SSCP Study 175 QUESTIONS WITH COMPLETE SOLUTIONS
ARO correct answer: Incidents/year What does STRIDE stand for? correct answer: Spoofing Tampering Repudiation Information disclosure Denial of service Elevation of privilege Reduction Analysis correct answer: Breaks a system down into smaller components What does repeated software deficiencies indicate? correct answer: A need for a software architecture change What should threat modeling do? correct answer: Inform the rest of the security program Honeypot correct answer: Vulnerable computer that is set up to entice an intruder to break into it Honeynet correct answer: A network set up with intentional vulnerabilities. Port scanner correct answer: A type of software that searches a network host for open ports. Nmap is a type of port scanner Vulnerability scanner correct answer: Scanners test open ports for active vulnerabilities and provide info for remediation Nessus is a type of vul scanner Threat correct answer: External source of danger vulnerability correct answer: A flaw or weakness that allows a threat agent to bypass security. Risk correct answer: Vulnerability + threat White Box Testing correct answer: Attackers has full knowledge of the network environment Black box testing correct answer: Attackers has no knowledge of the network environment Grey box testing correct answer: Attackers has some knowledge of the network environment non-intrusive vulnerability scan correct answer: Safe mode that won't disrupt system operation Intrusive scanning correct answer: A "dangerous" mode that might disrupt system operation Credentialed scanning correct answer: Scan c
Written for
- Institution
-
Liberty University
- Course
-
SSCP
Document information
- Uploaded on
- March 6, 2023
- Number of pages
- 17
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
-
sscp study 175 questions with complete solutions
Also available in package deal