Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC 2 Credentials SSCP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SSCP Premium Access

View all detail and faqs for the SSCP exam


739 Students Passed

84% Average Score

91% Same Questions
Viewing page 8 out of 14 pages
Viewing questions 141-160 out of questions
Questions # 141:

Which of the following access control models introduces user security clearance and data classification?

Options:

A.

Role-based access control

B.

Discretionary access control

C.

Non-discretionary access control

D.

Mandatory access control

Questions # 142:

Which of the following attacks could capture network user passwords?

Options:

A.

Data diddling

B.

Sniffing

C.

IP Spoofing

D.

Smurfing

Questions # 143:

The three classic ways of authenticating yourself to the computer security software are: something you know, something you have, and something:

Options:

A.

you need.

B.

you read.

C.

you are.

D.

you do.

Questions # 144:

Which of the following is needed for System Accountability?

Options:

A.

Audit mechanisms.

B.

Documented design as laid out in the Common Criteria.

C.

Authorization.

D.

Formal verification of system design.

Questions # 145:

What does the simple security (ss) property mean in the Bell-LaPadula model?

Options:

A.

No read up

B.

No write down

C.

No read down

D.

No write up

Questions # 146:

Which one of the following authentication mechanisms creates a problem for mobile users?

Options:

A.

Mechanisms based on IP addresses

B.

Mechanism with reusable passwords

C.

one-time password mechanism.

D.

challenge response mechanism.

Questions # 147:

In Mandatory Access Control, sensitivity labels attached to object contain what information?

Options:

A.

The item's classification

B.

The item's classification and category set

C.

The item's category

D.

The items's need to know

Questions # 148:

Crime Prevention Through Environmental Design (CPTED) is a discipline that:

Options:

A.

Outlines how the proper design of a physical environment can reduce crime by directly affecting human behavior.

B.

Outlines how the proper design of the logical environment can reduce crime by directly affecting human behavior.

C.

Outlines how the proper design of the detective control environment can reduce crime by directly affecting human behavior.

D.

Outlines how the proper design of the administrative control environment can reduce crime by directly affecting human behavior.

Questions # 149:

Which type of control is concerned with avoiding occurrences of risks?

Options:

A.

Deterrent controls

B.

Detective controls

C.

Preventive controls

D.

Compensating controls

Questions # 150:

Which of the following classes is the first level (lower) defined in the TCSEC (Orange Book) as mandatory protection?

Options:

A.

B

B.

A

C.

C

D.

D

Questions # 151:

How can an individual/person best be identified or authenticated to prevent local masquarading attacks?

Options:

A.

UserId and password

B.

Smart card and PIN code

C.

Two-factor authentication

D.

Biometrics

Questions # 152:

In biometric identification systems, the parts of the body conveniently available for identification are:

Options:

A.

neck and mouth

B.

hands, face, and eyes

C.

feet and hair

D.

voice and neck

Questions # 153:

Which access control model provides upper and lower bounds of access capabilities for a subject?

Options:

A.

Role-based access control

B.

Lattice-based access control

C.

Biba access control

D.

Content-dependent access control

Questions # 154:

Which division of the Orange Book deals with discretionary protection (need-to-know)?

Options:

A.

D

B.

C

C.

B

D.

A

Questions # 155:

In regards to information classification what is the main responsibility of information (data) owner?

Options:

A.

determining the data sensitivity or classification level

B.

running regular data backups

C.

audit the data users

D.

periodically check the validity and accuracy of the data

Questions # 156:

Guards are appropriate whenever the function required by the security program involves which of the following?

Options:

A.

The use of discriminating judgment

B.

The use of physical force

C.

The operation of access control devices

D.

The need to detect unauthorized access

Questions # 157:

Like the Kerberos protocol, SESAME is also subject to which of the following?

Options:

A.

timeslot replay

B.

password guessing

C.

symmetric key guessing

D.

asymmetric key guessing

Questions # 158:

Which of the following is the WEAKEST authentication mechanism?

Options:

A.

Passphrases

B.

Passwords

C.

One-time passwords

D.

Token devices

Questions # 159:

In Synchronous dynamic password tokens:

Options:

A.

The token generates a new password value at fixed time intervals (this password could be based on the time of day encrypted with a secret key).

B.

The token generates a new non-unique password value at fixed time intervals (this password could be based on the time of day encrypted with a secret key).

C.

The unique password is not entered into a system or workstation along with an owner's PIN.

D.

The authentication entity in a system or workstation knows an owner's secret key and PIN, and the entity verifies that the entered password is invalid and that it was entered during the invalid time window.

Questions # 160:

Which of the following is used by RADIUS for communication between clients and servers?

Options:

A.

TCP

B.

SSL

C.

UDP

D.

SSH

Viewing page 8 out of 14 pages
Viewing questions 141-160 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.