SSCP Exam Questions
1,274 real SSCP exam questions with expert-verified answers and explanations. Page 14 of 26.
- Question #659Cryptography
Which of the following encryption algorithms does not deal with discrete logarithms?
Cryptographic algorithmsDiscrete logarithmRSAPublic-key cryptography - Question #660Cryptography
Which of the following statements pertaining to message digests is incorrect?
Message DigestsHash FunctionsCryptography BasicsData Integrity - Question #661Cryptography
Which type of attack is based on the probability of two different messages using the same hash function producing a common message digest?
Hash functionsCollision attacksBirthday attack - Question #662Cryptography
Which of the following elements is NOT included in a Public Key Infrastructure (PKI)?
PKICryptographyCertificatesIKE - Question #663Cryptography
Which of the following was developed in order to protect against fraud in electronic fund transfers (EFT) by ensuring the message comes from its claimed originator and that it has...
Message Authentication Code (MAC)Data IntegrityMessage AuthenticationEFT Security - Question #664Network and Communications Security
Which of the following statements pertaining to Secure Sockets Layer (SSL) is false?
SSL/TLSNetwork ProtocolsCryptographyAuthentication - Question #665Network and Communications Security
What is the name of the protocol use to set up and manage Security Associations (SA) for IP Security (IPSec)?
IPSecInternet Key Exchange (IKE)Security Associations (SA)Key Management - Question #666Cryptography
Which of the following binds a subject name to a public key value?
Public-key certificateDigital certificatePKIPublic key - Question #667Access Controls
What can be defined as a digital certificate that binds a set of descriptive data items, other than a public key, either directly to a subject name or to the identifier of another...
Digital CertificatesAttribute CertificatesPKIAuthorization - Question #668Cryptography
What can be defined as a data structure that enumerates digital certificates that were issued to CAs but have been invalidated by their issuer prior to when they were scheduled to...
PKICertificate RevocationARLCA Certificates - Question #669Cryptography
What is the name of the third party authority that vouches for the binding between the data items in a digital certificate?
digital certificatesPKICertification Authority (CA)trust anchor - Question #670Cryptography
What enables users to validate each other's certificate when they are certified under different certification hierarchies?
Cross-certificationPKICertificate validationTrust models - Question #671Cryptography
Which of the following would best define a digital envelope?
Digital EnvelopeHybrid EncryptionSymmetric Encryption - Question #672Cryptography
What can be defined as a value computed with a cryptographic algorithm and appended to a data object in such a way that any recipient of the data can use the signature to verify th...
Digital signaturesNon-repudiationData integrity - Question #673Cryptography
Which of the following can be best defined as computing techniques for inseparably embedding unobtrusive marks or labels as bits in digital data and for detecting or extracting the...
Digital watermarkingInformation hidingData embeddingCopyright protection - Question #674Network and Communications Security
Which of the following is an Internet IPsec protocol to negotiate, establish, modify, and delete security associations, and to exchange key generation and authentication data, inde...
IPsecISAKMPKey ManagementSecurity Associations - Question #675Network and Communications Security
Which of the following is defined as a key establishment protocol based on the Diffie-Hellman algorithm proposed for IPsec but superseded by IKE?
IPsecKey Exchange ProtocolsCryptography ProtocolsOAKLEY - Question #676Network and Communications Security
Which of the following is defined as an Internet, IPsec, key-establishment protocol, partly based on OAKLEY, that is intended for putting in place authenticated keying material for...
IKEIPsecKey ExchangeISAKMP - Question #677Cryptography
Which of the following can best be defined as a key distribution protocol that uses hybrid encryption to convey session keys. This protocol establishes a long-term key once, and th...
Key Distribution ProtocolHybrid EncryptionSKIPSession Keys - Question #678Cryptography
Which of the following can best be defined as a cryptanalysis technique in which the analyst tries to determine the key from knowledge of some plaintext-ciphertext pairs?
CryptanalysisKnown-plaintext attackCryptographic attacks - Question #679Cryptography
Which of the following is NOT a property of a one-way hash function?
Hash FunctionsCryptography PrinciplesData IntegrityMessage Digest - Question #680Cryptography
The Data Encryption Algorithm performs how many rounds of substitution and permutation?
DESData Encryption AlgorithmSymmetric EncryptionBlock Cipher Rounds - Question #681Cryptography
Which of the following statements is most accurate regarding a digital signature?
Digital SignaturesCryptographyData IntegrityAuthentication - Question #682Cryptography
The computations involved in selecting keys and in enciphering data are complex, and are not practical for manual use. However, using mathematical properties of modular arithmetic...
RSAModular ArithmeticGalois FieldsCryptographic Algorithms - Question #683Cryptography
Which of the following concerning the Rijndael block cipher algorithm is false?
RijndaelBlock CipherAESCryptography Parameters - Question #684Cryptography
This type of attack is generally most applicable to public-key cryptosystems, what type of attack am I ?
CryptographyCryptanalytic attacksChosen-ciphertext attackPublic-key cryptography - Question #685Cryptography
What is NOT true about a one-way hashing function?
HashingMessage IntegrityMessage AuthenticationCryptography Fundamentals - Question #686Incident Response and Recovery
You work in a police department forensics lab where you examine computers for evidence of crimes. Your work is vital to the success of the prosecution of criminals. One day you rec...
ForensicsEvidence HandlingChain of Custody - Question #687Cryptography
When we encrypt or decrypt data there is a basic operation involving ones and zeros where they are compared in a process that looks something like this: 0101 0001 Plain text 0111 0...
CryptographyBitwise operationsXOR - Question #688Cryptography
Which type of encryption is considered to be unbreakable if the stream is truly random and is as large as the plaintext and never reused in whole or part?
One-Time PadPerfect SecrecySymmetric EncryptionEncryption Principles - Question #689Cryptography
Which of the following answers is described as a random value used in cryptographic algorithms to ensure that patterns are not created during the encryption process?
Initialization VectorCryptographyEncryption - Question #690Security Concepts and Practices
Which of the following terms can be described as the process to conceal data into another file or media in a practice known as security through obscurity?
SteganographyData HidingSecurity Through Obscurity - Question #691Cryptography
Which of the following type of cryptography is used when both parties use the same key to communicate securely with each other?
Symmetric CryptographyShared Secret KeyEncryption - Question #692Cryptography
Complete the blanks. When using PKI, I digitally sign a message using my ______ key. The recipient verifies my signature using my ______ key.
Digital SignaturesPKIAsymmetric Cryptography - Question #693Cryptography
Which of the following BEST describes a function relying on a shared secret key that is used along with a hashing algorithm to verify the integrity of the communication content as...
Message Authentication CodeCryptographyIntegrityAuthentication - Question #694Network and Communications Security
Which of the following type of traffic can easily be filtered with a stateful packet filter by enforcing the context or state of the request?
Stateful FirewallTCP/IP ProtocolsNetwork SecurityFirewall Filtering - Question #695Network and Communications Security
Which of the following access methods is used by Ethernet?
EthernetCSMA/CDMedia Access ControlNetworking Fundamentals - Question #696Network and Communications Security
Which of the following layers provides end-to-end data transfer service?
OSI ModelTransport LayerNetworking FundamentalsEnd-to-end communication - Question #697Network and Communications Security
The IP header contains a protocol field. If this field contains the value of 17, what type of data is contained within the ip datagram?
IP HeaderUDPProtocol NumbersNetworking Protocols - Question #698Network and Communications Security
How do you distinguish between a bridge and a router?
Network devicesOSI ModelBridgesRouters - Question #699Network and Communications Security
ICMP and IGMP belong to which layer of the OSI model?
OSI ModelNetwork LayerICMPIGMP - Question #700Network and Communications Security
Telnet and rlogin use which protocol?
Transport ProtocolsTCP/IPNetwork ServicesTelnet - Question #701Access Controls
What is a limitation of TCP Wrappers?
TCP WrappersNetwork Access ControlUDP ServicesHost-based Security - Question #702Network and Communications Security
The IP header contains a protocol field. If this field contains the value of 6, what type of data is contained within the ip datagram?
IP HeaderProtocol FieldTCP/IPNetworking Protocols - Question #703Network and Communications Security
The IP header contains a protocol field. If this field contains the value of 1, what type of data is contained within the IP datagram?
IP HeaderProtocol NumbersICMPNetworking Fundamentals - Question #704Network and Communications Security
The IP header contains a protocol field. If this field contains the value of 2, what type of data is contained within the IP datagram?
IP headerProtocol fieldIGMPNetworking protocols - Question #705Network and Communications Security
What is the proper term to refer to a single unit of Ethernet data at the link layer of the DoD TCP model ?
Networking ConceptsOSI ModelDoD ModelEthernet Frame - Question #706Network and Communications Security
What is the proper term to refer to a single unit of IP data?
Networking FundamentalsIP DatagramOSI ModelProtocol Data Unit (PDU) - Question #707Systems and Application Security
You are running a packet sniffer on a network and see a packet containing a long string of "0x90 0x90 0x90 0x90...." in the middle of it traveling to an x86-based machine as a targ...
Buffer OverflowNOP SledExploit DetectionVulnerability Exploitation - Question #708Systems and Application Security
A packet containing a long string of NOP's followed by a command is usually indicative of what?
Buffer OverflowExploitationCode InjectionVulnerability