- Home
- ISC Certification
- CISSP Exam
- ISC.CISSP.v2026-05-25.q539 Practice Test
Question 156
What kind of certificate is used to validate a user identity?
Correct Answer: A
In cryptography, a public key certificate (or identity certificate) is an electronic document which incorporates a digital signature to bind together a public key with an identity - information such as the name of a person or an organization, their address, and so forth. The certificate can be used to verify that a public key belongs to an individual.
In a typical public key infrastructure (PKI) scheme, the signature will be of a certificate authority (CA). In a web of trust scheme, the signature is of either the user (a self-signed certificate) or other users ("endorsements"). In either case, the signatures on a certificate are attestations by the certificate signer that the identity information and the public key belong together.
In computer security, an authorization certificate (also known as an attribute certificate) is a digital document that describes a written permission from the issuer to use a service or a resource that the issuer controls or has access to use. The permission can be delegated.
Some people constantly confuse PKCs and ACs. An analogy may make the distinction clear. A PKC can be considered to be like a passport: it identifies the holder, tends to last for a long time, and should not be trivial to obtain. An AC is more like an entry visa: it is typically issued by a different authority and does not last for as long a time. As acquiring an entry visa typically requires presenting a passport, getting a visa can be a simpler process.
A real life example of this can be found in the mobile software deployments by large service providers and are typically applied to platforms such as Microsoft Smartphone (and related), Symbian OS, J2ME, and others.
In each of these systems a mobile communications service provider may customize the mobile terminal client distribution (ie. the mobile phone operating system or application environment) to include one or more root certificates each associated with a set of capabilities or permissions such as "update firmware", "access address book", "use radio interface", and the most basic one, "install and execute". When a developer wishes to enable distribution and execution in one of these controlled environments they must acquire a certificate from an appropriate CA, typically a large commercial CA, and in the process they usually have their identity verified using out-of-band mechanisms such as a combination of phone call, validation of their legal entity through government and commercial databases, etc., similar to the high assurance SSL certificate vetting process, though often there are additional specific requirements imposed on would-be developers/publishers.
Once the identity has been validated they are issued an identity certificate they can use to sign their software; generally the software signed by the developer or publisher's identity certificate is not distributed but rather it is submitted to processor to possibly test or profile the content before generating an authorization certificate which is unique to the particular software release. That certificate is then used with an ephemeral asymmetric key-pair to sign the software as the last step of preparation for distribution. There are many advantages to separating the identity and authorization certificates especially relating to risk mitigation of new content being accepted into the system and key management as well as recovery from errant software which can be used as attack vectors.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, 2001, McGraw-Hill/Osborne, page 540.
http://en.wikipedia.org/wiki/Attribute_certificate
http://en.wikipedia.org/wiki/Public_key_certificate
In a typical public key infrastructure (PKI) scheme, the signature will be of a certificate authority (CA). In a web of trust scheme, the signature is of either the user (a self-signed certificate) or other users ("endorsements"). In either case, the signatures on a certificate are attestations by the certificate signer that the identity information and the public key belong together.
In computer security, an authorization certificate (also known as an attribute certificate) is a digital document that describes a written permission from the issuer to use a service or a resource that the issuer controls or has access to use. The permission can be delegated.
Some people constantly confuse PKCs and ACs. An analogy may make the distinction clear. A PKC can be considered to be like a passport: it identifies the holder, tends to last for a long time, and should not be trivial to obtain. An AC is more like an entry visa: it is typically issued by a different authority and does not last for as long a time. As acquiring an entry visa typically requires presenting a passport, getting a visa can be a simpler process.
A real life example of this can be found in the mobile software deployments by large service providers and are typically applied to platforms such as Microsoft Smartphone (and related), Symbian OS, J2ME, and others.
In each of these systems a mobile communications service provider may customize the mobile terminal client distribution (ie. the mobile phone operating system or application environment) to include one or more root certificates each associated with a set of capabilities or permissions such as "update firmware", "access address book", "use radio interface", and the most basic one, "install and execute". When a developer wishes to enable distribution and execution in one of these controlled environments they must acquire a certificate from an appropriate CA, typically a large commercial CA, and in the process they usually have their identity verified using out-of-band mechanisms such as a combination of phone call, validation of their legal entity through government and commercial databases, etc., similar to the high assurance SSL certificate vetting process, though often there are additional specific requirements imposed on would-be developers/publishers.
Once the identity has been validated they are issued an identity certificate they can use to sign their software; generally the software signed by the developer or publisher's identity certificate is not distributed but rather it is submitted to processor to possibly test or profile the content before generating an authorization certificate which is unique to the particular software release. That certificate is then used with an ephemeral asymmetric key-pair to sign the software as the last step of preparation for distribution. There are many advantages to separating the identity and authorization certificates especially relating to risk mitigation of new content being accepted into the system and key management as well as recovery from errant software which can be used as attack vectors.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, 2001, McGraw-Hill/Osborne, page 540.
http://en.wikipedia.org/wiki/Attribute_certificate
http://en.wikipedia.org/wiki/Public_key_certificate
Question 157
A weak key of an encryption algorithm has which of the following properties?
Correct Answer: B
Question 158
Which of the following criteria ensures information is protected relative to its importance to the organization?
Correct Answer: B
The criteria that ensures information is protected relative to its importance to the organization is legal requirements, value, criticality, and sensitivity to unauthorized disclosure or modification. These criteria are the factors or the elements that determine the level or the degree of protection that the information needs or deserves, based on its importance or significance to the organization. These criteria are used to classify or categorize the information into different levels or categories, such as public, internal, confidential, or secret, and to apply or enforce the appropriate security controls or measures, such as encryption, access control, or backup, to protect the information from threats or risks, such as theft, loss, or corruption. Legal requirements are the criteria that define the protection of the information based on the legal, regulatory, or contractual obligations or standards that the organization must comply with, such as GDPR, HIPAA, or PCI DSS. Value is the criterion that defines the protection of the information based on the worth or the benefit that the information provides or generates for the organization, such as revenue, profit, or reputation. Criticality is the criterion that defines the protection of the information based on the impact or the consequence that the unavailability or the disruption of the information would cause to the organization, such as loss, damage, or harm. Sensitivity is the criterion that defines the protection of the information based on the exposure or the vulnerability of the information to unauthorized or malicious access, modification, or disclosure, such as confidentiality, integrity, or privacy. The value of the data to the organization's senior management, legal requirements determined by the organization headquarters' location, or organizational stakeholders, with classification approved by the management board are not the criteria that ensure information is protected relative to its importance to the organization, as they are not the factors or the elements that determine the level or the degree of protection that the information needs or deserves, based on its importance or significance to the organization. The value of the data to the organization's senior management is not a criterion that ensures information is protected relative to its importance to the organization, as it is a subjective or biased measure of the importance or the significance of the information, and it may not reflect the actual or the objective worth or benefit of the information for the organization. Legal requirements determined by the organization headquarters' location is not a criterion that ensures information is protected relative to its importance to the organization, as it is a limited or a narrow scope of the legal, regulatory, or contractual obligations or standards that the organization must comply with, and it may not cover or address the legal requirements of other locations or jurisdictions where the organization operates or conducts business.
Organizational stakeholders, with classification approved by the management board is not a criterion that ensures information is protected relative to its importance to the organization, as it is a process or a method of classifying or categorizing the information, and not a factor or an element that determines the level or the degree of protection that the information needs or deserves, based on its importance or significance to the organization. References: Official (ISC)2 Guide to the CISSP CBK, Fifth Edition, Chapter 1: Security and Risk Management, page 32.
Organizational stakeholders, with classification approved by the management board is not a criterion that ensures information is protected relative to its importance to the organization, as it is a process or a method of classifying or categorizing the information, and not a factor or an element that determines the level or the degree of protection that the information needs or deserves, based on its importance or significance to the organization. References: Official (ISC)2 Guide to the CISSP CBK, Fifth Edition, Chapter 1: Security and Risk Management, page 32.
Question 159
Which of the following is the top barrier for companies to adopt cloud technology?
Correct Answer: D
The top barrier for companies to adopt cloud technology is security. Cloud technology is a technology that enables the delivery or consumption of computing resources or services over the internet, such as servers, storage, databases, networks, applications, or analytics. Cloud technology can offer many benefits to companies, such as cost reduction, scalability, flexibility, or efficiency. However, cloud technology also poses many challenges or risks to companies, such as security, compliance, performance, or reliability. Security is the top barrier for companies to adopt cloud technology, as it is the most critical and complex issue that companies face when moving to or using the cloud. Security is the barrier that prevents or hinders the companies from adopting cloud technology, as it involves the protection of the data, the systems, and the users from unauthorized or malicious access, modification, or disruption, and the compliance with the legal, regulatory, or contractual obligations. Security is the barrier that requires or demands the most attention, effort, or resources from the companies when adopting cloud technology, as it involves the assessment, evaluation, or verification of the security posture, capabilities, or controls of the cloud provider, the cloud service, and the cloud customer, and the implementation, management, or monitoring of the security policies, procedures, or measures for the cloud environment. Migration period, data integrity, or cost are not the top barriers for companies to adopt cloud technology, as they are not the most critical or complex issues that companies face when moving to or using the cloud. Migration period is the time or the duration that it takes for the companies to transfer or migrate their data, systems, or applications from their on-premises or legacy environment to the cloud environment. Data integrity is the quality or the condition of the data that ensures that the data is accurate, complete, or consistent, and that the data is not corrupted, altered, or lost. Cost is the amount or the value of the money or the resources that the companies spend or invest in adopting or using the cloud technology. Migration period, data integrity, or cost are important or relevant issues that companies face when adopting cloud technology, but they are not the top barriers, as they are not the most critical or complex issues, and they can be addressed or resolved by using proper planning, testing, or optimization techniques or methods. References: Official (ISC)2 Guide to the CISSP CBK, Fifth Edition, Chapter 4: Communication and Network Security, page 287.
Question 160
Which of the following is used in database information security to hide information?
Correct Answer: B
Explanation/Reference:
Explanation:
Polyinstantiation is a process of interactively producing more detailed versions of objects by populating variables with different values or other variables. It is often used to prevent inference attacks by hiding information.
Incorrect Answers:
A: Inheritance is not used to hide database information. Within object orientation programming inheritance is a mechanism for code reuse and to allow independent extensions of the original software via public classes and interfaces.
C: Polymorphism is when different objects are given the same input and react differently. Polymorphism is not a way to hide database security information.
D: Delegation is a concept within object-oriented programming. Delegation does not concern information security for database.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 1136, 1186
http://en.wikipedia.org/wiki/Polyinstantiation
https://en.wikipedia.org/wiki/Polymorphism_(computer_science)
Explanation:
Polyinstantiation is a process of interactively producing more detailed versions of objects by populating variables with different values or other variables. It is often used to prevent inference attacks by hiding information.
Incorrect Answers:
A: Inheritance is not used to hide database information. Within object orientation programming inheritance is a mechanism for code reuse and to allow independent extensions of the original software via public classes and interfaces.
C: Polymorphism is when different objects are given the same input and react differently. Polymorphism is not a way to hide database security information.
D: Delegation is a concept within object-oriented programming. Delegation does not concern information security for database.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, pp. 1136, 1186
http://en.wikipedia.org/wiki/Polyinstantiation
https://en.wikipedia.org/wiki/Polymorphism_(computer_science)
- Other Version
- 1518ISC.CISSP.v2026-04-20.q414
- 10508ISC.CISSP.v2024-12-05.q999
- 9376ISC.CISSP.v2024-09-21.q999
- 9248ISC.CISSP.v2023-07-03.q999
- 3251ISC.CISSP.v2023-04-20.q206
- 7370ISC.CISSP.v2022-09-06.q331
- 8205ISC.CISSP.v2022-08-27.q376
- 13983ISC.CISSP.v2022-04-07.q650
- 145ISC.Fast2test.CISSP.v2021-12-03.by.osborn.827q.pdf
- 23501ISC.CISSP.v2021-10-01.q353
- Latest Upload
- 169MedicalProfessional.CCM.v2026-08-20.q62
- 211Cisco.300-610.v2026-08-19.q170
- 260CompTIA.PT0-003.v2026-08-19.q179
- 159Databricks.Databricks-Generative-AI-Engineer-Associate.v2026-08-18.q40
- 159SAP.C_CR125_2601.v2026-08-17.q28
- 212Salesforce.Field-Service-Consultant.v2026-08-17.q134
- 175Oracle.1Z0-1170.v2026-08-16.q64
- 185Oracle.1Z1-1170.v2026-08-16.q64
- 206Juniper.JN0-336.v2026-08-13.q60
- 441EMC.NCP-AII.v2026-08-13.q200
