Information Security

231. What is the most effective countermeasure against script injection attacks?

  1. Stateful inspection firewall
  2. Disallow server-side scripting in the end user's browser configuration
  3. Filter scripting characters in all input fields
  4. Disallow client-side scripting in the end user's browser configuration

Correct answer: (C)
Filter scripting characters in all input fields

232. What is the purpose of the Software Engineering Institute Capability Maturity Model Integration (SEI CMMI)?

  1. Objective assessment of the integrity of an organization's application programs
  2. Objective assessment of an organization's systems engineering processes
  3. Objective assessment of an organization's business processes
  4. Subjective assessment of an organization's systems engineering processes

Correct answer: (B)
Objective assessment of an organization's systems engineering processes

233. When an information system authenticates a user based on "what the user is," this refers to the use of:

  1. Authorization based upon the user's job title
  2. Role-based authentication
  3. Two-factor authentication
  4. Biometric authentication

Correct answer: (D)
Biometric authentication

234. Where is firmware primarily stored on a computer system?

  1. Trusted Platform Module
  2. Read-only memory
  3. Master boot record
  4. File system

Correct answer: (B)
Read-only memory

235. Which is the best approach for two parties who wish to establish a means for confirming the confidentiality and integrity of messages that they exchange:

  1. Digital signatures
  2. Encryption and digital signatures
  3. Key exchange
  4. Encryption

Correct answer: (B)
Encryption and digital signatures

236. Which of the following is NOT a deterrent control:

  1. Monitors showing video surveillance
  2. Guard dogs
  3. Surveillance notices
  4. Mantrap

Correct answer: (D)
Mantrap

237. Which of the following is NOT a risk associated with remote access:

  1. Risk associated with sensitive information is stored on a non- company-owned computer, out of the organization's control
  2. A non-company-owned computer with inadequate anti-malware protection can introduce an infection through remote access
  3. Anti-virus software on the remote computer will not be able to download virus definition updates
  4. If a split tunnel is used, the remote computer may be more vulnerable to attack

Correct answer: (C)
Anti-virus software on the remote computer will not be able to download virus definition updates

238. Which of the following is NOT an authentication protocol:

  1. Lightweight Directory Authentication Protocol
  2. Diameter
  3. RADIUS
  4. Lightweight Directory Access Protocol

Correct answer: (A)
Lightweight Directory Authentication Protocol

239. Which of the following statements about Crossover Error Rate (CER) is true:

  1. This is the point where the False Accept Rate falls below 50%
  2. This is the point where the False Reject Rate falls below 50%
  3. This is the point where False Reject Rate and False Accept Rate add to 100%
  4. This is the point where False Reject Rate and False Accept Rate are equal

Correct answer: (D)
This is the point where False Reject Rate and False Accept Rate are equal

240. Which of the following statements about Ethernet MAC addresses is TRUE:

  1. The MAC address is assigned using the DHCP protocol
  2. The first 3 bits designates the manufacturer of the device
  3. The first 3 bytes designates the manufacturer of the device
  4. The last 3 bytes designates the manufacturer of the device

Correct answer: (C)
The first 3 bytes designates the manufacturer of the device

Page 24 of 25