Systems Security Certified Practitioner (SSCP) - Exam Prep

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/161

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:25 PM on 8/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

162 Terms

1
New cards

Access Control Object

A passive entity that typically receives or contains some form of data.

2
New cards

Access Control Subject

An active entity and can be any user, program, or process that requests permission to cause data to flow from an access control object to the access control subject or between access control objects.

3
New cards

Asynchronous Password Token

A one-time password is generated without the use of a clock, either from a one-time pad or cryptographic algorithm.

4
New cards

Authorization

Determines whether a user is permitted to access a particular resource.

5
New cards

Connected Tokens

Must be physically connected to the computer to which the user is authenticating.

6
New cards

Contactless Tokens

Form a logical connection to the client computer but do not require a physical connection.

7
New cards

Disconnected Tokens

Have neither a physical nor logical connection to the client computer.

8
New cards

Entitlement

A set of rules, defined by the resource owner, for managing access to a resource (asset, service, or entity) and for what purpose.

9
New cards

Identity Management

The task of controlling information about users on computers.

10
New cards

Proof of Identity

Verify people's identities before the enterprise issues them accounts and credentials.

11
New cards

Kerberos

A popular network authentication protocol for indirect (third-party) authentication services.

12
New cards

Lightweight Directory Access Protocol (LDAP)

A client/server-based directory query protocol loosely based on X.500, commonly used to manage user information. LDAP is a front end and not used to manage or synchronize data per se as opposed to DNS.

13
New cards

Single Sign-On (SSO)

Designed to provide strong authentication using secret-key cryptography, allowing a single identity to be shared across multiple applications.

14
New cards

Static Password Token

The device contains a password that is physically hidden (not visible to the possessor) but that is transmitted for each authentication.

15
New cards

Synchronous Dynamic Password Token

A timer is used to rotate through various combinations produced by a cryptographic algorithm.

16
New cards

Trust Path

A series of trust relationships that authentication requests must follow between domains

17
New cards

Availability

Refers to the ability to access and use information systems when and as needed to support an organization's operations.

18
New cards

Breach

The intentional or unintentional release of secure information to an untrusted environment.

19
New cards

CMDB

A configuration management database (CMDB) is a repository that contains a collection of IT assets that are referred to as configuration items.

20
New cards

Compensating Controls

Introduced when the existing capabilities of a system do not support the requirements of a policy.

21
New cards

Confidentiality

Refers to the property of information in which it is only made available to those who have a legitimate need to know.

22
New cards

Configuration Management (CM)

A discipline that seeks to manage configuration changes so that they are appropriately approved and documented, so that the integrity of the security state is maintained, and so that disruptions to performance and availability are minimized.

23
New cards

Corrective Control

These controls remedy the circumstances that enabled unwarranted activity, and/ or return conditions to where they were prior to the unwanted activity.

24
New cards

COTS

A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can be purchased n the commercial marketplace and used under government contract.

25
New cards

Deduplication

A process that scans the entire collection of information looking for similar chunks of data that can be consolidated.

26
New cards

Defense-in-depth

Provision of several overlapping subsequent limiting barriers with no respect to one safety or security threshold, so that the threshold can only be surpassed if all barriers have failed.

27
New cards

Degaussing

A technique of erasing data on disk or tape (including video tapes) that, when performed properly, ensures that there is insufficient magnetic remanence to reconstruct data.

28
New cards

Deluge System

A fire suppression system with open sprinker heads, water is held back until a detector in the area is activated.

29
New cards

Deterrent Control

Controls that prescribe some sort of punishment, randing from embarrassment to job termination or jail time for noncompliance. Their intent is to dissuade people from performing unwanted acts.

30
New cards

Directive Control

Controls dictated by organizational and legal authorities.

31
New cards

Dry System

A fire suppression system that does not have water in the pipes until the electric valve is stimulated by excess heat.

32
New cards

Dual Control

A procedure that uses two or more entities (usually persons) operating in concert to protect a system resource, such that no single entity acting alone can access that resource.

33
New cards

Information Rights Management (IRM)

Assigns specific properties to an object such as how long the object may exist, what users or systems may access it, and if any notifications need to occur when the file is opened, modified, or printed.

34
New cards

Integrity

The property of information whereby it is recorded, used, and maintained in a way that ensures its completeness, accuracy, internal consistency, and usefulness for a stated purpose.

35
New cards

IT Asset Management (ITAM)

Entails collecting inventory and financial and contractual data to manage the IT asset throughout its life cycle.

36
New cards

Least Privilege

A security principle in which any user/process is given only the necessary, minimum level of access rights (privileges) explicitly, for the minimum amount of time, in order for it to complete its operation.

37
New cards

Non-repudiation

A service that is used to provide assurance of the integrity and origin of data in such a way that the integrity and origin can be verified by a third party as having originated from a specific entity in possession of the private key of the claimed signatory.

38
New cards

Pre-action System

A fire suppression system that contains water in the pipes but will not release the water until detectors in the area have been activated. This can eliminate concerns of water damage due to accidental or false activation.

39
New cards

Preventive Control

Controls that block unwanted actions.

40
New cards

Privacy

The rights and obligations of individuals and organizations with respect to the collection, use, retention, and disclosure of personal information.

41
New cards

Procedures

Step-by-step instructions for performing a specific task or set of tasks.

42
New cards

Release Management

A software engineering discipline that controls the release of applications, updates, and patches to the production environment.

43
New cards

Release Management Policy

Specifies the conditions that must be met for an application or component to be released to production, roles and responsibilities for packaging, approving, moving, and testing code releases, and approval and documentation requirements.

44
New cards

Release Manager

Responsible for planning, coordination, implementation, and communication of all application releases.

45
New cards

Separation of Duties

An operational security mechanism for preventing fraud and unauthorized use that requires two or more individuals to complete a task or perform a specific function.

46
New cards

Systems Integrity

The maintenance of a known good configuration and expected operational function.

47
New cards

Annualized Loss Expectancy (ALE)

The expected annual loss because of a risk to a specific asset.

48
New cards

Annualized Rate of Occurrence (ARO)

The expected number of exploitations by a specific threat of a vulnerability to an asset in a given year.

49
New cards

Antivirus Gateways

Monitoring control for viruses contained within communications of major application types, such as web traffic, e-mail, and FTP.

50
New cards

Asset

Anything of value that is owned by an organization. Assets include both tangible items such as information systems and physical property and intangible assets such as intellectual property.

51
New cards

Countermeasure

An added-on reactive security controls.

52
New cards

Exploit

A particular attack. It is named this way because these attacks exploit system vulnerabilities.

53
New cards

False Negative

The monitoring system missed reporting an exploit event by not firing an alarm.

54
New cards

False Positive

Monitoring triggered an event but nothing was actually wrong, and in doing so the monitoring has incorrectly identified benign communications as a danger.

55
New cards

Impact

The magnitude of harm that could be caused by a threat's exercise of a vulnerability.

56
New cards

Java/ActiveX Filters

These security gateway systems screen communications for these components and block or limit their transmission.

57
New cards

Likelihood

The probability that a potential vulnerability may be exercised within the construct of the associated threat environment.

58
New cards

Network Mapping

A process that "paints the picture" of which hosts are up and running externally or internally and what services are available on the system.

59
New cards

Promiscuous Interface

A network interface that collects and processes all of the packets sent to it regardless of the destination MAC address.

60
New cards

Risk

A function of the likelihood of a given threat source exercising a potential vulnerability, and the resulting impact of that adverse event on the organization.

61
New cards

Residual Risk

The risk that remains after risk reduction and mitigation efforts are complete.

62
New cards

Risk Assessments

Assess threats to information systems, system vulnerabilities and weaknesses, and the likelihood that threats will exploit these vulnerabilities and weaknesses to cause adverse effects.

63
New cards

Risk Register

Serves as a way for the organization to know their possible exposure at a given time.

64
New cards

Safeguard

A built-in proactive security control implemented to provide protection against threats.

65
New cards

Signature

A string of characters or activities found within processes or data communications that describes a known system attack.

66
New cards

Single Loss Expectancy (SLE)

The expected monetary loss to an organization from a threat to an asset.

67
New cards

Threat

The potential for a threat source to exercise (accidentally trigger or intentionally exploit) a specific vulnerability.

68
New cards

Threat Source

Either intent or method targeted at the intentional exploitation of a vulnerability or a situation or method that may accidentally trigger a vulnerability.

69
New cards

True Negative

The monitoring system has not recognized benign traffic as cause for concern.

70
New cards

True Positive

The monitoring system recognized an exploit event correctly.

71
New cards

Tuning

Customizing a monitoring system to your environment.

72
New cards

Vulnerability

A system weakness.

73
New cards

War Dialing

Attempts to locate unauthorized, also called rogue, modems connected to computers that are connected to networks.

74
New cards

War Driving

Involves traveling around with a wireless scanner looking for wireless access points.

75
New cards

Web Traffic Screening

These systems block web traffic to and from specific sites or sites of a specific type.

76
New cards

Business Continuity Planning

The proactive development of a plan that can be executed to restore business operations within predetermined times after a disaster or other significant disruption to the organization.

77
New cards

Adverse Events

Events with a negative consequence, such as system crashes, network packet floods, unauthorized use of system privileges, defacement of a web page, and execution of malicious code that destroys data.

78
New cards

Clustering

A method of configuring multiple computers so that they effectively operate as a single system.

79
New cards

Computer Security Incident

A violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.

80
New cards

Differential Backups

Records differences in data since the most recent full backup.

81
New cards

Event

Any observable occurrence in a system or network.

82
New cards

Full Backup

Copies the entire system to backup media.

83
New cards

Full Interruption Testing

When business operations are actually interrupted at the primary processing facility.

84
New cards

High Availability Clustering

A clustering method that uses multiple systems to reduce the risk associated with a single point of failure.

85
New cards

Incremental Backups

Records changes that are made to the system since the last incremental backup.

86
New cards

Intrusion Detection Systems (IDS)

Use available information to determine if an attack is underway, send alerts, and provide limited response capabilities.

87
New cards

Intrusion Prevention Systems (IPS)

Use available information to determine if an attack is underway, send alerts but also block the attack from reaching its intended target.

88
New cards

Locard's Principle of Exchange

States that when a crime is committed, the perpetrators leave something behind and take something with them, hence the exchange.

89
New cards

Maximum Tolerable Downtime (MTD)

The maximum amount of time that a business function can be unavailable before the organization is harmed to a degree that puts the survivability of the organization at risk.

90
New cards

Recovery Point Objective (RPO)

Specifies the point in time to which data could be restored in the event of a business continuity disruption.

91
New cards

Recovery Time Objective (RTO)

Indicates the period of time within which a business function or information system must be restored after a disruption.

92
New cards

Asymmetric

Two different but mathematically related keys are used where one key is used to encrypt and another is used to decrypt.

93
New cards

Asynchronous

Encrypt/Decrypt requests are processed in queues.

94
New cards

Certificate Authority (CA)

An entity trusted by one or more users as an authority in a network that issues, revokes, and manages digital certificates.

95
New cards

Cryptanalysis

The study of techniques for attempting to defeat cryptographic techniques and, more generally, information security services.

96
New cards

Cryptology

The science that deals with hidden, disguised, or encrypted communications. It embraces communications security and communications intelligence.

97
New cards

Cryptosystem

Represents the entire cryptographic operation. This includes the algorithm, the key, and key management functions.

98
New cards

Decryption

The reverse process from encryption. It is the process of converting a ciphertext message into plaintext through the use of the cryptographic algorithm and key that was used to do the original encryption.

99
New cards

Digital Certificate

An electronic document that contains the name of an organization or individual, the business address, the digital signature of the certificate authority issuing the certificate.

100
New cards

Digital Signatures

Provide authentication of a sender and integrity of a sender's message.