Skip to content

SSCP System Security Certified Practitioner (SSCP) Practice Questions

Prepare for SSCP with more than an answer.

1,299 questions in the full set20 sample questionsUpdated Sep 16, 2021
Exam fee
$249 USD
Level
Associate/Professional
Valid for
3 years
Domains covered on the exam 7
  1. Security Concepts and Practices16%
  2. Access Controls15%
  3. Risk Identification, Monitoring and Analysis15%
  4. Incident Response and Recovery14%
  5. Cryptography9%
  6. Network and Communications Security16%
  7. Systems and Application Security15%
  1. 1

    What is the most correct choice below when talking about the steps to resume normal operation at the primary site after the green light has been given by the salvage team?

    Show answer details

    Correct answer: C

    C-Explanation:
    It's interesting to note that the steps to resume normal processing operations will be different than the steps of the recovery plan; that is, the least critical work should be brought back first to the primary site.

  2. 2

    Which of the following is NOT a property of the Rijndael block cipher algorithm?

    Show answer details

    Correct answer: A

    A-Explanation:
    The above statement is NOT true and thus the correct answer. The maximum key size on Rijndael is 256 bits.-References:http://blogs.msdn.com/b/shawnfa/archive/2006/10/09/the-differences-between-rijndael-and-aes.aspx

  3. 3

    A server cluster looks like a:

    Show answer details

    Correct answer: A

    A-Explanation:
    The cluster looks like a single server from the user's point of view.
    Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 67.

  4. 4

    Which of the following is NOT a defined ISO basic task related to network management?

    Show answer details

    Correct answer: B

    B-Explanation:
    ISO has defined five basic tasks related to network management: Source: Information Systems Audit and Control Association, Certified Information Systems Auditor 2002 review manual, Chapter 3: Technical Infrastructure and Operational Practices (page 137).

  5. 5

    Which of the following is a telecommunication device that translates data from digital to analog form and back to digital?

    Show answer details

    Correct answer: C

    C-Explanation:
    A modem is a device that translates data from digital form and then back to digital for communication over analog lines.
    Source: Information Systems Audit and Control Association, Certified Information Systems Auditor 2002 review manual, Chapter 3: Technical Infrastructure and Operational Practices (page 114).

  6. 6

    Which of the following remote access authentication systems is the most robust?

    Show answer details

    Correct answer: A

    A-Explanation:
    TACACS+ is a proprietary Cisco enhancement to TACACS and is more robust than RADIUS. PAP is not a remote access authentication system but a remote node security protocol.
    Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page 122).

  7. 7

    A security practitioner is explaining the process of certificate validation. The user's browser needs to verify a web server's certificate, which was issued by an Intermediate CA. Which of the following statements accurately describes the process?

    graph TD RootCA[Root CA] -->|signs| IntermediateCA[Intermediate CA] IntermediateCA -->|signs| WebServer[Web Server Certificate] User[User's Browser] -->|verifies| WebServer

    Show answer details

    Correct answer: C

    Certificate validation requires building a chain of trust. The browser must validate each certificate in the chain up to a trusted Root CA whose certificate is pre-installed in the browser's trust store. This process involves using the public key of the issuer (e.g., Root CA) to verify the digital signature of the certificate it issued (e.g., Intermediate CA).

  8. 8

    What can be defined as: It confirms that users’ needs have been met by the supplied solution ?

    Show answer details

    Correct answer: A

    A-Explanation:
    Acceptance confirms that users’ needs have been met by the supplied solution.-Reference: http://www. aof.mod.uk/aofcontent/tactical/randa/content/randaintroduction.htm

  9. 9

    Which of the following steps is NOT one of the eight detailed steps of a Business Impact Assessment (BIA):

    Show answer details

    Correct answer: B

    B-Explanation:
    The eight detailed and granular steps of the BIA are: 1. Select Individuals to interview for the data gathering. 2. Create data gathering techniques (surveys, questionnaires, qualitative and quantitative approaches). 3. Identify the company's critical business functions. 4. Identify the resources that these functions depend upon. 5. Calculate how long these functions can survive without these resources. 6. Identify vulnerabilities and the threats to these functions. 7. Calculate risk for each of the different business functions. 8. Document findings and report them to management.

  10. 10

    An access system that grants users only those rights necessary for them to perform their work is operating on which security principle?

    Show answer details

    Correct answer: D

    D-Explanation:
    Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.

Create an account to continue.