Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials SSCP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam


739 Students Passed

84% Average Score

91% Same Questions
Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions
Questions # 21:

Which of the following is a CHARACTERISTIC of a decision support system (DSS) in regards to Threats and Risks Analysis?

Options:

A.

DSS is aimed at solving highly structured problems.

B.

DSS emphasizes flexibility in the decision making approach of users.

C.

DSS supports only structured decision-making tasks.

D.

DSS combines the use of models with non-traditional data access and retrieval functions.

Questions # 22:

Which of the following embodies all the detailed actions that personnel are required to follow?

Options:

A.

Standards

B.

Guidelines

C.

Procedures

D.

Baselines

Questions # 23:

Which of the following is an unintended communication path that is NOT protected by the system's normal security mechanisms?

Options:

A.

A trusted path

B.

A protection domain

C.

A covert channel

D.

A maintenance hook

Questions # 24:

Making sure that only those who are supposed to access the data can access is which of the following?

Options:

A.

confidentiality.

B.

capability.

C.

integrity.

D.

availability.

Questions # 25:

Which of the following is a not a preventative control?

Options:

A.

Deny programmer access to production data.

B.

Require change requests to include information about dates, descriptions, cost analysis and anticipated effects.

C.

Run a source comparison program between control and current source periodically.

D.

Establish procedures for emergency changes.

Questions # 26:

Which of the following exemplifies proper separation of duties?

Options:

A.

Operators are not permitted modify the system time.

B.

Programmers are permitted to use the system console.

C.

Console operators are permitted to mount tapes and disks.

D.

Tape operators are permitted to use the system console.

Questions # 27:

It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?

Options:

A.

security administrator

B.

security analyst

C.

systems auditor

D.

systems programmer

Questions # 28:

IT security measures should:

Options:

A.

Be complex

B.

Be tailored to meet organizational security goals.

C.

Make sure that every asset of the organization is well protected.

D.

Not be developed in a layered fashion.

Questions # 29:

Which of the following addresses a portion of the primary memory by specifying the actual address of the memory location?

Options:

A.

direct addressing

B.

Indirect addressing

C.

implied addressing

D.

indexed addressing

Questions # 30:

Which of the following statements pertaining to the security kernel is incorrect?

Options:

A.

The security kernel is made up of mechanisms that fall under the TCB and implements and enforces the reference monitor concept.

B.

The security kernel must provide isolation for the processes carrying out the reference monitor concept and they must be tamperproof.

C.

The security kernel must be small enough to be able to be tested and verified in a complete and comprehensive manner.

D.

The security kernel is an access control concept, not an actual physical component.

Questions # 31:

What can best be defined as the sum of protection mechanisms inside the computer, including hardware, firmware and software?

Options:

A.

Trusted system

B.

Security kernel

C.

Trusted computing base

D.

Security perimeter

Questions # 32:

Which of the following are the steps usually followed in the development of documents such as security policy, standards and procedures?

Options:

A.

design, development, publication, coding, and testing.

B.

design, evaluation, approval, publication, and implementation.

C.

initiation, evaluation, development, approval, publication, implementation, and maintenance.

D.

feasibility, development, approval, implementation, and integration.

Questions # 33:

Which of the following is best defined as an administrative declaration by a designated authority that an information system is approved to operate in a particular security configuration with a prescribed set of safeguards?

Options:

A.

Certification

B.

Declaration

C.

Audit

D.

Accreditation

Questions # 34:

What is called the formal acceptance of the adequacy of a system's overall security by the management?

Options:

A.

Certification

B.

Acceptance

C.

Accreditation

D.

Evaluation

Questions # 35:

Which of the following is the MOST important aspect relating to employee termination?

Options:

A.

The details of employee have been removed from active payroll files.

B.

Company property provided to the employee has been returned.

C.

User ID and passwords of the employee have been deleted.

D.

The appropriate company staff are notified about the termination.

Questions # 36:

Related to information security, integrity is the opposite of which of the following?

Options:

A.

abstraction

B.

alteration

C.

accreditation

D.

application

Questions # 37:

The Reference Validation Mechanism that ensures the authorized access relationships between subjects and objects is implementing which of the following concept:

Options:

A.

The reference monitor.

B.

Discretionary Access Control.

C.

The Security Kernel.

D.

Mandatory Access Control.

Questions # 38:

Who of the following is responsible for ensuring that proper controls are in place to address integrity, confidentiality, and availability of IT systems and data?

Options:

A.

Business and functional managers

B.

IT Security practitioners

C.

System and information owners

D.

Chief information officer

Questions # 39:

Which of the following would MOST likely ensure that a system development project meets business objectives?

Options:

A.

Development and tests are run by different individuals

B.

User involvement in system specification and acceptance

C.

Development of a project plan identifying all development activities

D.

Strict deadlines and budgets

Questions # 40:

Which of the following phases of a software development life cycle normally addresses Due Care and Due Diligence?

Options:

A.

Implementation

B.

System feasibility

C.

Product design

D.

Software plans and requirements

Viewing page 2 out of 14 pages
Viewing questions 21-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.