100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

Official (ISC)² SSCP Exam Questions & Answers 2023/2024

Rating
-
Sold
-
Pages
255
Grade
A+
Uploaded on
21-10-2023
Written in
2023/2024

Official (ISC)² SSCP Exam Questions & Answers 2023/2024 Access Control Object - ANSWER-A passive entity that typically receives or contains some form of data. Access Control Subject - ANSWER-An active entity and can be any user, program, or process that requests permission to cause data to flow from an access control object to the access control subject or between access control objects. Asynchronous Password Token - ANSWER-A one-time password is generated without the use of a clock, either from a one-time pad or cryptographic algorithm. Authorization - ANSWER-Determines whether a user is permitted to access a particular resource. Connected Tokens - ANSWER-Must be physically connected to the computer to which the user is authenticating. Contactless Tokens - ANSWER-Form a logical connection to the client computer but do not require a physical connection. Disconnected Tokens - ANSWER-Have neither a physical nor logical connection to the client computer. Entitlement - ANSWER-A set of rules, defined by the resource owner, for managing access to a resource (asset, service, or entity) and for what purpose. Identity Management - ANSWER-The task of controlling information about users on computers. Proof of Identity - ANSWER-Verify people's identities before the enterprise issues them accounts and credentials.

Show more Read less
Institution
Official ² SSCP
Course
Official ² SSCP











Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Official ² SSCP
Course
Official ² SSCP

Document information

Uploaded on
October 21, 2023
Number of pages
255
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Content preview

Official (ISC)² SSCP Exam Questions &
Answers 2023/2024

Access Control Object - ANSWER-A passive entity that typically receives or contains some form of data.



Access Control Subject - ANSWER-An active entity and can be any user, program, or process that
requests permission to cause data to flow from an access control object to the access control subject or
between access control objects.



Asynchronous Password Token - ANSWER-A one-time password is generated without the use of a clock,
either from a one-time pad or cryptographic algorithm.



Authorization - ANSWER-Determines whether a user is permitted to access a particular resource.



Connected Tokens - ANSWER-Must be physically connected to the computer to which the user is
authenticating.



Contactless Tokens - ANSWER-Form a logical connection to the client computer but do not require a
physical connection.



Disconnected Tokens - ANSWER-Have neither a physical nor logical connection to the client computer.



Entitlement - ANSWER-A set of rules, defined by the resource owner, for managing access to a resource
(asset, service, or entity) and for what purpose.



Identity Management - ANSWER-The task of controlling information about users on computers.



Proof of Identity - ANSWER-Verify people's identities before the enterprise issues them accounts and
credentials.

,Kerberos - ANSWER-A popular network authentication protocol for indirect (third-party) authentication
services.



Lightweight Directory Access Protocol (LDAP) - ANSWER-A client/server-based directory query protocol
loosely based on X.500, commonly used to manage user information. LDAP is a front end and not used to
manage or synchronize data per se as opposed to DNS.



Single Sign-On (SSO) - ANSWER-Designed to provide strong authentication using secret-key cryptography,
allowing a single identity to be shared across multiple applications.



Static Password Token - ANSWER-The device contains a password that is physically hidden (not visible to
the possessor) but that is transmitted for each authentication.



Synchronous Dynamic Password Token - ANSWER-A timer is used to rotate through various combinations
produced by a cryptographic algorithm.



Trust Path - ANSWER-A series of trust relationships that authentication requests must follow between
domains



6to4 - ANSWER-Transition mechanism for migrating from IPv4 to IPv6. It allows systems to use IPv6 to
communicate if their traffic has to transverse an IPv4 network.



Absolute addresses - ANSWER-Hardware addresses used by the CPU.



Abstraction - ANSWER-The capability to suppress unnecessary details so the important, inherent
properties can be examined and reviewed.



Accepted ways for handling risk - ANSWER-Accept, transfer, mitigate, avoid.



Access - ANSWER-The flow of information between a subject and an object.

,Access control matrix - ANSWER-A table of subjects and objects indicating what actions individual
subjects can take upon individual objects.



Access control model - ANSWER-An access control model is a framework that dictates how subjects
access objects.



Access controls - ANSWER-Are security features that control how users and systems communicate and
interact with other systems and resources.



Accreditation - ANSWER-Formal acceptance of the adequacy of a system's overall security by
management.



Active attack - ANSWER-Attack where the attacker does interact with processing or communication
activities.



ActiveX - ANSWER-A Microsoft technology composed of a set of OOP technologies and tools based on
COM and DCOM. It is a framework for defining reusable software components in a programming
language-independent manner



Address bus - ANSWER-Physical connections between processing components and memory segments
used to communicate the physical memory addresses being used during processing procedures.



Address resolution protocol (ARP) - ANSWER-A networking protocol used for resolution of network layer
IP addresses into link layer MAC addresses.



Address space layout randomization (ASLR) - ANSWER-Memory protection mechanism used by some
operating systems. The addresses used by components of a process are randomized so that it is harder
for an attacker to exploit specific memory vulnerabilities.



Algebraic attack - ANSWER-Cryptanalysis attack that exploits vulnerabilities within the intrinsic algebraic
structure of mathematical functions.



Algorithm - ANSWER-Set of mathematical and logic rules used in cryptographic functions.

, Analog signals - ANSWER-Continuously varying electromagnetic wave that represents and transmits
data.



Analytic attack - ANSWER-Cryptanalysis attack that exploits vulnerabilities within the algorithm structure.



Annualized loss expectancy (ALE) - ANSWER-Annual expected loss if a specific vulnerability is exploited
and how it affects a single asset. SLE × ARO = ALE.



Application programming interface (API) - ANSWER-Software interface that enables process-to-

process interaction. Common way to provide access to standard routines to a set of software programs.



Arithmetic logic unit (ALU) - ANSWER-A component of the computer's processing unit, in which
arithmetic and matching operations are performed.



AS/NZS 4360 - ANSWER-Australia and New Zealand business risk management assessment approach.



Assemblers - ANSWER-Tools that convert assembly code into the necessary machine-compatible binary
language for processing activities to take place.



Assembly language - ANSWER-A low-level programming language that is the mnemonic representation
of machine-level instructions.



Assurance evaluation criteria - ANSWER-Check-list and process of examining the security-relevant parts
of a system (TCB, reference monitor, security kernel) and assigning the system an assurance rating.



Asymmetric algorithm - ANSWER-Encryption method that uses two different key types, public and
private. Also called public key cryptography.



Asymmetric mode multiprocessing - ANSWER-When a computer has two or more CPUs and one CPU is
dedicated to a specific program while the other CPUs carry out general processing procedures

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Bensuda Oxford University
View profile
Follow You need to be logged in order to follow users or courses
Sold
849
Member since
3 year
Number of followers
445
Documents
21587
Last sold
2 days ago
ECONOMICS,NURSING,BIOLOGY AND ALL REVISION MATERIALS

DEDICATED TO PROVIDE YOU WITH THE BEST LEARNING MATERIALS THAT WILL IMPROVE YOUR GRADES ,WELCOME TO ALIZGRADES AND LETS DO IT TOGETHER!!! GOODLUCK!!!!!!!

3.7

158 reviews

5
74
4
24
3
25
2
11
1
24

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions