Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career.  Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. 

 In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.

 CISSP Exam Questions:


An edict stating that all evidence be labeled with information about who secured it and who validated it is called _______________.

  • A. CERT
  • B. Chain of custody
  • C. Direct evidence
  • D. Incident response policy


A thorough and accurate chain of custody record is critical in an investigation process. The process includes labeling physical evidence and compiling a complete history of how evidence was collected, analyzed, transported and preserved.

From <https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11>


The golden arches of McDonald's are protected under what intellectual property law?

  • A. Trademark
  • B. Trade secret
  • C. Logo protection
  • D. Copyright

 CORRECT ANSWER - A. Trademark 

Trademarks can exist in a variety of forms -- a word, shape, graphic or phrase. The determining factor is whether or not it alone represents the larger organization in the eyes of the outside world. McDonald's, for example, is known worldwide for its golden arches. This symbol is an identifier of the restaurant and thus falls under trademark law.

From <https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11>


Which is not true of the Federal Sentencing Guidelines, which were enacted in 1991?

  • A. Developed specifically to address white-collar crimes
  • B. Detailed the specific responsibilities of senior executives within companies
  • C. Established a maximum fine of $100 million
  • D. Encouraged the implementation of security policies and a security program

 CORRECT ANSWER - C. Established a maximum fine of $100 million 

Because laws and sentencing guidelines were not addressing white-collar crimes related to technology, the Federal Sentencing Guidelines were developed. These guidelines targeted the assumed responsibilities of senior executives and imposed maximum fines of $290 million per instance. However, these fines could be avoided if companies could prove proper due diligence and due care, and the existence of company-wide security policies and programs.

 From <https://searchsecurity.techtarget.com/quiz/CISSP-Domain-8-quiz-Law-Investigations-and-Ethics?q0=1&q1=0&q2=2&q3=1&q4=1&q5=1&q6=2&q7=0&q8=2&q9=0&q10=1&q11=3&q12=0&q13=3&q14=2&x=69&y=11>

