Test your basic knowledge |

SSCP: Systems Security Certified Practitioner

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. EDI (Electronic Data Interchange) differs from e- Commerce in that it ___________________.






2. Public keys are used for encrypting messages and private keys are used for __________messages.






3. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.






4. DES - Data Encryption standard has a 128 bit key and is ________






5. ___________ - generally considered 'need to know' access is given based on permissions granted to the user.






6. A formula used in Quantitative risk analysis






7. Cable modems are ___________than DSL connections






8. Countermeasures' main objectives






9. Countermeasures address security concerns in this category






10. Passwords: should be audited on a regular basis- should contain some form of your name or userid - should never be shared or written down






11. To help managers find the correct cost balance between risks and countermeasures






12. What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?






13. Companies can now be __________ just as easily as they can be sued for security compromises.






14. Which of the concepts best describes Availability in relation to computer resources?






15. The ability to identify and audit a user and his / her actions is known as ____________.






16. Diffie Hellman - RSA - and ___________ are all examples of Public Key cryptography?






17. MD5 is a ___________ algorithm






18. The PAP protocol sends passwords in clear text - while ____________ encrypts passwords. Both protocols are used by PPP (Point to Point Protocol) to transport IP traffic






19. HTTP - FTP - SMTP reside at which layer of the OSI model?






20. Smart cards are a secure alternative to which weak security mechanism?






21. EICAR is an example of a _____________ used to test AV products without introducing a live virus into the network.






22. Tiger - TCP Wrappers - TripWire - LogCheck - SATAN






23. It is difficult to prosecute a computer criminal if _________ are not deployed






24. Instructions or code that executes on an end user's machine from a web browser is known as __________ code.






25. Data being delivered from the source to the intended receiver without being altered






26. The __________ is the most dangerous part of a virus program.






27. Which organization(s) are responsible for the timely distribution of information security intelligence data?






28. This is more time consuming - numeric values - based on Annualized Loss Expectancy (ALE) formulas






29. An attempt to break an encryption algorithm is called _____________.






30. Unlike like viruses and worm - __________ are bogus messages that spread via email forwarding.






31. Logon and Logoff - Use of User Rights - Security Policy Change






32. Allows File owners to determine access rights.






33. Is the person who is attempting to log on really who they say they are? What form of access control does this questions stem from?






34. Digital Certificates use which protocol?






35. ______________ is a major component of an overall risk management program.






36. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______






37. A Security Reference Monitor relates to which DoD security standard?






38. The act of intercepting the first message in a public key exchange and substituting a bogus key for the original key is an example of which style of attack?






39. Identifying specific attempts to penetrate systems is the function of the _______________.






40. So far - no one has been able to crack the ____________ with Brute Force.






41. What is the following paragraph an example of? <<ATTN: This system is for the use of authorized persons only. If you use this system without authority - or if you abuse your authority - then you are subject to having all of your activities on this sy






42. When ________________it is very important to do document the chain of evidence by taking good notes and perform a bit-level back up of the data before analysis






43. Combine both boot and file virus behavior






44. The ability to adjust access control to the exact amount of permission necessary is called ______________.






45. There are 65536 _________






46. ___________________ viruses change the code order of the strain each time they replicate to another machine.






47. ____________ is a file system that was poorly designed and has numerous security flaws.






48. Code Review - Certification - Accreditation - Functional Design Review - System Test Review






49. Which layer of the OSI model handles encryption?






50. Committing computer crimes in such small doses that they almost go unnoticed.