Test your basic knowledge |

SSCP: Systems Security Certified Practitioner

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Contracting with an insurance company to cover losses due to information security breaches is known as risk __________.






2. A one way hash converts a string of random length into a _______________ encrypted string.






3. ____ members of the staff need to be educated in disaster recovery procedures.






4. ______________ relates to the concept of protecting data from unauthorized users.






5. Smart cards are a secure alternative to which weak security mechanism?






6. _________________should be Written down - Clearly Communicated to all system users - Audited and revised periodically.






7. __________________ will have weird characters printed at the beginning or end of an email message - what would it be anindication of?






8. Ways to deal with risk.






9. Diffie Hellman - RSA - and ___________ are all examples of Public Key cryptography?






10. Which range defines 'well known ports?'






11. DES - Data Encryption standard has a 128 bit key and is ________






12. The most secure method for storing backup tapes is?






13. Stealth viruses live in memory while __________ are written to disk






14. There are 65536 _________






15. A type of virus that resides in a Word or Excel document is called a ___________ virus?






16. Which form of media is handled at the Physical Layer (Layer 1) of the OSI Reference Model?






17. Code Review - Certification - Accreditation - Functional Design Review - System Test Review






18. What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?






19. EICAR is an example of a _____________ used to test AV products without introducing a live virus into the network.






20. A ______________ is an electronically generated record that ties a user's ID to their public key.






21. Macintosh computers are _____ at risk for receiving viruses.






22. This free (for personal use) program is used to encrypt and decrypt emails.






23. ___________________ viruses change the code order of the strain each time they replicate to another machine.






24. Unlike like viruses and worm - __________ are bogus messages that spread via email forwarding.






25. _______________ supply AV engines with false information to avoid detection






26. An attempt to break an encryption algorithm is called _____________.






27. Although it is considered a low tech attack ____________ is still a very effective way of gaining unauthorized access to network systems.






28. The act of intercepting the first message in a public key exchange and substituting a bogus key for the original key is an example of which style of attack?






29. One method that can reduce exposure to malicious code is to ___________________






30. What security principle is based on the division of job responsibilities - designed to prevent fraud?






31. Which organization(s) are responsible for the timely distribution of information security intelligence data?






32. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.






33. In a Public Key Infrastructure (PKI) - what is the role of a directory server?






34. A standardized list of the most common security weaknesses and exploits is the __________.






35. The PAP protocol sends passwords in clear text - while ____________ encrypts passwords. Both protocols are used by PPP (Point to Point Protocol) to transport IP traffic






36. Today - ______________ are almost as serious as security violations






37. ________ is the authoritative entity which lists port assignments






38. A true network security audit does include an audit for _____________






39. EDI (Electronic Data Interchange) differs from e- Commerce in that it ___________________.






40. Contain - Recover - Review - Identify - Prepare






41. Accounting - Authentication - and ____________ are the AAAs of information security.






42. Combine both boot and file virus behavior






43. Which auditing practice relates to the controlling of hardware - software - firmware - and documentation to insure it has not been improperly modified?






44. This is more time consuming - numeric values - based on Annualized Loss Expectancy (ALE) formulas






45. It is difficult to prosecute a computer criminal if _________ are not deployed






46. Identifying specific attempts to penetrate systems is the function of the _______________.






47. Digital Certificates use which protocol?






48. A Security Reference Monitor relates to which DoD security standard?






49. __________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.






50. Organizations that can be a valid Certificate Authority (CA)