Practitioner (SSCP) - Exam Answered
Access Control Object - Answer- A passive entity that typically receives or contains
some form of data.
Access Control Subject - Answer- An active entity and can be any user, program, or
process that requests permission to cause data to flow from an access control object to
the access control subject or between access control objects.
Asynchronous Password Token - Answer- A one-time password is generated without
the use of a clock, either from a one-time pad or cryptographic algorithm.
Authorization - Answer- Determines whether a user is permitted to access a particular
resource.
Connected Tokens - Answer- Must be physically connected to the computer to which
the user is authenticating.
Contactless Tokens - Answer- Form a logical connection to the client computer but do
not require a physical connection.
Disconnected Tokens - Answer- Have neither a physical nor logical connection to the
client computer.
Entitlement - Answer- A set of rules, defined by the resource owner, for managing
access to a resource (asset, service, or entity) and for what purpose.
Identity Management - Answer- The task of controlling information about users on
computers.
Proof of Identity - Answer- Verify people's identities before the enterprise issues them
accounts and credentials.
Kerberos - Answer- A popular network authentication protocol for indirect (third-party)
authentication services.
Lightweight Directory Access Protocol (LDAP) - Answer- A client/server-based directory
query protocol loosely based on X.500, commonly used to manage user information.
LDAP is a front end and not used to manage or synchronize data per se as opposed to
DNS.
, Single Sign-On (SSO) - Answer- Designed to provide strong authentication using
secret-key cryptography, allowing a single identity to be shared across multiple
applications.
Static Password Token - Answer- The device contains a password that is physically
hidden (not visible to the possessor) but that is transmitted for each authentication.
Synchronous Dynamic Password Token - Answer- A timer is used to rotate through
various combinations produced by a cryptographic algorithm.
Trust Path - Answer- A series of trust relationships that authentication requests must
follow between domains
Availability - Answer- Refers to the ability to access and use information systems when
and as needed to support an organization's operations.
Breach - Answer- The intentional or unintentional release of secure information to an
untrusted environment.
CMDB - Answer- A configuration management database (CMDB) is a repository that
contains a collection of IT assets that are referred to as configuration items.
Compensating Controls - Answer- Introduced when the existing capabilities of a system
do not support the requirements of a policy.
Confidentiality - Answer- Refers to the property of information in which it is only made
available to those who have a legitimate need to know.
Configuration Management (CM) - Answer- A discipline that seeks to manage
configuration changes so that they are appropriately approved and documented, so that
the integrity of the security state is maintained, and so that disruptions to performance
and availability are minimized.
Corrective Control - Answer- These controls remedy the circumstances that enabled
unwarranted activity, and/ or return conditions to where they were prior to the unwanted
activity.
COTS - Answer- A Federal Acquistion Regulation (FAR) term for commercial off-the-
shelf (COTS) items, that can be purchased n the commercial marketplace and used
under government contract.
Deduplication - Answer- A process that scans the entire collection of information looking
for similar chunks of data that can be consolidated.