Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

SFPC Security Fundamentals Professional Certification 2025/2026 | Full DoD CDSE Exam Prep Guide with 100+ Real and Recently Tested Questions & Correct Answers | Verified Study Bank for First-Time Pass | Updated Version for U.S. Federal & Military Security

Beoordeling
-
Verkocht
1
Pagina's
45
Cijfer
A+
Geüpload op
01-08-2025
Geschreven in
2025/2026

This is a high-quality, exam-ready study document created to help students excel in their tests, assignments, and final reviews. It includes well-organized content, verified questions and answers, and clear explanations to support thorough understanding and revision. The document is available immediately after payment and can be accessed both online and as a downloadable PDF. It is suitable for detailed study, last-minute review, and exam preparation. If you experience any difficulty accessing or downloading the document, feel free to contact me directly. I will personally ensure that you receive the file without delay. Your success is important, and I am committed to making sure you get the best support through reliable study materials.

Meer zien Lees minder
Instelling
Sfpc
Vak
Sfpc

Voorbeeld van de inhoud

SFPC Security Fundamentals Professional
Certification 2025/2026 | Full DoD CDSE Exam Prep
Guide with 100+ Real and Recently Tested Questions &
Correct Answers | Verified Study Bank for First-Time
Pass | Updated Version for U.S. Federal & Military
Security Professionals
QUESTION 1
What is the primary goal of the CIA triad in information security?
A) To ensure data availability only
B) To maintain data integrity only
C) To protect the confidentiality, integrity, and availability of information
D) To manage security incidents effectively
Correct Option: C
RATIONALE: The CIA triad encompasses three core principles of information security:
Confidentiality (ensuring that information is accessible only to those authorized to
have access), Integrity (ensuring the accuracy and reliability of data), and Availability
(ensuring that information is accessible to authorized users when needed). Together,
these principles form the foundation of effective security practices.


QUESTION 2
Which of the following is considered a physical security control?
A) Firewalls
B) Security guards
C) Encryption
D) Anti-virus software
Correct Option: B
RATIONALE: Physical security controls are measures that protect physical assets and
facilities. Security guards are a direct physical presence that helps deter unauthorized
access and respond to incidents, making them a key component of physical security.


QUESTION 3
What is the purpose of the Risk Management Framework (RMF)?
A) To eliminate all security risks
B) To identify, assess, and manage risks to information systems
C) To provide a structured approach for managing security risks
D) To comply with all federal regulations

,Correct Option: C
RATIONALE: The Risk Management Framework provides a structured process for
integrating security and risk management activities into the system development
lifecycle. It helps organizations identify, assess, and manage risks to ensure that
information systems are protected effectively while balancing security needs with
operational requirements.


QUESTION 4
Which regulation mandates federal agencies to secure their information systems?
A) HIPAA
B) GDPR
C) FISMA
D) SOX
Correct Option: C
RATIONALE: The Federal Information Security Management Act (FISMA) requires federal
agencies to develop, document, and implement an information security program to
protect their information systems. This includes conducting risk assessments and
implementing appropriate security controls.
QUESTION 5
What is the primary purpose of data encryption?
A) To improve data access speed
B) To protect data confidentiality
C) To enhance data integrity
D) To ensure data availability
Correct Option: B
RATIONALE: Data encryption transforms information into a coded format to prevent
unauthorized access. Its primary purpose is to protect confidentiality, ensuring that only
authorized users can read the data.


QUESTION 6
Which of the following is NOT a type of malware?
A) Virus
B) Worm
C) Firewall
D) Trojan horse
Correct Option: C
RATIONALE: A firewall is a security device that monitors and controls incoming and

,outgoing network traffic based on predetermined security rules. It is not classified as
malware, which refers to malicious software designed to harm or exploit devices.


QUESTION 7
In a risk assessment, what does the term "likelihood" refer to?
A) The impact of a risk
B) The probability that a risk will occur
C) The number of assets at risk
D) The cost of mitigation
Correct Option: B
RATIONALE: "Likelihood" refers to the probability that a specific risk will occur within a
defined timeframe. Understanding this helps organizations prioritize risks based on
their potential frequency.


QUESTION 8
Which security model focuses on the concept of least privilege?
A) Bell-LaPadula Model
B) Biba Model
C) Clark-Wilson Model
D) Brewer-Nash Model
Correct Option: C
RATIONALE: The Clark-Wilson Model emphasizes the principle of least privilege,
ensuring that users have only the necessary access rights to perform their tasks,
thereby reducing the risk of unauthorized actions.


QUESTION 9
A company discovers that an employee has been accessing sensitive data without
authorization. What should be the first step in addressing this incident?
A) Terminate the employee immediately
B) Inform the media about the breach
C) Conduct an investigation to understand the extent of the access
D) Change all passwords immediately
Correct Option: C
RATIONALE: Conducting an investigation is essential to understand the nature and
extent of the unauthorized access. This helps in determining the appropriate response
and mitigating any potential damage.

, QUESTION 10
Which of the following is a key component of an incident response plan?
A) Risk assessment
B) Security training
C) Incident detection and reporting
D) Business continuity planning
Correct Option: C
RATIONALE: Incident detection and reporting are critical components of an incident
response plan, ensuring that incidents are identified, logged, and addressed promptly
to minimize impact.


QUESTION 11
What type of attack involves overwhelming a system with traffic to disrupt
services?
A) Phishing
B) Man-in-the-middle
C) Denial of Service (DoS)
D) SQL Injection
Correct Option: C
RATIONALE: A Denial of Service (DoS) attack aims to make a service unavailable by
overwhelming it with excessive traffic, preventing legitimate users from accessing it.


QUESTION 12
During a security audit, an organization finds that several employees share
passwords. What is the most effective action to take?
A) Ignore the practice as it is common
B) Increase monitoring of user accounts
C) Implement a password policy and provide training on strong password practices
D) Change all passwords to a common one
Correct Option: C
RATIONALE: Implementing a password policy and providing training on creating strong,
unique passwords is an effective way to enhance security and reduce the risks
associated with shared passwords.


QUESTION 13

Geschreven voor

Instelling
Sfpc
Vak
Sfpc

Documentinformatie

Geüpload op
1 augustus 2025
Aantal pagina's
45
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

€16,24
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
brightonmunene Wgu
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
1040
Lid sinds
1 jaar
Aantal volgers
14
Documenten
3189
Laatst verkocht
4 dagen geleden
Brighton Academic Hub

Welcome to Brighton Lighton’s academic store — your trusted source for high-quality, well-organized study materials designed to help you excel. Each document is immediately available after purchase in both online and downloadable PDF formats, with no restrictions. All files are carefully prepared and regularly updated to ensure accuracy, relevance, and ease of understanding. If you encounter any issue accessing a file after payment, feel free to contact me directly and I will personally send you the document promptly. Your satisfaction and academic success are my top priority.

Lees meer Lees minder
3,5

44 beoordelingen

5
19
4
6
3
6
2
4
1
9

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen