SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
SSCP: Systems Security Certified Practitioner
Start Test
Study First
Subjects
:
certifications
,
sscp
,
it-skills
Instructions:
Answer
50
questions in
15 minutes
.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A one way hash converts a string of random length into a _______________ encrypted string.
Privacy violations
Fixed length
Mobile
Wild
2. Which auditing practice relates to the controlling of hardware - software - firmware - and documentation to insure it has not been improperly modified?
product development life cycle
RSA
Privacy violations
Configuration Control
3. Digital Certificates use which protocol?
X.509
Hackers and crackers
Directive
Intrusion Detection System
4. RSA is not based on a ________
Configuration Control
SYN Flooding
Symmetric algorithm
RADIUS
5. ____________ is a file system that was poorly designed and has numerous security flaws.
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
MAC - Mandatory Access Control
Presentation Layer - L6
NFS
6. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______
Decentralized access control
SYN Flooding
Verisign - Microsoft - Dell
Passfilt.dll
7. Contracting with an insurance company to cover losses due to information security breaches is known as risk __________.
Separation of Duties
128
Assignment
Passive network attack
8. Committing computer crimes in such small doses that they almost go unnoticed.
Multi-partite viruses
Decentralized access control
Salami attack
One way hash
9. DES - Data Encryption standard has a 128 bit key and is ________
Test virus
Not very difficult to break.
a good password policy
ISO
10. ___________________ viruses change the code order of the strain each time they replicate to another machine.
run applications as generic accounts with little or no privileges.
Polymorphic
Decentralized access control
a good password policy
11. Stealth viruses live in memory while __________ are written to disk
Ethernet
Logic bombs
Information
Environmental
12. ___________ - generally considered 'need to know' access is given based on permissions granted to the user.
DAC - Discretionary Access Control
To make user certificates available to others
Passive network attack
Polymorphic
13. __________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.
Decentralized access control
Sued for privacy violations
Protection of data from unauthorized users
Buffer Overflow
14. Countermeasures' main objectives
Depcrypting
Prevent - Recover - Detect
Data Classification
Confidentiality
15. So far - no one has been able to crack the ____________ with Brute Force.
IDEA algorithm
SLE - Single Loss Expectancy
CRACK
PGP
16. Although it is considered a low tech attack ____________ is still a very effective way of gaining unauthorized access to network systems.
Users can gain access to any resource upon request (assuming they have proper permissions)
Man In The Middle
Fixed length
Social Engineering
17. Which of the concepts best describes Availability in relation to computer resources?
CHAP
Stateful Inspection
product development life cycle
Users can gain access to any resource upon request (assuming they have proper permissions)
18. Which form of media is handled at the Physical Layer (Layer 1) of the OSI Reference Model?
Personal Firewall - IDS - host based - Antivirus
RSA
Ethernet
Polymorphic
19. Countermeasures address security concerns in this category
Environmental
Fixed length
Quantitative analysis
Information
20. When ________________it is very important to do document the chain of evidence by taking good notes and perform a bit-level back up of the data before analysis
SSL
Gathering digital evidence
Also
Detective
21. A ______________ is an electronically generated record that ties a user's ID to their public key.
Not very difficult to break.
Privacy violations
Certificate
a good password policy
22. Layer 4 of the OSI model corresponds to which layer of the DoD model?
Warning banners
Accountability
Layer 3 - Host to Host
Residual risk
23. The most secure method for storing backup tapes is?
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Multi-partite viruses
Off site in a climate controlled area
Personal Firewall - IDS - host based - Antivirus
24. __________________ will have weird characters printed at the beginning or end of an email message - what would it be anindication of?
Residual risk
Off site in a climate controlled area
A PGP Signed message
Cisco
25. Which of the following is NOT and encryption algorithm?
NFS
SSL
Intrusion Detection System
Biometrics
26. The act of intercepting the first message in a public key exchange and substituting a bogus key for the original key is an example of which style of attack?
Also
Man In The Middle
Configuration Control
Residual risk
27. Although they are accused of being one in the same - _______________ are two distinctly different groups with different goals pertaining to computers.
Off site in a climate controlled area
Hackers and crackers
A PGP Signed message
Directive
28. The PAP protocol sends passwords in clear text - while ____________ encrypts passwords. Both protocols are used by PPP (Point to Point Protocol) to transport IP traffic
CHAP
modems
Not very difficult to break.
Assignment
29. A security policy is a ___________ set of rules that must be followed explicitly in order to be effective.
Acceptance - Transfer - Mitigate
modems
Not rigid
Not very difficult to break.
30. __________ is a tool used by network administrators to capture packets from a network.
Log files
Directive
Decentralized access control
Sniffer
31. Contain - Recover - Review - Identify - Prepare
Preserve electronic evidence and protect it from any alteration
PGP
Residual risk
Steps in handling incidents
32. EICAR is an example of a _____________ used to test AV products without introducing a live virus into the network.
Fixed length
Test virus
Gathering digital evidence
All
33. S/MIME was developed for the protection of what communication mechanism(s)?
DSS - Digital Signature Standard
Hoaxes
Gathering digital evidence
Email
34. If your telephone company suddenly started billing you for caller ID and call forwarding without your permission - this practice is referred to as __________________.
Not rigid
Assignment
IPSEC
Cramming
35. HTTP - FTP - SMTP reside at which layer of the OSI model?
Layer 7 - Application
IDEA algorithm
DSS - Digital Signature Standard
Man In The Middle
36. Intentionally embedding secret data into a picture or some form of media is known as Steganographyor data ___________.
Privacy violations
modems
Steps in handling incidents
Data Hiding
37. In a Public Key Infrastructure (PKI) - what is the role of a directory server?
SET
Risk Equation
To make user certificates available to others
C2
38. The __________ is the most dangerous part of a virus program.
Virus definition downloads and system virus scans
Stealth viruses
Payload
Accountability
39. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.
Separation of Duties
SET
Business enabler
Information Security policies
40. Organizations that can be a valid Certificate Authority (CA)
Biometrics
Separation of Duties
Verisign - Microsoft - Dell
TIGER
41. Examples of One- Time Password technology
Warning banners
Less secure
Gathering digital evidence
S/Key - OPIE
42. ____ members of the staff need to be educated in disaster recovery procedures.
Cramming
Password audit
SLE - Single Loss Expectancy
All
43. Allows File owners to determine access rights.
Cisco
Sniffer
One way hash
Decentralized access control
44. Consists of checking for Minimum password length - Password aging - Password Strength - Blank Passwords?
DAC - Discretionary Access Control
Logic bombs
Password audit
Symmetric algorithm
45. ______________ is a Unix security scanning tool developed at Texas A&M university.
Layer 3 - Host to Host
TIGER
A PGP Signed message
Less secure
46. It is difficult to prosecute a computer criminal if _________ are not deployed
modems
Man In The Middle
Data Classification
Warning banners
47. A virus is considered to be 'in the ______ ' if it has been reported as replicating and causing harm to computers.
Symmetric algorithm
Wild
Main goal of a risk management program
Separation of Duties
48. Unclassified - Private - Confidential - Secret - Top Secret - and Internal Use Only are levels of ________________.
Off site in a climate controlled area
Data Classification
Stateful Inspection
Wild
49. Main goals of an information security program
DSS - Digital Signature Standard
Certificate
Confidentiality - Availability -Integrity of data
ISO
50. ________ is the authoritative entity which lists port assignments
SET
SSL
Main goal of a risk management program
IANA