SSCP Systems Security Certified Practitioner practice questions

226 free questions with answers and explanations.

Practice test
  1. 1.An organization is implementing a new authentication system that allows users to log in once to access multiple independent software systems without re-entering their credentials. This system relies on a central identity provider and security tokens. What is this authentication concept called?Access Controls
  2. 2.A security administrator is configuring access for a new human resources application. The application requires that users can only read their own personnel files but can view an aggregated, anonymized report of all employee salaries. What access control model best supports this specific requirement?Access Controls
  3. 3.A security engineer is evaluating different cryptographic algorithms for securing data in transit across a high-speed network. The primary concern is maintaining confidentiality and integrity with minimal latency. Which of the following cryptographic primitives, when correctly implemented, offers both confidentiality and integrity in a single operation?Cryptography
  4. 4.A software development team is implementing a feature that requires encrypting small, fixed-size data blocks (e.g., credit card numbers) before storing them in a database. They are considering using AES in Electronic Codebook (ECB) mode. What is the PRIMARY security concern with using AES-ECB for this purpose, especially if the same data blocks might appear multiple times?Cryptography
  5. 5.A company is designing a system that requires users to digitally sign documents to ensure non-repudiation. Which component of the digital signature process provides the assurance that the signer cannot later deny having signed the document?Cryptography
  6. 6.A system administrator needs to securely exchange a symmetric encryption key with a remote user over an insecure channel without prior shared secrets. Which cryptographic protocol is commonly used for this purpose?Cryptography
  7. 7.A financial institution requires its customers to use a username and password, along with a one-time code sent to their registered mobile device, to access their online banking portal. What type of authentication is being used?Access Controls
  8. 8.A small business is implementing a secure communication channel for its online transactions. They are considering a cryptographic algorithm that offers both confidentiality and integrity for streamed data, where data is processed bit by bit or byte by byte. Which of the following best describes such an algorithm?Cryptography
  9. 9.A system uses a custom block cipher in Electronic Codebook (ECB) mode to encrypt sensitive image files. A security audit reveals that while the encryption works, distinct patterns from the original image are still visible in the encrypted output. What is the fundamental reason for this vulnerability?Cryptography
  10. 10.An organization is implementing a new system where access to highly confidential documents is granted based on a combination of the user's security clearance level, the document's classification, the user's department, and the time of day. For example, a 'Top Secret' document can only be accessed by a 'Top Secret' cleared user from the 'Research' department between 9 AM and 5 PM. Which advanced authorization mechanism is best suited for this scenario?Access Controls
  11. 11.A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computer attacks. The developers are concerned that traditional hash functions might eventually be vulnerable to quantum algorithms that could find collisions more efficiently. Which characteristic is primarily sought in a post-quantum cryptographic hashing algorithm for this purpose?Cryptography
  12. 12.A system administrator is configuring a new file server. They decide that instead of assigning individual permissions to each user, they will create groups based on departments (e.g., 'Finance', 'HR', 'IT') and assign permissions to these groups. Users will then be added to the appropriate department group. Which access control model is this administrator implementing?Access Controls
  13. 13.A security architect is designing a system for secure communication between two IoT devices over an unreliable network. They need a cryptographic primitive that provides both data confidentiality and data integrity, while also allowing for efficient processing on resource-constrained devices. Which type of cryptographic algorithm is best suited for this combined requirement?Cryptography
  14. 14.A system administrator is configuring a new web server to use HTTPS. During the setup, they are prompted to select a cipher suite that ensures a unique session key is generated for every new connection, even if the server's long-term private key is compromised in the future. Which property does this requirement describe?Cryptography
  15. 15.A financial institution is implementing a system for secure online transactions. They require a mechanism to ensure that a customer cannot later deny having initiated a specific transaction, even if their private key is compromised after the transaction. Which cryptographic property, when properly implemented, primarily addresses this 'non-denial' aspect?Cryptography
  16. 16.A security auditor is reviewing an organization's cryptographic key management practices. The auditor discovers that the same symmetric key is used for both encrypting sensitive data at rest and for generating Message Authentication Codes (MACs) for data integrity. What is the most significant cryptographic risk introduced by this practice?Cryptography
  17. 17.A large enterprise is designing a new internal application that requires strong user authentication. They want to implement a system where user passwords are never stored in plain text and are difficult to reverse engineer, even if the database is compromised. Which cryptographic technique is BEST suited for this requirement?Cryptography
  18. 18.An organization uses an access control system where a subject's access rights to an object are determined by comparing the subject's security clearance level with the object's security classification label. The system strictly prevents a subject from writing information to an object with a lower security classification than their own clearance. Which access control model and specific property are being described?Access Controls
  19. 19.A security architect is designing an access control system for a highly dynamic environment where access decisions must be made in real-time based on a combination of a user's current location, the time of day, their role, and the sensitivity level of the data they are trying to access. Which access control model would be most suitable for this complex requirement?Access Controls
  20. 20.A security policy states that all administrative actions on critical systems must be approved by a second administrator before execution. This ensures that no single individual can perform a sensitive operation without oversight. Which access control principle is being enforced?Access Controls
  21. 21.A security engineer is designing a system that uses a Public Key Infrastructure (PKI) to manage digital certificates. They need to ensure that when a certificate is revoked, all relying parties are quickly and efficiently informed of its invalidation. Which method provides the most timely and resource-efficient way to check the revocation status of a single certificate in real-time?Cryptography
  22. 22.A software developer is implementing a new secure file storage system. The requirement is to encrypt large files efficiently while ensuring that the encryption process can be easily parallelized across multiple processor cores. Which type of encryption algorithm is best suited for this scenario?Cryptography
  23. 23.A large e-commerce company is implementing a new customer identity management system. They want to allow customers to use their existing social media accounts (e.g., Google, Facebook) to sign up and log in, rather than creating new credentials. Which identity and access management (IAM) concept is being implemented?Access Controls
  24. 24.A company is implementing a Public Key Infrastructure (PKI) to secure its internal communications. As part of this implementation, a server is designated to issue, revoke, and manage digital certificates. What role does this server fulfill within the PKI?Cryptography
  25. 25.A financial institution is implementing a system for secure online transactions. They require a cryptographic solution that ensures the integrity of the transaction data, confirms the sender's identity, and prevents the sender from later denying they sent the transaction. Which of the following cryptographic techniques BEST fulfills all three of these requirements?Cryptography
  26. 26.A system administrator is tasked with securing communication between two web servers over an untrusted network. They decide to use Transport Layer Security (TLS) with a cipher suite that includes an elliptic curve algorithm for key exchange and AES-256 for symmetric encryption. Which component of the TLS handshake process is primarily responsible for establishing a shared secret key for the symmetric encryption?Cryptography
  27. 27.A security administrator is implementing a new access control system that grants users only the permissions necessary to perform their specific job functions and revokes those permissions when their role changes or terminates. Which access control principle is being primarily applied?Access Controls
  28. 28.A developer is implementing a secure messaging application that needs to encrypt large files efficiently. The application also needs to ensure that the encrypted files cannot be decrypted even if the symmetric key is reused with the same plaintext, without revealing patterns. Which cryptographic component is crucial for introducing randomness into the encryption process to prevent such pattern recognition and ensure semantic security?Cryptography
  29. 29.A company is implementing a new system where access decisions are based on the sensitivity of the data, the clearance level of the user, and a formal classification scheme. This system prevents users from writing information to a lower security level than their current clearance and from reading information from a higher security level. Which access control model is being described?Access Controls
  30. 30.An incident response team is investigating a data breach where an attacker exfiltrated encrypted data from a database. The database used a simple key management system where the encryption key was stored on the same server as the encrypted data. If the attacker gained root access to the server, what core cryptographic principle was violated, making the encryption ineffective?Cryptography
  31. 31.A system administrator is configuring a new web server and needs to generate a strong, random key for its TLS certificate. The process requires a source of true randomness to ensure the cryptographic strength of the generated key. Which of the following is considered the BEST source for generating cryptographically strong random numbers?Cryptography
  32. 32.A financial institution is implementing a new customer authentication system. They require customers to provide something they know (password), something they have (a hardware token), and something they are (fingerprint scan). This approach is designed to achieve which specific security objective?Access Controls
  33. 33.A security consultant is explaining the concept of perfect forward secrecy (PFS) to a client. Which statement accurately describes how PFS enhances the security of encrypted communications?Cryptography
  34. 34.A company is implementing a new system that requires users to authenticate using a cryptographic key stored on a smart card, coupled with a PIN. This combination of authentication factors falls under which category of authentication?Access Controls
  35. 35.A company is implementing a new system for managing employee travel requests. The policy states that a travel request must be submitted by the employee, approved by their direct manager, and then approved by the finance department before travel funds are released. No single individual or department can approve a request entirely on their own. This design adheres to which security principle?Access Controls
  36. 36.A cloud service provider offers a service where customers can manage their own virtual machines. Each customer is responsible for setting permissions on their individual VMs and data within those VMs, determining who can access them and with what privileges. The provider enforces a base level of security but allows customers full control over their own resources. Which access control model is primarily demonstrated by the customer's ability to manage their own VM access?Access Controls
  37. 37.A developer is implementing a secure communication channel and needs to choose a cipher suite for TLS. They prioritize forward secrecy, meaning that compromise of a long-term private key will not compromise past session keys. Which of the following key exchange mechanisms should be selected to achieve this?Cryptography
  38. 38.A system administrator is tasked with updating the access control list (ACL) for a shared network folder. The folder currently has entries for 'Finance Group: Read/Write' and 'All Employees: Read'. A new requirement states that specific managers in the 'Finance Group' should also have 'Full Control' over certain subfolders, but not the entire shared folder. Which action should the administrator take FIRST to implement this requirement effectively?Access Controls
  39. 39.A forensic investigator is examining encrypted files found on a suspect's computer. The files were encrypted using a custom application. The investigator notices that a common attack vector involves guessing a short, predictable passphrase, which then directly acts as the encryption key. What cryptographic vulnerability is being exploited in this scenario?Cryptography
  40. 40.A security analyst is reviewing a system that uses cryptographic hashing to store user passwords. Which of the following properties of a cryptographic hash function ensures that an attacker cannot easily find two different inputs that produce the same hash output?Cryptography
  41. 41.A security analyst is investigating a suspected man-in-the-middle (MITM) attack against an internal web application. The application uses SSL/TLS for secure communication. Which of the following cryptographic concepts is primarily designed to prevent an attacker from successfully impersonating the legitimate server to the client?Cryptography
  42. 42.A system administrator is configuring a new web server and needs to generate a strong, truly random seed for cryptographic operations, such as generating TLS session keys. They are advised to use a hardware-based source for this randomness rather than a software-based pseudo-random number generator (PRNG). What is the primary advantage of using a Hardware Random Number Generator (HRNG) in this context?Cryptography
  43. 43.A system architect is designing a secure communication protocol between a client application and a server. They need to ensure that even if the server's private key is eventually compromised, past communication sessions cannot be decrypted by an attacker who recorded the encrypted traffic. Which cryptographic property is essential to achieve this goal?Cryptography
  44. 44.A security team is analyzing a custom cryptographic implementation. They discover that the encryption process relies heavily on a single, secret value that is used directly as the key for all encryption and decryption operations. This design choice primarily impacts which of the following cryptographic goals?Cryptography
  45. 45.A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computing attacks. Which of the following properties is MOST crucial for a hashing algorithm to be considered 'quantum-resistant'?Cryptography
  46. 46.A software developer is creating an application that requires a cryptographically secure random number generator for generating session keys. The operating system's default pseudo-random number generator (PRNG) is available, but the developer is concerned about its suitability for security-critical functions. Which characteristic is most important for a cryptographically secure random number generator (CSRNG) that the PRNG might lack?Cryptography
  47. 47.A system administrator is configuring a new web server to use HTTPS. They are deciding between using a block cipher in Cipher Block Chaining (CBC) mode or Counter (CTR) mode for data encryption. The primary concern is parallel processing for high throughput while maintaining strong security. Which mode would be most suitable for this requirement?Cryptography
  48. 48.A security analyst is reviewing a system that prevents users from downgrading the security classification of a document they are editing, even if they have read and write permissions at their current clearance level. This ensures that sensitive information does not accidentally or maliciously get released to a lower security domain. Which security model principle is being applied here?Access Controls
  49. 49.A security auditor is reviewing a company's data at rest encryption strategy. The auditor notes that a significant portion of sensitive PII (Personally Identifiable Information) is encrypted using a symmetric key that is stored on the same server as the encrypted data. Which of the following cryptographic best practices is being violated?Cryptography
  50. 50.A hospital's patient record system is designed such that medical staff can only access patient records during their active shift and only from designated hospital terminals within the secure network. Access attempts outside of these parameters are automatically denied. Which type of access control mechanism is primarily being used to enforce these restrictions?Access Controls