Step2Study
IT & TechnologySSCP100% Free

SSCP Systems Security Certified Practitioner

Practice bank
226 Qs
Real exam
125 Qs
Time limit
180 min
Passing
700 out of 1000 points

Exam blueprint

Access Controls
16%
Security Operations and Administration
16%
Risk Identification, Monitoring, and Analysis
15%
Incident Response and Recovery
14%
Cryptography
13%
Network and Communications Security
13%
Systems and Application Security
13%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 125 questions each · 180 min · pass 70% · 226 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

SSCP Systems Security Certified Practitioner practice test questions

Sample questions from the 226-question bank, with answers and explanations.

All questions
  1. 1. An organization is implementing a new authentication system that allows users to log in once to access multiple independent software systems without re-entering their credentials. This system relies on a central identity provider and security tokens. What is this authentication concept called?

    Access Controls

    • A. Biometric authentication
    • B. Single Sign-On (SSO)
    • C. Federated identity management
    • D. Multi-factor authentication (MFA)
    Show answer

    B. Single Sign-On (SSO)

    Single Sign-On (SSO) is an authentication scheme that allows a user to log in with a single ID and password to gain access to a connected system or systems without using different usernames or passwords.

  2. 2. A cryptocurrency project aims to use a hashing algorithm that is resistant to quantum computer attacks. The developers are concerned that traditional hash functions might eventually be vulnerable to quantum algorithms that could find collisions more efficiently. Which characteristic is primarily sought in a post-quantum cryptographic hashing algorithm for this purpose?

    Cryptography

    • A. Pre-image resistance against Grover's algorithm
    • B. Resistance to quantum collision-finding algorithms
    • C. Collision resistance against Shor's algorithm
    • D. Second pre-image resistance against quantum parallelism
    Show answer

    B. Resistance to quantum collision-finding algorithms

    The primary concern for hashing algorithms in a quantum computing context is their collision resistance. While Grover's algorithm can speed up pre-image attacks, quantum algorithms like those based on the birthday paradox (e.g., in a quantum search) can find collisions in hash functions much faster than classical methods. Therefore, a post-quantum hash needs to specifically resist quantum collision-finding.

  3. 3. A security engineer is evaluating different cryptographic algorithms for securing data in transit across a high-speed network. The primary concern is maintaining confidentiality and integrity with minimal latency. Which of the following cryptographic primitives, when correctly implemented, offers both confidentiality and integrity in a single operation?

    Cryptography

    • A. RSA
    • B. AES-GCM
    • C. AES-CBC
    • D. SHA-256
    Show answer

    B. AES-GCM

    AES-GCM (Galois/Counter Mode) is an authenticated encryption mode. It provides both confidentiality (encryption) and authenticity/integrity (via a Message Authentication Code or MAC) in a single, efficient operation, making it ideal for high-speed network communication.

  4. 4. A software development team is implementing a feature that requires encrypting small, fixed-size data blocks (e.g., credit card numbers) before storing them in a database. They are considering using AES in Electronic Codebook (ECB) mode. What is the PRIMARY security concern with using AES-ECB for this purpose, especially if the same data blocks might appear multiple times?

    Cryptography

    • A. It is computationally intensive and slow for small data blocks.
    • B. It requires a complex key management system, making implementation difficult.
    • C. It is susceptible to replay attacks due to lack of initialization vector.
    • D. It does not hide data patterns, as identical plaintext blocks produce identical ciphertext blocks.
    Show answer

    D. It does not hide data patterns, as identical plaintext blocks produce identical ciphertext blocks.

    ECB mode encrypts each block independently using the same key. This means that identical plaintext blocks will always produce identical ciphertext blocks. For data like credit card numbers, which might repeat or have common patterns (e.g., leading digits), this reveals patterns in the encrypted data, making it vulnerable to analysis.

  5. 5. A company is implementing a Public Key Infrastructure (PKI) to secure its internal communications. As part of this implementation, a server is designated to issue, revoke, and manage digital certificates. What role does this server fulfill within the PKI?

    Cryptography

    • A. Certificate Authority (CA)
    • B. Registration Authority (RA)
    • C. Certificate Repository (CR)
    • D. Validation Authority (VA)
    Show answer

    A. Certificate Authority (CA)

    The Certificate Authority (CA) is the trusted entity responsible for issuing, revoking, and managing digital certificates within a PKI.

  6. 6. A system administrator needs to securely exchange a symmetric encryption key with a remote user over an insecure channel without prior shared secrets. Which cryptographic protocol is commonly used for this purpose?

    Cryptography

    • A. MD5 (Message-Digest Algorithm 5)
    • B. AES (Advanced Encryption Standard)
    • C. RSA (Rivest–Shamir–Adleman)
    • D. Diffie-Hellman
    Show answer

    D. Diffie-Hellman

    Diffie-Hellman is a key exchange protocol that allows two parties to establish a shared secret key over an insecure communication channel without prior shared secrets.

  7. 7. A financial institution requires its customers to use a username and password, along with a one-time code sent to their registered mobile device, to access their online banking portal. What type of authentication is being used?

    Access Controls

    • A. Multi-factor authentication (MFA)
    • B. Biometric authentication
    • C. Federated authentication
    • D. Single-factor authentication
    Show answer

    A. Multi-factor authentication (MFA)

    Multi-factor authentication (MFA) requires a user to present two or more different authentication factors. In this case, 'something you know' (username/password) and 'something you have' (mobile device receiving a one-time code) are used.

  8. 8. A system uses a custom block cipher in Electronic Codebook (ECB) mode to encrypt sensitive image files. A security audit reveals that while the encryption works, distinct patterns from the original image are still visible in the encrypted output. What is the fundamental reason for this vulnerability?

    Cryptography

    • A. ECB mode encrypts identical plaintext blocks into identical ciphertext blocks
    • B. Lack of a strong key derivation function
    • C. Insufficient key length of the block cipher
    • D. The absence of a digital certificate for key exchange
    Show answer

    A. ECB mode encrypts identical plaintext blocks into identical ciphertext blocks

    Electronic Codebook (ECB) mode encrypts each block of plaintext independently. If two plaintext blocks are identical, they will produce identical ciphertext blocks. In images, areas of uniform color or repeating patterns will result in repeating ciphertext blocks, revealing patterns in the encrypted output, thereby compromising confidentiality.

  9. 9. An organization is implementing a new system where access to highly confidential documents is granted based on a combination of the user's security clearance level, the document's classification, the user's department, and the time of day. For example, a 'Top Secret' document can only be accessed by a 'Top Secret' cleared user from the 'Research' department between 9 AM and 5 PM. Which advanced authorization mechanism is best suited for this scenario?

    Access Controls

    • A. Attribute-Based Access Control (ABAC)
    • B. Role-Based Access Control (RBAC)
    • C. Mandatory Access Control (MAC)
    • D. Discretionary Access Control (DAC)
    Show answer

    A. Attribute-Based Access Control (ABAC)

    Attribute-Based Access Control (ABAC) is designed for highly granular and dynamic authorization decisions based on multiple attributes of the subject (user's clearance, department), the object (document classification), and the environment (time of day). This flexibility is ideal for complex, context-aware access policies.

  10. 10. A large e-commerce company is implementing a new customer identity management system. They want to allow customers to use their existing social media accounts (e.g., Google, Facebook) to sign up and log in, rather than creating new credentials. Which identity and access management (IAM) concept is being implemented?

    Access Controls

    • A. Privileged Access Management (PAM)
    • B. Decentralized Identity Management
    • C. Federated Identity Management
    • D. Centralized Identity Management
    Show answer

    C. Federated Identity Management

    Federated Identity Management allows users to authenticate with one identity provider (like Google or Facebook) and gain access to resources in other service providers without re-authenticating. This is precisely what the e-commerce company is trying to achieve.

  11. 11. A system administrator is configuring a new file server. They decide that instead of assigning individual permissions to each user, they will create groups based on departments (e.g., 'Finance', 'HR', 'IT') and assign permissions to these groups. Users will then be added to the appropriate department group. Which access control model is this administrator implementing?

    Access Controls

    • A. Role-Based Access Control (RBAC)
    • B. Mandatory Access Control (MAC)
    • C. Rule-Based Access Control
    • D. Discretionary Access Control (DAC)
    Show answer

    A. Role-Based Access Control (RBAC)

    Role-Based Access Control (RBAC) assigns permissions to roles, and then users are assigned to those roles. In this scenario, 'department groups' function as roles, and permissions are assigned to these groups, not directly to individual users.

  12. 12. A small business is implementing a secure communication channel for its online transactions. They are considering a cryptographic algorithm that offers both confidentiality and integrity for streamed data, where data is processed bit by bit or byte by byte. Which of the following best describes such an algorithm?

    Cryptography

    • A. Block Cipher
    • B. Asymmetric Algorithm
    • C. Stream Cipher
    • D. Hash Function
    Show answer

    C. Stream Cipher

    A stream cipher encrypts data continuously, bit by bit or byte by byte, making it suitable for streaming data. It maintains a state that changes with each encryption operation, unlike block ciphers.

  13. 13. A security architect is designing a system for secure communication between two IoT devices over an unreliable network. They need a cryptographic primitive that provides both data confidentiality and data integrity, while also allowing for efficient processing on resource-constrained devices. Which type of cryptographic algorithm is best suited for this combined requirement?

    Cryptography

    • A. Symmetric-key block cipher with a separate hashing algorithm
    • B. Authenticated Encryption with Associated Data (AEAD)
    • C. Digital signature algorithm
    • D. Asymmetric-key encryption
    Show answer

    B. Authenticated Encryption with Associated Data (AEAD)

    AEAD modes (like GCM or CCM) combine encryption for confidentiality and message authentication codes (MACs) for integrity and authenticity into a single, efficient cryptographic primitive. This avoids the complexities and potential pitfalls of 'encrypt-then-MAC' or 'MAC-then-encrypt' schemes, making it ideal for resource-constrained devices needing both confidentiality and integrity.

  14. 14. A system administrator is configuring a new web server to use HTTPS. During the setup, they are prompted to select a cipher suite that ensures a unique session key is generated for every new connection, even if the server's long-term private key is compromised in the future. Which property does this requirement describe?

    Cryptography

    • A. Key Separation
    • B. Perfect Forward Secrecy (PFS)
    • C. Key Derivation
    • D. Key Escrow
    Show answer

    B. Perfect Forward Secrecy (PFS)

    Perfect Forward Secrecy (PFS) ensures that a compromise of a server's long-term private key will not compromise past session keys. Each session key is independently generated and discarded after the session ends.

  15. 15. A financial institution is implementing a system for secure online transactions. They require a mechanism to ensure that a customer cannot later deny having initiated a specific transaction, even if their private key is compromised after the transaction. Which cryptographic property, when properly implemented, primarily addresses this 'non-denial' aspect?

    Cryptography

    • A. Integrity
    • B. Confidentiality
    • C. Non-repudiation
    • D. Availability
    Show answer

    C. Non-repudiation

    Non-repudiation is the cryptographic property that provides irrefutable proof of an action, such that the originator cannot later deny having performed it. Digital signatures, applied correctly, are the primary mechanism to achieve non-repudiation for transactions.

  16. 16. A security auditor is reviewing an organization's cryptographic key management practices. The auditor discovers that the same symmetric key is used for both encrypting sensitive data at rest and for generating Message Authentication Codes (MACs) for data integrity. What is the most significant cryptographic risk introduced by this practice?

    Cryptography

    • A. Vulnerability to replay attacks
    • B. Key compromise leading to loss of both confidentiality and integrity
    • C. Reduced key entropy
    • D. Increased computational overhead
    Show answer

    B. Key compromise leading to loss of both confidentiality and integrity

    Using the same key for different cryptographic functions (encryption and MAC generation) violates the principle of key separation. If this single key is compromised, an attacker gains both the ability to decrypt the data (breaking confidentiality) and to forge MACs (breaking integrity), allowing them to alter data undetectably.

  17. 17. A large enterprise is designing a new internal application that requires strong user authentication. They want to implement a system where user passwords are never stored in plain text and are difficult to reverse engineer, even if the database is compromised. Which cryptographic technique is BEST suited for this requirement?

    Cryptography

    • A. Digital signatures
    • B. Asymmetric encryption
    • C. Hashing with a salt
    • D. Symmetric encryption
    Show answer

    C. Hashing with a salt

    Hashing with a salt is the standard and most effective method for storing user passwords. Hashing transforms the password into a fixed-size string, making it irreversible, and the salt prevents rainbow table attacks and ensures identical passwords hash to different values.

  18. 18. An organization uses an access control system where a subject's access rights to an object are determined by comparing the subject's security clearance level with the object's security classification label. The system strictly prevents a subject from writing information to an object with a lower security classification than their own clearance. Which access control model and specific property are being described?

    Access Controls

    • A. Mandatory Access Control (MAC) and the *-Property (Star Property)
    • B. Discretionary Access Control (DAC) and the Simple Security Property
    • C. Role-Based Access Control (RBAC) and the No Write Down rule
    • D. Attribute-Based Access Control (ABAC) and the No Read Up rule
    Show answer

    A. Mandatory Access Control (MAC) and the *-Property (Star Property)

    Mandatory Access Control (MAC) uses security labels and clearances to enforce access. The *-Property (Star Property) in MAC specifically states that a subject cannot write to an object with a lower security classification (no write-down), which prevents information from flowing from a higher security level to a lower one.

  19. 19. A security architect is designing an access control system for a highly dynamic environment where access decisions must be made in real-time based on a combination of a user's current location, the time of day, their role, and the sensitivity level of the data they are trying to access. Which access control model would be most suitable for this complex requirement?

    Access Controls

    • A. Mandatory Access Control (MAC)
    • B. Role-Based Access Control (RBAC)
    • C. Attribute-Based Access Control (ABAC)
    • D. Discretionary Access Control (DAC)
    Show answer

    C. Attribute-Based Access Control (ABAC)

    Attribute-Based Access Control (ABAC) is designed for highly dynamic and granular access control. It evaluates a set of attributes (user, object, environment) to make real-time access decisions, perfectly matching the complex requirements described.

  20. 20. A security policy states that all administrative actions on critical systems must be approved by a second administrator before execution. This ensures that no single individual can perform a sensitive operation without oversight. Which access control principle is being enforced?

    Access Controls

    • A. Defense in depth
    • B. Need-to-know
    • C. Least privilege
    • D. Separation of duties
    Show answer

    D. Separation of duties

    Separation of duties is an access control principle that divides critical functions among multiple individuals to prevent any single person from being able to perform a complete sensitive operation, thereby reducing the risk of fraud, error, or malicious activity.

  21. 21. A security engineer is designing a system that uses a Public Key Infrastructure (PKI) to manage digital certificates. They need to ensure that when a certificate is revoked, all relying parties are quickly and efficiently informed of its invalidation. Which method provides the most timely and resource-efficient way to check the revocation status of a single certificate in real-time?

    Cryptography

    • A. Certificate Revocation List (CRL) distribution point
    • B. Online Certificate Status Protocol (OCSP)
    • C. Manual certificate verification
    • D. Trust Anchor distribution
    Show answer

    B. Online Certificate Status Protocol (OCSP)

    OCSP (Online Certificate Status Protocol) provides real-time, lightweight status checks for individual certificates. Instead of downloading a potentially large CRL, a client sends a request for a specific certificate's status to an OCSP responder, which returns a signed response indicating 'good,' 'revoked,' or 'unknown.' This is more efficient and timely than CRLs for single certificate checks.

  22. 22. A software developer is implementing a new secure file storage system. The requirement is to encrypt large files efficiently while ensuring that the encryption process can be easily parallelized across multiple processor cores. Which type of encryption algorithm is best suited for this scenario?

    Cryptography

    • A. Asymmetric encryption
    • B. Stream cipher
    • C. Block cipher in ECB mode
    • D. Block cipher in CBC mode
    Show answer

    B. Stream cipher

    Stream ciphers encrypt data bit by bit or byte by byte, making them inherently suitable for parallelization as each unit can be processed independently. This allows for high throughput, especially with large data sets.

  23. 23. A security analyst is reviewing a system that prevents users from downgrading the security classification of a document they are editing, even if they have read and write permissions at their current clearance level. This ensures that sensitive information does not accidentally or maliciously get released to a lower security domain. Which security model principle is being applied here?

    Access Controls

    • A. Strong Tranquility Property
    • B. Simple Security Property (No Read Up)
    • C. Discretionary Security Property
    • D. *-Property (Star Property or No Write Down)
    Show answer

    D. *-Property (Star Property or No Write Down)

    The Bell-LaPadula model's *-Property (Star Property) states that a subject cannot write to an object with a lower security classification (no write down). This prevents information from flowing from a higher security level to a lower one, directly matching the scenario.

  24. 24. A security auditor is reviewing a company's data at rest encryption strategy. The auditor notes that a significant portion of sensitive PII (Personally Identifiable Information) is encrypted using a symmetric key that is stored on the same server as the encrypted data. Which of the following cryptographic best practices is being violated?

    Cryptography

    • A. Key stretching
    • B. Key derivation
    • C. Key escrow
    • D. Key separation
    Show answer

    D. Key separation

    Storing the encryption key on the same server as the encrypted data violates the principle of key separation, which dictates that keys should be stored separately from the data they protect to prevent single points of compromise.

  25. 25. A security administrator is configuring access for a new human resources application. The application requires that users can only read their own personnel files but can view an aggregated, anonymized report of all employee salaries. What access control model best supports this specific requirement?

    Access Controls

    • A. Role-Based Access Control (RBAC)
    • B. Discretionary Access Control (DAC)
    • C. Context-Based Access Control
    • D. Mandatory Access Control (MAC)
    Show answer

    C. Context-Based Access Control

    Context-Based Access Control (CBAC) allows access decisions to be made based on environmental factors and the specific context of the request, such as the user's role, the time of access, the data being accessed, and the action being performed. This flexibility is ideal for scenarios where access varies dynamically based on the situation.

SSCP Systems Security Certified Practitioner flashcards

Tap a card to flip it. 162 flashcards in the full deck.

  • Single Sign-On (SSO)

    Flip card

    An authentication process that allows a user to access multiple independent software systems using a single set of login credentials.

    • Enhances user convenience by eliminating repeated logins.
    • Can improve security by centralizing authentication and reducing password fatigue.
    • Often implemented using protocols like SAML or OAuth.
    Study this card →
  • Post-Quantum Cryptography (PQC)

    Flip card

    Cryptographic algorithms designed to be secure against attacks from quantum computers, which could break many of the currently used public-key cryptographic algorithms.

    • Aims to replace current public-key cryptography.
    • Focuses on algorithms resistant to Shor's and Grover's algorithms.
    • Includes lattice-based, code-based, hash-based, and multivariate polynomial cryptography.
    Study this card →
  • Authenticated Encryption (AEAD)

    Flip card

    A type of encryption that simultaneously provides confidentiality, integrity, and authenticity for data. If any part of the ciphertext or associated authenticated data is modified, decryption and verification will fail.

    • Combines encryption with a Message Authentication Code (MAC).
    • Protects against tampering, decryption, and replay attacks.
    • Examples include AES-GCM and ChaCha20-Poly1305.
    Study this card →
  • AES-ECB Weakness

    Flip card

    Electronic Codebook (ECB) mode for block ciphers encrypts each block independently, leading to identical plaintext blocks producing identical ciphertext blocks, thus revealing data patterns.

    • Not suitable for encrypting large amounts of data or data with repeating patterns.
    • Often illustrated with the 'Tux' penguin example, where the outline of the penguin remains visible after encryption.
    • Should generally be avoided in favor of modes like CBC, CTR, or GCM for most applications.
    Study this card →
  • Certificate Authority (CA)

    Flip card

    A trusted entity in a PKI that issues, revokes, and manages digital certificates.

    • Root of trust in a PKI.
    • Digitally signs certificates it issues.
    • Maintains Certificate Revocation Lists (CRLs).
    Study this card →
  • Diffie-Hellman Key Exchange

    Flip card

    A cryptographic protocol that allows two parties to establish a shared secret key over an insecure communication channel.

    • Does not provide authentication by itself.
    • Vulnerable to man-in-the-middle attacks without authentication.
    • Based on the mathematical difficulty of the discrete logarithm problem.
    Study this card →
  • Multi-Factor Authentication (MFA)

    Flip card

    An authentication method that requires users to provide two or more distinct verification factors to gain access to a resource.

    • Significantly enhances security over single-factor authentication.
    • Combines different types of factors (knowledge, possession, inherence).
    • Commonly used in sensitive applications like banking.
    Study this card →
  • ECB Mode Vulnerability

    Flip card

    The vulnerability of Electronic Codebook (ECB) mode where identical plaintext blocks are encrypted into identical ciphertext blocks, revealing patterns in the encrypted data and compromising confidentiality.

    • Encrypts each block independently.
    • No chaining or initialization vector (IV).
    • Suitable only for very short, random data (e.g., encrypting other keys).
    Study this card →
  • Attribute-Based Access Control (ABAC)

    Flip card

    An authorization mechanism that grants or denies access to resources based on policies that evaluate attributes of the subject, object, action, and environmental conditions.

    • Provides highly granular and dynamic access control.
    • Scales well for complex environments with many users, resources, and conditions.
    • Policies are expressed as 'If-Then' rules based on attribute values.
    Study this card →
  • Federated Identity Management

    Flip card

    A system that allows for the portability of identity information across multiple, independent domains, enabling users to authenticate once and access various services without re-authentication.

    • Uses trusted identity providers (IdPs).
    • Enhances user convenience (single sign-on).
    • Reduces administrative burden for service providers.
    Study this card →
  • Role-Based Access Control (RBAC)

    Flip card

    An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job functions.

    • Simplifies access management in large organizations.
    • Reduces administrative overhead compared to DAC.
    • Roles can be hierarchical or constrained.
    Study this card →
  • Stream Cipher

    Flip card

    A symmetric key cipher that encrypts plaintext digits (bits or bytes) one at a time, and whose transformation of successive digits depends on the internal state of the cipher.

    • Encrypts data bit by bit or byte by byte.
    • Ideal for streaming data, real-time communication, and data of unknown length.
    • Requires a keystream generator to produce a pseudo-random sequence.
    Study this card →
  • Authenticated Encryption with Associated Data (AEAD)

    Flip card

    A type of encryption that simultaneously provides confidentiality (data privacy), integrity (data hasn't been altered), and authenticity (data comes from the expected source). It can also authenticate 'associated data' that is not encrypted.

    • Combines encryption and message authentication.
    • Prevents common cryptographic implementation pitfalls.
    • Often more efficient than separate encryption and MAC schemes.
    Study this card →
  • Perfect Forward Secrecy (PFS)

    Flip card

    A property of key agreement protocols that ensures that if one of the long-term keys is compromised, it does not compromise any past session keys derived from it.

    • Each session uses a unique, ephemeral session key.
    • Session keys are not derived directly from a master secret that could be compromised later.
    • Often implemented using Diffie-Hellman key exchange or elliptic curve Diffie-Hellman (ECDHE).
    Study this card →
  • Non-repudiation

    Flip card

    A cryptographic service that provides undeniable proof of the origin or integrity of data, or the identity of the sender, preventing the sender from falsely denying having sent a message or initiated a transaction.

    • Prevents denial of origin or action.
    • Typically achieved using digital signatures.
    • Crucial for legal and financial transactions.
    Study this card →
  • Key Separation (Cryptographic)

    Flip card

    The principle that different cryptographic keys should be used for different cryptographic functions (e.g., encryption, signing, MAC generation) to prevent a compromise of one key from undermining the security of other functions.

    • Assigns distinct keys for distinct operations.
    • Minimizes impact of key compromise.
    • Prevents cryptanalytic attacks that exploit multi-use keys.
    Study this card →
  • Password Hashing with Salt

    Flip card

    A cryptographic technique for securely storing passwords by transforming them into irreversible hash values, combined with a unique, random string (salt) for each password.

    • Protects against rainbow table attacks.
    • Ensures two identical passwords yield different hash values.
    • Makes brute-force attacks more computationally intensive.
    Study this card →
  • Bell-LaPadula Model: *-Property (Star Property)

    Flip card

    A security property within the Bell-LaPadula confidentiality model that prevents a subject from writing to an object that has a lower security classification (no write-down).

    • Aims to prevent information from flowing downwards to lower security levels.
    • Part of Mandatory Access Control (MAC).
    • Crucial for maintaining confidentiality in multi-level security systems.
    Study this card →
  • Separation of Duties

    Flip card

    An access control principle that divides critical functions and responsibilities among multiple individuals to prevent any single person from controlling an entire sensitive process end-to-end.

    • Reduces the risk of fraud, error, or malicious acts.
    • Requires multiple parties to complete a critical task.
    • Often implemented with dual control or two-person rules.
    Study this card →
  • Online Certificate Status Protocol (OCSP)

    Flip card

    A protocol used to obtain the revocation status of an X.509 digital certificate in real-time. Clients query an OCSP responder for the status of a specific certificate, receiving a signed response.

    • Provides real-time certificate revocation status.
    • More efficient than CRLs for single certificate checks.
    • Reduces network overhead compared to downloading large CRLs.
    Study this card →
  • Bell-LaPadula *-Property (Star Property)

    Flip card

    A rule in the Bell-LaPadula access control model that states a subject at a given security level cannot write to an object at a lower security level (also known as 'no write down').

    • Prevents information flow from higher to lower classification levels.
    • Crucial for maintaining confidentiality in multi-level security systems.
    • Works in conjunction with the Simple Security Property ('no read up').
    Study this card →
  • Key Separation

    Flip card

    The cryptographic principle of storing encryption keys separately from the data they protect to prevent unauthorized access to both simultaneously.

    • Enhances security by creating multiple points of failure for an attacker.
    • Often involves hardware security modules (HSMs) or separate key management systems.
    • Crucial for data at rest and data in transit encryption.
    Study this card →
  • Context-Based Access Control (CBAC)

    Flip card

    An access control model where decisions are made based on the context of the access request, including factors like user identity, time, location, data sensitivity, and the operation being performed.

    • Provides highly granular and dynamic access control.
    • Considers environmental and situational attributes.
    • Often used in environments with complex, changing access requirements.
    Study this card →
  • Rule-Based Access Control

    Flip card

    An access control mechanism that grants or denies access to resources based on a set of predefined rules or policies. These rules often incorporate conditions like time of day, location, or protocol.

    • Highly flexible and dynamic.
    • Rules are typically defined by administrators.
    • Can be used in conjunction with other models like RBAC or ABAC.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.