100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

(ISC)2 SSCP PRACTICE TEST 1 QUESTIONS AND ANSWERS

Rating
-
Sold
-
Pages
21
Grade
A+
Uploaded on
04-02-2026
Written in
2025/2026

(ISC)2 SSCP PRACTICE TEST 1 QUESTIONS AND ANSWERS

Institution
SSCP
Course
SSCP

Content preview

(ISC)2 SSCP PRACTICE TEST 1 QUESTIONS
AND ANSWERS



What is a teardrop attack and what category of attack is it? - Correct Answers -A
teardrop attack is a type of Denial-of-Service (DoS) attack that exploits vulnerabilities in
the way operating systems handle fragmented packets

The hearsay rule - Correct Answers -The hearsay rule says that a witness cannot testify
about what someone else told them, except under specific exceptions.

Jim has been asked to individually identify devices that users are bringing to work as
part of a new BYOD policy. The devices will not be joined to a central management
system like Active Directory, but he still needs to uniquely identify the systems. Which of
the following options will provide Jim with the best means of reliably identifying each
unique device? - Correct Answers -Use device fingerprinting via a web-based
registration system.

Greg would like to implement application control technology in his organization. He
would like to limit users to installing only approved software on their systems. What type
of application control would be appropriate in this situation? - Correct Answers -
Whitelisting

What is FAR and FRR? - Correct Answers -FAR (False Acceptance Rate) and FRR
(False Rejection Rate) are metrics used to evaluate the performance of biometric
security systems, such as fingerprint, facial recognition, and iris scanners. These
metrics help determine how accurately a biometric system distinguishes between
legitimate users and impostors.

What is CER and the ERR - Correct Answers -Crossover Error Rate (CER) / Equal
Error Rate (EER)
Definition: The CER, also known as the EER, is the point at which the False Acceptance
Rate (FAR) and the False Rejection Rate (FRR) are equal.

What is the difference between

A Discretionary account provisioning
B Workflow-based account provisioning
C Automated account provisioning
D Self-service account provisioning - Correct Answers -Example: A manager at a
company manually requests an account for a new employee by sending an email to the

,IT department. The IT team then creates the account based on the manager's
instructions

When a new employee joins a company, an automated HR system triggers a workflow
that sends an approval request to the employee's manager.

When a new employee's details are entered into the company's HR system, the system
automatically creates an account in the Active Directory and assigns the necessary
permissions based on the employee's role without any human intervention.

A new user signs up for a company's service through a web portal. They enter their
details, and the system automatically creates their account. The user can then
customize their account settings, choose additional services, and reset their password
without needing to contact support or IT staff.

Alex has been with the university he works at for more than 10 years. During that time,
he has been a system administrator and a database administrator, and he has worked
in the university's help desk. He is now a manager for the team that runs the university's
web applications.

He now has access to application servers, database servers, and AD workstations.

Since he now has access to all three, what is happening? - Correct Answers -Privilege
Creep
As Alex has changed roles, he retained access to systems that he no longer
administers. The provisioning system has provided rights to workstations and the
application servers he manages, but he should not have access to the databases he no
longer administers.

What type of motion detector senses changes in the electromagnetic fields in monitored
areas? - Correct Answers -Capacitance

What is a Photoelectric sensor? - Correct Answers -A photoelectric sensor is a type of
sensor that uses a light beam (often infrared) to detect the presence, absence, or
distance of an object. These sensors work by emitting a light beam from a transmitter
and detecting the reflection or interruption of that beam with a receiver.

Don's company is considering the use of an object-based storage system where data is
placed in a vendor-managed storage environment through the use of API calls. What
type of cloud computing service is in use? - Correct Answers -In this scenario, the
vendor is providing object-based storage, a core infrastructure service. Therefore, this is
an example of infrastructure as a service (IaaS).

What is the minimum interval at which an organization should conduct business
continuity plan refresher training for those with specific business continuity roles? -
Correct Answers -Annual basis

, What is Caas? - Correct Answers -CaaS stands for "Container as a Service." It's a cloud
service model that allows users to manage and deploy containers, which are
lightweight, portable units that bundle an application and its dependencies into a single
package.

What is the diff between
Black box
White box
Gray box
Zero box - Correct Answers -In black-box testing, the tester has no knowledge of the
internal workings or code of the system being tested.

White-box testing involves full knowledge of the internal workings of the system.

Gray-box testing is a hybrid approach that combines elements of both black-box and
white-box testing.

The term "Zero Box" is where there is zero or minimal setup, preparation, or information
provided to the tester.

What RADIUS alternative is commonly used for Cisco network gear and supports two-
factor authentication? - Correct Answers -TACACS+

What is XTACACS? - Correct Answers -The most advanced version of the TACACS
protocol, TACACS+ further improved security by adding encryption for the entire
communication session between the client (e.g., router or switch) and the server.
TACACS+ is more commonly used today than XTACACS, as it offers better security
and more granular control over user access.

TACACS+ and Kerberos - Correct Answers -TACACS+ is the most modern version of
TACACS, the Terminal Access Controller Access-Control System. It is a Cisco
proprietary protocol

Kerberos is a network authentication protocol rather than a remote user authentication
protocol

The difference between Class A Class B Class C Class D fire extinguishers - Correct
Answers -Class A Fire Extinguishers
Type of Fire: Combustible solids such as wood, paper, cloth, rubber, and plastics.

Class B Fire Extinguishers
Type of Fire: Flammable liquids and gases, such as gasoline, oil, paint, solvents, and
propane

Class C Fire Extinguishers

Written for

Institution
SSCP
Course
SSCP

Document information

Uploaded on
February 4, 2026
Number of pages
21
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
millyphilip West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
2840
Member since
3 year
Number of followers
1957
Documents
42083
Last sold
14 hours ago
white orchid store

EXCELLENCY IN ACCADEMIC MATERIALS ie exams, study guides, testbanks ,case, case study etc

3.7

540 reviews

5
234
4
86
3
103
2
31
1
86

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions