信息安全工程師當(dāng)天每日一練試題地址:http://www.jazzmuze.com/exam/ExamDay.aspx?t1=6
往期信息安全工程師每日一練試題匯總:http://www.jazzmuze.com/class27-6-1.aspx
信息安全工程師每日一練試題(2017/3/12)在線測(cè)試:http://www.jazzmuze.com/exam/ExamDay.aspx?t1=6&day=2017/3/12
信息安全工程師每日一練試題內(nèi)容(2017/3/12)
試題
1:
在Windows操作系統(tǒng)平臺(tái)上采用通用硬件設(shè)備和軟件開發(fā)工具搭建的電子商務(wù)信息系統(tǒng)宜采用( )作為信息安全系統(tǒng)架構(gòu)。
A.S2-MIS
B.MIS+S
C.S-MIS
D.PMIS
試題解析與討論:
http://www.jazzmuze.com/st/632218.html試題參考答案:C
試題
2: 一個(gè)摘要算法對(duì)不同長(zhǎng)度的文字進(jìn)行運(yùn)算所得的結(jié)果長(zhǎng)度是不同的()
A、是
B、否
試題解析與討論:
http://www.jazzmuze.com/st/2433718201.html試題參考答案:B
試題
3:
當(dāng)以下哪一類人員維護(hù)應(yīng)用系統(tǒng)軟件的時(shí)候,會(huì)造成對(duì)“職責(zé)分離”原則的違背?()
A.數(shù)據(jù)維護(hù)管理員
B.系統(tǒng)故障處理員
C.系統(tǒng)維護(hù)管理員
D.系統(tǒng)程序員
試題解析與討論:
http://www.jazzmuze.com/st/2601220208.html試題參考答案:D
試題
4:
當(dāng)用戶輸入的數(shù)據(jù)被一個(gè)解釋器當(dāng)作命令或查詢語句的一部分執(zhí)行時(shí),就會(huì)產(chǎn)生哪種類型的漏洞?()
A、緩沖區(qū)溢出
B、設(shè)計(jì)錯(cuò)誤
C、信息泄露
D、代碼注入
試題解析與討論:
http://www.jazzmuze.com/st/2656522594.html試題參考答案:D
試題
5:
安全專家在對(duì)某網(wǎng)站進(jìn)行安全部署時(shí),調(diào)整了Apache的運(yùn)行權(quán)限,從root權(quán)限降低為nobody用戶,以下操作的主要目的是:()
A.為了提高Apache軟件運(yùn)行效率
B.為了提高Apache軟件的可靠性
C.為了避免攻擊者通過Apache獲得root 權(quán)限
D.為了減少Apache上存在的漏洞
試題解析與討論:
http://www.jazzmuze.com/st/27508101.html試題參考答案:C
試題
6: The vice president of human resources has requested an audit to identify payroll overpayments for the previous year. Which would be the BEST audit technique to use in this situation?
A、Test data
B、Generalized audit software
C、Integrated test facility
D、Embedded audit module
試題解析與討論:
http://www.jazzmuze.com/st/2925024095.html試題參考答案:B
試題
7: A digital signature contains a message digest to:
A、show if the message has been altered after transmission.
B、define the encryption algorithm.
C、confirm the identity of the originator.
D、enable message transmission in a digital format.
試題解析與討論:
http://www.jazzmuze.com/st/293891002.html試題參考答案:A
試題
8: Which of the following should be of PRIMARY concern to an IS auditor reviewing the management of external IT service providers?
A、Minimizing costs for the services provided
B、Prohibiting the provider from subcontracting services
C、Evaluating the process for transferring knowledge to the IT department
D、Determining if the services were provided as contracted
試題解析與討論:
http://www.jazzmuze.com/st/2942316458.html試題參考答案:D
試題
9: 當(dāng)評(píng)估一個(gè)IDS系統(tǒng)時(shí),IS審計(jì)員應(yīng)當(dāng)最關(guān)注下列哪一項(xiàng):()
A、非威脅事件識(shí)別成威脅的數(shù)量
B、沒有系統(tǒng)被識(shí)別出來攻擊
C、自動(dòng)工具生成的報(bào)告/日志
D、被系統(tǒng)阻止的合法流量
試題解析與討論:
http://www.jazzmuze.com/st/300632037.html試題參考答案:B
試題
10: 對(duì)于一個(gè)特定的威脅,整體的商業(yè)風(fēng)險(xiǎn)可以表示成()
A.一個(gè)影響概率及震級(jí)的產(chǎn)物,如果威脅成功地變成一個(gè)弱點(diǎn)
B.影響的震級(jí),如果威脅成功地變成一個(gè)弱點(diǎn)
C.威脅成功地變成一個(gè)弱點(diǎn)的可能性
D.風(fēng)險(xiǎn)評(píng)估團(tuán)隊(duì)的整體判斷
試題解析與討論:
http://www.jazzmuze.com/st/302712199.html試題參考答案:A