Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the ISC 2 Credentials SSCP Questions and answers with ValidTests

Exam SSCP All Questions
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam

Viewing page 8 out of 14 pages
Viewing questions 141-160 out of questions
Questions # 141:

Which of the following usually provides reliable, real-time information without consuming network or host resources?

Options:

A.

network-based IDS

B.

host-based IDS

C.

application-based IDS

D.

firewall-based IDS

Expert Solution
Questions # 142:

Which of the following best describes signature-based detection?

Options:

A.

Compare source code, looking for events or sets of events that could cause damage to a system or network.

B.

Compare system activity for the behaviour patterns of new attacks.

C.

Compare system activity, looking for events or sets of events that match a predefined pattern of events that describe a known attack.

D.

Compare network nodes looking for objects or sets of objects that match a predefined pattern of objects that may describe a known attack.

Expert Solution
Questions # 143:

Which of the following Intrusion Detection Systems (IDS) uses a database of attacks, known system vulnerabilities, monitoring current attempts to exploit those vulnerabilities, and then triggers an alarm if an attempt is found?

Options:

A.

Knowledge-Based ID System

B.

Application-Based ID System

C.

Host-Based ID System

D.

Network-Based ID System

Expert Solution
Questions # 144:

Which of the following is used to monitor network traffic or to monitor host audit logs in real time to determine violations of system security policy that have taken place?

Options:

A.

Intrusion Detection System

B.

Compliance Validation System

C.

Intrusion Management System (IMS)

D.

Compliance Monitoring System

Expert Solution
Questions # 145:

Which of the following is NOT a valid reason to use external penetration service firms rather than corporate resources?

Options:

A.

They are more cost-effective

B.

They offer a lack of corporate bias

C.

They use highly talented ex-hackers

D.

They ensure a more complete reporting

Expert Solution
Questions # 146:

Attributable data should be:

Options:

A.

always traced to individuals responsible for observing and recording the data

B.

sometimes traced to individuals responsible for observing and recording the data

C.

never traced to individuals responsible for observing and recording the data

D.

often traced to individuals responsible for observing and recording the data

Expert Solution
Questions # 147:

Which of the following is needed for System Accountability?

Options:

A.

Audit mechanisms.

B.

Documented design as laid out in the Common Criteria.

C.

Authorization.

D.

Formal verification of system design.

Expert Solution
Questions # 148:

Several analysis methods can be employed by an IDS, each with its own strengths and weaknesses, and their applicability to any given situation should be carefully considered. There are two basic IDS analysis methods that exists. Which of the basic method is more prone to false positive?

Options:

A.

Pattern Matching (also called signature analysis)

B.

Anomaly Detection

C.

Host-based intrusion detection

D.

Network-based intrusion detection

Expert Solution
Questions # 149:

What setup should an administrator use for regularly testing the strength of user passwords?

Options:

A.

A networked workstation so that the live password database can easily be accessed by the cracking program.

B.

A networked workstation so the password database can easily be copied locally and processed by the cracking program.

C.

A standalone workstation on which the password database is copied and processed by the cracking program.

D.

A password-cracking program is unethical; therefore it should not be used.

Expert Solution
Questions # 150:

Which of the following would NOT violate the Due Diligence concept?

Options:

A.

Security policy being outdated

B.

Data owners not laying out the foundation of data protection

C.

Network administrator not taking mandatory two-week vacation as planned

D.

Latest security patches for servers being installed as per the Patch Management process

Expert Solution
Questions # 151:

Which of the following would be LESS likely to prevent an employee from reporting an incident?

Options:

A.

They are afraid of being pulled into something they don't want to be involved with.

B.

The process of reporting incidents is centralized.

C.

They are afraid of being accused of something they didn't do.

D.

They are unaware of the company's security policies and procedures.

Expert Solution
Questions # 152:

Attributes that characterize an attack are stored for reference using which of the following Intrusion Detection System (IDS) ?

Options:

A.

signature-based IDS

B.

statistical anomaly-based IDS

C.

event-based IDS

D.

inferent-based IDS

Expert Solution
Questions # 153:

Which of the following is NOT a VPN communications protocol standard?

Options:

A.

Point-to-point tunnelling protocol (PPTP)

B.

Challenge Handshake Authentication Protocol (CHAP)

C.

Layer 2 tunnelling protocol (L2TP)

D.

IP Security

Expert Solution
Questions # 154:

What is called an attack in which an attacker floods a system with connection requests but does not respond when the target system replies to those requests?

Options:

A.

Ping of death attack

B.

SYN attack

C.

Smurf attack

D.

Buffer overflow attack

Expert Solution
Questions # 155:

Network cabling comes in three flavors, they are:

Options:

A.

twisted pair, coaxial, and fiber optic.

B.

tagged pair, coaxial, and fiber optic.

C.

trusted pair, coaxial, and fiber optic.

D.

twisted pair, control, and fiber optic.

Expert Solution
Questions # 156:

Secure Shell (SSH-2) supports authentication, compression, confidentiality, and integrity, SSH is commonly used as a secure alternative to all of the following protocols below except:

Options:

A.

telnet

B.

rlogin

C.

RSH

D.

HTTPS

Expert Solution
Questions # 157:

Which device acting as a translator is used to connect two networks or applications from layer 4 up to layer 7 of the ISO/OSI Model?

Options:

A.

Bridge

B.

Repeater

C.

Router

D.

Gateway

Expert Solution
Questions # 158:

Secure Shell (SSH) is a strong method of performing:

Options:

A.

client authentication

B.

server authentication

C.

host authentication

D.

guest authentication

Expert Solution
Questions # 159:

Why does fiber optic communication technology have significant security advantage over other transmission technology?

Options:

A.

Higher data rates can be transmitted.

B.

Interception of data traffic is more difficult.

C.

Traffic analysis is prevented by multiplexing.

D.

Single and double-bit errors are correctable.

Expert Solution
Questions # 160:

SMTP can best be described as:

Options:

A.

a host-to-host email protocol.

B.

an email retrieval protocol.

C.

a web-based e-mail reading protocol.

D.

a standard defining the format of e-mail messages.

Expert Solution
Viewing page 8 out of 14 pages
Viewing questions 141-160 out of questions