0% found this document useful (1 vote)
182 views3 pages

SSCP Practice Quiz Insights

This document provides a 10 question practice quiz for the SSCP certification. The quiz covers topics related to information security including the CIA triad principles of confidentiality, integrity and availability. Specifically, it addresses questions about availability, integrity, separation of duties, asset definitions, data remanence, risk mitigation and the main goal of risk assessment programs. The document provides the questions, potential multiple choice answers, and identifies the single best correct answer with an explanation for each question.

Uploaded by

asdasdasdasd
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (1 vote)
182 views3 pages

SSCP Practice Quiz Insights

This document provides a 10 question practice quiz for the SSCP certification. The quiz covers topics related to information security including the CIA triad principles of confidentiality, integrity and availability. Specifically, it addresses questions about availability, integrity, separation of duties, asset definitions, data remanence, risk mitigation and the main goal of risk assessment programs. The document provides the questions, potential multiple choice answers, and identifies the single best correct answer with an explanation for each question.

Uploaded by

asdasdasdasd
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Practice Quiz

SSCP Practice Quiz

1. A user has some extremely valuable data. The data is backed up to a flash stick and
placed in a data safe. Which two principles of the CIA triad does this address?
a. Confidentiality and integrity
b. Confidentiality and availability
c. Integrity and availability
d. Availability and nonrepudiation

The correct answer is B. The user is ensuring a form of availability by having a data backup.
Confidentiality is being accomplished by locking up the flash stick. The question does not
describe any practice that could constitute integrity protection and the CIA triad does not deal
with nonrepudiation.

2. Which best describes the concept of availability?


a. Users can make authorized changes
b. There is a level of assurance that data hasn’t been altered
c. Data is available to authorized users when required
d. Backups are protected at off-site locations

The correct answer is C. Availability is the concept of having resources (not just data) available
whenever they are required. A and B best relate to integrity, while D is a more narrow
definition that combines availability with confidentiality.

3. What security principle might best be deployed to prevent fraud?


a. Least privilege
b. Auditing
c. Discretionary access control
d. Separation of duties

The correct answer is D. B assists in the detection of fraud but would not typically be able to
prevent the problem. A restricts access based upon the need-to-know element, but again does
not necessarily prevent the problem. C is irrelevant.

4. Define integrity.
a. Data being correct and up to date
b. Data being accessible
c. Protection from unauthorized access
d. Data being preserved in an unaltered state

SSCP Practice Quiz 1


Practice Quiz

The correct answer is D. A is partially correct as it is necessary to maintain good data quality.
Under most Data Protection Acts, we are required to ensure data is accurate and current.
However, our primary concern is to have confidence that the data we are processing is not
subjected to improper alteration by either accidental or intentional actions. B is a function of
availability and C is a function of authorization.

5. Which of the following is the BEST definition of an asset?


a. A hardware system in a data center
b. People in sensitive environments
c. Software running in a secure environment
d. An item perceived as having value

The correct answer is D. Even though A, B, and C are considered to be assets, the question is
asking for the best definition, not examples. An asset is anything that has value to the
organization.

6. What is the correct order of the asset lifecycle phases?


a. Create, use, share, store, archive, and destroy
b. Create, share, use, archive, store, and destroy
c. Create, store, use, share, archive, and destroy
d. Create, share, archive, use, store, and destroy

The correct answer is C. This is the correct order of the lifecycle phases of assets: create, store,
use, share, archive, and destroy. This is according to the Securosis Blog.

7. What is the best method for dealing with data remanence on SSDs?
a. Physical destruction
b. Degaussing
c. Formatting
d. Overwriting

The correct answer is A. Degaussing only works on magnetic media and formatting doesn’t
permanently delete data, as it may still be recovered forensically. Overwriting is not effective
on SSDs.

8. A list of company-restricted websites would best be handled in the first instance by


what type of control?
a. Physical
b. Administrative
c. Environmental
d. Technical

SSCP Practice Quiz 2


Practice Quiz

The correct answer is B. A physical control might be used to prevent access from a given
device and a technical control might be employed to enforce the corporate policy.
Environment is not one of the three types of control.

9. Whenever an organization chooses to perform risk mitigation to address a


particular risk, what other form of risk management will also be included?
a. Risk transference
b. Risk avoidance
c. Risk capture
d. Risk acceptance

The correct answer is D. Risk mitigation always leaves some residual risk; the purpose of risk
mitigation is to get risk down to an acceptable level.

10. What is the main goal of a risk assessment program?


a. To calculate annualized loss expectancy (ALE) formulas
b. To develop a disaster recovery plan (DRP)
c. To evaluate risk mitigation
d. To help balance the cost between risk and countermeasures

The correct answer is D. A is a process to calculate risk. C is a testing process and B is a


different business process.

SSCP Practice Quiz 3

Common questions

Powered by AI

The correct order of asset lifecycle phases is: create, store, use, share, archive, and destroy. Each phase is significant as it represents a stage in the asset's existence and management. Managing these phases ensures that assets are effectively utilized, protected, maintained, and ultimately disposed of in a secure manner .

The main objective of a risk assessment program is to help balance the cost between risk and countermeasures, ensuring that resources are allocated efficiently to provide adequate protection without overspending. This benefits the organization by optimizing risk management expenditures and improving decision-making regarding risk priorities .

Administrative controls play the role of establishing policies and procedures that dictate what websites are restricted and how these restrictions are enforced. These controls help formalize the rules that technical or physical mechanisms will implement to ensure compliance .

Backing up data to a flash stick and placing it in a data safe addresses the principles of confidentiality and availability in the CIA triad. Confidentiality is ensured by securing the flash stick in a data safe, while availability is maintained by having a backup that can be accessed if the original data is lost or corrupted .

The primary concern of data integrity within data protection frameworks is to ensure that data remains in an unaltered state. This involves protecting data from unauthorized alterations, whether intentional or accidental, allowing organizations to trust that the data being used is consistent and accurate .

Availability is crucial because it ensures that data and resources are accessible to authorized users whenever needed. It is best defined as data being available to authorized users when required, which supports operational continuity and minimizes disruptions to business processes .

Risk mitigation inherently includes risk acceptance because it focuses on reducing risk to an acceptable level rather than eliminating it entirely. The residual risk that remains after mitigation efforts is what the organization agrees to accept .

Separation of duties helps prevent fraud by ensuring that no single individual has control over all aspects of a critical function. This division of responsibilities means that potential fraud requires collusion, significantly reducing the likelihood of fraudulent actions going unnoticed .

Physical destruction is the best method for dealing with data remanence on SSDs because it ensures that all data is irrecoverably destroyed. Other methods like degaussing, formatting, or overwriting are ineffective due to the way SSDs store data electrically rather than magnetically .

The best definition of an asset is an item perceived as having value. This definition is preferred because it encompasses a wide array of items beyond tangible hardware or software, recognizing anything that holds value to the organization, including intangible elements like data and intellectual property .

You might also like