What is the motivation for use of the Online Certificate Status Protocol (OCSP)?
Correct Answer: C
Section: Mixed questions Explanation/Reference:
Question 82
Which of the following statements pertaining to message digests is incorrect?
Correct Answer: C
A message digest should be calculated using all of the original file's data, not the first 128 bytes. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 4: Cryptography (page 160).
Question 83
How does a Host Based Intrusion Detection System (HIDS) identify a potential attack?
Correct Answer: C
Section: Software Development Security
Question 84
In the public sector, as opposed to the private sector, due care is usually determined by
Correct Answer: D
Question 85
The Orange Book describes four hierarchical levels to categorize security systems. Which of the following levels require mandatory protection?
Correct Answer: A
Level B is the first to require Mandatory Protection. Because the higher levels also inherit the requirements of all lower levels, level A also requires Mandatory Protection. The following answers are incorrect: B and C. Is incorrect because Mandatory Protection is not required until level B, Level C is a lower level. A, B, and C. Is incorrect because Mandatory Protection is not required until level B, Level C is a lower level. B and D. Is incorrect because Mandatory Protection is not required until level B, Level D is a lower level. One of the first accpted evaluation standards was the Trusted Computer Security Evaluation Criteria or TCSEC. The Orange Book was part of this standard that defines four security divisions consisting of seven different classes for security ratings. The lowest class offering the least protection is D - Minimal protection. The highest classification would be A1 offering the most secure environment. As you go to the next division and class you inherit the requirements of the lower levels. So, for example C2 would also incorporate the requirements for C1 and D. The divisions and classes are: D - Minimal protection C - Discretionary protection C1 - Discretionary Security Protection C2 - Controlled Access Protection B - Mandatory Protection B1 - Labeled Security B2 - Structured Protection B3 - Security Domains A - Verified Protection A1 - Verified Design Wikipedia: "TCSEC was replaced with the development of the Common Criteria international standard originally published in 2005." References: OIG CBK, Security Architecture and Design (pages 329 - 330) AIO, 3rd Edition, Security Models and Architecture (pages 302 - 306) AIO, 4th Edition, Security Architecture and Design, pp357-361. Wikipedia - http://en.wikipedia.org/wiki/TCSEC#Divisions_and_Classes DOD TCSEC - http://www.cerberussystems.com/INFOSEC/stds/d520028.htm NSI reference for Orange book: http://nsi.org/Library/Compsec/orangebo.txt