SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
SSCP: Systems Security Certified Practitioner
Start Test
Study First
Subjects
:
certifications
,
sscp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. EDI (Electronic Data Interchange) differs from e- Commerce in that it ___________________.
Verisign - Microsoft - Dell
involves only computer to computer transactions
Host based - network based
Acceptance - Transfer - Mitigate
2. ____________ is a file system that was poorly designed and has numerous security flaws.
product development life cycle
Separation of Duties
NFS
Personal Firewall - IDS - host based - Antivirus
3. There are 6 types of security control practices. ___________ controls are management policies - procedures - and guidelines that usually effect the entire system. These types of controls deal with system auditing and usability.
Virus definition downloads and system virus scans
Steps in handling incidents
Log files
Directive
4. There are 5 classes of IP addresses available - but only 3 classes are in common use today
Ethernet
All
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Privacy violations
5. Although it is considered a low tech attack ____________ is still a very effective way of gaining unauthorized access to network systems.
Available service ports
Granularity
Logic bombs
Social Engineering
6. Allows File owners to determine access rights.
Separation of Duties
Authorization
Assignment
Decentralized access control
7. _________ is a form of Denial of Service attack which interrupts the TCP three way handshake and leaves half open connections.
SET
SYN Flooding
Passfilt.dll
Biometrics
8. Used in ______________:Retinal Scanning - Fingerprints - Face Recognition - Voice Recognition
Virus definition downloads and system virus scans
CHAP
A PGP Signed message
Biometrics
9. Which of the concepts best describes Availability in relation to computer resources?
Hackers and crackers
RSA
Users can gain access to any resource upon request (assuming they have proper permissions)
product development life cycle
10. A type of virus that resides in a Word or Excel document is called a ___________ virus?
Macro
Passwords
Layer 7 - Application
Sniffer
11. Identifying specific attempts to penetrate systems is the function of the _______________.
involves only computer to computer transactions
Privacy violations
TIGER
Intrusion Detection System
12. Is the person who is attempting to log on really who they say they are? What form of access control does this questions stem from?
Authentication
Intentions of the perpetrator
modems
Phreaks
13. Companies can now be __________ just as easily as they can be sued for security compromises.
Polymorphic
Sued for privacy violations
ISO
Social Engineering
14. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.
Man In The Middle
SET
Sued for privacy violations
Buffer Overflow
15. __________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.
Buffer Overflow
Separation of Duties
Steps in handling incidents
PGP
16. Stealth viruses live in memory while __________ are written to disk
TIGER
Logic bombs
Residual risk
Off site in a climate controlled area
17. A formula used in Quantitative risk analysis
Gathering digital evidence
Off site in a climate controlled area
Cisco
SLE - Single Loss Expectancy
18. Organizations that can be a valid Certificate Authority (CA)
SET
Assignment
Wild
Verisign - Microsoft - Dell
19. A one way hash converts a string of random length into a _______________ encrypted string.
Logic bombs
Fixed length
Business enabler
Acceptance - Transfer - Mitigate
20. This free (for personal use) program is used to encrypt and decrypt emails.
CRACK
PGP
TIGER
Not rigid
21. Unlike like viruses and worm - __________ are bogus messages that spread via email forwarding.
Warning Banner
NFS
Data Classification
Hoaxes
22. Data being delivered from the source to the intended receiver without being altered
Cryptanalysis
Protection of data from unauthorized users
a good password policy
Stealth viruses
23. This is more time consuming - numeric values - based on Annualized Loss Expectancy (ALE) formulas
Data Hiding
Decentralized access control
Quantitative analysis
Email
24. Cable modems are ___________than DSL connections
Risk assessment
To make user certificates available to others
Less secure
Authorization
25. A security policy is a ___________ set of rules that must be followed explicitly in order to be effective.
Not rigid
Buffer Overflow
Sued for privacy violations
Presentation Layer - L6
26. The __________ is the most dangerous part of a virus program.
Payload
a good password policy
Sued for privacy violations
PGP
27. There are 65536 _________
SSL
Symmetric algorithm
Verisign - Microsoft - Dell
Available service ports
28. Today - ______________ are almost as serious as security violations
Privacy violations
run applications as generic accounts with little or no privileges.
IANA
Logic bombs
29. They specifically target telephone networks
Unix / Linux based security tools?
Phreaks
Warning banners
S/Key - OPIE
30. Remote Access Dial-in User Service
A PGP Signed message
RADIUS
Decentralized access control
SET
31. Consists of checking for Minimum password length - Password aging - Password Strength - Blank Passwords?
Less secure
Password audit
Personal Firewall - IDS - host based - Antivirus
Also
32. Countermeasures' main objectives
Environmental
Prevent - Recover - Detect
SLE - Single Loss Expectancy
Passive network attack
33. MD5 is a ___________ algorithm
Test virus
RSA
One way hash
modems
34. Vulnerability x Threat = RISK is an example of the _______________.
Data Hiding
TIGER
Risk Equation
Preserve electronic evidence and protect it from any alteration
35. What security principle is based on the division of job responsibilities - designed to prevent fraud?
PGP
Configuration Control
TIGER
Separation of Duties
36. S/MIME was developed for the protection of what communication mechanism(s)?
Off site in a climate controlled area
Cryptanalysis
Email
Macro
37. __________________ will have weird characters printed at the beginning or end of an email message - what would it be anindication of?
IPSEC
Accountability
A PGP Signed message
CRACK
38. ______________ relates to the concept of protecting data from unauthorized users.
CVE - Common Vulnerabilities and Exposures
Decentralized access control
Confidentiality
Buffer Overflow
39. An attempt to break an encryption algorithm is called _____________.
run applications as generic accounts with little or no privileges.
involves only computer to computer transactions
Cryptanalysis
NFS
40. These should be done on a weekly basis
Salami attack
Virus definition downloads and system virus scans
Fixed length
modems
41. A true network security audit does include an audit for _____________
Confidentiality
modems
Data Hiding
Personal Firewall - IDS - host based - Antivirus
42. The ultimate goal of a computer forensics specialist is to ___________________.
Preserve electronic evidence and protect it from any alteration
Authentication
Configuration Control
SSL
43. PGP & PEM are programs that allow users to send encrypted messages to each other. What form of encryption do these programs use?
One way hash
RSA
Log files
A PGP Signed message
44. ______________ is a major component of an overall risk management program.
Steps in handling incidents
Stealth viruses
Password audit
Risk assessment
45. _______________ supply AV engines with false information to avoid detection
involves only computer to computer transactions
To make user certificates available to others
Logic bombs
Stealth viruses
46. ____ members of the staff need to be educated in disaster recovery procedures.
Host based - network based
Environmental
PGP
All
47. ___________________ is responsible for creating security policies and for communicating those policies to system users.
One way hash
ISO
Buffer Overflow
Layer 3 - Host to Host
48. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______
Passfilt.dll
Hoaxes
Acceptance - Transfer - Mitigate
SLE - Single Loss Expectancy
49. ______________ is a Unix security scanning tool developed at Texas A&M university.
TIGER
Sniffer
One way hash
Information Security policies
50. An intrusion detection system is an example of what type of countermeasure?
Warning banners
Detective
Decentralized access control
Symmetric algorithm