
Changing the Concept of SSCP Exam Preparation 2024
Getting SSCP Certification Made Easy! Get professional help from our SSCP Dumps PDF
Risk Identification, Analysis, & Monitoring (15%):
- Performing Various Security Evaluation Activities – This objective covers audit finding remediation, remediation validation, interpreting & reporting testing and scanning results, as well as participating in security testing;
- Operating & Maintaining Monitoring Systems – This area includes the information about logging, events of interest, source systems, as well as regulatory and legal concerns;
- Analyzing Monitoring Results – As for this domain, it requires the students’ skills in performing event data analysis, finding security anomalies and baselines, as well as your knowledge about the visualization, trends, and metrics. It also covers their expertise in documenting and communicating findings.
- Understanding the Process of Risk Management – It includes risk visibility & reporting, risk treatment, risk management frameworks, and risk management concepts;
ISC SSCP (System Security Certified Practitioner) Certification Exam is a globally recognized certification that validates the knowledge and skills of professionals who are responsible for implementing and managing cybersecurity programs. System Security Certified Practitioner (SSCP) certification exam is designed to assess the candidate's expertise in various areas of information security, such as network security, access controls, cryptography, and incident response.
NEW QUESTION # 309
Information security policies are a ___________________.
- A. Necessary evil
- B. Inconvenience for the end user
- C. All of the answers are correct
- D. Waste of time
- E. Business enabler
Answer: E
NEW QUESTION # 310
Which of the following security mode of operation does NOT require all users to have the clearance for all information processed on the system?
- A. Multilevel security mode
- B. System-high security mode
- C. Compartmented security mode
- D. Dedicated security mode
Answer: A
Explanation:
The multilevel security mode permits two or more classification levels of
information to be processed at the same time when all the users do not have the clearance
of formal approval to access all the information being processed by the system.
In dedicated security mode, all users have the clearance or authorization and need-to-know
to all data processed within the system.
In system-high security mode, all users have a security clearance or authorization to
access the information but not necessarily a need-to-know for all the information processed
on the system (only some of the data).
In compartmented security mode, all users have the clearance to access all the information
processed by the system, but might not have the need-to-know and formal access
approval.
Generally, Security modes refer to information systems security modes of operations used
in mandatory access control (MAC) systems. Often, these systems contain information at
various levels of security classification.
The mode of operation is determined by:
The type of users who will be directly or indirectly accessing the system.
The type of data, including classification levels, compartments, and categories, that are
processed on the system.
The type of levels of users, their need to know, and formal access approvals that the users
will have.
Dedicated security mode
In this mode of operation, all users must have:
Signed NDA for ALL information on the system.
Proper clearance for ALL information on the system.
Formal access approval for ALL information on the system.
A valid need to know for ALL information on the system.
All users can access ALL data.
System high security mode
In this mode of operation, all users must have:
Signed NDA for ALL information on the system.
Proper clearance for ALL information on the system.
Formal access approval for ALL information on the system.
A valid need to know for SOME information on the system.
All users can access SOME data, based on their need to know.
Compartmented security mode
In this mode of operation, all users must have:
Signed NDA for ALL information on the system.
Proper clearance for ALL information on the system.
Formal access approval for SOME information they will access on the system.
A valid need to know for SOME information on the system.
All users can access SOME data, based on their need to know and formal access
approval.
Multilevel security mode
In this mode of operation, all users must have:
Signed NDA for ALL information on the system.
Proper clearance for SOME information on the system.
Formal access approval for SOME information on the system.
A valid need to know for SOME information on the system.
All users can access SOME data, based on their need to know, clearance and formal
access approval.
REFERENCES:
WALLHOFF, John, CBK#6 Security Architecture and Models (CISSP Study Guide), April
2002 (page 6).
and
http://en.wikipedia.org/wiki/Security_Modes
NEW QUESTION # 311
When gathering digital evidence it is very important to do the following: (Choose all that apply)
- A. Document the chain of evidence by taking good notes
- B. Shut down the compromised system to avoid further attacks
- C. Reboot the victim system offline
- D. Perform a bit-level back up of the data before analysis
Answer: A,D
NEW QUESTION # 312
S/MIME was developed for the protection of what communication mechanism(s)?
- A. Wireless devices
- B. Email
- C. Firewalls
- D. Telephones
Answer: B
NEW QUESTION # 313
Crime Prevention Through Environmental Design (CPTED) is a discipline that:
- A. Outlines how the proper design of the logical environment can reduce crime by directly affecting human behavior.
- B. Outlines how the proper design of a physical environment can reduce crime by directly affecting human behavior.
- C. Outlines how the proper design of the detective control environment can reduce crime by directly affecting human behavior.
- D. Outlines how the proper design of the administrative control environment can reduce crime by directly affecting human behavior.
Answer: B
Explanation:
Crime Prevention Through Environmental Design (CPTED) is a discipline that outlines how the proper design of a physical environment can reduce crime by directly affecting human behavior. It provides guidance about lost and crime prevention through proper facility contruction and environmental components and procedures.
CPTED concepts were developed in the 1960s. They have been expanded upon and have matured as our environments and crime types have evolved. CPTED has been used not just to develop corporate physical security programs, but also for large-scale activities such as development of neighborhoods, towns, and cities. It addresses landscaping, entrances, facility and neighborhood layouts, lighting, road placement, and traffic circulation patterns. It looks at microenvironments, such as offices and rest-rooms, and macroenvironments, like campuses and cities.
Reference(s) used for this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 435). McGraw-Hill. Kindle Edition. and CPTED Guide Book
NEW QUESTION # 314
Which of the following is NOT part of the Kerberos authentication protocol?
- A. Authentication service (AS)
- B. Symmetric key cryptography
- C. Principals
- D. Public Key
Answer: D
Explanation:
There is no such component within kerberos environment. Kerberos uses
only symmetric encryption and does not make use of any public key component.
The other answers are incorrect because :
Symmetric key cryptography is a part of Kerberos as the KDC holds all the users' and
services' secret keys.
Authentication service (AS) : KDC (Key Distribution Center) provides an authentication
service
Principals : Key Distribution Center provides services to principals , which can be users ,
applications or network services.
References: Shon Harris , AIO v3 , Chapter - 4: Access Control , Pages : 152-155.
NEW QUESTION # 315
__________ is the most famous Unix password cracking tool.
- A. JOLT
- B. NMAP
- C. CRACK
- D. ROOT
- E. SNIFF
Answer: C
NEW QUESTION # 316
Knowledge-based Intrusion Detection Systems (IDS) are more common than:
- A. Network-based IDS
- B. Host-based IDS
- C. Behavior-based IDS
- D. Application-Based IDS
Answer: C
Explanation:
Knowledge-based IDS are more common than behavior-based ID systems.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 63.
Application-Based IDS - "a subset of HIDS that analyze what's going on in an application using the transaction log files of the application." Source: Official ISC2 CISSP CBK Review Seminar Student Manual Version 7.0 p. 87
Host-Based IDS - "an implementation of IDS capabilities at the host level. Its most significant difference from NIDS is intrusion detection analysis, and related processes are limited to the boundaries of the host." Source: Official ISC2 Guide to the CISSP CBK - p. 197
Network-Based IDS - "a network device, or dedicated system attached to the network, that monitors traffic traversing the network segment for which it is integrated." Source: Official ISC2 Guide to the CISSP CBK - p. 196
CISSP for dummies a book that we recommend for a quick overview of the 10 domains has nice and concise coverage of the subject:
Intrusion detection is defined as real-time monitoring and analysis of network activity and data for potential vulnerabilities and attacks in progress. One major limitation of current intrusion detection system (IDS) technologies is the requirement to filter false alarms lest the operator (system or security administrator) be overwhelmed with data. IDSes are classified in many different ways, including active and passive, network-based and host-based, and knowledge-based and behavior-based: Active and passive IDS
An active IDS (now more commonly known as an intrusion prevention system - IPS) is a system that's configured to automatically block suspected attacks in progress without any intervention required by an operator. IPS has the advantage of providing real-time corrective action in response to an attack but has many disadvantages as well. An IPS must be placed in-line along a network boundary; thus, the IPS itself is susceptible to attack. Also, if false alarms and legitimate traffic haven't been properly identified and filtered, authorized users and applications may be improperly denied access. Finally, the IPS itself may be used to effect a Denial of Service (DoS) attack by intentionally flooding the system with alarms that cause it to block connections until no connections or bandwidth are available.
A passive IDS is a system that's configured only to monitor and analyze network traffic activity and alert an operator to potential vulnerabilities and attacks. It isn't capable of performing any protective or corrective functions on its own. The major advantages of passive IDSes are that these systems can be easily and rapidly deployed and are not normally susceptible to attack themselves. Network-based and host-based IDS
A network-based IDS usually consists of a network appliance (or sensor) with a Network Interface Card (NIC) operating in promiscuous mode and a separate management interface. The IDS is placed along a network segment or boundary and monitors all traffic on that segment.
A host-based IDS requires small programs (or agents) to be installed on individual systems to be monitored. The agents monitor the operating system and write data to log files and/or trigger alarms. A host-based IDS can only monitor the individual host systems on which the agents are installed; it doesn't monitor the entire network. Knowledge-based and behavior-based IDS
A knowledge-based (or signature-based) IDS references a database of previous attack profiles and known system vulnerabilities to identify active intrusion attempts. Knowledge-based IDS is currently more common than behavior-based IDS.
Advantages of knowledge-based systems include the following:
It has lower false alarm rates than behavior-based IDS.
Alarms are more standardized and more easily understood than behavior-based IDS.
Disadvantages of knowledge-based systems include these:
Signature database must be continually updated and maintained.
New, unique, or original attacks may not be detected or may be improperly classified.
A behavior-based (or statistical anomaly-based) IDS references a baseline or learned
pattern of normal system activity to identify active intrusion attempts. Deviations from this
baseline or pattern cause an alarm to be triggered.
Advantages of behavior-based systems include that they
Dynamically adapt to new, unique, or original attacks.
Are less dependent on identifying specific operating system vulnerabilities.
Disadvantages of behavior-based systems include
Higher false alarm rates than knowledge-based IDSes.
Usage patterns that may change often and may not be static enough to implement an
effective behavior-based IDS.
NEW QUESTION # 317
Why does compiled code pose more of a security risk than interpreted code?
- A. Because malicious code can be embedded in compiled code and be difficult to detect.
- B. There is no risk difference between interpreted code and compiled code.
- C. Because compilers are not reliable.
- D. If the executed compiled code fails, there is a chance it will fail insecurely.
Answer: A
Explanation:
From a security standpoint, a compiled program is less desirable than an interpreted one because malicious code can be resident somewhere in the compiled code, and it is difficult to detect in a very large program.
NEW QUESTION # 318
Under the Business Exemption Rule to the hearsay evidence, which of the following exceptions would have no bearing on the inadmissibility of audit logs and audit trails in a court of law?
- A. Records are collected by senior or executive management.
- B. You can prove no one could have changed the records/data/logs that were collected.
- C. Records are collected at or near the time of occurrence of the act being investigated to generate automated reports.
- D. Records are collected during the regular conduct of business.
Answer: A
Explanation:
Explanation/Reference:
Hearsay evidence is not normally admissible in court unless it has firsthand evidence that can be used to prove the evidence's accuracy, trustworthiness, and reliability like a business person who generated the computer logs and collected them.
It is important that this person generates and collects logs as a normal part of his business and not just this one time for court. It has to be a documented process that is carried out daily.
The value of evidence depends upon the genuineness and competence of the source; therefore, since record collection is not an activity likely to be performed by senior or executive management, records collected by senior or executive management are not likely to be admissible in court.
Hearsay evidence is usually not admissible in court unless it meets the Business Records Exemption rule to the Hearsay evidence.
* In certain instances computer records fall outside of the hearsay rule (e.g., business records exemption)
* Information relates to regular business activities
* Automatically computer generated data
* No human intervention
* Prove system was operating correctly
* Prove no one changed the data
If you have a documented business process and you make use of intrusion detection tools, log analysis tools, and you produce daily reports of activities, then the computer generated data might be admissible in court and would not be considered Hearsay Evidence.
Reference(s) used for this question:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, chapter 10: Law, Investigation, and Ethics (page 676).
NEW QUESTION # 319
Which of the following is not a logical control when implementing logical access security?
- A. passwords.
- B. access profiles.
- C. userids.
- D. employee badges.
Answer: D
Explanation:
Employee badges are considered Physical so would not be a logical control.
The following answers are incorrect:
userids. Is incorrect because userids are a type of logical control. access profiles. Is incorrect because access profiles are a type of logical control. passwords. Is incorrect because passwords are a type of logical control.
NEW QUESTION # 320
There are 6 types of security control practices. ___________ controls are management policies, procedures, and guidelines that usually effect the entire system. These types of controls deal with system auditing and usability.
- A. Recovery
- B. Detective
- C. Combination
- D. Directive
- E. Preventive
- F. Corrective
Answer: D
NEW QUESTION # 321
What IDS approach relies on a database of known attacks?
- A. Signature-based intrusion detection
- B. Network-based intrusion detection
- C. Behavior-based intrusion detection
- D. Statistical anomaly-based intrusion detection
Answer: A
Explanation:
Explanation/Reference:
A weakness of the signature-based (or knowledge-based) intrusion detection approach is that only attack signatures that are stored in a database are detected. Network-based intrusion detection can either be signature-based or statistical anomaly-based (also called behavior-based).
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems (page 49).
NEW QUESTION # 322
How is Annualized Loss Expectancy (ALE) derived from a threat?
- A. SLE x ARO
- B. AV x EF
- C. SLE/EF
- D. ARO x (SLE - EF)
Answer: A
Explanation:
Three steps are undertaken in a quantitative risk assessment:
Initial management approval
Construction of a risk assessment team, and
The review of information currently available within the organization.
There are a few formulas that you MUST understand for the exam. See them below:
SLE (Single Loss Expectancy)
Single loss expectancy (SLE) must be calculated to provide an estimate of loss. SLE is
defined as the difference between the original value and the remaining value of an asset
after a single exploit.
The formula for calculating SLE is as follows: SLE = asset value (in $) x exposure factor
(loss due to successful threat exploit, as a %)
Losses can include lack of availability of data assets due to data loss, theft, alteration, or
denial of service (perhaps due to business continuity or security issues).
ALE (Annualized Loss Expectancy)
Next, the organization would calculate the annualized rate of occurrence (ARO).
This is done to provide an accurate calculation of annualized loss expectancy (ALE).
ARO is an estimate of how often a threat will be successful in exploiting a vulnerability over
the period of a year.
When this is completed, the organization calculates the annualized loss expectancy (ALE).
The ALE is a product of the yearly estimate for the exploit (ARO) and the loss in value of an
asset after an SLE.
The calculation follows ALE = SLE x ARO
Note that this calculation can be adjusted for geographical distances using the local annual
frequency estimate (LAFE) or the standard annual frequency estimate (SAFE). Given that
there is now a value for SLE, it is possible to determine what the organization should
spend, if anything, to apply a countermeasure for the risk in question.
Remember that no countermeasure should be greater in cost than the risk it mitigates,
transfers, or avoids.
Countermeasure cost per year is easy and straightforward to calculate. It is simply the cost
of the countermeasure divided by the years of its life (i.e., use within the organization).
Finally, the organization is able to compare the cost of the risk versus the cost of the
countermeasure and make some objective decisions regarding its countermeasure
selection.
The following were incorrect answers:
All of the other choices were incorrect.
The following reference(s) were used for this quesiton:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third
Edition ((ISC)2 Press) (Kindle Locations 10048-10069). Auerbach Publications. Kindle
Edition.
NEW QUESTION # 323
FTP, TFTP, SNMP, and SMTP are provided at what level of the Open Systems Interconnect (OSI) Reference Model?
- A. Network
- B. Transport
- C. Presentation
- D. Application
Answer: D
Explanation:
Application. The Layer 7 Application Layer of the Open Systems Interconnect (OSI) Reference Model is a service for applications and Operating Systems data transmission, for example FTP, TFTP, SNMP, and SMTP.
The following answers are incorrect: Network. The Network layer moves information between hosts that are not physically connected. It deals with routing of information. IP is a protocol that is used in Network Layer. FTP, TFTP, SNMP, and SMTP do not reside at the Layer 3 Network Layer in the OSI Reference Model.
Presentation. The Presentation Layer is concerned with the formatting of data into a standard presentation such as ASCII. FTP, TFTP, SNMP, and SMTP do not reside at the Layer 6 Presentation Layer in the OSI Reference Model.
Transport. The Transport Layer creates an end-to-end transportation between peer hosts. The transmission can be connectionless and unreliable such as UDP, or connection-oriented and ensure error-free delivery such as TCP. FTP, TFTP, SNMP, and SMTP do not reside at the Layer 4 Transportation Layer in the OSI Reference Model.
The following reference(s) were/was used to create this question: Reference: OSI/ISO.
Shon Harris AIO v.3 p. 420-421 ISC2 OIG, 2997 p.412-413
NEW QUESTION # 324
Which of the following is NOT a common category/classification of threat to an IT system?
- A. Natural
- B. Human
- C. Technological
- D. Hackers
Answer: D
Explanation:
Hackers are classified as a human threat and not a classification by itself.
All the other answers are incorrect. Threats result from a variety of factors, although they are classified in three types: Natural (e.g., hurricane, tornado, flood and fire), human (e.g. operator error, sabotage, malicious code) or technological (e.g. equipment failure, software error, telecommunications network outage, electric power failure).
NEW QUESTION # 325
A circuit level proxy is ___________________ when compared to an application level proxy.
- A. slower.
- B. more difficult to maintain.
- C. more secure.
- D. lower in processing overhead.
Answer: D
Explanation:
Since the circuit level proxy does not anayze the application content of the packet in making its decisions, it has lower overhead than an application level proxy.
"More difficult to maintain" is incorrect. Circuit level proxies are typicall easier to configure and simpler to maintain that an application level proxy.
"More secure" is incorrect. A circuit level proxy is not necessarily more secure than an application layer proxy.
"Slower" is incorrect. Because it is lower in overhead, a circuit level proxy is typically faster than an application level proxy.
References: CBK,pp. 466 - 467 AIO3, pp.488 - 490
NEW QUESTION # 326
......
Network & Communication Security (16%):
- Configuring & Operating Network-Based Security Devices – It evaluates your skills in performing various actions, including the network intrusion detection & prevention systems, traffic-shaping devices, firewalls & proxies, and routers & switches;
- Managing Network Access Controls – It contains the details regarding network access control & monitoring, network access control protocols & standards, and remote access operations & configuration;
- Configuring & Operating Wireless Technologies – This objective covers transmission security and wireless security devices.
- Managing Network Security – This subject area covers one’s knowledge of segmentation, logical & physical network device placement, and secure device management;
SSCP Exam Crack Test Engine Dumps Training With 1305 Questions: https://www.examcost.com/SSCP-practice-exam.html
Obtain the SSCP PDF Dumps Get 100% Outcomes Exam Questions For You To Pass: https://drive.google.com/open?id=190zFEuZCbt3N6ynQ0rWdl7Wmnfvjmu7e

