Systems Security Certified Practitioner (SSCP) - Exam Prep
with all Correct & 100% Verified Answers |Latest Version
|Already Graded A+
A passive entity that typically receives or contains some form of data. ✔Correct Answer-
Access Control Object
An active entity and can be any user, program, or process that requests permission to cause
data to flow from an access control object to the access control subject or between access
control objects. ✔Correct Answer-Access Control Subject
A one-time password is generated without the use of a clock, either from a one-time pad or
cryptographic algorithm. ✔Correct Answer-Asynchronous Password Token
Determines whether a user is permitted to access a particular resource. ✔Correct Answer-
Authorization
Must be physically connected to the computer to which the user is authenticating. ✔Correct
Answer-Connected Tokens
Form a logical connection to the client computer but do not require a physical connection.
✔Correct Answer-Contactless Tokens
Have neither a physical nor logical connection to the client computer. ✔Correct Answer-
Disconnected Tokens
A set of rules, defined by the resource owner, for managing access to a resource (asset, service,
or entity) and for what purpose. ✔Correct Answer-Entitlement
The task of controlling information about users on computers. ✔Correct Answer-Identity
Management
Verify people's identities before the enterprise issues them accounts and credentials.
✔Correct Answer-Proof of Identity
A popular network authentication protocol for indirect (third-party) authentication services.
✔Correct Answer-Kerberos
A client/server-based directory query protocol loosely based on X.500, commonly used to
manage user information. LDAP is a front end and not used to manage or synchronize data per
se as opposed to DNS. ✔Correct Answer-Lightweight Directory Access Protocol (LDAP)
, Designed to provide strong authentication using secret-key cryptography, allowing a single
identity to be shared across multiple applications. ✔Correct Answer-Single Sign-On (SSO)
The device contains a password that is physically hidden (not visible to the possessor) but that is
transmitted for each authentication. ✔Correct Answer-Static Password Token
A timer is used to rotate through various combinations produced by a cryptographic algorithm.
✔Correct Answer-Synchronous Dynamic Password Token
A series of trust relationships that authentication requests must follow between domains
✔Correct Answer-Trust Path
Refers to the ability to access and use information systems when and as needed to support an
organization's operations. ✔Correct Answer-Availability
The intentional or unintentional release of secure information to an untrusted environment.
✔Correct Answer-Breach
A configuration management database (CMDB) is a repository that contains a collection of IT
assets that are referred to as configuration items. ✔Correct Answer-CMDB
Introduced when the existing capabilities of a system do not support the requirements of a
policy. ✔Correct Answer-Compensating Controls
Refers to the property of information in which it is only made available to those who have a
legitimate need to know. ✔Correct Answer-Confidentiality
A discipline that seeks to manage configuration changes so that they are appropriately
approved and documented, so that the integrity of the security state is maintained, and so that
disruptions to performance and availability are minimized. ✔Correct Answer-Configuration
Management (CM)
These controls remedy the circumstances that enabled unwarranted activity, and/ or return
conditions to where they were prior to the unwanted activity. ✔Correct Answer-Corrective
Control
A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can
be purchased n the commercial marketplace and used under government contract. ✔Correct
Answer-COTS
A process that scans the entire collection of information looking for similar chunks of data that
can be consolidated. ✔Correct Answer-Deduplication
with all Correct & 100% Verified Answers |Latest Version
|Already Graded A+
A passive entity that typically receives or contains some form of data. ✔Correct Answer-
Access Control Object
An active entity and can be any user, program, or process that requests permission to cause
data to flow from an access control object to the access control subject or between access
control objects. ✔Correct Answer-Access Control Subject
A one-time password is generated without the use of a clock, either from a one-time pad or
cryptographic algorithm. ✔Correct Answer-Asynchronous Password Token
Determines whether a user is permitted to access a particular resource. ✔Correct Answer-
Authorization
Must be physically connected to the computer to which the user is authenticating. ✔Correct
Answer-Connected Tokens
Form a logical connection to the client computer but do not require a physical connection.
✔Correct Answer-Contactless Tokens
Have neither a physical nor logical connection to the client computer. ✔Correct Answer-
Disconnected Tokens
A set of rules, defined by the resource owner, for managing access to a resource (asset, service,
or entity) and for what purpose. ✔Correct Answer-Entitlement
The task of controlling information about users on computers. ✔Correct Answer-Identity
Management
Verify people's identities before the enterprise issues them accounts and credentials.
✔Correct Answer-Proof of Identity
A popular network authentication protocol for indirect (third-party) authentication services.
✔Correct Answer-Kerberos
A client/server-based directory query protocol loosely based on X.500, commonly used to
manage user information. LDAP is a front end and not used to manage or synchronize data per
se as opposed to DNS. ✔Correct Answer-Lightweight Directory Access Protocol (LDAP)
, Designed to provide strong authentication using secret-key cryptography, allowing a single
identity to be shared across multiple applications. ✔Correct Answer-Single Sign-On (SSO)
The device contains a password that is physically hidden (not visible to the possessor) but that is
transmitted for each authentication. ✔Correct Answer-Static Password Token
A timer is used to rotate through various combinations produced by a cryptographic algorithm.
✔Correct Answer-Synchronous Dynamic Password Token
A series of trust relationships that authentication requests must follow between domains
✔Correct Answer-Trust Path
Refers to the ability to access and use information systems when and as needed to support an
organization's operations. ✔Correct Answer-Availability
The intentional or unintentional release of secure information to an untrusted environment.
✔Correct Answer-Breach
A configuration management database (CMDB) is a repository that contains a collection of IT
assets that are referred to as configuration items. ✔Correct Answer-CMDB
Introduced when the existing capabilities of a system do not support the requirements of a
policy. ✔Correct Answer-Compensating Controls
Refers to the property of information in which it is only made available to those who have a
legitimate need to know. ✔Correct Answer-Confidentiality
A discipline that seeks to manage configuration changes so that they are appropriately
approved and documented, so that the integrity of the security state is maintained, and so that
disruptions to performance and availability are minimized. ✔Correct Answer-Configuration
Management (CM)
These controls remedy the circumstances that enabled unwarranted activity, and/ or return
conditions to where they were prior to the unwanted activity. ✔Correct Answer-Corrective
Control
A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can
be purchased n the commercial marketplace and used under government contract. ✔Correct
Answer-COTS
A process that scans the entire collection of information looking for similar chunks of data that
can be consolidated. ✔Correct Answer-Deduplication