SSCP Domain 1: Security Operations and Administration
Test with all Correct & 100% Verified Answers |
Guaranteed to Pass
Code of Ethics Canon 1 ✔Correct Answer-protect society, the infrastructure, and the common
good
Code of Ethics Canon 2 ✔Correct Answer-actions must be legal and ethical, no lying
Code of Ethics Canon 3 ✔Correct Answer-diligence and competence
Code of Ethics Canon 4 ✔Correct Answer-Actions must protect the profession, no cheating on
exams, helping others with exam questions, lying on letters of recommendation etc.
GAPP - Generally Accepted Privacy Principles ✔Correct Answer-outline 10 components of
data privacy
GAPP Component - Management ✔Correct Answer-organizations handling private
information should have policies, procedures and governance structures in place to protect
privacy
GAPP Component - Notice ✔Correct Answer-Data subjects should receive notice that their
information is being collected and used
GAPP Component - Consent ✔Correct Answer-Data subjects must be informed of their
options regarding the data they own
GAPP Component - Collection ✔Correct Answer-Collected data can only be used for purposes
outlined in privacy notices.
GAPP Component - Use, Retention and Disposal ✔Correct Answer-Data should be disposed of
as soon as it is not needed
GAPP Component - Access ✔Correct Answer-Subjects must be able to access and update their
own data
GAPP Component - Disclosure to Third Parties ✔Correct Answer-Data can only be shared with
third parties outlined in privacy agreements
GAPP Component - Security ✔Correct Answer-Organization must secure data
, GAPP Component - Quality ✔Correct Answer-Org must maintain data, keep it accurate
GAPP Component - Monitoring and Enforcement ✔Correct Answer-Org must have program in
place to maintain compliance with privacy policies, and provide dispute resolution mechanisms
Privilege Aggregation ✔Correct Answer-synonymous with privilege creep
Data Controller ✔Correct Answer-GDPR term for data owner, senior-most role in data
governance
Data Steward ✔Correct Answer-handles day to day data decision making and governance.
Delegated by data controller
Data Custodian ✔Correct Answer-store and process information and are often IT staff
members. Ensure that data protection policies are in place
Data Users ✔Correct Answer-those who work with data and information on a regular basis.
Must work within the rules set by data custodians and data stewards
Data Subjects ✔Correct Answer-individuals referred to in collected data
Data Lifecycle Step - Create ✔Correct Answer-new data is created, includes data modification
Data Lifecycle Step - Store ✔Correct Answer-Data is stored and cataloged
Data Lifecycle Step - Use ✔Correct Answer-Data is viewed or processed by individuals and
systems
Data Lifecycle Step - Share ✔Correct Answer-Permissions assigned to files, users granted
permissions
Data Lifecycle Step - Archive ✔Correct Answer-Data is moved from active storage to long-term
storage
Data Lifecycle Step - Destroy ✔Correct Answer-Data is destroyed when it is no longer needed,
must be securely destroyed
Clearing ✔Correct Answer-data is overwritten
Purging ✔Correct Answer-data is overwritten but better, more advanced than purging
Destroying ✔Correct Answer-obliteration of data
NIST 800-88 ✔Correct Answer-Data sanitization technique publication
Test with all Correct & 100% Verified Answers |
Guaranteed to Pass
Code of Ethics Canon 1 ✔Correct Answer-protect society, the infrastructure, and the common
good
Code of Ethics Canon 2 ✔Correct Answer-actions must be legal and ethical, no lying
Code of Ethics Canon 3 ✔Correct Answer-diligence and competence
Code of Ethics Canon 4 ✔Correct Answer-Actions must protect the profession, no cheating on
exams, helping others with exam questions, lying on letters of recommendation etc.
GAPP - Generally Accepted Privacy Principles ✔Correct Answer-outline 10 components of
data privacy
GAPP Component - Management ✔Correct Answer-organizations handling private
information should have policies, procedures and governance structures in place to protect
privacy
GAPP Component - Notice ✔Correct Answer-Data subjects should receive notice that their
information is being collected and used
GAPP Component - Consent ✔Correct Answer-Data subjects must be informed of their
options regarding the data they own
GAPP Component - Collection ✔Correct Answer-Collected data can only be used for purposes
outlined in privacy notices.
GAPP Component - Use, Retention and Disposal ✔Correct Answer-Data should be disposed of
as soon as it is not needed
GAPP Component - Access ✔Correct Answer-Subjects must be able to access and update their
own data
GAPP Component - Disclosure to Third Parties ✔Correct Answer-Data can only be shared with
third parties outlined in privacy agreements
GAPP Component - Security ✔Correct Answer-Organization must secure data
, GAPP Component - Quality ✔Correct Answer-Org must maintain data, keep it accurate
GAPP Component - Monitoring and Enforcement ✔Correct Answer-Org must have program in
place to maintain compliance with privacy policies, and provide dispute resolution mechanisms
Privilege Aggregation ✔Correct Answer-synonymous with privilege creep
Data Controller ✔Correct Answer-GDPR term for data owner, senior-most role in data
governance
Data Steward ✔Correct Answer-handles day to day data decision making and governance.
Delegated by data controller
Data Custodian ✔Correct Answer-store and process information and are often IT staff
members. Ensure that data protection policies are in place
Data Users ✔Correct Answer-those who work with data and information on a regular basis.
Must work within the rules set by data custodians and data stewards
Data Subjects ✔Correct Answer-individuals referred to in collected data
Data Lifecycle Step - Create ✔Correct Answer-new data is created, includes data modification
Data Lifecycle Step - Store ✔Correct Answer-Data is stored and cataloged
Data Lifecycle Step - Use ✔Correct Answer-Data is viewed or processed by individuals and
systems
Data Lifecycle Step - Share ✔Correct Answer-Permissions assigned to files, users granted
permissions
Data Lifecycle Step - Archive ✔Correct Answer-Data is moved from active storage to long-term
storage
Data Lifecycle Step - Destroy ✔Correct Answer-Data is destroyed when it is no longer needed,
must be securely destroyed
Clearing ✔Correct Answer-data is overwritten
Purging ✔Correct Answer-data is overwritten but better, more advanced than purging
Destroying ✔Correct Answer-obliteration of data
NIST 800-88 ✔Correct Answer-Data sanitization technique publication