SSCP practice Questions with Verified Answers (Correct Update)
Question 1: What can be defined as a table of subjects and objects indicating what actions
individual subjects can take upon individual objects?
A. A capacity table
B. An access control list
C. An access control matrix
D. A capability table
Answer: C. An Access Control Matrix
Question 2: Which access control model is best suited in an environment where a high security
level is required and where it is desired that only the administrator grants access control?
A. DAC
B. MAC
C. Access control matrix
D. TACACS
Answer: B. MAC
Question 3: Which access control model provides upper and lower bounds of access capabilities
for a subject?
A. Role-based access control
B. Lattice-based access control
C. Biba access control
D. Content-dependent access control
Answer: B Lattice-based access control
Question 4: How are memory cards and smart cards different?
A. Memory cards normally hold more memory than smart cards
B. Smart cards provide a two-factor authentication whereas memory cards don't
C. Memory cards have no processing power
D. Only smart cards can be used for ATM cards
Answer: C. Memory Cards have no processing power
Question 5: Why do buffer overflows happen? What is the main cause?
A. Because buffers can only hold so much data
B. Because of improper parameter checking within the application
C. Because they are an easy weakness to exploit
D. Because of insufficient system memory
Answer: B. because of improper parameter checking within the application
Page 1
,Question 6: What is the main focus of the Bell- LaPadula security model?
A. Accountability
B. Integrity
C. Confidentiality
D. Availability
Answer: C. Confidentiality
Question 7: Which of the following statements pertaining to the Bell-LaPadula is TRUE if you
are NOT making use of the strong star property?
A. It allows "read up."
B. It addresses covert channels.
C. It addresses management of access controls.
D. It allows "write up."
Answer: D. it allows "write up."
Question 8: Which security model introduces access to objects only through programs?
A. The Biba model
B. The Bell-LaPadula model
C. The Clark-Wilson model
D. The information flow model
Answer: C. The Clark-Wilson model
Question 9: Which security model ensures that actions that take place at a higher security level
do not affect actions that take place at a lower level?
A. The Bell-LaPadula model
B. The information flow model
C. The noninterference model
D. The Clark-Wilson model
Answer: C. the noninterference model
Question 10: Which of the following security models does NOT concern itself with the flow of
data?
A. The information flow model
B. The Biba model
C. The Bell-LaPadula model
D. The noninterference model
Answer: D. the noninterference model
Page 2
, Question 11: What Orange Book security rating is reserved for systems that have been
evaluated but fail to meet the criteria and requirements of the higher divisions?
A. A
B. D
C. E
D. F
Answer: B. D
Question 12: Which division of the Orange Book deals with discretionary protection
(need-to-know)?
A. D
B. C
C. B
D. A
Answer: B. C
Question 13: Which of the following are not Remote Access concerns?
A. Justification for remote access
B. Auditing of activities
C. Regular review of access privileges
D. Access badges
Answer: D. Access badges
Question 14: Smart cards are an example of which type of control?
A. Detective control
B. Administrative control
C. Technical control
D. Physical control
Answer: C. Technical Control
Question 15: What security model is dependent on security labels?
A. Discretionary access control
B. Label-based access control
C. Mandatory access control
D. Non-discretionary access control
Answer: C. Mandatory Access control
Page 3
Question 1: What can be defined as a table of subjects and objects indicating what actions
individual subjects can take upon individual objects?
A. A capacity table
B. An access control list
C. An access control matrix
D. A capability table
Answer: C. An Access Control Matrix
Question 2: Which access control model is best suited in an environment where a high security
level is required and where it is desired that only the administrator grants access control?
A. DAC
B. MAC
C. Access control matrix
D. TACACS
Answer: B. MAC
Question 3: Which access control model provides upper and lower bounds of access capabilities
for a subject?
A. Role-based access control
B. Lattice-based access control
C. Biba access control
D. Content-dependent access control
Answer: B Lattice-based access control
Question 4: How are memory cards and smart cards different?
A. Memory cards normally hold more memory than smart cards
B. Smart cards provide a two-factor authentication whereas memory cards don't
C. Memory cards have no processing power
D. Only smart cards can be used for ATM cards
Answer: C. Memory Cards have no processing power
Question 5: Why do buffer overflows happen? What is the main cause?
A. Because buffers can only hold so much data
B. Because of improper parameter checking within the application
C. Because they are an easy weakness to exploit
D. Because of insufficient system memory
Answer: B. because of improper parameter checking within the application
Page 1
,Question 6: What is the main focus of the Bell- LaPadula security model?
A. Accountability
B. Integrity
C. Confidentiality
D. Availability
Answer: C. Confidentiality
Question 7: Which of the following statements pertaining to the Bell-LaPadula is TRUE if you
are NOT making use of the strong star property?
A. It allows "read up."
B. It addresses covert channels.
C. It addresses management of access controls.
D. It allows "write up."
Answer: D. it allows "write up."
Question 8: Which security model introduces access to objects only through programs?
A. The Biba model
B. The Bell-LaPadula model
C. The Clark-Wilson model
D. The information flow model
Answer: C. The Clark-Wilson model
Question 9: Which security model ensures that actions that take place at a higher security level
do not affect actions that take place at a lower level?
A. The Bell-LaPadula model
B. The information flow model
C. The noninterference model
D. The Clark-Wilson model
Answer: C. the noninterference model
Question 10: Which of the following security models does NOT concern itself with the flow of
data?
A. The information flow model
B. The Biba model
C. The Bell-LaPadula model
D. The noninterference model
Answer: D. the noninterference model
Page 2
, Question 11: What Orange Book security rating is reserved for systems that have been
evaluated but fail to meet the criteria and requirements of the higher divisions?
A. A
B. D
C. E
D. F
Answer: B. D
Question 12: Which division of the Orange Book deals with discretionary protection
(need-to-know)?
A. D
B. C
C. B
D. A
Answer: B. C
Question 13: Which of the following are not Remote Access concerns?
A. Justification for remote access
B. Auditing of activities
C. Regular review of access privileges
D. Access badges
Answer: D. Access badges
Question 14: Smart cards are an example of which type of control?
A. Detective control
B. Administrative control
C. Technical control
D. Physical control
Answer: C. Technical Control
Question 15: What security model is dependent on security labels?
A. Discretionary access control
B. Label-based access control
C. Mandatory access control
D. Non-discretionary access control
Answer: C. Mandatory Access control
Page 3