• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 44 pages
Exam (elaborations)

(ISC)² Systems Security Certified Practitioner (SSCP) - CiberTeam EXAM QUESTIONS WITH VERIFIED ANSWERS RATED A+

Document preview thumbnail
Preview 4 out of 44 pages

(ISC)² Systems Security Certified Practitioner (SSCP) - CiberTeam EXAM QUESTIONS WITH VERIFIED ANSWERS RATED A+ A unique user or process identity used for accountability a)Identification b)Authentication - Answer- a Mass Lockouts a)Happens when an user forgets his/her password b)Happens when a number of failed login attempts occur - Answer- b Example of behavioral biometrics a)Signature analysis b)Fingerprint verification - Answer- a Ensures each user's privilege continues to be appropriate and reflects any changes in the user's access requirements as his/her role and/or responsibilities within the enterprise change. a)Periodic review of access levels b)Clearance - Answer- a The process of verification of the identity presented to the access control system belongs to the party that has presented it. a)Authorization b)Authentication - Answer- b What are the steps involved in biometric authentication solution process? Choose all that apply. a)Enrollment process b)Identification process c)Verification process - Answer- a c Devices that make use of user's personal physiological data in access control application. Choose all that apply. a)Hand geometry technology b)Signature analysis c)Finger print verification technology d)Voice pattern recognition - Answer- a c Examples of behavioral biometrics. a)Eye features scan b)Signature analysis c)Retina scan d)Voice pattern recognition - Answer- b d How is biometric accuracy measured? a)Type 1 error b)Type 2 error c)Type 3 error d)Type 4 error - Answer- a b The aim of NGI is to offer state of the art biometric identification services to improve the accuracy of the system. a)True b)False - Answer- a Used in addition to or in place of a password. a)Tokens b)Smart card - Answer- a This methodology aids in reducing the risk that a user would walk away from a device or system he/she has authenticated access to before properly logging out. a)Time outs b)Periodic authentication - Answer- b This is a type of authentication that involves the target system calling a registered phone number and requesting that the user enter his/her password over the phone prior to allowing the user to log in. a)Peripheral device recognition b)Out of band authentication - Answer- b Asynchronous password token is a one time password generated without the use of clock a)False b)True - Answer- b Strong authentication requires which of the following? a)At least two of the three authentication factors (knowledge/ownership/characteristic) c)Role based access control d)One-time password scheme e)Biometrics - Answer- a Security tokens are used to prove one's identity electronically. a)True b)False - Answer- a This type of tokens have neither a physical nor logical connection to the client computer. a)Connected tokens b)Disconnected tokens - Answer- b This type of tokens form a logical connection to the client computer. a)Contactless tokens b)Connected tokens - Answer- a Applications of smart card a)Healthcare applications b)Secure identity applications - Answer- a b An authentication mechanism that allows a single identity to be shared across multiple applications. a)Single sign-on b)Multi-factor authentication - Answer- a In two-way trust authentication requests can be passed between the two domains in both directions. a)True b)False - Answer- a In one-way trust authentication requests can be passed between the two domains in both directions. a)False b)True - Answer- a A series of trust relationships that authentication requests must follow between domains is called ---------- a)Trust path b)Domain controller - Answer- a The internet is a network based on TCP/IP protocols belonging to an organization. a)True b)False - Answer- b Extranet is a computer network that allows controlled access from the outside for specific business or educational purposes. a)False b)True - Answer- b Demilitarized zone is a global system of interconnected computer networks that use the standard Internet protocol suite to link several billion devices worldwide a)False b)True - Answer- a Communicate by modifying a stored object a)Timing channel b)Storage channel - Answer- b Transitive trust is an extension of trust between two parties in the same domain? a)False b)True - Answer- a An unidirectional authentication path that is created between two domains. a)Two-way trust b)One-way trust - Answer- b Different types of trust architectures. Choose all that apply. 1 / 1 point a)Internet b)Demilitarized Zone c)Intranet d)Extranet - Answer- all Determines whether a user is permitted to access a particular resource. a)Proofing b)Authorization - Answer- b Maintenance is comprised of user management, password management, and role/group management a)False b)True - Answer- b Devices and organizations are entities that do not require digital identity a)True b)False - Answer- b) What are the different types of entity that require digital identity? Choose all that apply. 1 / 1 point a)Code b)Devices c)Agents d)People e)Organizations - Answer- all The task of controlling information about users on computers. a)Proofing b)Identity management - Answer- b Creation of the identifier for the identity is related to: a)Provisioning b)Authorization - Answer- a Identity-proofing services verify people's identities a)True b)False - Answer- a People and devices are related to: a)Provisioning b)Entity - Answer- b Code is a type of entity a)True b)False - Answer- a Five areas that make up the identity management life cycle. 1 / 1 point a)Authentication b)Authorization c)Proofing d)Entitlement e)Provisioning f)Maintenanace - Answer- b c d e f Clark-Wilson Integrity Models are useful for protecting classified information from unauthorized access or leakage to unclassified systems. a)True b)False - Answer- a Rule based, role based, temporal, and attribute based access controls are all forms of access control a)True b)False - Answer- a An access control implementation where access permissions are allocated based on several subjects performing identical or similar functions is referred to as: a)Temporal access control b)Discretionary access control c)Role-based access control d)Rule-based access control - Answer- c In mandatory access control policy a central authority, not by the individual owner of an object, makes access control policy decisions and the owner cannot change access rights. a)True b)False - Answer- a Role hierarchies are a mutual way of organizing roles to reflect authority, responsibility, and competency a)True b)False - Answer- a Temporal isolation access control and time-based access control are different types of access controls a)True b)False - Answer- b Access based on the content of a field in a database. a)Context-dependent access control b)Content-dependent access control - Answer- b Access Control in absence of a defined owner. a)Non- Discretionary access control b)Mandatory access control - Answer- a The owner of an asset (system/data etc.) decides who should have access to their asset. These decisions are enforced by the system. a)Role-based access control b)Discretionary access control - Answer- b The model that is designed as an architectural reference for controlling access to sensitive data in government and military applications. a)Bell-LaPadula Model b)Biba Integrity Model - Answer- a View Based Access Controls are an example of: a)Constrained User Interface b)Audit control c)Side Channel d)Temporal constraint - Answer- a Question 2 According to the following scenario, what would be the most appropriate Access Control model to deploy? Scenario: A medical records database application is used by a health-care worker to access blood test records. If a record contains information about an HIV test, the health-care worker may be denied access to the existence of the HIV test and the results of the HIV test. Only specific hospital staff would have the necessary access control rights to view blood test records that contain any information about HIV tests. a)Discretionary Access Control b)Context-Based Access Control c)Content-Dependent Access Control d)Role Based Access Control - Answer- c Which of the following is one of the three primary rules in a Biba formal model? a)A subject cannot request services from an object that has a higher integrity level b)A subject cannot modify an object that has a lower integrity level. c)A subject can read an object that has a lower integrity level. d)A subject cannot read or modify an object of either a lower or higher integrity level. - Answer- a Which of the following is an example of a network device that uses Context-Based Access Control? a)Static packet filter b)Network IDS c)Stateful inspection firewall d)VLAN - Answer- c Which of the following is a principle component of an access control system? a)Auditing/Accounting b)Biometrics c)Crossover Error Rate d)Objects - Answer- d

Content preview

(ISC)² Systems Security Certified
Practitioner (SSCP) - CiberTeam EXAM
QUESTIONS WITH VERIFIED
ANSWERS RATED A+
A unique user or process identity used for accountability
a)Identification
b)Authentication - Answer- a

Mass Lockouts
a)Happens when an user forgets his/her password
b)Happens when a number of failed login attempts occur - Answer- b

Example of behavioral biometrics
a)Signature analysis
b)Fingerprint verification - Answer- a

Ensures each user's privilege continues to be appropriate and reflects any changes in
the user's access requirements as his/her role and/or responsibilities within the
enterprise change.
a)Periodic review of access levels
b)Clearance - Answer- a

The process of verification of the identity presented to the access control system
belongs to the party that has presented it.
a)Authorization
b)Authentication - Answer- b

What are the steps involved in biometric authentication solution process? Choose all
that apply.
a)Enrollment process
b)Identification process
c)Verification process - Answer- a c

Devices that make use of user's personal physiological data in access control
application. Choose all that apply.
a)Hand geometry technology
b)Signature analysis
c)Finger print verification technology
d)Voice pattern recognition - Answer- a c

Examples of behavioral biometrics.

,a)Eye features scan
b)Signature analysis
c)Retina scan
d)Voice pattern recognition - Answer- b d

How is biometric accuracy measured?
a)Type 1 error
b)Type 2 error
c)Type 3 error
d)Type 4 error - Answer- a b

The aim of NGI is to offer state of the art biometric identification services to improve the
accuracy of the system.
a)True
b)False - Answer- a

Used in addition to or in place of a password.
a)Tokens
b)Smart card - Answer- a

This methodology aids in reducing the risk that a user would walk away from a device or
system he/she has authenticated access to before properly logging out.
a)Time outs
b)Periodic authentication - Answer- b

This is a type of authentication that involves the target system calling a registered
phone number and requesting that the user enter his/her password over the phone prior
to allowing the user to log in.
a)Peripheral device recognition
b)Out of band authentication - Answer- b

Asynchronous password token is a one time password generated without the use of
clock
a)False
b)True - Answer- b

Strong authentication requires which of the following?
a)At least two of the three authentication factors (knowledge/ownership/characteristic)
c)Role based access control
d)One-time password scheme
e)Biometrics - Answer- a

Security tokens are used to prove one's identity electronically.
a)True
b)False - Answer- a

,This type of tokens have neither a physical nor logical connection to the client computer.
a)Connected tokens
b)Disconnected tokens - Answer- b

This type of tokens form a logical connection to the client computer.
a)Contactless tokens
b)Connected tokens - Answer- a

Applications of smart card
a)Healthcare applications
b)Secure identity applications - Answer- a b

An authentication mechanism that allows a single identity to be shared across multiple
applications.
a)Single sign-on
b)Multi-factor authentication - Answer- a

In two-way trust authentication requests can be passed between the two domains in
both directions.
a)True
b)False - Answer- a

In one-way trust authentication requests can be passed between the two domains in
both directions.
a)False
b)True - Answer- a

A series of trust relationships that authentication requests must follow between domains
is called ----------
a)Trust path
b)Domain controller - Answer- a

The internet is a network based on TCP/IP protocols belonging to an organization.
a)True
b)False - Answer- b

Extranet is a computer network that allows controlled access from the outside for
specific business or educational purposes.
a)False
b)True - Answer- b

Demilitarized zone is a global system of interconnected computer networks that use the
standard Internet protocol suite to link several billion devices worldwide
a)False
b)True - Answer- a

, Communicate by modifying a stored object
a)Timing channel
b)Storage channel - Answer- b

Transitive trust is an extension of trust between two parties in the same domain?
a)False
b)True - Answer- a

An unidirectional authentication path that is created between two domains.
a)Two-way trust
b)One-way trust - Answer- b

Different types of trust architectures. Choose all that apply.
point
a)Internet
b)Demilitarized Zone
c)Intranet
d)Extranet - Answer- all

Determines whether a user is permitted to access a particular resource.
a)Proofing
b)Authorization - Answer- b

Maintenance is comprised of user management, password management, and
role/group management
a)False
b)True - Answer- b

Devices and organizations are entities that do not require digital identity
a)True
b)False - Answer- b)

What are the different types of entity that require digital identity? Choose all that apply.
point
a)Code
b)Devices
c)Agents
d)People
e)Organizations - Answer- all

The task of controlling information about users on computers.
a)Proofing
b)Identity management - Answer- b

Creation of the identifier for the identity is related to:
a)Provisioning

Document information

Uploaded on
February 4, 2026
Number of pages
44
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$25.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ScholarExams
3.8
(73)
Sold
394
Followers
186
Items
11436
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions