[2024] Easy To Download SSCP Actual Exam Dumps Resources [Q762-Q778]

Share

[2024] Easy To Download SSCP Actual Exam Dumps Resources

Uplift Your SSCP Exam Marks With The Help of SSCP Dumps


Prerequisites

The applicants must possess a minimum of one year of cumulative, full-time, and paid work experience in at least one of the seven domains of the SSCP CBK. Additionally, they must pass the qualifying exam to get the certification. Those individuals who do not possess the required work experience can proceed to take the (ISC)2 SSCP test and earn the Associate of (ISC)2 certificate, while working to gain the required experience to obtain SSCP. In this case, you will need to get two years of experience to get the required expertise for the SSCP certification.

 

NEW QUESTION # 762
In biometric identification systems, at the beginning, it was soon apparent that truly positive identification could only be based on :

  • A. voice of a person
  • B. sex of a person
  • C. physical attributes of a person
  • D. age of a person

Answer: C

Explanation:
Today implementation of fast, accurate reliable and user-acceptable biometric identification systems is already under way.


NEW QUESTION # 763
Passwords can be required to change monthly, quarterly, or at other intervals:

  • A. not depending on the criticality of the information needing protection but depending on the password's frequency of use
  • B. depending on the criticality of the information needing protection
  • C. depending on the criticality of the information needing protection and the password's frequency of use
  • D. depending on the password's frequency of use

Answer: C

Explanation:
Section: Access Control
Explanation/Reference:
Passwords can be compromised and must be protected. In the ideal case, a password should only be used once. The changing of passwords can also fall between these two extremes. Passwords can be required to change monthly, quarterly, or at other intervals, depending on the criticality of the information needing protection and the password's frequency of use. Obviously, the more times a password is used, the more chance there is of it being compromised.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 36 & 37.


NEW QUESTION # 764
Which of the following is needed for System Accountability?

  • A. Audit mechanisms.
  • B. Formal verification of system design.
  • C. Documented design as laid out in the Common Criteria.
  • D. Authorization.

Answer: A

Explanation:
Is a means of being able to track user actions. Through the use of audit logs
and other tools the user actions are recorded and can be used at a later date to verify what
actions were performed.
Accountability is the ability to identify users and to be able to track user actions.
The following answers are incorrect:
Documented design as laid out in the Common Criteria. Is incorrect because the Common
Criteria is an international standard to evaluate trust and would not be a factor in System
Accountability.
Authorization. Is incorrect because Authorization is granting access to subjects, just
because you have authorization does not hold the subject accountable for their actions.
Formal verification of system design. Is incorrect because all you have done is to verify the
system design and have not taken any steps toward system accountability.
References:
OIG CBK Glossary (page 778)


NEW QUESTION # 765
The DES algorithm is an example of what type of cryptography?

  • A. Secret Key
  • B. Public Key
  • C. Two-key
  • D. Asymmetric Key

Answer: A

Explanation:
DES is also known as a Symmetric Key or Secret Key algorithm.
DES is a Symmetric Key algorithm, meaning the same key is used for encryption and
decryption.
For the exam remember that:
DES key Sequence is 8 Bytes or 64 bits (8 x 8 = 64 bits)
DES has an Effective key length of only 56 Bits. 8 of the Bits are used for parity purpose
only.
DES has a total key length of 64 Bits.
The following answers are incorrect:
Two-key This is incorrect because DES uses the same key for encryption and decryption.
Asymmetric Key This is incorrect because DES is a Symmetric Key algorithm using the
same key for encryption and decryption and an Asymmetric Key algorithm uses both a
Public Key and a Private Key.
Public Key. This is incorrect because Public Key or algorithm Asymmetric Key does not use
the same key is used for encryption and decryption.
References used for this question: http://en.wikipedia.org/wiki/Data_Encryption_Standard


NEW QUESTION # 766
What is defined as inference of information from other, intermediate, relevant facts?

  • A. Conclusive evidence
  • B. Secondary evidence
  • C. Circumstantial evidence
  • D. Hearsay evidence

Answer: C

Explanation:
Explanation/Reference:
Circumstantial evidence is defined as inference of information from other, intermediate, relevant facts.
Secondary evidence is a copy of evidence or oral description of its contents. Conclusive evidence is incontrovertible and overrides all other evidence and hearsay evidence is evidence that is not based on personal, first-hand knowledge of the witness, but was obtained from another source. Computer-generated records normally fall under the category of hearsay evidence.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 9: Law, Investigation, and Ethics (page 310).


NEW QUESTION # 767
A deviation from an organization-wide security policy requires which of the following?

  • A. Risk Containment
  • B. Risk Acceptance
  • C. Risk Reduction
  • D. Risk Assignment

Answer: B

Explanation:
A deviation from an organization-wide security policy requires you to manage the risk. If you deviate from the security policy then you are required to accept the risks that might occur.
In some cases, it may be prudent for an organization to simply accept the risk that is presented in certain scenarios. Risk acceptance is the practice of accepting certain risk(s), typically based on a business decision that may also weigh the cost versus the benefit of dealing with the risk in another way.
The OIG defines Risk Management as: This term characterizes the overall process.
The first phase of risk assessment includes identifying risks, risk-reducing measures, and the budgetary impact of implementing decisions related to the acceptance, avoidance, or transfer of risk.
The second phase of risk management includes the process of assigning priority to, budgeting, implementing, and maintaining appropriate risk-reducing measures.
Risk management is a continuous process of ever-increasing complexity. It is how we evaluate the impact of exposures and respond to them. Risk management minimizes loss to information assets due to undesirable events through identification, measurement, and control. It encompasses the overall security review, risk analysis, selection and evaluation of safeguards, cost-benefit analysis, management decision, and safeguard identification and implementation, along with ongoing effectiveness review.
Risk management provides a mechanism to the organization to ensure that executive management knows current risks, and informed decisions can be made to use one of the risk management principles: risk avoidance, risk transfer, risk mitigation, or risk acceptance.
The 4 ways of dealing with risks are: Avoidance, Transfer, Mitigation, Acceptance The following answers are incorrect:
Risk assignment. Is incorrect because it is a distractor, assignment is not one of the ways to manage risk.
Risk reduction. Is incorrect because there was a deviation of the security policy. You could have some additional exposure by the fact that you deviated from the policy.
Risk containment. Is incorrect because it is a distractor, containment is not one of the ways to manage risk.


NEW QUESTION # 768
In addition to the Legal Department, with what company function must the collection of physical evidence be coordinated if an employee is suspected?

  • A. External Audit Group
  • B. Human Resources
  • C. Industrial Security
  • D. Public Relations

Answer: B

Explanation:
If an employee is suspected of causing an incident, the human resources department may be involved--for example, in assisting with disciplinary proceedings.
Legal Department. The legal experts should review incident response plans, policies, and procedures to ensure their compliance with law and Federal guidance, including the right to privacy. In addition, the guidance of the general counsel or legal department should be sought if there is reason to believe that an incident may have legal ramifications, including evidence collection, prosecution of a suspect, or a lawsuit, or if there may be a need for a memorandum of understanding (MOU) or other binding agreements involving liability limitations for information sharing.
Public Affairs, Public Relations, and Media Relations. Depending on the nature and impact of an incident, a need may exist to inform the media and, by extension, the public.
The Incident response team members could include:
Management
Information Security
Legal / Human Resources
Public Relations
Communications
Physical Security
Network Security
Network and System Administrators
Network and System Security Administrators
Internal Audit
Events versus Incidents
An event is any observable occurrence in a system or network. Events include a user connecting to a file share, a server receiving a request for a web page, a user sending email, and a firewall blocking a connection attempt. Adverse events are events with a negative consequence, such as system crashes, packet floods, unauthorized use of system privileges, unauthorized access to sensitive data, and execution of malware that destroys data. This guide addresses only adverse events that are computer security- related, not those caused by natural disasters, power failures, etc.
A computer security incident is a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.
Examples of incidents are:
An attacker commands a botnet to send high volumes of connection requests to a web server, causing it to crash.
Users are tricked into opening a "quarterly report" sent via email that is actually malware; running the tool has infected their computers and established connections with an external host.
An attacker obtains sensitive data and threatens that the details will be released publicly if the organization does not pay a designated sum of money.
A user provides or exposes sensitive information to others through peer-to-peer file sharing services.
The following answers are incorrect:
Industrial Security. Is incorrect because it is not the best answer, the human resource department must be involved with the collection of physical evidence if an employee is suspected.
public relations. Is incorrect because it is not the best answer. It would be an important element to minimize public image damage but not the best choice for this question.
External Audit Group. Is incorrect because it is not the best answer, the human resource department must be involved with the collection of physical evidence if an employee is suspected.


NEW QUESTION # 769
Which of the following backup method must be made regardless of whether Differential or Incremental methods are used?

  • A. Tape backup method.
  • B. Full Backup Method.
  • C. Supplemental backup method.
  • D. Incremental backup method.

Answer: B

Explanation:
A Full Backup must be made regardless of whether Differential or Incremental methods are used.


NEW QUESTION # 770
What Orange Book security rating is reserved for systems that have been evaluated but fail to meet the criteria and requirements of the higher divisions?

  • A. F
  • B. A
  • C. D
  • D. E

Answer: C

Explanation:
D or "minimal protection" is reserved for systems that were evaluated under the TCSEC but did not meet the requirements for a higher trust level.
A is incorrect. A or "Verified Protectection" is the highest trust level under the TCSEC. E is incorrect. The trust levels are A - D so "E" is not a valid trust level.
F is incorrect. The trust levels are A - D so "F" is not a valid trust level.
CBK, pp. 329 - 330 AIO3, pp. 302 - 306


NEW QUESTION # 771
What is also known as 10Base5?

  • A. UTP
  • B. Thinnet
  • C. Thicknet
  • D. ARCnet

Answer: C

Explanation:
Section: Network and Telecommunications
Explanation/Reference:
Thicknet is a coaxial cable with segments of up to 500 meters, also known as 10Base5. Thinnet is a coaxial cable with segments of up to 185 meters. Unshielded twisted pair (UTP) has three variations: 10 Mbps (10BaseT), 100 Mbps (100BaseT) or 1 Gbps (1000BaseT). ARCnet is a LAN media access method.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page
108).


NEW QUESTION # 772
The MOST common threat that impacts a business's ability to function normally is:

  • A. Water Damage
  • B. Severe Weather
  • C. Power Outage
  • D. Labor Strike

Answer: C

Explanation:
The MOST common threat that impacts a business's ability to function
normally is power. Power interruption cause more business interruption than any other type
of event.
The second most common threat is Water such as flood, water damage from broken pipe,
leaky roof, etc...
Threats will be discovered while doing your Threats and Risk Assessments (TRA).
There are three elements of risks: threats, assets, and mitigating factors (countermeasures,
safeguards, controls).
A threat is an event or situation that if it occured would affect your business and may even
prevent it from functioning normally or in some case functioning at all. Evaluation of threats
is done by looking at Likelihood and Impact of possible threat. Safeguards,
countermeasures, and controls would be used to bring the threat level down to an
acceptable level.
Other common events that can impact a company are:
Weather, cable cuts, fires, labor disputes, transportation mishaps, hardware failure,
chemical spills, sabotage.
References:
The Official ISC2 Guide to the CISSP CBK, Second Edition, Page 275-276


NEW QUESTION # 773
Which of the following computer crime is MORE often associated with INSIDERS?

  • A. Password sniffing
  • B. IP spoofing
  • C. Denial of service (DOS)
  • D. Data diddling

Answer: D

Explanation:
Explanation/Reference:
It refers to the alteration of the existing data , most often seen before it is entered into an application.This type of crime is extremely common and can be prevented by using appropriate access controls and proper segregation of duties. It will more likely be perpetrated by insiders, who have access to data before it is processed.
The other answers are incorrect because :
IP Spoofing is not correct as the questions asks about the crime associated with the insiders. Spoofing is generally accomplished from the outside.
Password sniffing is also not the BEST answer as it requires a lot of technical knowledge in understanding the encryption and decryption process.
Denial of service (DOS) is also incorrect as most Denial of service attacks occur over the internet.
Reference : Shon Harris , AIO v3 , Chapter-10 : Law , Investigation & Ethics , Page : 758-760.


NEW QUESTION # 774
Which of the following protects a password from eavesdroppers and supports the encryption of communication?

  • A. Challenge Handshake Encryption Protocol (CHEP)
  • B. Challenge Handshake Authentication Protocol (CHAP)
  • C. Challenge Handshake Identification Protocol (CHIP)
  • D. Challenge Handshake Substitution Protocol (CHSP)

Answer: B

Explanation:
Explanation/Reference:
CHAP: A protocol that uses a three way hanbdshake The server sends the client a challenge which includes a random value(a nonce) to thwart replay attacks. The client responds with the MD5 hash of the nonce and the password.
The authentication is successful if the client's response is the one that the server expected.
Reference: Page 450, OIG 2007.
CHAP protects the password from eavesdroppers and supports the encryption of communication.
Reference: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 44.


NEW QUESTION # 775
Which Network Address Translation (NAT) is the most convenient and secure solution?

  • A. Hiding Network Address Translation
  • B. Dedicated Address Translation
  • C. Static Address Translation
  • D. Port Address Translation

Answer: D

Explanation:
Explanation/Reference:
Static network address translation offers the most flexibility, but it is not normally practical given the shortage of IP version 4 addresses. Hiding network address translation is was an interim step in the development of network address translation technology, and is seldom used because port address translation offers additional features above and beyond those present in hiding network address translation while maintaining the same basic design and engineering considerations. PAT is often the most convenient and secure solution.
Source: WACK, John et al., NIST Special publication 800-41, Guidelines on Firewalls and Firewall Policy, January 2002 (page 18).


NEW QUESTION # 776
It is a violation of the "separation of duties" principle when which of the following individuals access the software on systems implementing security?

  • A. systems programmer
  • B. systems auditor
  • C. security analyst
  • D. security administrator

Answer: A

Explanation:
Reason: The security administrator, security analysis, and the system auditor need access to portions of the security systems to accomplish their jobs. The system programmer does not need access to the working (AKA: Production) security systems.
Programmers should not be allowed to have ongoing direct access to computers running production systems (systems used by the organization to operate its business). To maintain system integrity, any changes they make to production systems should be tracked by the organization's change management control system.
Because the security administrator's job is to perform security functions, the performance of non- security tasks must be strictly limited. This separation of duties reduces the likelihood of loss that results from users abusing their authority by taking actions outside of their assigned functional responsibilities.


NEW QUESTION # 777
What is a limitation of TCP Wrappers?

  • A. It cannot control access to running UDP services.
  • B. The hosts. access control system requires a complicated directory tree.
  • C. They are too expensive.
  • D. It stops packets before they reach the application layer, thus confusing some proxy servers.

Answer: A

Explanation:
TCP Wrappers can control when a UDP server starts but has little control afterwards because UDP packets can be sent randomly.
The following answers are incorrect:
It stops packets before they reach the application layer, thus confusing some proxy servers. Is incorrect because the TCP Wrapper acts as an ACL restricting packets so would not confuse a proxy server because the packets would not arrive and would not be a limitation.
The hosts. access control system requires a complicated directory tree. Is incorrect because a simple directory tree is involved.
They are too expensive. Is incorrect because TCP Wrapper is considered open source with a BSD licensing scheme.


NEW QUESTION # 778
......

Use ISC SSCP Dumps To Succeed Instantly in SSCP Exam: https://www.itexamreview.com/SSCP-exam-dumps.html

Ultimate Guide to SSCP Dumps - Enhance Your Future Career Now: https://drive.google.com/open?id=1r_no5zv5FpeUzObqvNVHCH9lA8F_J52J