When conducting a third-party risk assessment of a new supplier, which of the following reports should be reviewed to confirm the operating effectiveness of the security, availability, confidentiality, and privacy trust principles?
Correct Answer: B
When conducting a third-party risk assessment of a new supplier, the Service Organization Control (SOC) 2, Type 2 report should be reviewed to confirm the operating effectiveness of the security, availability, confidentiality, and privacy trust principles. SOC 2 reports are issued by independent auditors and provide detailed information about a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. A Type 2 report includes an auditor's opinion on the design and operating effectiveness of the controls.
Question 147
Which Web Services Security (WS-Security) specification maintains a single authenticated identity across multiple dissimilar environments? Click on the correct specification in the image below.
Correct Answer:
Explanation: WS-Federation WS-Federation is the WS-Security specification that maintains a single authenticated identity across multiple dissimilar environments. WS-Federation is a specification that defines mechanisms for federated identity and access management, which allows users or devices to use a single identity or credential to access multiple or different applications, systems, or networks, without requiring to authenticate or to login separately or repeatedly for each application, system, or network. WS-Federation is based on the WS-Trust specification, which defines mechanisms for issuing, renewing, and validating security tokens, such as SAML assertions or Kerberos tickets, that can be used as credentials for federated identity and access management. References: CISSP Official (ISC)2 Practice Tests, Chapter 4, page 122; Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 4, page 179
Question 148
What is a hot-site facility?
Correct Answer: A
Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.
Question 149
Which choice below represents an application or system demonstrating a need for a high level of confidentiality protection and controls?
Correct Answer: C
Although elements of all of the systems described could require specific controls for confidentiality, given the descriptions above, system b fits the definition most closely of a system requiring a very high level of confidentiality. Answer a is an example of a system requiring high availability. Answer c is an example of a system that requires medium integrity controls. Answer d is a system that requires only a low level of confidentiality. Asystem may need protection for one or more of the following reasons: Confidentiality. The system contains information that requires protection from unauthorized disclosure. Integrity. The system contains information that must be protected from unauthorized, unanticipated, or unintentional modification. Availability. The system contains information or provides services which must be available on a timely basis to meet mission requirements or to avoid substantial losses. Source: NIST Special Publication 800-18, Guide for Developing Security Plans for Information Technology Systems
Question 150
An organization wants a service provider to authenticate users via the users' organization domain credentials. Which markup language should the organization's security personnel use to support the integration?