CISSP /58 CISSP Practice Exam Questions and Answers For Study 1 / 58 19. What is a significant security risk associated with biometric systems? Biometric data is hard to replace once compromised Physical characteristics can change over time Biometric systems are immune to spoofing The data can be easily reset like passwords 2 / 58 7. Which biometric method is least invasive and often used for user convenience in mobile devices? Iris recognition Facial recognition Fingerprint scanning Retina scanning 3 / 58 Which of the following are the valid categories of hand geometry scanning? Electrical and image-edge detection Mechanical and image-ridge detection. Logical and image-edge detection Mechanical and image-edge detection 4 / 58 Which one of the following is an important characteristic of an information security policy? Requires the identification of information owners. Quantifies the effect of the loss of the information. Lists applications that support the business function. Identifies major functional areas of information. 5 / 58 Type II errors occur when which of the following biometric system rates is high? False reject rate False accept rate Crossover error rate Speed and throughput rate 6 / 58 Why must senior management endorse a security policy? So that they will accept ownership for security within the organization. So that external bodies will recognize the organizations commitment to security. So that they can be held legally accountable. So that employees will follow the policy directives. 7 / 58 12. Which of the following is considered a physiological biometric identifier? Keystroke dynamics Gait recognition Retina scanning Voice recognition 8 / 58 Almost all types of detection permit a system's sensitivity to be increased or decreasedduring an inspection process. To have a valid measure of the system performance: none of the above choices is correct The CER is used the FAR is used the FRR is used 9 / 58 Which of the following eye scan methods is considered to be more intrusive? Reflective scans Retinal scans Iris scans Body scans 10 / 58 18. Which biometric system analyzes the distinctive patterns of blood vessels in the retina for identification? Hand geometry Iris recognition Retina scanning Facial recognition 11 / 58 6. What is a primary disadvantage of biometric systems? Users often forget how to use them They are very slow to process They are too secure They can be expensive to implement 12 / 58 Which one of the following should NOT be contained within a computer policy? Responsibilities of individuals and groups for protected information. Definition of management expectations. Statement of senior executive support. Definition of legal and regulatory controls. 13 / 58 2. Which of the following is NOT a type of biometric access control? Retina scanning Fingerprint scanning Passwords Iris recognition 14 / 58 In addition to the accuracy of the biometric systems, there are other factors that must alsobe considered: These factors include the enrollment time, but not the throughput rate, neither the acceptability. These factors include the enrollment time, the throughput rate, and acceptability These factors include the enrollment time and the throughput rate, but not acceptability These factors do not include the enrollment time, the throughput rate, and acceptability 15 / 58 By requiring the user to use more than one finger to authenticate, you can: Provide statistical improvements in MTBF Provide statistical improvements in FRR. Provide statistical improvements in ERR Provide statistical improvements in EAR. 16 / 58 9. Which metric measures the likelihood that a biometric system incorrectly rejects a legitimate user? False Rejection Rate (FRR) Equal Error Rate (EER) False Acceptance Rate (FAR) Cross Error Rate (CER) 17 / 58 14. Which of the following biometric methods has the highest accuracy? Hand geometry Fingerprint recognition Iris recognition Voice recognition 18 / 58 What is called the percentage of invalid subjects that are falsely accepted? True Acceptance Rate (TAR) or Type III error False Rejection Rate (FRR) or Type I Error False Acceptance Rate (FAR) or Type II Error Crossover Error Rate (CER) 19 / 58 Which of the following biometric parameters are better suited for authentication use over along period of time? Iris pattern Voice pattern Signature dynamics Retina pattern 20 / 58 15. Which type of biometric system captures the unique characteristics of the voice for authentication? Facial recognition Gait recognition Signature dynamics Voice recognition 21 / 58 Which of the following defines the intent of a system security policy? A brief, high-level statement defining what is and is not permitted during the operation of the system. A listing of tools and applications that will be used to protect the system. A definition of the particular settings that have been determined to provide optimum security. A definition of those items that must be excluded on the system. 22 / 58 21. Which biometric method uses the geometry of the hand for identification? Fingerprint recognition Palm vein scanning Hand geometry Retina scanning 23 / 58 8. What type of biometric system uses the measurement of the unique patterns in the colored ring around the pupil? Iris recognition Retina scanning Fingerprint scanning Hand geometry 24 / 58 23. What is the typical use case for biometric systems in multi-factor authentication (MFA)? Something you know All of the above Something you have Something you are 25 / 58 4. Which biometric system is based on the measurement of blood vessels in the hand? Iris recognition Palm vein scanning Fingerprint scanning Hand geometry 26 / 58 In biometric identification systems, at the beginning, it was soon apparent that truly positiveidentification could only be based on physical attributes of a person. This raised thenecessicity of answering 2 questions: what was the age of a person and his income level what was the sex of a person and his age what was the tone of the voice of a person and his habits what part of the body to be used and how to accomplish identification to be viable 27 / 58 1. What is the primary advantage of using biometric systems for authentication? Cost-effectiveness Unique identification Fast deployment Ease of use 28 / 58 The quality of finger prints is crucial to maintain the necessary: FAR FRR FRR and FAR ERR and FAR 29 / 58 Which of the following department managers would be best suited to oversee thedevelopment of an information security policy? Human Resources Information Systems Business operations Security administration 30 / 58 Which of the following are the types of eye scan in use today? Reflective scans and iris scans Retinal scans and reflective scans Retinal scans and iris scans Retinal scans and body scans. 31 / 58 13. In a biometric access system, what does a "template" refer to? The pattern of data flow in the network The physical device used to scan biometric traits A reference document used to design the system A record of an individual’s biometric data stored for comparison 32 / 58 What is the most critical characteristic of a biometric identifying system? Perceived intrusiveness Accuracy Reliability Storage requirements 33 / 58 What is "Failure to Enroll (FTE)" in biometric systems? A user's failure to provide the correct input at authentication A system's inability to correctly recognize a legitimate user A system's inability to reject an unauthorized user The system fails to properly record a user’s biometric data during enrollment 34 / 58 When developing an information security policy, what is the FIRST step that should be taken? Ensure policy is compliant with current working practices. Obtain copies of mandatory regulations. Seek acceptance from other departments. Gain management approval. 35 / 58 You are comparing biometric systems. Security is the top priority. A low is mostimportant in this regard. FAR MTBF ERR FRR 36 / 58 Which of the following choices is NOT part of a security policy? definition of overall steps of information security and the importance of security description of specific technologies used in the field of information security definition of general and specific responsibilities for information security management statement of management intend, supporting the goals and principles of information security 37 / 58 Which must bear the primary responsibility for determining the level of protection needed forinformation systems resources? Senior Management system auditors IS security specialists Seniors security analysts 38 / 58 17. Which of the following biometric methods is based on behavioral characteristics? Retina scanning Gait recognition Palm vein scanning Fingerprint recognition 39 / 58 All of the following are basic components of a security policy EXCEPT the statement of applicability and compliance requirements. definition of the issue and statement of relevant terms. statement of performance of characteristics and requirements. statement of roles and responsibilities 40 / 58 16. What is the main challenge of using facial recognition systems in poorly lit environments? High FAR rate Inability to process data High FRR rate Inaccurate biometric template generation 41 / 58 25. Which factor is least likely to affect the performance of a fingerprint recognition system? The user's age Dirt on the scanner Moisture on the user's finger High temperatures 42 / 58 10. Biometric systems provide which of the following advantages over traditional access methods like passwords? They eliminate the need to remember a password Biometric data is easier to replicate They are immune to hacking They are more cost-effective 43 / 58 In which one of the following documents is the assignment of individual roles andresponsibilities MOST appropriately defined? Enforcement guidelines Security policy Program manual Acceptable use policy 44 / 58 In the following choices there is one that is a typical biometric characteristics that is not used to uniquely authenticate an individual's identity? Iris scans Palm scans Retina scans Skin scans 45 / 58 Which of the following methods is more microscopic and will analyze the direction of the ridges of the fingerprints for matching? Minutia matching Flow direct None of the choices Ridge matching 46 / 58 Which of the following is being considered as the most reliable kind of personal identification? Token Finger print Password Ticket Granting 47 / 58 Which one of the following is NOT a fundamental component of a Regulatory Security Policy? Why is it to be done What is to be done. When it is to be done. Who is to do it. 48 / 58 22. Which of the following is an example of behavioral biometrics? Iris scanning Gait recognition Facial recognition Voice recognition 49 / 58 24. Which of the following reduces the risk of biometric spoofing? Multi-factor authentication (MFA) Biometric database replication Lower FAR Higher FRR 50 / 58 A security policy would include all of the following EXCEPT Background Enforcement Audit requirements Scope statement 51 / 58 3. What does the term "false acceptance rate (FAR)" refer to in a biometric system? The number of retries allowed in case of failure The percentage of unauthorized users incorrectly allowed access The percentage of authorized users incorrectly denied access The speed at which the system processes biometric data 52 / 58 20. Which of the following is considered the least secure biometric method due to environmental variables? Iris recognition Fingerprint recognition Retina scanning Voice recognition 53 / 58 Ensuring the integrity of business information is the PRIMARY concern of On-line Security Logical Security Encryption Security Procedural Security. 54 / 58 Which of the following biometrics devices has the highs Crossover Error Rate (CER)? Fingerprints Iris scan Voice pattern Hang Geometry 55 / 58 Which one of the following statements describes management controls that are instituted toimplement a security policy? They may be administrative, procedural, or technical. They are generally inexpensive to implement. They eliminate the need for most auditing functions. They prevent users from accessing any control function. 56 / 58 What is the function of a corporate information security policy? Issue guidelines in selecting equipment, configuration, design, and secure operations. Issue corporate standard to be used when addressing specific security problems. Define the specific assets to be protected and identify the specific tasks which must be completed to secure them Define the main security objectives which must be achieved and the security framework to meet business objectives. 57 / 58 Which of the following would be the first step in establishing an information securityprogram? Purchase of security access control software Development and implementation of an information security standards manual Development of a security awareness-training program Adoption of a corporate information security policy statement 58 / 58 5. Which of the following terms describes the point where the False Acceptance Rate (FAR) equals the False Rejection Rate (FRR)? Failure to Enroll (FTE) Biometric Error Rate (BER) Cross Error Rate (CER) Crossover Error Rate (CER) Your score is 0% Restart quiz