(ISC)² Systems Security Certified Practitioner (SSCP) Exam
with all Correct & 100% Verified Answers |Actual
Complete Update |Already Graded A+
A unique user or process identity used for accountability
a)Identification
b)Authentication ✔Correct Answer-a
Mass Lockouts
a)Happens when an user forgets his/her password
b)Happens when a number of failed login attempts occur ✔Correct Answer-b
Example of behavioral biometrics
a)Signature analysis
b)Fingerprint verification ✔Correct Answer-a
Ensures each user's privilege continues to be appropriate and reflects any changes in the user's
access requirements as his/her role and/or responsibilities within the enterprise change.
a)Periodic review of access levels
b)Clearance ✔Correct Answer-a
The process of verification of the identity presented to the access control system belongs to the
party that has presented it.
a)Authorization
b)Authentication ✔Correct Answer-b
What are the steps involved in biometric authentication solution process? Choose all that apply.
a)Enrollment process
b)Identification process
c)Verification process ✔Correct Answer-a c
Devices that make use of user's personal physiological data in access control application.
Choose all that apply.
a)Hand geometry technology
b)Signature analysis
c)Finger print verification technology
d)Voice pattern recognition ✔Correct Answer-a c
Examples of behavioral biometrics.
a)Eye features scan
b)Signature analysis
,c)Retina scan
d)Voice pattern recognition ✔Correct Answer-b d
How is biometric accuracy measured?
a)Type 1 error
b)Type 2 error
c)Type 3 error
d)Type 4 error ✔Correct Answer-a b
The aim of NGI is to offer state of the art biometric identification services to improve the
accuracy of the system.
a)True
b)False ✔Correct Answer-a
Used in addition to or in place of a password.
a)Tokens
b)Smart card ✔Correct Answer-a
This methodology aids in reducing the risk that a user would walk away from a device or system
he/she has authenticated access to before properly logging out.
a)Time outs
b)Periodic authentication ✔Correct Answer-b
This is a type of authentication that involves the target system calling a registered phone
number and requesting that the user enter his/her password over the phone prior to allowing
the user to log in.
a)Peripheral device recognition
b)Out of band authentication ✔Correct Answer-b
Asynchronous password token is a one time password generated without the use of clock
a)False
b)True ✔Correct Answer-b
Strong authentication requires which of the following?
a)At least two of the three authentication factors (knowledge/ownership/characteristic)
c)Role based access control
d)One-time password scheme
e)Biometrics ✔Correct Answer-a
Security tokens are used to prove one's identity electronically.
a)True
b)False ✔Correct Answer-a
This type of tokens have neither a physical nor logical connection to the client computer.
,a)Connected tokens
b)Disconnected tokens ✔Correct Answer-b
This type of tokens form a logical connection to the client computer.
a)Contactless tokens
b)Connected tokens ✔Correct Answer-a
Applications of smart card
a)Healthcare applications
b)Secure identity applications ✔Correct Answer-a b
An authentication mechanism that allows a single identity to be shared across multiple
applications.
a)Single sign-on
b)Multi-factor authentication ✔Correct Answer-a
In two-way trust authentication requests can be passed between the two domains in both
directions.
a)True
b)False ✔Correct Answer-a
In one-way trust authentication requests can be passed between the two domains in both
directions.
a)False
b)True ✔Correct Answer-a
A series of trust relationships that authentication requests must follow between domains is
called ----------
a)Trust path
b)Domain controller ✔Correct Answer-a
The internet is a network based on TCP/IP protocols belonging to an organization.
a)True
b)False ✔Correct Answer-b
Extranet is a computer network that allows controlled access from the outside for specific
business or educational purposes.
a)False
b)True ✔Correct Answer-b
Demilitarized zone is a global system of interconnected computer networks that use the
standard Internet protocol suite to link several billion devices worldwide
a)False
b)True ✔Correct Answer-a
, Communicate by modifying a stored object
a)Timing channel
b)Storage channel ✔Correct Answer-b
Transitive trust is an extension of trust between two parties in the same domain?
a)False
b)True ✔Correct Answer-a
An unidirectional authentication path that is created between two domains.
a)Two-way trust
b)One-way trust ✔Correct Answer-b
Different types of trust architectures. Choose all that apply.
point
a)Internet
b)Demilitarized Zone
c)Intranet
d)Extranet ✔Correct Answer-all
Determines whether a user is permitted to access a particular resource.
a)Proofing
b)Authorization ✔Correct Answer-b
Maintenance is comprised of user management, password management, and role/group
management
a)False
b)True ✔Correct Answer-b
Devices and organizations are entities that do not require digital identity
a)True
b)False ✔Correct Answer-b)
What are the different types of entity that require digital identity? Choose all that apply.
point
a)Code
b)Devices
c)Agents
d)People
e)Organizations ✔Correct Answer-all
The task of controlling information about users on computers.
a)Proofing
b)Identity management ✔Correct Answer-b
with all Correct & 100% Verified Answers |Actual
Complete Update |Already Graded A+
A unique user or process identity used for accountability
a)Identification
b)Authentication ✔Correct Answer-a
Mass Lockouts
a)Happens when an user forgets his/her password
b)Happens when a number of failed login attempts occur ✔Correct Answer-b
Example of behavioral biometrics
a)Signature analysis
b)Fingerprint verification ✔Correct Answer-a
Ensures each user's privilege continues to be appropriate and reflects any changes in the user's
access requirements as his/her role and/or responsibilities within the enterprise change.
a)Periodic review of access levels
b)Clearance ✔Correct Answer-a
The process of verification of the identity presented to the access control system belongs to the
party that has presented it.
a)Authorization
b)Authentication ✔Correct Answer-b
What are the steps involved in biometric authentication solution process? Choose all that apply.
a)Enrollment process
b)Identification process
c)Verification process ✔Correct Answer-a c
Devices that make use of user's personal physiological data in access control application.
Choose all that apply.
a)Hand geometry technology
b)Signature analysis
c)Finger print verification technology
d)Voice pattern recognition ✔Correct Answer-a c
Examples of behavioral biometrics.
a)Eye features scan
b)Signature analysis
,c)Retina scan
d)Voice pattern recognition ✔Correct Answer-b d
How is biometric accuracy measured?
a)Type 1 error
b)Type 2 error
c)Type 3 error
d)Type 4 error ✔Correct Answer-a b
The aim of NGI is to offer state of the art biometric identification services to improve the
accuracy of the system.
a)True
b)False ✔Correct Answer-a
Used in addition to or in place of a password.
a)Tokens
b)Smart card ✔Correct Answer-a
This methodology aids in reducing the risk that a user would walk away from a device or system
he/she has authenticated access to before properly logging out.
a)Time outs
b)Periodic authentication ✔Correct Answer-b
This is a type of authentication that involves the target system calling a registered phone
number and requesting that the user enter his/her password over the phone prior to allowing
the user to log in.
a)Peripheral device recognition
b)Out of band authentication ✔Correct Answer-b
Asynchronous password token is a one time password generated without the use of clock
a)False
b)True ✔Correct Answer-b
Strong authentication requires which of the following?
a)At least two of the three authentication factors (knowledge/ownership/characteristic)
c)Role based access control
d)One-time password scheme
e)Biometrics ✔Correct Answer-a
Security tokens are used to prove one's identity electronically.
a)True
b)False ✔Correct Answer-a
This type of tokens have neither a physical nor logical connection to the client computer.
,a)Connected tokens
b)Disconnected tokens ✔Correct Answer-b
This type of tokens form a logical connection to the client computer.
a)Contactless tokens
b)Connected tokens ✔Correct Answer-a
Applications of smart card
a)Healthcare applications
b)Secure identity applications ✔Correct Answer-a b
An authentication mechanism that allows a single identity to be shared across multiple
applications.
a)Single sign-on
b)Multi-factor authentication ✔Correct Answer-a
In two-way trust authentication requests can be passed between the two domains in both
directions.
a)True
b)False ✔Correct Answer-a
In one-way trust authentication requests can be passed between the two domains in both
directions.
a)False
b)True ✔Correct Answer-a
A series of trust relationships that authentication requests must follow between domains is
called ----------
a)Trust path
b)Domain controller ✔Correct Answer-a
The internet is a network based on TCP/IP protocols belonging to an organization.
a)True
b)False ✔Correct Answer-b
Extranet is a computer network that allows controlled access from the outside for specific
business or educational purposes.
a)False
b)True ✔Correct Answer-b
Demilitarized zone is a global system of interconnected computer networks that use the
standard Internet protocol suite to link several billion devices worldwide
a)False
b)True ✔Correct Answer-a
, Communicate by modifying a stored object
a)Timing channel
b)Storage channel ✔Correct Answer-b
Transitive trust is an extension of trust between two parties in the same domain?
a)False
b)True ✔Correct Answer-a
An unidirectional authentication path that is created between two domains.
a)Two-way trust
b)One-way trust ✔Correct Answer-b
Different types of trust architectures. Choose all that apply.
point
a)Internet
b)Demilitarized Zone
c)Intranet
d)Extranet ✔Correct Answer-all
Determines whether a user is permitted to access a particular resource.
a)Proofing
b)Authorization ✔Correct Answer-b
Maintenance is comprised of user management, password management, and role/group
management
a)False
b)True ✔Correct Answer-b
Devices and organizations are entities that do not require digital identity
a)True
b)False ✔Correct Answer-b)
What are the different types of entity that require digital identity? Choose all that apply.
point
a)Code
b)Devices
c)Agents
d)People
e)Organizations ✔Correct Answer-all
The task of controlling information about users on computers.
a)Proofing
b)Identity management ✔Correct Answer-b