SSCP Chapter 2 Exam Prep – WGU C845 |
Latest Update 2026 | Graded A+
How do you turn data into knowledge? - correct answerYou use lots of data to observe
general ideas and then test those ideas with more data you observe, until you can
finally make broad, general conclusions. These conclusions are what called knowledge.
Which is more important to a business - its information or its information technology? -
correct answerThe information is more important, because all that the information
technology does it make the information available to people to make decisions with.
As the IT security directory, Paul does not have anybody looking at systems monitoring
or event logging data. Which set of responsibilities is Paul in violation of? - correct
answerDue diligence
Explain the relationship between confidentiality and privacy, if any? - correct
answerConfidentiality is about keeping information secret so that we retain advantage
or do not come to harm; privacy is about choosing who can enter into one's life or
property.
Jayne discovers that someone in the company's HR department has been modifying
employee performance appraisals. If done without proper authorization, this would be
what kind of violation? - correct answerIntegrity
At a job interview, Fred is asked by the interviewer about activities, pictures, and
statements he's made by posting things on his Facebook and LinkedIn pages. This
question by the interviewer: - correct answerIs a legitimate one, since these pages are
published by Fred, and therefore they are speech he has made in public places.
A thunderstorm knocks out the commercial electric power to your company's
datacenter, shutting down everything. This impacts which aspect of information
security? - correct answerAvailability
Business logic is: - correct answerThe design of processes to achieve an objective
within the rules and constraints the business must operate within.
How does business logic relate to information security? - correct answerBusiness logic
represents decisions the company has made and may give it a competitive advantage
over others in the marketplace; it needs to be protected from unauthorized disclosure or
unauthorized change. Processes that implemented the business logic need to be
available to be run or used when needed. Thus, confidentiality, integrity, and availability
apply.
, Your company uses computer-controlled machine tools on the factory floor as part of its
assembly line. This morning, you've discovered that somebody erased a key set of
machine control parameter files, and the backups you have will need to be updated and
verified before you can use them. This may take most of the day to accomplish. What
information security attribute is involved here? - correct answerIntegrity
Protection of intellectual property (IP) is an example of what kind of information security
need? - correct answerConfidentiality
John works as the chief information security officer for a medium-sized chemical
processing firm. Which of the following groups of people would not be stakeholders in
the ongoing operation of this business? - correct answerState and local tax authorities
When you compare safety to security for information systems, which of the following
statements are correct? (Choose all the apply) - correct answerAC
Why is the preamble to (ISC)^2 Code of Ethics important to us as SSCPs? - correct
answerIt is vital to understand the code because it sets purpose and intentions; it's our
mission statement as professionals.
Due diligence means: - correct answerMaking sure that actions you've taken to fulfill
your responsibilities are working correctly and completely
Suppose that you work for a business or have a business as your client. As an SSCP,
which of the following groups do you have responsibilities to? (Choose all that apply) -
correct answerABCD
We often hear people talk about the need for information systems to be safe and
reliable. Is this the same as saying that they need to be secure? - correct answerYes,
because the objective of information security is to increase our confidence that we can
make sound and prudent decisions based on what those information systems are telling
us, and in doing so cause no harm.
As an SSCP, you work at the headquarters of a retail sales company that has many
stores around the country. Its training department has prepared different training
materials and operations manuals for in-store sales, warehouse staff, and other team
members to use in their jobs. Most of these describe procedures that people do as they
work with one another or with customers. From an information security standpoint,
which of the following statements are correct?
A. Since these all describe people-to-people interactions and processes, they are not
implemented by the IT department, and so they're not something that information
security is concerned with.
B. Most of their content is probably common practice in business and retail sales and so
would not be trade secrets, company propriety, or private to the company.
Latest Update 2026 | Graded A+
How do you turn data into knowledge? - correct answerYou use lots of data to observe
general ideas and then test those ideas with more data you observe, until you can
finally make broad, general conclusions. These conclusions are what called knowledge.
Which is more important to a business - its information or its information technology? -
correct answerThe information is more important, because all that the information
technology does it make the information available to people to make decisions with.
As the IT security directory, Paul does not have anybody looking at systems monitoring
or event logging data. Which set of responsibilities is Paul in violation of? - correct
answerDue diligence
Explain the relationship between confidentiality and privacy, if any? - correct
answerConfidentiality is about keeping information secret so that we retain advantage
or do not come to harm; privacy is about choosing who can enter into one's life or
property.
Jayne discovers that someone in the company's HR department has been modifying
employee performance appraisals. If done without proper authorization, this would be
what kind of violation? - correct answerIntegrity
At a job interview, Fred is asked by the interviewer about activities, pictures, and
statements he's made by posting things on his Facebook and LinkedIn pages. This
question by the interviewer: - correct answerIs a legitimate one, since these pages are
published by Fred, and therefore they are speech he has made in public places.
A thunderstorm knocks out the commercial electric power to your company's
datacenter, shutting down everything. This impacts which aspect of information
security? - correct answerAvailability
Business logic is: - correct answerThe design of processes to achieve an objective
within the rules and constraints the business must operate within.
How does business logic relate to information security? - correct answerBusiness logic
represents decisions the company has made and may give it a competitive advantage
over others in the marketplace; it needs to be protected from unauthorized disclosure or
unauthorized change. Processes that implemented the business logic need to be
available to be run or used when needed. Thus, confidentiality, integrity, and availability
apply.
, Your company uses computer-controlled machine tools on the factory floor as part of its
assembly line. This morning, you've discovered that somebody erased a key set of
machine control parameter files, and the backups you have will need to be updated and
verified before you can use them. This may take most of the day to accomplish. What
information security attribute is involved here? - correct answerIntegrity
Protection of intellectual property (IP) is an example of what kind of information security
need? - correct answerConfidentiality
John works as the chief information security officer for a medium-sized chemical
processing firm. Which of the following groups of people would not be stakeholders in
the ongoing operation of this business? - correct answerState and local tax authorities
When you compare safety to security for information systems, which of the following
statements are correct? (Choose all the apply) - correct answerAC
Why is the preamble to (ISC)^2 Code of Ethics important to us as SSCPs? - correct
answerIt is vital to understand the code because it sets purpose and intentions; it's our
mission statement as professionals.
Due diligence means: - correct answerMaking sure that actions you've taken to fulfill
your responsibilities are working correctly and completely
Suppose that you work for a business or have a business as your client. As an SSCP,
which of the following groups do you have responsibilities to? (Choose all that apply) -
correct answerABCD
We often hear people talk about the need for information systems to be safe and
reliable. Is this the same as saying that they need to be secure? - correct answerYes,
because the objective of information security is to increase our confidence that we can
make sound and prudent decisions based on what those information systems are telling
us, and in doing so cause no harm.
As an SSCP, you work at the headquarters of a retail sales company that has many
stores around the country. Its training department has prepared different training
materials and operations manuals for in-store sales, warehouse staff, and other team
members to use in their jobs. Most of these describe procedures that people do as they
work with one another or with customers. From an information security standpoint,
which of the following statements are correct?
A. Since these all describe people-to-people interactions and processes, they are not
implemented by the IT department, and so they're not something that information
security is concerned with.
B. Most of their content is probably common practice in business and retail sales and so
would not be trade secrets, company propriety, or private to the company.