Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 12 páginas
Examen

Systems Security Certified Practitioner (SSCP) - Exam Answered

Document preview thumbnail
Vista previa 2 fuera de 12 páginas

Systems Security Certified Practitioner (SSCP) - Exam Answered Access Control Object - Answer- A passive entity that typically receives or contains some form of data. Access Control Subject - Answer- An active entity and can be any user, program, or process that requests permission to cause data to flow from an access control object to the access control subject or between access control objects. Asynchronous Password Token - Answer- A one-time password is generated without the use of a clock, either from a one-time pad or cryptographic algorithm. Authorization - Answer- Determines whether a user is permitted to access a particular resource. Connected Tokens - Answer- Must be physically connected to the computer to which the user is authenticating. Contactless Tokens - Answer- Form a logical connection to the client computer but do not require a physical connection. Disconnected Tokens - Answer- Have neither a physical nor logical connection to the client computer. Entitlement - Answer- A set of rules, defined by the resource owner, for managing access to a resource (asset, service, or entity) and for what purpose. Identity Management - Answer- The task of controlling information about users on computers. Proof of Identity - Answer- Verify people's identities before the enterprise issues them accounts and credentials. Kerberos - Answer- A popular network authentication protocol for indirect (third-party) authentication services. Lightweight Directory Access Protocol (LDAP) - Answer- A client/server-based directory query protocol loosely based on X.500, commonly used to manage user information. LDAP is a front end and not used to manage or synchronize data per se as opposed to DNS. Single Sign-On (SSO) - Answer- Designed to provide strong authentication using secret-key cryptography, allowing a single identity to be shared across multiple applications. Static Password Token - Answer- The device contains a password that is physically hidden (not visible to the possessor) but that is transmitted for each authentication. Synchronous Dynamic Password Token - Answer- A timer is used to rotate through various combinations produced by a cryptographic algorithm. Trust Path - Answer- A series of trust relationships that authentication requests must follow between domains Availability - Answer- Refers to the ability to access and use information systems when and as needed to support an organization's operations. Breach - Answer- The intentional or unintentional release of secure information to an untrusted environment. CMDB - Answer- A configuration management database (CMDB) is a repository that contains a collection of IT assets that are referred to as configuration items. Compensating Controls - Answer- Introduced when the existing capabilities of a system do not support the requirements of a policy. Confidentiality - Answer- Refers to the property of information in which it is only made available to those who have a legitimate need to know. Configuration Management (CM) - Answer- A discipline that seeks to manage configuration changes so that they are appropriately approved and documented, so that the integrity of the security state is maintained, and so that disruptions to performance and availability are minimized. Corrective Control - Answer- These controls remedy the circumstances that enabled unwarranted activity, and/ or return conditions to where they were prior to the unwanted activity. COTS - Answer- A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can be purchased n the commercial marketplace and used under government contract. Deduplication - Answer- A process that scans the entire collection of information looking for similar chunks of data that can be consolidated. Defense-in-depth - Answer- Provision of several overlapping subsequent limiting barriers with no respect to one safety or security threshold, so that the threshold can only be surpassed if all barriers have failed. Degaussing - Answer- A technique of erasing data on disk or tape (including video tapes) that, when performed properly, ensures that there is insufficient magnetic remanence to reconstruct data. Deluge System - Answer- A fire suppression system with open sprinker heads, water is held back until a detector in the area is activated. Deterrent Control - Answer- Controls that prescribe some sort of punishment, randing from embarrassment to job termination or jail time for noncompliance. Their intent is to dissuade people from performing unwanted acts. Directive Control - Answer- Controls dictated by organizational and legal authorities. Dry System - Answer- A fire suppression system that does not have water in the pipes until the electric valve is stimulated by excess heat. Dual Control - Answer- A procedure that uses two or more entities (usually persons) operating in concert to protect a system resource, such that no single entity acting alone can access that resource. Information Rights Management (IRM) - Answer- Assigns specific properties to an object such as how long the object may exist, what users or systems may access it, and if any notifications need to occur when the file is opened, modified, or printed. Integrity - Answer- The property of information whereby it is recorded, used, and maintained in a way that ensures its completeness, accuracy, internal consistency, and usefulness for a stated purpose. IT Asset Management (ITAM) - Answer- Entails collecting inventory and financial and contractual data to manage the IT asset throughout its life cycle. Least Privilege - Answer- A security principle in which any user/process is given only the necessary, minimum level of access rights (privileges) explicitly, for the minimum amount of time, in order for it to complete its operation. Non-repudiation - Answer- A service that is used to provide assurance of the integrity and origin of data in such a way that the integrity and origin can be verified by a third party as having originated from a specific entity in possession of the private key of the claimed signatory. Pre-action System - Answer- A fire suppression system that contains water in the pipes but will not release the water until detectors in the area have been activated. This can eliminate concerns of water damage due to accidental or false activation. Preventive Control - Answer- Controls that block unwanted actions. Privacy - Answer- The rights and obligations of individuals and organizations with respect to the collection, use, retention, and disclosure of personal information. Procedures - Answer- Step-by-step instructions for performing a specific task or set of tasks. Release Management - Answer- A software engineering discipline that controls the release of applications, updates, and patches to the production environment. Release Management Policy - Answer- Specifies the conditions that must be met for an application or component to be released to production, roles and responsibilities for packaging, approving, moving, and testing code releases, and approval and documentation requirements. Release Manager - Answer- Responsible for planning, coordination, implementation, and communication of all application releases. Separation of Duties - Answer- An operational security mechanism for preventing fraud and unauthorized use that requires two or more individuals to complete a task or perform a specific function.

Vista previa del contenido

Systems Security Certified
Practitioner (SSCP) - Exam Answered
Access Control Object - Answer- A passive entity that typically receives or contains
some form of data.

Access Control Subject - Answer- An active entity and can be any user, program, or
process that requests permission to cause data to flow from an access control object to
the access control subject or between access control objects.

Asynchronous Password Token - Answer- A one-time password is generated without
the use of a clock, either from a one-time pad or cryptographic algorithm.

Authorization - Answer- Determines whether a user is permitted to access a particular
resource.

Connected Tokens - Answer- Must be physically connected to the computer to which
the user is authenticating.

Contactless Tokens - Answer- Form a logical connection to the client computer but do
not require a physical connection.

Disconnected Tokens - Answer- Have neither a physical nor logical connection to the
client computer.

Entitlement - Answer- A set of rules, defined by the resource owner, for managing
access to a resource (asset, service, or entity) and for what purpose.

Identity Management - Answer- The task of controlling information about users on
computers.

Proof of Identity - Answer- Verify people's identities before the enterprise issues them
accounts and credentials.

Kerberos - Answer- A popular network authentication protocol for indirect (third-party)
authentication services.

Lightweight Directory Access Protocol (LDAP) - Answer- A client/server-based directory
query protocol loosely based on X.500, commonly used to manage user information.
LDAP is a front end and not used to manage or synchronize data per se as opposed to
DNS.

, Single Sign-On (SSO) - Answer- Designed to provide strong authentication using
secret-key cryptography, allowing a single identity to be shared across multiple
applications.

Static Password Token - Answer- The device contains a password that is physically
hidden (not visible to the possessor) but that is transmitted for each authentication.

Synchronous Dynamic Password Token - Answer- A timer is used to rotate through
various combinations produced by a cryptographic algorithm.

Trust Path - Answer- A series of trust relationships that authentication requests must
follow between domains

Availability - Answer- Refers to the ability to access and use information systems when
and as needed to support an organization's operations.

Breach - Answer- The intentional or unintentional release of secure information to an
untrusted environment.

CMDB - Answer- A configuration management database (CMDB) is a repository that
contains a collection of IT assets that are referred to as configuration items.

Compensating Controls - Answer- Introduced when the existing capabilities of a system
do not support the requirements of a policy.

Confidentiality - Answer- Refers to the property of information in which it is only made
available to those who have a legitimate need to know.

Configuration Management (CM) - Answer- A discipline that seeks to manage
configuration changes so that they are appropriately approved and documented, so that
the integrity of the security state is maintained, and so that disruptions to performance
and availability are minimized.

Corrective Control - Answer- These controls remedy the circumstances that enabled
unwarranted activity, and/ or return conditions to where they were prior to the unwanted
activity.

COTS - Answer- A Federal Acquistion Regulation (FAR) term for commercial off-the-
shelf (COTS) items, that can be purchased n the commercial marketplace and used
under government contract.

Deduplication - Answer- A process that scans the entire collection of information looking
for similar chunks of data that can be consolidated.

Información del documento

Subido en
4 de febrero de 2026
Número de páginas
12
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$14.14

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Stuviaascorers
3.7
(67)
Vendido
376
Seguidores
185
Artículos
11056
Última venta
1 semana hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes