Q878. A software architect has been asked to build a platform to distribute music to thousands of users on a global scale. The architect has been reading about content delivery networks (CDN). Which of the following is a principal task to undertake?
The principal task that the architect should undertake for building a platform to distribute music to thousands of users on a global scale is to establish a media caching methodology. A platform is a type of software or system that provides the foundation or the infrastructure for developing, running, or delivering other software or applications, such as music distribution. A platform can provide various benefits, such as facilitating or enabling the creation, operation, or delivery of the software or applications, and enhancing the functionality, performance, or usability of the software or applications. A platform can also pose various challenges or issues, such as scalability, availability, or latency. A media caching methodology is a type of technique or approach that involves storing or saving the copies or the versions of the media content or data, such as music, on various locations or servers that are closer or nearer to the users or the customers, and that are connected or linked to a network or a service, such as a content delivery network (CDN). A media caching methodology can provide various benefits, such as improving or optimizing the distribution, delivery, or access of the media content or data, and reducing the bandwidth, cost, or time of the distribution, delivery, or access of the media content or data. Establishing a media caching methodology is the principal task that the architect should undertake for building a platform to distribute music to thousands of users on a global scale, as it can address or solve the challenges or issues of the platform, such as scalability, availability, or latency, and as it can ensure or enhance the quality, efficiency, or effectiveness of the platform . References: [CISSP CBK, Fifth Edition, Chapter 3, page 241]; [CISSP Practice Exam – FREE 20 Questions and Answers, Question 15].
Q885. Which choice below is NOT an element of a fiber optic cable?
A BNC refers to a Bayonet Neil Concelman RG58 connector for
10Base2. Fiber optic cable has three basic physical elements, the core,
the cladding, and the jacket. The core is the innermost transmission
medium, which can be glass or plastic. The next outer layer, the
cladding is also made of glass or plastic, but has different properties,
and helps to reflect the light back into the core. The outermost layer,
the jacket, provides protection from heat, moisture, and other environmental
elements. Source: Gigabit Ethernet by Jayant Kadambi, Ian
Crayford, and Mohan Kalkunte (Prentice Hall PTR, 1998).
Figure shows a cross-section of a fiber optic cable.
Exhibit:
Q887. During an IS audit, one of your auditors has observed that some of the critical servers in your organization can be accessed ONLY by using a shared/common user name and password. What should be the auditor’s PRIMARY concern be with this approach?
Explanation/Reference: Explanation: Identification and authentication are the keystones of most access control systems. Identification is the act of a user professing an identity to a system, usually in the form of a log-on ID to the system. Identification establishes user accountability for the actions on the system. Authentication is verification that the user’s claimed identity is valid and is usually implemented through a user password at log-on time. Audit trails list the actions performed by the user account used to perform the actions. However, if all the users are using the same user account, you have no way of knowing which person performed which action. Therefore, you have no “accountability”. Incorrect Answers: A: Password sharing is not the primary concern in this case. The only password shared is the password for the shared account. C: Shared account management is not a concern. The fact that the account is shared is the concern. D: Difficulty in auditing shared account is not the primary concern. Auditing a single account is not a problem. The problem is that you do not know which person is using the account at any given time. References: Krutz, Ronald L. and Russell Dean Vines, The CISSP and CAP Prep Guide: Mastering CISSP and CAP, Wiley Publishing, Indianapolis, 2007, p. 57
Q895. Who is responsible for implementing user clearances in computer-based information systems at the B3 level of the TCSEC rating?
Explanation/Reference:
Explanation:
Typical security administrator functions may include the following:
Setting user clearances, initial passwords, and other security characteristics for new users
Changing security profiles for existing users
Setting or changing file sensitivity labels
Setting the security characteristics of devices and communications channels
Reviewing audit data
Incorrect Answers:
B: System operators provide day-to-day operations of computer systems. They do not perform the tasks listed in the question.
C: Data owners are primarily responsible for determining the data’s sensitivity or classification levels. They can also be responsible for maintaining the information’s accuracy and integrity. They do not perform the tasks listed in the question.
D: Data custodians are delegated the responsibility of protecting data by its owner. They do not perform the tasks listed in the question.
References:
Krutz, Ronald L. and Russel Dean Vines, The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, New York, 2001, p. 211