{"id":523,"date":"2023-02-11T12:41:25","date_gmt":"2023-02-11T12:41:25","guid":{"rendered":"https:\/\/exam.real4prep.com\/?p=523"},"modified":"2023-02-11T12:41:25","modified_gmt":"2023-02-11T12:41:25","slug":"csslp-free-exam-questions-answers-pdf-updated-on-feb-2023-q18-q32","status":"publish","type":"post","link":"https:\/\/exam.real4prep.com\/zh\/2023\/02\/11\/csslp-free-exam-questions-answers-pdf-updated-on-feb-2023-q18-q32\/","title":{"rendered":"CSSLP Free Exam Questions &amp; Answers PDF Updated on Feb-2023 [Q18-Q32]"},"content":{"rendered":"\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-top\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;523&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;top&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;3&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;4.7&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;Rate this post&quot;,&quot;legend&quot;:&quot;4.7\\\/5 - (3 votes)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;CSSLP Free Exam Questions \\u0026amp; Answers PDF Updated on Feb-2023 [Q18-Q32]&quot;,&quot;width&quot;:&quot;133.8&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 133.8px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 19.2px;\">\n            4.7\/5 - (3 votes)    <\/div>\n    <\/div>\n<p><span style=\"font-size: 18px\"><strong><span style=\"color: red\">CSSLP Free Exam Questions and Answers PDF Updated on Feb-2023<\/span><\/strong><\/span><\/p>\n<p><strong><span style=\"color: red\">Latest CSSLP Exam Dumps Recently Updated 349 Questions<\/span><\/strong><\/p>\n<p><\/p>\n<h3>Secure Software Lifecycle Management (11%):<\/h3>\n<ul>\n<li>Promote software development\u2019s security culture.<\/li>\n<li>Integrate IRM (Integrated Risk Management);<\/li>\n<li>Explain and develop security documentation;<\/li>\n<li>Establish the standards and frameworks for security;<\/li>\n<li>Explain roadmap and strategy;<\/li>\n<\/ul>\n<p><\/p>\n<h3>Secure Software Testing (14%):<\/h3>\n<ul>\n<li>Secure test data;<\/li>\n<li>Track and classify security errors;<\/li>\n<li>Carry out verification &amp; validation testing.<\/li>\n<li>Validate documentations;<\/li>\n<li>Establish security test cases;<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<div id=\"watu_quiz\" class=\"quiz-area single-page-quiz\">\n<form action=\"\" method=\"post\" class=\"quiz-form \" id=\"quiz-208\" >\n<div class='watu-question' id='question-1'><div class='question-content'><p><strong>QUESTION 18<\/strong><br \/>Which of the following attacks causes software to fail and prevents the intended users from accessing software?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4056' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15727' \/><div class='watu-question-choice'><input type='radio' name='answer-4056[]' id='answer-id-15727' class='answer answer-1 js-answer-label answerof-4056' value='15727' \/>&nbsp;<label for='answer-id-15727' id='answer-label-15727' class='js-answer-label answer label-1'><span class='answer'>Enabling attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15728' \/><div class='watu-question-choice'><input type='radio' name='answer-4056[]' id='answer-id-15728' class='answer answer-1 js-answer-label answerof-4056' value='15728' \/>&nbsp;<label for='answer-id-15728' id='answer-label-15728' class='js-answer-label answer label-1'><span class='answer'>Reconnaissance attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15729' \/><div class='watu-question-choice'><input type='radio' name='answer-4056[]' id='answer-id-15729' class='answer answer-1 php-answer-label answerof-4056' value='15729' \/>&nbsp;<label for='answer-id-15729' id='answer-label-15729' class='php-answer-label answer label-1'><span class='answer'>Sabotage attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15730' \/><div class='watu-question-choice'><input type='radio' name='answer-4056[]' id='answer-id-15730' class='answer answer-1 js-answer-label answerof-4056' value='15730' \/>&nbsp;<label for='answer-id-15730' id='answer-label-15730' class='js-answer-label answer label-1'><span class='answer'>Disclosure attack<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>A sabotage attack is an attack that causes software to fail. It also prevents the intended users from accessing software. A sabotage attack is referred to as a denial of service (DoS) or compromise of availability. Answer B is incorrect. The reconnaissance attack enables an attacker to collect information about software and operating environment. Answer D is incorrect. The disclosure attack exposes the revealed data to an attacker. Answer A is incorrect. The enabling attack delivers an easy path for other attacks.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(1,this)' id='btn-1' value='See Answer'  \/><input type='hidden' id='questionType1' value='radio' class=''><\/div><div class='watu-question' id='question-2'><div class='question-content'><p><strong>QUESTION 19<\/strong><br \/>Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4057' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15731' \/><div class='watu-question-choice'><input type='radio' name='answer-4057[]' id='answer-id-15731' class='answer answer-2 php-answer-label answerof-4057' value='15731' \/>&nbsp;<label for='answer-id-15731' id='answer-label-15731' class='php-answer-label answer label-2'><span class='answer'>DIACAP<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15732' \/><div class='watu-question-choice'><input type='radio' name='answer-4057[]' id='answer-id-15732' class='answer answer-2 js-answer-label answerof-4057' value='15732' \/>&nbsp;<label for='answer-id-15732' id='answer-label-15732' class='js-answer-label answer label-2'><span class='answer'>SSAA<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15733' \/><div class='watu-question-choice'><input type='radio' name='answer-4057[]' id='answer-id-15733' class='answer answer-2 js-answer-label answerof-4057' value='15733' \/>&nbsp;<label for='answer-id-15733' id='answer-label-15733' class='js-answer-label answer label-2'><span class='answer'>DAA<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15734' \/><div class='watu-question-choice'><input type='radio' name='answer-4057[]' id='answer-id-15734' class='answer answer-2 js-answer-label answerof-4057' value='15734' \/>&nbsp;<label for='answer-id-15734' id='answer-label-15734' class='js-answer-label answer label-2'><span class='answer'>ISSO<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>DIACAP describes a residual risk as the risk remaining after a risk mitigation has occurred. The Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) is a process defined by the United States Department of Defense (DoD) for managing risk. DIACAP replaced the former process, known as DITSCAP (Department of Defense Information Technology Security Certification and Accreditation Process), in 2006. DoD Instruction (DoDI) 8510.01 establishes a standard DoD-wide process with a set of activities, general tasks, and a management structure to certify and accredit an Automated Information System (AIS) that will maintain the Information Assurance (IA) posture of the Defense Information Infrastructure (DII) throughout the system&#8217;s life cycle.DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. It identifies four phases: 1.System Definition 2.Verification 3.Validation 4.Re-Accreditation Answer D is incorrect. An Information System Security Officer (ISSO) plays the role of a supporter. The responsibilities of an Information System Security Officer (ISSO) are as follows: Manages the security of the information system that is slated for Certification &amp; Accreditation (C&amp;A). Insures the information systems configuration with the agency&#8217;s information security policy. Supports the information system owner\/information owner for the completion of security-related responsibilities. Takes part in the formal configuration management process. Prepares Certification &amp; Accreditation (C&amp;A) packages. Answer C is incorrect. The Designated Approving Authority (DAA), in the United States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. The DAA is responsible for implementing system security. The DAA can grant the accreditation and can determine that the system&#8217;s risks are not at an acceptable level and the system is not ready to be operational. Answer B is incorrect. System Security Authorization Agreement (SSAA) is an information security document used in the United States Department of Defense (DoD) to describe and accredit networks and systems. The SSAA is part of the Department of Defense Information Technology Security Certification and Accreditation Process, or DITSCAP (superseded by DIACAP). The DoD instruction (issues in December 1997, that describes DITSCAP and provides an outline for the SSAA document is DODI 5200.40. The DITSCAP application manual (DoD 8510.1-M), published in July 2000, provides additional details.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(2,this)' id='btn-2' value='See Answer'  \/><input type='hidden' id='questionType2' value='radio' class=''><\/div><div class='watu-question' id='question-3'><div class='question-content'><p><strong>QUESTION 20<\/strong><br \/>In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4058' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15735' \/><div class='watu-question-choice'><input type='radio' name='answer-4058[]' id='answer-id-15735' class='answer answer-3 js-answer-label answerof-4058' value='15735' \/>&nbsp;<label for='answer-id-15735' id='answer-label-15735' class='js-answer-label answer label-3'><span class='answer'>Full operational test<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15736' \/><div class='watu-question-choice'><input type='radio' name='answer-4058[]' id='answer-id-15736' class='answer answer-3 php-answer-label answerof-4058' value='15736' \/>&nbsp;<label for='answer-id-15736' id='answer-label-15736' class='php-answer-label answer label-3'><span class='answer'>Penetration test<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15737' \/><div class='watu-question-choice'><input type='radio' name='answer-4058[]' id='answer-id-15737' class='answer answer-3 js-answer-label answerof-4058' value='15737' \/>&nbsp;<label for='answer-id-15737' id='answer-label-15737' class='js-answer-label answer label-3'><span class='answer'>Paper test<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15738' \/><div class='watu-question-choice'><input type='radio' name='answer-4058[]' id='answer-id-15738' class='answer answer-3 js-answer-label answerof-4058' value='15738' \/>&nbsp;<label for='answer-id-15738' id='answer-label-15738' class='js-answer-label answer label-3'><span class='answer'>Walk-through test<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: A penetration testing is a method of evaluating the security of a computer system or network by simulating an attack from a malicious source. The process involves an active analysis of the system for any potential vulnerabilities that may result from poor or improper system configuration, known or unknown hardware or software flaws, or operational weaknesses in process or technical countermeasures. This analysis is carried out from the position of a potential attacker, and can involve active exploitation of security vulnerabilities. Any security issues that are found will be presented to the system owner together with an assessment of their impact and often with a proposal for mitigation or a technical solution. The intent of a penetration test is to determine feasibility of an attack and the amount of business impact of a successful exploit, if discovered. It is a component of a full security audit. Answer: C is incorrect. A paper test is the least complex test in the disaster recovery and business continuity testing approaches. In this test, the BCP\/DRP plan documents are distributed to the appropriate managers and BCP\/DRP team members for review, markup, and comment. This approach helps the auditor to ensure that the plan is complete and that all team members are familiar with their responsibilities within the plan. Answer: D is incorrect. A walk-through test is an extension of the paper testing in the business continuity and disaster recovery process. In this testing methodology, appropriate managers and BCP\/DRP team members discuss and walk through procedures of the plan. They also discuss the training needs, and clarification of critical plan elements. Answer: A is incorrect. A full operational test includes all team members and participants in the disaster recovery and business continuity process. This full operation test involves the mobilization of personnel. It restores operations in the same manner as an outage or disaster would. The full operational test extends the preparedness test by including actual notification, mobilization of resources, processing of data, and utilization of backup media for restoration.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(3,this)' id='btn-3' value='See Answer'  \/><input type='hidden' id='questionType3' value='radio' class=''><\/div><div class='watu-question' id='question-4'><div class='question-content'><p><strong>QUESTION 21<\/strong><br \/>The organization level is the Tier 1 and it addresses risks from an organizational perspective. What are the various Tier 1 activities? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4059' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15739' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4059[]' id='answer-id-15739' class='answer answer-4 php-answer-label answerof-4059' value='15739' \/>&nbsp;<label for='answer-id-15739' id='answer-label-15739' class='php-answer-label answer label-4'><span class='answer'>The organization plans to use the degree and type of oversight, to ensure that the risk management strategy is being effectively carried out.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15740' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4059[]' id='answer-id-15740' class='answer answer-4 php-answer-label answerof-4059' value='15740' \/>&nbsp;<label for='answer-id-15740' id='answer-label-15740' class='php-answer-label answer label-4'><span class='answer'>The level of risk tolerance.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15741' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4059[]' id='answer-id-15741' class='answer answer-4 php-answer-label answerof-4059' value='15741' \/>&nbsp;<label for='answer-id-15741' id='answer-label-15741' class='php-answer-label answer label-4'><span class='answer'>The techniques and methodologies an organization plans to employ, to evaluate information system- related security risks.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15742' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4059[]' id='answer-id-15742' class='answer answer-4 js-answer-label answerof-4059' value='15742' \/>&nbsp;<label for='answer-id-15742' id='answer-label-15742' class='js-answer-label answer label-4'><span class='answer'>The RMF primarily operates at Tier 1.<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The Organization Level is the Tier 1, and it addresses risks from an organizational perspective. It includes the following points: The techniques and methodologies an organization plans to employ, to evaluate information system-related security risks. During risk assessment, the methods and procedures the organization plans to use, to evaluate the significance of the risks identified. The types and extent of risk mitigation measures the organization plans to employ, to address identified risks. The level of risk tolerance. According to the environment of operation, how the organization plans to monitor risks on an ongoing basis, given the inevitable changes to organizational information system.<br\/>The organization plans to use the degree and type of oversight, in order to ensure that the risk management strategy is being effectively carried out.Answer: D is incorrect. The RMF primarily operates at Tier 3.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(4,this)' id='btn-4' value='See Answer'  \/><input type='hidden' id='questionType4' value='checkbox' class=''><\/div><div class='watu-question' id='question-5'><div class='question-content'><p><strong>QUESTION 22<\/strong><br \/>Which of the following approaches can be used to build a security program? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4060' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15743' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4060[]' id='answer-id-15743' class='answer answer-5 js-answer-label answerof-4060' value='15743' \/>&nbsp;<label for='answer-id-15743' id='answer-label-15743' class='js-answer-label answer label-5'><span class='answer'>Right-Up Approach<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15744' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4060[]' id='answer-id-15744' class='answer answer-5 js-answer-label answerof-4060' value='15744' \/>&nbsp;<label for='answer-id-15744' id='answer-label-15744' class='js-answer-label answer label-5'><span class='answer'>Left-Up Approach<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15745' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4060[]' id='answer-id-15745' class='answer answer-5 php-answer-label answerof-4060' value='15745' \/>&nbsp;<label for='answer-id-15745' id='answer-label-15745' class='php-answer-label answer label-5'><span class='answer'>Top-Down Approach<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15746' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4060[]' id='answer-id-15746' class='answer answer-5 php-answer-label answerof-4060' value='15746' \/>&nbsp;<label for='answer-id-15746' id='answer-label-15746' class='php-answer-label answer label-5'><span class='answer'>Bottom-Up Approach<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Top-Down Approach is an approach to build a security program. The initiation, support, and direction come from the top management and work their way through middle management and then to staff members. It is treated as the best approach. This approach ensures that the senior management, who is ultimately responsible for protecting the company assets, is driving the program. Bottom-Up Approach is an approach to build a security program. The lower-end team comes up with a security control or a program without proper management support and direction. It is less effective and doomed to fail. Answer:<br\/>A and B are incorrect. No such types of approaches exist<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(5,this)' id='btn-5' value='See Answer'  \/><input type='hidden' id='questionType5' value='checkbox' class=''><\/div><div class='watu-question' id='question-6'><div class='question-content'><p><strong>QUESTION 23<\/strong><br \/>Which of the following types of attacks is targeting a Web server with multiple compromised computers that are simultaneously sending hundreds of FIN packets with spoofed IP source IP addresses?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4061' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15747' \/><div class='watu-question-choice'><input type='radio' name='answer-4061[]' id='answer-id-15747' class='answer answer-6 php-answer-label answerof-4061' value='15747' \/>&nbsp;<label for='answer-id-15747' id='answer-label-15747' class='php-answer-label answer label-6'><span class='answer'>DDoS attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15748' \/><div class='watu-question-choice'><input type='radio' name='answer-4061[]' id='answer-id-15748' class='answer answer-6 js-answer-label answerof-4061' value='15748' \/>&nbsp;<label for='answer-id-15748' id='answer-label-15748' class='js-answer-label answer label-6'><span class='answer'>Evasion attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15749' \/><div class='watu-question-choice'><input type='radio' name='answer-4061[]' id='answer-id-15749' class='answer answer-6 js-answer-label answerof-4061' value='15749' \/>&nbsp;<label for='answer-id-15749' id='answer-label-15749' class='js-answer-label answer label-6'><span class='answer'>Insertion attack<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15750' \/><div class='watu-question-choice'><input type='radio' name='answer-4061[]' id='answer-id-15750' class='answer answer-6 js-answer-label answerof-4061' value='15750' \/>&nbsp;<label for='answer-id-15750' id='answer-label-15750' class='js-answer-label answer label-6'><span class='answer'>Dictionary attack<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: A distributed denial of service (DDoS) attack targets a Web server with multiple compromised computers that are simultaneously sending hundreds of FIN packets with spoofed IP source IP addresses.<br\/>DDoS attack occurs when multiple compromised systems flood the bandwidth or resources of a targeted system, usually one or more Web servers. These systems are compromised by attackers using a variety of methods. It is an attempt to make a computer resource unavailable to its intended users. This type of attack can cause the following to occur: Saturate network resources. Disrupt connections between two computers, thereby preventing communications between services. Disrupt services on a specific computer.<br\/>AnswerD is incorrect. Dictionary attack is a type of password guessing attack. This type of attack uses a<br\/>dictionary of common words to find out the password of a user. It can also use common words in either upper or lower case to find a password. There are many programs available on the Internet to automate and execute dictionary attacks. AnswerC is incorrect. In an insertion attack, an IDS accepts a packet and assumes that the host computer will also accept it. But in reality, when a host system rejects the packet, the IDS accepts the attacking string that will exploit vulnerabilities in the IDS. Such attacks can badly infect IDS signatures and IDS signature analysis. Answer: B is incorrect. An evasion attack is one in which an IDS rejects a malicious packet but the host computer accepts it. Since an IDS has rejected it, it does not check the contents of the packet. Hence, using this technique, an attacker can exploit the host computer.<br\/>In many cases, it is quite simple for an attacker to send such data packets that can easily perform evasion attacks on an IDSs.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(6,this)' id='btn-6' value='See Answer'  \/><input type='hidden' id='questionType6' value='radio' class=''><\/div><div class='watu-question' id='question-7'><div class='question-content'><p><strong>QUESTION 24<\/strong><br \/>Which of the following types of redundancy prevents attacks in which an attacker can get physical control of a machine, insert unauthorized software, and alter data?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4062' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15751' \/><div class='watu-question-choice'><input type='radio' name='answer-4062[]' id='answer-id-15751' class='answer answer-7 js-answer-label answerof-4062' value='15751' \/>&nbsp;<label for='answer-id-15751' id='answer-label-15751' class='js-answer-label answer label-7'><span class='answer'>Data redundancy<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15752' \/><div class='watu-question-choice'><input type='radio' name='answer-4062[]' id='answer-id-15752' class='answer answer-7 js-answer-label answerof-4062' value='15752' \/>&nbsp;<label for='answer-id-15752' id='answer-label-15752' class='js-answer-label answer label-7'><span class='answer'>Hardware redundancy<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15753' \/><div class='watu-question-choice'><input type='radio' name='answer-4062[]' id='answer-id-15753' class='answer answer-7 php-answer-label answerof-4062' value='15753' \/>&nbsp;<label for='answer-id-15753' id='answer-label-15753' class='php-answer-label answer label-7'><span class='answer'>Process redundancy<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15754' \/><div class='watu-question-choice'><input type='radio' name='answer-4062[]' id='answer-id-15754' class='answer answer-7 js-answer-label answerof-4062' value='15754' \/>&nbsp;<label for='answer-id-15754' id='answer-label-15754' class='js-answer-label answer label-7'><span class='answer'>Application redundancy<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Process redundancy permits software to run simultaneously on multiple geographically distributed locations, with voting on results. It prevents attacks in which an attacker can get physical control of a machine, insert unauthorized software, and alter data.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(7,this)' id='btn-7' value='See Answer'  \/><input type='hidden' id='questionType7' value='radio' class=''><\/div><div class='watu-question' id='question-8'><div class='question-content'><p><strong>QUESTION 25<\/strong><br \/>What are the security advantages of virtualization, as described in the NIST Information Security and Privacy Advisory Board (ISPAB) paper &#8220;Perspectives on Cloud Computing and Standards&#8221;? Each correct answer represents a complete solution. Choose three.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4063' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15755' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4063[]' id='answer-id-15755' class='answer answer-8 php-answer-label answerof-4063' value='15755' \/>&nbsp;<label for='answer-id-15755' id='answer-label-15755' class='php-answer-label answer label-8'><span class='answer'>It increases capabilities for fault tolerant computing.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15756' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4063[]' id='answer-id-15756' class='answer answer-8 php-answer-label answerof-4063' value='15756' \/>&nbsp;<label for='answer-id-15756' id='answer-label-15756' class='php-answer-label answer label-8'><span class='answer'>It adds a layer of security for defense-in-depth.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15757' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4063[]' id='answer-id-15757' class='answer answer-8 php-answer-label answerof-4063' value='15757' \/>&nbsp;<label for='answer-id-15757' id='answer-label-15757' class='php-answer-label answer label-8'><span class='answer'>It decreases exposure of weak software.<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15758' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4063[]' id='answer-id-15758' class='answer answer-8 js-answer-label answerof-4063' value='15758' \/>&nbsp;<label for='answer-id-15758' id='answer-label-15758' class='js-answer-label answer label-8'><span class='answer'>It decreases configuration effort.<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The security advantages of virtualization are as follows: It adds a layer of security for defense- in-depth. It provides strong encapsulation of errors. It increases intrusion detection through introspection. It decreases exposure of weak software. It increases the flexibility for discovery. It increases capabilities for fault tolerant computing using rollback and snapshot features. AnswerD is incorrect. Virtualization increases configuration effort because of complexity of the virtualization layer and composite system.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(8,this)' id='btn-8' value='See Answer'  \/><input type='hidden' id='questionType8' value='checkbox' class=''><\/div><div class='watu-question' id='question-9'><div class='question-content'><p><strong>QUESTION 26<\/strong><br \/>The DoD 8500 policy series represents the Department&#8217;s information assurance strategy. Which of the following objectives are defined by the DoD 8500 series? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4064' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15759' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4064[]' id='answer-id-15759' class='answer answer-9 php-answer-label answerof-4064' value='15759' \/>&nbsp;<label for='answer-id-15759' id='answer-label-15759' class='php-answer-label answer label-9'><span class='answer'>Defending systems<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15760' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4064[]' id='answer-id-15760' class='answer answer-9 js-answer-label answerof-4064' value='15760' \/>&nbsp;<label for='answer-id-15760' id='answer-label-15760' class='js-answer-label answer label-9'><span class='answer'>Providing IA Certification and Accreditation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15761' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4064[]' id='answer-id-15761' class='answer answer-9 php-answer-label answerof-4064' value='15761' \/>&nbsp;<label for='answer-id-15761' id='answer-label-15761' class='php-answer-label answer label-9'><span class='answer'>Providing command and control and situational awareness<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15762' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4064[]' id='answer-id-15762' class='answer answer-9 php-answer-label answerof-4064' value='15762' \/>&nbsp;<label for='answer-id-15762' id='answer-label-15762' class='php-answer-label answer label-9'><span class='answer'>Protecting information<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The various objectives of the DoD 8500 series are as follows: Protecting information Defending systems Providing command and control and situational awareness Making sure that the information assurance is integrated into processes Increasing security awareness throughout the DoD&#8217;s workforce<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(9,this)' id='btn-9' value='See Answer'  \/><input type='hidden' id='questionType9' value='checkbox' class=''><\/div><div class='watu-question' id='question-10'><div class='question-content'><p><strong>QUESTION 27<\/strong><br \/>How can you calculate the Annualized Loss Expectancy (ALE) that may occur due to a threat?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4065' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15763' \/><div class='watu-question-choice'><input type='radio' name='answer-4065[]' id='answer-id-15763' class='answer answer-10 php-answer-label answerof-4065' value='15763' \/>&nbsp;<label for='answer-id-15763' id='answer-label-15763' class='php-answer-label answer label-10'><span class='answer'>Single Loss Expectancy (SLE) X Annualized Rate of Occurrence (ARO)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15764' \/><div class='watu-question-choice'><input type='radio' name='answer-4065[]' id='answer-id-15764' class='answer answer-10 js-answer-label answerof-4065' value='15764' \/>&nbsp;<label for='answer-id-15764' id='answer-label-15764' class='js-answer-label answer label-10'><span class='answer'>Single Loss Expectancy (SLE)\/ Exposure Factor (EF)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15765' \/><div class='watu-question-choice'><input type='radio' name='answer-4065[]' id='answer-id-15765' class='answer answer-10 js-answer-label answerof-4065' value='15765' \/>&nbsp;<label for='answer-id-15765' id='answer-label-15765' class='js-answer-label answer label-10'><span class='answer'>Asset Value X Exposure Factor (EF)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15766' \/><div class='watu-question-choice'><input type='radio' name='answer-4065[]' id='answer-id-15766' class='answer answer-10 js-answer-label answerof-4065' value='15766' \/>&nbsp;<label for='answer-id-15766' id='answer-label-15766' class='js-answer-label answer label-10'><span class='answer'>Exposure Factor (EF)\/Single Loss Expectancy (SLE)<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>The Annualized Loss Expectancy (ALE) that occurs due to a threat can be calculated by multiplying the Single Loss Expectancy (SLE) with the Annualized Rate of Occurrence (ARO). Annualized Loss Expectancy (ALE) = Single Loss Expectancy (SLE) X Annualized Rate of Occurrence (ARO) Annualized Rate of Occurrence (ARO) is a number that represents the estimated frequency in which a threat is expected to occur. It is calculated based upon the probability of the event occurring and the number of employees that could make that event occur. Single Loss Expectancy (SLE) is the value in dollars that is assigned to a single event. SLE can be calculated by the following formula: SLE = Asset Value ($) X Exposure Factor (EF) The Exposure Factor (EF) represents the % of assets loss caused by a threat. The EF is required to calculate Single Loss Expectancy (SLE).<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(10,this)' id='btn-10' value='See Answer'  \/><input type='hidden' id='questionType10' value='radio' class=''><\/div><div class='watu-question' id='question-11'><div class='question-content'><p><strong>QUESTION 28<\/strong><br \/>Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4066' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15767' \/><div class='watu-question-choice'><input type='radio' name='answer-4066[]' id='answer-id-15767' class='answer answer-11 js-answer-label answerof-4066' value='15767' \/>&nbsp;<label for='answer-id-15767' id='answer-label-15767' class='js-answer-label answer label-11'><span class='answer'>Security Test and Evaluation (ST&amp;E)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15768' \/><div class='watu-question-choice'><input type='radio' name='answer-4066[]' id='answer-id-15768' class='answer answer-11 php-answer-label answerof-4066' value='15768' \/>&nbsp;<label for='answer-id-15768' id='answer-label-15768' class='php-answer-label answer label-11'><span class='answer'>Penetration testing<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15769' \/><div class='watu-question-choice'><input type='radio' name='answer-4066[]' id='answer-id-15769' class='answer answer-11 js-answer-label answerof-4066' value='15769' \/>&nbsp;<label for='answer-id-15769' id='answer-label-15769' class='js-answer-label answer label-11'><span class='answer'>Automated vulnerability scanning tool<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15770' \/><div class='watu-question-choice'><input type='radio' name='answer-4066[]' id='answer-id-15770' class='answer answer-11 js-answer-label answerof-4066' value='15770' \/>&nbsp;<label for='answer-id-15770' id='answer-label-15770' class='js-answer-label answer label-11'><span class='answer'>On-site interviews<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>The goal of penetration testing is to examine the IT system from the perspective of a threat-source, and to identify potential failures in the IT system protection schemes. Penetration testing, when performed in the risk assessment process, is used to assess an IT system&#8217;s capability to survive with the intended attempts to thwart system security. Answer A is incorrect. The objective of ST&amp;E is to ensure that the applied controls meet the approved security specification for the software and hardware and implement the organization&#8217;s security policy or meet industry standards.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(11,this)' id='btn-11' value='See Answer'  \/><input type='hidden' id='questionType11' value='radio' class=''><\/div><div class='watu-question' id='question-12'><div class='question-content'><p><strong>QUESTION 29<\/strong><br \/>Which of the following are included in Technical Controls? Each correct answer represents a complete solution. Choose all that apply.<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4067' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15771' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15771' class='answer answer-12 php-answer-label answerof-4067' value='15771' \/>&nbsp;<label for='answer-id-15771' id='answer-label-15771' class='php-answer-label answer label-12'><span class='answer'>Identification and authentication methods<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15772' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15772' class='answer answer-12 php-answer-label answerof-4067' value='15772' \/>&nbsp;<label for='answer-id-15772' id='answer-label-15772' class='php-answer-label answer label-12'><span class='answer'>Configuration of the infrastructure<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15773' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15773' class='answer answer-12 php-answer-label answerof-4067' value='15773' \/>&nbsp;<label for='answer-id-15773' id='answer-label-15773' class='php-answer-label answer label-12'><span class='answer'>Password and resource management<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15774' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15774' class='answer answer-12 php-answer-label answerof-4067' value='15774' \/>&nbsp;<label for='answer-id-15774' id='answer-label-15774' class='php-answer-label answer label-12'><span class='answer'>Implementing and maintaining access control mechanisms<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15775' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15775' class='answer answer-12 php-answer-label answerof-4067' value='15775' \/>&nbsp;<label for='answer-id-15775' id='answer-label-15775' class='php-answer-label answer label-12'><span class='answer'>Security devices<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15776' \/><div class='watu-question-choice'><input type='checkbox' name='answer-4067[]' id='answer-id-15776' class='answer answer-12 js-answer-label answerof-4067' value='15776' \/>&nbsp;<label for='answer-id-15776' id='answer-label-15776' class='js-answer-label answer label-12'><span class='answer'>Conducting security-awareness training<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Technical Controls are also known as Logical Controls. These controls include the following:<br\/>Implementing and maintaining access control mechanisms Password and resource management Identification and authentication methods Security devices Configuration of the infrastructure AnswerF is incorrect. It is a part of Administrative Controls.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(12,this)' id='btn-12' value='See Answer'  \/><input type='hidden' id='questionType12' value='checkbox' class=''><\/div><div class='watu-question' id='question-13'><div class='question-content'><p><strong>QUESTION 30<\/strong><br \/>Frank is the project manager of the NHH Project. He is working with the project team to create a plan to document the procedures to manage risks throughout the project. This document will define how risks will be identified and quantified. It will also define how contingency plans will be implemented by the project team. What document is Frank and the NHH Project team creating in this scenario?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4068' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15777' \/><div class='watu-question-choice'><input type='radio' name='answer-4068[]' id='answer-id-15777' class='answer answer-13 php-answer-label answerof-4068' value='15777' \/>&nbsp;<label for='answer-id-15777' id='answer-label-15777' class='php-answer-label answer label-13'><span class='answer'>Risk management plan<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15778' \/><div class='watu-question-choice'><input type='radio' name='answer-4068[]' id='answer-id-15778' class='answer answer-13 js-answer-label answerof-4068' value='15778' \/>&nbsp;<label for='answer-id-15778' id='answer-label-15778' class='js-answer-label answer label-13'><span class='answer'>Project plan<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15779' \/><div class='watu-question-choice'><input type='radio' name='answer-4068[]' id='answer-id-15779' class='answer answer-13 js-answer-label answerof-4068' value='15779' \/>&nbsp;<label for='answer-id-15779' id='answer-label-15779' class='js-answer-label answer label-13'><span class='answer'>Project management plan<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15780' \/><div class='watu-question-choice'><input type='radio' name='answer-4068[]' id='answer-id-15780' class='answer answer-13 js-answer-label answerof-4068' value='15780' \/>&nbsp;<label for='answer-id-15780' id='answer-label-15780' class='js-answer-label answer label-13'><span class='answer'>Resource management plan<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>The risk management plan, part of the comprehensive management plan, defines how risks will be identified, analyzed, monitored and controlled, and even responded to. A Risk management plan is a document arranged by a project manager to estimate the effectiveness, predict risks, and build response plans to mitigate them. It also consists of the risk assessment matrix. Risks are built in with any project, and project managers evaluate risks repeatedly and build plans to address them. The risk management plan consists of analysis of possible risks with both high and low impacts, and the mitigation strategies to facilitate the project and avoid being derailed through which the common problems arise. Risk management plans should be timely reviewed by the project team in order to avoid having the analysis become stale and not reflective of actual potential project risks. Most critically, risk management plans include a risk strategy for project execution. Answer C is incorrect. The project management plan is a comprehensive plan that communicates the intent of the project for all project management knowledge areas. Answer B is incorrect. The project plan is not an official PMBOK project management plan. Answer D is incorrect. The resource management plan defines the management of project resources, such as project team members, facilities, equipment, and contractors.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(13,this)' id='btn-13' value='See Answer'  \/><input type='hidden' id='questionType13' value='radio' class=''><\/div><div class='watu-question' id='question-14'><div class='question-content'><p><strong>QUESTION 31<\/strong><br \/>Which of the following phases of DITSCAP includes the activities that are necessary for the continuing operation of an accredited IT system in its computing environment and for addressing the changing threats that a system faces throughout its life cycle?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4069' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15781' \/><div class='watu-question-choice'><input type='radio' name='answer-4069[]' id='answer-id-15781' class='answer answer-14 js-answer-label answerof-4069' value='15781' \/>&nbsp;<label for='answer-id-15781' id='answer-label-15781' class='js-answer-label answer label-14'><span class='answer'>Phase 2, Verification<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15782' \/><div class='watu-question-choice'><input type='radio' name='answer-4069[]' id='answer-id-15782' class='answer answer-14 js-answer-label answerof-4069' value='15782' \/>&nbsp;<label for='answer-id-15782' id='answer-label-15782' class='js-answer-label answer label-14'><span class='answer'>Phase 3, Validation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15783' \/><div class='watu-question-choice'><input type='radio' name='answer-4069[]' id='answer-id-15783' class='answer answer-14 js-answer-label answerof-4069' value='15783' \/>&nbsp;<label for='answer-id-15783' id='answer-label-15783' class='js-answer-label answer label-14'><span class='answer'>Phase 1, Definition<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15784' \/><div class='watu-question-choice'><input type='radio' name='answer-4069[]' id='answer-id-15784' class='answer answer-14 php-answer-label answerof-4069' value='15784' \/>&nbsp;<label for='answer-id-15784' id='answer-label-15784' class='php-answer-label answer label-14'><span class='answer'>Phase 4, Post Accreditation Phase<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: Phase 4, Post Accreditation Phase, of the DITSCAP includes the activities that are necessary for the continuing operation of an accredited IT system in its computing environment and for addressing the changing threats that a system faces throughout its life cycle. AnswerC is incorrect. Phase 1, Definition, focuses on understanding the mission, the environment, and the architecture in order to determine the security requirements and level of effort necessary to achieve accreditation. Answer A is incorrect. Phase 2, Verification, verifies the evolving or modified system&#8217;s compliance with the information agreed on in the System Security Authorization Agreement (SSAA). Answer: B is incorrect. Phase 3 validates the compliance of a fully integrated system with the information stated in the SSAA.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(14,this)' id='btn-14' value='See Answer'  \/><input type='hidden' id='questionType14' value='radio' class=''><\/div><div class='watu-question' id='question-15'><div class='question-content'><p><strong>QUESTION 32<\/strong><br \/>Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='4070' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15785' \/><div class='watu-question-choice'><input type='radio' name='answer-4070[]' id='answer-id-15785' class='answer answer-15 js-answer-label answerof-4070' value='15785' \/>&nbsp;<label for='answer-id-15785' id='answer-label-15785' class='js-answer-label answer label-15'><span class='answer'>Single Loss Expectancy (SLE)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15786' \/><div class='watu-question-choice'><input type='radio' name='answer-4070[]' id='answer-id-15786' class='answer answer-15 php-answer-label answerof-4070' value='15786' \/>&nbsp;<label for='answer-id-15786' id='answer-label-15786' class='php-answer-label answer label-15'><span class='answer'>Annualized Rate of Occurrence (ARO)<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15787' \/><div class='watu-question-choice'><input type='radio' name='answer-4070[]' id='answer-id-15787' class='answer answer-15 js-answer-label answerof-4070' value='15787' \/>&nbsp;<label for='answer-id-15787' id='answer-label-15787' class='js-answer-label answer label-15'><span class='answer'>Safeguard<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='15788' \/><div class='watu-question-choice'><input type='radio' name='answer-4070[]' id='answer-id-15788' class='answer answer-15 js-answer-label answerof-4070' value='15788' \/>&nbsp;<label for='answer-id-15788' id='answer-label-15788' class='js-answer-label answer label-15'><span class='answer'>Exposure Factor (EF)<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Explanation\/Reference:<br\/>Explanation: The Annualized Rate of Occurrence (ARO) is a number that represents the estimated frequency at which a threat is expected to occur. It is calculated based upon the probability of the event occurring and the number of employees that could make that event occur. AnswerD is incorrect. The Exposure Factor (EF) represents the % of assets loss caused by a threat. The EF is required to calculate the Single Loss Expectancy (SLE). Answer: A is incorrect. The Single Loss Expectancy (SLE) is the value in dollars that is assigned to a single event. SLE = Asset Value ($) X Exposure Factor (EF) Answer: C is incorrect. Safeguard acts as a countermeasure for reducing the risk associated with a specific threat or a group of threats.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(15,this)' id='btn-15' value='See Answer'  \/><input type='hidden' id='questionType15' value='radio' class=''><\/div><div style='display:none' id='question-16'><br \/><div class='question-content'><img decoding=\"async\" src=\"https:\/\/exam.real4prep.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Loading ...\" title=\"Loading ...\" \/>&nbsp;Loading &#8230;<\/div><\/div><br \/>\n<input type=\"button\" name=\"action\" onclick=\"Watu.submitResult()\" id=\"action-button\" style=\"margin:0 auto 20px auto;\" value=\"View Results\"  class=\"watu-submit-button\" \/>\n<input type=\"hidden\" name=\"no_ajax\" value=\"0\"><input type=\"hidden\" name=\"quiz_id\" value=\"208\" \/>\n<input type=\"hidden\" id=\"watuStartTime\" name=\"start_time\" value=\"2026-09-23 20:16:50\" \/>\n<\/form>\n<\/div>\n<div id=\"watu-loading-result\" style=\"display:none;\">\n\t<p align=\"center\"><img decoding=\"async\" src=\"https:\/\/exam.real4prep.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Loading\" title=\"Loading\" \/><\/p>\n<\/div>\t\n<script type=\"text\/javascript\">\nvar exam_id=0;\nvar question_ids='';\nvar watuURL='';\njQuery(function($){\nquestion_ids = \"4056,4057,4058,4059,4060,4061,4062,4063,4064,4065,4066,4067,4068,4069,4070\";\nexam_id = 208;\nWatu.exam_id = exam_id;\nWatu.qArr = question_ids.split(',');\nWatu.post_id = 523;\nWatu.singlePage = '1';\nWatu.hAppID = \"0.35262800 1790194610\";\nwatuURL = \"https:\/\/exam.real4prep.com\/wp-admin\/admin-ajax.php\";\nWatu.noAlertUnanswered = 0;\n});\n\nfunction showanswer1(e,q) {\n\tvar check = new Array();\n\tjQuery('.answer-' + e).each(function (i) {\n\t\tcheck.push(this.checked)\n\t})\n\tlet textval = jQuery('.watu-textarea-' + e).val()\n\tif (jQuery.inArray(true, check) >= 0 || textval !== '' && textval !== undefined) {\n\t\tjQuery(q).stop().fadeOut(300)\n\t\tjQuery('.php-answer-label.label-' + e).addClass(\n\t\t\t'correct-answer'\n\t\t)\n\t\tjQuery('.answer-' + e).each(function (i) {\n\t\t\tif (this.checked && this.className.match(\/js\\-answer\/)) {\n\t\t\t\tvar number = this.id.toString().replace(\/\\D\/g, '')\n\t\t\t\tif (number) {\n\t\t\t\t\tjQuery('#answer-label-' + number).addClass('user-answer')\n\t\t\t\t}\n\t\t\t}\n\t\t})\n\t\tjQuery(q).siblings('.show-question-feedback').stop().fadeIn(300)\n\t\ttextval = ''\n\t} else if (textval == '' || textval == undefined){\n\t\t\/\/jQuery(\".hint\").stop().fadeIn(300)\n\t\talert('Please first answer the question');\n\t}\n}\nvar btnisshow = jQuery(\".php-answer-label\").length\nif (btnisshow > 0) {\n\tjQuery('.showchecked').show()\n} else {\n\tjQuery('.showchecked').hide()\n}\n<\/script>\n<h3>Who should take the exam<\/h3>\n<p>if you have the following prerequisite and required skills then you should take this exam for getting Certified Secure Software Lifecycle Professional (CSSLP) certificate.<\/p>\n<ul>\n<li>Minimum of 4 years of cumulative paid full-time Software Development Lifecycle (SDLC) professional work experience in 1 or more of the 8 domains of the (ISC)2 CSSLP CBK<\/li>\n<li>3 years of cumulative paid full-time SDLC professional work experience in 1 or more of the 8 domains of the CSSLP CBK<\/li>\n<li>4-year degree leading to a Baccalaureate, or regional equivalent in Computer Science, Information Technology (IT) or related fields.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>ISC CSSLP Real 2023 Braindumps Mock Exam Dumps: <a href=\"https:\/\/www.real4prep.com\/CSSLP-exam.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.real4prep.com\/CSSLP-exam.html<\/a><\/strong><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>CSSLP Free Exam Questions and Answers PDF Updated on Feb-2023 Latest CSSLP Exam Dumps Recently Updated 349 Questions Secure Software Lifecycle Management (11%): Promote software development\u2019s security&#8230; <\/p>","protected":false},"author":1,"featured_media":524,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[1487,1488],"tags":[1481,1484,1482,1483,1486,1485,1480],"class_list":["post-523","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-csslp","category-isc","tag-csslp-exam-cost","tag-csslp-latest-study-guide-questions","tag-csslp-reliable-exam-tutorial","tag-csslp-reliable-exam-voucher","tag-csslp-reliable-study-guide-questions","tag-csslp-reliable-test-questions-pdf","tag-csslp-valid-exam-pdf"],"_links":{"self":[{"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/posts\/523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/comments?post=523"}],"version-history":[{"count":0,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/posts\/523\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/media\/524"}],"wp:attachment":[{"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/media?parent=523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/categories?post=523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exam.real4prep.com\/zh\/wp-json\/wp\/v2\/tags?post=523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}