SSCP Domain 1 Questions with all Correct & 100%
Verified Answers |Latest Version |Guaranteed to Pass
What technique hides sensitive information inside another file, such as an image? ✔Correct
Answer-Stenography
Alan is applying access controls to ensure that employees in his company are not able to read
files that are not directly related to their job functions. What goal of information security is Alan
enforcing? ✔Correct Answer-Confidentiality
Security leaders planning to deploy a new security control should develop a business case for
that control. ✔Correct Answer-True
Which one of the following security controls provides the best ability to detect integrity issues?
✔Correct Answer-Hashing
Rick recently worked with his HR department to replace the first five digits of employee Social
Security Numbers with Xs. What technique did he use? ✔Correct Answer-Masking
What privacy law covers the financial services sector? ✔Correct Answer-GLBA
What security principle most directly applies to limiting information access? ✔Correct
Answer-Need to know
What security principle requires two individuals to perform a sensitive action? ✔Correct
Answer-Two-person control
RFCs should contain a plan to roll back the change if it fails. ✔Correct Answer-True
Which one of the following is not one of the GAPP principles?
- Integrity
- Collection
- Notice
- Management ✔Correct Answer-Integrity
Which one of the following is not a commonly-used business classification level?
- Internal
- Highly Sensitive
- Sensitive
- Top Secret ✔Correct Answer-Top Secret
, Which one of the following data sanitization strategies is most secure?
- destruction
- clearing
- erasing
- purging ✔Correct Answer-destruction
What technology is commonly used for big data assets?
- MySQL
- SQL Server
- NoSQL
- PostgreSQL ✔Correct Answer-NoSQL
What data security role is normally filled by a senior-level official who bears overall
responsibility for the data?
- Data custodian
- Data owner
- data guardian
- data steward ✔Correct Answer-Data owner
Once an organization complies with GAPP, best practice says they should collect as much
information as possible to provide good service, provided that they remain GAPP compliant.
✔Correct Answer-False
Security baselines often require hundreds or thousands of individual security settings on a
particular device. ✔Correct Answer-True
Organizations often customize industry security standards to meet their specific security and
business requirements. ✔Correct Answer-True
What U.S. federal government agency publishes security standards that are widely used
throughout the government and private industry? ✔Correct Answer-NIST
Which element of the security policy framework includes suggestions that are not mandatory?
- Guidelines
- Procedures
- Standards
- Policies ✔Correct Answer-Guidelines
Which one of the following is NOT one of the major principles of COBIT?
Verified Answers |Latest Version |Guaranteed to Pass
What technique hides sensitive information inside another file, such as an image? ✔Correct
Answer-Stenography
Alan is applying access controls to ensure that employees in his company are not able to read
files that are not directly related to their job functions. What goal of information security is Alan
enforcing? ✔Correct Answer-Confidentiality
Security leaders planning to deploy a new security control should develop a business case for
that control. ✔Correct Answer-True
Which one of the following security controls provides the best ability to detect integrity issues?
✔Correct Answer-Hashing
Rick recently worked with his HR department to replace the first five digits of employee Social
Security Numbers with Xs. What technique did he use? ✔Correct Answer-Masking
What privacy law covers the financial services sector? ✔Correct Answer-GLBA
What security principle most directly applies to limiting information access? ✔Correct
Answer-Need to know
What security principle requires two individuals to perform a sensitive action? ✔Correct
Answer-Two-person control
RFCs should contain a plan to roll back the change if it fails. ✔Correct Answer-True
Which one of the following is not one of the GAPP principles?
- Integrity
- Collection
- Notice
- Management ✔Correct Answer-Integrity
Which one of the following is not a commonly-used business classification level?
- Internal
- Highly Sensitive
- Sensitive
- Top Secret ✔Correct Answer-Top Secret
, Which one of the following data sanitization strategies is most secure?
- destruction
- clearing
- erasing
- purging ✔Correct Answer-destruction
What technology is commonly used for big data assets?
- MySQL
- SQL Server
- NoSQL
- PostgreSQL ✔Correct Answer-NoSQL
What data security role is normally filled by a senior-level official who bears overall
responsibility for the data?
- Data custodian
- Data owner
- data guardian
- data steward ✔Correct Answer-Data owner
Once an organization complies with GAPP, best practice says they should collect as much
information as possible to provide good service, provided that they remain GAPP compliant.
✔Correct Answer-False
Security baselines often require hundreds or thousands of individual security settings on a
particular device. ✔Correct Answer-True
Organizations often customize industry security standards to meet their specific security and
business requirements. ✔Correct Answer-True
What U.S. federal government agency publishes security standards that are widely used
throughout the government and private industry? ✔Correct Answer-NIST
Which element of the security policy framework includes suggestions that are not mandatory?
- Guidelines
- Procedures
- Standards
- Policies ✔Correct Answer-Guidelines
Which one of the following is NOT one of the major principles of COBIT?