SSCP Exam A and B with all Correct & 100% Verified
Answers |Actual Complete Update |Already Graded A+
Which of the following tools is NOT likely to be used by a hacker ✔Correct Answer-Tripwire
Which of the following would be LESS likely to prevent an employee from reporting an incident?
✔Correct Answer-B. The process of reporting incidents is centralized
Which of the following would NOT violate the Due Diligence concept? ✔Correct Answer-
Latest security patches for servers being installed as per the Patch Management process
What is the primary goal of setting up a honeypot ✔Correct Answer-To know when certain
types of attacks are in progress and to learn about attack techniques so the network can be
fortified.
Who is responsible for providing reports to the senior management on the effectiveness of the
security controls? ✔Correct Answer-Information systems auditors
Which of the following are the two MOST common implementations of Intrusion Detection
Systems? ✔Correct Answer-Network-based and host-based
Network-based Intrusion Detection systems ✔Correct Answer-A. Commonly reside on a
discrete network segment and monitor the traffic on that network segment.
Which of the following are additional terms used to describe knowledge-based IDS and
behavior-based IDS? ✔Correct Answer-A. signature-based IDS and statistical anomaly-based
IDS, respectively
Which of the following Intrusion Detection Systems (IDS) uses a database of attacks, known
system vulnerabilities, monitoring current attempts to exploit those vulnerabilities, and then
triggers an alarm if an attempt is found? ✔Correct Answer-Knowledge-based ID system
Knowledge-based Intrusion Detection Systems (IDS) are more common than: ✔Correct
Answer-C. Behavior-based IDS
Which of the following types of Intrusion Detection Systems uses behavioral characteristics of a
system's operation or network traffic to draw conclusions on whether the traffic represents a
risk to the network or host? ✔Correct Answer-Anomaly Detection
What ensures that the control mechanisms correctly implement the security policy for the
entire life cycle of an information system? ✔Correct Answer-Assurance procedures
, What IDS approach relies on a database of known attacks ✔Correct Answer-Signature-based
intrusion detection
Which of the following is most likely to be useful in detecting intrusions? ✔Correct Answer-C.
Audit trails
Which conceptual approach to intrusion detection system is the most common? ✔Correct
Answer-Knowledge-based intrusion detection
Several analysis methods can be employed by an IDS, each with its own strengths and
weaknesses, and their applicability to any given situation should be carefully considered. There
are two basic IDS analysis methods that exists. Which of the basic method is more prone to false
positive? ✔Correct Answer-B. Anomaly Detection
In order to enable users to perform tasks and duties without having to go through extra steps it
is important that the security controls and mechanisms that are in place have a degree of?
✔Correct Answer-Transparency
Which of the following is required in order to provide accountability ✔Correct Answer-Audit
trails
Which of the following is NOT a valid reason to use external penetration service firms rather
than corporate resources? ✔Correct Answer-They use talented ex-hackers
Which of the following statements pertaining to ethical hacking is incorrect? ✔Correct
Answer-D. Ethical hackers never use tools that have the potential of affecting servers or
services.
The viewing of recorded events after the fact using a closed-circuit TV camera is considered a
✔Correct Answer-Detective Control
Controls provide accountability for individuals who are accessing sensitive information. This
accountability is accomplished ✔Correct Answer-A. through access control mechanisms that
require identification and authentication and through the audit function
Which of the following tools is less likely to be used by a hacker? ✔Correct Answer-Tripwire
Why would anomaly detection IDSs often generate a large number of false positives?
✔Correct Answer-D. Because normal patterns of user and system behavior can vary wildly
What is the essential difference between a self-audit and an independent audit? ✔Correct
Answer-Objectivity
Answers |Actual Complete Update |Already Graded A+
Which of the following tools is NOT likely to be used by a hacker ✔Correct Answer-Tripwire
Which of the following would be LESS likely to prevent an employee from reporting an incident?
✔Correct Answer-B. The process of reporting incidents is centralized
Which of the following would NOT violate the Due Diligence concept? ✔Correct Answer-
Latest security patches for servers being installed as per the Patch Management process
What is the primary goal of setting up a honeypot ✔Correct Answer-To know when certain
types of attacks are in progress and to learn about attack techniques so the network can be
fortified.
Who is responsible for providing reports to the senior management on the effectiveness of the
security controls? ✔Correct Answer-Information systems auditors
Which of the following are the two MOST common implementations of Intrusion Detection
Systems? ✔Correct Answer-Network-based and host-based
Network-based Intrusion Detection systems ✔Correct Answer-A. Commonly reside on a
discrete network segment and monitor the traffic on that network segment.
Which of the following are additional terms used to describe knowledge-based IDS and
behavior-based IDS? ✔Correct Answer-A. signature-based IDS and statistical anomaly-based
IDS, respectively
Which of the following Intrusion Detection Systems (IDS) uses a database of attacks, known
system vulnerabilities, monitoring current attempts to exploit those vulnerabilities, and then
triggers an alarm if an attempt is found? ✔Correct Answer-Knowledge-based ID system
Knowledge-based Intrusion Detection Systems (IDS) are more common than: ✔Correct
Answer-C. Behavior-based IDS
Which of the following types of Intrusion Detection Systems uses behavioral characteristics of a
system's operation or network traffic to draw conclusions on whether the traffic represents a
risk to the network or host? ✔Correct Answer-Anomaly Detection
What ensures that the control mechanisms correctly implement the security policy for the
entire life cycle of an information system? ✔Correct Answer-Assurance procedures
, What IDS approach relies on a database of known attacks ✔Correct Answer-Signature-based
intrusion detection
Which of the following is most likely to be useful in detecting intrusions? ✔Correct Answer-C.
Audit trails
Which conceptual approach to intrusion detection system is the most common? ✔Correct
Answer-Knowledge-based intrusion detection
Several analysis methods can be employed by an IDS, each with its own strengths and
weaknesses, and their applicability to any given situation should be carefully considered. There
are two basic IDS analysis methods that exists. Which of the basic method is more prone to false
positive? ✔Correct Answer-B. Anomaly Detection
In order to enable users to perform tasks and duties without having to go through extra steps it
is important that the security controls and mechanisms that are in place have a degree of?
✔Correct Answer-Transparency
Which of the following is required in order to provide accountability ✔Correct Answer-Audit
trails
Which of the following is NOT a valid reason to use external penetration service firms rather
than corporate resources? ✔Correct Answer-They use talented ex-hackers
Which of the following statements pertaining to ethical hacking is incorrect? ✔Correct
Answer-D. Ethical hackers never use tools that have the potential of affecting servers or
services.
The viewing of recorded events after the fact using a closed-circuit TV camera is considered a
✔Correct Answer-Detective Control
Controls provide accountability for individuals who are accessing sensitive information. This
accountability is accomplished ✔Correct Answer-A. through access control mechanisms that
require identification and authentication and through the audit function
Which of the following tools is less likely to be used by a hacker? ✔Correct Answer-Tripwire
Why would anomaly detection IDSs often generate a large number of false positives?
✔Correct Answer-D. Because normal patterns of user and system behavior can vary wildly
What is the essential difference between a self-audit and an independent audit? ✔Correct
Answer-Objectivity