SSCP - Systems Security Certified Practitioner Practice Test

200 प्रश्न उपलब्ध

SSCP - Systems Security Certified Practitioner के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
125 परीक्षा प्रश्न
3 घंटे समय सीमा
Foundational स्तर
आपका अभ्यास
200 अभ्यास सवाल
3 घंटे 20 मिनट अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
पार करने की सीमा 700/1000 इस प्रमाणन के लिए प्रकाशित उत्तीर्णांक।
ISC2 से आधिकारिक उद्देश्य
ISC2200 अभ्यास प्रश्नबैंक 2026-07-24 को अपडेट हुआ
ब्लूप्रिंट सत्यापितISC2 official objectives के साथ जाँचा गयामेटाडेटा सत्यापित 2026-06-11हम कैसे सत्यापित करते हैं

परीक्षा का परिचय और विवरण

The Systems Security Certified Practitioner (SSCP) certification is a globally recognized credential offered by (ISC)² that validates a candidate's technical and operational proficiency in implementing, monitoring, and administering IT security infrastructure. Unlike management-focused certifications, the SSCP is designed for hands-on security practitioners-including security analysts, system engineers, network administrators, and security consultants-who are responsible for the day-to-day operation of security controls. The exam covers seven domains aligned with the (ISC)² Common Body of Knowledge (CBK): Access Controls, Cryptography, Incident Response and Recovery, Network and Communications Security, Risk Identification Monitoring and Analysis, Security Operations and Administration, and Systems and Application Security. Earning the SSCP demonstrates that you possess the technical skills to protect organizational assets, respond to security incidents, and ensure compliance with security policies. For employers, the SSCP is a trusted benchmark that reduces hiring risk and confirms a candidate's ability to perform critical security functions. For professionals, this certification opens doors to roles such as Security Administrator, Network Security Engineer, and SOC Analyst, and is often a stepping stone toward advanced certifications like the CISSP. With the global cybersecurity workforce shortage, holding an SSCP credential signals that you are part of a qualified, vetted community committed to industry best practices and ethical conduct.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

ISC2 SSCP - Systems Security Certified Practitioner

Place the following steps of the incident response process, as defined by NIST SP 800-61, in their CORRECT chronological order. 1. Containment, Eradication, and Recovery 2. Preparation 3. Post-Incident Activity 4. Detection and Analysis

स्पष्टीकरण:

सही क्रम निम्नलिखित है जो NIST कंप्यूटर सुरक्षा घटना प्रबंधन मार्गदर्शिका (SP 800-61) द्वारा परिभाषित घटना प्रतिक्रिया प्रक्रिया के चरणों को दर्शाता है:

सही क्रम निम्नलिखित है जो NIST कंप्यूटर सुरक्षा घटना प्रबंधन मार्गदर्शिका (SP 800-61) द्वारा परिभाषित घटना प्रतिक्रिया प्रक्रिया के चरणों को दर्शाता है:

  1. सजगता (Step 2), जिसमें घटना के पहले ही होने से पहले नीतियों, प्रक्रियाओं, टीमों और उपकरणों का निर्माण शामिल है। इसके बाद है व्याख्या और पता लगाना (Step 4), जहां संभावित घटनाओं की पहचान और जांच की जाती है ताकि उन्हें पुष्टि किया जा सके। एक बार पुष्टि हो जाने के बाद, सीमित करना, नष्ट करना, और पुनर्स्थापना चरण (Step 1) का पालन किया जाता है ताकि नुकसान को सीमित किया जा सके, खतरे को हटाया जा सके और प्रणालियों को पुनर्स्थापित किया जा सके। अंतिम चरण है घटना के बाद की गतिविधि (Step 3), जिसमें सबक सीखना, रिपोर्टिंग, और योजनाओं को अद्यतन करना शामिल है। 'PCER' (सजगता, सीमित करना, नष्ट करना, और पुनर्स्थापना) अक्षरों को याद रखना गलत है; सही प्रवाह सजगता -> व्याख्या/पता लगाना -> सीमित करना/नष्ट करना/पुनर्स्थापना -> घटना के बाद की गतिविधि है।
ISC2 SSCP - Systems Security Certified Practitioner

In the context of identity and access management, what does the principle of 'least privilege' primarily enforce?

स्पष्टीकरण:

श्रेणी के नामांकन और पहुंच प्रबंधन के संदर्भ में, 'कम से कम अधिकार' के सिद्धांत का मुख्य रूप से क्या प्रभावी होता है, इसका विवरण निम्नलिखित है:

कम से कम अधिकार एक मूलभूत सुरक्षा अवधारणा है जो उपयोगकर्ताओं, कार्यक्रमों या प्रक्रियाओं को उनके अधिकृत कार्यों को पूरा करने के लिए आवश्यक न्यूनतम स्तर की पहुंच (अनुमतियां, अधिकार, अधिकार) प्रदान करती है - और अधिक नहीं। यह दुर्घटनाओं, त्रुटियों या अनधिकृत उपयोगकर्ता क्रेडेंशियल्स के दुरुपयोग के संभावित नुकसान को सीमित करता है। यह पहुंच नियंत्रण रणनीतियों का एक मूलभूत घटक है। विकल्प बी सत्र समयबद्धता का वर्णन करता है, जो एक संबंधित लेकिन विशिष्ट नियंत्रण है। विकल्प सी समय पर पहुंच रद्दीकरण का एक हिस्सा वर्णित करता है, जो अक्सर प्रोविजनिंग सिस्टम द्वारा समर्थित होता है। विकल्प डी मल्टी-फैक्टर ऑथेंटिकेशन (एमएफए) का वर्णन करता है, जो पोस्ट-ऑथेंटिकेशन के बाद प्रदान किए गए पहुंच के स्तर को मजबूत करता है लेकिन सीधे परिभाषित नहीं करता है। कम से कम अधिकार का उद्देश्य किसी भी दिए गए खाते के 'हटारा सतह' या 'विस्फोट का क्षेत्रफल' को कम करना है।

Network and Communications Security

Attackers on a user VLAN send forged ARP replies after obtaining an IP address from DHCP. The switch can build a trusted binding table from DHCP assignments. Which controls should be paired?

ISC2 SSCP - Systems Security Certified Practitioner
Scenario

Secure Web Application Deployment A company is deploying a new customer-facing web application. The architecture includes a web server, an application server, and a database server, each on a separate host. The security team mandates that all communication between these tiers must be protected against eavesdropping and tampering.

Which of the following represents the MOST secure and practical network segmentation design to support this requirement?

स्पष्टीकरण:

विवरण: सुरक्षित वेब अनुप्रयोग प्रेषण

एक कंपनी एक नया ग्राहक-मुख्य वेब अनुप्रयोग प्रेषित कर रही है। वास्तुकला में एक वेब सर्वर, एक अनुप्रयोग सर्वर, और एक डेटाबेस सर्वर शामिल हैं, जिनमें प्रत्येक एक अलग होस्ट पर है। सुरक्षा टीम द्वारा मांग की गई है कि इन तीरों के बीच की सभी संचार को चोरी और हेरफेर के खिलाफ सुरक्षित किया जाए।

एक बहु-तीर सेगमेंटेशन मॉडल (वेब तीर, अनुप्रयोग/व्यवसायिक तर्क तीर, डेटा तीर) पूर्णतः सुरक्षित है। वेब सर्वर, जो सबसे अधिक उजागर है, डीएमजेड में रहता है। अनुप्रयोग सर्वर, जो सीधे इंटरनेट तक पहुंच योग्य नहीं होना चाहिए, एक अलग, अधिक सुरक्षित क्षेत्र (कभी-कभी 'मिडलवेयर' या 'अनुप्रयोग' डीएमजेड कहा जाता है) में रखा जाता है। डेटाबेस सर्वर, जो सबसे संवेदनशील डेटा रखता है, सबसे विश्वसनीय आंतरिक नेटवर्क सेगमेंट पर रखा जाता है। प्रत्येक क्षेत्र के बीच फ़ायरवॉल सख्त नियमों को लागू करते हैं (उदाहरण के लिए, डीएमजेड केवल विशिष्ट पोर्ट पर ऐप ज़ोन से बात कर सकता है, ऐप ज़ोन विशिष्ट पोर्ट पर डीबी से बात कर सकता है)। यह एक तीर को प्रभावित होने पर लेटरल गतिविधि को सीमित करता है। विकल्प बी आम है लेकिन कम सुरक्षित है क्योंकि यह ऐप और डीबी को एक साथ समूहित करता है। विकल्प ए कोई सेगमेंटेशन प्रदान नहीं करता है। विकल्प डी को यदि रिवर्स प्रॉक्सी हैक हो जाता है तो आंतरिक नेटवर्क को अनावश्यक रूप से उजागर करता है।

Network and Communications Security

An endpoint fails posture checks because EDR is disabled and critical patches are missing. The access switch should allow remediation services but block normal production access. Which network control supports this?

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

01Access Controls

02Cryptography

03Incident Response and Recovery

04Network and Communications Security

05Risk Identification, Monitoring and Analysis

06Security Concepts and Practices

07Systems and Application Security

परीक्षा विवरण SSCP | $249 USD | 3 घंटे

परीक्षा कोड SSCP
विक्रेता ISC2
परीक्षा शुल्क $249 USD
उत्तीर्ण अंक 700/1000
समय सीमा 3 घंटे
परीक्षा प्रश्न 125
प्रश्न प्रकारअभी इस भाषा में उपलब्ध नहीं है
पुनः परीक्षा नीति 30-day waiting period after first failed attempt. 90-day waiting period after second failed attempt. Maximum 3 attempts in a 12-month period. Full exam fee required for each retake.
ऑनलाइन निगरानी उपलब्ध
इसमें उपलब्ध
EnglishChineseGermanJapaneseKoreanSpanish

अक्सर पूछे जाने वाले प्रश्न

What are the prerequisites for taking the SSCP exam?

How does the SSCP differ from the CISSP?

Is the SSCP worth it for someone already holding CompTIA Security+?

How should I prepare for the SSCP exam?

What is the passing score and how is the exam structured?