Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 73 pages
Exam (elaborations)

SSCP Exam Review Questions. With correct and verified answers

Document preview thumbnail
Preview 4 out of 73 pages

SSCP Exam Review Questions. With correct and verified answers How many years of experience are required to earn the Associate of (ISC)2 designation? A. Zero B. One C. Two D. Five Correct answer [Security Fundamentals] A. You don't need to meet the experience requirement to earn the Associate of (ISC)2 designation, so zero years of experience are required. The SSCP certification requires one year of direct full-time security work experience. If you earn the Associate of (ISC)2 designation, you have two years from the date (ISC)2 notifies you that you have passed the SSCP exam to obtain the required experience and apply to become a fully certified SSCP (which includes submitting the required endorsement form). The CISSP certification requires five years of experience." "What are the three elements of the security triad? A. Authentication authorization, and accounting B. Confidentiality, integrity, and availability C. Identification, authentication, and authorization D. Confidentiality, integrity, and authorization – Correct answer [Security Fundamentals] B. The CIA security triad includes three fundamental principles of security designed to prevent losses in confidentiality, integrity, and availability. Authentication, authorization, and accounting are the AAAs of security, and identification, authentication, and authorization are required for accountability, but these are not part of the CIA security triad." "Who is responsible for ensuring that security controls are in place to protect against the loss of confidentiality integrity, or availability of their systems and data? A. IT administrators B. System and information owners C. CFO D. Everyone - Correct answer [Security Fundamentals] B. System and information owners are responsible for ensuring that these security controls are in place. IT administrators or other IT security personnel might implement and maintain them. While it can be argued that the Chief Executive Officer (CEO) is ultimately responsible for all security, the Chief Financial Officer is responsible for finances, not IT security. Assigning responsibility to everyone results in no one taking responsibility." "You are sending an e-mail to a business partner that includes proprietary data. You want to ensure that the partner can access the data but that no one else can. What security principle should you apply? A. Authentication B. Availability C. Confidentiality D. Integrity – Correct answer [Security Fundamentals] C. Confidentiality helps prevent the unauthorized disclosure of data to unauthorized personnel, and you can enforce it with encryption in this scenario. Authentication allows a user to claim an identity (such as with a username) and prove the identity (such as with a password). Availability ensures that data is available when needed. Integrity ensures that the data hasn't been modified." "Your organization wants to ensure that attackers are unable to modify data within a database. What security principle is the organization trying to enforce? A. Accountability B. Availability C. Confidentiality D. Integrity – Correct answer [Security Fundamentals] D. Integrity ensures that data is not modified, and this includes data within a database. Accountability ensures that systems identify users, track their actions, and monitor their behavior. Availability ensures that IT systems and data are available when needed. Confidentiality protects against the unauthorized disclosure of data." "An organization wants to ensure that authorized employees are able to access resources during normal business hours. What security principle is the organization trying to enforce? A. Accountability B. Availability C. Integrity D. Confidentiality – Correct answer [Security Fundamentals] B. Availability ensures that IT systems and data are available when needed, such as during normal business hours. Accountability ensures that users are accurately identified and authenticated, and their actions are tracked with logs. Integrity ensures that data is not modified. Confidentiality protects the unauthorized disclosure of data to unauthorized users." "An organization has created a disaster recovery plan. What security principle is the organization trying to enforce? A. Authentication B. Availability C. Integrity D. Confidentiality – Correct answer [Security Fundamentals] B. Availability ensures that IT systems and data are available when needed. Disaster recovery plans help an organization ensure availability of critical systems after a disaster. Users prove their identity with authentication. Integrity provides assurances that data and systems have not been modified. Confidentiality protects against the unauthorized disclosure of data." "Your organization has implemented a least privilege policy. Which of the following choices describes the most likely result of this policy? A. It adds multiple layers of security. B. No single user has full control over any process. C. Users can only access data they need to perform their jobs. D. It prevents users from denying they took an action. – Correct answer [Security Fundamentals] C. The principle of least privilege ensures that users have access to the data they need to perform their jobs, but no more. Defense in depth ensures an organization has multiple layers of security. Separation of duties ensures that no single user has full control over any process. Non-repudiation prevents users from denying they took an action." "Your organization wants to implement policies that will deter fraud by dividing job responsibilities. Which of the following policies should they implement? A. Nonrepudiation B. Least privilege C. Defense in depth D. Separation of duties - Correct answer [Security Fundamentals] D. Separation of duties helps prevent fraud by dividing job responsibilities and ensuring that no single person has complete control over an entire process. Nonrepudiation ensures that parties are not able to deny taking an action. The principle of least privilege ensures that users have only the rights and permissions they need to perform their jobs, but no more. Defense in depth provides a layered approach to security." "Which one of the following concepts provides the strongest security? A. Defense in depth B. Nonrepudiation C. Security triad D. AAAs of security - Correct answer [Security Fundamentals] A. Defense in depth provides a layered approach to security by implementing several different security practices simultaneously and is the best choice of the available answers to provide the strongest security. The security triad (confidentiality, integrity, and availability) identifies the main goals of security. Nonrepudiation prevents an individual from denying that he or she took an action. The AAAs of security are authentication, authorization, and accounting." "Which of the following would a financial institution use to validate an e-commerce transaction? A. Nonrepudiation B. Least privilege C. Authentication D. Signature - Correct answer [Security Fundamentals] A. Digital signatures used by some online institutions to validate transactions and provide nonrepudiation. Least privilege ensures that users have only the rights and permissions they need to perform their jobs, and no more. Authentication verifies a user's identity. A written signature is not used in e-commerce." "What are the AAAs of information security? A. Authentication, availability, and authorization B. Accounting, authentication, and availability C. Authentication, authorization, and accounting D. Availability, accountability, and authorization - Correct answer [Security Fundamentals] C. The AAAs of information security are authentication, authorization, and accounting. Availability is part of the CIA security triad (confidentiality, integrity, and availability), but it is not part of the AAAs of information security." "You want to ensure that a system can identify individual users track their activity, and log their actions. What does this provide? A. Accountability B. Availability C. Authentication D. Authorization - Correct answer [Security Fundamentals] A. If a system can identify individual users, track their activity, and log their actions, it provides accountability. Availability ensures the system is operational when needed. Authentication identifies the individual using credentials. Authorization identifies resources that a user can access." "Which of the following is required to support accountability? A. Encryption B. Authentication C. Hashing D. Redundant systems - Correct answer [Security Fundamentals] B. Users prove their identity with authentication, and strong authentication mechanisms are required to support accountability. Encryption helps provide confidentiality. Hashing helps provide integrity. Redundant systems help provide availability." "Which of the following statements accurately describes due care? A. It is the practice of implementing security policies and procedures to protect resources. B. Due care eliminates risk. C. A company is not responsible for exercising due care over PII. D. Organizations cannot be sued if they fail to exercise due care over resources such as customer data. - Correct answer [Security Fundamentals] A. Due care is the practice of implementing security policies and procedures to protect resources. You cannot eliminate risk. A company is responsible for exercising due care over PII and can be sued if it fails to exercise due care." "A user professes an identity by entering a user logon name and then enters a password. What is the purpose of the logon name? A. Authentication B. Accountability C. Identification D. Accounting - Correct answer [Access Controls] C. The logon name provides identification of the user. When combined with the username, the password provides authentication." "Access controls protect assets such as files by preventing unauthorized access. What must occur before a system can implement access controls to restrict access to these types of assets? A. Identification and authentication B. Identification and accountability C. Authentication and accounting D. Accountability and availability - Correct answer [Access Controls] A. Identification and authentication must occur before a system can implement access controls. Identification is the act of a user professing an identity, and authentication occurs when an authentication system verifies the user's credentials (such as a username and password)." "Users are required to enter a different password each time they log on. What type of password is this? A. Static password B. Cognitive password C. Passphrase D. Dynamic password - Correct answer [Access Controls] D. A dynamic password is a one-time password that changes for each session." "Authentication includes three types or factors. Which of the following best describes these authentication methods? A. Something you say, something you think, and something you are B. Something you know, something you have, and something you type C. Something you know, something you say, and something you are D. Something you know, something you have, and something you are - Correct answer [Access Controls] D. The three factors of authentication are something you know, something you have, and something you are. Something you think, something you type, or something you say are not authentication factors." "Which of the following choices does NOT ensure that a password is strong? A. Ensuring that the password is of a sufficient length B. Ensuring that the password is changed frequently C. Ensuring that the password has a mixture of different character types D. Ensuring that the password does not include any part of the user's name - Correct answer [Access Controls] B. A password should be changed regularly, but doing so doesn't ensure the password is strong. For example, if a user changes a password from "1234" to "4321," it is not strong. The other options all contribute to the strength of a password." "What can be used to prevent a user from reusing the same password? A. Minimum password age B. Maximum password age C. Password length D. Password history - Correct answer [Access Controls] D. Password history remembers users' previous passwords and prevents them from reusing passwords." "What form(s) of authentication are individuals using when they authenticate with a hardware token and a password? A. Something they have only B. Something they know only C. Something they have and something they know D. Something they have and something they are - Correct answer [Access Controls] C. The two factors of authentication are something they have (the hardware token) and something they know (the password). The third factor of authentication is something you are (using biometrics), but neither a hardware token nor a PIN uses biometrics." "An organization uses a biometric system with a one-to-many search method. What does this system provide for the organization? A. Authentication B. Accountability C. Authorization D. Identification - Correct answer [Access Controls] D. A biometric system used for identification uses a one-to-many search method. Biometric systems used for authentication use a one-to-one search method. Once a system identifies and authenticates a user, biometric systems are not used for accountability or authorization." "An organization has been using an iris scanner for authentication but has noticed a significant number of errors. Assuming the iris scanner is a high-quality scanner which of the following could affect its accuracy? A. False Acceptance Rate (FAR) B. False Rejection Rate (FRR) C. Sunlight shining into the scanner D. Faulty laser beam - Correct answer [Access Controls] C. Lighting affects the accuracy of an iris scanner, so sunlight shining into the scanner's aperture will affect the accuracy." "Which of the following metrics identifies the number of valid users that a biometric authentication system falsely rejects? A. FAR B. FRR C. CER D. AAA - Correct answer [Access Controls] B. The False Rejection Rate (FRR, also called a type 1 error) refers to the percentage of times a biometric system falsely rejects a known user." "Which of the following biometric methods has the lowest CER? A. Iris scan B. Handwriting analysis C. Keystroke dynamics D. Thumbprint scan - Correct answer [Access Controls] A. Iris scans are the most accurate of the items listed and have the lowest Crossover Error Rate (CER). A. Single sign-on (SSO) requires users to log on once, and it uses the same credentials for any other resources accessed during the session." "What is SSO? A. A system that requires user credentials once and uses the same credentials for the entire session B. An authentication system that requires users to use different credentials for each resource they access C. A secure system used for operations D. Any network that employs secure access controls - Correct answer [Access Controls] A. Single sign-on (SSO) requires users to log on once, and it uses the same credentials for any other resources accessed during the session." "What type of service does Kerberos provide? A. Authentication B. Accounting C. Availability D. Accountability - Correct answer [Access Controls] A. Kerberos provides authentication. Accounting and accountability are possible if a system can identify users and track their activities," "Of the following choices what most accurately identifies the major drawback of SSO systems? A. It allows users to access multiple systems after logging on once. B. It increases the difficulty for users to log on. C. It increases the administrative workload. D. It risks maximum unauthorized access with compromised accounts. - Correct answer [Access Controls] D. A major concern with SSO systems is that if any single account is compromised, it maximizes the potential unauthorized access." "What type of access control is identity based? A. Discretionary B. Non-discretionary C. ABAC D. Biba - Correct answer [Access Controls] A. A Discretionary Access Control (DAC) model assigns permissions to identities, making it an identity-based model." "What is the primary goal of the Bell-LaPadula model? A. Enforce separation of duties B. Enforce two-factor authentication C. Enforce confidentiality D. Enforce integrity - Correct answer [Access Controls] C. The Bell-LaPadula model has a primary goal of ensuring confidentiality." "Which of the following models helps enforce the principle of separation of duties? A. Chinese Wall and Clark-Wilson B. Chinese Wall and Biba C. Clark-Wilson and Bell-LaPadula D. Biba and Bell-LaPadula - Correct answer [Access Controls] A. Both the Clark-Wilson model and the Chinese Wall model enforce the principle of separation of duties. The Clark-Wilson model also enforces integrity, and the Chinese Wall model also helps prevent conflicts of interest. Biba enforces integrity. Bell-LaPadula enforces confidentiality." "Which of the following statements is true? A. An access control matrix is object based and a capability table is object based. B. An access control matrix is subject based and a capability table is object based. C. An access control matrix is object based and a capability table is subject based. D. An access control matrix is subject based and a capability table is subject based. - Correct answer [Access Controls] C. An access control matrix is object based and a capability table is subject based." "Which of the following will disable an account if an attacker tries to guess the password multiple times? A. A password policy B. An account lockout policy C. A password history D. De-provisioning accounts - Correct answer [Access Controls] B. An account lockout policy can disable an account if an attacker (or a user) enters the wrong password too many times." "Which of the following actions is most appropriate if an employee leaves the company? A. Delete the user's account as soon as possible. B. Disable the user's account as soon as possible. C. Change the user's password as soon as possible. D. Change the user's permissions as soon as possible. - Correct answer [Access Controls] B. User accounts should be disabled as soon as possible after the user leaves the company under any circumstances." "Which layer of the OSI Model defines cable standards? A. Physical layer B. Data Link layer C. Network layer D. Transport layer - Correct answer [Basic Networking and Communications] A. Cable standards are defined at the Physical layer, layer 1. They are not defined at the Data Link layer (layer 2), the Network layer (layer 3), or the Transport layer (layer 4)." "Which layer of the OSI Model packages data as a frame? A. Physical layer B. Data Link layer C. Network layer D. Transport layer - Correct answer [Basic Networking and Communications] B. The Data Link layer packages data as a frame. The Physical layer packages data as bits. The Network layer packages data as a packet. The Transport layer packages data as a segment." "Which layer of the OSI Model handles physical addressing? A. Physical layer B. Network layer C. Data Link layer D. Transport layer - Correct answer [Basic Networking and Communications] C. The Data Link layer uses physical addresses, also called hardware addresses and media access control (MAC) addresses. The Physical layer packages data as bits and doesn,t use addresses. The Network layer uses IP addresses (also called logical addresses). The Transport layer doesn,t use addresses but uses ports to identify traffic." "Which layer of the OSI Model packages data as a packet? A. Physical layer B. Data Link layer C. Network layer D. Transport layer - Correct answer [Basic Networking and Communications] C. The Network layer packages data as a packet. The Physical layer packages data as bits. The Data Link layer packages data as a frame. The Transport layer packages data as a segment." "Which layer of the OSI Model provides reliable end-to-end communication services? A. Physical layer B. Transport layer C. Data Link layer D. Host layer - Correct answer [Basic Networking and Communications] B. The Transport layer provides reliable end-to-end communication services. Neither the Physical layer nor the Data Link layer provides this service. The Host layer is on the TCP/IP Model, not the OSI Model." "Which layer of the OSI Model includes TCP and UDP? A. Transport layer B. Network layer C. Data Link layer D. Application - Correct answer [Basic Networking and Communications] A. The Transport layer includes the TCP and UDP protocols. These protocols are not implemented on the Network layer, the Data Link layer, or the Application layer." "Which of the following protocols is connection oriented? A. IP B. RIP C. TCP D. UDP - Correct answer [Basic Networking and Communications] C. TCP is connection oriented. IP uses TCP to provide a connection-oriented session but is not connection oriented itself. RIP is a routing protocol and is not connection oriented. UDP is connectionless. Instead of establishing a session, it makes a best effort to deliver data." "Which layer of the TCP/IP Model corresponds to the OSI Network layer? A. Host layer B. Application layer C. Internet layer D. Link layer - Correct answer [Basic Networking and Communications] C. The TCP/IP Internet layer corresponds to the OSI Network layer. The TCP/ IP Host (or Host-to-Host) layer corresponds to the OSI Transport layer. The TCP/IP Application layer corresponds to the Application, Presentation, and Session OSI layers. The TCP/IP Link layer (also called the Network Interface or Network Access layer) corresponds to the OSI Data Link and Physical layers." "Which of the following topologies avoids collisions using a token? A. IEEE 802.3 B. IEEE 802.5 C. CSMA/CD D. CSMA/CA - Correct answer [Basic Networking and Communications] B. IEEE 802.5 defines token ring networks, which avoid collisions using a token. Ethernet (IEEE 802.3) attempts to detect collisions using Carrier Sense Multiple Access with Collision Detection (CSMA/CD). Wireless networks (802.11) attempt to avoid collisions using Carrier Sense Multiple Access with Collision Avoidance (CSMA/CA)." "What protocol would a system use to determine a systems physical address? A. ARP B. RARP C. BootP D. DNS - Correct answer [Basic Networking and Communications] A. Systems use the Address Resolution Protocol (ARP) to identify the assigned physical (or MAC) address matching an assigned IP address. Reverse ARP (RARP) allows a system with a MAC address to get an IP address. The Bootstrap Protocol (BootP) allows a diskless system to get an IP address and then download the image of an operating system. Domain Name System (DNS) resolves host names to IP addresses but not physical addresses." "Which of these ports does DNS use? A. TCP 23 B. TCP 25 C. UDP 53 D. UDP 69 - Correct answer [Basic Networking and Communications] C. Domain Name System (DNS) uses UDP port 53 when clients query the DNS server and TCP port 53 when DNS servers transfer data between each other. Telnet uses TCP port 23. Simple Mail Transfer Protocol (SMTP) uses TCP port 25. Trivial FTP (TFTP) uses UDP port 69." "Which of the following protocols is commonly used with diagnostic utilities? A. TFTP B. RARP C. IGMP D. ICMP - Correct answer [Basic Networking and Communications] D. Many diagnostic utilities such as ping, pathping, and tracert use Internet Control Message Protocol (ICMP). Administrators commonly use Trivial FTP (TFTP) to transfer configuration files to and from network devices. Reverse ARP (RARP) allows a system with a MAC address to get an IP address. The Internet Group Message Protocol (IGMP) is used for IPv4 multicasting." "Which of the following accurately identifies a difference between FTP and TFTP? A. FTP uses UDP and TFTP uses TCP. B. FTP supports authentication but TFTP does not support authentication. C. TFTP sends data across a network in cleartext, but FTP encrypts data. D. TFTP is primarily used to transfer large files, and FTP is used to transfer configuration information to and from network devices., - Correct answer [Basic Networking and Communications] B. File Transfer Protocol (FTP) supports authentication, but Trivial FTP (TFTP) does not support authentication. FTP uses TCP ports 20 and 21, while TFTP uses UDP port 69. Both FTP and TFTP send data across a network in cleartext, but it is possible to encrypt FTP with Secure Shell (as SFTP). TFTP is commonly used to transfer configuration files to and from network devices, and FTP is primarily used to transfer large files." "Which of the following protocols is a more secure alternative for remote login? A. Telnet B. rlogin C. rexec D. SSH - Correct answer [Basic Networking and Communications] D. Secure Shell (SSH) encrypts data sent over a network and is the most secure method for remotely accessing systems of the given choices. Telnet, rlogin (which is remote login), and rexec (remote execute) all send data across a network in cleartext." "What port does POP3 use? A. 25 B. 110 C. 143 D. 443 - Correct answer [Basic Networking and Communications] B. Post Office Protocol version 3 (POP3) uses TCP port 110. Simple Mail Transfer Protocol (SMTP) uses TCP port 25. Internet Message Access Protocol version 4 (IMAP4) uses TCP port 143. HyperText Transfer Protocol Secure (HTTPS) uses TCP port 443." "You are purchasing a product from a website. Which of the following protocols will your system most likely use to provide confidentiality for this transaction? A. SSL B. SSH C. IPsec D. HTTP - Correct answer [Basic Networking and Communications] A. E-commerce transactions use HyperText Transfer Protocol Secure (HTTPS) for confidentiality, and Secure Sockets Layer (SSL) is one of the protocols used to encrypt HTTPS. While not one of the choices, Transport Layer Security (TLS) isalso commonly used to encrypt HTTPS. While Secure Shell (SSH) and Internet Protocol security (IPsec) both provide confidentiality with encryption, HTTPS doesn,t use SSH or IPsec. HTTP sends data in cleartext, so it doesn,t provide confidentiality." "Which of the following statements is correct related to IPsec? A. IPsec provides confidentiality by encrypting data with AH. B. IPsec provides confidentiality by encrypting data on the Network layer. C. IPsec AH uses protocol number 50. D. IPsec ESP uses protocol number 51. - Correct answer [Basic Networking and Communications] B. Internet Protocol security (IPsec) provides confidentiality by encrypting data on the Network layer. Encapsulating Security Payload (ESP) provides confidentiality by encrypting data, but Authentication Header (AH) only provides authentication and integrity. AH uses protocol number 51, and ESP uses protocol number 50." "What is the protocol number for IPsec AH? A. 1 B. 6 C. 50 D. 51 - Correct answer [Basic Networking and Communications] D. The protocol number for Internet Protocol security (IPsec) Authentication Header is 51. The protocol number for IPsec Encapsulating Security Protocol (ESP) is 50. The protocol number for Internet Control Message protocol (ICMP) is 1, and the protocol number for Transmission Control Protocol (TCP) is 6." "Where is a DMZ located? A. Behind the intranet firewall B. In front of the first intranet-facing firewall C. In front of the first Internet-facing firewall D. Behind the first Internet-facing firewall - Correct answer [Basic Networking and Communications] D. A demilitarized zone (DMZ), or perimeter network, is located behind the first Internet-facing firewall. It is not on the private network (behind the intranet firewall) or directly on the Internet (in front of the intranet or Internet-facing firewall)." "Which of the following is the recommended security mechanism to use with wireless networks? A. 802.11a B. 802.11g C. 802.11i D. 802.11n - Correct answer [Basic Networking and Communications] C. The 802.11i standard documents Wi-Fi Protected Access 2 (WPA2), the recommended security mechanism for wireless networks. It uses AES-based CCMP for very strong security. The other standards focus on the base frequency and speed of wireless networks, not security." "Which of the following best describes the mapping of data held within a switch's table? A. IP address to port B. MAC address to port C. IP address to MAC address D. Physical port to logical port - Correct answer [Advanced Networking & Communications] B. A table in a switch maps the media access control (MAC) address to the physical port. Routers map network IP addresses to the physical port with the corresponding gateway IP addresses. The Address Resolution Protocol (ARP) resolves IP addresses to MAC addresses, but this data is not held in a switch. Physical ports and logical ports are not mapped together." "Which of the following is the best choice to segment traffic on a network? A. VLAN B. EAP C. SSL D. TLS - Correct answer [Advanced Networking & Communications] A. A virtual local area network (VLAN) segments traffic on a network using a switch. Extensible Authentication Protocol (EAP) is used for authentication, not segmentation. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are transport encryption protocols and do not segment traffic." "Which of the following can provide security for VoIP? A. RADIUS B. TACACS+ C. PSTN D. SRTP - Correct answer [Advanced Networking & Communications] D. The Secure Real-time Transport Protocol (SRTP) provides confidentiality, authentication, and replay protection for Voice over IP (VoIP) transmissions. Remote Authentication Dial-in User Service (RADIUS) and Terminal Access Controller Access Control System+ (TACACS+) are used to provide authentication, authorization, and accounting (AAA) for remote access. The public switched telephone network (PSTN) is one of the methods used for Internet access." "Your organization has a private phone system. Of the following what is the best choice to control call forwarding? A. Ensure that the administrator password is kept private and changed often. B. Restrict phone numbers that can be used with call forwarding. C. Restrict long distance calling. D. Protect the phone system with physical security. - Correct answer [Advanced Networking & Communications] B. The primary way to control call forwarding is to restrict numbers that can be used for call forwarding. Protecting the administrator password and changing it often protects the overall system, but doesn't directly address call forwarding. Restricting long distance calling is also important, but it doesn't address call forwarding. Although physical security of the phone system is valuable, it won't control call forwarding." "Of the following choices what represents the primary benefits provided by a proxy server? A. Caching and filtering B. Authentication and caching C. Authentication, authorization, and accounting D. Stateful inspection - Correct answer [Advanced Networking & Communications] A. A proxy server can cache web pages that are retrieved from the Internet. It can also block users from accessing restricted websites by filtering the web page requests. A proxy server does not provide authentication directly, although some proxy servers can be tied into an authentication system. A proxy server does not normally perform firewall functions." "A packet-filtering firewall can block ICMP traffic such as ping requests. How does a packet-filtering firewall identify ICMP traffic? A. Based on the protocol ID having a value of 1 B. Based on the protocol ID having a value of 2 C. Based on the port of 50 D. Based on the port of 51 - Correct answer [Advanced Networking & Communications] A. Packet-filtering firewalls can filter traffic based on IP addresses, ports, and protocol IDs, and a protocol ID of 1 identifies Internet Control Message Protocol (ICMP) traffic. Internet Group Message Protocol (IGMP) uses a protocol ID of 2. Internet Protocol security (IPsec) is not identified by ports. IPsec Encapsulating Security Protocol (ESP) has a protocol ID of 50, and IPsec Authentication Header (AH) has a protocol ID of 51." "Which of the following choices provides the best protection against potentially malicious FTP commands? A. Defense diversity B. Packet-filtering firewall C. Stateful inspection firewall D. Application firewall - Correct answer [Advanced Networking & Communications] D. An application firewall (also called an application proxy or an application gateway firewall) can inspect commands used by individual protocols such as File Transfer Protocol (FTP) and block potentially malicious commands. Defense diversity refers to using firewalls from two different vendors in a demilitarized zone (DMZ). A packet-filtering firewall can only inspect individual packets for IP addresses, ports, and protocol IDs. A stateful inspection firewall can track the activity within TCP and UDP sessions, but can't interpret commands." "How can you provide defense diversity with a DMZ? A. Use a single firewall. B. Use two firewalls from the same vendor. C. Use two firewalls from different vendors. D. Ensure that only trusted partners are allowed access. - Correct answer [Advanced Networking & Communications] C. You can provide defense diversity with a DMZ by using two firewalls from different vendors. If a vulnerability appears in one, it's unlikely that a vulnerability will exist in the second firewall at the same time (unless the second is from the same vendor). A single firewall doesn't provide any diversity. An extranet (not a DMZ) would allow access only to trusted partners." "It's common to enable or install a firewall on a server to protect the server. What type of firewall is this? A. Network-based B. Hardware-based C. Packet-filtering D. Host-based - Correct answer [Advanced Networking & Communications] D. A host-based firewall is installed or enabled on individual hosts, such as desktop computers or servers, and provides protection for the host. Network- based firewalls protect the network rather than individual systems. Packet filtering identifies the method used by the firewall, and both network-based and host- based firewalls can filter packets." "Of the following choices what is NOT used for VPNs? A. L2TP B. PPTP C. SSLTP D. TLS - Correct answer [Advanced Networking & Communications] C. There is no such thing as SSLTP in the context of virtual private networks (VPNs). The other choices (L2TP, PPTP, and TLS) are used for VPNs." "What port does PPTP typically use? A. 143 B. 443 C. 1701 D. 1723 - Correct answer [Advanced Networking & Communications] D. The Point-to-Point Tunneling Protocol (PPTP) uses TCP port 1723. Internet Message Access Protocol version 4 (IMAP4) uses TCP port 143, Transport Layer Security (TLS) and Secure Sockets Layer (SSL) use TCP port 443, and Layer 2 Tunneling Protocol (L2TP) uses UDP port 1701." "What port does a TLS VPN typically use? A. 80 B. 88 C. 143 D. 443 - Correct answer [Advanced Networking & Communications] D. A Transport Layer Security (TLS) virtual private network (VPN) typically uses TCP port 443, the same port as HyperText Transfer Protocol Secure (HTTPS). HyperText Transfer Protocol (HTTP) uses TCP port 80. Kerberos uses TCP port 88. Internet Message Access Protocol version 4 (IMAP4) uses port 143." "How would users typically access a TLS VPN? A. With a web browser B. With a dedicated application C. With broadband access but never DSL access D. With an IMAP application - Correct answer [Advanced Networking & Communications] A. Users typically access a Transport Layer Security (TLS) virtual private network (VPN) using a web browser instead of a dedicated application. A TLS VPN is not dependent on a specific type of Internet connection (such as broadband or DSL). Internet Message Access Protocol (IMAP) is used with e-mail, not VPNs." "Of the following choices what indicates the primary improvement that MS-CHAPv2 included over previous protocols? A. Support for biometrics B. Use of certificates C. Mutual authentication D. Use of a nonce - Correct answer [Advanced Networking & Communications] C. MS-CHAPv2 uses mutual authentication, where the client authenticates to the server and the server authenticates to the client. MS-CHAPv2 does not directly support biometrics. MS-CHAPv2 can be used with the Extensible Authentication Protocol (EAP) to support certificates, but it cannot do so on its own. CHAP uses a nonce (a number used once), so this isn't an improvement." "Which of the following identifies the correct representation of RADIUS? A. Remote Access Dial-in User System. B. Remote Authentication Dial-in User Service C. Roaming Access Dial-in User Service D. Remote Authentication Dialing User System - Correct answer [Advanced Networking & Communications] B. RADIUS is an acronym for Remote Authentication Dial-in User Service. The other choices are not valid." "What port does TACACS+ typically use? A. 25 B. 49 C. 53 D. 443 - Correct answer [Advanced Networking & Communications] B. Terminal Access Controller Access Control System+ uses TCP port 49. Simple Mail Transport Protocol (SMTP) uses TCP port 25, Domain Name System (DNS) uses TCP port 53 and UDP port 53, and HyperText Transfer Protocol Secure (HTTPS) uses TCP port 443." "What can be used to examine the health of a client prior to allowing network access and restricting access of unhealthy clients to a quarantined network? A. RADIUS B. TACACS+ C. NAC D. SRTP - Correct answer [Advanced Networking & Communications] C. A network access control (NAC) system can check a system's health based on a predefined health policy and restrict the access of unhealthy clients to a quarantined network. Remote Authentication Dial-in User Service (RADIUS) and Terminal Access Controller Access Control System+ (TACACS+) are used to provide authentication, authorization, and accounting (AAA) for remote access. Secure Real-time Transport Protocol (SRTP) provides confidentiality, authentication, and replay protection for Voice over IP (VoIP) transmissions." "Which of the following represents the greatest risk to virtual systems? A. Confidentiality B. VM escape C. Increased costs for power and cooling D. Loss of control of data in the cloud - Correct answer [Advanced Networking & Communications] B. VM escape is a known attack against virtual systems. If the attack is successful, an attacker can access the host system and all virtual systems within the host. Loss of confidentiality (not confidentiality) is a risk that can be reduced with encryption. Virtualization reduces costs for power and cooling. Loss of control of data stored in the cloud is a risk associated with cloud computing, but organizations can use virtual systems internally to keep control of their data." "Which of the following is an example of SaaS? A. Access to an operating system over the Internet B. Access to a server over the Internet C. Web-based e-mail D. VM escape - Correct answer [Advanced Networking & Communications] C. Web-based e-mail is an example of Software-as-a-Service (SaaS). SaaS, also known as on-demand software, provides users with access to software or applications over the Internet. Platform-as-a-Service (PaaS) is a cloud computing service where users have access to a platform with an operating system. Infrastructure-as-a-Service (IaaS) provides users with access to hardware such as servers or network devices. VM escape is an attack on virtual systems." "An organization is sharing resources with another organization using cloud-based computing. Which of the following cloud operation models does this describe? A. Community B. Hybrid C. Private D. Public - Correct answer [Advanced Networking & Communications] A. A community cloud is a private cloud that is shared by two or more organizations. A hybrid cloud is a combination of any two or more clouds. A private cloud is only available to users within an organization. Public cloud- based services are provided by third-party vendors and are available to anyone." "What is an APT? A. A group often sponsored by a government, that has the capability and intent to launch persistent attacks against an organization B. Software that alerts a user that their system is infected with malware, but won't remove the malware unless the user pays a fee C. An attack that redirects users to a bogus website D. A scan to detect open ports - Correct answer [Attacks] A. An advanced persistent threat (APT) is a group of people (often sponsored by a government) that has the capability and intent to launch persistent attacks against organizations. Scareware is software that alerts a user their system is infected with malware, but won't remove the malware unless the user pays. Pharming is an attack that redirects users to a bogus website. A port scan is a scan that detects open ports." "What is the difference between a DoS attack and a DDoS attack? A. There is no real difference. B. A DoS attack uses technical methods but a DDoS attack uses nontechnical methods. C. A DDoS attack is an attack from a single system, but a DoS attack is an attack from multiple systems. D. A DoS attack is an attack from a single system, but a DDoS attack is an attack from multiple - Correct answer [Attacks] D. A DoS attack is an attack from a single system, and a DDoS attack is an attack from multiple systems. Both typically use technical methods." "Of the following choices what is a common DoS attack? A. TCP flood B. Tailgating C. Smishing the following choices, what is a common DoS attack? D. Whaling - Correct answer [Attacks] A. A TCP flood attack (also known as a SYN flood, TCP SYN, or TCP half- open attack) is a common DoS attack that withholds the third packet of the TCP three-way handshake. The other answers are not DoS attacks. Tailgating is a social engineering tactic. Smishing is a form of phishing using SMS messages. Whaling is a form of phishing against a single person, such as an executive." "Thousands of computers have been infected with malware and are periodically directed to send out spam to other computers. What does this describe? A. Zombies B. Spear phishing C. A botnet D. Phishing - Correct answer [Attacks] C. A botnet is a group of computers that an attacker has taken over and now controls from a command and control center. The individual computers are referred to as zombies, but together they are a botnet. They may be directed to send out phishing or spear phishing e-mails, but that is the attack, not the network." "Which of the following best identifies a computer controlled by a botnet? A. DoS computer B. DDoS computer C. Attacker D. Zombie - Correct answer [Attacks] D. Computers controlled within a botnet are commonly called zombies. They are not referred to as DoS or DDoS computers, or attackers, although they can be directed to take part in a DDoS attack." "An attacker is using Wireshark to capture and analyze TCP sessions. What is the best term that identifies this action? A. Dumpster diving B. Shoulder surfing C. Sniffing D. Vishing - Correct answer [Attacks] C. Sniffing is the practice of capturing and analyzing packets with a sniffer (a protocol analyzer). Dumpster diving refers to going through the trash looking for information. Shoulder surfing is the practice of looking over someone's shoulder to gain information, such as the password that a user enters to log on. Vishing is a form of phishing using telephones or VoIP." "A system has a protocol analyzer installed. What mode must the system operate in to capture all packets that reach it including those that are not directly addressed to or from the system? A. Promiscuous B. Nonpromiscuous C. DoS D. DDoS - Correct answer [Attacks] A. The network interface card of the system running the protocol analyzer (or sniffer) must be in promiscuous mode. If it is in nonpromiscuous mode, the sniffer will only capture packets addressed directly to or from the sniffer. DoS and DDoS are not modes for a sniffer." "An attacker has written a program to shave off a penny from each transaction and divert the penny to the attacker's bank account. What best describes this attack? A. Salami attack B. Sniffing attack C. Replay attack D. Covert channel - Correct answer [Attacks] A. A salami attack uses multiple small, usually unnoticeable actions, such as shaving a penny off a transaction. A sniffing attack uses a sniffer (protocol analyzer) to capture and analyze traffic. A replay attack captures data and then later resends it to impersonate one of the parties. A covert channel uses an uncommon communications path to exchange information surreptitiously." "Of the following choices what provides the best protection against buffer overflow attacks? A. SQL injection B. Input validation C. Cross-site scripting D. Code signing - Correct answer [Attacks] B. Input validation techniques validate data before using it and can help prevent a wide variety of attacks, including buffer overflow attacks. SQL injection is an attack that attempts to inject SQL code into an application. Cross-site scripting is an attack that attempts to inject HTML or JavaScript code into a web page. Code signing uses a certificate to digitally sign an application, but will not protect against buffer overflow attacks." "An application has received more input than it expected and the resulting error has exposed normally protected memory. What is the best explanation for what happened? A. Phishing attack B. Salami attack C. Buffer overflow D. Session hijacking - Correct answer [Attacks] C. A buffer overflow occurs when an application receives more input than it expected and it is not able to handle the error gracefully. Attackers exploit buffer overflows to insert malware into systems. The best protection against a buffer overflow is to keep systems up to date. A phishing attack is sent through e-mail. A salami attack uses multiple small, usually unnoticeable actions, such as shaving a penny off a transaction. Session hijacking attempts to take over a session." "What type of attack can access data in a database used by a website? A. Cross-site scripting B. Cross-site request forgery C. Rootkit D. SQL injection - Correct answer [Attacks] D. A successful SQL injection attack can access data in a database. Cross-site scripting injects HTML or JavaScript into a web page and runs the code on a user's system. A cross-site request forgery attack performs actions on behalf of a user without the user's knowledge. A rootkit is malware that takes over a user's system." "A website is preventing users from entering the and characters when they enter data. What is the website trying to prevent? A. SQL injection attack B. Cross-site scripting attack C. Input validation attack D. Trojan horse - Correct answer [Attacks] B. Cross-site scripting (XSS) injects HTML or JavaScript into a web page, and input validation techniques help prevent XSS attacks. The users are prevented from entering HTML or JavaScript tags that start with and end with . A SQL injection attack uses SQL code, but SQL code does not use or characters. Input validation is a prevention technique, not an attack. A Trojan horse is an application that looks like it's something useful but is actually something malicious." "A user receives an e-mail indicating that the bank has detected suspicious activity on the user's bank account. The message indicates the user should log on immediately to prevent loss of funds. What is the best term to describe this attack? A. Sniffing B. Session hijacking C. Phishing D. Tailgating - Correct answer [Attacks] C. A phishing attack sends an e-mail to multiple recipients impersonating an e-mail from a legitimate company, indicating a problem, urging the recipient to take action, and warning of dire consequences if the recipient doesn't respond. A sniffing attack uses a protocol analyzer such as Wireshark to capture and analyze traffic. Session hijacking attempts to take over sessions and doesn't use e-mail. Tailgating is the practice of one person following another into a secure area while only the first person provides credentials." "An attacker sends an e-mail to many members of an organization and spoofs the From address so that the e-mail looks like it came from within the organization. The e-mail tries to trick recipients into following a link. What is the best definition of this action? A. Phishing B. Spear phishing C. Whaling D. Vishing - Correct answer [Attacks] B. Spear phishing is a phishing tactic that targets a specific organization. Phishing doesn't target individual organizations, but instead casts a wide net, hoping to catch someone. Whaling targets a specific individual, such as an executive. Vishing uses voice methods such as the telephone or VoIP." "A system has been attacked by an exploit that isn't published. What type of attack is this? A. Scareware B. APT C. Pharming D. Zero day - Correct answer [Attacks] D. Zero day exploits are attacks that take advantage of vulnerabilities that are unpublished and often include attacks that are unknown by the vendor. The other answers are known methods. Scareware is malware that scares users into thinking their system is infected with a virus and encourages them to install malware on their system. An advanced persistent threat (APT) is a group of people who have the capability and intent to launch extended attacks against organizations. Pharming is an attack that redirects users to bogus websites." "A user connected to a free wireless network at a coffee shop to access Facebook. Later someone else started making posts on the user's page. What is the most likely cause of this? A. Zero day exploit B. WPS cracking C. Evil twin D. WPA cracking - Correct answer [Attacks] C. The most likely cause is an evil twin. An attacker likely created a free wireless hotspot in the coffee shop (perhaps on the attacker's laptop). When the user connected to it, the attacker captured the user's data, including logon credentials. This is a known attack, and whereas a zero day exploit is not widely known. Wi-Fi Protected Setup (WPS) cracking discovers the PIN of an access point and uses it to discover the access point's password. Wi-Fi Protected Access (WPA) cracking discovers the password on the access point by intercepting the four-way handshake and performing an offline brute-force attack." "An attacker uses nontechnical means to learn the e-mail address of a manager within a company. Which of the following best describes this attack? A. Social engineering B. Shoulder surfing C. Smishing D. Covert cramming - Correct answer [Attacks] A. Social engineering uses nontechnical (or low-technical) means to gain information, such as the names of people, e-mail addresses, and user credentials. Shoulder surfing is just looking over someone's shoulder, and although it may allow an attacker to see an e-mail address of a manager, it isn't the best answer. Smishing is a variant of phishing using SMS messages. There's no such thing as covert cramming." "Of the following choices what is the best method to prevent tailgating? A. Education B. Mantrap C. Antivirus software D. Access controls on the phone system - Correct answer [Attacks] B. A mantrap is the best method to prevent tailgating, which is the practice of one person following another into a secure area while only the first person provides credentials. Although education of employees can go a long way, ingrained courtesy sometimes overcomes security practices, and a person may actually open the door for a social engineer. Antivirus software, access controls, and the phone system aren't related to the social engineering practice of tailgating." "A user attempted to access http:/ A. Phishing B. Impersonation C. Whaling D. Pharming - Correct answer D. A pharming attack is one where the user is redirected to another website by manipulating one of the name resolution methods. Phishing involves sending an e-mail to many users and encouraging them to respond with personal information or by clicking a link. Impersonation, also known as masquerading or spoofing, is a social engineering tactic where the social engineer impersonates someone. Whaling is phishing attack that targets executives such as CEOs" "What is a primary goal of security-related user awareness training? A. Increase use of e-mail B. Change behavior C. Implement technical solutions D. Show how to use applications - Correct answer B. A primary goal of security awareness training is to change user behavior from unsafe practices to safe practices. It isn't related to applications such as e-mail, and end users aren't expected to implement technical solutions." "What type of virus attempts to protect itself from reverse engineering and prevent antivirus researchers from analyzing the malware? A. Armored virus B. Polymorphic virus C. Metamorphic virus D. Multipartite virus - Correct answer [Malicious Code and Activity] A. An armored virus attempts to prevent an AV researcher from reverse engineering it to determine what it is doing and how it is doing it. Although polymorphism and metamorphism can make it harder to reverse engineer a virus, they aren't the best answer, because these techniques primarily make it harder for AV software to detect the virus. A multipartite virus uses multiple methods of attack" "Which of the following malware types alters its own code to avoid detection by antivirus software? A. Armored virus B. Metamorphic virus C. Polymorphic virus D. Ransomware - Correct answer [Malicious Code and Activity] B. A metamorphic virus changes or mutates its code as it replicates itself to prevent detection. An armored virus uses techniques such as encryption to make it more difficult for AV researchers to decompile the virus. A polymorphic virus changes the file, but not the code. Ransomware takes over a user's computer and demands a monetary ransom to return control back to the user." "What type of malware can spread without any user intervention? A. Virus B. Trojan horse C. Worm D. Spyware - Correct answer [Malicious Code and Activity] C. Worms spread through a network without any user intervention. Viruses, Trojan horses, and spyware all require some level of interaction." "A software application appears to have a useful purpose but it includes malicious code. What does this describe? A. A virus B. A backdoor C. A worm D. A Trojan horse - Correct answer [Malicious Code and Activity] D. A Trojan horse appears to be something useful to the user but includes malicious code or malware. While Trojans often include viruses and backdoors, not all viruses and backdoors come from Trojans. Worms travel over the network and are not embedded in software applications." "After visiting a website a user sees a pop-up indicating a virus has infected his system and offering free antivirus software. He downloads the free antivirus software, but finds that it won't clean the virus unless he purchases the full version. What does this describe? A. Shareware B. Rootkit C. Freeware D. Scareware - Correct answer [Malicious Code and Activity] D. Scareware is malware that scares users into thinking a virus has infected their system and encourages them to install a free download. The free download appears as antivirus software that doesn't remove viruses unless users pay, but it often includes malware itself. Shareware is software that users are free to try and pay for if they like it and continue to use it. A rootkit takes over the system with root-level privileges. Freeware is free software." "When Sally turns her computer on she sees a screen indicating software has encrypted all of her data files. A message indicates she must pay $300 within 48 hours to access the decryption key. What does this describe? A. Logic bomb B. Ransomware C. Worm D. Spyware - Correct answer [Malicious Code and Activity] B. Ransomware takes control of a user's computer or data and demands a ransom to return control to the user. This scenario describes CryptoLocker. A logic bomb is malware that executes in response to an event such as a specific date and time. Worms infect computers over a network, and while worms deliver malware, not all worms include ransomware. Spyware is software installed on a user's system without the user's knowledge with the goal of spying on the user, not extorting money from the user." "An employee configured malicious code to execute at midnight on February 2. What does this describe? A. Logic bomb B. Groundhog Day virus C. Worm D. Ransomware - Correct answer [Malicious Code and Activity] A. A logic bomb is malware that executes in response to an event such as a specific date and time. While February 2 is Groundhog Day, the scenario doesn't describe a Groundhog Day virus. Worms infect computers over a network, not on a specific day. Ransomware takes control of a user's computer or data and demands a ransom from the user." "What type of malware takes control of the operating system at the kernel level? A. Trojan horse B. Worm C. Keylogger D. Rootkit - Correct answer [Malicious Code and Activity] D. A rootkit is a set of programs that runs on a system, largely undetected, because it runs at the kernel level or root level of the operating system. A Trojan horse is malware that looks like one thing but is something else. A worm is a type of malware that spreads through a network without any user intervention. A keylogger captures keystrokes from users." "A website developer wants to provide assurances to users that ActiveX controls used on the site are not malicious. What can provide this assurance? A. Input validation B. Code signing C. Code review D. Enabling cross-site scripting - Correct answer [Malicious Code and Activity] B. Code signing digitally signs ActiveX controls and provides assurances to users of who created the control and that it hasn't been modified. Input validation helps prevent injection attacks, but it's used to protect the website, not provide assurance to users. Code review is a valuable tool to detect problems with applications before an organization releases them. Cross-site scripting is an attack and would not be enabled." "What does antivirus software use to detect previously unknown viruses? A. Signatures B. Polymorphism C. Heuristics D. Armor - Correct answer [Malicious Code and Activity] C. Antivirus software uses heuristics to detect previously unknown viruses. Signatures detect known viruses. Polymorphism and armor are techniques used by virus authors to prevent the detection of a virus." "A virus is detected on a system based on the virus's behavior. What detected the virus? A. Heuristics B. A virus fingerprint C. A virus filter D. A signature - Correct answer [Malicious Code and Activity] A. Heuristics can detect malware based on the behavior of the malware and are designed to detect previously unknown viruses. There's no such thing as a virus filter or a virus fingerprint, although a virus signature does uniquely identify known malware similar to how a fingerprint can identify a person." "What should users do to ensure that antivirus software can detect recently released viruses? A. Update signatures B. Update the operating system C. Update the AV software D. Regularly purchase new AV software - Correct answer [Malicious Code and Activity] A. Antivirus software uses signature definition files to detect viruses, and these signatures must be regularly updated. It's not necessary to update the operating system, update the AV software, or purchase new AV software to detect recently released viruses." "Of the following choices how is malware most often delivered today? A. Over the Internet B. Via an intranet C. Via USB drives D. Through company policies - Correct answer [Malicious Code and Activity] A. The common way attackers deliver malware is over the Internet. While some attacks can come from internal intranet sources, they do not compete with the volume of attacks from the Internet. Unsuspecting users transmit viruses with USB drives, but this isn't as common as virus delivery over the Internet. Company policies would not deliver viruses." "A company authorizes users to transport data from work to home using USB drives. What's the best method of protecting systems from malware without affecting the user? A. Install AV software on the network firewall B. Install AV software on the e-mail server C. Install AV software on each user's work computer D. Prevent users from using USB drives - Correct answer [Malicious Code and Activity] C. Installing AV software on each user's work computer provides the best protection against a user inadvertently transporting malware from home to work. Installing software on the network firewall and on an e-mail server is a good practice, but it won't help if the virus is transported via a USB drive. Preventing the users from using USB drives will affect the users." "Of the following choices, what is the best technique you can implement on an e-mail server to reduce infection through e-mail? A. Block all e-mail B. Add a spam filter C. Add a polymorphic filter D. Remove all attachments - Correct answer [Malicious Code and Activity] B. The majority of malware comes through spam, so a spam filter can reduce infections through e-mail. An e-mail server isn't very useful if it blocks all e-mail or removes all attachments. E-mail servers don't have polymorphic filters." "Of the following choices which one is NOT a valid method to reduce malware infections? A. Don't open attachments from unsolicited e-mails. B. Don't click links in unsolicited e-mails. C. Don't send encrypted personal information via e-mail. D. Don't follow shortened links from unknown sources. - Correct answer [Malicious Code and Activity] C. If you need to send personal information via e-mail, the best choice is to send it in an encrypted format. All of the other choices are valid methods to reduce malware infections." "Of the following choices which one is a principle that prevents users from accidentally ins

Content preview

SSCP Exam Review Questions.
With correct and verified answers
How many years of experience are required to earn the Associate of (ISC)2 designation?

A. Zero
B. One
C. Two
D. Five

Correct answer [Security Fundamentals]

A. You don't need to meet the experience requirement to earn the Associate of (ISC)2 designation, so
zero years of experience are required. The SSCP certification requires one year of direct full-time
security work experience. If you earn the Associate of (ISC)2 designation, you have two years from
the date (ISC)2 notifies you that you have passed the SSCP exam to obtain the required experience
and apply to become a fully certified SSCP (which includes submitting the required endorsement
form). The CISSP certification requires five years of experience."

"What are the three elements of the security triad?

A. Authentication authorization, and accounting
B. Confidentiality, integrity, and availability
C. Identification, authentication, and authorization
D. Confidentiality, integrity, and authorization –

Correct answer [Security Fundamentals]

B. The CIA security triad includes three fundamental principles of security designed to prevent losses
in confidentiality, integrity, and availability. Authentication, authorization, and accounting are the
AAAs of security, and identification, authentication, and authorization are required for accountability,
but these are not part of the CIA security triad."

"Who is responsible for ensuring that security controls are in place to protect against the loss of
confidentiality integrity, or availability of their systems and data?

A. IT administrators
B. System and information owners
C. CFO
D. Everyone - Correct answer

[Security Fundamentals]

,B. System and information owners are responsible for ensuring that these security controls are in
place. IT administrators or other IT security personnel might implement and maintain them. While it
can be argued that the Chief Executive Officer (CEO) is ultimately responsible for all security, the
Chief Financial Officer is responsible for finances, not IT security. Assigning responsibility to everyone
results in no one taking responsibility."

"You are sending an e-mail to a business partner that includes proprietary data. You want to ensure
that the partner can access the data but that no one else can. What security principle should you
apply?

A. Authentication
B. Availability
C. Confidentiality
D. Integrity –

Correct answer [Security Fundamentals]

C. Confidentiality helps prevent the unauthorized disclosure of data to unauthorized personnel, and
you can enforce it with encryption in this scenario. Authentication allows a user to claim an identity
(such as with a username) and prove the identity (such as with a password). Availability ensures that
data is available when needed. Integrity ensures that the data hasn't been modified."

"Your organization wants to ensure that attackers are unable to modify data within a database. What
security principle is the organization trying to enforce?

A. Accountability
B. Availability
C. Confidentiality
D. Integrity –

Correct answer [Security Fundamentals]

D. Integrity ensures that data is not modified, and this includes data within a database.
Accountability ensures that systems identify users, track their actions, and monitor their behavior.
Availability ensures that IT systems and data are available when needed. Confidentiality protects
against the unauthorized disclosure of data."

"An organization wants to ensure that authorized employees are able to access resources during
normal business hours. What security principle is the organization trying to enforce?

A. Accountability
B. Availability
C. Integrity
D. Confidentiality –

Correct answer [Security Fundamentals]

,B. Availability ensures that IT systems and data are available when needed, such as during normal
business hours. Accountability ensures that users are accurately identified and authenticated, and
their actions are tracked with logs. Integrity ensures that data is not modified. Confidentiality
protects the unauthorized disclosure of data to unauthorized users."

"An organization has created a disaster recovery plan. What security principle is the organization
trying to enforce?

A. Authentication
B. Availability
C. Integrity
D. Confidentiality –

Correct answer [Security Fundamentals]

B. Availability ensures that IT systems and data are available when needed. Disaster recovery plans
help an organization ensure availability of critical systems after a disaster. Users prove their identity
with authentication. Integrity provides assurances that data and systems have not been modified.
Confidentiality protects against the unauthorized disclosure of data."

"Your organization has implemented a least privilege policy. Which of the following choices describes
the most likely result of this policy?

A. It adds multiple layers of security.
B. No single user has full control over any process.
C. Users can only access data they need to perform their jobs.
D. It prevents users from denying they took an action. –

Correct answer [Security Fundamentals]

C. The principle of least privilege ensures that users have access to the data they need to perform
their jobs, but no more. Defense in depth ensures an organization has multiple layers of security.
Separation of duties ensures that no single user has full control over any process. Non-repudiation
prevents users from denying they took an action."

"Your organization wants to implement policies that will deter fraud by dividing job responsibilities.
Which of the following policies should they implement?

A. Nonrepudiation
B. Least privilege
C. Defense in depth
D. Separation of duties - Correct answer [Security Fundamentals]

D. Separation of duties helps prevent fraud by dividing job responsibilities and ensuring that no
single person has complete control over an entire process. Nonrepudiation ensures that parties are
not able to deny taking an action. The principle of least privilege ensures that users have only the
rights and permissions they need to perform their jobs, but no more. Defense in depth provides a
layered approach to security."

, "Which one of the following concepts provides the strongest security?

A. Defense in depth
B. Nonrepudiation
C. Security triad
D. AAAs of security - Correct answer [Security Fundamentals]

A. Defense in depth provides a layered approach to security by implementing several different
security practices simultaneously and is the best choice of
the available answers to provide the strongest security. The security triad (confidentiality, integrity,
and availability) identifies the main goals of security. Nonrepudiation prevents an individual from
denying that he or she took an action. The AAAs of security are authentication, authorization, and
accounting."

"Which of the following would a financial institution use to validate an e-commerce transaction?

A. Nonrepudiation
B. Least privilege
C. Authentication
D. Signature - Correct answer [Security Fundamentals]

A. Digital signatures used by some online institutions to validate transactions and provide
nonrepudiation. Least privilege ensures that users have only the rights and permissions they need to
perform their jobs, and no more. Authentication verifies a user's identity. A written signature is not
used in e-commerce."

"What are the AAAs of information security?

A. Authentication, availability, and authorization
B. Accounting, authentication, and availability
C. Authentication, authorization, and accounting
D. Availability, accountability, and authorization - Correct answer [Security Fundamentals]

C. The AAAs of information security are authentication, authorization, and accounting. Availability is
part of the CIA security triad (confidentiality, integrity, and availability), but it is not part of the AAAs
of information security."

"You want to ensure that a system can identify individual users track their activity, and log their
actions. What does this provide?

A. Accountability
B. Availability
C. Authentication
D. Authorization - Correct answer [Security Fundamentals]

Document information

Uploaded on
October 10, 2024
Number of pages
73
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Smith01
4.6
(21)
Sold
75
Followers
10
Items
531
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions