SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
SSCP: Systems Security Certified Practitioner
Start Test
Study First
Subjects
:
certifications
,
sscp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. HTTP - FTP - SMTP reside at which layer of the OSI model?
Sued for privacy violations
Sniffer
Layer 7 - Application
Reboot or system startup
2. What is the main difference between computer abuse and computer crime?
IDEA algorithm
Privacy violations
Intentions of the perpetrator
ISO
3. RSA is not based on a ________
TIGER
Test virus
A PGP Signed message
Symmetric algorithm
4. Ways to deal with risk.
Acceptance - Transfer - Mitigate
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Reboot or system startup
Wild
5. Although it is considered a low tech attack ____________ is still a very effective way of gaining unauthorized access to network systems.
Authentication
Social Engineering
Cryptanalysis
Email
6. What is the following paragraph an example of? <<ATTN: This system is for the use of authorized persons only. If you use this system without authority - or if you abuse your authority - then you are subject to having all of your activities on this sy
Main goal of a risk management program
TIGER
Warning Banner
Gathering digital evidence
7. There are 5 classes of IP addresses available - but only 3 classes are in common use today
Salami attack
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
IANA
CHAP
8. The ability to identify and audit a user and his / her actions is known as ____________.
Acceptance - Transfer - Mitigate
IDEA algorithm
Not very difficult to break.
Accountability
9. The __________ is the most dangerous part of a virus program.
Polymorphic
Payload
Not very difficult to break.
Verisign - Microsoft - Dell
10. EICAR is an example of a _____________ used to test AV products without introducing a live virus into the network.
modems
Payload
Test virus
Layers 5 - 6 - & 7 - Session - Presentation - and Application Layers
11. Code Review - Certification - Accreditation - Functional Design Review - System Test Review
Logic bombs
Salami attack
All
product development life cycle
12. ____________ is used in mission critical systems and applications to lock down information based on sensitivity levels (Confidential - Top Secret - etc.
Information Security policies
X.509
MAC - Mandatory Access Control
Data Hiding
13. The ultimate goal of a computer forensics specialist is to ___________________.
Protection of data from unauthorized users
Preserve electronic evidence and protect it from any alteration
Authentication
Information
14. Identifying specific attempts to penetrate systems is the function of the _______________.
Intrusion Detection System
Social Engineering
SET
One way hash
15. ____ members of the staff need to be educated in disaster recovery procedures.
Acceptance - Transfer - Mitigate
RSA
All
CVE - Common Vulnerabilities and Exposures
16. Vulnerability x Threat = RISK is an example of the _______________.
Risk Equation
Logic bombs
Gathering digital evidence
Layer 3 - Host to Host
17. Intentionally embedding secret data into a picture or some form of media is known as Steganographyor data ___________.
Man In The Middle
Data Hiding
CVE - Common Vulnerabilities and Exposures
Decentralized access control
18. Is the person who is attempting to log on really who they say they are? What form of access control does this questions stem from?
Authentication
SET
Intrusion Detection System
Prevent - Recover - Detect
19. There are 65536 _________
Residual risk
RSA
Available service ports
Not very difficult to break.
20. ________ is a protocol developed by Visa and MasterCard to protect electronic transactions.
Polymorphic
Host based - network based
Stealth viruses
SET
21. Which major vendor adopted TACACS into its product line as a form of AAA architecture?
Data Hiding
Also
Quantitative analysis
Cisco
22. Unclassified - Private - Confidential - Secret - Top Secret - and Internal Use Only are levels of ________________.
IDEA algorithm
modems
Intentions of the perpetrator
Data Classification
23. S/MIME was developed for the protection of what communication mechanism(s)?
Privacy violations
Email
Assignment
run applications as generic accounts with little or no privileges.
24. Allows File owners to determine access rights.
Confidentiality
Decentralized access control
Class A: 1-126 - Class B: 128-191 - Class C: 192-223
Acceptance - Transfer - Mitigate
25. Cable modems are ___________than DSL connections
Salami attack
Unix / Linux based security tools?
RSA
Less secure
26. Data being delivered from the source to the intended receiver without being altered
Decentralized access control
Assignment
To make user certificates available to others
Protection of data from unauthorized users
27. Which range defines 'well known ports?'
modems
0-1023
Polymorphic
Granularity
28. An intrusion detection system is an example of what type of countermeasure?
Social Engineering
Intentions of the perpetrator
Passwords
Detective
29. A formula used in Quantitative risk analysis
Steps in handling incidents
SLE - Single Loss Expectancy
Passive network attack
Macro
30. PGP & PEM are programs that allow users to send encrypted messages to each other. What form of encryption do these programs use?
Information Security policies
RSA
PGP
run applications as generic accounts with little or no privileges.
31. Each password must have a combination of upper case - lower case - numbers and special characters - 6 character minimum password length - This rule is enforced by ______
Sued for privacy violations
Polymorphic
SLE - Single Loss Expectancy
Passfilt.dll
32. ____________ is a file system that was poorly designed and has numerous security flaws.
NFS
NT Audit events
Fixed length
Verisign - Microsoft - Dell
33. ________ is the authoritative entity which lists port assignments
involves only computer to computer transactions
SET
a good password policy
IANA
34. A virus is considered to be 'in the ______ ' if it has been reported as replicating and causing harm to computers.
TIGER
SSL
Information Security policies
Wild
35. To help managers find the correct cost balance between risks and countermeasures
Environmental
Main goal of a risk management program
Risk Equation
RADIUS
36. __________ is the most famous Unix password cracking tool.
Protection of data from unauthorized users
Accountability
Layer 7 - Application
CRACK
37. Smart cards are a secure alternative to which weak security mechanism?
Authentication
Phreaks
Passwords
128
38. The most secure method for storing backup tapes is?
Off site in a climate controlled area
To make user certificates available to others
Not very difficult to break.
Symmetric algorithm
39. IKE - Internet Key Exchange is often used in conjunction with what security standard?
Cisco
involves only computer to computer transactions
Prevent - Recover - Detect
IPSEC
40. Organizations that can be a valid Certificate Authority (CA)
Main goal of a risk management program
Sniffer
Verisign - Microsoft - Dell
Also
41. Companies can now be __________ just as easily as they can be sued for security compromises.
Hackers and crackers
Users can gain access to any resource upon request (assuming they have proper permissions)
Sued for privacy violations
Information Security policies
42. __________ is a tool used by network administrators to capture packets from a network.
Sniffer
Authentication
Acceptance - Transfer - Mitigate
Man In The Middle
43. _________ is a form of Denial of Service attack which interrupts the TCP three way handshake and leaves half open connections.
Business enabler
SYN Flooding
Acceptance - Transfer - Mitigate
Gathering digital evidence
44. A standardized list of the most common security weaknesses and exploits is the __________.
Main goal of a risk management program
Granularity
Quantitative analysis
CVE - Common Vulnerabilities and Exposures
45. Which layer of the OSI model handles encryption?
Presentation Layer - L6
Quantitative analysis
run applications as generic accounts with little or no privileges.
Email
46. The act of intercepting the first message in a public key exchange and substituting a bogus key for the original key is an example of which style of attack?
Risk Equation
Macro
Man In The Middle
Prevent - Recover - Detect
47. ______________ is a Unix security scanning tool developed at Texas A&M university.
TIGER
Test virus
Wild
Man In The Middle
48. Accounting - Authentication - and ____________ are the AAAs of information security.
Authorization
Residual risk
Layer 7 - Application
IANA
49. Name two types of Intrusion Detection Systems
IANA
Depcrypting
Unix / Linux based security tools?
Host based - network based
50. __________ attacks capitalize on programming errors and can allow the originator to gain additional privileges on a machine.
Cramming
Buffer Overflow
Payload
Stealth viruses