Test your basic knowledge |

SSCP: Systems Security Certified Practitioner

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. EDI (Electronic Data Interchange) differs from e- Commerce in that it ___________________.






2. ____________ is a file system that was poorly designed and has numerous security flaws.






3. There are 6 types of security control practices. ___________ controls are management policies - procedures - and guidelines that usually effect the entire system. These types of controls deal with system auditing and usability.






4. There are 5 classes of IP addresses available - but only 3 classes are in common use today






5. Although it is considered a low tech attack ____________ is still a very effective way of gaining unauthorized access to network systems.






6. Allows File owners to determine access rights.






7. _________ is a form of Denial of Service attack which interrupts the TCP three way handshake and leaves half open connections.






8. Used in ______________:Retinal Scanning - Fingerprints - Face Recognition - Voice Recognition






9. Which of the concepts best describes Availability in relation to computer resources?






10. A type of virus that resides in a Word or Excel document is called a ___________ virus?






11. Identifying specific attempts to penetrate systems is the function of the _______________.






12. Is the person who is attempting to log on really who they say they are? What form of access control does this questions stem from?






13. Companies can now be __________ just as easily as they can be sued for security compromises.






14. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.






15. __________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.






16. Stealth viruses live in memory while __________ are written to disk






17. A formula used in Quantitative risk analysis






18. Organizations that can be a valid Certificate Authority (CA)






19. A one way hash converts a string of random length into a _______________ encrypted string.






20. This free (for personal use) program is used to encrypt and decrypt emails.






21. Unlike like viruses and worm - __________ are bogus messages that spread via email forwarding.






22. Data being delivered from the source to the intended receiver without being altered






23. This is more time consuming - numeric values - based on Annualized Loss Expectancy (ALE) formulas






24. Cable modems are ___________than DSL connections






25. A security policy is a ___________ set of rules that must be followed explicitly in order to be effective.






26. The __________ is the most dangerous part of a virus program.






27. There are 65536 _________






28. Today - ______________ are almost as serious as security violations






29. They specifically target telephone networks






30. Remote Access Dial-in User Service






31. Consists of checking for Minimum password length - Password aging - Password Strength - Blank Passwords?






32. Countermeasures' main objectives






33. MD5 is a ___________ algorithm






34. Vulnerability x Threat = RISK is an example of the _______________.






35. What security principle is based on the division of job responsibilities - designed to prevent fraud?






36. S/MIME was developed for the protection of what communication mechanism(s)?






37. __________________ will have weird characters printed at the beginning or end of an email message - what would it be anindication of?






38. ______________ relates to the concept of protecting data from unauthorized users.






39. An attempt to break an encryption algorithm is called _____________.






40. These should be done on a weekly basis






41. A true network security audit does include an audit for _____________






42. The ultimate goal of a computer forensics specialist is to ___________________.






43. PGP & PEM are programs that allow users to send encrypted messages to each other. What form of encryption do these programs use?






44. ______________ is a major component of an overall risk management program.






45. _______________ supply AV engines with false information to avoid detection






46. ____ members of the staff need to be educated in disaster recovery procedures.






47. ___________________ is responsible for creating security policies and for communicating those policies to system users.






48. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______






49. ______________ is a Unix security scanning tool developed at Texas A&M university.






50. An intrusion detection system is an example of what type of countermeasure?