SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
1. Carla's organization recently suffered a data
file integrity monitoring
breach when an employee misplaced a laptop
containing sen-sitive customer information.
Which one of the follow-ing controls would be
least likely to prevent this type of breach
from reoccurring in the future?
2. Which information security goal is impacted availability
when an organization experiences a DoS or
DDoS attack?
data integrity
3. Lauren's multinational company is planning
a new cloud deployment and wants to
ensure compliance with the EU GDPR.
Which principle states that the individual
should have the right to receive personal
information concerning himself or herself
and share it with another data controller?
4. Kelly is adjusting her organization's password require- no expiration
ments to make them consistent with best
practice guidance from NIST. What should she
choose as the most appropriate time period
for password expira-tion?
5. What term is used to describe a set of common baseline
secu-rity configurations, often provided by a
third party?
6. During a port scan using nmap, Joseph discovers that FTP and
Telnet
a system shows two ports open that cause him
imme-diate worry: 21/open 23/open What
services are likely running on those ports?
1/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
7. Mark is considering replacing his SaaS
organization's cus-tomer relationship
management (CRM) solution with a new
product that is available in the cloud. This new
2/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
solution is completely managed by the
vendor, and Mark's company will not have to
write any code or manage any physical
resources. What type of cloud solution is Mark
considering?
Transitive trust
8. What type of trust relationship extends
beyond the two domains participating in the
trust to one or more of their subdomains?
Printer, Network-
9. During a port scan of his network, Alex finds enabled printers often
that a number of hosts respond on TCP ports
provide ser-
80, 443, 515,
and 9100 in offices throughout his organization. What vices via TCP
515 and 9100
type of devices is Alex likely discovering? and have both
nonse-cure and
secure web-en-abled
management inter-
faces on TCP 80 and
10. As part of his team's forensic investigation
443.
process, Matt signs drives and other
evidence out of storage before working with chain of custody
them. What type of documenta-tion is he
creating?
11. Which one of the following would be a reasonable ap- internal
scheduling appli-
plication for the use of self-signed digital certificates? cation,
Self-signed digital
certifi-cates should be
used only for internal-
facing appli-cations,
3/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
where the user base
trusts the internal-
ly generated digital
certifi-cate.
4/
35
LATEST VERSION |ALREADY GRADED A+
1. Carla's organization recently suffered a data
file integrity monitoring
breach when an employee misplaced a laptop
containing sen-sitive customer information.
Which one of the follow-ing controls would be
least likely to prevent this type of breach
from reoccurring in the future?
2. Which information security goal is impacted availability
when an organization experiences a DoS or
DDoS attack?
data integrity
3. Lauren's multinational company is planning
a new cloud deployment and wants to
ensure compliance with the EU GDPR.
Which principle states that the individual
should have the right to receive personal
information concerning himself or herself
and share it with another data controller?
4. Kelly is adjusting her organization's password require- no expiration
ments to make them consistent with best
practice guidance from NIST. What should she
choose as the most appropriate time period
for password expira-tion?
5. What term is used to describe a set of common baseline
secu-rity configurations, often provided by a
third party?
6. During a port scan using nmap, Joseph discovers that FTP and
Telnet
a system shows two ports open that cause him
imme-diate worry: 21/open 23/open What
services are likely running on those ports?
1/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
7. Mark is considering replacing his SaaS
organization's cus-tomer relationship
management (CRM) solution with a new
product that is available in the cloud. This new
2/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
solution is completely managed by the
vendor, and Mark's company will not have to
write any code or manage any physical
resources. What type of cloud solution is Mark
considering?
Transitive trust
8. What type of trust relationship extends
beyond the two domains participating in the
trust to one or more of their subdomains?
Printer, Network-
9. During a port scan of his network, Alex finds enabled printers often
that a number of hosts respond on TCP ports
provide ser-
80, 443, 515,
and 9100 in offices throughout his organization. What vices via TCP
515 and 9100
type of devices is Alex likely discovering? and have both
nonse-cure and
secure web-en-abled
management inter-
faces on TCP 80 and
10. As part of his team's forensic investigation
443.
process, Matt signs drives and other
evidence out of storage before working with chain of custody
them. What type of documenta-tion is he
creating?
11. Which one of the following would be a reasonable ap- internal
scheduling appli-
plication for the use of self-signed digital certificates? cation,
Self-signed digital
certifi-cates should be
used only for internal-
facing appli-cations,
3/
35
, SSCP EXAM 2 WITH ALL CORRECT & 100% VERIFIED ANSWERS |
LATEST VERSION |ALREADY GRADED A+
where the user base
trusts the internal-
ly generated digital
certifi-cate.
4/
35