Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Free and Premium Checkpoint 156-110 Dumps Questions Answers

Page: 1 / 4
Total 100 questions

Check Point Certified Security Principles Associate (CCSPA) Questions and Answers

Question 1

Which of the following are appropriate uses of asymmetric encryption? (Choose THREE.)

Options:

A.

Authentication

B.

Secure key-exchange mechanisms

C.

Public Web site access

D.

Data-integrity checking

E.

Sneaker net

Buy Now
Question 2

Which of the following is NOT a concern for enterprise physical security?

Options:

A.

Network Intrusion Detection Systems

B.

Social engineering

C.

Dumpster diving

D.

Property theft

E.

Unauthorized access to a facility

Question 3

A(n) _______ is the first step for determining which technical information assets should be protected.

Options:

A.

Network diagram

B.

Business Impact Analysis

C.

Office floor plan

D.

Firewall

E.

Intrusion detection system

Question 4

ABC Corporation's network requires users to authenticate to cross the border firewall, and before entering restricted segments. Servers containing sensitive information require separate authentication. This is an example of which type of access-control method?

Options:

A.

Single sign-on

B.

Decentralized access control

C.

Hybrid access control

D.

Layered access control

E.

Mandatory access control

Question 5

_________________ is a type of cryptography, where letters of an original message are systematically rearranged into another sequence.

Options:

A.

Symmetric-key exchange

B.

Steganography

C.

Transposition cipher

D.

Asymmetric-key encryption

E.

Simple substitution cipher

Question 6

Which of the following equations results in the Single Loss Expectancy for an asset?

Options:

A.

Asset Value x % Of Loss From Realized Exposure

B.

Asset Value x % Of Loss From Realized Threat

C.

Annualized Rate of Occurrence / Annualized Loss Expectancy

D.

Asset Value x % Of Loss From Realized Vulnerability

E.

Annualized Rate of Occurrence x Annualized Loss Expectancy

Question 7

Which of the following best describes an external intrusion attempt on a local-area network (LAN)?

Options:

A.

Internal users try to gain unauthorized access to information assets outside the organizational perimeter.

B.

External-intrusion attempts from sources outside the LAN are not granted permissions or rights to an organization's information assets.

C.

External users attempt to access public resources.

D.

External intruders attempt exploitation of vulnerabilities, to remove their own access.

E.

Internal users perform inappropriate acts on assets to which they have been given rights or permissions.

Question 8

If e-mail is subject to review by individuals other than the sender and recipient, what should be clearly stated in the organization's e-mail policy?

Options:

A.

Technologies and methods used to monitor and enforce the organization's policies

B.

Senior management and business-unit owner responsibilities and delegation options

C.

Clear, legally defensible definition of what constitutes a business record

D.

Consequences for violation of the organization's acceptable-use policy

E.

No expectation of privacy for e-mail communications, using the organization's resources

Question 9

Which type of Business Continuity Plan (BCP) test involves practicing aspects of the BCP, without actually interrupting operations or bringing an alternate site on-line?

Options:

A.

Structured walkthrough

B.

Checklist

C.

Simulation

D.

Full interruption

E.

Parallel

Question 10

A _______ _______ posture provides many levels of security possibilities, for access control.

Options:

A.

Layered defensive

B.

Multiple offensive

C.

Flat defensive

D.

Reactive defensive

E.

Proactive offensive

Question 11

Which of the following is an integrity requirement for Remote Offices/Branch Offices (ROBOs)?

Options:

A.

Private data must remain internal to an organization.

B.

Data must be consistent between ROBO sites and headquarters.

C.

Users must be educated about appropriate security policies.

D.

Improvised solutions must provide the level of protection required.

E.

Data must remain available to all remote offices.

Question 12

Which of the following statements about encryption's benefits is false? Encryption can: (Choose TWO.)

Options:

A.

significantly reduce the chance information will be modified by unauthorized entities.

B.

only be used to protect data in transit. Encryption provides no protection to stored data.

C.

allow private information to be sent over public networks, in relative safety.

D.

significantly reduce the chance information will be viewed by unauthorized entities.

E.

prevent information from being destroyed by malicious entities, while in transit.

Question 13

A security administrator implements Secure Configuration Verification (SCV), because SCV: (Choose THREE.)

Options:

A.

Does not enable the administrator to monitor the configuration of remote computers.

B.

Can block connectivity for machines that do not comply with the organization's security policy.

C.

Enables the administrator to monitor the configuration of remote computers.

D.

Prevents attackers from penetrating headquarters' Security Gateway.

E.

Confirms that a remote configuration complies with the organization's security policy.

Question 14

A(n) _______________ is an unintended communication path that can be used to violate a system security policy.

Options:

A.

Covert channel

B.

Integrity axiom

C.

Simple rule violation

D.

Inferred fact

E.

Aggregated data set

Question 15

Which of the following is MOST likely to cause management to view a security-needs proposal as invalid?

Options:

A.

Real-world examples

B.

Exaggeration

C.

Ranked threats

D.

Quantified risks

E.

Temperate manner

Page: 1 / 4
Total 100 questions