Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials SSCP Questions and answers with ValidTests

Exam SSCP All Questions
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam

Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions
Questions # 21:

In an organization, an Information Technology security function should:

Options:

A.

Be a function within the information systems function of an organization.

B.

Report directly to a specialized business unit such as legal, corporate security or insurance.

C.

Be lead by a Chief Security Officer and report directly to the CEO.

D.

Be independent but report to the Information Systems function.

Expert Solution
Questions # 22:

Who is ultimately responsible for the security of computer based information systems within an organization?

Options:

A.

The tech support team

B.

The Operation Team.

C.

The management team.

D.

The training team.

Expert Solution
Questions # 23:

An area of the Telecommunications and Network Security domain that directly affects the Information Systems Security tenet of Availability can be defined as:

Options:

A.

Netware availability

B.

Network availability

C.

Network acceptability

D.

Network accountability

Expert Solution
Questions # 24:

What is the most secure way to dispose of information on a CD-ROM?

Options:

A.

Sanitizing

B.

Physical damage

C.

Degaussing

D.

Physical destruction

Expert Solution
Questions # 25:

In Mandatory Access Control, sensitivity labels attached to object contain what information?

Options:

A.

The item's classification

B.

The item's classification and category set

C.

The item's category

D.

The items's need to know

Expert Solution
Questions # 26:

What can be defined as a table of subjects and objects indicating what actions individual subjects can take upon individual objects?

Options:

A.

A capacity table

B.

An access control list

C.

An access control matrix

D.

A capability table

Expert Solution
Questions # 27:

Which division of the Orange Book deals with discretionary protection (need-to-know)?

Options:

A.

D

B.

C

C.

B

D.

A

Expert Solution
Questions # 28:

Which of the following exemplifies proper separation of duties?

Options:

A.

Operators are not permitted modify the system time.

B.

Programmers are permitted to use the system console.

C.

Console operators are permitted to mount tapes and disks.

D.

Tape operators are permitted to use the system console.

Expert Solution
Questions # 29:

Which of the following is not a preventive operational control?

Options:

A.

Protecting laptops, personal computers and workstations.

B.

Controlling software viruses.

C.

Controlling data media access and disposal.

D.

Conducting security awareness and technical training.

Expert Solution
Questions # 30:

Which of the following is a disadvantage of a statistical anomaly-based intrusion detection system?

Options:

A.

it may truly detect a non-attack event that had caused a momentary anomaly in the system.

B.

it may falsely detect a non-attack event that had caused a momentary anomaly in the system.

C.

it may correctly detect a non-attack event that had caused a momentary anomaly in the system.

D.

it may loosely detect a non-attack event that had caused a momentary anomaly in the system.

Expert Solution
Questions # 31:

Which of the following tools is less likely to be used by a hacker?

Options:

A.

l0phtcrack

B.

Tripwire

C.

OphCrack

D.

John the Ripper

Expert Solution
Questions # 32:

If any server in the cluster crashes, processing continues transparently, however, the cluster suffers some performance degradation. This implementation is sometimes called a:

Options:

A.

server farm

B.

client farm

C.

cluster farm

D.

host farm

Expert Solution
Questions # 33:

What is called an attack where the attacker spoofs the source IP address in an ICMP ECHO broadcast packet so it seems to have originated at the victim's system, in order to flood it with REPLY packets?

Options:

A.

SYN Flood attack

B.

Smurf attack

C.

Ping of Death attack

D.

Denial of Service (DOS) attack

Expert Solution
Questions # 34:

Which layer of the OSI/ISO model handles physical addressing, network topology, line discipline, error notification, orderly delivery of frames, and optional flow control?

Options:

A.

Physical

B.

Data link

C.

Network

D.

Session

Expert Solution
Questions # 35:

Which of the following is NOT an advantage that TACACS+ has over TACACS?

Options:

A.

Event logging

B.

Use of two-factor password authentication

C.

User has the ability to change his password

D.

Ability for security tokens to be resynchronized

Expert Solution
Questions # 36:

What best describes a scenario when an employee has been shaving off pennies from multiple accounts and depositing the funds into his own bank account?

Options:

A.

Data fiddling

B.

Data diddling

C.

Salami techniques

D.

Trojan horses

Expert Solution
Questions # 37:

Which of the following BEST describes a function relying on a shared secret key that is used along with a hashing algorithm to verify the integrity of the communication content as well as the sender?

Options:

A.

Message Authentication Code - MAC

B.

PAM - Pluggable Authentication Module

C.

NAM - Negative Acknowledgement Message

D.

Digital Signature Certificate

Expert Solution
Questions # 38:

Which of the following can best define the "revocation request grace period"?

Options:

A.

The period of time allotted within which the user must make a revocation request upon a revocation reason

B.

Minimum response time for performing a revocation by the CA

C.

Maximum response time for performing a revocation by the CA

D.

Time period between the arrival of a revocation request and the publication of the revocation information

Expert Solution
Questions # 39:

Which of the following is defined as an Internet, IPsec, key-establishment protocol, partly based on OAKLEY, that is intended for putting in place authenticated keying material for use with ISAKMP and for other security associations?

Options:

A.

Internet Key exchange (IKE)

B.

Security Association Authentication Protocol (SAAP)

C.

Simple Key-management for Internet Protocols (SKIP)

D.

Key Exchange Algorithm (KEA)

Expert Solution
Questions # 40:

What is the length of an MD5 message digest?

Options:

A.

128 bits

B.

160 bits

C.

256 bits

D.

varies depending upon the message size.

Expert Solution
Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions