Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials SSCP Questions and answers with ValidTests

Exam SSCP All Questions
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam

Viewing page 5 out of 14 pages
Viewing questions 81-100 out of questions
Questions # 81:

Which of the following is the most reliable authentication method for remote access?

Options:

A.

Variable callback system

B.

Synchronous token

C.

Fixed callback system

D.

Combination of callback and caller ID

Expert Solution
Questions # 82:

Which of the following classes is the first level (lower) defined in the TCSEC (Orange Book) as mandatory protection?

Options:

A.

B

B.

A

C.

C

D.

D

Expert Solution
Questions # 83:

What is called the use of technologies such as fingerprint, retina, and iris scans to authenticate the individuals requesting access to resources?

Options:

A.

Micrometrics

B.

Macrometrics

C.

Biometrics

D.

MicroBiometrics

Expert Solution
Questions # 84:

A network-based vulnerability assessment is a type of test also referred to as:

Options:

A.

An active vulnerability assessment.

B.

A routing vulnerability assessment.

C.

A host-based vulnerability assessment.

D.

A passive vulnerability assessment.

Expert Solution
Questions # 85:

Which type of control is concerned with avoiding occurrences of risks?

Options:

A.

Deterrent controls

B.

Detective controls

C.

Preventive controls

D.

Compensating controls

Expert Solution
Questions # 86:

What kind of certificate is used to validate a user identity?

Options:

A.

Public key certificate

B.

Attribute certificate

C.

Root certificate

D.

Code signing certificate

Expert Solution
Questions # 87:

Which of the following security controls might force an operator into collusion with personnel assigned organizationally within a different function in order to gain access to unauthorized data?

Options:

A.

Limiting the local access of operations personnel

B.

Job rotation of operations personnel

C.

Management monitoring of audit logs

D.

Enforcing regular password changes

Expert Solution
Questions # 88:

What is Kerberos?

Options:

A.

A three-headed dog from the egyptian mythology.

B.

A trusted third-party authentication protocol.

C.

A security model.

D.

A remote authentication dial in user server.

Expert Solution
Questions # 89:

Which one of the following factors is NOT one on which Authentication is based?

Options:

A.

Type 1. Something you know, such as a PIN or password

B.

Type 2. Something you have, such as an ATM card or smart card

C.

Type 3. Something you are (based upon one or more intrinsic physical or behavioral traits), such as a fingerprint or retina scan

D.

Type 4. Something you are, such as a system administrator or security administrator

Expert Solution
Questions # 90:

Controls to keep password sniffing attacks from compromising computer systems include which of the following?

Options:

A.

static and recurring passwords.

B.

encryption and recurring passwords.

C.

one-time passwords and encryption.

D.

static and one-time passwords.

Expert Solution
Questions # 91:

A timely review of system access audit records would be an example of which of the basic security functions?

Options:

A.

avoidance.

B.

deterrence.

C.

prevention.

D.

detection.

Expert Solution
Questions # 92:

The control measures that are intended to reveal the violations of security policy using software and hardware are associated with:

Options:

A.

Preventive/physical

B.

Detective/technical

C.

Detective/physical

D.

Detective/administrative

Expert Solution
Questions # 93:

Which of the following is an example of a passive attack?

Options:

A.

Denying services to legitimate users

B.

Shoulder surfing

C.

Brute-force password cracking

D.

Smurfing

Expert Solution
Questions # 94:

In which of the following model are Subjects and Objects identified and the permissions applied to each subject/object combination are specified. Such a model can be used to quickly summarize what permissions a subject has for various system objects.

Options:

A.

Access Control Matrix model

B.

Take-Grant model

C.

Bell-LaPadula model

D.

Biba model

Expert Solution
Questions # 95:

In biometric identification systems, at the beginning, it was soon apparent that truly positive identification could only be based on physical attributes of a person. This raised the necessity of answering 2 questions :

Options:

A.

what was the sex of a person and his age

B.

what part of body to be used and how to accomplish identification that is viable

C.

what was the age of a person and his income level

D.

what was the tone of the voice of a person and his habits

Expert Solution
Questions # 96:

Which of the following is most relevant to determining the maximum effective cost of access control?

Options:

A.

the value of information that is protected

B.

management's perceptions regarding data importance

C.

budget planning related to base versus incremental spending.

D.

the cost to replace lost data

Expert Solution
Questions # 97:

What is called an automated means of identifying or authenticating the identity of a living person based on physiological or behavioral characteristics?

Options:

A.

Biometrics

B.

Micrometrics

C.

Macrometrics

D.

MicroBiometrics

Expert Solution
Questions # 98:

Which of the following access control models requires defining classification for objects?

Options:

A.

Role-based access control

B.

Discretionary access control

C.

Identity-based access control

D.

Mandatory access control

Expert Solution
Questions # 99:

What are the components of an object's sensitivity label?

Options:

A.

A Classification Set and a single Compartment.

B.

A single classification and a single compartment.

C.

A Classification Set and user credentials.

D.

A single classification and a Compartment Set.

Expert Solution
Questions # 100:

Single Sign-on (SSO) is characterized by which of the following advantages?

Options:

A.

Convenience

B.

Convenience and centralized administration

C.

Convenience and centralized data administration

D.

Convenience and centralized network administration

Expert Solution
Viewing page 5 out of 14 pages
Viewing questions 81-100 out of questions