Pass4itsure > ISC > ISC Certifications > SSCP > SSCP Online Practice Questions and Answers

SSCP Online Practice Questions and Answers

Questions 4

Organizations should consider which of the following first before allowing external access to their LANs via the Internet?

A. plan for implementing workstation locking mechanisms.

B. plan for protecting the modem pool.

C. plan for providing the user with his account usage information.

D. plan for considering proper authentication options.

Buy Now
Questions 5

Smart cards are an example of which type of control?

A. Detective control

B. Administrative control

C. Technical control

D. Physical control

Buy Now
Questions 6

Password management falls into which control category?

A. Compensating

B. Detective

C. Preventive

D. Technical

Buy Now
Questions 7

Physical security is accomplished through proper facility construction, fire and water protection, anti-theft mechanisms, intrusion detection systems, and security procedures that are adhered to and enforced. Which of the following is not a component that achieves this type of security?

A. Administrative control mechanisms

B. Integrity control mechanisms

C. Technical control mechanisms

D. Physical control mechanisms

Buy Now
Questions 8

The National Institute of Standards and Technology (NIST) standard pertaining to perimeter protection states that critical areas should be illuminated up to?

A. Illiminated at nine feet high with at least three foot-candles

B. Illiminated at eight feet high with at least three foot-candles

C. Illiminated at eight feet high with at least two foot-candles

D. Illuminated at nine feet high with at least two foot-candles

Buy Now
Questions 9

What can best be defined as the detailed examination and testing of the security features of an IT system or product to ensure that they work correctly and effectively and do not show any logical vulnerabilities, such as evaluation criteria?

A. Acceptance testing

B. Evaluation

C. Certification

D. Accreditation

Buy Now
Questions 10

Which of the following is an IDS that acquires data and defines a "normal" usage profile for the network or host?

A. Statistical Anomaly-Based ID

B. Signature-Based ID

C. dynamical anomaly-based ID

D. inferential anomaly-based ID

Buy Now
Questions 11

Which of the following questions is less likely to help in assessing an organization's contingency planning controls?

A. Is damaged media stored and/or destroyed?

B. Are the backup storage site and alternate site geographically far enough from the primary site?

C. Is there an up-to-date copy of the plan stored securely off-site?

D. Is the location of stored backups identified?

Buy Now
Questions 12

Which of the following is true about link encryption?

A. Each entity has a common key with the destination node.

B. Encrypted messages are only decrypted by the final node.

C. This mode does not provide protection if anyone of the nodes along the transmission path is compromised.

D. Only secure nodes are used in this type of transmission.

Buy Now
Questions 13

Which of the following would be used to detect and correct errors so that integrity and confidentiality of transactions over networks may be maintained while preventing unauthorize interception of the traffic?

A. Information security

B. Server security

C. Client security

D. Communications security

Buy Now
Exam Code: SSCP
Exam Name: System Security Certified Practitioner (SSCP)
Last Update: Jan 17, 2025
Questions: 1074
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99