Guaranteed Pass || Complete Study guide Graded A+
Wickyaplus stuvia
THIS EXAM CONTAINS:
WGU C845 SSCP
Task 1, 2 & 3
Information Systems Security - C845
Complete Study guide Graded A+
, x
WGU C845 SSCPEXAM STUDYGUIDEx x x x x
INFORMATION SYSTEM SECURITY
x x x
This guide covers essential SSCP topics organized into logical sections. Each section includes core
x x x x x x x x x x x x x
concepts, best practices, and comparisons where needed.
x x x x x x x
I. Security Fundamentals & Access Control x x x x
1. Configuration Management & Access Control Models x x x x x
● Configuration Management Practice x x
○ Purpose: Maintain system integrity via version control, audits, and baseline settings.
x x x x x x x x x x
○ Key Focus: Change management processes and accurate configuration documentation.
x x x x x x x x
● Access Control Models x x
○ Decentralized (Discretionary Access Control – DAC): Local decisions at the resource x x x x x x x x x x
level; users manage their own permissions.
x x x x x x
○ Mandatory Access Control (MAC): Centralized, strict policies defined by the
x x x x x x x x x
organization. x
○ Role-Based Access Control (RBAC): Access based on a user’s role within the
x x x x x x x x x x x
organization. x
○ Additional Methods: x
■ Capability Tables: Map subjects (users/processes) to permitted operations on x x x x x x x x
objects. x
■ Access Control Lists (ACLs): Collections of Access Control Entries (ACEs) x x x x x x x x x
xthat specify allowed or denied permissions. ● Device Authentication & Administrative Shares
x x x x x x x x x x x
○ Device Authentication: Uses certificates, tokens, or cryptographic keys to verify a device’s
x x x x x x x x x x x
identity. x
○ Administrative Shares: Hidden network shares (e.g., C$, ADMIN$) used for remote x x x x x x x x x x
management (note: these pose security risks if not managed properly).
x x x x x x x x x x
2. Account Management x
● Steps in Account Management:
x x x
○ Provisioning: Create accounts with appropriate roles and permissions. x x x x x x x
○ Modification: Update accounts as roles or job functions change. x x x x x x x x
○ Deactivation/Deletion: Disable or remove accounts that are no longer needed. ○ x x x x x x x x x x
Periodic Review: Regularly audit account permissions and activity.
x x x x x x x