WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
1. During what phase of the change management Analysis/Impact Assess-
process does the organization conduct peer review of ment
the change for accuracy and completeness?
2. Steve is responsible for work stations that handle pro- Sanitization
prietary information. What is the best option for these
workstations at the end of their lifecycle?
3. What is the earliest stage of a fire to use detection Incipient
technology to identify it?
4. What security control would provide the best defense Parameter Checking/In-
against a threat actor trying to execute a buffer over- put Validation
flow attack against a custom application?
5. Which of the following is NOT true of the ISC2 Code of B.
Ethics?
A. Adherence to the Code of Ethics is a condition of
Certification
B. The code of ethics applies to all security profession-
als
C. Failure to comply with the Code of Ethics could
result in revocation of certification
D. Members who observe a breach of the Code of
Ethics are required to report the possible violation
6. Under what type of software license does the recipient Public Domain
of software have an unlimited right to copy, modify,
distribute, or resell a software package?
7. What should Steve do if a FAR/FRR diagram does not Assess other biometric
provide an acceptable performance level for his orga- systems to compare them
nization's needs?
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
since the CER is used to
assess biometric devices.
8. What is the CER in biometric device measurment? Crossover Error Rate is the
number that results when
a biometric device is ad-
justed to provide equal
false acceptance and false
rejection rates.
9. What type of access control would be the best choice Attribute Based Access
for a person that would like to support a declaration Control ABAC
like "Only allow access to customer service on man-
aged devices on the wireless network between 8 am
and 7 pm"?
10. What is the benefit of an ABAC over a RBAC? An ABAC can be more spe-
cific thus more flexible
11. What is the primary advantage of decentralized ac- It provides control of ac-
cess control? cess to people closer to
the resources
12. How are rules set in ABAC systems? Uses boolean logic state-
ments which allow it to be
more flexible than RBAC
for temporary rules such
as to allow time limited ac-
cess.
13. Which of the following is best described as an access B
control model that focuses on subjects and identifies
the objects that each subject can access?
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
A. Access control list
B. Capability Table
C. Implicit denial list
D. Rights Management Matrix
14. Adam is accessing a standalone file server using a A. The file server has
username and password provided by the server ad- the correct information on
ministrator. Which one of the following entities is what activities Adam is AU-
guaranteed to have information necessary to com- THORIZED to perform
plete the authorization process?
A. File Server
B. Adam
C. Server Administrator
D. Adam's Supervisor
15. A new member at a 24 hour gym that uses fingerprints Since he was accepted as
to gain access after hours is surprised to find out that a different member this
he is registering as a different member. What type of was a Type 2 (false pos-
biometric factor error occurred? itive) error. If he was not
accepted and the door re-
mained locked it would
have been a Type 1 (false
negative) error.
16. You are tasked with adjusting your organizations NIST Special Publication
password requirements to make them align with best 800-63b suggests that or-
practices from NIST. What should you set password ganizations should not
expiration to? impose password expira-
tion requirements on end
users
17. Mandatory Access Control
(MAC)
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
What access control scheme labels subjects and ob-
jects and allows subjects to access objects when labels
match?
18. Mandatory Access Control is based on what type of Lattice Based
model?
19. You need to create a trust relationship between your This type of authentica-
company and a vendor. You need to implement the tion, where one domain
system so that it will allow users from the vendor's trusts users from another
organization to access your accounts payable system domain, is called federa-
using the accounts created for them by the vendor. tion.
What type of authentication do you need to imple-
ment?
20. Users change job positions quite often at your new A Role-Based Access Con-
company. Which type of access control would make trol would assign permis-
it easier to allow administrators to adjust permissions sion to roles and then
when these changes occur? the administrator would
A. Role-Based Access Control simply adjust the role of
B. Mandatory Access Control the user when he or she
C. Discretionary Access Control changes jobs
D. Rule-Based Access Control
21. Which of the following authenticators is appropriate C. Palm scans compare the
to use by itself rather than in combination with other vein patterns in the palm
biometric factors? to a database to authenti-
A. Voice pattern recognition cate a user.
B. Hand geometry
C. Palm scans
D. Heart/pulse patterns
22.
Study online at https://quizlet.com/_jpoy9g
1. During what phase of the change management Analysis/Impact Assess-
process does the organization conduct peer review of ment
the change for accuracy and completeness?
2. Steve is responsible for work stations that handle pro- Sanitization
prietary information. What is the best option for these
workstations at the end of their lifecycle?
3. What is the earliest stage of a fire to use detection Incipient
technology to identify it?
4. What security control would provide the best defense Parameter Checking/In-
against a threat actor trying to execute a buffer over- put Validation
flow attack against a custom application?
5. Which of the following is NOT true of the ISC2 Code of B.
Ethics?
A. Adherence to the Code of Ethics is a condition of
Certification
B. The code of ethics applies to all security profession-
als
C. Failure to comply with the Code of Ethics could
result in revocation of certification
D. Members who observe a breach of the Code of
Ethics are required to report the possible violation
6. Under what type of software license does the recipient Public Domain
of software have an unlimited right to copy, modify,
distribute, or resell a software package?
7. What should Steve do if a FAR/FRR diagram does not Assess other biometric
provide an acceptable performance level for his orga- systems to compare them
nization's needs?
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
since the CER is used to
assess biometric devices.
8. What is the CER in biometric device measurment? Crossover Error Rate is the
number that results when
a biometric device is ad-
justed to provide equal
false acceptance and false
rejection rates.
9. What type of access control would be the best choice Attribute Based Access
for a person that would like to support a declaration Control ABAC
like "Only allow access to customer service on man-
aged devices on the wireless network between 8 am
and 7 pm"?
10. What is the benefit of an ABAC over a RBAC? An ABAC can be more spe-
cific thus more flexible
11. What is the primary advantage of decentralized ac- It provides control of ac-
cess control? cess to people closer to
the resources
12. How are rules set in ABAC systems? Uses boolean logic state-
ments which allow it to be
more flexible than RBAC
for temporary rules such
as to allow time limited ac-
cess.
13. Which of the following is best described as an access B
control model that focuses on subjects and identifies
the objects that each subject can access?
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
A. Access control list
B. Capability Table
C. Implicit denial list
D. Rights Management Matrix
14. Adam is accessing a standalone file server using a A. The file server has
username and password provided by the server ad- the correct information on
ministrator. Which one of the following entities is what activities Adam is AU-
guaranteed to have information necessary to com- THORIZED to perform
plete the authorization process?
A. File Server
B. Adam
C. Server Administrator
D. Adam's Supervisor
15. A new member at a 24 hour gym that uses fingerprints Since he was accepted as
to gain access after hours is surprised to find out that a different member this
he is registering as a different member. What type of was a Type 2 (false pos-
biometric factor error occurred? itive) error. If he was not
accepted and the door re-
mained locked it would
have been a Type 1 (false
negative) error.
16. You are tasked with adjusting your organizations NIST Special Publication
password requirements to make them align with best 800-63b suggests that or-
practices from NIST. What should you set password ganizations should not
expiration to? impose password expira-
tion requirements on end
users
17. Mandatory Access Control
(MAC)
, WGU C845 SSCP 2026/2027
Study online at https://quizlet.com/_jpoy9g
What access control scheme labels subjects and ob-
jects and allows subjects to access objects when labels
match?
18. Mandatory Access Control is based on what type of Lattice Based
model?
19. You need to create a trust relationship between your This type of authentica-
company and a vendor. You need to implement the tion, where one domain
system so that it will allow users from the vendor's trusts users from another
organization to access your accounts payable system domain, is called federa-
using the accounts created for them by the vendor. tion.
What type of authentication do you need to imple-
ment?
20. Users change job positions quite often at your new A Role-Based Access Con-
company. Which type of access control would make trol would assign permis-
it easier to allow administrators to adjust permissions sion to roles and then
when these changes occur? the administrator would
A. Role-Based Access Control simply adjust the role of
B. Mandatory Access Control the user when he or she
C. Discretionary Access Control changes jobs
D. Rule-Based Access Control
21. Which of the following authenticators is appropriate C. Palm scans compare the
to use by itself rather than in combination with other vein patterns in the palm
biometric factors? to a database to authenti-
A. Voice pattern recognition cate a user.
B. Hand geometry
C. Palm scans
D. Heart/pulse patterns
22.