信息安全工程師當(dāng)天每日一練試題地址:http://www.jazzmuze.com/exam/ExamDay.aspx?t1=6
往期信息安全工程師每日一練試題匯總:http://www.jazzmuze.com/class27-6-1.aspx
信息安全工程師每日一練試題(2017/5/19)在線測(cè)試:http://www.jazzmuze.com/exam/ExamDay.aspx?t1=6&day=2017/5/19
信息安全工程師每日一練試題內(nèi)容(2017/5/19)
試題
1:
IPSec VPN安全技術(shù)沒有用到 ( ) 。
A、隧道技術(shù)
B、加密技術(shù)
C、入侵檢測(cè)技術(shù)
D、身份證認(rèn)證技術(shù)
試題解析與討論:
http://www.jazzmuze.com/st/71772471.html試題參考答案:C
試題
2: 雙宿主機(jī)通常有____個(gè)網(wǎng)絡(luò)接口()
A、1
B、2
C、3
試題解析與討論:
http://www.jazzmuze.com/st/2423413469.html試題參考答案:B
試題
3:
多層的樓房中,最適合做數(shù)據(jù)中心的位置是:()
A.一樓
B.地下室
C.頂樓
D.除以上外的任何樓層
試題解析與討論:
http://www.jazzmuze.com/st/2605716467.html試題參考答案:D
試題
4:
下列關(guān)于ISO15408《信息技術(shù)安全評(píng)估準(zhǔn)則》簡(jiǎn)稱CC標(biāo)準(zhǔn),關(guān)于CC模型中保護(hù)輪廓含義本身解釋正確的是:()
A、它是基于一類TOE的應(yīng)用環(huán)境規(guī)定的一組安全要求,并提出相應(yīng)級(jí)別的保證要求
B、它是基于一個(gè)或多個(gè)PP選擇性的提出的一組安全要求
C、它會(huì)包含PP要求或非PP要求的內(nèi)容,形成一組要求
D、它提出了安全要求實(shí)現(xiàn)的功能和質(zhì)量?jī)蓚€(gè)層面
試題解析與討論:
http://www.jazzmuze.com/st/2730028754.html試題參考答案:A
試題
5: From a control perspective, the PRIMARY objective of classifying information assets is to:
A、establish guidelines for the level of access controls that should be assigned.
B、ensure access controls are assigned to all information assets.
C、assist management and auditors in risk assessment.
D、identify which assets need to be insured against losses.
試題解析與討論:
http://www.jazzmuze.com/st/293229140.html試題參考答案:A
試題
6: An IS auditor inspected a windowless room containing phone switching and networking equipment and documentation binders. The room was equipped with two handheld fire extinguishers-one filled with CO 2 , the other filled with halon. Which of the following should be given the HIGHEST priority in the auditor's report?
A、The halon extinguisher should be removed because halon has a negative impact on the atmospheric ozone layer.
B、Both fire suppression systems present a risk of suffocation when used in a closed room.
C、The CO 2 extinguisher should be removed, because CO 2 is ineffective for suppressing fires involving solid combustibles (paper).
D、The documentation binders should be removed from the equipment room to reduce potential risks.
試題解析與討論:
http://www.jazzmuze.com/st/2956015905.html試題參考答案:B
試題
7: 一個(gè)投資顧問定期向客戶發(fā)送業(yè)務(wù)通訊(newsletter)e-mail,他想要確保沒有人修改他的newsletter。這個(gè)目標(biāo)可以用下列的方法達(dá)到:()
A、用顧問的私鑰加密newsletter的散列(hash)
B、用顧問的公鑰加密newsletter的散列(hash)
C、用顧問的私鑰對(duì)文件數(shù)據(jù)簽名
D、用顧問的私鑰加密newsletter
試題解析與討論:
http://www.jazzmuze.com/st/298681560.html試題參考答案:A
試題
8: 一個(gè)IS審計(jì)師在和一個(gè)會(huì)計(jì)師面談時(shí)發(fā)現(xiàn)他所做的事和崗位描述不符合,在這種情況下,他應(yīng)該()
A、得出結(jié)論控制是不充分的
B、擴(kuò)大實(shí)質(zhì)性測(cè)試的范圍
C、更多的依賴以前的審計(jì)結(jié)果
D、暫停審計(jì)
試題解析與討論:
http://www.jazzmuze.com/st/2992820041.html試題參考答案:B
試題
9: 目標(biāo)導(dǎo)向在設(shè)計(jì)和開發(fā)技術(shù)中的應(yīng)用最可能()
A.使模塊具有重用性
B.改進(jìn)系統(tǒng)的性能
C.提高操縱有效性
D.加快系統(tǒng)開發(fā)的生命周期
試題解析與討論:
http://www.jazzmuze.com/st/3022328864.html試題參考答案:A
試題
10: 哪一項(xiàng)步驟是最好的決定是否合適的恢復(fù)/重啟步驟存在()
A、檢查程序代碼
B、檢查操作文檔
C、關(guān)掉UPS,然后關(guān)掉電源
D、檢查程序文檔
試題解析與討論:
http://www.jazzmuze.com/st/3045015938.html試題參考答案:B