
[Feb-2023] Free SSCP Exam Dumps to Improve Exam Score
2023 Realistic SSCP Dumps Exam Tips Test Pdf Exam Material
Duration of Time
The total availability of time for the exam SSCP is 03 Hours. At this time candidates have to attempt all the given questions.
Introduction to ISC SSCP Certification Exam
ISC is the largest, most-respected certification in information security. ISC SSCP provides a single, globally trusted credential and integrity for professionals to demonstrate their competency in network security.
ISC has been a trusted security company for over four decades, making them a highly valued player in the cybersecurity market. In order to continue this perfection and increase market share, ISC has passed a new certification exam known as the ISC SSCP. This exam is an examination of an individual ability to perform certain security tasks in accordance with industry best practices and international standards. You may have enough skill and knowledge to take the exam, but you must have to polish them to pass the exam. ISC SSCP Dumps will help you to do it.
The purpose of the examination is to assess skills that will aid in securing information systems from external threats such as intrusion and interception activities. Passwords need to be strong enough so that people can not easily guess them; firewalls should be configured on all servers, including virtual ones; and users should always log off their computers when they are done using any system.
This qualifying exam covers seven domains with varying weights. The details of these subject areas are highlighted below:
Access Controls (16%):
- Supporting the Internetwork Trust Architecture – This one is about extranet, trust relationships, and third-party connections;
- Implementing Access Control – Here, you are required to understand mandatory, discretionary, subject-based, attribute-based, object-based, and non-discretionary.
- Implementing & Maintaining Authentication Techniques – This area covers federated access, single sign-on, single/multi-factor authentication, and device authentication;
- Participating in the Lifecycle of Identity Management – The potential candidates should understand the concepts, such as authorization, maintenance, proofing, entitlement, provisioning/de-provisioning, as well as Identity & Access Management systems;
NEW QUESTION 266
Which of the following statements pertaining to packet filtering is incorrect?
- A. It is not application dependant.
- B. It keeps track of the state of a connection.
- C. It operates at the network layer.
- D. It is based on ACLs.
Answer: B
Explanation:
Packet filtering is used in the first generation of firewalls and does not keep
track of the state of a connection. Stateful packet filtering does.
Source: WALLHOFF, John, CISSP Summary 2002, April 2002, CBK#2
Telecommunications and Network Security (page 6)
NEW QUESTION 267
Which of the following is NOT a characteristic or shortcoming of packet filtering gateways?
- A. They are appropriate for medium-risk environment.
- B. They don't protect against IP or DNS address spoofing.
- C. They do not support strong user authentication.
- D. The source and destination addresses, protocols, and ports contained in the IP packet header are the only information that is available to the router in making a decision whether or not to permit traffic access to an internal network.
Answer: A
Explanation:
Section: Network and Telecommunications
Explanation/Reference:
Packet filtering firewalls use routers with packet filtering rules to grant or deny access based on source address, destination address, and port.
They offer minimum security but at a very low cost, and can be an appropriate choice for a low-risk environment.
Source: TIPTON, Harold F. & KRAUSE, Micki, Information Security Management Handbook, 4th edition (volume 1), 2000, CRC Press, Chapter 3, Secured Connections to External Networks (page 60).
NEW QUESTION 268
Which of the following statements pertaining to software testing approaches is correct?
- A. The test plan and results should be retained as part of the system's permanent documentation.
- B. A bottom-up approach allows interface errors to be detected earlier.
- C. Black box testing is predicated on a close examination of procedural detail.
- D. A top-down approach allows errors in critical modules to be detected earlier.
Answer: A
Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
A bottom-up approach to testing begins testing of atomic units, such as programs or modules, and works upwards until a complete system testing has taken place. It allows errors in critical modules to be found early.
A top-down approach allows for early detection of interface errors and raises confidence in the system, as programmers and users actually see a working system. White box testing is predicated on a close examination of procedural detail. Black box testing examines some aspect of the system with little regard for the internal logical structure of the software.
Source: Information Systems Audit and Control Association, Certified Information Systems Auditor 2002 review manual, Chapter 6: Business Application System Development, Acquisition, Implementation and Maintenance (page 300).
Top Down Testing: An approach to integration testing where the component at the top of the component hierarchy is tested first, with lower level components being simulated by stubs. Tested components are then used to test lower level components. The process is repeated until the lowest level components have been tested.
Bottom Up Testing: An approach to integration testing where the lowest level components are tested first, then used to facilitate the testing of higher level components. The process is repeated until the component at the top of the hierarchy is tested.
Black Box Testing: Testing based on an analysis of the specification of a piece of software without reference to its internal workings. The goal is to test how well the component conforms to the published requirements for the component.
NEW QUESTION 269
When attempting to establish Liability, which of the following would be describe as performing the ongoing maintenance necessary to keep something in proper working order, updated, effective, or to abide by what is commonly expected in a situation?
- A. Due diligence
- B. Due care
- C. Due concern
- D. Due practice
Answer: B
Explanation:
Explanation/Reference:
My friend JD Murray at Techexams.net has a nice definition of both, see his explanation below:
Oh, I hate these two. It's like describing the difference between "jealously" and "envy." Kinda the same thing but not exactly. Here it goes:
Due diligence is performing reasonable examination and research before committing to a course of action.
Basically, "look before you leap." In law, you would perform due diligence by researching the terms of a contract before signing it. The opposite of due diligence might be "haphazard" or "not doing your homework."
Due care is performing the ongoing maintenance necessary to keep something in proper working order, or to abide by what is commonly expected in a situation. This is especially important if the due care situation exists because of a contract, regulation, or law. The opposite of due care is "negligence." In summary, Due Diligence is Identifying threats and risks while Due Care is Acting upon findings to mitigate risks
EXAM TIP:
The Due Diligence refers to the steps taken to identify risks that exists within the environment. This is base on best practices, standards such as ISO 27001, ISO 17799, and other consensus. The first letter of the word Due and the word Diligence should remind you of this. The two letters are DD = Do Detect.
In the case of due care, it is the actions that you have taken (implementing, designing, enforcing, updating) to reduce the risks identified and keep them at an acceptable level. The same apply here, the first letters of the work Due and the work Care are DC. Which should remind you that DC = Do correct.
The other answers are only detractors and not valid.
Reference(s) used for this question:
CISSP Study Guide, Syngress, By Eric Conrad, Page 419
HARRIS, Shon, All-In-One CISSP Certification Exam Guide Fifth Edition, McGraw-Hill, Page 49 and 110.
and
Corporate; (Isc)² (2010-04-20). Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press) (Kindle Locations 11494-11504). Taylor & Francis. Kindle Edition.
and
My friend JD Murray at Techexams.net
NEW QUESTION 270
What is called the access protection system that limits connections by calling back the number of a previously authorized location?
- A. Sendback systems
- B. Callback systems
- C. Callback forward systems
- D. Sendback forward systems
Answer: B
Explanation:
Call back Systems; Callback systems provide access protection by calling back the number of a previously authorized location, but this control can be compromised by call forwarding. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 35.
NEW QUESTION 271
Which of the following ASYMMETRIC encryption algorithms is based on the difficulty of FACTORING LARGE NUMBERS?
- A. El Gamal
- B. International Data Encryption Algorithm (IDEA)
- C. RSA
- D. Elliptic Curve Cryptosystems (ECCs)
Answer: C
Explanation:
Named after its inventors Ron Rivest , Adi Shamir and Leonard Adleman is based on the difficulty of factoring large prime numbers.
Factoring a number means representing it as the product of prime numbers. Prime numbers, such as 2, 3, 5, 7, 11, and 13, are those numbers that are not evenly divisible by any smaller number, except 1. A non-prime, or composite number, can be written as the product of smaller primes, known as its prime factors. 665, for example is the product of the primes 5, 7, and 19. A number is said to be factored when all of its prime factors are identified. As the size of the number increases, the difficulty of factoring increases rapidly.
The other answers are incorrect because:
El Gamal is based on the discrete logarithms in a finite field.
Elliptic Curve Cryptosystems (ECCs) computes discrete logarithms of elliptic curves.
International Data Encryption Algorithm (IDEA) is a block cipher and operates on 64 bit
blocks of data and is a SYMMETRIC algorithm.
Reference : Shon Harris , AIO v3 , Chapter-8 : Cryptography , Page : 638
NEW QUESTION 272
Which of the following is an issue with signature-based intrusion detection systems?
- A. Hackers can circumvent signature evaluations.
- B. It runs only on the windows operating system
- C. Signature databases must be augmented with inferential elements.
- D. Only previously identified attack signatures are detected.
Answer: D
Explanation:
Explanation/Reference:
An issue with signature-based ID is that only attack signatures that are stored in their database are detected.
New attacks without a signature would not be reported. They do require constant updates in order to maintain their effectiveness.
Reference used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 49.
NEW QUESTION 273
Which of the following is NOT a compensating measure for access violations?
- A. Security awareness
- B. Business continuity planning
- C. Backups
- D. Insurance
Answer: A
Explanation:
Section: Access Control
Explanation/Reference:
Security awareness is a preventive measure, not a compensating measure for access violations.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems (page 50).
NEW QUESTION 274
_________ is the act of a user professing an identity to a system.
- A. Authentication
- B. Identification
- C. Validation
- D. Confirmation
Answer: B
Explanation:
Identification is used to establish user accountability. Many times identification takes the form of a logon ID.
NEW QUESTION 275
Integrity = ______________
- A. Data being delivered from the source to the intended receiver without being altered
- B. Ability to access data when requested
- C. Protection of data from unauthorized users
- D. All answers are correct
- E. Data being kept correct and current
Answer: A
NEW QUESTION 276
The MOST common threat that impacts a business's ability to function normally is:
- A. Power Outage
- B. Water Damage
- C. Severe Weather
- D. Labor Strike
Answer: A
Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
The MOST common threat that impacts a business's ability to function normally is power. Power interruption cause more business interruption than any other type of event.
The second most common threat is Water such as flood, water damage from broken pipe, leaky roof, etc...
Threats will be discovered while doing your Threats and Risk Assessments (TRA).
There are three elements of risks: threats, assets, and mitigating factors (countermeasures, safeguards, controls).
A threat is an event or situation that if it occured would affect your business and may even prevent it from functioning normally or in some case functioning at all. Evaluation of threats is done by looking at Likelihood and Impact of possible threat. Safeguards, countermeasures, and controls would be used to bring the threat level down to an acceptable level.
Other common events that can impact a company are:
Weather, cable cuts, fires, labor disputes, transportation mishaps, hardware failure, chemical spills, sabotage.
References:
The Official ISC2 Guide to the CISSP CBK, Second Edition, Page 275-276
NEW QUESTION 277
Kerberos can prevent which one of the following attacks?
- A. playback (replay) attack.
- B. destructive attack.
- C. process attack.
- D. tunneling attack.
Answer: A
Explanation:
Each ticket in Kerberos has a timestamp and are subject to time expiration to help prevent these types of attacks.
The following answers are incorrect:
tunneling attack. This is incorrect because a tunneling attack is an attempt to bypass security and access low-level systems. Kerberos cannot totally prevent these types of attacks.
destructive attack. This is incorrect because depending on the type of destructive attack, Kerberos cannot prevent someone from physically destroying a server.
process attack. This is incorrect because with Kerberos cannot prevent an authorzied individuals from running processes.
NEW QUESTION 278
The IP header contains a protocol field. If this field contains the value of 51, what type of data is contained within the ip datagram?
- A. Authentication Header (AH)
- B. User datagram protocol (UDP)
- C. Transmission Control Protocol (TCP)
- D. Internet Control Message Protocol (ICMP)
Answer: A
Explanation:
Explanation/Reference:
TCP has the value of 6
UDP has the value of 17
ICMP has the value of 1
Reference:
SANS http://www.sans.org/resources/tcpip.pdf?ref=3871
NEW QUESTION 279
What is the maximum number of different keys that can be used when encrypting with Triple DES?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Section: Cryptography
Explanation/Reference:
Triple DES encrypts a message three times. This encryption can be accomplished in several ways. The most secure form of triple DES is when the three encryptions are performed with three different keys.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 4: Cryptography (page 152).
NEW QUESTION 280
What assesses potential loss that could be caused by a disaster?
- A. The Risk Assessment (RA)
- B. The Business Impact Analysis (BIA)
- C. The Business Assessment (BA)
- D. The Business Continuity Plan (BCP)
Answer: B
Explanation:
The Business Assessment is divided into two components. Risk Assessment (RA) and Business Impact Analysis (BIA). Risk Assessment is designed to evaluate existing exposures from the organization's environment, whereas the BIA assesses potential loss that could be caused by a disaster. The Business Continuity Plan's goal is to reduce the risk of financial loss by improving the ability to recover and restore operations efficiently and effectively.
Source: BARNES, James C. & ROTHSTEIN, Philip J., A Guide to Business Continuity Planning, John Wiley & Sons, 2001 (page 57). And: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 8: Business Continuity Planning and Disaster Recovery Planning (page 276).
NEW QUESTION 281
Attributes that characterize an attack are stored for reference using which of the following Intrusion Detection System (IDS) ?
- A. event-based IDS
- B. statistical anomaly-based IDS
- C. inferent-based IDS
- D. signature-based IDS
Answer: D
Explanation:
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 49.
NEW QUESTION 282
Volatile memory is referred to as ROM.
- A. Yes
- B. No
Answer: B
Explanation:
Volatile memory is Random Access Memory (RAM)
NEW QUESTION 283
What is NOT true about a one-way hashing function?
- A. It provides integrity of the message
- B. The results of a one-way hash is a message digest
- C. A hash cannot be reverse to get the message used to create the hash
- D. It provides authentication of the message
Answer: D
Explanation:
A one way hashing function can only be use for the integrity of a message and not for authentication or confidentiality. Because the hash creates just a fingerprint of the message which cannot be reversed and it is also very difficult to create a second message with the same hash.
A hash by itself does not provide Authentication. It only provides a weak form or integrity. It would be possible for an attacker to perform a Man-In-The-Middle attack where both the hash and the digest could be changed without the receiver knowing it.
A hash combined with your session key will produce a Message Authentication Code (MAC) which will provide you with both authentication of the source and integrity. It is sometimes referred to as a Keyed Hash. A hash encrypted with the sender private key produce a Digital Signature which provide authentication, but not the hash by itself. Hashing functions by themselves such as MD5, SHA1, SHA2, SHA-3 does not provide authentication.
Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2001, Page 548
NEW QUESTION 284
Which of the following is less likely to accompany a contingency plan, either within the plan itself or in the form of an appendix?
- A. The Business Impact Analysis.
- B. Equipment and system requirements lists of the hardware, software, firmware and other resources required to support system operations.
- C. Contact information for all personnel.
- D. Vendor contact information, including offsite storage and alternate site.
Answer: C
Explanation:
Why is this the correct answer? Simply because it is WRONG, you would have contact information for your emergency personnel within the plan but NOT for ALL of your personnel. Be careful of words such as ALL. According to NIST's Special publication 800-34, contingency plan appendices provide key details not contained in the main body of the plan. The appendices should reflect the specific technical, operational, and management contingency requirements of the given system. Contact information for recovery team personnel (not all personnel) and for vendor should be included, as well as detailed system requirements to allow for supporting of system operations. The Business Impact Analysis (BIA) should also be included as an appendix for reference should the plan be activated.
Reference(s) used for this question: SWANSON, Marianne, & al., National Institute of Standards and Technology (NIST), NIST Special Publication 800-34, Contingency Planning Guide for Information Technology Systems
NEW QUESTION 285
L2TP is considered to be a less secure protocol than PPTP.
- A. True
- B. False
Answer: B
NEW QUESTION 286
What are the three components of the AIC triad? (Choose three)
- A. Intelligence
- B. Accountability
- C. Availability
- D. Confidentiality
- E. Confinement
- F. Integrity
Answer: C,D,F
Explanation:
The AIC triad is: availability, integrity, and confidentiality. This is a key concept of security.
NEW QUESTION 287
......
Powerful SSCP PDF Dumps for SSCP Questions: https://www.pass4sures.top/ISCCertification/SSCP-testking-braindumps.html
Authentic SSCP Dumps - Free PDF Questions to Pass: https://drive.google.com/open?id=1ybUQ5Heo2PEITJOwtiR5nVlcj8B01Tct