SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
SSCP: Systems Security Certified Practitioner
Start Test
Study First
Subjects
:
certifications
,
sscp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. EDI (Electronic Data Interchange) differs from e- Commerce in that it ___________________.
Also
Confidentiality - Availability -Integrity of data
ISO
involves only computer to computer transactions
2. Public keys are used for encrypting messages and private keys are used for __________messages.
S/Key - OPIE
Multi-partite viruses
Depcrypting
Detective
3. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.
Stealth viruses
Man In The Middle
Layer 3 - Host to Host
SET
4. DES - Data Encryption standard has a 128 bit key and is ________
Logic bombs
Fixed length
Main goal of a risk management program
Not very difficult to break.
5. ___________ - generally considered 'need to know' access is given based on permissions granted to the user.
Passwords
Layer 7 - Application
DAC - Discretionary Access Control
Authentication
6. A formula used in Quantitative risk analysis
Intentions of the perpetrator
SLE - Single Loss Expectancy
Main goal of a risk management program
Virus definition downloads and system virus scans
7. Cable modems are ___________than DSL connections
Environmental
Main goal of a risk management program
Salami attack
Less secure
8. Countermeasures' main objectives
a good password policy
CRACK
Reboot or system startup
Prevent - Recover - Detect
9. Countermeasures address security concerns in this category
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Assignment
Information Security policies
Information
10. Passwords: should be audited on a regular basis- should contain some form of your name or userid - should never be shared or written down
Steps in handling incidents
To make user certificates available to others
Log files
a good password policy
11. To help managers find the correct cost balance between risks and countermeasures
Layer 7 - Application
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Main goal of a risk management program
IPSEC
12. What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?
Data Classification
Multi-partite viruses
Preserve electronic evidence and protect it from any alteration
Residual risk
13. Companies can now be __________ just as easily as they can be sued for security compromises.
Sued for privacy violations
Virus definition downloads and system virus scans
Biometrics
Business enabler
14. Which of the concepts best describes Availability in relation to computer resources?
modems
Unix / Linux based security tools?
Users can gain access to any resource upon request (assuming they have proper permissions)
Phreaks
15. The ability to identify and audit a user and his / her actions is known as ____________.
Accountability
NT Audit events
Information
PGP
16. Diffie Hellman - RSA - and ___________ are all examples of Public Key cryptography?
DSS - Digital Signature Standard
Quantitative analysis
Risk Equation
Information Security policies
17. MD5 is a ___________ algorithm
Passfilt.dll
X.509
One way hash
A PGP Signed message
18. The PAP protocol sends passwords in clear text - while ____________ encrypts passwords. Both protocols are used by PPP (Point to Point Protocol) to transport IP traffic
Layer 7 - Application
Wild
Mobile
CHAP
19. HTTP - FTP - SMTP reside at which layer of the OSI model?
Layer 7 - Application
Authentication
NT Audit events
Separation of Duties
20. Smart cards are a secure alternative to which weak security mechanism?
Passwords
Authorization
Risk assessment
Verisign - Microsoft - Dell
21. EICAR is an example of a _____________ used to test AV products without introducing a live virus into the network.
Quantitative analysis
Confidentiality
MAC - Mandatory Access Control
Test virus
22. Tiger - TCP Wrappers - TripWire - LogCheck - SATAN
Business enabler
modems
Unix / Linux based security tools?
Separation of Duties
23. It is difficult to prosecute a computer criminal if _________ are not deployed
Log files
Warning banners
Mobile
Hackers and crackers
24. Instructions or code that executes on an end user's machine from a web browser is known as __________ code.
Mobile
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Prevent - Recover - Detect
All
25. Data being delivered from the source to the intended receiver without being altered
Ethernet
Not very difficult to break.
A PGP Signed message
Protection of data from unauthorized users
26. The __________ is the most dangerous part of a virus program.
Hackers and crackers
Wild
DSS - Digital Signature Standard
Payload
27. Which organization(s) are responsible for the timely distribution of information security intelligence data?
Hackers and crackers
Users can gain access to any resource upon request (assuming they have proper permissions)
CERT - SANS - CERIAS - COAST
run applications as generic accounts with little or no privileges.
28. This is more time consuming - numeric values - based on Annualized Loss Expectancy (ALE) formulas
Quantitative analysis
Less secure
Off site in a climate controlled area
Information
29. An attempt to break an encryption algorithm is called _____________.
Decentralized access control
Cryptanalysis
Presentation Layer - L6
Directive
30. Unlike like viruses and worm - __________ are bogus messages that spread via email forwarding.
Hoaxes
Not very difficult to break.
128
CHAP
31. Logon and Logoff - Use of User Rights - Security Policy Change
NT Audit events
Payload
ISO
Multi-partite viruses
32. Allows File owners to determine access rights.
All
Available service ports
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Decentralized access control
33. Is the person who is attempting to log on really who they say they are? What form of access control does this questions stem from?
Authentication
Configuration Control
TIGER
Buffer Overflow
34. Digital Certificates use which protocol?
X.509
Stateful Inspection
SET
Passfilt.dll
35. ______________ is a major component of an overall risk management program.
Risk assessment
Warning Banner
C2
Cryptanalysis
36. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______
NT Audit events
Passfilt.dll
Phreaks
Available service ports
37. A Security Reference Monitor relates to which DoD security standard?
C2
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Phreaks
To make user certificates available to others
38. The act of intercepting the first message in a public key exchange and substituting a bogus key for the original key is an example of which style of attack?
Man In The Middle
Test virus
DSS - Digital Signature Standard
Less secure
39. Identifying specific attempts to penetrate systems is the function of the _______________.
Intrusion Detection System
128
RADIUS
Authorization
40. So far - no one has been able to crack the ____________ with Brute Force.
Confidentiality - Availability -Integrity of data
IDEA algorithm
Logic bombs
Reboot or system startup
41. What is the following paragraph an example of? <<ATTN: This system is for the use of authorized persons only. If you use this system without authority - or if you abuse your authority - then you are subject to having all of your activities on this sy
Wild
Preserve electronic evidence and protect it from any alteration
Warning Banner
C2
42. When ________________it is very important to do document the chain of evidence by taking good notes and perform a bit-level back up of the data before analysis
Gathering digital evidence
Logic bombs
Users can gain access to any resource upon request (assuming they have proper permissions)
a good password policy
43. Combine both boot and file virus behavior
Verisign - Microsoft - Dell
Authentication
Multi-partite viruses
Passwords
44. The ability to adjust access control to the exact amount of permission necessary is called ______________.
Granularity
Depcrypting
Ethernet
Authorization
45. There are 65536 _________
Available service ports
CVE - Common Vulnerabilities and Exposures
Fixed length
Decentralized access control
46. ___________________ viruses change the code order of the strain each time they replicate to another machine.
Cryptanalysis
Preserve electronic evidence and protect it from any alteration
Residual risk
Polymorphic
47. ____________ is a file system that was poorly designed and has numerous security flaws.
TIGER
IDEA algorithm
NFS
Logic bombs
48. Code Review - Certification - Accreditation - Functional Design Review - System Test Review
Assignment
Detective
product development life cycle
Logic bombs
49. Which layer of the OSI model handles encryption?
Presentation Layer - L6
Logic bombs
SYN Flooding
modems
50. Committing computer crimes in such small doses that they almost go unnoticed.
Quantitative analysis
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Salami attack
SSL