SSCP Questions
[Security Fundamentals]
How many years of experience are required to earn the Associate of (ISC)2 designation?
A. Zero
B. One
C. Two
D. Five - correct answer ✔✔A
[Security Fundamentals]
What are the three elements of the security triad?
A. Authentication authorization, and accounting
B. Confidentiality, integrity, and availability
C. Identification, authentication, and authorization
D. Confidentiality, integrity, and authorization - correct answer ✔✔B
[Security Fundamentals]
Who is responsible for ensuring that security controls are in place to protect against the loss of
confidentiality integrity, or availability of their systems and data?
A. IT administrators
B. System and information owners
C. CFO
,D. Everyone - correct answer ✔✔B
[Security Fundamentals]
You are sending an e-mail to a business partner that includes proprietary data. You want to ensure that
the partner can access the data but that no one else can. What security principle should you apply?
A. Authentication
B. Availability
C. Confidentiality
D. Integrity - correct answer ✔✔C
[Security Fundamentals]
Your organization wants to ensure that attackers are unable to modify data within a database. What
security principle is the organization trying to enforce?
A. Accountability
B. Availability
C. Confidentiality
D. Integrity - correct answer ✔✔D
[Security Fundamentals]
An organization wants to ensure that authorized employees are able to access resources during normal
business hours. What security principle is the organization trying to enforce?
A. Accountability
B. Availability
C. Integrity
,D. Confidentiality - correct answer ✔✔B
[Security Fundamentals]
An organization has created a disaster recovery plan. What security principle is the organization trying to
enforce?
A. Authentication
B. Availability
C. Integrity
D. Confidentiality - correct answer ✔✔B
[Security Fundamentals]
Your organization has implemented a least privilege policy. Which of the following choices describes the
most likely result of this policy?
A. It adds multiple layers of security.
B. No single user has full control over any process.
C. Users can only access data they need to perform their jobs.
D. It prevents users from denying they took an action. - correct answer ✔✔C
[Security Fundamentals]
Your organization wants to implement policies that will deter fraud by dividing job responsibilities. Which
of the following policies should they implement?
A. Nonrepudiation
B. Least privilege
C. Defense in depth
, D. Separation of duties - correct answer ✔✔D
[Security Fundamentals]
Which one of the following concepts provides the strongest security?
A. Defense in depth
B. Nonrepudiation
C. Security triad
D. AAAs of security - correct answer ✔✔A
[Security Fundamentals]
Which of the following would a financial institution use to validate an e-commerce transaction?
A. Nonrepudiation
B. Least privilege
C. Authentication
D. Signature - correct answer ✔✔A
[Security Fundamentals]
What are the AAAs of information security?
A. Authentication, availability, and authorization
B. Accounting, authentication, and availability
C. Authentication, authorization, and accounting
D. Availability, accountability, and authorization - correct answer ✔✔C
[Security Fundamentals]
How many years of experience are required to earn the Associate of (ISC)2 designation?
A. Zero
B. One
C. Two
D. Five - correct answer ✔✔A
[Security Fundamentals]
What are the three elements of the security triad?
A. Authentication authorization, and accounting
B. Confidentiality, integrity, and availability
C. Identification, authentication, and authorization
D. Confidentiality, integrity, and authorization - correct answer ✔✔B
[Security Fundamentals]
Who is responsible for ensuring that security controls are in place to protect against the loss of
confidentiality integrity, or availability of their systems and data?
A. IT administrators
B. System and information owners
C. CFO
,D. Everyone - correct answer ✔✔B
[Security Fundamentals]
You are sending an e-mail to a business partner that includes proprietary data. You want to ensure that
the partner can access the data but that no one else can. What security principle should you apply?
A. Authentication
B. Availability
C. Confidentiality
D. Integrity - correct answer ✔✔C
[Security Fundamentals]
Your organization wants to ensure that attackers are unable to modify data within a database. What
security principle is the organization trying to enforce?
A. Accountability
B. Availability
C. Confidentiality
D. Integrity - correct answer ✔✔D
[Security Fundamentals]
An organization wants to ensure that authorized employees are able to access resources during normal
business hours. What security principle is the organization trying to enforce?
A. Accountability
B. Availability
C. Integrity
,D. Confidentiality - correct answer ✔✔B
[Security Fundamentals]
An organization has created a disaster recovery plan. What security principle is the organization trying to
enforce?
A. Authentication
B. Availability
C. Integrity
D. Confidentiality - correct answer ✔✔B
[Security Fundamentals]
Your organization has implemented a least privilege policy. Which of the following choices describes the
most likely result of this policy?
A. It adds multiple layers of security.
B. No single user has full control over any process.
C. Users can only access data they need to perform their jobs.
D. It prevents users from denying they took an action. - correct answer ✔✔C
[Security Fundamentals]
Your organization wants to implement policies that will deter fraud by dividing job responsibilities. Which
of the following policies should they implement?
A. Nonrepudiation
B. Least privilege
C. Defense in depth
, D. Separation of duties - correct answer ✔✔D
[Security Fundamentals]
Which one of the following concepts provides the strongest security?
A. Defense in depth
B. Nonrepudiation
C. Security triad
D. AAAs of security - correct answer ✔✔A
[Security Fundamentals]
Which of the following would a financial institution use to validate an e-commerce transaction?
A. Nonrepudiation
B. Least privilege
C. Authentication
D. Signature - correct answer ✔✔A
[Security Fundamentals]
What are the AAAs of information security?
A. Authentication, availability, and authorization
B. Accounting, authentication, and availability
C. Authentication, authorization, and accounting
D. Availability, accountability, and authorization - correct answer ✔✔C