Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 61 pages
Exam (elaborations)

SSCP Test Questions and Correct Answers

Document preview thumbnail
Preview 4 out of 61 pages

SSCP Test Questions and Correct Answers

Content preview

SSCP




Your company adopts a new end-user security awareness program. This training includes malware
introduction, social media issues, password guidelines, data exposure, and lost

devices. How often should end users receive this training?



A) upon new hire

B) twice a year

C) one a year and upon termination

D) upon termination

E) upon new hire and once a year thereafter

F) once a year - Answer-E)

End users should receive security awareness training upon new hire and once a year thereafter. This
ensures that new hires understand security issues immediately. It also

ensures that end users receive updates to their security awareness knowledge on an annual basis



What is the term used to describe the risk management strategy of an organization altering a business
task to work around a specific event or activity in order to prevent

compromise?

,A) Deterrence

B) Acceptance

C) Transference

D) Avoidance - Answer-D)

Avoidance is the term used to describe the risk management strategy of an organization altering a
business task in order to work around a specific event or activity in order to

prevent compromise. By adjusting business processes to work around a risky activity or event, the
impact of a realized threat can be eliminated or reduced. This can be an

effective tool when designing a risk management strategy. Risk avoidance or risk removal is sometimes
considered a sub-category of risk mitigation. However, risk avoidance is not the dominate concept or
defining factor.



Which of the following types of activities is NOT commonly performed in preparation for a security
assessment?



A) Apply patches.

B) Collect host configuration documentation.

C) Review the security policies.

D) Analyze the change management procedures. - Answer-A)

Applying patches is not an activity commonly performed in preparation for a security assessment.
Applying patches is often part of the remediation actions taken after the security

assessment. The security assessment will determine where security is lax or where improvements to
security can be made. This may then require remediation activities such as

removing equipment, changing configuration, altering business processes, and applying patches.



When an organization has limited visibility of their risk, in addition to how risk affects daily operations, in
what state or condition is the organization?



A) Processing state

,B) Proactive state

C) Preventive state

D) Reactive state - Answer-D)

When an organization has limited visibility of their risk and on how risk affects daily operations, they are
in a reactive state. A reactive state or condition occurs when an

organization is only equipped to respond to compromises as they occur. This is a condition of always
being behind and being pushed by security violations into taking actions, often

without planning or consideration. Organizations should strive to break out of the reactive state in order
to become proactive. By implementing a risk management and response strategy, an organization can
become more aware of their ongoing and operational risks. They can take efforts to plan for potential
compromises and how to response

appropriately. By implementing a sound security strategy, risk can be managed rather than being only
reacted to.



How can a user be given the power to set privileges on an object for other users when within a DAC
operating system?



A) Give the user the modify privilege on the object.

B) Remove special permissions for the user on the object.

C) Grant the user full control over the object.

D) Issue an administrative job label to the user - Answer-C)

Granting the user full control over the object will provide a user with the power to set privileges on an
object for other users when within a DAC operating system. Three other

methods within a DAC environment to accomplish this are to 1) have the user be an owner of the object,
2) grant the user the change permissions special permission, or 3) be a member of the administrators
group. Any user who creates a new object is automatically the owner of that object, but administrators
can either take ownership or grant ownership

to other users. Administrators can take ownership in order to gain full access over an object.



Why is it important to evaluate intangible assets while performing a risk assessment?

, A) Intangible assets cannot be harmed by threats.

B) They can be sold for operating funds.

C) Only tangible assets have value.

D) Not all assets are tangible. - Answer-It is important to evaluate intangible assets while performing a
risk assessment because not all assets are tangible. Many assets are intangible, such as trade secrets,
intellectual

property, proprietary data, customer databases, contracts, agreements, public opinion, market share,
customer loyalty, and any and all data storage. Generally, an intangible asset is one that is not a physical
item. However, intangible assets can be very valuable and thus need protection. Evaluating the risks to
intangible assets is an early step towards implementing proper security measures.



How is subject-based access control different from object-based?



A) The focus is on an attribute or setting on the subject.

B) Labels on resources are the primary concern.

C) It always based on ACLs.

D) It is based on the content of the object - Answer-A)

Subject-based access control focuses on an attribute or setting on the subject for making authorization
decisions. It is also referred to as attribute-based access control. The

attributes or setting on a subject can be time of day, location, or internal or external to the private
network, and whether a valid authentication was performed within a specific

period of time. Another aspect of subject-based access control is to assign privileges to subjects based
specifically on their job responsibilities, as that is used in role-based access

control.



How is the chosen risk response strategy of risk acceptance proven and supported in a court of law?



A) With a document signed by senior management

Document information

Uploaded on
November 4, 2024
Number of pages
61
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Zanaya
4.5
(12)
Sold
78
Followers
29
Items
10176
Last sold
6 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions