• Home
  • Textbooks
  • The SSCP Prep Guide: Mastering the Seven Key Areas of System Security
  • Domain 3: Auditing and Monitoring

The SSCP Prep Guide: Mastering the Seven Key Areas of System Security

Debra S. Isaac, Michael J. Isaac

Chapter 4

Domain 3: Auditing and Monitoring - all with Video Answers

Educators


Chapter Questions

Problem 1

Which of the following statements is NOT true?
a. Monitoring is an activity that takes place in real time and views current activity on a network.
b. Monitoring retains detailed information for later review.
c. Auditing captures network activity.
d. Auditing retains information for later review.

Check back soon!

Problem 2

Relative to information systems security auditing, which of the following is NOT one of the reasons to conduct an audit?
a. To reconstruct events that might have caused a security breach
b. To identify a potential breach in security
c. To reconstruct activities performed during a breach in security
d. To develop techniques to prevent future breaches

Check back soon!

Problem 3

Which of the following statements is TRUE?
a. Most firewall systems do not provide logging functionality.
b. Application-proxy gateway firewalls provide more comprehensive logging output than stateful inspection packet filter firewalls.
c. Stateful inspection packet filter firewalls provide more comprehensive logging output than application-proxy gateway firewalls.
d. Application-proxy gateway firewalls encompass a smaller portion of the OSI model than stateful inspection packet filter firewalls.

Check back soon!

Problem 4

The mechanism used to synchronize the time reference for installed intrusion detection systems and for logging across the network is:
a. Network Time Protocol
b. Synchronous Network Logging Protocol
c. Time Synchronous Protocol
d. Network Coordination Protocol

Check back soon!
02:58

Problem 5

One of the rules in a rule set for a boundary router is given as:
$$
\begin{array}{llllll}
\text { RULE } & \begin{array}{l}
\text { SOURCE } \\
\text { ADDRESS }
\end{array} & \begin{array}{l}
\text { SOURCE } \\
\text { PORT }
\end{array} & \begin{array}{l}
\text { DESTINATION } \\
\text { ADDRESS }
\end{array} & \begin{array}{l}
\text { DESTINATION } \\
\text { PORT }
\end{array} & \text { ACTION } \\
\hline 4 & \text { Any } & \text { Any } & 192.168 .1 .2 & \text { SMTP } & \text { Allow } \\
\hline
\end{array}
$$
Which one of the following items BEST describes the permissions specified by the rule?
a. Prevents external users from directly addressing the firewall system
b. Permits internal users to access external servers
c. Permits inbound connections to the main firewall's SMTP port
d. Instructs the router to pass SMTP traffic to the main firewall, which in turn will forward the message traffic to the respective application proxies

Samriddhi Singh
Samriddhi Singh
Numerade Educator

Problem 6

Which of the following activities is NOT part of the process for establishing an audit trail?
a. Defining your roadmap
b. Developing your rule set
c. Auditing all violations
d. Not auditing exceptions

Check back soon!

Problem 7

The following activities are associated with auditing of what type of item?
- Creation, alteration, or dropping of a table
- Creation, alteration, or dropping of an index
- Statements renaming an object
- Performance statistics collection
- Granting and revoking of system type privilege
a. A network server
b. A database server
c. A mail server
d. A Web server

Check back soon!
01:22

Problem 8

Which of the following resources that are impacted by the auditing process poses the most difficulty to management?
a. Auditing systems' hardware
b. Software to implement logging
c. Human resources required for analyzing and interpreting the data
d. Offline storage for preserving the logs for a specified time period

Oluwadamilola Ameobi
Oluwadamilola Ameobi
Numerade Educator

Problem 9

Information about which one of the following activities is the LEAST important audit data to collect?
a. The use of privileged commands
b. Unsuccessful, unauthorized attempts to access files
c. Permission modifications
d. Successful, authorized accessing of files

Check back soon!

Problem 10

For events that are logged by the auditing process, which of the following data items is the LEAST important to collect?
a. Date and time of each event
b. Type of event
c. Denial of access resulting from excessive logon attempts
d. Non-system administrator functions

Check back soon!

Problem 11

The main purpose of monitoring an information system is:
a. Identifying a potential attack as it is occurring
b. Reconstructing incidents after they have occurred
c. Identifying incidents after they have occurred
d. Preventing the occurrence of incidents

Check back soon!

Problem 12

Which of the following items is NOT a type of network monitoring?
a. Network management monitoring
b. Mouse motion monitoring
c. Security monitoring
d. Key stroke monitoring

Check back soon!

Problem 13

Snort is:
a. An open-sourced audit system
b. An open-sourced keystroke monitoring system
c. A proprietary intrusion detection system
d. An open-sourced intrusion detection system

Check back soon!

Problem 14

A type of automated audit tool that provides the auditor with information concerning the network topology and assets is called:
a. An intrusion detection tool
b. A monitoring tool
c. A documentation tool
d. A discovery tool

Check back soon!

Problem 15

Automated tools such as SATAN and CYBERCOP perform which one of the following functions?
a. Vulnerability analysis
b. Intrusion detection
c. Data mining
d. Configuration management

Check back soon!

Problem 16

Which of the following items is NOT a correct, professional auditing standard?
a. Due professional care is exercised in all aspects of the information systems auditor's work.
b. If the information systems audit function is closely related to the area being audited, professional auditing practices must be enforced.
c. The information systems auditor will provide a report, in appropriate form and content, to the intended recipients upon completion of the audit work.
d. The responsibility, authority, and accountability of the information systems audit function must be appropriately documented in audit charters or in an engagement letter.

Check back soon!
02:05

Problem 17

A level of diligence that a prudent individual would practice under given circumstances is called:
a. Best effort
b. Basic practices
c. Due care
d. Least privilege

Dennis Howard
Dennis Howard
Numerade Educator

Problem 18

Which of the following statements is TRUE regarding a risk-based audit approach?
a. The cost to implement controls should be evaluated relative to the potential for loss if no controls are applied.
b. Residual risk can be eliminated by insurance coverage.
c. The risk mitigation is independent of management's tolerance for risk.
d. The means to eliminate risk through controls should be investigated.

Check back soon!

Problem 19

Risk that is a result of the failure of the auditing process to discover important errors is called:
a. Controls risk
b. Preventive risk
c. Inherent risk
d. Detection risk

Check back soon!

Problem 20

A control that is used to identify an area where an error has occurred is called:
a. Deterrent control
b. Detective control
c. Corrective control
d. Reactive control

Check back soon!

Problem 21

Which of the following items is MOST important in identifying potential irregularities during the audit process?
a. Size of the payroll for the organization being audited
b. Determining whether information systems best practices are used
c. Existence of a vacation policy that requires employees to take vacation in one or two-week blocks
d. Identifying the type of gateway used by the organization

Check back soon!

Problem 22

Control objectives are important in audit engagements because they:
a. Define audit duration
b. Define the cost of audit
c. Identify the main control issues based on management input and risk
d. Define testing steps

Check back soon!

Problem 23

Which of the following terms BEST describes "defining the roles and responsibilities of the auditors"?
a. Audit charter
b. Audit scope
c. Audit objectives
d. Control objectives

Check back soon!
02:04

Problem 24

Which of the following BEST meets the requirements of audit evidence sampling?
a. A confidence level higher than 90 percent based on repeated polling
b. Sufficient, reliable, relevant, useful, and supported by appropriate analyses
c. Should be conducted using the Delphi method
d. Should be conducted using random sampling

Harsh Gadhiya
Harsh Gadhiya
Numerade Educator

Problem 25

What are the key items to consider relative to the reportable findings of an audit?
a. Audit scope, materiality, and audit charter
b. Audit objectives, materiality, and management direction
c. Audit objectives and management direction
d. Audit objectives only

Check back soon!
04:30

Problem 26

An analysis that ensures that the underlying problem and not the symptoms is addressed is called:
a. Root cause analysis
b. Cost benefit analysis
c. Base problem analysis
d. Linear causal analysis

Samriddhi Singh
Samriddhi Singh
Numerade Educator

Problem 27

The definition "determining whether the system is being operated in accordance with accepted industry practices" refers to:
a. Monitoring
b. Auditing
c. Intrusion detection
d. Vulnerability analysis

Check back soon!
01:39

Problem 28

Which of the following BEST describes the given rule set for a boundary router?
$$
\begin{array}{llllll}
\text { RULE } & \begin{array}{l}
\text { SOURCE } \\
\text { ADDRESS }
\end{array} & \begin{array}{l}
\text { SOURCE } \\
\text { PORT }
\end{array} & \begin{array}{l}
\text { DESTINATION } \\
\text { ADDRESS }
\end{array} & \begin{array}{l}
\text { DESTINATION } \\
\text { PORT }
\end{array} & \text { ACTION } \\
\hline 4 & \text { Any } & \text { Any } & 192.168 .1 .0 & >1023 & \text { Allow } \\
\hline
\end{array}
$$
a. Allow external users to connect to the VPN server.
b. Allow internal servers to connect to external servers.
c. Allow external servers to send email to the proxy.
d. Allow return packets from established connections to return to the source systems.

James Kiss
James Kiss
Numerade Educator

Problem 29

Which of the following is NOT one of the processes for establishing an audit trail?
a. Define your roadmap.
b. Develop your rule set.
c. Audit all violations.
d. Audit all normalizations.

Check back soon!

Problem 30

Which of the following items is NOT an activity that should be logged on a relational database server?
a. Creation, alteration, or dropping of a database table
b. Enabling or disabling of the audit functionality
c. Any user statement that does not return an error message because the object referenced does not exist
d. Any user statement that renames a database object

Check back soon!