Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 21 pages
Exam (elaborations)

SSCP practice Questions with Verified Answers (Correct Update)

Document preview thumbnail
Preview 3 out of 21 pages

SSCP practice Questions with Verified Answers (Correct Update)

Content preview

SSCP practice Questions with Verified Answers (Correct Update)

Question 1: What can be defined as a table of subjects and objects indicating what actions
individual subjects can take upon individual objects?
A. A capacity table
B. An access control list
C. An access control matrix
D. A capability table

Answer: C. An Access Control Matrix

Question 2: Which access control model is best suited in an environment where a high security
level is required and where it is desired that only the administrator grants access control?
A. DAC
B. MAC
C. Access control matrix
D. TACACS

Answer: B. MAC

Question 3: Which access control model provides upper and lower bounds of access capabilities
for a subject?
A. Role-based access control
B. Lattice-based access control
C. Biba access control
D. Content-dependent access control

Answer: B Lattice-based access control

Question 4: How are memory cards and smart cards different?
A. Memory cards normally hold more memory than smart cards
B. Smart cards provide a two-factor authentication whereas memory cards don't
C. Memory cards have no processing power
D. Only smart cards can be used for ATM cards

Answer: C. Memory Cards have no processing power

Question 5: Why do buffer overflows happen? What is the main cause?
A. Because buffers can only hold so much data
B. Because of improper parameter checking within the application
C. Because they are an easy weakness to exploit
D. Because of insufficient system memory

Answer: B. because of improper parameter checking within the application



Page 1

,Question 6: What is the main focus of the Bell- LaPadula security model?
A. Accountability
B. Integrity
C. Confidentiality
D. Availability

Answer: C. Confidentiality

Question 7: Which of the following statements pertaining to the Bell-LaPadula is TRUE if you
are NOT making use of the strong star property?
A. It allows "read up."
B. It addresses covert channels.
C. It addresses management of access controls.
D. It allows "write up."

Answer: D. it allows "write up."

Question 8: Which security model introduces access to objects only through programs?
A. The Biba model
B. The Bell-LaPadula model
C. The Clark-Wilson model
D. The information flow model

Answer: C. The Clark-Wilson model

Question 9: Which security model ensures that actions that take place at a higher security level
do not affect actions that take place at a lower level?
A. The Bell-LaPadula model
B. The information flow model
C. The noninterference model
D. The Clark-Wilson model

Answer: C. the noninterference model

Question 10: Which of the following security models does NOT concern itself with the flow of
data?
A. The information flow model
B. The Biba model
C. The Bell-LaPadula model
D. The noninterference model

Answer: D. the noninterference model




Page 2

, Question 11: What Orange Book security rating is reserved for systems that have been
evaluated but fail to meet the criteria and requirements of the higher divisions?
A. A
B. D
C. E
D. F

Answer: B. D

Question 12: Which division of the Orange Book deals with discretionary protection
(need-to-know)?
A. D
B. C
C. B
D. A

Answer: B. C

Question 13: Which of the following are not Remote Access concerns?
A. Justification for remote access
B. Auditing of activities
C. Regular review of access privileges
D. Access badges

Answer: D. Access badges

Question 14: Smart cards are an example of which type of control?
A. Detective control
B. Administrative control
C. Technical control
D. Physical control

Answer: C. Technical Control

Question 15: What security model is dependent on security labels?
A. Discretionary access control
B. Label-based access control
C. Mandatory access control
D. Non-discretionary access control

Answer: C. Mandatory Access control




Page 3

Document information

Uploaded on
September 21, 2026
Number of pages
21
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
DrJon
3.8
(160)
Sold
593
Followers
188
Items
23563
Last sold
13 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions