[Mar-2022] ISC SSCP Exam Practice Test Questions - PassSureExam
Updated Certification Exam SSCP Dumps - Practice Test Questions
ISC SSCP candidate can face following difficulties in writing the ISC SSCP Certification Exam
The difficulty in writing the ISC SSCP certification exam is like an obstacle wall that limits students from being able to complete this certification. Students may take the exam' multiple times before being able to knot a passing score. It is not unusual that some students will be discouraged by this and may not continue or even try continuing with the certification class. There is also a big pool of students falling victim to failing their exams before even reaching one-third of the way through them. This is wrong and would cause more obstacles in completing this certification for some students. The difficulty in writing the ISC SSCP exam is mainly caused by the fact that there is a lack of sufficient information and methods to satisfactorily prepare oneself for such an exam. There are so many good and reasonable resources with useful information and up-to-date study materials but they are not easily available. But there is a source named ISC SSCP Dumps which has helped by providing PDF braindumps for the preparation of the ISC SSCP exam. The level of difficulty can be improved if one had access to such limited resources, such as more tutorials, explanations, and preparatory products on how to prepare for such an examination or making these sources more readily available through computer programs or website links. Anyone who has written and got his hands on the certification exam will know that getting stuck on questions during test day can really cause havoc with one's progress throughout the rest of their preparation period.
These difficult situations typically occur because the applicant has not fully studied for the ISC SSCP exam and has not adequately prepared and practiced daily and as a result makes many mistakes during the test. It isn't always someone's fault though. People just don't know how to prepare or where to go to get materials that can help them pass this exam. This is why we developed our website to serve as a means for people to learn how to prepare for such an examination and what materials they need in order to prepare and prepare themselves for such an examination. The ISC SSCP Exam is difficult to write because it's a high-stakes, high-stress rate exam. When you put your mind to the task of writing the test you quickly discover that not only is there a lot in it, but in order to pass this exam, you have to be perfectly well-versed in all the information. There are unlimited prep courses available for this test, but you can prepare on your own as well. In this article, we'll inform you about some of the best ways to help you study and then pass your ISC SSCP Exam.
NEW QUESTION 644
Which of the following is less likely to be included in the change control sub-phase of the maintenance phase of a software product?
- A. Determining the interface that is presented to the user
- B. Recreating and analyzing the problem
- C. Establishing the priorities of requests
- D. Estimating the cost of the changes requested
Answer: C
Explanation:
Explanation/Reference:
Change control sub-phase includes Recreating and analyzing the problem, Determining the interface that is presented to the user, and Establishing the priorities of requests.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 7: Applications and Systems Development (page
252).
NEW QUESTION 645
Address Resolution Protocol (ARP) interrogates the network by sending out a?
- A. multicast.
- B. broadcast.
- C. unicast.
- D. semicast.
Answer: B
Explanation:
Explanation/Reference:
ARP interrogates the network by sending out a broadcast seeking a network node that has a specific IP address, and asks it to reply with its hardware address. A broadcast message is sent to everyone whether or not the message was requested. A traditional unicast is a "one-to-one" or "narrowcast" message. A multicast is a "one-to-many" message that is traditionally only sent to those machine that requested the information. Semicast is an imposter answer.
Source: KRUTZ, Ronald L & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 87.
NEW QUESTION 646
One purpose of a security awareness program is to modify:
- A. employee's attitudes and behaviors towards enterprise's security posture
- B. management's approach towards enterprise's security posture
- C. attitudes of employees with sensitive data
- D. corporate attitudes about safeguarding data
Answer: A
Explanation:
Explanation/Reference:
security awareness training is to modify employees behaviour and attitude towards towards enterprise's security posture.
Security-awareness training is performed to modify employees' behavior and attitude toward security. This can best be achieved through a formalized process of security-awareness training.
It is used to increase the overall awareness of security throughout the company. It is targeted to every single employee and not only to one group of users.
Unfortunately you cannot apply a patch to a human being, the only thing you can do is to educate employees and make them more aware of security issues and threats. Never underestimate human stupidity.
Reference(s) used for this question:
TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.
also see:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 130). McGraw-Hill. Kindle Edition.
NEW QUESTION 647
In order to enable users to perform tasks and duties without having to go through extra steps it is important that the security controls and mechanisms that are in place have a degree of?
- A. Complexity
- B. Simplicity
- C. Transparency
- D. Non-transparency
Answer: C
Explanation:
The security controls and mechanisms that are in place must have a degree of transparency.
This enables the user to perform tasks and duties without having to go through extra steps because of the presence of the security controls. Transparency also does not let the user know too much about the controls, which helps prevent him from figuring out how to circumvent them. If the controls are too obvious, an attacker can figure out how to compromise them more easily.
Security (more specifically, the implementation of most security controls) has long been a sore point with users who are subject to security controls. Historically, security controls have been very intrusive to users, forcing them to interrupt their work flow and remember arcane codes or processes (like long passwords or access codes), and have generally been seen as an obstacle to getting work done. In recent years, much work has been done to remove that stigma of security controls as a detractor from the work process adding nothing but time and money. When developing access control, the system must be as transparent as possible to the end user. The users should be required to interact with the system as little as possible, and the process around using the control should be engineered so as to involve little effort on the part of the user.
For example, requiring a user to swipe an access card through a reader is an effective way to ensure a person is authorized to enter a room. However, implementing a technology (such as RFID) that will automatically scan the badge as the user approaches the door is more transparent to the user and will do less to impede the movement of personnel in a busy area.
In another example, asking a user to understand what applications and data sets will be required when requesting a system ID and then specifically requesting access to those resources may allow for a great deal of granularity when provisioning access, but it can hardly be seen as transparent. A more transparent process would be for the access provisioning system to have a role-based structure, where the user would simply specify the role he or she has in the organization and the system would know the specific resources that user needs to access based on that role. This requires less work and interaction on the part of the user and will lead to more accurate and secure access control decisions because access will be based on predefined need, not user preference.
When developing and implementing an access control system special care should be taken to ensure that the control is as transparent to the end user as possible and interrupts his work flow as little as possible.
The following answers were incorrect: All of the other detractors were incorrect.
Reference(s) used for this question:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, 6th edition. Operations Security, Page 1239-1240
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (Kindle Locations 25278-25281). McGraw-Hill. Kindle Edition.
Schneiter, Andrew (2013-04-15). Official (ISC)2 Guide to the CISSP CBK, Third Edition : Access Control ((ISC)2 Press) (Kindle Locations 713-729). Auerbach Publications. Kindle Edition.
NEW QUESTION 648
Pin, Password, Passphrases, Tokens, smart cards, and biometric devices are all items that can be used for Authentication. When one of these item listed above in conjunction with a second factor to validate authentication, it provides robust authentication of the individual by practicing which of the following?
- A. Multi-party authentication
- B. Mandatory authentication
- C. Two-factor authentication
- D. Discretionary authentication
Answer: C
Explanation:
Once an identity is established it must be authenticated. There exist numerous technologies and implementation of authentication methods however they almost all fall under three major areas.
There are three fundamental types of authentication:
Authentication by knowledge-something a person knows Authentication by possession-something a person has
Authentication by characteristic-something a person is
Logical controls related to these types are called "factors."
Something you know can be a password or PIN, something you have can be a token fob or
smart card, and something you are is usually some form of biometrics.
Single-factor authentication is the employment of one of these factors, two-factor
authentication is using two of the three factors, and three-factor authentication is the
combination of all three factors.
The general term for the use of more than one factor during authentication is multifactor
authentication or strong authentication.
Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third
Edition ((ISC)2 Press) (Kindle Locations 2367-2379). Auerbach Publications. Kindle
Edition.
NEW QUESTION 649
How should a doorway of a manned facility with automatic locks be configured?
- A. It should be configured to be fail-safe.
- B. It should not allow piggybacking.
- C. It should have a door delay cipher lock.
- D. It should be configured to be fail-secure.
Answer: A
Explanation:
Section: Access Control
Explanation/Reference:
Access controls are meant to protect facilities and computers as well as people.
In some situations, the objectives of physical access controls and the protection of people's lives may come into conflict. In theses situations, a person's life always takes precedence.
Many physical security controls make entry into and out of a facility hard, if not impossible. However, special consideration needs to be taken when this could affect lives. In an information processing facility, different types of locks can be used and piggybacking should be prevented, but the issue here with automatic locks is that they can either be configured as fail-safe or fail-secure.
Since there should only be one access door to an information processing facility, the automatic lock to the only door to a man-operated room must be configured to allow people out in case of emergency, hence to be fail- safe (sometimes called fail-open), meaning that upon fire alarm activation or electric power failure, the locking device unlocks. This is because the solenoid that maintains power to the lock to keep it in a locked state fails and thus opens or unlocks the electronic lock.
Fail Secure works just the other way. The lock device is in a locked or secure state with no power applied.
Upon authorized entry, a solinoid unlocks the lock temporarily. Thus in a Fail Secure lock, loss of power of fire alarm activation causes the lock to remain in a secure mode.
Reference(s) used for this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 451). McGraw-Hill. Kindle Edition.
and
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 20249-20251). Auerbach Publications. Kindle Edition.
NEW QUESTION 650
Which of the following are NOT a countermeasure to traffic analysis?
- A. Eavesdropping.
- B. Sending noise.
- C. Faraday Cage
- D. Padding messages.
Answer: A
Explanation:
Eavesdropping is not a countermeasure, it is a type of attack where you are collecting traffic and attempting to see what is being send between entities communicating with each other.
The following answers are incorrect:
Padding Messages. Is incorrect because it is considered a countermeasure you make messages uniform size, padding can be used to counter this kind of attack, in which decoy traffic is sent out over the network to disguise patterns and make it more difficult to uncover patterns. Sending Noise. Is incorrect because it is considered a countermeasure, tansmitting non-informational data elements to disguise real data.
Faraday Cage Is incorrect because it is a tool used to prevent emanation of electromagnetic waves. It is a very effective tool to prevent traffic analysis.
NEW QUESTION 651
Which of the following backup methods is primarily run when time and tape space permits, and is used for the system archive or baselined tape sets?
- A. full backup method.
- B. tape backup method.
- C. differential backup method.
- D. incremental backup method.
Answer: A
Explanation:
The Full Backup Method is primarily run when time and tape space permits,
and is used for the system archive or baselined tape sets.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 69.
NEW QUESTION 652
What is called the type of access control where there are pairs of elements that have the least upper bound of values and greatest lower bound of values?
- A. Discretionary model
- B. Rule model
- C. Mandatory model
- D. Lattice model
Answer: D
Explanation:
Explanation/Reference:
In a lattice model, there are pairs of elements that have the least upper bound of values and greatest lower bound of values.
Reference(s) used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 34.
NEW QUESTION 653
Notifying the appropriate parties to take action in order to determine the extent of the severity of an incident and to remediate the incident's effects is part of:
- A. Incident Recognition
- B. Incident Response
- C. Incident Evaluation
- D. Incident Protection
Answer: B
Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
These are core functions of the incident response process.
"Incident Evaluation" is incorrect. Evaluation of the extent and cause of the incident is a component of the incident response process.
"Incident Recognition" is incorrect. Recognition that an incident has occurred is the precursor to the initiation of the incident response process.
"Incident Protection" is incorrect. This is an almost-right-sounding nonsense answer to distract the unwary.
References
CBK, pp. 698 - 703
NEW QUESTION 654
Which of the following is an IP address that is private (i.e. reserved for internal networks, and not a valid address to use on the Internet)?
- A. 192.166.42.5
- B. 192.1.42.5
- C. 192.175.42.5
- D. 192.168.42.5
Answer: D
Explanation:
This is a valid Class C reserved address. For Class C, the reserved addresses are 192.168.0.0 - 192.168.255.255.
The private IP address ranges are defined within RFC 1918:
RFC 1918 private ip address range
The following answers are incorrect:
192.166.42.5 Is incorrect because it is not a Class C reserved address.
192.175.42.5 Is incorrect because it is not a Class C reserved address.
192.1.42.5 Is incorrect because it is not a Class C reserved address.
NEW QUESTION 655
What is called an automated means of identifying or authenticating the identity of a living person based on physiological or behavioral characteristics?
- A. Micrometrics
- B. MicroBiometrics
- C. Biometrics
- D. Macrometrics
Answer: C
Explanation:
Explanation/Reference:
Biometrics; Biometrics are defined as an automated means of identifying or authenticating the identity of a living person based on physiological or behavioral characteristics.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Pages 37,38.
NEW QUESTION 656
If any server in the cluster crashes, processing continues transparently, however, the cluster suffers some performance degradation. This implementation is sometimes called a:
- A. client farm
- B. host farm
- C. server farm
- D. cluster farm
Answer: C
Explanation:
If any server in the cluster crashes, processing continues transparently,
however, the cluster suffers some performance degradation. This implementation is
sometimes called a "server farm."
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the
Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 67.
NEW QUESTION 657
When preparing a business continuity plan, who of the following is responsible for identifying and prioritizing time-critical systems?
- A. BCP committee
- B. Functional business units
- C. Executive management staff
- D. Senior business unit management
Answer: D
Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
Many elements of a BCP will address senior management, such as the statement of importance and priorities, the statement of organizational responsibility, and the statement of urgency and timing. Executive management staff initiates the project, gives final approval and gives ongoing support. The BCP committee directs the planning, implementation, and tests processes whereas functional business units participate in implementation and testing.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 8: Business Continuity Planning and Disaster Recovery Planning (page 275).
NEW QUESTION 658
Kerberos can prevent which one of the following attacks?
- A. playback (replay) attack.
- B. tunneling attack.
- C. destructive attack.
- D. process attack.
Answer: A
Explanation:
Each ticket in Kerberos has a timestamp and are subject to time expiration to help prevent these types of attacks.
The following answers are incorrect:
tunneling attack. This is incorrect because a tunneling attack is an attempt to bypass security and access low-level systems. Kerberos cannot totally prevent these types of attacks.
destructive attack. This is incorrect because depending on the type of destructive attack, Kerberos cannot prevent someone from physically destroying a server.
process attack. This is incorrect because with Kerberos cannot prevent an authorzied individuals from running processes.
NEW QUESTION 659
__________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.
- A. Buffer Overflow
- B. Coordinated
- C. SYN Flood
- D. Denial of Service
- E. Distributed Denial of Service
Answer: A
NEW QUESTION 660
What does the Clark-Wilson security model focus on?
- A. Accountability
- B. Integrity
- C. Confidentiality
- D. Availability
Answer: B
Explanation:
Section: Access Control
Explanation/Reference:
The Clark-Wilson model addresses integrity. It incorporates mechanisms to enforce internal and external consistency, a separation of duty, and a mandatory integrity policy.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 5: Security Architectures and Models (page 205).
NEW QUESTION 661
Making sure that the data is accessible when and where it is needed is which of the following?
- A. acceptability
- B. integrity
- C. confidentiality
- D. availability
Answer: D
Explanation:
Explanation/Reference:
Availability is making sure that the data is accessible when and where it is needed.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 59.
NEW QUESTION 662
Which of the following is a disadvantage of a statistical anomaly-based intrusion detection system?
- A. it may correctly detect a non-attack event that had caused a momentary anomaly in the system.
- B. it may falsely detect a non-attack event that had caused a momentary anomaly in the system.
- C. it may loosely detect a non-attack event that had caused a momentary anomaly in the system.
- D. it may truly detect a non-attack event that had caused a momentary anomaly in the system.
Answer: B
Explanation:
Explanation/Reference:
Some disadvantages of a statistical anomaly-based ID are that it will not detect an attack that does not significantly change the system operating characteristics, or it may falsely detect a non-attack event that had caused a momentary anomaly in the system.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 49.
NEW QUESTION 663
To understand the 'whys' in crime, many times it is necessary to understand MOM. Which of the following is not a component of MOM?
- A. Means
- B. Motivation
- C. Methods
- D. Opportunities
Answer: C
Explanation:
Explanation/Reference:
To understand the whys in crime, many times it is necessary to understand the Motivations, Opportunities, and Means (MOM). Motivations are the who and why of a crime. Opportunities are the where and when of a crime, and Means pertains to the capabilities a criminal would need to be successful. Methods is not a component of MOM.
NEW QUESTION 664
Which of the following is defined as an Internet, IPsec, key-establishment protocol, partly based on OAKLEY, that is intended for putting in place authenticated keying material for use with ISAKMP and for other security associations?
- A. Key Exchange Algorithm (KEA)
- B. Security Association Authentication Protocol (SAAP)
- C. Simple Key-management for Internet Protocols (SKIP)
- D. Internet Key exchange (IKE)
Answer: D
Explanation:
Explanation/Reference:
RFC 2828 (Internet Security Glossary) defines IKE as an Internet, IPsec, key-establishment protocol (partly based on OAKLEY) that is intended for putting in place authenticated keying material for use with ISAKMP and for other security associations, such as in AH and ESP.
The following are incorrect answers:
SKIP is a key distribution protocol that uses hybrid encryption to convey session keys that are used to encrypt data in IP packets.
The Key Exchange Algorithm (KEA) is defined as a key agreement algorithm that is similar to the Diffie- Hellman algorithm, uses 1024-bit asymmetric keys, and was developed and formerly classified at the secret level by the NSA.
Security Association Authentication Protocol (SAAP) is a distracter.
Reference(s) used for this question:
SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000.
NEW QUESTION 665
A Security Kernel is defined as a strict implementation of a reference monitor mechanism responsible for enforcing a security policy. To be secure, the kernel must meet three basic conditions, what are they?
- A. Confidentiality, Integrity, and Availability
- B. Completeness, Isolation, and Verifiability
- C. Policy, mechanism, and assurance
- D. Isolation, layering, and abstraction
Answer: B
Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
A security kernel is responsible for enforcing a security policy. It is a strict implementation of a reference monitor mechanism. The architecture of a kernel operating system is typically layered, and the kernel should be at the lowest and most primitive level.
It is a small portion of the operating system through which all references to information and all changes to authorizations must pass. In theory, the kernel implements access control and information flow control between implemented objects according to the security policy.
To be secure, the kernel must meet three basic conditions:
completeness (all accesses to information must go through the kernel),
isolation (the kernel itself must be protected from any type of unauthorized access), and verifiability (the kernel must be proven to meet design specifications).
The reference monitor, as noted previously, is an abstraction, but there may be a reference validator, which usually runs inside the security kernel and is responsible for performing security access checks on objects, manipulating privileges, and generating any resulting security audit messages.
A term associated with security kernels and the reference monitor is the trusted computing base (TCB). The TCB is the portion of a computer system that contains all elements of the system responsible for supporting the security policy and the isolation of objects. The security capabilities of products for use in the TCB can be verified through various evaluation criteria, such as the earlier Trusted Computer System Evaluation Criteria (TCSEC) and the current Common Criteria standard.
Many of these security terms-reference monitor, security kernel, TCB-are defined loosely by vendors for purposes of marketing literature. Thus, it is necessary for security professionals to read the small print and between the lines to fully understand what the vendor is offering in regard to security features.
TIP FOR THE EXAM:
The terms Security Kernel and Reference monitor are synonymous but at different levels.
As it was explained by Diego:
While the Reference monitor is the concept, the Security kernel is the implementation of such concept (via hardware, software and firmware means).
The two terms are the same thing, but on different levels: one is conceptual, one is "technical" The following are incorrect answers:
Confidentiality, Integrity, and Availability
Policy, mechanism, and assurance
Isolation, layering, and abstraction
Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 13858-13875). Auerbach Publications. Kindle Edition.
NEW QUESTION 666
......
List of Career opportunities after getting ISC SSCP Certification
A list of career opportunities that one might find after getting ISC SSCP Certification:
- Information assurance specialist
- Security officer (SO), senior management/senior executive/programmer/engineer/data analyst etc.
- Systems administrator and IT specialist
- Information security professional
- Information technology manager (IT)
- Security auditor
Updated Verified SSCP dumps Q&As - Pass Guarantee or Full Refund: https://passleader.passsureexam.com/SSCP-pass4sure-exam-dumps.html