Security (SSCP) Questions with Verified Answers (Correct Update)
Question 1: Which of the following is a symmetric algorithm?
Answer: C
Question 2: A Diffie-Hellman B RSA C AES D HMAC
Answer: B
Question 3: How can a user be given the power to set privileges on an object for other users
when within a DAC operating system?
Answer: B
Question 4: Your company adopts a new end- user security awareness program. This training
includes malware introduction, social media issues, password guidelines, data exposure, and lost
devices. How often should end users receive this training?
Answer: B
Question 5: What type of event is more likely to trigger the business continuity plan (BCP)
rather than the disaster recovery plan (DRP)?
Answer: B
Question 6: What is the IEEE standard known as port-based network access control which is
used to leverage authentication already present in a network to validate clients connecting over
hardware devices, such as wireless access points or VPN concentrators?
Answer: A
Question 7: A IEEE 802.1x B IEEE 802.15 C IEEE 802.3 D IEEE 802.11
Answer: C
Question 8: Why is change control and management used as a component of software asset
management?
Answer: C
Question 9: What is the cost benefit equation?
Answer: A
Page 1
, Question 10: What is the best means to restore the most current form of data when a backup
strategy is based on starting each week off with a full backup followed by a daily differential?
Answer: A
Question 11: Which of the following is not considered an example of a non- discretionary access
control system?
Answer: B
Question 12: How should countermeasures be implemented as part of the recovery phase of
incident response?
Answer: D
Question 13: Remote control malware was found on a client device, and an unknown attacker
was manipulating the network from afar. The attack resulted in the network switches reverting
to flooding mode, thereby enabling the attacker to eavesdrop on a significant portion of network
communications. After reviewing IDS and traffic logs, you determine that this was
accomplished by an attack utility which generated a constant Ethernet frames with random
source MAC addresses. What can be done to prevent this attack from occurring in the future?
Answer: C
Question 14: How is quantitative risk analysis performed?
Answer: C
Question 15: What special component on a motherboard can be used to securely store the
encryption key for whole drive encryption?
Answer: C
Question 16: A CMOS B RAM C TPM D CPU
Answer: A
Question 17: When is it appropriate to contact law enforcement when an organization
experiences a security breach?
Answer: A
Page 2
Question 1: Which of the following is a symmetric algorithm?
Answer: C
Question 2: A Diffie-Hellman B RSA C AES D HMAC
Answer: B
Question 3: How can a user be given the power to set privileges on an object for other users
when within a DAC operating system?
Answer: B
Question 4: Your company adopts a new end- user security awareness program. This training
includes malware introduction, social media issues, password guidelines, data exposure, and lost
devices. How often should end users receive this training?
Answer: B
Question 5: What type of event is more likely to trigger the business continuity plan (BCP)
rather than the disaster recovery plan (DRP)?
Answer: B
Question 6: What is the IEEE standard known as port-based network access control which is
used to leverage authentication already present in a network to validate clients connecting over
hardware devices, such as wireless access points or VPN concentrators?
Answer: A
Question 7: A IEEE 802.1x B IEEE 802.15 C IEEE 802.3 D IEEE 802.11
Answer: C
Question 8: Why is change control and management used as a component of software asset
management?
Answer: C
Question 9: What is the cost benefit equation?
Answer: A
Page 1
, Question 10: What is the best means to restore the most current form of data when a backup
strategy is based on starting each week off with a full backup followed by a daily differential?
Answer: A
Question 11: Which of the following is not considered an example of a non- discretionary access
control system?
Answer: B
Question 12: How should countermeasures be implemented as part of the recovery phase of
incident response?
Answer: D
Question 13: Remote control malware was found on a client device, and an unknown attacker
was manipulating the network from afar. The attack resulted in the network switches reverting
to flooding mode, thereby enabling the attacker to eavesdrop on a significant portion of network
communications. After reviewing IDS and traffic logs, you determine that this was
accomplished by an attack utility which generated a constant Ethernet frames with random
source MAC addresses. What can be done to prevent this attack from occurring in the future?
Answer: C
Question 14: How is quantitative risk analysis performed?
Answer: C
Question 15: What special component on a motherboard can be used to securely store the
encryption key for whole drive encryption?
Answer: C
Question 16: A CMOS B RAM C TPM D CPU
Answer: A
Question 17: When is it appropriate to contact law enforcement when an organization
experiences a security breach?
Answer: A
Page 2