
Latest [Jul 23, 2023] 100% Passing Guarantee - Brilliant SSCP Exam Questions PDF
SSCP Certification – Valid Exam Dumps Questions Study Guide! (Updated 1074 Questions)
NEW QUESTION # 183
Single Sign-on (SSO) is characterized by which of the following advantages?
- A. Convenience and centralized network administration
- B. Convenience and centralized data administration
- C. Convenience
- D. Convenience and centralized administration
Answer: D
Explanation:
Convenience -Using single sign-on users have to type their passwords only once when they first log in to access all the network resources; and Centralized Administration as some single sign-on systems are built around a unified server administration system. This allows a single administrator to add and delete accounts across the entire network from one user interface.
The following answers are incorrect:
Convenience - alone this is not the correct answer.
Centralized Data or Network Administration - these are thrown in to mislead the student. Neither are a benefit to SSO, as these specifically should not be allowed with just an SSO.
References: TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 1, page 35. TIPTON, Harold F. & HENRY, Kevin, Official (ISC)2 Guide to the CISSP CBK, 2007, page
180.
NEW QUESTION # 184
Which of the following is NOT a symmetric key algorithm?
- A. Digital Signature Standard (DSS)
- B. Triple DES (3DES)
- C. Blowfish
- D. RC5
Answer: A
Explanation:
Digital Signature Standard (DSS) specifies a Digital Signature Algorithm (DSA) appropriate for applications requiring a digital signature, providing the capability to generate signatures (with the use of a private key) and verify them (with the use of the corresponding public key). Source: HARRIS, Shon, All-In-One CISSP Certification Exam Guide, McGraw-Hill/Osborne, 2002, chapter 8: Cryptography (page 550).
Reference: DSS: http://www.itl.nist.gov/fipspubs/fip186.htm.
NEW QUESTION # 185
Which of the following is NOT a correct notation for an IPv6 address?
- A. 2001:0db8:0:0:0:0:1428:57ab
- B. ABCD:EF01:2345:6789:ABCD:EF01:2345:6789
- C. ::1
- D. 2001:DB8::8:800::417A
Answer: D
Explanation:
Explanation/Reference:
This is not a correct notation for an IPv6 address because the the "::" can only appear once in an address.
The use of "::" is a shortcut notation that indicates one or more groups of 16 bits of zeros.
::1 is the loopback address using the special notation
Reference: IP Version 6 Addressing Architecture
http://tools.ietf.org/html/rfc4291#section-2.1
NEW QUESTION # 186
Which of the following statements pertaining to ethical hacking is incorrect?
- A. Ethical hacking should not involve writing to or modifying the target systems negatively.
- B. Ethical hackers never use tools that have the potential of affecting servers or services.
- C. An organization should use ethical hackers who do not sell auditing, hardware, software, firewall, hosting, and/or networking services.
- D. Testing should be done remotely to simulate external threats.
Answer: B
Explanation:
This means that many of the tools used for ethical hacking have the potential of exploiting vulnerabilities and causing disruption to IT system. It is up to the individuals performing the tests to be familiar with their use and to make sure that no such disruption can happen or at least shoudl be avoided.
The first step before sending even one single packet to the target would be to have a signed agreement with clear rules of engagement and a signed contract. The signed contract explains to the client the associated risks and the client must agree to them before you even send one packet to the target range. This way the client understand that some of
the test could lead to interruption of service or even crash a server. The client signs that he
is aware of such risks and willing to accept them.
The following are incorrect answers:
An organization should use ethical hackers who do not sell auditing, hardware, software,
firewall, hosting, and/or networking services. An ethical hacking firm's independence can
be questioned if they sell security solutions at the same time as doing testing for the same
client. There has to be independance between the judge (the tester) and the accuse (the
client).
Testing should be done remotely to simulate external threats Testing simulating a cracker
from the Internet is often time one of the first test being done, this is to validate perimeter
security. By performing tests remotely, the ethical hacking firm emulates the hacker's
approach more realistically.
Ethical hacking should not involve writing to or modifying the target systems negatively.
Even though ethical hacking should not involve negligence in writing to or modifying the
target systems or reducing its response time, comprehensive penetration testing has to be
performed using the most complete tools available just like a real cracker would.
Reference(s) used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten
Domains of Computer Security, John Wiley & Sons, 2001, Appendix F: The Case for
Ethical Hacking (page 520).
NEW QUESTION # 187
In regards to information classification what is the main responsibility of information (data) owner?
- A. audit the data users
- B. periodically check the validity and accuracy of the data
- C. determining the data sensitivity or classification level
- D. running regular data backups
Answer: C
Explanation:
Section: Access Control
Explanation/Reference:
Making the determination to decide what level of classification the information requires is the main responsibility of the data owner.
The data owner within classification is a person from Management who has been entrusted with a data set that belong to the company. It could be for example the Chief Financial Officer (CFO) who has been entrusted with all financial date or it could be the Human Resource Director who has been entrusted with all Human Resource data. The information owner will decide what classification will be applied to the data based on Confidentiality, Integrity, Availability, Criticality, and Sensitivity of the data.
The Custodian is the technical person who will implement the proper classification on objects in accordance with the Data Owner. The custodian DOES NOT decide what classification to apply, it is the Data Owner who will dictate to the Custodian what is the classification to apply.
NOTE:
The term Data Owner is also used within Discretionary Access Control (DAC). Within DAC it means the person who has created an object. For example, if I create a file on my system then I am the owner of the file and I can decide who else could get access to the file. It is left to my discretion. Within DAC access is granted based solely on the Identity of the subject, this is why sometimes DAC is referred to as Identity Based Access Control.
The other choices were not the best answer
Running regular backups is the responsibility of custodian.
Audit the data users is the responsibility of the auditors
Periodically check the validity and accuracy of the data is not one of the data owner responsibility Reference(s) used for this question:
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Page 14, Chapter 1: Security Management Practices.
NEW QUESTION # 188
Which of the following is NOT a technical control?
- A. Monitoring for physical intrusion
- B. Intrusion Detection Systems
- C. Identification and authentication methods
- D. Password and resource management
Answer: A
Explanation:
Explanation/Reference:
It is considered to be a 'Physical Control'
There are three broad categories of access control: administrative, technical, and physical. Each category has different access control mechanisms that can be carried out manually or automatically. All of these access control mechanisms should work in concert with each other to protect an infrastructure and its data.
Each category of access control has several components that fall within it, a partial list is shown here. Not all controls fall into a single category, many of the controls will be in two or more categories. Below you have an example with backups where it is in all three categories:
Administrative Controls
Policy and procedures
- A backup policy would be in place
Personnel controls
Supervisory structure
Security-awareness training
Testing
Physical Controls
Network segregation
Perimeter security
Computer controls
Work area separation
Data backups (actual storage of the media, i:e Offsite Storage Facility) Cabling
Technical Controls
System access
Network architecture
Network access
Encryption and protocols
Control zone
Auditing
Backup (Actual software doing the backups)
The following answers are incorrect :
Password and resource management is considered to be a logical or technical control.
Identification and authentication methods is considered to be a logical or technical control.
Intrusion Detection Systems is considered to be a logical or technical control.
Reference : Shon Harris , AIO v3 , Chapter - 4 : Access Control , Page : 180 - 185
NEW QUESTION # 189
The high availability of multiple all-inclusive, easy-to-use hacking tools that do NOT require much technical knowledge has brought a growth in the number of which type of attackers?
- A. Black hats
- B. White hats
- C. Phreakers
- D. Script kiddies
Answer: D
Explanation:
Explanation/Reference:
As script kiddies are low to moderately skilled hackers using available scripts and tools to easily launch attacks against victims.
The other answers are incorrect because :
Black hats is incorrect as they are malicious , skilled hackers.
White hats is incorrect as they are security professionals.
Phreakers is incorrect as they are telephone/PBX (private branch exchange) hackers.
Reference : Shon Harris AIO v3 , Chapter 12: Operations security , Page : 830
NEW QUESTION # 190
Which of the following is true of network security?
- A. A whitewall is a necessity in today's connected world.
- B. A firewall is a necessity in today's connected world.
- C. A black firewall is a necessity in today's connected world.
- D. A firewall is a not a necessity in today's connected world.
Answer: B
Explanation:
Section: Network and Telecommunications
Explanation/Reference:
Commercial firewalls are a dime-a-dozen in todays world. Black firewall and whitewall are just distracters.
NEW QUESTION # 191
Which of the following statements pertaining to disk mirroring is incorrect?
- A. Mirroring offers a higher fault tolerance than parity.
- B. Mirroring is usually the less cost-effective solution.
- C. Mirroring offers better performance in read operations but writing hinders system performance.
- D. Mirroring is a hardware-based solution only.
Answer: D
Explanation:
Explanation/Reference:
With mirroring, the system writes the data simultaneously to separate drives or arrays.
The advantage of mirroring are minimal downtime, simple data recovery, and increased performance in reading from the disk.
The disadvantage of mirroring is that both drives or disk arrays are processing in the writing to disks function, which can hinder system performance.
Mirroring has a high fault tolerance and can be implemented either through a hardware RAID controller or through the operating system. Since it requires twice the disk space than actual data, mirroring is the less cost-efficient data redundancy strategy.
Source: SWANSON, Marianne, & al., National Institute of Standards and Technology (NIST), NIST Special Publication 800-34, Contingency Planning Guide for Information Technology Systems, December 2001 (page 45).
NEW QUESTION # 192
What is the greatest danger from DHCP?
- A. An intruder on the network impersonating a DHCP server and thereby misconfiguring the DHCP clients.
- B. Having the organization's mail server unreachable.
- C. Having the wrong router used as the default gateway.
- D. Having multiple clients on the same LAN having the same IP address.
Answer: A
Explanation:
The greatest danger from BootP or DHCP (Dynamic Host Control Protocol)
is from an intruder on the network impersonating a DHCP server and thereby
misconfiguring the DHCP clients. Other choices are possible consequences of DHCP
impersonation.
Source: STREBE, Matthew and PERKINS, Charles, Firewalls 24seven, Sybex 2000,
Chapter 4: Sockets and Services from a Security Viewpoint.
NEW QUESTION # 193
Which of the following statements pertaining to link encryption is false?
- A. It provides protection against packet sniffers and eavesdroppers.
- B. It encrypts all the data along a specific communication path.
- C. User information, header, trailers, addresses and routing data that are part of the packets are encrypted.
- D. Information stays encrypted from one end of its journey to the other.
Answer: D
Explanation:
Section: Network and Telecommunications
Explanation/Reference:
When using link encryption, packets have to be decrypted at each hop and encrypted again.
Information staying encrypted from one end of its journey to the other is a characteristic of end-to-end encryption, not link encryption.
Link Encryption vs. End-to-End Encryption
Link encryption encrypts the entire packet, including headers and trailers, and has to be decrypted at each hop.
End-to-end encryption does not encrypt the IP Protocol headers, and therefore does not need to be decrypted at each hop.
Reference: All in one, Page 735 & Glossary
and
Source: WALLHOFF, John, CBK#5 Cryptography (CISSP Study Guide), April 2002 (page 6).
NEW QUESTION # 194
What is defined as the manner in which the network devices are organized to facilitate communications?
- A. LAN transmission protocols
- B. LAN transmission methods
- C. LAN topologies
- D. LAN media access methods
Answer: C
Explanation:
Explanation/Reference:
A network topology defines the manner in which the network devices are organized to facilitate communications. Common LAN technologies are:
bus
ring
star
meshed
LAN transmission methods refer to the way packets are sent on the network and are:
unicast
multicast
broadcast
LAN transmission protocols are the rules for communicating between computers on a LAN. Common LAN transmission protocols are:
CSMA/CD
polling
token-passing
LAN media access methods control the use of a network (physical and data link layers). They can be:
Ethernet
ARCnet
Token ring
FDDI
Source: KRUTZ, Ronald L & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 3: Telecommunications and Network Security (page
105).
NEW QUESTION # 195
When an outgoing request is made on a port number greater than 1023, this type of firewall creates an ACL to allow the incoming reply on that port to pass:
- A. Application level proxy
- B. Dynamic packet filtering
- C. CIrcuit level proxy
- D. packet filtering
Answer: B
Explanation:
Section: Network and Telecommunications
Explanation/Reference:
The dynamic packet filtering firewall is able to create ACL's on the fly to allow replies on dynamic ports (higher than 1023).
Packet filtering is incorrect. The packet filtering firewall usually requires that the dynamic ports be left open as a group in order to handle this situiation.
Circuit level proxy is incorrect. The circuit level proxy builds a conduit between the trusted and untrusted hosts and does not work by dynamically creating ACL's.
Application level proxy is incorrect. The application level proxy "proxies" for the trusted host in its communications with the untrusted host. It does not dynamically create ACL's to control traffic.
NEW QUESTION # 196
Why does compiled code pose more of a security risk than interpreted code?
- A. If the executed compiled code fails, there is a chance it will fail insecurely.
- B. Because compilers are not reliable.
- C. Because malicious code can be embedded in compiled code and be difficult to detect.
- D. There is no risk difference between interpreted code and compiled code.
Answer: C
Explanation:
From a security standpoint, a compiled program is less desirable than an interpreted one because malicious code can be resident somewhere in the compiled code, and it is difficult to detect in a very large program.
NEW QUESTION # 197
Which type of control is concerned with restoring controls?
- A. Preventive controls
- B. Corrective controls
- C. Detective controls
- D. Compensating controls
Answer: B
Explanation:
Corrective controls are concerned with remedying circumstances and
restoring controls.
Detective controls are concerned with investigating what happen after the fact such as logs
and video surveillance tapes for example.
Compensating controls are alternative controls, used to compensate weaknesses in other
controls.
Preventive controls are concerned with avoiding occurrences of risks.
Source: TIPTON, Hal, (ISC)2, Introduction to the CISSP Exam presentation.
NEW QUESTION # 198
A momentary low voltage, from 1 cycle to a few seconds, is a:
- A. sag
- B. fault
- C. blackout
- D. spike
Answer: A
Explanation:
Section: Risk, Response and Recovery
Explanation/Reference:
A momentary low voltage is a sag. A synonym would be a dip.
Risks to electrical power supply:
POWER FAILURE
Blackout: complete loss of electrical power
Fault: momentary power outage
POWER DEGRADATION
Brownout: an intentional reduction of voltage by the power company.
Sag/dip: a short period of low voltage
POWER EXCESS
Surge: Prolonged rise in voltage
Spike: Momentary High Voltage
In-rush current: the initial surge of current required by a load before it reaches normal operation.
- Transient: line noise or disturbance is superimposed on the supply circuit and can cause fluctuations in electrical power Refence(s) used for this question:
Harris, Shon (2012-10-25). CISSP All-in-One Exam Guide, 6th Edition (p. 462). McGraw-Hill. Kindle Edition.
NEW QUESTION # 199
Which of the following would be the best reason for separating the test and development environments?
- A. To control the stability of the test environment.
- B. To restrict access to systems under test.
- C. To secure access to systems under development.
- D. To segregate user and development staff.
Answer: A
Explanation:
Section: Security Operation Adimnistration
Explanation/Reference:
The test environment must be controlled and stable in order to ensure that development projects are tested in a realistic environment which, as far as possible, mirrors the live environment.
Reference(s) used for this question:
Information Systems Audit and Control Association, Certified Information Systems Auditor 2002 review manual, chapter 6: Business Application System Development, Acquisition, Implementation and Maintenance (page
309).
NEW QUESTION # 200
Which of the following statements is NOT true of IPSec Transport mode?
- A. When ESP is used for the security protocol, the hash is only applied to the upper layer protocols contained in the packet
- B. If used in gateway-to-host communication, gateway must act as host
- C. Set-up when end-point is host or communications terminates at end-points
- D. It is required for gateways providing access to internal systems
Answer: D
Explanation:
Explanation/Reference:
Source: TIPTON, Harold F & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 2, 2001, CRC Press, NY, Pages 166-167.
NEW QUESTION # 201
One of the following statements about the differences between PPTP and L2TP is NOT true
- A. L2TP works well with all firewalls and network devices that perform NAT.
- B. PPTP can run only on top of IP networks.
- C. L2TP supports AAA servers
- D. PPTP is an encryption protocol and L2TP is not.
Answer: A
Explanation:
Section: Network and Telecommunications
Explanation/Reference:
L2TP is affected by packet header modification and cannot cope with firewalls and network devices that perform NAT.
"PPTP can run only on top of IP networks." is correct as PPTP encapsulates datagrams into an IP packet, allowing PPTP to route many network protocols across an IP network.
"PPTP is an encryption protocol and L2TP is not." is correct. When using PPTP, the PPP payload is encrypted with Microsoft Point-to-Point Encryption (MPPE) using MSCHAP or EAP-TLS.
"L2TP supports AAA servers" is correct as L2TP supports TACACS+ and RADIUS.
NOTE:
L2TP does work over NAT. It is possible to use a tunneled mode that wraps every packet into a UDP packet.
Port 4500 is used for this purpose. However this is not true of PPTP and it is not true as well that it works well with all firewalls and NAT devices.
References:
All in One Third Edition page 545
Official Guide to the CISSP Exam page 124-126
NEW QUESTION # 202
......
SSCP are Available for Instant Access: https://www.torrentexam.com/SSCP-exam-latest-torrent.html
SSCP Dumps 2023 - New ISC SSCP Exam Questions: https://drive.google.com/open?id=1_pfvn9ziVTvQGG7fA8MF_zbr-qYeIKRi

