Isc

CSSLP practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 43-question bank.

Provider
Isc
Question bank
43
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CSSLP, a certification listed under Isc. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isc. The certification credential is issued by Isc, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following models uses a directed graph to specify the rights that a subject can transfer to an object or that a subject can take from another subject?

    Choose one answer.

    • Take-Grant Protection Model
    • Biba Integrity Model
    • Bell-LaPadula Model
    • Access Matrix
  2. Question 2 · 1

    You are the project manager for GHY Project and are working to create a risk response for a negative risk. You and the project team have identified the risk that the project may not complete on time, as required by the management, due to the creation of the user guide for the software you're creating. You have elected to hire an external writer in order to satisfy the requirements and to alleviate the risk event. What type of risk response have you elected to use in this instance?

    Choose one answer.

    • Transference
    • Exploiting
    • Avoidance
    • Sharing
  3. Question 3 · 1

    Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one?

    Choose one answer.

    • Configuration Identification
    • Configuration Verification and Auditing
    • Configuration Status Accounting
    • Configuration Item Costing
    Read explanation

    Configuration item cost is not a valid activity for configuration management. Cost changes are managed by the cost change control system; configuration management is concerned with changes to the features and functions of the project deliverables.

  4. Question 4 · 1

    Which of the following types of redundancy prevents attacks in which an attacker can get physical control of a machine, insert unauthorized software, and alter data?

    Choose one answer.

    • Data redundancy
    • Hardware redundancy
    • Process redundancy
    • Application redundancy
    Read explanation

    Process redundancy permits software to run simultaneously on multiple geographically distributed locations, with voting on results. It prevents attacks in which an attacker can get physical control of a machine, insert unauthorized software, and alter data.

  5. Question 5 · 1

    Which of the following individuals inspects whether the security policies, standards, guidelines, and procedures are efficiently performed in accordance with the company's stated security objectives?

    Choose one answer.

    • Information system security professional
    • Data owner
    • Senior management
    • Information system auditor
  6. Question 6 · 1

    Which of the following process areas does the SSE-CMM define in the 'Project and Organizational Practices' category? Each correct answer represents a complete solution. Choose all that apply.

    Choose all answers that apply.

    • Provide Ongoing Skills and Knowledge
    • Verify and Validate Security
    • Manage Project Risk
    • Improve Organization's System Engineering Process
    Read explanation

    Project and Organizational Practices include the following process areas: PA12: Ensure Quality PA13: Manage Configuration PA14: Manage Project Risk PA15: Monitor and Control Technical Effort PA16: Plan Technical Effort PA17: Define Organization's System Engineering Process PA18: Improve Organization's System Engineering Process PA19: Manage Product Line Evolution PA20: Manage Systems Engineering Support Environment PA21: Provide Ongoing Skills and Knowledge PA22: Coordinate with Suppliers

  7. Question 7 · 1

    The LeGrand Vulnerability-Oriented Risk Management method is based on vulnerability analysis and consists of four principle steps. Which of the following processes does the risk assessment step include? Each correct answer represents a part of the solution. Choose all that apply.

    Choose all answers that apply.

    • Remediation of a particular vulnerability
    • Cost-benefit examination of countermeasures
    • Identification of vulnerabilities
    • Assessment of attacks
  8. Question 8 · 1

    The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE? Each correct answer represents a complete solution. Choose all that apply.

    Choose all answers that apply.

    • An ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).
    • An ISSE provides advice on the continuous monitoring of the information system.
    • An ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A).
    • An ISSE provides advice on the impacts of system changes. E. An ISSO takes part in the development activities that are required to implement system
    Read explanation

    An Information System Security Officer (ISSO) plays the role of a supporter. The responsibilities of an Information System Security Officer (ISSO) are as follows: Manages the security of the information system that is slated for Certification & Accreditation (C&A). Insures the information systems configuration with the agency's information security policy. Supports the information system owner/information owner for the completion of security-related responsibilities. Takes part in the formal configuration management process. Prepares Certification & Accreditation (C&A) packages. An Information System Security Engineer (ISSE) plays the role of an advisor. The responsibilities of an Information System Security Engineer are as follows: Provides view on the continuous monitoring of the information system. Provides advice on the impacts of system changes. Takes part in the configuration management process. Takes part in the development activities that are required to implement system changes. Follows approved system changes.

  9. Question 9 · 1

    In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?

    Choose one answer.

    • Full operational test
    • Penetration test
    • Paper test
    • Walk-through test
  10. Question 10 · 1

    You work as a systems engineer for BlueWell Inc. Which of the following tools will you use to look outside your own organization to examine how others achieve their performance levels, and what processes they use to reach those levels?

    Choose one answer.

    • Benchmarking
    • Six Sigma
    • ISO 9001:2000
    • SEI-CMM
  11. Question 11 · 1

    FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?

    Choose one answer.

    • Level 2
    • Level 3
    • Level 5
    • Level 1
    • Level 4
  12. Question 12 · 1

    You work as the senior project manager in SoftTech Inc. You are working on a software project using configuration management. Through configuration management you are decomposing the verification system into identifiable, understandable, manageable, traceable units that are known as Configuration Items (CIs). According to you, which of the following processes is known as the decomposition process of a verification system into Configuration Items?

    Choose one answer.

    • Configuration status accounting
    • Configuration identification
    • Configuration auditing
    • Configuration control
  13. Question 13 · 1

    Bill is the project manager of the JKH Project. He and the project team have identified a risk event in the project with a high probability of occurrence and the risk event has a high cost impact on the project. Bill discusses the risk event with Virginia, the primary project customer, and she decides that the requirements surrounding the risk event should be removed from the project. The removal of the requirements does affect the project scope, but it can release the project from the high risk exposure. What risk response has been enacted in this project?

    Choose one answer.

    • Mitigation
    • Transference
    • Acceptance
    • Avoidance
  14. Question 14 · 1

    Martha registers a domain named Microsoft.in. She tries to sell it to Microsoft Corporation. The infringement of which of the following has she made?

    Choose one answer.

    • Copyright
    • Trademark
    • Patent
    • Intellectual property
    Read explanation

    According to the Lanham Act, domain names fall under trademarks law. A new section 43(d) of the Trademark Act (Lanham Act) states that anyone who in bad faith registers, traffics in, or uses a domain name that infringes or dilutes another's trademark has committed trademark infringement. Factors involved in assessing bad faith focus on activities typically associated with cyberpiracy or cybersquatting, such as whether the registrant has offered to sell the domain name to the trademark holder for financial gain without having used or intended to use it for a bona fide business; whether the domain-name registrant registered multiple domain names that are confusingly similar to the trademarks of others; and whether the trademark incorporated in the domain name is distinctive and famous. Other factors are whether the domain name consists of the legal name or common handle of the domain-name registrant and whether the domain-name registrant previously used the mark in connection with a bona fide business.

  15. Question 15 · 1

    Which of the following roles is also known as the accreditor?

    Choose one answer.

    • Data owner
    • Chief Risk Officer
    • Chief Information Officer
    • Designated Approving Authority

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free