups such as Masters of Deception conferred a kind of credibility on their members.
Script kiddie A script kiddie(or skiddie) is a non-expert who breaks into computer systems by using pre-packaged automated tools written by others, usually with little understanding of the underlying concept-hence the term script (i.e. a prearranged plan or set of activities) kiddie (i.e. kid, child-an individual lacking knowledge and experience, immature). Often time they do not even understand how they are taken advantage of the system, they do not underrstand the weakness being exploited, all they know is how to use a tool that somone else has built.
Neophyte A neophyte, "n00b", or "newbie" is someone who is new to hacking or phreaking and has almost no knowledge or experience of the workings of technology, and hacking.
Hacktivist A hacktivist is a hacker who utilizes technology to announce a social, ideological, religious, or political message. In general, most hacktivism involves website defacement or denial-of-service attacks.
The following reference(s) were/was used to create this question:
2 011. EC-COUNCIL Official Curriculum, Ethical Hacking and Countermeasures, v7.1,
Module 1, Page. 15.
and
https://en.wikipedia.org/wiki/Hacker_%28computer_security%29
The term "Hacker" originally meant a Unix computer enthusiast but has been villainized in the media as a "Criminal Hacker" for a mass audience. A hacker used to be known as a good person who would add functionality within software or would make things work better.
To most people today "Hacker" means criminal "Criminal Cracker", it is synonymous with
Cracker or someone who get access to a system without the owner authorization.
As seen in news reports in 2011 and later hackers associated with the "Anonymous" movement have attacked finance and/or credit card companies, stolen enough information to make contributions to worthy charities on behalf of organizations they see as contrary to the public good. These sorts of attackers/hackers could be considered suicide hackers.
Some did get caught and prosecuted while carrying out their cause. Nobody can know if they knew their activities would land them in court and/or prison but they had to have known of the risk and proceeded anyway.
The following answers are incorrect:
Black Hat hackers are also known as crackers and are merely hackers who "violates computer security for little reason beyond maliciousness or for personal gain". Black Hat
Hackers are "the epitome of all that the public fears in a computer criminal". Black Hat
Hackers break into secure networks to destroy data or make the network unusable for those who are authorized to use the network.
White Hat Hackers are law-abiding, reputable experts defending assets and not breaking laws. A white hat hacker breaks security for non-malicious reasons, for instance testing their own security system. The term "white hat" in Internet slang refers to an ethical hacker.
This classification also includes individuals who perform penetration tests and vulnerability assessments within a contractual agreement. Often, this type of 'white hat' hacker is called an ethical hacker. The International Council of Electronic Commerce Consultants, also known as the EC-Council has developed certifications, courseware, classes, and online training covering the diverse arena of Ethical Hacking.
Note about White Hat: As reported by Adin Kerimov, a white hat would not be worried about going to jail as he is doing a test with authorization as well and he has a signed agreement. While this is a true point he BEST choice is Suicide Hackers for the purpose of the exam, a white hat hacker would not disregard law and the autority. .
Gray Hat Hackers work both offensively and defensively and can cross the border between legal/ethical behavior and illegal/unethical behavior. A grey hat hacker is a combination of a
Black Hat and a White Hat Hacker. A Grey Hat Hacker may surf the internet and hack into a computer system for the sole purpose of notifying the administrator that their system has been hacked, for example. Then they may offer to repair their system for a small fee.
OTHER TYPES OF HACKERS
Elite hacker is a social status among hackers, elite is used to describe the most skilled.
Newly discovered exploits will circulate among these hackers. Elite groups such as Masters of Deception conferred a kind of credibility on their members.
Script kiddie A script kiddie(or skiddie) is a non-expert who breaks into computer systems by using pre-packaged automated tools written by others, usually with little understanding of the underlying concept-hence the term script (i.e. a prearranged plan or set of activities) kiddie (i.e. kid, child-an individual lacking knowledge and experience, immature). Often time they do not even understand how they are taken advantage of the system, they do not underrstand the weakness being exploited, all they know is how to use a tool that somone else has built.
Neophyte A neophyte, "n00b", or "newbie" is someone who is new to hacking or phreaking and has almost no knowledge or experience of the workings of technology, and hacking.
Hacktivist A hacktivist is a hacker who utilizes technology to announce a social, ideological, religious, or political message. In general, most hacktivism involves website defacement or denial-of-service attacks.
The following reference(s) were/was used to create this question:
2 011. EC-COUNCIL Official Curriculum, Ethical Hacking and Countermeasures, v7.1,
Module 1, Page. 15.
and
https://en.wikipedia.org/wiki/Hacker_%28computer_security%29
CISSP Exam Question 188
If traveling abroad and a customs official demands to examine a personal computer, which of the following should be assumed?
Correct Answer: C
If traveling abroad and a customs official demands to examine a personal computer, the most reasonable assumption is that the hard drive has been copied. The hard drive is the component of the computer that stores the data and the operating system, and it can be easily copied or cloned by using a device or a software. The customs official may copy the hard drive to inspect its contents, to search for illegal or suspicious data, or to obtain sensitive or valuable data. The hard drive may not be stolen, as the customs official may return the computer to the owner after the examination. The Internet Protocol (IP) address may not be copied, as the IP address is not a fixed or permanent attribute of the computer, but rather a dynamic and temporary identifier that is assigned by the network. The Media Access Control (MAC) address may not be stolen, as the MAC address is a unique and permanent identifier that is embedded in the network interface card (NIC) of the computer, and it cannot be easily changed or modified.
CISSP Exam Question 189
Which of the following is the MOST effective preventative method to identify security flaws in software?
Correct Answer: B
The most effective preventative method to identify security flaws in software is to perform a structured code review. A security flaw is a defect or weakness in the software that can compromise or affect the security of the software, such as the confidentiality, integrity, availability, or accountability of the software, or the data or information that is processed or stored by the software. A security flaw can also expose the software to various security threats or risks, such as unauthorized access, data leakage, or malware infection. A security flaw can be identified or detected by using various methods or techniques, such as testing, scanning, or auditing, that can analyze or evaluate the software for any security vulnerabilities, weaknesses, or flaws. A structured code review is a method or technique that can be used to identify security flaws in software. A structured code review is a process that involves the systematic and comprehensive examination or inspection of the source code or the program code of the software, by the developers, testers, or reviewers, to identify or detect any errors, bugs, or flaws in the code, that may affect the functionality, performance, or security of the software. A structured code review can help to identify security flaws in software, by using various methods or techniques, such as manual review, automated review, or peer review, that can check or verify the quality, accuracy, or compliance of the code, as well as by using various tools or standards, such as code analyzers, code checkers, or code guidelines, that can assist or support the code review process. A structured code review can also help to prevent security flaws in software, by identifying or detecting the security flaws in the early stages of the software development life cycle, such as the design, development, or implementation phases, rather than in the later stages of the software development life cycle, such as the testing, deployment, or maintenance phases, and by allowing the correction or remediation of the security flaws before they become more costly, complex, or critical. Monitoring performance in production environments, performing application penetration testing, or using automated security
CISSP Exam Question 190
What do the ILOVEYOU and Melissa virus attacks have in common?
Correct Answer: C
Explanation/Reference:
Explanation:
While a masquerading attack can be considered a type of social engineering, the Melissa and ILOVEYOU viruses are examples of masquerading attacks, even if it may cause some kind of denial of service due to the web server being flooded with messages. In this case, the receiver confidently opens a message coming from a trusted individual, only to find that the message was sent using the trusted party's identity.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw- Hill/Osborne,2002, Chapter 10:
Law, Investigation, and Ethics (page 650).
Explanation:
While a masquerading attack can be considered a type of social engineering, the Melissa and ILOVEYOU viruses are examples of masquerading attacks, even if it may cause some kind of denial of service due to the web server being flooded with messages. In this case, the receiver confidently opens a message coming from a trusted individual, only to find that the message was sent using the trusted party's identity.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw- Hill/Osborne,2002, Chapter 10:
Law, Investigation, and Ethics (page 650).
- Other Version
- 4678ISC.CISSP.v2026-05-11.q720
- 12804ISC.CISSP.v2024-12-24.q999
- 63ISC.Braindumpspass.CISSP.v2022-04-14.by.egbert.619q.pdf
- 11813ISC.CISSP.v2022-02-09.q619
- 10644ISC.CISSP.v2021-08-21.q483
- Latest Upload
- 105CIRO.CIRE.v2026-10-10.q55
- 105Cisco.200-301.v2026-10-10.q516
- 105Oracle.1Z0-1170.v2026-10-10.q78
- 106Salesforce.Rev-Con-201.v2026-10-10.q96
- 183Google.Professional-Machine-Learning-Engineer.v2026-10-09.q179
- 143HP.HPE7-V01.v2026-10-09.q25
- 155Google.Professional-Cloud-Network-Engineer.v2026-10-09.q135
- 163Salesforce.Sales-Con-201.v2026-10-08.q104
- 168ACAMS.CAMS.v2026-10-08.q94
- 174CheckPoint.156-315.82.v2026-10-07.q59
