100% Pass Top-selling SSCP Exams - New 2021 ISC Pratice Exam [Q497-Q513]

Share

100% Pass Top-selling SSCP Exams - New 2021 ISC  Pratice Exam

ISC Certification Dumps SSCP Exam for Full Questions - Exam Study Guide

NEW QUESTION 497
What is the main purpose of Corporate Security Policy?

  • A. To communicate management's intentions in regards to information security
  • B. To provide detailed steps for performing specific actions
  • C. To provide a common framework for all development activities
  • D. To transfer the responsibility for the information security to all users of the organization

Answer: A

Explanation:
Explanation/Reference:
A Corporate Security Policy is a high level document that indicates what are management`s intentions in regard to Information Security within the organization. It is high level in purpose, it does not give you details about specific products that would be use, specific steps, etc..
The organization's requirements for access control should be defined and documented in its security policies. Access rules and rights for each user or group of users should be clearly stated in an access policy statement. The access control policy should minimally consider:
Statements of general security principles and their applicability to the organization Security requirements of individual enterprise applications, systems, and services Consistency between the access control and information classification policies of different systems and networks
Contractual obligations or regulatory compliance regarding protection of assets Standards defining user access profiles for organizational roles
Details regarding the management of the access control system
As a Certified Information System Security Professional (CISSP) you would be involved directly in the drafting and coordination of security policies, standards and supporting guidelines, procedures, and baselines.
Guidance provided by the CISSP for technical security issues, and emerging threats are considered for the adoption of new policies. Activities such as interpretation of government regulations and industry trends and analysis of vendor solutions to include in the security architecture that advances the security of the organization are performed by the CISSP as well.
The following are incorrect answers:
To transfer the responsibility for the information security to all users of the organization is bogus. You CANNOT transfer responsibility, you can only tranfer authority. Responsibility will also sit with upper management. The keyworks ALL and USERS is also an indication that it is the wrong choice.
To provide detailed steps for performing specific actions is also a bogus detractor. A step by step document is referred to as a procedure. It details how to accomplish a specific task.
To provide a common framework for all development activities is also an invalid choice. Security Policies are not restricted only to development activities.
Reference Used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 1551-1565). Auerbach Publications. Kindle Edition.
and
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 9109-9112). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 498
The basic language of modems and dial-up remote access systems is:

  • A. Synchronous Interaction.
  • B. Asynchronous Communication.
  • C. Asynchronous Interaction.
  • D. Synchronous Communication.

Answer: B

Explanation:
Asynchronous Communication is the basic language of modems and dial-up remote access systems.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 100.

 

NEW QUESTION 499
Which of the following media is MOST resistant to tapping?

  • A. microwave.
  • B. twisted pair.
  • C. fiber optic.
  • D. coaxial cable.

Answer: C

Explanation:
Fiber Optic is the most resistant to tapping because Fiber Optic uses a light to transmit the signal. While there are some technologies that will allow to monitor the line passively, it is very difficult to tap into without detection sot this technology would be the MOST resistent to tapping.
The following answers are in correct:
microwave. Is incorrect because microwave transmissions can be intercepted if in the path of the broadcast without detection.
twisted pair. Is incorrect because it is easy to tap into a twisted pair line. coaxial cable. Is incorrect because it is easy to tap into a coaxial cable line.

 

NEW QUESTION 500
Which of the following should be emphasized during the Business Impact Analysis (BIA) considering that the BIA focus is on business processes?

  • A. Priorities
  • B. Service levels
  • C. Composition
  • D. Dependencies

Answer: D

Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
The Business Impact Analysis (BIA) identifies time-critical aspects of the critical business processes, and determines their maximum tolerable downtime. The BIA helps to Identify organization functions, the capabilities of each organization unit to handle outages, and the priority and sequence of functions and applications to be recovered, identify resources required for recovery of those areas and interdependencies In performing the Business Impact Analysis (BIA) it is very important to consider what the dependencies are.
You cannot bring a system up if it depends on another system to be operational. You need to look at not only internal dependencies but external as well. You might not be able to get the raw materials for your business so dependencies are very important aspect of a BIA.
The BIA committee will not truly understand all business processes, the steps that must take place, or the resources and supplies these processes require. So the committee must gather this information from the people who do know- department managers and specific employees throughout the organization. The committee starts by identifying the people who will be part of the BIA data-gathering sessions. The committee needs to identify how it will collect the data from the selected employees, be it through surveys, interviews, or workshops. Next, the team needs to collect the information by actually conducting surveys, interviews, and workshops. Data points obtained as part of the information gathering will be used later during analysis. It is important that the team members ask about how different tasks- whether processes, transactions, or services, along with any relevant dependencies- get accomplished within the organization.
The following answers are incorrect:
composition This is incorrect because it is not the best answer. While the make up of business may be important, if you have not determined the dependencies first you may not be able to bring the critical business processes to a ready state or have the materials on hand that are needed.
priorities This is incorrect because it is not the best answer. While the priorities of processes are important, if you have not determined the dependencies first you may not be able to bring the critical business processes to a ready state or have the materials on hand that are needed.
service levels This is incorrect because it is not the best answer. Service levels are not as important as dependencies.
Reference(s) used for this question:
Schneiter, Andrew (2013-04-15). Official (ISC)2 Guide to the CISSP CBK, Third Edition : Business Continuity and Disaster Recovery Planning (Kindle Locations 188-191). . Kindle Edition.
and
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (Kindle Locations 18562-18568).
McGraw-Hill. Kindle Edition.

 

NEW QUESTION 501
Which of the following service is not provided by a public key infrastructure (PKI)?

  • A. Integrity
  • B. Access control
  • C. Authentication
  • D. Reliability

Answer: D

Explanation:
Explanation/Reference:
A Public Key Infrastructure (PKI) provides confidentiality, access control, integrity, authentication and non- repudiation.
It does not provide reliability services.
Reference(s) used for this question:
TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.

 

NEW QUESTION 502
In biometric identification systems, at the beginning, it was soon apparent that truly positive identification could only be based on :

  • A. voice of a person
  • B. physical attributes of a person
  • C. sex of a person
  • D. age of a person

Answer: B

Explanation:
Section: Access Control
Explanation/Reference:
Today implementation of fast, accurate reliable and user-acceptable biometric identification systems is already under way.
From: TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 1, Page 7.

 

NEW QUESTION 503
Which of the following exemplifies proper separation of duties?

  • A. Operators are not permitted modify the system time.
  • B. Tape operators are permitted to use the system console.
  • C. Console operators are permitted to mount tapes and disks.
  • D. Programmers are permitted to use the system console.

Answer: A

Explanation:
Explanation/Reference:
This is an example of Separation of Duties because operators are prevented from modifying the system time which could lead to fraud. Tasks of this nature should be performed by they system administrators.
AIO defines Separation of Duties as a security principle that splits up a critical task among two or more individuals to ensure that one person cannot complete a risky task by himself.
The following answers are incorrect:
Programmers are permitted to use the system console. Is incorrect because programmers should not be permitted to use the system console, this task should be performed by operators. Allowing programmers access to the system console could allow fraud to occur so this is not an example of Separation of Duties..
Console operators are permitted to mount tapes and disks. Is incorrect because operators should be able to mount tapes and disks so this is not an example of Separation of Duties.
Tape operators are permitted to use the system console. Is incorrect because operators should be able to use the system console so this is not an example of Separation of Duties.
References:
OIG CBK Access Control (page 98 - 101)
AIOv3 Access Control (page 182)

 

NEW QUESTION 504
Which of the following is best defined as a circumstance in which a collection of information items is required to be classified at a higher security level than any of the individual items that comprise it?

  • A. Inference
  • B. Clustering
  • C. Aggregation
  • D. Collision

Answer: C

Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
The Internet Security Glossary (RFC2828) defines aggregation as a circumstance in which a collection of information items is required to be classified at a higher security level than any of the individual items that comprise it.
Source: SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000.

 

NEW QUESTION 505
Communications and network security relates to transmission of which of the following?

  • A. voice, data and multimedia
  • B. voice and multimedia
  • C. data and multimedia
  • D. voice

Answer: B

Explanation:
Section: Network and Telecommunications
Explanation
Explanation/Reference:
From the published (ISC)2 goals for the Certified Information Systems Security Professional candidate:
The CISSP candidate should be familiar to communications and network security as it relates to voice, data, multimedia, and facsimile transmissions in terms of local area, wide area, and remote access.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 57.

 

NEW QUESTION 506
While there are many different models for IT system life cycle, most contain five unique phases.
Which of the following would be the last phase?

  • A. Operation / Maintenance
  • B. Disposal
  • C. Implementation
  • D. Initiation
  • E. Development

Answer: B

Explanation:
The order of implementation is: initiation, development, implementation, operation/maintenance, and disposal.

 

NEW QUESTION 507
A business continuity plan should list and prioritize the services that need to be brought back after a disaster strikes. Which of the following services is more likely to be of primary concern in the context of what your Disaster Recovery Plan would include?

  • A. Marketing/Public relations
  • B. Data/Telecomm/IS facilities
  • C. Facilities security
  • D. IS Operations

Answer: B

Explanation:
The main concern when recovering after a disaster is data, telecomm and IS
facilities. Other services, in descending priority order are: IS operations, IS support
services, market structure, marketing/public relations, customer service & systems support,
market regulation/surveillance, listing, application development, accounting services,
facilities, human resources, facilities security, legal and Office of the Secretary, national
sales.
Source: BARNES, James C. & ROTHSTEIN, Philip J., A Guide to Business Continuity
Planning, John Wiley & Sons, 2001 (page 129).

 

NEW QUESTION 508
What is called a sequence of characters that is usually longer than the allotted number for a password?

  • A. anticipated phrase
  • B. Real phrase
  • C. passphrase
  • D. cognitive phrase

Answer: C

Explanation:
Explanation/Reference:
A passphrase is a sequence of characters that is usually longer than the allotted number for a password.
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, page 37.

 

NEW QUESTION 509
Which of the following can best be defined as a key distribution protocol that uses hybrid encryption to convey session keys. This protocol establishes a long-term key once, and then requires no prior communication in order to establish or exchange keys on a session-by-session basis?

  • A. Internet Security Association and Key Management Protocol (ISAKMP)
  • B. Diffie-Hellman Key Distribution Protocol
  • C. Simple Key-management for Internet Protocols (SKIP)
  • D. IPsec Key exchange (IKE)

Answer: C

Explanation:
RFC 2828 (Internet Security Glossary) defines Simple Key Management for Internet Protocols (SKIP) as:
A key distribution protocol that uses hybrid encryption to convey session keys that are used to encrypt data in IP packets.
SKIP is an hybrid Key distribution protocol similar to SSL, except that it establishes a long-term key once, and then requires no prior communication in order to establish or exchange keys on a session-by-session basis. Therefore, no connection setup overhead exists and new keys values are not continually generated. SKIP uses the knowledge of its own secret key or private component and the destination's public component to calculate a unique key that can only be used between them.
IKE stand for Internet Key Exchange, it makes use of ISAKMP and OAKLEY internally. Internet Key Exchange (IKE or IKEv2) is the protocol used to set up a security association (SA) in the IPsec protocol suite. IKE builds upon the Oakley protocol and ISAKMP. IKE uses X.509 certificates for authentication and a Diffie-Hellman key exchange to set up a shared session secret from which cryptographic keys are derived.
The following are incorrect answers:
ISAKMP is an Internet IPsec protocol to negotiate, establish, modify, and delete security associations, and to exchange key generation and authentication data, independent of the details of any specific key generation technique, key establishment protocol, encryption algorithm, or authentication mechanism.
IKE is an Internet, IPsec, key-establishment protocol (partly based on OAKLEY) that is intended for putting in place authenticated keying material for use with ISAKMP and for other security associations, such as in AH and ESP.
IPsec Key exchange (IKE) is only a detracto.
Reference(s) used for this question:
SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000. and http://en.wikipedia.org/wiki/Simple_Key-Management_for_Internet_Protocol and http://en.wikipedia.org/wiki/Simple_Key-Management_for_Internet_Protocol

 

NEW QUESTION 510
Password management falls into which control category?

  • A. Technical
  • B. Preventive
  • C. Compensating
  • D. Detective

Answer: B

Explanation:
Section: Access Control
Explanation/Reference:
Password management is an example of preventive control.
Proper passwords prevent unauthorized users from accessing a system.
There are literally hundreds of different access approaches, control methods, and technologies, both in the physical world and in the virtual electronic world. Each method addresses a different type of access control or a specific access need.
For example, access control solutions may incorporate identification and authentication mechanisms, filters, rules, rights, logging and monitoring, policy, and a plethora of other controls. However, despite the diversity of access control methods, all access control systems can be categorized into seven primary categories.
The seven main categories of access control are:
1. Directive: Controls designed to specify acceptable rules of behavior within an organization
2. Deterrent: Controls designed to discourage people from violating security directives
3. Preventive: Controls implemented to prevent a security incident or information breach
4. Compensating: Controls implemented to substitute for the loss of primary controls and mitigate risk down to an acceptable level
5. Detective: Controls designed to signal a warning when a security control has been breached
6. Corrective: Controls implemented to remedy circumstance, mitigate damage, or restore controls
7. Recovery: Controls implemented to restore conditions to normal after a security incident Reference(s) used for this question:
Hernandez CISSP, Steven (2012-12-21). Official (ISC)2 Guide to the CISSP CBK, Third Edition ((ISC)2 Press) (Kindle Locations 1156-1176). Auerbach Publications. Kindle Edition.

 

NEW QUESTION 511
Which access control model is best suited in an environment where a high security level is required and where it is desired that only the administrator grants access control?

  • A. TACACS
  • B. DAC
  • C. MAC
  • D. Access control matrix

Answer: C

Explanation:
Explanation/Reference:
MAC provides high security by regulating access based on the clearance of individual users and sensitivity labels for each object. Clearance levels and sensitivity levels cannot be modified by individual users -- for example, user Joe (SECRET clearance) cannot reclassify the "Presidential Doughnut Recipe" from
"SECRET" to "CONFIDENTIAL" so that his friend Jane (CONFIDENTIAL clearance) can read it. The administrator is ultimately responsible for configuring this protection in accordance with security policy and directives from the Data Owner.
DAC is incorrect. In DAC, the data owner is responsible for controlling access to the object.
Access control matrix is incorrect. The access control matrix is a way of thinking about the access control needed by a population of subjects to a population of objects. This access control can be applied using rules, ACL's, capability tables, etc.
TACACS is incorrect. TACACS is a tool for performing user authentication.
References:
CBK, p. 187, Domain 2: Access Control.
AIO3, Chapter 4, Access Control.

 

NEW QUESTION 512
Related to information security, availability is the opposite of which of the following?

  • A. destruction
  • B. documentation
  • C. distribution
  • D. delegation

Answer: A

Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
Availability is the opposite of "destruction."
Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 59.

 

NEW QUESTION 513
......

Authentic Best resources for SSCP Online Practice Exam: https://www.testpassed.com/SSCP-still-valid-exam.html

SSCP Test Engine Practice Exam: https://drive.google.com/open?id=1FXj5HqhuJeYYqg-4D9fPkTl3qkeAbV1M