SSCP Final Test with all Correct & 100% Verified Answers
|Actual Complete Update |Already Graded A+
Jack works as an investigating officer in Private Corporate Investigation Agency Services. He
wants to save an evidence, that he collected from the location where an incident happened, for
future use so that he can have that information whenever needed. Which is the most volatile
memory he can use to save the collected evidence? ✔Correct Answer-CPU cache
Which choice best describes Bluetooth? ✔Correct Answer-A method of data synchronization
between devices
Authorization for multiple applications using one set of credentials is best described by which of
the following? ✔Correct Answer-Single Sign-on
How is separation of duties typically implemented? ✔Correct Answer-Segment administrative
tasks into compartments, and then assign one or more distinct administrators into each
compartment.
When considering a disaster which of the following is not a commonly accepted definition?
✔Correct Answer-An occurrence that is outside the normal functional baselines
A type of wireless network attack monitors wireless signals for clients making requests to
connect to wireless base stations. It then takes the details from those requests to spoof the
identity of the requested base station in order to fool the client devices into connecting to the
false version of their trusted network. Which attack is this describing? ✔Correct Answer-Evil
twin
How does mandatory access control determine which objects a subject can access? ✔Correct
Answer-Through the use of classification labels
Which of the following is NOT a method by which devices are assigned to VLAN network
segments? ✔Correct Answer-Transport-layer port assignment
Which of the following best describes the time that it takes to register with a biometric system,
by providing samples of a personal characteristic? ✔Correct Answer-Enrollment time
How can a company ensure protection against eavesdropping and session hijacking for its
workers connecting to a public cloud? ✔Correct Answer-Use a VPN.
Which type of client-side program always runs in a sandbox? ✔Correct Answer-Java applet
,When hashing a message, which of the following security goals is being provided? ✔Correct
Answer-Integrity
How does a typical SIEM or systems management console retrieve event details from a source
system? ✔Correct Answer-SNMP
A company is concerned about unauthorized entities attacking their wireless network. The
company has chosen to disable SSID broadcast in order to hide their base station and prevent
unauthorized connections. Which of the following statements are correct of this scenario?
✔Correct Answer-It does not resolve the issue because the SSID is still present in most other
management frames.
Which of the following is true about biometric scan technology? ✔Correct Answer-A number
of points extracted from the item scanned are stored.
A business asset is best described by which of the following? ✔Correct Answer-Competitive
advantage, capability, credibility, or goodwill
Which term is used to indicate the function of access control or defining which subjects can
perform various tasks on specific objects? ✔Correct Answer-Authorization
Other than implementing preventative measures and planning out response and recovery
strategies, what is another important element that will help minimize data loss in the event of a
harmful event that would trigger a disaster recovery policy (DRP)? ✔Correct Answer-Prior
warning of impending harm
To prevent any one person from having too much control or power, or performing fraudulent
acts, which of the following solutions should not be implemented? ✔Correct Answer-Job
rotation
Which of the following best describes an endpoint device? ✔Correct Answer-Computer
printer
What is the correct description of a certificate? ✔Correct Answer-A certificate contains the
owner's public key.
A backup site is best described by which of the following options? ✔Correct Answer-A
computer facility with power and HVAC and all servers and communications. All applications are
ready to be installed and configured, and recent data is available to be restored to the site.
What does an acceptable use policy AUP state? ✔Correct Answer-The acceptable and
unacceptable uses for organizational resources
,Which option provides the best description of the first action to take during incident response?
✔Correct Answer-Follow the procedures in the incident response plan.
Which of the following best describes maximum tolerable downtime? ✔Correct Answer-The
amount of time a business process may be off-line before the viability of the organization is in
severe jeopardy
Which choice best describes a zombie? ✔Correct Answer-A member of a botnet
Which option is not part of the prevention primary security category? ✔Correct Answer-Using
an alternate site after a disaster
What type of attack cannot be blocked or resolved with a software fix or a hardware upgrade?
✔Correct Answer-Social engineering
Crossover error rate (CER) refers to which of the following graphical intersections? ✔Correct
Answer-False rejection rate and false acceptance rate
Which of the following is a term used for a rogue Wi-Fi access point that appears to be
legitimate but actually has been set up to intercept wireless communications? ✔Correct
Answer-Evil twin
Your company is about to launch a new Web site offering services and features that are
commonly requested but rarely offered by other existing sites. The market research shows that
the new site will be very popular and will have significant user growth for years. You have been
given the responsibility to set up user authentication. Your requirements are the following:
Each user must be uniquely identified.
Multifactor authentication should be supported.
Authentication should provide protection of a user's identity even if your Web site's servers are
compromised by hackers.
How would you implement the authentication for this Web site? ✔Correct Answer-Set up a
one-way federated access with an existing major social network site.
Which of the following is part of a business continuity plan? ✔Correct Answer-The recovery
point objective
A clipping level does which of the following? ✔Correct Answer-Defines a threshold of activity
that, after crossed, sets off an operator alarm or alert
How does PGP provide e-mail confidentiality? ✔Correct Answer-Through random symmetric
keys and the use of public keys
What are the three categories of controls? ✔Correct Answer-Physical, logical (technical), and
administrative
, Encapsulation provides what type of action? ✔Correct Answer-Places one type of packet
inside another
Evidence should be tracked utilizing which of the following methods? ✔Correct Answer-Chain
of custody
Which answer is most accurate regarding firewalls? ✔Correct Answer-They filter traffic based
upon inspecting packets.
Why is multifactor authentication considered more secure than single-factor authentication?
✔Correct Answer-Multifactor authentication requires multiple distinct attacks to perform
impersonation.
What is a significant difference between the secure protocols of TLS-encrypted SMTP and the
use of S/MIME for the protection of e-mail communications? ✔Correct Answer-One provides
end-to-end protection of messages, while the other only secures a local link.
Which group represents the most likely source of an asset being lost through inappropriate
computer use? ✔Correct Answer-Employees
What must every policy possess in order to be successfully implemented? ✔Correct Answer-
Senior executive endorsement
Which of the following best describes privileged users? ✔Correct Answer-They are super-
users or administrators
During an access system audit, a number of active accounts were discovered from employees
who had left the company over the past two years. What are these accounts called? ✔Correct
Answer-Orphaned accounts
Which option most accurately defines a threat? ✔Correct Answer-Possibility for a source to
exploit a specific vulnerability
Which security plan is used to restore normal operations in the event of the full interruption of
mission critical business functions? ✔Correct Answer-Disaster recovery plan
Which of the following is not a control category? ✔Correct Answer-Preventative
What is the component of IPSec that handles key generation and distribution? ✔Correct
Answer-Internet Key Exchange
Which of the following statements best describes Kerberos? ✔Correct Answer-An
authentication, single sign-on protocol
|Actual Complete Update |Already Graded A+
Jack works as an investigating officer in Private Corporate Investigation Agency Services. He
wants to save an evidence, that he collected from the location where an incident happened, for
future use so that he can have that information whenever needed. Which is the most volatile
memory he can use to save the collected evidence? ✔Correct Answer-CPU cache
Which choice best describes Bluetooth? ✔Correct Answer-A method of data synchronization
between devices
Authorization for multiple applications using one set of credentials is best described by which of
the following? ✔Correct Answer-Single Sign-on
How is separation of duties typically implemented? ✔Correct Answer-Segment administrative
tasks into compartments, and then assign one or more distinct administrators into each
compartment.
When considering a disaster which of the following is not a commonly accepted definition?
✔Correct Answer-An occurrence that is outside the normal functional baselines
A type of wireless network attack monitors wireless signals for clients making requests to
connect to wireless base stations. It then takes the details from those requests to spoof the
identity of the requested base station in order to fool the client devices into connecting to the
false version of their trusted network. Which attack is this describing? ✔Correct Answer-Evil
twin
How does mandatory access control determine which objects a subject can access? ✔Correct
Answer-Through the use of classification labels
Which of the following is NOT a method by which devices are assigned to VLAN network
segments? ✔Correct Answer-Transport-layer port assignment
Which of the following best describes the time that it takes to register with a biometric system,
by providing samples of a personal characteristic? ✔Correct Answer-Enrollment time
How can a company ensure protection against eavesdropping and session hijacking for its
workers connecting to a public cloud? ✔Correct Answer-Use a VPN.
Which type of client-side program always runs in a sandbox? ✔Correct Answer-Java applet
,When hashing a message, which of the following security goals is being provided? ✔Correct
Answer-Integrity
How does a typical SIEM or systems management console retrieve event details from a source
system? ✔Correct Answer-SNMP
A company is concerned about unauthorized entities attacking their wireless network. The
company has chosen to disable SSID broadcast in order to hide their base station and prevent
unauthorized connections. Which of the following statements are correct of this scenario?
✔Correct Answer-It does not resolve the issue because the SSID is still present in most other
management frames.
Which of the following is true about biometric scan technology? ✔Correct Answer-A number
of points extracted from the item scanned are stored.
A business asset is best described by which of the following? ✔Correct Answer-Competitive
advantage, capability, credibility, or goodwill
Which term is used to indicate the function of access control or defining which subjects can
perform various tasks on specific objects? ✔Correct Answer-Authorization
Other than implementing preventative measures and planning out response and recovery
strategies, what is another important element that will help minimize data loss in the event of a
harmful event that would trigger a disaster recovery policy (DRP)? ✔Correct Answer-Prior
warning of impending harm
To prevent any one person from having too much control or power, or performing fraudulent
acts, which of the following solutions should not be implemented? ✔Correct Answer-Job
rotation
Which of the following best describes an endpoint device? ✔Correct Answer-Computer
printer
What is the correct description of a certificate? ✔Correct Answer-A certificate contains the
owner's public key.
A backup site is best described by which of the following options? ✔Correct Answer-A
computer facility with power and HVAC and all servers and communications. All applications are
ready to be installed and configured, and recent data is available to be restored to the site.
What does an acceptable use policy AUP state? ✔Correct Answer-The acceptable and
unacceptable uses for organizational resources
,Which option provides the best description of the first action to take during incident response?
✔Correct Answer-Follow the procedures in the incident response plan.
Which of the following best describes maximum tolerable downtime? ✔Correct Answer-The
amount of time a business process may be off-line before the viability of the organization is in
severe jeopardy
Which choice best describes a zombie? ✔Correct Answer-A member of a botnet
Which option is not part of the prevention primary security category? ✔Correct Answer-Using
an alternate site after a disaster
What type of attack cannot be blocked or resolved with a software fix or a hardware upgrade?
✔Correct Answer-Social engineering
Crossover error rate (CER) refers to which of the following graphical intersections? ✔Correct
Answer-False rejection rate and false acceptance rate
Which of the following is a term used for a rogue Wi-Fi access point that appears to be
legitimate but actually has been set up to intercept wireless communications? ✔Correct
Answer-Evil twin
Your company is about to launch a new Web site offering services and features that are
commonly requested but rarely offered by other existing sites. The market research shows that
the new site will be very popular and will have significant user growth for years. You have been
given the responsibility to set up user authentication. Your requirements are the following:
Each user must be uniquely identified.
Multifactor authentication should be supported.
Authentication should provide protection of a user's identity even if your Web site's servers are
compromised by hackers.
How would you implement the authentication for this Web site? ✔Correct Answer-Set up a
one-way federated access with an existing major social network site.
Which of the following is part of a business continuity plan? ✔Correct Answer-The recovery
point objective
A clipping level does which of the following? ✔Correct Answer-Defines a threshold of activity
that, after crossed, sets off an operator alarm or alert
How does PGP provide e-mail confidentiality? ✔Correct Answer-Through random symmetric
keys and the use of public keys
What are the three categories of controls? ✔Correct Answer-Physical, logical (technical), and
administrative
, Encapsulation provides what type of action? ✔Correct Answer-Places one type of packet
inside another
Evidence should be tracked utilizing which of the following methods? ✔Correct Answer-Chain
of custody
Which answer is most accurate regarding firewalls? ✔Correct Answer-They filter traffic based
upon inspecting packets.
Why is multifactor authentication considered more secure than single-factor authentication?
✔Correct Answer-Multifactor authentication requires multiple distinct attacks to perform
impersonation.
What is a significant difference between the secure protocols of TLS-encrypted SMTP and the
use of S/MIME for the protection of e-mail communications? ✔Correct Answer-One provides
end-to-end protection of messages, while the other only secures a local link.
Which group represents the most likely source of an asset being lost through inappropriate
computer use? ✔Correct Answer-Employees
What must every policy possess in order to be successfully implemented? ✔Correct Answer-
Senior executive endorsement
Which of the following best describes privileged users? ✔Correct Answer-They are super-
users or administrators
During an access system audit, a number of active accounts were discovered from employees
who had left the company over the past two years. What are these accounts called? ✔Correct
Answer-Orphaned accounts
Which option most accurately defines a threat? ✔Correct Answer-Possibility for a source to
exploit a specific vulnerability
Which security plan is used to restore normal operations in the event of the full interruption of
mission critical business functions? ✔Correct Answer-Disaster recovery plan
Which of the following is not a control category? ✔Correct Answer-Preventative
What is the component of IPSec that handles key generation and distribution? ✔Correct
Answer-Internet Key Exchange
Which of the following statements best describes Kerberos? ✔Correct Answer-An
authentication, single sign-on protocol