1
Systems Security Certified Practitioner (SSCP) - Exam Prep/
Exam Questions with Correct Verified Answers/ Rated A+
Access Control Object –
✓ A passive entity that typically receives or contains some form of data
Access Control Subject –
✓ An active entity and can be any user, program, or process that requests permission to cause data
to flow from an access control object to the access control subject or between access control
objects.
Asynchronous Password Token –
✓ A one-time password is generated without the use of a clock, either from a one-time pad or
cryptographic algorithm.
Information Rights Management (IRM) –
✓ Assigns specific properties to an object such as how long the object may exist, what users or
systems may access it, and if any notifications need to occur when the file is opened, modified,
or printed.
Integrity –
✓ The property of information whereby it is recorded, used, and maintained in a way that ensures
its completeness, accuracy, internal consistency, and usefulness for a stated purpose.
IT Asset Management (ITAM) –
✓ Entails collecting inventory and financial and contractual data to manage the IT asset throughout
its life cycle.
, 2
Least Privilege –
✓ A security principle in which any user/process is given only the necessary, minimum level of
access rights (privileges) explicitly, for the minimum amount of time, in order for it to complete
its operation.
Non-repudiation –
✓ A service that is used to provide assurance of the integrity and origin of data in such a way that
the integrity and origin can be verified by a third party as having originated from a specific entity
in possession of the private key of the claimed signatory.
Confidentiality –
✓ Refers to the property of information in which it is only made available to those who have a
legitimate need to know.
Configuration Management (CM) –
✓ A discipline that seeks to manage configuration changes so that they are appropriately approved
and documented, so that the integrity of the security state is maintained, and so that disruptions
to performance and availability are minimized.
Corrective Control –
✓ These controls remedy the circumstances that enabled unwarranted activity, and/ or return
conditions to where they were prior to the unwanted activity.
COTS –
✓ A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can
be purchased n the commercial marketplace and used under government contract.
Deduplication –
✓ A process that scans the entire collection of information looking for similar chunks of data that
can be consolidated.
, 3
Defense-in-depth –
✓ Provision of several overlapping subsequent limiting barriers with no respect to one safety or
security threshold, so that the threshold can only be surpassed if all barriers have failed.
Degaussing –
✓ A technique of erasing data on disk or tape (including video tapes) that, when performed
properly, ensures that there is insufficient magnetic remanence to reconstruct data.
Pre-action System –
✓ A fire suppression system that contains water in the pipes but will not release the water until
detectors in the area have been activated. This can eliminate concerns of water damage due to
accidental or false activation.
Authorization –
✓ Determines whether a user is permitted to access a particular resource.
Connected Tokens –
✓ Must be physically connected to the computer to which the user is authenticating.
Contactless Tokens –
✓ Form a logical connection to the client computer but do not require a physical connection.
Disconnected Tokens –
✓ Have neither a physical nor logical connection to the client computer.
Entitlement –
✓ A set of rules, defined by the resource owner, for managing access to a resource (asset, service,
or entity) and for what purpose.
Systems Security Certified Practitioner (SSCP) - Exam Prep/
Exam Questions with Correct Verified Answers/ Rated A+
Access Control Object –
✓ A passive entity that typically receives or contains some form of data
Access Control Subject –
✓ An active entity and can be any user, program, or process that requests permission to cause data
to flow from an access control object to the access control subject or between access control
objects.
Asynchronous Password Token –
✓ A one-time password is generated without the use of a clock, either from a one-time pad or
cryptographic algorithm.
Information Rights Management (IRM) –
✓ Assigns specific properties to an object such as how long the object may exist, what users or
systems may access it, and if any notifications need to occur when the file is opened, modified,
or printed.
Integrity –
✓ The property of information whereby it is recorded, used, and maintained in a way that ensures
its completeness, accuracy, internal consistency, and usefulness for a stated purpose.
IT Asset Management (ITAM) –
✓ Entails collecting inventory and financial and contractual data to manage the IT asset throughout
its life cycle.
, 2
Least Privilege –
✓ A security principle in which any user/process is given only the necessary, minimum level of
access rights (privileges) explicitly, for the minimum amount of time, in order for it to complete
its operation.
Non-repudiation –
✓ A service that is used to provide assurance of the integrity and origin of data in such a way that
the integrity and origin can be verified by a third party as having originated from a specific entity
in possession of the private key of the claimed signatory.
Confidentiality –
✓ Refers to the property of information in which it is only made available to those who have a
legitimate need to know.
Configuration Management (CM) –
✓ A discipline that seeks to manage configuration changes so that they are appropriately approved
and documented, so that the integrity of the security state is maintained, and so that disruptions
to performance and availability are minimized.
Corrective Control –
✓ These controls remedy the circumstances that enabled unwarranted activity, and/ or return
conditions to where they were prior to the unwanted activity.
COTS –
✓ A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can
be purchased n the commercial marketplace and used under government contract.
Deduplication –
✓ A process that scans the entire collection of information looking for similar chunks of data that
can be consolidated.
, 3
Defense-in-depth –
✓ Provision of several overlapping subsequent limiting barriers with no respect to one safety or
security threshold, so that the threshold can only be surpassed if all barriers have failed.
Degaussing –
✓ A technique of erasing data on disk or tape (including video tapes) that, when performed
properly, ensures that there is insufficient magnetic remanence to reconstruct data.
Pre-action System –
✓ A fire suppression system that contains water in the pipes but will not release the water until
detectors in the area have been activated. This can eliminate concerns of water damage due to
accidental or false activation.
Authorization –
✓ Determines whether a user is permitted to access a particular resource.
Connected Tokens –
✓ Must be physically connected to the computer to which the user is authenticating.
Contactless Tokens –
✓ Form a logical connection to the client computer but do not require a physical connection.
Disconnected Tokens –
✓ Have neither a physical nor logical connection to the client computer.
Entitlement –
✓ A set of rules, defined by the resource owner, for managing access to a resource (asset, service,
or entity) and for what purpose.