Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 21 pages
Exam (elaborations)

SSCP 5th Edition Question Bank with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Document preview thumbnail
Preview 3 out of 21 pages

SSCP 5th Edition Question Bank with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Content preview

SSCP 5th Edition Question Bank with all Correct & 100%
Verified Answers |Actual Complete Update |Already
Graded A+

Security measures and mechanisms implemented to regulate and manage access to resources,
systems, or data within an organization's IT environment. They determine who is allowed to
access what, under what conditions, and in what manner, aiming to prevent unauthorized
access, protect sensitive information, enforce security policies, and ensure compliance with
regulatory requirements. ✔Correct Answer-Access controls

The security goal that generates the requirement for actions of an entity to be traced uniquely
to that entity. This supports non-repudiation, deterrence, fault isolation, intrusion detection and
prevention, and after-action recovery and legal action. ✔Correct Answer-Accountability

In a TCP three-way handshake, this is a confirmation message of receipt to begin data
transmission. ✔Correct Answer-ACK

When discharging gas suppression systems, this can produce a very loud "bang". The resultant
sound wave can cause degradation or destruction of sensitive IT equipment. ✔Correct
Answer-Acoustic shock

Controls implemented through policy and procedure. Examples include access control processes
and requiring multiple personnel to conduct a specific operation. In modern environments,
these are often enforced in conjunction with physical and/or technical controls, such as an
access-granting policy for new users that requires login and approval by the hiring manager.
✔Correct Answer-Administrative controls

An event with negative consequences, such as a system crash, network packet flood,
unauthorized use of system privileges, defacement of a web page, or execution of malicious
code that destroys data. ✔Correct Answer-Adverse event

The estimated yearly loss the organization can expect due to threat impact on assets, measured
in financial terms. Using this method, a return on investment can be calculated to ensure
approved countermeasures are cost-effective. Calculated by multiplying the single loss
expectancy (SLE) by the expected annual rate of occurrence (ARO). ✔Correct Answer-Annual
Loss Expectancy (ALE)

The expected number of exploitations by a specific threat of a vulnerability to an asset each
year. ✔Correct Answer-Annual Rate of Occurrence (ARO)

,An imprecise, generic term which refers to the growth in services, tools, technologies, and
capabilities being offered via the internet to businesses and consumers. XaaS capabilities may or
may not be cloud-hosted. Unlike SaaS, PaaS, and IaaS, XaaS does not represent or imply any
consistent architectural ideas, approaches, concepts, or designs. ✔Correct Answer-Anything
as a Service (XaaS)

A piece of software within a system that defines how other components or systems can use that
system. This interface defines the types of requests that can be made, how to make them, and
the data formats that must be used. ✔Correct Answer-Application Programming Interface
(API)

Fundamental concepts or properties of a system in its environment embodied in its elements,
relationships, and the principles of its design and evolution. Source: ISO/IEC/ISEEE 42010.
✔Correct Answer-Architecture

1. In forensics, a physical or logical item or set of items, such as a file on a thumb drive or the
thumb drive itself. Investigators must determine which of these are taken into custody as
evidence and which can remain at the scene as they have no evidentiary value to the
investigation. 2. In audits and assessments, the output produced by operational or special tests,
a physical object, file, data records in other formats, or notes and recordings from an interview
that are analyzed as part of the audit or assessment. ✔Correct Answer-Artifact

Anything of value that is owned by an organization. This can include both tangible items such as
information systems and physical property and intangible items such as intellectual property.
✔Correct Answer-Asset

A cryptographic system which uses two different but mathematically related keys, one for
encryption and the other for decryption. Public Key Infrastructure uses this type of encryption
through the use of public and private keys to ensure confidentiality while enforcing non-
repudiation. Asymmetric keys are also used to exchange other cryptographic keys as well as
digital signatures. ✔Correct Answer-Asymmetric encryption

A one-time password is generated without the use of a clock, either from a one- time pad or
cryptographic algorithm. ✔Correct Answer-Asynchronous password token

This is an access control paradigm whereby access rights are granted to users with policies that
combine attributes together. ✔Correct Answer-Attribute-Based Access Control (ABAC)

Independent review and examination of records and activities to assess the adequacy of system
controls and ensure compliance with established policies and operational procedures. Source:
CNSSI-40089. ✔Correct Answer-Audit

A security measure designed to protect a communications system against acceptance of
fraudulent transmission or simulation by establishing the validity of a transmission, message,

, originator, or a means of verifying an individual's eligibility to receive specific categories of
information. ✔Correct Answer-Authentication

The process of initially establishing access privileges of an individual and subsequently verifying
the acceptability of a request for access. ✔Correct Answer-Authorization

Ensuring timely and reliable access to and use of information by authorized users. ✔Correct
Answer-Availability

An unauthorized way to access a computer system that bypasses the system's security
measures. ✔Correct Answer-Backdoor

Large volumes of structured and unstructured data. The data may be collected from multiple
entities, internal systems, and publicly sourced information. ✔Correct Answer-Big data

Malcode that spreads in the wild by copying itself to the Master Boot Record (MBR) of a hard
disk and boot sectors of floppy disks. Brain, the first PC virus, is an example. ✔Correct
Answer-Boot sector virus

A computer program that operates as an agent, a user, or other program to simulate a human
activity. These are normally used to automate certain tasks, meaning they can run without
specific instructions from humans. ✔Correct Answer-Bot

This term is formed from the words "robot" and "network." Cyber criminals use special Trojan
viruses to breach the security of several users' computers, take control of each computer, and
organize all the infected machines into a network of "bots" that the criminal can remotely
manage. ✔Correct Answer-Botnet

A router that connects the internet to a company's intranet via a demilitarized zone (DMZ). This
router, which may be located at the ISP, is an external firewall that connects to the company's
internal firewall and proxy server within the DMZ. ✔Correct Answer-Boundary router

The intentional or unintentional release of secure information to an untrusted environment. The
loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar
occurrence where a person other than an authorized user accesses or potentially accesses
personally identifiable information, or an authorized user accesses personally identifiable
information for other than an authorized purpose. Source: NIST SP 800-53 Rev. 5. ✔Correct
Answer-Breach

A networking device that connects larger LAN networks with a group of smaller LAN networks.
✔Correct Answer-Bridge

A condition at an interface under which more input can be placed into a buffer or data holding
area than the intended capacity allocated (due to insecure or unbound allocation parameters),

Document information

Uploaded on
August 28, 2026
Number of pages
21
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Studyclub
3.6
(14)
Sold
67
Followers
1
Items
13153
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions