The Secure Hash Algorithm (SHA) is specified in the Digital Encryption Standard. This is the most widely used encryption to date. It is used to encrypt millions of files ranging from matters of national security, to bank accounts, and electronic funds transfers.
Question 7
What is the difference between the OCSP (Online Certificate Status Protocol) and a Certificate Revocation List (CRL)?
Correct Answer: A
Explanation/Reference: Explanation: The CA is responsible for creating and handing out certificates, maintaining them, and revoking them if necessary. Revocation is handled by the CA, and the revoked certificate information is stored on a certificate revocation list (CRL). This is a list of every certificate that has been revoked. This list is maintained and updated periodically. Online Certificate Status Protocol (OCSP) is being used more and more rather than the cumbersome CRL approach. When using just a CRL, the user's browser must either check a central CRL to find out if the certification has been revoked or the CA has to continually push out CRL values to the clients to ensure they have an updated CRL. If OCSP is implemented, it does this work automatically in the background. It carries out real-time validation of a certificate and reports back to the user whether the certificate is valid, invalid, or unknown. OCSP checks the CRL that is maintained by the CA. So the CRL is still being used, but now we have a protocol developed specifically to check the CRL during a certificate validation process. Incorrect Answers: B: The OCSP (Online Certificate Status Protocol) is not a proprietary certificate mechanism developed by Microsoft; it is an open standard. C: The OCSP (Online Certificate Status Protocol) is not used only by Active Directory. D: The OCSP (Online Certificate Status Protocol) is not a way to check the attributes of a certificate; it is a way to check the revocation status of a certificate. References: Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, pp. 836-837
Question 8
Which of the following would an information security professional use to recognize changes to content, particularly unauthorized changes?
Correct Answer: C
Question 9
Lack of which of the following options could cause a negative effect on an organization's reputation, revenue, and result in legal action, if the organization fails to perform due diligence?
Correct Answer: C
Section: Mixed questions
Question 10
A trade secret:
Correct Answer: D
This defines a trade secret. *Answer "Provides the owner with a legally enforceable right to exclude others from practicing the art covered for a specified time period" refers to a patent. *Answer "Protects original works of authorship" refers to a copyright. *Answer "Is a word, name, symbol, color, sound, product shape, or device used to identify goods and to distinguish them from those made or sold by others" refers to a trademark.
Newest CISSP Exam PDF Dumps shared by BraindumpsPass.com for Helping Passing CISSP Exam! BraindumpsPass.com now offer the updated CISSP exam dumps, the BraindumpsPass.com CISSP exam questions have been updated and answers have been corrected get the latest BraindumpsPass.com CISSP pdf dumps with Exam Engine here: