Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials SSCP Questions and answers with ValidTests

Exam SSCP All Questions
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam

Viewing page 6 out of 14 pages
Viewing questions 101-120 out of questions
Questions # 101:

Which type of password provides maximum security because a new password is required for each new log-on?

Options:

A.

One-time or dynamic password

B.

Congnitive password

C.

Static password

D.

Passphrase

Expert Solution
Questions # 102:

Which of the following statements relating to the Bell-LaPadula security model is FALSE (assuming the Strong Star property is not being used) ?

Options:

A.

A subject is not allowed to read up.

B.

The property restriction can be escaped by temporarily downgrading a high level subject.

C.

A subject is not allowed to read down.

D.

It is restricted to confidentiality.

Expert Solution
Questions # 103:

Which access control model achieves data integrity through well-formed transactions and separation of duties?

Options:

A.

Clark-Wilson model

B.

Biba model

C.

Non-interference model

D.

Sutherland model

Expert Solution
Questions # 104:

What is the difference between Access Control Lists (ACLs) and Capability Tables?

Options:

A.

Access control lists are related/attached to a subject whereas capability tables are related/attached to an object.

B.

Access control lists are related/attached to an object whereas capability tables are related/attached to a subject.

C.

Capability tables are used for objects whereas access control lists are used for users.

D.

They are basically the same.

Expert Solution
Questions # 105:

Which of the following can best eliminate dial-up access through a Remote Access Server as a hacking vector?

Options:

A.

Using a TACACS+ server.

B.

Installing the Remote Access Server outside the firewall and forcing legitimate users to authenticate to the firewall.

C.

Setting modem ring count to at least 5.

D.

Only attaching modems to non-networked hosts.

Expert Solution
Questions # 106:

Which of following is not a service provided by AAA servers (Radius, TACACS and DIAMETER)?

Options:

A.

Authentication

B.

Administration

C.

Accounting

D.

Authorization

Expert Solution
Questions # 107:

The end result of implementing the principle of least privilege means which of the following?

Options:

A.

Users would get access to only the info for which they have a need to know

B.

Users can access all systems.

C.

Users get new privileges added when they change positions.

D.

Authorization creep.

Expert Solution
Questions # 108:

What is the main concern with single sign-on?

Options:

A.

Maximum unauthorized access would be possible if a password is disclosed.

B.

The security administrator's workload would increase.

C.

The users' password would be too hard to remember.

D.

User access rights would be increased.

Expert Solution
Questions # 109:

RADIUS incorporates which of the following services?

Options:

A.

Authentication server and PIN codes.

B.

Authentication of clients and static passwords generation.

C.

Authentication of clients and dynamic passwords generation.

D.

Authentication server as well as support for Static and Dynamic passwords.

Expert Solution
Questions # 110:

Which of the following is related to physical security and is not considered a technical control?

Options:

A.

Access control Mechanisms

B.

Intrusion Detection Systems

C.

Firewalls

D.

Locks

Expert Solution
Questions # 111:

Which of the following monitors network traffic in real time?

Options:

A.

network-based IDS

B.

host-based IDS

C.

application-based IDS

D.

firewall-based IDS

Expert Solution
Questions # 112:

Who can best decide what are the adequate technical security controls in a computer-based application system in regards to the protection of the data being used, the criticality of the data, and it's sensitivity level ?

Options:

A.

System Auditor

B.

Data or Information Owner

C.

System Manager

D.

Data or Information user

Expert Solution
Questions # 113:

If an organization were to monitor their employees' e-mail, it should not:

Options:

A.

Monitor only a limited number of employees.

B.

Inform all employees that e-mail is being monitored.

C.

Explain who can read the e-mail and how long it is backed up.

D.

Explain what is considered an acceptable use of the e-mail system.

Expert Solution
Questions # 114:

In the process of gathering evidence from a computer attack, a system administrator took a series of actions which are listed below. Can you identify which one of these actions has compromised the whole evidence collection process?

Options:

A.

Using a write blocker

B.

Made a full-disk image

C.

Created a message digest for log files

D.

Displayed the contents of a folder

Expert Solution
Questions # 115:

Which of the following are additional terms used to describe knowledge-based IDS and behavior-based IDS?

Options:

A.

signature-based IDS and statistical anomaly-based IDS, respectively

B.

signature-based IDS and dynamic anomaly-based IDS, respectively

C.

anomaly-based IDS and statistical-based IDS, respectively

D.

signature-based IDS and motion anomaly-based IDS, respectively.

Expert Solution
Questions # 116:

Which of the following questions are least likely to help in assessing controls covering audit trails?

Options:

A.

Does the audit trail provide a trace of user actions?

B.

Are incidents monitored and tracked until resolved?

C.

Is access to online logs strictly controlled?

D.

Is there separation of duties between security personnel who administer the access control function and those who administer the audit trail?

Expert Solution
Questions # 117:

Why would anomaly detection IDSs often generate a large number of false positives?

Options:

A.

Because they can only identify correctly attacks they already know about.

B.

Because they are application-based are more subject to attacks.

C.

Because they can't identify abnormal behavior.

D.

Because normal patterns of user and system behavior can vary wildly.

Expert Solution
Questions # 118:

Knowledge-based Intrusion Detection Systems (IDS) are more common than:

Options:

A.

Network-based IDS

B.

Host-based IDS

C.

Behavior-based IDS

D.

Application-Based IDS

Expert Solution
Questions # 119:

Which of the following types of Intrusion Detection Systems uses behavioral characteristics of a system’s operation or network traffic to draw conclusions on whether the traffic represents a risk to the network or host?

Options:

A.

Network-based ID systems.

B.

Anomaly Detection.

C.

Host-based ID systems.

D.

Signature Analysis.

Expert Solution
Questions # 120:

Network-based Intrusion Detection systems:

Options:

A.

Commonly reside on a discrete network segment and monitor the traffic on that network segment.

B.

Commonly will not reside on a discrete network segment and monitor the traffic on that network segment.

C.

Commonly reside on a discrete network segment and does not monitor the traffic on that network segment.

D.

Commonly reside on a host and and monitor the traffic on that specific host.

Expert Solution
Viewing page 6 out of 14 pages
Viewing questions 101-120 out of questions