PRACTITIONER (SSCP) -FINAL EXAM
QUESTIONS COMPLETE WITH OUTLINED
ANSWERS
\Q\.Which of the following items is not considered as a physical access control? - ANSWERS✔-
Host-based IDS
An HIDS (host-based intrusion detection system) is considered as technical/logical control. It
monitors activity on a single computer only, including process calls and information recorded in
system, application, security, and host-based firewall logs.
\Q\.What factors must you consider for the design and implementation of access control
mechanisms? - ANSWERS✔-Vulnerabilities: Shortcomings in a system
Risks: Measured by the likelihood that any particular threat may be carried out
Threats: Possible violations
\Q\.Which of the following types of access control seeks to discover evidence of an unwanted,
unauthorized, or illicit behavior or an activity? - ANSWERS✔-Detective
\Q\.What are the examples of administrative access controls?
,Each correct answer represents a complete solution. Choose all that apply - ANSWERS✔-
Security Awareness Program
Information Security Policy
\Q\.Which of the following models is designed for ensuring data integrity? - ANSWERS✔-Biba
The Biba model, also called the Biba Integrity model, is a formal state transition system of
computer security policy used to depict a set of access control rules designed for ensuring data
integrity.
\Q\.A large table includes multiple subjects and objects and identifies the access to various
objects. What is this table called? - ANSWERS✔-Access control matrix
\Q\.Single sign-on (SSO) is a centralized access control technique that allows a subject to be
authenticated only once on a system. Which of the following are examples of SSO?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-
KryptoKnight
Kerberos
SESAME
\Q\.Which type of access control defines the statement below?
"It uses a predefined set of access privileges for an object of the system." - ANSWERS✔-
Mandatory
,\Q\.Which of the following ensures that a user is assigned with only required access and
permission to complete their work? - ANSWERS✔-Principle of least privilege
\Q\.What are the guidelines of a good password policy?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-- Do
not share computer accounts or passwords with others.
- Do not use the same password for more than one account.
- Do not ever write down a password.
- Do not communicate a password by telephone, email, or instant messaging.
- Change passwords whenever there is a doubt, as they may have been compromised.
- Use alpha-numeric passwords.
\Q\.Which of the following statements are true about entitlement?
Each correct answer represents a complete solution. Choose two. - ANSWERS✔-It follows the
principle of least privilege
It indicates about the privileges granted to users
\Q\.Which of the following 'Code of Ethics Canons' are described under 'Protect society, the
commonwealth, and the infrastructure'?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-
Promote and preserve public trust and confidence in information and systems.
, Promote the understanding and acceptance of prudent information security measures.
Preserve and strengthen the integrity of the public infrastructure.
\Q\.Which of the following specifies systems that inspects and maintains things that are of value
to an entity or group? - ANSWERS✔-Asset management
\Q\.Which of the following levels are included in the commercial business/private sector data
classification?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-
Confidential
Private
Sensitive
Public
\Q\.Which of the following statements are true about asset management?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-It
specifies the step that manages important items within an organization.
It helps organizations to track hardware and software of the systems.
\Q\.Which type of assurances are defined by the TCSEC (Trusted Computer System Evaluation
Criteria) book?
Each correct answer represents a complete solution. Choose all that apply. - ANSWERS✔-Life
cycle assurance: Ensures that a trusted computer base is designed with the controlled standards