[Dec 18, 2021] Get New SSCP Certification Practice Test Questions Exam Dumps [Q55-Q79]

Share

[Dec 18, 2021] Get New SSCP Certification Practice Test Questions Exam Dumps

Real SSCP Exam Dumps Questions Valid SSCP Dumps PDF


Who should take the exam

if you have the following prerequisite and required skills then you should take this exam for getting System Security Certified Practitioner (SSCP) certificate.

  • A 1-year prerequisite pathway will be granted for candidates who received a degree (bachelors or masters) in a cybersecurity program.
  • Minimum of 1-year cumulative work experience in 1 or more of the 7 domains of the SSCP CBK

ISC2 SSCP Exam Certification Details:

Sample QuestionsISC2 SSCP Sample Questions
Exam Price$249 (USD)
Passing Score700/1000
Schedule ExamPearson VUE
Number of Questions125

 

NEW QUESTION 55
Which of the following statements pertaining to RADIUS is incorrect:

  • A. A RADIUS server can act as a proxy server, forwarding client requests to other authentication domains.
  • B. Most RADIUS servers can work with DIAMETER servers.
  • C. Most of RADIUS clients have a capability to query secondary RADIUS servers for redundancy.
  • D. Most RADIUS servers have built-in database connectivity for billing and reporting purposes.

Answer: B

Explanation:
Section: Access Control
Explanation/Reference:
This is the correct answer because it is FALSE.
Diameter is an AAA protocol, AAA stands for authentication, authorization and accounting protocol for computer networks, and it is a successor to RADIUS.
The name is a pun on the RADIUS protocol, which is the predecessor (a diameter is twice the radius).
The main differences are as follows:
Reliable transport protocols (TCP or SCTP, not UDP)
The IETF is in the process of standardizing TCP Transport for RADIUS
Network or transport layer security (IPsec or TLS)
The IETF is in the process of standardizing Transport Layer Security for RADIUS Transition support for RADIUS, although Diameter is not fully compatible with RADIUS Larger address space for attribute-value pairs (AVPs) and identifiers (32 bits instead of 8 bits) Client-server protocol, with exception of supporting some server-initiated messages as well Both stateful and stateless models can be used Dynamic discovery of peers (using DNS SRV and NAPTR) Capability negotiation Supports application layer acknowledgements, defines failover methods and state machines (RFC 3539) Error notification Better roaming support More easily extended; new commands and attributes can be defined Aligned on 32-bit boundaries Basic support for user-sessions and accounting A Diameter Application is not a software application, but a protocol based on the Diameter base protocol (defined in RFC 3588). Each application is defined by an application identifier and can add new command codes and/or new mandatory AVPs. Adding a new optional AVP does not require a new application.
Examples of Diameter applications:
Diameter Mobile IPv4 Application (MobileIP, RFC 4004)
Diameter Network Access Server Application (NASREQ, RFC 4005)
Diameter Extensible Authentication Protocol (EAP) Application (RFC 4072) Diameter Credit-Control Application (DCCA, RFC 4006) Diameter Session Initiation Protocol Application (RFC 4740) Various applications in the 3GPP IP Multimedia Subsystem All of the other choices presented are true. So Diameter is backwork compatible with Radius (to some extent) but the opposite is false.
Reference(s) used for this question:
TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 2,
2001, CRC Press, NY, Page 38.
and
https://secure.wikimedia.org/wikipedia/en/wiki/Diameter_%28protocol%29

 

NEW QUESTION 56
Which of the following is an issue with signature-based intrusion detection systems?

  • A. Signature databases must be augmented with inferential elements.
  • B. Hackers can circumvent signature evaluations.
  • C. Only previously identified attack signatures are detected.
  • D. It runs only on the windows operating system

Answer: C

Explanation:
Explanation/Reference:
An issue with signature-based ID is that only attack signatures that are stored in their database are detected.
New attacks without a signature would not be reported. They do require constant updates in order to maintain their effectiveness.
Reference used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 49.

 

NEW QUESTION 57
CORRECT TEXT
A ___________ is a signal sent from a receiving machine to another host asking it to slow down the rate at which it is sending information.

Answer:

Explanation:
Quench

 

NEW QUESTION 58
Which of the following refers to the data left on the media after the media has been erased?

  • A. semi-hidden
  • B. recovery
  • C. remanence
  • D. sticky bits

Answer: C

Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
Actually the term "remanence" comes from electromagnetism, the study of the electromagnetics. Originally referred to (and still does in that field of study) the magnetic flux that remains in a magnetic circuit after an applied magnetomotive force has been removed. Absolutely no way a candidate will see anywhere near that much detail on any similar CISSP question, but having read this, a candidate won't be likely to forget it either.
It is becoming increasingly commonplace for people to buy used computer equipment, such as a hard drive, or router, and find information on the device left there by the previous owner; information they thought had been deleted. This is a classic example of data remanence: the remains of partial or even the entire data set of digital information. Normally, this refers to the data that remain on media after they are written over or degaussed. Data remanence is most common in storage systems but can also occur in memory.
Specialized hardware devices known as degaussers can be used to erase data saved to magnetic media. The measure of the amount of energy needed to reduce the magnetic field on the media to zero is known as coercivity.
It is important to make sure that the coercivity of the degausser is of sufficient strength to meet object reuse requirements when erasing data. If a degausser is used with insufficient coercivity, then a remanence of the data will exist. Remanence is the measure of the existing magnetic field on the media; it is the residue that remains after an object is degaussed or written over.
Data is still recoverable even when the remanence is small. While data remanence exists, there is no assurance of safe object reuse.
Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 4207-4210). Auerbach Publications. Kindle Edition.
and
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 19694-19699). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 59
___________________ is ultimately responsible for security and privacy violations.

  • A. OS Software
  • B. Security Officer
  • C. CIO / CEO
  • D. Person committing the violation

Answer: C

 

NEW QUESTION 60
Which of the following computer recovery sites is the least expensive and the most difficult to test?

  • A. non-mobile hot site
  • B. cold site
  • C. warm site
  • D. mobile hot site

Answer: B

Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
Is the least expensive because it is basically a structure with power and would be the most difficult to test because you would have to install all of the hardware infrastructure in order for it to be operational for the test.
The following answers are incorrect:
non-mobile hot site. Is incorrect because it is more expensive then a cold site and easier to test because all of the infrastructure is in place.
mobile hot site. Is incorrect because it is more expensive then a cold site and easier to test because all of the infrastructure is in place.
warm site. Is incorrect because it is more expensive then a cold site and easier to test because more of the infrastructure is in place.

 

NEW QUESTION 61
Which communication method is characterized by very high speed transmission rates that are governed by electronic clock timing signals?

  • A. Asynchronous Communication.
  • B. Synchronous Communication.
  • C. Full duplex Communication.
  • D. Automatic Communication.

Answer: B

Explanation:
Synchronous Communication is characterized by very high speed transmission rates that are governed by electronic clock timing signals. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 100

 

NEW QUESTION 62
The primary purpose for using one-way hashing of user passwords within a password file is which of the following?

  • A. It minimizes the amount of processing time used for encrypting passwords.
  • B. It prevents an unauthorized person from reading the password.
  • C. It prevents an unauthorized person from trying multiple passwords in one logon attempt.
  • D. It minimizes the amount of storage required for user passwords.

Answer: B

Explanation:
The whole idea behind a one-way hash is that it should be just that - one-way. In other words, an attacker should not be able to figure out your password from the hashed version of that password in any mathematically feasible way (or within any reasonable length of time).
Password Hashing and Encryption In most situations , if an attacker sniffs your password from the network wire, she still has some work to do before she actually knows your password value because most systems hash the password with a hashing algorithm, commonly MD4 or MD5, to ensure passwords are not sent in cleartext.
Although some people think the world is run by Microsoft, other types of operating systems
are out there, such as Unix and Linux. These systems do not use registries and SAM
databases, but contain their user passwords in a file cleverly called "shadow." Now, this
shadow file does not contain passwords in cleartext; instead, your password is run through
a hashing algorithm, and the resulting value is stored in this file.
Unixtype systems zest things up by using salts in this process. Salts are random values
added to the encryption process to add more complexity and randomness. The more
randomness entered into the encryption process, the harder it is for the bad guy to decrypt
and uncover your password. The use of a salt means that the same password can be
encrypted into several thousand different formats. This makes it much more difficult for an
attacker to uncover the right format for your system.
Password Cracking tools
Note that the use of one-way hashes for passwords does not prevent password crackers
from guessing passwords. A password cracker runs a plain-text string through the same
one-way hash algorithm used by the system to generate a hash, then compares that
generated has with the one stored on the system. If they match, the password cracker has
guessed your password.
This is very much the same process used to authenticate you to a system via a password.
When you type your username and password, the system hashes the password you typed
and compares that generated hash against the one stored on the system - if they match,
you are authenticated.
Pre-Computed password tables exists today and they allow you to crack passwords on Lan
Manager (LM) within a VERY short period of time through the use of Rainbow Tables. A
Rainbow Table is a precomputed table for reversing cryptographic hash functions, usually
for cracking password hashes. Tables are usually used in recovering a plaintext password
up to a certain length consisting of a limited set of characters. It is a practical example of a
space/time trade-off also called a Time-Memory trade off, using more computer processing
time at the cost of less storage when calculating a hash on every attempt, or less
processing time and more storage when compared to a simple lookup table with one entry
per hash. Use of a key derivation function that employs a salt makes this attack unfeasible.
You may want to review "Rainbow Tables" at the links:
http://en.wikipedia.org/wiki/Rainbow_table
http://www.antsight.com/zsl/rainbowcrack/
Today's password crackers:
Meet oclHashcat. They are GPGPU-based multi-hash cracker using a brute-force attack
(implemented as mask attack), combinator attack, dictionary attack, hybrid attack, mask
attack, and rule-based attack.
This GPU cracker is a fusioned version of oclHashcat-plus and oclHashcat-lite, both very
well-known suites at that time, but now deprecated. There also existed a now very old
oclHashcat GPU cracker that was replaced w/ plus and lite, which - as said - were then
merged into oclHashcat 1.00 again.
This cracker can crack Hashes of NTLM Version 2 up to 8 characters in less than a few
hours. It is definitively a game changer. It can try hundreds of billions of tries per seconds
on a very large cluster of GPU's. It supports up to 128 Video Cards at once.
I am stuck using Password what can I do to better protect myself?
You could look at safer alternative such as Bcrypt, PBKDF2, and Scrypt.
bcrypt is a key derivation function for passwords designed by Niels Provos and David
Mazieres, based on the Blowfish cipher, and presented at USENIX in 1999. Besides
incorporating a salt to protect against rainbow table attacks, bcrypt is an adaptive function:
over time, the iteration count can be increased to make it slower, so it remains resistant to
brute-force search attacks even with increasing computation power.
In cryptography, scrypt is a password-based key derivation function created by Colin
Percival, originally for the Tarsnap online backup service. The algorithm was specifically
designed to make it costly to perform large-scale custom hardware attacks by requiring
large amounts of memory. In 2012, the scrypt algorithm was published by the IETF as an
Internet Draft, intended to become an informational RFC, which has since expired. A
simplified version of scrypt is used as a proof-of-work scheme by a number of
cryptocurrencies, such as Litecoin and Dogecoin.
PBKDF2 (Password-Based Key Derivation Function 2) is a key derivation function that is
part of RSA Laboratories' Public-Key Cryptography Standards (PKCS) series, specifically
PKCS #5 v2.0, also published as Internet Engineering Task Force's RFC 2898. It replaces
an earlier standard, PBKDF1, which could only produce derived keys up to 160 bits long.
PBKDF2 applies a pseudorandom function, such as a cryptographic hash, cipher, or HMAC
to the input password or passphrase along with a salt value and repeats the process many
times to produce a derived key, which can then be used as a cryptographic key in
subsequent operations. The added computational work makes password cracking much
more difficult, and is known as key stretching. When the standard was written in 2000, the
recommended minimum number of iterations was 1000, but the parameter is intended to be increased over time as CPU speeds increase. Having a salt added to the password reduces the ability to use precomputed hashes (rainbow tables) for attacks, and means that multiple passwords have to be tested individually, not all at once. The standard recommends a salt length of at least 64 bits.
The other answers are incorrect:
"It prevents an unauthorized person from trying multiple passwords in one logon attempt." is incorrect because the fact that a password has been hashed does not prevent this type of brute force password guessing attempt.
"It minimizes the amount of storage required for user passwords" is incorrect because hash algorithms always generate the same number of bits, regardless of the length of the input. Therefore, even short passwords will still result in a longer hash and not minimize storage requirements.
"It minimizes the amount of processing time used for encrypting passwords" is incorrect because the processing time to encrypt a password would be basically the same required to produce a one-way has of the same password.
Reference(s) used for this question:
http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/Scrypt http://en.wikipedia.org/wiki/Bcrypt Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 195) . McGraw-Hill. Kindle Edition.

 

NEW QUESTION 63
Risk reduction in a system development life-cycle should be applied:

  • A. Mostly to the disposal phase.
  • B. Mostly to the development phase.
  • C. Equally to all phases.
  • D. Mostly to the initiation phase.

Answer: C

Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
Risk is defined as the combination of the probability that a particular threat source will exploit, or trigger, a particular information system vulnerability and the resulting mission impact should this occur. Previously, risk avoidance was a common IT security goal. That changed as the nature of the risk became better understood.
Today, it is recognized that elimination of all risk is not cost-effective. A cost-benefit analysis should be conducted for each proposed control. In some cases, the benefits of a more secure system may not justify the direct and indirect costs. Benefits include more than just prevention of monetary loss; for example, controls may be essential for maintaining public trust and confidence. Direct costs include the cost of purchasing and installing a given technology; indirect costs include decreased system performance and additional training. The goal is to enhance mission/business capabilities by managing mission/business risk to an acceptable level.
Source: STONEBURNER, Gary & al, National Institute of Standards and Technology (NIST), NIST Special Publication 800-27, Engineering Principles for Information Technology Security (A Baseline for Achieving Security), June 2001 (page 8).

 

NEW QUESTION 64
You have been tasked to develop an effective information classification program. Which one of the following steps should be performed first?

  • A. Identify the data custodian who will be responsible for maintaining the security level of data
  • B. Specify the criteria that will determine how data is classified
  • C. Specify the security controls required for each classification level
  • D. Establish procedures for periodically reviewing the classification and ownership

Answer: B

Explanation:
According to the AIO 3rd edition, these are the necessary steps for a proper classification program:
1.Define classification levels.
2.Specify the criteria that will determine how data is classified.
3.Have the data owner indicate the classification of the data she is responsible for.
4.Identify the data custodian who will be responsible for maintaining data and its security level.
5.Indicate the security controls, or protection mechanisms, that are required for each classification level.
6.Document any exceptions to the previous classification issues.
7.Indicate the methods that can be used to transfer custody of the information to a different data owner.
8.Create a procedure to periodically review the classification and ownership. Communicate any changes to the data custodian.
9.Indicate termination procedures for declassifying the data.
10.
Integrate these issues into the security-awareness program so that all employees understand how to handle data at different classification levels.
Domain: Information security and risk management
Reference: AIO 3rd edition page 50

 

NEW QUESTION 65
Which of the following best ensures accountability of users for the actions taken within a system or domain?

  • A. Authorization
  • B. Identification
  • C. Authentication
  • D. Credentials

Answer: C

Explanation:
Details:
The only way to ensure accountability is if the subject is uniquely identified and
authenticated. Identification alone does not provide proof the user is who they claim to be.
After showing proper credentials, a user is authorized access to resources.
References:
HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002,
Chapter 4: Access Control (page 126).

 

NEW QUESTION 66
When a biometric system is used, which error type deals with the possibility of GRANTING access to impostors who should be REJECTED?

  • A. Type II error
  • B. Type III error
  • C. Crossover error
  • D. Type I error

Answer: A

Explanation:
Section: Access Control
Explanation/Reference:
When the biometric system accepts impostors who should have been rejected , it is called a Type II error or False Acceptance Rate or False Accept Rate.
Biometrics verifies an individual's identity by analyzing a unique personal attribute or behavior, which is one of the most effective and accurate methods of verifying identification.
Biometrics is a very sophisticated technology; thus, it is much more expensive and complex than the other types of identity verification processes. A biometric system can make authentication decisions based on an individual's behavior, as in signature dynamics, but these can change over time and possibly be forged.
Biometric systems that base authentication decisions on physical attributes (iris, retina, fingerprint) provide more accuracy, because physical attributes typically don't change much, absent some disfiguring injury, and are harder to impersonate.
When a biometric system rejects an authorized individual, it is called a Type I error (False Rejection Rate (FRR) or False Reject Rate (FRR)).
When the system accepts impostors who should be rejected, it is called a Type II error (False Acceptance Rate (FAR) or False Accept Rate (FAR)). Type II errors are the most dangerous and thus the most important to avoid.
The goal is to obtain low numbers for each type of error, but When comparing different biometric systems, many different variables are used, but one of the most important metrics is the crossover error rate (CER).
The accuracy of any biometric method is measured in terms of Failed Acceptance Rate (FAR) and Failed Rejection Rate (FRR). Both are expressed as percentages. The FAR is the rate at which attempts by unauthorized users are incorrectly accepted as valid. The FRR is just the opposite. It measures the rate at which authorized users are denied access.
The relationship between FRR (Type I) and FAR (Type II) is depicted in the graphic below . As one rate increases, the other decreases. The Cross-over Error Rate (CER) is sometimes considered a good indicator of the overall accuracy of a biometric system. This is the point at which the FRR and the FAR have the same value. Solutions with a lower CER are typically more accurate.
See graphic below from Biometria showing this relationship. The Cross-over Error Rate (CER) is also called the Equal Error Rate (EER), the two are synonymous.

Cross Over Error Rate
The other answers are incorrect:
Type I error is also called as False Rejection Rate where a valid user is rejected by the system.
Type III error : there is no such error type in biometric system.
Crossover error rate stated in percentage , represents the point at which false rejection equals the false acceptance rate.
Reference(s) used for this question:
http://www.biometria.sk/en/principles-of-biometrics.html
and
Shon Harris, CISSP All In One (AIO), 6th Edition , Chapter 3, Access Control, Page 188-189 and Tech Republic, Reduce Multi_Factor Authentication Cost

 

NEW QUESTION 67
Which of the following computer design approaches is based on the fact that in earlier technologies, the instruction fetch was the longest part of the cycle?

  • A. Scalar processors
  • B. Complex Instruction Set Computers (CISC)
  • C. Reduced Instruction Set Computers (RISC)
  • D. Pipelining

Answer: B

Explanation:
Explanation/Reference:
Complex Instruction Set Computer (CISC) uses instructions that perform many operations per instruction.
It was based on the fact that in earlier technologies, the instruction fetch was the longest part of the cycle.
Therefore, by packing more operations into an instruction, the number of fetches could be reduced.
Pipelining involves overlapping the steps of different instructions to increase the performance in a computer. Reduced Instruction Set Computers (RISC) involve simpler instructions that require fewer clock cycles to execute. Scalar processors are processors that execute one instruction at a time.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 5: Security Architectures and Models (page 188).

 

NEW QUESTION 68
Who is responsible for providing reports to the senior management on the effectiveness of the security controls?

  • A. Data owners
  • B. Data custodians
  • C. Information systems auditors
  • D. Information systems security professionals

Answer: C

Explanation:
IT auditors determine whether systems are in compliance with the security policies, procedures, standards, baselines, designs, architectures, management direction and other requirements" and "provide top company management with an independent view of the controls that have been designed and their effectiveness."
"Information systems security professionals" is incorrect. Security professionals develop the security policies and supporting baselines, etc.
"Data owners" is incorrect. Data owners have overall responsibility for information assets and assign the appropriate classification for the asset as well as ensure that the asset is protected with the proper controls.
"Data custodians" is incorrect. Data custodians care for an information asset on behalf of the data owner.
References:
CBK, pp. 38 - 42. AIO3. pp. 99 - 104

 

NEW QUESTION 69
What is called a system that is capable of detecting that a fault has occurred and has the ability to correct the fault or operate around it?

  • A. A fail soft system
  • B. A fault-tolerant system
  • C. A fail safe system
  • D. A failover system

Answer: B

Explanation:
Explanation/Reference:
A fault-tolerant system is capable of detecting that a fault has occurred and has the ability to correct the fault or operate around it. In a fail-safe system, program execution is terminated, and the system is protected from being compromised when a hardware or software failure occurs and is detected. In a fail- soft system, when a hardware or software failure occurs and is detected, selected, non-critical processing is terminated. The term failover refers to switching to a duplicate "hot" backup component in real-time when a hardware or software failure occurs, enabling processing to continue.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 5: Security Architecture and Models (page 196).

 

NEW QUESTION 70
Which of the following is NOT a common backup method?

  • A. Daily backup method
  • B. Incremental backup method
  • C. Differential backup method
  • D. Full backup method

Answer: A

Explanation:
Explanation/Reference:
A daily backup is not a backup method, but defines periodicity at which backups are made. There can be daily full, incremental or differential backups.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page
69).

 

NEW QUESTION 71
Application Layer Firewalls operate at the:

  • A. OSI protocol Layer seven, the Application Layer.
  • B. OSI protocol Layer four, the Transport Layer.
  • C. OSI protocol Layer five, the Session Layer.
  • D. OSI protocol Layer six, the Presentation Layer.

Answer: A

Explanation:
Since the application layer firewall makes decisions based on application-layer information in the packet, it operates at the application layer of the OSI stack.
"OSI protocol layer 6, the presentation layer" is incorrect. The application layer firewall must have access to the application layer information in the packet and therefore operates at the application layer.
"OSI protocol layer 5, the session layer" is incorrect. The application layer firewall must have access to the application layer information in the packet and therefore operates at the application layer.
"OSI protocol layer 4, the transport layer" is incorrect. The application layer firewall must have access to the application layer information in the packet and therefore operates at the application layer.
References:
CBK, p. 467 AIO3, pp.488 - 490

 

NEW QUESTION 72
Which of the following control pairings include: organizational policies and procedures, pre-employment background checks, strict hiring practices, employment agreements, employee termination procedures, vacation scheduling, labeling of sensitive materials, increased supervision, security awareness training, behavior awareness, and sign-up procedures to obtain access to information systems and networks?

  • A. Preventive/Technical Pairing
  • B. Preventive/Administrative Pairing
  • C. Preventive/Physical Pairing
  • D. Detective/Administrative Pairing

Answer: B

Explanation:
Section: Access Control
Explanation/Reference:
The Answer: Preventive/Administrative Pairing: These mechanisms include organizational policies and procedures, pre-employment background checks, strict hiring practices, employment agreements, friendly and unfriendly employee termination procedures, vacation scheduling, labeling of sensitive materials, increased supervision, security awareness training, behavior awareness, and sign-up procedures to obtain access to information systems and networks.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 34.

 

NEW QUESTION 73
In the statement below, fill in the blank:
Law enforcement agencies must get a warrant to search and seize an individual's property, as stated in the
_____ Amendment.

  • A. Third.
  • B. Second.
  • C. Fourth.
  • D. First.

Answer: C

Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
The Fourth Amendment does not apply to a seizure or an arrest by private citizens.
Search and seizure activities can get tricky depending on what is being searched for and where.
For example, American citizens are protected by the Fourth Amendment against unlawful search and seizure, so law enforcement agencies must have probable cause and request a search warrant from a judge or court before conducting such a search.
The actual search can only take place in the areas outlined by the warrant. The Fourth Amendment does not apply to actions by private citizens unless they are acting as police agents. So, for example, if Kristy's boss warned all employees that the management could remove files from their computers at any time, and her boss was not a police officer or acting as a police agent, she could not successfully claim that her Fourth Amendment rights were violated. Kristy's boss may have violated some specific privacy laws, but he did not violate Kristy's Fourth Amendment rights.
In some circumstances, a law enforcement agent may seize evidence that is not included in the warrant, such as if the suspect tries to destroy the evidence. In other words, if there is an impending possibility that evidence might be destroyed, law enforcement may quickly seize the evidence to prevent its destruction. This is referred to as exigent circumstances, and a judge will later decide whether the seizure was proper and legal before allowing the evidence to be admitted. For example, if a police officer had a search warrant that allowed him to search a suspect's living room but no other rooms, and then he saw the suspect dumping cocaine down the toilet, the police officer could seize the cocaine even though it was in a room not covered under his search warrant. After evidence is gathered, the chain of custody needs to be enacted and enforced to make sure the evidence's integrity is not compromised.
All other choices were only detractors.
Reference(s) used for this question:
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (p. 1057). McGraw-Hill. Kindle Edition.

 

NEW QUESTION 74
The Terminal Access Controller Access Control System (TACACS) employs which of the following?

  • A. a user ID and symmetric password for network access
  • B. a user ID and static password for network access
  • C. a user ID and asymmetric password for network access
  • D. a user ID and dynamic password for network access

Answer: B

Explanation:
For networked applications, the Terminal Access Controller Access Control System (TACACS) employs a user ID and a static password for network access.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 44.

 

NEW QUESTION 75
Which of the following statements pertaining to firewalls is incorrect?

  • A. Firewalls create bottlenecks between the internal and external network.
  • B. Firewalls are used to create security checkpoints at the boundaries of private networks.
  • C. Firewalls protect a network at all layers of the OSI models.
  • D. Firewalls allow for centralization of security services in machines optimized and dedicated to the task.

Answer: C

Explanation:
Explanation/Reference:
Firewalls can protect a network at multiple layers of the OSI models, however most of the firewalls do not have the ability to monitor the payload of the packets and see if an application level attack is taking place.
Today there are a new breed of firewall called Unified Threat Managers or UTM. They are a collection of products on a single computer and not necessarily a typical firewall. A UTM can address all of the layers but typically a firewall cannot.
Firewalls are security checkpoints at the boundaries of internal networks through which every packet must pass and be inspected, hence they create bottlenecks between the internal and external networks. But since external connections are relatively slow compared to modern computers, the latency caused by this bottleneck can almost be transparent.
By implementing the concept of border security, they centralize security services in machines optimized and dedicated to the task, thus relieving the other hosts on the network from that function.
Source: STREBE, Matthew and PERKINS, Charles, Firewalls 24seven, Sybex 2000, Chapter 1:
Understanding Firewalls.

 

NEW QUESTION 76
What security model implies a central authority that define rules and sometimes global rules, dictating what subjects can have access to what objects?

  • A. Non-discretionary access control
  • B. Mandatory access control
  • C. Discretionary access control
  • D. Flow Model

Answer: A

Explanation:
Section: Access Control
Explanation/Reference:
As a security administrator you might configure user profiles so that users cannot change the system's time, alter system configuration files, access a command prompt, or install unapproved applications. This type of access control is referred to as nondiscretionary, meaning that access decisions are not made at the discretion of the user. Nondiscretionary access controls are put into place by an authoritative entity (usually a security administrator) with the goal of protecting the organization's most critical assets.
Non-discretionary access control is when a central authority determines what subjects can have access to what objects based on the organizational security policy. Centralized access control is not an existing security model.
Both, Rule Based Access Control (RuBAC or RBAC) and Role Based Access Controls (RBAC) falls into this category.
Reference(s) used for this question:
Harris, Shon (2012-10-18). CISSP All-in-One Exam Guide, 6th Edition (p. 221). McGraw-Hill. Kindle Edition.
and
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems (page 33).

 

NEW QUESTION 77
Which is NOT a suitable method for distributing certificate revocation information?

  • A. CA revocation mailing list
  • B. Distribution point CRL
  • C. OCSP (online certificate status protocol)
  • D. Delta CRL

Answer: A

Explanation:
The following are incorrect answers because they are all suitable methods.
A Delta CRL is a CRL that only provides information about certificates whose statuses have changed since the issuance of a specific, previously issued CRL.
The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate.
A Distribution point CRL or CRL Distribution Point, a location specified in the CRL Distribution Point (CRL DP) X.509, version 3, certificate extension when the certificate is issued.
References:
RFC 2459: Internet X.509 Public Key Infrastru http://csrc.nist.gov/groups/ST/crypto_apps_infra/documents/sliding_window.pdf http://www.ipswitch.eu/online_certificate_status_protocol_en.html Computer Security Handbook By Seymour Bosworth, Arthur E. Hutt, Michel E. Kabay http://books.google.com/books?id=rCx5OfSFUPkC&printsec=frontcover&dq=Computer+Se curity+Handbook#PRA6-PA4,M1

 

NEW QUESTION 78
Which of the following questions is less likely to help in assessing physical and environmental protection?

  • A. Are entry codes changed periodically?
  • B. Are appropriate fire suppression and prevention devices installed and working?
  • C. Is physical access to data transmission lines controlled?
  • D. Are there processes to ensure that unauthorized individuals cannot read, copy, alter, or steal printed or electronic information?

Answer: D

Explanation:
Explanation/Reference:
Physical security and environmental security are part of operational controls, and are measures taken to protect systems, buildings, and related supporting infrastructures against threats associated with their physical environment. All the questions above are useful in assessing physical and environmental protection except for the one regarding processes that ensuring that unauthorized individuals cannot access information, which is more a production control.
Source: SWANSON, Marianne, NIST Special Publication 800-26, Security Self-Assessment Guide for Information Technology Systems, November 2001 (Pages A-21 to A-24).

 

NEW QUESTION 79
......

SSCP Exam Dumps - PDF Questions and Testing Engine: https://quizmaterials.dumpsreview.com/SSCP-exam-dumps-review.html