Mixed Deck — All SSCA Topics Flashcards
100 cards from real SSCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All SSCA Topics flashcards as text
Which encryption standard is generally recommended for protecting sensitive data in Systems Security Certified Administrator?
Answer: AES-256 (Advanced Encryption Standard with 256-bit key)
AES-256 is the current industry standard for encrypting sensitive data, providing strong protection that is approved by government agencies for classified information.
What is the Diffie-Hellman key exchange primarily used for?
Answer: Allowing two parties to establish a shared secret over an untrusted channel
Diffie-Hellman enables two parties who have no prior shared secret to jointly derive a common symmetric key over an insecure channel without transmitting the key itself.
Which encryption standard is generally recommended for protecting sensitive data in Systems Security Certified Administrator?
Answer: AES-256 (Advanced Encryption Standard with 256-bit key)
AES-256 is the current industry standard for encrypting sensitive data, providing strong protection that is approved by government agencies for classified information.
What is the most important competency assessed in Emerging Technologies & Trends for professionals in this field?
Answer: Applied knowledge and practical problem-solving ability
Emerging Technologies & Trends assessment focuses on applied knowledge and practical problem-solving ability, ensuring professionals can effectively perform in real-world situations.
What is the relationship between Vulnerability Assessment & Penetration Testing and ethical professional conduct?
Answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Vulnerability Assessment & Penetration Testing, as professional conduct and integrity underpin all aspects of practice in this field.
What is a Certificate Signing Request (CSR)?
Answer: A message sent to a CA containing the applicant's public key and identity information
A CSR is a standardized message (typically PKCS#10 format) that an entity sends to a CA, containing its public key and identity details to request a signed certificate.
In multi‑factor authentication, which factor is considered "something you are"?
Answer: Fingerprint scan
In multi-factor authentication, "something you are" refers to a biometric factor, which is a unique physical characteristic of an individual. A fingerprint scan falls into this category, providing a strong and personal method of identity verification beyond just passwords or tokens.
What does the principle of least privilege require in an IAM system?
Answer: Provide limited access needed for job duties
The principle of least privilege in an Identity and Access Management (IAM) system requires that users are granted only the minimum level of access necessary to perform their specific job duties. This minimizes the potential for unauthorized actions, accidental errors, or malicious activity, enhancing overall security.
In the context of Systems Security Certified Administrator, what does "standard of care" refer to?
Answer: The level of care a reasonably competent professional would provide
Standard of care refers to the level of care that a reasonably competent professional with similar training would provide under similar circumstances.
When a safety incident occurs in a Systems Security Certified Administrator-related workplace, what documentation is typically required?
Answer: Incident report including date, time, location, persons involved, and corrective actions
Comprehensive incident documentation including all relevant details is essential for regulatory compliance, investigation, and prevention of future incidents.
What type of assessment does a SSCA professional conduct to identify system weaknesses?
Answer: Vulnerability assessment and penetration testing
Vulnerability assessments and penetration testing are systematic approaches to identifying and evaluating security weaknesses in systems, networks, and applications.
What is the main security benefit of implementing account lockout policies?
Answer: Prevent brute‑force password attacks
Account lockout policies are a critical security measure designed to prevent brute-force password attacks. By temporarily disabling an account after a specified number of failed login attempts, these policies thwart attackers from repeatedly guessing passwords until they succeed, thus protecting user accounts.
Which best describes the scope of Emerging Technologies & Trends in professional practice?
Answer: A comprehensive area covering both theoretical foundations and practical applications
Emerging Technologies & Trends encompasses both theoretical foundations and practical applications that are essential to professional practice in this field.
What is the relationship between Disaster Recovery & Backup and ethical professional conduct?
Answer: Ethical considerations are integrated into all aspects of professional practice in this area
Ethical considerations are deeply integrated into Disaster Recovery & Backup, as professional conduct and integrity underpin all aspects of practice in this field.
What is the first step in the incident response lifecycle?
Answer: Preparation
The incident response lifecycle typically begins with the Preparation phase. This involves establishing policies, developing plans, training staff, and implementing security controls *before* an incident occurs. Effective preparation is crucial for an organization to respond quickly and effectively when an actual incident takes place, minimizing its impact.
Which of the following is a key component of project management in Systems Security Certified Administrator?
Answer: Defining clear objectives, timelines, and deliverables
Clear objectives, realistic timelines, and well-defined deliverables are fundamental components of effective project management that ensure successful outcomes.
Which cipher suite component provides forward secrecy by ensuring that past session keys cannot be recovered even if the server's long-term private key is compromised?
Answer: Ephemeral ECDHE key exchange
Ephemeral ECDHE generates a new key pair for each session; since session keys are never derived from the long-term private key, their compromise does not expose past sessions.
Which process involves reviewing and analyzing logs for unusual or suspicious activity?
Answer: Log review
Log review is the process of systematically examining system-generated records for unusual or suspicious activity. This proactive measure helps identify potential security breaches, policy violations, or operational issues that might otherwise go unnoticed, allowing for timely investigation and remediation.
In asymmetric cryptography, which key is used to verify a digital signature?
Answer: The signer's public key
A digital signature is created with the signer's private key and verified using the corresponding public key, confirming authenticity and non-repudiation.
In Systems Security Certified Administrator, what is the PRIMARY purpose of network segmentation?
Answer: To limit the spread of security breaches and control access between network zones
Network segmentation limits the lateral movement of attackers and controls access between different network zones, reducing the potential impact of security breaches.