Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials SSCP Questions and answers with ValidTests

Exam SSCP All Questions
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam

Viewing page 4 out of 14 pages
Viewing questions 61-80 out of questions
Questions # 61:

What are the three FUNDAMENTAL principles of security?

Options:

A.

Accountability, confidentiality and integrity

B.

Confidentiality, integrity and availability

C.

Integrity, availability and accountability

D.

Availability, accountability and confidentiality

Expert Solution
Questions # 62:

What is called the formal acceptance of the adequacy of a system's overall security by the management?

Options:

A.

Certification

B.

Acceptance

C.

Accreditation

D.

Evaluation

Expert Solution
Questions # 63:

Which of the following is not a responsibility of an information (data) owner?

Options:

A.

Determine what level of classification the information requires.

B.

Periodically review the classification assignments against business needs.

C.

Delegate the responsibility of data protection to data custodians.

D.

Running regular backups and periodically testing the validity of the backup data.

Expert Solution
Questions # 64:

Which property ensures that only the intended recipient can access the data and nobody else?

Options:

A.

Confidentiality

B.

Capability

C.

Integrity

D.

Availability

Expert Solution
Questions # 65:

Which of the following phases of a software development life cycle normally addresses Due Care and Due Diligence?

Options:

A.

Implementation

B.

System feasibility

C.

Product design

D.

Software plans and requirements

Expert Solution
Questions # 66:

When it comes to magnetic media sanitization, what difference can be made between clearing and purging information?

Options:

A.

Clearing completely erases the media whereas purging only removes file headers, allowing the recovery of files.

B.

Clearing renders information unrecoverable by a keyboard attack and purging renders information unrecoverable against laboratory attack.

C.

They both involve rewriting the media.

D.

Clearing renders information unrecoverable against a laboratory attack and purging renders information unrecoverable to a keyboard attack.

Expert Solution
Questions # 67:

What is called a system that is capable of detecting that a fault has occurred and has the ability to correct the fault or operate around it?

Options:

A.

A fail safe system

B.

A fail soft system

C.

A fault-tolerant system

D.

A failover system

Expert Solution
Questions # 68:

Which of the following rules is least likely to support the concept of least privilege?

Options:

A.

The number of administrative accounts should be kept to a minimum.

B.

Administrators should use regular accounts when performing routine operations like reading mail.

C.

Permissions on tools that are likely to be used by hackers should be as restrictive as possible.

D.

Only data to and from critical systems and applications should be allowed through the firewall.

Expert Solution
Questions # 69:

A security evaluation report and an accreditation statement are produced in which of the following phases of the system development life cycle?

Options:

A.

project initiation and planning phase

B.

system design specification phase

C.

development & documentation phase

D.

acceptance phase

Expert Solution
Questions # 70:

Which of the following would provide the BEST stress testing environment taking under consideration and avoiding possible data exposure and leaks of sensitive data?

Options:

A.

Test environment using test data.

B.

Test environment using sanitized live workloads data.

C.

Production environment using test data.

D.

Production environment using sanitized live workloads data.

Expert Solution
Questions # 71:

Which of the following classes is defined in the TCSEC (Orange Book) as discretionary protection?

Options:

A.

C

B.

B

C.

A

D.

D

Expert Solution
Questions # 72:

An alternative to using passwords for authentication in logical or technical access control is:

Options:

A.

manage without passwords

B.

biometrics

C.

not there

D.

use of them for physical access control

Expert Solution
Questions # 73:

Which access control model was proposed for enforcing access control in government and military applications?

Options:

A.

Bell-LaPadula model

B.

Biba model

C.

Sutherland model

D.

Brewer-Nash model

Expert Solution
Questions # 74:

In which of the following security models is the subject's clearance compared to the object's classification such that specific rules can be applied to control how the subject-to-object interactions take place?

Options:

A.

Bell-LaPadula model

B.

Biba model

C.

Access Matrix model

D.

Take-Grant model

Expert Solution
Questions # 75:

Which of the following biometric parameters are better suited for authentication use over a long period of time?

Options:

A.

Iris pattern

B.

Voice pattern

C.

Signature dynamics

D.

Retina pattern

Expert Solution
Questions # 76:

When a biometric system is used, which error type deals with the possibility of GRANTING access to impostors who should be REJECTED?

Options:

A.

Type I error

B.

Type II error

C.

Type III error

D.

Crossover error

Expert Solution
Questions # 77:

Which of the following would be used to implement Mandatory Access Control (MAC)?

Options:

A.

Clark-Wilson Access Control

B.

Role-based access control

C.

Lattice-based access control

D.

User dictated access control

Expert Solution
Questions # 78:

What does the Clark-Wilson security model focus on?

Options:

A.

Confidentiality

B.

Integrity

C.

Accountability

D.

Availability

Expert Solution
Questions # 79:

Which of the following Operation Security controls is intended to prevent unauthorized intruders from internally or externally accessing the system, and to lower the amount and impact of unintentional errors that are entering the system?

Options:

A.

Detective Controls

B.

Preventative Controls

C.

Corrective Controls

D.

Directive Controls

Expert Solution
Questions # 80:

Which type of password token involves time synchronization?

Options:

A.

Static password tokens

B.

Synchronous dynamic password tokens

C.

Asynchronous dynamic password tokens

D.

Challenge-response tokens

Expert Solution
Viewing page 4 out of 14 pages
Viewing questions 61-80 out of questions