CISSP Security Architecture And Design - Cyber Security & Ethical Hacking
Practice questions to test your knowledge and improve your understanding.
The total(sum)combination of protection mechanisms within a computer system. The TCB includes hardware - software - and firmware.
The Bell-LaPadula Model is a _______________.
Mandatory access control is enfored by the use of security labels.
A1 is also called "Verified Design" and requires formal verification of the design and specifications.
Permits a database to have two records that are identical except for Their classifications
The subject must have Need to Know for ONLY the information they are trying to access.
B1 is the ___________________ of the Trusted Network Interpretation (TNI) or TCSEC that offers labeled security protection.
Which evaluation class of the Trusted Network Interpretation (TNI) offers security domains?
What does the Clark-Wilson security model focus on
Certification is a Technical review that assesses the _____________ - where as Accreditation is management's Official acceptance of the information in the Certification process findings.
Happen because input data is not checked for appropriate length at time of input
TCB contains The Security Kernel and all ______________.
When a portion of primary memory is accessed by specifying the actual address of the memory location
Contains the beginning address
Static packet filtering firewalls are limited to ________.
Data in Cache can be accessed much more quickly than Data
What does the simple security (ss) property mean in the Bell-LaPadula model?
A ring protection system ________: User mode programs from direct access to peripherals and requires them to make use of services running at more privileged levels.
Audit data must be captured and protected to enforce accountability
What is called the formal acceptance of the adequacy of a system's overall security by management?
What is defined as the hardware - firmware and software elements of a trusted computing base that implement the reference monitor concept?
TCSEC addresses Confidentiality - but _____________ . The TCSEC focuses mainly on one attribute of Security Confidentiality.
The TCB is the ________________ within a computer system that work together to enforce a security policy.
The security kernel is the mechanism that _____________ of the reference monitor concept.
Applications and user activity
When a vendor submits a product for evaluation - it submits it to the ____________.
B3 is also called "Security Domains" and imposes more granularity in each protection mechanism.
If a system initializes in a secure state and all allowed state transitions are secure - the every subsequent state will be secure no matter what inputs occur.
Security Labels are not required until __________; thus C2 does not require security labels but B1 does
The Security Model Incorporates the ____________ that should be enforced in the system.
When a computer uses more than one CPU in parallel to execute instructions is known as?