
2025年最新の実際のGoShiken CC問題集PDFで100%合格率を保証します
無料ISC CC試験問題と解答
質問 # 52
The concept that the deployment of multiple types of controls provides better security than using a single type of control.
- A. VPN
- B. Defense in depth
- C. Internet
- D. Least privilege
正解:B
質問 # 53
Tekila works for a government agency. All data in the agency is assigned a particular sensitivity level, called a "classification." Every person in the agency is assigned a "clearance" level, which determines the classification of data each person can access.
What is the access control model being implemented in Tekila's agency?
- A. MAC (mandatory access control)
- B. RBAC (role-based access control
- C. DAC (discretionary access control)
- D. FAC (formal access control)
正解:A
質問 # 54
What is the overall objective of a disaster recovery (DR) effort?
- A. Save money
- B. Return to normal, full operations
- C. Enhance public perception of the organization
- D. Preserve critical business functions during a disaster
正解:B
質問 # 55
Which of the following activities is usually part of the configuration management process, but is also extremely helpful in countering potential attacks?
- A. Updating and patching systems
- B. Conferences with senior leadership
- C. Annual budgeting
- D. The annual shareholders' systems
正解:A
質問 # 56
Which of the following is probably the main purpose of configuration management?
- A. Ensuring only authorized are made to the IT environment
- B. Ensuring the organization adheres to privacy laws
- C. Keeping secret material protected
- D. Keeping out intruders
正解:A
質問 # 57
Steve is a security practitioner assigned to come up with a protective measure for ensuring cars don't collide with pedestrians. What is probably the most effective type of control for this task?
- A. Nuanced
- B. Technical
- C. Administrative
- D. Physical
正解:D
質問 # 58
Visitors to a secure facility need to be controlled. Controls useful for managing visitors include all of the following except:
- A. Fence
- B. Badges that differ from employee badges
- C. Sign-in sheet/tracking log
- D. Receptionist
正解:A
質問 # 59
Which of the following are not typically involved in incident detection?
- A. Regulators
- B. Security analysts
- C. Automated tools
- D. Users
正解:A
質問 # 60
Using Mandatory Access Control (MAC), we would use clearance for assigning which of these?
Response:
- A. Auditing.
- B. Authorization.
- C. Availability.
- D. Authentication.
正解:B
質問 # 61
A device that is commonly useful to have on the perimeter between two networks.
- A. User laptop
- B. IoT
- C. Camera
- D. Firewall
正解:D
質問 # 62
Hashing is often used to provide _______.
- A. Value
- B. Integrity
- C. Confidentiality
- D. Availability
正解:B
質問 # 63
The city of Grampon wants to know where all its public vehicles (garbage trucks, police cars, etc.) are at all times, so the city has GPS transmitters installed in all the vehicles. What kind of control is this?
- A. Technical
- B. Physical
- C. Administrative
- D. Entrenched
正解:A
質問 # 64
A device typically accessed by multiple users, often intended for a single purpose, such as managing email or web pages.
- A. Server
- B. Switch
- C. Laptop
- D. Router
正解:A
質問 # 65
The Triffid Corporation publishes a strategic overview of the company's intent to secure all the data the company possesses. This document is signed by Triffid senior management. What kind of document is this?
- A. Law
- B. Standard
- C. Policy
- D. Procedure
正解:C
質問 # 66
Archiving is typically done when _________.
- A. Data has become illegal
- B. Data has lost all value
- C. Data is ready to be destroyed
- D. Data is not needed for regular work purposes
正解:D
質問 # 67
Within the organization, who can identify risk?
- A. The security manager
- B. Any security team member
- C. Senior management
- D. Anyone
正解:D
質問 # 68
Which type of fire-suppression system is typically the safest for humans?
- A. Gaseous
- B. Oxygen-depletion
- C. Water
- D. Dirt
正解:C
質問 # 69
Trina and Doug both work at Triffid, Inc. Doug is having trouble logging into the network. Trina offers to log in for Doug, using Trina's credentials, so that Doug can get some work done.
What is the problem with this?
- A. Anything either of them do will be attributed to Trina
- B. It is against the law
- C. Doug is a bad person
- D. If Trina logs in for Doug, then Doug will never be encouraged to remember credential without assistance
正解:A
質問 # 70
A means to allow remote users to have secure access to the internal IT environment.
- A. MAC
- B. VLAN
- C. Internet
- D. VPN
正解:D
質問 # 71
For our authentication, we are looking at knowledge factors. Which is the MOST common knowledge factor in use today?
Response:
- A. Pass phrase.
- B. PINs.
- C. One-time passwords.
- D. Passwords.
正解:D
質問 # 72
What is the access control model being implemented in Tekila's agency?
- A. Discretionary access control (DAC)
- B. Formal access control (FAC)
- C. Mandatory access control (MAC)
- D. Role-based access control (RBAC)
正解:C
質問 # 73
Kerpak works in the security office of a medium-sized entertainment company. Kerpak is asked to assess a particular threat, and he suggests that the best way to counter this threat would be to purchase and implement a particular security solution. This is an example of _______.
- A. Acceptance
- B. Transference
- C. Avoidance
- D. Mitigation
正解:D
質問 # 74
Which common cloud deployment model typically features only a single customer's data/functionality stored on specific systems/hardware?
- A. Hybrid
- B. Public
- C. Private
- D. Community
正解:C
質問 # 75
Hoshi is an (ISC)² member who works for the Triffid Corporation as a data manager. Triffid needs a new firewall solution, and Hoshi is asked to recommend a product for Triffid to acquire and implement. Hoshi's cousin works for a firewall vendor; that vendor happens to make the best firewall available. What should Hoshi do?
- A. Recommend a different vendor/product
- B. Hoshi should ask to be recused from the task
- C. Disclose the relationship, but recommend the vendor/product
- D. Recommend the cousin's product
正解:C
質問 # 76
Inbound traffic from an external source seems to indicate much higher rates of communication than normal, to the point where the internal systems might be overwhelmed. Which security solution can often identify and potentially counter this risk?
- A. Turnstile
- B. Anti-malware
- C. Badge system
- D. Firewall
正解:D
質問 # 77
......
検証済みCC問題集と解答で最新CCをダウンロード:https://www.goshiken.com/ISC/CC-mondaishu.html
更新された100%カバー率でリアルCC試験問題で100%合格保証が付きます:https://drive.google.com/open?id=1r-YQYB3P13P5f7mBHev_t_IgzQL00miU