• Home
  • Textbooks
  • The SSCP Prep Guide: Mastering the Seven Key Areas of System Security
  • Domain 2: Administration

The SSCP Prep Guide: Mastering the Seven Key Areas of System Security

Debra S. Isaac, Michael J. Isaac

Chapter 3

Domain 2: Administration - all with Video Answers

Educators


Chapter Questions

Problem 1

In the CIA triad, the tenet of confidentiality guarantees that:
a. The data will not be altered by unauthorized means.
b. The data will not be seen by unauthorized eyes.
c. The data will be available to those who will need it.
d. The data will be protected from lower security levels.

Check back soon!

Problem 2

The concept of data integrity assures that:
a. The information will not be seen by those with a lower security clearance.
b. The information will not be lost or destroyed.
c. The information will be protected from fraudulent accounting.
d. The information will be protected from unintentional or unauthorized alteration.

Check back soon!

Problem 3

In a system life cycle, information security controls should be:
a. Part of the feasibility phase
b. Implemented prior to validation
c. Designed during the product implementation phase
d. Specified after the coding phase

Check back soon!

Problem 4

The software maintenance phase controls consist of:
a. Request control, configuration control, and change control
b. Request control, change control, and release control
c. Request control, release control, and access control
d. Change control, security control, and access control

Check back soon!
02:19

Problem 5

Place the following four information classification levels in their proper order, from the most-sensitive classification to the least sensitive:
a. Top secret
b. Unclassified
c. SBU
d. Secret

Dennis Howard
Dennis Howard
Numerade Educator
01:28

Problem 6

Place the following general information classification procedures in their proper order:
a. Publicize awareness of the classification controls.
b. Classify the data.
c. Specify the controls.
d. Specify the classification criteria.

Anitha Mary
Anitha Mary
Numerade Educator

Problem 7

Which statement below describes "separation of duties?"
a. Each user is granted the lowest clearance required for their tasks.
b. Helps ensure that no single individual (acting alone) can compromise security controls.
c. Requires that the operator have the minimum knowledge of the system to perform his task.
d. Limits the time an operator performs a task.

Check back soon!

Problem 8

Which choice below is NOT considered a defined role for information classification purposes?
a. Data owner
b. Data object
c. Data user
d. Data custodian

Check back soon!

Problem 9

Place the organizational data classification scheme in order from the most secure to the least:
a. Private
b. Sensitive
c. Confidential
d. Public

Check back soon!

Problem 10

What does the data encapsulation in the OSI model do?
a. Creates seven distinct layers
b. Wraps data from one layer around a data packet from an adjoining layer
c. Provides "best effort" delivery of a data packet
d. Makes the network transmission deterministic

Check back soon!

Problem 11

Place the five system security life cycle phases in order of procedure:
a. Development/acquisition phase
b. Initiation phase
c. Implementation phase
d. Disposal phase
e. Operation/maintenance phase

Check back soon!

Problem 12

Which term below describes the concept of separation of privilege?
a. A formal separation of command, program, and interface functions.
b. Active monitoring of facility entry access points.
c. Each user is granted the lowest clearance required for their tasks.
d. A combination of classification and categories that represents the sensitivity of information.

Check back soon!

Problem 13

What is a programmable logic device (PLD)?
a. A program resident on disk memory that executes a specific function
b. An integrated circuit with connections or internal logic gates that can be changed through a programming process
c. Random access memory (RAM) that contains the software to perform specific tasks
d. A volatile device

Check back soon!

Problem 14

Random access memory is:
a. Nonvolatile
b. Volatile
c. Programmed by using fusible links
d. Sequentially addressable

Check back soon!

Problem 15

Which choice MOST accurately describes the difference between the role of a data owner versus the role of a data custodian?
a. The custodian makes the initial information classification assignments, and the operations manager implements the scheme.
b. The custodian implements the information classification scheme after the initial assignment by the owner.
c. The custodian implements the information classification scheme after the initial assignment by the operations manager.
d. The data owner implements the information classification scheme after the initial assignment by the custodian.

Check back soon!

Problem 16

Primary storage is the:
a. Memory that provides non-volatile storage, such as floppy disks
b. Memory where information must be obtained by searching sequentially from the beginning of the memory space
c. Memory for the storage of instructions and data that are associated with the program being executed and directly addressable by the CPU
d. Memory used in conjunction with real memory to present a CPU with a larger, apparent address space

Check back soon!

Problem 17

What is a control packet sent around a Token Ring network called?
a. Secondary storage
b. A computer bus
c. A token
d. A field in object-oriented programming

Check back soon!

Problem 18

Which of the following is NOT a VPN standard or protocol?
a. UTP
b. PPTP
c. L2TP
d. IPSec

Check back soon!

Problem 19

Which choice below describes the process of data destruction?
a. Overwriting of data media intended to be reused in the same organization or area
b. Degaussing or thoroughly overwriting media intended to be removed from the control of the organization or area
c. Complete physical destruction of the media
d. Reusing data storage media after its initial use

Check back soon!

Problem 20

Which choice below is NOT an accurate statement about standards?
a. Standards specify the use of specific technologies in a uniform way.
b. Standards are not the first element created in an effective security policy program.
c. Standards help describe how policies will be implemented within an organization.
d. Standards are senior management's directives to create a computer security program.

Check back soon!
01:40

Problem 21

Which TCP/IP protocol below operates at the application layer?
a. IP
b. FTP
c. UDP
d. TCP

Vysakh M
Vysakh M
Numerade Educator

Problem 22

What is the Data Link Layer of the OSI reference model primarily responsible for?
a. Internetwork packet routing
b. LAN bridging
c. SMTP Gateway services
d. Signal regeneration and repeating

Check back soon!

Problem 23

Which choice below incorrectly describes the organization's responsibilities during an unfriendly termination?
a. System access should be removed as quickly as possible after termination.
b. The employee should be given time to remove whatever files he needs from the network.
c. Cryptographic keys in the employee's property must be returned.
d. Briefing on the continuing responsibilities for confidentiality and privacy.

Check back soon!

Problem 24

Which of the following is NOT a property of a packet filtering firewall?
a. Uses ACLs
b. Susceptible to IP spoofing
c. Intercepts all messages entering and leaving the network
d. Examines the source and destination addresses of the incoming packet

Check back soon!

Problem 25

Configuration management control refers to:
a. The use of privileged-entity controls for system administrator functions
b. The concept of "least control" in operations
c. Implementing resource protection schemes for hardware control
d. Ensuring that changes to the system do not unintentionally diminish security

Check back soon!

Problem 26

Which is NOT a layer in the OSI architecture model?
a. Session
b. Data Link
c. Host-to-host
d. Transport

Check back soon!

Problem 27

What choice below is an example of a guideline?
a. A recommendation for procedural controls.
b. The instructions on how to perform a Quantitative Risk Analysis.
c. Statements that indicate a senior management's intention to support InfoSec.
d. Step-by-step procedures on how to implement a safeguard.

Check back soon!

Problem 28

Which of the choices below is an OSI reference model Presentation Layer protocol, standard, or interface?
a. Structured Query Language (SQL)
b. Remote Procedure Call (RPC)
c. AppleTalk Session Protocol (ASP)
d. Musical Instrument Digital Interface (MIDI)

Check back soon!
05:15

Problem 29

What is the definition of configuration identification?
a. Identifying and documenting the functional and physical characteristics of each configuration item
b. Controlling changes to the configuration items and issuing versions of configuration items from the software library
c. Recording the processing of changes
d. Controlling the quality of the configuration management procedures

Samriddhi Singh
Samriddhi Singh
Numerade Educator

Problem 30

Which of the following terms is NOT associated with a Read-Only Memory (ROM)?
a. Firmware
b. Static RAM (SRAM)
c. Field Programmable Gate Array (FPGA)
d. Flash memory

Check back soon!