CISSP /58 CISSP Practice Exam Questions and Answers For Study 1 / 58 12. Which of the following is considered a physiological biometric identifier? Voice recognition Keystroke dynamics Retina scanning Gait recognition 2 / 58 16. What is the main challenge of using facial recognition systems in poorly lit environments? High FAR rate Inability to process data High FRR rate Inaccurate biometric template generation 3 / 58 22. Which of the following is an example of behavioral biometrics? Gait recognition Voice recognition Iris scanning Facial recognition 4 / 58 Which of the following department managers would be best suited to oversee thedevelopment of an information security policy? Information Systems Business operations Human Resources Security administration 5 / 58 What is called the percentage of invalid subjects that are falsely accepted? Crossover Error Rate (CER) True Acceptance Rate (TAR) or Type III error False Acceptance Rate (FAR) or Type II Error False Rejection Rate (FRR) or Type I Error 6 / 58 24. Which of the following reduces the risk of biometric spoofing? Biometric database replication Multi-factor authentication (MFA) Lower FAR Higher FRR 7 / 58 Which one of the following should NOT be contained within a computer policy? Responsibilities of individuals and groups for protected information. Definition of management expectations. Statement of senior executive support. Definition of legal and regulatory controls. 8 / 58 10. Biometric systems provide which of the following advantages over traditional access methods like passwords? They are more cost-effective Biometric data is easier to replicate They eliminate the need to remember a password They are immune to hacking 9 / 58 25. Which factor is least likely to affect the performance of a fingerprint recognition system? High temperatures Dirt on the scanner The user's age Moisture on the user's finger 10 / 58 The quality of finger prints is crucial to maintain the necessary: FRR FRR and FAR ERR and FAR FAR 11 / 58 Which of the following defines the intent of a system security policy? A definition of those items that must be excluded on the system. A brief, high-level statement defining what is and is not permitted during the operation of the system. A listing of tools and applications that will be used to protect the system. A definition of the particular settings that have been determined to provide optimum security. 12 / 58 In biometric identification systems, at the beginning, it was soon apparent that truly positiveidentification could only be based on physical attributes of a person. This raised thenecessicity of answering 2 questions: what was the age of a person and his income level what was the sex of a person and his age what part of the body to be used and how to accomplish identification to be viable what was the tone of the voice of a person and his habits 13 / 58 3. What does the term "false acceptance rate (FAR)" refer to in a biometric system? The percentage of authorized users incorrectly denied access The number of retries allowed in case of failure The percentage of unauthorized users incorrectly allowed access The speed at which the system processes biometric data 14 / 58 Which of the following is being considered as the most reliable kind of personal identification? Finger print Token Ticket Granting Password 15 / 58 A security policy would include all of the following EXCEPT Enforcement Background Audit requirements Scope statement 16 / 58 9. Which metric measures the likelihood that a biometric system incorrectly rejects a legitimate user? Cross Error Rate (CER) Equal Error Rate (EER) False Rejection Rate (FRR) False Acceptance Rate (FAR) 17 / 58 Which of the following methods is more microscopic and will analyze the direction of the ridges of the fingerprints for matching? None of the choices Ridge matching Minutia matching Flow direct 18 / 58 17. Which of the following biometric methods is based on behavioral characteristics? Gait recognition Fingerprint recognition Retina scanning Palm vein scanning 19 / 58 Which of the following would be the first step in establishing an information securityprogram? Purchase of security access control software Adoption of a corporate information security policy statement Development of a security awareness-training program Development and implementation of an information security standards manual 20 / 58 What is "Failure to Enroll (FTE)" in biometric systems? The system fails to properly record a user’s biometric data during enrollment A system's inability to reject an unauthorized user A user's failure to provide the correct input at authentication A system's inability to correctly recognize a legitimate user 21 / 58 Which of the following biometrics devices has the highs Crossover Error Rate (CER)? Hang Geometry Iris scan Fingerprints Voice pattern 22 / 58 13. In a biometric access system, what does a "template" refer to? The physical device used to scan biometric traits A record of an individual’s biometric data stored for comparison A reference document used to design the system The pattern of data flow in the network 23 / 58 7. Which biometric method is least invasive and often used for user convenience in mobile devices? Facial recognition Fingerprint scanning Iris recognition Retina scanning 24 / 58 Which of the following biometric parameters are better suited for authentication use over along period of time? Retina pattern Iris pattern Signature dynamics Voice pattern 25 / 58 Which of the following are the valid categories of hand geometry scanning? Electrical and image-edge detection Logical and image-edge detection Mechanical and image-ridge detection. Mechanical and image-edge detection 26 / 58 Why must senior management endorse a security policy? So that external bodies will recognize the organizations commitment to security. So that they will accept ownership for security within the organization. So that employees will follow the policy directives. So that they can be held legally accountable. 27 / 58 4. Which biometric system is based on the measurement of blood vessels in the hand? Palm vein scanning Hand geometry Fingerprint scanning Iris recognition 28 / 58 Which of the following are the types of eye scan in use today? Retinal scans and reflective scans Retinal scans and iris scans Retinal scans and body scans. Reflective scans and iris scans 29 / 58 In the following choices there is one that is a typical biometric characteristics that is not used to uniquely authenticate an individual's identity? Retina scans Skin scans Palm scans Iris scans 30 / 58 Which must bear the primary responsibility for determining the level of protection needed forinformation systems resources? IS security specialists system auditors Seniors security analysts Senior Management 31 / 58 Which one of the following statements describes management controls that are instituted toimplement a security policy? They are generally inexpensive to implement. They prevent users from accessing any control function. They may be administrative, procedural, or technical. They eliminate the need for most auditing functions. 32 / 58 What is the function of a corporate information security policy? Define the main security objectives which must be achieved and the security framework to meet business objectives. Issue corporate standard to be used when addressing specific security problems. Define the specific assets to be protected and identify the specific tasks which must be completed to secure them Issue guidelines in selecting equipment, configuration, design, and secure operations. 33 / 58 In which one of the following documents is the assignment of individual roles andresponsibilities MOST appropriately defined? Program manual Enforcement guidelines Acceptable use policy Security policy 34 / 58 2. Which of the following is NOT a type of biometric access control? Iris recognition Fingerprint scanning Retina scanning Passwords 35 / 58 When developing an information security policy, what is the FIRST step that should be taken? Obtain copies of mandatory regulations. Gain management approval. Ensure policy is compliant with current working practices. Seek acceptance from other departments. 36 / 58 23. What is the typical use case for biometric systems in multi-factor authentication (MFA)? Something you are All of the above Something you have Something you know 37 / 58 6. What is a primary disadvantage of biometric systems? Users often forget how to use them They are too secure They can be expensive to implement They are very slow to process 38 / 58 In addition to the accuracy of the biometric systems, there are other factors that must alsobe considered: These factors include the enrollment time, but not the throughput rate, neither the acceptability. These factors do not include the enrollment time, the throughput rate, and acceptability These factors include the enrollment time and the throughput rate, but not acceptability These factors include the enrollment time, the throughput rate, and acceptability 39 / 58 20. Which of the following is considered the least secure biometric method due to environmental variables? Voice recognition Fingerprint recognition Retina scanning Iris recognition 40 / 58 Which one of the following is NOT a fundamental component of a Regulatory Security Policy? When it is to be done. Who is to do it. What is to be done. Why is it to be done 41 / 58 Which one of the following is an important characteristic of an information security policy? Lists applications that support the business function. Requires the identification of information owners. Identifies major functional areas of information. Quantifies the effect of the loss of the information. 42 / 58 5. Which of the following terms describes the point where the False Acceptance Rate (FAR) equals the False Rejection Rate (FRR)? Biometric Error Rate (BER) Failure to Enroll (FTE) Cross Error Rate (CER) Crossover Error Rate (CER) 43 / 58 Ensuring the integrity of business information is the PRIMARY concern of Logical Security Encryption Security On-line Security Procedural Security. 44 / 58 Almost all types of detection permit a system's sensitivity to be increased or decreasedduring an inspection process. To have a valid measure of the system performance: none of the above choices is correct the FRR is used the FAR is used The CER is used 45 / 58 19. What is a significant security risk associated with biometric systems? The data can be easily reset like passwords Biometric systems are immune to spoofing Physical characteristics can change over time Biometric data is hard to replace once compromised 46 / 58 You are comparing biometric systems. Security is the top priority. A low is mostimportant in this regard. FRR MTBF ERR FAR 47 / 58 1. What is the primary advantage of using biometric systems for authentication? Fast deployment Ease of use Unique identification Cost-effectiveness 48 / 58 18. Which biometric system analyzes the distinctive patterns of blood vessels in the retina for identification? Retina scanning Facial recognition Hand geometry Iris recognition 49 / 58 21. Which biometric method uses the geometry of the hand for identification? Retina scanning Hand geometry Palm vein scanning Fingerprint recognition 50 / 58 8. What type of biometric system uses the measurement of the unique patterns in the colored ring around the pupil? Iris recognition Hand geometry Retina scanning Fingerprint scanning 51 / 58 15. Which type of biometric system captures the unique characteristics of the voice for authentication? Gait recognition Facial recognition Signature dynamics Voice recognition 52 / 58 All of the following are basic components of a security policy EXCEPT the definition of the issue and statement of relevant terms. statement of performance of characteristics and requirements. statement of roles and responsibilities statement of applicability and compliance requirements. 53 / 58 14. Which of the following biometric methods has the highest accuracy? Iris recognition Fingerprint recognition Voice recognition Hand geometry 54 / 58 Which of the following eye scan methods is considered to be more intrusive? Reflective scans Iris scans Body scans Retinal scans 55 / 58 Type II errors occur when which of the following biometric system rates is high? False reject rate False accept rate Crossover error rate Speed and throughput rate 56 / 58 By requiring the user to use more than one finger to authenticate, you can: Provide statistical improvements in ERR Provide statistical improvements in MTBF Provide statistical improvements in EAR. Provide statistical improvements in FRR. 57 / 58 Which of the following choices is NOT part of a security policy? definition of general and specific responsibilities for information security management statement of management intend, supporting the goals and principles of information security definition of overall steps of information security and the importance of security description of specific technologies used in the field of information security 58 / 58 What is the most critical characteristic of a biometric identifying system? Reliability Perceived intrusiveness Accuracy Storage requirements Your score is 0% Restart quiz