exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 17 discussion

Actual exam question from ISC's CISSP
Question #: 17
Topic #: 1
[All CISSP Questions]

An organization is looking to include mobile devices in its asset management system for better tracking. In which system tier of the reference architecture would mobile devices be tracked?

  • A. 0
  • B. 1
  • C. 2
  • D. 3
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mark9999
Highly Voted 2 years, 4 months ago
Selected Answer: B
Although I went for B: I assume they're talking about the IT Asset Management(ITAM) Tiers of which there are three: So there is no Tier 0 Tier 1 - Asset Data Collection - method to inventory every software application and virtual OS that runs on the hardware you have in your inventory Tier 2 - Asset Data Intelligence - normalize the information, to map the assets to relevant information, and to link the assets to their contracts, projects, departments, and people. Tier 3 - Asset Lifecycle management - processes that control how you purchase, procure, and dispose of IT assets. This includes virtual devices and software, along with the associated software licenses. NIST has it as Tier 1 - Reporting, Analytics, Data storage Tier 2 - Data collection ie location/HW/SW Tier 3 - Enterprise assets - Servers, workstations, Laptops etc So for tracking mobile devices, according to these it could be Tier 3 as the diagrams seem to work backwards to what you would expect (devices at level 1 etc)
upvoted 16 times
jackdryan
1 year, 10 months ago
D is correct
upvoted 3 times
...
...
iRyae
Most Recent 1 week, 1 day ago
Selected Answer: B
There is no mention of NIST tiers, so assuming ITAM tiers, the answer is B. Mobile devices would be tracked starting from ITAM Tier 1 (for basic discovery) and continue through Tier 2 (for ongoing management and lifecycle tracking).
upvoted 1 times
...
5daa92f
1 month, 3 weeks ago
Selected Answer: A
Explanation: In reference architectures, Tier 0 typically represents the physical layer of the architecture, which includes devices such as sensors, actuators, and mobile devices. This layer is responsible for directly interacting with the physical environment and providing data to higher tiers for processing and analysis. For mobile devices, they are considered part of the asset layer that needs to be tracked and managed, making them belong to Tier 0 in most reference architectures. Breakdown of Tiers: Tier 0: Physical devices and endpoints (e.g., mobile devices, sensors, and other assets). Tier 1: Edge processing, where data from Tier 0 is collected, processed, or aggregated locally. Tier 2: Centralized systems for data management and processing, like enterprise servers. Tier 3: Business and analytics applications that leverage processed data for decision-making. Tracking mobile devices in an asset management system starts at the Tier 0 level, where their identification, status, and usage data are collected.
upvoted 1 times
...
attesco
2 months ago
Selected Answer: D
You guys should stop confusing people. The Right Answer is D. Read the NIST pub below
upvoted 1 times
...
Tuhaar
2 months ago
Selected Answer: D
Tier 3 as per NIST: Explanation: According to the NIST SP 1800-5 Vol B guidelines, Tier 3 is where mobile devices are actively tracked and managed using Mobile Device Management (MDM) and Enterprise Mobility Management (EMM) systems. This tier is responsible for managing the devices, monitoring their status, ensuring compliance with security policies, and making real-time decisions regarding their security posture.
upvoted 2 times
...
Ravnit
2 months, 1 week ago
Selected Answer: B
n the context of a reference architecture for tracking assets, mobile devices would typically be tracked in System Tier 1. This tier focuses on managing all end-user devices, including mobile devices, ensuring they are properly configured, secured, and monitored. So B is the right response
upvoted 1 times
...
Moose01
2 months, 3 weeks ago
Selected Answer: B
Per Google search: In a typical reference architecture, mobile devices would be tracked within the "Access" or "Presentation" tier as this layer represents the user interface and directly interacts with end-user devices like smartphones and tablets, where data is accessed and displayed. Key points about the access tier: Direct user interaction: This tier is where users interact with applications through their mobile devices, sending requests and receiving responses. Data presentation: The access tier is responsible for presenting data in a user-friendly format on the mobile device screen. Security considerations: Due to the direct user interaction, this tier requires robust security measures to protect sensitive data on mobile devices.
upvoted 1 times
...
Tuhaar
2 months, 4 weeks ago
Selected Answer: B
According to the NIST (National Institute of Standards and Technology) reference architecture, mobile devices would be tracked in Tier 1. Here's a brief overview of the tiers: Tier 0: This tier typically includes the physical infrastructure, such as hardware and network components. Tier 1: This tier includes the platform infrastructure, which encompasses operating systems, middleware, and mobile devices. Tier 2: This tier focuses on the application infrastructure, including applications and software services. Tier 3: This tier involves the business processes and information systems that support organizational operations.
upvoted 2 times
...
Fouad777
3 months, 1 week ago
Answer id B Tier 0: Facilities, power systems, and environmental controls. Tier 1: Hardware and software supporting IT infrastructure. Tier 2: Shared services like email, directories, and collaboration tools. Tier 3: Business-critical systems and databases.
upvoted 1 times
...
nuggetbutts
3 months, 2 weeks ago
Selected Answer: D
NIST ITAM Reference Architecture clearly states these would fall into Tier 3 systems. Tier 3 - Enterprise assets - Servers, workstations, Laptops etc
upvoted 2 times
...
M_MUN17
4 months, 2 weeks ago
The correct answer is A. 0. In a typical reference architecture, Tier 0 refers to the physical devices or endpoints, including mobile devices, that interact directly with the environment. Mobile devices, as physical assets, would be tracked in this tier because they represent the lowest level in the architecture, where the hardware and direct interfaces with the system occur. Tiers 1, 2, and 3 typically deal with higher levels of abstraction, such as applications, data processing, and overall system management.
upvoted 2 times
...
celomomo
4 months, 3 weeks ago
Context because I see people quoting different tiers. This is CISSP Sysytem Tier architecture reference: The protection ring model is a security architecture model that uses layers to control code execution and access in an operating system: Layer 0: The most trusted layer, where the operating system kernel resides Layer 1: Contains nonprivileged parts of the operating system Layer 2: Contains I/O drivers, low-level operations, and utilities Layer 3: Contains applications and processes
upvoted 1 times
...
celomomo
4 months, 3 weeks ago
Selected Answer: C
Tier 2: This tier encompasses end-user devices, such as desktops, laptops, and mobile devices. These are the devices used daily by the end users to perform their tasks
upvoted 2 times
...
Law88
5 months ago
Selected Answer: B
System tier 1 is responsible for identifying and discovering the assets that are owned, leased, or used by the organization, and collecting information about their attributes, location, status, and configuration. System tier 1 can use various methods and technologies to identify and discover assets, such as barcodes, QR codes, RFID tags, GPS, Bluetooth, Wi-Fi, etc.
upvoted 1 times
...
InclusiveSTEAM
5 months ago
B Mobile devices would be tracked in Tier 1 of the asset management reference architecture. Tier 1 focuses on the hardware and software assets that support the overall IT environment. This includes things like servers, workstations, network devices, and mobile devices that provide compute infrastructure and platforms. Tier 0 contains facilities, power systems and environmental controls. Tier 2 consists of shared services like directories, email systems, and collaboration tools. Tier 3 comprises core line of business systems and databases.
upvoted 1 times
...
tsummey
5 months, 2 weeks ago
Selected Answer: D
Tier 3 (Data Tier) Asset management systems store and manage data related to devices, including mobile devices. The Data Tier is responsible for data storage and management—this is where records of all assets (including mobile devices) are kept, tracked, and updated. Mobile devices, in this case, are considered assets whose information (e.g., device ID, status, configuration, etc.) needs to be stored, queried, and updated regularly. The system's Data Tier handles this critical function. Tier 1 (the presentation tier) does not store or manage the actual asset data—it just displays it to the user.
upvoted 1 times
...
Verm12
5 months, 3 weeks ago
Selected Answer: D
As per NIST 80SP1800-5b IS ASSET MANAGEMENT. It discusses the Reference architecture and how to implement such. Tier 2 includes the sensors and independent systems that feed data into the enterprise ITAM system. Tier 2 systems include passive and active collection sensor and agents. Tier 1 is the enterprise ITAM system that provides the aggregation of data from all Tier 2 systems into business and security intelligence. Tier 3 is composed of enterprise assets themselves. Tier 3 is made up of all of the assets being tracked including hardware, software, and virtual machines. To get this answer correct you must know and have read the NIST 1800 -5b. Link below.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago