SSCP Review| 275 Questions| with complete solutions| 77 pages
How many years of experience are required to earn the Associate of (ISC)2 designation? A. Zero B. One C. Two D. Five correct answer: [Security Fundamentals] A. You don't need to meet the experience requirement to earn the Associate of (ISC)2 designation, so zero years of experience are required. The SSCP certification requires one year of direct full-time security work experience. If you earn the Associate of (ISC)2 designation, you have two years from the date (ISC)2 notifies you that you have passed the SSCP exam to obtain the required experience and apply to become a fully certified SSCP (which includes submitting the required endorsement form). The CISSP certification requires five years of experience. What are the three elements of the security triad? A. Authentication authorization, and accounting B. Confidentiality, integrity, and availability C. Identification, authentication, and authorization D. Confidentiality, integrity, and authorization correct answer: [Security Fundamentals] B. The CIA security triad includes three fundamental principles of security designed to prevent losses in confidentiality, integrity, and availability. Authentication, authorization, and accounting are the AAAs of security, and identification, authentication, and authorization are required for accountability, but these are not part of the CIA security triad. Who is responsible for ensuring that security controls are in place to protect against the loss of confidentiality integrity, or availability of their systems and data? A. IT administrators B. System and information owners C. CFO D. Everyone correct answer: [Security Fundamentals] B. System and information owners are responsible for ensuring that these security controls are in place. IT administrators or other IT security personnel might implement and maintain them. While it can be argued that the Chief Executive Officer (CEO) is ultimately responsible for all security, the Chief Financial Officer is responsible for finances, not IT security. Assigning responsibility to everyone results in no one taking responsibility. You are sending an e-mail to a business partner that includes proprietary data. You want to ensure that the partner can access the data but that no one else can. What security principle should you apply? A. Authentication B. Availability C. Confidentiality D. Integrity correct answer: [Security Fundamentals] C. Confidentiality helps prevent the unauthorized disclosure of data to unauthorized personnel, and you can enforce it with encryption in this scenario. Authentication allows a user to claim an identity (such as with a username) and prove the identity (such as with a password). Availability ensures that data is available when needed. Integrity ensures that the data hasn't been modified. Your organization wants to ensure that attackers are unable to modify data within a database. What security principle is the organization trying to enforce? A. Accountability B. Availability C. Confidentiality D. Integrity correct answer: [Security Fundamentals] D. Integrity ensures that data is not modified, and this includes data within a database. Accountability ensures that systems identify users, track their actions, and monitor their behavior. Availability ensures that IT systems and data are available when needed. Confidentiality protects against the unauthorized disclosure of data. An organization wants to ensure that authorized employees are able to access resources during normal business hours. What security principle is the organization trying to enforce? A. Accountability B. Availability C. Integrity D. Confidentiality correct answer: [Security Fundamentals] B. Availability ensures that IT systems and data are available when needed, such as during normal business hours. Accountability ensures that users are accurately identified and authenticated, and their actions are tracked with logs. Integrity ensures that data is not modified. Confidentiality protects the unauthorized disclosure of data to unauthorized users. An organization has created a disaster recovery plan. What security principle is the organization trying to enforce? A. Authentication B. Availability C. Integrity D. Confidentiality correct answer: [Security Fundamentals] B. Availability ensures that IT systems and data are available when needed. Disaster recovery plans help an organization ensure availability of critical systems after a disaster. Users prove their identity with authentication. Integrity provides assurances that data and systems have not been modified. Confidentiality protects against the unauthor
Document information
- Uploaded on
- March 6, 2023
- Number of pages
- 77
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers