worksheet 10 questions

User Generated

ezr1

Computer Science

Description

Please submit 10 CISSP questions related to the domain 6: Security Assessment and Testing. Include both the answers and issues with incorrect answers..........................

User generated content is uploaded by users for the purposes of learning and should be used following Studypool's honor code & terms of service.

Explanation & Answer

Hey, check out the answer in the attached word file

Question 1
Which one of the following transitions is not acceptable during a code review using the Fagan inspection
process?
Rework->Inspection
Overview->Preparation
Rework->Preparation
Inspection->Rework
From the rework stage of a Fagan inspection, the only permissible transitions are to Inspection, Follow
Up or Planning as such Rework->Preparation is not acceptable while the rest are.

Question 2
When testing a new software package for vulnerabilities and one creates input for use in the tests using
the zzuf tool. What specific type of test is zzuf designed to assist with?
Port scanning
Fuzz testing
Static testing
Dynamic testing
Testers use the zzuf tool to conduct fuzz testing, which is a type of dynamic testing. This answer is
incorrect because dynamic testing is not the most specific possible answer. Static testing does not use
generated input as it works on source code without running the program. Port scanning is a network
testing technique and does not use the zzuf tool

Question 3
One would like to run a basic port scan again...


Anonymous
I was stuck on this subject and a friend recommended Studypool. I'm so glad I checked it out!

Studypool
4.7
Trustpilot
4.5
Sitejabber
4.4

Related Tags